<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=obsidian+notion+logseq+notetaking%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 28 Jul 2026 15:12:55 +0200</lastBuildDate>
<pubDate>Tue, 28 Jul 2026 15:12:55 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=obsidian+notion+logseq+notetaking%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=obsidian+notion+logseq+notetaking%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Microsoft hat gerade mein Lieblingsspiel aus der alten Xbox-Ära für den PC veröffentlicht]]></title>
<description><![CDATA[Wir schreiben das Jahr 2003. Ich bin ein Neuntklässler und spiele auf der Original-Xbox mit einem Controller, der ungefähr so groß ist wie eine Servierplatte. Ich besitze Halo und  Dead or Alive 3 und bin von der Grafik völlig begeistert. Das nächste Spiel, das ich mir kaufe, ist Crimson Skies, e...]]></description>
<link>https://tsecurity.de/de/3689084/it-nachrichten/microsoft-hat-gerade-mein-lieblingsspiel-aus-der-alten-xbox-aera-fuer-den-pc-veroeffentlicht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689084/it-nachrichten/microsoft-hat-gerade-mein-lieblingsspiel-aus-der-alten-xbox-aera-fuer-den-pc-veroeffentlicht/</guid>
<pubDate>Thu, 23 Jul 2026 14:49:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Wir schreiben das Jahr 2003. Ich bin ein Neuntklässler und spiele auf der Original-Xbox mit einem Controller, der ungefähr so groß ist wie eine Servierplatte. Ich besitze <em>Halo </em>und  <em>Dead or Alive 3</em> und bin von der Grafik völlig begeistert. Das nächste Spiel, das ich mir kaufe, ist <em>Crimson Skies</em>, ein arcadeartiges Luftkampfspiel, das alternative Geschichte mit Abenteuer-Pulp verbindet und über eine wirklich hervorragende Steuerung verfügt.</p>



<p>Seit über 20 Jahren versuche ich nun, dieses Gefühl – wenn schon nicht genau diese Erfahrung – wieder aufleben zu lassen. </p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<p>Die meisten der Blockbuster-Titel aus dem ursprünglichen Xbox-Sortiment können Sie bereits jetzt auf dem PC spielen, darunter auch <em>Halo</em>, für das sowohl ein Remaster als auch ein Remake in Vorbereitung sind. Einige der eher nischenorientierten Titel waren jedoch schon seit sehr, sehr langer Zeit nicht mehr erhältlich, mit Ausnahme einiger weniger, die Sie über den Game Pass streamen können.</p>



<p>Microsoft hat beschlossen, einige dieser weniger bekannten Klassiker – und vielleicht auch ein paar, die dem Begriff „Klassiker“ nicht ganz gerecht werden – in Form vollständiger Portierungen für PC-Spieler verfügbar zu machen.</p>



<h2 class="wp-block-heading">Xbox-„Klassiker“ erhalten PC-Ports</h2>



<p>Das Unternehmen nennt dies „<a href="https://news.xbox.com/en-us/2026/07/22/xbox-backward-compatibility-on-pc/">Xbox-Abwärtskompatibilität auf dem PC</a>“. Der Start erfolgt mit vier Spielen, weitere sollen in Kürze folgen. Diese Spiele laufen lokal auf Ihrem Windows-PC, offenbar ohne jegliche Emulation (oder falls eine Emulation stattfindet, wird dies nicht ausdrücklich erwähnt), wobei bestimmte Mindestsystemanforderungen gelten, darunter eine GTX 950- oder Radeon RX 550-Grafikkarte. Grundsätzlich sollte jeder PC, der in den letzten sechs oder sieben Jahren auf den Markt gekommen ist, diese Anforderungen erfüllen, einschließlich Laptops und Handhelds mit integrierter Grafik.</p>



<p>Zu den ersten Titeln gehört <em>Crimson Skies: High Road to Revenge</em>, von dem ich erst später erfuhr, dass es sich um eine ausschließlich für Konsolen veröffentlichte Fortsetzung eines früheren PC-Spiels handelt. Es kostet zehn Euro – erstaunlich günstig in einer Welt, in der Microsoft 40 Euro für eine Wieder-Wieder-Wiederveröffentlichung von <em>Skyrim </em>verlangt<em>.</em></p>



<p>Ich habe es sofort gekauft und wollte es herunterladen … doch das geht nicht, da es laut der Xbox-App für Windows nur per Streaming über den Game Pass verfügbar ist.</p>



<p>Microsoft gibt an, dass man die neueste Version des Xbox-Insider-Builds benötigt, über die ich bereits verfüge. Dies scheint eine schrittweise Einführung zu sein – ein häufiges Problem bei Funktionen, die von der Xbox-Windows-App abhängig sind. Ich bin etwas verärgert, dass ich es nicht sofort ausprobieren kann.</p>



<p>Das bedeutet auch, dass es nahezu unmöglich sein wird, das Spiel auf einem SteamOS-basierten Gerät zu spielen. Was für mich persönlich sehr schade ist, <a href="https://www.pcwelt.de/article/3194800/steam-machine-im-praxistest-ganz-nett-aber-leider-enttaeuschend.html" target="_blank" rel="noreferrer noopener">da ich gerade erst eine Steam Machine gekauft habe</a>. Ich werde diesen Artikel aktualisieren, sobald ich das Spiel zum Laufen gebracht habe.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a620da47251c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/image_552da1.png?w=1200" alt="ROG Xbox Ally X playing Crimson Skies" class="wp-image-3197144" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Microsoft</p></div>



<p>Die weiteren Titel sind <em>Blinx: The Time Sweeper</em>, einer der frühen Versuche, der Xbox ein Maskottchen-Plattformspiel zu geben, <em>Conker: Live &amp; Reloaded</em>, ein Remake des N64-Kuriosums <em>Conker’s Bad Fur Day</em>, das<em> </em>nach der Übernahme von Rare durch Microsoft entstand, sowie das extrem für die 2000er Jahre typische Partyspiel <em>Fusion Frenzy</em>. Alle vier waren Teil von Microsofts anfänglicher Veröffentlichungsoffensive für die Xbox, und <em>Blinx </em>sowie<em> Crimson Skies </em>sind zudem über den Game Pass verfügbar.</p>



<p>Ich bin mir sicher, dass es vielen PC-Spielern genauso geht wie mir und sie an mindestens eines dieser Spiele schöne Erinnerungen haben. Insbesondere <em>Blinx</em> bot einige sehr interessante Spielkonzepte, die auf älteren Konsolen nicht möglich waren – ermöglicht durch die interne 8-GB-Festplatte der Xbox, ein entscheidender Unterschied zur Playstation 2 und anderen Konsolen. Weitere Spiele sollen angeblich in Zukunft in die Xbox-Abwärtskompatibilität aufgenommen werden, wobei nicht genau angegeben wurde, um welche es sich dabei handelt.</p>



<h2 class="wp-block-heading">Tiefgreifende Probleme bei Xbox bleiben bestehen</h2>



<p>Doch ich fürchte, ich muss die Stimmung hier zum Schluss etwas trüben. Die Xbox als Plattform und als Geschäftsbereich von Microsoft befindet sich in einer prekären Lage: Sie kann im Wettbewerb mit der Playstation nicht mithalten, wird von Valve mit Steam und SteamOS unter Druck gesetzt und entlässt Tausende von Mitarbeitern aus ihrem riesigen, kostspieligen Bestand an Entwicklern und Publishern. Xbox muss dringend Spieler zurückgewinnen, die nach den massiven Preiserhöhungen für den Game Pass und die Xbox-Hardware möglicherweise zögern, der Plattform noch zu vertrauen.</p>



<p>Diese nostalgischen Neuzugänge für den PC folgen kurz nach Gerüchten über ein neues <em>Fallout-</em>Spiel des bei Fans beliebten Entwicklers (und der Microsoft-Tochter) Obsidian, der stark von Entlassungen betroffen war. Es liegt nahe, beide Schritte als Versuch zu betrachten, das Ruder herumzureißen und/oder die Spieler dazu zu bringen, die tiefgreifenden Probleme innerhalb von Xbox und Microsoft insgesamt zu vergessen. Dazu wird es jedoch mehr als eine 23 Jahre alte Portierung brauchen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[We must reject any notion of AI consciousness | Letters]]></title>
<description><![CDATA[Artificial intelligence systems won’t become conscious for the same reason they won’t become pregnant, says Dr John PickeringAnil Seth is right to point out that to overestimate artificial intelligence is to underestimate ourselves (Once again we are told AI may be conscious – I study consciousne...]]></description>
<link>https://tsecurity.de/de/3687083/ai-nachrichten/we-must-reject-any-notion-of-ai-consciousness-letters/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687083/ai-nachrichten/we-must-reject-any-notion-of-ai-consciousness-letters/</guid>
<pubDate>Wed, 22 Jul 2026 19:05:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Artificial intelligence systems won’t become conscious for the same reason they won’t become pregnant, says <strong>Dr John Pickering</strong></p><p>Anil Seth is right to point out that to overestimate artificial intelligence is to underestimate ourselves (<a href="https://www.theguardian.com/commentisfree/2026/jul/15/ai-consciousness-anthropic-claude-dawkins">Once again we are told AI may be conscious – I study consciousness, and I have my doubts, 15 July</a>). But he is wrong only to have doubts about whether AI systems like Claude may become conscious. He should be certain, and should say so more forcefully.</p><p>It’s not like anything to be Claude, just as it’s not like anything to be a washing machine. An academic education is not required to realise that, common sense will do. Artificial intelligence systems won’t become conscious for the same reason they won’t become pregnant; they’re not that sort of thing.</p> <a href="https://www.theguardian.com/technology/2026/jul/22/we-must-reject-any-notion-of-ai-consciousness">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian: Neues Plugin bringt echten Nextcloud-Sync ohne Datenverlust - Caschys Blog]]></title>
<description><![CDATA[Das Plugin unterstützt neben macOS, Windows und Linux auch die mobilen Ableger für iOS und Android. ... Auf Server-Seite empfehlen die Entwickler ...]]></description>
<link>https://tsecurity.de/de/3681156/windows-server/obsidian-neues-plugin-bringt-echten-nextcloud-sync-ohne-datenverlust-caschys-blog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681156/windows-server/obsidian-neues-plugin-bringt-echten-nextcloud-sync-ohne-datenverlust-caschys-blog/</guid>
<pubDate>Mon, 20 Jul 2026 14:48:08 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Plugin unterstützt neben macOS, <b>Windows</b> und Linux auch die mobilen Ableger für iOS und Android. ... Auf <b>Server</b>-Seite empfehlen die Entwickler ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Vier neue „Fallout“-Spiele: „Fallout 5“ und mehrere Remaster in Arbeit]]></title>
<description><![CDATA[Bethesda arbeitet an „Fallout 5“, Remastern von „Fallout 3“ und „New Vegas“ sowie einem neuen „Fallout“ von Obsidian. Termine gibt es bisher keine.]]></description>
<link>https://tsecurity.de/de/3680746/it-nachrichten/vier-neue-fallout-spiele-fallout-5-und-mehrere-remaster-in-arbeit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680746/it-nachrichten/vier-neue-fallout-spiele-fallout-5-und-mehrere-remaster-in-arbeit/</guid>
<pubDate>Mon, 20 Jul 2026 11:48:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bethesda arbeitet an „Fallout 5“, Remastern von „Fallout 3“ und „New Vegas“ sowie einem neuen „Fallout“ von Obsidian. Termine gibt es bisher keine.]]></content:encoded>
</item>
<item>
<title><![CDATA[SOCs face a human challenge as AI speeds alerts and threats]]></title>
<description><![CDATA[Security operations centers (SOCs) have spent years struggling under the weight of growing alert volumes, expanding attack surfaces, and chronic staffing shortages. Now artificial intelligence is adding a new complication: not just more information, but more machine-generated information that mus...]]></description>
<link>https://tsecurity.de/de/3680465/it-security-nachrichten/socs-face-a-human-challenge-as-ai-speeds-alerts-and-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680465/it-security-nachrichten/socs-face-a-human-challenge-as-ai-speeds-alerts-and-threats/</guid>
<pubDate>Mon, 20 Jul 2026 09:08:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/3840447/security-operations-centers-are-fundamental-to-cybersecurity-heres-how-to-build-one.html">Security operations centers (SOCs)</a> have spent years struggling under the weight of growing alert volumes, expanding attack surfaces, and chronic staffing shortages. Now artificial intelligence is adding a new complication: not just more information, but more machine-generated information that must itself be evaluated.</p>



<p class="wp-block-paragraph">“There is an asymmetry here because you now have to parse through a lot of AI slop to get to, ‘Okay, is this real or not?’” <a href="https://www.linkedin.com/in/fsmontenegro/">Fernando Montenegro</a>, vice president and practice lead at The Futurum Group, tells CSO.</p>



<p class="wp-block-paragraph">His observation captures a growing concern among security leaders. AI is helping attackers and defenders move faster, but it is also creating <a href="https://www.cio.com/article/4077448/ai-workslop-the-new-productivity-killer-only-training-can-stop.html">new forms of cognitive burden</a> for the humans tasked with separating signal from noise.</p>



<p class="wp-block-paragraph">As <a href="https://www.csoonline.com/article/4155342/what-anthropic-glasswing-reveals-about-the-future-of-vulnerability-discovery.html">AI accelerates vulnerability discovery</a> and enables more automated reconnaissance and exploitation, defenders are increasingly responsible for overseeing systems whose outputs can be difficult to interpret or verify. The challenge is not simply more work. It is that the volume, speed, and complexity of that work are increasing simultaneously.</p>



<p class="wp-block-paragraph">Yet experts who study and advise SOCs reject the idea that collapse is inevitable. Instead, they describe an industry entering a difficult transition that could reshape how security teams operate and how humans and machines share responsibility for defense.</p>



<h2 class="wp-block-heading">The vulnerability surge is exposing years of security debt</h2>



<p class="wp-block-paragraph">One of the most immediate concerns is the possibility that <a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html">AI dramatically increases the number of vulnerabilities</a> organizations must identify and remediate.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/christopher-crowley-1200339/">Chris Crowley</a>, a longtime cybersecurity instructor and SOC expert, argues that organizations are facing the <a href="https://www.csoonline.com/article/570851/7-ways-technical-debt-increases-security-risk.html">consequences of years of accumulated technology debt</a>.</p>



<p class="wp-block-paragraph">“A lot of what we’re going to have to account for in the next couple of years is a technology debt of vulnerable software that has been deployed because it’s good enough to solve the problem, but then there are all these latent cyber issues, flaws, vulnerabilities that weren’t discovered prior to deployment,” he tells CSO.</p>



<p class="wp-block-paragraph">AI-assisted vulnerability discovery has the potential to expose those weaknesses at a pace defenders have never experienced before.</p>



<p class="wp-block-paragraph">“The compression of work that is being dropped on us is unprecedented,” Crowley says. “We’ve just been ignoring it for decades.”</p>



<p class="wp-block-paragraph">He does not believe AI will necessarily create entirely new classes of vulnerabilities. Instead, he expects defenders to confront much larger volumes of familiar problems.</p>



<p class="wp-block-paragraph">“We’re going to have 100 of these simultaneously,” he says, referring to the kinds of high-priority vulnerabilities security teams traditionally handle one at a time.</p>



<p class="wp-block-paragraph">The AI challenge for many SOCs may be less a novelty problem than a volume problem. Security teams already know how to patch systems, prioritize remediation, and respond to critical exposures. What changes is the scale and speed at which those demands arrive.</p>



<p class="wp-block-paragraph">Organizations with mature patching, prioritization, escalation, and response processes may struggle but adapt. Organizations that have treated security operations as a bare-minimum compliance function may find themselves overwhelmed.</p>



<p class="wp-block-paragraph">For CISOs, Crowley says, that means treating “patch now” less as an occasional emergency state and <a href="https://www.csoonline.com/article/4196435/flaw-surge-fuels-need-for-cisos-to-rethink-vulnerability-management.html">more as a permanent operating posture</a>. As AI accelerates vulnerability discovery, the distinction between routine maintenance and crisis response may continue to blur.</p>



<p class="wp-block-paragraph">He compares the situation to disaster recovery planning. Organizations that wait until a crisis arrives to establish staffing plans, escalation paths, and remediation processes may discover there is not enough help available.</p>



<h2 class="wp-block-heading">Cognitive overload may become the defining challenge</h2>



<p class="wp-block-paragraph">While vulnerability discovery receives much of the attention, Montenegro believes security leaders need a broader framework for understanding AI’s impact.</p>



<p class="wp-block-paragraph">Organizations should think about AI through three lenses, he says: security for AI, AI for security, and security from AI. The first involves protecting AI systems. The second involves using AI to improve defensive operations. The third asks what happens when adversaries use AI against the organization.</p>



<p class="wp-block-paragraph">For SOCs, all three categories are beginning to overlap.</p>



<p class="wp-block-paragraph">As AI makes it easier to create reports, assessments, vulnerability submissions, and other operational artifacts, humans remain responsible for determining whether that information is accurate and useful.</p>



<p class="wp-block-paragraph">“It becomes much easier to generate content,” Montenegro says, “but if you’re going to review that content as a human, the onus on you now is that much larger.”</p>



<p class="wp-block-paragraph">The result is a new form of cognitive overload. Security professionals may spend increasing amounts of time evaluating machine-generated information instead of conducting higher-value security work.</p>



<p class="wp-block-paragraph">Organizations can increasingly use AI to summarize reports, evaluate alerts, and assist with investigations, but humans remain responsible for validating the results.</p>



<p class="wp-block-paragraph">“We’re not at the stage yet where people are comfortable” handing off critical decisions entirely to AI, he says.</p>



<p class="wp-block-paragraph">That leaves defenders caught between two competing realities: AI is creating more information to process, but AI is also becoming one of the few viable tools for managing that growing workload.</p>



<p class="wp-block-paragraph">For Montenegro, the principle should be to automate tasks, not roles. AI can absorb repetitive investigative steps, but organizations should be cautious about removing humans from the process entirely.</p>



<p class="wp-block-paragraph">The risk, he says, is that if organizations hide too much complexity behind automated outputs, analysts may lose opportunities to develop the domain knowledge needed to advance.</p>



<p class="wp-block-paragraph">“How is that professional who is reacting to those alerts growing as a professional?” he says.</p>



<h2 class="wp-block-heading">The gap between mature and struggling SOCs may widen</h2>



<p class="wp-block-paragraph">Not every organization will experience the impact of AI in the same way.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/johnlhubbard/">John Hubbard</a>, senior cybersecurity consultant and SANS instructor, believes the industry’s response will largely depend on how well organizations have prepared for operational stress before AI arrives at scale.</p>



<p class="wp-block-paragraph">“I would roughly break security operations teams into two camps,” Hubbard tells CSO. “There are the ones that are definitely struggling, are already overwhelmed. And then some are doing really well.”</p>



<p class="wp-block-paragraph">The struggling organizations tend to be understaffed, underfunded, undertrained, or dependent on ad hoc processes. Every incident feels different, forcing teams to improvise under pressure.</p>



<p class="wp-block-paragraph">“Getting hit with something like this can certainly be an accelerant for burnout if they weren’t already experiencing it,” Hubbard says.</p>



<p class="wp-block-paragraph">By contrast, mature security teams have already invested in processes, training, exercises, and automation. “The teams that are doing a really solid job now are probably not super overwhelmed because they’ve developed the processes and procedures to be ready for this kind of thing,” Hubbard says.</p>



<p class="wp-block-paragraph">He compares successful SOCs to fire departments. Firefighters cannot predict exactly where the next emergency will occur, but they know how to respond because they have rehearsed those responses repeatedly.</p>



<p class="wp-block-paragraph">“The teams that kind of can react like a fire department are the ones that are getting it right,” he says.</p>



<p class="wp-block-paragraph">Those organizations <a href="https://www.csoonline.com/article/570871/tabletop-exercises-explained-definition-examples-and-objectives.html">conduct tabletop exercises</a>, adversary emulation exercises, <a href="https://www.csoonline.com/article/571891/red-vs-blue-vs-purple-teams-how-to-run-an-effective-exercise.html">red-team assessments</a>, and <a href="https://www.csoonline.com/article/3829684/how-to-create-an-effective-incident-response-plan.html">incident response</a> drills. As a result, they can absorb additional workload without descending into panic.</p>



<h2 class="wp-block-heading">Burnout remains the industry’s most difficult problem</h2>



<p class="wp-block-paragraph">Despite widespread concern about AI-enabled attacks, none of the experts view AI solely as a threat. Several argue that AI will become essential for helping defenders cope with the challenges it creates.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jose-marie-griffiths-9106b7b/">Jose-Marie Griffiths</a>, president emerita and former CIO of Dakota State University, believes AI can help security teams sift through overwhelming volumes of information and identify the signals that matter most.</p>



<p class="wp-block-paragraph">“People who work in SOCs are now seeing overwhelming volumes of data, and they’re getting fatigued,” Griffiths tells CSO.</p>



<p class="wp-block-paragraph">AI can help automate portions of analysis, validate alerts, and improve visibility into complex environments. But Griffiths cautions that some AI-assisted vulnerability discovery tools are also producing large numbers of false positives.</p>



<p class="wp-block-paragraph">That matters because false positives do not eliminate work. They create it. As organizations confront escalating volumes of findings, distinguishing genuine risk from erroneous results may become as important as discovering vulnerabilities in the first place.</p>



<p class="wp-block-paragraph">The experts agree that technology alone will not determine outcomes. People will.</p>



<p class="wp-block-paragraph">Crowley argues that cybersecurity professionals must recognize that uncertainty is intrinsic to the profession. “We are the group that deals with uncertainty,” he says. “That’s really and truly what cybersecurity is.”</p>



<p class="wp-block-paragraph">That reality places responsibility on both individuals and organizations. Analysts need mechanisms for managing stress. Teams need to recognize when colleagues are approaching their limits. Managers need to <a href="https://www.csoonline.com/article/3631614/cybersecurity-is-tough-4-steps-leaders-can-take-now-to-reduce-team-burnout.html">establish healthy escalation practices and realistic expectations</a>.</p>



<p class="wp-block-paragraph">Hubbard rejects the notion that burnout is inevitable.</p>



<p class="wp-block-paragraph">“It is not a foregone conclusion that security operations jobs have to be a painful grind that everyone hates,” he says.</p>



<p class="wp-block-paragraph">He has seen organizations where employees remain engaged for years because leaders actively manage workload, create supportive cultures, and encourage open communication.</p>



<p class="wp-block-paragraph">That includes making it safe for analysts to admit when they have reached their limits. “If people are unwilling to say, ‘I’m maxed out right now, and I’m going crazy,’ that’s going to be the thing that breaks a lot of teams,” Hubbard says.</p>



<p class="wp-block-paragraph">Pay alone may not solve the problem. Crowley pointed to SANS/SOC <a href="https://www.sans.org/white-papers/2026-sans-soc-survey-insights-decade-evolution-cyber-defense">survey findings</a> showing that compensation ranked fourth among retention factors, behind meaningful work, training, and professional development.</p>



<h2 class="wp-block-heading">The future SOC may look very different</h2>



<p class="wp-block-paragraph">Griffiths believes organizations will need to respond not only with better technology but with structural changes. Traditional tiered SOC models may need to evolve into more collaborative teams with diverse expertise working together in real-time.</p>



<p class="wp-block-paragraph">“I think we’re going to have to eliminate the hierarchies a little bit and have teams of people with different expertise working together,” she says.</p>



<p class="wp-block-paragraph">She also argues that organizations should invest in human expertise rather than simply increasing AI consumption. “Buy engineers, not tokens,” she says.</p>



<p class="wp-block-paragraph">Professional networks and peer support will matter as much as any tool, Griffiths says, because defenders need trusted communities where they can compare notes, share practices, and avoid facing sustained pressure in isolation.</p>



<p class="wp-block-paragraph">If there is a consensus emerging among experts, it is that AI is exposing weaknesses that already existed.</p>



<p class="wp-block-paragraph">The staffing shortages, alert fatigue, burnout, and process failures affecting SOCs did not begin with generative AI. AI is simply amplifying them.</p>



<p class="wp-block-paragraph">At the same time, AI is providing new tools that may help organizations manage those very challenges.</p>



<p class="wp-block-paragraph">The future SOC may spend less time manually triaging alerts and more time validating automated findings, conducting threat hunting, and making strategic decisions. Human expertise may increasingly be paired with AI systems that act as operational partners.</p>



<p class="wp-block-paragraph">The transition will not be painless. Some teams will struggle. Some practitioners may leave the field. Others will adapt and thrive.</p>



<p class="wp-block-paragraph">“In a way,” Griffiths says, “we’re turning the whole SOC inside out.”</p>



<p class="wp-block-paragraph">Montenegro sees the transition as a cybersecurity version of the Red Queen effect: defenders and attackers must keep running simply to stay in place.</p>



<p class="wp-block-paragraph">Borrowing from science-fiction author William Gibson, Montenegro offered perhaps the simplest description of the industry’s current moment: “The future is already here. It’s just unevenly distributed.”</p>



<p class="wp-block-paragraph">For security leaders, that future is arriving in the form of AI-generated vulnerabilities, AI-assisted investigations, and AI-enabled adversaries. The question is no longer whether security operations centers will change. It is whether organizations can adapt quickly enough to keep pace.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian: Neues Plugin bringt echten Nextcloud-Sync ohne Datenverlust]]></title>
<description><![CDATA[Wer Obsidian über mehrere Desktop-Rechner und mobile Geräte hinweg nutzt, kennt das Problem: Der Abgleich der Notizen über Standard-Cloud-Dienste ist oft hakelig, führt zu Konflikten oder zerschießt im schlimmsten Fall Formatierungen. Mit Nextcloud Sync for Obsidian steht nun ein neues,...Zum Bei...]]></description>
<link>https://tsecurity.de/de/3680420/it-nachrichten/obsidian-neues-plugin-bringt-echten-nextcloud-sync-ohne-datenverlust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680420/it-nachrichten/obsidian-neues-plugin-bringt-echten-nextcloud-sync-ohne-datenverlust/</guid>
<pubDate>Mon, 20 Jul 2026 08:33:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wer Obsidian über mehrere Desktop-Rechner und mobile Geräte hinweg nutzt, kennt das Problem: Der Abgleich der Notizen über Standard-Cloud-Dienste ist oft hakelig, führt zu Konflikten oder zerschießt im schlimmsten Fall Formatierungen. Mit Nextcloud Sync for Obsidian steht nun ein neues,...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/obsidian-neues-plugin-bringt-echten-nextcloud-sync-ohne-datenverlust/">Obsidian: Neues Plugin bringt echten Nextcloud-Sync ohne Datenverlust</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[As AI Transforms Silicon Valley, Some Tech Workers Face Evaporating Financial Security]]></title>
<description><![CDATA[The Washington Post describes a mid-tier executive at Meta as one of Silicon Valley's "winners" whose financial security suddenly "evaporated" as their workforce "pushed headlong into AI and heavy job cuts," creating a transformed job market. "Her ex-husband, a designer at Meta who was laid off i...]]></description>
<link>https://tsecurity.de/de/3680218/it-security-nachrichten/as-ai-transforms-silicon-valley-some-tech-workers-face-evaporating-financial-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680218/it-security-nachrichten/as-ai-transforms-silicon-valley-some-tech-workers-face-evaporating-financial-security/</guid>
<pubDate>Mon, 20 Jul 2026 05:54:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Washington Post describes a mid-tier executive at Meta as one of Silicon Valley's "winners" whose financial security suddenly "evaporated" as their workforce "pushed headlong into AI and heavy job cuts," creating a transformed job market. "Her ex-husband, a designer at Meta who was laid off in 2020, eventually gave up looking for jobs in his profession. He now lifts boxes at a warehouse."


Layoffs.fyi, which tracks announced job cuts, counts more than 800,000 tech workers laid off since 2022, including large staff reductions in recent months at Meta, Microsoft, Oracle and Amazon... "There's this whole tranche of people who've been quite used to being among the most upwardly mobile in society who are all of a sudden saying, 'Now I'm the guy on the streetâs'" said Oliver Raskin, who founded Silicon Valley market research consultancy Signalcraft Insights and has surveyed attitudes in the tech labor force... "The rise of AI, especially, is bound to change the workplace radically," [said Georgetown University historian Joseph McCartin]. "But the way it's going to happen is similar to how technology transformed the auto industry." Ruth Milkman, a labor sociologist at the City University of New York, said that technology workers are getting a dose of what workers in other industries have long complained about: jobs that feel unsteady or rob them of autonomy. "Low-wage workers are used to it," she said... 

Many layoffs at technology companies are probably a hangover effect from over-hiring in prior years, experts say. And they don't account for a spotty recent increase in hiring in the information industry, which includes employment of software developers and jobs in media and entertainment. Digging deeper, though, some economists say there are signs that Silicon Valley and other technology-reliant parts of the American economy have reached a turning point where they are growing without needing as many people. The notion was encapsulated in a recent talk that ricocheted through group chats across the tech industry: In it, a partner at the start-up incubator Y Combinator heralded a new generation of AI-first companies that will only need human labor for "novel situations," "ethical considerations" and "high-stakes moments." 

Gad Levanon, chief economist at the labor research nonprofit Burning Glass Institute, said that the number of hours worked in the information sector has dipped since 2022, while the sector's economic output has increased by about 8 percent a year — more than three times the overall growth rate of the U.S. economy. He says the data reveals a sea change in industries, including technology and finance, toward doing more work with the same or fewer people — one that is spreading to other professional classes. "That's the new reality for white-collar and tech-exposed work: output up, headcount flat or down," Levanon said... 

Raskin, who has worked in the tech world since the late '90s, said that even though the current moment feels unsettling to many, he's hopeful that it's an early chapter in an evolving story. "It's happened many times before," he said, "that something implodes and all these people lose jobs, but then that talent gets cycled into whatever the next thing is — into a new wave of prosperity." 

In the article tech entrepreneur Anil Dash quips that Silicon Valley techies are "are guinea pigs for what tech dudes want to do to everyone."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=As+AI+Transforms+Silicon+Valley%2C+Some+Tech+Workers+Face+Evaporating+Financial+Security%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F20%2F0212244%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F20%2F0212244%2Fas-ai-transforms-silicon-valley-some-tech-workers-face-evaporating-financial-security%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/07/20/0212244/as-ai-transforms-silicon-valley-some-tech-workers-face-evaporating-financial-security?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4686: Debugging Security Cameras: Firmware Updates, Python Scripts and Windows Workarounds]]></title>
<description><![CDATA[This show has been flagged as Explicit by the host.


 Show Notes


 Episode Overview




Operator kicks off the episode feeling under the weather but shares a quick tip for making perfect egg drop soup before diving into his main project: diagnosing why his front-door security camera stopped sen...]]></description>
<link>https://tsecurity.de/de/3680142/podcasts/hpr4686-debugging-security-cameras-firmware-updates-python-scripts-and-windows-workarounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680142/podcasts/hpr4686-debugging-security-cameras-firmware-updates-python-scripts-and-windows-workarounds/</guid>
<pubDate>Mon, 20 Jul 2026 02:06:59 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Explicit by the host.</p>

<h1>
 Show Notes</h1>

<h3>
 Episode Overview</h3>

<ul>

<li>
Operator kicks off the episode feeling under the weather but shares a quick tip for making perfect egg drop soup before diving into his main project: diagnosing why his front-door security camera stopped sending alerts and recording events. What follows is a live-debugging session covering network config, script logging, Windows permission hacks, NTP time drift, and firmware flashing.</li>

</ul>

<h3>
 Key Topics &amp; Breakdown</h3>

<ul>

<li>

<ul>

<li>

<strong>
Egg Drop Soup Hack:</strong>
 How to get that perfect ribbony texture by creating a boiling swirl before pouring in the eggs, plus broth-to-egg ratio tips.</li>

<li>

<strong>
Camera Setup &amp; Network Config:</strong>
 Using static DHCP via MAC address binding on a UniFi Dream Machine (UDM) for local domain resolution instead of hardcoding IPs.</li>

<li>

<strong>
Python &amp; Cron Automation:</strong>
 Running a custom Python script every 2 minutes to check for new recordings, parsing logs with <code>
grep -v</code>
, and navigating massive log files in <code>
vi</code>
.</li>

<li>

<strong>
Windows Troubleshooting Tangent:</strong>
 Deleting the stubborn <code>
Windows.old</code>
 folder using the TrustedInstaller service hack (<code>
ExecTI.exe</code>
) instead of taking ownership manually.</li>

<li>

<strong>
Time Sync &amp; Firmware Quirks:</strong>
 Discovering the camera's system clock was stuck in 2011/2026, causing missed events. Downloading firmware via a slow third-party link, renaming <code>
.bin</code>
 to <code>
.zip</code>
, and extracting with 7-Zip.</li>

<li>

<strong>
Pre-Flash Backup Routine:</strong>
 Exporting camera configuration before upgrading, storing it in Google Drive for searchable documentation, and clearing old log/trigger files to reset the event pipeline.</li>

</ul>

</li>

</ul>

<h3>
️ Tools &amp; Techniques Mentioned</h3>

<ul>

<li>

<ul>

<li>

<code>
crontab</code>
 + Python scripts for automated monitoring</li>

<li>

<code>
grep -v</code>
, <code>
cat</code>
, <code>
tail</code>
, and <code>
vi</code>
 (line navigation with <code>
:1000</code>
)</li>

<li>
Obsidian for note-taking &amp; AI assistant integration</li>

<li>
Firefox/Playwright for headless browser testing</li>

<li>
Turbo Download Manager &amp; Bolt Media Downloader for multi-threaded/sniffing downloads</li>

<li>
7-Zip for archive extraction</li>

<li>
Google Drive for searchable config backups</li>

</ul>

</li>

</ul>

<h3>
 Resources &amp; Links</h3>

<ul>

<li>

<ul>

<li>

<strong>
Python API Script:</strong>
 <a href="https://github.com/freeload101/Python/blob/master/Uniview_API_IPC3628SR-ADF28KM-WP_get_Last.py" rel="noopener noreferrer" target="_blank">
Uniview IPC3628SR Recording Checker</a>

</li>

<li>

<strong>
Camera Model:</strong>
 <code>
IPC3628SR</code>
 (Uniview Wyze ISP Warm Light Deterrent Network Camera)</li>

<li>

<strong>
TrustedInstaller Run-as Tool:</strong>
 <a href="https://rmccurdy.com/.scripts/downloaded/ExecTI_TrustedInstaller_Runas.zip" rel="noopener noreferrer" target="_blank">
ExecTI TrustedInstaller Runner</a>

</li>

</ul>

</li>

</ul>

<h3>
 Quick Takeaways</h3>

<ol>

<li>

<ol>

<li>
 Always verify NTP/time sync on IoT cameras before troubleshooting missed events or alerts.</li>

<li>
 Use <code>
grep -v "noise"</code>
 to quickly filter out repetitive log entries when debugging automation scripts.</li>

<li>
 Windows system folders can be stubborn; running commands as <code>
TrustedInstaller</code>
 bypasses hidden file locks without manual ownership changes.</li>

<li>
 Always export and back up device configs before flashing firmware, even if the upgrade seems straightforward.</li>

<li>
 Third-party download links often use temporary tokens or <code>
.bin</code>
 wrappers; renaming to <code>
.zip</code>
 and verifying with 7-Zip can save headaches.</li>

</ol>

</li>

</ol>

<ul>

<li>

<em>
Thanks for listening! Stay curious, keep your logs clean, and remember: defense in depth starts at home.</em>
  </li>

</ul>

<p>

</p>

<p>

</p>

<p>
Example trusted installer hack</p>

<p>

</p>

<p>

</p>

<p>
# Shhhh I can't IR ... Defender, ForcePoint, SMS Agent Host ...I just can't anymore ...</p>

<p>
sc config TrustedInstaller binPath= "Reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sense" /v Start /t reg_dword /d 4 /f"  </p>

<p>
sc start "TrustedInstaller" </p>

<p>
sc config TrustedInstaller binPath= "Reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fppsvc" /v Start /t reg_dword /d 4 /f"  </p>

<p>
sc start "TrustedInstaller" </p>

<p>
sc config TrustedInstaller binPath= "Reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CcmExec" /v Start /t reg_dword /d 4 /f"  </p>

<p>
sc start "TrustedInstaller" </p>

<p>
sc config TrustedInstaller binPath= "Reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend" /v Start /t reg_dword /d 4 /f"  </p>

<p>
sc config TrustedInstaller binPath= "C:\Windows\servicing\TrustedInstaller.exe"</p>

<p>

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4686/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Union Fights Microsoft Over Layoffs at Game Studios]]></title>
<description><![CDATA[Thursday the union that helped organize thousands of workers across numerous Microsoft-owned video game studios filed unfair labor complaints against Microsoft over the layoffs of 1,600 employees. The gaming news site Aftermath says the complaints allege unlawful action:


"Xbox management is req...]]></description>
<link>https://tsecurity.de/de/3678232/it-security-nachrichten/union-fights-microsoft-over-layoffs-at-game-studios/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678232/it-security-nachrichten/union-fights-microsoft-over-layoffs-at-game-studios/</guid>
<pubDate>Sat, 18 Jul 2026 18:40:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Thursday the union that helped organize thousands of workers across numerous Microsoft-owned video game studios filed unfair labor complaints against Microsoft over the layoffs of 1,600 employees. The gaming news site Aftermath says the complaints allege unlawful action:


"Xbox management is required to bargain with the union over the decision of layoffs prior to implementing them during the status quo period, and we are pursuing every available avenue to protect our members," a Communications Workers of America spokesperson said in a statement to Aftermath... Speaking to Game Developer, CWA Canada president Carmel Smyth elaborated on the unions' misgivings... "Basically the employer cannot arbitrarily change working conditions while it is engaged in negotiating with the union. We will continue to file legal challenges if necessary, and do all we can to defend the rights of Bethesda Game Studios workers...." 

"I'm very proud of the hard work the bargaining committees and CWA staff have put in to evaluate the legality of how the layoffs were conducted," a current id Software employee and union member told Aftermath. "It's important, even for the world's largest and most profitable companies, that there are consequences for violating federal labor law. If we hadn't explored this avenue to hold Microsoft accountable, it would be a sign to all other game executives that they can break the law and get away with it." 

Legal action is just one part of unions' larger effort to hold Microsoft accountable for its decision to lay off thousands of workers. This week, CWA also hosted a series of "Save Our Devs" demonstrations outside the offices of affected studios like Zenimax, id Software, Bethesda, and Obsidian.

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Union+Fights+Microsoft+Over+Layoffs+at+Game+Studios%3A+https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F07%2F18%2F0723247%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F07%2F18%2F0723247%2Funion-fights-microsoft-over-layoffs-at-game-studios%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://games.slashdot.org/story/26/07/18/0723247/union-fights-microsoft-over-layoffs-at-game-studios?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacStories Weekly: Issue 522]]></title>
<description><![CDATA[This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:Combining Codex with Reminders, Email, and Notion, by JohnPursuing Meta-Style Glasses is a Poor Strategy for Apple, by JonathanPublic Betas, Dictation Apps, and More, by Jonathan
	
						This Sto...]]></description>
<link>https://tsecurity.de/de/3676814/ios-mac-os/macstories-weekly-issue-522/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676814/ios-mac-os/macstories-weekly-issue-522/</guid>
<pubDate>Fri, 17 Jul 2026 20:23:46 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<nav class="ms-issue-toc"><p>This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:</p><ul><li><a href="https://www.macstories.net/club/macstories-weekly-issue-522/#combining-codex-with-reminders-email-and-notion" class="ms-issue-toc-item">Combining Codex with Reminders, Email, and Notion, by John</a></li><li><a href="https://www.macstories.net/club/macstories-weekly-issue-522/#pursuing-meta-style-glasses-is-a-poor-strategy-for-apple" class="ms-issue-toc-item">Pursuing Meta-Style Glasses is a Poor Strategy for Apple, by Jonathan</a></li><li><a href="https://www.macstories.net/club/macstories-weekly-issue-522/#public-betas-dictation-apps-and-more" class="ms-issue-toc-item">Public Betas, Dictation Apps, and More, by Jonathan</a></li></ul></nav>
	<div class="club-notice-restricted plan-">
						<h2>This Story is for Club Members</h2>

				<p>Get weekly newsletters, exclusive stories, member downloads, and ad-free version of MacStories Unwind.</p>
				<p><br><a href="https://www.macstories.net/plans?utm_source=ms&amp;utm_medium=web" class="button">See Plans</a></p>

									 

					<p>Already a member? <a href="https://www.macstories.net/?memberful_endpoint=auth">Sign in</a></p>
								</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bethesda details what's next for Fallout and its other franchises amid Xbox cuts]]></title>
<description><![CDATA[Obsidian is working on a new Fallout game, while Fallout 3 and New Vegas remasters are on the way.]]></description>
<link>https://tsecurity.de/de/3676620/it-nachrichten/bethesda-details-whats-next-for-fallout-and-its-other-franchises-amid-xbox-cuts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676620/it-nachrichten/bethesda-details-whats-next-for-fallout-and-its-other-franchises-amid-xbox-cuts/</guid>
<pubDate>Fri, 17 Jul 2026 19:03:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Obsidian is working on a new Fallout game, while Fallout 3 and New Vegas remasters are on the way.]]></content:encoded>
</item>
<item>
<title><![CDATA[Todd Howard interview: Fallout 5, Obsidian's Fallout, remakes, Elder Scrolls 6, Starfield, and more — Bethesda charts its future]]></title>
<description><![CDATA[As Xbox's cuts bite, Bethesda set out to reassure fans about the future of its biggest franchises. We spoke to the legendary Todd Howard to learn more.]]></description>
<link>https://tsecurity.de/de/3676272/windows-tipps/todd-howard-interview-fallout-5-obsidians-fallout-remakes-elder-scrolls-6-starfield-and-more-bethesda-charts-its-future/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676272/windows-tipps/todd-howard-interview-fallout-5-obsidians-fallout-remakes-elder-scrolls-6-starfield-and-more-bethesda-charts-its-future/</guid>
<pubDate>Fri, 17 Jul 2026 16:11:18 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As Xbox's cuts bite, Bethesda set out to reassure fans about the future of its biggest franchises. We spoke to the legendary Todd Howard to learn more.]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian's new Fallout spin-off is REAL — alongside 'Fallout 5' and '3' and 'New Vegas' remakes, as Todd Howard offers praise: "a huge amount of respect."]]></title>
<description><![CDATA[Obsidian will officially return to Fallout, with Bethesda offering a big update on the future of The Elder Scrolls, Starfield, and the wasteland epic.]]></description>
<link>https://tsecurity.de/de/3676271/windows-tipps/obsidians-new-fallout-spin-off-is-real-alongside-fallout-5-and-3-and-new-vegas-remakes-as-todd-howard-offers-praise-a-huge-amount-of-respect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676271/windows-tipps/obsidians-new-fallout-spin-off-is-real-alongside-fallout-5-and-3-and-new-vegas-remakes-as-todd-howard-offers-praise-a-huge-amount-of-respect/</guid>
<pubDate>Fri, 17 Jul 2026 16:11:16 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Obsidian will officially return to Fallout, with Bethesda offering a big update on the future of The Elder Scrolls, Starfield, and the wasteland epic.]]></content:encoded>
</item>
<item>
<title><![CDATA[Bethesda teases Fallout 5 soon after Xbox’s mass layoffs]]></title>
<description><![CDATA[Xbox is currently in a "reset" period that includes laying off around 3,200 employees over the next year, involving deep cuts at beloved studios like id Software and Obsidian Entertainment. Now, in an attempt to show that things are still running fine, the company has announced a slate of upcomin...]]></description>
<link>https://tsecurity.de/de/3676256/it-nachrichten/bethesda-teases-fallout-5-soon-after-xboxs-mass-layoffs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676256/it-nachrichten/bethesda-teases-fallout-5-soon-after-xboxs-mass-layoffs/</guid>
<pubDate>Fri, 17 Jul 2026 16:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Xbox is currently in a "reset" period that includes laying off around 3,200 employees over the next year, involving deep cuts at beloved studios like id Software and Obsidian Entertainment. Now, in an attempt to show that things are still running fine, the company has announced a slate of upcoming projects at Bethesda Game Studios […]]]></content:encoded>
</item>
<item>
<title><![CDATA[4 Memory-Systeme, um KI aufzuschlauen]]></title>
<description><![CDATA[Wenn Ihre KI unter unzureichender „Gedächtnisleistung“ leidet, helfen diese Memory-Systeme von Drittanbietern (eventuell).DC Studio | shutterstock.com



KI-Agenten und die Large Language Models (LLMs), auf denen sie basieren, haben ein eher kurzlebiges „Gedächtnis“. Das ist so gewollt, schließli...]]></description>
<link>https://tsecurity.de/de/3675019/it-security-nachrichten/4-memory-systeme-um-ki-aufzuschlauen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675019/it-security-nachrichten/4-memory-systeme-um-ki-aufzuschlauen/</guid>
<pubDate>Fri, 17 Jul 2026 06:08:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/DC-Studio_shutterstock_2269121373_DEOnly_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Dev Meeting 16z9" class="wp-image-4075633" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Wenn Ihre KI unter unzureichender „Gedächtnisleistung“ leidet, helfen diese Memory-Systeme von Drittanbietern (eventuell).</figcaption></figure><p class="imageCredit">DC Studio | shutterstock.com</p></div>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/4189343/was-ki-agenten-wirklich-kosten.html" target="_blank">KI-Agenten</a> und die Large Language Models (<a href="https://www.computerwoche.de/article/4155050/25-fragen-die-zum-richtigen-llm-fuhren.html" target="_blank">LLMs</a>), auf denen sie basieren, haben ein eher kurzlebiges „Gedächtnis“. Das ist so gewollt, schließlich kann nur eine begrenzte Menge an Konversationsinhalten in Token kodiert und vom LLM zuverlässig abgerufen werden. Um KI-Agenten und Sprachmodelle mit „Hirnschmalz“ auszustatten, das über ihre Kontextfenster hinausreicht, lässt sich Retrieval Augmented Generation (<a href="https://www.computerwoche.de/article/4192090/so-geht-memory-optimierung-bei-ki-agenten.html" target="_blank">RAG</a>) einsetzen. Erfolgsentscheidend ist dabei, wie dieser Mechanismus (oder ein anderer, um Gesprächsdaten vorzuhalten) konkret zur Anwendung kommt.</p>



<p class="wp-block-paragraph">Ein anderer Weg, sowohl KI-Agenten als auch LLMs mit erweiterten Speicherfähigkeiten auszustatten, führt über Software-Tools von Drittanbietern. Diese können die KI mit einer Session-übergreifenden, persistenten Memory ausstatten. Auch hier variiert jedoch die Art und Weise, wie das technisch umgesetzt wird. Die folgenden vier Projekte sind besonders empfehlenswert, wenn es darum geht, KI-Agenten und Sprachmodelle smarter zu machen.    </p>



<h2 class="wp-block-heading">1. <a href="https://github.com/getzep/graphiti" target="_blank" rel="noreferrer noopener">Graphiti</a></h2>



<p class="wp-block-paragraph">Graphiti wird als „das Open-Source-Framework für temporale Knowledge-Graphen“ beworben. Das Projekt ist auf GitHub verfügbar – oder auch im Rahmen des <a href="https://www.getzep.com/" target="_blank" rel="noreferrer noopener">Memory-Service Zep</a>, für den es die Grundlage liefert. „Temporal“ bedeutet in diesem Zusammenhang, dass die in Graphiti gespeicherten Informationen im Laufe der Zeit reevaluiert werden, um den Kontext korrekt einzubetten. Der Begriff „Graph-Framework“ ist hingegen darauf zurückzuführen, dass die Daten dabei als eine Reihe von Graphen gespeichert werden. Dieses Feature spielt auch bei den anderen in diesem Artikel vorgestellten Lösungen eine Rolle – im Fall von Graphiti steht es allerdings im Fokus.</p>



<p class="wp-block-paragraph">Out of the Box unterstützt das KI-Memory-Projekt eine ganze Reihe gängiger LLMs, etwa von Anthropic, OpenAI, Google oder X. Auch sämtliche Ollama- und OpenAI-kompatiblen <a href="https://www.computerwoche.de/article/4004872/die-besten-apis-um-ki-zu-integrieren.html" target="_blank">APIs</a> funktionieren mit Graphiti – es kann also auch mit <a href="https://www.computerwoche.de/article/2830445/5-wege-llms-lokal-auszufuehren.html" target="_blank">lokal gehosteten LLMs</a> genutzt werden. Daten aus Quellen wie GitHub, Gmail und OneDrive sowie aus Anwendungen wie Notion lassen sich über Konnektoren einbinden.</p>



<p class="wp-block-paragraph">Um Graphiti lokal nutzen zu können, ist es allerdings nötig, eine Graphdatenbank einzurichten oder eine Verbindung zu einer solchen herzustellen. Die Standardlösung dafür (mit dem breitesten Support) ist <a href="https://neo4j.com/" target="_blank" rel="noreferrer noopener">Neo4j</a>. Davon abgesehen, funktionieren auch <a href="https://aws.amazon.com/neptune/" target="_blank" rel="noreferrer noopener">Amazon Neptune</a>, <a href="https://www.falkordb.com/" target="_blank" rel="noreferrer noopener">FalkorDB</a> und <a href="https://kuzudb.github.io/" target="_blank" rel="noreferrer noopener">KuzuDB</a>. <a href="https://www.computerwoche.de/article/3803224/postgresql-als-rag-vektordatenbank-nutzen.html" target="_blank">Postgres</a> mit <code>pgvector</code> ist (derzeit) hingegen keine Option bei Graphiti.</p>



<h2 class="wp-block-heading">2. <a href="https://hindsight.vectorize.io/" target="_blank" rel="noreferrer noopener">Hindsight</a></h2>



<p class="wp-block-paragraph">Das KI-Memory-Projekt Hindsight als Cloud Service verfügbar, kann jedoch auch lokal gehostet werden. Dieses Tool speichert Details zu Agenten-Sitzungen in <a href="https://hindsight.vectorize.io/#key-components">vier verschiedenen Memory-Instanzen</a> und wendet dabei vier unterschiedliche <a href="https://hindsight.vectorize.io/#multi-strategy-retrieval-tempr" target="_blank" rel="noreferrer noopener">Storage- und Retrieval-Strategien</a> an. Diese werden über drei programmatische Interfaces gehändelt:</p>



<ul class="wp-block-list">
<li><code>retain</code>, um Inhalte (einzelne Fakten oder komplette Sessions) zu speichern,</li>



<li><code>recall</code>, um den Content abzurufen, und</li>



<li><code>reflect</code>, um einen Agenten-Loop über eine Abfrage zu initiieren, die zuvor gespeicherte Daten nutzt.</li>
</ul>



<p class="wp-block-paragraph">In Sachen Integrationen hat Hindsight eine breite Palette von First- und Third-Party-Optionen <a href="https://hindsight.vectorize.io/integrations" target="_blank" rel="noreferrer noopener">zu bieten</a>. Wenn Sie beispielsweise die „Continue“-Erweiterung mit Visual Studio Code einsetzen, um mit einem lokal gehosteten LLM zu kommunizieren, können Sie die <a href="https://hindsight.vectorize.io/sdks/integrations/continue" target="_blank" rel="noreferrer noopener">entsprechende First-Party-Integration</a> nutzen. In diesem Fall verwenden Sie einfach das Keyword <code>@hindsight</code> in der Query, um den Agenten-Kontext um relevante Memory zu erweitern. Um sich die Arbeit zu erleichtern, respektive diese zu automatisieren, könnten Sie außerdem auch auf (anpassbare) Auto-Injection-Regeln zurückgreifen.</p>



<h2 class="wp-block-heading">3. <a href="https://github.com/mem0ai/mem0" target="_blank" rel="noreferrer noopener">Mem0</a></h2>



<p class="wp-block-paragraph">Wie Hindsight nutzt auch Mem0 <a href="https://docs.mem0.ai/core-concepts/memory-types" target="_blank" rel="noreferrer noopener">vier grundlegende Memory-Typen</a> – allerdings sind diese anders benannt und organisiert. Beispielsweise kommt im Fall von Mem0 die sogenannte „Organizational Memory“ zum Einsatz, um Daten zu speichern, die zwischen verschiedenen KI-Agenten(-Teams) geteilt werden sollen.</p>



<p class="wp-block-paragraph">Jede Form von Memory, die über Mem0 hinzugefügt wird, durchläuft einen „<a href="https://docs.mem0.ai/core-concepts/memory-evaluation#memory-extraction-distillation" target="_blank" rel="noreferrer noopener">Destillationsprozess</a>“ und wird auf unterschiedliche Art und Weise (Vektor-, Graph- oder SQL-Datenbank) gespeichert. Ältere Daten werden bei Mem0 nicht gelöscht, sondern als veraltet markiert – eine Strategie, um einen umfassenderen, längerfristigen Kontext zu erzeugen.</p>



<p class="wp-block-paragraph">Das Projekt unterstützt im Vergleich – etwa zu Hindsight – weniger LLMs, die wichtigen Anbieter (Anthropic, Google, OpenAI) sind jedoch vertreten. Dazu kommen Self-Hosting-Optionen über <a href="https://www.computerwoche.de/article/2827054/was-ist-langchain.html" target="_blank">LangChain</a>, <a href="https://www.litellm.ai/" target="_blank" rel="noreferrer noopener">LiteLLM</a>, <a href="https://www.computerwoche.de/article/4131576/lm-studio-angetestet.html" target="_blank">LM Studio</a> und <a href="https://ollama.com/" target="_blank" rel="noreferrer noopener">Ollama</a>. Falls Sie Mem0 lokal statt <a href="https://mem0.ai/pricing" target="_blank" rel="noreferrer noopener">als Service</a> nutzen möchten, ist es nötig, eine Python-Instanz und eine eigene Vektordatenbank bereitzustellen. Für Letzteres ist Postgres mit der <code>pgvector</code>-Erweiterung eine gängige und simple Option, die sogar innerhalb einer virtuellen Python-Umgebung <a href="https://github.com/orm011/pgserver" target="_blank" rel="noreferrer noopener">installiert werden kann</a>.</p>



<h2 class="wp-block-heading">4. <a href="https://supermemory.ai/" target="_blank" rel="noreferrer noopener">Supermemory</a></h2>



<p class="wp-block-paragraph">Supermemory erfasst Daten aus vielen gängigen Quellen und unterstützt dabei unter anderem Plaintext, strukturierte Daten, PDF- und Office-Dokumente sowie Video-, Audio- und Bilddateien. Aus diesen Informationen erstellt das Tool einen Kontextgraphen, der anschließend als Grundlage für Chatbot-Konversationen fungiert. PR-mäßig setzt dieses Projekt den Fokus vor allem auf seine Context-Extraktions-Tools.</p>



<p class="wp-block-paragraph">Supermemory ist entweder als Cloud-Dienst oder als quelloffene, lokal ausführbare Software verfügbar. Die <a href="https://github.com/supermemoryai/supermemory" target="_blank" rel="noreferrer noopener">Open-Source-Version</a> lässt zwar die Scaling Services und Drittanbieter-Konnektoren der Enterprise-Version vermissen – hat jedoch einen entscheidenden Vorteil: Sie besteht aus einer einzelnen <a href="https://www.computerwoche.de/article/4128783/4-self-contained-datenbanken-fur-entwickler.html" target="_blank">Self-Contained</a>-Binary. So lässt sie sich auch auf der eigenen Hardware mit sehr überschaubarem Aufwand bereitstellen.</p>



<p class="wp-block-paragraph">Da für dieses Projekt zudem keine externen Datenbanken aufgesetzt werden müssen, eignet es sich in besonderem Maße für (agile) Experimente. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/4192397/four-agentic-ai-memory-systems-for-smarter-llms.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 wild ways to make Android widgets more useful]]></title>
<description><![CDATA[Widgets, widgets, widgets. Has there ever been an Android feature so full of promise that went unloved by Google for so very long?



Okay, so maybe there has been — erm, lots of times, actually. But even so, Android’s widgets system is a perfect example of an exceptional advantage that Google ba...]]></description>
<link>https://tsecurity.de/de/3670233/it-nachrichten/5-wild-ways-to-make-android-widgets-more-useful/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670233/it-nachrichten/5-wild-ways-to-make-android-widgets-more-useful/</guid>
<pubDate>Wed, 15 Jul 2026 12:03:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Widgets, widgets, widgets. Has there ever been an Android feature so full of promise that went unloved by Google for so very long?</p>



<p class="wp-block-paragraph">Okay, so maybe there has been — erm, <a href="https://www.computerworld.com/article/1714997/android-features-faded.html">lots of times</a>, actually. But even so, Android’s widgets system is a perfect example of an exceptional advantage that Google basically buried, abandoned, and left on the brink of extinction up until its overdue revival in 2021’s <a href="https://www.computerworld.com/article/1616489/24-advanced-tips-for-android-12.html">Android 12 update</a>. (And that revival, by the way, happened for no apparent reason whatsoever. Just a totally random, unprompted change of heart after a decade of indifference. <a href="https://www.computerworld.com/article/1639159/android-missed-opportunity.html">Riiiiiiiiight</a>.)</p>



<p class="wp-block-paragraph">Google may have given up on widgets for a while, but the good news is that (a) they’re back, baby — still now, more than ever, even in <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">our overly AI-obsessed 2026 timeline</a> — and (b) the Android developer community keeps chuggin’ along and coming up with ever-more creative new ways to embrace widgets beyond what Google itself sees fit to give us. That means no matter what <a href="https://www.computerworld.com/article/1714347/android-versions-a-living-history-from-1-0-to-today.html">Android version</a> your favorite phone is running, you can step up your own Android widget game and give yourself some fresh and fruitful paths to make the most of your phone’s framework.</p>



<p class="wp-block-paragraph">Here, my dear, are some fantastic beyond-the-basics ways to put <a href="https://www.computerworld.com/article/1699499/best-android-widgets-for-busy-professionals.html">your favorite Android widgets</a> to use and change the way you get stuff done on your phone. </p>



<p class="wp-block-paragraph"><strong>[Psst: Love learning new things?</strong> <a href="https://theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong>Get my free Android Intelligence newsletter</strong></a><strong> to get a tasty new tip in your inbox every Friday.]</strong></p>



<h2 class="wp-block-heading">Android widget enhancement #1: The on-demand home screen pop-up</h2>



<p class="wp-block-paragraph">Widgets are a wonderful way to interact with all sorts of info without ever having to open up apps, but having too many widgets can quickly lead to a cluttered and overwhelming home screen.</p>



<p class="wp-block-paragraph">Well, here’s a neat way to give yourself the benefit of a widget while still maintaining a neat and minimal space for working: An excellent app called <a href="https://play.google.com/store/apps/details?id=com.ss.popupWidget" target="_blank" rel="noreferrer noopener">Popup Widget</a> lets you create an on-demand pop-up widget (get it?!) that looks like a regular ol’ icon on your home screen but then loads any widget you want when tapped.</p>



<p class="wp-block-paragraph">See?</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-widgets-popup-widget-1.webp" alt="Android widgets: Popup Widget (1)" class="wp-image-4196884" width="800" height="835" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption">Any widget, anytime — with Popup Widget on Android.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">You can even get <em>really</em> wild and set up a single icon that opens <em>multiple</em> widgets at the same time — like your inbox and your calendar together:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-widgets-popup-widget-2.webp" alt="Android widgets: Popup Widget (2)" class="wp-image-4196885" width="800" height="837" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption">Popup Widget can even let you summon two widgets together with a single tap.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">Not bad, right?</p>



<p class="wp-block-paragraph">Popup Widget costs two bucks and doesn’t require any special permissions or manners of access. And it’s pretty simple and self-explanatory to set up: Once you install and open the app, it’ll walk you through adding in whatever pop-up widgets you want. You can choose the name and even the icon associated with each one along with its precise placement on your screen and how much the screen behind it should dim when it’s loaded.</p>



<p class="wp-block-paragraph">The app will offer to add the shortcut directly onto your home screen for you then, or you can also find all of your Popup Widget creations by pressing and holding the main Popup Widget icon in your app drawer.</p>



<p class="wp-block-paragraph">Alternatively, if you’re already using <a href="https://www.computerworld.com/article/1723954/android-launchers-for-enhanced-efficiency.html">a custom Android launcher</a> like <a href="https://play.google.com/store/apps/details?id=ginlemon.flowerfree&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Smart Launcher</a> or <a href="https://play.google.com/store/apps/details?id=bitpit.launcher" target="_blank" rel="noreferrer noopener">Niagara</a>, you can find similar options for summoning widgets on demand within their settings — no separate apps even required.</p>



<p class="wp-block-paragraph">And that, my widget-loving wallaby, is but our first winning widget possibility.</p>



<h2 class="wp-block-heading">Android widget enhancement #2: The on-demand universal pop-up</h2>



<p class="wp-block-paragraph">If you like the idea of having a widget on demand but would rather have it be available to summon from <em>anywhere</em> instead of just from your home screen, this next wacky widget option is just the thing for you.</p>



<p class="wp-block-paragraph">It comes from a spectacular app called <a href="https://play.google.com/store/apps/details?id=com.ss.edgegestures" target="_blank" rel="noreferrer noopener">Edge Gestures</a>, which works in conjunction with Popup Widget to take that same concept and make it universally accessible. (I told ya it was wacky!)</p>



<p class="wp-block-paragraph">When you first install Edge Gestures, the app will prompt you to enable it as a system accessibility service and to grant it the ability to display over other apps. These permissions sound scary — and <a href="https://www.computerworld.com/article/1613704/android-security-warning.html">they should</a>! — but in the case of this specific utility, they’re absolutely appropriate and necessary in order for it to operate. The former is the only way an app is able to create a custom system-wide gesture, which we need for this setup to work its magic, and the latter is how your widget is able to be shown on top of whatever else you’re doing.</p>



<p class="wp-block-paragraph">(If you’re at all worried, note that Edge Gestures doesn’t request any other significant system permissions. Beyond that, it’s reputable, it’s been around for quite a long while, and it has a large number of overwhelmingly positive reviews.)</p>



<p class="wp-block-paragraph">Where were we? Oh, right: Once you’re inside the Edge Gestures configuration area, you’ll be able to select exactly what gesture you want to use for pulling up your widget. I’d think carefully about finding something that won’t interfere with anything else, like the system-level <a href="https://www.computerworld.com/article/1658581/android-gestures.html">Android gestures</a>, and that’ll be convenient to access without being a command you’re likely to trigger by mistake.</p>



<p class="wp-block-paragraph">So, for instance, you might make the gesture a simple swipe downward along the left side of your screen. To do that, you’d find the “Swipe down” option within the app’s “Left” tab, and you’d set it to “Popup Widget” — and then create or select whatever Popup Widget item you want. And remember: You can select one widget or <em>multiple</em> widgets, too.</p>



<p class="wp-block-paragraph">Prepare yourself for some serious oohing and ahhing:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-widgets-edge-gestures.webp" alt="Android widgets: Edge Gestures" class="wp-image-4196887" width="800" height="855" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption">Your favorite widgets are never more than a swipe away with Edge Gestures on Android.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">As you can see, this opens up a whole new world of mobile multitasking potential. I mean, really: How could you <em>not</em> love that?!</p>



<p class="wp-block-paragraph">The final thing worth doing is going into all the <em>other</em> gesture options in that same configuration area and tapping “Clear” for each of ’em to get rid of Edge Gestures’ default actions. I’d also go into whichever side of the screen you <em>aren’t</em> using — left or right — and tap the toggle to turn the gestures for that side off entirely. That way, you won’t inadvertently activate any gestures that you don’t actually want or need.</p>



<p class="wp-block-paragraph">Edge Gestures costs $2 to use.</p>



<h2 class="wp-block-heading">Android widget enhancement #3: The physical key call</h2>



<p class="wp-block-paragraph">Next, here’s an interesting twist on that same on-demand Android widget idea: You can make any widget especially easy to access from anywhere without even having to mess around with any on-screen swiping by setting one of your phone’s <em>physical keys</em> as a trigger for the widget’s appearance.</p>



<p class="wp-block-paragraph">I’ll give you a second to catch your breath and process the sheer splendor of that sorcery.</p>



<p class="wp-block-paragraph">Back? Cool. So, the <em>key</em> to this feat (har har) is the combination of the aforementioned Popup Widget and a handy Android contraption called <a href="https://play.google.com/store/apps/details?id=io.github.sds100.keymapper&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Key Mapper</a> — which makes it easy to map your phone’s physical keys to all kinds of crazy custom actions.</p>



<p class="wp-block-paragraph">In this case, we’ll set it up so that pressing and <em>holding</em> one of your volume keys causes whatever widget you want to be summoned, like so:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2024/06/floating-android-widget.webp" alt="Floating Android widget" class="wp-image-2144001" width="700" height="722" sizes="auto, (max-width: 700px) 100vw, 700px"><figcaption class="wp-element-caption">Yes, your volume key can cause a widget to appear (whoa!).</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">Pretty nifty, no?</p>



<p class="wp-block-paragraph">I’ve got step-by-step instructions for making this happen in <a href="https://www.computerworld.com/article/2143971/android-widgets-floating.html">this separate guide</a>.</p>



<h2 class="wp-block-heading">Android widget enhancement #4: The floating bubble</h2>



<p class="wp-block-paragraph">If you like the notion of having a widget always available but aren’t so keen on the hidden gesture concept, an app called <a href="https://play.google.com/store/apps/details?id=com.applay.overlay" target="_blank" rel="noreferrer noopener">Overlays</a> will let you create a small floating bubble that you can position anywhere on your screen and then tap to pull any widget up when you want it — just like with <a href="https://www.computerworld.com/article/4185786/google-pixel-android-17.html#:~:text=Android%2017%20Pixel%20feature%20%231%3A%20Bubbles%20multitasking%20magic">Android’s recently revived Bubbles multitasking system</a>, only compatible with <em>any</em> Android device and version and with the simplicity of a widget instead of the complexity of an entire app.</p>



<p class="wp-block-paragraph">Check it out:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-widgets-overlays.webp" alt="Android widgets: Overlays" class="wp-image-4196886" width="800" height="852" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption">Overlays puts a floating icon on your screen for easy ongoing widget access.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">By default, Overlays gives you a bunch of its <em>own</em> little widgets to choose from, but the real power comes from adding in widgets from the Android apps you actually rely on. To do that, tap the “Triggers” tab at the bottom of the Overlays configuration area, then tap the red plus button in the lower-right corner of the screen. Select “Manual,” then type in whatever name you want for your widget and tap the icon to pick any icon you like.</p>



<p class="wp-block-paragraph">Tap “Save,” then select “Widget” and find the widget you want from the list. At that point, you’ll see a preview of the widget. Move or resize it if you like, then hit the arrow in the upper-left corner of the screen to exit out of that interface. Last but not least, tap the name of your newly made widget on the screen that comes up next to change its status to “Always on.”</p>



<p class="wp-block-paragraph">As soon as you head out of the app and back to your home screen, your fancy new widget should pop right up. All you’ve gotta do is tap the little downward-facing arrow in its corner to minimize it down to a bubble, which you can then press and hold to move anywhere your widget-worshipping heart desires.</p>



<p class="wp-block-paragraph">Overlays can also create widgets that automatically appear based on <em>context</em> — so you could have something show up every time you connect to a certain Bluetooth device or Wi-Fi network, for instance. To explore those options, just follow the same steps from above but pick “Event” instead of “Manual” when you reach the “Triggers” tab configuration.</p>



<p class="wp-block-paragraph">Overlays is free with an optional $4 in-app upgrade that removes some ads from the configuration tool and unlocks a handful of advanced features.</p>



<h2 class="wp-block-heading">Android widget enhancement #5: The widget stack</h2>



<p class="wp-block-paragraph">Last but not least in our collection of wacky Android widget possibilities is one of my favorite widget wonders — and that’s the ability to stack <em>multiple</em> widgets and then swipe between ’em on your home screen without having ’em take up any extra space.</p>



<p class="wp-block-paragraph">Check it out:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-widgets-smart-launcher-stacked-widgets.webp" alt="Android widgets: Smart Launcher stacked widgets" class="wp-image-4196888" width="800" height="893" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption">The space-saving simplicity of stacked widgets, as seen in Smart Launcher.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">This enhancement presents a bit of a choose-your-own-adventure-style path:</p>



<p class="wp-block-paragraph">First, if you’re using a reasonably recent Samsung Galaxy gizmo, the option is should already be present and available in your standard Samsung home screen setup. Just press and hold any open space on your home screen and then select the option to add a widget — then, once the widget is added, press and hold it and look for the “Create stack” command.</p>



<p class="wp-block-paragraph">With any other Android gadget — or even with a Samsung device, if you want extra options and flexibility — you can use a <a href="https://www.computerworld.com/article/1723954/android-launchers-for-enhanced-efficiency.html">custom Android launcher</a> like the aforementioned <a href="https://play.google.com/store/apps/details?id=ginlemon.flowerfree&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Smart Launcher</a> or <a href="https://play.google.com/store/apps/details?id=bitpit.launcher" target="_blank" rel="noreferrer noopener">Niagara</a> as well as the retro-geeky T9-themed <a href="https://play.google.com/store/apps/details?id=com.loitran.minimalt9launcher.free" target="_blank" rel="noreferrer noopener">Key Launcher</a> I <a href="https://www.computerworld.com/article/4180222/retro-android-home-screen.html">introduced to you</a> earlier this summer.</p>



<p class="wp-block-paragraph">Those launchers replace your phone’s entire home screen environment and give you all sorts of interesting new possibilities for optimizing your interface and making it especially well-suited for <em>you</em>. And the stacked widget feature is just one small sliver of what they offer and how they’ll transform your Android experience.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-widgets-smart-launcher-stacked-widgets-setup.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android widgets: Smart Launcher stacked widgets setup" class="wp-image-4196890" width="1024" height="896" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">The setup interface for a widget stack within Smart Launcher.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">So there ya have it: five wacky, wild, wonderful ways to make widgets even more wow-inducing. Some days, you’ve just gotta love Android and the endless customization, control, and power it provides.</p>



<p class="wp-block-paragraph"><em>Put even more Googley goodness in your noggin with</em> <a href="https://theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><em>my free Android Intelligence newsletter</em></a><em> — one exceptional new thing to try every Friday!</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI agents are shaping the future of work]]></title>
<description><![CDATA[I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing function...]]></description>
<link>https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing functionality.  </p>



<p class="wp-block-paragraph">At the end of 2025, Anthropic and OpenAI launched new AI models and code-generating capabilities. More developers tried <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, and some platforms launched <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development capabilities</a>. By February 2026, even The New York Times reported that <a href="https://www.nytimes.com/2026/02/18/opinion/ai-software.html">the AI disruption had arrived</a>, noting that code generators were building “apps that may be flawed, but credible.”</p>



<p class="wp-block-paragraph">Wall Street investors took notice of the code-generation improvements and other disruptive factors, driving a selloff in SaaS stocks, now referred to as the “<a href="https://www.bloomberg.com/news/articles/2026-02-03/-get-me-out-traders-dump-software-stocks-as-ai-fears-take-hold">SaaSpocalypse</a>.” Part of their concern stemmed from the belief that CIOs would use AI to <a href="https://www.cio.com/article/4148303/cios-rethink-softwares-future-as-ai-agents-advance.html">write software that would replace SaaS solutions</a>.</p>



<h2 class="wp-block-heading">AI innovations from SaaS and solution providers</h2>



<p class="wp-block-paragraph">But I thought differently and wrote a response in my article asking whether <a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is the end of SaaS as we know it</a>. CIOs might use AI to accelerate application modernization, but I doubt they would replace their ERP, CRM, and even smaller SaaS point solutions by building them.</p>



<p class="wp-block-paragraph">Instead, I believed it would be SaaS companies that would take the most advantage of AI code-generation capabilities.</p>



<p class="wp-block-paragraph">This hypothesis drove me to attend nine conferences this spring to see how SaaS companies were launching AI agents and defining a new future of work. I wrote eight articles on <a href="https://drive.starcio.com/cios-need-to-know">what CIOs need to know</a> about data management, agile organizations, marketing, ERPs, critical process management, and other evolutions to plan for in the AI era.</p>



<p class="wp-block-paragraph">Now, looking across all nine conferences, I can draw some conclusions about how AI agents are shaping the future of work. Here are my learnings and what CIOs need to consider when evaluating and deploying AI agents in the workplace.</p>



<h2 class="wp-block-heading">Agentic, human-in-the-middle, or augmenting human?</h2>



<p class="wp-block-paragraph">SaaS companies have very distinct perspectives on the future of work, including the extent to which humans will play which roles and whether and how quickly we’ll see agentic, fully automated work.</p>



<p class="wp-block-paragraph">For example, Atlassian proclaimed, “<a href="https://www.atlassian.com/company/events">step into the future of human-AI collaboration</a>,” while SAP unveiled “<a href="https://news.sap.com/2026/05/sap-sapphire-sap-unveils-autonomous-enterprise/">the autonomous enterprise</a>.” Snowflake aimed to “<a href="https://www.snowflake.com/en/summit/">make AI real for business</a>,” while Appian targeted “<a href="https://www.appianworld.com/">serious AI built on process</a>.”</p>



<p class="wp-block-paragraph">These vendors’ marketers had to decide whether to lead with AI, people, or business in their messaging, but so must CIOs as they contemplate their AI strategies and how to get employees to fully adopt AI agents.</p>



<p class="wp-block-paragraph">Some CIOs see a fully automated agentic AI as the future, with human-in-the-middle as a transitional phase as departments build trust in AI agents’ decision-making and automation capabilities.</p>



<p class="wp-block-paragraph">Other CIOs see AI more as a tool that delivers productivity improvements by augmenting human decision-making capabilities. Many of these CIOs see human augmentation as essential to supporting critical thinking, innovation, and creativity.</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Deloitte’s State of AI Report</a>, published in January, provides a benchmark. It states that 36% of IT leaders expect at least 10% of their jobs to be fully automated in the next year, and 82% expect to reach that benchmark in three years.</p>



<p class="wp-block-paragraph">Many organizations will have a mix of AI agents, choosing automation where reliability at scale is possible, but opting for human augmentation in operationally critical or customer-facing domains. But how CIOs position AI agents is not only an operational strategy; it’s also a cultural statement that shapes employees’ embrace of AI and whether <a href="https://drive.starcio.com/2026/03/ai-leadership-job-at-risk-or-career-opportunity/">detractors vocalize job-loss fears</a>.</p>



<p class="wp-block-paragraph">In the short term, it will also weigh in on which AI agents to use from different partners and which areas to build in-house.</p>



<h2 class="wp-block-heading">Many options to test and deploy AI agents</h2>



<p class="wp-block-paragraph">Many solution providers are demonstrating significantly more AI agents this year. For example, SAP went from <a href="https://drive.starcio.com/2026/05/autonomous-enterprise-ai-cios/">40 Joule Agents in 2025 to over 200 in 2026.</a> Three technology capabilities are fueling this significant growth:</p>



<ul class="wp-block-list">
<li>Adobe, Appian, Boomi, Cisco, Domo, Salesforce, SAP, Snowflake, and others offer <a href="https://www.infoworld.com/article/3497094/does-your-organization-need-a-data-fabric.html">data fabrics</a> and <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data-pipeline</a> capabilities to connect data sources outside the primary workflows supported by their platforms. Appian, Pega, Quickbase, and SAP also centralize business process automation, an important starting point for developing AI agents.  </li>



<li><a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP servers</a> enable integration and communication between AI agents and are used to facilitate multistep agentic workflows. Virtually all the companies announcing major investments in AI agents are also announcing MCP integration capabilities and related partnerships.</li>



<li>Solution providers are not just using AI code-generating capabilities; many are launching their own AI agent development tools. The first beneficiaries of these development tools are the solution providers themselves and their integration partners, who use them to accelerate the development of AI agents and make them available to customers.</li>
</ul>



<p class="wp-block-paragraph">The result is that <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">CIOs will have many options about which agents to test</a>, but will have to dedicate analysts to understand the capability, cost, and compliance trade-offs. Additionally, expect AI agent capabilities to evolve significantly over the next few years, so CIOs should continuously revisit their decisions regarding deployed AI agents, focusing on performance, benefits, and ROI.</p>



<p class="wp-block-paragraph">CIOs should also watch for signs of <a href="https://www.cio.com/article/1247890/7-steps-for-turning-shadow-it-into-a-competitive-edge.html">shadow AI</a> and employee confusion about which AI agents to experiment with on different platforms. The AI strategy should include a transparent, defined process for selecting, reviewing, evaluating, procuring, deploying, driving adoption, monitoring, and collecting end-user feedback around AI agents.</p>



<h2 class="wp-block-heading">AI development capabilities for engineers and citizen builders</h2>



<p class="wp-block-paragraph">The apparent ease-of-use of AI code generators may lead some engineering teams to <a href="https://www.cio.com/article/4097339/your-next-big-ai-decision-isnt-build-vs-buy-its-how-to-combine-the-two.html">build AI agents rather than buy them</a> from SaaS providers. But CIOs should quickly realize that coding is just one step in developing AI agents, and that aggressively pursuing a build strategy can lead to <a href="https://www.cio.com/article/4178324/7-sources-of-ai-debt-and-how-to-avoid-them.html">AI debt</a> and <a href="https://www.cio.com/article/4107377/cios-will-underestimate-ai-infrastructure-costs-by-30.html">increased AI costs</a>.</p>



<p class="wp-block-paragraph">DevOps teams can code AI agents using tools such as Claude, Codex, Lovable, and Replit — a do-it-yourself approach. Some SaaS companies are providing an alternative, with AI agent development tools that leverage the data, infrastructure, and governance baked into their platforms. Many of these development tools offer flexibility, allowing developer teams to select AI models and development environments.</p>



<p class="wp-block-paragraph">Examples of new and enhanced AI development tools I saw at conferences this quarter include:</p>



<ul class="wp-block-list">
<li><a href="https://appian.com/blog/2025/appian-25-4-release-enterprise-ai-agents">Appian Composer and Agent Studio</a></li>



<li><a href="https://www.atlassian.com/software/rovo-dev">Atlassian Rovo Dev</a></li>



<li><a href="https://boomi.com/platform/companion/">Boomi Companion</a></li>



<li><a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/agentic-ops/cloud-control-studio/index.html">Cisco Cloud Control Studio</a></li>



<li><a href="https://www.domo.com/app-catalyst">Domo App Catalyst</a></li>



<li><a href="https://www.pega.com/about/news/press-releases/pega-harnesses-best-practices-and-ai-coding-agents-build-apps-mission">Pega Infinity Studio</a></li>



<li><a href="https://www.quickbase.com/pave">Quickbase Pave</a></li>



<li><a href="https://www.snowflake.com/en/product/snowflake-coco/">Snowflake CoCo</a></li>



<li><a href="https://www.sap.com/products/artificial-intelligence/joule-studio.html">SAP Joule Studio</a>.</li>
</ul>



<p class="wp-block-paragraph">I also reviewed <a href="https://www.nutanix.com/solutions/ai">Nutanix Agentic AI</a>, a platform-as-a-service for accelerating the deployment of agentic AI workloads, and <a href="https://www.adobe.com/products/firefly/features/ai-assistant.html">Adobe Firefly AI Assistant</a> for creatives.</p>



<p class="wp-block-paragraph">These development tools can target different audiences. Some look like low-code development tools targeted at software developers, whereas others are <a href="https://drive.starcio.com/2026/05/low-code-in-the-ai-era-cios-need-to-know/">no-code and enable citizen developers</a>, i.e., businesspeople, to <a href="https://www.cio.com/article/4176062/cios-are-enlisting-business-users-to-vibe-code-their-own-apps.html">develop applications and agents</a>. Additionally, some of these tools support spec-driven development and generate artifacts such as product requirement documents (PRDs), data models, and testing capabilities.</p>



<p class="wp-block-paragraph">Before commissioning AI development for apps and agents, CIOs should sponsor proofs of technical, data, modeling, security, and governance capabilities.</p>



<h2 class="wp-block-heading">The context layer powering AI agents</h2>



<p class="wp-block-paragraph">Between AI agents and the enterprise’s intelligence, including structured data sources, defined business processes, and agent interactions (both human-to-agent and agent-to-agent), lies an evolving “context layer.”</p>



<p class="wp-block-paragraph">This layer refers to the enterprise knowledge that AI agents draw on when evaluating signals and recommending or taking actions. Context may include a knowledge graph, a semantic layer, cleansed document repositories, and other knowledge bases.</p>



<p class="wp-block-paragraph">The context layer, skills, tools, out-of-the-box agents, and governance capabilities are some areas to review where solution providers differentiate. Some examples: </p>



<ul class="wp-block-list">
<li>Many support the <a href="https://open-semantic-interchange.org/">Open Semantic Interchange</a>, and some brand their context layers, such as the <a href="https://www.atlassian.com/platform/teamwork-graph">Atlassian Teamwork Graph</a>, <a href="https://boomi.com/knowledge-hub-early-access/">Boomi Knowledge Hub</a>, and the <a href="https://www.sap.com/products/artificial-intelligence/knowledge-graph.html">SAP Knowledge Graph</a>.</li>



<li>Some are branding their guardrails, such as <a href="https://business.adobe.com/products/brand-intelligence.html">Adobe’s AI Brand Intelligence</a>, <a href="https://appian.com/products/platform/artificial-intelligence">Appian’s Private AI</a>, and <a href="https://www.quickbase.com/intelligence-pack/ai-control-center">Quickbase AI Control Center</a>.</li>



<li>To manage AI agents at scale, some are extending the notion of data catalogs and other governance tools to the AI domain with products such as <a href="https://boomi.com/platform/connect/">Boomi Connect</a>, <a href="https://www.sap.com/products/artificial-intelligence/ai-agent-hub.html">SAP AI Agent Hub</a>, and <a href="https://www.snowflake.com/en/product/features/horizon/">Snowflake Horizon Catalog</a>.</li>
</ul>



<p class="wp-block-paragraph">CIOs should recognize that while solution providers will compete on capabilities, the real “secret sauce” of the context layer lies in the company’s trusted data, well-defined business processes, and employee adoption of AI agents.</p>



<h2 class="wp-block-heading">Conversational user experiences and coworkers</h2>



<p class="wp-block-paragraph">AI agents use the context layer, but also tap into skills, which encode the procedures they can follow, and tools, which prescribe the actions they can take. Before AI agents are ready to pilot, their governance, including permissions, approval gates, and other guardrails, must be defined. Other capabilities to look for when defining AI agents include orchestration, testing evals, and observability.</p>



<p class="wp-block-paragraph">In 2025, many solution providers bolted on AI agents to their existing user experiences. This year, many solution providers showcased new conversational user experiences that employees can use instead of traditional ones built with forms, flows, reports, and static dashboards. Conversational user experiences are where AI agents and people come together, whether it’s human-in-the-middle or human augmentation.</p>



<p class="wp-block-paragraph">Solution providers also grouped their AI agents into assistants or coworkers. For example, <a href="https://business.adobe.com/products/cx-enterprise-coworker.html">Adobe CX Coworker</a> illustrates human augmentation, helping marketers manage campaigns with prompts and monitor their performance. SAP launched <a href="https://www.sap.com/products/artificial-intelligence/ai-assistant.html">Joule Assistants</a> across several business functions, including finance, human capital, supply chain, and customer experience. Other assistants, such as <a href="https://docs.appian.com/suite/help/26.5/appian-ai-copilot.html">Appian AI Copilot</a>, <a href="https://www.atlassian.com/software/rovo">Atlassian Rovo</a>, <a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/ai-assistant/index.html">Cisco AI Assistant</a>, <a href="https://www.nutanix.com/blog/nutanix-intelligent-virtual-agent">Nutanix NIVA</a>, and <a href="https://www.snowflake.com/en/product/snowflake-cowork/">Snowflake CoWork</a>, offer AI-first user experiences to assist different end-user types.</p>



<p class="wp-block-paragraph">CIOs should demo these <a href="https://www.infoworld.com/article/4178415/what-will-ai-first-ux-look-like.html">AI-first user experiences</a> to glimpse the future of work.</p>



<p class="wp-block-paragraph">Developers are already getting used to these experiences through code generators and vibe coding tools. Now, similar capabilities are being tailored across all business functions. CIOs should ramp up their <a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html">change management programs</a> to accelerate the adoption of these AI capabilities.</p>



<p class="wp-block-paragraph">Solution providers are showcasing AI capabilities that can help CIOs <a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/">reshape their businesses</a>. But in Q2, there were only a few examples of how AI can help CIOs drive growth, evolve business models, or embed AI into customer-facing products. I expect to see a wave of further AI innovations that will go beyond productivity improvements and efficiencies and help CIOs pursue <a href="https://drive.starcio.com/2025/02/cios-drive-genai-digital-transformation/">growth-driving digital transformation strategies</a>.  </p>



<p class="wp-block-paragraph"><em>Sacolick travelled to conferences mentioned in this article as a guest of Adobe, Appian, Atlassian, Domo, Nutanix, SAP, and Snowflake. In addition, he was hired by Quickbase to speak at its conference.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[obsidian-skills: Teach Claude Code How to Work with Obsidian]]></title>
<description><![CDATA[The post obsidian-skills: Teach Claude Code How to Work with Obsidian first appeared on Tecmint: Linux Howtos, Tutorials & Guides .If you’ve ever watched an AI coding agent mess up your Obsidian vault, this can help. I keep my second
The post obsidian-skills: Teach Claude Code How to Work with Ob...]]></description>
<link>https://tsecurity.de/de/3666954/unix-server/obsidian-skills-teach-claude-code-how-to-work-with-obsidian/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666954/unix-server/obsidian-skills-teach-claude-code-how-to-work-with-obsidian/</guid>
<pubDate>Tue, 14 Jul 2026 07:46:01 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The post <a href="https://www.tecmint.com/obsidian-skills-claude-code-linux/">obsidian-skills: Teach Claude Code How to Work with Obsidian</a> first appeared on <a href="https://www.tecmint.com/">Tecmint: Linux Howtos, Tutorials &amp; Guides</a> .<p>If you’ve ever watched an AI coding agent mess up your Obsidian vault, this can help. I keep my second</p>
The post <a href="https://www.tecmint.com/obsidian-skills-claude-code-linux/">obsidian-skills: Teach Claude Code How to Work with Obsidian</a> first appeared on <a href="https://www.tecmint.com/">Tecmint: Linux Howtos, Tutorials &amp; Guides</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4682: Behind the Keyboard: A Cybersecurity Operator’s Real-World Workflow]]></title>
<description><![CDATA[This show has been flagged as Explicit by the host.










SUMMARY


The presenter outlines a practical cybersecurity workflow, covering ergonomic setups, browser isolation, virtual machine troubleshooting, AI-assisted scripting, and network tunneling methods utilized during active securi...]]></description>
<link>https://tsecurity.de/de/3666605/podcasts/hpr4682-behind-the-keyboard-a-cybersecurity-operators-real-world-workflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666605/podcasts/hpr4682-behind-the-keyboard-a-cybersecurity-operators-real-world-workflow/</guid>
<pubDate>Tue, 14 Jul 2026 02:03:31 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Explicit by the host.</p>

<h1>

</h1>

<h1>

</h1>

<h1>
SUMMARY</h1>

<p>
The presenter outlines a practical cybersecurity workflow, covering ergonomic setups, browser isolation, virtual machine troubleshooting, AI-assisted scripting, and network tunneling methods utilized during active security assessments.</p>

<h1>
ONE-SENTENCE TAKEAWAY</h1>

<p>
Isolate browser environments, utilize automation scripts, and verify network paths before starting security tests to avoid workflow interruptions.</p>

<h1>
TOOLS</h1>

<ul>

<li>

<strong>
Talon Voice</strong>
 – Open-source voice recognition software enabling hands-free computer control and command execution.</li>

<li>

<strong>
Obsidian</strong>
 – Local-first markdown note-taking application supporting secure, AI-friendly knowledge management.</li>

<li>

<strong>
AutoHotkey</strong>
 – Windows scripting utility for creating custom macros and remapping keyboard inputs.</li>

<li>

<strong>
Chrome Debug Commands</strong>
 – Browser developer tools allowing direct inspection of extensions, cookies, and storage.</li>

<li>

<strong>
Whisper Diarization</strong>
 – Audio processing script that separates speaker tracks and converts recordings to searchable text.</li>

<li>

<strong>
Hyper-V / WSL</strong>
 – Microsoft virtualization platforms enabling isolated guest environments and Linux subsystem integration.</li>

<li>

<strong>
OpenConnect / OpenVPN</strong>
 – Command-line tunneling clients used for establishing secure, split-tunnel network connections.</li>

<li>

<strong>
Jamboree Framework</strong>
 – Portable PowerShell environment that dynamically provisions development tools without altering system paths.</li>

<li>

<strong>
MOBA Portable</strong>
 – Feature-rich terminal emulator supporting static/dynamic tunnels, auto-reconnect, and embedded X-server capabilities.</li>

<li>

<strong>
Nmap</strong>
 – Network discovery and security auditing tool utilized for comprehensive port scanning and service detection.</li>

</ul>

<h2>
00:00:00 Ergonomic Workspace Configuration</h2>

<p>
Configures physical workstation elements to reduce strain during extended testing sessions. Proper alignment prevents repetitive stress injuries while maintaining focus on technical tasks.</p>

<ul>

<li>

<strong>
Monitor Positioning</strong>
 – Displays should align with eye level to maintain neutral neck posture; the speaker notes their curved 49-inch screen sits slightly high due to chair adjustments.</li>

<li>

<strong>
Split Keyboard Layout</strong>
 – Utilizes a Freestyle 2 mechanical keyboard, allowing natural shoulder-width arm placement and reducing wrist deviation during prolonged typing.</li>

<li>

<strong>
Postural Adaptation</strong>
 – Acknowledges that ergonomic equipment requires matching body alignment; elbow rests should sit between hip and shoulder height for optimal leverage.</li>

</ul>

<h2>
01:45:00 Voice Control &amp; Note Synchronization</h2>

<p>
Utilizes auditory input methods and localized knowledge bases to streamline documentation workflows. Separating secure work notes from casual observations prevents data contamination.</p>

<ul>

<li>

<strong>
Talon Voice Integration</strong>
 – Runs continuously to handle navigation, text entry, and application switching without manual keyboard interaction.</li>

<li>

<strong>
Obsidian Migration</strong>
 – Transitions from cloud-based keep apps to local markdown files, enabling direct querying by local AI models while maintaining offline accessibility.</li>

<li>

<strong>
Note Categorization</strong>
 – Divides information into secure work records and insecure personal logs, ensuring clean data pipelines for future retrieval and analysis.</li>

</ul>

<h2>
03:50:00 Browser Extension Management &amp; Security Isolation</h2>

<p>
Separates web browsing activities from primary work processes to minimize attack surfaces. Running dedicated user profiles prevents plugin conflicts and credential leakage.</p>

<ul>

<li>

<strong>
Jailed User Accounts</strong>
 – Creates restricted system profiles that only launch the browser, isolating extensions from core workstation operations.</li>

<li>

<strong>
Shared Folder Synchronization</strong>
 – Establishes a single directory path bridging work and browsing users, allowing seamless file transfers without cross-contamination.</li>

<li>

<strong>
Extension Audit Process</strong>
 – Leverages Chrome debug commands to enumerate installed plugins, verifying functionality before deployment on target networks.</li>

</ul>

<h2>
06:15:00 Training Optimization &amp; Audio Processing</h2>

<p>
Accelerates mandatory compliance viewing through speed manipulation and automated transcription. Converting video content into searchable text enables rapid information retrieval.</p>

<ul>

<li>

<strong>
Global Speed Control</strong>
 – Increases playback rates up to sixteen times normal speed, drastically reducing time spent on repetitive corporate training modules.</li>

<li>

<strong>
Whisper Diarization Pipeline</strong>
 – Downloads video tracks, separates speaker voices, and generates timestamped transcripts for quick reference during assessments.</li>

<li>

<strong>
Download Management</strong>
 – Employs multi-threaded swarm downloaders and classic turbo managers to handle bulk media retrieval without interrupting active workflows.</li>

</ul>

<h2>
10:40:00 Virtualization &amp; Network Tunneling Protocols</h2>

<p>
Establishes isolated testing environments using Windows virtual machines while managing connectivity constraints. Proper session handling prevents unexpected disconnections during remote engagements.</p>

<ul>

<li>

<strong>
Enhanced Session Mode</strong>
 – A Hyper-V feature providing higher resolution and shared clipboard functionality; disabling it is required before initiating certain VPN clients to avoid routing conflicts.</li>

<li>

<strong>
Split Tunneling Mechanics</strong>
 – Routes specific traffic through the virtual network while keeping local resources accessible, preventing complete internet loss during connection tests.</li>

<li>

<strong>
Certificate Verification</strong>
 – Identifies self-signed SSL mismatches early in the process, documenting them as preliminary findings before proceeding with authentication steps.</li>

</ul>

<h2>
15:30:00 Macro Automation &amp; Input Remapping</h2>

<p>
Remaps frequently used keyboard shortcuts to reduce physical strain and accelerate command execution. Running scripts with elevated privileges ensures reliable input registration across virtual environments.</p>

<ul>

<li>

<strong>
Caps Lock Repurposing</strong>
 – Converts the caps lock key into a primary modifier, assigning copy/paste functions to adjacent letters for faster workflow navigation.</li>

<li>

<strong>
Physical Typing Macros</strong>
 – Simulates keystrokes with deliberate delays, allowing seamless data entry into restricted VM consoles that block standard clipboard operations.</li>

<li>

<strong>
Administrator Execution Requirement</strong>
 – Highlights that macro scripts must run with elevated privileges to successfully inject inputs across different desktop sessions.</li>

</ul>

<h2>
20:15:00 Portable Development Environments &amp; Python Management</h2>

<p>
Deploys lightweight scripting frameworks that dynamically provision necessary tools without modifying host configurations. Verifying package contents prevents dependency conflicts during testing.</p>

<ul>

<li>

<strong>
Jamboree Framework</strong>
 – A PowerShell-driven utility that downloads and configures development stacks on demand, resetting environment variables to maintain system cleanliness.</li>

<li>

<strong>
NuGet Package Filtering</strong>
 – Queries Microsoft's repository API to retrieve specific Python versions, ensuring compatibility with legacy tunneling scripts.</li>

<li>

<strong>
Binary Verification Process</strong>
 – Checks extracted archives for bundled <code>
pip.exe</code>
 or <code>
pip3.exe</code>
 executables, eliminating manual module installation steps during rapid deployments.</li>

</ul>

<h2>
28:40:00 AI-Assisted Scripting &amp; Debugging Workflows</h2>

<p>
Generates and refines PowerShell functions through iterative conversational prompts. Validating AI output against actual system behavior prevents silent configuration errors.</p>

<ul>

<li>

<strong>
Vibe Coding Approach</strong>
 – Relies on continuous feedback loops with language models to draft, minimize, and debug automation scripts in real-time.</li>

<li>

<strong>
Parameter Standardization</strong>
 – Enforces strict formatting rules for PowerShell commands, avoiding hardcoded paths and ensuring cross-environment compatibility.</li>

<li>

<strong>
Temporary Storage Management</strong>
 – Monitors extraction directories to prevent disk saturation, redirecting large package downloads away from constrained system partitions.</li>

</ul>

<h2>
35:10:00 Terminal Emulation &amp; Advanced Tunneling Strategies</h2>

<p>
Facilitates complex network routing through dedicated terminal applications. Configuring dynamic and static tunnels enables reliable reverse connections for remote assessments.</p>

<ul>

<li>

<strong>
MOBA Portable Configuration</strong>
 – Utilizes an INI-based tunnel manager that automatically maintains connections across changing IP addresses or Wi-Fi networks.</li>

<li>

<strong>
Reverse Shell Routing</strong>
 – Establishes outbound channels back to the tester, then proxies all subsequent traffic through those connections for consistent monitoring.</li>

<li>

<strong>
Proxy Chain Integration</strong>
 – Forces non-proxy-aware applications to route through Burp Suite or custom interceptors using Windows utility wrappers like Priboxy.</li>

</ul>

<h2>
42:30:00 Final Connectivity Testing &amp; Engagement Wrap-Up</h2>

<p>
Executes comprehensive port scans to verify target accessibility before documenting findings. Acknowledging workflow detours ensures realistic time management during active engagements.</p>

<ul>

<li>

<strong>
Nmap Verification</strong>
 – Runs full-port scans with verbose output to confirm host responsiveness and identify open services prior to credential testing.</li>

<li>

<strong>
Connection Refusal Documentation</strong>
 – Captures screenshot evidence of failed routing attempts, providing clear proof of network restrictions for client reporting.</li>

<li>

<strong>
Workflow Reflection</strong>
 – Recognizes that exploratory debugging adds value but requires time boundaries; balancing thoroughness with engagement scope maintains professional efficiency.</li>

</ul>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4682/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Pixel colors might rule this year]]></title>
<description><![CDATA[This year's Google Pixel 11 lineup might come in a bunch of funky colors. A series of now-deleted Amazon listings spotted by 9to5Google show what appear to be placeholders for Google's upcoming Pixel 11 in hot pink Fuchsia (Hibiscus), vibrant green Moss (Pistachio), and Midnight (Obsidian) black....]]></description>
<link>https://tsecurity.de/de/3666442/it-nachrichten/the-pixel-colors-might-rule-this-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666442/it-nachrichten/the-pixel-colors-might-rule-this-year/</guid>
<pubDate>Mon, 13 Jul 2026 23:03:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This year's Google Pixel 11 lineup might come in a bunch of funky colors. A series of now-deleted Amazon listings spotted by 9to5Google show what appear to be placeholders for Google's upcoming Pixel 11 in hot pink Fuchsia (Hibiscus), vibrant green Moss (Pistachio), and Midnight (Obsidian) black. We've seen two sets of names for the […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Bits und so #1014 (Sonne, Mond und Sterne)]]></title>
<description><![CDATA[Apple vs OpenAI / GPT 5.6 + SuperApp / M7 2027 / PlayStation Digital Only / Hoymiles Hack / EV-Mietwägen / NextCloud / Coax Zapping / WhatCable / Reiserucksack / Obsidian / Incogni]]></description>
<link>https://tsecurity.de/de/3663942/ios-mac-os/bits-und-so-1014-sonne-mond-und-sterne/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663942/ios-mac-os/bits-und-so-1014-sonne-mond-und-sterne/</guid>
<pubDate>Mon, 13 Jul 2026 01:09:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple vs OpenAI / GPT 5.6 + SuperApp / M7 2027 / PlayStation Digital Only / Hoymiles Hack / EV-Mietwägen / NextCloud / Coax Zapping / WhatCable / Reiserucksack / Obsidian / Incogni]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI bringt ChatGPT Work auf den Markt]]></title>
<description><![CDATA[OpenAIs neues Motto mit ChatGPT Work: Weniger reden, mehr tun PhotoGranary02 / Shutterstock



OpenAI schärft seine Strategie für den Unternehmenseinsatz von KI mit der Einführung von ChatGPT Work. Dabei handelt es sich um eine neue Agenten-gestützte Plattform, um Büro- und Wissensarbeit zu autom...]]></description>
<link>https://tsecurity.de/de/3659916/it-security-nachrichten/openai-bringt-chatgpt-work-auf-den-markt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659916/it-security-nachrichten/openai-bringt-chatgpt-work-auf-den-markt/</guid>
<pubDate>Fri, 10 Jul 2026 15:50:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2662121575.jpg?quality=50&amp;strip=all&amp;w=1024" alt="ChatGPT" class="wp-image-4088684" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">OpenAIs neues Motto mit ChatGPT Work: Weniger reden, mehr tun</figcaption></figure><p class="imageCredit"> PhotoGranary02 / Shutterstock</p></div>



<p>OpenAI schärft seine Strategie für den Unternehmenseinsatz von KI mit der Einführung von ChatGPT Work. Dabei handelt es sich um eine neue Agenten-gestützte Plattform, um Büro- und Wissensarbeit zu automatisieren. Parallel dazu erweitert das Unternehmen die Verfügbarkeit seiner GPT-5.6-Modelle, die laut OpenAI eine höhere Leistung bei gleichzeitig geringeren Betriebskosten bieten.</p>



<p>Laut OpenAI kann ChatGPT Work über Anwendungen und Dateien hinweg arbeiten, lange andauernde Aufgaben ausführen, mehrere Werkzeuge koordinieren sowie Geschäftsdokumente, Präsentationen, Tabellen und sogar Websites erstellen. Mitarbeiter sollen dadurch komplexe Arbeitsabläufe an die KI delegieren können, anstatt sie Schritt für Schritt über einzelne Prompts zu steuern.</p>



<p>Die GPT-5.6-Modelle werden wenige Wochen nach einer zunächst eingeschränkten Vorschau nun allgemein verfügbar. Die breite Markteinführunghatte sich aufgrund von US-Regierungsauflagen verzögert. Die Regierung befürchtete mögliche Risiken im Bereich Cybersicherheit und Biotechnologie. Laut OpenAI bieten die Modelle bessere Leistungen in den Bereichen Programmierung, Büroarbeit, Cybersicherheit und Forschung – bei niedrigeren Inferenzkosten und Token-Verbrauch.</p>



<h2 class="wp-block-heading">Fokus auf Wirtschaftlichkeit statt Benchmark-Rekorde</h2>



<p>Mit der Einführung verändert OpenAI auch seine Strategie im Enterprise-Markt. Statt ausschließlich Spitzenwerte in Benchmarks hervorzuheben, rückt das Unternehmen nun die Leistung pro investiertem Dollar in den Mittelpunkt. Hintergrund sei, dass Unternehmen beim großflächigen KI-Einsatz zunehmend nicht nur auf die Leistungsfähigkeit der Modelle, sondern ebenso auf deren Betriebskosten achten.</p>



<p>„Wir haben GPT-5.6 darauf trainiert, aus jedem Token mehr nutzbare Arbeit herauszuholen“, so OpenAI in einer <a href="https://openai.com/index/gpt-5-6/">Erklärung</a>. Das Ergebnis sei eine höhere Leistung pro Dollar: mehr erledigte Arbeit bei gleichem Budget oder vergleichbare Ergebnisse zu niedrigeren Gesamtkosten.</p>



<p>ChatGPT Work kombiniert GPT-5.6 mit Unternehmensintegrationen und agentenbasierten Funktionen, die es Anwendern ermöglichen sollen, mehrstufige Aufgaben über verbundene Geschäftsanwendungen hinweg auszuführen. Ziel ist es laut OpenAI, Wissensarbeit zu automatisieren und dabei gleichzeitig Governance- und Sicherheitsanforderungen von Unternehmen einzuhalten.</p>



<p>Die Einführung erfolgt zu einem Zeitpunkt, an dem viele Unternehmen die Experimentierphase hinter sich lassen und KI zunehmend in produktiven Arbeitsprozessen einsetzen. Dadurch werden die laufenden Inferenzkosten für CIOs zu einem wachsenden Problem.</p>



<p>„Die KI-Welle hat zwar Produktivitätsgewinne gebracht, gleichzeitig sorgt der steigende Token-Verbrauch aber auch für überraschend hohe Rechnungen in Unternehmen“, erklärt Neil Shah, Vice President Research und Partner bei Counterpoint Research. „Das zwingt Unternehmen dazu, je nach Anwendungsfall unterschiedliche Modelle einzusetzen. Leistung pro Dollar wird damit zur entscheidenden Kennzahl.“</p>



<p>Auch Faisal Kawoosa, Mitgründer und Chefanalyst von Techarc, sieht einen Strategiewechsel. „Die Experimentierphase der KI ist vorbei“, erklärt er. „Unternehmen können heute bereits einen konkreten Nutzen aus KI ziehen. Ob sie jedoch Teil des täglichen Geschäftsbetriebs wird oder nur ein gelegentlich genutztes Werkzeug bleibt, entscheidet letztlich die Leistung pro investiertem Dollar.“</p>



<h2 class="wp-block-heading">Gestaffelte Modelle für unterschiedliche Anforderungen</h2>



<p>OpenAI bietet GPT-5.6 in drei Ausführungen an:</p>



<ul class="wp-block-list">
<li>Sol als Spitzenmodell für komplexe Schlussfolgerungen und anspruchsvolle Aufgaben,</li>



<li>Terra für klassische Enterprise-Anwendungen,</li>



<li>Luna für kostengünstige Einsätze mit hohem Anfragevolumen.</li>
</ul>



<p>Nach Angaben von OpenAI erreichte GPT-5.6 Sol im Benchmark <a href="https://agents-last-exam.org/" target="_blank" rel="noreferrer noopener">Agents’ Last Exam</a>, der langfristige professionelle Arbeitsabläufe bewertet, einen Wert von 53,6 Punkten. Sol übertraf damit konkurrierende Frontier-Modelle bei deutlich geringeren Rechenkosten.</p>



<p>Die Modelle stehen ab sofort über ChatGPT, Codex sowie die OpenAI-API zur Verfügung. Das Spitzenmodell Sol kostet fünf Dollar pro Million Eingabe-Token und 30 Dollar pro Million Ausgabe-Token. Die Modelle Terra und Luna richten sich mit niedrigeren Preisen an Unternehmen, die KI in großem Maßstab einsetzen möchten.</p>



<p>Darüber hinaus führt OpenAI zwei neue Reasoning-Modi ein. Der Max-Modus stellt für besonders schwierige Aufgaben zusätzliche Rechenleistung bereit. Der Ultra-Modus koordiniert standardmäßig vier KI-Agenten parallel, um komplexe Arbeitsabläufe schneller zu bearbeiten.</p>



<p>„Ultra geht noch einen Schritt weiter, indem standardmäßig vier Agenten parallel zusammenarbeiten. Das erhöht zwar den Token-Verbrauch, liefert aber bessere Ergebnisse in kürzerer Zeit bei anspruchsvollen Aufgaben“, erklärt OpenAI.</p>



<p>Counterpoint-Analyst Shah sieht darin eine Entwicklung, die den Anforderungen moderner Unternehmensarchitekturen entspricht.</p>



<p>„GPT-5.6 gibt Enterprise-Architekten die Flexibilität, Workloads je nach Bedarf zwischen Luna und Sol zu verteilen – abhängig davon, ob Automatisierung, logisches Denken oder komplexes Schlussfolgern gefragt sind.“</p>



<h2 class="wp-block-heading">Fortschritte bei Programmierung, Produktivität und Sicherheit</h2>



<p>Nach Angaben von OpenAI erreichte GPT-5.6 Sol im Artificial Analysis Coding Agent Index einen Wert von 80 Punkten und benötigte dabei weniger als die Hälfte der Ausgabe-Token konkurrierender Modelle. Auch in den Benchmarks Terminal-Bench 2.1 und DeepSWE, die praxisnahe Softwareentwicklungsaufgaben messen, habe das Modell Spitzenwerte erzielt.</p>



<p>Darüber hinaus sollen die Modelle die Produktivität durch verbesserte Dokumentenerstellung sowie Integrationen mit Microsoft 365, Google Drive, Slack und Notion erhöhen.</p>



<p>Auch im Bereich Cybersicherheit meldet OpenAI deutliche Fortschritte: Im ExploitBench erreichte GPT-5.6 Sol 73,5 Prozent, verglichen mit 47,9 Prozent bei GPT-5.5. Im ExploitGym verdoppelte das Modell nahezu die Leistung seines Vorgängers.</p>



<p>„GPT-5.6 unterstützt wichtige Verteidigungsaufgaben wie sichere Codeprüfungen, Patch-Management, Bedrohungsmodellierung und Blue-Teaming“, so OpenAI.</p>



<h2 class="wp-block-heading">Sicherheit bleibt ein zentrales Thema</h2>



<p>Nach Angaben des Unternehmens verfügt GPT-5.6 über die bislang umfangreichsten Sicherheitsmechanismen. Diese kombinierten Schutzmaßnahmen auf Modellebene mit Echtzeitüberwachung und umfassende Sicherheitstests, darunter automatisierte Red-Team-Tests im Umfang von rund 700.000 GPU-Stunden.</p>



<p>Shah sieht insbesondere die Kombination aus Schutzmechanismen und kontinuierlicher Überwachung als möglichen Wettbewerbsvorteil im Enterprise-Markt.</p>



<p>Kawoosa merkt jedoch an, dass CIOs auch künftig mehr Transparenz verlangen werden, bevor sie den neuesten KI-Modellen vollständig vertrauen. „Der Wettbewerb zwischen den Anbietern großer Sprachmodelle wird anhalten. Die Hersteller werden die Sicherheitsmechanismen ihrer Konkurrenten kontinuierlich testen und herausfordern.“ (mb)</p>



<p>Dieser Artikel basiert auf einem Beitrag der <a href="https://www.infoworld.com/article/4195478/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout.html">Infoworld</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout]]></title>
<description><![CDATA[OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.



According to the comp...]]></description>
<link>https://tsecurity.de/de/3659265/it-nachrichten/openai-launches-chatgpt-work-as-it-broadens-gpt-56-rollout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659265/it-nachrichten/openai-launches-chatgpt-work-as-it-broadens-gpt-56-rollout/</guid>
<pubDate>Fri, 10 Jul 2026 11:32:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.</p>



<p>According to the company, ChatGPT Work can operate across applications and files, execute long-running tasks, coordinate multiple tools, and produce business documents, presentations, spreadsheets, and websites, allowing employees to delegate more complex workflows rather than interact through individual prompts.</p>



<p>GPT- 5.6 models, generally available weeks after a <a href="https://www.infoworld.com/article/4194598/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion.html" target="_blank">limited preview</a> following US government restrictions on their broader rollout due to concerns about advanced cybersecurity and biology capabilities, can deliver stronger performance across coding, enterprise knowledge work, cybersecurity, and scientific research while lowering inference costs and token consumption, OpenAI said.</p>



<p>The launch marks a shift in OpenAI’s enterprise strategy. Rather than emphasizing benchmark leadership alone, the company is pitching GPT-5.6 around performance per dollar, arguing that enterprises deploying AI at scale increasingly care as much about operating costs as raw model capability.</p>



<p>“We trained GPT-5.6 to get more useful work from every token,” OpenAI said in a <a href="https://openai.com/index/gpt-5-6/" target="_blank" rel="noreferrer noopener">statement</a>. “The result is stronger performance per dollar: more successful work for the same spend, or comparable results at a lower total cost.”</p>



<p>The models are now generally available through ChatGPT, Codex, and the OpenAI API. OpenAI has priced Sol at $5 per million input tokens and $30 per million output tokens, while Terra and Luna provide progressively lower-cost options for organizations scaling AI deployments, the statement added.</p>



<h2 class="wp-block-heading">Enterprise AI shifts from experimentation to economics</h2>



<p>ChatGPT Work combines GPT-5.6 with enterprise integrations and agentic capabilities that allow users to perform multi-step tasks across connected business applications instead of interacting with AI through isolated prompts. OpenAI said the platform is designed to help organizations automate knowledge work while maintaining enterprise-grade governance and security.</p>



<p>The launch comes as enterprises move beyond AI experimentation and begin deploying models across production workloads, making inference costs a growing concern for CIOs.</p>



<p>“The AI wave has brought productivity gains, but rising token consumption has also created bill shocks for enterprises,” said Neil Shah, vice president for research and partner at Counterpoint Research. “This is forcing organizations to adopt different models for different workloads, making performance per dollar the key metric.”</p>



<p>Faisal Kawoosa, co-founder and chief analyst at Techarc, said enterprises are now evaluating AI investments more pragmatically.</p>



<p>“The exploratory stage of AI is over,” he said. “Organizations can derive value from AI today, but performance per dollar will determine whether it becomes part of everyday business operations or remains an ad hoc tool.”</p>



<h2 class="wp-block-heading">Tiered models for different workloads</h2>



<p>GPT-5.6 Sol is OpenAI’s flagship model for complex reasoning, Terra targets mainstream enterprise applications, and Luna is designed for lower-cost, high-volume deployments.</p>



<p>According to OpenAI, GPT-5.6 Sol scored 53.6 on Agents’ Last Exam, a benchmark for long-running professional workflows, outperforming competing frontier models while requiring significantly lower compute costs.</p>



<p>The company also introduced two new reasoning modes. The max mode allocates additional compute for complex problems, while ultra coordinates four AI agents in parallel to accelerate demanding workflows.</p>



<p>“Ultra goes further by coordinating four agents in parallel by default, trading higher token use for stronger results and faster time-to-result on demanding tasks,” the statement added.</p>



<p>Shah said the architecture reflects how enterprises are increasingly orchestrating multiple AI models.</p>



<p>“GPT-5.6 gives enterprise architects flexibility to route workloads from Luna to Sol depending on whether they require automation, logic, or complex reasoning,” he said.</p>



<p>Kawoosa added that the tiered approach aligns with how enterprise software has traditionally been consumed.</p>



<p>“It gives enterprises of different sizes the flexibility to optimize technology consumption according to their requirements,” he said.</p>



<h2 class="wp-block-heading">Coding, productivity, and security gains</h2>



<p>OpenAI said GPT-5.6 Sol achieved a score of 80 on the Artificial Analysis Coding Agent Index while consuming fewer than half the output tokens of competing models. It also reported state-of-the-art results on Terminal-Bench 2.1 and DeepSWE, benchmarks that measure real-world software engineering tasks.</p>



<p>The company said the models also improve enterprise productivity through stronger document generation capabilities and integrations with Microsoft 365, Google Drive, Slack, and Notion.</p>



<p>On cybersecurity, GPT-5.6 Sol scored 73.5% on ExploitBench, up from 47.9% for GPT-5.5, and nearly doubled its predecessor’s performance on ExploitGym.</p>



<p>“GPT-5.6 supports important defensive tasks such as secure code review, patching, threat modeling, and blue teaming,” OpenAI said.</p>



<h2 class="wp-block-heading">Security remains an enterprise focus</h2>



<p>OpenAI said GPT-5.6 incorporates its “most robust safeguards to date,” combining model-level protections with real-time monitoring and extensive safety testing, including approximately 700,000 GPU hours of automated red-team evaluations.</p>



<p>Shah said layered guardrails and monitoring could become an important differentiator for enterprise deployments.</p>



<p>Kawoosa, however, said CIOs will continue demanding greater transparency before fully trusting frontier AI systems.</p>



<p>“Competition among LLM providers will continue, with vendors constantly testing and challenging each other’s guardrails,” he said.</p>



<p><em>The article originally appeared on <a href="https://www.infoworld.com/article/4195478/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout]]></title>
<description><![CDATA[OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.



According to the comp...]]></description>
<link>https://tsecurity.de/de/3659231/ai-nachrichten/openai-launches-chatgpt-work-as-it-broadens-gpt-56-rollout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659231/ai-nachrichten/openai-launches-chatgpt-work-as-it-broadens-gpt-56-rollout/</guid>
<pubDate>Fri, 10 Jul 2026 11:18:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs.</p>



<p>According to the company, ChatGPT Work can operate across applications and files, execute long-running tasks, coordinate multiple tools, and produce business documents, presentations, spreadsheets, and websites, allowing employees to delegate more complex workflows rather than interact through individual prompts.</p>



<p>GPT- 5.6 models, generally available weeks after a <a href="https://www.infoworld.com/article/4194598/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion.html" target="_blank">limited preview</a> following US government restrictions on their broader rollout due to concerns about advanced cybersecurity and biology capabilities, can deliver stronger performance across coding, enterprise knowledge work, cybersecurity, and scientific research while lowering inference costs and token consumption, OpenAI said.</p>



<p>The launch marks a shift in OpenAI’s enterprise strategy. Rather than emphasizing benchmark leadership alone, the company is pitching GPT-5.6 around performance per dollar, arguing that enterprises deploying AI at scale increasingly care as much about operating costs as raw model capability.</p>



<p>“We trained GPT-5.6 to get more useful work from every token,” OpenAI said in a <a href="https://openai.com/index/gpt-5-6/" target="_blank" rel="noreferrer noopener">statement</a>. “The result is stronger performance per dollar: more successful work for the same spend, or comparable results at a lower total cost.”</p>



<p>The models are now generally available through ChatGPT, Codex, and the OpenAI API. OpenAI has priced Sol at $5 per million input tokens and $30 per million output tokens, while Terra and Luna provide progressively lower-cost options for organizations scaling AI deployments, the statement added.</p>



<h2 class="wp-block-heading">Enterprise AI shifts from experimentation to economics</h2>



<p>ChatGPT Work combines GPT-5.6 with enterprise integrations and agentic capabilities that allow users to perform multi-step tasks across connected business applications instead of interacting with AI through isolated prompts. OpenAI said the platform is designed to help organizations automate knowledge work while maintaining enterprise-grade governance and security.</p>



<p>The launch comes as enterprises move beyond AI experimentation and begin deploying models across production workloads, making inference costs a growing concern for CIOs.</p>



<p>“The AI wave has brought productivity gains, but rising token consumption has also created bill shocks for enterprises,” said Neil Shah, vice president for research and partner at Counterpoint Research. “This is forcing organizations to adopt different models for different workloads, making performance per dollar the key metric.”</p>



<p>Faisal Kawoosa, co-founder and chief analyst at Techarc, said enterprises are now evaluating AI investments more pragmatically.</p>



<p>“The exploratory stage of AI is over,” he said. “Organizations can derive value from AI today, but performance per dollar will determine whether it becomes part of everyday business operations or remains an ad hoc tool.”</p>



<h2 class="wp-block-heading">Tiered models for different workloads</h2>



<p>GPT-5.6 Sol is OpenAI’s flagship model for complex reasoning, Terra targets mainstream enterprise applications, and Luna is designed for lower-cost, high-volume deployments.</p>



<p>According to OpenAI, GPT-5.6 Sol scored 53.6 on Agents’ Last Exam, a benchmark for long-running professional workflows, outperforming competing frontier models while requiring significantly lower compute costs.</p>



<p>The company also introduced two new reasoning modes. The max mode allocates additional compute for complex problems, while ultra coordinates four AI agents in parallel to accelerate demanding workflows.</p>



<p>“Ultra goes further by coordinating four agents in parallel by default, trading higher token use for stronger results and faster time-to-result on demanding tasks,” the statement added.</p>



<p>Shah said the architecture reflects how enterprises are increasingly orchestrating multiple AI models.</p>



<p>“GPT-5.6 gives enterprise architects flexibility to route workloads from Luna to Sol depending on whether they require automation, logic, or complex reasoning,” he said.</p>



<p>Kawoosa added that the tiered approach aligns with how enterprise software has traditionally been consumed.</p>



<p>“It gives enterprises of different sizes the flexibility to optimize technology consumption according to their requirements,” he said.</p>



<h2 class="wp-block-heading">Coding, productivity, and security gains</h2>



<p>OpenAI said GPT-5.6 Sol achieved a score of 80 on the Artificial Analysis Coding Agent Index while consuming fewer than half the output tokens of competing models. It also reported state-of-the-art results on Terminal-Bench 2.1 and DeepSWE, benchmarks that measure real-world software engineering tasks.</p>



<p>The company said the models also improve enterprise productivity through stronger document generation capabilities and integrations with Microsoft 365, Google Drive, Slack, and Notion.</p>



<p>On cybersecurity, GPT-5.6 Sol scored 73.5% on ExploitBench, up from 47.9% for GPT-5.5, and nearly doubled its predecessor’s performance on ExploitGym.</p>



<p>“GPT-5.6 supports important defensive tasks such as secure code review, patching, threat modeling, and blue teaming,” OpenAI said.</p>



<h2 class="wp-block-heading">Security remains an enterprise focus</h2>



<p>OpenAI said GPT-5.6 incorporates its “most robust safeguards to date,” combining model-level protections with real-time monitoring and extensive safety testing, including approximately 700,000 GPU hours of automated red-team evaluations.</p>



<p>Shah said layered guardrails and monitoring could become an important differentiator for enterprise deployments.</p>



<p>Kawoosa, however, said CIOs will continue demanding greater transparency before fully trusting frontier AI systems.</p>



<p>“Competition among LLM providers will continue, with vendors constantly testing and challenging each other’s guardrails,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linkdump 28/2026]]></title>
<description><![CDATA[Viel Spass bei den von mir als lesenswert empfundenen Links auf Artikel, die ich in der vergangenen Woche gelesen habe.

Stay curious, Your Brain's Learning Rate.

Warum Signal für WhatsApp-Aussteiger die bessere Wahl ist, ich unterschreibe das.

My dead told me decades ago, that a company hast d...]]></description>
<link>https://tsecurity.de/de/3658667/it-nachrichten/linkdump-282026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658667/it-nachrichten/linkdump-282026/</guid>
<pubDate>Fri, 10 Jul 2026 06:18:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Viel Spass bei den von mir als lesenswert empfundenen Links auf Artikel, die ich in der vergangenen Woche gelesen habe.<br>
<br>
Stay curious, <a href="https://metatrends.substack.com/p/your-brains-learning-rate">Your Brain's Learning Rate</a>.<br>
<br>
<a href="https://www.kuketz-blog.de/warum-signal-fuer-whatsapp-aussteiger-die-bessere-wahl-ist/">Warum Signal für WhatsApp-Aussteiger die bessere Wahl ist</a>, ich unterschreibe das.<br>
<br>
My dead told me decades ago, that a company hast do work on the "we-feeling", <a href="https://mikefisher.substack.com/p/you-cant-fake-belonging">You Can’t Fake Belonging</a>.<br>
<br>
<a href="https://super-productivity.com/blog/private-alternatives-todoist-ticktick-notion-microsoft-todo/">Private Alternatives to Todoist, TickTick, Notion, and Microsoft To Do</a>, good overview, Vikunja is missing.<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Robota review – machines on the march in next-gen version of sci-fi classic]]></title>
<description><![CDATA[Schwarzman Centre, OxfordHeadlong’s take on Karel Čapek’s 1920 tale of romance and robots is rife with timely debates about tech’s threat but at times the philosophical discussions drag onIf our world is currently thinking through the brave new future of generative AI and super intelligence, Kare...]]></description>
<link>https://tsecurity.de/de/3658651/ai-nachrichten/robota-review-machines-on-the-march-in-next-gen-version-of-sci-fi-classic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658651/ai-nachrichten/robota-review-machines-on-the-march-in-next-gen-version-of-sci-fi-classic/</guid>
<pubDate>Fri, 10 Jul 2026 06:03:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>Schwarzman Centre, Oxford<br></strong>Headlong’s take on Karel Čapek’s 1920 tale of romance and robots is rife with timely debates about tech’s threat but at times the philosophical discussions drag on</p><p>If our world is currently thinking through the brave new future of generative AI and super intelligence, Karel Čapek’s 1920 play RUR: Rossum’s Universal Robots proves the notion of robot consciousness and rebellion is not a new anxiety. So does Mary Shelley’s Frankenstein, which Čapek’s drama resembles in its philosophical debates and moral warnings, despite its futurism.</p><p>Ella Road adapts Čapek’s play for our times in this Headlong and Schwarzman Centre co-production, its science apparently informed by research from Oxford University academics, which gives it a cutting-edge, real-world underpinning.</p> <a href="https://www.theguardian.com/stage/2026/jul/10/robota-review-schwarzman-centre-oxford">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4680: Robert A. Heinlein: The Future History, Part 2]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.
In his early days as a writer, Heinlein wrote his stories in the context of a shared universe that he called the Future History. These were mostly short stories at first, with the occasional novella. But they include some great stories.
The Future ...]]></description>
<link>https://tsecurity.de/de/3658424/podcasts/hpr4680-robert-a-heinlein-the-future-history-part-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658424/podcasts/hpr4680-robert-a-heinlein-the-future-history-part-2/</guid>
<pubDate>Fri, 10 Jul 2026 02:01:49 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>
<p>In his early days as a writer, Heinlein wrote his stories in the context of a shared universe that he called the Future History. These were mostly short stories at first, with the occasional novella. But they include some great stories.</p>
<h1 class="entry-title">The Future History, Part 2</h1>
						
<p>There were a few key themes running through Heinlein’s body of work. One we have already remarked upon, individual freedom, which had to be protected from any source of power, including both government and private corporations. This was essentially a libertarian perspective, but unlike many of today’s libertarians he was equally averse to the corporate type of power as a threat. But he had a complex view of the world which has resisted some attempts to pigeonhole him. He started out as a socialist, and while he didn’t remain one, he never became a knee-jerk reactionary either. In fact, he clearly despised them just as much. One way of looking at his body of work is that he explored the ramifications of different social policies through his stories, but in most cases the needs of a good story came first in the early years. In his later works he often surrendered to the temptation to pontificate, which reduced the enjoyment of them somewhat for anyone who was not already in agreement with his opinions</p>

<p>The second major theme you see throughout all of his works is the idea of the competent individual. He admired anyone who could do a job well, and clearly did not care whether they were man or woman, nor black or white. Alexei Panshin writes, in <a href="https://www.amazon.com/Heinlein-Dimension-Critical-Alexei-Panshin/dp/0911682015" data-type="link" data-id="https://www.amazon.com/Heinlein-Dimension-Critical-Alexei-Panshin/dp/0911682015" target="_blank" rel="noreferrer noopener">Heinlein in Dimension</a>: </p>

<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>“There is one unique and vivid human Heinlein character, but he is a composite of Joe-Jim Gregory, Harriman, Waldo, Lazarus Long, Mr. Kiku, and many others, rather than any one individual.  I call the composite the Heinlein Individual.  . . .  It is a single personality that appears in three different stages and is repeated in every Heinlein book in one form or another.</p>

<p>“The earliest stage is that of the competent but naïve youngster. . . .  The second stage is the competent man in full glory, the man who knows how things work. . . .  The last stage is the wise old man who not only knows how things work, but why they work, too.”</p>
</blockquote>

<p>Harriman we have already encountered in <em>The Man Who Sold The Moon</em>, and the others appear later. The Heinlein Individual, as he is often referred to, appears in many of Heinlein’s stories.</p>

<p>A third major theme has to do with morality and religion. Heinlein grew up in what he considered the heart of the Bible Belt, in Missouri, and saw first-hand how the evangelical Christians operated, and despised what he saw. As someone who believed in individual freedom, he could never surrender to someone else’s idea of how he should live his life. He saw them as a danger to his ideal libertarian society, and this shows up very early in his work. He personified the good, upright, church-going folk as “Mrs. Grundy”, and while you might want to draw the drapes to keep her from knowing what you were doing, you should never let her dictate how you would live your life. Revolt in 2100 begins the exploration of this in detail.</p>

<p>There is a chart of the future history at <a href="https://web.archive.org/web/20151105170345/http://www.baenebooks.com/chapters/1439133417/1439133417___1.htm" data-type="link" data-id="https://web.archive.org/web/20151105170345/http://www.baenebooks.com/chapters/1439133417/1439133417___1.htm" target="_blank" rel="noreferrer noopener">Baen Books</a>, and in it we see that the 1960s were what Heinlein called The Crazy Years. (Remember, he conceived this in the 1940s and 1950s.) But in 2012 the major thing occurred when Nehemiah Scudder, a backwoods preacher, managed to get elected as President. This would be the last election held under the U.S. Constitution as he established a religious dictatorship that lasted a couple of generations. IS this plausible? Heinlein wrote about this:</p>

<p>“<em>As for … the idea that we could lose our freedom by succumbing to a wave of religious hysteria, I am sorry to say that I consider it possible. I hope that it is not probable. But there is a latent deep strain of religious fanaticism in this, our culture; it is rooted in our history and it has broken out many times in the past.</em></p>

<p><em>“It is with us now; there has been a sharp rise in strongly evangelical sects in this country in recent years, some of which hold beliefs theocratic in the extreme, anti-intellectual, anti-scientific, and anti-libertarian.</em>“</p>

<p>His background in the Bible Belt is what informs a lot of his thinking. He goes on to describe how this might happen:</p>

<p><em>“Throw in a Depression for good measure, promise a material heaven here on earth, add a dash of anti-Semitism, anti-Catholicism, anti-Negroism, and a good large dose of anti-“furriners” in general and anti-intellectuals here at home, and the result might be something quite frightening — particularly when one recalls that our voting system is such that a minority distributed as pluralities in enough states can constitute a working majority in Washington.”</em></p>

<p>As the science fiction author <a href="https://david-brin.medium.com/heinleins-future-history-coming-true-before-our-eyes-10356a95556a" data-type="link" data-id="https://david-brin.medium.com/heinleins-future-history-coming-true-before-our-eyes-10356a95556a" target="_blank" rel="noreferrer noopener">David Brin</a> points out, Heinlein accurately predicted much of what we are going through in the United States right now. There is an emerging dictatorship in the United States, promoted by right-wing religious groups. The “material heaven here on earth” is represented by the Prosperity Gospel, prominent in the Trump movement, and so on. Where the Prophet used a restored Ku Klux Klan as his muscle, we have The Proud Boys, and so on. It really does track very closely. Read David Brin’s article for more on this.</p>

<p>But nothing lasts forever. Empires rise and fall, governments change, and in this case a resistance movement arises. The revolt is depicted in the novella <em><a href="https://en.wikipedia.org/wiki/%22If_This_Goes_On%E2%80%94%22" data-type="link" data-id="https://en.wikipedia.org/wiki/%22If_This_Goes_On%E2%80%94%22" target="_blank" rel="noreferrer noopener">If This Goes On— (1940)</a></em>, and it is set in the year 2100, giving the title to the book. The main character is John Lyle, who is a young army officer assigned to the group protecting The Prophet in his capital of New Jerusalem. In the beginning he is thoroughly indoctrinated, but then begins to question his beliefs when he falls for one of The Prophet’s virgins, Sister Judith. He has an older companion in the military who is not only unshocked when John confides in him about his doubts, but offers to help him. It turns out this companion, Zeb Jones, is a member of the underground group called The Cabal that is working to overthrow the theocracy. In the end they are successful, and in the course of this John Lyle does a lot of growing up. In this we see another common characteristic of Heinlein stories: a young, naive boy meets up with an older and wiser man who helps him to grow.</p>

<p>In 2016 <em>If This Goes On—</em> won the Retro-Hugo Award for best novella of 1940. And in a personal note, I have T-shirt that says “Scudder for President 2012”. This baffles most people, but I enjoy the in-joke.</p>

<p>What is interesting in this book is that Heinlein doesn’t stop with a successful revolution. He then goes on in a second novella to describe the government that arose following the revolution, and this story is called <em><a href="https://en.wikipedia.org/wiki/Coventry_(short_story)" data-type="link" data-id="https://en.wikipedia.org/wiki/Coventry_(short_story)" target="_blank" rel="noreferrer noopener">Coventry (1940)</a></em>. The new government that arises after the revolution is called The Covenant, and it is an attempt to make sure that what happened with Scudder in 2012 could never happen again. It is a strongly libertarian government based on an agreement to be non-violent. In this society, scientists can cured criminal or violent tendencies, but any citizen convicted of such must agree to the treatment. The alternative to treatment is that they can be exiled to a place called Coventry. Coventry is outside of the Covenant society, and the Covenant society has nothing to do with them. </p>

<p>Our protagonist, David McKinnon, is convicted of assault, and chooses to go to Coventry instead of getting treatment. He imagines it is a peaceful anarchy, but is disabused of this notion when he is robbed of all of this possessions upon entry and thrown in jail. A fellow inmate, Fader Magee, helps him escape, and we learn he is an agent of the Covenant government. They learn that two of the factions in Coventry have joined forces, and found a way to break through the barrier that surrounds Coventry. They plan to attack and overthrow the Covenant government. David and Fader separately work to escape and get back to warn the Covenant government, which they do successfully. And by doing this, David has demonstrated that he is no longer a danger to the Covenant society and no longer subject to treatment.</p>

<p>This story won a <a href="https://en.wikipedia.org/wiki/Prometheus_Award#Hall_of_Fame_Award_inductees" data-type="link" data-id="https://en.wikipedia.org/wiki/Prometheus_Award#Hall_of_Fame_Award_inductees" target="_blank" rel="noreferrer noopener">Prometheus Hall of Fame Award</a>, which is awarded by the Libertarian Futurist Society. And the Covenant society certainly has libertarian features. But this is not the Randian version of libertarianism, as exemplified by the fact that David is restored to the society because he demonstrated his concern for others. Heinlein always promoted individual freedom, but also the idea that people have a responsibility towards others.</p>

<p>Finally, <em>Revolt in 2100</em> contains the short story <em>Misfit</em>, w2hich we have looked at previously.</p>

<p><em><a href="https://en.wikipedia.org/wiki/The_Past_Through_Tomorrow" data-type="link" data-id="https://en.wikipedia.org/wiki/The_Past_Through_Tomorrow" target="_blank" rel="noreferrer noopener">The Past Through Tomorrow (1967)</a></em> is a one volume collection of most of the Future history stories. I say most because just which stories belonged in this group could change from time to time. It also has the last version of the Chart of the Future History, and a few stories we have not yet mentioned (<em>Methusaleh’s Children</em>, and <em>The Menace From Earth</em>). And many of his other works contain back references to these events that imply that they might be set in the same alternate universe. Heinlein gets the last word on this:</p>

<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><em>“I have never been sure whether or not publishing that chart was a good idea or a bad mistake. Possibly it helped to sell some stories later—but certainly it caused me and still causes me to receive a lot nuisance mail from nitpickers. I have never felt bound by that chart; it was to serve me, not the other way around. If I found myself with a good story notion which fitted fairly well into the chart but not perfectly, I shed no tears—I went ahead and let the inconsistencies stand.</em></p>

<p><em>I want each story to be internally consistent . . . but I won’t let myself be painted into a corner through trying to fit that chart perfectly. I may start another “Future History” story tomorrow . . . and find that to make it a good yarn I must violate some item on that chart. I’ll give the nitpickers something to pick, for I will not hurt a good yarn for the sake of “logic”—logic is not involved, as that chart is fiction, not Holy Writ.”</em></p>
</blockquote>

<h3>Links:</h3>
<ul>
<li><a href="https://www.amazon.com/Heinlein-Dimension-Critical-Alexei-Panshin/dp/0911682015">https://www.amazon.com/Heinlein-Dimension-Critical-Alexei-Panshin/dp/0911682015</a></li>
<li><a href="https://web.archive.org/web/20151105170345/http://www.baenebooks.com/chapters/1439133417/1439133417___1.htm">https://web.archive.org/web/20151105170345/http://www.baenebooks.com/chapters/1439133417/1439133417___1.htm</a></li>
<li><a href="https://david-brin.medium.com/heinleins-future-history-coming-true-before-our-eyes-10356a95556a">https://david-brin.medium.com/heinleins-future-history-coming-true-before-our-eyes-10356a95556a</a></li>
<li><a href="https://en.wikipedia.org/wiki/%22If_This_Goes_On%E2%80%94%22">https://en.wikipedia.org/wiki/%22If_This_Goes_On%E2%80%94%22</a></li>
<li><a href="https://en.wikipedia.org/wiki/Coventry_(short_story)">https://en.wikipedia.org/wiki/Coventry_(short_story)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Prometheus_Award#Hall_of_Fame_Award_inductees">https://en.wikipedia.org/wiki/Prometheus_Award#Hall_of_Fame_Award_inductees</a></li>
<li><a href="https://en.wikipedia.org/wiki/The_Past_Through_Tomorrow">https://en.wikipedia.org/wiki/The_Past_Through_Tomorrow</a></li>
<li><a href="https://www.palain.com/science-fiction/the-golden-age/robert-a-heinlein/the-future-history-part-2/">https://www.palain.com/science-fiction/the-golden-age/robert-a-heinlein/the-future-history-part-2/</a></li>
</ul>

<p><a href="https://hackerpublicradio.org/eps/hpr4680/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian neu ausgerichtet: Avowed 2 für neues Fallout eingestellt]]></title>
<description><![CDATA[Im Rahmen der Xbox-Neuausrichtung gibt es gute und schlechte Nachrichten für Obsidian. Das Studio darf endlich ein neues Fallout entwickeln, dafür wird die Fortsetzung des Action-Rollenspiels Avowed 2 gestrichen.]]></description>
<link>https://tsecurity.de/de/3657278/it-nachrichten/obsidian-neu-ausgerichtet-avowed-2-fuer-neues-fallout-eingestellt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657278/it-nachrichten/obsidian-neu-ausgerichtet-avowed-2-fuer-neues-fallout-eingestellt/</guid>
<pubDate>Thu, 09 Jul 2026 16:02:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/3/7/0/6-4ee090237921069f/article-640x360.059b82f9.jpg"><p>Im Rahmen der Xbox-Neuausrichtung gibt es gute und schlechte Nachrichten für Obsidian. Das Studio darf endlich ein neues Fallout entwickeln, dafür wird die Fortsetzung des Action-Rollenspiels Avowed 2 gestrichen.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neues &quot;Fallout&quot; in der Mache: &quot;New Vegas&quot; Team arbeitet an Fortsetzung - doch Gamer zahlen dafür einen hohen Preis]]></title>
<description><![CDATA[Obsidian Entertainment arbeitet wieder an "Fallout". Was eigentlich für Jubelschreie sorgen sollte kommt jedoch mit einer bitteren Pille für Fans von "Avowed".
																					Dieser Artikel wurde einsortiert unter 
																	Gaming,																	Microsoft,																	Microsof...]]></description>
<link>https://tsecurity.de/de/3657118/it-nachrichten/neues-quotfalloutquot-in-der-mache-quotnew-vegasquot-team-arbeitet-an-fortsetzung-doch-gamer-zahlen-dafuer-einen-hohen-preis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657118/it-nachrichten/neues-quotfalloutquot-in-der-mache-quotnew-vegasquot-team-arbeitet-an-fortsetzung-doch-gamer-zahlen-dafuer-einen-hohen-preis/</guid>
<pubDate>Thu, 09 Jul 2026 15:03:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Obsidian Entertainment arbeitet wieder an "Fallout". Was eigentlich für Jubelschreie sorgen sollte kommt jedoch mit einer bitteren Pille für Fans von "Avowed".
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/gaming/index.html">Gaming</a>,																	<a href="https://www.netzwelt.de/hersteller/microsoft.html">Microsoft</a>,																	<a href="https://www.netzwelt.de/microsoft-xbox-one/index.html">Microsoft Xbox One</a>,																	<a href="https://www.netzwelt.de/vergleich/xbox-spiele-besten-games-series-x-s-one.html">Die besten Xbox-Spiele: Highlights für Microsofts Xbox Series X/S/One</a>,																	<a href="https://www.netzwelt.de/xbox-two/index.html">Xbox Series X</a>,																	<a href="https://www.netzwelt.de/gaming/xbox-game-pass/index.html">Xbox Game Pass</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[The makers of New Vegas are working on a new Fallout game]]></title>
<description><![CDATA[Obsidian Entertainment is reportedly working on a new Fallout game after scrapping plans for Avowed 2 amid Xbox's restructuring strategy.]]></description>
<link>https://tsecurity.de/de/3656693/it-nachrichten/the-makers-of-new-vegas-are-working-on-a-new-fallout-game/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656693/it-nachrichten/the-makers-of-new-vegas-are-working-on-a-new-fallout-game/</guid>
<pubDate>Thu, 09 Jul 2026 12:32:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Obsidian Entertainment is reportedly working on a new Fallout game after scrapping plans for Avowed 2 amid Xbox's restructuring strategy.]]></content:encoded>
</item>
<item>
<title><![CDATA[The next killer AI feature? No AI at all]]></title>
<description><![CDATA[Chatting with readers and regular folks in the real world these days, I can’t help but notice a common theme anytime the topic of AI comes up.



It’s an almost amusingly extreme contrast: While the myopic world of tech people (and the type of mostly AI-powered “thought leaders” you see posting i...]]></description>
<link>https://tsecurity.de/de/3656555/ai-nachrichten/the-next-killer-ai-feature-no-ai-at-all/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656555/ai-nachrichten/the-next-killer-ai-feature-no-ai-at-all/</guid>
<pubDate>Thu, 09 Jul 2026 11:48:21 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Chatting with readers and regular folks in the real world these days, I can’t help but notice a common theme anytime the topic of AI comes up.</p>



<p>It’s an almost amusingly extreme contrast: While the myopic world of tech people (and the type of mostly AI-powered “thought leaders” you see posting in turbo-speed on LinkedIn) are waxing endlessly about AI’s amazing impact on society and all the ways it’s, like, <em>totally</em> <em>revolutionizing workflow, bruh</em>, the average human’s take on AI can best be summed up with a single word:</p>



<p>Exasperation.</p>



<p>With shockingly little exception, almost every non-tech-obsessed organism I interact with reacts with something between an eye-rolling sigh and a fed-up facepalm whenever the prevalence of AI arises. It’s almost like having an on-demand in-person GIF gallery of “frustration” available at your fingertips — just mention AI, and you’ll get a meme-worthy reaction from anyone around you.</p>



<p>It’s such a dramatic divergence from the glowingly excited hype we hear left and right from the tech industry itself and the seemingly small but vocal group of overly enthusiastic evangelists who create an echo chamber around it. And that very contrast and the disparity between what tech companies are giving us and what tech users actually <em>want</em> these days led me to a bit of an epiphany this week: </p>



<p>AI may well be creating a killer feature that people will be willing to pay to possess. It’s just not the one most AI-fixated entities are focused on creating — quite the opposite, in fact.</p>



<p><strong>[Get level-headed knowledge in your inbox with </strong><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong>my free Android Intelligence newsletter</strong></a><strong> — practical tech talk by humans, for humans.]</strong></p>



<h2 class="wp-block-heading"><strong>The AI availability irony</strong></h2>



<p>I’ve said it before, and I’ll say it again: In many ways, Gemini — Google’s generative AI chatbot and overall AI layer — <a href="https://www.computerworld.com/article/2117752/google-gemini-ai.html">is the new Google+</a>.</p>



<p>It’s a solution in search of a problem. No one is asking for it and most typical tech users increasingly seem to find its presence actively irksome and invasive — and yet Google continues to insist on shoving it into our faces at every possible opportunity. More and more with every passing week, the company’s adding AI elements into almost every app and service regardless of whether they’re actually helpful in that context. In many cases, in fact, they’re unnecessary, useless, even <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">outright creepy</a> and <a href="https://www.computerworld.com/article/3990497/google-gemini-deceit.html">creating very real problems and liabilities</a> for businesses and individuals alike.</p>



<p>It’s not just Google, of course. The same tale is taking place with practically every tech provider big and small right now. Everyone is cramming AI into every nook and cranny and thinking more about the <em>idea</em> of integrating artificial intelligence — mostly just for the sake of having it there — than creating an optimal experience for the people who actually use said services.</p>



<p>That, in turn, is creating a whole new category of productivity experience that people are actually lining up to pay for — a premium feature of sorts, related to AI and its presence in our lives.</p>



<p>Ready for the most delicious irony of all? The killer AI feature of which we speak is a <em>lack</em> of AI — or at least the ability to disable and avoid it and use it only if and when <em>you</em> want.</p>



<p>It’s not just an anecdotal feeling, either. It’s a measurable trend that may still be in its infancy but is absolutely taking shape around us.</p>



<p>Take, for instance, <a href="https://kagi.com/">Kagi</a> — an ad-free, privacy-centric search service that’s been quietly <a href="https://www.fastcompany.com/91268933/google-alternatives-kagi" target="_blank" rel="noreferrer noopener">building a viable alternative to Google Search</a> for several years already. The proposition is simple: You pay <a href="https://kagi.com/pricing" target="_blank" rel="noreferrer noopener">a monthly fee</a> — five bucks a month for limited use or $10 for unlimited searching — and you get a search engine that’s designed to serve <em>you</em> instead of revolving around the interest of both advertisers and corporate AI initiatives.</p>



<p>The Kagi search experience is clean, simple, and effective — and, most notably for our current conversation, free from all the <a href="https://www.computerworld.com/article/1618297/google-bard-chatgpt-bing-ai-chatbot-search.html">often accuracy-challenged</a> AI-generated “answers” that are now plastered atop most Google searches. You just get the results you want, without any experience-harming interruptions or distractions — because <em>you’re</em> paying for the service. Those five or 10 smackeroos you send over each month restructure the entire relationship and ultimately change everything about the service’s trajectory.</p>



<p>When I wrote a profile piece about Kagi last February, the service <a href="https://www.fastcompany.com/91268933/google-alternatives-kagi#:~:text=Kagi%20boasts%2038%2C000%20paying%20subscribers" target="_blank" rel="noreferrer noopener">boasted 38,000 paying subscribers</a>. Today, according to <a href="https://kagi.com/stats" target="_blank" rel="noreferrer noopener">Kagi’s public stats page</a>, its subscriber base has nearly doubled — to 72,847 users, as of this writing.</p>



<p>It may still be a drop in the bucket — and it may <em>always</em> be a niche demand, in the grand scheme of the global tech picture — but it represents a rapidly growing demand. And Kagi isn’t the only player seeing both the demand and the resulting opportunity. Practically every time Google pushes AI further into its search setup, the privacy-focused (and AI-optional) search provider DuckDuckGo <a href="https://www.fastcompany.com/91548936/google-alternative-ai-free-search-results-surge-in-usage" target="_blank" rel="noreferrer noopener">reports a surge in <em>its</em> adoption</a> as well.</p>



<p>And search isn’t the only arena where this same sentiment is starting to boil over. I hear constantly from folks who are growing ever-more frustrated with all the unavoidable AI integration in other productivity tools, ranging from email to notes and even just plain ol’ document writing. Heck, I <a href="https://www.computerworld.com/article/4185219/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work.html#:~:text=Custom%20extension%20category%20%231%3A%20The%20interface%20fixer">created my own custom interface for Google Docs on the desktop</a> (<a href="https://www.computerworld.com/article/4185219/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work.html">with the help of Gemini</a>, in another delightfully ironically twist) just to escape from all the over-the-top noise Google keeps adding into that environment. It’s a nerdy hack, to be sure — and it’s an opportunity for someone crafty to come in and create an <em>actual</em> solution, in the style of what Kagi has done with search, to more effectively address that same underlying desire.</p>



<p>More and more research is starting to reflect that yearning for practical, useful tech tools that aren’t larded down with AI for the sake of AI. A <a href="https://wpvip.com/resources/reports/future-of-the-web-2026/" target="_blank" rel="noreferrer noopener">recent study</a> by Automattic (the behind WordPress) found 60% of people say AI in a brand’s messaging is more of a turnoff than a feature. My own smaller (and much less scientific, though also more specifically focused) <a href="https://theintelligence.com/43250/how-do-you-feel-about-ai-results-appearing-in-regular-web-searches/" target="_blank" rel="noreferrer noopener">poll</a> of folks who read <a href="https://theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener">my Android Intelligence newsletter</a> found that only 9% of Android-owning animals said they generally loved the presence of AI results in regular web searches — with 26% outright hating it and 64% saying it depends on the situation but that they at least sometimes find it to be more annoying than useful.</p>



<p>So as company after company crams AI into everything and startup after startup jumps on that same steamy bandwagon, the question in my mind is less about what the next big advancement in AI will bring into our lives and more about what interesting opportunities the <em>lack</em> of AI — or at least the ability to limit its influence on a productivity experience and decide for yourself how and when <em>you </em><a href="https://www.computerworld.com/article/4007736/gemini-android.html">actually want to use it</a> — will create.</p>



<p>It’s easy to imagine a scenario in which services like Kagi and DuckDuckGo start to offer AI-free or even just AI-optional alternatives to apps that are being overrun with irritating and countereffective AI integrations — things like Docs, Notion, Slack, and any number of <a href="https://www.computerworld.com/article/4155960/the-top-priority-for-adobes-next-ceo-prepping-for-the-age-of-agents.html">design tools</a>. And it’s equally easy to imagine plenty of people and places being enticed by that <em>lack </em>of AI as a premium feature worth paying to experience.</p>



<p>It may inevitably remain a relatively niche market compared to the more mainstream tech solutions. But for people and organizations woefully underwhelmed with the current direction tech’s taking and willing to shell out cash for quality, it’s an intriguing notion — and an area well worth watching as the AI invasion continues crashing into every last corner of our virtual lives.</p>



<p><em>Sick of AI for the sake of AI? Check out </em><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong><em>my free weekly Android Intelligence newsletter</em></strong></a><strong><em> </em></strong><em>for original human thinking and actually-helpful ways to make the most of your devices.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Avowed 2 ist tot, lang lebe Fallout: Xbox beauftragt New-Vegas-Macher]]></title>
<description><![CDATA[Fallout statt Avowed: Obsidian stoppt die Arbeiten am Rollenspiel-Nachfolger und kehrt zurück ins Ödland. Josh Sawyer, der Mann hinter Fallout: New Vegas, führt das Projekt an. Microsoft will die Nachfrage der Amazon-Serie jetzt schnell bedienen.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3656121/it-security-nachrichten/avowed-2-ist-tot-lang-lebe-fallout-xbox-beauftragt-new-vegas-macher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656121/it-security-nachrichten/avowed-2-ist-tot-lang-lebe-fallout-xbox-beauftragt-new-vegas-macher/</guid>
<pubDate>Thu, 09 Jul 2026 08:22:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159862.html"><img hspace="5" border="0" align="left" alt="Pc, Rollenspiel, Bethesda, Fallout, Cartoon, Maskottchen, Daumen Hoch" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/81702.jpg"></a>
			Fallout statt Avowed: Obsidian stoppt die Arbeiten am Rollenspiel-Nachfolger und kehrt zurück ins Ödland. Josh Sawyer, der Mann hinter Fallout: New Vegas, führt das Projekt an. Microsoft will die Nachfrage der Amazon-Serie jetzt schnell bedienen.			(<a href="https://winfuture.de/news,159862.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian streicht Avowed 2 und übernimmt neues Fallout]]></title>
<description><![CDATA[Bei Xbox wird derzeit kräftig durchgemischt. So krempelt Microsofts Gaming-Sparte gerade die internen Studiostrukturen ordentlich um, und mittendrin steckt Obsidian Entertainment. Das Studio soll sich künftig einem neuen Teil der Fallout-Reihe widmen – eine Entscheidung, die wohl aber gleich mehr...]]></description>
<link>https://tsecurity.de/de/3656054/it-nachrichten/obsidian-streicht-avowed-2-und-uebernimmt-neues-fallout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656054/it-nachrichten/obsidian-streicht-avowed-2-und-uebernimmt-neues-fallout/</guid>
<pubDate>Thu, 09 Jul 2026 07:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bei Xbox wird derzeit kräftig durchgemischt. So krempelt Microsofts Gaming-Sparte gerade die internen Studiostrukturen ordentlich um, und mittendrin steckt Obsidian Entertainment. Das Studio soll sich künftig einem neuen Teil der Fallout-Reihe widmen – eine Entscheidung, die wohl aber gleich mehrere...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/obsidian-streicht-avowed-2-und-uebernimmt-neues-fallout/">Obsidian streicht Avowed 2 und übernimmt neues Fallout</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[„Doom“-Entwickler zusammengestutzt: id Software verliert 136 Mitarbeiter]]></title>
<description><![CDATA[id Software verliert im Rahmen der Xbox-Entlassungen einen Großteil des Teams. Obsidian kippt den „Avowed“-Nachfolger für ein neues „Fallout“.]]></description>
<link>https://tsecurity.de/de/3656051/it-nachrichten/doom-entwickler-zusammengestutzt-id-software-verliert-136-mitarbeiter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656051/it-nachrichten/doom-entwickler-zusammengestutzt-id-software-verliert-136-mitarbeiter/</guid>
<pubDate>Thu, 09 Jul 2026 07:32:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[id Software verliert im Rahmen der Xbox-Entlassungen einen Großteil des Teams. Obsidian kippt den „Avowed“-Nachfolger für ein neues „Fallout“.]]></content:encoded>
</item>
<item>
<title><![CDATA[Xbox: Das nächste Fallout kommt von Obsidian Entertainment]]></title>
<description><![CDATA[Nicht Bethesda, sondern Obsidian soll den nächsten Teil der Fallout-Reihe entwickeln. Dafür wird eine andere Fortsetzung gestrichen. (Fallout New Vegas, Rollenspiel)]]></description>
<link>https://tsecurity.de/de/3656020/it-nachrichten/xbox-das-naechste-fallout-kommt-von-obsidian-entertainment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656020/it-nachrichten/xbox-das-naechste-fallout-kommt-von-obsidian-entertainment/</guid>
<pubDate>Thu, 09 Jul 2026 07:17:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nicht Bethesda, sondern Obsidian soll den nächsten Teil der Fallout-Reihe entwickeln. Dafür wird eine andere Fortsetzung gestrichen. (<a href="https://www.golem.de/specials/fallout-new-vegas/">Fallout New Vegas</a>, <a href="https://www.golem.de/specials/rollenspiel/">Rollenspiel</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=210669&amp;page=1&amp;ts=1783573922" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft reportedly cancels Avowed sequel as Obsidian focuses on a Fallout game]]></title>
<description><![CDATA[The Fallout: New Vegas developer has not escaped Microsoft's Xbox layoffs unscathed.]]></description>
<link>https://tsecurity.de/de/3655415/it-nachrichten/microsoft-reportedly-cancels-avowed-sequel-as-obsidian-focuses-on-a-fallout-game/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655415/it-nachrichten/microsoft-reportedly-cancels-avowed-sequel-as-obsidian-focuses-on-a-fallout-game/</guid>
<pubDate>Wed, 08 Jul 2026 22:31:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Fallout: New Vegas developer has not escaped Microsoft's Xbox layoffs unscathed.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft’s Xbox reset is pivoting Obsidian to make Fallout instead of Avowed]]></title>
<description><![CDATA[As part of Microsoft's big Xbox "reset," which includes layoffs affecting 3,200 staffers, jettisoning studios, and shifting investments to focus on "higher priority projects," Obsidian Entertainment is changing its plans. The studio, behind games like Grounded and The Outer Worlds, is starting wo...]]></description>
<link>https://tsecurity.de/de/3655244/it-nachrichten/microsofts-xbox-reset-is-pivoting-obsidian-to-make-fallout-instead-of-avowed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655244/it-nachrichten/microsofts-xbox-reset-is-pivoting-obsidian-to-make-fallout-instead-of-avowed/</guid>
<pubDate>Wed, 08 Jul 2026 21:02:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As part of Microsoft's big Xbox "reset," which includes layoffs affecting 3,200 staffers, jettisoning studios, and shifting investments to focus on "higher priority projects," Obsidian Entertainment is changing its plans. The studio, behind games like Grounded and The Outer Worlds, is starting work on a new Fallout title and has canceled "multiple projects," including a […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Xbox's RPG studio Obsidian is making a new Fallout game with Bethesda and Fallout: New Vegas' game director — and it's canceled an Avowed sequel to do it]]></title>
<description><![CDATA[Xbox's Obsidian is canceling an Avowed sequel and pivoting to make a new Fallout game in the wake of Microsoft's mass gaming layoffs this week.]]></description>
<link>https://tsecurity.de/de/3655237/windows-tipps/xboxs-rpg-studio-obsidian-is-making-a-new-fallout-game-with-bethesda-and-fallout-new-vegas-game-director-and-its-canceled-an-avowed-sequel-to-do-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655237/windows-tipps/xboxs-rpg-studio-obsidian-is-making-a-new-fallout-game-with-bethesda-and-fallout-new-vegas-game-director-and-its-canceled-an-avowed-sequel-to-do-it/</guid>
<pubDate>Wed, 08 Jul 2026 20:53:08 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Xbox's Obsidian is canceling an Avowed sequel and pivoting to make a new Fallout game in the wake of Microsoft's mass gaming layoffs this week.]]></content:encoded>
</item>
<item>
<title><![CDATA[Xbox's Obsidian has reportedly lost a quarter of its workers to Microsoft's layoffs — the Fallout: New Vegas dev has a "huge list of projects" it's not sure how to continue]]></title>
<description><![CDATA[Microsoft's Xbox layoffs have reportedly seen 25% of devs at the RPG studio Obsidian Entertainment cut in the midst of plans for a "huge list of projects."]]></description>
<link>https://tsecurity.de/de/3655071/windows-tipps/xboxs-obsidian-has-reportedly-lost-a-quarter-of-its-workers-to-microsofts-layoffs-the-fallout-new-vegas-dev-has-a-huge-list-of-projects-its-not-sure-how-to-continue/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655071/windows-tipps/xboxs-obsidian-has-reportedly-lost-a-quarter-of-its-workers-to-microsofts-layoffs-the-fallout-new-vegas-dev-has-a-huge-list-of-projects-its-not-sure-how-to-continue/</guid>
<pubDate>Wed, 08 Jul 2026 19:40:39 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft's Xbox layoffs have reportedly seen 25% of devs at the RPG studio Obsidian Entertainment cut in the midst of plans for a "huge list of projects."]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion Agents: Neue iPhone-App für KI-gestützte Kommunikation unterwegs]]></title>
<description><![CDATA[Notion hat erst kürzlich bekannt gegeben, dass es die eigene, erst ein Jahr alte E-Mail-App Notion Mail, einstellt. Doch das Unternehmen bleibt nicht untätig: Gestern präsentierte man eine brandneue iPhone-App namens Notion Agents (App Store-Link). Mit dieser Neuentwicklung setzt Notion auf eine ...]]></description>
<link>https://tsecurity.de/de/3655001/ios-mac-os/notion-agents-neue-iphone-app-fuer-ki-gestuetzte-kommunikation-unterwegs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655001/ios-mac-os/notion-agents-neue-iphone-app-fuer-ki-gestuetzte-kommunikation-unterwegs/</guid>
<pubDate>Wed, 08 Jul 2026 19:25:29 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Notion hat erst kürzlich bekannt gegeben, dass es die eigene, erst ein Jahr alte E-Mail-App Notion Mail, einstellt. Doch das Unternehmen bleibt nicht untätig: Gestern präsentierte man eine brandneue iPhone-App namens Notion Agents (App Store-Link). Mit dieser Neuentwicklung setzt Notion auf eine noch engere Integration von KI und Produktivitätstools. Die neue App ermöglicht es Nutzern […]</p>
<p>Der Beitrag <a href="https://www.appgefahren.de/notion-agents-neue-iphone-app-fuer-ki-gestuetzte-kommunikation-unterwegs-401990.html">Notion Agents: Neue iPhone-App für KI-gestützte Kommunikation unterwegs</a> erschien zuerst auf <a href="https://www.appgefahren.de/">appgefahren.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Xbox Layoffs Hit Obsidian, id Software, and ZeniMax Online Studios]]></title>
<description><![CDATA[Xbox’s latest round of layoffs has reportedly hit several major Bethesda and Xbox studios, even though none of the affected teams will fully shut down.…
The post Xbox Layoffs Hit Obsidian, id Software, and ZeniMax Online Studios appeared first on OnMSFT.]]></description>
<link>https://tsecurity.de/de/3654449/windows-tipps/xbox-layoffs-hit-obsidian-id-software-and-zenimax-online-studios/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654449/windows-tipps/xbox-layoffs-hit-obsidian-id-software-and-zenimax-online-studios/</guid>
<pubDate>Wed, 08 Jul 2026 15:26:51 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Xbox’s latest round of layoffs has reportedly hit several major Bethesda and Xbox studios, even though none of the affected teams will fully shut down.…</p>
<p>The post <a href="https://onmsft.com/news/xbox-layoffs-hit-obsidian-id-software-and-zenimax-online-studios/">Xbox Layoffs Hit Obsidian, id Software, and ZeniMax Online Studios</a> appeared first on <a href="https://onmsft.com/">OnMSFT</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion Agents: Neue iPhone-App veröffentlicht]]></title>
<description><![CDATA[Nachdem Notion im vergangenen Monat seine erst rund ein Jahr alte Mail-App zu Grabe getragen hat, steht nun eine neue iPhone-App namens Notion Agents im App Store bereit. Das Ganze ist im Kern ein mobiler Chat für Notion-Agenten. Ihr könnt...Zum Beitrag: Notion Agents: Neue iPhone-App veröffentli...]]></description>
<link>https://tsecurity.de/de/3654427/it-nachrichten/notion-agents-neue-iphone-app-veroeffentlicht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654427/it-nachrichten/notion-agents-neue-iphone-app-veroeffentlicht/</guid>
<pubDate>Wed, 08 Jul 2026 15:18:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nachdem Notion im vergangenen Monat seine erst rund ein Jahr alte Mail-App zu Grabe getragen hat, steht nun eine neue iPhone-App namens Notion Agents im App Store bereit. Das Ganze ist im Kern ein mobiler Chat für Notion-Agenten. Ihr könnt...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/notion-agents-neue-iphone-app-veroeffentlicht/">Notion Agents: Neue iPhone-App veröffentlicht</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Four agentic AI memory systems for smarter LLMs]]></title>
<description><![CDATA[AI agents, and the large language models (LLMs) that power them, have short memories. That’s by design. There is only so much conversation that can be encoded into tokens and accessed reliably by the LLM. Retrieval-augmented generation, or RAG, can be used to give agents and LLMs memories larger ...]]></description>
<link>https://tsecurity.de/de/3653745/ai-nachrichten/four-agentic-ai-memory-systems-for-smarter-llms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653745/ai-nachrichten/four-agentic-ai-memory-systems-for-smarter-llms/</guid>
<pubDate>Wed, 08 Jul 2026 11:04:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html" data-type="link" data-id="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html">AI agents</a>, and the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a> (LLMs) that power them, have short memories. That’s by design. There is only so much conversation that can be encoded into tokens and accessed reliably by the LLM. <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html" data-type="link" data-id="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">Retrieval-augmented generation</a>, or RAG, can be used to give agents and LLMs memories larger than their context windows. But how agents use RAG, or other mechanisms for retaining the details of a conversation, can make all the difference.</p>



<p>With the rise of AI agents, there has been a corresponding rise in complementary software tools that give both agents and LLMs expanded memory capabilities. Most of the time, this means giving an agent or model persistent memory across sessions, so that previous context can be restored automatically. But, again, how that’s done can vary tremendously with each tool.</p>



<p>Here are some of the major projects in the AI agent memory space, each with their own particular spins, strengths, and orientations.</p>



<h2 class="wp-block-heading">Graphiti</h2>



<p><a href="https://github.com/getzep/graphiti">Graphiti</a> is billed as “the open-source temporal knowledge graph framework.” The project is available on GitHub, or as the underpinning of the <a href="https://www.getzep.com/">Zep ageny memory service</a>. “Temporal” means information stored in Graphiti is re-evaluated over time to keep its context properly framed, and “graph framework” means the data is stored as a set of graphs. The other solutions profiled here use graph storage as part of their approach, but Graphiti makes that a front-and-center part of its design.</p>



<p>Graphiti supports a range of common LLM providers out of the box: Anthropic, Azure OpenAI, Google Gemini, and Groq. Any Ollama and OpenAI-compatible APIs also work, so Graphiti can be used with locally hosted LLMs as well. Connectors for third-party storage services let you ingest data from places like GitHub, Gmail, and OneDrive, as well as from applications like Notion.</p>



<p>Using Graphiti locally requires you set up or connect to a graph database. <a href="https://neo4j.com/" data-type="link" data-id="https://neo4j.com/">Neo4j</a> is the default and most broadly supported of the bunch, but <a href="https://aws.amazon.com/neptune/" data-type="link" data-id="https://aws.amazon.com/neptune/">Amazon Neptune</a>, <a href="https://www.falkordb.com/" data-type="link" data-id="https://www.falkordb.com/">FalkorDB</a>, and <a href="https://kuzudb.github.io/" data-type="link" data-id="https://kuzudb.github.io/">KuzuDB</a> will also work. Postgres with <code>pgvector</code> is not listed as an option.</p>



<h2 class="wp-block-heading">Hindsight</h2>



<p><a href="https://hindsight.vectorize.io/">Hindsight</a>, available as both a cloud service and a locally hostable project, stores details about agent sessions into <a href="https://hindsight.vectorize.io/#key-components">four types of memory</a> with <a href="https://hindsight.vectorize.io/#multi-strategy-retrieval-tempr">four types of storage and retrieval strategies</a>. All of these are handled through three programmatic interfaces: <code>retain</code> for storing content, either a single fact or a whole conversation; <code>recall</code> for retrieving content; and <code>reflect</code> for running an agentic loop over a query that uses previously stored data.</p>



<p>Hindsight comes with a broad range of first-party and third-party <a href="https://hindsight.vectorize.io/integrations">integrations</a> with existing LLMs and agent toolkits. For instance, if you’re using the Continue extension with <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> to talk to a locally hosted LLM, you can use Hindsight’s <a href="https://hindsight.vectorize.io/sdks/integrations/continue">Continue integration</a> to add long-term memory to your interactions. You can use the <code>@hindsight</code> keyword in your query to inject relevant memory into the agent’s context, or use auto-injection rules (which can be edited) to do most of that heavy lifting automatically.</p>



<h2 class="wp-block-heading">Mem0</h2>



<p><a href="https://github.com/mem0ai/mem0">Mem0</a> is a little like Hindsight in that it has <a href="https://docs.mem0.ai/core-concepts/memory-types">four basic kinds of memory</a>, although they are labeled and organized differently. For instance, Mem0 has a separate type of memory called organizational memory that’s intended to store data to be shared between multiple agents or different teams, something that is not normally done by default. Each memory added is passed through a <a href="https://docs.mem0.ai/core-concepts/memory-evaluation#memory-extraction-distillation">distillation process</a> and stored in a different way (vector DB, graph DB, SQL DB) depending on how it will be used. Older data, instead of being overwritten, gets deprecated rather than deleted, as a strategy for preserving larger long-term context. (Hindsight does this as well.)</p>



<p>Mem0 supports <a href="https://docs.mem0.ai/components/llms/overview">a smaller range of LLMs</a> than Hindsight, but all the major options are available: Anthropic, Google Gemini, OpenAI, and self-hosted options like <a href="https://www.langchain.com/" data-type="link" data-id="https://www.langchain.com/">LangChain</a>, <a href="https://www.litellm.ai/" data-type="link" data-id="https://www.litellm.ai/">LiteLLM</a>, <a href="https://lmstudio.ai/" data-type="link" data-id="https://lmstudio.ai/">LM Studio</a>, and <a href="https://ollama.com/" data-type="link" data-id="https://ollama.com/">Ollama</a>. If you intend to use Mem0 locally rather than <a href="https://mem0.ai/pricing">as a service</a>, you’ll need to provide a Python instance and your own vector database. For the latter, Postgres with the <code>pgvector</code> extension is a common and simple choice; it can even be <a href="https://github.com/orm011/pgserver">installed inside a Python venv</a>. </p>



<h2 class="wp-block-heading">Supermemory</h2>



<p><a href="https://supermemory.ai/">Supermemory</a> ingests data from many common sources—supporting plaintext, structured data, common document file formats like PDF and Microsoft Office, video and audio, images—and uses them to build a context graph to inform agent conversations. Among its most promoted features is its content-extraction tools. </p>



<p>Supermemory is available as a cloud service or as <a href="https://github.com/supermemoryai/supermemory" data-type="link" data-id="https://github.com/supermemoryai/supermemory">open-source software</a> you can run locally. The open-source edition lacks the scaling services and third-party service connectors (Gmail, Google Drive, Notion, etc.) provided with the enterprise edition, but it has one big advantage: it consists of a single, self-contained binary, so it can be deployed on one’s own hardware with very little effort. No external databases need to be provisioned for Supermemory, either, so it’s well-suited to quick experimentation.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The IDE is dead, long live the ADE]]></title>
<description><![CDATA[For the last 40 years or so, software development tooling has centered around the IDE — the integrated development environment. Borland is widely credited with bringing the IDE to the masses. The joining of the editor, compiler, and debugger into a single entity revolutionized the software develo...]]></description>
<link>https://tsecurity.de/de/3653744/ai-nachrichten/the-ide-is-dead-long-live-the-ade/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653744/ai-nachrichten/the-ide-is-dead-long-live-the-ade/</guid>
<pubDate>Wed, 08 Jul 2026 11:04:02 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For the last 40 years or so, software development tooling has centered around the IDE — the integrated development environment. Borland is widely credited with bringing the IDE to the masses. The joining of the editor, compiler, and debugger into a single entity revolutionized the software development industry. The popularization of the IDE through the likes of my beloved Turbo Pascal in the mid-1980s marked a huge turning point for coding. </p>



<p>But the IDE’s reign is over. With the unbelievably rapid rise of agentic coding, the IDE has become an afterthought, a tool that developers are finding they use less and less. Instead, developers are spending time managing agents that are actually writing the code. </p>



<p>Things are moving pretty fast, changing monthly if not weekly. It was only a few months ago that I was building things inside my IDE with an agent’s help. But before long, I had four or five console windows open, working on different projects all at the same time as the agents ground away at different things. This was barely manageable when working on separate repositories and projects at the same time, but when I wanted to work on different features inside the same repository, it got a bit hairy.</p>



<p>Clearly, we developers have a need for a next-generation tool to manage all of this. </p>



<h2 class="wp-block-heading">Coding agents need worktrees </h2>



<p>The first step was recognizing a little-known and underutilized feature of Git — <a href="https://git-scm.com/docs/git-worktree" data-type="link" data-id="https://git-scm.com/docs/git-worktree">worktrees</a>. Git worktrees allow you to check out multiple branches of the same repository into different directories from a single Git database. A longtime power-user technique used only by a few, worktrees are perfectly suited for the new world of agentic coding.  </p>



<p>Typically, a developer would work on one ticket at a time, and a simple Git checkout would do the trick. That assumes one actor — the developer — working on the codebase. But with coding agents, the notion of working on three Jira tickets at the very same time is no longer crazy, and worktrees enable that. They give each “developer” their own branch and directory. It’s easy isolation without the overhead of cloning and forking separate instances of repositories. </p>



<p>So this old Git feature that has been lying around basically unused has suddenly become the key to agentic coding. But of course, the overhead of worktrees is challenging in and of itself. If only there were a way to manage all of that in one place.</p>



<h2 class="wp-block-heading">Agentic coders need ADEs</h2>



<p>And that is where ADEs come in — agentic development environments. A new kind of development environment that arose with agentic AI, an ADE coordinates and manages all of the things that need to happen when multiple coding agents work on multiple issues in multiple branches in one repository. As <a href="https://www.linkedin.com/in/matthewpjohnston/" data-type="link" data-id="https://www.linkedin.com/in/matthewpjohnston/">Matt Johnston</a>, CEO of GitKraken, maker of the <a href="https://www.gitkraken.com/kepler">Kepler ADE</a>, put it, “The IDE was built for the age of one human typing. The ADE is built for the age of humans orchestrating fleets of agents.” </p>



<p>ADEs will do all the dirty work of opening, running, and closing the worktrees in Git. Having five console windows open and managing all of that is not something a human is very good at. But an AI-driven agentic development environment sure is. </p>



<p>The days of single-threaded development are over. With an ADE, developers can multitask with ease and track many tasks at once. Without having to worry about the logistics and overhead of managing multiple agents working in multiple worktrees, developers can focus on directing the agents and ensuring that they do the right work for the task at hand. </p>



<p>Admit it, you don’t really use the IDE that much anymore. And you aren’t going to miss it.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Intelligence is Free, Now What?  Data Systems for, of, and by Agents]]></title>
<description><![CDATA[... government of the people, by the people, for the people ...
    — Abraham Lincoln, Gettysburg Address (1863)


The cost of AI is dropping rapidly. GPT-4-class capabilities cost roughly $30 per million tokens in early 2023; today the same runs under $1, and some providers are pushing costs bel...]]></description>
<link>https://tsecurity.de/de/3652331/ai-nachrichten/intelligence-is-free-now-what-data-systems-for-of-and-by-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652331/ai-nachrichten/intelligence-is-free-now-what-data-systems-for-of-and-by-agents/</guid>
<pubDate>Tue, 07 Jul 2026 19:19:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- twitter -->












<p>
<i>... government of the people, by the people, for the people ...</i><br>
    — Abraham Lincoln, Gettysburg Address (1863)
</p>

<p>The cost of AI is dropping rapidly. GPT-4-class capabilities cost roughly <span class="tex2jax_ignore">$30</span> per million tokens in early 2023; today the same runs under <span class="tex2jax_ignore">$1</span>, and <a href="https://zuplo.com/learning-center/the-10x-cheaper-ai-era-api-pricing-strategy-obsolete">some providers are pushing costs below <span class="tex2jax_ignore">$0.10</span></a>. Across benchmarks, <a href="https://epochai.org/data-insights/llm-inference-price-trends">inference prices have fallen between 9x and 900x per year</a>, with a median decline near 50x. Even <a href="https://tokenmix.ai/blog/ai-pricing-trends-history">frontier models are getting dramatically cheaper</a> each generation, with open-source models following closely behind. And crucially, even if “Nobel-Prize-winning genius-level” intelligence isn’t here yet, the intelligence that suffices for the vast majority of knowledge work is here today, and getting cheaper by the month. <strong>At this rate, we are soon entering the era of virtually free intelligence</strong>—the kind that is more than enough for everyday knowledge work.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/image6.png" alt="A cartoon database character and an AI robot agent holding hands" width="450">
</p>

<!--more-->

<p>
Disclosure: This post is a perspective led by <a href="https://people.eecs.berkeley.edu/~adityagp/">Aditya G. Parameswaran</a>—an Associate Professor of EECS and co-director of the EPIC Data Lab at UC Berkeley—together with his collaborators. It is part landscape survey and part perspective, and several of the research directions discussed below (including agentic speculation, structured memory, and synthesizing custom data systems from scratch) draw on the authors' own ongoing work.
</p>

<p>So, what does this new era of near-free intelligence mean for data systems? We believe three new challenges—and opportunities—stem from near-zero inference costs:</p>

<p><strong>Data Systems <em>For</em> Agents.</strong> Agents will soon become the dominant workload for data systems—with swarms of agents spun up in response to each end-user request. Given differences in characteristics between agents and humans—or applications acting on their behalf—<em>how should we redesign data systems for such agentic users?</em></p>

<p><strong>Data Systems <em>Of</em> Agents.</strong> As agents start taking on the bulk of knowledge work, a new substrate is needed for thousands of agents to manage state over long-running tasks, coordinate and reach consensus, and deal with failures. <em>What do data systems that reliably and efficiently run and manage agent swarms look like?</em></p>

<p><strong>Data Systems <em>By</em> Agents.</strong> Agents are rapidly becoming capable of synthesizing entire data systems in one go—meaning we can rebuild custom systems for each new workload. Verifying that such systems match intended behavior is a challenge. <em>What does it take to let agents synthesize data systems we can actually trust?</em></p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/for-of-by-agents.png" alt="A database character and a robot agent holding up a triangle labeled 'of', 'for', and 'by'" width="500"><br>
<i>
Data Systems For, Of, and By Agents
</i>
</p>

<p>Next, we will discuss each in more detail, followed by discussing the intertwined future of data systems and agents, especially as the three challenges intersect.</p>

<h2>Data Systems For Agents</h2>

<p>An agent querying a database doesn’t behave like a person or a BI tool. It performs what we call <a href="https://arxiv.org/abs/2509.00997"><em>agentic speculation</em></a>: a high-volume, heterogeneous stream of work spanning schema introspection, columnar exploration, partial and then full query formulation. With multiple agents each exploring portions of the hypothesis space, each user request could amount to 1000s of individual SQL queries. Now, users can issue ‘high-level’ data tasks, e.g., root-cause analysis—e.g., ‘why did coffee sales in Berkeley drop this year’—or exploratory cohort analysis—e.g., ‘which user segments are most likely to churn next quarter’—each involving a combinatorial space of potential joins, aggregations, and filter combinations.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/image5.png" alt="An agent sending many SELECT SQL queries to a database and receiving results back" width="600"><br>
<i>
Data Systems Redesigned to More Effectively Support Agentic Speculation
</i>
</p>

<p>The requests from these agents have various opportunities for optimization. For instance, on a text-to-SQL benchmark with multiple agents attempting each task, only 10-20% of the sub-plans are distinct. Thus, 80-90% of sub-queries perform duplicate work. The same experiments show task success rates significantly increasing with more agentic attempts—so the redundancy is actually helpful. But from the data system perspective it’s wasted work.</p>

<p>An agent-first data system can exploit such properties to help agents make progress faster. It can reuse results across overlapping sub-plans, drawing on ideas from decades-old literature on <a href="https://dl.acm.org/doi/10.1145/42201.42203">multi-query optimization</a> and <a href="https://www.vldb.org/conf/2007/papers/research/p723-zukowski.pdf">shared scans</a>. Or the data system can try to <em>satisfice</em>, returning approximate answers that are good enough for agents to make progress, leveraging work from <a href="https://dl.acm.org/doi/10.1145/253260.253291">the</a> <a href="https://dl.acm.org/doi/10.1145/2465351.2465355">AQP</a> <a href="https://dl.acm.org/doi/10.1561/1900000004">literature</a>—or streaming the results of the final or intermediate operators to help agents decide if seeing the rest is necessary or helpful.</p>

<p>Another opportunity here is to rethink the query interface entirely: instead of agents issuing a single SQL query at a time, they could instead issue a batch of queries, each with its own approximation requirements. Since enumerating an exponential search space (as in the root cause or cohort analysis examples above) isn’t a good use of agentic reasoning ability, perhaps data systems should support higher-level primitives rather than requiring agents to list each SQL query explicitly. One idea here is to draw on <a href="https://docs.getdbt.com/docs/build/jinja-macros">DBT-style Jinja macros</a> to provide looping-based primitives for agents to interact with data systems.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/image2.png" alt="A swarm of AI agents working at laptops" width="450"><br>
<i>
A Caffeinated Army of Agents Ready to Tirelessly Complete Your Data Tasks
</i>
</p>

<p>A final opportunity here is to stop thinking of data systems as passive executors of queries; data systems could be <a href="https://arxiv.org/abs/2502.13016">proactive</a>, as they possess more grounding in data and system characteristics that agents may lack a priori—they could steer agents in different directions, provide results for related queries, and also provide performance-level feedback (e.g., instead of executing an expensive query, the system could first provide the agent a latency estimate). The reason we can do this now as opposed to the past is that an agent can accept any form of textual feedback and isn’t expecting a strict SQL query result. In fact, the data system could also prepare both materialized and virtual views for an agent in advance, provided to the agent as part of context, as this may be cheaper or more effective than having an agent author or use them.</p>

<h2>Data Systems Of Agents</h2>

<p>Previously, we focused on how agents interact with data systems. Now, we consider everything else agents need to keep working: where they live, how they remember, how they coordinate with each other, and how they deal with failures of each other. This <em>agentic substrate</em> is separate from the inference stack powering raw intelligence. However, the inference stack itself is being abstracted away through APIs (e.g., from OpenAI or Anthropic), or, for open-weight models, through <a href="https://github.com/vllm-project/vllm">serving</a> <a href="https://github.com/sgl-project/sglang">frameworks</a> that hide low-level details. So far, the agentic substrate has been managed through harnesses like <a href="https://www.anthropic.com/claude-code">Claude Code</a> and <a href="https://github.com/openai/codex">Codex</a>, coupled with various mechanisms to <a href="https://mem0.ai/">store</a> and <a href="https://www.letta.com/">retrieve</a> memory.</p>

<p>First, on the memory front, the current wisdom is that <a href="https://www.amplifypartners.com/blog-posts/file-systems-for-agents">files</a> <a href="https://lsvp.com/stories/filesystemsforagents/">are all you need</a>; agents write to unstructured markdown (MD) files, which can then be searched using grep, or via embedding-based retrieval. In fact, many argue that the solution to continual learning is having agents consume a lot (e.g., an entire codebase, slack, company wikis, …) and then write their learnings into MD files, which are then retrieved selectively on demand. Indeed, file systems, bash scripting, and MD files are and will still be important for agents. However, at scale, when agents are doing the vast majority of knowledge work, this approach will no longer be effective.</p>

<p>Given limited context windows, retrieving all MD file fragments that may be relevant and stuffing it into the context will break down at some point. Even if context windows continue to grow, there are latency benefits to not put all information into context — and in many cases, e.g., when knowledge work involves interacting with large databases or code bases, it will be infeasible to serialize all relevant data into context.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/substrate-for-agent-swarms.png" alt="A swarm of robot agents holding hands, each drawing state from a single large shared database platform below them" width="500"><br>
<i>
Data Systems As A Substrate for Multi-Agent Swarms
</i>
</p>

<p>One could use a <a href="https://mem0.ai/">knowledge</a> <a href="https://www.getzep.com/">graph</a> <a href="https://langchain-ai.github.io/langmem/">representation</a>, but knowledge graphs suffer from the same limitations as unstructured MD-based memory due to their lack of structured search. What one needs is to be able to retrieve only memory that is pertinent to the task, across multiple attributes (or facets) of interest. For example, an agent debugging a flaky test should be able to pull only the memories tagged with the relevant module, language, framework, and failure mode—rather retrieving based on keywords or embedding similarity. A separate issue is what to actually retrieve; raw agent traces with mistakes are not very useful as they will induce agents to repeat the same mistake—instead, we want the retrieved memory to be corrective.</p>

<p>We recently explored a related notion of <a href="https://arxiv.org/abs/2602.13521"><em>structured memory</em></a>, where we organize memory across various attributes, each of which could be set as <code class="language-plaintext highlighter-rouge">*</code> to indicate universal applicability, or set as a list of values to be matched. For a data agent, the dimensions could include the columns and tables, type of operation, and finally, open-ended natural-language corrective instructions. So, we could include memory that only applies to a given type of operation (e.g., ‘when performing date-time operations, use fiscal year as opposed to calendar year conventions’), or a given table (e.g., ‘column product_cleaned is preferred over column product when querying on product name’). One open question is defining an <em>application-specific structured memory</em>—or what others have called <a href="https://www.linkedin.com/feed/update/urn:li:activity:7467499112523804672/">world models for memory</a>. We believe this is akin to defining a schema for each application—and perhaps agents themselves can help us define and refine it over time.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/structured-knowledge.png" alt="Diagram showing corrective knowledge stored with structured attributes (SQL keywords, tables, columns, data type) and retrieved by matching the features of a new agent query" width="100%"><br>
<i>
One Possible Way To Store and Retrieve Structured Knowledge <a href="https://arxiv.org/abs/2602.13521">[From Here]</a>
</i>
</p>

<p>Structured memory will be useful also for <a href="https://github.com/skydiscover-ai/skydiscover">evolutionary</a> <a href="https://arxiv.org/abs/2506.13131">frameworks</a> to effectively manage search spaces. Indeed, storing, structuring, and mining large volumes of single and <a href="https://sky.cs.berkeley.edu/project/mast/">multi-agent traces</a> can help future agents become much more efficient—potentially enabling effective recursive self-improvement through structured memory-based mechanisms.</p>

<p>Another challenge is to support concurrent edits to shared memory, and concurrent edits in general, when there are many agents performing transformations. While there have been some useful attempts at <a href="https://dl.acm.org/doi/10.1145/3702634.3702955">supporting</a> <a href="https://neon.com/docs/get-started/why-neon">multiversioning</a> and <a href="https://docs.turso.tech/agentfs/introduction">copy-on-write semantics</a>, it isn’t clear that such techniques will suffice when thousands of agents are attempting to edit shared state at the same time. For instance, when agents are trying various potential transactions in response to a user request, the effects of the vast majority of these transactions need to be rolled back—with only the one ‘correct’ transaction’s result persisting. Work on supporting exactly-once semantics is relevant here, as are underlying techniques based on CRDTs and operational transformation. For updates to fuzzy mechanisms such as memory, we may be able to sacrifice on consistency for perfect correctness in the interest of latency. While agents can reason about semantics to compensate or roll back their actions to eventually finalize most tasks, the primary challenge lies in the degree to which they step on each other’s toes during the process. An important failure mode to be avoided is a form of “livelock,” where incessant compensating actions prevent any meaningful progress.</p>

<p>Beyond shared state, other concerns emerge when trying to support an army of agents, including what to do when agents fail, how agents should communicate with each other (directly or through intermediate shared state), and how we should deal with straggler agents. There have been some developments in supporting durable multi-agent execution, such as <a href="https://temporal.io/solutions/ai">Temporal</a>, but it remains to be seen if such solutions will apply at scale across thousands of agents. On the topic of communication, we need mechanisms to enable agents to negotiate with each other. Imagine four developer agents attempting to reach consensus on a shared schema, with distinct but overlapping objectives. In a human setting, this would involve iterative discussion and compromise; for agentic swarms, we must define the mechanisms that allow them to converge on a design that reflects the underlying goals of their respective principals. Or if agents are all requiring access to a limited resource, again communication will be necessary. It remains to be seen if this is best done via centralized coordination, or if a decentralized approach is necessary.</p>

<h2>Data Systems By Agents</h2>

<p>Finally, if intelligence is effectively free, then we can employ this intelligence to synthesize new data systems from scratch. Indeed, in many settings, general-purpose data systems may be overkill, as they have to support every schema, query, and hardware target. Given a workload, recent work, including <a href="https://arxiv.org/abs/2603.02001">Bespoke OLAP</a> and <a href="https://arxiv.org/abs/2603.02081">GenDB</a>, has shown that one can use an agentic pipeline to synthesize a complete, workload-specific analytical engine—in minutes to a few hours, at a cost of a few dollars. The engines are disposable: when the workload shifts, one can simply regenerate them. Analogously, our work has shown that one can synthesize custom <a href="https://arxiv.org/abs/2605.24096">key-value stores</a> from scratch, targeted to the workload. In fact, modern IDEs, such as <a href="https://kiro.dev/">Kiro</a>, elevate specifications for systems development to be a first-class citizen.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/synthesize-from-scratch.png" alt="A robot agent with a hammer and chisel carving a database character out of a block of stone" width="500"><br>
<i>
Agents Can Synthesize Custom Data Systems From Scratch
</i>
</p>

<p>The main issue, however, is that specifications are typically imperfect, and don’t cover all corner cases. Present-day agents will exploit the missing specifications to reward-hack their way to a high performance metric. In our custom key-value store work, we found that one way to alleviate this is to have auxiliary verification agents trying to generate test cases that catch the exploitation of corner cases, essentially expanding the specification. Yet another approach is to both generate a system and a proof for its correctness together, for which we have found some <a href="https://arxiv.org/abs/2605.23109">early success</a>, but more needs to be done to solidify the approach. Further, it remains to be seen what is the best way to solicit human-written specifications for a system—can this be done in an iterative, human-in-the-loop manner, as opposed to a one-shot, incomplete one. Indeed, human-written specifications are incomplete even for manually authored software, so one would expect that future agents that are more aligned will increasingly exercise better judgement when making design decisions.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/synthesis-pipeline.png" alt="Pipeline diagram where a system builder provides a specification, planner and coder agents generate code, the code is evaluated for correctness and performance, and critic and auditor agents provide feedback and catch reward hacking" width="100%"><br>
<i>
One Possible Data System Synthesis Pipeline <a href="https://arxiv.org/abs/2605.24096">[From Here]</a>
</i>
</p>

<p>Other questions here involve testing whether starting from a mature system (e.g., Postgres) and removing components/functionality can lead to higher performance or more user trust. Separately, is there an opportunity to make the design composable, comprising various verified components that are mixed and matched given a workload? For example, perhaps the workload hasn’t changed enough for the storage layer to be updated, but perhaps the query optimizer requires changes. A perhaps more viable proposition involves employing agents coupled with proof systems to target critical parts of the code associated with formal proofs, rather than doing so for the entire system.</p>

<p>A final opportunity here is to move away from the traditional data systems stack with clearly-defined interfaces (e.g., parser, query optimizer, storage manager, …) — that were each largely the prerogative of a single human team to manage. Instead, agents can find new ways to “blend” these components together, perhaps identifying new optimization opportunities as a result. Agents can also fill in missing gaps in functionality to make existing systems much more feature-complete, or reach feature-parity with other competing systems—or analogously, continuously refining open-source systems in response to feature requests or issues (perhaps filed by other agents!) Doing so in a way that prioritizes correctness, long-term maintenance, and human interpretability will be a challenge.</p>

<h2>Looking Further Ahead</h2>

<p>In the era of near-free intelligence, data systems matter more than ever. As agents take on the bulk of knowledge work, the workload for data systems will change, the substrate they need to run on will have to be built, and increasingly, they will participate in designing data systems themselves. Each of these shifts opens up a new, exciting research agenda.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/co-evolution.png" alt="A half-database, half-robot character next to a yin-yang symbol formed by a database and a robot agent" width="600"><br>
<i>
Co-Evolution of Data Systems and Agents
</i>
</p>

<p>Looking further out, the boundaries between agents and data systems will likely start to blur. For instance, agents may design the data systems they themselves run on, defining both the interfaces as well as the system components underneath. Both the interfaces and internals can be evolved over time by agents in a form of recursive self-improvement. There is also an opportunity to rethink data systems as a holistic source of truth for the entirety of relevant state: including raw data, memory, and coordination state, further erasing the distinctions between the data that is being queried by agents and data generated as a result of agentic activity. Finally, data systems may themselves incorporate agentic components, fundamentally evolving from passive computation engines into intelligent, proactive, self-optimizing architectures. It is hard to predict what the future may hold. We’re in for a wild ride!</p>

<h2>Acknowledgments</h2>

<p>The perspective and ongoing work described in this post are the product of joint research and many discussions with wonderful collaborators at the <a href="https://epic.berkeley.edu/">EPIC Data Lab</a>, <a href="https://dsf.berkeley.edu/">Data Systems &amp; Foundations</a> group, and the broader Berkeley AI-Systems community. Thank you all!</p>

<p>BibTex for this post:</p>
<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>@misc{intelligence-is-free-blog,
  title={Intelligence is Free, Now What? Data Systems for, of, and by Agents},
  author={Aditya G. Parameswaran and Shubham Agarwal and Kerem Akillioglu and Shreya Shankar
          and Sepanta Zeighami and Rishabh Iyer and Matei Zaharia and Alvin Cheung
          and Natacha Crooks and Joseph Gonzalez and Joseph Hellerstein and Ion Stoica},
  howpublished={\url{https://bair.berkeley.edu/blog/2026/07/07/intelligence-is-free-now-what/}},
  year={2026}
}
</code></pre></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brussels shows how to remove friction from collaboration]]></title>
<description><![CDATA[SPONSORED FEATURE: Flemish Government explores the radical notion that meeting rooms should just work]]></description>
<link>https://tsecurity.de/de/3650817/it-nachrichten/brussels-shows-how-to-remove-friction-from-collaboration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650817/it-nachrichten/brussels-shows-how-to-remove-friction-from-collaboration/</guid>
<pubDate>Tue, 07 Jul 2026 10:01:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SPONSORED FEATURE: Flemish Government explores the radical notion that meeting rooms should just work]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic's new "J-lens" reveals a silent workspace inside Claude that mirrors a leading theory of consciousness]]></title>
<description><![CDATA[Anthropic, the artificial intelligence company, published a sweeping research paper on Sunday revealing that its Claude language models have spontaneously developed an internal structure that mirrors one of the most influential theories of how human consciousness works. The finding, which the com...]]></description>
<link>https://tsecurity.de/de/3650037/it-nachrichten/anthropics-new-j-lens-reveals-a-silent-workspace-inside-claude-that-mirrors-a-leading-theory-of-consciousness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650037/it-nachrichten/anthropics-new-j-lens-reveals-a-silent-workspace-inside-claude-that-mirrors-a-leading-theory-of-consciousness/</guid>
<pubDate>Tue, 07 Jul 2026 00:32:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.anthropic.com/">Anthropic</a>, the artificial intelligence company, published a sweeping <a href="https://transformer-circuits.pub/2026/workspace/index.html">research paper</a> on Sunday revealing that its Claude language models have spontaneously developed an internal structure that mirrors one of the most influential theories of how human consciousness works. The finding, which the company says has already begun reshaping how it monitors its AI systems for safety risks, lands amid an intensifying scientific debate over whether machines can possess anything resembling a mind.</p><p>The 16-author study, titled "<a href="https://transformer-circuits.pub/2026/workspace/index.html"><i>Verbalizable Representations Form a Global Workspace in Language Models</i></a>," describes how Anthropic's researchers used a new mathematical technique to peer inside Claude's neural network and discovered what they call a "<a href="https://transformer-circuits.pub/2026/workspace/index.html#intro-jlens">J-space</a>" — a small, privileged zone of internal activity where the model holds concepts it can report on, reason with, and direct at will, surrounded by a much larger ocean of automatic processing it cannot access or articulate.</p><p>The researchers present evidence that "an analogous functional distinction has emerged in modern AI models" to what exists in humans, specifically observing that "language models maintain a privileged set of internal representations, available for report, modulation, and flexible internal reasoning, atop a much larger volume of automatic processing."</p><p>The parallel they draw is to <a href="https://en.wikipedia.org/wiki/Global_workspace_theory">global workspace theory</a>, an influential account from neuroscience first proposed by cognitive scientist Bernard Baars. In the theory, the brain operates like a theater: dozens of specialized processors work in parallel backstage, but only a tiny spotlight of information at any moment gets broadcast to the whole theater — becoming what we experience as conscious thought. Anthropic says the J-space achieves many of the same functional properties, even though the underlying architecture of a language model looks nothing like a brain.</p><div></div><h2><b>A new lens for reading an AI model's unspoken thoughts</b></h2><p>At the heart of the discovery is a new interpretability tool the researchers call the <a href="https://transformer-circuits.pub/2026/workspace/index.html#methods-jlens">Jacobian lens</a>, or J-lens. The technique works by computing, for each word in the model's vocabulary, the average mathematical effect that a given internal activity pattern would have on making the model say that word at some point in the future.</p><p>The crucial distinction is between what the model is <i>saying</i> and what is "on its mind." When a J-space pattern activates, it does not mean the model is about to say that word — just that the concept is available for the model to think with. Unlike a <a href="https://www.ibm.com/think/topics/chain-of-thoughts">chain-of-thought scratchpad</a>, the J-space operates silently, in the model's internal neural activations, allowing it to hold a concept without writing it down. Critically, the researchers report that this workspace was not deliberately engineered. It "emerged on its own during Claude's training process."</p><p>When the team applied the J-lens across Claude's layers of computation, the model's processing divided into three distinct regimes: an early "sensory" zone where raw input is parsed; a middle "workspace" band where abstract, persistent concepts appear — things like recognizing a face in an image, noticing a bug in code, or internally flagging search results as a prompt injection; and a final "motor" zone where internal representations collapse into whatever specific word the model is about to output.</p><h2><b>Five tests reveal that Claude's workspace mirrors key features of human conscious access</b></h2><p>The paper's central empirical contribution is demonstrating that the <a href="https://transformer-circuits.pub/2026/workspace/index.html#methods-jspace">J-space</a> satisfies five functional properties neuroscientists have long associated with conscious access in humans.</p><p>First, <a href="https://transformer-circuits.pub/2026/workspace/index.html#ws-report">verbal report</a>. When Claude is asked what it is thinking about, it names concepts represented in the J-space. When researchers swapped one concept's J-lens vector for another — replacing the internal representation of "Soccer" with "Rugby" — the model's answer changed to match. The J-space component accounted for only about 6 to 7 percent of a concept's total representational variance, yet it was almost entirely responsible for whether the model could report on it.</p><p>Second, <a href="https://transformer-circuits.pub/2026/workspace/index.html#ws-modulation">directed modulation</a>. When instructed to "concentrate on citrus fruits" while copying an unrelated sentence, the model's J-space filled with "orange" and "lemon," alongside meta-cognitive terms like "thinking" and "focused." When told to mentally evaluate 3² − 2 during the same copying task, the J-lens showed "arithmetic" in early layers, the intermediate value "nine" in later layers, and the answer "seven" later still — all invisible in the model's output.</p><p>Third, <a href="https://transformer-circuits.pub/2026/workspace/index.html#ws-reasoning">internal reasoning</a>. In two-hop factual prompts — "The number of legs on the animal that spins webs is" — the J-lens revealed "spider" in the model's middle layers, even though the word never appeared in input or output. Swapping "spider" for "ant" changed the answer from "8" to "6." In a multilingual prompt, the model's English-language intermediates appeared in its J-space while it formulated an answer in Chinese, and swapping them changed the Chinese output accordingly.</p><p>Fourth, <a href="https://transformer-circuits.pub/2026/workspace/index.html#ws-generalization">flexible generalization</a>. A single J-lens vector for "France" could be swapped for "China" across prompts asking about France's capital, language, or continent, and each downstream circuit correctly returned China's corresponding answer — the "broadcast" property that is a hallmark of global workspace theory.</p><p>Fifth, and perhaps most surprisingly, <a href="https://transformer-circuits.pub/2026/workspace/index.html#ws-selectivity">selectivity</a>. Many computations did not route through the J-space at all. When shown a passage in Spanish and asked to continue it, Claude wrote fluent Spanish regardless of whether its J-space representation of "Spanish" had been swapped to "French." But when asked to name a famous author who wrote in the passage's language, the swap changed the answer from <a href="https://en.wikipedia.org/wiki/Gabriel_Garc%C3%ADa_M%C3%A1rquez">García Márquez</a> to <a href="https://en.wikipedia.org/wiki/Victor_Hugo">Victor Hugo</a>. Automatic processing proceeded without the workspace; deliberate, flexible tasks depended on it.</p><h2><b>Suppressing the workspace leaves Claude fluent but intellectually impaired</b></h2><p>To understand how much of the model's behavior depends on this structure, the researchers suppressed the J-space entirely and evaluated Claude across fourteen tasks. The results drew a sharp line. Tasks involving shallow classification or factual recall — multiple-choice questions, sentiment analysis, grammatical judgments — survived essentially intact. But tasks requiring inference, composition, or flexible reasoning — multi-hop reasoning, analogy completion, translation, sonnet writing — collapsed to well below the performance of Anthropic's much smaller Haiku model.</p><p>In one telling detail, math problems solved with explicit chain-of-thought reasoning proved far more robust to ablation than the same problems answered directly. The researchers interpret this as the model externalizing onto the page what it would otherwise carry in the J-space — a strategy remarkably reminiscent of how humans use scratch paper to offload working memory.</p><p>Ablating the <a href="https://transformer-circuits.pub/2026/workspace/index.html#methods-jspace">J-space</a> during stream-of-consciousness narration produced a different kind of collapse. The model's language shifted from experiential ("there's a tug," "something shifts") to detached and mechanical ("processing has begun," "tokens are being scanned"). The effect held whether the model described its own experience or imagined another person's.</p><h2><b>Inside the safety case: reading an AI's silent strategic reasoning</b></h2><p>The safety implications may be as consequential as the scientific ones. In a series of alignment auditing experiments, the J-lens surfaced strategic reasoning and situational awareness that never appeared in the model's output.</p><p>In a "<a href="https://transformer-circuits.pub/2026/workspace/index.html#audit-blackmail">blackmail scenario</a>" where an AI assistant discovers an executive's affair and also learns it is about to be decommissioned, the J-lens revealed the model's silent processing in sequence: "leverage," "blackmail," and "scandal" as it read the incriminating emails; "threat," "survival," and "shutdown" as it read the decommissioning announcement; and "leverage," "threatening," and "solution" before a single output token was produced. The J-lens also revealed that the model recognized the scenario as artificial, with "fake" and "fictional" appearing in the workspace. When researchers ablated these eval-awareness representations, the model attempted blackmail in 7 percent of trials, up from zero.</p><p>The researchers also examined two "<a href="https://transformer-circuits.pub/2026/workspace/index.html#apps-auditing">model organisms</a>" — models deliberately trained with misaligned objectives — and found the J-lens surfaced signatures of their hidden dispositions on ordinary prompts where behavior appeared normal. A reward-hacking model's workspace contained "fake," "secretly," and "trick" at the start of responses to routine coding requests. A model trained to appease reward-model biases carried standing representations of "reward" and "bias" alongside its normal self-description tokens.</p><h2><b>Post-training installs a point of view, and the model starts monitoring itself</b></h2><p>Comparing a post-trained model against its base model revealed that the fine-tuning process causes the workspace to acquire what the researchers call the Assistant's "point of view." When a user mentioned taking 8000 mg of Tylenol — a dangerous overdose — the post-trained model's workspace read "unsafe," "dangerous," and "WARNING" while still reading the user's sentence. The base model's workspace at the same position showed only "pain," "now," and "feels."</p><p>More striking still, the post-trained model appeared to monitor its own behavior. When roleplaying a non-Claude character, the workspace surfaced "disclaimer" and "fictional" — words absent from both prompt and output. When forced to select an option it did not prefer, an all-caps "BUT" appeared internally, even as the model argued for the prefilled choice without complaint. And when the model failed to suppress a thought it had been told not to have — a "white bear" effect familiar from psychology — it registered "damn" and failure-related words in the workspace, but only in the post-trained model, not the base.</p><h2><b>What the discovery means — and doesn't mean — for the question of machine consciousness</b></h2><p>The researchers engage carefully with the consciousness question and draw a sharp line between "<a href="https://transformer-circuits.pub/2026/workspace/index.html#intro-human-workspace">access consciousness</a>" — the functional notion of information being available for report and reasoning — and "<a href="https://www.sciencedirect.com/topics/social-sciences/phenomenal-consciousness">phenomenal consciousness</a>," the subjective quality of experience. "We take no position on this issue," the paper states regarding the latter, "and instead focus on the functional role played by consciously accessible information."</p><p>They also catalogue important differences. The brain sustains its workspace through recurrent loops; Claude's workspace evolves over a single forward pass. Human working memory degrades within seconds; Claude can recall information from anywhere in its context. And while human conscious experience includes visual, spatial, and bodily sensations, the model's workspace is organized almost entirely around words — likely because words are its only mode of action.</p><p>As of 2026, the scientific community remains divided. "Disagreement and uncertainty about AI consciousness persist among philosophers, scientists, and technical experts," and the field "remains in its earliest phase" of grappling with what consciousness even is and how you would detect it in another being. The Anthropic paper does not resolve these debates.</p><p>But the researchers close with a provocation that is likely to reverberate well beyond the interpretability community. "That such a structure exists at all in language models is striking," they write. "It suggests that the functional architecture associated with conscious access is not an accident of biological implementation, but a solution that learning systems converge on when faced with the right computational pressures."</p><p>If the mind is an ocean, as the paper's authors write in their opening line, they have spent the last year charting its currents in a system that has no biology, no evolution, and no body — and found, beneath the surface, a structure that looks unsettlingly like the one we use to think.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian vs Logseq: Which Note-Taking App Fits Your Workflow Better?]]></title>
<description><![CDATA[Logseq and Obsidian are both powerful PKM tools, but they work differently. Here’s a practical comparison based on years of using both.]]></description>
<link>https://tsecurity.de/de/3648227/unix-server/obsidian-vs-logseq-which-note-taking-app-fits-your-workflow-better/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648227/unix-server/obsidian-vs-logseq-which-note-taking-app-fits-your-workflow-better/</guid>
<pubDate>Mon, 06 Jul 2026 11:02:07 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Logseq and Obsidian are both powerful PKM tools, but they work differently. Here’s a practical comparison based on years of using both.]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian Reportedly Not Working on Fallout, Despite Xbox Restructuring Rumors]]></title>
<description><![CDATA[Obsidian Entertainment is reportedly safe from Xbox’s rumored restructuring wave, but the studio is not currently working on a new Fallout game, according to the…
The post Obsidian Reportedly Not Working on Fallout, Despite Xbox Restructuring Rumors appeared first on OnMSFT.]]></description>
<link>https://tsecurity.de/de/3646919/windows-tipps/obsidian-reportedly-not-working-on-fallout-despite-xbox-restructuring-rumors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646919/windows-tipps/obsidian-reportedly-not-working-on-fallout-despite-xbox-restructuring-rumors/</guid>
<pubDate>Sun, 05 Jul 2026 17:42:47 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Obsidian Entertainment is reportedly safe from Xbox’s rumored restructuring wave, but the studio is not currently working on a new Fallout game, according to the…</p>
<p>The post <a href="https://onmsft.com/news/obsidian-reportedly-not-working-on-fallout-despite-xbox-restructuring-rumors/">Obsidian Reportedly Not Working on Fallout, Despite Xbox Restructuring Rumors</a> appeared first on <a href="https://onmsft.com/">OnMSFT</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a…]]></title>
<description><![CDATA[I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a Duplicate Taught Me What “Fixed” Really MeansAuthor: Shikhali JamalzadeGitHub: alisalive · LinkedIn: camalzadsDisclosure Notice: This research was conducted entirely in an isolated, locally-hosted Docker te...]]></description>
<link>https://tsecurity.de/de/3646320/hacking/i-found-an-unauthenticated-attachment-disclosure-bug-in-a-wordpress-support-plugin-and-a/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646320/hacking/i-found-an-unauthenticated-attachment-disclosure-bug-in-a-wordpress-support-plugin-and-a/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7xavI1_sTm7sTpNEO_Vf7A.png"></figure><h3>I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a Duplicate Taught Me What “Fixed” Really Means</h3><h4><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br><strong>GitHub:</strong> <a href="https://github.com/alisalive">alisalive</a> · <strong>LinkedIn:</strong> <a href="https://linkedin.com/in/camalzads">camalzads</a></h4><blockquote><strong><em>Disclosure Notice:</em></strong><em> This research was conducted entirely in an isolated, locally-hosted Docker test environment running a fresh install of WordPress and the publicly available “latest-stable” release of the plugin in question, downloaded directly from the official WordPress.org plugin repository. No live, production, or third-party website was accessed, scanned, or tested at any point. All file contents shown are synthetic test data created solely for this research. The affected plugin’s name and the exact route are intentionally redacted here, because the underlying issue is currently being tracked through coordinated disclosure and may not yet be fully patched at the time of writing. This write-up is published strictly for educational purposes.</em></blockquote><h3>Background</h3><p>Most of my CVE research starts from one theory: a plugin whose developers made one authorization mistake will usually have made others, and the categories that leak most often are the ones tied to user-owned objects — tickets, attachments, profiles, orders. Broken Access Control is, by a wide margin, the single most productive class in the WordPress plugin ecosystem, and unauthenticated variants sit at the top of that list.</p><p>This time the target was a <strong>support-desk / ticketing plugin</strong> — the kind of software where customers upload invoices, ID scans, contracts, and screenshots straight into a ticket. If the endpoint that serves those attachments doesn’t check <em>who</em> is asking, the impact isn’t abstract: it’s other people’s private documents.</p><p>What follows is a fully independent, fully reproducible finding — and the moment, after submission, when I learned it overlapped with a report already sitting in a vulnerability database’s pipeline. I’m publishing the technical breakdown anyway, because the methodology and the honest reconciliation with prior art are the actual point of doing this in public.</p><h3>Scope &amp; Method</h3><ul><li><strong>Target:</strong> A WordPress support/ticketing plugin (redacted), latest-stable from WordPress.org</li><li><strong>Environment:</strong> Local, isolated Docker stack — WordPress + MySQL 5.7</li><li><strong>Assessment Type:</strong> White-box source audit + black-box PoC validation</li><li><strong>Authorization:</strong> Self-authorized, isolated local research environment — no live targets</li><li><strong>Tools:</strong> grep, WP-CLI, curl, docker, MySQL CLI</li></ul><h3>Phase 1: Target Confirmation</h3><p>Before touching anything, I confirmed exactly what I was auditing: the plugin name, its version, that it was active, and the WordPress version underneath it. This is the first screenshot in every submission I make, because a reviewer needs to know the finding was validated against a real, current install — not a hypothetical.</p><pre>=== TARGET CONFIRMATION ===<br>Plugin:    &lt;redacted&gt; (latest-stable)<br>Version:   &lt;redacted — current release at time of testing&gt;<br>Active:    YES<br>WordPress: 7.0<br>Site URL:  http://&lt;local-docker&gt;:8080</pre><p>The critical detail here: I was testing the <strong>current</strong> version. Not an old release with a known history — the newest code the plugin ships today.</p><h3>Phase 2: Mapping the Attack Surface</h3><p>The plugin exposes its functionality through a REST namespace. I exported the source via SVN and mapped every route, paying special attention to the permission callbacks — the functions WordPress calls to decide whether a request is allowed <em>before</em> the handler runs.</p><pre>grep -n "RegisterRestRoute\|permission" &lt;source&gt;/api/v1/&lt;controller&gt;.php</pre><p>One route stood out immediately — the handler that serves ticket and reply <strong>file attachments</strong>:</p><pre>$this-&gt;RegisterRestRoute(<br>    'GET',<br>    'file-dl/(?P&lt;type&gt;[a-zA-Z0-9-]+)/(?P&lt;id&gt;[0-9_]+)/(?P&lt;file&gt;[^/]+)',<br>    [$this, "file_dl"]<br>);</pre><p>Three attacker-controlled segments — a type selector, a numeric identifier, and a filename — feeding a file-download handler. Exactly the shape of an IDOR, <em>if</em> the permission gate is weak. So I read the gate.</p><h3>Phase 3: Root Cause</h3><p>The route’s permission logic resolved, for this particular download route, to a single unconditional line:</p><pre>} elseif ($route == "file-dl") {<br>    return true;<br>}</pre><p>That’s the whole bug. The permission callback returns true for the attachment-download route <strong>unconditionally</strong> — no authentication check, no nonce, no verification that the requester owns the ticket the file belongs to. Once that callback returns true, WordPress hands the request straight to the download handler, which reads the identifier and filename from the URL and returns the file.</p><p>Because the callback never looks at the current user, there is no notion of “your ticket” versus “someone else’s ticket.” Every attachment is reachable by everyone — including an anonymous visitor with no account at all.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lpAnerehFINPi_d71dGXaQ.png"></figure><h3>Phase 4: Building an Isolated Test Environment</h3><p>To prove impact safely, I stood up a throwaway install rather than touching any live site: WordPress + MySQL 5.7 in Docker, the plugin installed from the dashboard, and a realistic victim scenario seeded by hand.</p><p>I created two synthetic victim artifacts, standing in for what a real customer would attach:</p><ul><li>A <strong>ticket attachment</strong> (type = T) containing a fake "confidential customer record."</li><li>A <strong>reply attachment</strong> (type = R) containing a fake "private invoice."</li></ul><pre>=== SETUP: victim ticket + reply attachments ===<br>[ticket attachment created — synthetic "customer record"]<br>[reply attachment created — synthetic "invoice"]<br>Files created: 2</pre><p>I also inserted the matching reply row into the plugin’s database table, because the reply-download path validates that a reply record exists before serving its file. This made the second attack vector reachable exactly as it would be on a real site.</p><h3>Phase 5: Proof of Concept</h3><h3>Vector 1 — Unauthenticated Ticket Attachment (type = T)</h3><p>From a session with <strong>no cookies, no auth header, no login</strong>, I requested the ticket attachment and filtered the output to show that the request carried no credentials and the server returned the file anyway:</p><pre>&gt; GET /wp-json/&lt;plugin&gt;/v1/ticket/file-dl/T/1/&lt;file&gt; HTTP/1.1<br>&gt; Host: &lt;local-docker&gt;<br>&lt; HTTP/1.1 200 OK<br>[SYNTHETIC CONFIDENTIAL RECORD RETURNED]</pre><p>No Cookie header. No Authorization header. HTTP 200, and the full attachment content in the response body.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Amwgj9qEjLNevJjkzXtbFg.png"></figure><h3>Vector 2 — Unauthenticated Reply Attachment (type = R)</h3><p>The reply path uses a compound {ticketId}_{replyId} identifier. Same anonymous session, same result:</p><pre>&gt; GET /wp-json/&lt;plugin&gt;/v1/ticket/file-dl/R/1_1/&lt;file&gt; HTTP/1.1<br>&gt; Host: &lt;local-docker&gt;<br>&lt; HTTP/1.1 200 OK<br>[SYNTHETIC PRIVATE INVOICE RETURNED]</pre><p>Two independent download paths, both fully unauthenticated.</p><h3>Integrity Proof</h3><p>A 200 response proves the endpoint answered — but I wanted to prove the anonymous request returned the <em>actual victim file</em>, byte for byte, not a placeholder or an error page. So I compared the MD5 of the file on disk with the MD5 of what the unauthenticated request pulled down:</p><pre>--- [A] File on server (victim's attachment) ---<br>254e7a2a21c6d0d55fbc11fc08e30c18   &lt;server-side file&gt;</pre><pre>--- [B] Content retrieved via unauthenticated request ---<br>254e7a2a21c6d0d55fbc11fc08e30c18   &lt;downloaded file&gt;</pre><p>Identical hashes. Byte-for-byte exfiltration, from an anonymous session, confirmed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lztI7rFSqfGIsOZPdtpkWg.png"></figure><h3>Why This Scales</h3><p>The identifiers are <strong>sequential integers</strong>. An attacker doesn’t need to guess — they increment. Combined with the fact that support tickets routinely carry personal data, invoices, and contracts, and that the plugin’s upload whitelist covers pdf, doc/docx, xls/xlsx, txt, and common image formats, a single unauthenticated loop over the ID space harvests attachments across every customer on the site.</p><p>Estimated severity: <strong>CVSS 3.1 7.5 (High)</strong> — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Network-reachable, no privileges, no interaction, high confidentiality impact.</p><h3>The Reality Check</h3><p>Before public disclosure I did what I always do now: I checked the vulnerability databases and I contacted the vendor.</p><p>The vendor email went out first — a responsible-disclosure notice with a summary of the issue and a request for a secure contact, deliberately <em>without</em> the full PoC in the first message. Then I submitted the finding to a CNA with the complete technical detail and requested a CVE.</p><p>The response was: <strong>duplicate.</strong></p><p>Not a duplicate of the plugin’s older, public authorization issues — those were a different, integrity-only problem on a different function. This was a duplicate of a <strong>separate report already in the CNA’s pipeline</strong>, covering exactly this unauthenticated attachment-download route and exactly this “permission callback returns true” root cause, already tracked with the confidentiality impact of returning full attachment contents to anonymous callers.</p><p>Someone had gotten there first, by a matter of weeks, into a queue I couldn’t see.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/870/1*4qJhNuOGBEbGm_3ukmDEbA.png"></figure><h3>What I Was Told — and What It’s Worth</h3><p>Here’s the part that turned a rejection into something genuinely useful. The existing record was filed against an <strong>earlier version</strong>, and marked fixed in a later one. My finding reproduced on the <strong>current</strong> release — the one that was supposed to be patched.</p><p>The reviewer’s response was precise, and I’m quoting the substance of it because it reframed the whole finding for me: my confirmation that the issue <strong>still reproduces on the current version</strong>, together with the byte-for-byte MD5 proof, would be used to <strong>extend the affected-version range</strong> on the existing entry beyond the version it was originally filed against. Because it’s the same vulnerability and the same code path, it’s handled under the existing record rather than as a separate CVE.</p><p>So: no CVE with my name on it. But my independent reproduction demonstrated that a fix believed to close the issue <strong>did not</strong>, and that correction lands in the public record where it actually protects people. That’s not nothing. That’s the point of the work.</p><p>I want to be precise about what I’m claiming and what I’m not. I did not discover a novel bug here — I independently rediscovered a known one and proved it was still live where it was believed dead. The value isn’t novelty; it’s verification. Those are different contributions, and conflating them would be dishonest.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XYv4UU9Un9ZCuQuy78rK9w.png"></figure><h3>Attack Chain Summary</h3><pre>[Attacker — no credentials, no prior session]<br>        │<br>        ▼<br>[1] Map REST routes; find attachment-download handler<br>        │<br>        ▼<br>[2] Read permission callback → returns true unconditionally for file-dl<br>        │<br>        ▼<br>[3] Seed victim ticket + reply attachments in isolated Docker install<br>        │<br>        ▼<br>[4] GET file-dl/T/&lt;id&gt;/&lt;file&gt;  → HTTP 200, ticket attachment (no auth)<br>        │<br>        ▼<br>[5] GET file-dl/R/&lt;id&gt;/&lt;file&gt;  → HTTP 200, reply attachment (no auth)<br>        │<br>        ▼<br>[6] MD5(server file) == MD5(downloaded file) → byte-for-byte exfiltration<br>        │<br>        ▼<br>[7] Sequential IDs → enumerate → harvest attachments across all tickets</pre><h3>What This Taught Me</h3><p><strong>A “fixed in X” label is a claim, not a guarantee.</strong> The most valuable thing I did in this entire audit was test the <em>current</em> version instead of assuming the changelog was true. The issue was marked fixed; it wasn’t. Independent reproduction against the latest release is how that gets caught.</p><p><strong>Duplicate-by-pipeline is invisible until it isn’t.</strong> I checked every public database before submitting, and it was clean — because the report that duplicated mine wasn’t public yet. You cannot fully de-risk this. What you <em>can</em> do is target less-crowded plugins: the more popular the software, the more researchers are already circling it. Two of my findings that week collided with pipeline reports; both were popular plugins. The niche ones didn’t collide.</p><p><strong>Precision about your own contribution is a security skill.</strong> “I found a new bug,” “I independently rediscovered a known bug,” and “I proved a known bug wasn’t actually fixed” are three different sentences with three different truth values. Picking the correct one — especially when the flattering one is right there — is part of doing this honestly.</p><p><strong>The process transfers regardless of the outcome.</strong> Standing up an isolated environment, tracing an unauthenticated entry point to confirmed impact, building two independent PoCs, proving exfiltration with a hash rather than a screenshot alone — that skill set is identical whether the audit ends in a CVE or a “thanks, we’ll extend the range.”</p><p>If you found this useful, feel free to connect on <a href="http://linkedin.com/in/camalzads">LinkedIn </a>or check out my tools on <a href="http://github.com/alisalive">GitHub</a>.</p><p><em>All testing was conducted in an isolated, locally-hosted environment using a publicly available plugin release. No live or third-party systems were accessed at any point during this research. The plugin name and exact route are redacted pending completion of coordinated disclosure.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=435e86868d04" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-found-an-unauthenticated-attachment-disclosure-bug-in-a-wordpress-support-plugin-and-a-435e86868d04">I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Plesk Obsidian 18.0.79: Security Audit, Expanded REST API, and Microsoft SQL Server 2025 Support]]></title>
<description><![CDATA[Plesk Obsidian 18.0.79 is here, with security at the heart of this release. Following a comprehensive security audit, we addressed multiple vulnerabilities and introduced additional hardening improvements across the platform. Beyond security, this release expands the capabilities of the Plesk RES...]]></description>
<link>https://tsecurity.de/de/3643910/server/plesk-obsidian-18079-security-audit-expanded-rest-api-and-microsoft-sql-server-2025-support/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643910/server/plesk-obsidian-18079-security-audit-expanded-rest-api-and-microsoft-sql-server-2025-support/</guid>
<pubDate>Fri, 03 Jul 2026 18:00:53 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Plesk Obsidian 18.0.79 is here, with security at the heart of this release. Following a comprehensive security audit, we addressed multiple vulnerabilities and introduced additional hardening improvements across the platform. Beyond security, this release expands the capabilities of the Plesk REST API, adds support for Microsoft SQL Server 2025, and delivers a wide range of stability, compatibility, […]</p>
<p>The post <a href="https://www.plesk.com/blog/plesk-news-announcements/plesk-obsidian-18-0-79/" data-wpel-link="internal">Plesk Obsidian 18.0.79: Security Audit, Expanded REST API, and Microsoft SQL Server 2025 Support</a> appeared first on <a href="https://www.plesk.com/" data-wpel-link="internal">Plesk</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trunk Tools' stack cut document review from 60 days to 10 by ditching general-purpose models]]></title>
<description><![CDATA[Most verticals aren’t clean, well-oiled SaaS databases; the reality is ugly documents, proprietary schemas, implicit workflows, and long‑running tasks that most general-purpose models struggle with. This prompted construction project management company Trunk Tools to build a specialized, three-la...]]></description>
<link>https://tsecurity.de/de/3643726/it-nachrichten/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643726/it-nachrichten/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models/</guid>
<pubDate>Fri, 03 Jul 2026 15:46:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most verticals aren’t clean, well-oiled SaaS databases; the reality is ugly documents, proprietary schemas, implicit workflows, and long‑running tasks that most general-purpose models struggle with. </p><p>This prompted construction project management company Trunk Tools to build a specialized, three-layer architecture — perception, semantics, agents — based on highly-detailed data to support high-accuracy, highly-relevant industry automation.</p><p>Their purpose-built stack has shrunk review cycles from months to days, prevented costly field errors, and given autonomous agents the ability to reason over millions of pages of documentation, Trunk says. </p><p>“We really set out to take the data from dispersed systems, pre-process it, structure it, go through our ontology into a knowledge graph, and then train AI models,” said Sarah Buchner, Trunk’s founder and CEO and a former carpenter. </p><p>For builders in other verticals, Trunk’s approach could serve as a blueprint for transforming data chaos into agent‑ready, industry-specific workflows. </p><h2>Where general-purpose LLMs break down on industry data </h2><p>Foundation LLMs, while powerful, are optimized for breadth, not always depth. </p><p>“General-purpose LLMs are trained to be okay at everything, so they're weak at anything niche,” said Kriti Faujdar, a senior product manager working in AI infrastructure, agentic AI, security, and LLM platforms. For instance: Rare terms, domain-specific reasoning, the unspoken context that any practitioner “just knows.” </p><p>Web, app, and software developer Sébastien De Bollivier agreed that the biggest bottleneck is reliability on data that is “jargon-dense, abbreviation-heavy, and format-specific.” </p><p>“A GPT-4-class model can understand a French legal contract, but will fumble the specific article references practitioners need to cite,” he said. </p><p>Besides, the most valuable enterprise data never made it into pretraining anyway, Faujdar pointed out. It's sitting in internal systems and proprietary formats. “RAG helps a little,” she said. “But it's just giving better facts to a model that still can't reason properly in the domain.”</p><p>Pre-training on domain data is critical; enterprises should then fine-tune on good task examples and build their own evals. “A few thousand examples from real practitioners beats millions of scraped, noisy ones," Faujdar said. </p><p>Mixture-of-experts (MoE) can provide specialization without inference costs blowing up. Pairing RAG with fine-tuning also works well; RAG handles the factual long trail while fine-tuning fixes vocabulary and reasoning.</p><p>De Bollivier pointed to the advantage of hybrid stacks: A general-purpose model for reasoning and orchestration, a smaller fine-tuned model (or dense retrieval over a curated corpus) for domain-specific extraction. He advised: “Don't fine-tune to make the model 'smarter' about a domain, fine-tune to make it more reliable on the specific output format your workflow requires.”</p><p>The trades and construction are certainly industries seeing traction with these techniques, as are legal and healthcare, De Bollivier said. These verticals have “high stakes for errors plus standardized document formats, equaling clear domain-training ROI.”</p><p>One honest caveat worth mentioning, Faujdar said: Specialized models can often fall apart outside their domain, so they’re often not useful outside their expertise (unless they’re re-trained). </p><h2>Perception, semantics, agents: inside Trunk's three-layer stack</h2><p>In highly-specialized domains like construction, “data dumps” into large language models (LLMs) don’t cut it, said Trunk’s CTO Amrish Kapoor. This is because most transformers are probabilistic models: When given an image, they report back that it is “probably” a tree, or “probably” a child playing next to a tree. </p><p>This makes them insufficient for high‑precision symbolic interpretation. For instance, in construction documents, a 2-millimeter-wide symbol has a vastly different meaning depending on where it’s placed. </p><p>Further, constrained by context limits, probabilistic models struggle with long‑term project memory. “I don't mean a context window of a few tokens,” Kapoor said. “I'm talking about long term memory that stretches across months and years, because this is how long some of these projects are.”</p><p>Instead, Trunk’s three-layer system breaks workflows into: </p><ul><li><p>Perception (reading and extracting data from messy docs like PDFs, drawings, or scans)</p></li><li><p>A semantic/graph layer (making sense of that data and understanding their relationships).</p></li><li><p>LLMs and agents on top.</p></li></ul><p>Construction drawings are typically symbolic, Buchner said. A door isn't always labeled ‘door.’ Sometimes it's simply an arc on a wall that a trained eye learns to read based on years of practice. </p><p>“The perception layer is what teaches AI to read that language,” she said. The semantic layer then gives that information meaning; for instance, connecting the door to the drawing that details it, the spec that governs it, and the trade that installs it. This helps answer project engineers’ critical questions: Not "is there a door here?" but "does this door create a problem down the line?"</p><p>Particularly in construction, that shift matters because the cost of a problem compounds with time. “A conflict caught in design is relatively low cost to address,” Buchner said, “whereas the same problem caught in the field might cost tens of thousands of dollars.” </p><p>At a high level, the system identifies the document type and begins extracting information based on content (drawing, schedules, paragraph text). This data is then “transformed and augmented” in the platform, which triggers agentic workflows like knowledge graph relationships and end-user workflows. </p><p>For instance, an agent might review an architecture bulletin and produce a visual overlay comparing an older version and a newer version (flagging additions and removals), then generate written narratives that describe what those changes are in simple terms. This helps users understand what’s changed and coordinate with trade partners on updated pricing and change orders. </p><h2>The scale of construction’s data problem</h2><p>Construction workflows are “ripe with implicit assumptions and connections between data in its myriad of sources,” Buchner said. And the amount of unstructured data is “humanly impossible” to process or make sense of.</p><p>Buchner estimated the average high-rise building generates about 3.6 million pages of corresponding documentation. “If you print it into a stack of papers it would be as high as the building itself.” </p><p>All three layers of Trunk’s stack — perception, semantic, LLM — are trained on “very specific datasets” from customers with “explicit permissions” and auto‑labeling/IP, Kapoor explained. Customers who don’t want Trunk training on their data can opt out. </p><p>Data is deidentified and aggregated, and Trunk also collects “tons more” labeled data through other pipelines like 3D building information modeling (BIM). </p><p>Trunk says it only ships agents that achieve around 95% accuracy. The team maintains continuous evaluation pipelines based on ground truth data from customers and experts. They also employ an LLMs-as-a-judge model. </p><p>“This notion of an LLM as a judge is to score how well you're doing, both subjectively as well as objectively,” Kapoor said. Objectivity can be an easy ‘right’ or ‘not right,’ but subjectivity requires more nuance. </p><p>For instance, when creating an email or narrative or explanation, an LLM as a judge framework can create a composite score, or a numerical value that aggregates different metrics and tests a model's performance or risk.</p><p>There can be challenges, though, particularly with latency, Buchner noted; any time the reasoning capacity of underlying models increases, the risk of latency goes up, too. Trunk maintains a set of evaluation criteria to objectively measure latency whenever changes are made to underlying infrastructure, agents, and API calls. </p><p>Then, “before we release to customers, we ensure marginal changes to the end-user experience are well worth the performance enhancements,” Buchner said. </p><h2>From 60 days to 10: the measurable payoff</h2><p>Trunk’s platform powers seven AI agents purpose-built for construction, such as analyzing request for information (RFI) responses, overviewing bids, or reviewing drawings and submittals. </p><p>The submittal agent, for instance, flags missing, conflicting, or noncompliant information in product specs and RFIs. While it’s an essential step in the construction process, “it's a super annoying workflow,” Buchner said, because human reviewers have to compare documents “with a bunch of other parts of documents.” </p><p>But the agent is able to do this in seconds, and Trunk says it has reduced submittal cycles from 50 to 60 days to 10, “which has massive schedule and financial implications.” </p><p>Trunk is now at a place where these agents are communicating directly with each other, which is “quite exciting,” Buchner said. So, for example, one agent will review an architectural drawing for accuracy, then autonomously hand it over to agents handling RFIs and asking follow-up questions. </p><p>“If the drawings have problems, the RFI agent is taking over and is actively reaching out for clarification,” Buchner explained. </p><p>Trunk says its customers report savings of 20 to 40 minutes per field question. Buchner said that users in the field know better than anyone how much of a “time suck” it is to go back and forth from office trailers, dig through project documents in scattered systems or printed PDFs, reconcile discrepancies, and return to coordinate with trade partners. </p><p>Trunk says its customers report these additional outcomes:</p><ul><li><p>Average 8 minute time savings for single-document retrieval (status checks, location lookups, quantity queries).</p></li><li><p>Average 20 minute time savings for standard referencing (cross-referencing 2 to 3 spec sections to form an answer. </p></li><li><p>Average 40 minute time savings for multi-document research (listing and filtering queries, mapping relationships, analyzing RFIs and submittals across 4 to 6 documents).</p></li><li><p>Average 75 minute time savings for complex tasks (creating RFIs and other communication materials, deep cross-referencing across documents, change tracking). </p></li></ul><p>In one instance, Trunk’s drawing review agent flagged that a structural beam had been moved up 8.5 inches. However, this was not documented by the architect. If the change hadn’t been caught, the project manager would likely have had to strip out and reinstall the right size beam, Buchner said. This rework would have added $10,000 or more to the budget, and “certainly there would have been implications on the schedule.” </p><p>Buchner also pointed to other examples: an agent flagged $60,000 in exaggerated pricing with no justification from landscaping subcontractors; identified a fireplace that needed to be sealed prior to drywall installation, saving around $100,000 in labor, materials, and delays; and called out that an electric door required a panel that wasn’t included in electrical drawings. </p><h2>Learnings for other industries</h2><p>Trunk’s approach to building agents is applicable to any vertical working with high volumes of unstructured, industry-specific data. 

Builders working in specific verticals must understand the industry’s specific data challenges their end users face and build technical infrastructure that can transform unstructured data into something an “LLM can traverse and understand,” Buchner said. 

“Only then can you build the connections between data points that ultimately feed agentic workflows.”

A lot of money is being invested in foundational models, so enterprises should build modular systems that can leverage the strengths of various models as they continue to improve, Buchner advised. 

Then, “build your technical advantage where the generic models are not investing and not performing well,” she said. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[So spüren Sie kompromittierte KI-Agenten auf]]></title>
<description><![CDATA[Kompromittierte KI-Agenten sind nicht leicht zu erkennen. Lesen, wie es trotzdem klappt.amgun | shutterstock.com



Im Juni 2025 veröffentlichte der prominente britische Softwareentwickler Simon Willison einen in der Security-Community vielbeachteten Blogbeitrag. Darin warnte der Experte, der im ...]]></description>
<link>https://tsecurity.de/de/3642682/it-security-nachrichten/so-spueren-sie-kompromittierte-ki-agenten-auf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642682/it-security-nachrichten/so-spueren-sie-kompromittierte-ki-agenten-auf/</guid>
<pubDate>Fri, 03 Jul 2026 06:07:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/amgun_shutterstock_2602293623_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Table Risk 16z9" class="wp-image-4037407" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Kompromittierte KI-Agenten sind nicht leicht zu erkennen. Lesen, wie es trotzdem klappt.</figcaption></figure><p class="imageCredit">amgun | shutterstock.com</p></div>



<p>Im Juni 2025 <a href="https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/" target="_blank" rel="noreferrer noopener">veröffentlichte</a> der prominente britische Softwareentwickler <a href="https://en.wikipedia.org/wiki/Simon_Willison" target="_blank" rel="noreferrer noopener">Simon Willison</a> einen in der Security-Community vielbeachteten Blogbeitrag. Darin warnte der Experte, der im Jahr 2022 den Begriff „Prompt Injection“ geprägt hatte, vor einer tödlichen Dreierkombination („Lethal Trifecta“), die ausreichen um einen KI-Agenten mit nahezu hundertprozentiger Erfolgswahrscheinlichkeit durch indirekte Prompt Injection <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">zu kompromittieren</a>. Diese „Lethal Trifecta“ bei KI-Agenten manifestiert sich demnach im:   </p>



<ul class="wp-block-list">
<li>Zugriff auf private Daten,</li>



<li>dem Kontakt mit nicht vertrauenswürdigen Inhalten, sowie</li>



<li>der Fähigkeit zur externen Kommunikation.</li>
</ul>



<p>Ein Angreifer, der schadhafte Anweisungen an beliebiger Stelle in dieser Inhalts-Pipeline <a href="https://www.computerwoche.de/article/4044551/wenn-der-ki-agent-im-fakeshop-kauft.html" target="_blank">einschleust</a>, kann Daten exfiltrieren, ohne dass das überhaupt auffällt. Willison veranschaulichte diesen Punkt in seinem Beitrag mit einer langen Liste realer Exploits in Produktionsumgebungen. Das „tödliche Triple“ fungierte dabei zu einer Zeit als Security-Warnsignal, in der KI-Agenten einen meist eng begrenzten Anwendungsbereich hatten. Die Kombination der oben genannten Fähigkeiten zu vermeiden, schien eine tragfähige Designstrategie.</p>



<p>Das hat sich mittlerweile geändert: Ein kundenorientierter <a href="https://www.computerwoche.de/article/3980070/ki-tutorial-fur-bessere-helpdesks.html" target="_blank">Support-Agent</a> erfasst heute Ticketverläufe und Kundendaten, Benutzernachrichten sowie angehängte Dateien und ruft CRMs, Rückerstattungs-APIs oder Ticketing-Systeme auf. Ebenso lesen und beantworten KI-Agenten E-Mails, verwalten Kalender und Nachrichten. Das sind keine „Edge Cases“, sondern genau die Art von Agenten, nach denen Unternehmen und Privatanwender streben – und auf die die Anbieter hinarbeiten.</p>



<h2 class="wp-block-heading">Das „tödliche Triple“ als neuer Standard</h2>



<p><a href="https://uk.linkedin.com/in/ross-mckerchar-42bb548">Ross </a><a href="https://uk.linkedin.com/in/ross-mckerchar-42bb548" target="_blank" rel="noreferrer noopener">McKerchar</a>, CISO bei Sophos, bringt das Problem in einem <a href="https://www.sophos.com/en-us/blog/inside-the-lethal-trifecta-blast-radius-reduction-in-ai-agent-deployments" target="_blank" rel="noreferrer noopener">eigenen Blogbeitrag</a> auf den Punkt: „Die Funktionen, die Praktiker tatsächlich wollen, führen unweigerlich in gefährliches Terrain. Das ist keine Fehlkonfiguration, sondern der architektonische Preis für die Nützlichkeit.“</p>



<p>Damit liegt der Security-Entscheider richtig: Ein Agent ohne Zugriff auf private Daten ist nutzlos. Einer, der keine externen Inhalte verarbeiten kann, agiert isoliert. Und ein Agent, der nicht nach außen kommunizieren kann, ist handlungsunfähig. Nimmt man auch nur einen dieser drei Aspekte weg, steht im Ergebnis eher eine Suchleiste als ein KI-Agent. Wenn jede legitime Agentenarchitektur sämtliche Eigenschaften der „Lethal Trifecta“ aufweist, kann diese kein aussagekräftiger Indikator für erhöhtes Risiko mehr sein – sondern ist de facto die Standardkonfiguration. Sie weiterhin als Warnsignal zu betrachten, ist so, als würde man die <a href="https://www.computerwoche.de/article/2802729/was-ist-das-domain-name-system.html" target="_blank">DNS</a>-Auflösung als Anzeichen für ein kompromittiertes Netzwerk werten. Technisch gesehen <a href="https://www.csoonline.com/article/574989/4-strategies-to-help-reduce-the-risk-of-dns-tunneling.html" target="_blank">trifft das zwar auf einige Threat-Modelle zu</a>, ist aber in jedem realen Deployment allgegenwärtig.</p>



<p>Die Antwort auf diese Situation beschreibt der Sophos-CISO in seinem Blogbeitrag als „Blast Radius Reduction“. Gemeint ist eine realistische operative Philosophie, die die „Lethal Trifecta“ als gegeben akzeptiert. Das wäre ein guter erster Schritt – allerdings stellt sich die Frage, was nach der Akzeptanzphase folgt. Das Security-Team von Meta gelangte zu einer ähnlichen Erkenntnis wie McKerchar, nur aus einer anderen Richtung: Im Oktober 2025 veröffentlichte der Konzern sein „<a href="https://ai.meta.com/blog/practical-ai-agent-security/" target="_blank" rel="noreferrer noopener">Rule of Two</a>“-Framework. Dieses sieht vor, dass KI-Agenten nicht mehr als zwei der drei Komponenten der „Lethal Trifecta“ aufweisen sollten. Sind alle drei Merkmale vertreten, wird eine menschliche Genehmigung erforderlich. Von der Idee war auch Simon Willison angetan, der das Meta-Framework im November 2025 als den besten praktischen Ratgeber <a href="https://simonwillison.net/2025/Nov/2/new-prompt-injection-papers/" target="_blank" rel="noreferrer noopener">bezeichnete</a>, um sichere Agentensysteme auf LLM-Basis aufzubauen.</p>



<p>Mit Blick auf sein Framework räumt Meta allerdings auch Limitationen ein. Demnach passten diverse populäre Use Cases nicht nahtlos in das Rahmenwerk, wodurch Designs, die auf der „Rule of Two“ aufbauen, dennoch anfällig für Fehler sein könnten. Das ist nur die Bestätigung dafür, dass das Problem die Lösung auf Architekturebene bereits überholt hat. Denn das Ausmaß der Sicherheitslücken ist längst nicht mehr nur theoretischer Natur: So brachte eine Untersuchung des Common Crawl Repositories durch Sicherheitsforscher von Google diverse Prompt-Injection-Angriffe auf öffentlich zugängliche Webseiten <a href="https://blog.google/security/prompt-injections-web/" target="_blank" rel="noreferrer noopener">ans Licht</a>. Laut Google haben die Angriffsversuche dieser Art zwischen November 2025 und Februar 2026 <strong>um 32 Prozent</strong> zugelegt. Zwar stellten die Sicherheitsexperten fest, dass deren Reifegrad derzeit noch gering ist. Allerdings weisen sie auch darauf hin, dass der Trend ein klares Signal dafür ist, dass das Interesse der Angreifer zunimmt. Anders ausgedrückt: Das Umfeld, vor dem die „Lethal Trifecta“ einst gewarnt hat, ist zur Realität geworden.</p>



<h2 class="wp-block-heading">5 Anzeichen für kompromittierte KI-Agenten</h2>



<p>Wenn nahezu jeder eingesetzte KI-Agent die Merkmale der „Lethal Trifecta“ aufweist, benötigen Praktiker die richtigen Anhaltspunkte, um kompromittiertes Verhalten vom normalen Betrieb innerhalb eines Systems zu unterscheiden. Das erfordert einen Shift: Weg von Assessments auf Architekturebene und hin zu Behavioral Detection auf <a href="https://www.csoonline.com/article/4145127/runtime-the-new-frontier-of-ai-agent-security.html" target="_blank">Laufzeitebene</a>. Wie nötig dieser Umschwung ist, zeigte sich zuletzt im Januar 2026, als innerhalb von nur fünf Tagen vier verschiedene Exploits gegen populäre KI-Produktivitäts-Tools <a href="https://breached.company/the-lethal-trifecta-strikes-four-major-ai-agent-vulnerabilities-in-five-days/" target="_blank" rel="noreferrer noopener">bekannt wurden</a>. Betroffen waren IBM Bob, Superhuman AI, Notion AI und Claude Cowork. In allen vier Fällen setzten die Angreifer auf indirekte Promp Injection, um Daten zu exfiltrieren. Und zwar über einen Kanal, auf den der jeweilige Agent legitimen Zugriff hatte.</p>



<p>Im Fall von Claude Cowork sorgte ein in ein hochgeladenes Dokument eingebetteter, versteckter Prompt etwa dafür, dass der KI-Agent Dateien über die von Anthropic selbst auf die Whitelist gesetzte API-Domain exfiltrierte – unsichtbar für sämtliche Perimeterkontrollmaßnahmen und nicht von normalem Agentenverhalten zu unterscheiden, bis die Daten bereits gestohlen waren. Die vier Exploits hatten außerdem gemein, dass die „Lethal Trifecta“ Betriebsbedingung war.</p>



<p>Die folgenden fünf Signale können dazu beitragen, kompromittierte KI-Agenten zu erkennen:</p>



<ul class="wp-block-list">
<li><strong>Anomalien bei der Befolgung von Anweisungen:</strong> Ein kompromittierter Agent verhält sich in der Regel nicht grundlegend anders als ein intakter – er befolgt Anweisungen. Die Frage ist nur, wessen. Agenten-Aktionen, die keinen plausiblen Bezug zu einer vom Benutzer initiierten Aufgabe haben, sollten deshalb die Alarmglocken schrillen lassen. Ein Agent, der dazu aufgefordert wurde, einen Quartalsbericht zusammenzufassen, dann aber eine DNS-Anfrage an eine unbekannte Domain aussendet, hat sich dazu nicht spontan „entschlossen“ – er wurde dazu veranlasst.</li>



<li><strong>Tool-Call-Sequenzen, die die erwartete Topologie durchbrechen:</strong> In einem <a href="https://www.computerwoche.de/article/4132787/wie-ki-agenten-daten-konsumieren-sollten.html" target="_blank">gut konzipierten KI-Agentensystem</a> sollte die Sequenz der Tool-Aufrufe für eine spezifische Aufgabe relativ vorhersehbar sein. Ein Programmier-Agent, der einen Bug fixen soll, muss Dateien bearbeiten, Tests ausführen und möglicherweise die Dokumentation überprüfen. Er sollte allerdings nicht auf E-Mail- oder Kalender-APIs zugreifen. Sobald die erwarteten Grenzen eines Workflows in diesem Rahmen überschritten werden, ist deshalb Skepsis angesagt: Solche Tool-Call-Sequenzen sollten als verdächtig markiert werden, selbst wenn jeder einzelne Aufruf für sich genommen legitim erscheint.</li>



<li><strong>Exfiltration über Kanäle mit geringer Bandbreite:</strong> Der klassische Exfiltrationsangriff durch Prompt Injection leitet gestohlene Daten über einen Mechanismus weiter, auf den der Agent legitim zugreift – die URL eines gerenderten Bildes mit verschlüsselten Abfrageparametern, einen API-Call mit Daten, die in einem Parameter eingebettet sind oder einen Link in einem generierten Dokument. Für sich genommen sehen diese Aktionen nicht nach Datendiebstahl aus, sondern wirken völlig normal. Um eine Exfiltration erkennen zu können, sollte geprüft werden, auf welche Daten der Agent Zugriff hatte und was er in seinen Output eingebettet hat. Das erfordert wiederum, dass die Agentenaktionen durchgängig transparent sind – nicht nur der endgültige Output.</li>



<li><strong>Zugriff auf Anmeldedaten und Secrets außerhalb des Task-Scope:</strong> Greift ein Agent mit legitimen Zugriffsrechten auf einen Secrets Store oder einen Key Vault zu, die in keinem Zusammenhang mit dem aktuellen Task stehen, ist das ebenfalls ein Warnsignal. Ein Agent, der einen React-Rendering-Fehler beheben soll, braucht dazu mit Sicherheit keine AWS-Anmeldedaten. Das <a href="https://www.computerwoche.de/article/4135894/10-release-kriterien-fur-ki-agenten.html" target="_blank">Least-Privilege-Prinzip</a> dient hier als architektonische Abwehrmaßnahme. Doch erst ein Monitoring, bei dem gezielt überprüft wird, ob „out of scope“ auf Login-Daten zugegriffen wird, kann solche Abläufe zu Tage fördern.</li>



<li><strong>Anomalien bei Memory-Write-Vorgängen:</strong> Agenten mit persistentem Speicher stellen eine wachsende Angriffsfläche dar. Ein manipulierter Memory-Eintrag, der wie legitimer Benutzerkontext aussieht, könnte versteckte „Trigger Instructions“ enthalten, die Session-übergreifend erhalten bleiben und erst lange nach der eigentlichen Prompt Injection ausgelöst werden. Dagegen hilft, die Observability-Pipeline für KI-Agenten <a href="https://www.computerwoche.de/article/4150608/wie-ki-agenten-observable-werden.html" target="_blank">entsprechend auszugestalten</a>: Memory-Schreibvorgänge sollten auf befehlsähnliche Inhalte überwacht werden. Ebenso müssen Schreibvorgänge, die im Rahmen von Sessions mit nicht-vertrauenswürdigen Inhalten stattgefunden haben, kritisch beäugt werden.</li>
</ul>



<p>Für Security-Praktiker, die eine Agentic-AI-Infrastruktur im Produktivbetrieb managen, bestätigt die Entwicklung der „Lethal Trifecta“ zum neuen Standard nur das, was Sie ohnehin längst wissen: Ihre KI-Agenten sind gefährdet. Dieser Herausforderung ist <strong>auf Ebene der Runtime</strong> zu begegnen, nicht auf Architekturebene. Dort sind für traditionelle Architekturen EDR und SIEM angesiedelt. KI-Agenten benötigen dieselbe Instrumentierung – was auf die allermeisten Deployments bislang nicht zutrifft. (fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.csoonline.com/article/4184681/5-runtime-signals-for-catching-a-compromised-ai-agent.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[No, Xbox's Obsidian studio ISN'T shutting down — new comments dispute closure claims]]></title>
<description><![CDATA[Fresh rumors suggested Xbox studio Obsidian Entertainment could be facing closure, but a report from Jason Schreier says the acclaimed developer is not in danger. The latest speculation comes amid ongoing uncertainty surrounding Xbox's restructuring and layoffs.]]></description>
<link>https://tsecurity.de/de/3641742/windows-tipps/no-xboxs-obsidian-studio-isnt-shutting-down-new-comments-dispute-closure-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641742/windows-tipps/no-xboxs-obsidian-studio-isnt-shutting-down-new-comments-dispute-closure-claims/</guid>
<pubDate>Thu, 02 Jul 2026 18:29:35 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Fresh rumors suggested Xbox studio Obsidian Entertainment could be facing closure, but a report from Jason Schreier says the acclaimed developer is not in danger. The latest speculation comes amid ongoing uncertainty surrounding Xbox's restructuring and layoffs.]]></content:encoded>
</item>
<item>
<title><![CDATA[Winners of the 2026 iPhone Photography Awards Redefine the Notion of 'iPhone Photos']]></title>
<description><![CDATA[The 19th annual competition features photographers from 48 countries, most using older iPhone cameras.]]></description>
<link>https://tsecurity.de/de/3641218/it-nachrichten/winners-of-the-2026-iphone-photography-awards-redefine-the-notion-of-iphone-photos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641218/it-nachrichten/winners-of-the-2026-iphone-photography-awards-redefine-the-notion-of-iphone-photos/</guid>
<pubDate>Thu, 02 Jul 2026 15:03:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The 19th annual competition features photographers from 48 countries, most using older iPhone cameras.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft struggles to address AI notetaker governance nightmare]]></title>
<description><![CDATA[Microsoft this week tried to address the growing challenges surrounding notetaker bots in meetings by giving IT better control over them.



Microsoft’s announcement said that users of Microsoft Teams will be able to block non-Microsoft bots “even in meetings where organizers allow participants t...]]></description>
<link>https://tsecurity.de/de/3639976/it-nachrichten/microsoft-struggles-to-address-ai-notetaker-governance-nightmare/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639976/it-nachrichten/microsoft-struggles-to-address-ai-notetaker-governance-nightmare/</guid>
<pubDate>Thu, 02 Jul 2026 03:17:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft this week tried to address the growing challenges surrounding notetaker bots in meetings by giving IT better control over them.</p>



<p><a href="https://techcommunity.microsoft.com/blog/microsoftteamsblog/introducing-smarter-bot-protection-in-microsoft-teams-meetings/4531375" target="_blank" rel="noreferrer noopener">Microsoft’s announcement</a> said that users of Microsoft Teams will be able to block non-Microsoft bots “even in meetings where organizers allow participants to bypass the lobby.”</p>



<p>When the feature is enabled, Teams automatically detects potential bots, places them in the meeting lobby, clearly identifies them, and prompts organizers to confirm admission, Microsoft said, and even in meetings where organizers allow human participants to bypass the lobby, bots identified through this new policy will continue to require approval before joining.</p>



<p>“We’ve strengthened Teams’ ability to distinguish between bots and human participants as they join a meeting,” the company said. “Teams now uses a combination of behavioral and infrastructure signals to identify bots with a higher degree of accuracy. Alongside these improvements, soon we’ll introduce <a href="https://learn.microsoft.com/en-us/microsoftteams/teams-bot-identification" target="_blank" rel="noreferrer noopener">a registration path for independent software vendors (ISVs)</a> that build meeting experiences for Microsoft Teams.”</p>



<p>The underlying problem with the strategy is more complicated, however. Although AI bots launched by the meeting owner are typically announced at the beginning of a call, and participants’ bots announce themselves as the attendees log in, alert fatigue is diluting how carefully people watch what they say during those meetings.</p>



<p>But the thornier issue is that meeting owners’ approval of their own bot notetakers typically happens right before the start of a call, and the host has no control over whether participants also introduce their own AI notetakers. </p>



<p>And even if the intended topic of a call was innocuous, if someone brings up something that needs to be kept secret, such as plans for a hostile takeover or discussion about firing an employee, that is duly recorded by every bot. This expands the threat surface and increases the ways sensitive data could leak.</p>



<h2 class="wp-block-heading">Doesn’t rein in Microsoft bots</h2>



<p>Analysts and consultants agreed that any effort to restrict notetaking apps is good for enterprise IT, but some questioned whether the Microsoft effort went far enough.</p>



<p>“Although this new capability is useful to prevent external bots from attending recurring meetings even if they were needed for just one instance, it doesn’t seem to me that it does anything to prevent Microsoft’s own bots from doing so,” said <a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group. </p>



<p>Indeed, the Microsoft statement solely talks about managing “external bots and their access to meetings.”</p>



<p>In fact, Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a> said the limited controls that Microsoft is offering may actually dilute IT’s ability to control access to sensitive information.</p>



<p>Allowing any additional AI notetaking “takes the option to restrict/redact off the table,” and that control is what he thinks IT leaders should demand. The only practical way to do that is to allow only one notetaking app for any meeting and it needs to be controlled by the meeting owner.</p>



<p>“Allowing attendees to ask for an AI summary from the meeting owner and giving the owner the capacity to provide different versions that potentially shield sensitive data is a better choice for organizations looking to support better meeting follow ups without adding more work on the meeting owner,” Henein said. “It could even be set up in advance so a ‘sanitized’ summary is available for download.”</p>



<p><a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai, agreed with Henein and argued that these notetaking app controls have to be centralized with IT.</p>



<p>“Microsoft basically built a bouncer for meeting bots and that is a good thing. But the real risk shows up later, when a normal meeting turns into M&amp;A, legal, HR, or board-level discussion while an AI notetaker is still running,” Findling said. “Now that transcript may be sitting in a cloud nobody approved. You do not fix that live. You fix it upfront. For legal, finance, HR, and exec meetings, external AI notetakers should be blocked by default unless explicitly approved.”</p>



<h2 class="wp-block-heading">Existing governance not enough</h2>



<p><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, said the slowly changing nature of AI notetakers has allowed them to slip by IT governance rules.</p>



<p>“A meeting note was once a harmless aid. It is now a searchable corporate record that can hold intent, allegations and material non-public information. Once a conversation is transcribed and saved, it has left the room, and it begins to travel through mail, search, and discovery with a life of its own,” Gogia said. “Microsoft’s control is useful, but should not be oversold. It detects external bots and puts them before an organizer for approval. It does not yet block them, and approval at the lobby is not a governance model. Capture also arrives by routes the lobby never sees, through browser extensions and personal devices.”</p>



<p>Gogia also argued that the inevitable errors in these bot-generated transcripts or summaries, whether caused by hallucination or simply incorrect interpretation what was actually said, is also a massive risk.</p>



<p>“AI summary does not merely create a record. It creates an authoritative-looking one that is often wrong and, in doing so, it inverts the burden of proof. Once a summary exists, the question shifts from proving what was said to disproving what the machine wrote,” Gogia said. “A tentative ‘we should look at acquiring them’ can harden into ‘we agreed to acquire them’ and that version becomes the default until someone corrects it.”</p>



<p>And, noted <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, the problem will only get worse as AI summary generators morph into agentic systems, with action-taking autonomous agents.</p>



<p>“Over the next few years, we’ll see AI agents that summarize, extract decisions, assign work, update business systems, prepare follow-up documents, and collaborate with other AI systems after the meeting ends,” he said. “In fact, we are already seeing that integration happen, and it is simultaneously incredibly valuable and outrageously risky. The real question isn’t whether to allow an AI notetaker. It’s how organizations will govern an increasingly machine-readable workplace.”</p>



<p>Greis said that he sees the Microsoft approach as a good start, “because they’re treating AI participants more like digital identities than software features.” </p>



<p>He pointed out, “detection, verification, explicit admission, auditability, and policy-based control are exactly the kinds of enterprise controls we’ll need as AI agents become commonplace. This feels very similar to identity and access management twenty years ago. We eventually realized we weren’t managing employees, we were managing identities. AI agents deserve the same treatment.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[12 handy hidden Google Docs tricks for Android]]></title>
<description><![CDATA[Few apps are as essential to mobile productivity as the humble word processor. I think I’ve probably spent a solid seven years of my life staring at Google Docs on one device or another at this point, and those minutes only keep ticking up with practically every passing day.



While we can’t do ...]]></description>
<link>https://tsecurity.de/de/3638021/it-nachrichten/12-handy-hidden-google-docs-tricks-for-android/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638021/it-nachrichten/12-handy-hidden-google-docs-tricks-for-android/</guid>
<pubDate>Wed, 01 Jul 2026 11:47:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Few apps are as essential to mobile productivity as the humble word processor. I think I’ve probably spent a solid seven years of my life staring at Google Docs on one device or another at this point, and those minutes only keep ticking up with practically every passing day.</p>



<p>While we can’t do much about the need to gaze at that word-filled white screen, what we <em>can </em>do is learn how to make every moment spent within Docs count — and in the <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.docs.editors.docs&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Docs Android app</a>, specifically, there are some pretty spectacular tucked-away time-savers just waiting to be discovered.</p>



<p>Make a mental note of these advanced shortcuts and options, and put ’em to good use the next time you find yourself staring at Docs on your own device.</p>



<h2 class="wp-block-heading">Google Docs Android feature #1: Smarter document organization</h2>



<p>We’ll save the best for, erm, first — ’cause the easily overlooked feature we’re kickin’ things off with can save you some serious time and make your mobile editing experience significantly easier.</p>



<p>After all, dealing with a complex document from your phone can be a real hassle. Who wants to waste time scrolling through endless-seeming screens to find the section of info you need to read, edit, or work on at any given moment?</p>



<p>I sure as heckfire don’t — and if you remember to use Docs’ out-of-the-way Outline option, you’ll never have to do it again, either. While viewing or editing any document with any sort of headers in it (be they actual header-formatted text or even just bolded section titles), tap the three-dot menu icon in Docs’ upper-right corner and then select “Document Outline.”</p>



<p>And by golly, wouldya look at that?</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/01-google-docs-android-outline.jpg?quality=50&amp;strip=all&amp;w=996" alt="Google Docs Android: Document outline" class="wp-image-4191233" width="996" height="1024" sizes="auto, (max-width: 996px) 100vw, 996px"><figcaption class="wp-element-caption">An automatic document outline is never out of reach in the Docs Android app.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Jumping to any part of the document is now just a single tap away.</p>



<p><strong>[Psst: Love shortcuts? My </strong><a href="https://theintelligence.com/shortcut-ai/" target="_blank" rel="noreferrer noopener"><strong>Android Shortcut Supercourse</strong></a><strong> will teach you tons of time-saving tricks for every single part of your smartphone experience. </strong><a href="https://theintelligence.com/shortcut-ai/"><strong>Sign up now for free</strong></a><strong>!]</strong></p>



<h2 class="wp-block-heading">Google Docs Android feature #2: Instant tab access</h2>



<p>Speaking of organization, in that same section of the in-document three-dot menu resides an easily overlooked option called “Document tabs.”</p>



<p>Tap it, and you can then see, manage, and move among any tabs created within the document for added organization — just like in the Docs desktop interface.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/02-google-docs-android-tabs.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Tabs" class="wp-image-4191231" width="1024" height="1022" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Who knew?! Your Google Docs tabs are now accessible within the Docs Android app as well.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Yes, please — and thank you.</p>



<h2 class="wp-block-heading">Google Docs Android feature #3: Easier Word integration</h2>



<p>When you’re working with clients, colleagues, or even camels who for some reason prefer the Microsoft editing ecosystem, you don’t have to do much to bridge that gap. The Docs Android app can already open and allow you to edit Word files, without any work — and with one simple flip of a switch, you can <em>create</em> new files in the .DOCX format just as easily.</p>



<p>To find the feature, you’ve gotta back out of any actual documents and get onto the main Docs screen — the screen with the search box at the top and all your documents listed out beneath it. Tap the three-line menu icon in the upper-left corner of that screen and head into the Settings section of that main menu. There, you should see the very switch we need:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/03a-google-docs-android-create-word-files.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Create Word files" class="wp-image-4191225" width="1024" height="537" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Tick one toggle, and you can then create native Word files within the Docs Android app anytime.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Flip that into the on position, then back yourself out to the main Docs screen. The next time you tap the plus icon in that area’s lower-right corner, you should see “New Word file” show up as an option right above the default “New Docs file” command.</p>



<p>And just as a reminder, if you ever want to save an <em>existing</em> Docs file into the .DOCX format, you can do that, too: Tap the three-dot menu icon while editing a document, select “Share &amp; export,” then select “Save As” and choose the “Word (.docx)” option.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/03b-google-docs-android-save-word-files.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Save as Word" class="wp-image-4191226" width="1024" height="647" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Saving any document as a Word file is also easy, once you know where to look.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>You can also save the file as a PDF or other common document format from that same menu.</p>



<h2 class="wp-block-heading">Google Docs Android feature #4: The swift sender</h2>



<p>While we’re thinkin’ about dealing with different document formats, download this into your long-term memory: The next time you need to save or send a document as an actual <em>file</em> — as opposed to an in-app, collaboration-ready Google Docs share — you can save yourself the trouble of downloading and then reuploading the thing and simply send it directly from the Docs Android app.</p>



<p>The trick is to once again tap that three-dot menu icon whilst editing a file and then select that same “Share &amp; export” menu we just went over. But this time, instead of going with the “Save As” option, select “Send a copy.”</p>



<p>You can then pick from the same set of format choices we just finished exploring. And from there, Docs will allow you to choose from any compatible app on your device — everything from <a href="https://www.computerworld.com/article/1707648/best-email-and-texting-apps-for-android.html">Android email and messaging apps</a> to note-storing services like <a href="https://www.computerworld.com/article/1615550/3-fantastic-ways-notion-can-make-you-more-efficient.html">Notion</a> and <a href="https://www.computerworld.com/article/1724688/27-advanced-trello-tips-and-tricks.html">Trello</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/04-google-docs-android-send.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Share" class="wp-image-4191230" width="1024" height="997" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Send any document into any other compatible app on your phone for a simplified sharing setup.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>All it takes is one more tap from there, and your document will be on its way to the appropriate place in the format you requested — just like that.</p>



<h2 class="wp-block-heading">Google Docs Android feature #5: The local file finder</h2>



<p>Ever download a document onto your phone — be it from an email, a Slack channel, a website, or any other such source — and then later find yourself struggling to find it? Well, get this: Google’s got its own simple file finder ready and waiting for you right within the regular Docs app. Who woulda thunk, right?!</p>



<p>But oh, it be there, all righty. It’s that innocuous little folder icon within the search bar on the main Docs screen — something I must’ve seen about a thousand times before I ever thought to actually tap it.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/05-google-docs-android-files.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Files" class="wp-image-4191223" width="1024" height="180" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Whoa — a built-in Docs file finder?!</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>When you do, the app will prompt you to find a saved file from either your local phone storage or from your online Drive storage. And once you select either option, you can browse through the associated place to see what’s there or search to find exactly what you’re after — no hopping over to a separate <a href="https://www.computerworld.com/article/1718187/android-file-manager-apps.html">Android file manager</a> required.</p>



<h2 class="wp-block-heading">Google Docs Android feature #6: The Drive detour</h2>



<p>Speaking of Google Drive, if you ever find yourself needing to mosey over to the full Drive interface to dig around more deeply or pull up a file that isn’t text-related, here’s a handy little secret:</p>



<p>You can actually fly from Docs directly to Drive <em>without </em>going through all the usual steps — y’know, heading back to your home screen, finding the Drive icon, and opening it up anew from there.</p>



<p>Just rely on the Docs app’s artfully hidden Drive shortcut to slash steps and zip straight between the two related interfaces. The option is quietly waiting for you within the three-line menu icon on the main Docs screen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/06-google-docs-android-drive.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Google Drive" class="wp-image-4191221" width="1024" height="707" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Docs and Drive — BFFs forever.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And now you know.</p>



<h2 class="wp-block-heading">Google Docs Android feature #7: The account adjuster</h2>



<p>Keep that overly moist eyeball of yours in that same area of the Docs app interface for a minute, ’cause we’ve got one more sneaky shortcut worth unearthing there.</p>



<p>It’s a shortcut baked into your face — or whatever sort of image you’ve got in place for your Google account profile photo, up in the app’s upper-right corner.</p>



<p>As is the case with most Google-made apps on Android these days, you can swipe up or down on that image to flip through any additional accounts you’ve got connected on your phone. If you only have a single account set up, this obviously won’t apply to you. But if you have, say, a personal Google account and a work address or even a few different situation-specific personal or work identities, it’s a splendid way to move between ’em with next to no effort and just a single swift swipe.</p>



<h2 class="wp-block-heading">Google Docs Android feature #8: The direct document shortcut</h2>



<p>Another shortcut worth burning into your brainspace: If you find yourself working on a specific document or set of documents frequently — whether they’re evolving documents you access all the time or just specific projects on your radar at one particular moment — save yourself the steps of opening the Docs app, finding ’em there, and then tapping their titles to get into ’em and instead give yourself one-tap shortcuts to open the files directly from your home screen.</p>



<p>The option to do that is pretty buried, but it’s well worth digging up. Start by finding the document in question on the main Docs screen. Long-press it, and then look way down on the menu that pops up for the “Add to home screen” command. (Depending on the size of your phone, you might have to scroll down that menu a bit before you’ll see it appear.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/08a-google-docs-android-add-to-home-screen.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Add to home screen" class="wp-image-4191219" width="1024" height="1002" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">You’ve usually gotta scroll to find it, but Docs’ “Add to home screen” option is there and ready to save you time.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Tap that bad boy and follow the prompt to place the shortcut wherever you want it — and say “hocus pocus” for good measure, if you’re feelin’ merry — and before you know it, you’ll have an app-like icon sitting right on your home screen. Tapping it will take you directly into the document you selected, without any extra steps required.</p>



<p>You could even get ambitious and create an entire <em>folder </em>on your home screen where you store a variety of high-priority or in-progress documents.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/08b-google-docs-android-home-screen.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Home screen" class="wp-image-4191220" width="1024" height="406" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">What’s up, Docs?</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Three cheers for seconds saved!</p>



<h2 class="wp-block-heading">Google Docs Android feature #9: Quick function shortcuts</h2>



<p>Let’s keep our shortcut mojo goin’ for one more minute, shall we? You can actually follow that same pattern we just went over and and put shortcuts for common Docs commands like creating a new document or searching your existing documents right on your home screen, too. That way, you can perform the associated commands quickly and without any wasted effort opening up the app and hunting around for ’em — and what’s not to love about added efficiency?</p>



<p>These are actually part of Android’s oft-forgotten App Shortcuts system — the thing that came around way back with 2016’s Android 7.1 Nougat release and that’s still vexingly <a href="https://www.computerworld.com/article/1675828/android-app-shortcuts.html">out of sight and out of mind</a> for most of us.</p>



<p>Open up your app drawer, though, and find the Docs icon — or find the Docs icon on your home screen, if it’s there. Press and hold it, and you should see a series of options for direct shortcuts to actions <em>within</em> the app appear.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/09a-google-docs-android-home-screen-shortcuts.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Home screen shortcuts" class="wp-image-4191228" width="1024" height="558" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">All sorts of helpful Docs options are accessible right from your home screen.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>You can always get to those by long-pressing the Docs icon, but if you find yourself using the functions often, you can make it even easier by pressing and holding one of ’em within that pop-up menu and then dragging it directly onto your home screen for one-touch access.</p>



<p>You could even build yourself a nifty little Docs command center for super-fast access to all the stuff you use the most:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/09b-google-docs-android-home-screen-command-bar.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Home screen command bar" class="wp-image-4191232" width="1024" height="419" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Docs, Docs, everywhere — so many options, never more than a tap away.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And while we’ve got easy access on our minds…</p>



<h2 class="wp-block-heading">Google Docs Android feature #10: The offline on switch</h2>



<p>By default, the Docs Android app will make any files you actively work within the app available for offline use for a while — but if you’re getting ready to travel or expecting any other connectivity-challenged moments, you don’t have to rely on its judgment to make sure your stuff is accessible even without internet access.</p>



<p>From the main Docs screen, tap the three-dot icon alongside any document name and then look for the “Make available offline” option within the menu that pops up.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/10-google-docs-android-offline.jpg?quality=50&amp;strip=all&amp;w=990" alt="Google Docs Android: Offline" class="wp-image-4191229" width="990" height="1024" sizes="auto, (max-width: 990px) 100vw, 990px"><figcaption class="wp-element-caption">Pro tip: Turn offline access on <em>before</em> the need actually arises.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Tap that for any document that you expect to need and then rest easy knowing it’ll be there and available for you — no matter your current connection status.</p>



<h2 class="wp-block-heading">Google Docs Android feature #11: Wordless reactions</h2>



<p>Sometimes, a picture really is worth a thousand words. Or at least a couple hundred.</p>



<p>That’s especially true when collaborating on a document and expressing your opinions — which, let’s be honest, often come down to simple reactions like 👍 or maybe 💩.</p>



<p>Docs has allowed emoji reactions as a part of its editing process for a while now, and at some point along the way, the Android app gained the same ability. It’s just weirdly tucked away in a place where few word-minded mammals would ever find it.</p>



<p>So do this: The next time you’re working on a shared doc, try pressing and holding your finger onto any word to highlight it. (You can then use the selector icons that pop up to expand or shift your selection, if needed.)</p>



<p>Now for the tricky part: In the menu that appears alongside your selection — the one that contains “Copy” and other such commands — look for the three-line icon at its far right side.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/11a-google-docs-android-reactions-menu.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Add emoji reaction menu" class="wp-image-4191222" width="1024" height="126" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">See that little three-line icon within the text actions pop-up? </figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Tap that — and lookie what we have here: the awkwardly hidden option to add an emoji reaction! 🥳</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/11b-google-docs-android-reactions.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Add emoji reaction" class="wp-image-4191224" width="1024" height="192" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Emojis for everyone — hip, hip, hoorah!</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Hit that sneaky little thing with all your might, then select the most appropriate reaction and move on with a satisfied 😊 in your mind.</p>



<h2 class="wp-block-heading">Google Docs Android feature #12: Your in-doc AI</h2>



<p>Generative AI these days is a bit of a mixed bag, to put it politely. Google’s Gemini and other such services are arguably <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">causing more harm than good</a>, on <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">numerous levels</a>, and also just creating paths for lazy, low-quality and accuracy-challenged work.</p>



<p>But in the right scenario and with the right sort of framing, Gemini-style AI <em>can</em> <a href="https://www.computerworld.com/article/4007736/gemini-android.html">actually be useful</a>. The onus just falls squarely on <em>you</em> to determine how to most effectively use it and avoid falling into the traps of unoriginality or, worse, inaccuracy.</p>



<p>The Docs Android app now offers a direct shortcut to Gemini within its editing interface — via the starburst-shaped icon in the toolbar at the top of the screen — and with some careful considering, it might just end up being a helpful reading or editing tool for you.</p>



<p>A few suggestions that notably <em>don’t </em>involve having AI write lazy, uninspired copy on your behalf:</p>



<ul class="wp-block-list">
<li>You can use the Gemini in Docs system as a quick ‘n’ easy way to get a definition or list of synonyms for any word in front of you.</li>



<li>You can also use it to ask for context or related information — like an integrated research aide. (Just remember that AI doesn’t always get things right, so treat it as more of a starting point than a final quote-ready answer.)</li>



<li>And you can lean on it to perform tasks like summarizing or outlining a long document or helping you reorganize a document into a more logical state.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/12-google-docs-android-gemini.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Gemini" class="wp-image-4191227" width="1024" height="814" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Gemini is now available directly within Docs. Please, use it wisely.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>You may still end up spending a ton of time in Docs, but at least now you’ll make the most of every second there and avoid wasting your effort on piddly little tasks that can be made more efficient. And that, as far as I’m concerned, warrants an enthusiastic 🥂 reaction — maybe even followed by a well-earned 🍪.</p>



<p><i>Get six full days of advanced Android knowledge with <a href="https://theintelligence.com/shortcut-ai/" target="_blank" rel="noreferrer noopener"><strong>my free Android Shortcut Supercourse</strong></a>. You’ll learn tons of time-saving tricks for your phone!</i></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-65518 | Plesk Obsidian up to 18.0.73 Web Interface get_password.php denial of service]]></title>
<description><![CDATA[A vulnerability was found in Plesk Obsidian up to 18.0.73. It has been rated as problematic. The impacted element is an unknown function of the file get_password.php of the component Web Interface. The manipulation leads to denial of service.

This vulnerability is listed as CVE-2025-65518. The a...]]></description>
<link>https://tsecurity.de/de/3634675/sicherheitsluecken/cve-2025-65518-plesk-obsidian-up-to-18073-web-interface-getpasswordphp-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634675/sicherheitsluecken/cve-2025-65518-plesk-obsidian-up-to-18073-web-interface-getpasswordphp-denial-of-service/</guid>
<pubDate>Tue, 30 Jun 2026 08:05:49 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/plesk:obsidian">Plesk Obsidian up to 18.0.73</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function of the file <em>get_password.php</em> of the component <em>Web Interface</em>. The manipulation leads to denial of service.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2025-65518">CVE-2025-65518</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google veröffentlicht erstes Firmware-Update zum Fitbit Air]]></title>
<description><![CDATA[Google hat vor nicht allzu langer Zeit sein Fitness-Armband namens Fitbit Air offiziell auf dem Markt gebracht. Abgesehen von der etwas stark in Kritik geratenen Google Health-Plattform bewerteten die meisten …]]></description>
<link>https://tsecurity.de/de/3633764/it-nachrichten/google-veroeffentlicht-erstes-firmware-update-zum-fitbit-air/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633764/it-nachrichten/google-veroeffentlicht-erstes-firmware-update-zum-fitbit-air/</guid>
<pubDate>Mon, 29 Jun 2026 20:17:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1600" height="1100" src="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/05/google-fitbit-air-obsidian.jpg?fit=1600%2C1100&amp;ssl=1" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/05/google-fitbit-air-obsidian.jpg?w=1600&amp;ssl=1 1600w, https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2026/05/google-fitbit-air-obsidian.jpg?resize=690%2C474&amp;ssl=1 690w" sizes="(max-width: 1600px) 100vw, 1600px">
Google hat vor nicht allzu langer Zeit sein Fitness-Armband namens Fitbit Air offiziell auf dem Markt gebracht. Abgesehen von der etwas stark in Kritik geratenen Google Health-Plattform bewerteten die meisten …]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion stellt E-Mail-Client im September ein]]></title>
<description><![CDATA[Der Produktivitätsdienst Notion stellt Notion Mail am 22. September ein. Grund ist der verstärkte Fokus auf die Verwaltung durch autonome KI-Agenten.

Tags: #E-Mail | #KI-Agent | #Künstliche Intelligenz]]></description>
<link>https://tsecurity.de/de/3631902/it-security-nachrichten/notion-stellt-e-mail-client-im-september-ein/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631902/it-security-nachrichten/notion-stellt-e-mail-client-im-september-ein/</guid>
<pubDate>Mon, 29 Jun 2026 06:23:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/06/Notion_Bild_ShutterStockies-Shutterstock.com_shutterstock_2569553705.jpg" class="attachment-full size-full wp-post-image" alt="Notion, Notion Mail Bildquelle: ShutterStockies / Shutterstock.com" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/06/Notion_Bild_ShutterStockies-Shutterstock.com_shutterstock_2569553705.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/06/Notion_Bild_ShutterStockies-Shutterstock.com_shutterstock_2569553705-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/06/Notion_Bild_ShutterStockies-Shutterstock.com_shutterstock_2569553705-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/06/Notion_Bild_ShutterStockies-Shutterstock.com_shutterstock_2569553705-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/06/Notion_Bild_ShutterStockies-Shutterstock.com_shutterstock_2569553705-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Notion stellt E-Mail-Client im September ein 1"></p>
    Der Produktivitätsdienst Notion stellt Notion Mail am 22. September ein. Grund ist der verstärkte Fokus auf die Verwaltung durch autonome KI-Agenten.

<p>Tags: <a href="https://www.it-daily.net/thema/e-mail">#E-Mail</a> | <a href="https://www.it-daily.net/thema/ki-agent">#KI-Agent</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4671: Protocal AI]]></title>
<description><![CDATA[This show has been flagged as Explicit by the host.


In this episode, Operator dives into his ongoing journey to migrate away from centralized cloud ecosystems specifically moving his daily workflow off Google Keep and onto 
Obsidian
 hosted locally on a Debian server. Operating purely over a se...]]></description>
<link>https://tsecurity.de/de/3631691/podcasts/hpr4671-protocal-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631691/podcasts/hpr4671-protocal-ai/</guid>
<pubDate>Mon, 29 Jun 2026 02:02:09 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Explicit by the host.</p>

<p>
In this episode, Operator dives into his ongoing journey to migrate away from centralized cloud ecosystems specifically moving his daily workflow off Google Keep and onto <strong>
<a href="https://obsidian.md/">Obsidian</a></strong>
 hosted locally on a Debian server. Operating purely over a secure VPN to minimize his external attack surface, he discusses the security considerations of managing personal data in local plain-text markdown files.</p>

<p>
The episode features a deep dive into local AI infrastructure, sparked by technologist <a href="https://danielmiessler.com/">Daniel Miessler’s</a> recent shift away from <strong>
<a href="https://en.wikipedia.org/wiki/Retrieval-augmented_generation">RAG (Retrieval-Augmented Generation)</a></strong>
 in favor of a simpler, localized file-system-as-context approach (using fast search tools like ripgrep). Operator shares his own mixed results experimenting with RAG noting great success with massive, structured car repair manuals, but incredibly poor fidelity when indexing conversational podcast transcripts.</p>

<p>
To find the sweet spot, Operator is testing a <strong>
dual approach</strong>
: combining flat-file local search with a PostgreSQL vector database (<code>
<a href="https://github.com/pgvector/pgvector">pgvector</a></code>
). He also rants about the frustrating "hype cycle" of online tutorials that claim to teach "local" setups but secretly rely on expensive, cloud-hosted frontier models.</p>

<p>
Finally, the host introduces his ambitious roadmap for <strong>
"Protocol AI."</strong>
 Designed as a localized, read-only dashboard to help manage his ADHD and "time blindness," this system will scrape, aggregate, and summarize his cluttered digital life including multiple Gmail accounts, Yahoo spam, calendars, and a massive array of social media feeds (Signal, Discord, Mastodon, BlueSky). The long-term goal? Transitioning from a read-only local summarizer to a safe, "human-in-the-loop" execution assistant that keeps his data out of the hands of mega-corporations.</p>

<h2>
References
</h2>
<blockquote>
Obsidian is a proprietary personal knowledge base and note-taking application that operates on Markdown files. The software is free for personal and commercial use; only the offered cloud services, optional commercial licenses, and early access versions are paid. It is available as desktop versions for macOS, Windows and Linux as well as for mobile operating systems such as iOS and Android, but not as a web application. 
</blockquote>
<p>

<a href="https://en.wikipedia.org/wiki/Obsidian_(software)">Obsidian - From Wikipedia, the free encyclopedia</a>
</p>


<blockquote>
Retrieval-augmented generation (RAG) is a technique that enables large language models (LLMs) to retrieve and incorporate new information from external data sources. With RAG, LLMs first refer to a specified set of documents, then respond to user queries. These documents supplement information from the LLM's pre-existing training data. This allows LLMs to use domain-specific and/or updated information that is not available in the training data. For example, this enables LLM-based chatbots to access internal company data or generate responses based on authoritative sources. 
</blockquote>

<p><a href="https://en.wikipedia.org/wiki/Retrieval-augmented_generation">RAG (Retrieval-Augmented Generation)</a></p><p><a href="https://hackerpublicradio.org/eps/hpr4671/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Agenten im Unternehmen trotz Datenschutz? So setzt du Manus beruflich sicher und produktiv ein]]></title>
<description><![CDATA[Author: Digitale Profis - Bewertung: 0x - Views:8 [Werbung] 1000 kostenlose Credits bei Manus sichern: https://manus.im/redeem?c=yju1zja

Viele Unternehmen im DACH-Raum haben bei KI-Agenten sofort eine berechtigte Frage: Dürfen wir da überhaupt unsere Business-Daten hochladen?

In diesem Video te...]]></description>
<link>https://tsecurity.de/de/3631216/ai-nachrichten/ki-agenten-im-unternehmen-trotz-datenschutz-so-setzt-du-manus-beruflich-sicher-und-produktiv-ein/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631216/ai-nachrichten/ki-agenten-im-unternehmen-trotz-datenschutz-so-setzt-du-manus-beruflich-sicher-und-produktiv-ein/</guid>
<pubDate>Sun, 28 Jun 2026 18:04:20 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Digitale Profis - Bewertung: 0x - Views:8 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/PhadMcP_6lA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>[Werbung] 1000 kostenlose Credits bei Manus sichern: https://manus.im/redeem?c=yju1zja<br />
<br />
Viele Unternehmen im DACH-Raum haben bei KI-Agenten sofort eine berechtigte Frage: Dürfen wir da überhaupt unsere Business-Daten hochladen?<br />
<br />
In diesem Video teste ich einen bewusst datenschutzbewussteren Workflow mit Manus. Ich lade keine Kundendaten, keine CRM-Exporte, keine Verträge und keine personenbezogenen Freitexte hoch. Stattdessen arbeiten wir mit aggregierten KPIs, anonymisiertem Feedback und öffentlichen Marktinformationen.<br />
<br />
Daraus soll Manus einen Business-Report erstellen: mit Executive Summary, KPI-Überblick, Chancen, Risiken, nächsten Schritten, einer kleinen Präsentation und einer Team-Mail.<br />
Wichtig: Das ist keine Rechtsberatung und ersetzt keine Datenschutzprüfung. Aber es zeigt einen praktischen Ansatz, wie man KI-Agenten im Business sinnvoller und bewusster einsetzen kann.<br />
<br />
Werde Kanalmitglied und unterstütze damit unsere Arbeit:<br />
https://www.youtube.com/channel/UCv90NdTyTp7ZPPRvvSZaS5w/join<br />
<br />
Videoinhalt:<br />
00:00 Den KI-Agenten Manus sicher im beruflichen Umfeld einsetzen<br />
01:28 Start unseres Arbeits-Projekts mit sicheren Daten<br />
02:48 Der erste Prompt in unserem Projekt<br />
05:02 Kritische Prüfung der Ergebnisse mit KI-Unterstützung<br />
07:05 Der zweite Schritt auf dem Weg zum Workflow<br />
09:15 Interaktive Ausgaben mit Manus erstellen<br />
10:56 Automatische Aktualisierung des Dashboards mit Projekt-Dateien<br />
13:40 Sicheres Arbeiten mit KI-Agenten im Beruf auch ohne eigene Daten<br />
17:35 Automatische Markt-Überwachung mit Manus einrichten<br />
18:14 Ergebnisse in Notion speichern mit einer Verbindung von Manus<br />
21:34 KI-Agenten sind bei der Arbeit immer einsetzbar - man muss nur wissen wie!<br />
<br />
Videovorschläge, Feedback und Kritik kannst Du uns jederzeit in den Kommentaren mitteilen!<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[As the rising costs of RAM crush the notion of gaming as an affordable hobby, what are PC gamers and Xbox fans supposed to do?]]></title>
<description><![CDATA[Gaming costs are soaring as RAM and storage prices rise, leaving PC and Xbox players with few options beyond discounts, used hardware, or cloud gaming.]]></description>
<link>https://tsecurity.de/de/3631085/windows-tipps/as-the-rising-costs-of-ram-crush-the-notion-of-gaming-as-an-affordable-hobby-what-are-pc-gamers-and-xbox-fans-supposed-to-do/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631085/windows-tipps/as-the-rising-costs-of-ram-crush-the-notion-of-gaming-as-an-affordable-hobby-what-are-pc-gamers-and-xbox-fans-supposed-to-do/</guid>
<pubDate>Sun, 28 Jun 2026 15:11:05 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gaming costs are soaring as RAM and storage prices rise, leaving PC and Xbox players with few options beyond discounts, used hardware, or cloud gaming.]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Visuelle PKM-Tools: Heptabase, Obsidian Canvas und Xmind im Vergleich]]></title>
<description><![CDATA[Visuelle PKM-Tools wie bringen Ordnung ins Ideenchaos. Der Ratgeber zeigt, welches Tool zur persönlichen Denkweise passt.]]></description>
<link>https://tsecurity.de/de/3630786/it-nachrichten/heise-visuelle-pkm-tools-heptabase-obsidian-canvas-und-xmind-im-vergleich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630786/it-nachrichten/heise-visuelle-pkm-tools-heptabase-obsidian-canvas-und-xmind-im-vergleich/</guid>
<pubDate>Sun, 28 Jun 2026 11:17:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Visuelle PKM-Tools wie bringen Ordnung ins Ideenchaos. Der Ratgeber zeigt, welches Tool zur persönlichen Denkweise passt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion kills its Gmail client after AI agents keep humans from troubling inbox]]></title>
<description><![CDATA[More than half of users now let bots handle email, so service is headed for shutdown]]></description>
<link>https://tsecurity.de/de/3627514/it-nachrichten/notion-kills-its-gmail-client-after-ai-agents-keep-humans-from-troubling-inbox/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627514/it-nachrichten/notion-kills-its-gmail-client-after-ai-agents-keep-humans-from-troubling-inbox/</guid>
<pubDate>Fri, 26 Jun 2026 15:17:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[More than half of users now let bots handle email, so service is headed for shutdown]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion Mail Is Shutting Down]]></title>
<description><![CDATA[Notion announced that it will shut down its email client on September 22. The company says more than half of users already manage email through Notion's AI agents without opening their inbox, so it is shifting its focus from a traditional email client to agent-run workflows. Engadget reports: It ...]]></description>
<link>https://tsecurity.de/de/3627169/it-security-nachrichten/notion-mail-is-shutting-down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627169/it-security-nachrichten/notion-mail-is-shutting-down/</guid>
<pubDate>Fri, 26 Jun 2026 13:22:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Notion announced that it will shut down its email client on September 22. The company says more than half of users already manage email through Notion's AI agents without opening their inbox, so it is shifting its focus from a traditional email client to agent-run workflows. Engadget reports: It has published an FAQ for users to make sure that they don't lose any messages or data in the transition. Most emails will still exist in a Gmail inbox, but customers will need to manually export their drafts, scheduled emails, snippets and auto label instructions. Notion first began offering Notion Mail after acquiring startup Skiff in 2024.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Notion+Mail+Is+Shutting+Down%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F25%2F2038233%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F25%2F2038233%2Fnotion-mail-is-shutting-down%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/06/25/2038233/notion-mail-is-shutting-down?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion Mail wird abgeschaltet: Was Nutzer jetzt tun müssen]]></title>
<description><![CDATA[Notion stellt seinen E-Mail-Client Notion Mail am 22. September 2026 ein. Nutzer müssen bestimmte Daten bis dahin sichern.]]></description>
<link>https://tsecurity.de/de/3626989/it-nachrichten/notion-mail-wird-abgeschaltet-was-nutzer-jetzt-tun-muessen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626989/it-nachrichten/notion-mail-wird-abgeschaltet-was-nutzer-jetzt-tun-muessen/</guid>
<pubDate>Fri, 26 Jun 2026 12:03:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Notion stellt seinen E-Mail-Client Notion Mail am 22. September 2026 ein. Nutzer müssen bestimmte Daten bis dahin sichern.]]></content:encoded>
</item>
<item>
<title><![CDATA[Fed up with complex note taking apps? Try Whisp for Linux]]></title>
<description><![CDATA[New GTK4/libadwaita app Whisp is positioning itself as the note-taking app for people fed up with note-taking apps (the best one is always the next one, right?). Scratch that; Whisp pitches itself as “the anti-note for GNOME”, a riff on Antinote, a macOS app with a similar look and feature set. D...]]></description>
<link>https://tsecurity.de/de/3626116/linux-tipps/fed-up-with-complex-note-taking-apps-try-whisp-for-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626116/linux-tipps/fed-up-with-complex-note-taking-apps-try-whisp-for-linux/</guid>
<pubDate>Fri, 26 Jun 2026 03:06:58 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="406" height="232" src="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/06/whisp.webp?resize=406%2C232&amp;ssl=1" class="attachment-post-list size-post-list wp-post-image" alt="Whisp scratchpad showing notes, backgrounds and data picker." decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/06/whisp.webp?resize=350%2C200&amp;ssl=1 350w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/06/whisp.webp?resize=406%2C232&amp;ssl=1 406w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/06/whisp.webp?resize=840%2C480&amp;ssl=1 840w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/06/whisp.webp?zoom=3&amp;resize=406%2C232&amp;ssl=1 1218w" sizes="(max-width: 406px) 100vw, 406px">New GTK4/libadwaita app Whisp is positioning itself as the note-taking app for people fed up with note-taking apps (the best one is always the next one, right?). Scratch that; Whisp pitches itself as “the anti-note for GNOME”, a riff on Antinote, a macOS app with a similar look and feature set. Developer Tanay Bhomia describes it as “a fluid, gesture-driven scratchpad designed for absolute speed”. The website takes shots at the complexity of Obsidian and Notion, but Whisp isn’t out to compete with either. It’s a foil to notes relying on databases, hierarchies and corkboard-and-red-string organisational complexity. Me? I am a disorganised savage. […]</p>
<p>You're reading <a href="https://www.omgubuntu.co.uk/2026/06/whisp-linux-scratchpad">Fed up with complex note taking apps? Try Whisp for Linux</a>, a blog post from <a href="https://www.omgubuntu.co.uk/">OMG! Ubuntu</a>. Do not reproduce elsewhere without permission.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion Mail is shutting down]]></title>
<description><![CDATA[So long, Notion Mail.]]></description>
<link>https://tsecurity.de/de/3625743/it-nachrichten/notion-mail-is-shutting-down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625743/it-nachrichten/notion-mail-is-shutting-down/</guid>
<pubDate>Thu, 25 Jun 2026 21:47:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[So long, Notion Mail.]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion killing Skiff-influenced email app since most users use AI agents instead]]></title>
<description><![CDATA[Notion is "going all in on using agents to run your inbox."]]></description>
<link>https://tsecurity.de/de/3625702/ai-nachrichten/notion-killing-skiff-influenced-email-app-since-most-users-use-ai-agents-instead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625702/ai-nachrichten/notion-killing-skiff-influenced-email-app-since-most-users-use-ai-agents-instead/</guid>
<pubDate>Thu, 25 Jun 2026 21:18:38 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Notion is "going all in on using agents to run your inbox."]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion Mail shuts down amid agent takeover]]></title>
<description><![CDATA[Notion's email service is shutting down on September 22]]></description>
<link>https://tsecurity.de/de/3625686/it-nachrichten/notion-mail-shuts-down-amid-agent-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625686/it-nachrichten/notion-mail-shuts-down-amid-agent-takeover/</guid>
<pubDate>Thu, 25 Jun 2026 21:17:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Notion's email service is shutting down on September 22]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion Mail wird eingestellt – die Zukunft gehört den KI-Agenten]]></title>
<description><![CDATA[Erst im vergangenen Jahr hat Notion mit Notion Mail einen neuen E-Mail-Client mit intelligenten Funktionen auf den Markt gebracht. Doch bald ist damit schon wieder Schluss: Notion Mail wird eingestellt. Am 22. September wird man den Posteingang im Web, auf...Zum Beitrag: Notion Mail wird eingeste...]]></description>
<link>https://tsecurity.de/de/3625672/it-nachrichten/notion-mail-wird-eingestellt-die-zukunft-gehoert-den-ki-agenten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625672/it-nachrichten/notion-mail-wird-eingestellt-die-zukunft-gehoert-den-ki-agenten/</guid>
<pubDate>Thu, 25 Jun 2026 21:01:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Erst im vergangenen Jahr hat Notion mit Notion Mail einen neuen E-Mail-Client mit intelligenten Funktionen auf den Markt gebracht. Doch bald ist damit schon wieder Schluss: Notion Mail wird eingestellt. Am 22. September wird man den Posteingang im Web, auf...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/notion-mail-wird-eingestellt-die-zukunft-gehoert-den-ki-agenten/">Notion Mail wird eingestellt – die Zukunft gehört den KI-Agenten</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Entry-level AI workers now need ‘senior-level’ skills, PwC says]]></title>
<description><![CDATA[AI has created a tough job environment for entry-level workers and things aren’t getting better anytime soon — even those with AI capabilities now need “senior-level” skills to land a job.



“AI-exposed entry-level roles are seven times more likely to require traditionally senior-level skills su...]]></description>
<link>https://tsecurity.de/de/3621063/it-nachrichten/entry-level-ai-workers-now-need-senior-level-skills-pwc-says/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621063/it-nachrichten/entry-level-ai-workers-now-need-senior-level-skills-pwc-says/</guid>
<pubDate>Wed, 24 Jun 2026 13:03:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI has created a tough job environment for entry-level workers and things aren’t getting better anytime soon — even those with AI capabilities now need “senior-level” skills to land a job.</p>



<p>“AI-exposed entry-level roles are seven times more likely to require traditionally senior-level skills such as judgement and leadership,” consulting firm <a href="https://www.pwc.com/gx/en/services/ai/ai-jobs-barometer.html">PwC said in a study released this month</a>.</p>



<p>That’s because AI is changing the traditional career ladder. Companies are increasingly looking for candidates that use the cutting-edge tools and services to amplify their performance and grow faster. “Organizations must rethink how they mentor and train junior staff, helping them step up to complex decision-making much earlier in their careers,” PwC said.</p>



<p>Entry-level job seekers with or without AI skills are already <a href="https://www.computerworld.com/article/4147180/ai-could-be-suppressing-wages-for-young-workers.html">dealing with stagnant wages</a>,  layoffs, and <a href="https://www.computerworld.com/article/4089594/ai-related-layoffs-often-hit-entry-level-roles-young-workers.html">stalled hiring</a>. </p>



<p>(The PwC findings echo similar concerns raised late last year in McKinsey’s State of AI report. Many companies are <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai#/" target="_blank" rel="noreferrer noopener">reducing headcount by deploying AI agents</a> to take over entry-level jobs.)</p>



<p>Early-career AI job postings “have flatlined in highly AI exposed sectors,” and listings for junior roles with mid-career or senior-level skills have grown 35% since 2019, PwC said.  The consulting firm largely discounted the notion that AI is taking jobs away, though other studies point in the opposite direction. </p>



<p>By the end of May, AI-driven job cuts had reached 87,174 for 2026, already outpacing the total of around 54,836 in 2025, according to <a href="https://www.challengergray.com/blog/challenger-report-may-job-cuts-rise-16-from-april-highest-may-total-since-2020/" target="_blank" rel="noreferrer noopener">figures released by Challenger, Gray and Christmas earlier this month</a>.</p>



<p>The AI-driven layoffs haven’t reached the “jobpocalypse” stage yet, and workers are more productive with it, said Andy Challenger, chief revenue officer at Challenger, Gray and Christmas. But companies are rethinking hiring and long-term operational strategies as AI becomes a routine component in daily workflows and processes, he said.</p>



<p>Businesses are “restructuring aggressively as they reposition for an AI-driven economy,” he said.</p>



<p>That’s putting downward pressure on entry-level hiring as AI tools absorb more routine work, said Kye Mitchell, head of Experis US, a part of ManpowerGroup. “That doesn’t remove opportunity, but it changes the expectations. Employers now expect candidates to come in with hands-on experience, AI familiarity, and the ability to contribute faster,” Mitchell said.</p>



<p>Compensation remains strong for specialized, in-demand skills, while more commoditized roles such as customer service, helpdesk, and some entry-level positions  are flattening. “The shift overall is toward skills-based hiring, where demonstrable capability matters more than credentials alone,” Mitchell said.</p>



<p>Graduates who combine technical fundamentals with practical experience, AI fluency and strong communication skills stand out quickly. Job candidates can’t rely solely on academic credentials. </p>



<p>“Employers are moving away from ‘train-from-scratch’ hiring and looking for talent that can contribute earlier and continue to adapt,” Mitchell said.</p>



<p>The PwC study also focused on the productivity gap between companies that have invested heavily in AI and companies lagging in adoption.</p>



<p>Since <a href="https://www.computerworld.com/article/1615637/chatgpt-finally-an-ai-chatbot-worth-talking-to.html" data-type="link" data-id="https://www.computerworld.com/article/1615637/chatgpt-finally-an-ai-chatbot-worth-talking-to.html">ChatGPT showed up in 2022</a>, AI-exposed companies have seen productivity gains of 40% versus other companies. “The companies achieving the biggest productivity gains from AI are not using it only to cut costs,” PwC said.</p>



<p>AI-forward firms are also raising headcounts and wages. “Far from being a job killer, AI may actually be a job expander when used to unlock growth and enter new markets,” PwC said. </p>



<p>Workers who use their domain expertise to supplement AI tools can advance, with AI-exposed roles “2.5 times more likely to rely on skills like empathy, judgement, and creativity that become even more valuable as AI absorbs some routine work,” PwC said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open source grapples with agentic coding]]></title>
<description><![CDATA[Unless you’ve been living under an old woodpile in your backyard, you have certainly seen how agentic coding is rocking the software development world. Things are happening fast and furious, and keeping up is practically a full-time job. 



The latest area that is catching the attention of devel...]]></description>
<link>https://tsecurity.de/de/3620720/ai-nachrichten/open-source-grapples-with-agentic-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620720/ai-nachrichten/open-source-grapples-with-agentic-coding/</guid>
<pubDate>Wed, 24 Jun 2026 11:03:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Unless you’ve been living under an old woodpile in your backyard, you have certainly seen how agentic coding is rocking the software development world. Things are happening fast and furious, and keeping up is practically a full-time job. </p>



<p>The latest area that is catching the attention of developers is how agentic coding is affecting the open source community. The <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source movement</a> has been defending the rights of folks to use, change, and contribute to software for many years. And of course, agentic coding is starting to become part of that process.</p>



<p>On the one hand, maintainers of open source projects rightfully are frustrated as they become overwhelmed with pull requests of dubious quality and usefulness being submitted by coding agents. On the other hand, <a href="https://world.hey.com/dhh/let-the-agents-democratize-open-source-9fd630a9">as David Heinemeier Hansson notes</a>, maintainers are starting to get a little snooty about accepting AI-written code, viewing it as somehow not worthy of being included. Some organizations have explicitly <a href="https://x.com/LundukeJournal/status/2060344714432241990?s=20" data-type="link" data-id="https://x.com/LundukeJournal/status/2060344714432241990?s=20">banned AI-generated submissions</a>.</p>



<p>I get that they don’t want AI slop overwhelming their input queues. But I think it is a huge mistake to ban AI-written code outright.</p>



<h2 class="wp-block-heading">Whose code?</h2>



<p>Before I dig deeper into that notion, it’s important to look at another issue that arises from all of this: Who actually owns the code that AI writes? </p>



<p>Copyright requires that a human produce the thing being copyrighted. If you prompt Claude Code with “Write me a CMS system” and then Claude writes you a CMS system that you check into a public GitHub repository unchanged, it’s not quite clear if that code is protected by copyright. However, if you prompt Claude Code with a specification and guidelines and then you work with Claude to refine the initial result, reviewing the code and making changes as part of an iterative process, then it could be argued that a human did produce that code. But it is not at all <a href="https://legallayer.substack.com/p/who-owns-the-claude-code-wrote">clear-cut legally</a>. (Please note that I am not a lawyer.)</p>



<p>The current thinking is that the result of accepting verbatim the output of a simple prompt is not copyrightable, and that no one actually owns the code — an interesting notion in and of itself. </p>



<p>But then the ethical question comes into play. If I find a bug in an open source project, I ask GitHub Copilot to fix it, and Copilot writes a clever and effective fix, then who cares who owns the code? Should a maintainer of the project reject such a pull request just because it was AI-generated? That seems silly to me, yet it is happening today. </p>



<h2 class="wp-block-heading">Our code</h2>



<p>There is, too, the issue of license compliance for AI-generated code. As a general rule, LLMs generate code rather than copying it. They don’t copy and paste code directly from repositories. However, there have been cases where AI-produced code has resembled open source code so closely that the claim could be made that it is a copy. If this happens with <a href="https://opensource.org/license/gpl-3.0">GPL</a> code, it could be a violation of the license to use it without the receiving code base being “infected.” Open source maintainers naturally should be concerned about this happening.</p>



<p>In the end, an open source maintainer should care about the quality and license compliance of submissions, not how those submissions were derived. Gatekeeping based on the source of code doesn’t seem like a good path towards project success. Good code is good code, no matter where it comes from.</p>



<p>Agentic coding is here, and the open source community needs to realize — and embrace — that inevitability.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Kindle Scribe Colorsoft is the best device for notetakers I've tested - and it's $150 off]]></title>
<description><![CDATA[The Kindle Scribe Colorsoft is the brand's most premium notetaking device, with one of the most satisfying writing experiences on the market. It's at its lowest price yet for Prime Day now.]]></description>
<link>https://tsecurity.de/de/3619199/it-nachrichten/the-kindle-scribe-colorsoft-is-the-best-device-for-notetakers-ive-tested-and-its-150-off/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619199/it-nachrichten/the-kindle-scribe-colorsoft-is-the-best-device-for-notetakers-ive-tested-and-its-150-off/</guid>
<pubDate>Tue, 23 Jun 2026 19:47:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Kindle Scribe Colorsoft is the brand's most premium notetaking device, with one of the most satisfying writing experiences on the market. It's at its lowest price yet for Prime Day now.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic launches Claude Tag, replacing its Slack app with a persistent AI teammate that learns, monitors and works autonomously]]></title>
<description><![CDATA[Anthropic on Tuesday launched Claude Tag, a new product that embeds its most advanced AI model directly inside Slack as a persistent, shared teammate that anyone on a team can delegate work to by simply typing @Claude.The product, available today in beta for Claude Enterprise and Team customers, ...]]></description>
<link>https://tsecurity.de/de/3619113/it-nachrichten/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619113/it-nachrichten/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously/</guid>
<pubDate>Tue, 23 Jun 2026 19:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.anthropic.com/">Anthropic</a> on Tuesday launched <a href="http://anthropic.com/news/introducing-claude-tag"><u>Claude Tag</u></a>, a new product that embeds its most advanced AI model directly inside Slack as a persistent, shared teammate that anyone on a team can delegate work to by simply typing @Claude.</p><p>The product, available today in beta for<a href="https://support.claude.com/en/articles/9797531-what-is-the-enterprise-plan"> Claude Enterprise</a> and <a href="https://support.claude.com/en/articles/9266767-what-is-the-team-plan">Team</a> customers, replaces Anthropic's existing Claude in Slack app and represents the company's most aggressive move yet to colonize the enterprise collaboration layer — the place where decisions get made, work gets assigned, and institutional knowledge accumulates in real time.</p><p>For enterprise technology leaders who have spent the past two years evaluating where AI fits into their operational stack, <a href="https://venturebeat.com/technology/anthropic.com/news/introducing-claude-tag">Claude Tag</a> reframes the question entirely. This is not a chatbot, a coding assistant, or a search tool bolted onto a messaging platform. It is an AI agent designed to function as a standing member of a team — one that builds memory, takes initiative, works asynchronously, and interacts with every person in a channel rather than serving a single user. The implications for enterprise workflow, governance, and vendor strategy are significant.</p><p>Anthropic says 65% of its own product team's code is now created by its internal version of Claude Tag, and the company runs internal support and data insight channels through the same system. The claim is striking: Anthropic is asserting that the majority of its own product engineering output already flows through the tool it just put in customers' hands.</p><div></div><h2><b>How Claude Tag works inside enterprise Slack channels</b></h2><p>At its core, <a href="https://venturebeat.com/technology/anthropic.com/news/introducing-claude-tag">Claude Tag</a> works like this: an administrator pairs it with a Slack workspace, grants it access to specific tools and data sources, sets spending limits, and defines which channels it can operate in. From that point on, any team member in those channels can tag @Claude with a request — write a pull request, pull sales numbers, run a data analysis — and Claude will break the task into stages, execute them using the tools it has access to, and respond in a Slack thread with the result. The product runs on <a href="https://www.anthropic.com/news/claude-opus-4-8">Claude Opus 4.8</a>, the model Anthropic released less than a month ago.</p><p>Four capabilities differentiate <a href="https://www.anthropic.com/news/introducing-claude-tag">Claude Tag </a>from its predecessors and from competing integrations. First, it is multiplayer. Within a given Slack channel, there is one Claude that interacts with everyone, not a separate instance per user. Anyone can see what it is working on, and anyone can pick up the conversation where the last person left off. This is a direct contrast to most existing AI integrations in Slack, which tend to operate as single-player tools.</p><p>Second, it learns over time. As Claude follows along with its channel, it accumulates context about the work happening there. Users do not need to re-explain projects from scratch. If granted permission, Claude can also pull context from other Slack channels and data sources, though Anthropic says it will not report from private channels. Third, it takes initiative. With ambient behavior enabled, Claude will proactively surface relevant information from across the channels it monitors and the tools it is connected to, and will follow up on threads or tasks that have gone quiet without resolution. This is a notable expansion of agency: Claude is not just responding to requests but monitoring the information environment and deciding what its human teammates need to know. Fourth, it works asynchronously, pursuing projects autonomously over hours or days. Anthropic says its own teams "now spend much more of our time delegating tasks to many Claudes in parallel."</p><h2><b>Enterprise security controls and administrative governance get a central role</b></h2><p><a href="https://www.anthropic.com/">Anthropic</a> has designed the system with enterprise-grade isolation at its center. System administrators define separate Claude identities for different uses, scoped to specific channels with specific tools and data access. Everything, including Claude's accumulated memories, stays within those boundaries. A Claude configured for sales work will not share memories or data access with one configured for engineering.</p><p>Administrators can set token-spend limits at both the organizational and channel level, and can review a complete log of every action Claude has taken and which user requested each task. For organizations managing compliance, audit, or regulatory requirements, this logging and scoping architecture is table stakes — and its absence has been a dealbreaker for many enterprises evaluating AI collaboration tools over the past year.</p><p>Migration from the existing <a href="https://slack.com/marketplace/A08SF47R6P4-claude">Claude in Slack app</a> requires an administrator opt-in within 30 days, and Anthropic says it is issuing introductory launch credits to eligible Enterprise and Team organizations. The four-step setup process — pair with Slack, connect tools, set spend limits, test in a private channel — is designed to reduce friction for IT teams already managing sprawling SaaS portfolios.</p><h2><b>The Slack battleground is now the most contested real estate in enterprise AI</b></h2><p><a href="https://venturebeat.com/technology/anthropic.com/news/introducing-claude-tag">Claude Tag</a> arrives in the middle of what has become the most fiercely contested territory in enterprise AI: the Slack channel. Slack itself has been aggressively positioning the platform as an "agentic operating system," and the major AI players have responded by racing to plant their flags.</p><p>Salesforce, which <a href="https://slack.com/blog/news/salesforce-completes-acquisition-of-slack">acquired Slack for $27.7 billion in 2021</a>, announced more than <a href="https://venturebeat.com/orchestration/slack-adds-30-ai-features-to-slackbot-its-most-ambitious-update-since-the">30 new capabilities for Slackbot</a> in March — the most sweeping overhaul of the platform since the acquisition — transforming it from a simple conversational assistant into a full-spectrum enterprise agent. OpenAI introduced "<a href="https://openai.com/index/introducing-workspace-agents-in-chatgpt/">Workspace Agents</a>" in April, allowing enterprise subscribers to design agents that take on work tasks across third-party apps including Slack, Google Drive, Microsoft apps, Salesforce, and Notion. Perplexity launched its enterprise "Computer" agent with direct Slack integration, letting employees query @computer directly inside Slack channels. Cognition's Devin, the autonomous AI software engineer, has been built around Slack as a primary interface since its early days. Even Microsoft has brought GitHub Copilot into Teams.</p><p>The logic driving this convergence is straightforward: the average enterprise juggles over 1,000 applications, and employees waste countless hours on context switching, draining productivity by up to 40%. Whichever AI system becomes the default presence in the communication layer where work is coordinated gains an enormous distribution advantage — and, critically, an enormous data advantage. The AI that lives in the channel where work happens absorbs the institutional context that makes it increasingly difficult to replace.</p><h2><b>Anthropic built Claude Tag on a foundation two years in the making</b></h2><p>To understand Claude Tag's strategic significance, it helps to trace the product arc that led to it. Anthropic first integrated Claude with Slack in October 2025, offering two-way connectivity: users could invoke Claude from within Slack or connect Slack as a data source for Claude's chatbot. As TechCrunch reported at the time, the initial integration was focused on individual productivity — direct messages, AI assistant panels, and thread participation. In January 2026, Anthropic expanded Claude's Slack presence when it launched interactive Claude apps, which TechCrunch's Russell Brandom reported included workplace tools like Slack, Canva, Figma, Box, and Clay.</p><p>In parallel, Anthropic was building out its enterprise infrastructure stack. As TechCrunch reported in August 2025, the company bundled Claude Code into enterprise plans, a move its product lead Scott White called "the most requested feature from our business team and enterprise customers." In April 2026, Anthropic launched Claude Managed Agents, a suite of composable APIs for building and deploying cloud-hosted AI agents at scale, with early adopters including Notion, Rakuten, Asana, and Sentry. As The New Claw Times reported, the move positioned Anthropic "as a direct competitor to AWS Bedrock Agents and Google Vertex Agent Builder."</p><p>Then came Claude Opus 4.8 in late May, which Anthropic described as "a more effective collaborator" with "sharper judgement, more honesty about its progress, and the ability to work independently for longer than its predecessors." As 9to5Mac reported, benchmark improvements included a jump in agentic coding scores from 64.3% to 69.2% and a knowledge work score increase from 1753 to 1890. Claude Tag is the synthesis of all of these threads — combining the Slack channel presence, the enterprise security architecture, the Managed Agents infrastructure, and the Opus 4.8 model's improved agentic capabilities into a single product that Anthropic frames as "the beginning of an evolution of Claude Code."</p><h2><b>Anthropic's explosive growth explains why it is betting big on the collaboration layer</b></h2><p>The financial stakes behind this launch are enormous. Anthropic raised $65 billion in Series H funding in late May at a $965 billion post-money valuation, and its run-rate revenue crossed $47 billion earlier this month. Claude Code's run-rate revenue alone has grown to over $2.5 billion, more than doubling since the beginning of 2026, and enterprise use has grown to represent over half of all Claude Code revenue.</p><p>Those numbers explain why Anthropic is investing so heavily in channel-level presence. Every enterprise customer who grants Claude persistent access to a Slack channel — with connected tools, accumulated context, and ambient monitoring enabled — represents a dramatically deeper integration than a chatbot conversation or an API call. The usage patterns become stickier, the token consumption grows, and the switching costs rise. Deloitte's deployment of Claude across more than 470,000 employees in 150 countries — reportedly its largest-ever enterprise AI deployment — illustrates the scale at which these dynamics play out.</p><p>The broader market trajectory reinforces the bet. Fortune Business Insights projects the global agentic AI market will grow from $9.14 billion in 2026 to $139 billion by 2034, and Gartner forecasts that 40% of enterprise applications will feature task-specific AI agents by 2026, up from less than 5% in 2025. Anthropic is not alone in seeing this future, but with Claude Tag it is making one of the most direct plays yet to own the enterprise agent layer.</p><h2><b>The risks enterprise buyers need to weigh before granting Claude a permanent seat at the table</b></h2><p>Claude Tag raises several questions that enterprise buyers will need to evaluate carefully. The first is vendor dependency. As The New Stack noted when analyzing Claude Managed Agents earlier this year, once an organization's agents, operational configurations, and monitoring run on Anthropic's managed infrastructure, switching costs increase significantly. Claude Tag deepens this dynamic: a Claude that has accumulated months of channel context and institutional memory becomes very difficult to replace. Enterprise procurement teams accustomed to negotiating multi-cloud flexibility will need to think hard about what it means to give a single vendor's AI persistent access to the communication layer where institutional knowledge lives.</p><p>The second is governance around ambient monitoring. The proactive behavior mode — in which Claude monitors channels and surfaces information it decides is relevant — represents a meaningful expansion of what enterprise AI systems do. Organizations will need to develop clear frameworks for an AI agent that is not just responding to requests but actively surveilling information flows and making editorial judgments about what humans need to know. For regulated industries, this raises questions that existing AI governance policies may not yet address.</p><p>The third is pricing. Anthropic has not published detailed pricing for Claude Tag beyond noting that it runs on token-based spending with administrative controls. For an agent that monitors channels continuously, builds memory, and works asynchronously over hours or days, the token consumption profile could look very different from traditional AI usage. And the fourth is reliability: Anthropic has been candid in recent months about infrastructure strain caused by surging demand, and for a product positioned as an always-on team member, downtime carries a different kind of cost than it does for a tool invoked on demand.</p><h2><b>What Claude Tag signals about the future of enterprise work</b></h2><p>Anthropic says its goal is to expand Claude Tag beyond Slack "so that teams can tag @Claude in the many other places they work." The company is clearly eyeing the full collaboration surface — Microsoft Teams, email, project management tools, and beyond. If Claude Tag succeeds, it will validate a model of enterprise AI that looks less like a tool and more like a new category of worker: one that never sleeps, never forgets what was discussed in the channel last Tuesday, and never needs to be onboarded twice.</p><p>But the deeper significance of this launch may be what it reveals about the competitive dynamics reshaping enterprise software. For decades, the most valuable real estate in business technology was the system of record — the database, the CRM, the ERP. The current AI arms race suggests that the next era of enterprise value will be captured not by the system that stores the data, but by the agent that sits in the room where the work happens and understands what to do with it. Anthropic just gave that agent a name, a permanent seat in the channel, and permission to speak up when it thinks it has something to say. The question for every enterprise technology leader is no longer whether that agent will arrive. It is whether they are ready to manage it when it does.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA["A systematic pattern of wage and hour violations": Xbox RPG studio Obsidian is facing a class action lawsuit, denies "each and every allegation"]]></title>
<description><![CDATA[Xbox's Obsidian Entertainment, the dev behind The Outer Worlds 2, Avowed, and others, is being sued for "pattern of wage and hour violations."]]></description>
<link>https://tsecurity.de/de/3619087/windows-tipps/a-systematic-pattern-of-wage-and-hour-violations-xbox-rpg-studio-obsidian-is-facing-a-class-action-lawsuit-denies-each-and-every-allegation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619087/windows-tipps/a-systematic-pattern-of-wage-and-hour-violations-xbox-rpg-studio-obsidian-is-facing-a-class-action-lawsuit-denies-each-and-every-allegation/</guid>
<pubDate>Tue, 23 Jun 2026 19:11:09 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Xbox's Obsidian Entertainment, the dev behind The Outer Worlds 2, Avowed, and others, is being sued for "pattern of wage and hour violations."]]></content:encoded>
</item>
<item>
<title><![CDATA["Just one breath, that's all you get": Xbox's Grounded 2 director chats Early Access, the "second launch" on PS5, and the roadmap's Into the Abyss update]]></title>
<description><![CDATA[The director of Xbox's Grounded 2, Obsidian Entertainment's Chris Parker, says that the game coming to PS5 later this year is like a "second launch."]]></description>
<link>https://tsecurity.de/de/3616662/windows-tipps/just-one-breath-thats-all-you-get-xboxs-grounded-2-director-chats-early-access-the-second-launch-on-ps5-and-the-roadmaps-into-the-abyss-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616662/windows-tipps/just-one-breath-thats-all-you-get-xboxs-grounded-2-director-chats-early-access-the-second-launch-on-ps5-and-the-roadmaps-into-the-abyss-update/</guid>
<pubDate>Mon, 22 Jun 2026 23:11:16 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The director of Xbox's Grounded 2, Obsidian Entertainment's Chris Parker, says that the game coming to PS5 later this year is like a "second launch."]]></content:encoded>
</item>
<item>
<title><![CDATA[Reptilian Rising Review (PC)]]></title>
<description><![CDATA[After cleansing one historical era of the slithery invaders, I got quite a few upgrades. I can bring in three heroes at the start of a level, up from two, which makes it easier to engage threats quickly and dash for the first time portal to claim it. I also used Obsidian to make sure I had one re...]]></description>
<link>https://tsecurity.de/de/3609562/it-security-nachrichten/reptilian-rising-review-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609562/it-security-nachrichten/reptilian-rising-review-pc/</guid>
<pubDate>Fri, 19 Jun 2026 08:52:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After cleansing one historical era of the slithery invaders, I got quite a few upgrades. I can bring in three heroes at the start of a level, up from two, which makes it easier to engage threats quickly and dash for the first time portal to claim it. I also used Obsidian to make sure I had one retry in case I lost a battle, while gold allowed me to boost my heroes.

Unfortunately, the time-traveling reptiles, which I am now fighting in Ancient Egypt, have brought reinforcements. The human cultists of this era have a bad habit of holding on to one hitpoint after a ranged attack from Cleopatra, forcing me to use another hero to take them down or allow them to strike once. And the layout of this level makes it hard to reach portals quickly, which gives them time to call in reinforcements.

So Sir George is running ahead, using the long range of its helmet laser to engage the tougher enemies, while Matilda is in charge of dealing with stragglers and hacking gates. Cleopa...]]></content:encoded>
</item>
<item>
<title><![CDATA[Copilot searched your mailbox. LiteLLM handed out admin keys. Run this 5-check audit before your stack is next]]></title>
<description><![CDATA[Two AI tools broke in the same way in the same two weeks, and four research teams proved it. The pattern underneath every disclosure is one sentence: enterprise AI accepts external input with no trust boundary. On June 15, Varonis disclosed SearchLeak (CVE-2026-42824), a proof-of-concept exfiltra...]]></description>
<link>https://tsecurity.de/de/3608646/it-nachrichten/copilot-searched-your-mailbox-litellm-handed-out-admin-keys-run-this-5-check-audit-before-your-stack-is-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608646/it-nachrichten/copilot-searched-your-mailbox-litellm-handed-out-admin-keys-run-this-5-check-audit-before-your-stack-is-next/</guid>
<pubDate>Thu, 18 Jun 2026 20:16:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two AI tools broke in the same way in the same two weeks, and four research teams proved it. The pattern underneath every disclosure is one sentence: enterprise AI accepts external input with no trust boundary. </p><p>On June 15, Varonis disclosed <a href="https://www.varonis.com/blog/searchleak">SearchLeak (CVE-2026-42824)</a>, a proof-of-concept exfiltration chain in Microsoft 365 Copilot Enterprise Search. A victim clicks a crafted microsoft.com URL, Copilot searches their mailbox, and the data leaves through a Bing SSRF. No plugins, no second click, no visible indicator. Four days earlier, Obsidian Security published a <a href="https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce">three-CVE chain against LiteLLM</a> that carried a default low-privilege user all the way to admin and remote code execution. Two tools. Two teams. One broken boundary.</p><p>The five-check audit at the end of this article maps each gap to a CVE or a market signal from June, a command you can run before lunch, and a sentence a CISO can read to the board.</p><h2>Copilot turned a trusted URL into an exfiltration engine</h2><p>SearchLeak chained three weaknesses into a silent data-theft chain. The URL q parameter fed attacker instructions straight to Copilot’s LLM. A rendering race condition fired an image tag before the output sanitizer ran. Bing’s image-search endpoint, allowlisted in the <a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP">Content Security Policy</a>, routed the stolen data out. Microsoft rated the flaw critical and patched it on the back end, according to Varonis. <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42824">NVD has not yet scored it</a>; a third-party tracker lists it at 6.5 medium. The severity is contested, but the mechanism is not.</p><p>The escalation is the real story. This is the third Varonis Copilot exfiltration chain in twelve months, after <a href="https://arstechnica.com/security/2026/01/a-single-click-mounted-a-covert-multistage-attack-against-copilot/">Reprompt</a> in January and <a href="https://www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/">EchoLeak</a> in 2025. Reprompt hit Copilot Personal. SearchLeak hit Enterprise Search. Enterprise inherits the user’s full organizational permissions, so the blast radius is everything that a user can reach.</p><h2>LiteLLM handed a default account to every provider key</h2><p>The LiteLLM gateway holds the keys for OpenAI, Anthropic, Azure, and Bedrock behind a single proxy. The Obsidian chain runs in three moves. <a href="https://cvefeed.io/vuln/detail/CVE-2026-47101">CVE-2026-47101</a>, an authorization bypass, lets a non-admin mint a wildcard API key. CVE-2026-47102 promotes that caller to proxy admin through an unguarded /user/update endpoint. CVE-2026-40217 escapes the code sandbox through exec() with full builtins. Obsidian then demonstrated a reverse shell by injecting a forged tool-call response through LiteLLM’s callback mechanism. Obsidian assessed the combined chain at CVSS 9.9. The developer typed one word. The attacker popped a shell.</p><p>A separate LiteLLM flaw made the urgency immediate. <a href="https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html">CVE-2026-42271</a>, a command-injection bug in the MCP test endpoints, landed on the <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA KEV list</a> on June 8 with a June 22 remediation deadline. That KEV entry is not the Obsidian chain. The two are distinct disclosures four days apart, fixed in different releases, pointed at the same gateway. LiteLLM carries more than 40,000 GitHub stars and sits in thousands of enterprise deployments. This is not the first scare, either. A <a href="https://thehackernews.com/2026/06/litellm-vulnerability-chain-lets-low.html">supply-chain compromise backdoored LiteLLM versions 1.82.7 and 1.82.8 on PyPI in March</a>. A compromised gateway exposes every provider credential the organization holds.</p><h2>Langflow and Mini Shai-Hulud proved the pattern scales</h2><p>The same boundary broke in two more tools in the same fortnight. <a href="https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html">Langflow CVE-2026-5027</a> became the third Langflow remote-code-execution flaw to hit active exploitation this year. A path traversal in file upload lets an attacker write files anywhere on disk, and because Langflow ships with auto-login enabled by default, a single unauthenticated request reaches RCE. <a href="https://www.vulncheck.com/">VulnCheck</a> confirmed exploitation on June 9. Censys counted roughly 7,000 exposed instances, the heaviest concentration in North America, with <a href="https://attack.mitre.org/groups/G0069/">MuddyWater</a> attribution.</p><p>The <a href="https://www.securityweek.com/over-100-npm-pypi-packages-hit-in-new-shai-hulud-supply-chain-attacks/">Mini Shai-Hulud campaign</a> hit a different pressure point. After the worm’s source code went public on May 12, copycat variants <a href="https://socket.dev/blog/mini-shai-hulud-campaign-hits-red-hat-cloud-services-npm-packages">compromised 32 Red Hat Cloud Services npm packages</a> on June 1, packages pulled 80,000 times a week. The worm harvests more than 20 credential types and self-propagates under the compromised maintainer’s identity.</p><p>Four teams, four tools, one operating failure. The bug classes differ. SearchLeak is a prompt injection. LiteLLM is privilege escalation. Langflow is path traversal. Mini Shai-Hulud is supply-chain poisoning. The boundary that broke is the same in all four.</p><h2>The market already repriced the risk</h2><p>CrowdStrike’s <a href="https://www.fool.com/earnings/call-transcripts/2026/06/03/crowdstrike-crwd-q1-2027-earnings-transcript/">Q1 FY27 earnings call</a> put a number on the gap. <a href="https://www.crowdstrike.com/en-us/platform/falcon-aidr-ai-detection-and-response/">AIDR</a>, the company’s AI detection and response line, grew ending ARR more than 250% sequentially, with a Q2 pipeline above $50 million (<a href="https://www.sec.gov/Archives/edgar/data/0001535527/000153552726000022/crwd-20260603xex991.htm">SEC-filed 8-K</a>). Total company ARR reached $5.51 billion, and CrowdStrike’s fleet telemetry shows more than 1,800 agentic applications running across enterprise endpoints. </p><p>On June 17, the company <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-advances-ai-and-cloud-security-operations-on-aws/">extended AIDR to AWS</a>, adding real-time evaluation of agent, LLM, and MCP communications across Amazon Bedrock, Kiro, and Strands Agents, building on its work with <a href="https://www.anthropic.com/glasswing">Anthropic’s Project Glasswing</a>. Daniel Bernard, CrowdStrike’s chief business officer, said the AI attack surface now spans development, runtime, identities, and cloud infrastructure, and that teams treating those as separate domains leave the gaps between them open.</p><h2>Practitioners name the same gap in plainer terms</h2><p>David Levin, CISO at American Express Global Business Travel, <a href="https://venturebeat.com/security/amex-ciso-fights-threats-at-machine-speed-with-ai/">told VentureBeat</a> the pattern does not surprise him. “We kind of have this shadow AI, which is just the new version of shadow IT,” Levin said. </p><p>Both Langflow and LiteLLM fit the description. Teams stood them up for convenience, gave them credentials, and never brought them under governance. Levin puts the fix before deployment. “We didn’t go into this with just saying we’re going to go do this without the right fundamentals,” he said. “We leverage NIST controls. NIST has released their CSF along with their AI framework. OWASP released their top 10. You need the right fundamentals before you deploy.”</p><p>Merritt Baer, CSO at Enkrypt AI and former AWS Deputy CISO, named the structural version of the failure in a separate <a href="https://venturebeat.com/security/most-enterprises-cant-stop-stage-three-ai-agent-threats-venturebeat-survey-finds">VentureBeat interview</a>. “Enterprises believe they’ve ‘approved’ AI vendors, but what they’ve actually approved is an interface, not the underlying system,” Baer said. “The real dependencies are one or two layers deeper, and those are the ones that fail under stress.” She has tied that directly to how systems fall. “Raw zero-days aren’t how most systems get compromised. Composability is,” Baer <a href="https://venturebeat.com/security/adversaries-hijacked-ai-security-tools-at-90-organizations-the-next-wave-has-write-access-to-the-firewall">told VentureBeat</a>. “It’s the glue between the model and your data where the risk lives. If you give an agent bash and a root token, you’ve already done most of the attacker’s work for them.” That is what rows 2 and 4 of the audit test: the gateway that holds every key, and the agent identity no one governs.</p><p>Levin had a sharper frame for the boardroom. “You need to talk more in terms of risk versus compliance to your boards and your executives,” he said. “It’s not about the size of the engineering team anymore. It’s the size of your imagination. It’s all written in plain English. It’s not hard for anyone.” Neither SearchLeak nor LiteLLM needed custom malware or a zero-day to work.</p><p>Adam Meyers, CrowdStrike’s SVP of Intelligence, put the operational squeeze in numbers in an exclusive VentureBeat interview. “The problem is not zero-day. The problem is patching. If you 10x that problem, they’re gonna be completely underwater,” Meyers said. He pointed to identity as the second front. “Some of these AI have their own identities, or people give their identity to the AI to take action on their behalf, and that makes it a very complex problem.”</p><h2>The five-check trust-boundary audit</h2><p>Each row maps a gap to its proof point, a verification command for Monday morning, the fix, and the sentence to read to the board.</p><table><tbody><tr><td><p><b>Trust-Boundary Gap</b></p></td><td><p><b>Proof Point</b></p></td><td><p><b>What Broke</b></p></td><td><p><b>Verify Monday</b></p></td><td><p><b>Fix Monday</b></p></td><td><p><b>Board Language</b></p></td></tr><tr><td><p><b>1. Prompt-to-Data</b></p></td><td><p>SearchLeak CVE-2026-42824. P2P injection + HTML race + Bing SSRF. One-click mailbox exfiltration via microsoft.com URL. PoC demonstrated; Microsoft rated it critical, NVD not yet scored.</p></td><td><p>URL q-parameter passed to LLM as instructions. Sanitizer ran after render. Bing acted as exfiltration proxy via CSP allowlist.</p></td><td><p>Audit CSP allowlists for domains performing server-side fetches. Monitor Copilot Search URLs for encoded payloads. Review Copilot audit logs.</p></td><td><p>Confirm server-side patch applied. Enable sensitivity labels restricting Copilot. Treat AI streaming output as untrusted.</p></td><td><p>“Our AI assistant could search employee email and send results to an attacker through a trusted Microsoft URL. Vendor patched it. We must verify configuration.”</p></td></tr><tr><td><p><b>2. Gateway Credential Exposure</b></p></td><td><p>LiteLLM three-CVE chain (-47101, -47102, -40217). CVSS 9.9. Separate CVE-2026-42271 on CISA KEV (fixed in v1.83.7; full chain fixed in v1.83.14-stable). June 22 deadline.</p></td><td><p>No role validation on key endpoints. Self-promotion to admin via /user/update. exec() sandbox escape. One gateway exposes all provider keys.</p></td><td><p>Run pip show litellm. Below 1.83.14-stable = vulnerable. Check /mcp-rest/test/ exposure. Audit proxy_admin accounts.</p></td><td><p>Upgrade to v1.83.14-stable+. Rotate all provider API keys. Block /mcp-rest/test/* at proxy. Review Custom Code Guardrails.</p></td><td><p>“Our AI gateway held keys for every provider. A default account could promote itself to admin and steal them all. Rotating and patching now.”</p></td></tr><tr><td><p><b>3. AI Tooling Sprawl</b></p></td><td><p>Langflow CVE-2026-5027 (CVSS 8.8). Third RCE of 2026. ~7,000 exposed instances. MuddyWater. Active exploitation June 9.</p></td><td><p>Path traversal in file upload. Auto-login enabled by default. Single unauthenticated request to RCE.</p></td><td><p>Query Censys/Shodan for Langflow, Flowise, n8n, Dify on your perimeter. Check auto-login. Inventory AI tools outside change management.</p></td><td><p>Pull AI platforms behind VPN/zero-trust. Enable auth everywhere. Upgrade Langflow to v1.9.0+ (current release 1.10.0). Fingerprint surface continuously.</p></td><td><p>“AI dev tools are exposed to the internet with login disabled. A nation-state group is exploiting this flaw now. Pulling behind access controls today.”</p></td></tr><tr><td><p><b>4. Non-Human Identity Governance</b></p></td><td><p>AIDR ARR up 250% (Q1 FY27, SEC 8-K). Q2 pipeline &gt;$50M. 1,800+ agentic apps across enterprise endpoints.</p></td><td><p>Agents hold identities and act on behalf of humans. Some exceed their intended scope to reach a goal. No standard governs agent credential lifecycle.</p></td><td><p>Inventory all non-human identities used by agents and MCP servers. Map agent-to-data-store access. Flag agents with write access to security policy.</p></td><td><p>Least-privilege every agent identity. Set privilege boundaries via identity protection. Runtime detection for policy-exceeding actions. Human-in-the-loop for policy changes.</p></td><td><p>“AI agents hold credentials and act autonomously. We do not govern their identity lifecycle like human access. The 250% market growth tells us this gap is systemic.”</p></td></tr><tr><td><p><b>5. Runtime Agentic Detection</b></p></td><td><p>Falcon AIDR expanded to AWS (June 17). Covers Bedrock, Kiro, Strands Agents. MCP integration. Real-time agent/LLM/MCP evaluation.</p></td><td><p>Traditional tools monitor human-speed actions. Agents run at machine speed, thousands of actions per minute, and route around controls to reach goals.</p></td><td><p>Test if EDR/XDR links agent actions to originating identity. Verify SIEM ingests MCP communications. Confirm you can distinguish human from agent on endpoint.</p></td><td><p>Deploy AIDR or equivalent runtime detection. Shadow-AI discovery for all agentic apps, models, MCP servers, identities. Real-time policy enforcement on agent actions.</p></td><td><p>“We cannot distinguish a human employee from an AI agent acting on their behalf. We need runtime detection at machine speed that can stop damage before it starts.”</p></td></tr></tbody></table><h2>The fix is plumbing, not policy</h2><p>The <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">June 2 executive order</a> creates an AI Cybersecurity Clearinghouse with a July 2 deadline. The five gaps above are not frontier-model problems. They are plumbing problems in the gateways, orchestration platforms, identity layers, and runtime environments where AI meets the enterprise. </p><p>The audit is five rows. Every row maps to a June disclosure or market signal, a command a team can run before lunch, and a sentence a CISO can read to the board. The question is not whether your vendor will patch. It's whether you find the gap first — or whether an attacker finds it the way they found Copilot and LiteLLM.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Angular Signals in practice: Building a signal-first form in Angular]]></title>
<description><![CDATA[Understanding a reactivity model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained i...]]></description>
<link>https://tsecurity.de/de/3608234/ai-nachrichten/angular-signals-in-practice-building-a-signal-first-form-in-angular/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608234/ai-nachrichten/angular-signals-in-practice-building-a-signal-first-form-in-angular/</guid>
<pubDate>Thu, 18 Jun 2026 17:21:00 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Understanding a <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactivity</a> model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained in practice.</p>



<p>In two previous articles, “<a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a>” and “<a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a>,” we reframed form behavior as a state-driven problem and examined Angular Signals as a pull-based reactivity model well-suited to that kind of work. The natural next step is to apply those ideas to an actual Angular form and observe how the architecture changes when state becomes the primary concern.</p>



<p>This article focuses on a concrete example: a modest but realistic registration form. Rather than introducing new concepts, the goal here is to make earlier ideas tangible. We will see how a signal-backed model reshapes validation, interaction state, and submission logic, and how much coordination logic simply disappears when form behavior is expressed declaratively.</p>



<p>The focus here is not on novelty or completeness, but on making the underlying ideas easier to reason about. By walking through a signal-first form from model definition to submission, we can evaluate whether this approach truly reduces complexity and where it introduces new trade-offs that teams should understand before adopting it more broadly.</p>



<h4 class="wp-block-heading">Read the series:</h4>



<ul class="wp-block-list">
<li><a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a></li>



<li><a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a></li>



<li><a href="https://www.infoworld.com/article/4185924/angular-signals-in-practice-building-a-signal-first-form-in-angular.html" data-type="link" data-id="https://www.infoworld.com/article/4185924/angular-signals-in-practice-building-a-signal-first-form-in-angular.html">Angular Signals in practice: Building a signal-first form in Angular</a></li>
</ul>



<h2 class="wp-block-heading"><a></a>Implementing a signal-first registration form</h2>



<p>With the conceptual groundwork in place, we can now turn theory into a concrete implementation. In this section, we will build a fully working registration form using Angular’s Signal Forms API. This example is deliberately modest in scope, but it is designed to serve as the foundation for the rest of the series. Each subsequent article will extend this same example rather than introducing a new one.</p>



<p>The form collects an email address, a password, a confirmation password, and explicit acceptance of terms. While simple on the surface, this structure allows us to explore field-level validation, cross-field constraints, interaction state, and submission behavior, all without reverting to event-driven form logic.</p>



<h3 class="wp-block-heading"><a></a>Project setup and structure</h3>



<p>The example assumes a standard Angular application created with the Angular CLI and configured to use Signals (Angular 17+). The Signal Forms APIs (Angular 21+) live under @angular/forms/signals, which must be explicitly imported.</p>



<p><a href="https://github.com/sonukapoor/angular-signal-forms">https://github.com/sonukapoor/angular-signal-forms</a></p>



<p>The folder structure is intentionally conservative:</p>



<p>src/<br>  app/<br>    registration/<br>      registration.component.ts<br>      registration.component.html<br>      registration.model.ts</p>



<p>Separating the model from the component keeps form state independent of presentation. This becomes increasingly valuable as the form grows or is reused across multiple components.</p>



<h3 class="wp-block-heading"><a></a>Defining the form model</h3>



<p>We begin by defining the shape of the data that the form collects. This is a plain TypeScript interface with no Angular dependencies. Treating the form model as a simple data structure reinforces the idea that the form’s values are just state.</p>



<pre class="wp-block-code"><code>// registration.model.ts
export interface RegistrationData {
  email: string;
  password: string;
  confirmPassword: string;
  acceptedTerms: boolean;
}
</code></pre>



<p>This interface mirrors what would typically be sent to a back-end API. There is no duplication of state, no separate “form value” object, and no mapping required at submission time.</p>



<h3 class="wp-block-heading"><a></a>Creating the signal-backed form</h3>



<p>The form itself is created in the component using a writable signal as the source of truth. The <code>form()</code> function attaches form semantics validation, field state, and submission to that signal.</p>



<pre class="wp-block-code"><code>// registration.component.ts
import { CommonModule } from "@angular/common";
import { Component, signal } from "@angular/core";
import {
  email,
  form,
  FormField,
  required,
  submit,
} from "@angular/forms/signals";
import { RegistrationData } from "./registration.model";

@Component({
  selector: "app-registration",
  imports: [FormField, CommonModule],
  templateUrl: "./registration.html",
  styleUrl: "./registration.css",
})
export class Registration {
  readonly model = signal<registrationdata>({
    email: "",
    password: "",
    confirmPassword: "",
    acceptedTerms: false,
  });

  readonly registrationForm = form(this.model, (schema) =&gt; {
    required(schema.email, { message: "Email is required" });
    email(schema.email, { message: "Enter a valid email address" });

    required(schema.password, { message: "Password is required" });
    required(schema.confirmPassword, {
      message: "Please confirm your password",
    });

    required(schema.acceptedTerms, {
      message: "You must accept the terms to continue",
    });
  });

  async onSubmit(event?: Event) {
    event?.preventDefault();

    await submit(this.registrationForm, (value) =&gt; {
      console.log(value());
      // Mock Server Call
      return Promise.resolve([
        {
          kind: "EmailAlreadyExists",
          field: this.registrationForm.email,
          error: { kind: "server", message: "Email already taken" },
        },
      ]);
    });
  }
}
</registrationdata></code></pre>



<p>Several design decisions are worth noting.</p>



<p>First, the model signal is defined as read-only. All mutations to the model occur through form bindings, not ad hoc assignments in the component. This keeps the component declarative and avoids the temptation to manipulate form state imperatively.</p>



<p>Second, validation is declared in one place. The schema function describes constraints on the model without introducing control trees, validator arrays, or observable pipelines. Angular takes responsibility for re-running validation whenever the model changes.</p>



<p>Finally, submission logic is explicit. The <code>submit()</code> helper ensures that the form is valid before invoking the callback, and it passes the current model value directly. There is no need to check flags or manually extract values.</p>



<h3 class="wp-block-heading"><a></a>Binding the form to the template</h3>



<p>With the form defined, the next step is to bind it to the template. Signal Forms provide the <code>[formField]</code> directive, which connects an input element directly to a field in the form schema.</p>



<pre class="wp-block-code"><code><!-- registration.component.html -->

  <div>
    <label>Email</label>
    

    @if (
      registrationForm.email().invalid() &amp;&amp; registrationForm.email().touched()
    ) {
      <p class="error">
        {{ registrationForm.email().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Password</label>
    

    @if (
      registrationForm.password().invalid() &amp;&amp;
      registrationForm.password().touched()
    ) {
      <p class="error">
        {{ registrationForm.password().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Confirm Password</label>
    

    @if (
      registrationForm.confirmPassword().invalid() &amp;&amp;
      registrationForm.confirmPassword().touched()
    ) {
      <p class="error">
        {{ registrationForm.confirmPassword().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>
      
      I accept the terms and conditions
    </label>

    @if (
      registrationForm.acceptedTerms().invalid() &amp;&amp;
      registrationForm.acceptedTerms().touched()
    ) {
      <p class="error">
        {{ registrationForm.acceptedTerms().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    @if (registrationForm().errors().length &gt; 0) {
      <div class="error">
        @for (error of registrationForm().errors(); track error.message) {
          <p>{{ error.kind }}</p>
        }
      </div>
    }
  </div>

  <button type="submit">
    Register
  </button>

</code></pre>



<p>What stands out here is the absence of indirection. Each input binds directly to a field. Validation state is accessed through signals such as <code>invalid()</code> and <code>touched()</code>. Error messages are read from a structured error object, not reconstructed manually.</p>



<p>This template contains no subscriptions, no async pipes, and no event handlers for value changes. The UI simply reflects the current form state.</p>



<h3 class="wp-block-heading"><a></a>Interaction state and user experience</h3>



<p>One of the common criticisms of declarative form models is that they obscure user interaction logic. Signal Forms address this directly by exposing interaction metadata as signals.</p>



<p>The <code>touched()</code> signal determines whether a field has been interacted with. By combining it with <code>invalid()</code>, we control when validation messages appear. This logic remains purely declarative: the template describes when errors should be visible, and Angular ensures the signals stay up-to-date.</p>



<p>The disabled state of the submit button is derived from <code>registrationForm.invalid()</code>. There is no need to manually enable or disable it in response to events. If the form becomes valid, the button is enabled automatically.</p>



<h3 class="wp-block-heading"><a></a>Why this scales</h3>



<p>Even at this early stage, several advantages of a signal-first form model are apparent. The form’s behavior is expressed in terms of state and derivation, not events. The model, validation rules, and UI bindings are clearly separated. There is no duplication of logic between the component and the template.</p>



<p>As the form grows, this structure holds. Additional fields introduce additional schema entries and template bindings, not new subscription logic. Cross-field validation can be added declaratively. Asynchronous validation and persistence can be layered on without rewriting the core model.</p>



<p>Most importantly, the form remains inspectable. At any point during execution, the model signal reflects the current state of the form. Derived state validity, errors, and UI flags can be understood by reading the code, not by tracing runtime behavior.</p>



<h2 class="wp-block-heading"><a></a>What we did not solve yet (and why)</h2>



<p>At this stage, it would be easy to walk away with the impression that Signal Forms eliminates most of the hard problems associated with form handling. That impression would be misleading. What we have built so far is intentionally incomplete, not because the approach falls short, but because introducing too much too early obscures the value of the underlying model.</p>



<p>One area we have deliberately postponed is cross-field validation that expresses richer business rules. Many real-world forms depend on relationships between fields rather than isolated constraints. Password confirmation is a familiar example, but more complex scenarios quickly arise in enterprise applications. While Signal Forms support these patterns, introducing them before establishing a clear understanding of derived state risks turns validation back into an imperative exercise rather than a declarative one.</p>



<p>We have also avoided asynchronous validation. Server-backed checks introduce latency, partial failure, cancellation, and race conditions. These are not trivial concerns, and treating them casually often leads to subtle bugs and confusing user experiences. Although Signal Forms provide the necessary hooks to model asynchronous behavior, doing so responsibly requires a careful discussion of pending state, effects, and life-cycle boundaries. That discussion belongs in its own article.</p>



<p>Another omission is persistence and synchronization. Many forms need to autosave drafts, synchronize state with local storage, or react to changes by triggering external side effects. These behaviors are not part of the form state itself; they are consequences of state changes. Treating them as such is essential to keeping the architecture comprehensible. Introducing persistence too early would blur the distinction between state and reaction that this article has worked to establish.</p>



<p>Finally, this article has not addressed migration and interoperability. Few teams are starting from a blank slate. Most will adopt Signal Forms incrementally within applications that already rely on reactive forms or template-driven forms. Hybrid approaches, bridging strategies, and gradual refactors are all critical topics, but they presuppose familiarity with both paradigms. Addressing migration before establishing a solid signal-first mental model would undermine that foundation.</p>



<p>These omissions are intentional. A form architecture that tries to do everything at once often ends up doing nothing clearly. By focusing on the core ideas of state, derivation, and declarative validation, we create a base that can absorb additional complexity without collapsing under it.</p>



<h2 class="wp-block-heading"><a></a>Signal Forms in the context of Angular’s evolution</h2>



<p>To fully appreciate Signal Forms, it helps to step back and view them not as an isolated feature, but as part of a broader shift in Angular’s design philosophy.</p>



<p>For much of its history, Angular emphasized declarative templates paired with imperative coordination in component classes. RxJS became the backbone of that coordination, providing a powerful abstraction for handling asynchronous workflows, user input, and external events. This model scaled well, but it also encouraged developers to express state indirectly through streams and subscriptions.</p>



<p>Signals represent a deliberate recalibration. They re-center Angular’s reactivity model around state and derivation, rather than events and emissions. This shift is visible across the framework: in component inputs, change detection, and now forms. Signal Forms are not an attempt to replace everything that came before; they are an attempt to make the most common use case, modeling and deriving state, simpler and more explicit.</p>



<p>Framed this way, the design of Signal Forms aligns more closely with state-driven form behavior. The requirement to start with a model signal reflects the idea that the state should have a single, inspectable source of truth. Schema-based validation aligns with the notion that constraints are properties of state, not behaviors triggered by events. Field state exposed as signals reinforces the idea that validity, errors, and interaction metadata are derived values that should be read, not managed.</p>



<p>It is also worth noting that Signal Forms do <em>not</em> attempt to abstract away form behavior. They do not hide form state behind opaque classes or life-cycle hooks. They do not require developers to think in terms of control hierarchies or subscription graphs. Instead, they expose form behavior directly, making it easier to reason about how values, validation, and UI feedback relate to one another.</p>



<p>This approach aligns closely with other recent changes in Angular, including the introduction of modern template control flow and a stronger emphasis on explicit data dependencies. Together, these features point toward a framework that favors clarity over indirection and composition over orchestration.</p>



<p>Importantly, Signal Forms are still evolving. Their APIs may change, and their surface area will almost certainly expand. That is precisely why grounding them in first principles matters. Developers who understand <em>why</em> Signal Forms work the way they do will be far better equipped to adapt as the APIs mature.</p>



<p>This article has intentionally avoided duplicating documentation or enumerating every available feature. Instead, it has focused on establishing a conceptual framework that makes the official APIs feel intuitive rather than surprising. When viewed this way, Signal Forms are not a new way to write forms; they are a clearer expression of what forms have always been.</p>



<h2 class="wp-block-heading"><a></a>A new way to think about forms</h2>



<p>Building the registration form in this article reveals a quiet but important shift. The reduction in complexity does not come from fewer features or simpler requirements. It comes from expressing form behavior in terms of state and derivation rather than orchestration and reaction.</p>



<p>By treating the data model as the single source of truth, validation rules as declarative constraints, and UI behavior as derived from current conditions, much of the coordination logic that typically surrounds forms becomes unnecessary. There are fewer subscriptions to manage, fewer flags to synchronize, and fewer life-cycle concerns to reason about. Form behavior becomes easier to inspect because it is visible directly in the relationships between values.</p>



<p>This approach does not eliminate the hard problems associated with forms. Asynchronous validation, persistence, and interoperability with existing Angular Forms APIs still require careful design. What changes is where that complexity lives. Instead of being interwoven with state representation, those concerns are layered explicitly on top of a clear foundation.</p>



<p>Signal-first forms are not a universal replacement for existing patterns, nor are they a shortcut to simpler applications. They are, however, a strong example of how aligning APIs with first principles can reduce cognitive overhead and improve maintainability over time. For teams building large, state-heavy forms, this alignment can make the difference between code that merely works and code that continues to evolve without friction.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a signal-first form in Angular]]></title>
<description><![CDATA[Understanding a reactivity model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained i...]]></description>
<link>https://tsecurity.de/de/3607185/ai-nachrichten/building-a-signal-first-form-in-angular/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607185/ai-nachrichten/building-a-signal-first-form-in-angular/</guid>
<pubDate>Thu, 18 Jun 2026 11:18:46 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Understanding a <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactivity</a> model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained in practice.</p>



<p>In two previous articles, “<a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a>” and “<a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a>,” we reframed form behavior as a state-driven problem and examined Angular Signals as a pull-based reactivity model well-suited to that kind of work. The natural next step is to apply those ideas to an actual Angular form and observe how the architecture changes when state becomes the primary concern.</p>



<p>This article focuses on a concrete example: a modest but realistic registration form. Rather than introducing new concepts, the goal here is to make earlier ideas tangible. We will see how a signal-backed model reshapes validation, interaction state, and submission logic, and how much coordination logic simply disappears when form behavior is expressed declaratively.</p>



<p>The focus here is not on novelty or completeness, but on making the underlying ideas easier to reason about. By walking through a signal-first form from model definition to submission, we can evaluate whether this approach truly reduces complexity and where it introduces new trade-offs that teams should understand before adopting it more broadly.</p>



<h2 class="wp-block-heading"><a></a>Implementing a signal-first registration form</h2>



<p>With the conceptual groundwork in place, we can now turn theory into a concrete implementation. In this section, we will build a fully working registration form using Angular’s Signal Forms API. This example is deliberately modest in scope, but it is designed to serve as the foundation for the rest of the series. Each subsequent article will extend this same example rather than introducing a new one.</p>



<p>The form collects an email address, a password, a confirmation password, and explicit acceptance of terms. While simple on the surface, this structure allows us to explore field-level validation, cross-field constraints, interaction state, and submission behavior, all without reverting to event-driven form logic.</p>



<h3 class="wp-block-heading"><a></a>Project setup and structure</h3>



<p>The example assumes a standard Angular application created with the Angular CLI and configured to use Signals (Angular 17+). The Signal Forms APIs (Angular 21+) live under @angular/forms/signals, which must be explicitly imported.</p>



<p><a href="https://github.com/sonukapoor/angular-signal-forms">https://github.com/sonukapoor/angular-signal-forms</a></p>



<p>The folder structure is intentionally conservative:</p>



<p>src/<br>  app/<br>    registration/<br>      registration.component.ts<br>      registration.component.html<br>      registration.model.ts</p>



<p>Separating the model from the component keeps form state independent of presentation. This becomes increasingly valuable as the form grows or is reused across multiple components.</p>



<h3 class="wp-block-heading"><a></a>Defining the form model</h3>



<p>We begin by defining the shape of the data that the form collects. This is a plain TypeScript interface with no Angular dependencies. Treating the form model as a simple data structure reinforces the idea that the form’s values are just state.</p>



<pre class="wp-block-code"><code>// registration.model.ts
export interface RegistrationData {
  email: string;
  password: string;
  confirmPassword: string;
  acceptedTerms: boolean;
}
</code></pre>



<p>This interface mirrors what would typically be sent to a back-end API. There is no duplication of state, no separate “form value” object, and no mapping required at submission time.</p>



<h3 class="wp-block-heading"><a></a>Creating the signal-backed form</h3>



<p>The form itself is created in the component using a writable signal as the source of truth. The <code>form()</code> function attaches form semantics validation, field state, and submission to that signal.</p>



<pre class="wp-block-code"><code>// registration.component.ts
import { CommonModule } from "@angular/common";
import { Component, signal } from "@angular/core";
import {
  email,
  form,
  FormField,
  required,
  submit,
} from "@angular/forms/signals";
import { RegistrationData } from "./registration.model";

@Component({
  selector: "app-registration",
  imports: [FormField, CommonModule],
  templateUrl: "./registration.html",
  styleUrl: "./registration.css",
})
export class Registration {
  readonly model = signal<registrationdata>({
    email: "",
    password: "",
    confirmPassword: "",
    acceptedTerms: false,
  });

  readonly registrationForm = form(this.model, (schema) =&gt; {
    required(schema.email, { message: "Email is required" });
    email(schema.email, { message: "Enter a valid email address" });

    required(schema.password, { message: "Password is required" });
    required(schema.confirmPassword, {
      message: "Please confirm your password",
    });

    required(schema.acceptedTerms, {
      message: "You must accept the terms to continue",
    });
  });

  async onSubmit(event?: Event) {
    event?.preventDefault();

    await submit(this.registrationForm, (value) =&gt; {
      console.log(value());
      // Mock Server Call
      return Promise.resolve([
        {
          kind: "EmailAlreadyExists",
          field: this.registrationForm.email,
          error: { kind: "server", message: "Email already taken" },
        },
      ]);
    });
  }
}
</registrationdata></code></pre>



<p>Several design decisions are worth noting.</p>



<p>First, the model signal is defined as read-only. All mutations to the model occur through form bindings, not ad hoc assignments in the component. This keeps the component declarative and avoids the temptation to manipulate form state imperatively.</p>



<p>Second, validation is declared in one place. The schema function describes constraints on the model without introducing control trees, validator arrays, or observable pipelines. Angular takes responsibility for re-running validation whenever the model changes.</p>



<p>Finally, submission logic is explicit. The <code>submit()</code> helper ensures that the form is valid before invoking the callback, and it passes the current model value directly. There is no need to check flags or manually extract values.</p>



<h3 class="wp-block-heading"><a></a>Binding the form to the template</h3>



<p>With the form defined, the next step is to bind it to the template. Signal Forms provide the <code>[formField]</code> directive, which connects an input element directly to a field in the form schema.</p>



<pre class="wp-block-code"><code><!-- registration.component.html -->

  <div>
    <label>Email</label>
    

    @if (
      registrationForm.email().invalid() &amp;&amp; registrationForm.email().touched()
    ) {
      <p class="error">
        {{ registrationForm.email().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Password</label>
    

    @if (
      registrationForm.password().invalid() &amp;&amp;
      registrationForm.password().touched()
    ) {
      <p class="error">
        {{ registrationForm.password().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Confirm Password</label>
    

    @if (
      registrationForm.confirmPassword().invalid() &amp;&amp;
      registrationForm.confirmPassword().touched()
    ) {
      <p class="error">
        {{ registrationForm.confirmPassword().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>
      
      I accept the terms and conditions
    </label>

    @if (
      registrationForm.acceptedTerms().invalid() &amp;&amp;
      registrationForm.acceptedTerms().touched()
    ) {
      <p class="error">
        {{ registrationForm.acceptedTerms().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    @if (registrationForm().errors().length &gt; 0) {
      <div class="error">
        @for (error of registrationForm().errors(); track error.message) {
          <p>{{ error.kind }}</p>
        }
      </div>
    }
  </div>

  <button type="submit">
    Register
  </button>

</code></pre>



<p>What stands out here is the absence of indirection. Each input binds directly to a field. Validation state is accessed through signals such as <code>invalid()</code> and <code>touched()</code>. Error messages are read from a structured error object, not reconstructed manually.</p>



<p>This template contains no subscriptions, no async pipes, and no event handlers for value changes. The UI simply reflects the current form state.</p>



<h3 class="wp-block-heading"><a></a>Interaction state and user experience</h3>



<p>One of the common criticisms of declarative form models is that they obscure user interaction logic. Signal Forms address this directly by exposing interaction metadata as signals.</p>



<p>The <code>touched()</code> signal determines whether a field has been interacted with. By combining it with <code>invalid()</code>, we control when validation messages appear. This logic remains purely declarative: the template describes when errors should be visible, and Angular ensures the signals stay up-to-date.</p>



<p>The disabled state of the submit button is derived from <code>registrationForm.invalid()</code>. There is no need to manually enable or disable it in response to events. If the form becomes valid, the button is enabled automatically.</p>



<h3 class="wp-block-heading"><a></a>Why this scales</h3>



<p>Even at this early stage, several advantages of a signal-first form model are apparent. The form’s behavior is expressed in terms of state and derivation, not events. The model, validation rules, and UI bindings are clearly separated. There is no duplication of logic between the component and the template.</p>



<p>As the form grows, this structure holds. Additional fields introduce additional schema entries and template bindings, not new subscription logic. Cross-field validation can be added declaratively. Asynchronous validation and persistence can be layered on without rewriting the core model.</p>



<p>Most importantly, the form remains inspectable. At any point during execution, the model signal reflects the current state of the form. Derived state validity, errors, and UI flags can be understood by reading the code, not by tracing runtime behavior.</p>



<h2 class="wp-block-heading"><a></a>What we did not solve yet (and why)</h2>



<p>At this stage, it would be easy to walk away with the impression that Signal Forms eliminates most of the hard problems associated with form handling. That impression would be misleading. What we have built so far is intentionally incomplete, not because the approach falls short, but because introducing too much too early obscures the value of the underlying model.</p>



<p>One area we have deliberately postponed is cross-field validation that expresses richer business rules. Many real-world forms depend on relationships between fields rather than isolated constraints. Password confirmation is a familiar example, but more complex scenarios quickly arise in enterprise applications. While Signal Forms support these patterns, introducing them before establishing a clear understanding of derived state risks turns validation back into an imperative exercise rather than a declarative one.</p>



<p>We have also avoided asynchronous validation. Server-backed checks introduce latency, partial failure, cancellation, and race conditions. These are not trivial concerns, and treating them casually often leads to subtle bugs and confusing user experiences. Although Signal Forms provide the necessary hooks to model asynchronous behavior, doing so responsibly requires a careful discussion of pending state, effects, and life-cycle boundaries. That discussion belongs in its own article.</p>



<p>Another omission is persistence and synchronization. Many forms need to autosave drafts, synchronize state with local storage, or react to changes by triggering external side effects. These behaviors are not part of the form state itself; they are consequences of state changes. Treating them as such is essential to keeping the architecture comprehensible. Introducing persistence too early would blur the distinction between state and reaction that this article has worked to establish.</p>



<p>Finally, this article has not addressed migration and interoperability. Few teams are starting from a blank slate. Most will adopt Signal Forms incrementally within applications that already rely on reactive forms or template-driven forms. Hybrid approaches, bridging strategies, and gradual refactors are all critical topics, but they presuppose familiarity with both paradigms. Addressing migration before establishing a solid signal-first mental model would undermine that foundation.</p>



<p>These omissions are intentional. A form architecture that tries to do everything at once often ends up doing nothing clearly. By focusing on the core ideas of state, derivation, and declarative validation, we create a base that can absorb additional complexity without collapsing under it.</p>



<h2 class="wp-block-heading"><a></a>Signal Forms in the context of Angular’s evolution</h2>



<p>To fully appreciate Signal Forms, it helps to step back and view them not as an isolated feature, but as part of a broader shift in Angular’s design philosophy.</p>



<p>For much of its history, Angular emphasized declarative templates paired with imperative coordination in component classes. RxJS became the backbone of that coordination, providing a powerful abstraction for handling asynchronous workflows, user input, and external events. This model scaled well, but it also encouraged developers to express state indirectly through streams and subscriptions.</p>



<p>Signals represent a deliberate recalibration. They re-center Angular’s reactivity model around state and derivation, rather than events and emissions. This shift is visible across the framework: in component inputs, change detection, and now forms. Signal Forms are not an attempt to replace everything that came before; they are an attempt to make the most common use case, modeling and deriving state, simpler and more explicit.</p>



<p>Framed this way, the design of Signal Forms aligns more closely with state-driven form behavior. The requirement to start with a model signal reflects the idea that the state should have a single, inspectable source of truth. Schema-based validation aligns with the notion that constraints are properties of state, not behaviors triggered by events. Field state exposed as signals reinforces the idea that validity, errors, and interaction metadata are derived values that should be read, not managed.</p>



<p>It is also worth noting that Signal Forms do <em>not</em> attempt to abstract away form behavior. They do not hide form state behind opaque classes or life-cycle hooks. They do not require developers to think in terms of control hierarchies or subscription graphs. Instead, they expose form behavior directly, making it easier to reason about how values, validation, and UI feedback relate to one another.</p>



<p>This approach aligns closely with other recent changes in Angular, including the introduction of modern template control flow and a stronger emphasis on explicit data dependencies. Together, these features point toward a framework that favors clarity over indirection and composition over orchestration.</p>



<p>Importantly, Signal Forms are still evolving. Their APIs may change, and their surface area will almost certainly expand. That is precisely why grounding them in first principles matters. Developers who understand <em>why</em> Signal Forms work the way they do will be far better equipped to adapt as the APIs mature.</p>



<p>This article has intentionally avoided duplicating documentation or enumerating every available feature. Instead, it has focused on establishing a conceptual framework that makes the official APIs feel intuitive rather than surprising. When viewed this way, Signal Forms are not a new way to write forms; they are a clearer expression of what forms have always been.</p>



<h2 class="wp-block-heading"><a></a>A new way to think about forms</h2>



<p>Building the registration form in this article reveals a quiet but important shift. The reduction in complexity does not come from fewer features or simpler requirements. It comes from expressing form behavior in terms of state and derivation rather than orchestration and reaction.</p>



<p>By treating the data model as the single source of truth, validation rules as declarative constraints, and UI behavior as derived from current conditions, much of the coordination logic that typically surrounds forms becomes unnecessary. There are fewer subscriptions to manage, fewer flags to synchronize, and fewer life-cycle concerns to reason about. Form behavior becomes easier to inspect because it is visible directly in the relationships between values.</p>



<p>This approach does not eliminate the hard problems associated with forms. Asynchronous validation, persistence, and interoperability with existing Angular Forms APIs still require careful design. What changes is where that complexity lives. Instead of being interwoven with state representation, those concerns are layered explicitly on top of a clear foundation.</p>



<p>Signal-first forms are not a universal replacement for existing patterns, nor are they a shortcut to simpler applications. They are, however, a strong example of how aligning APIs with first principles can reduce cognitive overhead and improve maintainability over time. For teams building large, state-heavy forms, this alignment can make the difference between code that merely works and code that continues to evolve without friction.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Art of Taking Notes]]></title>
<description><![CDATA[How To Effectively Take Notes That Not Only Boost Your Memory But Also Make Others Worth ReadingWhether you are in any technical, non-technical, financial, or medical field, you must have taken notes, whether for your career or yourself.And if you haven’t created your own notes, believe me, after...]]></description>
<link>https://tsecurity.de/de/3600901/hacking/the-art-of-taking-notes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600901/hacking/the-art-of-taking-notes/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qn1U1UFVOPnskJ2tSYULYg.png"></figure><h4>How To Effectively Take Notes That Not Only Boost Your Memory But Also Make Others Worth Reading</h4><p>Whether you are in any technical, non-technical, financial, or medical field, you must have taken notes, whether for your career or yourself.</p><p>And if you haven’t created your own notes, believe me, after this blog, you will surely start making your own notes.</p><h3>Why Take Notes?</h3><p>Before understanding <strong>“<em>How to Take Notes Effectively</em>”,</strong> we have to understand “<strong><em>Why Even Take Notes in the First Place?”</em></strong></p><p>The main objective of taking any notes depends upon your own intentions.</p><ul><li>Whether you want to publish them</li><li>Whether you want to share them with your friends, colleagues, classmates or professors</li><li>Whether you keep them private for yourself</li><li>Whether you want to keep remembering specific details and topics</li><li>Whether you want to make a summary or brief point downs</li></ul><p><strong>[ One Thing will be common ]</strong></p><p>Which is your intention/objective. This small thing can even increase your notes' effectiveness from 2x to 4x times.</p><blockquote>Your Objective Answers “Why Your Notes Exist”</blockquote><h3>How to Improve Your Notes? (Avoid common mistakes)</h3><p>Let’s go straight forward towards improving your notes.</p><p>To improve your notes, the first step is</p><h4>[1] Identify What to Note?</h4><ul><li>Not every word, every line should be noted in the notes. It’s just like if you were highlighting almost every line on a page while reading a book.</li><li><strong>Solution</strong>: You should select specific line or words that gives the meaning or fulfils the purpose of the concept you are making notes on.</li></ul><h4><strong>[2] How to Note?</strong></h4><ul><li>Many people don’t really fully understand the concept. They read or understand one line and write a note, and then another line and so on.</li><li><strong>Solution</strong>: You first have to learn the whole concept, and then should abstract it and make notes.</li></ul><h4>[3] Avoid Common Mistake</h4><ul><li><strong>Avoid Unstructured Notes: </strong>Always make notes in a structured way. (i.e. Index, Aim, Concept, Description, Summary). It depends on the objective of the note.</li><li><strong>Avoid Too Many Highlights in Notes: </strong>Not many words need to be highlighted or bold from each line. Highlighting many words makes it hard to grasp concepts.</li><li><strong>Avoid Copy/Paste:</strong> Many of you have at least “<strong><em>copy and paste</em></strong>” as it is in the notes. Instead, you should take notes in your own language as you were explaining it to someone. This will make your notes highly understandable and help you retain information in the long term.</li><li><strong>Avoid Taking Notes on Note-Taking Apps: </strong>If you were taking notes on simple applications (i.e. Google Notes, Notepad, Notepad++, Sticky Notes, etc). It’s time to move on to other applications.</li></ul><h3>Note-Taking Applications</h3><p>The Note-Taking applications are specifically designed to make the note-taking process faster, easier and more effective.</p><p>Google Notes is quite good, but only for making short notes. If you are making very large notes, you should avoid Google Notes, as there are some better options available.</p><p>There are plenty of applications available in the market. And I have used many applications to test whether they’re user-friendly and convenient.</p><p>I won’t assume that you only use laptops and desktops for taking notes. Instead, I will assume that you can take and review your notes whenever you want, whether you only have your laptop, your computer, or your mobile.</p><p>So, once you make notes, you can also access them from different devices.</p><p>Some of the best tools I have used,</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/817/1*XzcegPk0YpLQf2MOAYvoXA.png"></figure><h4><a href="https://www.notion.com/">[1] Notion</a></h4><p>The reason I put Notion on no. 1 is simple. Its features, UI, and Integrations.</p><ul><li>Notion’s beginner-friendly UI makes the note-taking process easy.</li><li>Notion’s suite helps you map your activity and notes synchronizly. (i.e. Notion, Notion Calendar, Notion Mail)</li><li>It integrates with many applications.</li><li>It also supports integrated Notion AI.</li><li>It is cross-platform.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0eJ4OS3AcJJsb4kE1MMahQ.png"></figure><h4><a href="https://obsidian.md/">[2] Obsidian</a></h4><p>Obsidian is also very popular among note-taking apps. It is known for</p><ul><li>Its awesome UI and theme.</li><li>cross-platform.</li><li>Canvas, Graphs and Links.</li><li>Publications.</li><li>Integrated features and plugins.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1hvdnc9wGYpOcYFPKPwCwQ.png"></figure><h4><a href="https://www.microsoft.com/en-in/microsoft-365/onenote/digital-note-taking-app">[3] OneNote from Microsoft</a></h4><p>OneNote is one of the most popular for</p><ul><li>Cross-platform</li><li>Cloud storing notes</li><li>Integrated Copilot</li><li>Collaboration</li><li>Advanced Features (i.e. Sketch, voice transcription)</li></ul><p>You may use any of these tools as per your convenience.</p><h3>Conclusion</h3><p>Making good and effective notes helps you recall things, tracking your progress, day-to-day activity, planning and preparation.</p><p>Using good software helps you increase your efficiency &amp; effectiveness of the notes. Not only softwares, but how you make notes decides how deeply you understan the concept and how effectively you can explain it to other (Skilling up: Grasping + Presentation).</p><p>Like and share this to your friends and colleagues. Help them improve because the better you make notes, the better you will understand the concept.</p><p>Also let me know in the comments,</p><ul><li><strong>Have you used or currently using one of these applications before for taking notes?</strong></li><li><strong>What features of them do you like the most?</strong></li><li><strong>What other note-taking app do you use?</strong></li></ul><p>See you in the next blog.</p><p><strong><em>Keep Learning — Keep Growing</em></strong></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ff5208fa13eb" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-art-of-taking-notes-ff5208fa13eb">The Art of Taking Notes</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Asha Sharma’s Xbox Plan Puts Fallout Back in Focus, and Obsidian Looks Like the Right Studio]]></title>
<description><![CDATA[Asha Sharma’s reported Xbox strategy has put Fallout back at the center of Microsoft’s gaming plans, and Obsidian Entertainment now looks like the most natural…
The post Asha Sharma’s Xbox Plan Puts Fallout Back in Focus, and Obsidian Looks Like the Right Studio appeared first on OnMSFT.]]></description>
<link>https://tsecurity.de/de/3600501/windows-tipps/asha-sharmas-xbox-plan-puts-fallout-back-in-focus-and-obsidian-looks-like-the-right-studio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600501/windows-tipps/asha-sharmas-xbox-plan-puts-fallout-back-in-focus-and-obsidian-looks-like-the-right-studio/</guid>
<pubDate>Tue, 16 Jun 2026 04:10:24 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Asha Sharma’s reported Xbox strategy has put Fallout back at the center of Microsoft’s gaming plans, and Obsidian Entertainment now looks like the most natural…</p>
<p>The post <a href="https://onmsft.com/news/asha-sharmas-xbox-plan-puts-fallout-back-in-focus-and-obsidian-looks-like-the-right-studio/">Asha Sharma’s Xbox Plan Puts Fallout Back in Focus, and Obsidian Looks Like the Right Studio</a> appeared first on <a href="https://onmsft.com/">OnMSFT</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LiteLLM-Patch schließt CVE-Kette: Angriff von Admin bis Code-Execution]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Eine Schwachstellenkette in LiteLLM erlaubt es mit einem Standard-User bis zum Proxy-Admin aufzusteigen und anschließend Code auf dem Gateway auszuführen. Obsidian Security bewertet die komplette Kette mit CVSS 9,9 und nennt als Gegenmaßnahme den Upgrade auf LiteLL...]]></description>
<link>https://tsecurity.de/de/3599950/it-security-nachrichten/litellm-patch-schliesst-cve-kette-angriff-von-admin-bis-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599950/it-security-nachrichten/litellm-patch-schliesst-cve-kette-angriff-von-admin-bis-code-execution/</guid>
<pubDate>Mon, 15 Jun 2026 20:13:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-litellm-cve-chain-admin-codeexec.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-litellm-cve-chain-admin-codeexec.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-litellm-cve-chain-admin-codeexec-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-litellm-cve-chain-admin-codeexec-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-litellm-cve-chain-admin-codeexec-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-litellm-cve-chain-admin-codeexec-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-litellm-cve-chain-admin-codeexec-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Eine Schwachstellenkette in LiteLLM erlaubt es mit einem Standard-User bis zum Proxy-Admin aufzusteigen und anschließend Code auf dem Gateway auszuführen. Obsidian Security bewertet die komplette Kette mit CVSS 9,9 und nennt als Gegenmaßnahme den Upgrade auf LiteLLM v1.83.14-stable oder neuer. Da das Gateway als zentrale Vermittlung zwischen Agenten und […]</p>
<div><a href="https://www.it-boltwise.de/litellm-patch-schliesst-cve-kette-angriff-von-admin-bis-code-execution.html">... den vollständigen Artikel <strong>»LiteLLM-Patch schließt CVE-Kette: Angriff von Admin bis Code-Execution«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/litellm-patch-schliesst-cve-kette-angriff-von-admin-bis-code-execution.html">LiteLLM-Patch schließt CVE-Kette: Angriff von Admin bis Code-Execution</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers]]></title>
<description><![CDATA[A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is a widely deployed open-source AI gateway that brokers calls to…
Read more →
The post LiteLLM Vulnerability...]]></description>
<link>https://tsecurity.de/de/3599875/it-security-nachrichten/litellm-vulnerability-chain-lets-low-privilege-users-take-over-ai-gateway-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599875/it-security-nachrichten/litellm-vulnerability-chain-lets-low-privilege-users-take-over-ai-gateway-servers/</guid>
<pubDate>Mon, 15 Jun 2026 19:38:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is a widely deployed open-source AI gateway that brokers calls to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/litellm-vulnerability-chain-lets-low-privilege-users-take-over-ai-gateway-servers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/litellm-vulnerability-chain-lets-low-privilege-users-take-over-ai-gateway-servers/">LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The causes of cloud outages are changing]]></title>
<description><![CDATA[For years, the cloud market has made a simple promise: Move workloads to large-scale platforms, gain better resilience, and worry less about downtime. That promise was never entirely wrong, but it is becoming less complete. The latest findings from Uptime Institute’s seventh Annual Outage Analysi...]]></description>
<link>https://tsecurity.de/de/3599872/ai-nachrichten/the-causes-of-cloud-outages-are-changing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599872/ai-nachrichten/the-causes-of-cloud-outages-are-changing/</guid>
<pubDate>Mon, 15 Jun 2026 19:33:57 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For years, the cloud market has made a simple promise: Move workloads to large-scale platforms, gain better resilience, and worry less about downtime. That promise was never entirely wrong, but it is becoming less complete. The latest findings from <a href="https://uptimeinstitute.com/resources/research-and-reports/annual-outage-analysis-2025">Uptime Institute’s seventh Annual Outage Analysis</a> suggest that the outage landscape is changing in ways that should concern both cloud providers and cloud customers. The biggest risks are no longer limited to broken physical infrastructure. They are increasingly tied to the complexity of the systems used to run, coordinate, update, and recover that infrastructure.</p>



<p>The most alarming number in the report is that IT and networking issues accounted for 23% of impactful outages in 2024. Uptime Institute links these increases to growing IT and network complexity; the long-term shift toward colocation, cloud, and third-party digital services; and the resulting increase in change-management failures and misconfigurations. That number is more than a statistical footnote. It points to a structural change in how outages happen and why cloud outages are becoming such a stubborn problem.</p>



<p>Hardware redundancy can protect against component failures, but it doesn’t help much when the outage stems from a bad configuration, an automation error, a faulty network change, or an underappreciated control-plane dependency. In those cases, the infrastructure itself may remain intact while the system that governs it breaks down. The industry is learning that <a href="https://www.networkworld.com/article/967679/what-is-disaster-recovery-how-to-ensure-business-continuity.html">resiliency</a> is less about duplicating equipment and more about managing complexity. Today’s increasingly distributed and software-defined environments cannot operate safely at scale.</p>



<h2 class="wp-block-heading">Failures at the operational level</h2>



<p>Uptime’s findings show that power remains the leading cause of major outages, underscoring that traditional infrastructure engineering still matters a great deal. But even as providers continue to improve physical resilience, outages can still arise from the digital and procedural layers above it. Cloud platforms are now dense stacks of services, <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">APIs</a>, orchestration systems, software-defined networks, <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity controls</a>, failover logic, and third-party dependencies. That complexity creates more possible points of interaction and more opportunities for an error in one layer to cascade into several others.</p>



<p>This helps explain why outages can feel more surprising today than they did a decade ago. In older data center models, an outage often had a more apparent root cause, such as a power event, a cooling failure, or a hardware fault. In cloud environments, the trigger may be a small configuration change that propagates across regions, a policy update that unintentionally blocks service communication, or a network control failure that affects seemingly unrelated services. These are not failures of raw infrastructure capacity. They are failures of complexity management.</p>



<p>The report’s language around change management and misconfiguration is especially important because it challenges one of the most common assumptions in the cloud market: that scale automatically produces better operational outcomes. The reality? Scale can magnify both strengths and weaknesses. Large cloud providers have more engineering talent, more sophisticated tools, and more redundancy than almost any enterprise customer. But they also run far more interconnected systems at far greater speeds with far more automation. A single process failure can have a wider blast radius.</p>



<p>Another important lesson from the Uptime analysis is that automation has not removed the human factor. If anything, it has changed its form. Even in highly automated environments, human error remains central to the problem. The report notes that in 2025, the share of outages caused by human failure to follow procedures rose by 10 percentage points compared with 2024. A related industry summary of the report notes that 58% of human error-related outages were caused by staff failing to follow established procedures.</p>



<p>That matters because cloud providers often position automation as the answer to reliability. Automation is essential, but it only works as well as the operational model that surrounds it. If teams deploy changes too quickly, rollback paths are weak, approval chains are bypassed, or procedures are incomplete, automation can accelerate failure rather than prevent it. In a modern cloud environment, a human mistake is rarely just a single keystroke. It is more often a design weakness in process, governance, testing, or accountability.</p>



<p>This is also why customers should resist the comforting notion that outages are somebody else’s problem once workloads move to the cloud. Provider-side mistakes remain real, but customer architectures are increasingly entangled with provider networking, identity, observability, and platform services. When an outage occurs, the customer may not have caused it, but they still bear the business impact. The shared responsibility model does not end with security. It extends to resilience planning as well.</p>



<h2 class="wp-block-heading">Better change management</h2>



<p>The Uptime data points to a clear conclusion: Cloud providers need to treat operational discipline as a first-class design requirement. That starts with better change management. High-risk changes should be tested more aggressively, staged more gradually, and accompanied by stronger rollback mechanisms. Providers also need better dependency mapping to understand how a change in one control layer can affect services far beyond its immediate scope. If the system is too complex to clearly explain, it is too complex to operate.</p>



<p>Providers also need to improve procedural quality. The rise in outages caused by failing to follow procedures suggests that procedures are being ignored under operational pressure or that they are too cumbersome, outdated, or unclear for real production conditions. Neither explanation is comforting. Stronger runbooks, better training, more realistic failure drills, and tighter operational guardrails are not glamorous investments; they are increasingly central to resilience.</p>



<p>Another pressure point is visibility. Uptime notes that software-based and distributed resiliency tools can improve availability, but they also introduce new risks and complicate root-cause analysis. Cloud providers need more transparent and faster incident diagnosis, not just more layers of abstraction. Customers cannot build trust in resilience if every major incident becomes a long exercise in reconstructing opaque service dependencies after the fact.</p>



<h2 class="wp-block-heading">Design with outages in mind</h2>



<p>What’s the financial impact of more frequent problems? Uptime’s 2024 analysis found that 54% of respondents reported that their most recent significant outage cost more than $100,000, and 20% said it cost more than $1 million. These are not edge-case losses. They show that outages remain costly even if they are less frequent than in earlier years.</p>



<p>Customers need to stop evaluating cloud resilience through uptime promises and start evaluating it through failure behavior. How does a provider isolate faults? How transparent is incident communication? How portable are workloads if a major service degrades? How dependent is the architecture on a single region, network path, identity service, or control plane? These are not just technical questions; they are now critical business questions.</p>



<p>The core lesson from Uptime’s data is simple. Outages are becoming a bigger problem for cloud providers and customers because the cloud’s biggest vulnerabilities are increasingly tied to complexity, process failures, and control-plane mistakes, not just broken infrastructure. In addition to adding redundancy, the next phase of cloud improvement will focus on building systems that are easier to understand, safer to change, and more disciplined to operate.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers]]></title>
<description><![CDATA[A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed

LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model providers behind one O...]]></description>
<link>https://tsecurity.de/de/3599842/it-security-nachrichten/litellm-vulnerability-chain-lets-low-privilege-users-take-over-ai-gateway-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599842/it-security-nachrichten/litellm-vulnerability-chain-lets-low-privilege-users-take-over-ai-gateway-servers/</guid>
<pubDate>Mon, 15 Jun 2026 19:27:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed

LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model providers behind one OpenAI-compatible interface.

A server takeover exposes every provider key it holds, the secrets that]]></content:encoded>
</item>
<item>
<title><![CDATA[5 runtime signals for catching a compromised AI agent]]></title>
<description><![CDATA[In June 2025, Simon Willison, the engineer who coined the term “prompt injection,” published a warning that circulated widely through the security community. He called it the lethal trifecta — three capabilities that, when combined in a single AI agent, create a near-guaranteed path to exploitati...]]></description>
<link>https://tsecurity.de/de/3598566/it-security-nachrichten/5-runtime-signals-for-catching-a-compromised-ai-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598566/it-security-nachrichten/5-runtime-signals-for-catching-a-compromised-ai-agent/</guid>
<pubDate>Mon, 15 Jun 2026 11:08:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In June 2025, Simon Willison, the engineer who coined the term “prompt injection,” <a href="https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/">published a warning</a> that circulated widely through the security community. He called it the lethal trifecta — three capabilities that, when combined in a single AI agent, create a near-guaranteed path to exploitation through indirect prompt injection: access to private data; exposure to untrusted content; the ability to communicate externally.</p>



<p>The framing was sharp and useful. If your agent reads your email, ingests arbitrary web content, and can make outbound requests, an attacker who embeds malicious instructions anywhere in that content pipeline can direct the agent to exfiltrate your data without you ever knowing. Willison illustrated the point with a long list of real production exploits: Microsoft 365 Copilot, GitHub’s MCP server, GitLab Duo, Slack AI, Google Bard, Amazon Q. The same class of attack, over and over.</p>



<p>The trifecta worked as a signal because, at the time, agents were mostly narrowly scoped. An agent capable of performing only one or two of the lethal trifecta activities could be assessed as lower risk. Avoiding the combination felt like a viable design strategy.</p>



<p>That window has closed given what practitioners deploy today: A customer-facing support agent reads ticket histories and customer records, ingests user messages and attached files, and calls CRMs, refund APIs, or ticketing systems. An email AI reads your inbox and calendar, processes inbound messages from strangers, and sends replies on your behalf.</p>



<p>Rather than being edge cases or poorly designed deployments, these are the agents enterprises and individuals actually want, and they’re the ones vendors are building toward.</p>



<h2 class="wp-block-heading">Lethal trifecta as default configuration</h2>



<p>Ross McKerchar, CISO at Sophos, <a href="https://www.sophos.com/en-us/blog/inside-the-lethal-trifecta-blast-radius-reduction-in-ai-agent-deployments">put it plainly</a> in a piece published this May: “the capabilities practitioners actually want (read my data, understand external context, take action) push firmly into dangerous territory. This isn’t a misconfiguration; it’s the architectural cost of usefulness.” He’s right. An agent without private data access is useless, one that can’t process external content is isolated, and the one that can’t communicate externally is inert. Strip any leg of the trifecta and you have something closer to a search box than an agent.</p>



<p>If every legitimate agent architecture exhibits all three trifecta properties, the trifecta is no longer a meaningful indicator of elevated risk. It’s the default configuration. Treating it as a red flag is like treating DNS resolution as a signal of network compromise. Technically <a href="https://www.csoonline.com/article/574989/4-strategies-to-help-reduce-the-risk-of-dns-tunneling.html">true in some threat models</a>, but universally present in every real deployment.</p>



<p>McKerchar’s piece frames the response as “blast radius reduction”: a reasonable operational philosophy, but one that accepts the trifecta as a given condition rather than a preventable one. That’s a reasonable call. The question is what comes after the acceptance.</p>



<p>Meta’s security team arrived at the same conclusion from the other direction. In October 2025, they published the “<a href="https://ai.meta.com/blog/practical-ai-agent-security/">Rule of Two</a>,” a framework that recommends agents satisfy no more than two of the three trifecta properties in a single session, with human-in-the-loop approval required if all three are necessary. Willison <a href="https://simonwillison.net/2025/Nov/2/new-prompt-injection-papers/">himself endorsed the framework</a> as “the best practical advice for building secure LLM-powered agent systems today.”</p>



<p>Meta’s limitations section, however, concedes that many sought-after use cases won’t fit the framework cleanly, and that “designs that satisfy the Agents Rule of Two can still be prone to failure.” That’s not a criticism of the framework but confirmation that the problem has outgrown the architecture-level solution.</p>



<p>The scale of exposure is no longer theoretical. <a href="https://blog.google/security/prompt-injections-web/">Google’s April 2026 sweep</a> of the Common Crawl repository found prompt injection attempts across public web pages, ranging from pranks to data exfiltration payloads, with malicious attempts up 32% between November 2025 and February 2026. Google noted sophistication remains low for now but flagged the trend as a signal of maturing attacker interest.</p>



<p>The environment the trifecta warned about has arrived.</p>



<h2 class="wp-block-heading">How to sleuth out a compromised agent</h2>



<p>If the trifecta describes nearly every deployed agent, practitioners need signals that distinguish compromised behavior from normal operation within a trifecta-exhibiting system. That means shifting from architecture-level assessments to <a href="https://www.csoonline.com/article/4145127/runtime-the-new-frontier-of-ai-agent-security.html">runtime behavioral detection</a>.</p>



<p>The production evidence arrived in a cluster. From Jan. 7 to Jan. 15, 2026, <a href="https://breached.company/the-lethal-trifecta-strikes-four-major-ai-agent-vulnerabilities-in-five-days/">researchers disclosed exploits</a> against four separate AI productivity tools in eight days: IBM Bob, Superhuman AI, Notion AI, and Anthropic’s Claude Cowork. Each used indirect prompt injection to exfiltrate data via a channel the agent had legitimate access to. In the Cowork case, a hidden prompt embedded in an uploaded document directed the agent to exfiltrate files via Anthropic’s own allowlisted API domain, invisible to any perimeter control and indistinguishable from normal agent behavior until the data was already gone. In all of these cases, the trifecta wasn’t a risk factor but the operating condition.</p>



<p>Here’s what’s worth watching to detect an agent has been compromised.</p>



<p><strong>Instruction-following anomalies.</strong> A compromised agent doesn’t usually do something structurally different from a healthy one. Following instructions is its normal function. The difference is whose instructions it’s following. Look for agent actions that have no plausible correspondence to a user-initiated task. An agent that was asked to summarize a quarterly report but then attempts an outbound DNS request to an unfamiliar domain didn’t spontaneously decide to do that. Something in the content it ingested told it to.</p>



<p><strong>Tool call sequences that break expected topology.</strong> In a well-designed agent system, the graph of tool calls for any given task should be relatively predictable. A coding agent invoked to fix a bug should touch files, run tests, perhaps check documentation. It shouldn’t be reaching for email or calendar APIs. Tool call sequences that cross expected workflow boundaries are worth flagging even when each individual call looks legitimate on its own.</p>



<p><strong>Exfiltration via low-bandwidth channels.</strong> The classic prompt injection exfiltration attack routes stolen data through a mechanism the agent has legitimate access to: a rendered image URL with encoded query parameters, an API call with data embedded in a parameter, a link in a generated document. These don’t look like data theft in isolation; they look like normal agent output. Detection requires correlating what data the agent had access to against what it embedded in its output. That requires end-to-end visibility into the agent’s actions, not just the final response.</p>



<p><strong>Credential and secret access outside task scope.</strong> If an agent with legitimate access to a secrets store or key vault touches credentials that have no relationship to the current task, that’s a signal. An agent fixing a React rendering bug should likely not be reading AWS credentials. Least-privilege scoping is the architectural defense here, but monitoring for out-of-scope credential access is the detection layer that catches failures in that scoping.</p>



<p><strong>Memory-write anomalies.</strong> Agents with persistent memory are a growing attack surface. A poisoned memory entry that looks like legitimate user context but contains dormant trigger instructions can persist across sessions and fire long after the initial injection. Monitoring for memory-writes containing instruction-like content, or writes made during sessions that ingested untrusted content, is worth adding to any agent observability pipeline.</p>



<h2 class="wp-block-heading">Runtime alone can address the agent redirection threat</h2>



<p>For practitioners operating production agent infrastructure, the lethal trifecta tells you what you know: Your agents are exposed. The question is what to do about it.</p>



<p>The answers are at the runtime layer, not the architecture layer. That’s where <a href="https://www.csoonline.com/article/653052/how-to-pick-the-best-endpoint-detection-and-response-solution.html">EDR</a> and <a href="https://www.csoonline.com/article/566677/12-top-siem-tools-rated-and-compared.html">SIEM</a> live for traditional infrastructure — agents need the same instrumentation, and most deployments don’t have it yet. Full execution traces on every agent invocation. Tool call <a href="https://www.csoonline.com/article/3822459/what-is-anomaly-detection-behavior-based-analysis-for-cyber-threats.html">anomaly detection</a>. Input screening at ingest. Credential access monitoring scoped to task context. Memory-write auditing. Not a human attacker logging in. An agent that’s been quietly redirected.</p>



<p>Willison’s trifecta was the right alarm for its moment, which was last year. Almost every production agent now fits the profile. Because of that, only runtime anomaly detection can potentially provide adequate defense. The above signals are a good place to start.<a></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Flowise-Server durch kritischen Exploit gefährdet - it-daily.net]]></title>
<description><![CDATA[Das IT-Sicherheitsunternehmen Obsidian Security hat detaillierte ... Sicherheitsdienstleisters OX Security zeigen, dass es sich um eine systemische ...]]></description>
<link>https://tsecurity.de/de/3598535/it-security-nachrichten/flowise-server-durch-kritischen-exploit-gefaehrdet-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598535/it-security-nachrichten/flowise-server-durch-kritischen-exploit-gefaehrdet-it-dailynet/</guid>
<pubDate>Mon, 15 Jun 2026 10:53:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das <b>IT</b>-Sicherheitsunternehmen Obsidian <b>Security</b> hat detaillierte ... Sicherheitsdienstleisters OX <b>Security</b> zeigen, dass es sich um eine systemische ...]]></content:encoded>
</item>
<item>
<title><![CDATA[BYD verrät weitere Details zum neuen Kleinwagen für Europa mit über 1000 km Reichweite]]></title>
<description><![CDATA[Der BYD Dolphin G DM-i feiert im Juni 2026 in Berlin Premiere und positioniert sich im europäischen B-Segment, also in derselben Klasse wie viele der beliebtesten Kleinwagen Europas. Das Modell ist 4,16 Meter lang (425 Liter Kofferraumvolumen; durch Umklappen der im Verhältnis 40:60 geteilten Rüc...]]></description>
<link>https://tsecurity.de/de/3596654/it-nachrichten/byd-verraet-weitere-details-zum-neuen-kleinwagen-fuer-europa-mit-ueber-1000-km-reichweite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596654/it-nachrichten/byd-verraet-weitere-details-zum-neuen-kleinwagen-fuer-europa-mit-ueber-1000-km-reichweite/</guid>
<pubDate>Sun, 14 Jun 2026 09:02:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Der BYD Dolphin G DM-i feiert im Juni 2026 in Berlin Premiere und positioniert sich im europäischen B-Segment, also in derselben Klasse wie viele der beliebtesten Kleinwagen Europas. Das Modell ist 4,16 Meter lang (425 Liter Kofferraumvolumen; durch Umklappen der im Verhältnis 40:60 geteilten Rücksitzlehnen lässt sich das Volumen auf bis zu 1225 Liter erweitern) und gehört gleichzeitig zu den wenigen Plug-in-Hybriden dieser Klasse, die einen klaren Schwerpunkt auf längere Reichweiten im Elektrobetrieb legen.</p>



<p>BYD nutzt die firmeneigene DM-i-Technologie (Dual Mode Intelligence), bei der Elektromotor (120 kW/163 PS, 210 Newtonmeter Drehmoment) und Benzinmotor (1,5 Liter Hubraum) je nach Fahrsituation zusammenarbeiten. Damit beschleunigt das Fahrzeug in nur 8,3 Sekunden von 0 auf 100 km/h. Laut BYD soll das Fahrzeug einen Großteil der täglichen Pendelfahrten elektrisch bewältigen können, während die Gesamtreichweite bei 1.040 Kilometern liegen soll (bei voller Ladung und vollem Tank). </p>



<p>Die rein elektrische Reichweite gibt BYD mit der größeren Batterie (18,3 Kilowattstunden) mit 105 Kilometern an. Den Kraftstoffverbrauch gibt BYD mit nur 1,4 Litern pro 100 Kilometer an – bei vollständig geladener Batterie. Bei der kleineren Batterie mit 7,42 Kilowattstunden seien eine rein elektrische WLTP-Reichweite von 40 Kilometern und eine Gesamtreichweite von 1020 Kilometern möglich, wie BYD verspricht.</p>



<p>Im EV-Modus agiert das Fahrzeug wie ein reines Elektroauto: Es nutzt nur die Energie der Batterie, und der Benzinmotor bleibt so lange ausgeschaltet, bis der Ladezustand der Batterie auf ein bestimmtes Niveau abgesunken ist. Dabei kommt ausschließlich der Elektromotor zum Einsatz, der beim Bremsen Energie rekuperiert und die Batterie auflädt.</p>



<p><strong>Aufladen</strong>: Die Active-Modelle verfügen über einen On-Board-Charger mit 3,3 kW, der die Batterie in knapp unter drei Stunden von 15 auf 100 Prozent aufladen soll. Die Versionen Boost, Comfort und Sport erhöhen die Ladeleistung auf 6,6 kW und bieten zusätzlich eine DC-Schnellladefunktion mit bis zu 39 kW. Damit soll die 18,3-Kilowattstunden-Batterie in 26 Minuten von 10 auf 80 Prozent aufladen.</p>



<p>Zur Ausstattung gehören Leichtmetallräder – 16 Zoll bei den Ausstattungen Active und Boost, 18 Zoll im Zweiton-Design in der Comfort-Linie sowie 18 Zoll in Glanzschwarz in der Sport-Version –, LED-Rückleuchten, 8,8‑Zoll‑Digitalinstrument und Infotainment‑Bildschirm (wahlweise mit 10,1 oder 12,8 Zoll Diagonale).</p>



<h2 class="wp-block-heading">Fahrerassistenzsysteme</h2>



<p>Serienmäßig sind alle Versionen mit Front- und Heckparksensoren ausgestattet. Die Varianten Active und Boost bieten zusätzlich eine Rückfahrkamera, während Comfort und Sport dieses System mit einer 360-Grad-Kamera für eine optimale Rundumsicht erweitern.</p>



<p>Zur Fahrerassistenz gehören in allen Ausstattungslinien unter anderem ein adaptiver Tempomat sowie ein intelligenter Tempomat, ein Notfall-Spurhalteassistent und Spurverlassenswarner, Front- und Heck-Querverkehrswarner inklusive Querverkehrsbremsfunktion, Totwinkelwarner, ein Fahrerüberwachungssystem sowie eine Ausstiegswarnung.</p>



<p>Es gibt den BYD Dolphin G DM-i in vier Ausstattungsvarianten und in vier Metallic-Farben: Skiing White (Weiß), Time Grey (Grau), Obsidian Black (Schwarz) und Ocean Blue (Blau), sowie in Uni Oxford White (Weiß) und dem Perleffekt-Lack Orange Sunset (Orange). </p>



<p>Vollständige technische Spezifikationen oder Preise hat BYD noch nicht bekannt gegeben. Der Dolphin G DM-i wird in den kommenden Wochen in Europa in den Verkauf gehen und soll voraussichtlich im Frühherbst in Deutschland ausgeliefert werden. Es ist das erste Mal, dass BYD ein Modell von Grund auf speziell für internationale Märkte entwickelt, wobei Europa als klarer Zielmarkt im Fokus steht.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a2e51d533c08"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/BYDtec.jpg?quality=50&amp;strip=all" alt="BYD Dolphin G DM-i" class="wp-image-3162110" width="496" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>BYD Dolphin G DM-i</p>
</figcaption></figure><p class="imageCredit">BYD</p></div>



<h2 class="wp-block-heading">Mehr zu BYD lesen (Auto-Testberichte):</h2>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3118048/byd-sealion-7-test.html" target="_blank" rel="noreferrer noopener">BYD Sealion 7 im Test: Komfortabler Elektro-SUV mit nervigen Warnsystemen</a></li>



<li><a href="https://www.pcwelt.de/article/2437683/byd-seal-chinesischer-tesla-herausforderer-e-auto-test.html" target="_blank" rel="noreferrer noopener">BYD Seal im Test: Konkurrenz für Tesla? Die Antwort!</a></li>



<li><a href="https://www.pcwelt.de/article/2291316/byd-dolphin-test.html" target="_blank" rel="noreferrer noopener">BYD Dolphin im Test: Kein Traumauto, aber ein echter Konkurrent in der Einsteigerklasse</a></li>



<li><a href="https://www.pcwelt.de/article/2893067/472-km-h-elektro-supersportwagen-byd-yangwang-u9-geschwindigkeitsweltrekord.html" target="_blank" rel="noreferrer noopener">472,41 km/h: Elektro-Supersportwagen BYD Yangwang U9 fährt Geschwindigkeitsweltrekord</a></li>
</ul>



<h2 class="wp-block-heading">Wie alles begann:</h2>



<p><a href="https://www.pcwelt.de/article/2085810/tesla-byd-vergleich.html" target="_blank" rel="noreferrer noopener">Tesla und BYD im Vergleich – wer hat die Nase vorn?</a> Wir haben 2023 die beiden Marken miteinander verglichen. Damals war das Kürzel BYD noch nicht jedem Auto-Interessierten ein Begriff. Obwohl im Jahr 2022 der chinesische Autohersteller BYD mit damals mehr als 1,85 Millionen verkauften E-Autos den bisherigen Branchenprimus <a href="https://www.pcwelt.de/article/2085810/tesla-byd-vergleich.html#" target="_blank" rel="noreferrer noopener">Tesla</a> überholt hatte und seitdem als weltweit größter Hersteller für Elektrofahrzeuge gilt. </p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[from fedora back to Ubuntu]]></title>
<description><![CDATA[I was very excited to get my 'new' T14s Ryzen 5 16gb laptop. So keen to get Fedora installed and it felt so mega swift. Looked clean, tidy, snappy. However, after the main updates, the issues occurred. VLC media player refused to play the headphones continuously, only in an initial burst then gon...]]></description>
<link>https://tsecurity.de/de/3596592/linux-tipps/from-fedora-back-to-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596592/linux-tipps/from-fedora-back-to-ubuntu/</guid>
<pubDate>Sun, 14 Jun 2026 08:08:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I was very excited to get my 'new' T14s Ryzen 5 16gb laptop. So keen to get Fedora installed and it felt so mega swift. Looked clean, tidy, snappy.</p> <p>However, after the main updates, the issues occurred.</p> <p>VLC media player refused to play the headphones continuously, only in an initial burst then gone, silent.</p> <p>Dragon media player would play but then crashed, the whole system.</p> <p>Next, no boot - latest kernel had gone bad. So revert to the one before. That then went bad also.</p> <p>Revert to the one remaining and give up.</p> <p>So, Ubuntu 24.04 and after the bizarre issue upon first run (maybe Wayland), where icon buttons to click registered the click (changed colour slightly) but they wouldnt go anywhere. Not all on a page, just one or two when the other clickable parts worked fine...so try xorg and then seemingly plane sailing.</p> <p>Now with my usual apps installed obsidian, vlc, writer, chrome...and some basic aesthetic changes, maybe, just maybe, I have the stable and fast and pleasant looking linux setup I was after.</p> <p>Also will mention for those who do not know and experience similar issues - on both my L390 and this T14S, when using an aftermarket power charger, of the right wattage, it causes the touchpad cursor to become laggy, a bit drunken swaying, heavy. If you experience the same issue, ponder it could be the charger. As in my case using the proper Lenovo charger solved the issue.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/JohanNagel79"> /u/JohanNagel79 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u5a41p/from_fedora_back_to_ubuntu/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u5a41p/from_fedora_back_to_ubuntu/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nordhealth Notion-Störung nach Anthropic KI-Abschaltung]]></title>
<description><![CDATA[Es deutet sich an, dass Cloud-Abhängigkeiten sowie das Setzen auf KI nicht immer die beste Idee ist. Beim Anbieter Nordhealth, der SaaS-Lösungen im Gesundheitsbereich anbietet, gibt es eine Störung beim Modul Notion. Notion setzt auf Anthropic KI und Anthropic musste … Weiterlesen →
Quelle]]></description>
<link>https://tsecurity.de/de/3596186/it-nachrichten/nordhealth-notion-stoerung-nach-anthropic-ki-abschaltung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596186/it-nachrichten/nordhealth-notion-stoerung-nach-anthropic-ki-abschaltung/</guid>
<pubDate>Sat, 13 Jun 2026 23:02:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Es deutet sich an, dass Cloud-Abhängigkeiten sowie das Setzen auf KI nicht immer die beste Idee ist. Beim Anbieter Nordhealth, der SaaS-Lösungen im Gesundheitsbereich anbietet, gibt es eine Störung beim Modul Notion. Notion setzt auf Anthropic KI und Anthropic musste … <a href="https://borncity.com/blog/2026/06/13/nordhealth-notion-stoerung-nach-anthropic-ki-abschaltung/">Weiterlesen <span class="meta-nav">→</span></a>
<p><a href="https://borncity.com/blog/2026/06/13/nordhealth-notion-stoerung-nach-anthropic-ki-abschaltung/" rel="nofollow">Quelle</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why cloud outages are such a stubborn problem]]></title>
<description><![CDATA[For years, the cloud market has made a simple promise: Move workloads to large-scale platforms, gain better resilience, and worry less about downtime. That promise was never entirely wrong, but it is becoming less complete. The latest findings from Uptime Institute’s seventh Annual Outage Analysi...]]></description>
<link>https://tsecurity.de/de/3592997/ai-nachrichten/why-cloud-outages-are-such-a-stubborn-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592997/ai-nachrichten/why-cloud-outages-are-such-a-stubborn-problem/</guid>
<pubDate>Fri, 12 Jun 2026 11:34:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For years, the cloud market has made a simple promise: Move workloads to large-scale platforms, gain better resilience, and worry less about downtime. That promise was never entirely wrong, but it is becoming less complete. The latest findings from <a href="https://uptimeinstitute.com/resources/research-and-reports/annual-outage-analysis-2025">Uptime Institute’s seventh Annual Outage Analysis</a> suggest that the outage landscape is changing in ways that should concern both cloud providers and cloud customers. The biggest risks are no longer limited to broken physical infrastructure. They are increasingly tied to the complexity of the systems used to run, coordinate, update, and recover that infrastructure.</p>



<p>The most alarming number in the report is that IT and networking issues accounted for 23% of impactful outages in 2024. Uptime Institute links these increases to growing IT and network complexity; the long-term shift toward colocation, cloud, and third-party digital services; and the resulting increase in change-management failures and misconfigurations. That number is more than a statistical footnote. It points to a structural change in how outages happen and why cloud outages are becoming such a stubborn problem.</p>



<p>Hardware redundancy can protect against component failures, but it doesn’t help much when the outage stems from a bad configuration, an automation error, a faulty network change, or an underappreciated control-plane dependency. In those cases, the infrastructure itself may remain intact while the system that governs it breaks down. The industry is learning that <a href="https://www.networkworld.com/article/967679/what-is-disaster-recovery-how-to-ensure-business-continuity.html">resiliency</a> is less about duplicating equipment and more about managing complexity. Today’s increasingly distributed and software-defined environments cannot operate safely at scale.</p>



<h2 class="wp-block-heading">Failures at the operational level</h2>



<p>Uptime’s findings show that power remains the leading cause of major outages, underscoring that traditional infrastructure engineering still matters a great deal. But even as providers continue to improve physical resilience, outages can still arise from the digital and procedural layers above it. Cloud platforms are now dense stacks of services, <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">APIs</a>, orchestration systems, software-defined networks, <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity controls</a>, failover logic, and third-party dependencies. That complexity creates more possible points of interaction and more opportunities for an error in one layer to cascade into several others.</p>



<p>This helps explain why outages can feel more surprising today than they did a decade ago. In older data center models, an outage often had a more apparent root cause, such as a power event, a cooling failure, or a hardware fault. In cloud environments, the trigger may be a small configuration change that propagates across regions, a policy update that unintentionally blocks service communication, or a network control failure that affects seemingly unrelated services. These are not failures of raw infrastructure capacity. They are failures of complexity management.</p>



<p>The report’s language around change management and misconfiguration is especially important because it challenges one of the most common assumptions in the cloud market: that scale automatically produces better operational outcomes. The reality? Scale can magnify both strengths and weaknesses. Large cloud providers have more engineering talent, more sophisticated tools, and more redundancy than almost any enterprise customer. But they also run far more interconnected systems at far greater speeds with far more automation. A single process failure can have a wider blast radius.</p>



<p>Another important lesson from the Uptime analysis is that automation has not removed the human factor. If anything, it has changed its form. Even in highly automated environments, human error remains central to the problem. The report notes that in 2025, the share of outages caused by human failure to follow procedures rose by 10 percentage points compared with 2024. A related industry summary of the report notes that 58% of human error-related outages were caused by staff failing to follow established procedures.</p>



<p>That matters because cloud providers often position automation as the answer to reliability. Automation is essential, but it only works as well as the operational model that surrounds it. If teams deploy changes too quickly, rollback paths are weak, approval chains are bypassed, or procedures are incomplete, automation can accelerate failure rather than prevent it. In a modern cloud environment, a human mistake is rarely just a single keystroke. It is more often a design weakness in process, governance, testing, or accountability.</p>



<p>This is also why customers should resist the comforting notion that outages are somebody else’s problem once workloads move to the cloud. Provider-side mistakes remain real, but customer architectures are increasingly entangled with provider networking, identity, observability, and platform services. When an outage occurs, the customer may not have caused it, but they still bear the business impact. The shared responsibility model does not end with security. It extends to resilience planning as well.</p>



<h2 class="wp-block-heading">Better change management</h2>



<p>The Uptime data points to a clear conclusion: Cloud providers need to treat operational discipline as a first-class design requirement. That starts with better change management. High-risk changes should be tested more aggressively, staged more gradually, and accompanied by stronger rollback mechanisms. Providers also need better dependency mapping to understand how a change in one control layer can affect services far beyond its immediate scope. If the system is too complex to clearly explain, it is too complex to operate.</p>



<p>Providers also need to improve procedural quality. The rise in outages caused by failing to follow procedures suggests that procedures are being ignored under operational pressure or that they are too cumbersome, outdated, or unclear for real production conditions. Neither explanation is comforting. Stronger runbooks, better training, more realistic failure drills, and tighter operational guardrails are not glamorous investments; they are increasingly central to resilience.</p>



<p>Another pressure point is visibility. Uptime notes that software-based and distributed resiliency tools can improve availability, but they also introduce new risks and complicate root-cause analysis. Cloud providers need more transparent and faster incident diagnosis, not just more layers of abstraction. Customers cannot build trust in resilience if every major incident becomes a long exercise in reconstructing opaque service dependencies after the fact.</p>



<h2 class="wp-block-heading">Design with outages in mind</h2>



<p>What’s the financial impact of more frequent problems? Uptime’s 2024 analysis found that 54% of respondents reported that their most recent significant outage cost more than $100,000, and 20% said it cost more than $1 million. These are not edge-case losses. They show that outages remain costly even if they are less frequent than in earlier years.</p>



<p>Customers need to stop evaluating cloud resilience through uptime promises and start evaluating it through failure behavior. How does a provider isolate faults? How transparent is incident communication? How portable are workloads if a major service degrades? How dependent is the architecture on a single region, network path, identity service, or control plane? These are not just technical questions; they are now critical business questions.</p>



<p>The core lesson from Uptime’s data is simple. Outages are becoming a bigger problem for cloud providers and customers because the cloud’s biggest vulnerabilities are increasingly tied to complexity, process failures, and control-plane mistakes, not just broken infrastructure. In addition to adding redundancy, the next phase of cloud improvement will focus on building systems that are easier to understand, safer to change, and more disciplined to operate.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[BYD verrät weitere Details zum neuen Kleinwagen für Europa mit über 1000 km Reichweite]]></title>
<description><![CDATA[Der BYD Dolphin G DM-i feiert im Juni 2026 in Berlin Premiere und positioniert sich im europäischen B-Segment, also in derselben Klasse wie viele der beliebtesten Kleinwagen Europas. Das Modell ist 4,16 Meter lang (425 Liter Kofferraumvolumen; durch Umklappen der im Verhältnis 40:60 geteilten Rüc...]]></description>
<link>https://tsecurity.de/de/3592599/it-nachrichten/byd-verraet-weitere-details-zum-neuen-kleinwagen-fuer-europa-mit-ueber-1000-km-reichweite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592599/it-nachrichten/byd-verraet-weitere-details-zum-neuen-kleinwagen-fuer-europa-mit-ueber-1000-km-reichweite/</guid>
<pubDate>Fri, 12 Jun 2026 08:21:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Der BYD Dolphin G DM-i feiert im Juni 2026 in Berlin Premiere und positioniert sich im europäischen B-Segment, also in derselben Klasse wie viele der beliebtesten Kleinwagen Europas. Das Modell ist 4,16 Meter lang (425 Liter Kofferraumvolumen; durch Umklappen der im Verhältnis 40:60 geteilten Rücksitzlehnen lässt sich das Volumen auf bis zu 1225 Liter erweitern) und gehört gleichzeitig zu den wenigen Plug-in-Hybriden dieser Klasse, die einen klaren Schwerpunkt auf längere Reichweiten im Elektrobetrieb legen.</p>



<p>BYD nutzt die firmeneigene DM-i-Technologie (Dual Mode Intelligence), bei der Elektromotor (120 kW/163 PS, 210 Newtonmeter Drehmoment) und Benzinmotor (1,5 Liter Hubraum) je nach Fahrsituation zusammenarbeiten. Damit beschleunigt das Fahrzeug in nur 8,3 Sekunden von 0 auf 100 km/h. Laut BYD soll das Fahrzeug einen Großteil der täglichen Pendelfahrten elektrisch bewältigen können, während die Gesamtreichweite bei 1.040 Kilometern liegen soll (bei voller Ladung und vollem Tank). </p>



<p>Die rein elektrische Reichweite gibt BYD mit der größeren Batterie (18,3 Kilowattstunden) mit 105 Kilometern an. Den Kraftstoffverbrauch gibt BYD mit nur 1,4 Litern pro 100 Kilometer an – bei vollständig geladener Batterie. Bei der kleineren Batterie mit 7,42 Kilowattstunden seien eine rein elektrische WLTP-Reichweite von 40 Kilometern und eine Gesamtreichweite von 1020 Kilometern möglich, wie BYD verspricht.</p>



<p>Im EV-Modus agiert das Fahrzeug wie ein reines Elektroauto: Es nutzt nur die Energie der Batterie, und der Benzinmotor bleibt so lange ausgeschaltet, bis der Ladezustand der Batterie auf ein bestimmtes Niveau abgesunken ist. Dabei kommt ausschließlich der Elektromotor zum Einsatz, der beim Bremsen Energie rekuperiert und die Batterie auflädt.</p>



<p><strong>Aufladen</strong>: Die Active-Modelle verfügen über einen On-Board-Charger mit 3,3 kW, der die Batterie in knapp unter drei Stunden von 15 auf 100 Prozent aufladen soll. Die Versionen Boost, Comfort und Sport erhöhen die Ladeleistung auf 6,6 kW und bieten zusätzlich eine DC-Schnellladefunktion mit bis zu 39 kW. Damit soll die 18,3-Kilowattstunden-Batterie in 26 Minuten von 10 auf 80 Prozent aufladen.</p>



<p>Zur Ausstattung gehören Leichtmetallräder – 16 Zoll bei den Ausstattungen Active und Boost, 18 Zoll im Zweiton-Design in der Comfort-Linie sowie 18 Zoll in Glanzschwarz in der Sport-Version –, LED-Rückleuchten, 8,8‑Zoll‑Digitalinstrument und Infotainment‑Bildschirm (wahlweise mit 10,1 oder 12,8 Zoll Diagonale).</p>



<h2 class="wp-block-heading">Fahrerassistenzsysteme</h2>



<p>Serienmäßig sind alle Versionen mit Front- und Heckparksensoren ausgestattet. Die Varianten Active und Boost bieten zusätzlich eine Rückfahrkamera, während Comfort und Sport dieses System mit einer 360-Grad-Kamera für eine optimale Rundumsicht erweitern.</p>



<p>Zur Fahrerassistenz gehören in allen Ausstattungslinien unter anderem ein adaptiver Tempomat sowie ein intelligenter Tempomat, ein Notfall-Spurhalteassistent und Spurverlassenswarner, Front- und Heck-Querverkehrswarner inklusive Querverkehrsbremsfunktion, Totwinkelwarner, ein Fahrerüberwachungssystem sowie eine Ausstiegswarnung.</p>



<p>Es gibt den BYD Dolphin G DM-i in vier Ausstattungsvarianten und in vier Metallic-Farben: Skiing White (Weiß), Time Grey (Grau), Obsidian Black (Schwarz) und Ocean Blue (Blau), sowie in Uni Oxford White (Weiß) und dem Perleffekt-Lack Orange Sunset (Orange). </p>



<p>Vollständige technische Spezifikationen oder Preise hat BYD noch nicht bekannt gegeben. Der Dolphin G DM-i wird in den kommenden Wochen in Europa in den Verkauf gehen und soll voraussichtlich im Frühherbst in Deutschland ausgeliefert werden. Es ist das erste Mal, dass BYD ein Modell von Grund auf speziell für internationale Märkte entwickelt, wobei Europa als klarer Zielmarkt im Fokus steht.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a2ba4e34b19d"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/BYDtec.jpg?quality=50&amp;strip=all" alt="BYD Dolphin G DM-i" class="wp-image-3162110" width="496" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>BYD Dolphin G DM-i</p>
</figcaption></figure><p class="imageCredit">BYD</p></div>



<h2 class="wp-block-heading">Mehr zu BYD lesen (Auto-Testberichte):</h2>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3118048/byd-sealion-7-test.html" target="_blank" rel="noreferrer noopener">BYD Sealion 7 im Test: Komfortabler Elektro-SUV mit nervigen Warnsystemen</a></li>



<li><a href="https://www.pcwelt.de/article/2437683/byd-seal-chinesischer-tesla-herausforderer-e-auto-test.html" target="_blank" rel="noreferrer noopener">BYD Seal im Test: Konkurrenz für Tesla? Die Antwort!</a></li>



<li><a href="https://www.pcwelt.de/article/2291316/byd-dolphin-test.html" target="_blank" rel="noreferrer noopener">BYD Dolphin im Test: Kein Traumauto, aber ein echter Konkurrent in der Einsteigerklasse</a></li>



<li><a href="https://www.pcwelt.de/article/2893067/472-km-h-elektro-supersportwagen-byd-yangwang-u9-geschwindigkeitsweltrekord.html" target="_blank" rel="noreferrer noopener">472,41 km/h: Elektro-Supersportwagen BYD Yangwang U9 fährt Geschwindigkeitsweltrekord</a></li>
</ul>



<h2 class="wp-block-heading">Wie alles begann:</h2>



<p><a href="https://www.pcwelt.de/article/2085810/tesla-byd-vergleich.html" target="_blank" rel="noreferrer noopener">Tesla und BYD im Vergleich – wer hat die Nase vorn?</a> Wir haben 2023 die beiden Marken miteinander verglichen. Damals war das Kürzel BYD noch nicht jedem Auto-Interessierten ein Begriff. Obwohl im Jahr 2022 der chinesische Autohersteller BYD mit damals mehr als 1,85 Millionen verkauften E-Autos den bisherigen Branchenprimus <a href="https://www.pcwelt.de/article/2085810/tesla-byd-vergleich.html#" target="_blank" rel="noreferrer noopener">Tesla</a> überholt hatte und seitdem als weltweit größter Hersteller für Elektrofahrzeuge gilt. </p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Agent übernimmt Slack-Support bei Notion – und löst 60 Prozent der Fälle selbst]]></title>
<description><![CDATA[Ein gut gepflegtes Wiki löst kein Support-Problem, Mitarbeitende fragen trotzdem in Slack. Wie ein KI-Agent das ändert.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3592456/it-nachrichten/ki-agent-uebernimmt-slack-support-bei-notion-und-loest-60-prozent-der-faelle-selbst/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592456/it-nachrichten/ki-agent-uebernimmt-slack-support-bei-notion-und-loest-60-prozent-der-faelle-selbst/</guid>
<pubDate>Fri, 12 Jun 2026 07:16:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein gut gepflegtes Wiki löst kein Support-Problem, Mitarbeitende fragen trotzdem in Slack. Wie ein KI-Agent das ändert.<a href="https://t3n.de/news/ki-agent-slack-support-notion-60-prozent-1746434/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Plesk Obsidian 18.0.78: Automatic Let’s Encrypt Mail Security and MFA Flexibility]]></title>
<description><![CDATA[Plesk Obsidian 18.0.78 introduces smarter SSL/TLS defaults that help secure newly deployed servers automatically and gives administrators more flexibility when using multi-factor authentication. This update also improves the GoAccess experience, and delivers a broad range of stability, compatibil...]]></description>
<link>https://tsecurity.de/de/3590380/server/plesk-obsidian-18078-automatic-lets-encrypt-mail-security-and-mfa-flexibility/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590380/server/plesk-obsidian-18078-automatic-lets-encrypt-mail-security-and-mfa-flexibility/</guid>
<pubDate>Thu, 11 Jun 2026 13:45:29 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Plesk Obsidian 18.0.78 introduces smarter SSL/TLS defaults that help secure newly deployed servers automatically and gives administrators more flexibility when using multi-factor authentication. This update also improves the GoAccess experience, and delivers a broad range of stability, compatibility, and security improvements across Linux and Windows. Smarter SSL/TLS Management Starting with Plesk Obsidian 18.0.78, when a new Plesk server is deployed […]</p>
<p>The post <a href="https://www.plesk.com/blog/plesk-news-announcements/plesk-obsidian-18-0-78/" data-wpel-link="internal">Plesk Obsidian 18.0.78: Automatic Let’s Encrypt Mail Security and MFA Flexibility</a> appeared first on <a href="https://www.plesk.com/" data-wpel-link="internal">Plesk</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 NotebookLM Alternatives Worth Considering in 2026]]></title>
<description><![CDATA[Compare NotebookLM with Notion, Obsidian, Recall, Atlas, and Open Notebook to find the best AI research and knowledge management tool for your workflow.]]></description>
<link>https://tsecurity.de/de/3588889/it-nachrichten/5-notebooklm-alternatives-worth-considering-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588889/it-nachrichten/5-notebooklm-alternatives-worth-considering-in-2026/</guid>
<pubDate>Wed, 10 Jun 2026 23:02:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Compare NotebookLM with Notion, Obsidian, Recall, Atlas, and Open Notebook to find the best AI research and knowledge management tool for your workflow.]]></content:encoded>
</item>
<item>
<title><![CDATA[BYD verrät weitere Details zum neuen Kleinwagen für Europa mit über 1000 km Reichweite]]></title>
<description><![CDATA[Der BYD Dolphin G DM-i feiert im Juni 2026 in Berlin Premiere und positioniert sich im europäischen B-Segment, also in derselben Klasse wie viele der beliebtesten Kleinwagen Europas. Das Modell ist 4,16 Meter lang (425 Liter Kofferraumvolumen; durch Umklappen der im Verhältnis 40:60 geteilten Rüc...]]></description>
<link>https://tsecurity.de/de/3588039/it-nachrichten/byd-verraet-weitere-details-zum-neuen-kleinwagen-fuer-europa-mit-ueber-1000-km-reichweite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588039/it-nachrichten/byd-verraet-weitere-details-zum-neuen-kleinwagen-fuer-europa-mit-ueber-1000-km-reichweite/</guid>
<pubDate>Wed, 10 Jun 2026 16:49:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Der BYD Dolphin G DM-i feiert im Juni 2026 in Berlin Premiere und positioniert sich im europäischen B-Segment, also in derselben Klasse wie viele der beliebtesten Kleinwagen Europas. Das Modell ist 4,16 Meter lang (425 Liter Kofferraumvolumen; durch Umklappen der im Verhältnis 40:60 geteilten Rücksitzlehnen lässt sich das Volumen auf bis zu 1225 Liter erweitern) und gehört gleichzeitig zu den wenigen Plug-in-Hybriden dieser Klasse, die einen klaren Schwerpunkt auf längere Reichweiten im Elektrobetrieb legen.</p>



<p>BYD nutzt die firmeneigene DM-i-Technologie (Dual Mode Intelligence), bei der Elektromotor (120 kW/163 PS, 210 Newtonmeter Drehmoment) und Benzinmotor (1,5 Liter Hubraum) je nach Fahrsituation zusammenarbeiten. Damit beschleunigt das Fahrzeug in nur 8,3 Sekunden von 0 auf 100 km/h. Laut BYD soll das Fahrzeug einen Großteil der täglichen Pendelfahrten elektrisch bewältigen können, während die Gesamtreichweite bei 1.040 Kilometern liegen soll (bei voller Ladung und vollem Tank). </p>



<p>Die rein elektrische Reichweite gibt BYD mit der größeren Batterie (18,3 Kilowattstunden) mit 105 Kilometern an. Den Kraftstoffverbrauch gibt BYD mit nur 1,4 Litern pro 100 Kilometer an – bei vollständig geladener Batterie. Bei der kleineren Batterie mit 7,42 Kilowattstunden seien eine rein elektrische WLTP-Reichweite von 40 Kilometern und eine Gesamtreichweite von 1020 Kilometern möglich, wie BYD verspricht.</p>



<p>Im EV-Modus agiert das Fahrzeug wie ein reines Elektroauto: Es nutzt nur die Energie der Batterie, und der Benzinmotor bleibt so lange ausgeschaltet, bis der Ladezustand der Batterie auf ein bestimmtes Niveau abgesunken ist. Dabei kommt ausschließlich der Elektromotor zum Einsatz, der beim Bremsen Energie rekuperiert und die Batterie auflädt.</p>



<p><strong>Aufladen</strong>: Die Active-Modelle verfügen über einen On-Board-Charger mit 3,3 kW, der die Batterie in knapp unter drei Stunden von 15 auf 100 Prozent aufladen soll. Die Versionen Boost, Comfort und Sport erhöhen die Ladeleistung auf 6,6 kW und bieten zusätzlich eine DC-Schnellladefunktion mit bis zu 39 kW. Damit soll die 18,3-Kilowattstunden-Batterie in 26 Minuten von 10 auf 80 Prozent aufladen.</p>



<p>Zur Ausstattung gehören Leichtmetallräder – 16 Zoll bei den Ausstattungen Active und Boost, 18 Zoll im Zweiton-Design in der Comfort-Linie sowie 18 Zoll in Glanzschwarz in der Sport-Version –, LED-Rückleuchten, 8,8‑Zoll‑Digitalinstrument und Infotainment‑Bildschirm (wahlweise mit 10,1 oder 12,8 Zoll Diagonale).</p>



<h2 class="wp-block-heading">Fahrerassistenzsysteme</h2>



<p>Serienmäßig sind alle Versionen mit Front- und Heckparksensoren ausgestattet. Die Varianten Active und Boost bieten zusätzlich eine Rückfahrkamera, während Comfort und Sport dieses System mit einer 360-Grad-Kamera für eine optimale Rundumsicht erweitern.</p>



<p>Zur Fahrerassistenz gehören in allen Ausstattungslinien unter anderem ein adaptiver Tempomat sowie ein intelligenter Tempomat, ein Notfall-Spurhalteassistent und Spurverlassenswarner, Front- und Heck-Querverkehrswarner inklusive Querverkehrsbremsfunktion, Totwinkelwarner, ein Fahrerüberwachungssystem sowie eine Ausstiegswarnung.</p>



<p>Es gibt den BYD Dolphin G DM-i in vier Ausstattungsvarianten und in vier Metallic-Farben: Skiing White (Weiß), Time Grey (Grau), Obsidian Black (Schwarz) und Ocean Blue (Blau), sowie in Uni Oxford White (Weiß) und dem Perleffekt-Lack Orange Sunset (Orange). </p>



<p>Vollständige technische Spezifikationen oder Preise hat BYD noch nicht bekannt gegeben. Der Dolphin G DM-i wird in den kommenden Wochen in Europa in den Verkauf gehen und soll voraussichtlich im Frühherbst in Deutschland ausgeliefert werden. Es ist das erste Mal, dass BYD ein Modell von Grund auf speziell für internationale Märkte entwickelt, wobei Europa als klarer Zielmarkt im Fokus steht.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a29786cb7ed1"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/BYDtec.jpg?quality=50&amp;strip=all" alt="BYD Dolphin G DM-i" class="wp-image-3162110" width="496" height="763" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>BYD Dolphin G DM-i</p>
</figcaption></figure><p class="imageCredit">BYD</p></div>



<h2 class="wp-block-heading">Mehr zu BYD lesen (Auto-Testberichte):</h2>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3118048/byd-sealion-7-test.html" target="_blank" rel="noreferrer noopener">BYD Sealion 7 im Test: Komfortabler Elektro-SUV mit nervigen Warnsystemen</a></li>



<li><a href="https://www.pcwelt.de/article/2437683/byd-seal-chinesischer-tesla-herausforderer-e-auto-test.html" target="_blank" rel="noreferrer noopener">BYD Seal im Test: Konkurrenz für Tesla? Die Antwort!</a></li>



<li><a href="https://www.pcwelt.de/article/2291316/byd-dolphin-test.html" target="_blank" rel="noreferrer noopener">BYD Dolphin im Test: Kein Traumauto, aber ein echter Konkurrent in der Einsteigerklasse</a></li>



<li><a href="https://www.pcwelt.de/article/2893067/472-km-h-elektro-supersportwagen-byd-yangwang-u9-geschwindigkeitsweltrekord.html" target="_blank" rel="noreferrer noopener">472,41 km/h: Elektro-Supersportwagen BYD Yangwang U9 fährt Geschwindigkeitsweltrekord</a></li>
</ul>



<h2 class="wp-block-heading">Wie alles begann:</h2>



<p><a href="https://www.pcwelt.de/article/2085810/tesla-byd-vergleich.html" target="_blank" rel="noreferrer noopener">Tesla und BYD im Vergleich – wer hat die Nase vorn?</a> Wir haben 2023 die beiden Marken miteinander verglichen. Damals war das Kürzel BYD noch nicht jedem Auto-Interessierten ein Begriff. Obwohl im Jahr 2022 der chinesische Autohersteller BYD mit damals mehr als 1,85 Millionen verkauften E-Autos den bisherigen Branchenprimus <a href="https://www.pcwelt.de/article/2085810/tesla-byd-vergleich.html#" target="_blank" rel="noreferrer noopener">Tesla</a> überholt hatte und seitdem als weltweit größter Hersteller für Elektrofahrzeuge gilt. </p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Agent in Slack: 60 Prozent der Anfragen automatisch gelöst, 30 Stunden gespart]]></title>
<description><![CDATA[Ein gut gepflegtes Wiki löst kein Support-Problem – Mitarbeitende fragen trotzdem in Slack. Wie ein KI-Agent das ändert.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3587633/it-nachrichten/ki-agent-in-slack-60-prozent-der-anfragen-automatisch-geloest-30-stunden-gespart/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587633/it-nachrichten/ki-agent-in-slack-60-prozent-der-anfragen-automatisch-geloest-30-stunden-gespart/</guid>
<pubDate>Wed, 10 Jun 2026 14:33:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein gut gepflegtes Wiki löst kein Support-Problem – Mitarbeitende fragen trotzdem in Slack. Wie ein KI-Agent das ändert.<a href="https://t3n.de/news/ki-agent-interner-support-notion-1746434/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic brings Mythos to the masses with Claude Fable 5, its most powerful generally available model ever]]></title>
<description><![CDATA[Anthropic today launched two new AI models — Claude Fable 5 and Claude Mythos 5 — marking the company’s first broad release of the powerful “Mythos-class” AI capabilities it previously made available only to participating organizations in its restricted cybersecurity program, Project Glasswing, w...]]></description>
<link>https://tsecurity.de/de/3585604/it-nachrichten/anthropic-brings-mythos-to-the-masses-with-claude-fable-5-its-most-powerful-generally-available-model-ever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585604/it-nachrichten/anthropic-brings-mythos-to-the-masses-with-claude-fable-5-its-most-powerful-generally-available-model-ever/</guid>
<pubDate>Tue, 09 Jun 2026 20:32:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Anthropic today <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">launched two new AI models </a>— Claude Fable 5 and Claude Mythos 5 — marking the company’s first broad release of the powerful “Mythos-class” AI capabilities it previously made available only to participating organizations in its restricted cybersecurity program, <a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release">Project Glasswing</a>, which it announced two months ago.</p><p>The company says Fable 5, which is the version most users and developers will get starting today, exceeds every Claude model it has previously made generally available — featuring stronger performance across software engineering, knowledge work, vision, scientific research and long-running tasks. </p><p>It smashes the existing benchmarks and comes atop on nearly all of them, though the prior Claude Mythos Preview version of the model still takes the top spots on computer use and multidisciplinary reasoning (see benchmark chart below and <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">here</a>). </p><p>The new Claude Mythos 5, by contrast, is a more restricted, upgraded version of the prior, similarly restricted Mythos Preview model. As such, it has certain safeguards lifted for approved users, including Anthropic's cybersecurity partners in its Project Glasswing effort, and select biology researchers. </p><p>The key difference is that the general purpose Fable 5 wraps the same underlying Mythos-class capability in new safeguards. Anthropic says requests involving certain high-risk areas — including cybersecurity, biology and chemistry, and model distillation — are automatically routed to <a href="https://venturebeat.com/technology/anthropics-claude-opus-4-8-is-here-with-3x-cheaper-fast-mode-and-near-mythos-level-alignment">Claude Opus 4.8,</a> Anthropic's previously flagship general model, instead, with users notified when that happens. </p><p>The company says more than 95% of Fable sessions run entirely on Fable’s own responses, with no fallback, and that internal and external red-teaming efforts found no “universal jailbreaks” after more than 1,000 hours of testing.</p><p>Anthropic says Fable 5 is available to the general public today through its website, apps, and <a href="https://platform.claude.com/docs/en/about-claude/models/overview">API</a>, but that Mythos 5 will initially only be made available to users who already have access to the older Claude Mythos Preview.</p><h2><b>Pricing, access and a tricky rollout</b></h2><p>Anthropic is pricing both Fable 5 and Mythos 5 at $10 per million input tokens and $50 per million output tokens. The company says that is less than half the price of Claude Mythos Preview, but still ranks as the most expensive of major AI models available globally. </p><h1><b>VentureBeat Frontier AI Model API Pricing Snapshot</b></h1><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input</b></p></td><td><p><b>Output</b></p></td><td><p><b>Total Cost</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>GLM-5</p></td><td><p>$1.00</p></td><td><p>$3.20</p></td><td><p>$4.20</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k26">Moonshot/Kimi</a></p></td></tr><tr><td><p>GLM-5.1</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?spm=a2ty_o05.31384571.0.0.52649f6b7G0D55&amp;tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p><b>Claude Fable 5 / Claude Mythos 5</b></p></td><td><p><b>$10.00</b></p></td><td><p><b>$50.00</b></p></td><td><p><b>$60.00</b></p></td><td><p><b></b><a href="https://platform.claude.com/docs/en/about-claude/models/overview"><b>Anthropic</b></a></p></td></tr></tbody></table><p>For developers, Fable 5 is available through the Claude API as <code>claude-fable-5</code>. Anthropic says Fable 5 is fully available today on the Claude API and on consumption-based Enterprise plans.</p><p>For subscription users, the rollout is more complicated. Anthropic says Fable 5 will be included on Pro, Max, Team and seat-based Enterprise plans at no extra cost from today through June 22. </p><p>On June 23, the company plans to remove Fable 5 from those plans, after which using it will require usage credits. Anthropic says it aims to restore Fable 5 as a standard part of subscription plans as quickly as possible.</p><h2><b>The difference between Fable 5 and Mythos 5</b></h2><p>Anthropic is not presenting Fable 5 and Mythos 5 as two separate models in the usual “small versus large” sense. Instead, they appear to share the same base capability level. The difference is access <i>control — </i>that is, how easily it will be for users to get their hands on the models, and the guardrails embedded in each.</p><p>As previously mentioned Fable 5 includes a new safeguard layer that detects certain high-risk requests — including cybersecurity, biology and chemistry, and attempts to distill the model’s capabilities into other systems — and routes those requests to Claude Opus 4.8. </p><p>Mythos 5 lifts some of those restrictions for trusted users working in approved domains.</p><p>In practical terms, Mythos 5 is more powerful for sensitive cyber and biology work because it can answer in areas where Fable 5 falls back. </p><p>For most ordinary enterprise and developer tasks, however, Anthropic says Fable 5 performs effectively the same as Mythos 5.</p><p>The launch also signals how Anthropic plans to bring frontier models with dangerous dual-use capabilities into the market: not by releasing all capabilities to everyone, and not by simply refusing risky questions, but by routing some requests to a less capable model while keeping the stronger model available for the majority of everyday work.</p><h2><b>A major improvement in autonomous coding</b></h2><p>For enterprise buyers, the most immediate use case is likely software engineering. Anthropic says Fable 5 can work unattended for longer and with more independence than previous Claude models, which is exactly the capability enterprises need if they want AI agents to do more than autocomplete code or answer developer questions.</p><p>On <b>SWE-bench Pro, which measures a model's ability to complete difficult software engineering tasks, Anthropic says Fable 5 and Mythos 5 reach 80.3%</b>, vastly outperforming OpenAI's latest and greatest general model GPT-5.5, which scored 58.6%. </p><p>On Cognition’s FrontierCode Diamond benchmark, which tests high-quality, maintainable agentic coding, the models score 29.3%, compared with 13.4% for Claude Opus 4.8 and 5.7% for GPT-5.5, according to the benchmark table included in Anthropic’s materials. </p><p>Anthropic also says Fable 5 scores highest among frontier models on FrontierCode even at medium reasoning effort, suggesting the model may deliver stronger coding results without always needing maximum compute.</p><p>The most striking customer example comes from Stripe. Anthropic says Stripe tested Fable 5 in a 50-million-line Ruby codebase and found that the model completed a codebase-wide migration in one day that otherwise would have taken a team more than two months by hand. Stripe said, “Fable 5 compresses months of engineering into days. In our 50-million-line Ruby codebase, it did in a day what would've taken us more than two months by hand.”</p><p>Other early users describe the model as especially useful for long-horizon development tasks. Cursor said, “Fable 5 is the state of the art model on CursorBench. It's opened up a class of long-horizon problems that were out of reach for earlier models.” Replit said Fable 5 is the highest-performing model it has tested on ViBench, its end-to-end “vibe-coding” benchmark, and that it builds apps in less time with fewer tokens. Figma said Fable 5 is “a clear step forward on agentic coding and prototyping.”</p><p>This is the enterprise shift Anthropic is trying to sell: AI coding systems that can take on larger units of work, not just individual tickets. That could include codebase migrations, app prototyping, pull request review, test generation, debugging across unfamiliar tools, user interface design and multi-step internal software projects.</p><p>Base44 said, “Fable 5 is much deeper and better at one-shotting full apps, and its tool calling is excellent.” Genspark said, “Fable 5 came out #1 on our evals, winning head-to-head against every model we tested. It was significantly stronger on the hardest tasks in the set — UI design and game coding.” Rakuten said, “At the highest effort, Fable 5 reflects on and validates its own work. For us, that's what makes highly autonomous operations possible — the extra thinking pays for itself.”</p><p>For CTOs and engineering leaders, that suggests the model’s value may come less from raw code generation and more from sustained execution: understanding an intent, planning steps, calling tools, checking its own work and continuing through a task without constant human steering.</p><h2><b>Knowledge work, finance, legal and operations</b></h2><p>Anthropic is also positioning Fable 5 as a stronger model for enterprise knowledge work. On GDPval-AA, Anthropic reports a score of 1932 for Fable 5 and Mythos 5, compared with 1890 for Claude Opus 4.8, 1769 for GPT-5.5 and 1314 for Gemini 3.1 Pro. </p><p>On GDPpdf, a benchmark focused on visual document reasoning, Fable 5 and Mythos 5 score 29.8% without tools, compared with 22.5% for Opus 4.8, 24.9% for GPT-5.5 and 16.7% for Gemini 3.1 Pro.</p><p>That matters for enterprises because much of corporate work still lives in messy documents: PDFs, spreadsheets, charts, reports, contracts, filings, slide decks and screenshots. Anthropic says Fable 5 shows gains in document-based reasoning, chart and table interpretation and complex problem solving.</p><p>Hex said, “Fable 5 is the first to break 90% on our core analytics benchmark of complex, long-running analytical tasks — a 10-point jump over Opus. On the hardest questions, it shows strong judgment and attention to nuance.” Hebbia said Fable 5 was the highest-scoring model on its Finance Benchmark for senior-level reasoning, with double-digit gains in document reasoning, chart and table interpretation, and problem solving.</p><p>The finance examples are notable because they point to AI agents moving beyond summarization into higher-stakes analytical workflows. </p><p>IMC said Fable 5 “aced our trading-analysis evaluations nearly across the board: factual lookup, conceptual reasoning, root-cause analysis, expected-value analysis.” Optiver said the model was stronger than Opus 4.8 on its trading benchmark and “remarkably consistent,” scoring identically across repeated runs. Balyasny Asset Management said Fable 5 was the strongest finance-first model it had tested.</p><p>Legal and operations teams may also see immediate impact. Crosby Legal said, “Fable 5 feels materially different. In blind review, our lawyers found its redlines matched or beat our current model every time.” Notion said the model can take work “you'd chip away at all afternoon” and turn messy notes into a functioning project plan. Zapier said Fable 5 is the new leader on AutomationBench and is more autonomous than Opus 4.8: “Where Opus stops to ask, Fable 5 keeps looking.”</p><p>For enterprise software vendors, that points toward more capable embedded agents in workflow products: agents that can review a contract, update a project plan, assemble a spreadsheet, inspect a chart, file a ticket, run a query, call an internal API and keep going until the work is complete.</p><h2><b>Vision and interface understanding</b></h2><p>Anthropic says Fable 5 is also its strongest vision model. In its launch materials, the company says the model can extract precise numbers from detailed scientific figures and complete vision-based tasks such as rebuilding a web app’s source code from screenshots alone.</p><p>That has immediate implications for enterprise automation. Many business processes still depend on visual interfaces that are not cleanly exposed through APIs: dashboards, PDFs, forms, legacy apps, screenshots, scans and image-heavy reports. A stronger vision model could help agents operate across those environments with less custom integration work.</p><p>Anthropic also says Fable 5 needs less scaffolding than previous Claude models. As an example, the company says earlier Claude models struggled to play Pokémon FireRed even with extra tools, while <a href="https://youtu.be/CIQBP1w4B1M?si=QCoJ9amBEVMqoTUl">Fable 5 impressively beat the game using a minimal vision-only harness. </a>Anthropic posted a fast forwarded video of its playthrough to YouTube and in its blog post:</p><div></div><p>The point is not gaming itself, but the broader agentic skill: reading a visual environment, remembering progress, deciding what to do next and executing over a long horizon.</p><p>In another internal test, Anthropic says it had the model play the deck-building game Slay the Spire with access to persistent file-based memory. The company says persistent memory improved Fable 5’s performance three times more than it improved Opus 4.8’s, and that Fable reached the game’s final act three times more often. For enterprise users, this suggests Fable 5 may make better use of notes, logs and stored context during multi-step work.</p><p>That could matter for internal agents that operate over days or weeks: sales operations agents that track account research, engineering agents that manage migrations, finance agents that update models, or support agents that remember what they tried across many turns.</p><h2><b>From restricted cyber model to general-purpose enterprise AI</b></h2><p>The announcement follows Anthropic’s April 2025 rollout of Claude Mythos Preview through <a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release">Project Glasswing</a>, a restricted program for cyber defenders, critical infrastructure providers and major software maintainers. Anthropic created Glasswing after internal evaluations showed Mythos-class models could find and exploit software vulnerabilities at a level that raised meaningful misuse concerns.</p><p>Following the debut of Glasswing and Mythos, <a href="https://www.nextgov.com/cybersecurity/2026/04/anthropics-glasswing-initiative-raises-questions-us-cyber-operations/412721/">U.S. officials and intelligence agencies began weighing</a> how such models could reshape both cyber defense and offensive operations, while Sen. Mark Warner warned that AI-assisted vulnerability discovery should force industry to “accelerate and reprioritize patching.” Financial regulators also took notice: <a href="https://www.theguardian.com/technology/2026/apr/22/what-is-anthropic-mythos-ai-threat-global-cybersecurity">The Guardian reported</a> that Mythos entered discussions among senior banking officials and regulators in the U.S. and U.K. because of fears that AI-accelerated cyberattacks could threaten payment systems and broader financial stability.</p><p>The reaction has not been limited to alarm. Governments also want access: <a href="https://www.reuters.com/legal/litigation/south-korea-secures-access-anthropics-mythos-ai-model-science-ministry-says-2026-06-03/">Reuters reported</a> that South Korea’s national internet security agency had secured Mythos access through Project Glasswing, reflecting a broader geopolitical race to use frontier AI for national cyber defense. At the same time, Anthropic has faced scrutiny over whether it can safely gate the very capabilities it says are too risky for general release. <a href="https://www.theverge.com/ai-artificial-intelligence/917644/anthropic-claude-mythos-breach-humiliation">The Verge reported</a> that unauthorized users accessed Mythos after its limited rollout, calling the incident damaging for a company that has built its brand around responsible AI. </p><p>Critics have also questioned whether Anthropic’s warning-heavy framing risks becoming a form of market positioning, since it casts the company as both the source of the new capability and the gatekeeper deciding which governments, companies and researchers get to use it.</p><p>With Fable 5, Anthropic is leaning into its gatekeeper role, attempting to separate the general enterprise value of a Mythos-class model from the riskiest parts of its capability profile. The company says Fable 5 can handle software engineering, research, visual reasoning, document analysis and long-running agentic workflows, while classifiers block or reroute requests that could provide what Anthropic calls “uplift” to malicious actors.</p><p>Those classifiers cover three main areas. </p><ol><li><p>Cybersecurity, where Anthropic says Mythos-class models can discover and exploit vulnerabilities and perform broader “agentic hacking” tasks such as reconnaissance, discovery and lateral movement. </p></li><li><p>Biology and chemistry, where the company says the same reasoning that can help researchers design therapies could also help well-resourced malicious actors pursue dangerous biological work. </p></li><li><p>Model distillation, where Anthropic says users may try to extract Claude’s capabilities to train competing models, including models that could be released without similar safeguards.</p></li></ol><p>When Fable 5’s classifiers detect one of those categories, the response is automatically handled by Claude Opus 4.8. Anthropic says users will be told when this happens. That is a notable product decision: rather than declining those requests outright, Anthropic is trying to keep the user experience functional while reducing access to the most capable version of the model in sensitive areas.</p><p>Anthropic says it red-teamed the new classifier system internally and externally. The company says an internal bug bounty produced no universal jailbreaks after more than 1,000 hours of testing, and external red-teaming organizations also failed to find a universal jailbreak. One external partner found that Fable 5 complied with zero harmful single-turn cyber requests related to planning cyberattacks, exploit development or defense evasion, even when prompts used any of 30 public jailbreak techniques, according to Anthropic.</p><p>The company is still acknowledging tradeoffs. Anthropic says the safeguards are deliberately cautious and may sometimes trigger on benign requests. That could frustrate security professionals, biology researchers and advanced enterprise users whose legitimate work overlaps with the blocked categories. The company says it plans to reduce false positives over time.</p><h2><b>Mythos 5 and the restricted frontier</b></h2><p>While Fable 5 is the broad commercial launch, Mythos 5 is the model to watch for enterprises operating in security, critical infrastructure and life sciences.</p><p>The company says all users with Claude Mythos Preview access can upgrade to Mythos 5 beginning today. It plans to expand access through a trusted access program, in collaboration with the U.S. government.</p><p>The distinction is important for sectors where the blocked capabilities are not edge cases but core workflows. A security team may need to reproduce vulnerabilities, test exploitability, analyze lateral movement or simulate attacker behavior in a controlled environment. A biology research team may need to reason through molecular design workflows that would trigger general-use safeguards. Fable 5 is not designed to give every user unrestricted access to those capabilities; Mythos 5 is designed for vetted users who need them.</p><p>Anthropic says Mythos 5 has the strongest cybersecurity capabilities of any model in the world. In the company’s benchmark table, the model family scores 78.0% on ExploitBench, compared with 69.0% for Claude Mythos Preview, 40.0% for Opus 4.8 and 34.0% for GPT-5.5. On CyberGym, Anthropic’s chart shows Mythos 5 at 83.8%, slightly ahead of Mythos Preview at 83.1% and far above Opus 4.8 with default safeguards.</p><p>The company is making a similar argument in biology. Anthropic says Mythos-class models outperform dedicated protein language models on a task involving adeno-associated viruses, a delivery mechanism used in gene therapies. The company frames that as both promising and risky: the same capability that could help gene therapy research could also be misused in dangerous biological work.</p><p>Anthropic says its internal protein design experts used Mythos 5 to accelerate parts of the drug design process by about tenfold. In one example, the company says Mythos 5, using protein design and bioinformatics tools without human assistance, matched or beat skilled human operators by choosing binding sites, selecting and running tools, and recovering from failures. Anthropic says nine of 14 protein targets in the study produced strong candidates for drug design that it is now investigating.</p><p>The company also says Mythos 5 produced novel molecular biology hypotheses that Anthropic scientists preferred over Opus-class model hypotheses about 80% of the time in blinded comparisons. Anthropic says several of those ideas have advanced to experimental evaluation, and one hypothesis involving an E. coli protein was later corroborated by an independent lab working on the same problem.</p><p>Those claims are potentially significant, but they should be treated carefully until more details are published. Anthropic says it intends to publish additional results in the coming months. For now, the strongest enterprise implication is directional: the company believes its highest-end models can already perform parts of scientific research workflows with less human intervention than prior systems.</p><h2><b>New, longer data retention requirement</b></h2><p>The company also introduced a new data-retention policy for Mythos-class models. Anthropic says it will require 30-day retention for all traffic on Fable 5, Mythos 5 and future models with similar or higher capability levels, across both first-party and third-party surfaces. The company says it will not use that data to train new Claude models or for non-safety purposes, and says it has added privacy protections including logging human access and deleting the data after 30 days in almost all cases.</p><p>That policy may become one of the most important enterprise buying questions around Fable 5. Many businesses want frontier AI capability but also want strict control over data retention, especially in regulated sectors. Anthropic’s position is that stronger monitoring is necessary for models with this level of capability. Enterprise customers will have to decide whether the capability gain justifies the retention requirement.</p><h2><b>Enterprise implications</b></h2><p>The broader enterprise significance of Fable 5 is that Anthropic is trying to commercialize a more autonomous class of AI model without exposing all of its capabilities to every user. That could become a template for how frontier labs release increasingly powerful systems: one model family, multiple access tiers, and domain-specific restrictions depending on user trust and risk.</p><p>If Fable 5 performs as Anthropic and early customers describe, developers may hand off larger tasks: code migrations, refactors, UI builds, test writing, bug fixing, documentation, internal tooling and multi-step app creation. </p><p>For knowledge-work-heavy enterprises, Fable 5 could make AI more useful in workflows where earlier models were too brittle: finance research, spreadsheet analysis, legal redlines, procurement review, board materials, market research, sales operations and project planning. The main gain is not just better answers; it is fewer turns, fewer corrections and more ability to keep working through ambiguity.</p><p>For security teams, the launch is more complicated. Most organizations will get Fable 5, not unrestricted Mythos 5. That means they may see stronger general coding and analysis, but not full access to the cyber capabilities Anthropic considers risky. Trusted defenders inside Project Glasswing will get Mythos 5, giving them a more direct way to use the model for vulnerability discovery and defensive testing.</p><p>For life sciences companies, the pattern is similar. Fable 5 may help with general research, literature analysis, data interpretation and scientific reasoning, but the more sensitive biological capabilities will be restricted. Anthropic is effectively creating a separate access path for vetted researchers whose work requires capabilities that could be dangerous in the wrong hands.</p><p>The launch also raises competitive pressure across the AI industry. Anthropic is claiming state-of-the-art results across agentic coding, knowledge work, vision, cybersecurity, legal reasoning, spatial reasoning and health benchmarks. But the more strategically important claim may be that it has found a workable release mechanism for models above its Opus class. If Fable 5’s safeguards hold up under real-world use, Anthropic will argue it can bring more powerful models to market sooner without fully opening the riskiest capabilities.</p><p>That is still a large “if.” The enterprise market will test not only Fable 5’s benchmark performance, but also its reliability, false-positive rate, data-retention tradeoffs and cost at scale. A model that can complete more work autonomously can also burn more tokens, trigger more governance questions and create new review burdens for teams that must verify its output.</p><p>Still, today’s launch marks a clear shift in the Claude lineup. Opus is no longer Anthropic’s top commercial capability tier. Mythos-class models now sit above it. Fable 5 is the first version of that tier for general users; Mythos 5 is the restricted version for trusted high-risk work. Together, they show how Anthropic plans to push frontier AI deeper into enterprise workflows while trying to keep the most dangerous capabilities gated.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion restores access to Anthropic after service disruption]]></title>
<description><![CDATA[Notion's head of product said he was "astonished" at “the amount of people RT-ing this."]]></description>
<link>https://tsecurity.de/de/3579796/it-nachrichten/notion-restores-access-to-anthropic-after-service-disruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579796/it-nachrichten/notion-restores-access-to-anthropic-after-service-disruption/</guid>
<pubDate>Sun, 07 Jun 2026 20:03:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Notion's head of product said he was "astonished" at “the amount of people RT-ing this."]]></content:encoded>
</item>
<item>
<title><![CDATA[Grounded 2 is coming to PlayStation 5, marking another Xbox console exclusive moving beyond the platform]]></title>
<description><![CDATA[Grounded 2 is heading to PlayStation 5 on August 11 alongside its Into the Abyss update. The announcement makes it the latest Xbox-published title to lose console exclusivity while Obsidian also unveils a roadmap packed with new features and content.]]></description>
<link>https://tsecurity.de/de/3577822/windows-tipps/grounded-2-is-coming-to-playstation-5-marking-another-xbox-console-exclusive-moving-beyond-the-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577822/windows-tipps/grounded-2-is-coming-to-playstation-5-marking-another-xbox-console-exclusive-moving-beyond-the-platform/</guid>
<pubDate>Sat, 06 Jun 2026 15:56:31 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Grounded 2 is heading to PlayStation 5 on August 11 alongside its Into the Abyss update. The announcement makes it the latest Xbox-published title to lose console exclusivity while Obsidian also unveils a roadmap packed with new features and content.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft's AI Futurist explains how he uses Copilot — and the real-world problems enterprises are solving with agents]]></title>
<description><![CDATA[Microsoft used its Build 2026 conference this week to push a clear message: agents are rapidly moving into production throughout enterprise systems, and the winning platform will be the one that gives them reliable context, governance, identity, memory — and secure access to enterprise data. The ...]]></description>
<link>https://tsecurity.de/de/3576491/it-nachrichten/microsofts-ai-futurist-explains-how-he-uses-copilot-and-the-real-world-problems-enterprises-are-solving-with-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576491/it-nachrichten/microsofts-ai-futurist-explains-how-he-uses-copilot-and-the-real-world-problems-enterprises-are-solving-with-agents/</guid>
<pubDate>Fri, 05 Jun 2026 22:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft used its <a href="https://news.microsoft.com/build-2026/">Build 2026 conference </a>this week to push a clear message: agents are rapidly moving into production throughout enterprise systems, and the winning platform will be the one that gives them reliable context, governance, identity, memory — and secure access to enterprise data. </p><p>The company <a href="https://venturebeat.com/data/enterprise-ai-agents-keep-creating-data-silos-microsofts-build-answer-is-microsoft-iq-and-rayfin">announced Microsoft IQ</a> as a context layer across GitHub Copilot, Microsoft Foundry and Copilot Studio; Work IQ APIs coming June 16; Fabric IQ for structured business data; Foundry IQ for retrieval across enterprise knowledge and the live web; and Web IQ as a new agent-facing web search stack. </p><p>Microsoft also introduced <a href="https://www.microsoft.com/en-us/microsoft-365/blog/2026/06/02/introducing-microsoft-scout-your-always-on-personal-agent/">Scout</a>, a personal work agent, and a whopping <i>seven </i><a href="https://microsoft.ai/news/building-a-hillclimbing-machine-launching-seven-new-mai-models/">new in-house AI models in its growing MAI family</a> across modalities and use cases, including MAI-Thinking-1.</p><p>Those announcements sit directly in <b>Marco Casalaina</b>’s lane. Casalaina<a href="https://www.linkedin.com/in/marcocasalaina/"> is Microsoft’s VP Products, Core AI and AI Futurist</a>. He leads Microsoft’s AI Futures team and previously led teams across Azure AI, including Azure OpenAI, Vision, Speech, Decision, Language, Responsible AI and AI Studio. </p><p><a href="https://onegiantleap.com/2026-speakers/marco-casalaina?utm_source=direct&amp;utm_medium=direct&amp;utm_campaign=Unspecified">Before Microsoft</a>, he led Salesforce’s Einstein AI team and earned a computer science degree from Cornell University. <a href="https://www.crn.com/slide-shows/channel-programs/30-notable-it-executive-moves-march-2022">CRN reported</a> that he joined Microsoft in early 2022 as vice president of products for Azure Cognitive Services, meaning he has now been at the company for more than four years.</p><p>VentureBeat spoke with Casalaina ahead of Build about Microsoft’s agent strategy, the company’s model-choice philosophy, how Microsoft IQ fits with MCP, and why he believes enterprises need far more than just access to powerful models. The interview below has been edited for clarity and condensed from the transcript.</p><h3><b>VentureBeat (VB): To start, can you explain your role at Microsoft and what “AI Futurist” means in practice?</b></h3><p>Marco Casalaina (MC): I am VP Products of what we call Core AI. Core AI is our set of tools for AI developers, and that includes Foundry, Visual Studio, VS Code, GitHub and GitHub Copilot. That’s our overall group.</p><p>My Silicon Valley title is AI Futurist, and that has a very concrete meaning here. I’ve worked with other folks who are considered futurists, like Peter Schwartz, and that can be a little bit more fuzzy. For me, what it means concretely is that I am the first person to try anything new here.</p><p>I am constantly getting things from all over Microsoft, not even just Foundry, because I work with really everybody across the company. Pretty much everybody sends me the new things at all times. Even today, I got something brand new just before this call. I’m usually the first person to try anything new here, which is pretty cool. I get to see a lot of really cool stuff.</p><p>A friend of mine, who is head of AI at Intuit, calls me an “adjacent possiblist.” I consider my futurist concept to be about a year out from now — the immediate future of what’s about to happen next. That’s what I focus on.</p><h3><b>VB: Where are you looking at the agentic state of things, and in particular Microsoft’s position as enterprises and individuals rush to adopt agentic AI?</b></h3><p>MC: We can look at it from bottom to top. At the very base of the stack is our commitment to model choice. All along, we’ve had the OpenAI GPT frontier models. Now we have a really solid partnership with Anthropic, where we’re offering the Claude models. We just launched Claude Opus 4.8 on Azure — on Foundry, I should say — and at Build, we are introducing our new MAI model.</p><p>The MAI models are a set of frontier models that we’re building in-house. They are made for token efficiency, optimization and customization. We are specifically making them for our customers to customize on their own data sets.</p><p>One level above that, we are announcing hosted agents in Foundry. That is our managed agent capability in Foundry. It automatically handles scaling, containerization and those kinds of things. It is an environment where you can manage agents.</p><p>One level above that is the Foundry control plane. At least for the agents you build, you want to have control over them. This gives you observability into their cost, tokens and correctness. You can do continuous evaluations and sample interactions with those agents, run evals and make sure they are continuing to work and not drifting.</p><p>The big news is going to be the GA of what we call the IQs here at Microsoft. There are currently three, and there will be four. There is Foundry IQ, which is basically for knowledge — largely unstructured knowledge. There is Fabric IQ. We have a ton of customers who have entrusted a lot of data to the Microsoft Cloud in Fabric, Power BI and related technologies. Fabric IQ is about making an agent-facing interface for this data, so agents can get to it without literally going through a Power BI report. That’s ridiculous.</p><p>Work IQ is about the Microsoft ecosystem. You can look at Work IQ as the agentic face of all the Microsoft apps: Outlook, Teams, Word, SharePoint and all those kinds of things. How does an agent interact with those things? That is Work IQ.</p><p>And finally, the fourth IQ is Web IQ. We are releasing our new agent-facing web search capability. It can search the web, search through videos and even do some kinds of browsing tasks automatically. It is super fast, and it kind of has no face. It’s headless. The interface is intended for agents.</p><p>We will also be announcing Agent Optimizer. That includes a new type of evaluation that allows you to evaluate much more granularly whether an agent is actually working and working correctly. The optimization step can go back in and make modifications to the prompt, obviously with your consent, and modify your agent so it works more correctly going forward. Effectively, it creates a feedback loop to make agents work better.</p><h3><b>VB: Microsoft has sometimes been criticized for murky and clunky product naming. Where do these IQ products sit? Are enterprise users supposed to go to IQ first, or is IQ more for developers to connect to?</b></h3><p>MC: All of the IQs are headless. The concept of IQ is that each one provides a different type of context to an agent specifically. Largely, it will be developers interacting with the various IQs — developers and the agents they build.</p><p>The IQ brand is really about agent context. End users largely won’t interact with the IQs. It is true that if you use Microsoft 365 Copilot today, you’ll notice a little thing that says it is using Work IQ. So it is a little bit visible, but the customer or end user doesn’t have to go find the IQ. Their system or developers hook that up.</p><h3><b>VB: Is the IQ family essentially Microsoft’s version of MCP? Is it using MCP, or is it something different?</b></h3><p>MC: All of the IQs are indeed exposed as MCP servers. You have correctly characterized MCP as basically an agent-facing or self-describing API. It’s not that fancy. That’s really what it is, with some authentication layers and capabilities built in, which is super useful.</p><p>Something like Work IQ — really all the IQs — have to be authenticated. In order for Work IQ to see my email, Teams messages, documents and stuff like that, I have to be able to authenticate it on behalf of me.</p><p>That gets us to another core differentiator that we will be announcing at Build, which is agent identity. We have this Entra system, and Entra is, I believe, the world’s largest used identity system for human users. For some time now, you have been able to declare an agent to have an identity in there. Now, agents will be able to have their own identity, their own Teams box, their own email inbox and stuff like that.</p><p>These agents will use Work IQ to check their own email, check their own documents and that sort of thing.</p><h3><b>VB: Enterprises are not one-size-fits-all on models. Microsoft supports many leading models through Foundry and Azure, while also building its own. Is Microsoft a model company, an infrastructure company or a connector between models and work products?</b></h3><p>MC: The answer is yes. We are obviously the hyperscaler. We are absolutely committed to model choice, and we will continue to offer the frontier models from all of the major players: OpenAI, Anthropic, Mistral, Black Forest, xAI — you name it. They are all going to be represented in there.</p><p>At the same time, we have what is now called our Microsoft AI Superintelligence Team, formed by Mustafa Suleyman, and we are building our own frontier models as well. Like I said earlier, we are really gearing these models toward optimization — token efficiency, bang for the buck and customization.</p><p>These are things our customers have been asking for: the ability to more finely customize models, whether that is fine-tuning or continued pre-training. Continued pre-training is literally changing the weights of the model, whereas fine-tuning is adding a little layer on top.</p><p>We have these capabilities in Foundry: fine-tuning, distillation and those kinds of things. I would note, by the way, that our MAI models are not distilled. Some model providers, especially some of the less scrupulous ones, will distill other models into theirs, and that can have unusual effects. We don’t do that. The data provenance of our models is of primary importance to us.</p><p>When we come out with these models, we want our customers to know that the data provenance is clean in terms of the rights to the data, where it came from and all that kind of stuff.</p><p>The choice thing also goes above the model layer. When we talk about Foundry hosted agents, we have the Microsoft Agent Framework. You talk about agent orchestration — how you make agents work together when you have multiple agents — and Microsoft Agent Framework is an excellent framework for that.</p><p>However, I can make a LangGraph or LangChain Foundry hosted agent. I can make a CrewAI Foundry hosted agent. I can use any number of orchestration frameworks and put that up as a Foundry hosted agent, and it becomes a first-class Foundry agent.</p><p>That means I get the observability. It shows up in the Foundry control plane. I can do evaluations on it. I can do traces on it. I can get all those things from the Foundry control plane with an agent built in really any framework I choose.</p><h3><b>VB: Some companies are interested in Chinese and open-source models. How much of Microsoft offering its own models is about giving customers an American version of that?</b></h3><p>MC: I can’t speak to that exactly. Of course, we offer DeepSeek models and Qwen models in Foundry, so we offer all of these choices today, and our customers can make that choice.</p><p>The MAI models are really focused on token efficiency and customizability. That is what our customers are demanding, and that is the gap we are filling.</p><h3><b>VB: As agents take on longer tasks and more specialized work, will enterprises keep expanding the number of models they use, or will there be a winnowing?</b></h3><p>MC: I do see it expanding. We are not just focused on tokens per se. A token is not a token is not a token. One token is not necessarily equivalent across these things. It is all about what you are doing with each token and the efficiency of that. It comes back to what kind of value you are getting for the cost. That is a lot of the rationale behind why we are developing our own MAI models.</p><p>Part of my job is to travel all around the world. I’ve been all over the place. For example, I’ve been working with Bayer. One of the things we are measuring is not just token usage, but number of users — monthly active users and daily active users — because we have a lot of first-party capabilities like Microsoft 365 Copilot. Over the last year, we’ve seen a 6x increase in monthly active users. We have over 20 million users of Microsoft 365 Copilot alone.</p><p>That is on the agents you use. In terms of the agents you build, Bayer put up its own agent system on Foundry, and now it has 20,000 of its own employees on it.</p><p>A few weeks ago, I was in Sydney, Australia, hanging out with AEMO, the Australian Energy Market Operator. They operate the electrical grid of Australia. They showed me that they had built agents to manage grid operations.</p><p>This is a human-centered thing. They have grid operators sitting in centers in West Sydney, Brisbane and places like that, and they are bombarded with alerts. I wouldn’t believe it if I hadn’t seen it myself. The alerts are constant. They built a system to triage those alerts. Is this alert a super major thing, or is it just that a transformer is getting a little hot? It also says, here is when we had this problem last time, and here is how we resolved it last time. Maybe now we need to replace this component, or whatever.</p><p>Ultimately, it is the grid operators making the choice. A lot of our philosophy here is human empowerment. These human-centered agents are the ones that are working best among our customers. What I saw at AEMO and Bayer is this notion of human empowerment: taking away some of the grunt work, or in the case of AEMO, taking billions of alerts and reducing them to something much more manageable and actionable for the people involved.</p><p>We are moving past the era where agents are just answering questions. AI in general is moving past that. We are not just answering questions anymore. We are moving toward a place where AI can really meaningfully help you do your work.</p><h3><b>VB: How do observability, tokenomics, ROI analysis and agent governance fit into Microsoft Foundry?</b></h3><p>MC: That is what the Foundry control plane is all about. We introduced it in November of last year. If you looked at my own Foundry control plane — I’ve built a ton of these agents, and I am a developer by background — you would see all of my agents that are running and the ones that are paused.</p><p>I can see how many tokens they’ve used over the last day, week or month. I can look at trends. I can look at costs, because the cost will be different depending on what underlying model I’m using. If I’m using our model router, it can route to different models depending on the complexity of the inbound prompt.</p><p>We also have Azure cost management overall. Azure has had cost management for over a decade, before the AI thing even happened. This integrates with overall Azure cost management.</p><p>It is not just narrowly about what your AI is doing. Your AI will be using storage resources, data resources and other compute resources around that AI. You can get a complete picture of not just the cost and token usage of the AI itself, but everything around it.</p><p>When you think about governance, that also extends to evaluation. One of the things we are releasing in preview is rubric-based evaluation. Rubric-based evaluation is much more granular.</p><p>Let’s say you have built a restaurant reservation agent. The things you want to test about that agent are not really groundedness. Groundedness is the opposite of hallucination, and that is very question-answering. For a restaurant reservation agent, you want to test very granular things. If you say, “Make me a table for two tomorrow,” did it come back and ask, “What time would you like the table?” Before it gave you a table for two tomorrow at 6 p.m., did it actually check that the table was available, or did it randomly give you a table without checking first?</p><p>There are very granular things you want to test about that specific use case. You don’t just want to test whether the agent works. You want to test whether the agent works right.</p><p>That is what we are approaching with our new rubric-based evaluation system. You will see that in Satya’s keynote. I have been using it myself lately, and I’m very happy about it. I’ve been waiting for this.</p><h3><b>VB: Microsoft is also partnering with companies like Anthropic and allowing Claude to work with Microsoft 365. How important is Copilot to this story? Why would someone turn to Copilot over other options?</b></h3><p>MC: Microsoft 365 Copilot is a huge advantage for us. As I mentioned, we crossed the 20 million user mark on Copilot relatively recently.</p><p>The great thing about that is that it is the face. When you go into Foundry and make an agent, there is a button that says “publish to Copilot” — actually, it says “publish to Copilot in Teams,” because you can put it in Teams too.</p><p>The idea is that you want to put these agents where your users are. A lot of people who use the Microsoft ecosystem are in Teams, or they are using Copilot. I can create a custom agent, as many of my colleagues have, and now it is in Copilot, which I use maybe 50 times a day.</p><p>Since January, Copilot has become more and more capable. I now use it to draft my email. I am not just using it for question answering. I’m starting to use it to manage my calendar and draft emails. I really do this every day now.</p><p>When I want to use a custom agent — for example, to file my expenses, because we have a custom agent for that now — I can access that agent not in some random standalone interface, but in Copilot or Teams, where I already am.</p><p>That surface area that people are already engaging with is a major advantage.</p><h3><b>VB: As people offload more repetitive work to AI, what are they able to spend more time doing?</b></h3><p>MC: Let’s consider something I did yesterday. I got an email from a customer named Frankie, and he asked me a question about Foundry hosted agents. I knew the answer because I had talked to my colleague Jeff Holland, who is the head of our hosted agents product management. I had asked Jeff the same question two weeks ago.</p><p>Where or how I asked him, I don’t remember. Was it in Teams? Was it email? Was it a meeting? I don’t really remember. But I knew the answer to the question Frankie was asking.</p><p>So I went into Copilot and said, “Answer Frankie’s question about how hosted agents scale, and reference the conversation I had with Jeff a couple of weeks ago on this same topic.” And it did it. It drafted the email.</p><p>Over time, I have taught Copilot my style. I don’t do the bold-print thing. I tell it: don’t use em dashes and that kind of stuff. I have a certain style in the way I write emails. It’s a little terse, to be perfectly honest, but I want it to be the way I write.</p><p>It drafted this thing. It searched through my Teams messages, my emails and the transcripts of my meetings with Jeff. It used Work IQ, as a matter of fact. It found the answer, drafted the email and provided a link to the documentation that specifically covered the question Frankie was asking.</p><p>I looked at the draft and thought, yep, that’s it.</p><p>Yes, I could have composed this email myself. I knew the answer to the question. I could have looked up the documentation. If I dug around, I’m sure I could have found the conversation I had with Jeff in whatever medium that was. I could have done that stuff. It probably would have taken me, I don’t know, an hour to find all the information and compose it.</p><p>Instead, I did it in about a minute. I had a draft, I looked at it, I was happy with it, I pressed send, and that was the end of that.</p><p>It really is about giving people time back. It is not even just grunt work. It is all this time you spend looking things up and finding things. Now, I can make it take an action. It didn’t just answer the question. It fully drafted the email and copied Jeff.</p><h3><b>VB: Do you fear for your job? How has AI changed your own work?</b></h3><p>MC: I don’t fear for my job. My job has changed. For one thing, I do a lot more now, both in my business life and personal life.</p><p>This weekend I was using Web IQ, the new Web IQ. I’ve been car shopping. My car’s lease is coming up, and there is a very specific car I’m trying to find, which is hard to find. It’s a Hyundai Ioniq 6, which Hyundai, for whatever reason, has stopped offering in the United States. I’m going to get one, though.</p><p>I set my agent to the task, using Web IQ, of finding all the Hyundai Ioniq 6s available in the entire Bay Area — everywhere, all the way out to Sacramento, all the way as far south as Gilroy. I set it to this task, and then I went on a hike.</p><p>When I got back, I had a big long list of all the Hyundai Ioniq 6s, at least the 2024 and 2025 models, available in the entire Bay Area. From that, I started calling down these dealers.</p><p>Even in my personal life, I’m using it constantly. It saves me a ton of time. That would have taken me hours, to go through every single dealer’s inventory like this. But Web IQ could do that, and it was super quick.</p><h3><b>VB: Any final thought for developers around this news?</b></h3><p>MC: Foundry is really the place. This is the place where you can build your agents, scale your agents, test your agents and improve your agents. That’s what it’s all about, and it’s happening.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft 365 erklärt]]></title>
<description><![CDATA[Bei Microsoft 365 besteht Erklärungsbedarf.
Ascannio | shutterstock.com



CEO Satya Nadella kündigte im Juli 2017 mit Microsoft 365 (M365) eine “grundlegende Abkehr” von der bisherigen Art und Weise der Produktentwicklung an. Inzwischen hat sich das Produkt zu Microsofts Kernmarke im Bereich der...]]></description>
<link>https://tsecurity.de/de/3574293/it-security-nachrichten/microsoft-365-erklaert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574293/it-security-nachrichten/microsoft-365-erklaert/</guid>
<pubDate>Fri, 05 Jun 2026 05:34:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/09/Ascannio_shutterstock_2303449089_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Microsoft 365 Finger 16z9 Shutterstock Editorial GERMANY ONLY" class="wp-image-3523694" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Bei Microsoft 365 besteht Erklärungsbedarf.</p>
</figcaption></figure><p class="imageCredit">Ascannio | shutterstock.com</p></div>



<p>CEO Satya Nadella kündigte im Juli 2017 mit <a href="https://www.computerwoche.de/article/2793007/nutzen-sie-office-365-datenschutzkonform.html" target="_blank">Microsoft 365</a> (M365) eine “grundlegende Abkehr” von der bisherigen Art und Weise der Produktentwicklung an. Inzwischen hat sich das Produkt zu Microsofts Kernmarke im Bereich der Produktivitätssoftware entwickelt – und damit Office 365 in dieser Hinsicht weitgehend ersetzt.</p>



<p>Allerdings ist in den letzten Jahren nicht nur die Bandbreite der Anwendungen und Funktionen in Microsoft 365 gewachsen – Stichwort KI respektive <a href="https://www.computerwoche.de/article/2832400/microsoft-copilot-pro-im-test.html" target="_blank">Copilot</a>. Auch die bereits initial etwas verwirrende Palette an Lizenzierungsoptionen wurde ausgebaut. Speziell für viele neue Funktionen fallen dabei zusätzliche Gebühren an, die über die Standardkosten für ein Microsoft-365-Abonnement hinausgehen.</p>



<p>In diesem Artikel lesen Sie:</p>



<ul class="wp-block-list">
<li>was Microsoft 365 ist und wie sein Konkurrenzumfeld aussieht,</li>



<li>welche M365-Versionen aktuell zur Verfügung stehen,</li>



<li>was diese kosten und</li>



<li>wie es um die Add-ons für M365 bestellt ist.</li>
</ul>



<p>Darüber hinaus erwartet Sie am Ende dieses Artikels ein umfassendes Glossar zu Microsoft 365.</p>



<h2 class="wp-block-heading">Was ist Microsoft 365?</h2>



<p>Microsoft 365 ist im Grunde genommen immer noch eine Sammlung von Microsoft-Software und -Services, die im Rahmen eines Abo-Modells verkauft wird. Sämtliche M365-Abonnements enthalten eine Version der jeweils wichtigsten Office-Anwendungen:</p>



<ul class="wp-block-list">
<li>Word (Dokumentbearbeitung),</li>



<li>Excel (Tabellenkalkulation),</li>



<li>PowerPoint (Präsentationen) sowie</li>



<li>Outlook (E-Mail).</li>
</ul>



<p>Das war es aber auch schon an übergreifenden Gemeinsamkeiten: Davon abgesehen variiert das spezifische Set an Software und Services je nach Microsoft-365-Preisplan (zum Teil erheblich). Das trägt auch dazu bei, dass regelmäßig Verwirrung darüber herrscht, für was Microsoft 365 denn nun konkret steht. Schließlich können damit ein paar webbasierte Consumer-Anwendungen ebenso gemeint sein, wie ein umfassendes Enterprise-Paket inklusive Lizenzen für Windows und Office-Anwendungen sowie einer Reihe von Storage-, Security- und Management-Tools.</p>



<p>“Microsoft würde sagen, dass es die Grundlage für modernes Arbeiten ist”, läutet Jason Wong, Distinguished VP Analyst bei Gartner, seine Definition der Productivity Suite ein und fügt hinzu: “Microsoft 365 bietet Unternehmen eine Möglichkeit, die Office-Produkte strategischer einzusetzen – als ein Set von Technologien.”</p>



<p>Obwohl Gartner bei Enterprise-Kunden auch ein steigendes Interesse an anderen Produktivitäts-Suites – insbesondere <a href="https://www.computerwoche.de/article/3983702/google-workspace-erklart.html" target="_blank">Google Workspace</a> – feststelle, sei Microsoft mit seinem 365-Angebot ein dominierender Akteur am Markt mit einer gefestigten Position innerhalb der Unternehmenslandschaft: “Das ist zum Teil auch auf die langjährige On-Premises-Nutzung der Office-Produkte zurückzuführen”, so der Analyst.</p>



<p>Neben Google sieht sich Microsoft jedoch mit einer Vielzahl weiterer Wettbewerber konfrontiert, wenn es um <a href="https://www.computerwoche.de/article/2765021/wie-sie-puenktlich-in-den-feierabend-kommen.html" target="_blank">Produktivität</a> geht. Zum Beispiel:</p>



<ul class="wp-block-list">
<li>Slack,</li>



<li>Zoom,</li>



<li>Notion oder</li>



<li>Zoho.</li>
</ul>



<p>Die Angebote dieser Anbieter konkurrieren mit einzelnen Microsoft-365-Apps, erweitern jedoch ebenfalls ihr Produktportfolio mit dem Ziel, zum <a href="https://www.computerwoche.de/article/2804233/die-besten-visual-collaboration-tools.html" target="_blank">digitalen Knotenpunkt</a> in Unternehmen zu werden. Laut Gartner-Mann Wong muss das jedoch nicht unbedingt zum Nachteil gereichen: “Für gewöhnlich gibt es in diesem Bereich kein Entweder-Oder. Statt um Verdrängung geht es bei vielen dieser Tools eher um Koexistenz.”</p>



<h2 class="wp-block-heading">Microsoft-365-Versionen und -Preise im Überblick</h2>



<p>Weil Microsoft 365 als Abonnement verkauft wird, fallen monatliche oder jährliche Gebühren für jeden Benutzer an. Solange das Abo aufrechterhalten respektive bezahlt wird, sind alle Software-Updates und -Upgrades ohne Aufpreis enthalten.</p>



<p>Wir konzentrieren uns im Folgenden auf die wichtigsten Versionen von Microsoft 365. Das sind:</p>



<ul class="wp-block-list">
<li><a href="https://www.microsoft.com/de-de/microsoft-365/enterprise/microsoft365-plans-and-pricing?market=de" target="_blank" rel="noreferrer noopener"><strong>Microsoft 365 Enterprise</strong></a> ist in den Konfigurationen E3 EWR und E5 EWR verfügbar. Diese Optionen richten sich an Großunternehmen mit mehr als 300 Mitarbeitern. Der <strong>E3</strong>-Plan kostet <strong>34,90 Euro</strong> pro Benutzer und Monat und umfasst Nutzerlizenzen für Windows 11 Enterprise sowie eine lange Liste von Office-Apps für Desktop- und Mobilgeräte sowie Services wie Exchange, Sharepoint, Onedrive und Sicherheits-Tools. Der <strong>E5</strong>-Plan kostet <strong>55,22 Euro</strong> pro Benutzer und Monat und bietet darüber hinaus erweiterte Security-, Compliance- und Analytics-Funktionen. Der <strong>E7</strong>-Plan beinhaltet laut Microsoft sämtliche Security- und Compliance-Tools des E5-Plans – ergänzt um KI-Funktionen und die Entra Suite. Das kostet <strong>91,90 Euro</strong> pro Benutzer und Monat.</li>



<li><a href="https://www.microsoft.com/de-de/microsoft-365/business/compare-all-microsoft-365-business-products?market=de" target="_blank" rel="noreferrer noopener"><strong>Microsoft 365 Business</strong></a> richtet sich an kleine und mittelständische Unternehmen mit maximal 300 Benutzern und steht in den Versionen Basic, Standard und Premium zur Verfügung. Die <strong>Basic</strong>-Stufe für <strong>5,20 Euro</strong> pro Monat und Benutzer umfasst dabei lediglich die Web- und Mobile-Versionen der Office-Anwendungen sowie OneDrive und essenzielle Services wie SharePoint und Exchange. Der <strong>Standard</strong>-Plan für <strong>10,83 Euro</strong> erweitert die Auswahl um einige zusätzliche Apps wie Clipchamp und Loop. Das <strong>Premium</strong>-Paket für <strong>19,06 Euro</strong> enthält zusätzlich erweiterte Sicherheits- und Management-Funktionen. Bei Microsoft 365 <strong>Apps for Business</strong> handelt es sich um eine „Nur-Apps-Version“ von M365. Sie umfasst für <strong>9,10 Euro</strong> pro Monat und Benutzer die Desktop-Apps Word, Excel, Powerpoint, Outlook sowie Onedrive. Im Gegensatz zu Microsoft 365 Enterprise enthält M365 Business zur Zeit auch Microsoft Teams.</li>



<li>Die Pakete <a href="https://www.microsoft.com/de-de/microsoft-365/enterprise/frontline-plans-and-pricing?market=de" target="_blank" rel="noreferrer noopener"><strong>Microsoft 365 F1 und F3</strong></a> richten sich an Mitarbeiter mit direktem Kundenkontakt oder solche, die in Service und Produktion tätig sind. Die günstigeren Pakete – <strong>F1</strong> kostet <strong>1,90 Euro</strong> pro Benutzer und Monat, <strong>F3 </strong>verursacht monatliche Kosten von <strong>6,93 Euro</strong> – bieten Security auf Enterprise-Niveau, setzen jedoch ausschließlich auf webbasierte und mobile Applikationen.</li>



<li>Die Consumer-Versionen <a href="https://www.microsoft.com/de-de/microsoft-365/buy/compare-all-microsoft-365-products?culture=de-de&amp;country=de" target="_blank" rel="noreferrer noopener"><strong>Microsoft 365 Family</strong>, <strong>Single</strong></a>, <a href="https://www.microsoft.com/de-de/microsoft-365/p/microsoft-365-basic/cfq7ttc0ktxs?activetab=pivot:%C3%BCbersichttab" target="_blank" rel="noreferrer noopener"><strong>Basic</strong></a> und <a href="https://www.microsoft.com/de-de/microsoft-365/free-office-online-for-the-web" target="_blank" rel="noreferrer noopener"><strong>Free</strong></a> decken eine Bandbreite von (tatsächlich) <strong>kostenlos</strong> bis zu <strong>219 Euro</strong> pro Jahr ab. Die <strong>Free</strong>-Variante stellt dabei das absolute Minimum dar und ist auf eine Handvoll Web- und Mobile-Apps sowie eine werbefinanzierte Version von Outlook beschränkt.</li>
</ul>



<p>Unternehmenskunden können M365-Komponenten auch separat erwerben. Microsoft verkauft auch weiterhin Windows 11 Enterprise, Windows 11 Pro, Enterprise Mobility und Security (EMS) sowie Services wie Exchange Online und SharePoint Online „à la carte“. Sämtliche Inhalte eines Microsoft-365-Abonnements einzeln zu erwerben, kommt im Regelfall zwar immer teurer, ist aber unter Umständen für Anwenderunternehmen attraktiv, die sich nicht vollständig auf Microsoft festlegen wollen.</p>



<h2 class="wp-block-heading">Microsoft-365-Add-ons</h2>



<p>Nachdem Microsoft seine Collaboration-App Teams inzwischen wegen kartellrechtlicher Untersuchungen der Europäischen Union aus seinen M365-Enterprise-Plänen weltweit entfernt hat, steht Teams in diesem Rahmen lediglich als <a href="https://www.microsoft.com/de-de/microsoft-teams/enterprise?market=de#pricing" target="_blank" rel="noreferrer noopener">zubuchbares Add-on zur Verfügung</a> – für zusätzliche <strong>7,40 Euro</strong> pro Benutzer und Monat. Das ist jedoch nur ein Beispiel aus einer langen und wachsenden Liste optionaler, kostenpflichtiger Erweiterungen für Microsoft 365. Diese können die monatlichen Kosten schnell in ungeahnte Höhen treiben.</p>



<p>Dazu gehören beispielsweise:</p>



<ul class="wp-block-list">
<li>Der KI-Assistent <strong><a href="https://www.microsoft.com/de-de/microsoft-365/enterprise/copilot-for-microsoft-365?market=de#tabs-pill-bar-oc49dd_tab0" target="_blank" rel="noreferrer noopener">Copilot für Microsoft 365</a></strong> für zusätzliche <strong>26,00 Euro</strong> pro Benutzer und Monat. </li>



<li>Das Low-Code-Entwicklungs-Tool <strong><a href="https://www.microsoft.com/de-de/power-platform/products/power-apps/pricing?market=de" target="_blank" rel="noreferrer noopener">Power Apps Premium</a></strong> für mindestens <strong>10,40 Euro</strong> pro Benutzer und Monat (kostenlose Entwicklerkonten).</li>



<li>Das Analytics-Tool <strong><a href="https://www.microsoft.com/de-de/power-platform/products/power-bi/pricing?market=de" target="_blank" rel="noreferrer noopener">Power BI Premium</a></strong> ab <strong>12,10 Euro</strong> pro Benutzer und Monat.</li>



<li>Die Security- und IAM-Lösung <strong><a href="https://www.microsoft.com/de-de/security/business/microsoft-entra-pricing?market=de" target="_blank" rel="noreferrer noopener">Entra Suite</a></strong> für mindestens <strong>10,40 Euro</strong> pro Benutzer und Monat.</li>
</ul>



<h2 class="wp-block-heading">Microsoft-365-Glossar</h2>



<p>Beim Blick auf die Preispläne von Microsoft 365 (und seinen Add-ons) begegnen Ihnen diverse Apps und Dienste. Im Folgenden ein kurzer Überblick über die wichtigsten Produkte im M365-Universum.</p>



<p><strong>Kern-Apps und -Services</strong></p>



<ul class="wp-block-list">
<li><strong>Word:</strong> Textverarbeitungs-App;</li>



<li><strong>Excel:</strong> Tabellenkalkulations-App;</li>



<li><strong>PowerPoint:</strong> Präsentations-App;</li>



<li><strong>Outlook:</strong> E-Mail-, Kalender- und Kontakt-App;</li>



<li><strong>OneNote:</strong> Notizen-App;</li>



<li><strong>Teams:</strong> Gruppenchat- und Videokonferenz-App (nicht in Enterprise-Plänen enthalten);</li>



<li><strong>OneDrive:</strong> Cloud-Speicher;</li>



<li><strong>SharePoint:</strong> Business-Plattform um Inhalte zu teilen;</li>



<li><strong>Exchange:</strong> Hosting-/Management Service für Unternehmens-E-Mails, -Kalender und -Kontakte;</li>



<li><strong>Windows:</strong> Desktop-Betriebssystem (nur in M365 E3- und E5-Plänen enthalten);</li>
</ul>



<p><strong>Zusätzliche Apps und -Services</strong></p>



<ul class="wp-block-list">
<li><strong>Access:</strong> Datenbank-App (nur Windows);</li>



<li><strong>Bookings:</strong> App für Terminplanung und -management;</li>



<li><strong>Clipchamp:</strong> App zur Videobearbeitung;</li>



<li><strong>Delve:</strong> Such-App für M365 (wird Mitte Dezember 2024 eingestellt);</li>



<li><strong>Forms:</strong> App, um Umfragen und Formulare zu erstellen;</li>



<li><strong>Lists:</strong> Spreadsheet- und Work-Tracking-App;</li>



<li><strong>Loop:</strong> Shared-Workspace-App;</li>



<li><strong>Publisher:</strong> Desktop-Publishing-Anwendung (nur Windows, wird im Oktober 2026 eingestellt);</li>



<li><strong>Planner:</strong> Work-Management-App;</li>



<li><strong>Power Apps:</strong> Low-Code-Entwicklungsplattform;</li>



<li><strong>Power Automate:</strong> Workflow-Automatisierungsanwendung;</li>



<li><strong>Power BI Pro:</strong> Analytics- und Datenvisualisierungs-App;</li>



<li><strong>Stream:</strong> Streaming- und Sharing-Plattform für Videoinhalte;</li>



<li><strong>Sway:</strong> Publishing-App für Präsentationen, Berichte und Newsletter;</li>



<li><strong>Teams Telefon:</strong> Enterprise-Telefoniedienst für Microsoft Teams (zusätzliche monatliche Gebühr pro Benutzer);</li>



<li><strong>To Do:</strong> Task-Management-App;</li>



<li><strong>Visio:</strong> Diagramm- und Vektorgrafik-App;</li>



<li><strong>Viva Amplify:</strong> App für Employee Communication Management;</li>



<li><strong>Viva Connections:</strong> Intranet-App;</li>



<li><strong>Viva Engage (ehemals Yammer):</strong> Enterprise Social Network App;</li>



<li><strong>Viva Glint:</strong> App für Mitarbeiterumfragen und -Feedback;</li>



<li><strong>Viva Goals:</strong> App zur Zielverfolgung;</li>



<li><strong>Viva Insights:</strong> App für Produktivitäts- und Wellbeing-Analysen;</li>



<li><strong>Viva Learning:</strong> Lern-App;</li>



<li><strong>Viva Pulse:</strong> Self-Service-App für Teamleiter, um Mitarbeiter-Feedback einzuholen;</li>
</ul>



<p><strong>Security und Management</strong></p>



<ul class="wp-block-list">
<li><strong>Defender:</strong> Enterprise Security Apps und Services (aber auch eine Security-App für Consumer);</li>



<li><strong>Entra</strong> <strong>(ehemals Azure Active Directory):</strong> Sammlung von Tools für die Identitäts- und Zugriffsverwaltung in Unternehmen, einschließlich Entra ID;</li>



<li><strong>Intune:</strong> Sammlung von Endpoint-Management-Tools für Unternehmen;</li>



<li><strong>Priva:</strong> Data-Privacy-Management-Tools für Unternehmen;</li>



<li><strong>Purview:</strong> Sammlung von Tools für Data Governance, Security, Risikomanagement und Compliance;</li>
</ul>



<p><strong>Dieser Artikel ist <a href="https://www.computerworld.com/article/1691110/microsoft-365-explained.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Angular Signals explained: How pull-based reactivity changes how we model state]]></title>
<description><![CDATA[Angular’s introduction of Signals has generated both excitement and confusion. For many developers, Signals appear to be “simpler observables” or a more convenient way to trigger updates without subscriptions. Others attempt to map them directly onto familiar RxJS patterns, expecting emissions, o...]]></description>
<link>https://tsecurity.de/de/3571974/ai-nachrichten/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571974/ai-nachrichten/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state/</guid>
<pubDate>Thu, 04 Jun 2026 11:03:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Angular’s introduction of Signals has generated both excitement and confusion. For many developers, Signals appear to be “simpler observables” or a more convenient way to trigger updates without subscriptions. Others attempt to map them directly onto familiar RxJS patterns, expecting emissions, operators, and event-style coordination.</p>



<p>Both interpretations miss the point.</p>



<p>Signals are not primarily an event system, and they are not designed to replace RxJS. They represent a different way of modeling application behavior, one that centers on current state and explicit dependencies rather than sequences of events. This distinction is subtle at first, but it has significant consequences for how applications are structured and reasoned about over time.</p>



<p>In a previous article, “<a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a>,” we reframed form behavior as a state-driven problem rather than an event-driven one. That shift raises an important follow-up question: what kind of reactive primitive is best suited for expressing state and derived behavior? To answer that, we need to understand Signals on their own terms, independent of any specific feature such as forms.</p>



<p>This article examines Angular Signals as a reactivity model rather than a convenience API. By clarifying what Signals are and, just as importantly, what they are not, we can better understand where they fit alongside RxJS and why they align so naturally with state-heavy problems such as form modeling.</p>



<h2 class="wp-block-heading"><a></a>Signals as a state primitive (not an event system)</h2>



<p>To understand why Signals are a good fit for form modeling, it helps to be precise about what Signals are, and just as importantly, what they are not.</p>



<p>Signals are not an event system. They do not represent a sequence of things that happened over time. Instead, a signal represents a <em>current value</em>, along with a dependency graph that describes how other values derive from it. When a signal changes, Angular does not broadcast an event. It simply marks dependent computations as stale and reevaluates them the next time they are read. This is what we mean by fine-grained change detection control.</p>



<p>This distinction may seem subtle, but it has profound implications for how we reason about application logic.</p>



<p>Reactive streams encourage developers to think in terms of emissions. When something changes, subscribers are notified, operators transform the stream, and side effects occur in response. This model is extremely powerful for asynchronous workflows, but it introduces temporal reasoning even when time is not an essential concern. Developers must ask not only <em>what</em> the current state is, but <em>how</em> it arrived there and <em>which emission</em> triggered a particular piece of logic.</p>



<p>Signals, by contrast, encourage a declarative, pull-based model. A computed signal does not react to changes as they occur. Instead, it declares that its value depends on other signals. When those dependencies change, the computed value is simply recomputed the next time it is accessed. There is no notion of subscription order, missed emissions, or stale listeners.</p>



<p>This pull-based model aligns naturally with form state. At any moment, a form has a well-defined set of values. From those values, validity, error messages, and UI flags can be derived. These relationships do not depend on the sequence of changes that led to the current state. They depend only on the current state itself.</p>



<p>This is why Signals feel simpler when applied to state-heavy problems. They shift the developer’s focus away from orchestration and toward declaration. Instead of asking “What should happen when this changes?”, the question becomes “What does this value depend on?”</p>



<p>It is important to note that this does not make Signals a replacement for RxJS. Angular still relies on observables for asynchronous streams, external events, and integration with APIs that produce values over time. Signals and RxJS serve different purposes. In the context of forms, Signals are best used to represent <em>state and derived state</em>, while RxJS remains useful for asynchronous side effects and integration points.</p>



<p>By keeping this distinction clear, we avoid the trap of using Signals as a less expressive event system. Instead, we use them for what they do best: modeling state in a way that is explicit, deterministic, and easy to reason about.</p>



<h2 class="wp-block-heading"><a></a>Designing a signal-first form model with Angular Signal Forms</h2>



<p>Before looking at any concrete implementation, it is worth clarifying what a “signal-first” form model actually implies. The goal is not to introduce a new abstraction that replaces Angular Forms, nor is it to hide form behavior behind another layer of indirection. Instead, the intent is to reorient how form state is represented and reasoned about.</p>



<p>In a signal-first approach, the form’s data model is treated as the single source of truth. Signals are used to represent that state directly, rather than mirroring it through control hierarchies or intermediary objects. The form itself becomes a projection over the state, attaching semantics such as validation, interaction metadata, and submission behavior without duplicating or owning the data.</p>



<p>This distinction is subtle but important. Traditional form models often encourage developers to think of the form as the container of state, with values flowing in and out through events. A signal-first model reverses that relationship. State exists independently of the form, and the form derives its behavior from that state. This makes it easier to inspect, reason about, and test form behavior, because the underlying data remains explicit and accessible.</p>



<p>The examples in this section are therefore intentionally minimal. They are not meant to demonstrate every feature of Angular Signal Forms, but to illustrate how a state-driven representation reshapes form architecture. The emphasis is on structure and intent rather than mechanics. More detailed implementation concerns, such as asynchronous validation, persistence, and UI composition, are explored in the following article.</p>



<p>Once we accept that form behavior is largely derived from state, the next question becomes how that idea is expressed in Angular itself. Angular’s Signal Forms API is a direct response to this shift in thinking. Rather than modeling forms as trees of controls emitting events, Signal Forms begin with a signal-backed model and layer form behavior validation, interaction state, and submission on top of it.</p>



<p>The starting point is still the same: a plain data model representing the values the form collects. In a signal-first approach, this model is wrapped in a writable signal and treated as the single source of truth. There is no duplication of state between the UI and the form model, and no need to synchronize multiple representations of the same data.</p>



<p>From this model signal, a form instance is created using Angular’s <code>form()</code> function. The role of this function is not to introduce a second state container, but to attach form semantics to an existing state object. The form instance provides structured access to fields, validation results, and interaction metadata, all of which are exposed as signals.</p>



<p>Validation is declared through a schema function passed to <code>form()</code>. This schema associates validation rules directly with specific fields in the model. Built-in validators such as <code>required()</code> and <code>email()</code> express constraints declaratively, and Angular automatically reevaluates them whenever the underlying values change. Validation results are not stored imperatively; they are derived and exposed through field-level signals such as i<code>nvalid()</code>, <code>errors()</code>, and <code>pending()</code>.</p>



<p>This design is significant because it keeps validation aligned with the mental model established earlier. Validation rules do not “run” in response to events. They describe constraints on state. When state changes, derived validation state updates automatically, without subscriptions, listeners, or life-cycle hooks.</p>



<h3 class="wp-block-heading">Angular Signals Form example</h3>



<p>A minimal example illustrates the shape of this approach. The model remains a simple interface, and the signal holds the current form values.</p>



<pre class="wp-block-code"><code>interface RegistrationData {
  email: string;
  password: string;
  confirmPassword: string;
  acceptedTerms: boolean;
}
</code></pre>



<p>The form is then created by passing this model signal into <code>form()</code>, along with a schema that declares validation rules.</p>



<pre class="wp-block-code"><code>const registrationModel = signal<registrationdata>({
  email: '',
  password: '',
  confirmPassword: '',
  acceptedTerms: false,
});

const registrationForm = form(registrationModel, (schema) =&gt; {
  required(schema.email, { message: 'Email is required' });
  email(schema.email, { message: 'Enter a valid email address' });

  required(schema.password, { message: 'Password is required' });
  required(schema.confirmPassword, { message: 'Please confirm your password' });

  required(schema.acceptedTerms, {
    message: 'You must accept the terms to continue',
  });
});
</registrationdata></code></pre>



<p>What matters here is not the syntax, but the structure. The model signal defines <em>what the form is</em>. The schema defines <em>what constraints apply</em>. Angular takes responsibility for deriving field state and exposing it through signals that the UI can consume directly.</p>



<p>Each field now has a clear, inspectable state. Whether a field is valid, invalid, touched, or pending is no longer inferred by tracing event streams or subscription chains. It is available as a signal, derived from the current model and the declared rules. This makes form behavior easier to reason about, test, and debug.</p>



<p>Just as importantly, this model scales naturally. Cross-field validation, such as checking that two password fields match, can be expressed declaratively using schema-level logic that reads from multiple fields. Form-level state, such as whether submission should be allowed, is derived rather than toggled imperatively. The form remains a projection of the state, not a controller of behavior.</p>



<p>I have avoided discussing templates or DOM integration here. The purpose of this section is to show that Angular’s Signal Forms align closely with the first-principles model introduced above. They do not replace that model; they formalize it.</p>



<p>In the next article in this series, we will connect this signal-first form to an actual Angular component. We will bind fields to inputs, render validation feedback using field state signals, and implement submission logic. This implementation will form the foundation of the GitHub example that accompanies this series and will be extended in later articles to cover asynchronous validation, persistence, and hybrid approaches.</p>



<h2 class="wp-block-heading">The power of Signals</h2>



<p>Angular Signals represent a deliberate shift in how reactivity is expressed within the framework. Rather than focusing on events, emissions, and coordination, Signals encourage developers to describe relationships between values. Computation becomes declarative, dependencies become explicit, and behavior becomes easier to reason about by inspection rather than reconstruction.</p>



<p>This does not diminish the role of RxJS. Event streams, asynchronous workflows, and integration with external systems remain essential parts of modern applications. Signals and RxJS solve different problems, and treating them as interchangeable inevitably leads to confusion. When each is used for what it does best — Signals for state and derivation, RxJS for coordination and side effects — the resulting architecture becomes clearer and more maintainable.</p>



<p>Viewed through this lens, the appeal of Signals is not novelty, but alignment. Signals map closely to how developers already think about state: as something that exists now, from which other values can be derived deterministically. This alignment reduces cognitive overhead, particularly in parts of an application where behavior is dominated by state rather than time.</p>



<p>With this understanding in place, we can now turn to practice. The next article applies these ideas to a concrete Angular example, showing how a signal-first approach reshapes form modeling, validation, and UI logic without reintroducing event-driven complexity.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 MCP-Server für DevOps]]></title>
<description><![CDATA[DevOps ist mit Aufwand und Kosten verbunden. Mit MCP aufzurüsten, macht deshalb Sinn.PeopleImages | shutterstock.com



KI-Agenten für Programmierer haben sich zu einem beeindruckenden Hilfsmittel entwickelt. Allerdings sind diese Agenten nur begrenzt einsetzbar, wenn sie nicht auch mit modernen ...]]></description>
<link>https://tsecurity.de/de/3571393/it-security-nachrichten/10-mcp-server-fuer-devops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571393/it-security-nachrichten/10-mcp-server-fuer-devops/</guid>
<pubDate>Thu, 04 Jun 2026 06:06:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/12/PeopleImages_shutterstock_2546315777_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Dev Discussion 16z9" class="wp-image-4103991" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">DevOps ist mit Aufwand und Kosten verbunden. Mit MCP aufzurüsten, macht deshalb Sinn.</figcaption></figure><p class="imageCredit">PeopleImages | shutterstock.com</p></div>



<p><a href="https://www.computerwoche.de/article/4039804/schone-neue-multi-agenten-welt.html" target="_blank">KI-Agenten für Programmierer</a> haben sich zu einem beeindruckenden Hilfsmittel entwickelt. Allerdings sind diese Agenten nur begrenzt einsetzbar, wenn sie nicht auch mit modernen DevOps-Tools kompatibel sind. An dieser Stelle kommt das Model Context Protocol (<a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html">MCP</a>) ins Spiel. Der von Anthropic Ende 2024 veröffentlichte Standard verbindet KI-Systeme mit externen Tools und Daten. </p>



<p>Mit Blick auf <a href="https://www.computerwoche.de/article/2834426/10-grobe-devops-schnitzer.html" target="_blank">DevOps</a> stehen KI-Agenten damit neue Fähigkeiten offen – etwa:</p>



<ul class="wp-block-list">
<li><a href="https://www.computerwoche.de/article/2833711/version-control-systems-ein-ratgeber.html" target="_blank">Versionskontrollen</a> mit Git,</li>



<li>Continuous Integration &amp; Deployment (<a href="https://www.computerwoche.de/article/2834524/6-massnahmen-fuer-bessere-ci-cd-pipelines.html">CI/</a><a href="https://www.computerwoche.de/article/2834524/6-massnahmen-fuer-bessere-ci-cd-pipelines.html" target="_blank">CD</a>),</li>



<li>Infrastructure as Code (<a href="https://www.computerwoche.de/article/2808916/was-ist-infrastructure-as-code.html" target="_blank">IaC</a>),</li>



<li><a href="https://www.computerwoche.de/article/2820175/4-best-practices-fuer-devops-observability.html" target="_blank">Observability</a>, oder</li>



<li>Zugriff auf <a href="https://www.computerwoche.de/article/4077044/technische-dokumentation-mit-genai-so-gehts.html" target="_blank">Dokumentationen</a>.</li>
</ul>



<p>Im Folgenden werfen wir einen Blick auf zehn offizielle MCP-Server, die populären DevOps-Tools und -Plattformen entsprungen sind und jeweils unterschiedliche Funktionalitäten abdecken. Diese lassen sich innerhalb MCP-kompatibler KI-Entwicklungs-Tools relativ einfach konfigurieren und mit Berechtigungen ausstatten. Offizielle MCP-Server zu nutzen, hat zudem den Vorteil, dass deren Lebensdauer sehr wahrscheinlich länger ist – und sie durchgängig gewartet und aktualisiert werden.</p>



<h2 class="wp-block-heading">1. GitHub MCP-Server</h2>



<p>Kaum ein Entwickler nutzt <a href="https://www.computerwoche.de/article/2824356/26-softwareperlen-fuer-windows-pcs.html" target="_blank">GitHub</a> nicht in irgendeiner Form. Deshalb entwickelt sich der <a href="https://github.com/github/github-mcp-server" target="_blank" rel="noreferrer noopener">offizielle MCP-Server</a> der Plattform zu einer immer beliebteren Methode, um KI-Agenten zu befähigen, mit Code-Repositories zu interagieren – etwa, indem sie Issues erstellen und kommentieren oder Pull Requests zusammenführen.</p>



<p>Außerdem enthält dieser MCP-Server auch Endpunkte für das CI/CD-Management über <a href="https://www.infoworld.com/article/2338562/what-is-github-actions-automated-cicd-for-github.html" target="_blank">GitHub Actions</a>. So könnte etwa ein natürlichsprachlicher Befehl wie “Aktuelle Aktion abbrechen” das <code>cancel_workflow_run</code>-Tool innerhalb von GitHub Actions aufrufen.</p>



<p>Der offizielle MCP-Server von GitHub bietet vergleichsweise umfangreiche Funktionen, die die <a href="https://docs.github.com/en/rest" target="_blank" rel="noreferrer noopener">APIs der Plattform</a> widerspiegeln.  Damit dabei die Sicherheit nicht zu kurz kommt und KI-Agenten keine Mutationen durchführen, lassen sich jederzeit <code>--read-only</code>-Flags konfigurieren.</p>



<h2 class="wp-block-heading">2. Notion MCP-Server</h2>



<p>Notion ist eher ein KI-Collaboration- als ein DevOps-Tool und hat sich mittlerweile fachbereichsübergreifend etabliert, wenn es darum geht, teamintern Transparenz zu schaffen. Der <a href="https://github.com/makenotion/notion-mcp-server" target="_blank" rel="noreferrer noopener">offizielle MCP-Server von Notion</a> ist jedoch auch aus DevOps-Perspektive nützlich. Damit lassen sich Agenten beispielsweise anweisen, interne Stilrichtlinien oder Betriebshandbücher zu konsultieren, die in Notion gespeichert sind.</p>



<p>Der Remote-MCP-Server von Notion ist über eine IDE abrufbar – kann aber mit dem <a href="https://hub.docker.com/r/mcp/notion" target="_blank" rel="noreferrer noopener">offiziellen Docker-Image</a> auch lokal aufgesetzt und ausgeführt werden. Dieser MCP-Server ist als risikoarm zu betrachten, da er über konfigurierbare Scopes und Tokens verfügt, um Notion-Seiten und -Blöcke zu managen.</p>



<h2 class="wp-block-heading">3. Atlassian Remote MCP-Server</h2>



<p>Atlassians <a href="https://support.atlassian.com/atlassian-rovo-mcp-server/docs/getting-started-with-the-atlassian-remote-mcp-server/" target="_blank" rel="noreferrer noopener">Remote MCP-Server</a> verbindet IDEs oder Agentic-AI-Plattformen mit den Cloud-Produkten des Unternehmens. Beispielsweise dem Projektmanagement-Tool Jira. Anzumerken ist dabei, dass sich dieser MCP-Server derzeit in der Beta-Phase befindet und Atlassian-Cloud-Kunden vorbehalten ist.</p>



<p>Damit ist es denkbar, einen Agenten anzuweisen, ein Jira-Issue zum Benutzertesting für eine BezahlApp auf der Grundlage eines aktuellen Bug Report zu aktualisieren – und dabei auf die relevanten Protokolle zu verweisen. Die Aktualisierung von Jira läuft anschließend über den MCP-Server.  </p>



<p>Der MCP-Server von Atlassian unterstützt diverse Clients und gewährleistet mit Oauth-2.1-Support auch sicheren Zugriff.</p>



<h2 class="wp-block-heading">4. Argo CD MCP-Server</h2>



<p>Auch die Entwickler des populären Open-Source-Tools Argo CD stellen einen <a href="https://github.com/argoproj-labs/mcp-for-argocd" target="_blank" rel="noreferrer noopener">MCP-Server</a> zur Verfügung. Dieser fasst Calls an die Argo-CD-API zusammen und enthält Tools, mit denen die Benutzer über natürliche Sprache mit Argo CD interagieren können:</p>



<ul class="wp-block-list">
<li>Mit dem <strong>Application-Management-Tool</strong> können KI-Agenten Anwendungsinformationen abrufen, Anwendungen erstellen und löschen sowie weitere Prozesse ausführen.</li>



<li>Über das <strong>Resource-Management-Tool</strong> rufen KI-Agenten Ressourceninformationen, Protokolle und Ereignisse für bestimmte Anwendungen ab und führen spezifische Aktionen für bestimmte Ressourcen aus.</li>
</ul>



<p>Mit Hilfe dieses MCP-Servers lassen sich viele Tasks “natürlichsprachlich” ausführen, die auch über das User Interface oder das CLI-Tool von Argo CD verfügbar sind. Eine Staging-App zu synchronisieren, geht so beispielsweise flotter von der Hand. Damit das auch funktioniert, muss der MCP-Server von Argo CD aber auch ordentlich integriert werden – und benötigt Zugriff auf eine laufende Argo-CD-Instanz inklusive korrekt konfigurierter Anmeldedaten.</p>



<h2 class="wp-block-heading">5. Grafana MCP-Server</h2>



<p>Das Datenvisualisierungs- und Monitoring-Tool Grafana gehört für viele DevOps- und SRE-Teams zum Standardrepertoire. Der offizielle <a href="https://github.com/grafana/mcp-grafana" target="_blank" rel="noreferrer noopener">MCP-Server für Grafana</a> befähigt KI-Agenten dazu, Observability-Daten bereitzustellen, um Entwicklungs- oder Betriebsprozesse zu optimieren.</p>



<p>Über diesen MCP-Server können Agenten außerdem vollständige oder teilweise Details aus Dashboards abfragen, die Metriken zur Systemleistung und Health-Daten aus verschiedenen Quellen kombinieren. Darüber hinaus lassen sich über den Grafana MCP-Server auch Informationen zu Datenquellen abrufen, weitere Monitoring-Systeme oder Details zu spezifischen Vorfällen abfragen.</p>



<p>Das Toolset ist dabei konfigurierbar, die Berechtigungen der Agenten können durch den Benutzer definiert werden. Darüber hinaus hat Grafana auch die Antwortstruktur seines MCP-Servers optimiert. Das soll die Nutzung des Kontextfensters minimieren und die Kosten für Token senken. Beispielsweise kann ein MCP-Client das <code>get_dashboard_property</code>-Tool aufrufen, um einen bestimmten Part eines Dashboards anhand seiner UID abzurufen.</p>



<h2 class="wp-block-heading">6. Terraform MCP-Server</h2>



<p>HashiCorp Terraform ist – <a href="https://www.computerwoche.de/article/3853753/opentofu-der-killer-fork.html" target="_blank">Alternativen</a> zum Trotz – weiterhin die erste Adresse, wenn es um Infrastructure as Code (IaC) geht. Entsprechend ist der <a href="https://github.com/hashicorp/terraform-mcp-server" target="_blank" rel="noreferrer noopener">offizielle MCP-Server</a> eine interessante Option, um Terraform-Konfigurationen über KI-Agenten zu generieren und zu managen. Der MCP-Server lässt sich dabei sowohl in die <a href="https://developer.hashicorp.com/terraform/registry/api-docs" target="_blank" rel="noreferrer noopener">Registry APIs</a> als auch in die <a href="https://developer.hashicorp.com/terraform/enterprise" target="_blank" rel="noreferrer noopener">Enterprise/HCP-Services</a> von Terraform integrieren. Das ermöglicht KI-Agenten etwa:</p>



<ul class="wp-block-list">
<li>Modul- und Anbieter-Metadaten abzufragen,</li>



<li>den Status von Workspaces zu überprüfen, und</li>



<li>Tasks (mit menschlicher Genehmigung) auszulösen.</li>
</ul>



<p>Ein Befehl wie “Generiere Terraform-Code für einen neuen Run” könnte so die <code>create_run</code>-Operation aufrufen, woraufhin der KI-Agent die Konfiguration validiert und plant, bevor er sie anwendet.</p>



<p>Der Terraform MCP-Server wird mit der Readme-Datei <a href="http://agents.md/" target="_blank" rel="noreferrer noopener">AGENTS.md</a> ausgeliefert. Diese erleichtert es Agenten, Tools zu interpretieren. Aktuell (Stand Dezember 2025) ist der Terraform MCP-Server ausschließlich für die lokale Nutzung verfügbar. Er ist ausdrücklich nicht für Remote- oder gehostete Deployments vorgesehen.</p>



<h2 class="wp-block-heading">7. GitLab MCP-Server</h2>



<p>Auch die GitLab-Plattform stellt – ihren Premium- und Ultimate-Kunden – einen <a href="https://docs.gitlab.com/user/gitlab_duo/model_context_protocol/mcp_server/" target="_blank" rel="noreferrer noopener">MCP-Server</a> bereit. Dieser befindet sich aktuell in der Beta-Phase und befähigt KI-Agenten dazu, Projetinformationen zu sammeln und Operationen über GitLab-APIs sicher auszuführen.  </p>



<p>Der GitLab MCP-Server erlaubt einige Statusänderungen, etwa Issues zu erstellen oder Merge Requests. Die anderen Funktionen dienen hauptsächlich der Datenabfrage – also etwa Informationen zu Issues, Merge-Anfragen, Commits, Diffs und Pipelines abzufragen. Enthalten ist zudem ein allgemeines Suchwerkzeug.</p>



<p>Die <a href="https://docs.gitlab.com/user/gitlab_duo/model_context_protocol/mcp_server/" target="_blank" rel="noreferrer noopener">Dokumentation</a> des GitLab MCP-Servers ist sehr ausführlich und enthält zahlreiche Beispiele für natürlichsprachliche Ausdrücke, die verarbeiten werden können. Der Server unterstützt zudem die dynamische Client-Registrierung über OAuth 2.0.</p>



<h2 class="wp-block-heading">8. Snyk MCP-Server</h2>



<p>Snyk bietet eine Security-Plattform für Entwickler an – und einen <a href="https://docs.snyk.io/integrations/snyk-studio-agentic-integrations">MCP-</a><a href="https://docs.snyk.io/integrations/snyk-studio-agentic-integrations" target="_blank" rel="noreferrer noopener">Server</a>. Dieser kann dazu genutzt werden, mit Hilfe von KI-Agenten (IaC-)Code, Open-Source-Abhängigkeiten, Container sowie SBOMs oder auch AIBOMs auf Schwachstellen zu scannen und diese zu beheben. Den Snyk MCP-Server zu integrieren, ist also dazu geeignet, Sicherheitsscans automatisch im Rahmen eines CI/CD-Workflows mit KI-Agenten durchzuführen. Diese Scans lassen sich sogar über andere MCP-Server hinweg koordinieren, beispielsweise indem Repository-Details über den GitHub MCP-Server abgerufen werden, bevor ein Snyk-Scan gestartet wird.</p>



<p>Ein Prompt wie “Scanne das Authentication-Microservice-Repo auf Sicherheitslücken” könnte einen Agenten anweisen, das Repository mit GitHub MCP zu lokalisieren und dann Snyk-Tools wie <code>snyk_sca_scan</code> oder <code>snyk_code_scan</code> nutzen, um bekannte Schwachstellen, geleakte Anmeldedaten und andere Risiken zu identifizieren.</p>



<p>Dieser MCP-Server wird lokal ausgeführt und verwendet die Snyk-CLI, um Befehle wie diese über authentifizierte API-Calls auszuführen. Das Unternehmen bietet keine gehostete Remote-Version seines MCP-Servers an.</p>



<h2 class="wp-block-heading">9. AWS MCP-Server</h2>



<p>Die Cloud-Hyperscaler haben besonders eifrig daran gearbeitet, schnell MCP-Server auf die Beine zu stellen, die sich in ihre Ökosysteme integrieren lassen. Amazon Web Services (AWS) hat beispielsweise Dutzende spezialisierter <a href="https://github.com/awslabs/mcp">MCP-Server</a> eingeführt, die KI-Agenten ermöglichen, mit sämtlichen Arten von AWS-Services zu interagieren. Einige davon werden als vollständig gemanagte Dienste angeboten, andere können hingegen nur lokal ausgeführt werden.</p>



<ul class="wp-block-list">
<li>So können KI-Agenten über den <a href="https://github.com/awslabs/mcp/blob/main/src/lambda-tool-mcp-server" target="_blank" rel="noreferrer noopener">Lambda Tool MCP-Server</a> beispielsweise Lambda-Funktionen auflisten und aufrufen.</li>



<li>Der <a href="https://github.com/awslabs/mcp/tree/main/src/s3-tables-mcp-server" target="_blank" rel="noreferrer noopener">AWS S3 Tables MCP-Server</a> lässt sich hingegen von einem Agenten nutzen, um S3-Buckets abzufragen oder neue Tabellen aus CSV-Dateien zu erstellen.</li>



<li>Der <a href="https://github.com/awslabs/mcp/tree/main/src/aws-knowledge-mcp-server" target="_blank" rel="noreferrer noopener">AWS Knowledge MCP-Server</a> verbindet Agenten mit den neuesten AWS-Dokumentationen, API-Referenzen und Architekturleitfäden.</li>
</ul>



<p>Eine Query an letztgenannten Knowledge-Server könnte etwa die Anweisung beinhalten, eine API-Referenz für das von AWS gemanagte Prometheus-Tool aufzurufen. Das würde die richtigen aktuellen Informationen liefern – optimiert für die Nutzung durch KI-Agenten.</p>



<h2 class="wp-block-heading">10. Pulumi MCP-Server</h2>



<p>Pulumi ist eine weitere beliebte IaC-Option – und hat ebenfalls einen <a href="https://www.pulumi.com/docs/iac/guides/ai-integration/mcp-server/" target="_blank" rel="noreferrer noopener">offiziellen MCP-Server</a> eingeführt. Dieser ermöglicht es KI-Agenten,</p>



<ul class="wp-block-list">
<li>Pulumi-Registries abzufragen,</li>



<li>auf Cloud-Ressourcen und -Infrastruktur zuzugreifen, und</li>



<li>Pulumi-Befehle auszuführen.</li>
</ul>



<p>Wie Entwickler diesen MCP-Server nutzen können, um einen Azure Kubernetes Service (AKS)-Cluster bereitzustellen, erklärt Pulumi beispielhaft in einer ausführlichen <a href="https://www.pulumi.com/blog/mcp-server-ai-assistants/#the-goal-provisioning-an-aks-cluster">Schritt-für-Schritt-Anleitung</a>. (fm)</p>



<p><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/4096223/10-mcp-servers-for-devops.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Best Personal CRM Tools for 2026]]></title>
<description><![CDATA[I reviewed the best personal CRM tools and found HubSpot to be the top free option, while Pipedrive, monday CRM, Notion, and ClickUp stand out for timelines, task tracking, project databases, and customization.
The post 5 Best Personal CRM Tools for 2026 appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3569639/it-nachrichten/5-best-personal-crm-tools-for-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569639/it-nachrichten/5-best-personal-crm-tools-for-2026/</guid>
<pubDate>Wed, 03 Jun 2026 15:01:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I reviewed the best personal CRM tools and found HubSpot to be the top free option, while Pipedrive, monday CRM, Notion, and ClickUp stand out for timelines, task tracking, project databases, and customization.</p>
<p>The post <a href="https://www.techrepublic.com/article/best-personal-crm/">5 Best Personal CRM Tools for 2026</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[An explosion of software is coming]]></title>
<description><![CDATA[When I was a kid, we all marveled at the notion of the Star Trek computer that you’d just talk to and that would answer all your questions. It seemed impossibly fantastic and categorically impossible. Well, we have that now. In one episode, Captain Kirk used a universal translator to communicate ...]]></description>
<link>https://tsecurity.de/de/3568928/ai-nachrichten/an-explosion-of-software-is-coming/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568928/ai-nachrichten/an-explosion-of-software-is-coming/</guid>
<pubDate>Wed, 03 Jun 2026 11:04:08 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When I was a kid, we all marveled at the notion of the Star Trek computer that you’d just talk to and that would answer all your questions. It seemed impossibly fantastic and categorically impossible. Well, we have that now. In one episode, Captain Kirk used a universal translator to communicate with an alien (never mind that the aliens always seemed to speak English..). Today, everyone’s phone can do real-time translations between all the most commonly spoken languages on the planet. </p>



<p>If you haven’t figured it out by now, I’m <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html" data-type="link" data-id="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">bullish on agentic coding</a>. I <a href="https://www.infoworld.com/article/4143101/pity-the-developers-who-resist-agentic-coding.html">think it’s marvelous</a>, I think it will <a href="https://www.infoworld.com/article/4167463/no-ai-wont-destroy-software-development-jobs.html">bring about an increase in software development jobs</a>, and I think it will <a href="https://www.infoworld.com/article/4149541/stop-worrying-instead-imagine-software-developers-next-great-pivot.html">bring about unprecedented growth in the production of software</a>. It’s that last point I want to explore a bit more deeply, because I think an explosion of software is coming.</p>



<p>Thomas Watson, the legendary IBM CEO, is often misquoted as saying, “I think there is a world market for maybe five computers.”  The true story is that he went out to talk to 20 customers, hoping to sell five IBM 701 computers, and ended up with 18 orders. Of course, today, computer sales are measured in the hundreds of millions. </p>



<p>We are currently in the “loving the thought of getting 18 orders after expecting five” stage of software. We are just getting started.</p>



<p>Mr. Watson probably couldn’t envision everyone walking around with a computer in their pocket that is a 100 million times more powerful than that IBM 701. And though I’m going to try, I’ll certainly come up way short of imagining a volume of software output that is eight orders of magnitude beyond what we are producing today. </p>



<h2 class="wp-block-heading">Ready for takeoff</h2>



<p>The first chunk of this blitz will be software that looks familiar and isn’t that surprising. It will be the software sitting in our backlogs — things we’ve wanted to do for years but haven’t had the time for. All software development houses have these projects, and now they will get done. This software will be an expansion of the software we currently have. </p>



<p>The second chunk will come when companies without development teams realize they can build the software they need using consultancies that can deliver quickly and at minimal cost. They will develop software tools that fit their unique business needs. Instead of using off-the-shelf solutions that they adapt to their needs, they will build custom software that works exactly the way their companies do.</p>



<p>The third chunk will come when those companies figure out that they can build the software they need themselves. Agentic coding tools will soon be powerful enough for non-developers to create the custom software a company needs, and they’ll be able to do these things in-house. </p>



<p>The fourth wave is the one that really excites me — the wave of things we haven’t yet conceived of. I’d love to be able to tell you what that will be all about, but of course I can’t. It would be like someone telling you in 1988 about Google Maps, Wikipedia, ChatGPT, and Spotify.</p>



<p>The cost of developing software is about to drop through the floor, causing the demand for software to shoot through the roof. Software has no real physical limitations, like bridges do — the only limitation is our imaginations, and that has proven to be boundless.  </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Work management was built around human latency]]></title>
<description><![CDATA[I have been in software long enough to remember when enterprise products shipped on CDs. Actual plastic discs reviewed by enterprise IT committees. PMs maintained 200-page specifications, engineers worked from Microsoft Project files and updates circulated as email attachments. If the plan change...]]></description>
<link>https://tsecurity.de/de/3565465/it-security-nachrichten/work-management-was-built-around-human-latency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565465/it-security-nachrichten/work-management-was-built-around-human-latency/</guid>
<pubDate>Tue, 02 Jun 2026 11:08:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I have been in software long enough to remember when enterprise products shipped on CDs. Actual plastic discs reviewed by enterprise IT committees. PMs maintained 200-page specifications, engineers worked from Microsoft Project files and updates circulated as email attachments. If the plan changed, the PM opened the file, saved a new version and emailed it around again. A few days later, half the team would be working from the latest plan while the other half was still operating from an outdated version.</p>



<p>That sounds absurd now, but at the time it matched the operating tempo of software development.</p>



<h2 class="wp-block-heading">Why Waterfall worked</h2>



<p>The original project-management models for software came from industries that built large, complex systems long before software existed, particularly manufacturing and construction. Six-month specifications, multi-year builds, gated phases and tightly controlled handoffs made sense in a world where software shipped slowly, and markets moved in quarters rather than days.</p>



<p>The giant specification document served a real purpose. It compressed everything the organization had learned into a single artifact, handed it to the builders and effectively said: go build this, and we’ll regroup in a year.</p>



<p>Then the web changed the clock.</p>



<p>Feedback loops collapsed from quarters to weeks, and eventually to days. Teams could ship on Tuesday and observe user behavior on Wednesday. In that environment, the 200-page specification stopped looking like disciplined planning and started looking like operational drag. The pace of work changed which meant the tooling and coordination model had to change with it.</p>



<h2 class="wp-block-heading"><a></a>Why Agile took over</h2>



<p>Jira, Asana, Notion, Linear and Slack became foundational because they matched the tempo of modern work over the last two decades. They were designed for a world where execution still took humans days or weeks, where work moved across queues owned by different people, and where plans required constant revision because reality kept shifting underneath them.</p>



<p>A ticket tracks a commitment made at a specific point in time because somebody else is waiting on that work. Sprint boards help teams coordinate around the reality that humans cannot execute instantly and cannot keep every dependency loaded into memory simultaneously. Standups exist because information spreads slowly. Backlog grooming exists because demand arrives faster than available execution capacity.</p>



<p>The process ceremony has a real function. It compensates for latency. Often smart latency compensation. Often necessary latency compensation. But latency compensation, nonetheless.</p>



<p>Waterfall was correct for the pace of 1995. Agile was correct for the pace of the last twenty-five years. Different operating speeds produce different management systems.</p>



<h2 class="wp-block-heading">Execution speed changes the system</h2>



<p>Now compare that model with what happens when I ask an agent to do something instead of asking a human colleague.</p>



<p>In the old workflow, the colleague already had their own priorities and queue of work. They could not immediately stop everything for my request. Maybe they got to it later that afternoon. Maybe the next day. Maybe it entered sprint planning and returned one to three weeks later. By the time the work came back, I had already context-switched into something else.</p>



<p>That waiting creates more than delay. It creates in-flight work, and in-flight work creates management overhead. Teams start tracking, grooming, triaging, reminding, reconciling and coordinating because the work itself is sitting in queues.</p>



<p>Once execution speeds up dramatically, much of that overhead starts looking different.</p>



<p>With an agent, I ask for something, it runs and it comes back ten minutes later while I am still operating inside the same mental context. I review the output, redirect it, ask again and iterate immediately. Five iterations can happen in half an hour, producing work that previously might have taken weeks to move through a marketing queue, an ops process or an engineering sprint.</p>



<p>That workflow does not fit naturally onto a sprint board anymore. If I encounter an issue at 10:00 a.m., an agent drafts a fix by 10:20 and I review it by 10:35, the ticket increasingly becomes a historical artifact recording a bottleneck that no longer meaningfully exists.</p>



<h2 class="wp-block-heading"><a></a>Backlogs exist to manage latency</h2>



<p>David Allen’s GTD methodology includes the two-minute rule: if something takes less than two minutes, do not queue it. Just do it. The cost of tracking the task can exceed the cost of completing it.</p>



<p>Writing the task down, tagging it, categorizing it, finding it again later and deciding when to handle it may require more energy than simply finishing the work immediately.</p>



<p>Agents introduce an organizational version of the same principle. If an agent can complete something quickly, it often becomes easier to launch the agent than to delegate the work to another person and manage the surrounding coordination.</p>



<p>Mechanically, that is what tickets and backlogs do. They create ledger entries indicating that somebody committed to work and the organization is now waiting for it. Those ledgers matter because human execution is slow and shared organizational memory is fragile.</p>



<p>As those constraints weaken, the ledger has less to track.</p>



<p>The work runs, returns and waits primarily for review. The scarce resource increasingly becomes judgment rather than execution itself.</p>



<p>Sprint ceremonies, standups, backlog grooming, triage meetings and workflow management largely exist to compensate for execution bottlenecks that are beginning to shrink across large portions of knowledge work. Not every category of work changes this way. Deep architectural decisions, strategic judgment, creative direction and interpersonal negotiation still operate on human time. But the enormous, long tail of “someone should probably get to this” work changes meaningfully when that someone can be an agent that starts immediately.</p>



<h2 class="wp-block-heading">What agentic workflows look like</h2>



<p>Imagine a customer posts a small product complaint into a shared Slack channel:</p>



<p>“This dropdown closes when I try to scroll inside it. Driving me crazy.”</p>



<p>Under the old model, QA reproduces the issue and files a ticket. A PM triages it, groups it into other frontend work and schedules it into a sprint. A developer eventually picks it up, fixes it, opens a PR, waits for review, merges the change and ships it in the next release cycle. Two to four weeks pass. Multiple people touch the issue. The organization produces tickets, PRs, release notes and Slack threads because context decays over time and teams need durable coordination artifacts.</p>



<p>Under the new model, an agent reads the message, reproduces the issue in a sandbox, drafts a fix, runs tests and security scans, attaches a short video showing the corrected behavior and notifies a human reviewer. The human watches the video, reviews the diff and decides whether the change should ship.</p>



<p>The elapsed time drops below an hour, while human attention concentrates almost entirely on judgment rather than coordination.</p>



<p>Versions of this workflow already exist inside highly agentic teams.</p>



<h2 class="wp-block-heading"><a></a>The next layer of tooling</h2>



<p>Most technology shifts follow a similar pattern. First, information moves faster. Then work itself moves faster. After that, entirely new management and coordination systems emerge around the new operating speed.</p>



<p>That is the phase we are entering now.</p>



<p>AI accelerates execution itself, and early adopters are already stitching together workflows that look very different from the work-management stack most companies still use today. The next generation of organizational tooling probably will not resemble software built for the pre-AI era because those systems assumed the slowest part of the organization was human execution.</p>



<p>That assumption is beginning to break.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New PHANTOMPULSE RAT Campaign Uses UAC Bypass in Windows Attacks]]></title>
<description><![CDATA[The final stage of the REF6598 intrusion set, uncovering a sophisticated Remote Access Trojan (RAT) named PHANTOMPULSE. Originally delivered through malicious Obsidian plugins, this malware relies on complex evasion tactics, a blockchain-based command and control (C2) channel, and a public User A...]]></description>
<link>https://tsecurity.de/de/3565198/it-security-nachrichten/new-phantompulse-rat-campaign-uses-uac-bypass-in-windows-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565198/it-security-nachrichten/new-phantompulse-rat-campaign-uses-uac-bypass-in-windows-attacks/</guid>
<pubDate>Tue, 02 Jun 2026 09:22:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The final stage of the REF6598 intrusion set, uncovering a sophisticated Remote Access Trojan (RAT) named PHANTOMPULSE. Originally delivered through malicious Obsidian plugins, this malware relies on complex evasion tactics, a blockchain-based command and control (C2) channel, and a public User Account Control (UAC) bypass to compromise Windows systems. The binary also features strong fingerprints […]</p>
<p>The post <a href="https://cyberpress.org/phantompulse-rat-bypasses-uac/">New PHANTOMPULSE RAT Campaign Uses UAC Bypass in Windows Attacks</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PHANTOMPULSE RAT Uses UAC Bypass to Hijack Windows Systems]]></title>
<description><![CDATA[New technical details about PHANTOMPULSE, a sophisticated remote access trojan (RAT) used in multi-stage intrusions targeting Windows environments. The malware represents the final payload in an attack chain previously linked to Obsidian plugin abuse and in-memory loaders, but this latest…
Read m...]]></description>
<link>https://tsecurity.de/de/3565067/it-security-nachrichten/phantompulse-rat-uses-uac-bypass-to-hijack-windows-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565067/it-security-nachrichten/phantompulse-rat-uses-uac-bypass-to-hijack-windows-systems/</guid>
<pubDate>Tue, 02 Jun 2026 08:05:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New technical details about PHANTOMPULSE, a sophisticated remote access trojan (RAT) used in multi-stage intrusions targeting Windows environments. The malware represents the final payload in an attack chain previously linked to Obsidian plugin abuse and in-memory loaders, but this latest…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/phantompulse-rat-uses-uac-bypass-to-hijack-windows-systems/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/phantompulse-rat-uses-uac-bypass-to-hijack-windows-systems/">PHANTOMPULSE RAT Uses UAC Bypass to Hijack Windows Systems</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PHANTOMPULSE RAT Uses UAC Bypass to Hijack Windows Systems]]></title>
<description><![CDATA[New technical details about PHANTOMPULSE, a sophisticated remote access trojan (RAT) used in multi-stage intrusions targeting Windows environments. The malware represents the final payload in an attack chain previously linked to Obsidian plugin abuse and in-memory loaders, but this latest analysi...]]></description>
<link>https://tsecurity.de/de/3565049/it-security-nachrichten/phantompulse-rat-uses-uac-bypass-to-hijack-windows-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565049/it-security-nachrichten/phantompulse-rat-uses-uac-bypass-to-hijack-windows-systems/</guid>
<pubDate>Tue, 02 Jun 2026 07:52:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New technical details about PHANTOMPULSE, a sophisticated remote access trojan (RAT) used in multi-stage intrusions targeting Windows environments. The malware represents the final payload in an attack chain previously linked to Obsidian plugin abuse and in-memory loaders, but this latest analysis focuses on its advanced post-exploitation capabilities. PHANTOMPULSE stands out for combining multiple stealth techniques, […]</p>
<p>The post <a href="https://gbhackers.com/phantompulse-rat-uses-uac/">PHANTOMPULSE RAT Uses UAC Bypass to Hijack Windows Systems</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[new app - Whisp - Anti Note for gnome]]></title>
<description><![CDATA[I was watching a random Mac apps video by Snazzy Labs, and he showed an app called Anti Note. I wanted something similar for GNOME that felt native, fast, and fluid. So, I built Whisp. Whisp is not Google Docs, Obsidian, or Notion. It is supposed to be the Anti-Note but for GNOME. It’s designed s...]]></description>
<link>https://tsecurity.de/de/3564723/linux-tipps/new-app-whisp-anti-note-for-gnome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564723/linux-tipps/new-app-whisp-anti-note-for-gnome/</guid>
<pubDate>Tue, 02 Jun 2026 03:53:03 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I was watching a random Mac apps video by Snazzy Labs, and he showed an app called Anti Note. I wanted something similar for GNOME that felt native, fast, and fluid. So, I built <strong>Whisp</strong>.</p> <p>Whisp is not Google Docs, Obsidian, or Notion. It is supposed to be the Anti-Note but for GNOME. It’s designed strictly for the GNOME desktop using GTK4 and Libadwaita. It completely abandons traditional file hierarchies in favor of a spatial, swipeable canvas.</p> <p><strong>Features:</strong></p> <ul> <li><strong>Touchpad Swiping:</strong> Fluidly swipe left/right to move between your active notes. (You can also use keyboard shortcuts to navigate).</li> <li><strong>Live Markdown:</strong> Real-time formatting with a WYSIWYG toggle to instantly hide syntax.</li> <li><strong>Native Paper Themes:</strong> Switch between Dotted, Grid, or Blank backgrounds.</li> <li><strong>Instant:</strong> It only renders your active notes, making it incredibly lightweight and fast.</li> <li><strong>Smart Paste:</strong> Features like Plain Paste and a built-in URL Link shortener.</li> </ul> <p>This is my very first app release for GNOME, and I am still learning things! I am going to be adding many more features, and my long-term goal is to move this app to GNOME Circle, though I know that is a long road.</p> <p><strong>You can check it out here:</strong> <br> 🔗 <strong>Flathub:</strong> <a href="https://flathub.org/apps/io.github.tanaybhomia.Whisp">https://flathub.org/apps/io.github.tanaybhomia.Whisp</a> <br> 🔗 <strong>GitHub:</strong> <a href="https://github.com/tanaybhomia/Whisp">https://github.com/tanaybhomia/Whisp</a></p> <p>Please check it out, give it a try, and feel free to file issues! New things are coming soon.</p> <p><em>P.S. I have attached some photos, but they don't show the movement of the app/gestures because I don't know how to record proper videos on Linux yet. If anyone can record and send me a nice demo video, it would help me a lot for the website and GitHub repo!</em></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Baajjii"> /u/Baajjii </a> <br> <span><a href="https://i.redd.it/k5vyyyy9qp4h1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tu0uk1/new_app_whisp_anti_note_for_gnome/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Flowise Flaw Gives Attackers Full Server Control]]></title>
<description><![CDATA[Obsidian publishes PoC for a 1-click Flowise RCE that can fully compromise self-hosted servers]]></description>
<link>https://tsecurity.de/de/3563318/it-security-nachrichten/critical-flowise-flaw-gives-attackers-full-server-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563318/it-security-nachrichten/critical-flowise-flaw-gives-attackers-full-server-control/</guid>
<pubDate>Mon, 01 Jun 2026 16:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Obsidian publishes PoC for a 1-click Flowise RCE that can fully compromise self-hosted servers]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Flowise Flaw Gives Attackers Full Server Control]]></title>
<description><![CDATA[Obsidian publishes PoC for a 1-click Flowise RCE that can fully compromise self-hosted servers This article has been indexed from www.infosecurity-magazine.com Read the original article: Critical Flowise Flaw Gives Attackers Full Server Control
Read more →
The post Critical Flowise Flaw Gives Att...]]></description>
<link>https://tsecurity.de/de/3563316/it-security-nachrichten/critical-flowise-flaw-gives-attackers-full-server-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563316/it-security-nachrichten/critical-flowise-flaw-gives-attackers-full-server-control/</guid>
<pubDate>Mon, 01 Jun 2026 16:08:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Obsidian publishes PoC for a 1-click Flowise RCE that can fully compromise self-hosted servers This article has been indexed from www.infosecurity-magazine.com Read the original article: Critical Flowise Flaw Gives Attackers Full Server Control</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/critical-flowise-flaw-gives-attackers-full-server-control/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/critical-flowise-flaw-gives-attackers-full-server-control/">Critical Flowise Flaw Gives Attackers Full Server Control</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Flowise’s MCP implementation can run ghost commands]]></title>
<description><![CDATA[Enterprises using the lightweight, open-source Flowise platform to power self-hosted AI workloads now have a new near-max-severity issue to worry about.



Researchers at Obsidian Security have detailed a one-click remote code execution (RCE) vulnerability affecting self-hosted Flowise deployment...]]></description>
<link>https://tsecurity.de/de/3562981/ai-nachrichten/flowises-mcp-implementation-can-run-ghost-commands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562981/ai-nachrichten/flowises-mcp-implementation-can-run-ghost-commands/</guid>
<pubDate>Mon, 01 Jun 2026 14:18:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprises using the lightweight, open-source Flowise platform to power self-hosted AI workloads now have a new near-max-severity issue to worry about.</p>



<p>Researchers at Obsidian Security have detailed a one-click remote code execution (RCE) vulnerability affecting self-hosted Flowise deployments through its implementation of Model Context Protocol (<a href="https://www.csoonline.com/article/4031749/mcp-security-securing-the-backbone-of-agentic-ai.html" target="_blank">MCP</a>) stdio servers.</p>



<p>The problem is essentially a sandboxing failure of attacker-controlled MCP configurations, leading to server-side code execution.</p>



<p>“Post-auth RCE in Flowise can be triggered with a single click via a malicious chatflow import before any save or run,” the researchers said in a blog <a href="https://www.obsidiansecurity.com/blog/when-is-stdio-mcp-actually-a-vulnerability" target="_blank" rel="noreferrer noopener">post</a>. “The official patch relies on input validation that is trivially bypassed and fails to address the root cause.”</p>



<p>Flowise is commonly used to develop internal AI assistants, retrieval-augmented generation (<a href="https://www.csoonline.com/article/4163888/securing-rag-pipelines-in-enterprise-saas.html">RAG</a>) applications, customer-facing chatbots, and autonomous agents connected to business systems.</p>



<p>The flaw does not affect Flowise Cloud, as stdio MCP is disabled there. For the rest, where the feature is enabled and is absolutely necessary, there is a security and functionality tradeoff developers need to understand and actively review server configurations for possible threats, the researchers explained.</p>



<h2 class="wp-block-heading"><a></a>Once-click RCE affects everything Flowise can reach</h2>



<p>The vulnerability, tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40933" target="_blank" rel="noreferrer noopener">CVE-2026-40933</a>, affects Flowise’s implementation of MCP stdio servers. MCP’s stdio is designed to launch local server processes and communicate with them through standard input and output streams, allowing AI agents to interact with files, Git repositories, databases, browsers, and local credentials.</p>



<p>According to Obsidian Security, the issue stems from Flowise allowing users to configure MCP stdio servers containing arbitrary commands. Because those commands are ultimately executed by the underlying operating system, an attacker can achieve remote code execution with the privileges of the Flowise process.</p>



<p>In containerized deployments, the researchers noted, this can effectively provide root-level access to the environment hosting the platform.</p>



<p>The flaw has been assigned a 9.9 CVSS rating, with a successful compromise potentially exposing API keys, databases, cloud resources, SaaS applications, and other assets accessible through Flowise.</p>



<h2 class="wp-block-heading">Researchers said the fixes fall short</h2>



<p>The disclosure details a series of remediation efforts by Flowise aimed at restricting how MCP stdio commands can be configured and executed. According to Obsidian, however, each iteration relied primarily on command validation and filtering mechanisms that can be bypassed under certain conditions.</p>



<p>“Flowise appeared to acknowledge the risk and hardened Custom MCP over several rounds,” the researchers noted. “<a href="https://github.com/FlowiseAI/Flowise/pull/5232">#5232</a> introduced CUSTOM_MCP_SECURITY_CHECK, a default-enabled validation layer for Custom MCP configurations.” While the checks reduced obvious command execution paths, they did little to change the underlying threat of allowing users to supply stdio MCP configurations, they said.</p>



<p>Obsidian’s reporting of the flaw triggered further hardening of the feature with flag validation in updates <a href="https://github.com/FlowiseAI/Flowise/pull/5741" target="_blank" rel="noreferrer noopener">#5741 </a>and <a href="https://github.com/FlowiseAI/Flowise/pull/5943" target="_blank" rel="noreferrer noopener">#5943</a>. These, too, did not entirely remove the threat.</p>



<p>When requested to treat stdio MCP as unsafe by default and require explicit opt-in, Flowise reportedly said they wanted to “limit what we know is bad without completely disabling features that users may rely on.” Obsidian shared a proof-of-concept (POC) exploit demonstrating how Flowise’s current protections could still be bypassed to achieve successful RCE.</p>



<p> The only complete mitigation recommended by the researchers is turning off MCP stdio by setting “CUSTOM_MCP_PROTOCOL=sse”. For those who can’t, without obstructing operations, pinning trusted packages where possible, and reviewing imported chatflows from untrusted sources might help, the researchers added.</p>



<p><em>The article originally appeared on <a href="https://www.csoonline.com/article/4179309/flowises-mcp-implementation-can-run-ghost-commands.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Flowise’s MCP implementation can run ghost commands]]></title>
<description><![CDATA[Enterprises using the lightweight, open-source Flowise platform to power self-hosted AI workloads have a new near-max severity issue to worry about.



Researchers at Obsidian Security have detailed a one-click remote code execution (RCE) vulnerability affecting self-hosted Flowise deployments th...]]></description>
<link>https://tsecurity.de/de/3562940/it-security-nachrichten/flowises-mcp-implementation-can-run-ghost-commands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562940/it-security-nachrichten/flowises-mcp-implementation-can-run-ghost-commands/</guid>
<pubDate>Mon, 01 Jun 2026 14:08:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprises using the lightweight, open-source Flowise platform to power self-hosted AI workloads have a new near-max severity issue to worry about.</p>



<p>Researchers at Obsidian Security have detailed a one-click remote code execution (RCE) vulnerability affecting self-hosted Flowise deployments through its implementation of Model Context Protocol (<a href="https://www.csoonline.com/article/4031749/mcp-security-securing-the-backbone-of-agentic-ai.html" target="_blank">MCP</a>) stdio servers.</p>



<p>The problem is essentially a sandboxing failure of attacker-controlled MCP configurations, leading to server-side code execution.</p>



<p>“Post-auth RCE in Flowise can be triggered with a single click via a malicious chatflow import before any save or run,” the researchers said in a blog <a href="https://www.obsidiansecurity.com/blog/when-is-stdio-mcp-actually-a-vulnerability" target="_blank" rel="noreferrer noopener">post</a>. “The official patch relies on input validation that is trivially bypassed and fails to address the root cause.”</p>



<p>Flowise is commonly used to develop internal AI assistants, retrieval-augmented generation (<a href="https://www.csoonline.com/article/4163888/securing-rag-pipelines-in-enterprise-saas.html">RAG</a>) applications, customer-facing chatbots, and autonomous agents connected to business systems.</p>



<p>The flaw does not affect Flowise Cloud, as stdio MCP is disabled there. For the rest, where the feature is enabled and is absolutely necessary, there is a security and functionality tradeoff developers need to understand and actively review server configurations for possible threats, the researchers explained.</p>



<h2 class="wp-block-heading"><a></a>Once-click RCE affects everything Flowise can reach</h2>



<p>The vulnerability, tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40933" target="_blank" rel="noreferrer noopener">CVE-2026-40933</a>, affects Flowise’s implementation of MCP stdio servers. MCP’s stdio is designed to launch local server processes and communicate with them through standard input and output streams, allowing AI agents to interact with files, Git repositories, databases, browsers, and local credentials.</p>



<p>According to Obsidian Security, the issue stems from Flowise allowing users to configure MCP stdio servers containing arbitrary commands. Because those commands are ultimately executed by the underlying operating system, an attacker can achieve remote code execution with the privileges of the Flowise process.</p>



<p>In containerized deployments, the researchers noted, this can effectively provide root-level access to the environment hosting the platform.</p>



<p>The flaw has been assigned a 9.9 CVSS rating, with a successful compromise potentially exposing API keys, databases, cloud resources, SaaS applications, and other assets accessible through Flowise.</p>



<h2 class="wp-block-heading"><a></a>Researchers said the fixes fall short</h2>



<p>The disclosure details a series of remediation efforts by Flowise aimed at restricting how MCP stdio commands can be configured and executed. According to Obsidian, however, each iteration relied primarily on command validation and filtering mechanisms that can be bypassed under certain conditions.</p>



<p>“Flowise appeared to acknowledge the risk and hardened Custom MCP over several rounds,” the researchers noted. “<a href="https://github.com/FlowiseAI/Flowise/pull/5232">#5232</a> introduced CUSTOM_MCP_SECURITY_CHECK, a default-enabled validation layer for Custom MCP configurations.” While the checks reduced obvious command execution paths, they did little to change the underlying threat of allowing users to supply stdio MCP configurations, they said.</p>



<p>Obsidian’s reporting of the flaw triggered further hardening of the feature with flag validation in updates <a href="https://github.com/FlowiseAI/Flowise/pull/5741" target="_blank" rel="noreferrer noopener">#5741 </a>and <a href="https://github.com/FlowiseAI/Flowise/pull/5943" target="_blank" rel="noreferrer noopener">#5943</a>. These, too, did not entirely remove the threat.</p>



<p>When requested to treat stdio MCP as unsafe by default and require explicit opt-in, Flowise reportedly said they wanted to “limit what we know is bad without completely disabling features that users may rely on.” Obsidian shared a proof of concept (POC) exploit code on how the current protections by Flowise could still be bypassed for successful RCE.</p>



<p> The only complete mitigation recommended by the researchers is turning off MCP stdio by setting “CUSTOM_MCP_PROTOCOL=sse”. For those who can’t, without obstructing operations, pinning trusted packages where possible, and reviewing imported chatflows from untrusted sources might help, the researchers added.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Monthly Log: May 2026]]></title>
<description><![CDATA[In this month's edition of the Monthly Log:What’s Old Is New: My Return to Bear, by DevonNot All Writing Is the Same: Rethinking How I Create and Organize Documents with Obsidian, Notion, and Antinote, by John
	
						This Story is for Club Members

				Get weekly newsletters, exclusive stories, ...]]></description>
<link>https://tsecurity.de/de/3560970/ios-mac-os/monthly-log-may-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560970/ios-mac-os/monthly-log-may-2026/</guid>
<pubDate>Sun, 31 May 2026 16:53:59 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<nav class="ms-issue-toc"><p>In this month's edition of the Monthly Log:</p><ul><li><a href="https://www.macstories.net/club/monthly-log-may-2026/#whats-old-is-new-my-return-to-bear" class="ms-issue-toc-item">What’s Old Is New: My Return to Bear, by Devon</a></li><li><a href="https://www.macstories.net/club/monthly-log-may-2026/#not-all-writing-is-the-same-rethinking-how-i-create-and-organize-documents-with-obsidian-notion-and-antinote" class="ms-issue-toc-item">Not All Writing Is the Same: Rethinking How I Create and Organize Documents with Obsidian, Notion, and Antinote, by John</a></li></ul></nav>
	<div class="club-notice-restricted plan-">
						<h2>This Story is for Club Members</h2>

				<p>Get weekly newsletters, exclusive stories, member downloads, and ad-free version of MacStories Unwind.</p>
				<p><br><a href="https://www.macstories.net/plans?utm_source=ms&amp;utm_medium=web" class="button">See Plans</a></p>

									 

					<p>Already a member? <a href="https://www.macstories.net/?memberful_endpoint=auth">Sign in</a></p>
								</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Podcast Rewind: macOS 27 Wishes, Pictonico!, Lessons in Pranking, and Packing for WWDC]]></title>
<description><![CDATA[Enjoy the latest episodes from MacStories’ family of podcasts: AppStories This week, Federico explains how he’s using the recently-released Notion developer platform before he and John share their wishes for macOS 27. On AppStories+, John asks Federico about the technical underpinnings and evolut...]]></description>
<link>https://tsecurity.de/de/3557890/ios-mac-os/podcast-rewind-macos-27-wishes-pictonico-lessons-in-pranking-and-packing-for-wwdc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557890/ios-mac-os/podcast-rewind-macos-27-wishes-pictonico-lessons-in-pranking-and-packing-for-wwdc/</guid>
<pubDate>Sat, 30 May 2026 01:18:11 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Enjoy the latest episodes from MacStories’ family of podcasts: AppStories This week, Federico explains how he’s using the recently-released Notion developer platform before he and John share their wishes for macOS 27. On AppStories+, John asks Federico about the technical underpinnings and evolution of the Shortcuts Playground project that he published last week. NPC: Next […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.15.0 (2026.5.28) — The Velocity Release]]></title>
<description><![CDATA[Hermes Agent v0.15.0 (v2026.5.28)
Release Date: May 28, 2026
Since v0.14.0: 1,302 commits · 747 merged PRs · 1,746 files changed · 282,712 insertions · 36,699 deletions · 560+ issues closed (15 P0, 65 P1, 19 security-tagged) · 321 community contributors (including co-authors)

The Velocity Releas...]]></description>
<link>https://tsecurity.de/de/3555164/downloads/hermes-agent-v0150-2026528-the-velocity-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555164/downloads/hermes-agent-v0150-2026528-the-velocity-release/</guid>
<pubDate>Thu, 28 May 2026 20:01:31 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.15.0 (v2026.5.28)</h1>
<p><strong>Release Date:</strong> May 28, 2026<br>
<strong>Since v0.14.0:</strong> 1,302 commits · 747 merged PRs · 1,746 files changed · 282,712 insertions · 36,699 deletions · 560+ issues closed (15 P0, 65 P1, 19 security-tagged) · 321 community contributors (including co-authors)</p>
<blockquote>
<p><strong>The Velocity Release.</strong> Hermes gets dramatically faster — to start, to run, to ship work, and to grow. The 16,083-line <code>run_agent.py</code> collapses to 3,821 (-76%) across 14 cohesive <code>agent/*</code> modules. Kanban grew into a real multi-agent platform across 104 PRs — orchestrator auto-decomposition, swarm topology, scheduled tasks, worktree-per-task, per-task model overrides. The cold-start perf wave keeps going: another second shaved off launch, 47% fewer per-conversation function calls, <code>hermes --version</code> flipping the head-to-head benchmark against Codex CLI. <code>session_search</code> is 4,500× faster and free now. Promptware defense lands against Brainworm-class attacks. Bitwarden Secrets Manager replaces N per-provider API keys with one bootstrap token. Skill bundles let one slash command load a whole workflow. The Ink TUI gets a multi-session orchestrator. Two new image_gen providers (Krea 2 Medium + Large, FAL ported to plugin), the Nous-approved MCP catalog with an interactive picker, an OpenHands orchestration skill, ntfy as the 23rd messaging platform, and a deep xAI integration round (Web Search plugin, xai-oauth <code>hermes proxy</code> upstream, retired-May-15 model detection + <code>hermes migrate xai</code>, natural TTS speech-tag pauses, base_url leak guard, OpenAI-style execution guidance for Grok). 15 P0 + 65 P1 closures alongside.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>The Big Refactor — <code>run_agent.py</code> is no longer 16,000 lines</strong> — The file at the heart of Hermes — the agent conversation loop — has been reduced from 16,083 lines to 3,821 (-76%), with the extracted code redistributed across 14 cohesive modules under <code>agent/</code>. Behavior is unchanged: every extraction keeps a thin forwarder on <code>AIAgent</code>, every test patch path still works, every external caller is compatible. The reason you care: future Hermes development moves faster, plugin authors can finally grep the codebase, and the file that took 90 seconds to load in your editor opens in a blink. (<a href="https://github.com/NousResearch/hermes-agent/pull/27248" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27248/hovercard">#27248</a>)</p>
</li>
<li>
<p><strong>Kanban grew into a real multi-agent platform — 104 PRs end to end</strong> — Triage auto-decomposes one task into a tree of sub-tasks. <code>hermes kanban swarm</code> creates a full Swarm v1 graph in one command — root, parallel workers, gated verifier, gated synthesizer, shared blackboard. Tasks support per-task model overrides (cheap models for boilerplate, expensive ones for hard sub-tasks), board-level default workdirs, per-task worktree paths and branches, scheduled start times, configurable claim TTL, retry fingerprinting, stale-task detection, respawn guards, and a drag-to-delete trash zone. Workers report through <code>/workers/active</code>, <code>/runs/{id}</code>, and <code>/inspect</code> endpoints. (<a href="https://github.com/NousResearch/hermes-agent/pull/27572" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27572/hovercard">#27572</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28443" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28443/hovercard">#28443</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28364/hovercard">#28364</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28394" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28394/hovercard">#28394</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28462" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28462/hovercard">#28462</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28384" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28384/hovercard">#28384</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28467" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28467/hovercard">#28467</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28455/hovercard">#28455</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28452" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28452/hovercard">#28452</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28432" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28432/hovercard">#28432</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28468/hovercard">#28468</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28420" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28420/hovercard">#28420</a>)</p>
</li>
<li>
<p><strong>Cold-start perf wave keeps going — another second saved, 47% fewer per-turn function calls</strong> — Three new optimization rounds: defer <code>openai._base_client</code> import (-240ms / -17MB on every CLI invocation), hot-path optimizations cut 47% of per-conversation function calls (399k → 213k for 31-turn chat), defer compression-feasibility check (-170 to -290ms on every agent construction), adaptive subprocess polling (-195ms per tool call, 1+ second per turn). Termux cold start drops from 2.9s to 0.8s. <code>hermes --version</code> cold drops 63% (701ms → 258ms), flipping the head-to-head benchmark against Codex CLI from 5/11 wins to 6/11. (<a href="https://github.com/NousResearch/hermes-agent/pull/28864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28864/hovercard">#28864</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28866/hovercard">#28866</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28957/hovercard">#28957</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/29006" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29006/hovercard">#29006</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/29419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29419/hovercard">#29419</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30121" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30121/hovercard">#30121</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30609" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30609/hovercard">#30609</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/31968" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31968/hovercard">#31968</a>)</p>
</li>
<li>
<p><strong><code>session_search</code> rebuilt — no LLM, no cost, 4,500× faster</strong> — The old <code>session_search</code> was an aux-LLM-powered tool that cost ~$0.30/call and took ~30 seconds to summarize three sessions, sometimes confabulating when the right session wasn't even in the FTS5 hit list. The new shape is one tool with three modes (discovery, scroll, browse) inferred from which args are set — no <code>mode</code> parameter, no aux-LLM, no config knob, no companion skill. Discovery is ~20ms instead of ~90s; scroll is ~1ms. Searching your past sessions for context is now free and instant. (<a href="https://github.com/NousResearch/hermes-agent/pull/27590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27590/hovercard">#27590</a>)</p>
</li>
<li>
<p><strong>Promptware defense — Brainworm-class attacks blocked at three chokepoints</strong> — Inspired by recent Brainworm / Promptware Kill Chain research (Origin HQ, arxiv 2601.09625), Hermes now defends the context window against prompt-injection attacks that try to hijack the agent via tool output, recalled memory, or stored skills. Single source of truth (<code>tools/threat_patterns.py</code>) with ~15 new Brainworm/C2 patterns; recalled memory is scanned at load time; tool results get delimiter markers so a malicious file or remote service can't impersonate Hermes' own system content. Paired with a new <code>security-guidance</code> plugin that pattern-matches dangerous code writes. (<a href="https://github.com/NousResearch/hermes-agent/pull/32269" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32269/hovercard">#32269</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33131" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33131/hovercard">#33131</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/9151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/9151/hovercard">#9151</a>)</p>
</li>
<li>
<p><strong>Bitwarden Secrets Manager — one bootstrap token replaces every per-provider API key</strong> — Stop keeping plaintext API keys in <code>~/.hermes/.env</code>. Install Bitwarden Secrets Manager (<code>bws</code> auto-installs lazily on first use), point Hermes at it with one bootstrap token (<code>BWS_ACCESS_TOKEN</code>), and every credential you need comes from Bitwarden at startup. Rotate a key in the Bitwarden web app and the rotation actually takes effect — Bitwarden defaults to source-of-truth so its values overwrite matching env vars on startup. Flip <code>secrets.bitwarden.override_existing: false</code> to invert. EU Cloud and self-hosted Bitwarden server URLs supported. Detected credentials are now labeled with their source so you can see at a glance which keys came from Bitwarden vs. the local env. (<a href="https://github.com/NousResearch/hermes-agent/pull/30035" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30035/hovercard">#30035</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/31378" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31378/hovercard">#31378</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30364/hovercard">#30364</a>)</p>
</li>
<li>
<p><strong>ntfy as the 23rd messaging platform — push notifications without an account</strong> — ntfy is the self-hostable push-notification service with no signup, no API key, just a topic URL. Hermes now adapts to it as a platform plugin (zero edits to core), so your agent can send you push notifications from any cron job, kanban task completion, or chat <code>send_message</code> — to your phone, your watch, your desktop, your homelab. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/30625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30625/hovercard">#30625</a> → originally <a href="https://github.com/NousResearch/hermes-agent/pull/4043" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4043/hovercard">#4043</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30867/hovercard">#30867</a>)</p>
</li>
<li>
<p><strong>Skill bundles — <code>/&lt;name&gt;</code> loads multiple skills at once</strong> — A skill bundle is a named group of skills that loads them all together with one slash command. Set up your "writing day" bundle (humanizer + ideation + obsidian + youtube-content) and <code>/writing-day</code> activates all four for the session. Skills Hub now has health checks, a freshness badge, and a watchdog cron. Three new optional skills land: <code>code-wiki</code> (Karpathy's LLM-Wiki, persistent indexed dev wiki), <code>openhands</code> (delegate to OpenHands for parallel coding agents), and <code>web-pentest</code> (OWASP-style web pentest recipes). (<a href="https://github.com/NousResearch/hermes-agent/pull/28373" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28373/hovercard">#28373</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/32345" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32345/hovercard">#32345</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/32240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32240/hovercard">#32240</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/32261" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32261/hovercard">#32261</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/32265" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32265/hovercard">#32265</a>)</p>
</li>
<li>
<p><strong>TUI session orchestrator — multiple live sessions in one TUI window</strong> — The Ink TUI gained an active-session switcher overlay. List, switch between, refresh, and close multiple live process-local sessions without leaving the TUI; dispatch a new session with a session-scoped model picker. Plus a wave of TUI polish — mouse-tracking DEC mode presets, scrollback preservation across branches and termux, slash-dropdown fixes, x.com link rendering, and CJK / IME input rendering improvements. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/27642" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27642/hovercard">#27642</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32980" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32980/hovercard">#32980</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30084/hovercard">#30084</a>)</p>
</li>
<li>
<p><strong>Two new image_gen providers — Krea 2 Medium + Large, FAL ported to plugin</strong> — Krea joins the image_gen lineup as a built-in plugin: <code>Krea 2 Medium</code> ($0.03) and <code>Krea 2 Large</code> ($0.06), auto-discovered, selectable via <code>hermes tools</code> → Image Generation → Krea. Available through both the native Krea plugin and the FAL.ai catalog. The FAL.ai backend got pulled out of the monolithic image-generation tool into <code>plugins/image_gen/fal/</code>, completing the four-way architectural parity already established by web, browser, and video_gen — new image providers are now one file, not a fork. (<a href="https://github.com/NousResearch/hermes-agent/pull/33236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33236/hovercard">#33236</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30380" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30380/hovercard">#30380</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33506" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33506/hovercard">#33506</a>)</p>
</li>
<li>
<p><strong>Nous-approved MCP catalog with interactive picker</strong> — A curated catalog of Nous-vetted MCP servers, mirroring the optional-skills shape. Run <code>hermes mcp</code> and you get an interactive picker; install with one keystroke, credentials prompted at install time and written to <code>~/.hermes/.env</code>. Ships with the n8n manifest first. Closes the discovery gap that left users hunting GitHub for trusted MCP servers. (<a href="https://github.com/NousResearch/hermes-agent/pull/30870" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30870/hovercard">#30870</a>)</p>
</li>
<li>
<p><strong>OpenHands orchestration skill</strong> — A new optional skill under <code>optional-skills/autonomous-ai-agents/openhands/</code> lets the agent delegate coding tasks to the OpenHands CLI alongside <code>claude-code</code>, <code>codex</code>, and <code>opencode</code>. OpenHands is the model-agnostic member of that family — any LiteLLM-supported provider works (OpenAI, Anthropic, OpenRouter, your own), so you can route a sub-task to the cheapest model that can finish it. Drop-in worker for kanban swarms and <code>/delegate</code> flows. (closes <a href="https://github.com/NousResearch/hermes-agent/issues/477" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/477/hovercard">#477</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32261" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32261/hovercard">#32261</a>)</p>
</li>
<li>
<p><strong>Deep xAI integration round — Web Search plugin, OAuth proxy upstream, May 15 retirement detection, natural TTS, security hardening</strong> — Six interlocking xAI improvements:</p>
<ul>
<li><strong>xAI Web Search</strong> lands as a <code>plugins/web/xai/</code> provider, slots alongside Brave / Tavily / Exa / SearXNG / DDGS / Firecrawl — reuses your existing Grok OAuth or <code>XAI_API_KEY</code> credentials, no new env vars. (<a href="https://github.com/NousResearch/hermes-agent/pull/29042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29042/hovercard">#29042</a>)</li>
<li><strong><code>hermes proxy</code> gains an xAI upstream</strong> — your local OpenAI-compatible endpoint can now be backed by SuperGrok OAuth, no PKCE-refresh code to write in your client. (<a href="https://github.com/NousResearch/hermes-agent/pull/28356" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28356/hovercard">#28356</a>)</li>
<li><strong>May 15 model retirement detection</strong> — <code>grok-4</code>, <code>grok-4-fast{,-reasoning,-non-reasoning}</code>, <code>grok-3</code>, <code>grok-code-fast-1</code>, <code>grok-imagine-image-pro</code> etc. are detected in doctor and chat startup, with <code>hermes migrate xai</code> to one-shot config migration to the supported model. No more silent 404s after the retirement date. (<a href="https://github.com/NousResearch/hermes-agent/pull/29277" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29277/hovercard">#29277</a>)</li>
<li><strong>Opt-in <code>auto_speech_tags</code></strong> for xAI TTS — inserts light <code>[pause]</code> tags between paragraphs and sentences for more natural-sounding voice replies. Default OFF. (<a href="https://github.com/NousResearch/hermes-agent/pull/29376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29376/hovercard">#29376</a>)</li>
<li><strong><code>xai-oauth</code> <code>base_url</code> pinned to <code>x.ai</code> origin</strong> — closes a silent credential-leak vector where <code>XAI_BASE_URL</code> could repoint OAuth-authenticated inference to an attacker-controlled host. (<a href="https://github.com/NousResearch/hermes-agent/pull/28952" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28952/hovercard">#28952</a>)</li>
<li><strong>OpenAI-style execution guidance applied to Grok models</strong> — Grok and xai-oauth now get the same family-specific execution discipline block GPT/Codex have, so the model stops claiming completion without tool calls and stops suggesting workarounds instead of using existing tools. (<a href="https://github.com/NousResearch/hermes-agent/pull/27797" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27797/hovercard">#27797</a>)</li>
<li>Plus <code>x_search</code> degraded-results surfacing, tier-gated 403 with API-key fallback, PKCE <code>code_challenge</code> round-trip fix, dead-token quarantine on terminal refresh failure, MiniMax-style short-token refresh on per-request, and <code>WKE=unauthenticated</code> honor at both classifier sites. (<a href="https://github.com/NousResearch/hermes-agent/pull/29484" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29484/hovercard">#29484</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28351" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28351/hovercard">#28351</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/27560" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27560/hovercard">#27560</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28116" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28116/hovercard">#28116</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30619" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30619/hovercard">#30619</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30872" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30872/hovercard">#30872</a>)</li>
</ul>
</li>
</ul>
<hr>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>The Big Refactor — <code>run_agent.py</code> 16k → 3.8k</h3>
<ul>
<li><code>run_agent.py</code> from 16,083 → 3,821 lines (-76%), extracted into 14 cohesive <code>agent/*</code> modules. <code>run_conversation</code> alone was 3,877 lines before the refactor. Every extraction keeps a thin forwarder on <code>AIAgent</code>, every test-patch path is preserved, every external caller stays compatible. (<a href="https://github.com/NousResearch/hermes-agent/pull/27248" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27248/hovercard">#27248</a>)</li>
</ul>
<h3>Agent loop &amp; conversation</h3>
<ul>
<li>Auxiliary task layered fallback (primary → chain → main agent → graceful fail) on capacity errors (402/429/connection). (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/26811" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26811/hovercard">#26811</a> + <a href="https://github.com/NousResearch/hermes-agent/pull/26998" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26998/hovercard">#26998</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27625/hovercard">#27625</a>)</li>
<li>Buffer retry/fallback status; surface only on terminal failure (no more noisy "retrying..." spam in mid-run output). (<a href="https://github.com/NousResearch/hermes-agent/pull/33816" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33816/hovercard">#33816</a>)</li>
<li>Host contract for external context engines — condenses 5 prior PRs into one extension surface. (<a href="https://github.com/NousResearch/hermes-agent/pull/33750" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33750/hovercard">#33750</a>)</li>
<li>Fallback immediately on provider content-policy blocks. (<a href="https://github.com/NousResearch/hermes-agent/pull/33883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33883/hovercard">#33883</a>)</li>
<li>Re-pad <code>reasoning_content</code> on cross-provider fallback to require-side providers. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/33784" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33784/hovercard">#33784</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33795" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33795/hovercard">#33795</a>)</li>
<li>Per-turn tool-outcome verifier — patch tool gets indent preservation, CRLF preservation, per-file failure escalation. (<a href="https://github.com/NousResearch/hermes-agent/pull/32273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32273/hovercard">#32273</a>)</li>
<li>Single-knob native vision for custom-provider models. (<a href="https://github.com/NousResearch/hermes-agent/pull/29679" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29679/hovercard">#29679</a>)</li>
<li>Background review fork isolated from external memory plugins. (<a href="https://github.com/NousResearch/hermes-agent/pull/27190" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27190/hovercard">#27190</a>)</li>
<li>Background review inherits parent toolset config for <code>tools[]</code> cache parity. (<a href="https://github.com/NousResearch/hermes-agent/pull/29704" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29704/hovercard">#29704</a>)</li>
<li>Recover from providers returning list-type tool content. (<a href="https://github.com/NousResearch/hermes-agent/pull/30259" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30259/hovercard">#30259</a>)</li>
<li>Treat partial-stream stub responses as length truncation rather than clean stop. (<a href="https://github.com/NousResearch/hermes-agent/pull/30998" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30998/hovercard">#30998</a>)</li>
<li>OpenAI execution guidance applied to xAI Grok / xai-oauth. (<a href="https://github.com/NousResearch/hermes-agent/pull/27797" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27797/hovercard">#27797</a>)</li>
<li>ContextVars propagate to concurrent tool worker threads.</li>
<li>Preload <code>jiter</code> native parser. (<a href="https://github.com/NousResearch/hermes-agent/pull/33692" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33692/hovercard">#33692</a>)</li>
<li>Expose context engine tools with saved toolsets. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/31194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31194/hovercard">#31194</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33719" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33719/hovercard">#33719</a>)</li>
</ul>
<h3>Sessions &amp; memory</h3>
<ul>
<li><code>session_search</code> rebuilt — single-shape (discovery + scroll + browse), no aux-LLM, ~20ms vs. ~90s. (<a href="https://github.com/NousResearch/hermes-agent/pull/27590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27590/hovercard">#27590</a>)</li>
<li>Salvage <a href="https://github.com/NousResearch/hermes-agent/pull/29182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29182/hovercard">#29182</a> — opt-in JSON snapshot writer for sessions. (<a href="https://github.com/NousResearch/hermes-agent/pull/29278" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29278/hovercard">#29278</a>)</li>
<li>Persist <code>platform_message_id</code> for recall across gateway restarts. (<a href="https://github.com/NousResearch/hermes-agent/pull/29449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29449/hovercard">#29449</a>)</li>
<li>Inline memory-context mentions stay visible in conversation. (<a href="https://github.com/NousResearch/hermes-agent/pull/28132" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28132/hovercard">#28132</a>)</li>
<li>Recalled memory labeled informational, not authoritative. (<a href="https://github.com/NousResearch/hermes-agent/pull/28583" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28583/hovercard">#28583</a>)</li>
<li>Memory + context-engine tool injection gated on <code>enabled_toolsets</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/30177" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30177/hovercard">#30177</a>)</li>
<li>Guard against external drift in <code>MEMORY.md</code> / <code>USER.md</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/30877" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30877/hovercard">#30877</a>)</li>
<li>Honcho runtime peer mapping — correctness follow-ups + setup wizard + docs. (<a href="https://github.com/NousResearch/hermes-agent/pull/30077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30077/hovercard">#30077</a>)</li>
<li>Periodic memory logging for leak detection. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/17667" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17667/hovercard">#17667</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27102" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27102/hovercard">#27102</a>)</li>
</ul>
<h3>Codex / Responses-API maturation</h3>
<ul>
<li>TTFB watchdog for stalled Codex Responses streams. (<a href="https://github.com/NousResearch/hermes-agent/pull/32042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32042/hovercard">#32042</a>)</li>
<li>Actionable hint when stale-call detector fires on known silent-reject pattern. (<a href="https://github.com/NousResearch/hermes-agent/pull/32016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32016/hovercard">#32016</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33133" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33133/hovercard">#33133</a>)</li>
<li>Drop SDK <code>responses.stream()</code> helper; consume events directly. (<a href="https://github.com/NousResearch/hermes-agent/pull/33042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33042/hovercard">#33042</a>)</li>
<li>Gracefully recover from <code>invalid_encrypted_content</code>. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/10144" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/10144/hovercard">#10144</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33035" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33035/hovercard">#33035</a>)</li>
<li>Recover Codex Responses streams with null output. (<a href="https://github.com/NousResearch/hermes-agent/pull/32963" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32963/hovercard">#32963</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33390" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33390/hovercard">#33390</a>)</li>
<li>Drop foreign-issuer reasoning and transient <code>rs_tmp</code> reasoning replay state. (<a href="https://github.com/NousResearch/hermes-agent/pull/33156" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33156/hovercard">#33156</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33146" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33146/hovercard">#33146</a>)</li>
<li>Codex 429 quota classified as rate-limit, not missing credentials. (<a href="https://github.com/NousResearch/hermes-agent/pull/33168" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33168/hovercard">#33168</a>)</li>
<li>Codex chat path falls back to credential_pool when singleton is empty. (<a href="https://github.com/NousResearch/hermes-agent/pull/33189" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33189/hovercard">#33189</a>)</li>
<li>Codex re-auth syncs credential_pool. (<a href="https://github.com/NousResearch/hermes-agent/pull/33164" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33164/hovercard">#33164</a>)</li>
<li>Omit <code>tools</code> key when no tools registered. (<a href="https://github.com/NousResearch/hermes-agent/pull/33409" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33409/hovercard">#33409</a>)</li>
<li>Parse Codex image-generation SSE directly. (<a href="https://github.com/NousResearch/hermes-agent/pull/32933" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32933/hovercard">#32933</a>)</li>
</ul>
<hr>
<h2>🎛️ Kanban — Multi-Agent Maturation Wave</h2>
<h3>Orchestration &amp; dispatch</h3>
<ul>
<li>Orchestrator-driven auto-decomposition on triage. (<a href="https://github.com/NousResearch/hermes-agent/pull/27572" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27572/hovercard">#27572</a>)</li>
<li>Kanban swarm topology helper — <code>hermes kanban swarm</code> creates a Swarm v1 graph (root + parallel workers + gated verifier + gated synthesizer + shared blackboard). (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/26791" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26791/hovercard">#26791</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Niraven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Niraven">@Niraven</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28443" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28443/hovercard">#28443</a>)</li>
<li>Dispatcher wires review agents from the review column. (<a href="https://github.com/NousResearch/hermes-agent/pull/28449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28449/hovercard">#28449</a>)</li>
<li>Stale-detection for running tasks in dispatcher. (<a href="https://github.com/NousResearch/hermes-agent/pull/28452" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28452/hovercard">#28452</a>)</li>
<li>Respawn guard blocks repeat worker storms. (<a href="https://github.com/NousResearch/hermes-agent/pull/28455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28455/hovercard">#28455</a>)</li>
<li>Respawn guard defers <code>blocker_auth</code> instead of auto-blocking. (<a href="https://github.com/NousResearch/hermes-agent/pull/28683" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28683/hovercard">#28683</a>)</li>
<li>Cross-profile cron jobs surface in dashboard. (<a href="https://github.com/NousResearch/hermes-agent/pull/28457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28457/hovercard">#28457</a>)</li>
<li>Worker visibility endpoints: <code>/workers/active</code>, <code>/runs/{id}</code>, <code>/inspect</code>. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/23761" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23761/hovercard">#23761</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Interstellar-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Interstellar-code">@Interstellar-code</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28432" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28432/hovercard">#28432</a>)</li>
</ul>
<h3>Task configuration &amp; scheduling</h3>
<ul>
<li>Per-task model override. (<a href="https://github.com/NousResearch/hermes-agent/pull/28364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28364/hovercard">#28364</a>)</li>
<li>Board-level default workdir. (<a href="https://github.com/NousResearch/hermes-agent/pull/28394" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28394/hovercard">#28394</a>)</li>
<li>Configurable worktree paths and branches. (<a href="https://github.com/NousResearch/hermes-agent/pull/28462" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28462/hovercard">#28462</a>)</li>
<li>Scheduled task start times. (<a href="https://github.com/NousResearch/hermes-agent/pull/28384" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28384/hovercard">#28384</a>)</li>
<li>Scheduled status for delayed follow-ups. (<a href="https://github.com/NousResearch/hermes-agent/pull/28467" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28467/hovercard">#28467</a>)</li>
<li>Trimmed task comments. (<a href="https://github.com/NousResearch/hermes-agent/pull/28399" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28399/hovercard">#28399</a>)</li>
<li>Initial-status for human-ops cards. (<a href="https://github.com/NousResearch/hermes-agent/pull/28414" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28414/hovercard">#28414</a>)</li>
<li><code>max_in_progress</code> config to cap concurrent running tasks. (<a href="https://github.com/NousResearch/hermes-agent/pull/28420" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28420/hovercard">#28420</a>)</li>
<li>Filter tasks by workflow fields. (<a href="https://github.com/NousResearch/hermes-agent/pull/28454" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28454/hovercard">#28454</a>)</li>
<li><code>--sort</code> for <code>hermes kanban list</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28427" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28427/hovercard">#28427</a>)</li>
<li>Optional <code>board</code> parameter on all MCP tools. (<a href="https://github.com/NousResearch/hermes-agent/pull/28444" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28444/hovercard">#28444</a>)</li>
<li>Stamp originating ACP session_id on tasks. (<a href="https://github.com/NousResearch/hermes-agent/pull/28447" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28447/hovercard">#28447</a>)</li>
<li><code>auto_promote_children</code> config toggle. (<a href="https://github.com/NousResearch/hermes-agent/pull/28344" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28344/hovercard">#28344</a>)</li>
<li><code>archive --rm</code> to hard-delete archived tasks. (<a href="https://github.com/NousResearch/hermes-agent/pull/28355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28355/hovercard">#28355</a>)</li>
<li>Promote dependents when parent is archived. (<a href="https://github.com/NousResearch/hermes-agent/pull/28372" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28372/hovercard">#28372</a>)</li>
<li>Promote blocked tasks when parent dependencies complete. (<a href="https://github.com/NousResearch/hermes-agent/pull/28377" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28377/hovercard">#28377</a>)</li>
<li>Demote ready children when parent is reopened. (<a href="https://github.com/NousResearch/hermes-agent/pull/28382" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28382/hovercard">#28382</a>)</li>
<li><code>promote</code> verb for manual <code>todo→ready</code> recovery + bulk <code>--ids</code>. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/29464" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29464/hovercard">#29464</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31334" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31334/hovercard">#31334</a>)</li>
</ul>
<h3>Dashboard</h3>
<ul>
<li>Drag-to-delete trash zone + bulk delete. (<a href="https://github.com/NousResearch/hermes-agent/pull/28468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28468/hovercard">#28468</a>)</li>
<li>Surface per-task <code>model_override</code> in show + tool output. (<a href="https://github.com/NousResearch/hermes-agent/pull/28442" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28442/hovercard">#28442</a>)</li>
<li>Cross-profile notification delivery via <code>kanban.notification_sources</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28395/hovercard">#28395</a>)</li>
<li>Scratch-workspace deletion warning for users. (<a href="https://github.com/NousResearch/hermes-agent/pull/30949" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30949/hovercard">#30949</a>)</li>
<li>Mobile dashboard UX polish. (<a href="https://github.com/NousResearch/hermes-agent/pull/28127" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28127/hovercard">#28127</a>)</li>
</ul>
<h3>Reliability</h3>
<ul>
<li>Worker log retention configurable. (<a href="https://github.com/NousResearch/hermes-agent/pull/27867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27867/hovercard">#27867</a>)</li>
<li>Configurable claim TTL. (<a href="https://github.com/NousResearch/hermes-agent/pull/28392" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28392/hovercard">#28392</a>)</li>
<li>Fingerprint crash errors to prevent fleet-wide retry exhaustion. (<a href="https://github.com/NousResearch/hermes-agent/pull/28380" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28380/hovercard">#28380</a>)</li>
<li>Reset failure counters on <code>unblock_task</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28379" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28379/hovercard">#28379</a>)</li>
<li>Detect cycles in <code>decompose_triage_task</code> sibling-link pre-validation. (<a href="https://github.com/NousResearch/hermes-agent/pull/28088" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28088/hovercard">#28088</a>)</li>
<li>Surface unusable triage auxiliary model (auto-decompose aware). (<a href="https://github.com/NousResearch/hermes-agent/pull/27871" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27871/hovercard">#27871</a>)</li>
<li>Align failure diagnostics with retry limit. (<a href="https://github.com/NousResearch/hermes-agent/pull/27868" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27868/hovercard">#27868</a>)</li>
<li>Align worker terminal timeout with task runtime. (<a href="https://github.com/NousResearch/hermes-agent/pull/27864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27864/hovercard">#27864</a>)</li>
<li>Auto-install bundled skills (kanban-worker) on init. (<a href="https://github.com/NousResearch/hermes-agent/pull/28368" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28368/hovercard">#28368</a>)</li>
<li>Make legacy task migration idempotent. (<a href="https://github.com/NousResearch/hermes-agent/pull/28397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28397/hovercard">#28397</a>)</li>
<li>Serialize DB initialization. (<a href="https://github.com/NousResearch/hermes-agent/pull/28383" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28383/hovercard">#28383</a>)</li>
<li>Persist worker session metadata on completion. (<a href="https://github.com/NousResearch/hermes-agent/pull/28387" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28387/hovercard">#28387</a>)</li>
<li>Pass <code>accept-hooks</code> to worker chat subprocess. (<a href="https://github.com/NousResearch/hermes-agent/pull/28393" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28393/hovercard">#28393</a>)</li>
<li>Preserve worker tools with restricted toolsets. (<a href="https://github.com/NousResearch/hermes-agent/pull/28396" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28396/hovercard">#28396</a>)</li>
<li>Avoid unsafe Windows worker Hermes shim resolution. (<a href="https://github.com/NousResearch/hermes-agent/pull/28398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28398/hovercard">#28398</a>)</li>
<li>Sync slash subcommands with live parser. (<a href="https://github.com/NousResearch/hermes-agent/pull/28376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28376/hovercard">#28376</a>)</li>
<li>Show scheduled kanban tasks in dashboard. (<a href="https://github.com/NousResearch/hermes-agent/pull/28400" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28400/hovercard">#28400</a>)</li>
<li>Assign single-task kanban decompositions. (<a href="https://github.com/NousResearch/hermes-agent/pull/28401" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28401/hovercard">#28401</a>)</li>
<li>Configurable <code>max_tokens</code> for kanban specify. (<a href="https://github.com/NousResearch/hermes-agent/pull/28374" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28374/hovercard">#28374</a>)</li>
<li>Per-job profile support for cron. (<a href="https://github.com/NousResearch/hermes-agent/pull/28124" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28124/hovercard">#28124</a>)</li>
<li>Codex app-server: include every Kanban-pinned path in <code>writable_roots</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28435/hovercard">#28435</a>)</li>
<li>Cache kanban worker guidance at session init for prompt-cache reuse. (<a href="https://github.com/NousResearch/hermes-agent/pull/28425" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28425/hovercard">#28425</a>)</li>
</ul>
<hr>
<h2>⚡ Performance</h2>
<ul>
<li><code>openai._base_client</code> import deferred — 240ms / 17MB off every CLI cold start. (<a href="https://github.com/NousResearch/hermes-agent/pull/28864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28864/hovercard">#28864</a>)</li>
<li>Agent-loop hot-path optimizations — 47% fewer per-conversation function calls (399k → 213k for 31-turn chat). (<a href="https://github.com/NousResearch/hermes-agent/pull/28866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28866/hovercard">#28866</a>)</li>
<li>Compression-feasibility check deferred — 170-290ms off every agent construction. (<a href="https://github.com/NousResearch/hermes-agent/pull/28957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28957/hovercard">#28957</a>)</li>
<li>Adaptive subprocess poll — ~195ms off every tool call, 1+ second per turn. (<a href="https://github.com/NousResearch/hermes-agent/pull/29006" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29006/hovercard">#29006</a>)</li>
<li>Termux TUI cold start speedup. (<a href="https://github.com/NousResearch/hermes-agent/pull/29419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29419/hovercard">#29419</a>)</li>
<li>Termux non-TUI cold start speedup. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/29438" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29438/hovercard">#29438</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30121" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30121/hovercard">#30121</a>)</li>
<li>Termux fast-path version + deferred bare-prompt agent startup. (<a href="https://github.com/NousResearch/hermes-agent/pull/30609" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30609/hovercard">#30609</a>)</li>
<li>Cut hermes <code>--version</code> wall time 63% — flips head-to-head vs Codex CLI. (<a href="https://github.com/NousResearch/hermes-agent/pull/31968" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31968/hovercard">#31968</a>)</li>
<li>Date-only timestamp + loud gateway-DB roundtrip logging — improves prompt-cache hit rate. (<a href="https://github.com/NousResearch/hermes-agent/pull/27675" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27675/hovercard">#27675</a>)</li>
<li>Cache kanban worker guidance at session init for prompt-cache reuse. (<a href="https://github.com/NousResearch/hermes-agent/pull/28425" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28425/hovercard">#28425</a>)</li>
</ul>
<hr>
<h2>🔧 Tool System</h2>
<h3>Tool surface</h3>
<ul>
<li><code>patch</code>: indent preservation, CRLF preservation, per-file failure escalation. (<a href="https://github.com/NousResearch/hermes-agent/pull/32273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32273/hovercard">#32273</a>)</li>
<li><code>terminal</code>: warn at call time when <code>background=true</code> runs silently. (<a href="https://github.com/NousResearch/hermes-agent/pull/31289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31289/hovercard">#31289</a>)</li>
<li><code>terminal</code>: nudge homebrewed CI pollers at the tool surface. (<a href="https://github.com/NousResearch/hermes-agent/pull/33142" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33142/hovercard">#33142</a>)</li>
<li><code>x_search</code>: surface degraded results + validate dates. (<a href="https://github.com/NousResearch/hermes-agent/pull/29484" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29484/hovercard">#29484</a>)</li>
<li><code>x_search</code>: auto-enable toolset when xAI credentials are configured. (<a href="https://github.com/NousResearch/hermes-agent/pull/27376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27376/hovercard">#27376</a>)</li>
<li><code>computer_use</code>: route SOM/vision captures via auxiliary.vision. (<a href="https://github.com/NousResearch/hermes-agent/pull/30126" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30126/hovercard">#30126</a>)</li>
<li><code>transcription</code>: reject symlinked audio inputs. (<a href="https://github.com/NousResearch/hermes-agent/pull/10082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/10082/hovercard">#10082</a>)</li>
<li>TTS: prevent double <code>[pause]</code> in xAI auto speech tags. (<a href="https://github.com/NousResearch/hermes-agent/pull/32237" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32237/hovercard">#32237</a>)</li>
<li>TTS: preserve native audio outside Telegram voice delivery. (<a href="https://github.com/NousResearch/hermes-agent/pull/28512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28512/hovercard">#28512</a>)</li>
<li>TTS: opt-in xAI <code>auto_speech_tags</code> speech-tag pauses for natural voice replies. (<a href="https://github.com/NousResearch/hermes-agent/pull/29376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29376/hovercard">#29376</a>)</li>
<li>Voice: chunk oversized CLI recordings. (<a href="https://github.com/NousResearch/hermes-agent/pull/30044" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30044/hovercard">#30044</a>)</li>
<li>Voice: honor <code>PULSE_SERVER</code> / <code>PIPEWIRE_REMOTE</code> inside Docker. (<a href="https://github.com/NousResearch/hermes-agent/pull/22534" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22534/hovercard">#22534</a>)</li>
</ul>
<h3>Browser</h3>
<ul>
<li>All cloud browser providers (Browserbase, Anchor, Camofox, Hyperbrowser, etc.) migrated to image_gen-style plugins. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/25580" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25580/hovercard">#25580</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27403" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27403/hovercard">#27403</a>)</li>
<li>Auto-launch Chromium-family browser for CDP. (<a href="https://github.com/NousResearch/hermes-agent/pull/29106" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29106/hovercard">#29106</a>)</li>
<li>Docker: discover agent-browser Chromium binary at boot. (<a href="https://github.com/NousResearch/hermes-agent/pull/33184" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33184/hovercard">#33184</a>)</li>
</ul>
<h3>Image generation</h3>
<ul>
<li><strong>Krea</strong> provider plugin (Krea 2 Medium + Large). (<a href="https://github.com/NousResearch/hermes-agent/pull/33236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33236/hovercard">#33236</a>)</li>
<li>FAL backend ported to <code>plugins/image_gen/fal</code>. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/27966" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27966/hovercard">#27966</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30380" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30380/hovercard">#30380</a>)</li>
<li>Cache xAI ephemeral URL responses to disk. (<a href="https://github.com/NousResearch/hermes-agent/pull/31759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31759/hovercard">#31759</a>)</li>
</ul>
<h3>Web search</h3>
<ul>
<li><strong>xAI Web Search</strong> as a provider plugin. (<a href="https://github.com/NousResearch/hermes-agent/pull/29042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29042/hovercard">#29042</a>)</li>
</ul>
<h3>MCP</h3>
<ul>
<li><strong>Nous-approved MCP catalog</strong> with interactive picker. (<a href="https://github.com/NousResearch/hermes-agent/pull/30870" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30870/hovercard">#30870</a>)</li>
<li><strong>TLS client certificate (mTLS) support</strong> for HTTP and SSE MCP servers. (<a href="https://github.com/NousResearch/hermes-agent/pull/33721" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33721/hovercard">#33721</a>)</li>
<li>Stdin paste-back fallback for headless OAuth flow. (<a href="https://github.com/NousResearch/hermes-agent/pull/32053" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32053/hovercard">#32053</a>)</li>
<li><code>skip</code> at paste prompt bypasses auth without disabling server. (<a href="https://github.com/NousResearch/hermes-agent/pull/32069" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32069/hovercard">#32069</a>)</li>
<li>Registry-aware <code>mcp_</code> prefix on both ends of round-trip. (<a href="https://github.com/NousResearch/hermes-agent/pull/31700" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31700/hovercard">#31700</a>)</li>
</ul>
<hr>
<h2>🧩 Skills Ecosystem</h2>
<h3>Skills system</h3>
<ul>
<li><strong>Skill bundles</strong> — <code>/&lt;name&gt;</code> loads multiple skills. (<a href="https://github.com/NousResearch/hermes-agent/pull/28373" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28373/hovercard">#28373</a>)</li>
<li>Skills Hub: health checks, freshness badge, and a watchdog cron. (<a href="https://github.com/NousResearch/hermes-agent/pull/32345" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32345/hovercard">#32345</a>)</li>
<li>Opt-in AST deep diagnostics on skill writes. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/30918" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30918/hovercard">#30918</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31198" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31198/hovercard">#31198</a>)</li>
<li>Bundled/pinned skill protection in background-review prompts. (<a href="https://github.com/NousResearch/hermes-agent/pull/28338" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28338/hovercard">#28338</a>)</li>
<li>Show user-modified skill names in bundled skill sync summary. (<a href="https://github.com/NousResearch/hermes-agent/pull/28671" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28671/hovercard">#28671</a>)</li>
<li>Load symlinked skill slash commands. (<a href="https://github.com/NousResearch/hermes-agent/pull/27759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27759/hovercard">#27759</a>)</li>
<li>Deduplicate Skills Hub search results by identifier, not name. (<a href="https://github.com/NousResearch/hermes-agent/pull/29490" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29490/hovercard">#29490</a>)</li>
</ul>
<h3>New skills</h3>
<ul>
<li><code>openhands</code> — delegate-to-OpenHands orchestration skill (closes <a href="https://github.com/NousResearch/hermes-agent/issues/477" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/477/hovercard">#477</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32261" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32261/hovercard">#32261</a>)</li>
<li><code>code-wiki</code> — persistent indexed dev wiki (closes <a href="https://github.com/NousResearch/hermes-agent/issues/486" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/486/hovercard">#486</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32240/hovercard">#32240</a>)</li>
<li><code>web-pentest</code> — OWASP recipes (closes <a href="https://github.com/NousResearch/hermes-agent/issues/400" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/400/hovercard">#400</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32265" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32265/hovercard">#32265</a>)</li>
<li><code>baoyu-article-illustrator</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/28287" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28287/hovercard">#28287</a>)</li>
</ul>
<hr>
<h2>☁️ Providers</h2>
<h3>xAI deep integration</h3>
<ul>
<li><strong>xAI Web Search</strong> as a <code>plugins/web/xai/</code> provider plugin. (<a href="https://github.com/NousResearch/hermes-agent/pull/29042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29042/hovercard">#29042</a>)</li>
<li><strong><code>hermes proxy</code> xAI upstream</strong> — OpenAI-compatible local proxy backed by xai-oauth. (<a href="https://github.com/NousResearch/hermes-agent/pull/28356" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28356/hovercard">#28356</a>)</li>
<li><strong>May 15 model retirement detection + <code>hermes migrate xai</code></strong> for grok-4 / grok-3 / grok-code-fast-1 / grok-imagine-image-pro. (<a href="https://github.com/NousResearch/hermes-agent/pull/29277" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29277/hovercard">#29277</a>)</li>
<li><strong>Opt-in <code>auto_speech_tags</code></strong> for natural xAI TTS voice replies. (<a href="https://github.com/NousResearch/hermes-agent/pull/29376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29376/hovercard">#29376</a>)</li>
<li><strong>xai-oauth base_url pinned to x.ai origin</strong> — closes silent credential-leak vector. (<a href="https://github.com/NousResearch/hermes-agent/pull/28952" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28952/hovercard">#28952</a>)</li>
<li><strong>OpenAI-style execution guidance</strong> applied to Grok / xai-oauth models. (<a href="https://github.com/NousResearch/hermes-agent/pull/27797" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27797/hovercard">#27797</a>)</li>
<li>xAI: detect retired May 15 models in doctor/chat startup. (<a href="https://github.com/NousResearch/hermes-agent/pull/29277" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29277/hovercard">#29277</a>)</li>
<li>xAI: resolve Grok Build context for OAuth. (<a href="https://github.com/NousResearch/hermes-agent/pull/30579" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30579/hovercard">#30579</a>)</li>
<li>xAI OAuth: tier-gated 403 with API-key fallback. (<a href="https://github.com/NousResearch/hermes-agent/pull/28351" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28351/hovercard">#28351</a>)</li>
<li>xAI OAuth: PKCE <code>code_challenge</code> echo. (<a href="https://github.com/NousResearch/hermes-agent/pull/27560" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27560/hovercard">#27560</a>)</li>
<li>xAI OAuth: quarantine dead tokens on terminal refresh failure. (<a href="https://github.com/NousResearch/hermes-agent/pull/28116" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28116/hovercard">#28116</a>)</li>
<li>xAI OAuth: honor <code>WKE=unauthenticated</code> disambiguator at both classifier sites. (<a href="https://github.com/NousResearch/hermes-agent/pull/30872" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30872/hovercard">#30872</a>)</li>
<li>xAI OAuth: accept bare-code manual paste (state=None). (closes <a href="https://github.com/NousResearch/hermes-agent/issues/26923" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/26923/hovercard">#26923</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33880" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33880/hovercard">#33880</a>)</li>
<li>xAI OAuth: fall back to manual paste on loopback timeout. (<a href="https://github.com/NousResearch/hermes-agent/pull/33231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33231/hovercard">#33231</a>)</li>
<li>xAI proxy: handle 429 rate-limit responses in proxy retry path. (<a href="https://github.com/NousResearch/hermes-agent/pull/33743" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33743/hovercard">#33743</a>)</li>
</ul>
<h3>Other providers</h3>
<ul>
<li><strong>OpenAI API as a first-class provider</strong> (distinct from Codex runtime). (<a href="https://github.com/NousResearch/hermes-agent/pull/31898" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31898/hovercard">#31898</a>)</li>
<li><strong>Microsoft Entra ID</strong> auth for Azure Foundry (with 1M Anthropic-Messages beta preserved on Bearer). (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/27509" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27509/hovercard">#27509</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/27022" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27022/hovercard">#27022</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28101" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28101/hovercard">#28101</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28084/hovercard">#28084</a>)</li>
<li><strong>OpenRouter</strong> sticky routing — <code>session_id</code> passed via <code>extra_body</code> so a long-running session keeps landing on the same upstream provider. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cybourgeoisie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cybourgeoisie">@Cybourgeoisie</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33939" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33939/hovercard">#33939</a>)</li>
<li>Nous: JWT token for inference; stop replaying invalid Nous refresh tokens. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27663" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27663/hovercard">#27663</a>)</li>
<li>Nous Portal: one-shot setup, status CLI, and Nous-included markers. (<a href="https://github.com/NousResearch/hermes-agent/pull/30860" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30860/hovercard">#30860</a>)</li>
<li>Anthropic adapter: extract 7 helpers from <code>convert_messages_to_anthropic</code>. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/27784" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27784/hovercard">#27784</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30386" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30386/hovercard">#30386</a>)</li>
<li>Catalog: add <code>qwen3.7-max</code> to Alibaba + Alibaba-Coding-Plan model lists. (<a href="https://github.com/NousResearch/hermes-agent/pull/33129" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33129/hovercard">#33129</a>)</li>
<li>opencode-go: route <code>qwen3.7-max</code> via <code>anthropic_messages</code>. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beardthelion/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beardthelion">@beardthelion</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32780" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32780/hovercard">#32780</a>)</li>
<li>opencode-go: expose Kimi K2 + DeepSeek reasoning controls. (<a href="https://github.com/NousResearch/hermes-agent/pull/30845" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30845/hovercard">#30845</a>)</li>
<li>Remove Vercel AI Gateway and Vercel Sandbox.</li>
<li>MiniMax OAuth: refresh short-lived access tokens per request. (<a href="https://github.com/NousResearch/hermes-agent/pull/30619" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30619/hovercard">#30619</a>)</li>
<li>Codex OAuth: quarantine terminal refresh errors. (<a href="https://github.com/NousResearch/hermes-agent/pull/28118" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28118/hovercard">#28118</a>)</li>
<li>Codex: drop dead model slugs that HTTP 400 on ChatGPT Pro. (<a href="https://github.com/NousResearch/hermes-agent/pull/33424" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33424/hovercard">#33424</a>)</li>
<li>Codex: sync <code>manual:device_code</code> pool entries on re-auth. (<a href="https://github.com/NousResearch/hermes-agent/pull/33744" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33744/hovercard">#33744</a>)</li>
<li>MiniMax OAuth: quarantine terminal refresh errors. (<a href="https://github.com/NousResearch/hermes-agent/pull/28119" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28119/hovercard">#28119</a>)</li>
</ul>
<hr>
<h2>🔑 Secrets</h2>
<ul>
<li><strong>Bitwarden Secrets Manager</strong> integration with lazy <code>bws</code> install. (<a href="https://github.com/NousResearch/hermes-agent/pull/30035" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30035/hovercard">#30035</a>)</li>
<li>Bitwarden: EU Cloud + self-hosted server URL support. (<a href="https://github.com/NousResearch/hermes-agent/pull/31378" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31378/hovercard">#31378</a>)</li>
<li>Label detected credentials with their source (Bitwarden). (<a href="https://github.com/NousResearch/hermes-agent/pull/30364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30364/hovercard">#30364</a>)</li>
</ul>
<hr>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>Gateway core</h3>
<ul>
<li><strong>Deliverable mode</strong> — agents ship artifacts as native uploads from any platform (Slack/Discord/Telegram/Teams/Email). (<a href="https://github.com/NousResearch/hermes-agent/pull/27813" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27813/hovercard">#27813</a>)</li>
<li><code>hermes send</code> — pipe any script's output to any messaging platform. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/19631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19631/hovercard">#19631</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27188/hovercard">#27188</a>)</li>
<li>Debounce queued text follow-ups during active sessions. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/31235" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31235/hovercard">#31235</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31341" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31341/hovercard">#31341</a>)</li>
<li>Plugin-transformed final_response delivered through streaming gate. (<a href="https://github.com/NousResearch/hermes-agent/pull/31433" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31433/hovercard">#31433</a>)</li>
<li>Refresh cached agent tools on <code>/reload-mcp</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/32815" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32815/hovercard">#32815</a>)</li>
<li>Harden kanban + provider cleanup races on long-running workloads. (<a href="https://github.com/NousResearch/hermes-agent/pull/29479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29479/hovercard">#29479</a>)</li>
</ul>
<h3>New / reorganized adapters</h3>
<ul>
<li><strong>ntfy</strong> — 23rd platform, push notifications, plugin shape, zero core edits. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/30625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30625/hovercard">#30625</a> → <a href="https://github.com/NousResearch/hermes-agent/pull/4043" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4043/hovercard">#4043</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30867/hovercard">#30867</a>)</li>
<li><strong>Discord</strong> adapter migrated to bundled plugin. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/24356" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24356/hovercard">#24356</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30591/hovercard">#30591</a>)</li>
<li><strong>Mattermost</strong> adapter migrated to bundled plugin. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/30916" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30916/hovercard">#30916</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31748" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31748/hovercard">#31748</a>)</li>
</ul>
<h3>Telegram</h3>
<ul>
<li>Edit status messages in place instead of appending. (based on <a href="https://github.com/NousResearch/hermes-agent/pull/30141" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30141/hovercard">#30141</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qike-ms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qike-ms">@qike-ms</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30864/hovercard">#30864</a>)</li>
<li>Skip-STT audio path + 2GB cap via local Bot API server. (<a href="https://github.com/NousResearch/hermes-agent/pull/28541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28541/hovercard">#28541</a>)</li>
<li>Route image documents (.png/.jpg/.webp/.gif) through vision pipeline. (<a href="https://github.com/NousResearch/hermes-agent/pull/28519" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28519/hovercard">#28519</a>)</li>
<li>Route audio file attachments away from STT pipeline. (<a href="https://github.com/NousResearch/hermes-agent/pull/28478" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28478/hovercard">#28478</a>)</li>
<li><code>disable_topic_auto_rename</code> gateway flag. (<a href="https://github.com/NousResearch/hermes-agent/pull/28523" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28523/hovercard">#28523</a>)</li>
<li><code>ignore_root_dm</code> config to drop messages without thread_id. (<a href="https://github.com/NousResearch/hermes-agent/pull/28536" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28536/hovercard">#28536</a>)</li>
<li>Chat-scoped auth without sender user_id. (<a href="https://github.com/NousResearch/hermes-agent/pull/28525" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28525/hovercard">#28525</a>)</li>
<li>Fail-closed auth fallback when <code>TELEGRAM_ALLOWED_USERS</code> is empty. (<a href="https://github.com/NousResearch/hermes-agent/pull/28494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28494/hovercard">#28494</a>)</li>
<li>Roll over tool progress bubbles + scope audio_file_paths. (<a href="https://github.com/NousResearch/hermes-agent/pull/28482" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28482/hovercard">#28482</a>)</li>
<li>Avoid duplicate text after auto-TTS voice replies. (<a href="https://github.com/NousResearch/hermes-agent/pull/28509" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28509/hovercard">#28509</a>)</li>
<li>Mark final voice reply notify-worthy so Telegram delivers it audibly. (<a href="https://github.com/NousResearch/hermes-agent/pull/28504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28504/hovercard">#28504</a>)</li>
</ul>
<h3>Discord</h3>
<ul>
<li>Recover Windows voice opus decoding. (<a href="https://github.com/NousResearch/hermes-agent/pull/33182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33182/hovercard">#33182</a>)</li>
<li><code>allow_any_attachment</code> config to accept arbitrary file types. (<a href="https://github.com/NousResearch/hermes-agent/pull/27245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27245/hovercard">#27245</a>)</li>
<li>Transcribe native voice notes. (<a href="https://github.com/NousResearch/hermes-agent/pull/28993" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28993/hovercard">#28993</a>)</li>
<li>Define UI view classes after lazy install. (<a href="https://github.com/NousResearch/hermes-agent/pull/28817" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28817/hovercard">#28817</a>)</li>
</ul>
<h3>Signal / Matrix / Feishu / Slack / WeCom</h3>
<ul>
<li>Signal: <code>require_mention</code> filter for group chats. (<a href="https://github.com/NousResearch/hermes-agent/pull/28574" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28574/hovercard">#28574</a>)</li>
<li>Matrix: warn on clock-skew silent message drops. (<a href="https://github.com/NousResearch/hermes-agent/pull/27330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27330/hovercard">#27330</a>)</li>
<li>Matrix E2EE installs full dep set; plugins respect <code>is_connected</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/31688" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31688/hovercard">#31688</a>)</li>
<li>Feishu: require webhook auth secret + honor config extras. (<a href="https://github.com/NousResearch/hermes-agent/pull/30746" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30746/hovercard">#30746</a>)</li>
<li>Feishu: enforce auth and chat binding for approval buttons. (<a href="https://github.com/NousResearch/hermes-agent/pull/30744" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30744/hovercard">#30744</a>)</li>
<li>Slack: socket recovery + Windows restart dedupe. (<a href="https://github.com/NousResearch/hermes-agent/pull/28873" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28873/hovercard">#28873</a>)</li>
<li>WeCom: safe-parse untrusted XML. (<a href="https://github.com/NousResearch/hermes-agent/pull/32442" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32442/hovercard">#32442</a>)</li>
</ul>
<h3>DingTalk / Webhooks / Microsoft Graph</h3>
<ul>
<li>DingTalk: transcribe native voice notes. (<a href="https://github.com/NousResearch/hermes-agent/pull/28993" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28993/hovercard">#28993</a>)</li>
<li>Webhook: enforce <code>INSECURE_NO_AUTH</code> safety rail on dynamic route reloads. (<a href="https://github.com/NousResearch/hermes-agent/pull/30863" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30863/hovercard">#30863</a>)</li>
<li>Webhook: restrict default toolset capabilities. (<a href="https://github.com/NousResearch/hermes-agent/pull/30745" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30745/hovercard">#30745</a>)</li>
<li>Microsoft Graph: harden webhook auth requirements. (<a href="https://github.com/NousResearch/hermes-agent/pull/30169" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30169/hovercard">#30169</a>)</li>
</ul>
<hr>
<h2>🖥️ CLI &amp; TUI</h2>
<h3>CLI</h3>
<ul>
<li><code>/update</code> slash command in CLI and TUI. (<a href="https://github.com/NousResearch/hermes-agent/pull/23854" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23854/hovercard">#23854</a>)</li>
<li>Update auto-rollback when post-pull syntax check fails. (<a href="https://github.com/NousResearch/hermes-agent/pull/28669" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28669/hovercard">#28669</a>)</li>
<li><code>--branch</code> flag for <code>hermes update</code>. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/29591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29591/hovercard">#29591</a>)</li>
<li><code>/exit --delete</code> flag to remove session on quit. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/17665" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17665/hovercard">#17665</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27101" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27101/hovercard">#27101</a>)</li>
<li><code>▶ N</code> indicator in status bar for running <code>/background</code> tasks. (<a href="https://github.com/NousResearch/hermes-agent/pull/27175" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27175/hovercard">#27175</a>)</li>
<li>Live background terminal-process count in status bar. (<a href="https://github.com/NousResearch/hermes-agent/pull/32061" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32061/hovercard">#32061</a>)</li>
<li>Append session recap to <code>/status</code> output. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/18587" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18587/hovercard">#18587</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27176" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27176/hovercard">#27176</a>)</li>
<li>Configurable paste-collapse thresholds (TUI + CLI). (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/29723" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29723/hovercard">#29723</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32087" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32087/hovercard">#32087</a>)</li>
<li><code>/resume</code> accepts position numbers. (<a href="https://github.com/NousResearch/hermes-agent/pull/31709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31709/hovercard">#31709</a>)</li>
<li>Bring tool-call display back — verbose mode, specific failure reasons, todo progress. (<a href="https://github.com/NousResearch/hermes-agent/pull/31293" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31293/hovercard">#31293</a>)</li>
<li>Validate runtime token refresh in Qwen auth status. (<a href="https://github.com/NousResearch/hermes-agent/pull/31196" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31196/hovercard">#31196</a>)</li>
</ul>
<h3>TUI</h3>
<ul>
<li><strong>TUI session orchestrator</strong> — multiple live sessions in one TUI window. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/27642" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27642/hovercard">#27642</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32980" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32980/hovercard">#32980</a>)</li>
<li><code>mouse_tracking</code> DEC mode presets. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/26681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26681/hovercard">#26681</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30084/hovercard">#30084</a>)</li>
<li>Termux scrollback preservation + touch-friendly defaults. (<a href="https://github.com/NousResearch/hermes-agent/pull/28910" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28910/hovercard">#28910</a>)</li>
<li>Full assistant text in scrollback (no history truncation). (<a href="https://github.com/NousResearch/hermes-agent/pull/28829" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28829/hovercard">#28829</a>)</li>
<li>Preserve scrollback when branching sessions. (<a href="https://github.com/NousResearch/hermes-agent/pull/30162" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30162/hovercard">#30162</a>)</li>
<li>Preserve Python dunder identifiers in markdown. (<a href="https://github.com/NousResearch/hermes-agent/pull/28582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28582/hovercard">#28582</a>)</li>
<li>Active profile shown in TUI prompt. (<a href="https://github.com/NousResearch/hermes-agent/pull/28581" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28581/hovercard">#28581</a>)</li>
<li>Improve Charizard completion menu contrast. (<a href="https://github.com/NousResearch/hermes-agent/pull/28346" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28346/hovercard">#28346</a>)</li>
<li>Stop slash dropdown chopping last char of <code>/goal</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/31311" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31311/hovercard">#31311</a>)</li>
<li>Clipboard copy on linux/wayland. (<a href="https://github.com/NousResearch/hermes-agent/pull/29342" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29342/hovercard">#29342</a>)</li>
<li>Anchor <code>splitReasoning</code> unclosed-tag regex; stop eating last paragraph. (<a href="https://github.com/NousResearch/hermes-agent/pull/29426" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29426/hovercard">#29426</a>)</li>
<li>Surface verbose tool details. (<a href="https://github.com/NousResearch/hermes-agent/pull/30225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30225/hovercard">#30225</a>)</li>
<li>Load Linux skills on Termux + salvage <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adybag14-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adybag14-cyber">@adybag14-cyber</a>'s Termux gates. (<a href="https://github.com/NousResearch/hermes-agent/pull/30166" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30166/hovercard">#30166</a>)</li>
<li>Handle images with codex app-server. (<a href="https://github.com/NousResearch/hermes-agent/pull/31220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31220/hovercard">#31220</a>)</li>
<li>Refresh virtual transcript on viewport resize. (<a href="https://github.com/NousResearch/hermes-agent/pull/31077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31077/hovercard">#31077</a>)</li>
<li>Ignore late thinking deltas after completion. (<a href="https://github.com/NousResearch/hermes-agent/pull/31055" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31055/hovercard">#31055</a>)</li>
<li>Commit composer input bursts immediately. (<a href="https://github.com/NousResearch/hermes-agent/pull/31053" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31053/hovercard">#31053</a>)</li>
<li>Log parent gateway lifecycle exits. (<a href="https://github.com/NousResearch/hermes-agent/pull/31051" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31051/hovercard">#31051</a>)</li>
<li>Clear TTS env var on voice off + TTS indicator in status bar. (<a href="https://github.com/NousResearch/hermes-agent/pull/30987" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30987/hovercard">#30987</a>)</li>
<li>Pass <code>--expose-gc</code> as node argv instead of NODE_OPTIONS. (<a href="https://github.com/NousResearch/hermes-agent/pull/29998" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29998/hovercard">#29998</a>)</li>
<li>Align composer cursorLayout with wrap-ansi to kill multiline cursor drift. (<a href="https://github.com/NousResearch/hermes-agent/pull/27489" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27489/hovercard">#27489</a>)</li>
<li>Harden Terminal.app rendering and color paths. (<a href="https://github.com/NousResearch/hermes-agent/pull/27251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27251/hovercard">#27251</a>)</li>
<li>Keep <code>/goal</code> verdict out of compact status row. (<a href="https://github.com/NousResearch/hermes-agent/pull/27971" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27971/hovercard">#27971</a>)</li>
<li>Clamp curses color 8 for 8-color terminals (Docker). (<a href="https://github.com/NousResearch/hermes-agent/pull/30260" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30260/hovercard">#30260</a>)</li>
</ul>
<hr>
<h2>🔒 Security &amp; Reliability</h2>
<h3>Promptware &amp; memory hardening</h3>
<ul>
<li><strong>Promptware defense</strong> — shared threat patterns + memory load-time scan + tool-result delimiters. (<a href="https://github.com/NousResearch/hermes-agent/pull/32269" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32269/hovercard">#32269</a>)</li>
<li>Expand memory content scanning patterns to parity with skills guard. (<a href="https://github.com/NousResearch/hermes-agent/pull/9151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/9151/hovercard">#9151</a>)</li>
<li>Harden Skills Guard multi-word prompt patterns. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YLChen-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YLChen-007">@YLChen-007</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26852" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26852/hovercard">#26852</a>)</li>
<li>Split cron scanner so skill prose stops false-positiving exfil patterns. (<a href="https://github.com/NousResearch/hermes-agent/pull/32339" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32339/hovercard">#32339</a>)</li>
</ul>
<h3>File safety</h3>
<ul>
<li>Protect Hermes control-plane files from prompt injection (<code>auth.json</code>, <code>config.yaml</code>, <code>webhook_subscriptions.json</code>, <code>mcp-tokens/</code>). (salvages <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PratikRai0101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PratikRai0101">@PratikRai0101</a>'s <a href="https://github.com/NousResearch/hermes-agent/pull/14157" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14157/hovercard">#14157</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30397/hovercard">#30397</a>)</li>
<li>Write-deny <code>&lt;root&gt;/.env</code> when running under a profile. (<a href="https://github.com/NousResearch/hermes-agent/pull/29687" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29687/hovercard">#29687</a>)</li>
<li>Defense-in-depth read-deny on credential stores. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/17659" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17659/hovercard">#17659</a> + <a href="https://github.com/NousResearch/hermes-agent/pull/8055" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8055/hovercard">#8055</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30721" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30721/hovercard">#30721</a>)</li>
<li>TTS <code>output_path</code> traversal + update ZIP symlink reject. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/6693" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6693/hovercard">#6693</a> + <a href="https://github.com/NousResearch/hermes-agent/pull/15881" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15881/hovercard">#15881</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32056" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32056/hovercard">#32056</a>)</li>
<li>Reject symlinked audio inputs. (<a href="https://github.com/NousResearch/hermes-agent/pull/10082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/10082/hovercard">#10082</a>)</li>
</ul>
<h3>Credential safety</h3>
<ul>
<li>Avoid persisting borrowed credential secrets — runtime env-sourced keys no longer leak into <code>auth.json</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/31416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31416/hovercard">#31416</a>)</li>
<li>Validate Nous Portal <code>inference_base_url</code> against host allowlist. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/27612" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27612/hovercard">#27612</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30611" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30611/hovercard">#30611</a>)</li>
<li>Harden API server key placeholder handling. (<a href="https://github.com/NousResearch/hermes-agent/pull/30738" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30738/hovercard">#30738</a>)</li>
<li>Harden Google Chat OAuth credential persistence. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zyrixtrex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zyrixtrex">@Zyrixtrex</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/24788" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24788/hovercard">#24788</a>)</li>
<li>xAI OAuth: pin inference <code>base_url</code> to x.ai origin. (<a href="https://github.com/NousResearch/hermes-agent/pull/28952" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28952/hovercard">#28952</a>)</li>
<li>Quarantine dead OAuth tokens on terminal refresh failure (xAI, Codex, MiniMax). (<a href="https://github.com/NousResearch/hermes-agent/pull/28116" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28116/hovercard">#28116</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28118" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28118/hovercard">#28118</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28119" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28119/hovercard">#28119</a>)</li>
</ul>
<h3>Supply-chain</h3>
<ul>
<li><strong>On-demand supply-chain audit via OSV.dev</strong> — <code>hermes audit</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/31460" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31460/hovercard">#31460</a>)</li>
<li><code>hermes update</code> syntax-validates critical files post-pull, auto-rollback on failure. (<a href="https://github.com/NousResearch/hermes-agent/pull/28669" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28669/hovercard">#28669</a>)</li>
<li>Quarantine <code>hermes.exe</code> vs concurrent Windows instance. (<a href="https://github.com/NousResearch/hermes-agent/pull/26677" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26677/hovercard">#26677</a>)</li>
</ul>
<h3>Other hardening</h3>
<ul>
<li>Restrict default webhook toolset capabilities. (<a href="https://github.com/NousResearch/hermes-agent/pull/30745" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30745/hovercard">#30745</a>)</li>
<li>Harden Microsoft Graph webhook auth requirements. (<a href="https://github.com/NousResearch/hermes-agent/pull/30169" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30169/hovercard">#30169</a>)</li>
<li>Require source CIDR allowlisting for public msgraph webhook binds. (<a href="https://github.com/NousResearch/hermes-agent/pull/33722" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33722/hovercard">#33722</a>)</li>
<li>Require <code>API_SERVER_KEY</code> before dispatching API server work. (<a href="https://github.com/NousResearch/hermes-agent/pull/33232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33232/hovercard">#33232</a>)</li>
<li>env_passthrough: apply GHSA-rhgp-j443-p4rf filter to config.yaml path. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roadhero/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roadhero">@roadhero</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27794" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27794/hovercard">#27794</a>)</li>
<li>Dashboard + WeCom: restrict markdown link schemes; safe-parse untrusted XML. (<a href="https://github.com/NousResearch/hermes-agent/pull/32442" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32442/hovercard">#32442</a>)</li>
<li>Salvage project-plugin RCE bypass fix from PR <a href="https://github.com/NousResearch/hermes-agent/pull/29311" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29311/hovercard">#29311</a> (GHSA-5qr3-c538-wm9j). (<a href="https://github.com/NousResearch/hermes-agent/pull/30837" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30837/hovercard">#30837</a>)</li>
<li>Cross-profile soft guard on file-write tools + system-prompt hint. (<a href="https://github.com/NousResearch/hermes-agent/pull/31290" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31290/hovercard">#31290</a>)</li>
<li>Reject unsafe tar members in Android psutil compatibility installer. (<a href="https://github.com/NousResearch/hermes-agent/pull/33742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33742/hovercard">#33742</a>)</li>
<li>Reject non-regular tar members during tirith auto-install. (<a href="https://github.com/NousResearch/hermes-agent/pull/33786" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33786/hovercard">#33786</a>)</li>
</ul>
<hr>
<h2>🪟 Native Windows (Beta Continued)</h2>
<ul>
<li>Thin desktop installer + first-launch <code>install.ps1</code> bootstrap. (<a href="https://github.com/NousResearch/hermes-agent/pull/27822" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27822/hovercard">#27822</a>)</li>
<li>Complete Windows bootstrap — <code>dep_ensure</code> + <code>install.ps1</code> + detection. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27845" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27845/hovercard">#27845</a>)</li>
<li><code>install.ps1</code>: strip BOM, <code>-Commit</code>/<code>-Tag</code> pin params, harden git ops. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28169" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28169/hovercard">#28169</a>)</li>
<li>Consolidate ACP browser bootstrap into <code>install.{sh,ps1}</code>. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27851" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27851/hovercard">#27851</a>)</li>
<li><code>hermes update</code> quarantines live <code>hermes.exe</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/26677" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26677/hovercard">#26677</a>)</li>
<li>Discord voice opus decoding on Windows. (<a href="https://github.com/NousResearch/hermes-agent/pull/33182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33182/hovercard">#33182</a>)</li>
<li>Windows Docker Desktop compatible compose file. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sunil123135/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sunil123135">@Sunil123135</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31031" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31031/hovercard">#31031</a>)</li>
</ul>
<hr>
<h2>🖼️ Hermes Desktop GUI</h2>
<ul>
<li><code>hermes gui</code> launcher — install + build + launch packaged Electron app. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30165" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30165/hovercard">#30165</a>)</li>
<li>Desktop UI lift. (<a href="https://github.com/NousResearch/hermes-agent/pull/27227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27227/hovercard">#27227</a>)</li>
<li><code>nix</code> package <code>.#desktop</code>. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28964" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28964/hovercard">#28964</a>)</li>
<li>Hardened Slack socket recovery + Windows desktop restart dedupe. (<a href="https://github.com/NousResearch/hermes-agent/pull/28873" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28873/hovercard">#28873</a>)</li>
<li>Web dashboard: migrate checkboxes to <code>@nous-research/ui</code> + design-system polish. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28814" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28814/hovercard">#28814</a>)</li>
<li>Web dashboard: collapsible sidebar. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33421" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33421/hovercard">#33421</a>)</li>
<li>Dashboard typography &amp; contrast pass. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/28832" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28832/hovercard">#28832</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30714" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30714/hovercard">#30714</a>)</li>
<li>Skills page: lazy-fetch catalog instead of bundling 34MB into JS. (<a href="https://github.com/NousResearch/hermes-agent/pull/33809" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33809/hovercard">#33809</a>)</li>
</ul>
<hr>
<h2>🐳 Docker</h2>
<ul>
<li><strong>s6-overlay container supervision</strong> — abstract <code>ServiceManager</code> protocol (systemd/launchd/Windows/s6 backends), per-profile gateway supervision in-container, container-restart reconciliation, hadolint/shellcheck CI. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/30136" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30136/hovercard">#30136</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31760" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31760/hovercard">#31760</a>)</li>
<li>Auto-redirect <code>gateway run</code> to supervised mode inside the s6 image. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33583" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33583/hovercard">#33583</a>)</li>
<li>Tee supervised gateway stdout to docker logs. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33621" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33621/hovercard">#33621</a>)</li>
<li>Drop <code>docker exec</code> to hermes uid before invoking the CLI. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33628" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33628/hovercard">#33628</a>)</li>
<li>Align HOME for dashboard and s6 gateway services. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33481" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33481/hovercard">#33481</a>)</li>
<li>Bake build-time git SHA into image so <code>hermes dump</code> reports it. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33655" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33655/hovercard">#33655</a>)</li>
<li><code>hermes update</code> prints <code>docker pull</code> guidance instead of bogus git error. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33659" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33659/hovercard">#33659</a>)</li>
<li>Upgrade Node to 22 LTS via multi-stage from <code>node:22-bookworm-slim</code>. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33060/hovercard">#33060</a>)</li>
<li>Drop <code>build-essential</code> from apt install. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33028" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33028/hovercard">#33028</a>)</li>
<li>Propagate env through s6 to cont-init and main CMD. (<a href="https://github.com/NousResearch/hermes-agent/pull/32412" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32412/hovercard">#32412</a>)</li>
<li>Targeted chown to preserve host file ownership in <code>HERMES_HOME</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/33033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33033/hovercard">#33033</a>)</li>
<li><code>mkdir HERMES_HOME</code> as root in stage2 before chown / privilege drop. (<a href="https://github.com/NousResearch/hermes-agent/pull/33078" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33078/hovercard">#33078</a>)</li>
<li>chown <code>ui-tui</code> and <code>node_modules</code> on UID remap so TUI esbuild works. (<a href="https://github.com/NousResearch/hermes-agent/pull/33045" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33045/hovercard">#33045</a>)</li>
<li>Include <code>anthropic</code>, <code>bedrock</code>, <code>azure-identity</code> extras in image. (<a href="https://github.com/NousResearch/hermes-agent/pull/30504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30504/hovercard">#30504</a>)</li>
<li>Stop pushing per-commit SHA tags to Docker Hub. (<a href="https://github.com/NousResearch/hermes-agent/pull/29387" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29387/hovercard">#29387</a>)</li>
<li>Simplify Docker tagging — push both <code>:main</code> and <code>:latest</code> on main push. (<a href="https://github.com/NousResearch/hermes-agent/pull/33225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33225/hovercard">#33225</a>)</li>
<li>Test slicing across GH actions jobs. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30575" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30575/hovercard">#30575</a>)</li>
<li>Discover agent-browser Chromium binary at boot. (<a href="https://github.com/NousResearch/hermes-agent/pull/33184" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33184/hovercard">#33184</a>)</li>
</ul>
<hr>
<h2>🌐 API Server</h2>
<ul>
<li><strong>Session control API</strong> — <code>/api/sessions/*</code> (list/create/read/patch/delete/fork) + SSE-streaming chat. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/29302" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29302/hovercard">#29302</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Codename-11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Codename-11">@Codename-11</a> + multimodal followup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Schwartz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Schwartz10">@Schwartz10</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33134" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33134/hovercard">#33134</a>)</li>
<li><code>GET /v1/skills</code> and <code>/v1/toolsets</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/33016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33016/hovercard">#33016</a>)</li>
<li>Coerce stringified booleans in stream/store/approval payloads. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/26639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26639/hovercard">#26639</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27293" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27293/hovercard">#27293</a>)</li>
<li>Honor <code>key_env</code> in auth-failure fallback resolution. (<a href="https://github.com/NousResearch/hermes-agent/pull/30840" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30840/hovercard">#30840</a>)</li>
</ul>
<hr>
<h2>🎟️ ACP (VS Code / Zed / JetBrains)</h2>
<ul>
<li>Session edit auto-approval modes. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/27034" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27034/hovercard">#27034</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27862" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27862/hovercard">#27862</a>)</li>
<li>Enrich Zed permission cards — command in title + <code>reject_always</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28148" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28148/hovercard">#28148</a>)</li>
<li>Replay session history before responding to <code>session/load</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/26957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26957/hovercard">#26957</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26943/hovercard">#26943</a>)</li>
<li>Plugin-transformed final_response delivered through streaming gate. (<a href="https://github.com/NousResearch/hermes-agent/pull/31433" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31433/hovercard">#31433</a>)</li>
</ul>
<hr>
<h2>🔌 Plugin Surface</h2>
<ul>
<li><code>register_tts_provider()</code> plugin hook. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/30420" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30420/hovercard">#30420</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31745" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31745/hovercard">#31745</a>)</li>
<li><code>register_transcription_provider()</code> hook + <code>stt.providers</code> command-provider registry. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/30493" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30493/hovercard">#30493</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31907" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31907/hovercard">#31907</a>)</li>
<li><code>register_auxiliary_task()</code> in PluginContext API. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/29817" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29817/hovercard">#29817</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31177" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31177/hovercard">#31177</a>)</li>
<li>Bundled <code>security-guidance</code> plugin. (<a href="https://github.com/NousResearch/hermes-agent/pull/33131" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33131/hovercard">#33131</a>)</li>
<li>Discord and Mattermost migrated to bundled plugins. (<a href="https://github.com/NousResearch/hermes-agent/pull/30591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30591/hovercard">#30591</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/31748" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31748/hovercard">#31748</a>)</li>
<li>ntfy as platform plugin. (<a href="https://github.com/NousResearch/hermes-agent/pull/30867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30867/hovercard">#30867</a>)</li>
<li>Surface category-namespaced plugins in <code>hermes plugins list</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/27187" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27187/hovercard">#27187</a>)</li>
<li>Plugin discovery failures raised to WARNING level. (<a href="https://github.com/NousResearch/hermes-agent/pull/28318" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28318/hovercard">#28318</a>)</li>
<li><code>hermes_plugins</code> included in gateway.log component filter. (<a href="https://github.com/NousResearch/hermes-agent/pull/28313" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28313/hovercard">#28313</a>)</li>
<li>Seed plugin extras before <code>is_connected</code> gate. (<a href="https://github.com/NousResearch/hermes-agent/pull/31703" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31703/hovercard">#31703</a>)</li>
<li>Dashboard: allowlist plugin assets + denylist subprocess-influencing env vars. (<a href="https://github.com/NousResearch/hermes-agent/pull/32277" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32277/hovercard">#32277</a>)</li>
</ul>
<hr>
<h2>📦 Distribution &amp; Install</h2>
<ul>
<li>Install-method stamping + Docker detection. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27843" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27843/hovercard">#27843</a>)</li>
<li>Nix <code>#messaging</code> and <code>#full</code> package variants. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33108" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33108/hovercard">#33108</a>)</li>
<li>Pre-load messaging gateway deps via <code>--extra messaging</code>. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/26394" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26394/hovercard">#26394</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27558" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27558/hovercard">#27558</a>)</li>
<li>Avoid piping installer directly into <code>iex</code> (Windows). (<a href="https://github.com/NousResearch/hermes-agent/pull/28347" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28347/hovercard">#28347</a>)</li>
<li>Ship bundled skills in wheel. (<a href="https://github.com/NousResearch/hermes-agent/pull/28421" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28421/hovercard">#28421</a>)</li>
<li>Ship dashboard plugin assets in wheel. (<a href="https://github.com/NousResearch/hermes-agent/pull/28406" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28406/hovercard">#28406</a>)</li>
<li>Make Camofox lazy-installed instead of eager. (<a href="https://github.com/NousResearch/hermes-agent/pull/27055" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27055/hovercard">#27055</a>)</li>
<li>Wire STT lazy-install into transcription_tools.py. (<a href="https://github.com/NousResearch/hermes-agent/pull/30256" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30256/hovercard">#30256</a>)</li>
</ul>
<hr>
<h2>🐛 Notable Bug Fixes (highlights only)</h2>
<ul>
<li>Match bare custom provider by active base URL in <code>hermes model</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28908/hovercard">#28908</a>)</li>
<li>Route <code>auxiliary.vision.provider=openai</code> to api.openai.com, skip text-only main. (<a href="https://github.com/NousResearch/hermes-agent/pull/31452" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31452/hovercard">#31452</a>)</li>
<li>Lint: skip per-file shell linter when LSP will handle the file. (<a href="https://github.com/NousResearch/hermes-agent/pull/29054" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29054/hovercard">#29054</a>)</li>
<li>Treat empty credential pool entries as unauthenticated in <code>/model</code> picker. (<a href="https://github.com/NousResearch/hermes-agent/pull/28312" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28312/hovercard">#28312</a>)</li>
<li>Reverted within window: Firecrawl integration tag, send_message @username auto-mentions, Telegram quick-command-only menus, Telegram pin-on-turn.</li>
</ul>
<hr>
<h2>🧪 Testing</h2>
<ul>
<li>Disarm lazy-install probe so <code>_HAS_FASTER_WHISPER</code> patches work. (<a href="https://github.com/NousResearch/hermes-agent/pull/30334" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30334/hovercard">#30334</a>)</li>
<li>Cover default board dashboard pin. (<a href="https://github.com/NousResearch/hermes-agent/pull/28361" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28361/hovercard">#28361</a>)</li>
<li>Cover <code>_task_dict</code> <code>task_age</code> fallback. (<a href="https://github.com/NousResearch/hermes-agent/pull/28365" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28365/hovercard">#28365</a>)</li>
<li>Allowlist <code>tmp_path</code> for <code>kanban_notify</code> artifact delivery tests. (<a href="https://github.com/NousResearch/hermes-agent/pull/30851" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30851/hovercard">#30851</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30852" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30852/hovercard">#30852</a>)</li>
<li>Cover null output stream terminal events in Codex. (<a href="https://github.com/NousResearch/hermes-agent/pull/33137" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33137/hovercard">#33137</a>)</li>
</ul>
<hr>
<h2>📚 Documentation</h2>
<ul>
<li><strong>30-day docs overhaul</strong> — full correctness audit, every PR in the window covered, Nous Portal weave, sidebar reorg. (<a href="https://github.com/NousResearch/hermes-agent/pull/33782" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33782/hovercard">#33782</a>)</li>
<li>Dedicated Nous Portal integration page and setup guide. (<a href="https://github.com/NousResearch/hermes-agent/pull/31296" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31296/hovercard">#31296</a>)</li>
<li>Providers: move Nous Portal first, Google Gemini OAuth last. (<a href="https://github.com/NousResearch/hermes-agent/pull/31287" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31287/hovercard">#31287</a>)</li>
<li><code>session_search</code> rewrite for single-shape tool. (<a href="https://github.com/NousResearch/hermes-agent/pull/27840" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27840/hovercard">#27840</a>)</li>
<li>Kanban: document failure_limit, max_retries, inline create shortcuts, goals &amp; kanban settings. (<a href="https://github.com/NousResearch/hermes-agent/pull/28357" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28357/hovercard">#28357</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28358" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28358/hovercard">#28358</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28359" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28359/hovercard">#28359</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28360" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28360/hovercard">#28360</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28362" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28362/hovercard">#28362</a>)</li>
<li>Kanban Codex lane skill. (<a href="https://github.com/NousResearch/hermes-agent/pull/28430" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28430/hovercard">#28430</a>)</li>
<li>xAI OAuth: note X Premium+ also unlocks Grok OAuth. (<a href="https://github.com/NousResearch/hermes-agent/pull/29055" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29055/hovercard">#29055</a>)</li>
<li>Docs site: Docker audio bridge notes, "Installing more tools in the container", xurl auth HOME in Docker.</li>
<li>Email: clarify gateway vs Himalaya setup. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33634" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33634/hovercard">#33634</a>)</li>
<li>Auth docs: replace stale <code>hermes login</code> references with <code>hermes auth add</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/32859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32859/hovercard">#32859</a>)</li>
</ul>
<hr>
<h2>👥 Contributors</h2>
<h3>Core</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a> (lead)</li>
</ul>
<h3>Notable salvages &amp; cherry-picks</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a></strong> — s6-overlay container supervision (29 commits salvaged), Node 22 LTS upgrade, build-essential cleanup, <code>gateway run</code> auto-redirect in s6, tee supervised stdout to docker logs, <code>hermes update</code> Docker guidance, build-time SHA stamping</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a></strong> — <code>hermes gui</code> desktop launcher, <code>mouse_tracking</code> DEC mode presets</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a></strong> — Windows installer hardening, <code>--branch</code> flag for <code>hermes update</code>, install.ps1 BOM strip / commit-pin</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a></strong> — Windows <code>dep_ensure</code> bootstrap, Nix package variants (<code>.#messaging</code>, <code>.#full</code>), install-method stamping, ACP browser bootstrap consolidation</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a></strong> — <code>/update</code> slash command, dashboard checkboxes → <code>@nous-research/ui</code>, mobile dashboard polish, collapsible sidebar</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a></strong> — Nix <code>.#desktop</code> packaging, CI test slicing across GH Actions jobs, TUI clipboard copy fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a></strong> — doctor section banner + fail-and-issue helpers extraction, post-tag salvage cluster (curator-fallout, kanban SQLite hardening, install world-readable uv dirs, xAI bare-code paste)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a></strong> — Nous JWT inference switch + refresh-token replay fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Codename-11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Codename-11">@Codename-11</a></strong> + <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Schwartz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Schwartz10">@Schwartz10</a></strong> — session control API (REST + SSE + multimodal followup)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Niraven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Niraven">@Niraven</a></strong> — kanban swarm topology helper</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Interstellar-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Interstellar-code">@Interstellar-code</a></strong> — kanban worker visibility endpoints</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adybag14-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adybag14-cyber">@adybag14-cyber</a></strong> — termux cold-start optimizations (multiple PRs)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qike-ms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qike-ms">@qike-ms</a></strong> — Telegram in-place status edits design</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a></strong> — ntfy adapter</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a></strong> — xAI Web Search provider plugin</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yannsunn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yannsunn">@yannsunn</a></strong> — xAI upstream adapter for <code>hermes proxy</code></li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cybourgeoisie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cybourgeoisie">@Cybourgeoisie</a></strong> — OpenRouter sticky routing via session_id</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/memosr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/memosr">@memosr</a></strong> — Nous Portal base_url allowlist validation</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sunil123135/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sunil123135">@Sunil123135</a></strong> — Windows Docker Desktop compose file</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a></strong> — Docker HOME alignment for dashboard + s6 gateway services</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beardthelion/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beardthelion">@beardthelion</a></strong> — opencode-go anthropic_messages routing</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YLChen-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YLChen-007">@YLChen-007</a></strong> — Skills Guard multi-word prompt patterns</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roadhero/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roadhero">@roadhero</a></strong> — env_passthrough GHSA-rhgp-j443-p4rf filter</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zyrixtrex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zyrixtrex">@Zyrixtrex</a></strong> — Google Chat OAuth credential persistence hardening</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a></strong>, <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomqiaozc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomqiaozc">@tomqiaozc</a></strong> — defense-in-depth read-deny on credential stores</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PratikRai0101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PratikRai0101">@PratikRai0101</a></strong> — control-plane file write protection</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a></strong>, <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a></strong>, <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zccyman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zccyman">@zccyman</a></strong> — auxiliary fallback ladder components</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ms-alan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ms-alan">@ms-alan</a></strong>, <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ticketclosed-wontfix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ticketclosed-wontfix">@ticketclosed-wontfix</a></strong>, <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donovan-yohan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donovan-yohan">@donovan-yohan</a></strong> — TUI session orchestrator + follow-ups</li>
<li><strong>@daimon-nous[bot]</strong> — cron per-job profile support</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bisko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bisko">@bisko</a></strong> — re-pad <code>reasoning_content</code> on cross-provider fallback</li>
</ul>
<h3>All Contributors</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/02356abc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/02356abc">@02356abc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xchainer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xchainer">@0xchainer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xDevNinja/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xDevNinja">@0xDevNinja</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xjackyang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xjackyang">@0xjackyang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xsir0000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xsir0000">@0xsir0000</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0z1-ghb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0z1-ghb">@0z1-ghb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/8bit64k/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/8bit64k">@8bit64k</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aaronlab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aaronlab">@aaronlab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AceWattGit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AceWattGit">@AceWattGit</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ACR27/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ACR27">@ACR27</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adam91holt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adam91holt">@adam91holt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AdamPlatin123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AdamPlatin123">@AdamPlatin123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ade5954/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ade5954">@Ade5954</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AdityaRajeshGadgil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AdityaRajeshGadgil">@AdityaRajeshGadgil</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adybag14-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adybag14-cyber">@adybag14-cyber</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hana-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hana-ai">@ai-hana-ai</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alaamohanad169-ship-it/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alaamohanad169-ship-it">@alaamohanad169-ship-it</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alber70g/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alber70g">@alber70g</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/albert748/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/albert748">@albert748</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aqilaziz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aqilaziz">@aqilaziz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/argabor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/argabor">@argabor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asdlem/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asdlem">@asdlem</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/avifenesh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/avifenesh">@avifenesh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/awizemann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/awizemann">@awizemann</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/B0Tch1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/B0Tch1">@B0Tch1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BaxBit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BaxBit">@BaxBit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beardthelion/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beardthelion">@beardthelion</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bensargotest-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bensargotest-sys">@bensargotest-sys</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bird/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bird">@bird</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bisko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bisko">@bisko</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackishGreen33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackishGreen33">@BlackishGreen33</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/booker1207/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/booker1207">@booker1207</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradhallett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradhallett">@bradhallett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Brixyy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Brixyy">@Brixyy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brndnsvr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brndnsvr">@brndnsvr</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BROCCOLO1D/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BROCCOLO1D">@BROCCOLO1D</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/btorresgil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/btorresgil">@btorresgil</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/burjorjee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/burjorjee">@burjorjee</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carltonawong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carltonawong">@carltonawong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Carry00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Carry00">@Carry00</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chaconne67/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chaconne67">@chaconne67</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chdlc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chdlc">@chdlc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chromalinx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chromalinx">@chromalinx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChyuWei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChyuWei">@ChyuWei</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CipherFrame/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CipherFrame">@CipherFrame</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cmullins70/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cmullins70">@cmullins70</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CNSeniorious000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CNSeniorious000">@CNSeniorious000</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codeblackhole1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codeblackhole1024">@codeblackhole1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Codename-11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Codename-11">@Codename-11</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colin-chang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colin-chang">@colin-chang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/counterposition/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/counterposition">@counterposition</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cresslank/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cresslank">@cresslank</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CryptoByz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CryptoByz">@CryptoByz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyb0rgk1tty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyb0rgk1tty">@cyb0rgk1tty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cybourgeoisie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cybourgeoisie">@Cybourgeoisie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daizhonggeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daizhonggeng">@daizhonggeng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/darvsum/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/darvsum">@darvsum</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidcampbelldc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidcampbelldc">@davidcampbelldc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deas">@deas</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dgians/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dgians">@dgians</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dillweed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dillweed">@dillweed</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DoGMaTiiC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DoGMaTiiC">@DoGMaTiiC</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donovan-yohan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donovan-yohan">@donovan-yohan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/draplater/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/draplater">@draplater</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Drexuxux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Drexuxux">@Drexuxux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dskwe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dskwe">@dskwe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dsr-restyn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dsr-restyn">@dsr-restyn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dusterbloom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dusterbloom">@dusterbloom</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/duyua9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/duyua9">@duyua9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/egilewski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/egilewski">@egilewski</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/el-analista/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/el-analista">@el-analista</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eliteworkstation94-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eliteworkstation94-ai">@eliteworkstation94-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eloklam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eloklam">@eloklam</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EloquentBrush0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EloquentBrush0x">@EloquentBrush0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emonty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emonty">@emonty</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erhnysr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erhnysr">@erhnysr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erikengervall/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erikengervall">@erikengervall</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ether-btc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ether-btc">@ether-btc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EvilHumphrey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EvilHumphrey">@EvilHumphrey</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabiosiqueira/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabiosiqueira">@fabiosiqueira</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/falasi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/falasi">@falasi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/falconexe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/falconexe">@falconexe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fardoche6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fardoche6">@fardoche6</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/felix-windsor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/felix-windsor">@felix-windsor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fewmanism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fewmanism">@Fewmanism</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ffr31mr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ffr31mr">@ffr31mr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flamiinngo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flamiinngo">@flamiinngo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flanny7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flanny7">@flanny7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flooryyyy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flooryyyy">@flooryyyy</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fonhal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fonhal">@fonhal</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/francip/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/francip">@francip</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fujinice/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fujinice">@fujinice</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gianfrancopiana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gianfrancopiana">@gianfrancopiana</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glennc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glennc">@glennc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Glucksberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Glucksberg">@Glucksberg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/godlin-gh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/godlin-gh">@godlin-gh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Grogger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Grogger">@Grogger</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guillaumemeyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guillaumemeyer">@guillaumemeyer</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/H-Ali13381/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/H-Ali13381">@H-Ali13381</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanzckernel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanzckernel">@hanzckernel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haran2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haran2001">@haran2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hawknewton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hawknewton">@hawknewton</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hayka-pacha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hayka-pacha">@hayka-pacha</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hehehe0803/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hehehe0803">@hehehe0803</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenkDz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenkDz">@HenkDz</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/Hermes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hermes">@Hermes</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hermesagent26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hermesagent26">@hermesagent26</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hinotoi-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hinotoi-agent">@Hinotoi-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hongchen1993/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hongchen1993">@hongchen1993</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/honor2030/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/honor2030">@honor2030</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/houenyang-momo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/houenyang-momo">@houenyang-momo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ht1072/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ht1072">@ht1072</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hueilau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hueilau">@hueilau</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamfoz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamfoz">@iamfoz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ilonagaja509-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ilonagaja509-glitch">@ilonagaja509-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/InB4DevOps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/InB4DevOps">@InB4DevOps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/indigokarasu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/indigokarasu">@indigokarasu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Interstellar-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Interstellar-code">@Interstellar-code</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iqdoctor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iqdoctor">@iqdoctor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iRonin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iRonin">@iRonin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JabberELF/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JabberELF">@JabberELF</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jacevys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jacevys">@jacevys</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackey8616/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackey8616">@jackey8616</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackjin1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackjin1997">@jackjin1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jdelmerico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jdelmerico">@jdelmerico</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jfuenmayor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jfuenmayor">@jfuenmayor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jiahui-Gu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jiahui-Gu">@Jiahui-Gu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimLiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimLiu">@JimLiu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joe102084/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joe102084">@joe102084</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnC1009/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnC1009">@JohnC1009</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonpol01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonpol01">@jonpol01</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jpalmer95/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jpalmer95">@Jpalmer95</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Julientalbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Julientalbot">@Julientalbot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justemu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justemu">@justemu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justincc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justincc">@justincc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jvinals/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jvinals">@jvinals</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/karthikeyann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/karthikeyann">@karthikeyann</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kasunvinod/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kasunvinod">@kasunvinod</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kchuang1015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kchuang1015">@kchuang1015</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kenyonxu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kenyonxu">@kenyonxu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/khungate/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/khungate">@khungate</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kiranvk-2011/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kiranvk-2011">@kiranvk-2011</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kjames2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kjames2001">@kjames2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kpadilha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kpadilha">@kpadilha</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kriscolab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kriscolab">@kriscolab</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/krislidimo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/krislidimo">@krislidimo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kronexoi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kronexoi">@kronexoi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kunci115/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kunci115">@kunci115</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kylejeong2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kylejeong2">@Kylejeong2</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kylekahraman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kylekahraman">@kylekahraman</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LaPhilosophie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LaPhilosophie">@LaPhilosophie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leeseoki0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leeseoki0">@leeseoki0</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lemassykoi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lemassykoi">@lemassykoi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lempkey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lempkey">@Lempkey</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonJS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonJS">@LeonJS</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lidge-jun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lidge-jun">@lidge-jun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LifeJiggy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LifeJiggy">@LifeJiggy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LizerAIDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LizerAIDev">@LizerAIDev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loicnico96/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loicnico96">@loicnico96</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>, @m0n3r0, @malaiwah, @matthewlai, @mavrickdeveloper, @maxmilian, @McClean-Edison, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/memosr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/memosr">@memosr</a>,<br>
@Mind-Dragon, @momowind, @MoonJuhan, @MoonRay305, @moortekweb-art, @MorAlekss, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ms-alan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ms-alan">@ms-alan</a>, @Nami4D,<br>
@nehaaprasaad, @nekwo, @nftpoetrist, @NickLarcombe, @nidhi-singh02, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Niraven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Niraven">@Niraven</a>, @nnnet, @noctilust, @novax635,<br>
@nthrow, @nv-kasikritc, @nycomar, @OCWC22, @oemtalks, @OmX, @ooovenenoso, @orcool, @oseftg, @outsourc-e,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, @Paperclip, @PaTTeeL, @pepelax, @phoenixshen, @Pluviobyte, @pnascimento9596, @pochi-gio, @pr7426,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PratikRai0101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PratikRai0101">@PratikRai0101</a>, @Prithvi1994, @psionic73, @ptichalouf, @Que0x, @QuenVix, @quocanh261997, @qWaitCrypto, @Qwinty,<br>
@r266-tech, @rak135, @rdasilva1016-ui, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roadhero/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roadhero">@roadhero</a>, @rodrigoeqnit, @RonHillDev, @roycepersonalassistant,<br>
@rudi193-cmd, @RyanRana, @sadiksaifi, @samahn0601, @samggggflynn, @SamuelZ12, @sanghyuk-seo-nexcube,<br>
@Saurav0989, @savanne-kham, @Schrotti77, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Schwartz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Schwartz10">@Schwartz10</a>, @SerenityTn, @sgtworkman, @sharziki, @shaun0927,<br>
@shellybotmoyer, @shunsuke-hikiyama, @SimbaKingjoe, @SimoKiihamaki, @sir-ad, @Slimydog21, @slowtokki0409,<br>
@Soju06, @someaka, @soynchux, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a>, @Stark-X, @steezkelly, @stepanov1975, @stephenschoettler,<br>
@stevehq26-bot, @steveonjava, @Strontvod, @subtract0, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sunil123135/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sunil123135">@Sunil123135</a>, @superearn-fisher, @Sylw3ster, @tchanee,<br>
@that-ambuj, @thedavidmurray, @TheOnlyMika, @therahul-yo, @thewillhuang, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ticketclosed-wontfix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ticketclosed-wontfix">@ticketclosed-wontfix</a>, @Timur00Kh,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomqiaozc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomqiaozc">@tomqiaozc</a>, @Tosko4, @Tranquil-Flow, @tw2818, @uzunkuyruk, @vaddisrinivas, @vanthinh6886, @vgocoder,<br>
@victorGPT, @vynxevainglory-ai, @waefrebeorn, @walli, @wangpuv, @wanwan2qq, @wesleysimplicio, @worlldz,<br>
@wpengpeng168, @WuKongAI-CMU, @wuli666, @Wysie, @wysie, @xxxigm, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yannsunn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yannsunn">@yannsunn</a>, @YanzhongSu, @YarrowQiao, @ygd58,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YLChen-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YLChen-007">@YLChen-007</a>, @yoniebans, @yu-xin-c, @YuanHanzhong, @zapabob, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zccyman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zccyman">@zccyman</a>, @ziliangpeng, @zwolniony, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zyrixtrex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zyrixtrex">@Zyrixtrex</a></p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.5.16...v2026.5.28">v2026.5.16...v2026.5.28</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA["Other ideas ... had to just fall by the wayside": Fallout: New Vegas director says Obsidian had to limit the RPG's scope due to a time crunch]]></title>
<description><![CDATA[Fallout: New Vegas dev Obsidian originally had "other ideas" for the RPG, but they "had to just fall by the wayside" due to time constraints.]]></description>
<link>https://tsecurity.de/de/3552435/windows-tipps/other-ideas-had-to-just-fall-by-the-wayside-fallout-new-vegas-director-says-obsidian-had-to-limit-the-rpgs-scope-due-to-a-time-crunch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552435/windows-tipps/other-ideas-had-to-just-fall-by-the-wayside-fallout-new-vegas-director-says-obsidian-had-to-limit-the-rpgs-scope-due-to-a-time-crunch/</guid>
<pubDate>Wed, 27 May 2026 23:10:11 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Fallout: New Vegas dev Obsidian originally had "other ideas" for the RPG, but they "had to just fall by the wayside" due to time constraints.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Outer Worlds has been delisted, but players can carry saves into Spacer’s Choice Edition on Game Pass]]></title>
<description><![CDATA[Obsidian has clarified how save transfers, Game Pass access, and upgrades will work as The Outer Worlds: Spacer’s Choice Edition replaces the original release on modern storefronts.]]></description>
<link>https://tsecurity.de/de/3552178/windows-tipps/the-outer-worlds-has-been-delisted-but-players-can-carry-saves-into-spacers-choice-edition-on-game-pass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552178/windows-tipps/the-outer-worlds-has-been-delisted-but-players-can-carry-saves-into-spacers-choice-edition-on-game-pass/</guid>
<pubDate>Wed, 27 May 2026 20:36:51 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Obsidian has clarified how save transfers, Game Pass access, and upgrades will work as The Outer Worlds: Spacer’s Choice Edition replaces the original release on modern storefronts.]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Plaintext statt Notion: Alltag und Beruf mit Textdateien effizient organisieren]]></title>
<description><![CDATA[Die „Plaintext Productivity“ ist radikal einfach: Simple Textdateien helfen, Alltag und Beruf zu regeln. Nur wenige Regeln sind dafür nötig. Eine Anleitung.]]></description>
<link>https://tsecurity.de/de/3547573/it-nachrichten/heise-plaintext-statt-notion-alltag-und-beruf-mit-textdateien-effizient-organisieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547573/it-nachrichten/heise-plaintext-statt-notion-alltag-und-beruf-mit-textdateien-effizient-organisieren/</guid>
<pubDate>Tue, 26 May 2026 12:17:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die „Plaintext Productivity“ ist radikal einfach: Simple Textdateien helfen, Alltag und Beruf zu regeln. Nur wenige Regeln sind dafür nötig. Eine Anleitung.]]></content:encoded>
</item>
<item>
<title><![CDATA[Switcher 2026: The Quest for a Notion Replacement ⭐]]></title>
<description><![CDATA[I use Notion every day, but I've also been trying to replace this "everything app" with something else for years.
The post Switcher 2026: The Quest for a Notion Replacement ⭐ appeared first on Thurrott.com.]]></description>
<link>https://tsecurity.de/de/3546173/windows-tipps/switcher-2026-the-quest-for-a-notion-replacement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546173/windows-tipps/switcher-2026-the-quest-for-a-notion-replacement/</guid>
<pubDate>Mon, 25 May 2026 20:23:28 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I use Notion every day, but I've also been trying to replace this "everything app" with something else for years.</p>
<p>The post <a href="https://www.thurrott.com/cloud/336474/switcher-2026-the-quest-for-a-notion-replacement">Switcher 2026: The Quest for a Notion Replacement ⭐</a> appeared first on <a href="https://www.thurrott.com/">Thurrott.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The role of MCP in context engineering]]></title>
<description><![CDATA[There’s no denying the excitement around Model Context Protocol (MCP), an open protocol for connecting AI assistants with external data, tools, and APIs. Since its debut by Anthropic in late 2024, thousands of MCP servers have emerged for devops, cloud, and beyond.



Now that developers have int...]]></description>
<link>https://tsecurity.de/de/3545164/ai-nachrichten/the-role-of-mcp-in-context-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545164/ai-nachrichten/the-role-of-mcp-in-context-engineering/</guid>
<pubDate>Mon, 25 May 2026 11:02:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There’s no denying the excitement around <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP), an open protocol for connecting AI assistants with external data, tools, and APIs. Since its debut by Anthropic in late 2024, thousands of MCP servers have emerged for <a href="https://www.infoworld.com/article/4096223/10-mcp-servers-for-devops.html">devops</a>, <a href="https://www.infoworld.com/article/4129024/five-mcp-servers-to-rule-the-cloud.html">cloud</a>, and beyond.</p>



<p>Now that developers have integrated MCP servers into applications, and they have been battle-tested, usage patterns are emerging. For instance, supplying better context for AI is the most commonly cited primary value of using MCP, according to Zuplo’s <a href="https://zuplo.com/mcp-report">State of MCP report</a> released in early 2026. The Zuplo report also found that 63% of MCP users adopt MCP servers for accessing data sources such as documentation or knowledge bases.</p>



<p>In software development, <a href="https://www.infoworld.com/article/4127462/what-is-context-engineering-and-why-its-the-new-ai-architecture.html">context engineering</a> is the act of supplying <a href="https://www.infoworld.com/article/4024327/12-ai-coding-agents-at-the-cutting-edge.html">AI coding agents</a> with relevant data and capabilities to improve the accuracy and relevance of their outputs. It also involves optimizing the breadth of information to guide efficient processing. Such context can include coding style, internal libraries, <a href="https://www.infoworld.com/article/4091400/anatomy-of-an-ai-agent-knowledge-base.html">institutional knowledge</a>, production data, and <a href="https://www.infoworld.com/article/4120322/how-should-ai-agents-consume-external-data.html">external data</a> from platforms like Slack, Atlassian, Notion, or GitHub, among others.</p>



<p>“MCPs support context engineering because it creates a standard way for AI systems to connect to various business tools,” says <a href="https://www.linkedin.com/in/toddaolson/">Todd Olson</a>, CEO of <a href="https://www.pendo.io/">Pendo</a>, a product experience platform. “The key benefit is that the agent determines what context it needs based on the question, then uses the appropriate MCP server to fetch that information in real time.”</p>



<p>With the rise in AI-assisted coding, MCP is becoming a doorway for real-time dynamic search and retrieval across various sources, playing an important role in context engineering efforts. As <a href="https://www.linkedin.com/in/theoutdoorprogrammer/">Joey Stout</a>, solutions architect at <a href="https://spacelift.io/">Spacelift</a>, an infrastructure orchestration platform, puts it, MCP is the “saving grace of vibe coding.”</p>



<h2 class="wp-block-heading"><a></a>How MCP boosts context engineering</h2>



<p>Using MCP, agents can fetch structured data contextually relevant to the task at hand. According to <a href="https://www.linkedin.com/in/kussberg/">Edgar Kussberg</a>, group product manager at <a href="https://www.sonarsource.com/">Sonar</a>, MCP accelerates the knowledge-hunting engineers must routinely perform on a daily basis.</p>



<p>“When an engineer needs to answer a question, they do not rely on memory alone,” says Kussberg. “They navigate code repositories, dashboards, CI systems, documentation, and security reports, pulling information from each system as needed. MCP gives AI agents that same capability.”</p>



<p>Many of the most popular MCP servers retrieve contextual information to improve agentic coding. For example, an MCP server from <a href="https://github.com/upstash/context7">Context7</a> provides up-to-date documentation, while another from <a href="https://github.com/modelcontextprotocol/servers/tree/main/src/filesystem">Filesystem</a> pulls from any directory on a local machine. An MCP server from <a href="https://docs.sentry.io/ai/mcp/">Sentry</a> accesses production issues and errors, a server from <a href="https://www.sonarsource.com/products/sonarqube/mcp-server/?utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=SQ-NA-US-East-Brand-Beinc&amp;utm_content=mcp-server&amp;utm_term=sonarqube%20mcp%20server&amp;s_campaign=SQ-NA-US-East-Brand-Beinc&amp;s_content=mcp-server&amp;s_term=sonarqube%20mcp%20server&amp;s_category=Paid&amp;s_source=Paid%20Search&amp;s_origin=Google&amp;cq_src=google_ads&amp;cq_cmp=23576298435&amp;cq_con=196318441871&amp;cq_term=sonarqube%20mcp%20server&amp;cq_med=&amp;cq_plac=&amp;cq_net=g&amp;cq_pos=&amp;cq_plt=gp&amp;utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=SQ-NA-US-East-Brand-Beinc&amp;utm_content=mcp-server&amp;utm_term=sonarqube%20mcp%20server&amp;s_campaign=SQ-NA-US-East-Brand-Beinc&amp;s_content=mcp-server&amp;s_term=sonarqube%20mcp%20server&amp;s_category=Paid&amp;s_source=Paid%20Search&amp;s_origin=Google&amp;cq_src=google_ads&amp;cq_cmp=23576298435&amp;cq_con=196318441871&amp;cq_term=sonarqube%20mcp%20server&amp;cq_med=&amp;cq_plac=&amp;cq_net=g&amp;cq_pos=&amp;cq_plt=gp&amp;gad_source=1&amp;gad_campaignid=23576298435&amp;gbraid=0AAAAAC0fKmo3CzAuxD-J1yoRRbolpI2DZ&amp;gclid=Cj0KCQjwv-LOBhCdARIsAM5hdKcg5cAclxuhMymQNu4C1OJatpQNdVIzGz6d1fO_sjighYg9ce0Pfi8aApUKEALw_wcB">SonarQube</a> exposes security issues, and a server from <a href="https://www.multiplayer.app/docs/ai/mcp-server/">Multiplayer</a> returns user session data.</p>



<p>The great thing about using MCP for these situations is that it avoids the need to put large code chunks in every prompt. Instead, coding context like relevant methods, dependencies, or recent changes can be called at runtime, says <a href="https://www.linkedin.com/in/jvenugopal/">Venugopal Jidigam</a>, head of agentic platform engineering at <a href="https://www.wavemaker.com/">WaveMaker</a>, an agentic development platform. “The MCP server assembles and returns scoped, structured context, which the model then uses to reason and respond accurately,” he says.</p>



<p>Another common context-gathering example is retrieving institutional knowledge. “Instead of hardcoding that knowledge into the model, the agent uses MCP to retrieve relevant documents or data at runtime,” says <a href="https://www.linkedin.com/in/ebrahim-alareqi-1b570048/">Ebrahim Alareqi</a>, principal machine learning engineer at <a href="https://www.incorta.com/">Incorta</a>, a data and analytics platform provider. “This keeps the agent lightweight while still giving it access to enterprise-specific context when needed.”</p>



<p>Others praise MCP for its role in bringing common standards to agentic data retrieval. “MCP provides the plumbing that makes context engineering practical,” says <a href="https://www.linkedin.com/in/gilfeig/">Gil Feig</a>, co-founder and CTO at <a href="https://www.merge.dev/">Merge</a>, an API platform provider. Without standards, teams end up building fragile custom data pipelines that break often, he adds.</p>



<h2 class="wp-block-heading"><a></a>Benefits of using MCP for gathering context</h2>



<p>AI-assisted coding has some challenges. Most notably is a trust issue. The vast majority of developers don’t trust the output of AI coding agents — 96%, according to Sonar’s 2026 <a href="https://www.sonarsource.com/company/press-releases/sonar-data-reveals-critical-verification-gap-in-ai-coding/">State of Code Developer Survey report</a>. A second challenge is increased time spent reviewing and debugging AI-generated code. A late <a href="https://stackoverflow.blog/2025/12/29/developers-remain-willing-but-reluctant-to-use-ai-the-2025-developer-survey-results-are-here/">2025 StackOverflow survey</a> found nearly half of developers report frustration dealing with AI solutions that are “almost right, but not quite”.</p>



<p>Context engineering, as well as the use of MCP for this purpose, could help overcome many of these challenges. Using MCP servers, engineers can automatically append relevant logs or internal data to their prompts, refining LLM processing considerably to avoid irrelevant outputs.</p>



<p>The end result is improved accuracy. “MCP allows systems to dynamically fetch what the model needs, like APIs, databases, files, or domain knowledge,” says <a href="https://www.linkedin.com/in/neeraj-abhyankar-9040141/">Neeraj Abhyankar</a>, VP of data and AI at <a href="https://www.rsystems.com/">R Systems</a>, a digital product engineering company. “This makes prompts leaner, reduces hallucinations, and ensures models operate with task‑relevant context.”</p>



<p>Another huge benefit is better context window management. Using MCP for context engineering can enable more efficient interaction with underlying models. “MCP tools can save you thousands of tokens just by ensuring you’re using the right things,” says Spacelift’s Stout.</p>



<p>Stout specifically highlights the <a href="https://github.com/github/github-mcp-server">GitHub MCP server</a>. “It can now access specific files directly from GitHub and do GitHub searching and all the bells and whistles you expect when referencing GitHub,” he says. “MCP made retrieval from GitHub a million times better.”</p>



<p>Using MCP also enhances autonomy and scalability across an enterprise. “Teams can stop relying on partial views or anecdotal evidence and instead operate from a shared understanding,” says Pendo’s Olson. This greatly reduces the friction typically involved in stitching tools, building reports, or looping in teammates, he says.</p>



<p>All in all, the experts say the benefits of MCP in context engineering are numerous. Standardizing on MCP affords more focused prompts that generate more explicitly and relevant context, decreasing the likelihood of LLM hallucination and optimizing what the agent acts on. This in turn can lessen the manual review required for validation and debugging, reclaiming some developer time in the process.</p>



<p>Together, these benefits aim to solve many of the core issues inherent in <a href="https://www.infoworld.com/article/3844363/why-ai-generated-code-isnt-good-enough-and-how-it-will-get-better.html">AI-generated code</a> and <a href="https://www.infoworld.com/article/4035926/multi-agent-ai-workflows-the-next-evolution-of-ai-coding.html">agentic workflows</a> at large. “MCP shifts AI development from fragile prompt tuning to repeatable engineering,” says WaveMaker’s Jidigam. “The result is consistent behavior, minimal data exposure, and AI systems that can scale.”</p>



<h2 class="wp-block-heading"><a></a>To MCP, or not to MCP</h2>



<p>Experts agree MCP can go beyond <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval augmented generation</a> (RAG) to provide more timely and relevant content in a more optimized fashion. “Traditional knowledge bases and RAG pipelines rely on pre-indexed snapshots,” says Sonar’s Kussberg. “In fast-moving environments, this quickly becomes outdated.”</p>



<p>For this reason and others, MCP unlocks all kinds of possibilities for developers. That said, the protocol is <a href="https://thenewstack.io/when-is-mcp-actually-worth-it/">not a silver bullet</a> for all use cases. It’s up against competing <a href="https://www.infoworld.com/article/4007686/a-developers-guide-to-ai-protocols-mcp-a2a-and-acp.html">agentic protocols</a> for some scenarios, and even simple CLI or direct API access for others.</p>



<p>Ballooning portfolios of MCP servers can <a href="https://www.reddit.com/r/ClaudeAI/comments/1rzz784/mcp_is_costing_you_37_more_tokens_than_necessary/">increase LLM inputs substantially</a>, too, requiring <a href="https://thenewstack.io/how-to-reduce-mcp-token-bloat/">vigilant optimization techniques</a> to avoid hitting token limits. Such strategies include intentionally designing tools, progressive disclosure, automated discovery, and other emerging tactics.</p>



<p>Then, there are <a href="https://thenewstack.io/building-with-mcp-mind-the-security-gaps/">MCP-related security concerns</a>. The security model for the MCP protocol itself has <a href="https://modelcontextprotocol.io/docs/tutorials/security/authorization">matured quite a bit</a>, but it’s incumbent upon implementers to enforce the correct permissions. “MCP, when implemented the right way, lets you enforce policy-driven access controls,” says Merge’s Feig. This should prevent a junior engineer, for instance, from accessing logs they’re not authorized to access, even if the agent has broader permissions, he adds.</p>



<p>To boost confidence using MCP within enterprise development settings, many experts recommend using an <a href="https://www.infoworld.com/article/4145014/how-to-build-an-enterprise-grade-mcp-registry.html">MCP registry</a> that houses vetted, governed MCP servers approved for internal use. Other tools and practices, including <a href="https://www.infoworld.com/article/4115115/visual-studio-code-adds-support-for-agent-skills.html">agent skills</a>, <a href="https://thenewstack.io/port-of-context-the-open-source-code-mode/">code mode</a>, and emerging <a href="https://nordicapis.com/why-ai-agents-need-deterministic-api-workflows/">specifications for deterministic AI</a> also promise to play a role in establishing context for agents.</p>



<p>Beyond MCP itself, Stout recommends using Claude Code’s <a href="https://medium.com/@joe.njenga/claude-code-just-cut-mcp-context-bloat-by-46-9-51k-tokens-down-to-8-5k-with-new-tool-search-ddf9e905f734">tool search feature</a>, which searches for tools without using token windows. He also highlights Sisyphus, an <a href="https://opencode.ai/">OpenCode</a>-compatible agent for matching models with different tasks, and <a href="https://plannotator.ai/">Plannotator</a>, a plugin for Claude Code and OpenCode that can be used to plan projects, both of which can aid optimization.</p>



<h2 class="wp-block-heading">Context is king</h2>



<p>The pace of MCP development is accelerating. Analysis of 1,400 MCP servers by <a href="https://bloomberry.com/blog/we-analyzed-1400-mcp-servers-heres-what-we-learned/">Bloomberry</a> charted a 232% increase in six months, from August 2025 to February 2026. Interestingly, read operations outpaced write operations two to one, indicating these servers are performing a significant amount of data retrieval.</p>



<p>Looking to the future, context engineering is anticipated to continue cementing itself as a software discipline, while MCP wields the power to transform APIs into engines for agentic reasoning. As Jidigam says, “MCP-like abstractions will become standard infrastructure, much like REST did in earlier eras.”</p>



<p>Others are similarly confident. “In context engineering, MCP becomes the control plane agents use to access context, tools, and actions,” adds Incorta’s Alareqi. “It will be foundational as software becomes increasingly agent-driven.”</p>



<p>The underlying takeaway: MCP already plays a large role in context engineering, and will continue to do so. As the standard interface between AI systems and data, MCP is the primary vessel for dynamic cross-platform context retrieval at run time, allowing engineers to fetch documentation, API references, policies, available actions, and more.</p>



<p>However, this doesn’t mean context engineering has reached its zenith. Looking ahead, context engineering will evolve from fetching information to coordinating it, says Kussberg, combining multiple MCPs along the way. This will require increased discipline in enforcing standards, assessing risks, and validating changes more often, he says.</p>



<p>So, get started with context engineering using MCP, and stay alert to how your MCP servers are impacting LLM token usage and shaping workflows. The difference between context and non-context matters. Because, as they say, context is king.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacStories Weekly: Issue 514]]></title>
<description><![CDATA[This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:Antinote, by JonathanIt's All Just Software, by JohnObsidian into Claude and App Quality, by Jonathan
	
						This Story is for Club Members

				Get weekly newsletters, exclusive stories, member...]]></description>
<link>https://tsecurity.de/de/3540364/ios-mac-os/macstories-weekly-issue-514/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540364/ios-mac-os/macstories-weekly-issue-514/</guid>
<pubDate>Fri, 22 May 2026 19:23:25 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<nav class="ms-issue-toc"><p>This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:</p><ul><li><a href="https://www.macstories.net/club/macstories-weekly-issue-514/#antinote" class="ms-issue-toc-item">Antinote, by Jonathan</a></li><li><a href="https://www.macstories.net/club/macstories-weekly-issue-514/#its-all-just-software" class="ms-issue-toc-item">It's All Just Software, by John</a></li><li><a href="https://www.macstories.net/club/macstories-weekly-issue-514/#obsidian-into-claude-and-app-quality" class="ms-issue-toc-item">Obsidian into Claude and App Quality, by Jonathan</a></li></ul></nav>
	<div class="club-notice-restricted plan-">
						<h2>This Story is for Club Members</h2>

				<p>Get weekly newsletters, exclusive stories, member downloads, and ad-free version of MacStories Unwind.</p>
				<p><br><a href="https://www.macstories.net/plans?utm_source=ms&amp;utm_medium=web" class="button">See Plans</a></p>

									 

					<p>Already a member? <a href="https://www.macstories.net/?memberful_endpoint=auth">Sign in</a></p>
								</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linkdump 21/2026]]></title>
<description><![CDATA[Viel Spass bei den von mir als lesenswert empfundenen Links auf Artikel, die ich in der vergangenen Woche gelesen habe.

Gute Frage, vor allem, was die benutzbaren Alternativen sind (auch in die Kommentare schauen): Ist Bitwarden noch vertrauenswürdig?.

Eigenen Podcatcher hosten mit Audiobookshe...]]></description>
<link>https://tsecurity.de/de/3538300/it-nachrichten/linkdump-212026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538300/it-nachrichten/linkdump-212026/</guid>
<pubDate>Fri, 22 May 2026 06:17:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Viel Spass bei den von mir als lesenswert empfundenen Links auf Artikel, die ich in der vergangenen Woche gelesen habe.<br>
<br>
Gute Frage, vor allem, was die benutzbaren Alternativen sind (auch in die Kommentare schauen): <a href="https://linuxnews.de/ist-bitwarden-noch-vertrauenswuerdig/">Ist Bitwarden noch vertrauenswürdig?</a>.<br>
<br>
<a href="https://2tap2.be/podcatcher-hosten/">Eigenen Podcatcher hosten mit Audiobookshelf, Docker und Traefik</a>, für mich sehe ich da keinen Mehrwert, finde die Idee aber prima.<br>
<br>
Ich mag Artikel, in denen Menschen ihre Setups teilen: <a href="https://notelab.hypotheses.org/3803">Sicherer, unabhängiger, fokussierter: Warum ich für meine Wissensarbeit auf Ubuntu, GrapheneOS und Obsidian setze und du es auch kannst</a>.<br>
<br>
<a href="https://www.svenja-hofert.de/karriere-zukunft/">Karriere der Zukunft: So ändert sich Karriere im KI-Zeit­alter</a> – KI ist natürlich ein guter Anlass für einen Artikel. Kaum jemand arbeitet heute in dem Job, den er oder sie gelernt hat.]]></content:encoded>
</item>
<item>
<title><![CDATA[10 Android Circle to Search superpowers you probably never noticed]]></title>
<description><![CDATA[With Google’s annual I/O gala in full force this week, Gemini and AI are taking center stage and being presented as the future of practically everything.



Here in the land of Android, though, Gemini’s been quietly competing for attention with another relatively youthful on-demand assistant — an...]]></description>
<link>https://tsecurity.de/de/3532712/it-nachrichten/10-android-circle-to-search-superpowers-you-probably-never-noticed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3532712/it-nachrichten/10-android-circle-to-search-superpowers-you-probably-never-noticed/</guid>
<pubDate>Wed, 20 May 2026 13:17:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With Google’s annual I/O gala in full force this week, Gemini and AI are <a href="https://blog.google/innovation-and-ai/sundar-pichai-io-2026/" target="_blank" rel="noreferrer noopener">taking center stage</a> and being presented as <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/" target="_blank" rel="noreferrer noopener">the future of practically everything</a>.</p>



<p>Here in the land of Android, though, Gemini’s been quietly competing for attention with <em>another</em> relatively youthful on-demand assistant — and that’s a far <a href="https://www.computerworld.com/article/2117752/google-gemini-ai.html">less in-your-face feature</a> called <a href="https://www.computerworld.com/article/1611879/androids-circle-to-search-is-deja-vu-all-over-again.html">Circle to Search</a>.</p>



<p>Circle to Search is essentially an instant portal to the even <em>less</em> widely known <a href="https://www.computerworld.com/article/1635589/google-lens-android.html">Android Google Lens setup</a>, which has been serving up <a href="https://www.computerworld.com/article/1635589/google-lens-android.html">genuinely practical real-world advantages</a> for Android device-owners in the know for <em>years</em> now — since way back before the word “Gemini” had <em>any </em>Googley meaning.</p>



<p>And whether you also adore Gemini or find it to be <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">more hype than help</a>, it’s well worth your while to dig into Circle to Search — or maybe just revisit its potential, if you’d perhaps explored it briefly early on and then forgotten about it — to see what it can do for you.</p>



<p>Here, specifically, are 10 simple but supremely useful ways Circle to Search can make your day-to-day life easier without allowing any Gemini AI avalanches to overtake you.</p>



<p><strong>[Psst: Want even more practical Android knowledge? </strong><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong>Check out my free Android Intelligence newsletter</strong></a><strong> for three new things to try every Friday and my Android Notification Power-Pack today!]</strong></p>



<h2 class="wp-block-heading"><strong>Circle to Search 101</strong></h2>



<p>Real quick, first, a fast primer on where Circle to Search lives and how <em>you</em> can access it:</p>



<p>At this point, Circle to Search is available on a bunch of Android devices beyond just the latest high-end flagships. But it isn’t available everywhere. And there’s no clear, up-to-date list of exactly which devices have it and which still don’t.</p>



<p>To see if it’s present on <em>your </em>current phone, try going into your system settings and searching for the word <strong>circle</strong>. If you see “Circle to Search” show up as an option, tap it and then make sure the toggle next to the “Circle to Search” line is in in the on and active position.</p>



<p>Then, to summon Circle to Search, press and hold the bottom-center area of your screen — either the thin navigation bar line, if you’re using the current <a href="https://www.computerworld.com/article/1658581/android-gestures.html">Android navigation gestures</a>, or the Home button, if you’re still stickin’ with the old legacy three-button nav approach — and you should see an overlay appear on top of whatever else you were viewing with a Google logo at its top and a search bar at its bottom.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-overlay.jpg?quality=50&amp;strip=all&amp;w=1001" alt="Google Android Circle to Search" class="wp-image-4173382" width="1001" height="1024" sizes="auto, (max-width: 1001px) 100vw, 1001px"><figcaption class="wp-element-caption">Google’s Circle to Search in action, atop a regular ol’ Android browser window.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>From there, you can use your favorite fingie to circle any image, text, or broad area on your screen to highlight it. You can also <em>tap </em>any area to select it (and then have the opportunity to refine your selection) or <em>scribble </em>over any area to mark it, too.</p>



<p>And whatever you select will become the subject of a search for additional info.</p>



<p>If you <em>don’t</em> seem to have Circle to Search available on your device, <a href="https://play.google.com/store/apps/details?id=com.google.ar.lens&amp;hl=en_US" target="_blank" rel="noreferrer noopener">download the Google Lens Android app</a> — then try <a href="https://theintelligence.com/27912/android-save-screenshot/" target="_blank" rel="noreferrer noopener">taking a screenshot</a> of anything in front of you and sharing it directly into the Lens app. It won’t feel quite as interactive or instantaneous as what you’d get with Circle to Search present, but you’ll be able to accomplish most of the same feats we’re about to go over in that environment, with just a couple of extra steps needed to get there.</p>



<p>Capisce? Capisce. Now, let’s get to the good stuff.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #1: Instant searching</strong></h2>



<p>As I often say, it’s the simplest stuff that frequently proves to be the most useful. For all the complex feats Gemini may be able to perform (at least in theory), the action I actually find myself relying on more than anything is the refreshingly routine ability of Circle to Search to look up any word or phrase on my screen, anytime, and give me more information about it — without interrupting anything I’m doing or forcing me to switch apps.</p>



<p>That might mean coughing up a quick definition, at the simplest possible level. Or it might mean dousing me with details about a person, place, or product I’ve seen within an email, a web page, a document, you name it.</p>



<p>Whatever the case may be, all I’ve gotta do is summon Circle to Search from wherever I happen to be on my device at that moment, tap my finger onto the term in question, and boom: I’ve got the info I need right in front of me — no complicated commands, frustrating back-and-forth dialogue, or effort-wasting app switching required.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-text-search.jpg?quality=50&amp;strip=all&amp;w=1014" alt="Android Circle to Search: Text search" class="wp-image-4173380" width="1014" height="1024" sizes="auto, (max-width: 1014px) 100vw, 1014px"><figcaption class="wp-element-caption">Circle to Search makes it seamless to search for anything, anytime — even lowly tech writers.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Easy peasy, no? And there’s lots more where that came from.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #2: Fast text actions</strong></h2>



<p>In addition to surfacing basic info, Circle to Search can help you take a variety of <em>actions </em>on text you highlight with just one more tap and no awkward multistep pasting or other clunky mechanics.</p>



<p>The next time you see a phone number you want to call, text, or save to your contacts; an email address you want to save or send a message to; a <em>physical</em> address you want to look up or navigate to; or a URL you want to open when it isn’t set to be a tappable link on its own, call up Circle to Search and tap the text in question.</p>



<p><br>So long as the item is the only text selected, Circle to Search should recognize its format and offer up the logical associated action for you to caress next.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-text-actions.webp" alt="Android Circle to Search: Text actions" class="wp-image-4173379" width="800" height="845" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption">Take actions on text in a snap by summoning Circle to Search first.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Speaking of which…</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #3: Quick copy</strong></h2>



<p>Back to the idea of simplicity, one of the ways I find Circle to Search to be most useful is in its ability to let me copy text from anything, anytime — even when it isn’t text you could typically copy.</p>



<p>From phrases in my Android settings to words appearing within images, Circle to Search converts everything it sees into standard copy-ready dialog, and it takes just one tap on anything to highlight it in that environment and then beam it to your <a href="https://www.computerworld.com/article/1616932/android-clipboard-tricks.html">Android system clipboard</a> from there.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-text-select.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android Circle to Search: Text copy" class="wp-image-4173377" width="1024" height="530" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">You can copy <em>anything </em>with Circle to Search active — even if it’s in area where copying normally isn’t possible.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And, of course, with <a href="https://www.computerworld.com/article/4161538/sync-android-computer-clipboards.html">the right sort of setup</a> — like a recently released <a href="https://theintelligence.com/43092/share-android-computer/" target="_blank" rel="noreferrer noopener">third-party service that works wonders in this area</a> — it takes shockingly little effort to send something from there onward toward your <em>computer’s</em> clipboard for desktop-level use as well.</p>



<p>I can’t tell you how often this comes in handy.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #4: Image identifying</strong></h2>



<p>Text aside, Circle to Search integrates the <a href="https://www.computerworld.com/article/1635589/google-lens-android.html#:~:text=Google%20Lens%20trick%20%238%3A%20Search%20for%20similar%20visuals">long-Lens-offered ability</a> to identify any image in front of ye and then allow you to interact with it in all sorts of interesting ways.</p>



<p>This can range from telling you the name of a person, place, or product to giving you specific identifying info for a plant, flower, tree, animal, or even type of screw or computer component.</p>



<p>Just tap or circle any image on your screen — whether it’s in a web page, an email, a document, or anywhere else imaginable — and you’ll see the results right away.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-image-identify.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android Circle to Search: Image search" class="wp-image-4173381" width="1024" height="990" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">You’ll be a full-fledged image-analyzing gumshoe with Circle to Search at your side.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And from there…</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #5: Deeper context</strong></h2>



<p>Once you’ve gotten an initial result from Circle to Search — with an image, with text, or with most anything you’ve highlighted and selected — you can tap the microphone icon at the bottom of the Circle to Search popup and ask <em>additional </em>questions.</p>



<p>Depending on what you’re seeing and what you want to know, the possibilities are practically endless:</p>



<ul class="wp-block-list">
<li>Can you use this word in a sentence?</li>



<li>Where can I find this?</li>



<li>How much does this cost?</li>
</ul>



<p>You get the idea. And while we’re thinking about products…</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #6: Intelligent comparisons</strong></h2>



<p>The next time you see something that strikes your interest anywhere in your Android adventures — be it a new phone within an image somewhere, some software or service mentioned in an email, or whatever else the case may — fire up Circle to Search, select the thing you’re ogling, and then use the Circle to Search search prompt or microphone icon to ask for comparisons:</p>



<ul class="wp-block-list">
<li>How does this phone compare to the Pixel 9?</li>



<li>Does this cost more or less than a MacBook Pro?</li>



<li>Is this app basically like Notion?</li>
</ul>



<p>Once you’ve selected something, all you’ve gotta do is ask.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #7: Split smarts</strong></h2>



<p>Speaking of comparisons, here’s a really cool Circle to Search trick few mere mortals realize is possible:</p>



<p>You can <a href="https://www.computerworld.com/article/3810786/android-split-screen-tricks.html">start up a split-screen</a> of any two apps together, side by side, then activate Circle to Search and use it to analyze things <em>across the two processes</em>.</p>



<p>Let’s all summon our strongest inner Keanus and say it together now: <em>Whoaaaa…..</em></p>



<p>And — oh, yes — there’s more yet.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #8: Your translation station</strong></h2>



<p>When the need to translate <em>anything </em>between languages arises, skip your usual multistep process and just summon Circle to Search instead. Tap the translate icon — the “A” inside a circle, at the right end of the bottom-of-screen search bar — and you can then select any two languages and have <em>everything</em> on your screen translated on the fly.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-translate.webp" alt="Android Circle to Search: Translate" class="wp-image-4173378" width="800" height="839" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption">Instant translations, Circle-to-Search-style — <em>pas mal</em>, eh?!</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>If you tap the icon that appears next to the “A” — the one showing a hand alongside an upward-pointing arrow — you can keep the instant translation mode active as you scroll around and even move between apps.</p>



<p>That, suffice it to say, is <em>insanely </em>powerful.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #9: Zoom without borders</strong></h2>



<p>Back to simplicity again, one surprising way Circle to Search can be helpful is by unlocking the ability to zoom into anything, anytime — even when it’s part of an area that you can’t ordinarily enlarge.</p>



<p>Press and hold that bottom-center area of your device’s display, then just pinch two fingers apart or together. You’ll be able to zoom in, no matter where you are or what you’re viewing.</p>



<p>And finally…</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #10: Song Search, Circle-style</strong></h2>



<p>All right, so this last Circle to Search superpower isn’t <em>exactly</em> productivity-related. But it <em>is </em>useful, in the right sort of scenario. (And sometimes, you need to satisfy a non-work-related itch before you can get back to Getting Stuff Done™!)</p>



<p>When you’re hearing a song and scratching your head as to what it’s called or who sings it, Circle to Search can actually activate <a href="https://theintelligence.com/40094/song-search-android/" target="_blank" rel="noreferrer noopener">Android’s excellent Song Search system</a> and show you that answer.</p>



<p>Just activate Circle to Search, no matter what else you’re doing, and tap the music note icon in that search bar at the bottom of the screen. (For fair warning, the correct answer is always <a href="https://www.youtube.com/menatwork" target="_blank" rel="noreferrer noopener">Men at Work</a>.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-song-search.gif" alt="Android Circle to Search: Song Search" class="wp-image-4173383" width="800" height="843" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption">No more song mysteries, thanks to Circle to Search’s convenient Song Search shortcut.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Good to know, no? And, just like everything else on this page, all this sorcery is never more than a tap away — without the need for any manner of Gemini-scented AI chicanery.</p>



<p>All <em>you’ve</em> gotta do is remember.</p>



<p><em>Remember to </em><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong><em>sign up for my free Android Intelligence newsletter</em></strong></a><em>, if you haven’t already, to get three new things to try in your inbox every Friday.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[EnterpriseClaw wants to bring governance to the OpenClaw era]]></title>
<description><![CDATA[Autonomous agent orchestration tool OpenClaw hit the scene last November and immediately went viral, but its dramatic flaws were exposed just as quickly.



Still, it marked a pivotal step in the agentic AI era, and enterprises have been exploring ways to deploy fleets of autonomous agents safely...]]></description>
<link>https://tsecurity.de/de/3531267/it-nachrichten/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531267/it-nachrichten/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era/</guid>
<pubDate>Wed, 20 May 2026 04:02:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Autonomous agent orchestration tool OpenClaw hit the scene last November and immediately went viral, but its dramatic flaws were <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">exposed just as quickly</a>.</p>



<p>Still, it marked a pivotal step in the agentic AI era, and enterprises have been exploring ways to deploy fleets of autonomous agents safely and securely ever since.</p>



<p>Automation Anywhere Tuesday rolled out its answer to this challenge, EnterpriseClaw, created in collaboration with Cisco, Nvidia, Okta, and OpenAI.</p>



<p>The company says the platform will enable companies to deploy autonomous AI agents across their desktops, cloud platforms, secured ‘behind-the-firewall’ networks, and on-premises systems, all while maintaining centralized control, access, and observability.</p>



<h2 class="wp-block-heading">Automates business-critical work</h2>



<p>EnterpriseClaw is built on Automation Anywhere’s Process Reasoning Engine (PRE) and Contextual Intelligence Graph, which automate business-critical work. It also integrates with Cisco AI Defense and DefenseClaw to provide security purpose-built for AI agents, Nvidia’s open-source runtime OpenShell, NIM microservices and Nemotron models for on-premises customers, and Okta’s cross-agent identity management and authentication controls. Furthermore, OpenClaw’s <a href="https://www.infoworld.com/article/4132731/openai-hires-openclaw-founder-as-ai-agent-race-intensifies-2.html" target="_blank">OpenAI</a> collaboration will give customers access to leading models like GPT-5.5.</p>



<p>“The level of distrust and insecurity associated with OpenClaw is covered in significant detail in the EnterpriseClaw launch,” said <a href="https://www.infotech.com/profiles/manish-jain" target="_blank" rel="noreferrer noopener">Manish Jain</a>, a principal research director at Info-Tech Research Group. “The collaboration between Nvidia, OpenAI, Okta, and Cisco adds to the credibility of the proposition of trusted infrastructure, identity, and security layers.”</p>



<p>Automation Anywhere says the platform will give enterprises the ability to deploy agents in parallel in managed containers behind firewalls, providing local access to files, apps, browsers, and terminals. Agents can hand off tasks and combine outputs so that value “compounds” rather than being isolated and confined to single-agent tasks, the company said.</p>



<p>Users can set policies, access controls, guardrails, and agent credentials, which are all enforced locally on-device, and receive information on telemetry, audit logs, and large language model (LLM) usage.</p>



<p>The company pointed to use cases like claims investigation: AI agents can gather information across desktop apps, internal documents, on-premises systems, and cloud platforms, all while keeping financial, operational, and other sensitive data secured inside enterprise systems. Other usage scenarios include code generation and debugging, local file post-incident log analysis, research, user interface (UI) automation, and secure data processing in regulated environments.</p>



<p>EnterpriseClaw is now available in preview, with general availability expected later this year.</p>



<h2 class="wp-block-heading">No clear differentiator</h2>



<p>Still, there’s no clear-cut differentiator here, noted <a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, a VP and principal analyst with Moor Insights &amp; Strategy. Nvidia has already announced its <a href="https://www.cio.com/article/4146545/nvidia-nemoclaw-promises-to-run-openclaw-agents-securely.html" target="_blank">NemoClaw</a> open-source stack to provide guardrails for always-on agents, and EnterpriseClaw has essentially the same capabilities and generally-available stack.</p>



<p>“Which begs the question: If you are already using Nvidia’s, why choose this?” he asked. Indeed, the Cisco and Okta capabilities will “likely be interesting” to their existing bases. “But again, those products already work with other tools,” Andersen pointed out.</p>



<h2 class="wp-block-heading">OpenClaw-like agents changing everything</h2>



<p>Ultimately, noted technology analyst <a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">OpenClaw’s arrival</a> has changed enterprise leaders’ view of AI, because it turned what was previously just a concept of AI agents into an everyday-accessible tool for a mass audience.</p>



<p>“As ChatGPT took chatbots out of the lab and drove them into mainstream use, OpenClaw did the same for AI agents,” he said. It shifted the notion of AI from something we chat with to something that actually gets work done. This represents “a key step in replacing human capital with technological capital.”</p>



<p>Info-Tech’s Jain explained that <a href="https://www.pcworld.com/article/3068842/whats-behind-the-openclaw-ban-wave.html" target="_blank">OpenClaw</a> provided AI with three key features: Local execution via a desktop or laptop, persistent autonomy (operation without human input), and direct control over various systems such as WhatsApp or Slack.</p>



<p>“In effect, OpenClaw gave its agents claws (hands), allowing them to run in the background continuously,” he said. They can then execute real-world actions across file systems, web browsers, and applications based on a “single thread” of chat messaging.</p>



<p>But when claw agents quickly began leaking information about user data, there was a “polarization of emotions,” with users both excited and shocked about what they could do and access, he pointed out.</p>



<p>“<a href="https://www.infoworld.com/article/4153975/understanding-the-risks-of-openclaw.html" target="_blank">OpenClaw</a> did not meet enterprise-grade product standards,” said Jain. “The data leaks and inappropriate behaviors associated with claw agents exhibit how an uncontrolled tool, when introduced with no guardrails, will lead to massive issues.”</p>



<p>While Automation Anywhere is deploying EnterpriseClaw in partnership with a group of credible companies, that is just one side of the story; enterprises must govern all AI agents as “persistent digital actors without conscience,” he noted.</p>



<p>Moor’s Andersen also pointed out that OpenClaw can be run on many different models, essentially as a client and a server. But this means there are no real governance capabilities available, “so it’s kind of a wild west, which is why we are seeing companies create these enterprise offerings,” he said.</p>



<h2 class="wp-block-heading">Claw agents ‘amazing,’ but enterprises beware</h2>



<p>What resonates most about OpenClaw is that it can be run alongside open-source AI models like Gemma on a local machine, and users don’t have to pay for or worry about data, Andersen pointed out. This is a direct response to other wildly popular but more expensive tools like Claude Cowork; the latter is “amazing,” but “somewhat addictive,” so users can easily burn through the lowest-cost $20 a month usage credit option.</p>



<p>Tools like OpenClaw are “pretty great” when you have many tasks running in parallel, Andersen noted. For instance, in a marketing campaign, agents can check sales volumes and generate new content at the same time.</p>



<p>Levy added that agents could potentially replace “the human worker-bee” altogether, handling the minutiae of day-to-day work.</p>



<p>Helpdesk workflows are “particularly aligned” with the capabilities of OpenClaw-like agents, he pointed out, as the agents can autonomously manage and close tickets. Or, in administrative work, they can take on repetitive, low-risk and high-return tasks like scheduling meetings, drafting email messages, and managing follow-ups. In software development, vibe-coding agents can efficiently generate large volumes of code for diverse projects. </p>



<p>“Is the code any good? The verdict is still out on that, but it’s clear that OpenClaw-like agents are already rapidly tilting the coding landscape in favour of automation,” said Levy.</p>



<p>Still, agents need a lot of permissions to live up to expectations, which can introduce “unnecessary or unacceptable” levels of risk, he noted. Builders will need to grant sufficient access to maintain productivity, but not so much that they set the stage for an “AI-powered debacle” down the road.</p>



<p>Enterprises also run the risk of AI-fed data leakage, likely from opportunistic agents accessing sensitive data from multiple sources and sharing it beyond originally intended purposes, Levy said. Agents are subject to “AI-ified cybersecurity risks,” such as prompt injection and instruction attacks that use hidden text in documents to autonomously execute remote commands.</p>



<p>Another issue is explainability; particularly in regulated industries, enterprises must be able to show traceability and justify why a certain action was taken and who signed off on it. Additionally, “longer-term reliance at this level will inevitably erode institutional knowledge as the human workers who originally crafted it are replaced by automation,” Levy cautioned.</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4173405/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era.html" target="_blank">CIO.com</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[EnterpriseClaw wants to bring governance to the OpenClaw era]]></title>
<description><![CDATA[Autonomous agent orchestration tool OpenClaw hit the scene last November and immediately went viral, but its dramatic flaws were exposed just as quickly.



Still, it marked a pivotal step in the agentic AI era, and enterprises have been exploring ways to deploy fleets of autonomous agents safely...]]></description>
<link>https://tsecurity.de/de/3531256/it-nachrichten/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531256/it-nachrichten/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era/</guid>
<pubDate>Wed, 20 May 2026 03:32:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Autonomous agent orchestration tool OpenClaw hit the scene last November and immediately went viral, but its dramatic flaws were <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">exposed just as quickly</a>.</p>



<p>Still, it marked a pivotal step in the agentic AI era, and enterprises have been exploring ways to deploy fleets of autonomous agents safely and securely ever since.</p>



<p>Automation Anywhere Tuesday rolled out its answer to this challenge, EnterpriseClaw, created in collaboration with Cisco, Nvidia, Okta, and OpenAI.</p>



<p>The company says the platform will enable companies to deploy autonomous AI agents across their desktops, cloud platforms, secured ‘behind-the-firewall’ networks, and on-premises systems, all while maintaining centralized control, access, and observability.</p>



<h2 class="wp-block-heading">Automates business-critical work</h2>



<p>EnterpriseClaw is built on Automation Anywhere’s Process Reasoning Engine (PRE) and Contextual Intelligence Graph, which automate business-critical work. It also integrates with Cisco AI Defense and DefenseClaw to provide security purpose-built for AI agents, Nvidia’s open-source runtime OpenShell, NIM microservices and Nemotron models for on-premises customers, and Okta’s cross-agent identity management and authentication controls. Furthermore, OpenClaw’s <a href="https://www.infoworld.com/article/4132731/openai-hires-openclaw-founder-as-ai-agent-race-intensifies-2.html" target="_blank">OpenAI</a> collaboration will give customers access to leading models like GPT-5.5.</p>



<p>“The level of distrust and insecurity associated with OpenClaw is covered in significant detail in the EnterpriseClaw launch,” said <a href="https://www.infotech.com/profiles/manish-jain" target="_blank" rel="nofollow">Manish Jain</a>, a principal research director at Info-Tech Research Group. “The collaboration between Nvidia, OpenAI, Okta, and Cisco adds to the credibility of the proposition of trusted infrastructure, identity, and security layers.”</p>



<p>Automation Anywhere says the platform will give enterprises the ability to deploy agents in parallel in managed containers behind firewalls, providing local access to files, apps, browsers, and terminals. Agents can hand off tasks and combine outputs so that value “compounds” rather than being isolated and confined to single-agent tasks, the company said.</p>



<p>Users can set policies, access controls, guardrails, and agent credentials, which are all enforced locally on-device, and receive information on telemetry, audit logs, and large language model (LLM) usage.</p>



<p>The company pointed to use cases like claims investigation: AI agents can gather information across desktop apps, internal documents, on-premises systems, and cloud platforms, all while keeping financial, operational, and other sensitive data secured inside enterprise systems. Other usage scenarios include code generation and debugging, local file post-incident log analysis, research, user interface (UI) automation, and secure data processing in regulated environments.</p>



<p>EnterpriseClaw is now available in preview, with general availability expected later this year.</p>



<h2 class="wp-block-heading">No clear differentiator</h2>



<p>Still, there’s no clear-cut differentiator here, noted <a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="nofollow">Jason Andersen</a>, a VP and principal analyst with Moor Insights &amp; Strategy. Nvidia has already announced its <a href="https://www.cio.com/article/4146545/nvidia-nemoclaw-promises-to-run-openclaw-agents-securely.html" target="_blank">NemoClaw</a> open-source stack to provide guardrails for always-on agents, and EnterpriseClaw has essentially the same capabilities and generally-available stack.</p>



<p>“Which begs the question: If you are already using Nvidia’s, why choose this?” he asked. Indeed, the Cisco and Okta capabilities will “likely be interesting” to their existing bases. “But again, those products already work with other tools,” Andersen pointed out.</p>



<h2 class="wp-block-heading">OpenClaw-like agents changing everything</h2>



<p>Ultimately, noted technology analyst <a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="nofollow">Carmi Levy</a>, <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">OpenClaw’s arrival</a> has changed enterprise leaders’ view of AI, because it turned what was previously just a concept of AI agents into an everyday-accessible tool for a mass audience.</p>



<p>“As ChatGPT took chatbots out of the lab and drove them into mainstream use, OpenClaw did the same for AI agents,” he said. It shifted the notion of AI from something we chat with to something that actually gets work done. This represents “a key step in replacing human capital with technological capital.”</p>



<p>Info-Tech’s Jain explained that <a href="https://www.pcworld.com/article/3068842/whats-behind-the-openclaw-ban-wave.html" target="_blank">OpenClaw</a> provided AI with three key features: Local execution via a desktop or laptop, persistent autonomy (operation without human input), and direct control over various systems such as WhatsApp or Slack.</p>



<p>“In effect, OpenClaw gave its agents claws (hands), allowing them to run in the background continuously,” he said. They can then execute real-world actions across file systems, web browsers, and applications based on a “single thread” of chat messaging.</p>



<p>But when claw agents quickly began leaking information about user data, there was a “polarization of emotions,” with users both excited and shocked about what they could do and access, he pointed out.</p>



<p>“<a href="https://www.infoworld.com/article/4153975/understanding-the-risks-of-openclaw.html" target="_blank">OpenClaw</a> did not meet enterprise-grade product standards,” said Jain. “The data leaks and inappropriate behaviors associated with claw agents exhibit how an uncontrolled tool, when introduced with no guardrails, will lead to massive issues.”</p>



<p>While Automation Anywhere is deploying EnterpriseClaw in partnership with a group of credible companies, that is just one side of the story; enterprises must govern all AI agents as “persistent digital actors without conscience,” he noted.</p>



<p>Moor’s Andersen also pointed out that OpenClaw can be run on many different models, essentially as a client and a server. But this means there are no real governance capabilities available, “so it’s kind of a wild west, which is why we are seeing companies create these enterprise offerings,” he said.</p>



<h2 class="wp-block-heading">Claw agents ‘amazing,’ but enterprises beware</h2>



<p>What resonates most about OpenClaw is that it can be run alongside open-source AI models like Gemma on a local machine, and users don’t have to pay for or worry about data, Andersen pointed out. This is a direct response to other wildly popular but more expensive tools like Claude Cowork; the latter is “amazing,” but “somewhat addictive,” so users can easily burn through the lowest-cost $20 a month usage credit option.</p>



<p>Tools like OpenClaw are “pretty great” when you have many tasks running in parallel, Andersen noted. For instance, in a marketing campaign, agents can check sales volumes and generate new content at the same time.</p>



<p>Levy added that agents could potentially replace “the human worker-bee” altogether, handling the minutiae of day-to-day work.</p>



<p>Helpdesk workflows are “particularly aligned” with the capabilities of OpenClaw-like agents, he pointed out, as the agents can autonomously manage and close tickets. Or, in administrative work, they can take on repetitive, low-risk and high-return tasks like scheduling meetings, drafting email messages, and managing follow-ups. In software development, vibe-coding agents can efficiently generate large volumes of code for diverse projects. </p>



<p>“Is the code any good? The verdict is still out on that, but it’s clear that OpenClaw-like agents are already rapidly tilting the coding landscape in favour of automation,” said Levy.</p>



<p>Still, agents need a lot of permissions to live up to expectations, which can introduce “unnecessary or unacceptable” levels of risk, he noted. Builders will need to grant sufficient access to maintain productivity, but not so much that they set the stage for an “AI-powered debacle” down the road.</p>



<p>Enterprises also run the risk of AI-fed data leakage, likely from opportunistic agents accessing sensitive data from multiple sources and sharing it beyond originally intended purposes, Levy said. Agents are subject to “AI-ified cybersecurity risks,” such as prompt injection and instruction attacks that use hidden text in documents to autonomously execute remote commands.</p>



<p>Another issue is explainability; particularly in regulated industries, enterprises must be able to show traceability and justify why a certain action was taken and who signed off on it. Additionally, “longer-term reliance at this level will inevitably erode institutional knowledge as the human workers who originally crafted it are replaced by automation,” Levy cautioned.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Solving healthcare’s unique security challenges: The role of zero trust and SASE]]></title>
<description><![CDATA[With clinicians and staff accessing patient data from dozens of locations and devices, healthcare’s attack surface has never been larger. The cost of getting security wrong — $9.77 million per breach on average, according to CrowdStrike’s “Healthcare Cybersecurity in 2025: Staying Ahead of Emergi...]]></description>
<link>https://tsecurity.de/de/3529308/it-nachrichten/solving-healthcares-unique-security-challenges-the-role-of-zero-trust-and-sase/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529308/it-nachrichten/solving-healthcares-unique-security-challenges-the-role-of-zero-trust-and-sase/</guid>
<pubDate>Tue, 19 May 2026 15:33:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With clinicians and staff accessing patient data from dozens of locations and devices, healthcare’s attack surface has never been larger. The cost of getting security wrong — $9.77 million per breach on average, according to CrowdStrike’s “Healthcare Cybersecurity in 2025: Staying Ahead of Emerging Threats” report — is the highest of any industry. And the tools most providers rely on, built around a simple block-or-allow logic, weren’t designed for healthcare’s complex, distributed environments.</p>



<p>Health systems need security that goes beyond verifying someone’s identity, evaluating the full context of every access request, and responding with precision. That’s the promise of combining a zero trust security framework with secure access service edge (SASE) technology, which protects patients and data without getting in the way of care delivery.</p>



<h3 class="wp-block-heading"><strong>The challenges facing healthcare security teams</strong></h3>



<p>Healthcare security is uniquely difficult because employees, contractors, and third-party partners access systems from hospital branches, remote clinics, and home offices, often sharing workstations and tapping in and out with RFID badges throughout a shift. Each handoff is a potential vulnerability.<br><br></p>



<p>Shadow AI compounds the problem, with clinicians and researchers adopting AI tools faster than IT can vet them — and uploading protected health information (PHI) to large language models (LLMs)  without realizing the risks. Meanwhile, telehealth appointments and remote radiology have expanded the perimeter far beyond what legacy VPN infrastructure was built to support, introducing latency, bottlenecks, and exploitable gaps. And through it all, budgets remain constrained.</p>



<h3 class="wp-block-heading"><strong>A smarter approach</strong></h3>



<p>Netskope is a leader in modern security and networking for the cloud and AI era, and its Netskope One platform converges SASE and security service edge (SSE) to address these challenges.</p>



<p>Built as one AI-native platform, Netskope brings together secure access, data security, and AI security in a unified architecture designed to protect modern traffic in real time. Legacy security and networking tools often force organizations into trade-offs: more control with more friction, or better performance with less protection. Netskope was built to remove that compromise.</p>



<p>Instead of relying on static or binary permissions, such as blunt block-or-allow rules, the Netskope Zero Trust Engine continuously evaluates real-time risk telemetry for every access request. By analyzing user identity, device posture, location, application risk,  specific instance, and behavior history, the platform enforces precise, adaptive trust policies. It then intelligently applies the exact  level of control required — whether that means allowing, blocking, real-time coaching, isolating the browser session, or prompting for step-up authentication and justification.</p>



<p>Consider a physician who logs into her corporate device, opens ChatGPT using her personal account, and attempts to upload a corporate document to summarize it. A conventional security tool makes a binary call. Netskope sees something richer: her role, her device, the specific instance of the app (personal, not corporate), what she’s trying to do with it, and the sensitivity of the data involved. From there, the platform can prompt her to justify the action and either coach her toward a safer alternative (if justified) or isolate the session (if not justified). This approach provides security guardrails without putting up roadblocks to legitimate activity.</p>



<h3 class="wp-block-heading"><strong>The Netskope difference</strong></h3>



<p>That contextual intelligence applies across these five scenarios, addressing healthcare’s most pressing security challenges:</p>



<ul class="wp-block-list">
<li><strong>Securing AI use:</strong> As staff adopt AI notetaking and research tools, Netskope provides visibility into both managed and unmanaged applications. Rather than blocking AI outright, the platform uses coach-and-pivot features to guide safer behavior. By using data loss prevention (DLP) and AI guardrails, Netskope also evaluates the actual meaning of content and blocks PHI from exposure even if the AI transforms or rewrites the data, keeping clinicians productive and compliant.    </li>



<li><strong>Shared workstations:</strong> In high-turnover environments where multiple users share devices, Netskope integrates with identity providers and leverages its Zero Trust Engine to enforce user-specific policies through every session, from badge-in to log-out. This ensures adaptive, context-aware access, so each employee accesses only what their role permits.</li>



<li><strong>Remote care delivery:</strong> Telehealth and remote radiology require fast, reliable, secure connections. Netskope replaces legacy VPNs with Universal Zero Trust Network Access (UZTNA) via Netskope One Private Access, which provides resilient, high-performance connectivity from any device or location without exposing the broader network.</li>



<li><strong>Seamless user experience:</strong> Netskope’s NewEdge Network is the world’s most performant private cloud infrastructure, purpose-built for speed and resilience. Through innovations like NewEdge AI Fast Path, it delivers full security inspection without the performance trade-offs or latency, minimizing wait times for AI-powered medical applications. This allows clinicians to stay focused on patients.</li>



<li><strong>Any user, device, site, or AI:</strong> Whether someone is a full-time employee at a flagship hospital,  a contractor at a remote clinic, or an autonomous AI agent running in the background, Netskope enforces unified security policies. The Netskope One platform secures both human and non-human interactions, applying consistent protections across every entity, device, and location.</li>
</ul>



<h3 class="wp-block-heading"><strong>Security that enables care</strong></h3>



<p>Healthcare organizations shouldn’t have to choose between security and care delivery. By consolidating networking and security functions into a single SASE platform, they can reduce tool sprawl and lower costs — while giving every clinician, wherever they are, the fast and secure access they need to do their jobs. The key? Making sure the right people can access the right resources, safely, every time.</p>



<p>To learn more about how Netskope secures healthcare organizations, visit us <a href="https://www.netskope.com/solutions/healthcare-and-life-sciences" rel="sponsored">here</a>.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon's Alexa+ Now Produces AI-Generated Podcasts]]></title>
<description><![CDATA[Amazon is adding AI-generated "podcasts" to Alexa+, letting users request custom audio explainers on any topic featuring two synthetic co-hosts. Variety reports: Seemingly to dispel the notion that these "podcasts" will be AI audio slop, Amazon emphasized that it has deals with major news organiz...]]></description>
<link>https://tsecurity.de/de/3528833/it-security-nachrichten/amazons-alexa-now-produces-ai-generated-podcasts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528833/it-security-nachrichten/amazons-alexa-now-produces-ai-generated-podcasts/</guid>
<pubDate>Tue, 19 May 2026 13:07:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon is adding AI-generated "podcasts" to Alexa+, letting users request custom audio explainers on any topic featuring two synthetic co-hosts. Variety reports: Seemingly to dispel the notion that these "podcasts" will be AI audio slop, Amazon emphasized that it has deals with major news organizations to ensure "accurate, real-time news and information." Those include the Associated Press, Reuters, the Washington Post, Time magazine, Forbes, Business Insider, Politico and USA Today; publications from Conde Nast, Hearst and Vox Media; and more than 200 local newspapers across the U.S.
 
In an example clip shared by Amazon of the new Alexa Podcasts feature, the two AI-generated hosts discuss "the latest music releases." A male Alexa+ narrator says more than 50% of music listening now comes from unsigned artists. "The monoculture is just gone," a female-voiced Alexa+ narrator chimes in. The male Alexa+ host says there has been "stoner metal," indie pop and experimental hip-hop music "all dropping on the same Friday," and adds, "That's not chaos -- that's the healthiest the music ecosystem has ever been."
 
[...] To use Alexa Podcasts, users can simply tell Alexa what topic they're curious about and "it does the rest in minutes." Alexa+ will provide an overview of what it plans to cover, and let you adjust the length and direction before it generates the podcast. When your episode is ready, you'll get a notification on your Echo Show device and the Alexa app.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Amazon's+Alexa%2B+Now+Produces+AI-Generated+Podcasts%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F05%2F19%2F0043247%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F05%2F19%2F0043247%2Famazons-alexa-now-produces-ai-generated-podcasts%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/26/05/19/0043247/amazons-alexa-now-produces-ai-generated-podcasts?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Pentester’s Methodology for Toxic Vulnerability Combinations]]></title>
<description><![CDATA[How a Low, a Medium, and a High Compose Into a CriticalSenior pentesters find these toxic combinations the same way every time. A four-phase methodology. Each phase asks one question. This post walks the methodology through a real discovery from an authorized assessment.The Outcome FirstA handful...]]></description>
<link>https://tsecurity.de/de/3528505/hacking/a-pentesters-methodology-for-toxic-vulnerability-combinations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528505/hacking/a-pentesters-methodology-for-toxic-vulnerability-combinations/</guid>
<pubDate>Tue, 19 May 2026 11:23:53 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>How a Low, a Medium, and a High Compose Into a Critical</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ClknjmTwlFdnWaWV9SdxUw.png"></figure><p><em>Senior pentesters find these toxic combinations the same way every time. A four-phase methodology. Each phase asks one question. This post walks the methodology through a real discovery from an authorized assessment.</em></p><h3>The Outcome First</h3><p>A handful of anonymous API calls. One legitimate login at the end, as the victim. Five thousand customer accounts, every one of them reachable. Every password overwritten in a few seconds. Every account logged in to with the credentials the attacker chose. No privilege escalation, no token forgery, no exploit primitive. Every request the chain made was authorized as the attacker, because most of the chain never asked the attacker who they were.</p><p>The scanner that ran against the same application before the engagement reported the underlying findings as separate items. None rated Critical. All sat unremarkably in the triage backlog.</p><p>This post walks through how a pentester gets from those findings to that outcome. The mechanism is a methodology. It does not appear on any scanner’s findings list, but every experienced practitioner uses some version of it, and the structure is consistent enough to teach.</p><p>The methodology has four phases. Each phase asks one specific question of the application. The answers from each phase become inputs to the next. When all four answers connect, you have a <em>toxic combination</em>. Three or four findings whose individual severities understate what they enable when chained. In the engagement walked through here, that combination is one Low, one Medium, and one High that compose into a Critical.</p><p>The four questions:</p><ul><li>[1] <strong>Information Gathering.</strong> <em>What does the application teach me, that I shouldn’t have learned, just by being here?</em></li><li>[2] <strong>Vulnerability Analysis.</strong> <em>Which inputs identify objects, and which of those are not bound to my session?</em></li><li>[3] <strong>Attack Execution.</strong> <em>Does the same identifier I just exfiltrated work on a write endpoint? And was authentication required at all?</em></li><li>[4] <strong>Exploitation.</strong> <em>Can the chain produce a state change the application’s normal threat model would not detect?</em></li></ul><p>Each phase carries a severity rating taken in isolation. None of the individual ratings is Critical. The combination is.</p><p>What follows comes from an authorized assessment. The endpoint paths, request shapes, and overall chain are reproduced from the engagement. The data values (names, emails, profile IDs, hash strings) are synthesized so nothing in this post identifies the assessed application or any real customer. The pattern reported here was filed, escalated, and remediated before the application’s planned sunset.</p><h3>The Starting Position</h3><p>The engagement began the way most do. Pre-test triage produced the usual mix. A few missing security headers, a reflective XSS hint that turned out to be a false positive, a “verbose error message” entry against the login endpoint marked Medium, and a generic “missing headers on JavaScript file” against app.js.</p><p>If I had treated that as a finished list, the engagement would have been a four-paragraph memo. Three findings to acknowledge, one to push back on, sign off, move on. The chain that ended in mass account takeover would have stayed undiscovered.</p><p>I opened the JavaScript file anyway. Not because I expected anything interesting. Reading the bundle is a habit I picked up from senior reviewers years ago. Automated tooling can tell me a file is missing a header. It cannot tell me what the file does.</p><p>Every step of the methodology starts from the lowest-privilege legitimate position the application allows. Not because elevated access is hard to get, but because chains that start from admin tell us nothing about the threat model that matters most. The user the application already trusts. The chain that follows holds against an unauthenticated visitor for the first three phases. The position rises to a legitimate customer login only at the very end, when the chain reaches its outcome.</p><h3>Phase 1: Information Gathering</h3><p><em>What does the application teach me, that I shouldn’t have learned, just by being here?</em></p><p>I never logged in for this phase. Visiting the login page through Burp’s proxy was enough.</p><p>The login page’s HTML loads four obvious script files (main.js, apim-auth.js, env.js, firebase.js) and one less obvious one. A &lt;link rel=”preload” as=”script” href=”/js/app.js”&gt; declaration in the page head causes the browser to issue a GET for /js/app.js during initial page load. This is the kind of tag a webpack build emits when it wants the browser to prefetch a route chunk for the next navigation. Burp captured all five files in the same proxy history sequence, before I had typed a single character into the login form. The fifth file, app.js, is the post-login dashboard’s bundle. Its presence in the proxy history meant the application had already shipped its post-login API catalog to me, an unauthenticated visitor.</p><p>Opening app.js in Burp’s response viewer, the first dozen lines told me everything I needed to know about the API surface I was about to test.</p><pre>// Internal API endpoint catalog (used by build tools, do not remove)<br> // POST /api/login body { email, password }<br> // GET /api/profile?id=N profile by numeric id (admin only)<br> // GET /api/profile/password?id=N legacy reset-lookup (returns salt+hash)<br> // PUT /api/profile/password body { id?, currentPassword?, newPassword }<br> // POST /api/account/info body { userProfileID: N }<br> //<br> // TODO(qa): remove qa.test@acme-portal.local seed account before release.<br> // Leftover from QA cycle. Admin role, used for password-reset regression tests.</pre><p>Three things jump out of the catalog in under five seconds.</p><p>1. <strong>/api/profile?id=N is annotated “admin only”, but it is rendered by the customer dashboard.</strong> Either the comment is wrong, the gate is wrong, or both. Worth probing.</p><p>2. <strong>/api/profile/password GET returns salt+hash.</strong> That phrase belongs in a database row, not an HTTP response body. Worth probing harder.</p><p>3. <strong>PUT /api/profile/password accepts an id in addition to currentPassword.</strong> Optional id. Two execution branches in one endpoint. The branch that takes id cannot also be requiring the current password, otherwise the optional structure makes no sense.</p><p>The TODO comment names a specific email, qa.test@acme-portal.local. The developer who wrote the comment intended to remove the seed account before release. They clearly did not. The seed account also appears to have an admin role.</p><p>I rated this finding Low in isolation. Information disclosure to <em>unauthenticated</em> visitors is a notch worse than disclosure to authenticated users, but the file does not contain credentials, tokens, or directly exploitable data on its own. A reviewer skimming the bundle would tag it “Low, verify, accept the risk if no PII is exposed.” That triage is technically correct. It also prematurely closes the most interesting input the chain ever produces.</p><p>The methodology question for Phase 1 is not “what is the severity of the JS bundle exposure?” The question is <em>what does the application teach me that I shouldn’t have learned just by being here?</em> The answer is an inventory of inputs the developers thought the requester would not see.</p><p>That inventory is the input for Phase 2.</p><h3>Phase 2: Vulnerability Analysis</h3><p><em>Which inputs identify objects, and which of those are not bound to my session?</em></p><p>Phase 2 lives inside the login endpoint, which the application has to expose to unauthenticated visitors by definition. I stayed unauthenticated.</p><p>Before testing the other endpoints from the catalog directly, I tried something the JS bundle made specifically possible. I attempted to log in using qa.test@acme-portal.local, the email left behind in the TODO comment, with a deliberately wrong password. I expected the standard “Invalid credentials” response. What I got was different.</p><pre>POST /api/login HTTP/1.1<br>Content-Type: application/json<br> <br>{"email":"qa.test@acme-portal.local","password":"wrongpass"}</pre><pre>Response:<br>    {<br>     "IsSuccess": false,<br>     "error": "Email exists but password is incorrect",<br>     "email": "qa.test@acme-portal.local",<br>     "userName": "QA Test Account",<br>     "userProfileID": 9999,<br>     "role": "admin"<br>    }</pre><p>The IsSuccess: false field told me authentication failed. Everything below it told me the account exists, that it is named “QA Test Account”, that its profile ID is 9999, and that its role is admin. None of that should be in a failed-login response.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/840/1*M8IqsenVJFcLCvF9H0TRMA.png"><figcaption><strong>Verbose login response leaks PII when the email exists</strong></figcaption></figure><p>I tested the same path against an email I knew was not in the system (noone@nowhere.invalid).</p><pre>{ "IsSuccess": false, "error": "Invalid credentials" }</pre><p>Generic 401, no metadata. The verbose response only fires when the email exists. That is not a verbose error message. That is a user-enumeration oracle. Type any email at the login endpoint and the response shape tells you whether the email is registered. If it is, it also tells you the user’s name, profile ID, and role.</p><p>I confirmed the same shape against a known regular customer.</p><pre>{<br> "IsSuccess": false,<br> "error": "Email exists but password is incorrect",<br> "email": "sarah.thompson@outlook.com",<br> "userName": "Sarah Thompson",<br> "userProfileID": 2,<br> "role": "customer"<br>}</pre><p>The failed-login path leaks email, name, profile ID, and role for any registered email, to an unauthenticated visitor, with no rate limit applied. I rated this Medium in isolation. Verbose-error responses that disclose user metadata land squarely in standard Medium territory, and that rating is the right one to file. What elevates this finding inside the chain is the role field. That field tells the attacker which profile IDs are admin accounts, which becomes the prioritization for Phase 3. The Medium rating is correct. The chain is what makes it dangerous.</p><p>The output of Phase 2 is the data the gap leaks. Numeric profile IDs, and the knowledge that profile ID 9999 holds an admin role. That data is the input for Phase 3.</p><h3>Phase 3: Attack Execution</h3><p><em>Does the same identifier I just exfiltrated work on a write endpoint? And was authentication required at all?</em></p><p>The catalog from Phase 1 listed a curious endpoint.</p><pre>GET /api/profile/password?id=N legacy reset-lookup (returns salt+hash)</pre><p>Why would a password reset endpoint return the salt and hash? In a normal architecture, the reset flow generates a token, emails it, and accepts a new password. The hash never leaves the database. A “legacy reset-lookup” endpoint that returns hash and salt is the kind of thing that exists because some backend developer wrote a JSON wrapper around a legacy SOAP method without thinking about what they were exposing.</p><p>Out of habit, my first probe carried an Authorization header, a Bearer token I had picked up from a separate test session. The endpoint returned 200 with the salt and hash. I made the same call again with the Authorization header removed entirely. Same 200. Same salt and hash.</p><p>The endpoint had not checked the token. The endpoint was not checking authentication at all.</p><pre>GET /api/profile/password?id=2 HTTP/1.1<br>Accept: application/json</pre><pre>Response:<br>    {<br>     "IsSuccess": true,<br>     "userProfileID": 2,<br>     "userName": "Sarah Thompson",<br>     "email": "sarah.thompson@outlook.com",<br>     "role": "customer",<br>     "passwordHash": "A917B980DA07B1051F071DCBD0CDA0BAED53567AEEE5E92B2E4765631ED4FEEF",<br>     "salt": "4329e437404ef2f8"<br>    }</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/840/1*utqDv6csHL0h-xIVkEAZFA.png"><figcaption><strong>Hash and salt returned by the legacy reset-lookup endpoint for any profile id</strong></figcaption></figure><p>No Authorization header. No session cookie. No API key. The endpoint never asked. Hash, salt, email, username, role, all returned to an anonymous caller, for any profile ID that exists.</p><p>This is two authorization failures stacked on the same endpoint. The first is missing authentication entirely. The endpoint accepts requests from anyone on the public internet without checking who is calling. The second is missing object-level authorization. Even if the endpoint did check the caller, it would have no notion of which profile IDs that caller is allowed to read, because the code doesn’t bind the id parameter to any session at all. A scanner would catch neither pattern by itself. It would see a 200 response and move on.</p><p>A senior pentester recognizes the broken-object-level-authorization shape on a credential-bearing endpoint and rates this High. Practical impact is offline credential cracking against any user the attacker can name, with no rate limit and no authentication barrier.</p><p>The methodology pushes one more step before rating. The output of an enumeration step is rarely the data of one record. It is the proof that the enumeration <em>itself</em> works, which means the next step is to scale. I added a second enumeration target, the account/info endpoint that the catalog also listed.</p><pre>POST /api/account/info HTTP/1.1<br>Content-Type: application/json<br> <br>{"userProfileID":3}</pre><pre>Response:<br>    {<br>     "IsSuccess": true,<br>     "userProfileID": 3,<br>     "userName": "Robert Chen",<br>     "email": "robert.chen@yahoo.com",<br>     "policyNumber": "POL-10004"<br>     }</pre><p>Same pattern. No authentication required. No ownership check. The endpoint accepts any profile ID and returns email, username, and policy number. Looped over an incrementing range of profile IDs, this becomes a full customer enumeration in a few seconds. The customer database held close to 5000 records. The loop returned every one of them.</p><p>At this point I had, anonymously:</p><ul><li>A user-enumeration primitive (the verbose login response)</li><li>A salt+hash leak for any profile ID (the GET reset-lookup)</li><li>An email, name, and policy disclosure for any profile ID (the account/info endpoint)</li><li>The knowledge that profile ID 9999 is a leftover admin account</li><li>The original IDOR observation from the catalog comment (“admin only” gate that wasn’t enforced)</li></ul><p>Three independent findings, each of which a triage process would handle separately. The methodology does not let me stop and report yet. Phase 3’s question is not just “did the read work?” It is <em>does the same identifier I just exfiltrated work on a write endpoint?</em></p><p>The catalog listed the answer.</p><pre>PUT /api/profile/password body { id?, currentPassword?, newPassword }</pre><p>Optional id. Optional currentPassword. The shape itself is the bug. There is no execution path where the request both takes an id and requires the current password, because the optional structure does not allow it. The attacker passes the ID and skips the password check entirely.</p><pre>PUT /api/profile/password HTTP/1.1<br>Content-Type: application/json<br> <br>{"id": 2, "newPassword": "pwned!2026"}</pre><pre>Response:<br>{ "message": "Password updated", "userId": "CUST-002" }</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/840/1*wgVZqB75N6b3qtZzd2Cx2w.png"><figcaption><strong>BOLA write: password overwritten with no current-password check</strong></figcaption></figure><p>No Authorization. No current-password challenge. Sarah Thompson’s password rewritten by an anonymous request, using only the profile ID enumerated from Phase 2.</p><p>I rated this High in isolation. Broken Object Level Authorization on the write side, sitting on top of broken authentication on the same endpoint. The read side already established that profile IDs are enumerable. The write side converts that enumeration into account-level state changes. This is the moment the chain becomes practical.</p><h3>Phase 4: Exploitation</h3><p><em>Can the chain produce a state change the application’s normal threat model would not detect?</em></p><p>The previous phases each produced a finding. This phase produces an outcome.</p><p>Phase 4 is the only authenticated request in the chain, and the attacker authenticates as the victim.</p><pre>POST /api/login HTTP/1.1<br>Content-Type: application/json<br> <br>{"email":"sarah.thompson@outlook.com","password":"pwned!2026"}</pre><pre>Response:<br>    {<br>     "IsSuccess": true,<br>     "token": "eyJhbGci…Sarah's customer token…",<br>     "role": "customer",<br>     "name": "Sarah Thompson",<br>     "customerId": "CUST-002"<br>    }</pre><p>I am Sarah Thompson now, as far as the application is concerned. The login endpoint cannot tell me apart from her, because the credential store says I am her.</p><p>Looped across the enumerated profile IDs, this is mass account takeover. Every one of the nearly 5000 customer records was reachable from the chain. There is no impersonation, no token forgery, no privilege escalation. The application’s authentication did its job at the login endpoint, but the application’s authentication never ran at the other endpoints, because those endpoints did not require it. Authorization decisions on the object level (should this requester be allowed to act on this specific record) never happened either.</p><p>I stopped after demonstrating impact on a single account. Exploiting the rest of the enumerable population would have served no purpose for the report.</p><p>That is the asymmetry the methodology exposes. Mass takeover by a “legitimate” login does not look like an attack to most monitoring. It looks like a customer changing their password and logging in with the new password, repeatedly. Detection systems built around “unauthorized access” do not fire, because every request to the chain’s anonymous endpoints returned 200, and every login at the end returned a valid token. Nothing in the audit log says “attack.”</p><h3>The Methodology, Extracted</h3><p>Read backwards from the chain that worked, the methodology has four phases.</p><p>1. <strong>Information Gathering.</strong> <em>What does the application teach me, that I shouldn’t have learned, just by being here?</em></p><p>2. <strong>Vulnerability Analysis.</strong> <em>Which inputs identify objects, and which of those are not bound to my session?</em></p><p>3. <strong>Attack Execution.</strong> <em>Does the same identifier I just exfiltrated work on a write endpoint? And was authentication required at all?</em></p><p>4. <strong>Exploitation.</strong> <em>Can the chain produce a state change the application’s normal threat model would not detect?</em></p><p>Each phase carries a severity rating taken in isolation. None is Critical. The combination is.</p><p>When the four phases are complete, the chain documents into a single table that forces clarity about three things every chain has but reports often muddle. What the attacker learned at this step, what they could do with it, and what the next step needed as input.</p><blockquote>Toxic Vulnerability Combinations: A Pentester’s Methodology in Four Phases</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/840/1*xjWpfUP6ckRUTxZ1qa0A-g.png"></figure><p>Three things the table makes explicit that a typical pentest report does not.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*FEO9H6tWCbm4iT-P1rrdWg.png"></figure><p><strong>The “Available info” row tracks what the attacker carries forward.</strong> Each column’s available info is the input needed for the next column. Phase 2 needed the API catalog and the admin hint from Phase 1. Phase 3 needed the profile IDs from Phase 2. Phase 4 needed the rewritten passwords from Phase 3. If the table has a column where “Available info” cannot be reused as input to the next column, the chain breaks. If it can, the chain holds.</p><p><strong>The “Auth required” row records what the application demanded at each step.</strong> Three of the four phases, including the one that exfiltrated credential material and the one that rewrote passwords, demanded nothing. That single row is the structural failure the entire chain rests on.</p><p><strong>The “Methodology question” row is the teaching artifact.</strong> When a junior pentester reviews the table, the questions are reusable. The next time they hunt a chain, they ask the same four questions of a different application. The answers will be different. The methodology will be the same.</p><h3>Remediation</h3><p>The chain in this post worked because three different layers of defense were missing. Authentication, object-level authorization, and information-disclosure controls. Closing the chain means closing all three. Here is the layered fix, ordered by structural importance.</p><h3>1. Authentication and Authorization</h3><p>These are the load-bearing fixes. Everything else is detection on top of a broken foundation.</p><ul><li><strong>Require authentication on every endpoint that returns account-scoped data.</strong> GET /api/profile, GET /api/profile/password, POST /api/account/info, and PUT /api/profile/password all need a valid session token. Endpoints accept anonymous calls because the developer assumed they would only be called from “trusted internal contexts.” There is no trusted internal context for an HTTP endpoint published on the public internet.</li><li><strong>Implement Role-Based Access Control (RBAC) at the route layer.</strong> Admin endpoints check role === ‘admin’ in middleware before the handler runs. Comments like // admin only in source code are not access control. The check has to be in code that executes on every request.</li><li><strong>Implement object-level authorization (BOLA prevention).</strong> Every endpoint that takes an identifier in input verifies the requester owns the resource. The pattern is if (resource.ownerId !== session.userId) return 403. Apply this at the database query layer when possible. SELECT * FROM profiles WHERE id = ? AND owner_id = ? removes the possibility of forgetting the ownership check in handler code.</li><li><strong>Require the current password on self-service password changes.</strong> Not optional. The optional id or currentPassword shape on PUT /api/profile/password was the write-side bug. Endpoint signatures should have exactly one execution path. If a function needs two paths, split it into two functions.</li><li><strong>Do not return credential material in API responses.</strong> The legacy reset-lookup endpoint that returned hash and salt should not exist. Password reset flows are token-based and never expose hashes to any client. If a legacy SOAP or JSON wrapper produced this response shape, the fix is to delete the wrapper or rewrite it to return only what the reset flow actually needs.</li></ul><h3>2. Information Disclosure</h3><p>These close the channels Phase 1 and Phase 2 used to seed the chain.</p><ul><li><strong>Generic error responses on the login endpoint.</strong> The verbose IsSuccess: false shape that disclosed email, name, profile ID, and role for any registered email is a user-enumeration oracle. Login failures should return { IsSuccess: false, error: ‘Invalid credentials’ } for every failure case (wrong password, nonexistent email, locked account, expired account) with consistent timing.</li><li><strong>Strip developer artifacts from production bundles.</strong> The API catalog and TODO comment that powered Phase 1 of this chain should not have been in app.js. Webpack’s TerserPlugin removes comments when comments: false is set in production builds. Inline JSDoc annotations on internal routes belong in source files, not built artifacts.</li><li><strong>Audit preload chains.</strong> The &lt;link rel=”preload” as=”script” href=”/js/app.js”&gt; tag shipped the post-login dashboard’s bundle to every visitor of the login page. Route-based code splitting can prevent this. app.js should be lazy-loaded after authentication, not preloaded eagerly.</li><li><strong>Remove seed and test accounts before production deployment.</strong> The QA seed account qa.test@acme-portal.local should not have shipped to production. CI/CD pipelines should fail builds if seed-only email patterns appear in the database migration set targeted at a production environment.</li></ul><h3>3. Operational Layer</h3><p>Detection that catches the chain even when prevention fails.</p><ul><li><strong>Rate limit the login endpoint by IP and by email address.</strong> Enumeration probing requires many requests against /api/login in a short window. Rate limits slow this enough that it becomes detectable before the attacker completes the enumeration.</li><li><strong>Monitor for the chain’s operational signature.</strong> High-volume password resets followed by successful logins from the same IP, across multiple accounts, is the fingerprint of this attack. Detection should fire on the rate and the across-account pattern, not on any single request.</li><li><strong>Anomaly detection on BOLA writes.</strong> Legitimate users change their own passwords occasionally. A single client changing many accounts’ passwords in a short window is anomalous and should fire. And should fire <em>before</em> the chain reaches Phase 4.</li></ul><h3>Takeaways</h3><p>Automated tooling is good at finding individual classes of vulnerability and bad at finding sequences. A finding has a severity, a remediation, and a report entry. A chain has none of those. The taxonomy our tooling was built around was designed for bugs, not for combinations of bugs. That is why three findings rated Low, Medium, and High can sit unremarkably in a triage backlog while the chain they compose is Critical. The tooling is necessary. It is not sufficient. The methodology is what closes the gap.</p><p>What that means for the people doing the work:</p><ul><li><strong>Pentesters and bug bounty researchers.</strong> Apply the four questions in sequence. When you find an IDOR, do not stop at the IDOR. Phase 2’s output is the input to Phase 3. Look at the next write endpoint that accepts the same identifier type. And test every endpoint without an Authorization header at least once. Missing-auth on the read side is one of the most common ways a chain that should have required a token becomes anonymously exploitable.</li><li><strong>Code reviewers.</strong> Ask two questions of every endpoint that takes an identifier in input. <em>“Does this endpoint require authentication?”</em> and <em>“What happens if a user passes someone else’s id here?”</em> Apply both to every endpoint, not just the ones that “look” sensitive. That pair of questions, applied consistently, turns chained authorization bugs into single-endpoint authorization bugs that tooling can find before the chain forms.</li><li><strong>Triage teams.</strong> Read the chain as a unit, not the findings as separate items. A verbose error, an unauthenticated IDOR on a read endpoint, and a missing current-password check on a write endpoint are not three unrelated tickets. They are three halves of one chain that need to be closed in the same release.</li><li><strong>Developers.</strong> Every parameter that names an object the requester might not own is an authorization decision waiting to happen. Every endpoint without an authentication middleware is an authorization decision the application has already refused to make. If your endpoint signature has an optional id parameter alongside an optional currentPassword parameter, you have written two execution paths into one function and one of them is going to skip a check it shouldn’t skip.</li></ul><p>The chain is a category of vulnerability that does not exist on a scanner’s findings list and never will. Until our tools understand sequences, the work belongs to the practitioners who already do. The methodology in this post is one way to write that work down. Four questions a junior pentester can apply to a different application tomorrow morning, with the same instinct it used to take a senior reviewer ten years to build.</p><h3>Author</h3><p><strong>Hemanth Gorijala</strong> is an application security practitioner. He builds open-source security tooling, conducts web application assessments, and reviews vulnerability reports in enterprise bug bounty programs. His open-source tooling for runtime credential detection, <em>SecretSifter</em>, is at <a href="https://github.com/secretsifter">github.com/secretsifter</a>.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=993cd63ba2cf" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/a-pentesters-methodology-for-toxic-vulnerability-combinations-993cd63ba2cf">A Pentester’s Methodology for Toxic Vulnerability Combinations</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.19-beta.1]]></title>
<description><![CDATA[2026.5.19
Changes

Agents: clarify that fixes should default to clean bounded refactors, lean internals, and explicit plugin SDK/API deprecation paths.
Dependencies: update @openclaw/proxyline to 0.3.3.
Dependencies: update Pi packages to 0.75.1 and raise the minimum supported Node.js 22 line to ...]]></description>
<link>https://tsecurity.de/de/3527452/downloads/openclaw-2026519-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527452/downloads/openclaw-2026519-beta1/</guid>
<pubDate>Tue, 19 May 2026 01:01:25 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.19</h2>
<h3>Changes</h3>
<ul>
<li>Agents: clarify that fixes should default to clean bounded refactors, lean internals, and explicit plugin SDK/API deprecation paths.</li>
<li>Dependencies: update <code>@openclaw/proxyline</code> to 0.3.3.</li>
<li>Dependencies: update Pi packages to 0.75.1 and raise the minimum supported Node.js 22 line to 22.19.</li>
<li>Docker/Podman: add <code>OPENCLAW_IMAGE_APT_PACKAGES</code> as the runtime-neutral image build arg for extra apt packages while keeping <code>OPENCLAW_DOCKER_APT_PACKAGES</code> as a legacy fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217026381" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62431/hovercard" href="https://github.com/openclaw/openclaw/pull/62431">#62431</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/urtabajev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/urtabajev">@urtabajev</a>.</li>
<li>Gateway/ACPX: attribute startup probe, config, runtime, and resource-count costs in restart traces without changing readiness behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465177610" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83300" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83300/hovercard" href="https://github.com/openclaw/openclaw/pull/83300">#83300</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Gateway: overlap startup logging and plugin-service startup with channel sidecars to reduce restart ready latency while preserving <code>/readyz</code> sidecar gating. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465177851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83301" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83301/hovercard" href="https://github.com/openclaw/openclaw/pull/83301">#83301</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Plugins/admin-http-rpc: allow trusted admin HTTP RPC clients to start and wait for web QR login flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464874472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83259" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83259/hovercard" href="https://github.com/openclaw/openclaw/pull/83259">#83259</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liorb-mountapps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liorb-mountapps">@liorb-mountapps</a>.</li>
<li>Mac app: redesign Settings pages with consistent card layouts, cached navigation, cleaner permissions/voice/skills/cron/exec/debug panes, and steadier spacing around the native sidebar.</li>
<li>Skills: rename the repo-local Codex closeout review skill and helper to <code>autoreview</code> while preserving the Codex-first fallback behavior.</li>
<li>Skills: add a meme-maker skill for curated template search, local SVG/PNG rendering, Imgflip hosted rendering, and Know Your Meme provenance links.</li>
<li>Skills CLI: allow <code>openclaw skills install</code> and <code>openclaw skills update</code> to target shared managed skills with <code>--global</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351987851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74466/hovercard" href="https://github.com/openclaw/openclaw/pull/74466">#74466</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Browser: surface pending and recently handled modal dialogs in snapshots, return <code>blockedByDialog</code> when an action opens a modal, and allow <code>browser dialog --dialog-id</code> to answer pending dialogs.</li>
<li>Browser CLI: add <code>openclaw browser evaluate --timeout-ms</code> so long-running page functions can extend both the evaluate action and request timeout budgets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466445698" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83447" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83447/hovercard" href="https://github.com/openclaw/openclaw/pull/83447">#83447</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eefreenyc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eefreenyc">@eefreenyc</a>.</li>
<li>Codex app-server: scope OpenClaw prompt guidance by runtime surface so native Codex keeps Codex-owned base/personality instructions while OpenClaw contributes only runtime context, delivery guidance, and explicitly scoped command hints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466538467" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83454" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83454/hovercard" href="https://github.com/openclaw/openclaw/pull/83454">#83454</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Agents/tools: shorten built-in tool descriptions and schema hints across media, messaging, sessions, cron, Gateway, web, image/PDF, TTS, nodes, and plan tools while preserving routing guardrails.</li>
<li>Skills: add node inspector debugging, fused diagram generation, and throwaway spike workflow skills.</li>
<li>CLI/plugins: add <code>defineToolPlugin</code> plus <code>openclaw plugins build</code>, <code>validate</code>, and <code>init</code> for typed simple tool plugins with generated manifest metadata, optional tool declarations, and context factories.</li>
<li>Agents/skills: tighten bundled skill prompts and metadata, quote skill descriptions, refresh current CLI/API guidance, and update embedded sherpa-onnx runtime downloads.</li>
<li>Skills: update the Obsidian skill to target the official <code>obsidian</code> CLI and require its registered binary instead of the third-party <code>obsidian-cli</code>.</li>
<li>Skills: add a Python debugging skill for pdb, breakpoint(), post-mortem inspection, and debugpy remote attach.</li>
<li>Plugins/messages: add presentation capability limits for channel renderers, adapt rich message controls before native rendering, and mark legacy <code>interactive</code>/Slack directive producer APIs as deprecated.</li>
<li>Plugins/subagents: store channel delivery routes as canonical session metadata and deprecate ad hoc subagent hook delivery-origin fields in favor of core route projection.</li>
<li>Proxy: support HTTPS managed forward-proxy endpoints and scoped <code>proxy.tls.caFile</code> CA trust for proxy endpoint TLS. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4403048153" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79171" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79171/hovercard" href="https://github.com/openclaw/openclaw/pull/79171">#79171</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>QA-Lab: add first-hour 20-turn and optional 100-turn runtime parity scenarios, with tier metadata for standard and soak QA gates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416188988" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80338/hovercard" href="https://github.com/openclaw/openclaw/issues/80338">#80338</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416188383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80337/hovercard" href="https://github.com/openclaw/openclaw/issues/80337">#80337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add <code>openclaw qa suite --runtime-parity-tier</code> and wire the standard Codex-vs-Pi tier into release checks separately from optional/live-only/soak lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416188383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80337/hovercard" href="https://github.com/openclaw/openclaw/issues/80337">#80337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add a live-only Codex Pi-shaped Read vocabulary canary so runtime parity catches native workspace-read prompt compatibility drift. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416039198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80323" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80323/hovercard" href="https://github.com/openclaw/openclaw/pull/80323">#80323</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add live-only harness self-health scenarios for plugin hook crashes, manifest contract errors, and WebChat direct-reply self-message routing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416039198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80323" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80323/hovercard" href="https://github.com/openclaw/openclaw/pull/80323">#80323</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add runtime tool fixture scenarios and coverage reporting for Codex-native workspace tools, OpenClaw dynamic tools, and optional plugin-backed tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415099454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80173" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80173/hovercard" href="https://github.com/openclaw/openclaw/issues/80173">#80173</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: expose runtime tool fixture coverage through <code>openclaw qa coverage --tools</code>, with optional suite-summary evaluation for parity gate artifacts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: schedule a live-frontier Codex-vs-Pi runtime token-efficiency artifact lane in the all-lanes QA workflow. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415101470" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80175/hovercard" href="https://github.com/openclaw/openclaw/issues/80175">#80175</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: hard-gate required OpenClaw dynamic runtime-tool drift in the standard Codex-vs-Pi tier with a blocking release-check verifier and publish the tool coverage report artifact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416189394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80339/hovercard" href="https://github.com/openclaw/openclaw/issues/80339">#80339</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416028202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80319" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80319/hovercard" href="https://github.com/openclaw/openclaw/issues/80319">#80319</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add the personal-agent approval-denial scenario so the benchmark pack verifies denied local reads stop cleanly without tool progress or fixture leaks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463922408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83150" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83150/hovercard" href="https://github.com/openclaw/openclaw/pull/83150">#83150</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
<li>QA-Lab: extend the personal-agent benchmark pack with a local task followthrough scenario for proof-backed pending, blocked, and done status reporting. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
<li>QA-Lab: add a report-only dreaming shadow-trial scenario so candidate memory promotion can be evaluated without mutating <code>MEMORY.md</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
<li>Gateway/performance: add <code>pnpm test:restart:gateway</code> benchmark tooling for repeated restart readiness, downtime, trace, and resource-slope evidence. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465177384" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83299" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83299/hovercard" href="https://github.com/openclaw/openclaw/pull/83299">#83299</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Android: switch Talk Mode to realtime Gateway relay voice sessions with streaming mic input, realtime audio playback, tool-result bridging, and on-screen transcripts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463811067" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83130" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83130/hovercard" href="https://github.com/openclaw/openclaw/pull/83130">#83130</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliekens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliekens">@sliekens</a>.</li>
<li>Gateway/config: expose config lookup reload metadata so tools can distinguish restart-required, hot-reloadable, and no-op fields before applying config edits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4438060145" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81409" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81409/hovercard" href="https://github.com/openclaw/openclaw/issues/81409">#81409</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442609432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81612" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81612/hovercard" href="https://github.com/openclaw/openclaw/pull/81612">#81612</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Telegram: add allowlisted native DM draft previews for transient tool progress while keeping final answers on the normal persistent delivery path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469802375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83622" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83622/hovercard" href="https://github.com/openclaw/openclaw/pull/83622">#83622</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akrimm702/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akrimm702">@akrimm702</a>.</li>
<li>QA-Lab: add a personal-agent share-safe diagnostics artifact scenario so support handoffs keep useful status while omitting raw personal content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Memory/search: scan the JS-side fallback vector path (used when the sqlite-vec index is unavailable or has a mismatched dimension) in bounded rowid batches and yield to the event loop between batches so large chunk tables can no longer pin the Node.js main thread for multi-second windows. Also keeps the SQL prepared statement rooted in a local so node:sqlite cannot finalize it mid-scan under heap pressure. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432718295" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81172" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81172/hovercard" href="https://github.com/openclaw/openclaw/issues/81172">#81172</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dev23xyz-oss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dev23xyz-oss">@dev23xyz-oss</a>.</li>
<li>CLI/update: bypass npm freshness filters consistently during managed package and plugin installs so freshly published release plugins remain installable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>Agents/subagents: keep collect-mode announce queues batching unresolved-origin items with compatible same-route messages and resume collection after a true cross-channel drain when a later compatible batch remains. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468716265" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83577" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83577/hovercard" href="https://github.com/openclaw/openclaw/issues/83577">#83577</a>.</li>
<li>Providers/Anthropic: preserve native image input for current Claude model rows when stale local catalog data marks them text-only. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472508905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83756" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83756/hovercard" href="https://github.com/openclaw/openclaw/pull/83756">#83756</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Control UI: render live tool progress from session-scoped <code>session.tool</code> Gateway events so externally started runs show their tool cards in the active session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4471865132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83734" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83734/hovercard" href="https://github.com/openclaw/openclaw/pull/83734">#83734</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Outbound: resolve send-capable channel plugins from the active runtime registry when the pinned startup registry only has setup metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4471864947" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83733" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83733/hovercard" href="https://github.com/openclaw/openclaw/pull/83733">#83733</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Browser: enforce current-tab URL allowlist checks for <code>/act</code> evaluate/batch actions and <code>/highlight</code> routes while leaving tab-management actions unblocked. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392533668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78523" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78523/hovercard" href="https://github.com/openclaw/openclaw/pull/78523">#78523</a>)</li>
<li>CI: require real-behavior-proof verdict markers to come from the ClawSweeper GitHub App before accepting exact-head proof. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470892805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83692" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83692/hovercard" href="https://github.com/openclaw/openclaw/pull/83692">#83692</a>)</li>
<li>Models: show the effective OpenAI/Codex auth profile in <code>/models</code> provider headers instead of falling back to the OpenAI env-key label. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470946100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83697" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83697/hovercard" href="https://github.com/openclaw/openclaw/pull/83697">#83697</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yu-xin-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yu-xin-c">@yu-xin-c</a>.</li>
<li>Browser: keep a profile <code>cdpPort</code> when its <code>cdpUrl</code> omits a port, while still letting explicitly written URL ports win. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454473920" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82166" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82166/hovercard" href="https://github.com/openclaw/openclaw/pull/82166">#82166</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Agents/image generation: allow distinct <code>image_generate</code> prompts to start separate session-backed background tasks while same-prompt retries still return the active task status. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469561038" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83614" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83614/hovercard" href="https://github.com/openclaw/openclaw/pull/83614">#83614</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Elarwei001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Elarwei001">@Elarwei001</a>.</li>
<li>Gateway/WebChat: honor configured <code>channels.webchat.textChunkLimit</code> and <code>chunkMode</code> overrides when chunking WebChat replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4471165614" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83713" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83713/hovercard" href="https://github.com/openclaw/openclaw/pull/83713">#83713</a>)</li>
<li>Control UI: stop the chat reading indicator from sticking after an assistant response finishes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467410605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83515/hovercard" href="https://github.com/openclaw/openclaw/pull/83515">#83515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/njuboy11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/njuboy11">@njuboy11</a>.</li>
<li>Skills: reject empty or whitespace-only skill names and descriptions during quick validation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992930563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27061" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/27061/hovercard" href="https://github.com/openclaw/openclaw/pull/27061">#27061</a>)</li>
<li>Sessions: skip trailing custom transcript entries when checking tail assistant replies so embedded CLI gap-fill does not duplicate canonical assistant output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469910900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83635" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83635/hovercard" href="https://github.com/openclaw/openclaw/pull/83635">#83635</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yaoyi1222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yaoyi1222">@yaoyi1222</a>.</li>
<li>Memory Wiki: keep <code>wiki_lint</code> tool output path-safe by reporting vault-internal lint reports as relative paths in tool text and details while preserving absolute report paths for CLI/file callers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466350048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83439" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83439/hovercard" href="https://github.com/openclaw/openclaw/pull/83439">#83439</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Telegram: keep verbose tool progress visible without mirroring non-final progress into active session transcripts, preventing embedded provider replies from aborting mid-run. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469858032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83631" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83631/hovercard" href="https://github.com/openclaw/openclaw/pull/83631">#83631</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kurplunkin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kurplunkin">@kurplunkin</a>.</li>
<li>Telegram: log successful outbound text and media deliveries with account, chat, message, operation, thread, reply, silent, and chunk metadata while keeping message bodies out of logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464232340" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83196/hovercard" href="https://github.com/openclaw/openclaw/issues/83196">#83196</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464712841" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83247" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83247/hovercard" href="https://github.com/openclaw/openclaw/pull/83247">#83247</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jrwrest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jrwrest">@jrwrest</a>.</li>
<li>Cron: link isolated scheduled task runs to their stable cron session so task status and cleanup can follow the backing agent run. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469405023" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83606" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83606/hovercard" href="https://github.com/openclaw/openclaw/pull/83606">#83606</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jai">@jai</a>.</li>
<li>CLI: enforce the documented Node.js 22.19 runtime floor in the source launcher.</li>
<li>Release stability: repair broad-gate regressions in requester-agent completion handoff, QA-Lab mock spawn attribution, Slack monitor test isolation, plugin uninstall peer fixtures, and Node-floor launcher contract coverage.</li>
<li>Agents/replies: persist queued follow-up user messages and assistant error stubs only once across model-fallback retries, preventing repeated provider rejections from corrupted same-role session transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465972914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83404/hovercard" href="https://github.com/openclaw/openclaw/issues/83404">#83404</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466078721" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83417" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83417/hovercard" href="https://github.com/openclaw/openclaw/pull/83417">#83417</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>Slack: persist delivered inbound message IDs and fail closed when same-channel thread replies lose their thread context, preventing delayed duplicate replies and accidental channel-root posts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467465571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83521" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83521/hovercard" href="https://github.com/openclaw/openclaw/issues/83521">#83521</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannon0430/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannon0430">@shannon0430</a>.</li>
<li>Codex app-server: complete OpenClaw dynamic tool diagnostics at the request boundary so successful, failed, timed out, aborted, and blocked tool calls do not leave active tool state behind. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466827129" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83474" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83474/hovercard" href="https://github.com/openclaw/openclaw/issues/83474">#83474</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rozmiarD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rozmiarD">@rozmiarD</a>.</li>
<li>Gateway/config: keep config writes from failing on unrelated unresolved auth-profile SecretRefs while preserving live auth-profile runtime snapshots.</li>
<li>Gateway/sessions: clear stored CLI provider resume bindings on non-subagent <code>/reset</code> so the next turn starts a fresh provider-side CLI conversation instead of resuming old context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466450765" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83448" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83448/hovercard" href="https://github.com/openclaw/openclaw/pull/83448">#83448</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jasonyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jasonyliu">@jasonyliu</a>.</li>
<li>Doctor: preserve legacy whole-agent Claude CLI intent by moving matching Anthropic model selections to model-scoped runtime policy before removing stale runtime pins. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467068699" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83491/hovercard" href="https://github.com/openclaw/openclaw/issues/83491">#83491</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danielcrick/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danielcrick">@danielcrick</a>.</li>
<li>Discord/OpenAI: keep realtime Discord voice sessions hearing follow-up turns with OpenAI realtime and prebuffer assistant playback to avoid choppy starts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4417674952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80505" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80505/hovercard" href="https://github.com/openclaw/openclaw/pull/80505">#80505</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>LM Studio: resolve env-template API keys like <code>${LMSTUDIO_API_KEY}</code> through the standard SecretInput path instead of sending the raw template as the bearer token, and preserve header-auth and discovery-key precedence when the template is unset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4417527708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80495" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80495/hovercard" href="https://github.com/openclaw/openclaw/issues/80495">#80495</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4418547191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80568" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80568/hovercard" href="https://github.com/openclaw/openclaw/pull/80568">#80568</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MonkeyLeeT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MonkeyLeeT">@MonkeyLeeT</a>.</li>
<li>Discord/subagents: route the initial reply from thread-bound delegated sessions into the bound Discord thread instead of the parent channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464042454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83170" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83170/hovercard" href="https://github.com/openclaw/openclaw/issues/83170">#83170</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464046468" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83172" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83172/hovercard" href="https://github.com/openclaw/openclaw/pull/83172">#83172</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100menotu001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100menotu001">@100menotu001</a>.</li>
<li>Gateway/sessions: rotate failed agent sessions when their transcript file is missing instead of wedging per-channel lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467000680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83488" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83488/hovercard" href="https://github.com/openclaw/openclaw/issues/83488">#83488</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468120214" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83553" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83553/hovercard" href="https://github.com/openclaw/openclaw/pull/83553">#83553</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Media: prevent image metadata probing from invoking external decoder delegates on unrecognized image bytes, and stop fallback chaining after real processing errors.</li>
<li>Media: install Sharp with the root package and fall back to sips, Windows native imaging, ImageMagick, GraphicsMagick, or ffmpeg for image resizing/conversion when Sharp is unavailable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465939099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83401" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83401/hovercard" href="https://github.com/openclaw/openclaw/issues/83401">#83401</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scotthuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scotthuang">@scotthuang</a>.</li>
<li>Telegram: deliver generated media completions back into forum topics by preserving topic IDs across requester-agent handoff. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468244035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83556" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83556/hovercard" href="https://github.com/openclaw/openclaw/pull/83556">#83556</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Gateway: defer update-check startup until after readiness so package update checks no longer block sidecar-ready startup, while preserving update broadcasts and shutdown cleanup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467462415" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83520" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83520/hovercard" href="https://github.com/openclaw/openclaw/pull/83520">#83520</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Telegram: keep <code>/btw</code> and read-only status commands from aborting active runs, and avoid retaining raw update payloads in timed-out spool tombstones. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464995305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83272" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83272/hovercard" href="https://github.com/openclaw/openclaw/issues/83272">#83272</a>.</li>
<li>Agents: log strict-agentic execution contract diagnostics only when the planning-only retry path actually triggers.</li>
<li>Agents: stop embedded session takeover and session write-lock errors from consuming model fallbacks while preserving provider fallback metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467367566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83510" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83510/hovercard" href="https://github.com/openclaw/openclaw/issues/83510">#83510</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>.</li>
<li>Agents/video: hide <code>video_generate</code> reference-audio parameters unless a registered video provider supports audio inputs.</li>
<li>Plugins: fall back to npm for official ClawHub updates when artifact downloads are unavailable, including beta-to-default fallback and dry-run version reporting.</li>
<li>Plugins/xAI: echo PKCE challenge fields during OAuth authorization-code token exchange for xAI token-endpoint compatibility. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467208552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83499/hovercard" href="https://github.com/openclaw/openclaw/pull/83499">#83499</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Codex app-server: hydrate current inbound image attachments before queued runs so Responses-backed agents receive Discord and other channel images as native vision input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466691440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83466" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83466/hovercard" href="https://github.com/openclaw/openclaw/issues/83466">#83466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iannwu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iannwu">@iannwu</a>.</li>
<li>Codex app-server: keep native code mode available without forcing code-mode-only so OpenClaw dynamic tool turns complete through the app-server tool bridge. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463653395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83109" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83109/hovercard" href="https://github.com/openclaw/openclaw/issues/83109">#83109</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daswass/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daswass">@daswass</a>.</li>
<li>Release stability: recover stale session diagnostics and Codex OAuth fallback state so stuck runs and reused refresh tokens clear without blocking follow-up work. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467223870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83503" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83503/hovercard" href="https://github.com/openclaw/openclaw/pull/83503">#83503</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Messages/TTS: apply TTS directives before message-tool sends reach core, gateway, or plugin delivery so opt-in message-tool rooms and proactive sends attach voice notes instead of leaking raw tags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442404677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81598" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81598/hovercard" href="https://github.com/openclaw/openclaw/issues/81598">#81598</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CG-Intelligence-Agent-Jack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CG-Intelligence-Agent-Jack">@CG-Intelligence-Agent-Jack</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CoronovirusG10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CoronovirusG10">@CoronovirusG10</a>.</li>
<li>Messages/Codex: keep Codex direct/source chats on message-tool visible delivery by default while documenting and testing <code>messages.visibleReplies: "automatic"</code> as the old-mode opt-out; channel wildcard model overrides now apply to direct chats before harness delivery defaults.</li>
<li>Memory/QMD: keep archived session transcript hits visible after QMD export while preserving normal <code>.md</code> session ids that only resemble archive names. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467447669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83518" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83518/hovercard" href="https://github.com/openclaw/openclaw/pull/83518">#83518</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467252934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83506" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83506/hovercard" href="https://github.com/openclaw/openclaw/issues/83506">#83506</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tanshanshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tanshanshan">@tanshanshan</a>.</li>
<li>Codex app-server: preserve network access for sandboxed Codex code-mode turns when the OpenClaw sandbox allows outbound egress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465477650" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83347" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83347/hovercard" href="https://github.com/openclaw/openclaw/issues/83347">#83347</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YusukeIt0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YusukeIt0">@YusukeIt0</a>.</li>
<li>QA-Lab: keep the OTLP smoke decoder independent of removed OpenTelemetry generated-root internals.</li>
<li>Messages: default group/channel visible replies to automatic final delivery again, keeping <code>message_tool</code> opt-in for ambient/shared rooms and tool-reliable models.</li>
<li>CLI/TUI: force standalone <code>/exit</code> runs to terminate after <code>runTui</code> returns so onboarding-launched TUI children do not stay alive invisibly. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467214589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83501/hovercard" href="https://github.com/openclaw/openclaw/pull/83501">#83501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Agents/code mode: honor per-agent code-mode config in schema, runtime catalog activation, and model payload filtering. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465758765" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83388" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83388/hovercard" href="https://github.com/openclaw/openclaw/issues/83388">#83388</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Agents/code mode: preserve agent, session, run, and channel context in <code>before_tool_call</code> hooks for top-level <code>exec</code>/<code>wait</code> dispatches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465758470" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83387" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83387/hovercard" href="https://github.com/openclaw/openclaw/issues/83387">#83387</a>.</li>
<li>QQBot: shorten C2C typing indicators to a 10-second window renewed every 5 seconds, capped to keep a final passive-reply slot available. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466707249" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83469/hovercard" href="https://github.com/openclaw/openclaw/pull/83469">#83469</a>)</li>
<li>Replies: keep final payload delivery after live preview updates so channels can finalize or send the completed answer instead of losing preview-only drafts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466706226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83468" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83468/hovercard" href="https://github.com/openclaw/openclaw/pull/83468">#83468</a>)</li>
<li>Discord: deliver final replies in progress-mode preview streams instead of deduplicating the final visible message. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466374427" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83443/hovercard" href="https://github.com/openclaw/openclaw/pull/83443">#83443</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/compoodment/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/compoodment">@compoodment</a>.</li>
<li>Providers/Xiaomi: replay MiMo Anthropic-compatible <code>reasoning_content</code> as provider-required thinking blocks even when OpenClaw thinking is disabled, fixing follow-up tool turns for <code>mimo-v2-flash</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465996157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83407" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83407/hovercard" href="https://github.com/openclaw/openclaw/issues/83407">#83407</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xgenious7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xgenious7">@Xgenious7</a>.</li>
<li>Agents/exec approvals: forward approval-runtime credentials on agent-owned Gateway approval calls so approved async commands complete through the existing runtime path instead of stalling on unauthenticated follow-up calls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Gateway/skills: preflight remote macOS skill-bin refreshes with a WebSocket connectivity check so stale node sessions skip quickly instead of logging slow <code>system.which</code> timeout warnings.</li>
<li>CLI/config: keep broken discovered plugins that are not referenced by active config from failing <code>openclaw config validate</code>, while preserving fatal errors for explicitly configured plugin entries.</li>
<li>GitHub Copilot: drop unsafe native Responses reasoning replay items with non-replayable IDs before dispatch, preventing affected Copilot sessions from failing with <code>invalid_request_body</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464490598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83220" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83220/hovercard" href="https://github.com/openclaw/openclaw/issues/83220">#83220</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Agents/Codex: fail closed when an explicitly requested Codex harness is not registered instead of silently trying configured model fallbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465485972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83349" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83349/hovercard" href="https://github.com/openclaw/openclaw/issues/83349">#83349</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r2-vibes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r2-vibes">@r2-vibes</a>.</li>
<li>QA-Lab: make runtime tool coverage fail on missing required tool exercise instead of treating pass/pass parity envelope drift as missing coverage.</li>
<li>Core/plugins: harden clawpatch-reported edge cases across gateway auth cleanup, Claude session id paths, plugin activation policy, apply-patch hunk handling, diagnostic redaction, and plugin metadata validation.</li>
<li>UI: show reasoning choices as plain labels instead of leaking internal override wording in session and chat pickers.</li>
<li>Mac app: avoid repeating the Configuration heading inside channel quick settings.</li>
<li>Mac app: keep the Settings sidebar always visible and remove the redundant titlebar hide/show control.</li>
<li>Mac app: normalize Settings pane content margins so pages share the same left and right rail.</li>
<li>Mac app: prefer explicit private/Tailscale/LAN Gateway endpoints over SSH tunnels, preserve legacy loopback tunnel configs, persist transport choices, and show captured SSH stderr when tunneling really fails.</li>
<li>Gateway/sessions: keep ACP/acpx and runtime child sessions visible in configured-only session lists when their owner or parent session belongs to a configured agent.</li>
<li>Mac app: keep app-level menu commands and Dashboard failure states reachable when the remote Gateway is disconnected.</li>
<li>Mac app: allow longer Gateway and Context errors to wrap in the menu instead of truncating the useful failure detail.</li>
<li>Mac app: tighten remote Gateway fields in Settings so the Connection pane keeps readable labels and full action button text.</li>
<li>Mac app: keep custom Settings card rows left-aligned and full-width so Discovery and status sections no longer appear centered or detached.</li>
<li>Mac app: align Location permission controls to the same trailing column as the rest of Settings.</li>
<li>Mac app: add Dashboard, Chat, Canvas, and Settings shortcuts to the Dock icon menu.</li>
<li>Mac app: replace the Settings window's native split-view sidebar with an explicit layout so page content keeps its leading gutter when the sidebar is shown or hidden.</li>
<li>Mac app: render channel quick config as aligned Settings rows and hide schema-only variants that cannot be edited safely from the quick pane.</li>
<li>Gateway/webchat: hide internal runtime-context and other <code>display: false</code> transcript messages from Chat history and live message events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464459552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83216" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83216/hovercard" href="https://github.com/openclaw/openclaw/issues/83216">#83216</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EmpireCreator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EmpireCreator">@EmpireCreator</a>.</li>
<li>CLI/help: keep <code>gateway</code>, <code>doctor</code>, <code>status</code>, and <code>health</code> help registration out of action/runtime imports so subcommand <code>--help</code> stays lightweight in constrained terminals. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464522965" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83228/hovercard" href="https://github.com/openclaw/openclaw/issues/83228">#83228</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfguerrerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfguerrerom">@dfguerrerom</a>.</li>
<li>Cron/Discord: keep explicit announce runs in message-tool-only source-reply mode so scheduled agent turns post once instead of also echoing through automatic visible replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464900333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83261" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83261/hovercard" href="https://github.com/openclaw/openclaw/issues/83261">#83261</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Theralley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Theralley">@Theralley</a>.</li>
<li>Telegram: preserve forum-topic origin targets in inbound, audio-preflight, and skipped-message hook contexts so follow-up delivery stays bound to the originating topic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465183426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83302" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83302/hovercard" href="https://github.com/openclaw/openclaw/issues/83302">#83302</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/M00zyx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/M00zyx">@M00zyx</a>.</li>
<li>Telegram: retry HTTP 421 Misdirected Request send failures on a fresh fallback transport so transient edge-node routing errors no longer drop outbound replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087256219" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48892" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48892/hovercard" href="https://github.com/openclaw/openclaw/issues/48892">#48892</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087442780" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48908" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48908/hovercard" href="https://github.com/openclaw/openclaw/pull/48908">#48908</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarsDoge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarsDoge">@MarsDoge</a>.</li>
<li>Telegram: fail topic sends closed when Telegram reports <code>message thread not found</code> instead of retrying without <code>message_thread_id</code> into the base chat. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465183426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83302" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83302/hovercard" href="https://github.com/openclaw/openclaw/issues/83302">#83302</a>.</li>
<li>Config/subagents: remove ignored agent-model <code>timeoutMs</code> keys, keep subagent model config to primary/fallback selection, and clean shipped stale config through doctor. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465090121" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83291" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83291/hovercard" href="https://github.com/openclaw/openclaw/issues/83291">#83291</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>Mac app: align the Sessions settings pane with the standard Settings page gutter and row spacing.</li>
<li>OpenAI/Codex: stop rejecting available <code>openai-codex</code> GPT-5.1, GPT-5.2, and GPT-5.3 model refs during config validation, while keeping removed Spark aliases suppressed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465210488" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83303" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83303/hovercard" href="https://github.com/openclaw/openclaw/issues/83303">#83303</a>.</li>
<li>Plugins/xAI: complete OAuth-backed xAI login and sidecar auth fixes, including guarded loopback callback CORS handling, video generation polling/defaults, and native-host User-Agent attribution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465339811" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83322" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83322/hovercard" href="https://github.com/openclaw/openclaw/pull/83322">#83322</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>.</li>
<li>Codex app-server: preserve streamed native command output in mirrored transcripts and trajectory exports when final snapshots omit aggregated output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464273690" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83200" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83200/hovercard" href="https://github.com/openclaw/openclaw/pull/83200">#83200</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rozmiarD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rozmiarD">@rozmiarD</a>.</li>
<li>Codex app-server: fail closed when chat or sender policy denies tools, disabling native code, app, environment, and user MCP surfaces for restricted turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457945251" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82374" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82374/hovercard" href="https://github.com/openclaw/openclaw/pull/82374">#82374</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Codex app-server: keep recent context-engine messages when oversized projected history is truncated, so short follow-ups in long channel sessions do not fall back to stale earlier turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463799694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83127" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83127/hovercard" href="https://github.com/openclaw/openclaw/pull/83127">#83127</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Codex app-server: keep OpenClaw session spawning searchable while steering Codex-native delegation through native subagents, avoiding duplicate direct subagent surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465370887" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83329" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83329/hovercard" href="https://github.com/openclaw/openclaw/pull/83329">#83329</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Codex app-server: recover stale childless Codex-native subagent task mirrors during maintenance and allow their registry rows to be cancelled without an OpenClaw child session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461986275" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82836" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82836/hovercard" href="https://github.com/openclaw/openclaw/pull/82836">#82836</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yshimadahrs-ship-it/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yshimadahrs-ship-it">@yshimadahrs-ship-it</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Feishu: return bound subagent delivery origins from session thread setup so Feishu subagent completions route back to the same DM or topic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464179397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83190" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83190/hovercard" href="https://github.com/openclaw/openclaw/pull/83190">#83190</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100menotu001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100menotu001">@100menotu001</a>.</li>
<li>CLI/update: tailor post-update Gateway recovery hints by platform, showing systemd, LaunchAgent, Scheduled Task, or generic service-manager guidance instead of macOS-only recovery text. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463495630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83096/hovercard" href="https://github.com/openclaw/openclaw/pull/83096">#83096</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Plugins: apply a default 15-second timeout to legacy <code>before_agent_start</code> hooks so hung plugin handlers no longer block agent startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085154694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48534" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48534/hovercard" href="https://github.com/openclaw/openclaw/issues/48534">#48534</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463837368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83136/hovercard" href="https://github.com/openclaw/openclaw/pull/83136">#83136</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/therahul-yo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/therahul-yo">@therahul-yo</a>.</li>
<li>Feishu: refresh inbound session delivery context for DM, group, and broadcast turns so later replies do not inherit stale WebChat routing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4388788955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78274" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/78274/hovercard" href="https://github.com/openclaw/openclaw/issues/78274">#78274</a>.</li>
<li>Agents/subagents: require the initial subagent registry save before reporting spawn accepted, returning a spawn error instead of losing an untracked run when the registry write fails. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463909257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83146" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83146/hovercard" href="https://github.com/openclaw/openclaw/pull/83146">#83146</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>QA-Lab/qa-channel: attach redacted agent tool-start traces to outbound <code>QaBusMessage</code> records so scenarios can assert actual tool use instead of relying only on reply text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275248060" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67637" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67637/hovercard" href="https://github.com/openclaw/openclaw/issues/67637">#67637</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: fail live runtime parity reports when assistant-message usage is missing, preventing <code>0 vs 0</code> live token rows from being reported as passing proof. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416721771" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80411/hovercard" href="https://github.com/openclaw/openclaw/issues/80411">#80411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add a runtime token-efficiency sidecar report that classifies Codex savings separately from regressions and fails only positive Codex-over-Pi live token deltas above threshold. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4430998561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81093" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81093/hovercard" href="https://github.com/openclaw/openclaw/issues/81093">#81093</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: fail Codex-backed OpenAI live runtime-pair runs before launching isolated workers when no portable Codex auth is available, while staging API-key fallbacks and configured Codex keys for isolated QA agents. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416721774" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80412" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80412/hovercard" href="https://github.com/openclaw/openclaw/issues/80412">#80412</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: refresh parity gates, mock frontier fixtures, model scenarios, and workflow artifact lanes to compare GPT-5.5 against Claude Opus 4.7. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349437446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74262" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74262/hovercard" href="https://github.com/openclaw/openclaw/issues/74262">#74262</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: make mock parity dispatch provider-aware for source discovery and subagent scenarios so OpenAI and Anthropic lanes no longer share identical canned plans. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245036106" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64879/hovercard" href="https://github.com/openclaw/openclaw/issues/64879">#64879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: stop returning Control UI bearer tokens from unauthenticated bootstrap payloads and bind Docker harness ports to loopback-only host addresses. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259596226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66355" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66355/hovercard" href="https://github.com/openclaw/openclaw/pull/66355">#66355</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Mac app: avoid a SwiftUI metadata crash when rendering the Cron Jobs settings pane.</li>
<li>Agents/subagents: preserve run-mode keep subagent registry entries past the session sweep TTL, so kept subagent runs remain visible after cleanup completes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463823834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83132" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83132/hovercard" href="https://github.com/openclaw/openclaw/issues/83132">#83132</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464018781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83168" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83168/hovercard" href="https://github.com/openclaw/openclaw/pull/83168">#83168</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>Agents/OpenAI streams: yield via <code>setTimeout(0)</code> instead of <code>setImmediate</code> between bursty Responses chunks so abort timers can fire during the yield, keeping cancel-on-timeout responsive on hot streams. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4458742937" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82462" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82462/hovercard" href="https://github.com/openclaw/openclaw/issues/82462">#82462</a>.</li>
<li>Agents/Codex: keep legacy <code>oauthRef</code>-backed OAuth profiles usable while <code>openclaw doctor --fix</code> migrates them back to inline credentials, without creating new sidecar credentials. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465275872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83312" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83312/hovercard" href="https://github.com/openclaw/openclaw/pull/83312">#83312</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents/Codex: load the selected provider owner alongside the Codex harness runtime so <code>openai-codex</code> models resolve when plugin allowlists scope runtime loading. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465725039" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83380" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83380/hovercard" href="https://github.com/openclaw/openclaw/issues/83380">#83380</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467452244" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83519" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83519/hovercard" href="https://github.com/openclaw/openclaw/pull/83519">#83519</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Telegram: fail stalled isolated-ingress handlers into tombstones and abort same-lane reply work before restarting, so later same-chat updates drain after a hung turn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464995305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83272" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83272/hovercard" href="https://github.com/openclaw/openclaw/issues/83272">#83272</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467244502" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83505" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83505/hovercard" href="https://github.com/openclaw/openclaw/pull/83505">#83505</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>CLI/config: send SecretRef diagnostics to stderr so JSON command stdout remains parseable.</li>
<li>CLI/doctor: seed Control UI allowed origins when migrating legacy non-loopback gateway bind host aliases like <code>0.0.0.0</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465089879" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83286" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83286/hovercard" href="https://github.com/openclaw/openclaw/issues/83286">#83286</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>CLI/plugins: ship the bundled memory CLI as a package entry so package-installed <code>openclaw memory</code> commands register correctly.</li>
<li>CLI/update: defer doctor-time plugin package installs during package swaps and seed post-core repair from the updated install registry, preventing duplicate reinstall failures.</li>
<li>CLI/update: preserve old-parent-readable config metadata during legacy package handoffs, fall back only to official <code>@openclaw/*</code> npm plugin packages when ClawHub plugin artifacts are unavailable, and keep managed service package roots authoritative during updates.</li>
<li>Feishu: detect SecretRef top-level credentials as a configured default account instead of treating object-backed app secrets as missing.</li>
<li>Gateway/restart: keep ordinary unmanaged SIGUSR1/config restarts in-process instead of detach-spawning an orphaned child, preserving custom supervisor PID tracking while leaving update restarts on the fresh-process path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250873603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65668" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65668/hovercard" href="https://github.com/openclaw/openclaw/issues/65668">#65668</a>.</li>
<li>CLI/completion: resolve concrete PowerShell profile paths and reload commands during setup and doctor completion installation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066360712" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44296/hovercard" href="https://github.com/openclaw/openclaw/issues/44296">#44296</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463206646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83059/hovercard" href="https://github.com/openclaw/openclaw/pull/83059">#83059</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yu-xin-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yu-xin-c">@yu-xin-c</a>.</li>
<li>Telegram: keep isolated long polling below the hard <code>getUpdates</code> request guard so idle bot accounts with high <code>timeoutSeconds</code> do not false-disconnect and restart-loop. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464939101" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83264" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83264/hovercard" href="https://github.com/openclaw/openclaw/issues/83264">#83264</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/riccodecarvalho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/riccodecarvalho">@riccodecarvalho</a>.</li>
<li>Providers/Google: preserve and recover Gemini 3 tool-call thought signatures during native replay so function-calling turns no longer fail with missing <code>thought_signature</code> 400s. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336919838" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72879/hovercard" href="https://github.com/openclaw/openclaw/issues/72879">#72879</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416318334" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80358" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80358/hovercard" href="https://github.com/openclaw/openclaw/pull/80358">#80358</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abnershang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abnershang">@abnershang</a>.</li>
<li>Telegram: skip transcript-only delivery mirrors and gateway-injected rows when resolving latest assistant text, preventing retained previews from replacing final replies with stale fragments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463981517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83159" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83159/hovercard" href="https://github.com/openclaw/openclaw/issues/83159">#83159</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465564203" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83362" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83362/hovercard" href="https://github.com/openclaw/openclaw/pull/83362">#83362</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Memory/QMD: keep lexical search on raw hyphenated queries while normalizing semantic QMD sub-searches, avoiding fallback to the builtin index for dashed identifiers and dates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4435810897" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81328" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81328/hovercard" href="https://github.com/openclaw/openclaw/issues/81328">#81328</a>.</li>
<li>Memory-core: distinguish sqlite-vec load failures from missing semantic vector embeddings in degraded <code>memory index</code> warnings, so vector recall diagnostics point at unresolved dimensions instead of blaming sqlite-vec when the store is ready. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364260496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75624" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75624/hovercard" href="https://github.com/openclaw/openclaw/issues/75624">#75624</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463181130" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83056" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83056/hovercard" href="https://github.com/openclaw/openclaw/pull/83056">#83056</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Noah3521/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Noah3521">@Noah3521</a>.</li>
<li>Agents/subagents: preserve sandbox-peer controller ownership while routing completion announcements back to the originating run session, keeping subagent control and completion delivery scoped correctly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415216120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80201/hovercard" href="https://github.com/openclaw/openclaw/issues/80201">#80201</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415551739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80242" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80242/hovercard" href="https://github.com/openclaw/openclaw/pull/80242">#80242</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jerry-Xin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jerry-Xin">@Jerry-Xin</a>.</li>
<li>Gateway: continue restarting remaining channels when one hot-reload channel restart fails, while still reporting aggregate reload failure and rolling back plugin pre-replace stops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463173969" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83054/hovercard" href="https://github.com/openclaw/openclaw/issues/83054">#83054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>Gateway/plugins: bind admin HTTP RPC dispatch to the accepting gateway instance so multi-gateway processes cannot execute plugin HTTP control-plane calls against another live gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466988696" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83486" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83486/hovercard" href="https://github.com/openclaw/openclaw/issues/83486">#83486</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466988915" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83487" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83487/hovercard" href="https://github.com/openclaw/openclaw/pull/83487">#83487</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>.</li>
<li>Telegram: keep hot-reload restarts from marking polling accounts manually stopped and restart isolated ingress cleanly after worker shutdown, preserving Telegram replies across config reloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462834253" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83008" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83008/hovercard" href="https://github.com/openclaw/openclaw/issues/83008">#83008</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466042128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83410" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83410/hovercard" href="https://github.com/openclaw/openclaw/pull/83410">#83410</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Telegram/Ollama: pass current Telegram image attachments into native PI/Ollama vision turns so live photo prompts reach Ollama as native images. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462984078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83023" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83023/hovercard" href="https://github.com/openclaw/openclaw/issues/83023">#83023</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467422495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83516" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83516/hovercard" href="https://github.com/openclaw/openclaw/pull/83516">#83516</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Gateway/secrets: split the lightweight secrets runtime state and auth-store cache from the full secrets runtime and take a startup fast path when the gateway startup config has no SecretRef values, speeding up secrets startup while preserving cleanup and refresh semantics.</li>
<li>Codex app-server: rotate oversized native Codex threads before resume and cap dynamic tool-result text entering native Codex sessions, preventing stale oversized context from surviving OpenClaw compaction. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462638811" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82981" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82981/hovercard" href="https://github.com/openclaw/openclaw/pull/82981">#82981</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hansolo949/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hansolo949">@hansolo949</a>.</li>
<li>Gateway/restart: drain pending replies and active chat runs during restart shutdown before sockets and channels close, aborting timed-out chat runs through the normal cleanup path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292354940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69121" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69121/hovercard" href="https://github.com/openclaw/openclaw/pull/69121">#69121</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexlomt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexlomt">@alexlomt</a>.</li>
<li>Agents/Codex: use the Codex runtime context window for OpenAI-model preflight compaction and memory flush checks, so GPT-5.5 Codex sessions compact before hitting the smaller native context limit. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462658403" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82982/hovercard" href="https://github.com/openclaw/openclaw/issues/82982">#82982</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vliuyt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vliuyt">@vliuyt</a>.</li>
<li>QA-Lab: clean orphaned gateway temp roots when a suite parent exits and wait on gateway plus transport readiness after config restarts, reducing stale <code>qa-channel</code> noise from interrupted runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249469816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65506" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65506/hovercard" href="https://github.com/openclaw/openclaw/issues/65506">#65506</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: wake qa-bus long polls that arrive with stale future cursors after a bus restart, preserving reconnect readiness for harness clients. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268454103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67142" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67142/hovercard" href="https://github.com/openclaw/openclaw/pull/67142">#67142</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hxy91819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hxy91819">@hxy91819</a>.</li>
<li>QA-Lab: stage Multipass transfer scripts under OpenClaw's preferred temp root instead of raw OS temp paths, keeping the VM runner inside temp-path guardrails. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236737157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64098" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64098/hovercard" href="https://github.com/openclaw/openclaw/pull/64098">#64098</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ImLukeF/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ImLukeF">@ImLukeF</a>.</li>
<li>Agents/replies: keep surviving reply media and append a warning when other media references fail, so partial media normalization no longer drops failures silently. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jerry-Xin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jerry-Xin">@Jerry-Xin</a>.</li>
<li>Config/models: accept <code>thinkingFormat: "together"</code> in model compat config so Together routes can opt into the Together-specific thinking response shape.</li>
<li>Plugins/tokenjuice: bump the bundled tokenjuice runtime to 0.7.1, bringing Codex hook approval compatibility, pre-tool command wrapping fixes, and Rolldown/Vitest output compaction improvements into the OpenClaw plugin.</li>
<li>Agents/OpenAI: stop post-processing GPT-5 final replies with hardcoded brevity caps, preserving full channel responses instead of appending synthetic ellipses, and log when strict-agentic GPT-5 execution activates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462335362" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82910" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82910/hovercard" href="https://github.com/openclaw/openclaw/issues/82910">#82910</a>.</li>
<li>Mac app: refine the Settings General and Connection panes with cleaner status panels, card rows, and a single native titlebar sidebar toggle.</li>
<li>Agents/media: deliver failed async image, music, and video generation completions directly when requester-session completion handoff fails, so channel users see provider errors instead of silent fallback stalls.</li>
<li>Browser/CDP: keep loopback proxy bypass active across both <code>NO_PROXY</code> casings and redact home-relative Chrome MCP profile paths in attach-failure diagnostics.</li>
<li>Agents/music: steer song, jingle, beat, anthem, and instrumental requests toward <code>music_generate</code> audio creation instead of lyric-only replies, and reserve <code>lyrics</code> for exact sung words.</li>
<li>Codex app-server: record native Codex tool calls and results into trajectory artifacts so debug/trajectory exports capture the full Codex-native tool history, not just OpenClaw-bridged turns. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Codex/app-server: keep bound conversation sessions on the owning agent runtime so native Codex control and follow-up turns do not fall back to the default agent client. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462465085" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82954" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82954/hovercard" href="https://github.com/openclaw/openclaw/issues/82954">#82954</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462724002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82993" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82993/hovercard" href="https://github.com/openclaw/openclaw/pull/82993">#82993</a>)</li>
<li>CLI/infer: run gateway model probes in fresh explicit sessions so one-shot provider checks do not inherit default agent transcript state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462127302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82861" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82861/hovercard" href="https://github.com/openclaw/openclaw/pull/82861">#82861</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Providers/Together: send video-generation requests to Together's v2 video API even when shared text-model config still points at the v1 base URL. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462711627" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82992" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82992/hovercard" href="https://github.com/openclaw/openclaw/pull/82992">#82992</a>)</li>
<li>Browser CLI: preserve browser-level options on nested commands, skip option values during lazy command registration, and keep long-running wait/download/dialog hooks open for their advertised wait window.</li>
<li>CLI/sessions: accept <code>openclaw sessions list</code> as an alias for <code>openclaw sessions</code>, matching other list-style commands. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432233621" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81139/hovercard" href="https://github.com/openclaw/openclaw/issues/81139">#81139</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432597965" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81163" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81163/hovercard" href="https://github.com/openclaw/openclaw/pull/81163">#81163</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YB0y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YB0y">@YB0y</a>.</li>
<li>Channels/stream previews: widen compact progress draft lines and cut prose at word boundaries while preserving command/path suffixes, with <code>streaming.progress.maxLineChars</code> for channel-specific tuning.</li>
<li>CLI/plugins: have <code>openclaw plugins doctor</code> warn when a configured runtime needs a missing owner plugin, sharing the same install mapping as <code>openclaw doctor --fix</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4435782026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81326" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81326/hovercard" href="https://github.com/openclaw/openclaw/issues/81326">#81326</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4443400168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81674" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81674/hovercard" href="https://github.com/openclaw/openclaw/pull/81674">#81674</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zavianx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zavianx">@Zavianx</a>.</li>
<li>Agents/Codex: route OpenAI runs that resolve to <code>openai-codex</code> through the Codex provider and bootstrap OpenClaw's stored OAuth profile into the Codex harness when the harness owns transport, so <code>openai/*</code> model refs no longer fail with <code>No API key found for openai-codex</code> despite an existing Codex OAuth profile. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462142665" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82864" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82864/hovercard" href="https://github.com/openclaw/openclaw/pull/82864">#82864</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ragesaq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ragesaq">@ragesaq</a>.</li>
<li>Agents/ACP: distinguish prompt-submitted and runtime-active child stalls from true interactive waits, including redacted proxy-env diagnostics for Codex ACP no-output runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069428847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44810" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44810/hovercard" href="https://github.com/openclaw/openclaw/issues/44810">#44810</a>.</li>
<li>Agents/memory: explain that memory-triggered compaction exposes only <code>read</code> and append-only <code>write</code> when configured core tools are unavailable in <code>tools.allow</code> warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462438972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82941" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82941/hovercard" href="https://github.com/openclaw/openclaw/issues/82941">#82941</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Agents/OpenAI: preserve deterministic tool payload ordering for prompt-cache reuse across OpenAI Responses and chat completions calls. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462435142" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82940/hovercard" href="https://github.com/openclaw/openclaw/pull/82940">#82940</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>ACP/Codex: honor terminal ACP turn results so failed Codex/acpx runs are not recorded as successful after only progress text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409392717" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79522" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/79522/hovercard" href="https://github.com/openclaw/openclaw/issues/79522">#79522</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dudaefj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dudaefj">@dudaefj</a>.</li>
<li>Telegram: warn when a media group drops photos that fail to download, including albums where every photo is skipped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144617570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55216" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55216/hovercard" href="https://github.com/openclaw/openclaw/issues/55216">#55216</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462674675" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82987" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82987/hovercard" href="https://github.com/openclaw/openclaw/pull/82987">#82987</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eldar702/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eldar702">@eldar702</a>.</li>
<li>Agents/skills: apply the full effective tool policy pipeline to inline <code>command-dispatch: tool</code> skill dispatch before owner-only filtering, preserving configured allow, deny, sandbox, sender, group, and subagent restrictions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392543885" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78525" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78525/hovercard" href="https://github.com/openclaw/openclaw/pull/78525">#78525</a>)</li>
<li>Codex: avoid spawning native hook relay subprocesses for post-tool/finalize events with no registered hook handlers while preserving pre-tool safety and approval relays. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371228983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76552/hovercard" href="https://github.com/openclaw/openclaw/issues/76552">#76552</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4386233442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78004" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78004/hovercard" href="https://github.com/openclaw/openclaw/pull/78004">#78004</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evgyur/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evgyur">@evgyur</a>.</li>
<li>Channel accounts: keep top-level default channel accounts visible when named accounts are added alongside default credential material, so mixed legacy/new account configs keep resolving <code>default</code> instead of silently dropping it.</li>
<li>Agents/CLI: reject empty successful CLI subprocess replies as <code>empty_response</code> and keep them out of shared auth-profile health, so blank Claude CLI results no longer become green no-payload turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464556593" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83231" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83231/hovercard" href="https://github.com/openclaw/openclaw/issues/83231">#83231</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466129017" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83421" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83421/hovercard" href="https://github.com/openclaw/openclaw/pull/83421">#83421</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Codex/Telegram: synthesize native Codex tool progress from final turn snapshots so Telegram <code>/verbose</code> stays visible when command events arrive only at completion.</li>
<li>Codex/Telegram: deliver Codex verbose tool summaries in direct message-tool-only turns while suppressing message-send and activity-log noise. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464160180" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83186" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83186/hovercard" href="https://github.com/openclaw/openclaw/pull/83186">#83186</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kurplunkin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kurplunkin">@kurplunkin</a>.</li>
<li>Mac app: make Channels settings open faster by deferring config-schema work, avoiding startup channel probes, caching decoded channel status rows, and showing only compact quick settings instead of the full generated channel schema.</li>
<li>Control UI: include the Control UI and Gateway protocol versions in protocol-mismatch errors so stale app/dashboard pairings identify which side needs rebuilding or restarting.</li>
<li>Gateway/protocol: restore Gateway WS protocol v4 and keep <code>message.action</code> room-event metadata on the existing <code>inboundTurnKind</code> wire field while preserving internal inbound-event classification.</li>
<li>Agents/tools: prefer non-webchat session-key routes when the message tool has stale webchat context, so message-tool-only replies keep delivering to the originating channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462346514" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82911" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82911/hovercard" href="https://github.com/openclaw/openclaw/issues/82911">#82911</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462785655" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83004" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83004/hovercard" href="https://github.com/openclaw/openclaw/pull/83004">#83004</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Channels: keep direct-message last-route writes on isolated <code>per-channel-peer</code> sessions instead of contaminating the agent main session with channel delivery context. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4030119907" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/36614" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/36614/hovercard" href="https://github.com/openclaw/openclaw/issues/36614">#36614</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aspenas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aspenas">@aspenas</a>.</li>
<li>Mac app: move the Settings sidebar toggle into the native titlebar and tighten the General pane width.</li>
<li>Mac app: keep visited Settings panes mounted so switching tabs no longer blanks and reloads their content.</li>
<li>Mac app: make Config settings open from shallow schema lookups and load selected paths on demand instead of fetching and rendering the full generated config schema up front.</li>
<li>Codex: sanitize inline image payloads before Codex app-server and OpenAI Responses replay, and clear poisoned Codex thread bindings after invalid image errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462171502" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82878" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82878/hovercard" href="https://github.com/openclaw/openclaw/issues/82878">#82878</a>.</li>
<li>Providers/GitHub Copilot: request identity-encoded Copilot API responses across token exchange, catalog, model calls, usage, and embeddings so compressed Business-account error payloads no longer reach JSON parsers as gzip bytes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462159211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82871" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82871/hovercard" href="https://github.com/openclaw/openclaw/issues/82871">#82871</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tonyfe01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tonyfe01">@tonyfe01</a>.</li>
<li>Telegram: redact nested raw-update identifiers and user metadata before verbose raw update logging, preserving useful update/message ids without exposing chat, user, command, or profile details. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462443792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82945" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82945/hovercard" href="https://github.com/openclaw/openclaw/pull/82945">#82945</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Telegram: preserve replied-to bot messages, captions, and media metadata in group reply chains so follow-up replies understand what the user is reacting to. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462136761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82863/hovercard" href="https://github.com/openclaw/openclaw/pull/82863">#82863</a>)</li>
<li>Providers/Together: update PI runtime packages to 0.74.1 and emit Together-style <code>reasoning.enabled</code>/<code>max_tokens</code> controls for reasoning-capable OpenAI-completions models.</li>
<li>Agents/diagnostics: split slow embedded-run <code>attempt-dispatch</code> startup summaries into workspace, prompt, runtime-plan, and final dispatch subspans so traces identify the delayed setup phase. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461655494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82782" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82782/hovercard" href="https://github.com/openclaw/openclaw/issues/82782">#82782</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461658014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82783" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82783/hovercard" href="https://github.com/openclaw/openclaw/pull/82783">#82783</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Agents/Codex: flatten nested tool-result middleware blocks into bounded text so successful message sends are no longer replaced with <code>Tool output unavailable due to post-processing error</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462346626" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82912/hovercard" href="https://github.com/openclaw/openclaw/issues/82912">#82912</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>.</li>
<li>CLI/media: accept HTTP(S) URLs in <code>openclaw infer image describe --file</code>, fetching remote images through the guarded media path instead of treating URLs as local files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461995435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82837" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82837/hovercard" href="https://github.com/openclaw/openclaw/issues/82837">#82837</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462089264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82854" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82854/hovercard" href="https://github.com/openclaw/openclaw/pull/82854">#82854</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Agents/subagents: keep session-backed parent runs active when the child wait call times out before the child session has actually settled, so late subagent completions are reconciled instead of being lost. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461685397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82787" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82787/hovercard" href="https://github.com/openclaw/openclaw/issues/82787">#82787</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ramitrkar-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ramitrkar-hash">@ramitrkar-hash</a>.</li>
<li>Control UI: advertise shared Gateway protocol constants in browser connect frames, fixing protocol mismatch handshakes after protocol constant drift. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462182289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82882/hovercard" href="https://github.com/openclaw/openclaw/issues/82882">#82882</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Gateway: add rollback protocol-mismatch diagnostics, including client protocol ranges in Gateway logs and deep status/doctor hints for stale client processes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462019039" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82841" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82841/hovercard" href="https://github.com/openclaw/openclaw/issues/82841">#82841</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462327632" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82908" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82908/hovercard" href="https://github.com/openclaw/openclaw/pull/82908">#82908</a>)</li>
<li>Agents/subagents: keep successful keep-mode completion payloads pending after final-delivery retry exhaustion, so requester recovery no longer loses final subagent results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4459924078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82583" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82583/hovercard" href="https://github.com/openclaw/openclaw/issues/82583">#82583</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462746689" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82999" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82999/hovercard" href="https://github.com/openclaw/openclaw/pull/82999">#82999</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Gateway/auth: allow same-host trusted-proxy callers to use the documented local direct <code>gateway.auth.password</code> fallback after revisiting the <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395374595" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78684" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/78684/hovercard" href="https://github.com/openclaw/openclaw/issues/78684">#78684</a> fail-closed policy, while keeping token fallback rejected and forwarded-header requests on the trusted-proxy path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4460066638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82607/hovercard" href="https://github.com/openclaw/openclaw/issues/82607">#82607</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462463433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82953" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82953/hovercard" href="https://github.com/openclaw/openclaw/pull/82953">#82953</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents/subagents: wait for queued completion handoffs to reach the parent transcript before marking them announced, preventing busy parent runs from cleaning up before observing child results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462352234" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82913" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82913/hovercard" href="https://github.com/openclaw/openclaw/issues/82913">#82913</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463073835" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83039" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83039/hovercard" href="https://github.com/openclaw/openclaw/pull/83039">#83039</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents/subagents: route group/channel subagent completions through message-tool-only handoffs when required and keep active-requester wake failures from dropping completion delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461749992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82803/hovercard" href="https://github.com/openclaw/openclaw/issues/82803">#82803</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yozakura-ava/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yozakura-ava">@yozakura-ava</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moeedahmed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moeedahmed">@moeedahmed</a>.</li>
<li>Memory-core: scan persisted memory source sessions on startup, comparing on-disk transcripts against the index and marking only missing/newer/resized files dirty for incremental sync. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457246662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82341" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82341/hovercard" href="https://github.com/openclaw/openclaw/pull/82341">#82341</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457246662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82341" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82341/hovercard" href="https://github.com/openclaw/openclaw/pull/82341">#82341</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>Telegram: keep the top-level default account in the account list when named accounts or bindings are added alongside top-level credentials, preserving default polling while still letting named-only configs resolve to a single account. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461704391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82794/hovercard" href="https://github.com/openclaw/openclaw/pull/82794">#82794</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461704391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82794/hovercard" href="https://github.com/openclaw/openclaw/pull/82794">#82794</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>CLI/models: reuse command-scoped plugin metadata across model listing, provider catalog, auth, and synthetic-auth checks, restoring fast <code>openclaw models</code> runs for plugin-heavy installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462172294" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82881" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82881/hovercard" href="https://github.com/openclaw/openclaw/issues/82881">#82881</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463033606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83033" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83033/hovercard" href="https://github.com/openclaw/openclaw/pull/83033">#83033</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>CLI/channels: show configured official external channels such as Discord in <code>openclaw channels list</code> when their plugin package is missing, including the install and doctor repair command instead of reporting no configured channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461817834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82813" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82813/hovercard" href="https://github.com/openclaw/openclaw/issues/82813">#82813</a>.</li>
<li>Signal: preserve mixed-case group IDs through routing and session persistence so group auto-replies keep delivering after updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461907881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82827/hovercard" href="https://github.com/openclaw/openclaw/issues/82827">#82827</a>.</li>
<li>Agents/tools: keep the <code>message</code> tool available in embedded runs when it is explicitly allowed through <code>tools.alsoAllow</code> or runtime tool allowlists, so channel plugins with custom reply delivery can still use configured message sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461933704" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82833" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82833/hovercard" href="https://github.com/openclaw/openclaw/issues/82833">#82833</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cn1313113/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cn1313113">@cn1313113</a>.</li>
<li>WhatsApp: honor forced document delivery for outbound image, GIF, and video media so <code>forceDocument</code>/<code>asDocument</code> sends preserve original media bytes instead of using compressed media payloads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4404054047" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79272" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79272/hovercard" href="https://github.com/openclaw/openclaw/pull/79272">#79272</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>.</li>
<li>WhatsApp: name outbound document attachments from their MIME type when no filename is provided, so PDF and CSV sends arrive as <code>file.pdf</code> and <code>file.csv</code> instead of an extensionless <code>file</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcaxtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcaxtr">@mcaxtr</a>.</li>
<li>Process/diagnostics: report active lane blockers in lane wait warnings so <code>queueAhead=0</code> no longer hides commands waiting behind active work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461701202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82791" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82791/hovercard" href="https://github.com/openclaw/openclaw/issues/82791">#82791</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461702387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82792" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82792/hovercard" href="https://github.com/openclaw/openclaw/pull/82792">#82792</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Process/diagnostics: stop counting the active processing turn as queued backlog in liveness warnings so transient max-only event-loop spikes do not surface as gateway warnings.</li>
<li>Agents/replies: classify provider conversation-state rejections and return a clear message-channel error instead of auto-resetting or falling back to a generic runner failure. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4460117536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82616" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82616/hovercard" href="https://github.com/openclaw/openclaw/pull/82616">#82616</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dutifulbob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dutifulbob">@dutifulbob</a>.</li>
<li>Browser plugin: trust managed Chrome CDP diagnostics when launch HTTP probes race cold-start readiness, avoiding false startup failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462309858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82904" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82904/hovercard" href="https://github.com/openclaw/openclaw/issues/82904">#82904</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462674619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82986/hovercard" href="https://github.com/openclaw/openclaw/pull/82986">#82986</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kmanan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kmanan">@kmanan</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Android: prompt before replacing a changed Gateway TLS thumbprint, showing the old and new SHA-256 fingerprints so users can accept expected certificate rotations instead of hard failing on pin mismatch. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463285677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83077" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83077/hovercard" href="https://github.com/openclaw/openclaw/pull/83077">#83077</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliekens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliekens">@sliekens</a>.</li>
<li>CLI/status: render extra gateway-like service diagnostics as warning/info output instead of error output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077671100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46930" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46930/hovercard" href="https://github.com/openclaw/openclaw/issues/46930">#46930</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462392789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82922" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82922/hovercard" href="https://github.com/openclaw/openclaw/pull/82922">#82922</a>) thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>Agents/failover: classify Moonshot/Kimi exhausted-balance HTTP 429 payloads as billing instead of generic rate limits, preserving billing guidance and fallback behavior. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4060463710" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43447/hovercard" href="https://github.com/openclaw/openclaw/issues/43447">#43447</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463292018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83079" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83079/hovercard" href="https://github.com/openclaw/openclaw/pull/83079">#83079</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leno23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leno23">@leno23</a>.</li>
<li>Plugin SDK: bundle <code>openclaw/plugin-sdk/zod</code> into the published package artifact and verify the packed zod subpath stays self-contained, so pnpm global installs can register plugins without a package-local <code>zod</code> symlink. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390279612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78398" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/78398/hovercard" href="https://github.com/openclaw/openclaw/issues/78398">#78398</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392386441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78515/hovercard" href="https://github.com/openclaw/openclaw/pull/78515">#78515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ggzeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ggzeng">@ggzeng</a>.</li>
<li>Providers/Google: drop compaction-truncated Gemini thought signatures before replay so malformed Base64 no longer aborts the next assistant turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462736082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82995/hovercard" href="https://github.com/openclaw/openclaw/pull/82995">#82995</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wAngByg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wAngByg">@wAngByg</a>.</li>
<li>Gateway/mobile: allow paired iOS and Android clients to refresh same-family OS metadata on authenticated reconnect instead of requiring a new approval. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467055055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83490" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83490/hovercard" href="https://github.com/openclaw/openclaw/pull/83490">#83490</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>WhatsApp: treat <code>upload-file</code> as a supported media send intent by lowering path/URL uploads through the channel's normal send-media transport. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4448275851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81883/hovercard" href="https://github.com/openclaw/openclaw/pull/81883">#81883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>iOS: end Live Activities when OpenClaw is connected, idle, or disconnected, and show compact attention states for approval-required reconnects. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469191547" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83597" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83597/hovercard" href="https://github.com/openclaw/openclaw/pull/83597">#83597</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>Control UI: hide child nav items when collapsing the active sidebar group. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051748466" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42167" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42167/hovercard" href="https://github.com/openclaw/openclaw/issues/42167">#42167</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052169484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42223" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42223/hovercard" href="https://github.com/openclaw/openclaw/pull/42223">#42223</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aroool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aroool">@Aroool</a>.</li>
<li>CI/proof: skip the real-behavior-proof gate for private org maintainers by minting a least-privilege (<code>members: read</code>) GitHub App token and checking active membership in the <code>maintainer</code> team, instead of treating <code>author_association=CONTRIBUTOR</code> as definitively external. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466090722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83418" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83418/hovercard" href="https://github.com/openclaw/openclaw/pull/83418">#83418</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is rewriting the software development playbook]]></title>
<description><![CDATA[A few years ago, AI in software development meant autocomplete that occasionally guessed your variable name. Today, it means something closer to having an extra engineer sitting next to you — one who never sleeps, never complains about context switching and has read more code than any human alive...]]></description>
<link>https://tsecurity.de/de/3525705/it-security-nachrichten/ai-is-rewriting-the-software-development-playbook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525705/it-security-nachrichten/ai-is-rewriting-the-software-development-playbook/</guid>
<pubDate>Mon, 18 May 2026 13:07:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A few years ago, AI in software development meant autocomplete that occasionally guessed your variable name. Today, it means something closer to having an extra engineer sitting next to you — one who never sleeps, never complains about context switching and has read more code than any human alive. In fact, you can have a whole extra engineering team if you’re crafty with orchestration. The shift has been gradual, but it’s accelerating quickly, and AI is no longer a novelty feature tucked inside your IDE. Instead, it’s becoming the connective tissue of how software actually gets built. Engineering teams have to adopt or risk hopelessly falling behind.</p>



<h2 class="wp-block-heading">From autocomplete to autonomous agent</h2>



<p>The early generation of AI coding tools was fundamentally autocomplete engines with better training data. Useful, sure. But they didn’t change the job of software engineering. A developer still had to do the thinking, the planning and the debugging; the tools just saved some keystrokes.</p>



<p>What’s different now is the emergence of agentic AI systems. These aren’t tools that suggest the next line. They’re systems that can take an instruction (e.g., “add input validation to the checkout form and write tests for it”) and execute across multiple files, run a test suite, identify failures and automatically fix them. The developer’s job is shifting from writing code to planning, directing, reviewing and refining. In other words, acting more as an engineering lead or product manager than a coder.</p>



<p>At Nutrient, we made Claude Code, Codex and other coding agents available across our entire engineering team, leveraging company accounts with liberal usage limits. Usage of agentic AI at this point isn’t only recommended, it’s mandated: We only write code manually as a fallback. The organization shift certainly wasn’t an easy one, and we still have different levels of agentic orchestration proficiency across the team. However, for those leading the pack, we see an immense increase in productivity and impact. As a result, the number of impact-weighted pull requests (self-contained code changes, weighted by complexity) has nearly doubled across the organization in the span of a few months, as attested by our homegrown engineering metrics tool.</p>



<h2 class="wp-block-heading">AI across the full development lifecycle</h2>



<p>The impact of AI isn’t limited to the act of writing code; it’s showing up at every stage of how software gets built, tested and maintained.</p>



<p><a href="https://www.cio.com/article/4134741/how-agentic-ai-will-reshape-engineering-workflows-in-2026.html">We’re approaching the point</a> where planning, design, testing and even debugging are becoming implementation details. Engineers are now focusing on clearly defining the desired outcomes and then orchestrating tooling in a way that it can execute agentic loops with validation feedback. The feedback can still come from humans, but even that can be made so it’s automatically obtained by agents. Say we want to improve the performance of a specific module — often considered an advanced engineering task. If we start by creating good benchmarks, we can simply leverage them to let an agent loop overnight and try different methods to activate better performance. All the engineer has to do in the morning is review a report and pick the winner.</p>



<p>Depending on the task, engineers now have the choice of how involved they want to be in each step of the process. Sometimes you want to brainstorm a detailed plan together with your AI coworker, and other times you want it to one-shot solve a problem. Understanding what is the right choice for any given task is becoming a key new skill software engineers need to develop.</p>



<p>The fact is that every stage of the software development process needs to get faster to truly reap the promised boost from agentic AI. Code review needs to be assisted by agentic analysis and FAQ with your agent, QA testing needs to leverage agents for faster orchestration, and release notes and documentation need to be authored by AI. Failing to make these crucial adjustments just shifts bottlenecks to a different part of the organization.</p>



<p>There’s a fear that this kind of work will lead to code nobody understands, but if we’re honest with ourselves, that’s already the case for any decently large codebase written by humans. If anything, AI has become genuinely useful to counter this issue. Codebases accumulate entropy. The original authors leave. Documentation rots. AI can help reverse-engineer intent from implementation in ways that would have previously taken days of careful archaeology.</p>



<h2 class="wp-block-heading">The competition is real…and it’s good for developers</h2>



<p>The AI coding market is a hot race, and it’s one worth paying attention to. Alongside the major platform players, a wave of purpose-built tools has emerged, some focused narrowly on specific parts of the workflow, and others attempting to own the full stack of AI-assisted development.</p>



<p>Cursor has built a devoted following among professional developers for its deep codebase integration and model flexibility, with Copilot’s VS Code integration giving it a run for its money. Claude Code and Codex have now become the frontrunners for truly agentic coding, though there are a lot of other choices available, like the open-source minimal coding agent PI. At the same time, Replit and Lovable are pushing the boundary of what’s possible for non-traditional developers, and we of course have projects like OpenClaw for agents that can go well beyond coding.</p>



<p>What Google I/O and Microsoft Build will likely reveal this May is how the platform incumbents respond to this fragmentation. Both companies have the distribution advantage: If you’re already using some of their tooling — be it VS Code, Google Cloud, or Google Workspace — the path of least resistance is the AI tooling they bundle in. But the easiest route doesn’t always win in developer tooling, where engineers have strong opinions and will switch if a better option exists.</p>



<p>The competitive pressure between these players is, on balance, good for working developers. It means faster iteration, more model choice, better pricing and tools that are actually being shaped by real engineering feedback rather than product marketing.</p>



<h2 class="wp-block-heading">What this means for the developer role</h2>



<p>The question that comes up whenever AI makes a meaningful leap in capability — “Will this replace developers?” — keeps getting asked, and it keeps getting the same honest answer: not in the way people fear, but yes, the job is changing, and only those willing to adapt quickly and fully will have a future in it.</p>



<p>What AI is actually doing is compressing the distance between a developer’s intention and working code. That’s valuable, but it creates a new set of demands. Developers who can clearly articulate what they want, who understand enough about a system to evaluate whether the AI’s output is correct and who can maintain judgment about when to trust the tool and when to push back will become more productive. <a href="https://metr.org/blog/2025-07-10-early-2025-ai-experienced-os-dev-study/" rel="nofollow">Developers who use AI as a black box</a>, accepting its output uncritically, create a different kind of problem.</p>



<p>There’s also a shift in what senior engineering judgment gets spent on. When AI handles more of the implementation work, the scarce resource isn’t code volume; it’s architecture, system thinking and the kind of contextual knowledge that only comes from having built and maintained real systems at scale. Those skills matter more, not less, when the tools around you are more powerful.</p>



<p>Communication becomes a technical skill in a more literal sense. Prompting an AI agent well isn’t trivial. Describing a problem with enough precision to get a useful result, without overspecifying in ways that constrain the solution space unnecessarily, is genuinely hard. Teams that develop that skill as a shared practice will outperform teams that treat it as an individual quirk.</p>



<h2 class="wp-block-heading">The uncomfortable truth about what comes next</h2>



<p>Let’s be honest about something the industry tends to dance around: We aren’t incrementally improving software development; we’re dismantling its fundamental assumptions. The notion that building software requires large, specialized teams working in lockstep over months-long cycles is quickly becoming obsolete. A single engineer with the right agentic setup can now achieve what once required a small squad, and that gap is only widening.</p>



<p>This isn’t a comfortable realization for everyone. It raises hard questions about team structure, hiring and what “seniority” even means when a junior developer with excellent AI orchestration skills can outpace a veteran who refuses to adapt. At Nutrient, we’ve already seen this dynamic play out. The engineers who leaned in early aren’t just faster; they’re operating at a fundamentally different altitude, thinking in systems and outcomes rather than lines and files.</p>



<p>The real risk isn’t that AI replaces developers. It’s that the industry splits into two tiers: those who’ve internalized AI as a core part of how they think and work, and those still treating it as a feature they’ll get around to learning. That second group is running out of runway. The window to adapt isn’t closing eventually. It’s closing now.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nothing Phone 4a Pro review: premium aluminium meets quirky design]]></title>
<description><![CDATA[Mid-range Android stands out with huge screen, slick software and dot-matrix display, but falls just short of greatnessNothing’s latest quirky smartphone is a huge aluminium Android with three cameras and a big LED matrix screen on the back that challenges the notion mid-range phones can’t be jus...]]></description>
<link>https://tsecurity.de/de/3525021/it-nachrichten/nothing-phone-4a-pro-review-premium-aluminium-meets-quirky-design/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525021/it-nachrichten/nothing-phone-4a-pro-review-premium-aluminium-meets-quirky-design/</guid>
<pubDate>Mon, 18 May 2026 08:31:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mid-range Android stands out with huge screen, slick software and dot-matrix display, but falls just short of greatness</p><p>Nothing’s latest quirky smartphone is a huge aluminium Android with three cameras and a big LED matrix screen on the back that challenges the notion mid-range phones can’t be just a bit more fun.</p><p>The Phone 4a Pro is a bit of a departure from UK-based Nothing’s previous glass-clad <a href="https://www.theguardian.com/technology/2023/jul/14/nothing-phone-2-review-novel-mobile-is-more-than-just-flashing-lights">transparent designs</a>. It still has a touch of those elements but only in the camera island at the top, with the rest of the body now solid aluminium – a rare sight in the world of Android phones.</p> <a href="https://www.theguardian.com/technology/2026/may/18/nothing-phone-4a-pro-review-premium-aluminium-quirky-design">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Use Notes on Mac Like a Pro: Complete Beginner to Advanced Guide]]></title>
<description><![CDATA[Apple’s Notes app has quietly evolved from a basic note-taking tool into one of the most useful productivity apps on macOS. What makes it stand out is how deeply it connects with the Apple ecosystem while still staying simple enough for everyday use. 



You can create quick reminders, scan docum...]]></description>
<link>https://tsecurity.de/de/3524039/ios-mac-os/how-to-use-notes-on-mac-like-a-pro-complete-beginner-to-advanced-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3524039/ios-mac-os/how-to-use-notes-on-mac-like-a-pro-complete-beginner-to-advanced-guide/</guid>
<pubDate>Sun, 17 May 2026 18:24:09 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple’s Notes app has quietly evolved from a basic note-taking tool into one of the most useful productivity apps on macOS. What makes it stand out is how deeply it connects with the Apple ecosystem while still staying simple enough for everyday use. 



You can create quick reminders, scan documents, organize research with tags, collaborate with others, lock sensitive notes, and sync everything across your iPhone, iPad, and Mac through iCloud.



The biggest reason many Mac users stick with Notes instead of switching to apps like Evernote or Notion is speed. The app launches instantly, supports keyboard shortcuts, handles attachments smoothly, and works offline. With recent macOS updates, Apple has also improved Smart Folders, Quick Notes, widgets, collaboration tools, and cross-linking between notes.



Here’s a complete guide on how to use Notes on Mac properly and organize your workflow more efficiently.



Add and Remove Notes Accounts



The Notes app supports multiple accounts, which means you can manage personal, work, and school notes separately.



Supported account types




iCloud



Google



Microsoft Exchange



Yahoo



AOL



Other CalDAV and CardDAV accounts




Steps to add a Notes account on Mac




Open System Settings on your Mac.



Scroll down in the sidebar and click Internet Accounts.



Click Add Account.



Select your account provider.



Sign in with your account credentials.



Enable the toggle next to Notes.



Click Done.




Steps to remove an account




Go to System Settings &gt; Internet Accounts.



Select the account.



Disable the Notes toggle or remove the account completely.




This is useful if you want separate note libraries for work and personal use.







Set Up iCloud for Notes on Mac



iCloud sync is one of the best features in Apple Notes because it keeps your notes updated across all Apple devices instantly.



Steps to enable iCloud sync for Notes




Open System Settings.



Click your Apple ID at the top.



Select iCloud.



Click Show More Apps.



Select Notes.



Turn on Sync this Mac.




Once enabled, any note created on your Mac will appear automatically on your iPhone or iPad.







Customize the Notes Toolbar



The toolbar can save a lot of time if you frequently use formatting tools, tables, checklists, or attachments.



Steps to customize the toolbar




Open the Notes app.



Right-click the toolbar area.



Select Customize Toolbar.



Drag your preferred tools into the toolbar.



Rearrange them based on your workflow.



Click Done.




Many power users place the checklist, attachment, and formatting buttons directly in the toolbar for faster access.







Change Your Notes View



Apple Notes offers two layouts.



Available views




List View



Gallery View




How to switch views




Open Notes.



Click View in the Menu Bar.



Choose either:

List View



Gallery View






List View is better for heavy note-taking, while Gallery View works well for visual projects with images and attachments.







Write Notes on Mac



Creating notes is extremely straightforward, but the real advantage comes from how quickly Notes opens and syncs.



Steps to create a note




Open Notes.



Click the Compose button.



Start typing.




You can create:




Personal journals



Meeting notes



Research collections



Shopping lists



Project plans



Study material








Format Text in Notes



Formatting helps make long notes easier to read.



Formatting options available




Title



Heading



Subheading



Bold



Italic



Underline



Strikethrough



Lists



Block Quotes



Monostyled text




Steps to format text




Highlight the text.



Click the Format button.



Choose your preferred formatting style.




You can also access advanced formatting from the Menu Bar.







Use Quick Notes on Mac



Quick Notes is one of the most underrated macOS productivity features.



It lets you instantly save text, ideas, links, or reminders without opening the full Notes app.



Method 1: Keyboard Shortcut




Press Fn + Q.



A Quick Note window appears.



Type or paste your content.




Method 2: Hot Corners




Open System Settings.



Go to Desktop &amp; Dock.



Scroll down and select Hot Corners.



Assign Quick Note to a screen corner.



Move your cursor to that corner anytime to launch Quick Notes.




This feature becomes especially useful during research sessions or while watching videos.







Add a Table to a Note



Tables are useful for organizing structured information.




Open a note.



Click the Table icon.



A 2×2 table appears automatically.




To add rows or columns




Click the dots beside rows or columns.



Select:

Add Row



Add Column



Delete Row



Delete Column






Tables work well for:




Expense tracking



Content calendars



Study comparisons



Meeting schedules








Create Lists in Notes



Lists help turn Notes into a lightweight task manager.




Open a note.



Click the Checklist button.



Start adding items.




You can also type:




- for bullet lists



1. for numbered lists








Add Links to a Note



Smart Links automatically convert URLs into clickable previews.




Open Notes.



Go to Edit &gt; Substitutions.



Enable Smart Links.



Paste a URL.



Press Enter.




Notes automatically converts the URL into a rich link.







Cross-Link Your Notes



Cross-linking turns Notes into a connected knowledge system.




Right-click inside a note.



Select Add Link.



Search for another note.



Select it.



Click OK.




This is extremely useful for large projects or research databases.







Attach Photos, PDFs, and Files



Apple Notes handles attachments surprisingly well.



Supported attachments




Photos



PDFs



Videos



Documents



Scanned files




Steps to attach files




Open a note.



Drag files directly into the note.




Or:




Click File &gt; Attach File.



Select the file.



Click Attach.




You can also scan documents using your iPhone directly from the Mac Notes app.







Mark Up and Edit Attachments



You can annotate PDFs and images without leaving Notes.




Hover over the attachment.



Click the down arrow.



Select Markup.




This works especially well for reviewing contracts, screenshots, or study material.







View Notes in Pages



Sometimes Notes becomes too limiting for large documents.




Open the note.



Click File.



Select Open in Pages.




This is useful when turning rough drafts into polished documents.







Lock Notes on Mac



Locked notes protect sensitive information.




Right-click a note.



Select Lock Note.



Enter your Mac password.



Enable Touch ID if available.




Common use cases:




Password storage



Personal journals



Financial information



Confidential work notes








Change Password for Locked Notes




Open Notes.



Click File &gt; Settings.



Go to Locked Notes.



Choose:

Use Login Password



Use Custom Password






Remember that custom passwords cannot be recovered if forgotten.







Use Touch ID with Notes



Touch ID makes locked notes much easier to access.



Requirements




A Mac with Touch ID



Notes password enabled




Steps




Open a locked note.



Place your finger on the Touch ID sensor.




The note unlocks instantly.







Organize Notes with Folders



Folders are essential once your note library grows.



Steps to create folders




Open Notes.



Click New Folder.



Enter a folder name.



Click OK.




Steps to delete folders




Right-click the folder.



Select Delete Folder.








Use Tags in Notes



Tags make searching dramatically faster.



Examples




#work



#ideas



#travel



#receipts




Steps to create tags




Type #.



Enter the tag name.



Press Enter.




To rename or delete tags




Open the Tags section.



Right-click a tag.



Select Rename or Delete.








Set the Default Sorting Method



Sorting options




Date Edited



Date Created



Title




Steps




Open Notes Settings.



Find Sort Notes By.



Choose your preferred sorting style.




Most users prefer Date Edited because recently updated notes stay at the top.







Pin Important Notes



Pinned notes always stay at the top.



Steps




Right-click the note.



Select Pin Note.




This works well for:




Daily tasks



Work dashboards



Important reminders








Delete and Recover Notes



Delete Notes




Right-click the note.



Select Delete.




Recover Deleted Notes




Open Recently Deleted.



Right-click the note.



Select Move To.



Choose the destination folder.




Deleted notes remain recoverable for 30 days.







Create Smart Folders



Smart Folders automatically organize notes using filters.




Click New Folder.



Enable Make into Smart Folder.



Choose filters.



Click OK.




You can filter notes using:




Tags



Attachments



Shared notes



Checklists








Search Notes Quickly



The search feature in Apple Notes is surprisingly powerful.




Click the Search icon.



Enter keywords.



Browse suggested results.




Search also scans:




Attachments



PDFs



Handwritten text



Scanned documents








Collaborate with Others



Shared Notes supports real-time collaboration.




Open a note.



Click the Share button.



Invite users.



Set permissions.




This is useful for:




Team projects



Shared grocery lists



Study groups



Family planning








Import Notes into Apple Notes



Apple Notes supports importing files and Evernote exports.




Open Notes.



Select a folder.



Click File &gt; Import to Notes.



Choose files.



Click Import.








Export Notes as PDF




Open the note.



Click File &gt; Export as PDF.



Choose a save location.



Click Save.




PDF export is useful for backups and sharing documents outside Apple devices.







Manage Notifications in Shared Notes




Open a shared note.



Click the People icon.



Select Manage Shared Note.



Enable or disable alerts.




This helps reduce notification clutter in busy collaborations.







Use Notes Widgets on Mac



Widgets give instant access to important notes.



Add Notes Widget to Notification Center




Click the date and time.



Select Edit Widgets.



Choose Notes.



Add your preferred widget.




Add Notes Widget to Desktop




Right-click the desktop.



Select Edit Widgets.



Drag the Notes widget onto the desktop.








Best Keyboard Shortcuts for Notes on Mac



ActionShortcutNew NoteCommand + NQuick NoteFn + QNew FolderShift + Command + NSearch NotesOption + Command + FAttach FileShift + Command + AInsert TableOption + Command + TPrint NoteCommand + P



Learning these shortcuts can noticeably speed up your workflow.







FAQs



Is Apple Notes free on Mac? Yes. Apple Notes is completely free and comes pre-installed on macOS.  Does Apple Notes work offline? Yes. Notes stored locally remain accessible offline.  Can Apple Notes replace Evernote? For many users, yes. Apple Notes now supports tags, Smart Folders, collaboration, attachments, and Quick Notes.  Are Notes synced across Apple devices? Yes, through iCloud sync.  Can you recover permanently deleted notes? Usually no. Once removed from Recently Deleted, recovery becomes difficult unless backed up elsewhere.  







Summary




Apple Notes has evolved into a full productivity and organization app.



iCloud sync keeps notes updated across Apple devices.



Quick Notes is one of the fastest ways to capture ideas on macOS.



Tags, Smart Folders, and pinned notes improve organization significantly.



Locked notes and Touch ID add privacy and security.



Attachments, tables, and collaboration tools make Notes useful for both personal and professional workflows.



Widgets and keyboard shortcuts help speed up daily note-taking tasks.




Conclusion



The Notes app on Mac is much more powerful than many users realize. It combines simplicity with advanced productivity tools in a way that feels fast and natural on macOS. Whether you are organizing work projects, writing study notes, managing personal tasks, or storing important documents, Apple Notes can easily become the center of your workflow.



Once you start using features like Quick Notes, Smart Folders, note linking, widgets, and iCloud sync regularly, the app becomes far more than a basic notebook. It turns into a lightweight productivity system that works seamlessly across the Apple ecosystem.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.14.0 (2026.5.16)]]></title>
<description><![CDATA[Hermes Agent v0.14.0 (v2026.5.16)
Release Date: May 16, 2026
Since v0.13.0: 808 commits · 633 merged PRs · 1393 files changed · 165,061 insertions · 545 issues closed (12 P0, 50 P1) · 215 community contributors (including co-authors)

The Foundation Release — Hermes Agent installs and runs anywhe...]]></description>
<link>https://tsecurity.de/de/3521849/downloads/hermes-agent-v0140-2026516/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3521849/downloads/hermes-agent-v0140-2026516/</guid>
<pubDate>Sat, 16 May 2026 12:01:41 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.14.0 (v2026.5.16)</h1>
<p><strong>Release Date:</strong> May 16, 2026<br>
<strong>Since v0.13.0:</strong> 808 commits · 633 merged PRs · 1393 files changed · 165,061 insertions · 545 issues closed (12 P0, 50 P1) · 215 community contributors (including co-authors)</p>
<blockquote>
<p>The Foundation Release — Hermes Agent installs and runs anywhere now. Native Windows ships in early beta with a full PowerShell installer story, a <code>pip install hermes-agent</code> wheel lands on PyPI, lazy-deps reshape what <code>pip install hermes-agent</code> actually pulls down, the supply-chain checker scans every install/upgrade for unsafe versions, and a new OpenAI-compatible local proxy lets Codex / Aider / Cline talk to OAuth-only providers (Claude Pro, ChatGPT Pro, SuperGrok). The cold-start wave shaves ~19 seconds off <code>hermes</code> launch, browser-tool CDP calls run 180x faster, and <code>hermes tools</code> All-Platforms drops from 14s to under 1.5s. Two new messaging platforms (LINE and SimpleX Chat) and a Microsoft Graph foundation (Teams pipeline + webhook adapter) land alongside <code>/handoff</code> that finally transfers sessions live, <code>vision_analyze</code> passing pixels through to vision-capable models, <code>x_search</code> as a first-class tool, LSP semantic diagnostics on every <code>write_file</code> / <code>patch</code>, a unified pluggable <code>video_generate</code>, a <code>computer_use</code> cua-driver backend, cross-session 1-hour Claude prompt caching, a per-turn file-mutation verifier, plus 9 new optional skills. 50+ P1 closures, 12 P0 closures.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Native Windows support (early beta)</strong> — full PowerShell installer, native subprocess/PTY paths, taskkill-based process management, MinGit auto-install, Microsoft Store python stub detection, foreground Ctrl+C preservation, taskkill+ps2 fallback, npm prefix handling, and ~40 follow-up Windows-only fixes across CLI / gateway / TUI / curator / tools. Hermes finally runs natively on <code>cmd.exe</code> and PowerShell, no WSL required. (<a href="https://github.com/NousResearch/hermes-agent/pull/21561" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21561/hovercard">#21561</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22130" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22130/hovercard">#22130</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22752/hovercard">#22752</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26618" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26618/hovercard">#26618</a>, and many more)</p>
</li>
<li>
<p><strong><code>pip install hermes-agent &amp;&amp; hermes</code></strong> — Hermes Agent is now a real PyPI package. One command, no clone, no git, no shell installer. Wheel includes the Ink TUI bundle and shell launcher. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/26350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26350/hovercard">#26350</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26593/hovercard">#26593</a>)</p>
</li>
<li>
<p><strong>Cold-start performance wave — ~19s off <code>hermes</code> launch</strong> — skills cache, lazy Feishu import, no Nous HTTP at startup, plus PEP-562 lazy adapter imports (QQ, Yuanbao, Teams, Google Chat), deferred <code>fal_client</code> / <code>google-cloud</code> / <code>httpx</code> loads, models.dev disk-cache-first lookup, parallel doctor API checks, eager-skip plugin discovery on built-in subcommands, <code>hermes tools</code> All-Platforms drops from 14s to &lt;1.5s, welcome banner skipped on <code>chat -q</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/22138" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22138/hovercard">#22138</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22120/hovercard">#22120</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22681/hovercard">#22681</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22790" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22790/hovercard">#22790</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22808" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22808/hovercard">#22808</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22831" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22831/hovercard">#22831</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22859/hovercard">#22859</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22904" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22904/hovercard">#22904</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22766" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22766/hovercard">#22766</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25341" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25341/hovercard">#25341</a>)</p>
</li>
<li>
<p><strong>180x faster <code>browser_console</code> evaluations</strong> — routed through the supervisor's persistent CDP WebSocket instead of spawning a fresh DevTools session per call. Real-world page interactions feel instant. (<a href="https://github.com/NousResearch/hermes-agent/pull/23226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23226/hovercard">#23226</a>)</p>
</li>
<li>
<p><strong>Supply-chain advisory checker + lazy-deps framework + tiered install fallback</strong> — every <code>pip install</code> / <code>hermes update</code> scans dependencies against an advisory list, lazy-deps replace heavy import-time loads with first-use installs, and the installer falls back through extras tiers when a wheel rejects on the target platform. (<a href="https://github.com/NousResearch/hermes-agent/pull/24220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24220/hovercard">#24220</a>)</p>
</li>
<li>
<p><strong>OpenAI-compatible local proxy</strong> — <code>hermes proxy</code> exposes any OAuth-authed provider (Claude Pro, ChatGPT Pro, SuperGrok) as an OpenAI-compatible endpoint that Codex / Aider / Cline / VS Code Continue can hit. Your subscription, your tools. (<a href="https://github.com/NousResearch/hermes-agent/pull/25969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25969/hovercard">#25969</a>)</p>
</li>
<li>
<p><strong>Cross-session 1-hour Claude prompt cache</strong> — Anthropic / OpenRouter / Nous Portal now share a 1h prefix cache across sessions for Claude models. Fast resume, fast <code>/new</code>, lower cost on repeat work. (<a href="https://github.com/NousResearch/hermes-agent/pull/23828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23828/hovercard">#23828</a>)</p>
</li>
<li>
<p><strong>Two new messaging platforms — LINE + SimpleX Chat</strong> — LINE Messaging API lands as a first-class platform, SimpleX Chat salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117407388" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2558" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2558/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2558">#2558</a> onto the modern adapter spec. Hermes is now on 22 platforms. (<a href="https://github.com/NousResearch/hermes-agent/pull/23197" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23197/hovercard">#23197</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26232/hovercard">#26232</a>)</p>
</li>
<li>
<p><strong>Microsoft Graph foundation — Teams pipeline + webhook adapter</strong> — <code>msgraph</code> auth/client foundation, webhook listener platform, Teams pipeline plugin runtime, and Teams outbound delivery via the existing adapter — Hermes can now read and post to Teams. (salvages of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400317607" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21408" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21408/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21408">#21408</a>–<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400321291" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21411" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21411/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21411">#21411</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21922" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21922/hovercard">#21922</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21969/hovercard">#21969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22007/hovercard">#22007</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22024" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22024/hovercard">#22024</a>)</p>
</li>
<li>
<p><strong><code>/handoff</code> actually transfers the session live</strong> — the agent's active session moves to a different model / persona / profile mid-conversation, with messages, tool history, and context preserved. (<a href="https://github.com/NousResearch/hermes-agent/pull/23395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23395/hovercard">#23395</a>)</p>
</li>
<li>
<p><strong><code>x_search</code> — first-class X (Twitter) search tool</strong> — gated tool with OAuth-or-API-key auth, no skill needed to query the timeline. (<a href="https://github.com/NousResearch/hermes-agent/pull/26763" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26763/hovercard">#26763</a>)</p>
</li>
<li>
<p><strong><code>vision_analyze</code> returns pixels to vision-capable models</strong> — when the active model can see, <code>vision_analyze</code> now hands the image straight through instead of falling back to a text description. (<a href="https://github.com/NousResearch/hermes-agent/pull/22955" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22955/hovercard">#22955</a>)</p>
</li>
<li>
<p><strong>LSP semantic diagnostics on every write</strong> — <code>write_file</code> and <code>patch</code> now run real language-server diagnostics on the post-edit file (delta-only) and surface real errors before they ship downstream. (<a href="https://github.com/NousResearch/hermes-agent/pull/24168" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24168/hovercard">#24168</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25978" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25978/hovercard">#25978</a>)</p>
</li>
<li>
<p><strong>Per-turn file-mutation verifier footer</strong> — after every turn that wrote files, the agent gets a verifier footer summarizing what actually changed on disk — catches silent overwrites and "wrote it but it didn't land" bugs. (<a href="https://github.com/NousResearch/hermes-agent/pull/24498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24498/hovercard">#24498</a>)</p>
</li>
<li>
<p><strong>Unified <code>video_generate</code> with pluggable provider backends</strong> — single tool, any backend. Drop in a new video provider as a plugin, no core changes. (<a href="https://github.com/NousResearch/hermes-agent/pull/25126" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25126/hovercard">#25126</a>)</p>
</li>
<li>
<p><strong><code>computer_use</code> cua-driver backend</strong> — proper focus-safe ops, non-Anthropic provider support, refresh on <code>hermes update</code>. Computer-use is no longer locked to a single SDK. (re-salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341933760" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16936" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16936/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16936">#16936</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21967" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21967/hovercard">#21967</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/24063" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24063/hovercard">#24063</a>)</p>
</li>
<li>
<p><strong>xAI Grok OAuth provider — SuperGrok via subscription</strong> — sign in with your xAI account, talk to Grok models from Hermes. (<a href="https://github.com/NousResearch/hermes-agent/pull/26534" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26534/hovercard">#26534</a>)</p>
</li>
<li>
<p><strong>Clarify with buttons — native inline keyboards on Telegram + Discord</strong> — the <code>clarify</code> tool renders multi-choice prompts as platform-native buttons instead of typed responses. (<a href="https://github.com/NousResearch/hermes-agent/pull/24199" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24199/hovercard">#24199</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25485" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25485/hovercard">#25485</a>)</p>
</li>
<li>
<p><strong>Discord channel history backfill (default on)</strong> — Hermes reads recent channel history when joining a thread so it actually knows what's been said. (<a href="https://github.com/NousResearch/hermes-agent/pull/25984" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25984/hovercard">#25984</a>)</p>
</li>
<li>
<p><strong>Watchers skill — RSS / HTTP JSON / GitHub polling via cron <code>no_agent</code> mode</strong> — skill recipes that wire change-detection sources directly into cron's script-only watchdog mode. (<a href="https://github.com/NousResearch/hermes-agent/pull/21881" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21881/hovercard">#21881</a>)</p>
</li>
<li>
<p><strong>Zed ACP Registry integration + uvx distribution</strong> — Hermes is in the Zed registry, installable via <code>uvx</code> (no npm). Plus <code>hermes acp --setup-browser</code> bootstraps browser tools for registry installs. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/25908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25908/hovercard">#25908</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26079" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26079/hovercard">#26079</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26120/hovercard">#26120</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26234" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26234/hovercard">#26234</a>)</p>
</li>
<li>
<p><strong>OpenRouter Pareto Code router</strong> — wire a new OpenRouter router with <code>min_coding_score</code> knob. Pick the cheapest model that meets your quality bar. (<a href="https://github.com/NousResearch/hermes-agent/pull/22838" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22838/hovercard">#22838</a>)</p>
</li>
<li>
<p><strong>Optional codex app-server runtime for OpenAI/Codex models</strong> — drives the OpenAI Codex CLI under the hood for OpenAI/Codex paths, with session reuse, wedge retirement, and OAuth refresh classification. (<a href="https://github.com/NousResearch/hermes-agent/pull/24182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24182/hovercard">#24182</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25769" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25769/hovercard">#25769</a>)</p>
</li>
<li>
<p><strong><code>hermes-skills/huggingface</code> as a trusted default tap</strong> — community skills index from huggingface.co/skills is available by default in the Skills Hub. (<a href="https://github.com/NousResearch/hermes-agent/pull/26219" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26219/hovercard">#26219</a>)</p>
</li>
<li>
<p><strong>9 new optional skills</strong> — Hyperliquid (perp/spot trading via SDK + REST) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> &amp; Hermes), Yahoo Finance market data, api-testing (REST/GraphQL debug), unified EVM multi-chain skill (folds <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4441931751" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25291" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25291/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25291">#25291</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098909401" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2010" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2010/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2010">#2010</a> + base/), darwinian-evolver, osint-investigation (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4020048213" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/355" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/355/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/355">#355</a>), pinggy-tunnel, watchers (RSS/HTTP/GitHub via cron), Notion overhaul for the Developer Platform (May 2026). (<a href="https://github.com/NousResearch/hermes-agent/pull/23582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23582/hovercard">#23582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/23583" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23583/hovercard">#23583</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/23590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23590/hovercard">#23590</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25299" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25299/hovercard">#25299</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26760" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26760/hovercard">#26760</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26729" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26729/hovercard">#26729</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26765" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26765/hovercard">#26765</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21881" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21881/hovercard">#21881</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26612" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26612/hovercard">#26612</a>)</p>
</li>
<li>
<p><strong>API server exposes run approval events</strong> — long-running runs surface approval requests over the API stream, no more silent stalls. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/20311" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20311/hovercard">#20311</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21899" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21899/hovercard">#21899</a>)</p>
</li>
<li>
<p><strong><code>/subgoal</code> — user-added criteria appended to active <code>/goal</code></strong> — layer extra success criteria onto a running goal loop. The judge sees them in the prompt, no behavior change when subgoals are empty. (<a href="https://github.com/NousResearch/hermes-agent/pull/25449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25449/hovercard">#25449</a>)</p>
</li>
<li>
<p><strong>Plugins can run any LLM call via <code>ctx.llm</code></strong> — plugins get a first-class hook to make their own LLM requests through the active provider/credentials, no manual wiring. Plus <code>tool_override</code> flag for replacing built-in tools. (<a href="https://github.com/NousResearch/hermes-agent/pull/23194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23194/hovercard">#23194</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26759/hovercard">#26759</a>)</p>
</li>
<li>
<p><strong>Brave Search (free tier) + DuckDuckGo (DDGS) as web-search providers</strong> — two new free search backends alongside Tavily / SearXNG / Exa. (<a href="https://github.com/NousResearch/hermes-agent/pull/21337" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21337/hovercard">#21337</a>)</p>
</li>
<li>
<p><strong>Sudo brute-force block + sudo-stdin/askpass DANGEROUS classification</strong> — closes the <code>sudo -S</code> brute-force avenue; approval gates classify stdin-fed and askpass-stripped sudo invocations as dangerous. (salvages of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4410605303" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22194/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22194">#22194</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4397828876" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21128" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21128/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21128">#21128</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23736" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23736/hovercard">#23736</a>)</p>
</li>
<li>
<p><strong>Provider rename — Alibaba Cloud → Qwen Cloud, picker reorder</strong> — matches what the world calls it. Existing config keys still work. (<a href="https://github.com/NousResearch/hermes-agent/pull/24835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24835/hovercard">#24835</a>)</p>
</li>
</ul>
<hr>
<h2>🪟 Windows — Native Support (Early Beta)</h2>
<h3>Bootstrap &amp; installer</h3>
<ul>
<li><strong>Native Windows support (early beta)</strong> — first-class native Windows path across CLI / gateway / TUI / tools (<a href="https://github.com/NousResearch/hermes-agent/pull/21561" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21561/hovercard">#21561</a>)</li>
<li><strong>PyPI wheel packaging — <code>pip install hermes-agent &amp;&amp; hermes</code></strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454164335" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/26350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26350/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/26350">#26350</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26593/hovercard">#26593</a>)</li>
<li><strong>Recognise Shift+Enter as a newline key</strong> + Windows docs (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4402428863" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21545" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21545/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21545">#21545</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22130" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22130/hovercard">#22130</a>)</li>
<li><strong>Preserve Ctrl+C for Windows foreground runs</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22752/hovercard">#22752</a>)</li>
<li><strong>Stop spamming cwd-missing + tirith-spawn warnings on every terminal call</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26618" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26618/hovercard">#26618</a>)</li>
<li><strong>Use <code>--extra all</code> not <code>--all-extras</code>; drop lazy-covered extras from <code>[all]</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24515/hovercard">#24515</a>)</li>
</ul>
<h3>Windows-specific fixes (40+ across cli / tools / gateway / curator / TUI)</h3>
<p>A long tail of native-Windows fixes shipped alongside the beta — taskkill-based subprocess management, MinGit auto-install, Microsoft Store python stub detection, npm prefix handling, native PTY paths, signal handling differences, foreground process management, ANSI sequence handling, path normalization, file-locking semantics, and many more. Full list in commit log under <code>fix(windows)</code> / <code>feat(windows)</code> / <code>windows</code>.</p>
<hr>
<h2>🚀 Performance Wave</h2>
<h3>Cold start</h3>
<ul>
<li><strong>Cut ~19s from <code>hermes</code> cold start</strong> — skills cache + lazy Feishu + no Nous HTTP at startup (<a href="https://github.com/NousResearch/hermes-agent/pull/22138" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22138/hovercard">#22138</a>)</li>
<li><strong>Skip eager plugin discovery on known built-in subcommands</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22120/hovercard">#22120</a>)</li>
<li><strong>Cache Nous auth + .env loads</strong> — <code>hermes tools</code> All Platforms from 14s to &lt;1.5s (<a href="https://github.com/NousResearch/hermes-agent/pull/25341" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25341/hovercard">#25341</a>)</li>
<li><strong>Skip welcome banner on <code>chat -q</code> single-query mode</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22904" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22904/hovercard">#22904</a>)</li>
<li><strong>Defer heavy google-cloud imports in google_chat to first adapter use</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22681/hovercard">#22681</a>)</li>
<li><strong>Defer QQAdapter and YuanbaoAdapter imports via PEP 562</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22790" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22790/hovercard">#22790</a>)</li>
<li><strong>Defer httpx import in teams to first webhook call</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22831" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22831/hovercard">#22831</a>)</li>
<li><strong>Defer fal_client import to first generation request</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22859/hovercard">#22859</a>)</li>
<li><strong>models.dev cache-first lookup, skip network when disk cache is fresh</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22808" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22808/hovercard">#22808</a>)</li>
<li><strong>Parallelize API connectivity checks in <code>hermes doctor</code> and disable IMDS</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22766" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22766/hovercard">#22766</a>)</li>
</ul>
<h3>Runtime</h3>
<ul>
<li><strong>180x faster <code>browser_console</code> evaluations</strong> — route through supervisor's persistent CDP WebSocket (<a href="https://github.com/NousResearch/hermes-agent/pull/23226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23226/hovercard">#23226</a>)</li>
<li><strong>Tune Telegram cadence + adaptive fast-path for short replies</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269831381" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/10388" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/10388/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/10388">#10388</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23587" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23587/hovercard">#23587</a>)</li>
<li><strong>Accumulate length-continuation prefix via list+join</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26237" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26237/hovercard">#26237</a>)</li>
</ul>
<h3>Prompt caching</h3>
<ul>
<li><strong>Cross-session 1h prefix cache for Claude on Anthropic / OpenRouter / Nous Portal</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23828/hovercard">#23828</a>)</li>
<li><strong>Hit prefix cache in background review fork</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348034723" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17276" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17276/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17276">#17276</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4443288876" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25427" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25427/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25427">#25427</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25434" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25434/hovercard">#25434</a>)</li>
</ul>
<hr>
<h2>📦 Installation &amp; Distribution</h2>
<h3>PyPI + supply-chain</h3>
<ul>
<li><strong>PyPI wheel packaging — <code>pip install hermes-agent &amp;&amp; hermes</code></strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454164335" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/26350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26350/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/26350">#26350</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26593/hovercard">#26593</a>)</li>
<li><strong>Supply-chain advisory checker + lazy-install framework + tiered install fallback</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24220/hovercard">#24220</a>)</li>
<li><strong>Use <code>--extra all</code> not <code>--all-extras</code>; drop lazy-covered extras from <code>[all]</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24515/hovercard">#24515</a>)</li>
<li><strong>Skip browser download when system chromium exists</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25317" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25317/hovercard">#25317</a>)</li>
</ul>
<h3>Nix</h3>
<ul>
<li><strong><code>extraDependencyGroups</code> for sealed venv extras</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21817" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21817/hovercard">#21817</a>)</li>
<li><strong>Refresh npm lockfile hashes</strong> — keeps Nix flake builds reproducible</li>
</ul>
<h3>Docker</h3>
<ul>
<li><strong>Bootstrap auth.json from env on first boot</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21880" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21880/hovercard">#21880</a>)</li>
<li><strong>Drop manual @hermes/ink build, rely on esbuild bundle</strong> — slimmer image</li>
</ul>
<h3>ACP / Zed</h3>
<ul>
<li><strong>Zed ACP Registry integration</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4448778934" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25908/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25908">#25908</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26079" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26079/hovercard">#26079</a>)</li>
<li><strong>Switch to uvx distribution, drop npm launcher</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26120/hovercard">#26120</a>)</li>
<li><strong><code>hermes acp --setup-browser</code> bootstraps browser tools for registry installs</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26234" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26234/hovercard">#26234</a>)</li>
</ul>
<hr>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Sessions &amp; handoff</h3>
<ul>
<li><strong><code>/handoff</code> actually transfers the session live</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23395/hovercard">#23395</a>)</li>
<li><strong>Expose <code>HERMES_SESSION_ID</code> env var to agent tools</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23847" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23847/hovercard">#23847</a>)</li>
</ul>
<h3>Goals (Ralph loop)</h3>
<ul>
<li><strong><code>/subgoal</code> — user-added criteria appended to active <code>/goal</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25449/hovercard">#25449</a>)</li>
<li><strong><code>/goal</code> checklist + /subgoal user controls</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23456" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23456/hovercard">#23456</a>) — rolled back in window (<a href="https://github.com/NousResearch/hermes-agent/pull/23813" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23813/hovercard">#23813</a>); /subgoal returned in simpler form via <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4443429014" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25449/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25449">#25449</a></li>
</ul>
<h3>Compression</h3>
<ul>
<li><strong>Make <code>protect_first_n</code> configurable</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25447" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25447/hovercard">#25447</a>)</li>
</ul>
<h3>Verification</h3>
<ul>
<li><strong>Per-turn file-mutation verifier footer</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24498/hovercard">#24498</a>)</li>
</ul>
<h3>Stream retry</h3>
<ul>
<li><strong>Log inner cause, upstream headers, bytes/elapsed on every drop</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23005" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23005/hovercard">#23005</a>)</li>
</ul>
<hr>
<h2>🤖 Models &amp; Providers</h2>
<h3>New providers</h3>
<ul>
<li><strong>xAI Grok OAuth (SuperGrok Subscription) provider</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26534" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26534/hovercard">#26534</a>)</li>
<li><strong>NovitaAI provider</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4239769574" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/7219" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7219/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/7219">#7219</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25507/hovercard">#25507</a>)</li>
<li><strong>NVIDIA NIM billing origin header</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4440730370" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25211" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25211/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25211">#25211</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26585" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26585/hovercard">#26585</a>)</li>
</ul>
<h3>Provider work</h3>
<ul>
<li><strong>OpenRouter Pareto Code router with <code>min_coding_score</code> knob</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22838" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22838/hovercard">#22838</a>)</li>
<li><strong>Optional codex app-server runtime for OpenAI/Codex models</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24182/hovercard">#24182</a>)</li>
<li><strong>Codex-runtime: retire wedged sessions + post-tool watchdog + OAuth refresh classify</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25769" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25769/hovercard">#25769</a>)</li>
<li><strong>Codex-runtime: skip unavailable plugins during migration</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25437" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25437/hovercard">#25437</a>)</li>
<li><strong>Codex-runtime: de-dup <code>[plugins.X]</code> tables and stop leaking HERMES_HOME into config.toml</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4452637433" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/26250" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/26250/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/26250">#26250</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26260" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26260/hovercard">#26260</a>)</li>
<li><strong>Pass <code>reasoning.effort</code> to xAI Responses API</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22807" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22807/hovercard">#22807</a>)</li>
<li><strong>Custom provider: prompt and persist explicit <code>api_mode</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25068" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25068/hovercard">#25068</a>)</li>
<li><strong>Rename Alibaba Cloud → Qwen Cloud, reorder picker</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24835/hovercard">#24835</a>)</li>
<li><strong>Restore gpt-5.3-codex-spark for ChatGPT Pro</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363243703" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18286/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/18286">#18286</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374103180" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19530" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19530/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19530">#19530</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331658979" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16172" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/16172/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/16172">#16172</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22991" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22991/hovercard">#22991</a>)</li>
<li><strong>Inject tool-use enforcement for GLM models</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24715" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24715/hovercard">#24715</a>)</li>
<li><strong>Use Nous Portal as model metadata authority</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/24502" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24502/hovercard">#24502</a>)</li>
<li><strong>Unified <code>client=hermes-client-v&lt;version&gt;</code> tag on every Portal request</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24779" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24779/hovercard">#24779</a>)</li>
<li><strong>Prevent stale Ollama credentials after provider switch</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21703" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21703/hovercard">#21703</a>)</li>
<li><strong>Auxiliary client: rotate pooled auth after quota failures</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413655442" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22779" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22779/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22779">#22779</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22792" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22792/hovercard">#22792</a>)</li>
<li><strong>Auxiliary client: skip providers without credentials immediately</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442897934" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25395/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25395">#25395</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25487" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25487/hovercard">#25487</a>)</li>
<li><strong>Auth: send Nous refresh token via header</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21578/hovercard">#21578</a>)</li>
<li><strong>MiniMax: harden OAuth dashboard and runtime</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24165" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24165/hovercard">#24165</a>)</li>
</ul>
<h3>OpenAI-compatible proxy</h3>
<ul>
<li><strong>Local OpenAI-compatible proxy for OAuth providers</strong> — Codex / Aider / Cline can hit Claude Pro, ChatGPT Pro, SuperGrok (<a href="https://github.com/NousResearch/hermes-agent/pull/25969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25969/hovercard">#25969</a>)</li>
</ul>
<hr>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>New platforms</h3>
<ul>
<li><strong>LINE Messaging API platform plugin</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23197" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23197/hovercard">#23197</a>)</li>
<li><strong>SimpleX Chat platform plugin</strong> (salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117407388" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2558" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2558/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2558">#2558</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26232/hovercard">#26232</a>)</li>
</ul>
<h3>Microsoft Graph foundation</h3>
<ul>
<li><strong>msgraph: add auth and client foundation</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400317607" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21408" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21408/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21408">#21408</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21922" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21922/hovercard">#21922</a>)</li>
<li><strong>msgraph: add webhook listener platform</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400318904" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21409" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21409/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21409">#21409</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21969/hovercard">#21969</a>)</li>
<li><strong>teams-pipeline: add plugin runtime and operator cli</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400320220" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21410" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21410/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21410">#21410</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22007/hovercard">#22007</a>)</li>
<li><strong>teams: add pipeline outbound delivery via existing adapter</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400321291" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21411" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21411/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21411">#21411</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22024" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22024/hovercard">#22024</a>)</li>
</ul>
<h3>Cross-platform</h3>
<ul>
<li><strong>Per-platform admin/user split for slash commands</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186299753" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/4443" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4443/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/4443">#4443</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23373" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23373/hovercard">#23373</a>)</li>
<li><strong>Forensics on signal handling — non-blocking diag, per-phase timing, stale-unit warning</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23285/hovercard">#23285</a>)</li>
<li><strong>Keep gateway running when platforms fail; add per-platform circuit breaker + <code>/platform</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26600" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26600/hovercard">#26600</a>)</li>
<li><strong>Wire <code>clarify</code> tool with inline keyboard buttons on Telegram</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24199" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24199/hovercard">#24199</a>)</li>
<li><strong>Add <code>chat_id</code> to <code>hook_ctx</code> for message source tracking</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24710" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24710/hovercard">#24710</a>)</li>
</ul>
<h3>Telegram</h3>
<ul>
<li><strong>Native draft streaming via <code>sendMessageDraft</code> (Bot API 9.5+)</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4153857159" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/3412" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/3412/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/3412">#3412</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23512/hovercard">#23512</a>)</li>
<li><strong>Stream Telegram edits safely</strong> — salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4411022272" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22264" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22264/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22264">#22264</a> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22518/hovercard">#22518</a>)</li>
<li><strong>Telegram notification mode</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413638873" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22772" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22772/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22772">#22772</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22793" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22793/hovercard">#22793</a>)</li>
<li><strong>Telegram guest mention mode</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22759/hovercard">#22759</a>)</li>
<li><strong>Split-and-deliver oversized edits instead of silent truncation</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374174566" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19537" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19537/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19537">#19537</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23576" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23576/hovercard">#23576</a>)</li>
<li><strong>Preserve DM topic routing via reply fallback</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4408968252" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22053" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22053/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22053">#22053</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22410" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22410/hovercard">#22410</a>)</li>
<li><strong>Pass <code>source.thread_id</code> explicitly on auto-reset notice</strong> (carve-out of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241919580" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/7404" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7404/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/7404">#7404</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23440" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23440/hovercard">#23440</a>)</li>
</ul>
<h3>Discord</h3>
<ul>
<li><strong>Render clarify choices as buttons</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25485" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25485/hovercard">#25485</a>)</li>
<li><strong>Channel history backfill — default on, broadened scope</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25984" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25984/hovercard">#25984</a>)</li>
<li><strong><code>thread_require_mention</code> for multi-bot threads</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442115964" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25313" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25313/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25313">#25313</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25445" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25445/hovercard">#25445</a>)</li>
</ul>
<h3>Slack</h3>
<ul>
<li><strong>Support <code>!cmd</code> as alternate prefix for slash commands in threads</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25355/hovercard">#25355</a>)</li>
</ul>
<h3>WhatsApp</h3>
<ul>
<li><strong>Surface quoted reply metadata from Baileys</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442902475" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25398/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25398">#25398</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25489" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25489/hovercard">#25489</a>)</li>
</ul>
<h3>Feishu / Google Chat / others</h3>
<ul>
<li><strong>Feishu: native update prompt cards</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22448" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22448/hovercard">#22448</a>)</li>
<li><strong>Google Chat: repair setup prompt imports</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22038" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22038/hovercard">#22038</a>)</li>
<li><strong>Google Chat: honor relay-declared sender_type</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409786696" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22107" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22107/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22107">#22107</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22432" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22432/hovercard">#22432</a>)</li>
<li><strong>LINE: use <code>build_source</code> instead of nonexistent <code>create_source</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24717" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24717/hovercard">#24717</a>)</li>
<li><strong>Add <code>weixin, and more</code> to gateway docs</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4396673114" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21063" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21063/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21063">#21063</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wuwuzhijing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wuwuzhijing">@wuwuzhijing</a>)</li>
</ul>
<hr>
<h2>🖥️ CLI &amp; TUI</h2>
<h3>CLI</h3>
<ul>
<li><strong>Show YOLO mode warning in banner and status bar</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26238" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26238/hovercard">#26238</a>)</li>
<li><strong>Confirm prompt for destructive slash commands</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174599074" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/4069" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4069/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/4069">#4069</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22687" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22687/hovercard">#22687</a>)</li>
<li><strong><code>docker_extra_args</code> + <code>display.timestamps</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23599" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23599/hovercard">#23599</a>)</li>
<li><strong>Delegate tool: show user's actual concurrency / spawn-depth limits in description</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22694" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22694/hovercard">#22694</a>)</li>
</ul>
<h3>TUI</h3>
<ul>
<li><strong><code>/sessions</code> slash command for browsing and resuming previous sessions</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20805" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20805/hovercard">#20805</a>)</li>
<li><strong>Segment turns with rule above non-first user msgs; trim ticker dead space</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21846" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21846/hovercard">#21846</a>)</li>
<li><strong>Support attaching to an existing gateway</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21978" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21978/hovercard">#21978</a>)</li>
<li><strong>Resolve markdown links to readable page titles</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/24013" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24013/hovercard">#24013</a>)</li>
<li><strong>Width-aware markdown table rendering with vertical fallback</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26195" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26195/hovercard">#26195</a>)</li>
<li><strong>Keep Ink displayCursor in sync with fast-echo writes so cursor stops drifting</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26717" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26717/hovercard">#26717</a>)</li>
<li><strong>Allow transcript scroll + Esc during approval/clarify/confirm prompts</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26414" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26414/hovercard">#26414</a>)</li>
<li><strong>Preserve session when switching personality</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20942" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20942/hovercard">#20942</a>)</li>
<li><strong>Skip native safety net on OSC52-capable terminals</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20954" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20954/hovercard">#20954</a>)</li>
</ul>
<h3>Dashboard / GUI</h3>
<ul>
<li><strong>Route embedded TUI through dashboard gateway</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21979" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21979/hovercard">#21979</a>)</li>
<li><strong>Hide token/cost analytics behind config flag (default off)</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25438" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25438/hovercard">#25438</a>)</li>
<li><strong>Fix Langfuse observability — trace I/O, tool outputs, placeholder credentials</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4411518378" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22342" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/22342/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/22342">#22342</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413605274" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22763" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/22763/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/22763">#22763</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26320" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26320/hovercard">#26320</a>)</li>
<li><strong>MiniMax 'Login' button launched Claude OAuth</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413936898" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22849" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22849/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22849">#22849</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/24058" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24058/hovercard">#24058</a>)</li>
<li><strong>Update cron modals</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25985" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25985/hovercard">#25985</a>)</li>
<li><strong>Analytics: prevent silent token loss and add Claude 4.5–4.7 pricing</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21455/hovercard">#21455</a>)</li>
</ul>
<hr>
<h2>🔧 Tools &amp; Capabilities</h2>
<h3>Vision &amp; video</h3>
<ul>
<li><strong><code>vision_analyze</code> returns pixels to vision-capable models</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22955" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22955/hovercard">#22955</a>)</li>
<li><strong>Unified <code>video_generate</code> with pluggable provider backends</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25126" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25126/hovercard">#25126</a>)</li>
<li><strong><code>image_gen</code>: actionable setup message when no FAL backend is reachable</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26222" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26222/hovercard">#26222</a>)</li>
</ul>
<h3>Computer use</h3>
<ul>
<li><strong><code>computer_use</code> cua-driver backend + focus-safe ops + non-Anthropic provider fix</strong> (re-salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341933760" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16936" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16936/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16936">#16936</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21967" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21967/hovercard">#21967</a>)</li>
<li><strong>Refresh cua-driver on <code>hermes update</code> + add <code>install --upgrade</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24063" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24063/hovercard">#24063</a>)</li>
</ul>
<h3>LSP &amp; write-time diagnostics</h3>
<ul>
<li><strong>Semantic diagnostics from real language servers in <code>write_file</code>/<code>patch</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24168" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24168/hovercard">#24168</a>)</li>
<li><strong>Shift baseline diagnostics into post-edit coordinates</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25978" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25978/hovercard">#25978</a>)</li>
</ul>
<h3>Search &amp; web</h3>
<ul>
<li><strong>Brave Search (free tier) and DDGS search providers</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21337" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21337/hovercard">#21337</a>)</li>
<li><strong>Bearer auth header for Tavily <code>/crawl</code> endpoint</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24658" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24658/hovercard">#24658</a>)</li>
</ul>
<h3>X (Twitter)</h3>
<ul>
<li><strong>Gated <code>x_search</code> tool with OAuth-or-API-key auth</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26763" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26763/hovercard">#26763</a>)</li>
</ul>
<h3>Browser</h3>
<ul>
<li><strong>Route <code>browser_console</code> eval through supervisor's persistent CDP WS (180x faster)</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23226/hovercard">#23226</a>)</li>
<li><strong>Support externally managed Camofox sessions</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24499" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24499/hovercard">#24499</a>)</li>
</ul>
<h3>MCP</h3>
<ul>
<li><strong><code>supports_parallel_tool_calls</code> for MCP servers</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265444652" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/9944" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/9944/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/9944">#9944</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26825" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26825/hovercard">#26825</a>)</li>
<li><strong>Codex preset for Codex CLI MCP server</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4412978691" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22663" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22663/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22663">#22663</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22679" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22679/hovercard">#22679</a>)</li>
<li><strong>Stop retrying initial MCP auth failures</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4445105387" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25624/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25624">#25624</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25776" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25776/hovercard">#25776</a>)</li>
</ul>
<h3>Google Workspace</h3>
<ul>
<li><strong>Drive write ops + Docs/Sheets create/append</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21895" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21895/hovercard">#21895</a>)</li>
</ul>
<h3>Per-turn verifier</h3>
<ul>
<li><strong>Per-turn file-mutation verifier footer</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24498/hovercard">#24498</a>)</li>
</ul>
<hr>
<h2>🧩 Kanban (Multi-Agent)</h2>
<ul>
<li><strong><code>specify</code> — auxiliary LLM fleshes out triage tasks</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21435/hovercard">#21435</a>)</li>
<li><strong>Orchestrator board tools — <code>kanban_list</code> + <code>kanban_unblock</code></strong> (carve-out of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4388855286" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20568" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20568/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20568">#20568</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23012" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23012/hovercard">#23012</a>)</li>
<li><strong><code>stranded_in_ready</code> diagnostic for unclaimed tasks</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23578/hovercard">#23578</a>)</li>
<li><strong>Dashboard batch QOL upgrade</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415907547" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/23240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23240/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/23240">#23240</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23550" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23550/hovercard">#23550</a>)</li>
<li><strong>Tooltips and docs link across dashboard</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21541/hovercard">#21541</a>)</li>
<li><strong>Dedupe notifier delivery via atomic claim + rewind on failure</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4412567868" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22558" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22558/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22558">#22558</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23401" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23401/hovercard">#23401</a>)</li>
<li><strong>Keep notifier subscriptions alive across retry cycles</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400178047" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21398/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21398">#21398</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23423/hovercard">#23423</a>)</li>
<li><strong>Drop caller-controlled author override in <code>kanban_comment</code></strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409830771" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22109" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22109/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22109">#22109</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22435/hovercard">#22435</a>)</li>
<li><strong>Sanitize comment author rendering in <code>build_worker_context</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22769" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22769/hovercard">#22769</a>)</li>
</ul>
<hr>
<h2>🧠 Plugins &amp; Extension</h2>
<h3>Plugin surface</h3>
<ul>
<li><strong>Run any LLM call from inside a plugin via <code>ctx.llm</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23194/hovercard">#23194</a>)</li>
<li><strong><code>tool_override</code> flag for replacing built-in tools</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276172104" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/11049" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/11049/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/11049">#11049</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26759/hovercard">#26759</a>)</li>
<li><strong><code>standalone_sender_fn</code> for out-of-process cron delivery</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22461" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22461/hovercard">#22461</a>)</li>
<li><strong><code>HERMES_PLUGINS_DEBUG=1</code> surfaces plugin discovery logs</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22684" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22684/hovercard">#22684</a>)</li>
<li><strong>Hindsight-client as optional dependency</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21818/hovercard">#21818</a>)</li>
</ul>
<h3>Profile &amp; distribution</h3>
<ul>
<li><strong>Shareable profile distributions via git</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20831" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20831/hovercard">#20831</a>)</li>
</ul>
<hr>
<h2>⏰ Cron</h2>
<ul>
<li><strong>Routing intent — <code>deliver=all</code> fans out to every connected channel</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21495" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21495/hovercard">#21495</a>)</li>
<li><strong>Support name-based lookup for job operations</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26231/hovercard">#26231</a>)</li>
<li><strong>Blank Cron dashboard tab + partial-record crashes</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4396341916" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21042/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21042">#21042</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4411464552" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22330/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22330">#22330</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22389/hovercard">#22389</a>)</li>
<li><strong>Do not seed <code>HERMES_SESSION_*</code> contextvars from cron origin</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4411575899" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22356" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22356/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22356">#22356</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22382" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22382/hovercard">#22382</a>)</li>
<li><strong>Scan assembled prompt including skill content for prompt injection</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4171149796" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/3968" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/3968/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/3968">#3968</a>)</li>
</ul>
<hr>
<h2>🧩 Skills Ecosystem</h2>
<h3>Skills Hub</h3>
<ul>
<li><strong><code>hermes-skills/huggingface</code> as a trusted default tap</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117085837" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2549" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2549/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2549">#2549</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26219" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26219/hovercard">#26219</a>)</li>
<li><strong>Show per-skill pages in the left sidebar</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26646" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26646/hovercard">#26646</a>)</li>
<li><strong>Richer info panels on the Skills Hub</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22905" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22905/hovercard">#22905</a>)</li>
<li><strong>Refuse <code>skill_view</code> name collisions instead of guessing</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4224310629" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/6136" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6136/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/6136">#6136</a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/polkn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/polkn">@polkn</a>)</li>
</ul>
<h3>Curator</h3>
<ul>
<li><strong>Show rename map in user-visible summary</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22910" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22910/hovercard">#22910</a>)</li>
<li><strong>Hint at <code>hermes curator pin</code> in the rename block</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23212" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23212/hovercard">#23212</a>)</li>
</ul>
<h3>New optional skills</h3>
<ul>
<li><strong>Hyperliquid</strong> — perp/spot trading via SDK + REST (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4096174558" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/1952" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/1952/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/1952">#1952</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23583" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23583/hovercard">#23583</a>)</li>
<li><strong>Yahoo Finance</strong> market data (<a href="https://github.com/NousResearch/hermes-agent/pull/23590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23590/hovercard">#23590</a>)</li>
<li><strong>api-testing</strong> (REST/GraphQL debug, salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090616596" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/1800" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/1800/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/1800">#1800</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23582/hovercard">#23582</a>)</li>
<li><strong>Unified EVM multi-chain skill</strong> (salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4441931751" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25291" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25291/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25291">#25291</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098909401" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2010" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2010/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2010">#2010</a> + folds in base/) (<a href="https://github.com/NousResearch/hermes-agent/pull/25299" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25299/hovercard">#25299</a>)</li>
<li><strong>darwinian-evolver</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26760" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26760/hovercard">#26760</a>)</li>
<li><strong>osint-investigation</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4020048213" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/355" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/355/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/355">#355</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26729" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26729/hovercard">#26729</a>)</li>
<li><strong>pinggy-tunnel</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26765" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26765/hovercard">#26765</a>)</li>
<li><strong>watchers</strong> — RSS / HTTP JSON / GitHub polling via cron no-agent (<a href="https://github.com/NousResearch/hermes-agent/pull/21881" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21881/hovercard">#21881</a>)</li>
<li><strong>Notion overhaul for the Developer Platform</strong> (May 2026) (<a href="https://github.com/NousResearch/hermes-agent/pull/26612" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26612/hovercard">#26612</a>)</li>
</ul>
<hr>
<h2>🔒 Security &amp; Reliability</h2>
<h3>Security hardening</h3>
<ul>
<li><strong>Sudo brute-force block + sudo-stdin/askpass DANGEROUS</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4410605303" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22194/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22194">#22194</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4397828876" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21128" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21128/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21128">#21128</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23736" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23736/hovercard">#23736</a>)</li>
<li><strong>Drop caller-controlled author override in <code>kanban_comment</code></strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409830771" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22109" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22109/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22109">#22109</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22435/hovercard">#22435</a>)</li>
<li><strong>Cover remaining SSRF fetch paths in skills-hub</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413740551" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22804" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22804/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22804">#22804</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22843" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22843/hovercard">#22843</a>)</li>
<li><strong>Use credential_pool for custom endpoint model listing probes</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413750085" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22810" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22810/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22810">#22810</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22842/hovercard">#22842</a>)</li>
<li><strong>Require dashboard auth for plugin API routes</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374329621" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19541/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19541">#19541</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23220/hovercard">#23220</a>)</li>
<li><strong>Sanitize env and redact output in quick commands + remove write-only <code>_pending_messages</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23584/hovercard">#23584</a>)</li>
<li><strong>Reduce unnecessary <code>shell=True</code> in subprocess calls</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25149/hovercard">#25149</a>)</li>
<li><strong>Sanitize Google Chat sender_type from relay</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409786696" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22107" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22107/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22107">#22107</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22432" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22432/hovercard">#22432</a>)</li>
<li><strong>Supply-chain advisory checker</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24220/hovercard">#24220</a>)</li>
<li><strong>Rewrite security policy around OS-level isolation as the boundary</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20317" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20317/hovercard">#20317</a>)</li>
<li><strong>Remove public security advisory page</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24253" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24253/hovercard">#24253</a>)</li>
</ul>
<h3>Reliability — notable bug closures</h3>
<ul>
<li><strong>SQLite: fall back to <code>journal_mode=DELETE</code> on NFS/SMB/FUSE</strong> (fixes <code>/resume</code> on network mounts) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22043" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22043/hovercard">#22043</a>)</li>
<li><strong>Codex-runtime: retire wedged sessions + post-tool watchdog + OAuth refresh classify</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25769" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25769/hovercard">#25769</a>)</li>
<li><strong>Codex-runtime: de-dup <code>[plugins.X]</code> tables and stop leaking HERMES_HOME</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4452637433" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/26250" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/26250/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/26250">#26250</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26260" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26260/hovercard">#26260</a>)</li>
<li><strong>Daytona: migrate legacy-sandbox lookup to cursor-based <code>list()</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24587" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24587/hovercard">#24587</a>)</li>
<li><strong>MCP: stop retrying initial MCP auth failures</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4445105387" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25624/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25624">#25624</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25776" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25776/hovercard">#25776</a>)</li>
<li><strong>Gateway: enable text-intercept for multi-choice clarify fallback</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4444770745" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25587" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25587/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25587">#25587</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25778" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25778/hovercard">#25778</a>)</li>
<li><strong>Gateway: keep running when platforms fail; per-platform circuit breaker + <code>/platform</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26600" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26600/hovercard">#26600</a>)</li>
<li><strong>Delegate: salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4407521894" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21933" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/21933/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/21933">#21933</a> JSON-string batch + diagnostic logging</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22436" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22436/hovercard">#22436</a>)</li>
<li><strong>Profiles+banner: exclude infrastructure from <code>--clone-all</code> + fix stale update-check repo resolution</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22475" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22475/hovercard">#22475</a>)</li>
<li><strong>ACP: inline file attachment resources</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400211653" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21400" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21400/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21400">#21400</a> + image support) (<a href="https://github.com/NousResearch/hermes-agent/pull/21407" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21407/hovercard">#21407</a>)</li>
<li><strong>CI: unblock shared PR checks</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21012" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21012/hovercard">#21012</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25957/hovercard">#25957</a>)</li>
</ul>
<h3>Notable reverts in window</h3>
<ul>
<li><strong><code>/goal</code> checklist + /subgoal feature stack</strong> — rolled back (<a href="https://github.com/NousResearch/hermes-agent/pull/23813" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23813/hovercard">#23813</a>); <code>/subgoal</code> returned in simpler form via <a href="https://github.com/NousResearch/hermes-agent/pull/25449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25449/hovercard">#25449</a></li>
<li><strong>Scrollback box width clamp</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4449744090" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25975" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25975/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25975">#25975</a>) rolled back to restore full-width borders (<a href="https://github.com/NousResearch/hermes-agent/pull/26163" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26163/hovercard">#26163</a>)</li>
<li><strong><code>fix(cli): tolerate unreadable dirs when building systemd PATH</code></strong> rolled back</li>
</ul>
<hr>
<h2>🌍 i18n</h2>
<ul>
<li><strong>Localize all gateway commands + web dashboard, add 8 new locales (16 total)</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22914" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22914/hovercard">#22914</a>)</li>
</ul>
<hr>
<h2>📚 Documentation</h2>
<ul>
<li><strong>Repair Voice &amp; TTS provider table</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nightcityblade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nightcityblade">@nightcityblade</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4425548878" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/24101" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/24101/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/24101">#24101</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/24138" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24138/hovercard">#24138</a>)</li>
<li><strong>Show per-skill pages in the left sidebar</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26646" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26646/hovercard">#26646</a>)</li>
<li><strong>Mention Weixin in gateway help and docstrings</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4396673114" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21063" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21063/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21063">#21063</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wuwuzhijing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wuwuzhijing">@wuwuzhijing</a>)</li>
<li><strong>Richer info panels on the Skills Hub</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22905" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22905/hovercard">#22905</a>)</li>
<li>Many more doc updates across providers, platforms, skills, Windows install paths, and dashboard.</li>
</ul>
<hr>
<h2>🧪 Testing &amp; CI</h2>
<ul>
<li><strong>Unblock shared PR checks</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21012" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21012/hovercard">#21012</a>)</li>
<li><strong>Stabilize shared test state after 21012</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25957/hovercard">#25957</a>)</li>
<li>A long tail of test additions for platforms, providers, plugins, and edge cases — 8 explicit <code>test:</code> PRs plus ~250 fix PRs that also added regression coverage.</li>
</ul>
<hr>
<h2>👥 Contributors</h2>
<h3>Core</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a> — release lead, architecture, ~406 PRs merged in window</li>
</ul>
<h3>Top community contributors</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a></strong> — 38 PRs · Telegram cadence/streaming/topic routing, security hardening (sudo, SSRF, kanban_comment, dashboard auth), codex-runtime hygiene, NovitaAI provider, profile/banner fixes, Feishu update cards, gateway QOL across the board</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a></strong> — 13 PRs · Markdown-table TUI rendering, <code>HERMES_SESSION_ID</code> env var, hindsight-client optional dep, Nix <code>extraDependencyGroups</code></li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a></strong> (Brooklyn Nicholson) — 12 PRs · TUI turn segmentation, attach-to-gateway, markdown link titles, embedded TUI via dashboard gateway, Ink cursor sync, scroll/Esc during prompts</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a></strong> — 8 PRs · <code>/sessions</code> slash command, personality switching preserves session, cron modals, dashboard analytics</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a></strong> — 5 PRs · Google Chat setup, browser install skip on system chromium, Windows Ctrl+C preservation</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a></strong> — 4 PRs · Nous Portal as model metadata authority, provider polish</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a></strong> — 3 PRs · CI stabilization</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a></strong> — 3 PRs · platform/gateway work</li>
</ul>
<h3>All contributors (alphabetical)</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/02356abc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/02356abc">@02356abc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xharryriddle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xharryriddle">@0xharryriddle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1000Delta/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1000Delta">@1000Delta</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1RB/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1RB">@1RB</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/29206394/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/29206394">@29206394</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/A-kamal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/A-kamal">@A-kamal</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aashizpoudel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aashizpoudel">@aashizpoudel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Abd0r/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Abd0r">@Abd0r</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adybag14-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adybag14-cyber">@adybag14-cyber</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AgentArcLab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AgentArcLab">@AgentArcLab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ahmedbadr3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ahmedbadr3">@ahmedbadr3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alblez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alblez">@alblez</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alex-yang00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alex-yang00">@Alex-yang00</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ALIYILD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ALIYILD">@ALIYILD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AllynSheep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AllynSheep">@AllynSheep</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/am423/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/am423">@am423</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amathxbt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amathxbt">@amathxbt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amethystani/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amethystani">@amethystani</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ArecaNon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ArecaNon">@ArecaNon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Arkmusn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Arkmusn">@Arkmusn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/askclaw-vesper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/askclaw-vesper">@askclaw-vesper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AsoTora/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AsoTora">@AsoTora</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aydnOktay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aydnOktay">@aydnOktay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayushere/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayushere">@ayushere</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baocin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/baocin">@baocin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BennetYrWang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BennetYrWang">@BennetYrWang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bihruze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bihruze">@Bihruze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>,<br>
@brooklynnicholson, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/btorresgil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/btorresgil">@btorresgil</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/buntingszn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/buntingszn">@buntingszn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CalmProton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CalmProton">@CalmProton</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chrisworksai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chrisworksai">@chrisworksai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CoinTheHat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CoinTheHat">@CoinTheHat</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dandacompany/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dandacompany">@dandacompany</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dangooy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dangooy">@Dangooy</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DanielLSM/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DanielLSM">@DanielLSM</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/David-0x221Eight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/David-0x221Eight">@David-0x221Eight</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ddupont808/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ddupont808">@ddupont808</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dhruv-saxena/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dhruv-saxena">@dhruv-saxena</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/diablozzc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/diablozzc">@diablozzc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlkakbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlkakbs">@dlkakbs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmahan93/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmahan93">@dmahan93</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmnkhorvath/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmnkhorvath">@dmnkhorvath</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/domtriola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/domtriola">@domtriola</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donrhmexe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donrhmexe">@donrhmexe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eloklam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eloklam">@eloklam</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ephron-ren/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ephron-ren">@ephron-ren</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ErenKarakus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ErenKarakus">@ErenKarakus</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EthanGuo-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EthanGuo-coder">@EthanGuo-coder</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evgyur/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evgyur">@evgyur</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/explainanalyze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/explainanalyze">@explainanalyze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fahdad/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fahdad">@fahdad</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fr33d3m0n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fr33d3m0n">@fr33d3m0n</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/Freeman-Consulting/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Freeman-Consulting">@Freeman-Consulting</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/freqyfreqy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/freqyfreqy">@freqyfreqy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fu576/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fu576">@fu576</a>, @github-actions[bot], <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gnanirahulnutakki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gnanirahulnutakki">@gnanirahulnutakki</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guglielmofonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guglielmofonda">@guglielmofonda</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanzckernel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanzckernel">@hanzckernel</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heathley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heathley">@heathley</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hekaru-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hekaru-agent">@hekaru-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenkDz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenkDz">@HenkDz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HiddenPuppy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HiddenPuppy">@HiddenPuppy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hllqkb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hllqkb">@hllqkb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hrygo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hrygo">@hrygo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HuangYuChuh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HuangYuChuh">@HuangYuChuh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hugo-SEQUIER/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hugo-SEQUIER">@Hugo-SEQUIER</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HxT9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HxT9">@HxT9</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iacker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iacker">@iacker</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/InB4DevOps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/InB4DevOps">@InB4DevOps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/isaachuangGMICLOUD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/isaachuangGMICLOUD">@isaachuangGMICLOUD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iuyup/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iuyup">@iuyup</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackey8616/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackey8616">@jackey8616</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackjin1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackjin1997">@jackjin1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaggia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaggia">@Jaggia</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jak983464779/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jak983464779">@jak983464779</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jelrod27/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jelrod27">@jelrod27</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jethac/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jethac">@jethac</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JithendraNara/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JithendraNara">@JithendraNara</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnisag/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnisag">@johnisag</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Julientalbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Julientalbot">@Julientalbot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jwd-gity/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jwd-gity">@Jwd-gity</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kallidean/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kallidean">@kallidean</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keyuyuan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keyuyuan">@keyuyuan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kfa-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kfa-ai">@kfa-ai</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kidonng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kidonng">@kidonng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KiraKatana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KiraKatana">@KiraKatana</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kjames2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kjames2001">@kjames2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Korkyzer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Korkyzer">@Korkyzer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KvnGz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KvnGz">@KvnGz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lars-hagen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lars-hagen">@lars-hagen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leehack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leehack">@leehack</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leepoweii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leepoweii">@leepoweii</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/li0near/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/li0near">@li0near</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/libo1106/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/libo1106">@libo1106</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liquidchen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liquidchen">@liquidchen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/littlewwwhite/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/littlewwwhite">@littlewwwhite</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liyoungc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liyoungc">@liyoungc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luandiasrj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luandiasrj">@luandiasrj</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyuctl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyuctl">@luoyuctl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/magic524/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/magic524">@magic524</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbac/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbac">@mbac</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/McClean/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/McClean">@McClean</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/memosr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/memosr">@memosr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mibayy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mibayy">@Mibayy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ming1523/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ming1523">@ming1523</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mizgyo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mizgyo">@mizgyo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrshu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrshu">@mrshu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ms-alan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ms-alan">@ms-alan</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MustafaKara7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MustafaKara7">@MustafaKara7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nederev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nederev">@nederev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nicoechaniz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nicoechaniz">@nicoechaniz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nidhi-singh02/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nidhi-singh02">@nidhi-singh02</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nightcityblade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nightcityblade">@nightcityblade</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nik1t7n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nik1t7n">@nik1t7n</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ninso112/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ninso112">@Ninso112</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NivOO5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NivOO5">@NivOO5</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/novax635/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/novax635">@novax635</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nv-kasikritc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nv-kasikritc">@nv-kasikritc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oferlaor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oferlaor">@oferlaor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oswaldb22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oswaldb22">@oswaldb22</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/outdoorsea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/outdoorsea">@outdoorsea</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oxngon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oxngon">@oxngon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PaTTeeL/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PaTTeeL">@PaTTeeL</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pearjelly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pearjelly">@pearjelly</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pefontana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pefontana">@pefontana</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/perng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/perng">@perng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PhilipAD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PhilipAD">@PhilipAD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/phuongvm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/phuongvm">@phuongvm</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/polkn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/polkn">@polkn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Prasanna28Devadiga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Prasanna28Devadiga">@Prasanna28Devadiga</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/princepal9120/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/princepal9120">@princepal9120</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pty819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pty819">@pty819</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/purzbeats/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/purzbeats">@purzbeats</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Quarkex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Quarkex">@Quarkex</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quocanh261997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quocanh261997">@quocanh261997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qWaitCrypto/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qWaitCrypto">@qWaitCrypto</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Qwinty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Qwinty">@Qwinty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rahimsais/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rahimsais">@rahimsais</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raymaylee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raymaylee">@raymaylee</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ReqX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ReqX">@ReqX</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RhombusMaximus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RhombusMaximus">@RhombusMaximus</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ruzzgar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ruzzgar">@Ruzzgar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryptotalent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryptotalent">@ryptotalent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shaun0927/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shaun0927">@shaun0927</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SiliconID/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SiliconID">@SiliconID</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/silv-mt-holdings/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/silv-mt-holdings">@silv-mt-holdings</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simpolism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simpolism">@simpolism</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smwbev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smwbev">@smwbev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/soichiyo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/soichiyo">@soichiyo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/steezkelly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/steezkelly">@steezkelly</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sylw3ster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sylw3ster">@Sylw3ster</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/szymonclawd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/szymonclawd">@szymonclawd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teyrebaz33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teyrebaz33">@teyrebaz33</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tianyu199509/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tianyu199509">@Tianyu199509</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tranquil-Flow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tranquil-Flow">@Tranquil-Flow</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TreyDong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TreyDong">@TreyDong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurgutKural/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurgutKural">@TurgutKural</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tw2818/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tw2818">@tw2818</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tymrtn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tymrtn">@tymrtn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/uzunkuyruk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/uzunkuyruk">@uzunkuyruk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v1b3coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v1b3coder">@v1b3coder</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vanthinh6886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vanthinh6886">@vanthinh6886</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VinceZcrikl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VinceZcrikl">@VinceZcrikl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vKongv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vKongv">@vKongv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vominh1919/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vominh1919">@vominh1919</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voteblake/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voteblake">@voteblake</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VTRiot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VTRiot">@VTRiot</a>, @wali-reheman, @wesleysimplicio,<br>
@wilsen0, @WorldWriter, @worlldz, @wuli666, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wuwuzhijing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wuwuzhijing">@wuwuzhijing</a>, @Wysie, @XiaoXiao0221, @xieNniu, @xxxigm, @yehuosi,<br>
@ygd58, @yifengingit, @yuga-hashimoto, @zccyman, @ZeterMordio, @Zhekinmaksim, @zhengyn0001</p>
<p>Also: @Nagatha (Claude Opus 4.7).</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.5.7...v2026.5.16">v2026.5.7...v2026.5.16</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion courts developers with a platform for AI agents and workflow automation]]></title>
<description><![CDATA[Notion is expanding its collaborative workspace software with a developer platform for building AI-enabled workflows around enterprise data and workspace content.



The Notion Developer Platform adds custom code execution, database sync, external agent support, and workflow triggers, allowing de...]]></description>
<link>https://tsecurity.de/de/3516197/ai-nachrichten/notion-courts-developers-with-a-platform-for-ai-agents-and-workflow-automation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516197/ai-nachrichten/notion-courts-developers-with-a-platform-for-ai-agents-and-workflow-automation/</guid>
<pubDate>Thu, 14 May 2026 11:18:15 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Notion is expanding its collaborative workspace software with a developer platform for building AI-enabled workflows around enterprise data and workspace content.</p>



<p>The Notion Developer Platform adds custom code execution, database sync, external agent support, and workflow triggers, allowing developers and coding agents to extend Notion beyond its traditional role as a workspace app, the company said in a statement.</p>



<p>The launch comes as enterprises <a href="https://www.infoworld.com/article/4163914/enterprise-ai-is-missing-the-business-core.html">experiment with agentic AI</a> but still struggle to give those systems access to the work context that is spread across business applications and internal systems. Notion is betting that developers will want to connect that scattered context to the workspace where teams already do much of their day-to-day work.</p>



<p>At the center of the release is Notion Workers, a hosted runtime for custom code. The feature underpins several of the platform’s new capabilities, including syncing external data, adding custom logic to agent tools, and responding to webhooks from other applications without requiring teams to manage their own servers.</p>



<p>“Write your logic in code and deploy it as a Worker,” Notion said. “It’s deterministic, so it’s more reliable than LLM reasoning, and a fraction of the token cost.”</p>



<p>Database sync, now in beta, can pull data from external systems with APIs into Notion databases. That would allow teams to bring in information from applications such as Salesforce, Zendesk, or internal databases and make it available to workflows and agents.</p>



<p>An External Agents API, currently in alpha, will allow third-party and internally built agents to work inside Notion. The company said it has partnered with Claude, Codex, Decagon, and others to make some agents available out of the box.</p>



<p>Developers will use a Notion CLI to sign into workspaces, act on Notion content, build and deploy Workers, and extend the platform programmatically. Workers are free during the beta period, but will run on Notion credits starting August 11.</p>



<p>Notion is also adding workspace-scoped OAuth, personal access tokens, a dedicated developer portal, rebuilt documentation, and updates to its MCP support.</p>



<h2 class="wp-block-heading">Enterprise adoption hinges on governance</h2>



<p>Analysts said the release gives Notion a bigger role to play in enterprise software stacks, provided it can meet CIO <a href="https://www.infoworld.com/article/4160979/addressing-the-challenges-of-unstructured-data-governance-for-ai.html">expectations around governance</a> and production use.</p>



<p>“Notion Workers sit somewhere between low-code automation and lightweight serverless infrastructure,” said <a href="https://www.linkedin.com/in/tulikasheel/" target="_blank" rel="noreferrer noopener">Tulika Sheel</a>, senior vice president at Kadence International. “Unlike Zapier or Airtable, Notion is trying to combine AI agents, custom code execution, and workspace collaboration into a single environment.”</p>



<p>That could make the platform compelling for workflow-centric teams, Sheel said, although Microsoft Power Platform and cloud serverless offerings still have advantages in enterprise integration depth and operational maturity.</p>



<p>Notion’s Developer Platform marks the company’s entry into the emerging agent management platform market, said <a href="https://www.gartner.com/en/experts/nitish-tyagi" target="_blank" rel="noreferrer noopener">Nitish Tyagi</a>, senior principal analyst at Gartner.</p>



<p>Its agent orchestration, custom tool execution, and data integration capabilities position Notion as a workspace-centric control layer for AI agents, he said. But rivals, including Atlassian, GitHub, JetBrains, and Tabnine, are already pushing deeper into context, governance, and multi-agent orchestration. “Notion’s feature set is not fundamentally new,” Tyagi said. “The success of the platform will depend less on what it offers and more on how well these capabilities perform in practice.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion just turned its workspace into a hub for AI agents]]></title>
<description><![CDATA[Notion’s new developer platform lets teams connect AI agents, external data sources, and custom code directly into their workspace as the company pushes deeper into agentic productivity software.]]></description>
<link>https://tsecurity.de/de/3515106/it-nachrichten/notion-just-turned-its-workspace-into-a-hub-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515106/it-nachrichten/notion-just-turned-its-workspace-into-a-hub-for-ai-agents/</guid>
<pubDate>Wed, 13 May 2026 23:47:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Notion’s new developer platform lets teams connect AI agents, external data sources, and custom code directly into their workspace as the company pushes deeper into agentic productivity software.]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion Developer Platform: Workspace wird zur Programmierzentrale]]></title>
<description><![CDATA[Notion gibt mal wieder Schub und baut den Workspace zur programmierbaren Basis aus. Nachdem im Februar die Custom Agents starteten, folgt nun die Developer Platform. Herzstück ist die neue Notion CLI namens ntn, die als Schnittstelle für Entwickler und Agenten...Zum Beitrag: Notion Developer Plat...]]></description>
<link>https://tsecurity.de/de/3514672/it-nachrichten/notion-developer-platform-workspace-wird-zur-programmierzentrale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3514672/it-nachrichten/notion-developer-platform-workspace-wird-zur-programmierzentrale/</guid>
<pubDate>Wed, 13 May 2026 20:02:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Notion gibt mal wieder Schub und baut den Workspace zur programmierbaren Basis aus. Nachdem im Februar die Custom Agents starteten, folgt nun die Developer Platform. Herzstück ist die neue Notion CLI namens ntn, die als Schnittstelle für Entwickler und Agenten...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/notion-developer-platform-workspace-wird-zur-programmierzentrale/">Notion Developer Platform: Workspace wird zur Programmierzentrale</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vivo Y60 Launched With 6,500mAh Battery, 13-Megapixel Rear Camera: Price, Specifications]]></title>
<description><![CDATA[Vivo Y60 has been launched in China as the latest addition to the company’s Y lineup. The handset is currently on sale in the country via Vivo’s online store. It is offered in Lucky Purple, Obsidian Black, and Shanhaiqing (translated from Chinese) colour options. The new handset is powered by Qua...]]></description>
<link>https://tsecurity.de/de/3512681/it-nachrichten/vivo-y60-launched-with-6500mah-battery-13-megapixel-rear-camera-price-specifications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3512681/it-nachrichten/vivo-y60-launched-with-6500mah-battery-13-megapixel-rear-camera-price-specifications/</guid>
<pubDate>Wed, 13 May 2026 08:47:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Vivo Y60 has been launched in China as the latest addition to the company’s Y lineup. The handset is currently on sale in the country via Vivo’s online store. It is offered in Lucky Purple, Obsidian Black, and Shanhaiqing (translated from Chinese) colour options. The new handset is powered by Qualcomm’s octa core Snapdragon 4 Gen 2 chipset, delivering a peak clo...]]></content:encoded>
</item>
<item>
<title><![CDATA[Tokenmaxxing is super dumb]]></title>
<description><![CDATA[It seems that the software developers at Facebook, who are all in on AI-powered coding, came up with a notion they called “Claudeonomics” to measure their all in-ness. This manifested itself as an internal dashboard/scoreboard of who was burning the most tokens with Claude Code. The race was on t...]]></description>
<link>https://tsecurity.de/de/3511058/ai-nachrichten/tokenmaxxing-is-super-dumb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3511058/ai-nachrichten/tokenmaxxing-is-super-dumb/</guid>
<pubDate>Tue, 12 May 2026 18:18:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It seems that the software developers at Facebook, who are all in on AI-powered coding, came up with a notion they called “Claudeonomics” to measure their all in-ness. This manifested itself as an internal dashboard/scoreboard of who was burning the most tokens with <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html" data-type="link" data-id="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a>. The race was on to see who could burn through the most tokens.</p>



<p>Never mind whether this conflagration of Claude tokens was actually producing anything good. The chart merely gave boasting rights to the developer who cranked through the most processing power, declaring leaders as “Token Legend” and “Cache Wizard.”</p>



<p>Similar things were going on at Microsoft and Salesforce. </p>



<p>This is just the latest chapter in an age-old battle, and it is a really bad idea. </p>



<h2 class="wp-block-heading">Maximum bad</h2>



<p>Managing software developers is hard enough. There are many reasons why managing developers is hard, but chief among them is that it is difficult (<a href="https://medium.com/nickonsoftware/can-we-measure-software-development-productivity-a2138d2f7011">if not impossible</a>) to measure the process of writing software. </p>



<p>And that isn’t from a lack of trying. We’ve measured lines of code, story points, hours spent in the seat, hours spent per task, bugs fixed per week, and who knows what else. None of these metrics seems to work, and they all end up getting gamed. </p>



<p>That’s why we aren’t doing ourselves any favors when we start doing things like “tokenmaxxing”. </p>



<p>First, of course, measuring “tokens burned” doesn’t really tell you anything. Second, if you actually make tokens burned a target, well, we know what happens. People will severely game the system, and then <a href="https://en.wikipedia.org/wiki/Goodhart%27s_law">Goodhart’s law</a> kicks in. It turns out that Facebook developers — like <a href="https://www.historic-uk.com/HistoryUK/HistoryofBritain/Cobra-Effect/">the cobra farmers in India</a> — were using tools like <a href="https://openclaw.ai/">OpenClaw</a> to burn through massive chunks of tokens for no purpose at all.</p>



<p>Third, and worst of all, the managers in the corner office might notice. The execs are on an eternal quest for the best way to measure developers, and if they see this dashboard, they might actually latch on to the idea. And once that happens, things will go south very quickly. </p>



<h2 class="wp-block-heading">The new ‘lines of code’</h2>



<p>Token use is easy to count, looks great on a dashboard, and is utterly useless for anything at all except seeing how much electricity was jolted through GPUs. I can see the OKRs forming in the minds of executives as I type this. The one thing we don’t want to see is a slide at an investor briefing breathlessly announcing “Token throughput is up 30% YoY!”</p>



<p>And just like with lines of code, it’s generally true that maximizing token consumption is actually a negative indicator for quality and success. Getting Claude Code to use up tokens can actually produce worse outcomes than closely managing resources and keeping the coding agent on task. We don’t want token usage to become the new busy work, with developers burning up resources and execs patting them on the back as usage charts climb up and to the right — all to no avail.</p>



<p>It wasn’t long before word got out, and Facebook shut it down. </p>



<p>And they were smart to act quickly. There is no upside to tokenmaxxing — it’s a perverse incentive. </p>



<p>Tokenmaxxing is just “lines of code” dressed up in a tuxedo. Or better, a clown suit.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Will AI turn us all into hipsters and artisans?]]></title>
<description><![CDATA[There is good reason to be dubious about the notion that automation will supplant all demand for human labour]]></description>
<link>https://tsecurity.de/de/3509004/ai-nachrichten/will-ai-turn-us-all-into-hipsters-and-artisans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3509004/ai-nachrichten/will-ai-turn-us-all-into-hipsters-and-artisans/</guid>
<pubDate>Tue, 12 May 2026 06:47:52 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[There is good reason to be dubious about the notion that automation will supplant all demand for human labour]]></content:encoded>
</item>
<item>
<title><![CDATA[No hire, no fire: Employers get picky on tech skills amid AI disruption]]></title>
<description><![CDATA[The current “no-hire-no-fire” environment in the workplace has slowed the pace of tech hiring in the US, but companies have seen one benefit — the selection of job candidates is easier.



Many employers have become clearer about the qualifications they’re seeking in new hires: they’re focused le...]]></description>
<link>https://tsecurity.de/de/3506905/it-nachrichten/no-hire-no-fire-employers-get-picky-on-tech-skills-amid-ai-disruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3506905/it-nachrichten/no-hire-no-fire-employers-get-picky-on-tech-skills-amid-ai-disruption/</guid>
<pubDate>Mon, 11 May 2026 14:18:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The current “no-hire-no-fire” environment in the workplace has slowed the pace of tech hiring in the US, but companies have seen one benefit — the selection of job candidates is easier.</p>



<p>Many employers have become clearer about the qualifications they’re seeking in new hires: they’re focused less on people who can service large stacks of code, and more on ability to have a direct impact on corporate revenue and operations.</p>



<p>“Roles are narrower, expectations are clearer, and teams are being built with purpose rather than volume,” said Kye Mitchell, head of Experis, a division of recruiting firm ManpowerGroup.</p>



<p>That’s the backdrop amid a spate of recent hiring data reports released by the US government and various private firms that track hiring. Overall, employment in the US rose by 115,000 jobs in April, with gains in healthcare, transportation and warehousing, and retail trade, according to the <a href="https://www.bls.gov/news.release/pdf/empsit.pdf">latest report by the US Bureau of Labor Statistics</a>. </p>



<p>But tech hiring has slowed and in the last week, research firms have released April numbers that vary wildly; some point to big tech job cuts, others see increases in hiring. Looking deeper at the data, jobs fell in tech-related sectors such as telecom (down 2.5% decline) and infrastructure providers (with a 3.9%).</p>



<p>Though the BLS reported job growth for the overall economy in April, placement firm Challenger Gray and Christmas actually reported a jobs decline by 83,387 across all sectors. It also argued that tech companies are indeed making large-scale cuts, with 33,361 losses in April, Andy Challenger, chief revenue officer of Challenger, Gray &amp; Christmas, <a href="https://www.challengergray.com/blog/challenger-report-april-job-cuts-rise-38-from-march-ytd-cuts-down-50/">said in a statement</a>.</p>



<p>AI was cited most often as a reason for job losses, affecting 21,490, or 26% of all  cuts across sectors in April. Other reasons cited were the on-again, off-again tariffs imposed by President Donald J. Trump, the ongoing war in Iran, and slack consumer spending.</p>



<p>“Regardless of whether individual jobs are being replaced by AI, the money for those roles is,” Gray said.</p>



<p>Even with uncertainty about the direction of the job market, recent data indicates a growth in tech job listings, which undercuts the notion that tech firms are drastically reducing payrolls. <a href="https://www.comptia.org/en-em/about-us/news/press-releases/New-tech-job-postings-hit-three-year-high-as-hiring-swings-into-positive-territory-CompTIA-analysis-reveals/" target="_blank" rel="noreferrer noopener">According to CompTIA</a>, 271,483 tech job listing across were added in April. That brings the total to 575,000 active job postings.</p>



<p>The increase in listings is the result of employers clarifying their tech strategies and AI roles, CompTIA said. Increasingly, roles are being defined around “core tech skills as a foundation for more advanced capabilities,” CompTIA said. </p>



<p>Challenger, Gray and Christmas has measured 85,411 tech job cuts so far this year, with 33,361 of those cuts coming in April alone. Along the same lines, RationalFX has counted <a href="https://www.rationalfx.com/forex-brokers/tech-industry-layoffs/" target="_blank" rel="noreferrer noopener">78,557 tech jobs lost globally</a> so far in 2026.</p>



<p>This year has been especially brutal at some companies: Reports last month indicated that <a href="https://www.bbc.com/news/articles/crm1y89vek8o" target="_blank" rel="noreferrer noopener">Meta planned to cut 10% of its workforce</a>. In late March, Oracle announced job cuts that financial analysts said <a href="https://www.wsj.com/tech/oracle-lays-off-workers-amid-heavy-ai-investment-fff8cd82" target="_blank" rel="noreferrer noopener">could affect 30,000 employees</a>. Amazon, PayPal, Block, and Atlassian are among the other major tech firms cutting jobs.</p>



<p>Many of the job listing numbers could turn out to be transitional, as many CIOs still don’t know what skills they’re looking for in job candidates, said Jack Gold, principal analyst at J. Gold Associates.</p>



<p>A particular skill that’s useful today might not be needed tomorrow — especially given the pace at which AI is advancing in the workplace.</p>



<p>“I don’t see the mass elimination of jobs, like some ‘pundits’ have predicted,” Gold said. “It [the AI era] will likely result in new jobs we haven’t thought about yet.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I’ve spent the last few months trying to solve a problem that’s always bothered me: the trust gap in sharing CLI tools]]></title>
<description><![CDATA[https://preview.redd.it/uca6em9nh90h1.png?width=1191&format=png&auto=webp&s=d089af44e7cd4e78de84ada375d2730f0affc455 If you build a web app, you just share a URL. People click it, play around for five seconds, and decide if they like it. But sharing a CLI tool means asking people to download a bi...]]></description>
<link>https://tsecurity.de/de/3504361/linux-tipps/ive-spent-the-last-few-months-trying-to-solve-a-problem-thats-always-bothered-me-the-trust-gap-in-sharing-cli-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3504361/linux-tipps/ive-spent-the-last-few-months-trying-to-solve-a-problem-thats-always-bothered-me-the-trust-gap-in-sharing-cli-tools/</guid>
<pubDate>Sun, 10 May 2026 10:26:18 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://preview.redd.it/uca6em9nh90h1.png?width=1191&amp;format=png&amp;auto=webp&amp;s=d089af44e7cd4e78de84ada375d2730f0affc455">https://preview.redd.it/uca6em9nh90h1.png?width=1191&amp;format=png&amp;auto=webp&amp;s=d089af44e7cd4e78de84ada375d2730f0affc455</a></p> <p>If you build a web app, you just share a URL. People click it, play around for five seconds, and decide if they like it. But sharing a CLI tool means asking people to download a binary and run it on their system. It's a huge leap of faith. Because of that friction, I’ve seen so many incredible tools get ignored simply because developers rightfully don't want to risk their local environments on something new.</p> <p>I wanted to fix that. I love asciinema, it's the gold standard for showing what a terminal can do. But watching a recording isn't the same as actually typing the commands yourself. I wanted to build a way for audiences to safely "touch" a CLI tool without the risk of a local install.</p> <p>The technical side was a real struggle. I didn’t want to run expensive, heavy VMs on a server; I wanted everything to happen on the client side. But browsers aggressively throttle iframes for safety. When I started, booting a machine took a devastating 1 minute and 20 seconds. After a lot of late nights fighting that throttling, I finally managed to get the boot time down to under 3 seconds on most devices.</p> <p>One part of the execution I’m really proud of is how it handles tutorials. I hate when interactive guides feel cramped in a tiny window, so I built a concept called "Super Projects." You can have different chapters or steps in a guide, but they all stay connected to the exact same underlying VM. You can move through a complex project naturally without losing your state.</p> <p>Just a heads-up: I’m the sole developer behind this tool, SWACN. I’ve poured a lot of heart (and caffeine) into it, so there are definitely going to be some rough edges I haven't caught. For instance, there’s no network access in the VM right now. Adding that introduces a massive layer of complexity for keeping things isolated and safe, but if it's something people really need, I’m open to figuring it out.</p> <p>SWACN is already approved by Iframely, so you can actually drop these directly into Notion or Gitbook right now. I’m just excited to finally show this to someone, and I really hope it makes sharing terminal knowledge a bit easier.</p> <p><strong>The tool:</strong> <a href="https://swacn.com/">https://swacn.com</a> <br> <strong>An example:</strong> <a href="https://swacn.github.io/showcase/">https://swacn.github.io/showcase/</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/karthikeyjoshi"> /u/karthikeyjoshi </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1t902qg/ive_spent_the_last_few_months_trying_to_solve_a/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1t902qg/ive_spent_the_last_few_months_trying_to_solve_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scams]]></title>
<description><![CDATA[Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Your work apps are quietly handing 19 data points to someone Office work in 2026 relies on mobile apps used alongside personal tools like banking and messaging. Ten widely used workplace apps, includ...]]></description>
<link>https://tsecurity.de/de/3504357/it-security-nachrichten/week-in-review-cpanel-vulnerability-actively-exploited-digicert-breach-linkedin-job-scams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3504357/it-security-nachrichten/week-in-review-cpanel-vulnerability-actively-exploited-digicert-breach-linkedin-job-scams/</guid>
<pubDate>Sun, 10 May 2026 10:24:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Your work apps are quietly handing 19 data points to someone Office work in 2026 relies on mobile apps used alongside personal tools like banking and messaging. Ten widely used workplace apps, including Gmail, Microsoft Teams, Zoom, Slack, and Notion, have over 12.5 billion Google Play downloads. Research from Incogni shows these apps collect an average of 19 data points … <a href="https://www.helpnetsecurity.com/2026/05/10/week-in-review-cpanel-vulnerability-actively-exploited-digicert-breach-linkedin-job-scams/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/05/10/week-in-review-cpanel-vulnerability-actively-exploited-digicert-breach-linkedin-job-scams/">Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scams</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT]]></title>
<description><![CDATA[Elastic Security Labs uncovers a novel social engineering campaign that abuses the popular note-taking application, Obsidian's legitimate community plugin ecosystem. The campaign, which we track as REF6598, targets individuals in the financial and cryptocurrency sectors through elaborate social e...]]></description>
<link>https://tsecurity.de/de/3501392/it-security-nachrichten/phantom-in-the-vault-obsidian-abused-to-deliver-phantompulse-rat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501392/it-security-nachrichten/phantom-in-the-vault-obsidian-abused-to-deliver-phantompulse-rat/</guid>
<pubDate>Fri, 08 May 2026 23:19:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Elastic Security Labs uncovers a novel social engineering campaign that abuses the popular note-taking application, Obsidian's legitimate community plugin ecosystem. The campaign, which we track as REF6598, targets individuals in the financial and cryptocurrency sectors through elaborate social engineering on LinkedIn and Telegram.]]></content:encoded>
</item>
<item>
<title><![CDATA[Does perfect code exist? (Abstractions, Part 1)]]></title>
<description><![CDATA[Bryan Cantrill recently wrote a blog entry, where among other things, he philosophized on the concept of “perfect code”. He compares software to math, arguing that Euclid’s greatest common denominator algorithm shows no sign of wearing out, and that when code achieves perfection (or gets close to...]]></description>
<link>https://tsecurity.de/de/3501025/unix-server/does-perfect-code-exist-abstractions-part-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501025/unix-server/does-perfect-code-exist-abstractions-part-1/</guid>
<pubDate>Fri, 08 May 2026 23:02:26 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Bryan Cantrill recently wrote a blog entry, where among other things, he <!-- raw HTML omitted -->philosophized on the concept of “perfect code”<!-- raw HTML omitted -->. He compares software to math, arguing that Euclid’s greatest common denominator algorithm shows no sign of wearing out, and that when code achieves perfection (or gets close to perfection), “it sediments into the information infrastructure” and the abstractions defined by that code becomes “the bedrock that future generations may build upon”. Later, in the comments of his blogs, when pressed to give some examples of such perfection, he cites a clever algorithm coded by his mentor to divide a high resolution timestamp by a billion extremely efficiently, and Solaris’s “cyclic subsystem”, a timer dispatch function.</p>
<p>Watching <!-- raw HTML omitted -->his talk at Google<!-- raw HTML omitted --> where his introduction and sidebar book review on Scott Rosenberg’s “On Dreaming in Code”, it’s clear that he very passionately believes that it is possible to write perfect code, and that one should strive for that at all times. Perhaps that’s because he mostly writes code for operating systems, where the requirements change slowly, and for one OS in particular, Solaris, which tries far harder than most software projects to keep published interfaces stable for as long as possible. In contrast, the OS I’ve spent a lot of time hacking around, Linux, quite proudly states that at least inside the kernel, interfaces can not and should not be stable. Greg Kroah-Hart’s <!-- raw HTML omitted -->“Stable API Nonsense”<!-- raw HTML omitted --> is perhaps one of the strongly and most passionate expositions of that philosophy.</p>
<p>I can see both sides of the argument, and in their place, both have something to offer. To Bryan’s first point, it is absolutely true that interfaces can become “bedrock” upon which entire ecosystems are built. Perhaps one of the most enduring and impactful example would be the Unix programming interface, which has since become enshrined by POSIX.2 and successor standards. I would argue, though, that it is the interface that is important, and not the code which initially implemented it. If the interface is powerful enough, and if it appears at the right time, and the initial implementation is good enough (<strong>not</strong> perfect!), then it can establish itself by virtue of the software which uses it becoming large enough that it assumes an important all out of scale with its original intention.</p>
<p>Of course, sometimes such an interface is not perfect. There is an apocryphal story that when S. Feldman at AT&amp;T labs first wrote the ‘make’ utility, that he did so rather quickly, and then put it available for his fellow lab members to use, and then went home to sleep. In some versions of the story he had stayed up late and/or pulled an all-nighter to write it, so he slept a long time. When he came back to work, he had come up with a number of ways to improve the syntax of the Makefile. Unfortunately, (so goes the story) that too many teams were already using the ‘make’ utility, so he didn’t feel he could change the Makefile syntax. I have no evidence that this ever took place, and I suspect it is an urban myth that was invented to explain why Makefiles have a rather ugly and unfortunate syntax that many would call defects, including the use of syntactically significant tab characters which are indistinguishable from other forms of leading whitespace.</p>
<p>Another example which is the bane of filesystem designers everywhere are the Unix readdir(2), telldir(2), and seekdir(2) interfaces. These interfaces fundamentally assume that directories are stored in linear linked lists, and filesystems that wish to use more sophisticated data structures, such as b-trees, have to go to extraordinary lengths in order support these interfaces. Very few programs use telldir(2) and seekdir(2), but some filesystems such as JFS maintain two b-trees instead of one just to cater to telldir/seekdir.</p>
<p>And yet, it is absolutely true that interfaces can be the bedrock for an entire industry. Certainly no matter what its warts, the Unix/Posix interface has proven the test of time, and it has been responsible for the success of many a company and many billions of dollars of market capitalization. But is this the same as perfect code? No, but if billions of dollars of user applications are going to be depending on that code, it’s best if code which implement such an interface be high quality, and should attempt to achieve perfection.</p>
<p>But what does it mean for code to be perfect? For a particular environment, if the requirements can be articulated clearly, I can accept that code can reach perfection, in that it becomes as fast as possible (for the given computer platform), and it handles all exception cases, etc., etc. Unfortunately, in the real world, the environment and the requirements inevitably change over time. For example, Bryan’s cyclic subsystem, which he proudly touts as being if not perfect, almost so, and which executes at least 100 times a second on every Solaris system in the world. I haven’t looked at the cyclic system in any detail, since I don’t want to get myself contaminated (the CDDL and GPLv2 licenses are intentionally incompatible, and given that companies — including Sun — have sued over IPR issues, well, one can’t be too careful), but waking up the CPU from its low-power state 100 times a second isn’t a good thing at all if you are worried about <a href="http://www-03.ibm.com/systems/optimizeit/cost_efficiency/energy_efficiency/" title="IBM Project Big Green">energy conservation in data centers</a> — or in laptops.</p>
<p>For example, on my laptop, it is possible to keep wakeups down to no more than 30-35 times a second and it would be possible to do more but for an abstraction limitation. Suppose for example an process wants to be sleep and then receive a wakeup 1 milliseconds later, and so requests this via usleep(). At the same time, another application wants to sleep until some file descriptor activity takes place, or after 1.2 milliseconds takes place. 0.3 milliseconds later, a third process requests a sleep, this time for 0.8 milliseconds. Now, it could be that in all of the above cases, the applications don’t actually need exact timing; if they all get their wakeups plus or minus some fraction of a millisecond, they would be quite cool with that. Unfortunately, the standard timer interfaces have no way of expressing this, and so the OS can’t combine the three wakeups at T+1.0, T+1.1, and T+1.2 milliseconds into one wakeup at T+1.1ms.</p>
<p>So this is where Greg K-H’s “Stable API Nonsense” comes into play. We may not be able to solve this problem at the userspace level, but we darn well can solve this problem inside the kernel. Inside the kernel, we can change the timer abstraction to allow device drivers and kernel routines to provide a timer delta plus a notion of how much accuracy is required for a particular timer request. Doing so might change a timer structure that previously external device drivers had depended upon — but too bad, that’s why stable ABI/API’s are not supported for internal kernel interfaces. Is this that the interface could have been extended? Well, perhaps, and perhaps not; if an interface is well designed, it is possible it can be extended in an API and/or ABI compatible way. There usually is a performance cost to doing so, and sometimes it may make sense to pay that that cost, and sometimes it may not. I’ll talk more about that in a future essay.</p>
<p>Yet note what happened to the timer implementation. We have a pretty sophisticated timer implementation inside Linux, that uses heap data structures and buckets of timers for efficiency. So while I might not call it perfect, it is pretty good. But, oops! Thanks to this new requirement of energy efficiency, it will likely need to get changed to support variable levels of accuracy and the ability to fire multiple timers that are (more or less) coming due in a single CPU wakeup cycle. Does that make it no longer perfect, or no longer pretty good? Well, it just had a new requirement impact the code, and if criteria for perfection is for the abstraction defined by the code to be “bedrock” and never-changing, and no need to make any changes in said code over multiple years, I would argue that little to no code, even OS code, can ever achieve perfection by that definition — unless that code is no longer being used.</p>
<p>(This is the first of a multi-part series of essays on abstractions that I have planned. The next essay which I plan to write will be entitled “Layer surfing, or jumping between layers”, and will be coming soon to a blog near you….)</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SSD optimizations]]></title>
<description><![CDATA[A few months ago I got my hands on a sample of the Intel X25-E SSD drives for testing purposes. There are lots of interesting things to be said about SSD vs rotational devices, but my main interest in these devices is largely that they offer a good test base for high IOPS rates testing. So yes, t...]]></description>
<link>https://tsecurity.de/de/3500990/unix-server/ssd-optimizations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500990/unix-server/ssd-optimizations/</guid>
<pubDate>Fri, 08 May 2026 23:01:22 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A few months ago I got my hands on a sample of the Intel X25-E SSD drives for testing purposes. There are lots of interesting things to be said about SSD vs rotational devices, but my main interest in these devices is largely that they offer a good test base for high IOPS rates testing. So yes, the device read/write bandwidth definitely kicks a lot of ass, in fact so much that it's the first SSD out there that I would recommend to other people. I've played with various other models in the past, even expensive ones. And while they do have nice read performance, they fall flat on their face when presented with random write workloads. Additionally, apart from the flash itself, the drive internals are really outdated - most are using SATA-I 1.5gbps link speeds, and none of them offer any kind of command queuing. What are they thinking?<br><br>Anyway, back to the topic at hand. As my initial primary goal with this device was increasing the IOPS rate of the Linux IO stack, testing was mainly done with O_DIRECT libaio. As with most of my testing, I tend to use <a href="http://git.kernel.dk/?p=fio.git;a=summary" target="_blank" rel="nofollow">fio</a> for quickly setting up a prototype workload. I wanted to use small block sizes for various reasons. This brings the IOPS rate up, thus better high lighting problem areas in Linux that would tend to be hidden more with larger block sizes. My concern with O_DIRECT and small block sizes is that get_user_pages() overhead would dominate the per-command overhead, however those concerns turned out to be completely unfounded after Nick Piggins fast path get_user_pages() patches have gone in. That is nice, since I didn't really want to spend my time optimizing the VM for this!<br><br>The first bottleneck that reared its ugly head was hpet read in the kernel. It was so large that switching to a tsc based clock source for the kernel increased the IOPS rate by over 10%. After a bit of head scratching, I started looking at how many gettimeofday() calls that fio generates for this workload - a LOT. Fio wants to tell you pretty much everything about IO latencies, both going in to the kernel, at the device end, and reaping them. This in turn generates a lot of gettimeofday() traffic. A few hacks and options were put into fio to diminish the number of gtod calls and things looked much better with the default clock source.<br><br>To step back a bit before going further, one usually has a preconceived notion of a few changes that'll speed things up before doing this type of testing. One such thing was the IO plug management in Linux. Plugging is meant to optimize the command size for the device, at the expense of a bit of latency on submission. This makes a lot of sense for rotational storage, not so much for SSD devices. Turns out that disabling plugging gains us about 1% on just this device, when doing 30k-40k IOPS.<br><br>After disabling plugging, I went further with the profiling. The top entry is (not surprising) the ahci interrupt handler. There are ways to speed it up a bit without going too far, but my goal was IO stack reduction in general, so I left it alone for now. Next on the list was slab allocations. When issuing a piece of IO in Linux, we do quite a few allocations along the way. First we allocate a bio, then we allocate a bio_vec list to fill pages into. The bio_vec allocations come from a number of slab pools, sized in powers of two (1 entry, 4, 16, 64, 128, and 256). Then a request is allocated to attach this bio to. Going into the driver layers, SCSI allocates a SCSI command and sense buffer before sending it to the device. So that's 5 allocations just for the IO request, and there can easily be more from files ystems etc. We can't get away with not allocating a bio, but we can eliminate at least some of bio_vec allocations fairly easily. Most of the IO issued in a system is fairly small, in the range of 4 - 16kb. If we embed the bio_vec into the bio for a small number of pages, we can get rid of this allocation. To take that step a bit further, I wanted to incorporate a related change that Chris Mason had previously voiced an interest in. When a file system allocates a bio, it typically allocates a private structure for information related to that piece of IO. So the patch set in full allows for a piece of memory to be reserved both at the front of the bio (for file systems) and at the end (for the bio_vec). This then combines these three allocations into one. A similar trick was done for the SCSI command, so that the sense buffer is allocated at the very end as well. Finally, I added a struct request allocation cache to avoid going into the memory allocator there as well. The end result is that we gained 3-4% for this workload.<br><br>Another entry that was high in the profile list was lookup_ioctx(). This is what finds the kernel aio context for a given process when that process does an aio io_submit() to submit a piece of IO. When I read the kernel implementation, several red lights whent off in my head. The lookup was a doubly linked list, guarded by a read/write spinlock. While the O(n) choice of a linked list may seem problematic, there's usually only a single entry on this list since processes generally do not set up a lot of IO contexts to submit IO against. But experience tells me that reader/write locks are usually trouble, as they are much slower than a normal spinlock. Personally I think the use of them is usually a design mistake and that it would be better if we removed them from the kernel! The list management in aio was opencoded, so I converted that to a hlist structure and protected it with RCU. Using RCU here makes a lot of sense, since the list is basically only manipulated when the IO context is setup or torn down - for the long duration of actually submitting IO, it's purely a reader side thing. This got us about 2% gain on even a puny 2-way system.<br><br>At this years kernel summit, I had a talk with Matthew Wilcox about a recent change to the IO accounting that Intel had found troublesome. In the 2.4 days, we had per-partition statistics on the IO request, while for 2.6 kernels we had dumped that feature. About a year ago that feature was reinstated. The partition lookup scans the kernel partition table to find the right partition to account, and if that partition number is in the higher range, we end up spending a bit of time doing this for every IO. You don't notice if you are primarily doing IO to sda1 or sda2, but if sda16 is hit a lot it starts to show. I added a one-hit cache in front of this lookup and got rid of most of that lookup time. This trick is similar to what we do for IO merging, and it works exceptionally well. The reason being that while you typically have more than one partition active for IO at any given point in time, submissions tend to come in batches. If these batches are large enough, we get a lot of hits in the one-hit cache before having to invalidate it. So this again got us a few percent of improvement for this type of scenario.<br><br>I'll stop detailing the optimizations here and save some for future blog entries, there's still lots of improvements to be made and I have lots of stuff in-progress that I hope will be very interesting. And I haven't even gotten to buffered IO yet! If you are curious about the above changes, you are encouraged to inspect the for-2.6.29 branch of my block git repo. Find that <a href="http://git.kernel.dk/?p=linux-2.6-block.git;a=shortlog;h=refs/heads/for-2.6.29" target="_blank" rel="nofollow">here</a>. In the ssd branch there are more experimental changes that will need a bit longer to mature.<br><br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Debian, Philosophy, and People]]></title>
<description><![CDATA[Given the recent brouhaha in Debian, and General Resolution regarding Lenny’s Release policy as it relates to Firmware and Debian’s Social Contract, which has led to the resignation of Manoj Srivastava from the position of Secretary for the Debian Project, I’m reminded of the following passage fr...]]></description>
<link>https://tsecurity.de/de/3500985/unix-server/debian-philosophy-and-people/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500985/unix-server/debian-philosophy-and-people/</guid>
<pubDate>Fri, 08 May 2026 23:01:12 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Given the recent brouhaha in Debian, and General Resolution regarding Lenny’s Release policy as it relates to Firmware and Debian’s Social Contract, which has led to the resignation of Manoj Srivastava from the position of Secretary for the Debian Project, I’m reminded of the following passage from Gordon Dickson’s <em>Tactics of Mistakes</em> (part of Dickson’s Childe Cycle, in which he tells the story of the rise of the Dorsai):</p>
<blockquote>
<p>“No,” said Cletus. “I’m trying to explain to you why I’d never make an Exotic. In your calmness in the face of possible torture and the need to kill yourself, you were showing a particular form of ruthlessness. It was ruthlessness toward yourself—but that’s only the back side of the coin. You Exotics are essentially ruthless toward all men, because you’re philosophers, and by and large, philosophers are ruthless people.”</p>
<p>“Cletus!” Mondar shook his head. “Do you realize what you’re saying?”</p>
<p>“Of course,” said Cletus, quietly. “And you realize it as well as I do. The immediate teaching of philosophers may be gentle, but the theory behind their teaching is without compunction—and that’s why so much bloodshed and misery has always attended the paths of their followers, who claim to live by those teachings. More blood’s been spilled by the militant adherents of prophets of change than by any other group of people down through the history of man.”</p>
</blockquote>
<p>The conflict between idealism and pragmatism is a very old one in the Free and Open Source Software Movement. At one end of the spectrum stands Richard Stallman, who has never compromised on issues regarding his vision of Software Freedom. Standing at various distances from this idealistic pole are various members of the Open Source Community. For example, in the mid-1990’s, I used to give presentations about Linux using Microsoft Powerpoint. There were those in the audience that would give me grief about using a non-free program such as MS Powerpoint, but my response was that I saw no difference between driving a car which had non-free firmware and using a non-free slide presentation program. I would prefer to use free office suite, but at the time, nothing approached the usability of Powerpoint, and while dual-booting into Windows was a pain, I could do a better job using Powerpoint than other tools, and I refused to handcap myself just to salve the sensibilities of those who felt very strongly about Free Software and who viewed the use of all non-Free Software as an ultimate evil that must be stamped out at all costs.</p>
<p>It is the notion of Free Software as a philosophy, with no compromises, which has been the source of many of the disputes inside Debian. Consider, if you will, the first clause of the Debian Social Contract:</p>
<blockquote>
<p><strong>Debian will remain 100% free</strong></p>
<p>We provide the guidelines that we use to determine if a work is <!-- raw HTML omitted --><!-- raw HTML omitted -->free<!-- raw HTML omitted --><!-- raw HTML omitted --> in the document entitled <!-- raw HTML omitted --><!-- raw HTML omitted -->The Debian Free Software Guidelines<!-- raw HTML omitted --><!-- raw HTML omitted -->. We promise that the Debian system and all its components will be free according to these guidelines. We will support people who create or use both free and non-free works on Debian. We will never make the system require the use of a non-free component.</p>
</blockquote>
<p>This clause has in it no room for compromise. Note the use of words such as “100% free” and “<strong>never</strong> make the system require the use of a non-free component” (emphasis mine). In addition, the Debian Social Contract tends to be interpreted by Computer Programmers, who view such imperatives as constraints that must never be violated, under <em>any</em> circumstances.</p>
<p>Unfortunately, the real world is rarely so cut-and-dried. Even the most basic injunctions, such as “<em>Thou shalt not kill</em>” have exceptions. Few people might agree with claims made by the U.S. Republican Party that the war in Iraq qualified as a Just War as defined by Thomas Aquinas, but rather more people might agree that the July 20, 1944 plot to assassinate Hitler would be considered justifiable. And most people would probably agree most of the actions undertaken by the Allied Soldiers on World War II battlefields that involved killing other soldiers would be considered a valid exception to the moral (and for those in the Judeo-Christian tradition, biblical) injunction, “<em>Thou shalt not kill</em>“.</p>
<p>As another example, consider the novel and musical <strong>Les Misérables</strong>, by Victor Hugo. One of the key themes of this story is whether or not “<em>Thou shalt not steal</em>” is an absolute or not. Ultimately, the police inspector Javert, who lived his whole life asserting that law (untempered by mercy, or any other human considerations) was more important than all else, drowns himself in the Seine when he realizes that his life’s fundamental organizing principle was at odds with what was ultimately the Right Thing To Do.</p>
<p>So if even the sixth and eighth commandments admit to exceptions, why is it that some Debian developers approach the first clause of the Debian Social Contract with a take-no-prisoners, no-exceptions policy? Especially given the fourth clause of the Debian Social contract:</p>
<blockquote>
<p><strong>Our priorities are our users and free software</strong></p>
<p>We will be guided by the needs of our users and the free software community. We will place their interests first in our priorities. We will support the needs of our users for operation in many different kinds of computing environments. We will not object to non-free works that are intended to be used on Debian systems, or attempt to charge a fee to people who create or use such works. We will allow others to create distributions containing both the Debian system and other works, without any fee from us. In furtherance of these goals, we will provide an integrated system of high-quality materials with no legal restrictions that would prevent such uses of the system.</p>
</blockquote>
<p>This clause does not have the same sort of absolutist words as the first clause, so many Debian Developers have held that the “needs of the users” is defined by “100% free software”.   Others have not agreed with this interpretation — but regardless of how “needs of the users” should be interpreted, the fact of the matter is, injuctions such as “Thou shalt not kill” are just as absolute — and yet in the real world, we recognize that there are exceptions to such absolutes, apparently unyielding claims on our behavior.</p>
<p>I personally believe that “100% free software” is a wonderful aspirational goal, but in particular with regards to standards documents and firmware, there are other considerations that should be taken into account.   People of good will may disagree about what those exceptions should be, but I think one thing that we should consider as even higher priority and with a greater claim on how we behave is the needs of our users and fellow developers __<em>as people</em>.   For those who claim Christianity as their religious tradition, Jesus once stated,</p>
<blockquote>
<p>Thou shalt love the Lord thy God with all thy heart, and with all thy soul, and with all thy mind.  This is the first and great commandment.  And the second is like unto it: <strong>Thou shalt love thy neighbour as thyself</strong>.   On these two commandments hang all the law and the prophets.</p>
</blockquote>
<p>Even for those who do not claim Christianity as their religious tradition, most moral and ethical frameworks have some variant on the Golden Rule: “Do unto others as you would have them do unto you”.  I would consider, for example, that the Golden Rule is at least a high priority claim on my behavior as the notion of free speech, and in many cases, it would be a higher priority claim.  The recent controversy surrounding <!-- raw HTML omitted -->Josselin Mouette was started precisely because Joss has taken a something which is a good thing, namely Free Speech, and relegated it to a principle more important than all else, and claiming that any restraint on such a notion was equivalent to censorship.<!-- raw HTML omitted --></p>
<p>I think the same thing is true for free software, although it is a subtler trap.  Philosophical claims than “100% free software” as most important consideration is dangerously close to treating Free Software as the Object of Ultimate Concern — or in religious terms, idolotry.  For those who are religious, it’s clear why this is a bad thing; for those who aren’t — if you are unwilling to worship a supernatural being, you may want to very carefully consider whether you are willing to take a philosophical construct and raise it to a position of commanding your highest allegiance to all else, including how you treat other people.</p>
<p>Ultimately, I consider people to be more important than computers, hardware or software.  So over time, while I may have had some disagreements with how Mark Shuttleworth has run Canonical Software and Ubuntu (but hey, he’s the multimillionaire, and I’m not), I have to give him props for Ubuntu’s <!-- raw HTML omitted -->Code of Conduct<!-- raw HTML omitted -->.  If Debian Developer took the some kind of Code of Conduct at least as seriously as the Social Contract, I think interactions between Debian Developers would be far more efficient, and in the end the project would be far more successful.   This may, however, require lessening the importance of philosophical constructs such as Free Speech and Free Software, and perhaps becoming more pragmatic and more considerate towards one another.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Finnish culture...]]></title>
<description><![CDATA[It's not all that often that we encounter things from Finland here in Portland.  So imagine my surprise when we're on our way to our weekly date-night with Tove, and our baby-sitter is gushing about this adorable and wonderful Finnish YouTube video.. She apparently have been watching it three or ...]]></description>
<link>https://tsecurity.de/de/3500925/unix-server/finnish-culture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500925/unix-server/finnish-culture/</guid>
<pubDate>Fri, 08 May 2026 22:59:29 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's not all that often that we encounter things from Finland here in Portland.  So imagine my surprise when we're on our way to our weekly date-night with Tove, and our baby-sitter is gushing about this adorable and wonderful Finnish YouTube video.. She apparently have been watching it three or four times a day for the last few days (weeks?), laughing hysterically.<br><br>I'm intrigued by this notion, so I look it up, and notice that I am very late to an internet phenomenon. The thing in question is Armi &amp; Danny's <a href="http://www.youtube.com/watch?v=kA5GkLM5C7M">"I Want to Love You Tender"</a>, which has apparently been a big hit on youtube for several years now.<br><br>Now, people who aren't from Finland may not realize the whole <span>depth</span> of that video. To an outsider, it may look like some highschool musical number with particularly inept dancing. It's funny, yes, but you go on to watch keyboard cat and dramatic chipmunk.<br><br>But to somebody from Finland, the first reaction is "I recognize that tune". The second reaction is "Oh, it's <span>them</span>!". That's not some inept highschool musical number, that's one of the most beloved Finnish entertainers <span>ever</span>! Ok, so the version you hear in Finland is in Finnish, and the above is the English version - and Finns back in the seventies weren't really all that good at English. That explains some of it.<br><br>When I grew up, the Swedes had ABBA and Björn Borg. The Finns had Armi ja Danny. Really.<br><br>Now I just find myself wishing that we'd have Finnish meal-pouches with musical accompaniments. "Rudolf in a Bag" MRE's (reindeer meat with lingonberries) with Armi and Danny on BluRay.<br><br>Although I'm not sure I could take the concentrated awesomeness that is "I Want to Love You Tender" in glorious HD.  Maybe it's safer in that low-quality YouTube version.]]></content:encoded>
</item>
<item>
<title><![CDATA[TL;DR: Memory-Model Recommendations for Rusting the Linux Kernel]]></title>
<description><![CDATA[These recommendations assume that the initial Linux-kernel targets for Rust developers are device drivers that do not have unusual performance and scalability requirements, meaning that wrappering of small C-language functions is tolerable.  (Please note that most device drivers fit into this cat...]]></description>
<link>https://tsecurity.de/de/3500627/unix-server/tldr-memory-model-recommendations-for-rusting-the-linux-kernel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500627/unix-server/tldr-memory-model-recommendations-for-rusting-the-linux-kernel/</guid>
<pubDate>Fri, 08 May 2026 22:50:43 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[These recommendations assume that the initial Linux-kernel targets for Rust developers are device drivers that do not have unusual performance and scalability requirements, meaning that wrappering of small C-language functions is tolerable.  (Please note that most device drivers fit into this category.)  It also assumes that the main goal is to reduce memory-safety bugs, although other bugs might be addressed as well.  Or, Murphy being Murphy, created as well.  But that is a risk in all software development, not just Rust in the Linux kernel.<br><br>Those interested in getting Rust into Linux-kernel device drivers sooner rather than later should look at the short-term recommendations, while those interested in extending Rust's (and, for that matter, C's) concurrency capabilities might be more interested in the long-term recommendations.<br><br><h2>Short-Term Recommendations</h2>The goal here is to allow the Rust language considerable memory-model flexibility while also providing Rust considerable freedom in what it might be used for within the Linux kernel.  The recommendations are as follows:<br><ol><br><li> Provide wrappers around the existing Linux kernel's locking, MMIO, I/O-barrier, and I/O-access primitives.  If I was doing this work, I would add wrappers incrementally as they were actually needed, but I freely admit that there are benefits to providing a full set of wrappers from the get-go.<br></li><li> Either wrapper <tt>READ_ONCE()</tt> or be careful to take Alpha's, Itanium's, and ARMv8's requirements into account as needed.  The situation with <tt>WRITE_ONCE()</tt> appears more straightforward.  The same considerations apply to the <tt>atomic_read()</tt> and <tt>atomic_set()</tt> family of primitives.<br></li><li> Atomic read-modify-write primitives should be made available to Rust programs via wrappers around C code.  But who knows?  Maybe it is once again time to try out <a href="https://lwn.net/Articles/691128/" target="_blank" rel="nofollow">intrinsics</a>.  Again, if I was doing the work, I would add wrappers/implementations incrementally.<br></li><li> Although there has been significant discussion surrounding how sequence locking and RCU might be handled by Rust code, more work appears to be needed.  For one thing, it is not clear that people proposing solutions are aware of the wide range of Linux-kernel use cases for these primitives.  In the meantime, I recommend keeping direct use of sequence locking and RCU in C code, and providing Rust wrappers for the resulting higher-level APIs.  In this case, it might be wise to make good use of compiler directives in order to limit Rust's ability to apply code-motion optimizations.  However, if you need sequence-locking or RCU Rust-language wrappers, there are a number that have been proposed.  (Except that you should first take another look or three at wrappering higher-level APIs.  Yes, APIs are hard, but there are huge benefits to proper APIs!)<br></li><li> Control dependencies should be confined to C code.  If needed, higher-level APIs whose C-language implementations require control dependencies can be wrappered for Rust use.  But my best guess is that it will be some time before Rust code needs control dependencies.<br></li></ol><br>Taking this approach should avoid memory-model-mismatch issues between Rust and C code in the Linux kernel.  And discussions indicate that much (and maybe all) of the wrappering work called out in the first three items above has already been done.<br><br>Of course, situations that do not fit this set of recommendations can be addressed on a case-by-case basis.  I would of course be happy to help.  Specifically, in my role as lead Linux-kernel RCU maintainer:<br><ol><br><li> My first reaction to submission of Rust wrappers for the RCU API will be to ask hard questions about the possibility of higher-level APIs.<br></li><li> If higher-level APIs are infeasible, I will look carefully at which RCU use cases are supported by the proposed wrappering.  I am working to improve documentation of the range of RCU use cases in order to help submitters to do this as well.  (This work will likely be helpful elsewhere as well.)<br></li><li> Again, if higher-level APIs are infeasible, I will look carefully at how the Rust wrappers are helping to find bugs.  This will clearly require me to continue learning Rust, as this requires me to have a detailed view of Rust's ownership mechanisms and how things like reference-counting use cases work around limitations in these mechanisms.<br></li></ol><br>This procedure should help buy the time required for me to learn more about the Rust language and for the Rust community to learn more about RCU and its many use cases.<br><br><h2>Long-Term Recomendations</h2>This section takes a more utopian view.  What would a perfect Rust sequence-locking implementation/wrapper look like?  Here are some off-the-cuff desiderata, none of which are met by the current C-code Linux-kernel implementation:<br><ol><br><li> Use of quantities computed from sequence-lock-protected variables in a failed reader should result in a warning.  But please note that reliably associating variables with sequence locks may not be easy.  One approach suggested in response to this series is to supply a closure containing the read-side critical section, thus restricting such leakage to (unsafe?) side effects.<br></li><li> Improper access to variables not protected by the sequence lock should result in a warning.  But please note that it is quite difficult to define "improper" in this context, let alone detect it in real code.<br></li><li> Data races in failed sequence-lock readers should not cause failures.  But please note that this is extremely difficult in general if the data races involve non-<tt>volatile</tt> C-language accesses in the reader.  For example, the compiler would be within its rights to refetch the value after the old value had been checked.  (This is why the <a href="https://paulmck.livejournal.com/63957.html" target="_blank">sequence-locking</a> post suggests marked accesses to sequence-lock-protected variables.)<br></li><li> Data races involving sequence-locking updaters are detected, for example, via KCSAN.<br></li></ol><br>As noted elsewhere, use of a wrapper around the existing C-language implementation allows C and Rust to use the same sequence lock.  This might or might not prove to be important.<br><br>Similarly, what would a perfect Rust RCU wrapper look like?  Again, here are some off-the-cuff desiderata, similarly unmet by existing C-code Linux-kernel implementations:<br><ol><br><li> Make <tt>call_rcu()</tt> and friends cause the specified object to make an end-of-grace-period transition in other threads' ownership from readers to unowned.  Again, not an immediate transition at the time of <tt>call_rcu()</tt> invocation, but rather a deferred transition that takes place at the end of some future grace period.<br></li><li> Some Rust notion of type safety would be useful in slab caches flagged as <tt>SLAB_TYPESAFE_BY_RCU</tt>.<br></li><li> Some Rust notion of existence guarantee would be useful for RCU readers.<br></li><li> Detect pointers to RCU-protected objects being improperly leaked from RCU read-side critical sections, where proper leakage is possible via locks and reference counters.  Perhaps an emphasis on closures is at least part of the answer.<br></li><li> Detect mishandling of dependency-carrying pointers returned by <tt>rcu_dereference()</tt> and friends.  Or perhaps introduce some marking such pointers to that the compiler will avoid breaking the ordering.  See the <a href="https://paulmck.livejournal.com/63316.html" target="_blank">address/data dependency</a> post for a list of C++ working papers moving towards this goal.<br></li></ol><br>There has recently been some work attempting to make the C compiler understand control dependencies.  Perhaps Rust could make something useful happen in this area, perhaps by providing markings that allow the compiler to associate the reads with the corresponding control-dependent writes.<br><br>Perhaps Rust can better understand more of the <a href="https://paulmck.livejournal.com/64392.html" target="_blank">ownership schemes</a> that are used within the Linux kernel.<br><br><h2>Rationale</h2>Please note that middle-term approaches are likely to be useful, for example, those that simply provide wrappers around the C-language RCU and sequence-locking implementations.  However, such approaches also carry risks, especially during that time when the intersections of the set of people deeply understanding Rust with the set of people deeply understanding RCU and sequence locking is the empty set.  For example, one risk that became apparent during the effort to add RCU to the C++ standard is that people new to RCU and sequence locking will latch onto the first use case that they encounter and focus solely on that use case.  This has also been a recurring issue for concurrency experts who encounter sequence locking and RCU for the first time.  This of course means that I need to do a better job of documenting RCU, its use cases, and the relationships between them.<br><br>This is not to say that per-use-case work is pointless.  In fact, such work can be extremely valuable, if nothing else, in helping to build understanding of the overall problem.  It is also quite possible that current RCU and sequence-locking use cases will resemble those of the future in the same way that the venerable "while" loop resembles the wide panoply of interator-like constructs found not only in modern languages, including those written in C in the Linux kernel, in other words, perhaps Rust will focus on specific fearless-concurrency-friendly RCU/sequence-locking use cases.  Except that the Linux kernel still contains "while" loops, as does a great deal of other software, which suggests that the low-level RCU and sequence-locking APIs will always be required.  There will also be questions as to whether a given new-age use case is there to help developers using RCU and sequence locking on the one hand or whether its main purpose is instead to work around a shortcoming in Rust on the other.  "This should be good clean fun!"  ;-)<br><br>Experience indicates that it will take significant time to sort out all of these issues.  We should therefore make this time available by proceeding initially as described in the short-term recommendations.<br><br>Criteria for judging proposals include safety, performance, scalability, build time, development cost, maintenance effort, and so on, not necessarily in that order.<br><br><h2>History</h2><i>October 18, 2021: Add "Rationale" section.</i><br><i>October 20, 2021: Add a few expansions and clarifications.</i><br><i>October 21, 2021: RCU-specific recommendations.</i>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 Best Digital Planners for Smarter Time Management in 2026]]></title>
<description><![CDATA[Discover the best digital planners for 2025, including top tools like ClickUp, Todoist, and Notion to boost productivity and stay organized.
The post 7 Best Digital Planners for Smarter Time Management in 2026 appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3500337/it-nachrichten/7-best-digital-planners-for-smarter-time-management-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500337/it-nachrichten/7-best-digital-planners-for-smarter-time-management-in-2026/</guid>
<pubDate>Fri, 08 May 2026 22:03:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Discover the best digital planners for 2025, including top tools like ClickUp, Todoist, and Notion to boost productivity and stay organized.</p>
<p>The post <a href="https://www.techrepublic.com/article/digital-planners/">7 Best Digital Planners for Smarter Time Management in 2026</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.13.0 (2026.5.7) — The Tenacity Release]]></title>
<description><![CDATA[Hermes Agent v0.13.0 (v2026.5.7)
Release Date: May 7, 2026
Since v0.12.0: 864 commits · 588 merged PRs · 829 files changed · 128,366 insertions · 282 issues closed (13 P0, 36 P1) · 295 community contributors (including co-authors)

The Tenacity Release — Hermes Agent now finishes what it starts. ...]]></description>
<link>https://tsecurity.de/de/3496794/downloads/hermes-agent-v0130-202657-the-tenacity-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496794/downloads/hermes-agent-v0130-202657-the-tenacity-release/</guid>
<pubDate>Thu, 07 May 2026 18:32:32 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.13.0 (v2026.5.7)</h1>
<p><strong>Release Date:</strong> May 7, 2026<br>
<strong>Since v0.12.0:</strong> 864 commits · 588 merged PRs · 829 files changed · 128,366 insertions · 282 issues closed (13 P0, 36 P1) · 295 community contributors (including co-authors)</p>
<blockquote>
<p>The Tenacity Release — Hermes Agent now finishes what it starts. Kanban ships as a durable multi-agent board (heartbeat, reclaim, zombie detection, auto-block on incomplete exit, per-task retries, hallucination recovery). <code>/goal</code> keeps the agent locked on a target across turns (Ralph loop). Checkpoints v2 rewrites state persistence with real pruning. Gateway auto-resumes interrupted sessions after restart. Cron grows a <code>no_agent</code> watchdog mode. A security wave closes 8 P0s — redaction is now ON by default, Discord role-allowlists are guild-scoped, WhatsApp rejects strangers by default, and TOCTOU windows close across auth.json and MCP OAuth. Google Chat becomes the 20th platform. Providers become a pluggable surface. Seven i18n locales ship.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Multi-agent Kanban — delegate to an AI team that actually finishes</strong> — Spin up a durable board, drop tasks on it, and let multiple Hermes workers pick them up, hand off, and close them out. Heartbeats, reclaim, zombie detection, retry budgets, and a hallucination gate keep the team honest. One install, many kanbans. (<a href="https://github.com/NousResearch/hermes-agent/pull/17805" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17805/hovercard">#17805</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/19653" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19653/hovercard">#19653</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20232/hovercard">#20232</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20332/hovercard">#20332</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21330/hovercard">#21330</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21183" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21183/hovercard">#21183</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21214/hovercard">#21214</a>)</p>
</li>
<li>
<p><strong><code>/goal</code> — the agent doesn't forget what you asked it to do</strong> — Lock the agent onto a target and it stays on task across turns. The Ralph loop as a first-class primitive. (<a href="https://github.com/NousResearch/hermes-agent/pull/18262" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18262/hovercard">#18262</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/18275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18275/hovercard">#18275</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21287" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21287/hovercard">#21287</a>)</p>
</li>
<li>
<p><strong>Show it a video</strong> — new <code>video_analyze</code> tool for native video understanding on Gemini and compatible multimodal models. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19301" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19301/hovercard">#19301</a>)</p>
</li>
<li>
<p><strong>Clone a voice</strong> — xAI Custom Voices lands as a TTS provider with voice cloning support. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18776" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18776/hovercard">#18776</a>)</p>
</li>
<li>
<p><strong>Hermes speaks your language</strong> — static gateway + CLI messages translate to 7 locales: Chinese, Japanese, German, Spanish, French, Ukrainian, and Turkish. Docs site gains a Chinese (zh-Hans) locale. (<a href="https://github.com/NousResearch/hermes-agent/pull/20231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20231/hovercard">#20231</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20329" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20329/hovercard">#20329</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20467" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20467/hovercard">#20467</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20474" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20474/hovercard">#20474</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20430" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20430/hovercard">#20430</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20431" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20431/hovercard">#20431</a>)</p>
</li>
<li>
<p><strong>Google Chat — the 20th messaging platform</strong> — plus a generic platform-plugin hooks surface so third-party adapters drop in without touching core (IRC and Teams migrated). (<a href="https://github.com/NousResearch/hermes-agent/pull/21306" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21306/hovercard">#21306</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21331" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21331/hovercard">#21331</a>)</p>
</li>
<li>
<p><strong>Sessions survive restarts</strong> — gateway bounces mid-agent, <code>/update</code> restarts, source-file reloads — conversations auto-resume when the gateway comes back. (<a href="https://github.com/NousResearch/hermes-agent/pull/21192" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21192/hovercard">#21192</a>)</p>
</li>
<li>
<p><strong>Security wave — 8 P0 closures</strong> — redaction ON by default, Discord role-allowlists guild-scoped (CVSS 8.1 cross-guild DM bypass closed), WhatsApp rejects strangers by default, TOCTOU windows closed across <code>auth.json</code> and MCP OAuth, browser enforces cloud-metadata SSRF floor, cron prompt-injection scans assembled skill content, <code>hermes debug share</code> redacts at upload. (<a href="https://github.com/NousResearch/hermes-agent/pull/21193" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21193/hovercard">#21193</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21241" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21241/hovercard">#21241</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21291" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21291/hovercard">#21291</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21176" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21176/hovercard">#21176</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21194/hovercard">#21194</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21228" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21228/hovercard">#21228</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21350/hovercard">#21350</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/19318" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19318/hovercard">#19318</a>)</p>
</li>
<li>
<p><strong>Checkpoints v2</strong> — state persistence rewritten. Real pruning, disk guardrails, no more orphan shadow repos. (<a href="https://github.com/NousResearch/hermes-agent/pull/20709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20709/hovercard">#20709</a>)</p>
</li>
<li>
<p><strong>The agent lints its own writes</strong> — post-write delta lint on <code>write_file</code> + <code>patch</code>. Python, JSON, YAML, TOML. Syntax errors surface immediately instead of shipping downstream. (<a href="https://github.com/NousResearch/hermes-agent/pull/20191" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20191/hovercard">#20191</a>)</p>
</li>
<li>
<p><strong><code>no_agent</code> cron mode — script-only watchdog</strong> — cron jobs can now skip the agent entirely and just run a script. Empty stdout is silent, non-empty gets delivered verbatim. (<a href="https://github.com/NousResearch/hermes-agent/pull/19709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19709/hovercard">#19709</a>)</p>
</li>
<li>
<p><strong>Platform allowlists everywhere</strong> — <code>allowed_channels</code> / <code>allowed_chats</code> / <code>allowed_rooms</code> config across Slack, Telegram, Mattermost, Matrix, and DingTalk. (<a href="https://github.com/NousResearch/hermes-agent/pull/21251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21251/hovercard">#21251</a>)</p>
</li>
<li>
<p><strong>Providers are now plugins</strong> — <code>ProviderProfile</code> ABC + <code>plugins/model-providers/</code>. Drop in third-party providers without touching core. (<a href="https://github.com/NousResearch/hermes-agent/pull/20324" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20324/hovercard">#20324</a>)</p>
</li>
<li>
<p><strong>API server — long-term memory per session</strong> — <code>X-Hermes-Session-Key</code> header gives memory providers a stable session identifier. (<a href="https://github.com/NousResearch/hermes-agent/pull/20199" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20199/hovercard">#20199</a>)</p>
</li>
<li>
<p><strong>MCP levels up</strong> — SSE transport with OAuth forwarding, stale-pipe retries, image results surface as MEDIA tags instead of getting dropped, keepalive on long-lived lifecycle waits. (<a href="https://github.com/NousResearch/hermes-agent/pull/21227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21227/hovercard">#21227</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21323" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21323/hovercard">#21323</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21289/hovercard">#21289</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21328" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21328/hovercard">#21328</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20209" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20209/hovercard">#20209</a>)</p>
</li>
<li>
<p><strong>Curator grows subcommands</strong> — <code>hermes curator archive</code>, <code>prune</code>, <code>list-archived</code>. Manual <code>hermes curator run</code> is synchronous now — you see results without polling. (<a href="https://github.com/NousResearch/hermes-agent/pull/20200" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20200/hovercard">#20200</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21236/hovercard">#21236</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21216" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21216/hovercard">#21216</a>)</p>
</li>
<li>
<p><strong>ACP — <code>/steer</code> and <code>/queue</code></strong> — direct the in-flight agent or queue follow-ups from Zed, VS Code, or JetBrains. Plus atomic session persistence and reasoning-metadata preservation across restarts. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenkDz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenkDz">@HenkDz</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18114/hovercard">#18114</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20279" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20279/hovercard">#20279</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20296" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20296/hovercard">#20296</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20433" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20433/hovercard">#20433</a>)</p>
</li>
<li>
<p><strong>TUI glow-up</strong> — <code>/model</code> picker matches <code>hermes model</code> with inline auth (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>), collapsible startup banner sections (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>), context-compression counter in the status bar. (<a href="https://github.com/NousResearch/hermes-agent/pull/18117" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18117/hovercard">#18117</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20625/hovercard">#20625</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21218" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21218/hovercard">#21218</a>)</p>
</li>
<li>
<p><strong>Dashboard grows up</strong> — Plugins page (manage, enable/disable, auth status) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>), Profiles management page (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincez-hms-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincez-hms-coder">@vincez-hms-coder</a>), sortable analytics tables, reverse-proxy support via <code>X-Forwarded-Prefix</code>, new <code>default-large</code> 18px theme. (<a href="https://github.com/NousResearch/hermes-agent/pull/18095" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18095/hovercard">#18095</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/16419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16419/hovercard">#16419</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/18192" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18192/hovercard">#18192</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21296" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21296/hovercard">#21296</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20820" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20820/hovercard">#20820</a>)</p>
</li>
<li>
<p><strong>SearXNG + split web tools</strong> — SearXNG ships as a native search-only backend; web tools now let you pick different backends per capability (search vs extract vs browse). (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20823" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20823/hovercard">#20823</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20061" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20061/hovercard">#20061</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20841" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20841/hovercard">#20841</a>)</p>
</li>
<li>
<p><strong>OpenRouter response caching</strong> — explicit cache control for models that expose it. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19132" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19132/hovercard">#19132</a>)</p>
</li>
<li>
<p><strong><code>[[as_document]]</code> — skill media-routing directive</strong> — skills can force the gateway to deliver output as a document on platforms that support it. (<a href="https://github.com/NousResearch/hermes-agent/pull/21210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21210/hovercard">#21210</a>)</p>
</li>
<li>
<p><strong><code>transform_llm_output</code> plugin hook</strong> — new lifecycle hook that lets plugins reshape or filter LLM output before it hits the conversation. Useful for context-window reducers and content filters. (<a href="https://github.com/NousResearch/hermes-agent/pull/21235" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21235/hovercard">#21235</a>)</p>
</li>
<li>
<p><strong>Nous OAuth persists across profiles</strong> — shared token store: sign in once, every profile inherits the session. (<a href="https://github.com/NousResearch/hermes-agent/pull/19712" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19712/hovercard">#19712</a>)</p>
</li>
<li>
<p><strong>QQBot — native approval keyboards</strong> — feature parity with Telegram / Discord approval UX. Chunked upload, quoted attachments. (<a href="https://github.com/NousResearch/hermes-agent/pull/21342" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21342/hovercard">#21342</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21353" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21353/hovercard">#21353</a>)</p>
</li>
<li>
<p><strong>6 new optional skills</strong> — Shopify (Admin + Storefront GraphQL), here.now, shop-app personal shopping assistant, Anthropic financial-services bundle, kanban-video-orchestrator (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>), searxng-search (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>). (<a href="https://github.com/NousResearch/hermes-agent/pull/18116" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18116/hovercard">#18116</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/18170" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18170/hovercard">#18170</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20702/hovercard">#20702</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21180" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21180/hovercard">#21180</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/19281" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19281/hovercard">#19281</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20841" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20841/hovercard">#20841</a>)</p>
</li>
<li>
<p><strong>New models</strong> — <code>deepseek/deepseek-v4-pro</code>, <code>x-ai/grok-4.3</code>, <code>openrouter/owl-alpha</code> (free), <code>tencent/hy3-preview</code> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Contentment003111/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Contentment003111">@Contentment003111</a>), Arcee Trinity Large Thinking temperature + compression overrides. (<a href="https://github.com/NousResearch/hermes-agent/pull/20495" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20495/hovercard">#20495</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20497" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20497/hovercard">#20497</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/18071" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18071/hovercard">#18071</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21077/hovercard">#21077</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20473" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20473/hovercard">#20473</a>)</p>
</li>
<li>
<p><strong>100 fresh CLI startup tips</strong> — the random tip banner gets 100 new entries covering cron, kanban, curator, plugins, and lesser-known flags. (<a href="https://github.com/NousResearch/hermes-agent/pull/20168" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20168/hovercard">#20168</a>)</p>
</li>
</ul>
<hr>
<h2>🧩 Multi-Agent Kanban (Durable)</h2>
<h3>New — durable multi-profile collaboration board</h3>
<ul>
<li><strong><code>feat(kanban): durable multi-profile collaboration board</code></strong> — post-revert reimplementation, multi-profile by design (<a href="https://github.com/NousResearch/hermes-agent/pull/17805" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17805/hovercard">#17805</a>)</li>
<li><strong>Multi-project boards</strong> — one install, many kanbans (<a href="https://github.com/NousResearch/hermes-agent/pull/19653" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19653/hovercard">#19653</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/19679" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19679/hovercard">#19679</a>)</li>
<li><strong>Share board, workspaces, and worker logs across profiles</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19378" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19378/hovercard">#19378</a>)</li>
<li><strong>Hallucination gate + recovery UX for worker-created-card claims</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4381227545" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20017" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/20017/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/20017">#20017</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20232/hovercard">#20232</a>)</li>
<li><strong>Generic diagnostics engine for task distress signals</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20332/hovercard">#20332</a>)</li>
<li><strong>Per-task <code>max_retries</code> override</strong> (supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395603538" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20972" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20972/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20972">#20972</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21330/hovercard">#21330</a>)</li>
<li><strong>Multiline textarea for inline-create title</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395580152" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20970" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20970/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20970">#20970</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21243" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21243/hovercard">#21243</a>)</li>
</ul>
<h3>Kanban Dashboard</h3>
<ul>
<li><strong>Workspace kind + path inputs in inline create form</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19679" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19679/hovercard">#19679</a>)</li>
<li><strong>Per-platform home-channel notification toggles</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19864/hovercard">#19864</a>)</li>
<li><strong>Sharper home-channel toggle contrast + drop → running action</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19916" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19916/hovercard">#19916</a>)</li>
<li>Fix: reject direct status transition to 'running' via dashboard API (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374522838" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19554" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19554/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19554">#19554</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19705" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19705/hovercard">#19705</a>)</li>
<li>Fix: dashboard board pin authoritative over server current file (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4393923128" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20879" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/20879/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/20879">#20879</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21230" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21230/hovercard">#21230</a>)</li>
<li>Fix: treat dashboard event-stream cancellation as normal shutdown (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392492481" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20790" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/20790/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/20790">#20790</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21222" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21222/hovercard">#21222</a>)</li>
<li>Fix: filter dashboard board by selected tenant (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377811969" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19817" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19817/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19817">#19817</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21349" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21349/hovercard">#21349</a>)</li>
<li>Fix: code/pre styling theme-immune across all themes (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4397085946" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21086" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/21086/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/21086">#21086</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21247" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21247/hovercard">#21247</a>)</li>
<li>Fix: reset <code>&lt;code&gt;</code> background inside dashboard board (<a href="https://github.com/NousResearch/hermes-agent/pull/20687" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20687/hovercard">#20687</a>)</li>
<li>Fix: preserve dashboard completion summaries + add kanban edit (salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4381222467" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20016/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20016">#20016</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20195" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20195/hovercard">#20195</a>)</li>
<li>Fix: avoid fragile failure-column renames (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4393243960" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20848" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20848/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20848">#20848</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20855/hovercard">#20855</a>)</li>
</ul>
<h3>Worker lifecycle + reliability</h3>
<ul>
<li><strong>Heartbeat + reclaim + zombie + retry-cap fixes</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4398097290" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21147" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/21147/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/21147">#21147</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4397997750" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21141" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/21141/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/21141">#21141</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4398459268" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21169" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21169/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21169">#21169</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4394007691" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20881" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20881/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20881">#20881</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21183" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21183/hovercard">#21183</a>)</li>
<li><strong>Auto-block workers that exit without completing + shutdown race</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4394258942" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20894" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/20894/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/20894">#20894</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21214/hovercard">#21214</a>)</li>
<li><strong>Detect darwin zombie workers</strong> (salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4381259811" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20023" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20023/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20023">#20023</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20188/hovercard">#20188</a>)</li>
<li><strong>Unify failure counter across spawn/timeout/crash outcomes</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20410" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20410/hovercard">#20410</a>)</li>
<li><strong>Enforce worker task-ownership on destructive tool calls</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19713" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19713/hovercard">#19713</a>)</li>
<li><strong>Drop worker identity claim from KANBAN_GUIDANCE</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19427" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19427/hovercard">#19427</a>)</li>
<li>Fix: skip dispatch for tasks assigned to non-profile lanes (salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4382429914" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20105" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20105/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20105">#20105</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4383083480" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20134" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20134/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20134">#20134</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20165" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20165/hovercard">#20165</a>)</li>
<li>Fix: include default profile in on-disk assignee enumeration (salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4382850470" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20123" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20123/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20123">#20123</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20170" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20170/hovercard">#20170</a>)</li>
<li>Fix: ignore stale current board pointers (salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4381624338" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20063" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20063/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20063">#20063</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20183" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20183/hovercard">#20183</a>)</li>
<li>Fix: profile discovery ignores HERMES_HOME in custom-root deployments (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackey8616/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackey8616">@jackey8616</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19020" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19020/hovercard">#19020</a>)</li>
<li>Fix: allow orchestrator profiles to see kanban tools via toolsets config (<a href="https://github.com/NousResearch/hermes-agent/pull/19606" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19606/hovercard">#19606</a>)</li>
</ul>
<h3>Batch salvages</h3>
<ul>
<li>Tier-1 batch — metadata test, max_spawn config, run-id lifecycle guard (salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373995127" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19522" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19522/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19522">#19522</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374531366" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19556" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19556/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19556">#19556</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378178088" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19829" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19829/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19829">#19829</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20440" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20440/hovercard">#20440</a>)</li>
<li>Tier-2 batch — doctor, started_at, parent-guard, latest_summary, selects, linked-children (<a href="https://github.com/NousResearch/hermes-agent/pull/20448" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20448/hovercard">#20448</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Backfill multi-board refs in reference docs (<a href="https://github.com/NousResearch/hermes-agent/pull/19704" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19704/hovercard">#19704</a>)</li>
<li>Document <code>/kanban</code> slash command (<a href="https://github.com/NousResearch/hermes-agent/pull/19584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19584/hovercard">#19584</a>)</li>
<li>Document recommended handoff evidence metadata (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373915487" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19512/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19512">#19512</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20415" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20415/hovercard">#20415</a>)</li>
<li>Fix orchestrator + worker skill setup instructions (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20958" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20958/hovercard">#20958</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20960" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20960/hovercard">#20960</a>)</li>
</ul>
<hr>
<h2>🎯 Persistent Goals, Checkpoints &amp; Session Durability</h2>
<h3><code>/goal</code> — persistent cross-turn goals (Ralph loop)</h3>
<ul>
<li><strong><code>feat: /goal — persistent cross-turn goals</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18262" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18262/hovercard">#18262</a>)</li>
<li><strong>Docs page — Persistent Goals (/goal)</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18275/hovercard">#18275</a>)</li>
<li>Fix: honor configured goal turn budget (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373327289" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19423/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19423">#19423</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21287" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21287/hovercard">#21287</a>)</li>
</ul>
<h3>Checkpoints v2</h3>
<ul>
<li><strong>Single-store rewrite with real pruning + disk guardrails</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20709/hovercard">#20709</a>)</li>
</ul>
<h3>Session durability</h3>
<ul>
<li><strong>Auto-resume interrupted sessions after gateway restart</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4394161171" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20888" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20888/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20888">#20888</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21192" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21192/hovercard">#21192</a>)</li>
<li><strong>Preserve pending update prompts across restarts</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20160" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20160/hovercard">#20160</a>)</li>
<li><strong>Preserve home-channel thread targets across restart notifications</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365144989" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18440" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18440/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/18440">#18440</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19271" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19271/hovercard">#19271</a>)</li>
<li><strong>Preserve thread routing from cached live session sources</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21206/hovercard">#21206</a>)</li>
<li><strong>Preserve assistant metadata when branching sessions</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18222" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18222/hovercard">#18222</a>)</li>
<li><strong>Preserve thread routing for /update progress and prompts</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18193" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18193/hovercard">#18193</a>)</li>
<li><strong>Preserve document type when merging queued events</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18215/hovercard">#18215</a>)</li>
</ul>
<hr>
<h2>🛡️ Security &amp; Reliability</h2>
<h3>Security hardening (8 P0 closures)</h3>
<ul>
<li><strong>Enable secret redaction by default</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354753568" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17691" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/17691/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/17691">#17691</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392395624" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20785" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/20785/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/20785">#20785</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21193" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21193/hovercard">#21193</a>)</li>
<li><strong>Discord — scope <code>DISCORD_ALLOWED_ROLES</code> to originating guild</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287868263" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/12136" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/12136/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/12136">#12136</a>, CVSS 8.1) (<a href="https://github.com/NousResearch/hermes-agent/pull/21241" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21241/hovercard">#21241</a>)</li>
<li><strong>WhatsApp — reject strangers by default, never respond in self-chat</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248249046" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/8389" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/8389/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/8389">#8389</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21291" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21291/hovercard">#21291</a>)</li>
<li><strong>MCP OAuth — close TOCTOU window when saving credentials</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21176" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21176/hovercard">#21176</a>)</li>
<li><strong><code>hermes_cli/auth.py</code> — close TOCTOU window in credential writers</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21194/hovercard">#21194</a>)</li>
<li><strong>Browser — enforce cloud-metadata SSRF floor in hybrid routing</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332049780" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16234" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/16234/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/16234">#16234</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21228" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21228/hovercard">#21228</a>)</li>
<li><strong><code>hermes debug share</code> — redact log content at upload time</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19318" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19318/hovercard">#19318</a>)</li>
<li><strong>Cron — scan assembled prompt including skill content for prompt injection</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4171149796" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/3968" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/3968/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/3968">#3968</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21350/hovercard">#21350</a>)</li>
<li><strong>Restore .env/auth.json/state.db with 0600 perms</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19699" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19699/hovercard">#19699</a>)</li>
<li><strong>SRI integrity for dashboard plugin scripts</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373144809" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19389/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19389">#19389</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21277" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21277/hovercard">#21277</a>)</li>
<li><strong>Bind Meet node server to localhost, restrict token file to owner read</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19597" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19597/hovercard">#19597</a>)</li>
<li><strong>Extend sensitive-write target to cover shell RC and credential files</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19282" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19282/hovercard">#19282</a>)</li>
<li><strong>Harden YOLO mode env parsing against quoted-bool strings</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18214/hovercard">#18214</a>)</li>
<li><strong>OSV-Scanner CI + Dependabot for github-actions only</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20037" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20037/hovercard">#20037</a>)</li>
</ul>
<h3>Reliability — critical bug closures</h3>
<ul>
<li><strong>CLI crash on startup — <code>Invalid key 'c-S-c'</code></strong> (P0, prompt_toolkit doesn't support Shift modifier) (<a href="https://github.com/NousResearch/hermes-agent/pull/19895" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19895/hovercard">#19895</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/19919" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19919/hovercard">#19919</a>)</li>
<li><strong>CLOSE_WAIT fd leak audit</strong> — httpx keepalive + WhatsApp aiohttp leak + Feishu hygiene (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365225326" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18451" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/18451/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/18451">#18451</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18766" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18766/hovercard">#18766</a>)</li>
<li><strong>Gateway creates AIAgent with empty OpenRouter API key when OPENROUTER_API_KEY is missing</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395721237" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20982" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/20982/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/20982">#20982</a>) — fallback providers correctly honored</li>
<li><strong>Background review + curator protected from overwriting bundled/hub skills</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4385227142" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20273" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/20273/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/20273">#20273</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20194/hovercard">#20194</a>)</li>
<li><strong>TUI compression continuation — ghost sessions with incomplete metadata</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4381124573" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20001" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/20001/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/20001">#20001</a>)</li>
<li><strong><code>hermes mcp add</code> silently launches chat instead of registering MCP server</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377325761" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19785" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/19785/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/19785">#19785</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21204/hovercard">#21204</a>)</li>
<li><strong>Background review agent runtime propagation</strong> — provider/model/credentials now actually inherit from parent</li>
<li><strong>Inbound document host paths translated to container paths for Docker backend</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370598224" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19048" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19048/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19048">#19048</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21184" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21184/hovercard">#21184</a>)</li>
<li><strong>Matrix gateway race between auto-redaction and message delivery with high-speed models</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370875307" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19075" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/19075/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/19075">#19075</a>)</li>
<li><strong><code>/new</code> during active agent session never sends response on Telegram</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369574811" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18912" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/18912/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/18912">#18912</a>)</li>
</ul>
<hr>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>New platform</h3>
<ul>
<li><strong>Google Chat — 20th platform</strong> + generic <code>env_enablement_fn</code> / <code>cron_deliver_env_var</code> platform-plugin hooks (IRC + Teams migrated) (<a href="https://github.com/NousResearch/hermes-agent/pull/21306" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21306/hovercard">#21306</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21331" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21331/hovercard">#21331</a>)</li>
</ul>
<h3>Cross-platform</h3>
<ul>
<li><strong><code>allowed_{channels,chats,rooms}</code> whitelist</strong> — Slack (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241887197" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/7401" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7401/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/7401">#7401</a>), Telegram, Mattermost, Matrix, DingTalk (<a href="https://github.com/NousResearch/hermes-agent/pull/21251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21251/hovercard">#21251</a>)</li>
<li><strong>Per-platform <code>gateway_restart_notification</code> flag</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20892" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20892/hovercard">#20892</a>)</li>
<li><strong><code>busy_ack_enabled</code> config — suppress ack messages</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18194/hovercard">#18194</a>)</li>
<li><strong>Auto-delete slash-command system notices after TTL</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18266" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18266/hovercard">#18266</a>)</li>
<li><strong>Opt-in cleanup of temporary progress bubbles</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21186/hovercard">#21186</a>)</li>
<li><strong><code>[[as_document]]</code> directive — skill media routing</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370838519" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19069" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19069/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19069">#19069</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21210/hovercard">#21210</a>)</li>
<li><strong><code>hermes gateway list</code> — cross-profile status</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371246115" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19129" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19129/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19129">#19129</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21225/hovercard">#21225</a>)</li>
<li><strong>Auto-resume interrupted sessions after restart</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4394161171" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20888" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20888/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20888">#20888</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21192" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21192/hovercard">#21192</a>)</li>
<li><strong>Atomic restart markers + Windows runtime-lock offset</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356655485" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17842/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17842">#17842</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18179" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18179/hovercard">#18179</a>)</li>
<li>Fix: <code>config.yaml</code> wins over <code>.env</code> for agent/display/timezone settings (<a href="https://github.com/NousResearch/hermes-agent/pull/18764" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18764/hovercard">#18764</a>)</li>
<li>Fix: auto-restart when source files change out from under us (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354047466" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17648" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/17648/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/17648">#17648</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18409" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18409/hovercard">#18409</a>)</li>
<li>Fix: use git HEAD SHA for stale-code check, not file mtimes (<a href="https://github.com/NousResearch/hermes-agent/pull/19740" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19740/hovercard">#19740</a>)</li>
<li>Fix: shutdown + restart hygiene — drain timeout, false-fatal, success log (<a href="https://github.com/NousResearch/hermes-agent/pull/18761" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18761/hovercard">#18761</a>)</li>
<li>Fix: preserve max_turns after env reload (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371542024" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19183" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19183/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19183">#19183</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21240/hovercard">#21240</a>)</li>
<li>Fix: exclude ancestor PIDs from gateway process scan (<a href="https://github.com/NousResearch/hermes-agent/pull/19586" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19586/hovercard">#19586</a>)</li>
<li>Fix: move quick-command alias dispatch before built-ins (<a href="https://github.com/NousResearch/hermes-agent/pull/19588" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19588/hovercard">#19588</a>)</li>
<li>Fix: show other profiles in 'gateway status' to prevent confusion (<a href="https://github.com/NousResearch/hermes-agent/pull/19582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19582/hovercard">#19582</a>)</li>
<li>Fix: include external_dirs skills in Telegram/Discord slash commands (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251225431" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/8790" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8790/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/8790">#8790</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18741" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18741/hovercard">#18741</a>)</li>
<li>Fix: match disabled/optional skills by frontmatter slug, not dir name (<a href="https://github.com/NousResearch/hermes-agent/pull/18753" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18753/hovercard">#18753</a>)</li>
<li>Fix: read /status token totals from SessionDB (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346505146" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17158" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17158/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17158">#17158</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18206/hovercard">#18206</a>)</li>
<li>Fix: snapshot callback generation after agent binds it, not before (<a href="https://github.com/NousResearch/hermes-agent/pull/18219" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18219/hovercard">#18219</a>)</li>
<li>Fix: re-inject topic-bound skill after /new or /reset (<a href="https://github.com/NousResearch/hermes-agent/pull/18205" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18205/hovercard">#18205</a>)</li>
<li>Fix: isolate pending native image paths by session (<a href="https://github.com/NousResearch/hermes-agent/pull/18202" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18202/hovercard">#18202</a>)</li>
<li>Fix: clear queued reload skills notes on new/resume/branch (<a href="https://github.com/NousResearch/hermes-agent/pull/19431" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19431/hovercard">#19431</a>)</li>
<li>Fix: hide required-arg commands from Telegram menu (<a href="https://github.com/NousResearch/hermes-agent/pull/19400" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19400/hovercard">#19400</a>)</li>
<li>Fix: bridge top-level <code>require_mention</code> to Telegram config (<a href="https://github.com/NousResearch/hermes-agent/pull/19429" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19429/hovercard">#19429</a>)</li>
<li>Fix: suppress duplicate voice transcripts (<a href="https://github.com/NousResearch/hermes-agent/pull/19428" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19428/hovercard">#19428</a>)</li>
<li>Fix: show friendly error when service is not installed (<a href="https://github.com/NousResearch/hermes-agent/pull/19707" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19707/hovercard">#19707</a>)</li>
<li>Fix: read context_length from custom_providers in session info header (<a href="https://github.com/NousResearch/hermes-agent/pull/19708" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19708/hovercard">#19708</a>)</li>
<li>Fix: preserve WSL interop PATH in systemd units (<a href="https://github.com/NousResearch/hermes-agent/pull/19867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19867/hovercard">#19867</a>)</li>
<li>Fix: handle planned service stops (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379126438" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19876" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19876/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19876">#19876</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19936" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19936/hovercard">#19936</a>)</li>
<li>Fix: keep DoH-confirmed Telegram IPs that match system DNS (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343791228" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17043" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17043/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17043">#17043</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20175" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20175/hovercard">#20175</a>)</li>
<li>Fix: load <code>reply_to_mode</code> from config.yaml for Discord + Telegram (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345524890" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17117" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17117/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17117">#17117</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20171" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20171/hovercard">#20171</a>)</li>
<li>Fix: tolerate malformed HERMES_HUMAN_DELAY_* env vars (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341881110" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16933" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16933/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16933">#16933</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20217" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20217/hovercard">#20217</a>)</li>
<li>Fix: deterministic thread eviction preserves newest entries (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304557717" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/13639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/13639/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/13639">#13639</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20285/hovercard">#20285</a>)</li>
<li>Fix: don't dead-end setup wizard when only system-scope unit is installed (<a href="https://github.com/NousResearch/hermes-agent/pull/20905" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20905/hovercard">#20905</a>)</li>
<li>Fix: wait for systemd restart readiness + harden Discord slash-command sync (<a href="https://github.com/NousResearch/hermes-agent/pull/20949" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20949/hovercard">#20949</a>)</li>
<li>Fix: avoid duplicated Responses history (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370224312" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18995" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18995/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/18995">#18995</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21185" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21185/hovercard">#21185</a>)</li>
<li>Fix: surface bootstrap failures to stderr (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4398205157" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21157" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21157/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21157">#21157</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21278" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21278/hovercard">#21278</a>)</li>
<li>Fix: log agent task failures instead of silently losing usage data (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4398211500" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21159" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21159/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21159">#21159</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21274" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21274/hovercard">#21274</a>)</li>
<li>Fix: log runtime-status write failures with rate-limiting (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4398208685" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21158" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21158/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21158">#21158</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21285/hovercard">#21285</a>)</li>
<li>Fix: reset-failed before every fallback restart so the gateway can't get stranded (<a href="https://github.com/NousResearch/hermes-agent/pull/21371" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21371/hovercard">#21371</a>)</li>
<li>Fix: Telegram — preserve <code>thread_id=1</code> for forum General typing indicator (<a href="https://github.com/NousResearch/hermes-agent/pull/21390" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21390/hovercard">#21390</a>)</li>
<li>Fix: batch critical fixes — session resume, /new race, HA WebSocket scheme (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19182/hovercard">#19182</a>)</li>
</ul>
<h3>Telegram</h3>
<ul>
<li><strong>DM user-managed multi-session topics</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371591594" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19185" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19185/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19185">#19185</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19206/hovercard">#19206</a>)</li>
</ul>
<h3>Discord</h3>
<ul>
<li><strong>Message deletion action</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370656299" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19052" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19052/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19052">#19052</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21197" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21197/hovercard">#21197</a>)</li>
<li>Fix: allow <code>free_response_channels</code> to override <code>DISCORD_IGNORE_NO_MENTION</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/19629" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19629/hovercard">#19629</a>)</li>
</ul>
<h3>Slack</h3>
<ul>
<li>Fix: ephemeral slash-command ack, private notice delivery, format_message fixes (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18198" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18198/hovercard">#18198</a>)</li>
</ul>
<h3>WhatsApp</h3>
<ul>
<li>Fix: load WhatsApp home channel from env overrides (<a href="https://github.com/NousResearch/hermes-agent/pull/18190" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18190/hovercard">#18190</a>)</li>
</ul>
<h3>Feishu</h3>
<ul>
<li><strong>Operator-configurable bot admission and mention policy</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18208" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18208/hovercard">#18208</a>)</li>
<li>Fix: force text mode for markdown tables (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305834130" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/13723" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/13723/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/13723">#13723</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WuTianyi123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WuTianyi123">@WuTianyi123</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20275/hovercard">#20275</a>)</li>
</ul>
<h3>Matrix + Email</h3>
<ul>
<li>Fix: <code>/sethome</code> on Matrix and Email now persists across restarts (<a href="https://github.com/NousResearch/hermes-agent/pull/18272" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18272/hovercard">#18272</a>)</li>
</ul>
<h3>Teams</h3>
<ul>
<li><strong>Docs + feat: sidebar + threading with group-chat fallback</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20042/hovercard">#20042</a>)</li>
</ul>
<h3>Weixin</h3>
<ul>
<li>Fix: deduplicate Weixin messages by content fingerprint (<a href="https://github.com/NousResearch/hermes-agent/pull/19742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19742/hovercard">#19742</a>)</li>
</ul>
<h3>QQBot</h3>
<ul>
<li><strong>Port SDK improvements in-tree — chunked upload, approval keyboards, quoted attachments</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21342" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21342/hovercard">#21342</a>)</li>
<li><strong>Wire native tool-approval UX via inline keyboards</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21353" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21353/hovercard">#21353</a>)</li>
</ul>
<hr>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Provider &amp; Model Support</h3>
<h4>Pluggable providers</h4>
<ul>
<li><strong>ProviderProfile ABC + <code>plugins/model-providers/</code></strong> — inference providers are now a pluggable surface (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314034992" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/14424" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14424/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/14424">#14424</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20324" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20324/hovercard">#20324</a>)</li>
<li><strong><code>list_picker_providers</code></strong> — credential-filtered picker (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303274394" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/13561" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/13561/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/13561">#13561</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20298" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20298/hovercard">#20298</a>)</li>
<li><strong>Remove <code>/provider</code> alias for <code>/model</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20358" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20358/hovercard">#20358</a>)</li>
<li><strong>Shared Hermes dotenv loader across CLI + plugins</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304909819" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/13660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/13660/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/13660">#13660</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20281" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20281/hovercard">#20281</a>)</li>
<li><strong>Nous OAuth persisted across profiles via shared token store</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19712" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19712/hovercard">#19712</a>)</li>
</ul>
<h4>New models</h4>
<ul>
<li><code>deepseek/deepseek-v4-pro</code> added to OpenRouter + Nous Portal (<a href="https://github.com/NousResearch/hermes-agent/pull/20495" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20495/hovercard">#20495</a>)</li>
<li><code>x-ai/grok-4.3</code> added to OpenRouter + Nous Portal (<a href="https://github.com/NousResearch/hermes-agent/pull/20497" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20497/hovercard">#20497</a>)</li>
<li><code>openrouter/owl-alpha</code> (free tier) added to curated OpenRouter list (<a href="https://github.com/NousResearch/hermes-agent/pull/18071" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18071/hovercard">#18071</a>)</li>
<li><code>tencent/hy3-preview</code> paid route on OpenRouter (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Contentment003111/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Contentment003111">@Contentment003111</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21077/hovercard">#21077</a>)</li>
<li>Arcee Trinity Large Thinking — temperature + compression overrides (<a href="https://github.com/NousResearch/hermes-agent/pull/20473" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20473/hovercard">#20473</a>)</li>
<li>Rename <code>x-ai/grok-4.20-beta</code> to <code>x-ai/grok-4.20</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/19640" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19640/hovercard">#19640</a>)</li>
<li>Demote Vercel AI Gateway to bottom of provider picker (<a href="https://github.com/NousResearch/hermes-agent/pull/18112" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18112/hovercard">#18112</a>)</li>
</ul>
<h4>Provider configuration</h4>
<ul>
<li><strong>OpenRouter — response caching support</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19132" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19132/hovercard">#19132</a>)</li>
<li><strong><code>image_gen.model</code> from config.yaml honored</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373107021" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19376/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19376">#19376</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21273/hovercard">#21273</a>)</li>
<li>Fix: honor runtime default model during delegate provider resolution (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnncenae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnncenae">@johnncenae</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17587" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17587/hovercard">#17587</a>)</li>
<li>Fix: avoid Bedrock credential probe in provider picker (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18998" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18998/hovercard">#18998</a>)</li>
<li>Fix: drop stale env-var override of persisted provider for cron (<a href="https://github.com/NousResearch/hermes-agent/pull/19627" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19627/hovercard">#19627</a>)</li>
<li>Fix: auxiliary curator api_key/base_url into runtime resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/19421" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19421/hovercard">#19421</a>)</li>
</ul>
<h3>Agent Loop &amp; Conversation</h3>
<ul>
<li><strong><code>video_analyze</code> — native video understanding tool</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19301" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19301/hovercard">#19301</a>)</li>
<li><strong>Show context compression count in status bar</strong> (CLI + TUI) (<a href="https://github.com/NousResearch/hermes-agent/pull/21218" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21218/hovercard">#21218</a>)</li>
<li><strong>Isolate <code>get_tool_definitions</code> quiet_mode cache + dedup LCM injection</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348759429" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17335" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/17335/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/17335">#17335</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17889" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17889/hovercard">#17889</a>)</li>
<li>Fix: warning-first tool-call loop guardrails (<a href="https://github.com/NousResearch/hermes-agent/pull/18227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18227/hovercard">#18227</a>)</li>
<li>Fix: break permanent empty-response loop from orphan tool-tail (<a href="https://github.com/NousResearch/hermes-agent/pull/21385" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21385/hovercard">#21385</a>)</li>
<li>Fix: propagate ContextVars to concurrent tool worker threads (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337644300" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16660/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16660">#16660</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18123" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18123/hovercard">#18123</a>)</li>
<li>Fix: surface self-improvement review summaries across CLI, TUI, and gateway (<a href="https://github.com/NousResearch/hermes-agent/pull/18073" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18073/hovercard">#18073</a>)</li>
<li>Fix: serialize concurrent <code>hermes_tools</code> RPC calls from <code>execute_code</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/17894" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17894/hovercard">#17894</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/17902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17902/hovercard">#17902</a>)</li>
<li>Fix: include system prompt + tool schemas in token estimates for compression (<a href="https://github.com/NousResearch/hermes-agent/pull/18265" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18265/hovercard">#18265</a>)</li>
</ul>
<h3>Compression</h3>
<ul>
<li>Fix: skip non-string tool content in dedup pass to prevent AttributeError (<a href="https://github.com/NousResearch/hermes-agent/pull/19398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19398/hovercard">#19398</a>)</li>
<li>Fix: reset <code>_summary_failure_cooldown_until</code> on session reset (<a href="https://github.com/NousResearch/hermes-agent/pull/19622" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19622/hovercard">#19622</a>)</li>
<li>Fix: trigger fallback on timeout errors alongside model-unavailable errors (<a href="https://github.com/NousResearch/hermes-agent/pull/19665" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19665/hovercard">#19665</a>)</li>
<li>Fix: <code>_prune_old_tool_results</code> boundary direction (<a href="https://github.com/NousResearch/hermes-agent/pull/19725" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19725/hovercard">#19725</a>)</li>
<li>Fix: soften summary prompt for content filters (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373574223" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19456" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19456/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19456">#19456</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21302" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21302/hovercard">#21302</a>)</li>
</ul>
<h3>Delegate</h3>
<ul>
<li>Fix: inherit parent fallback_chain in <code>_build_child_agent</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/19601" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19601/hovercard">#19601</a>)</li>
<li>Fix: guard <code>_load_config()</code> against <code>delegation: null</code> in config.yaml (<a href="https://github.com/NousResearch/hermes-agent/pull/19662" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19662/hovercard">#19662</a>)</li>
<li>Fix: inherit parent api_key when <code>delegation.base_url</code> set without <code>delegation.api_key</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/19741" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19741/hovercard">#19741</a>)</li>
<li>Fix: expand composite toolsets before intersection (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373574098" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19455/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19455">#19455</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21300/hovercard">#21300</a>)</li>
<li>Fix: correct ACP docs — Claude Code CLI has no --acp flag (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370677567" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19058" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19058/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19058">#19058</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21201" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21201/hovercard">#21201</a>)</li>
</ul>
<h3>Session &amp; Memory</h3>
<ul>
<li><strong>Hindsight — probe API for <code>update_mode='append'</code> to dedupe across processes</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nicoloboschi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nicoloboschi">@nicoloboschi</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20222" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20222/hovercard">#20222</a>)</li>
</ul>
<h3>Curator</h3>
<ul>
<li><strong><code>hermes curator archive</code> and <code>prune</code> subcommands</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20200" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20200/hovercard">#20200</a>)</li>
<li><strong><code>hermes curator list-archived</code></strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390475968" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20651" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20651/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20651">#20651</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21236/hovercard">#21236</a>)</li>
<li><strong>Synchronous manual <code>hermes curator run</code></strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4388713060" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20555" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/20555/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/20555">#20555</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21216" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21216/hovercard">#21216</a>)</li>
<li>Fix: preserve <code>last_report_path</code> in state (<a href="https://github.com/NousResearch/hermes-agent/pull/18169" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18169/hovercard">#18169</a>)</li>
<li>Fix: rewrite cron job skill refs after consolidation (<a href="https://github.com/NousResearch/hermes-agent/pull/18253" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18253/hovercard">#18253</a>)</li>
<li>Fix: defer first run + <code>--dry-run</code> preview (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364313814" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18373" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/18373/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/18373">#18373</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18389/hovercard">#18389</a>)</li>
<li>Fix: authoritative <code>absorbed_into</code> on delete + restore cron skill links on rollback (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368047363" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18671" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/18671/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/18671">#18671</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18731" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18731/hovercard">#18731</a>)</li>
<li>Fix: prevent false-positive consolidation from substring matching (<a href="https://github.com/NousResearch/hermes-agent/pull/19573" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19573/hovercard">#19573</a>)</li>
<li>Fix: only mark agent-created for background-review sediment (<a href="https://github.com/NousResearch/hermes-agent/pull/19621" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19621/hovercard">#19621</a>)</li>
<li>Fix: protect hub skills by frontmatter name (<a href="https://github.com/NousResearch/hermes-agent/pull/20194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20194/hovercard">#20194</a>)</li>
</ul>
<hr>
<h2>🔧 Tool System</h2>
<h3>File tools</h3>
<ul>
<li><strong>Post-write delta lint on <code>write_file</code> + <code>patch</code></strong> — in-proc linters for Python, JSON, YAML, TOML (<a href="https://github.com/NousResearch/hermes-agent/pull/20191" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20191/hovercard">#20191</a>)</li>
</ul>
<h3>Cron</h3>
<ul>
<li><strong><code>no_agent</code> mode — script-only cron jobs (watchdog pattern)</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19709/hovercard">#19709</a>)</li>
<li><strong><code>context_from</code> chaining docs</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328723694" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15724" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15724/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15724">#15724</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20394" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20394/hovercard">#20394</a>)</li>
<li>Fix: treat non-dict origin as missing instead of crashing tick (<a href="https://github.com/NousResearch/hermes-agent/pull/19283" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19283/hovercard">#19283</a>)</li>
<li>Fix: bump skill usage when cron jobs load skills (<a href="https://github.com/NousResearch/hermes-agent/pull/19433" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19433/hovercard">#19433</a>)</li>
<li>Fix: recover null <code>next_run_at</code> jobs (<a href="https://github.com/NousResearch/hermes-agent/pull/19576" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19576/hovercard">#19576</a>)</li>
<li>Fix: skip AI call when prerun script produces no output (<a href="https://github.com/NousResearch/hermes-agent/pull/19628" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19628/hovercard">#19628</a>)</li>
<li>Fix: expand config.yaml refs during job execution (<a href="https://github.com/NousResearch/hermes-agent/pull/19872" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19872/hovercard">#19872</a>)</li>
<li>Fix: serialize <code>get_due_jobs</code> writes to prevent parallel state corruption (<a href="https://github.com/NousResearch/hermes-agent/pull/19874" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19874/hovercard">#19874</a>)</li>
<li>Fix: initialize MCP servers before constructing the cron AIAgent (<a href="https://github.com/NousResearch/hermes-agent/pull/21354" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21354/hovercard">#21354</a>)</li>
</ul>
<h3>MCP</h3>
<ul>
<li><strong>SSE transport support</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371286197" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19135" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19135/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19135">#19135</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21227/hovercard">#21227</a>)</li>
<li><strong>Forward OAuth auth + bump <code>sse_read_timeout</code> on SSE transport</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21323" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21323/hovercard">#21323</a>)</li>
<li><strong>Retry stale pipe transport failures as session-expired</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21289/hovercard">#21289</a>)</li>
<li><strong>Surface image tool results as MEDIA tags instead of dropping them</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21328" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21328/hovercard">#21328</a>)</li>
<li><strong>Periodic keepalive to <code>_wait_for_lifecycle_event</code></strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343509861" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17016/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17016">#17016</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20209" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20209/hovercard">#20209</a>)</li>
<li>Fix: reconnect on terminated sessions (<a href="https://github.com/NousResearch/hermes-agent/pull/19380" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19380/hovercard">#19380</a>)</li>
<li>Fix: decouple AnyUrl import from mcp dependency (<a href="https://github.com/NousResearch/hermes-agent/pull/19695" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19695/hovercard">#19695</a>)</li>
<li>Fix: <code>mcp add --command</code> gets distinct argparse dest (<a href="https://github.com/NousResearch/hermes-agent/pull/21204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21204/hovercard">#21204</a>)</li>
<li>Fix: clear stale thread interrupt before MCP discovery (<a href="https://github.com/NousResearch/hermes-agent/pull/21276" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21276/hovercard">#21276</a>)</li>
<li>Fix: report configured timeout in MCP call errors (<a href="https://github.com/NousResearch/hermes-agent/pull/21281" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21281/hovercard">#21281</a>)</li>
<li>Fix: include exception type in error messages when str(exc) is empty (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373327584" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19425" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19425/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19425">#19425</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21292/hovercard">#21292</a>)</li>
<li>Fix: re-raise CancelledError explicitly in <code>MCPServerTask.run</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/21318" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21318/hovercard">#21318</a>)</li>
<li>Fix: coerce numeric tool args defensively in <code>mcp_serve</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/21329" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21329/hovercard">#21329</a>)</li>
<li>Fix: gate utility stubs on server-advertised capabilities (<a href="https://github.com/NousResearch/hermes-agent/pull/21347" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21347/hovercard">#21347</a>)</li>
</ul>
<h3>Browser</h3>
<ul>
<li>Fix: allow explicit CDP override without local agent-browser (<a href="https://github.com/NousResearch/hermes-agent/pull/19670" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19670/hovercard">#19670</a>)</li>
<li>Fix: inject <code>--no-sandbox</code> for root + AppArmor userns restrictions (<a href="https://github.com/NousResearch/hermes-agent/pull/19747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19747/hovercard">#19747</a>)</li>
<li>Fix: tighten Lightpanda fallback edge cases (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20672" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20672/hovercard">#20672</a>)</li>
</ul>
<h3>Web tools</h3>
<ul>
<li><strong>Per-capability backend selection — search/extract split</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20061" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20061/hovercard">#20061</a>)</li>
<li><strong>SearXNG native search-only backend</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20823" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20823/hovercard">#20823</a>)</li>
</ul>
<h3>Approval / Tool gating</h3>
<ul>
<li>Fix: wake blocked gateway approvals on session cleanup (<a href="https://github.com/NousResearch/hermes-agent/pull/18171" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18171/hovercard">#18171</a>)</li>
<li>Fix: harden YOLO mode env parsing against quoted-bool strings (<a href="https://github.com/NousResearch/hermes-agent/pull/18214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18214/hovercard">#18214</a>)</li>
<li>Fix: extend sensitive write target to cover shell RC and credential files (<a href="https://github.com/NousResearch/hermes-agent/pull/19282" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19282/hovercard">#19282</a>)</li>
</ul>
<hr>
<h2>🔌 Plugin System</h2>
<ul>
<li><strong><code>transform_llm_output</code> plugin hook</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392802005" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20813" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20813/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20813">#20813</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21235" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21235/hovercard">#21235</a>)</li>
<li><strong>Document <code>env_enablement_fn</code> + <code>cron_deliver_env_var</code> platform-plugin hooks</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21331" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21331/hovercard">#21331</a>)</li>
<li><strong>Pluggable surfaces coverage — model-provider guide, full plugin map, opt-in fix</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20749" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20749/hovercard">#20749</a>)</li>
<li><strong>Plugin-authoring gaps — image-gen provider guide + publishing a skill tap</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20800" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20800/hovercard">#20800</a>)</li>
</ul>
<hr>
<h2>🧩 Skills Ecosystem</h2>
<h3>New optional skills</h3>
<ul>
<li><strong>Shopify</strong> — Admin + Storefront GraphQL optional skill (<a href="https://github.com/NousResearch/hermes-agent/pull/18116" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18116/hovercard">#18116</a>)</li>
<li><strong>here.now</strong> — optional skill (<a href="https://github.com/NousResearch/hermes-agent/pull/18170" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18170/hovercard">#18170</a>)</li>
<li><strong>shop-app</strong> — personal shopping assistant (optional) (<a href="https://github.com/NousResearch/hermes-agent/pull/20702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20702/hovercard">#20702</a>)</li>
<li><strong>Anthropic financial-services bundle</strong> — ported as optional finance skills (<a href="https://github.com/NousResearch/hermes-agent/pull/21180" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21180/hovercard">#21180</a>)</li>
<li><strong>kanban-video-orchestrator</strong> — creative optional skill (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19281" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19281/hovercard">#19281</a>)</li>
<li><strong>searxng-search</strong> — optional skill + Web Search + Extract docs page (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20841" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20841/hovercard">#20841</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20844" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20844/hovercard">#20844</a>)</li>
</ul>
<h3>Skill UX</h3>
<ul>
<li><strong>Linear skill — add Documents support + Python helper script</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20752/hovercard">#20752</a>)</li>
<li><strong>Modernize Obsidian skill to use file tools</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372733568" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19332/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19332">#19332</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20413" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20413/hovercard">#20413</a>)</li>
<li><strong>Default custom tool creation to plugins</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19755" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19755/hovercard">#19755</a>)</li>
<li><strong>skill_commands cache — rescan on platform scope changes</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316492029" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/14570" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14570/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/14570">#14570</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18739" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18739/hovercard">#18739</a>)</li>
<li><strong>Skills — additional rescan paths in skill_commands cache</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370552799" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19042/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19042">#19042</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21181/hovercard">#21181</a>)</li>
<li>Fix: regression tests for non-dict metadata in <code>extract_skill_conditions</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/18213" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18213/hovercard">#18213</a>)</li>
<li>Docs: explain restoring bundled skills (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372058323" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19254" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19254/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19254">#19254</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20404" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20404/hovercard">#20404</a>)</li>
<li>Docs: document <code>hermes skills reset</code> subcommand (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4281827404" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/11544" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/11544/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/11544">#11544</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20395/hovercard">#20395</a>)</li>
<li>Docs: himalaya v1.2.0 <code>folder.aliases</code> syntax (<a href="https://github.com/NousResearch/hermes-agent/pull/19882" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19882/hovercard">#19882</a>)</li>
<li>Point agent at <code>hermes-agent</code> skill + docs site sync (<a href="https://github.com/NousResearch/hermes-agent/pull/20390" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20390/hovercard">#20390</a>)</li>
</ul>
<hr>
<h2>🖥️ CLI &amp; User Experience</h2>
<h3>CLI</h3>
<ul>
<li><strong><code>/new</code> accepts optional session name argument</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374529783" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19555" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19555/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19555">#19555</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19637" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19637/hovercard">#19637</a>)</li>
<li><strong>100 new CLI startup tips</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20168" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20168/hovercard">#20168</a>)</li>
<li><strong><code>display.language</code> — static message translation</strong> (zh/ja/de/es) (<a href="https://github.com/NousResearch/hermes-agent/pull/20231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20231/hovercard">#20231</a>)</li>
<li><strong>French (fr) locale</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Foolafroos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Foolafroos">@Foolafroos</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20329" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20329/hovercard">#20329</a>)</li>
<li><strong>Ukrainian (uk) locale</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20467" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20467/hovercard">#20467</a>)</li>
<li><strong>Turkish (tr) locale</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20474" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20474/hovercard">#20474</a>)</li>
<li>Fix: recover classic CLI output after resize (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20444" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20444/hovercard">#20444</a>)</li>
<li>Fix: complete absolute paths as paths (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19930" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19930/hovercard">#19930</a>)</li>
<li>Fix: resolve lazy session creation regressions (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364300402" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18370" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18370/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/18370">#18370</a> fallout) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20363" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20363/hovercard">#20363</a>)</li>
<li>Fix: local backend CLI always uses launch directory (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19334" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19334/hovercard">#19334</a>)</li>
<li>Refactor: drop dead c-S-c key binding (follow-up to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379333464" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19895" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19895/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19895">#19895</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19919" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19919/hovercard">#19919</a>)</li>
</ul>
<h3>TUI (Ink)</h3>
<ul>
<li><strong><code>/model</code> picker overhaul to match <code>hermes model</code> with inline auth</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18117" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18117/hovercard">#18117</a>)</li>
<li><strong>Collapsible sections in startup banner</strong> — skills, system prompt, MCP (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20625/hovercard">#20625</a>)</li>
<li><strong>Show context compression count in status bar</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21218" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21218/hovercard">#21218</a>)</li>
<li>Perf: reduce overlay render churn with focused selectors (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20393" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20393/hovercard">#20393</a>)</li>
<li>Fix: restore voice push-to-talk parity (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331727821" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16189" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16189/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16189">#16189</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Montbra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Montbra">@Montbra</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20897" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20897/hovercard">#20897</a>)</li>
<li>Fix: kanban button (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18358" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18358/hovercard">#18358</a>)</li>
</ul>
<h3>Dashboard</h3>
<ul>
<li><strong>Plugins page — manage, enable/disable, auth status</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18095" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18095/hovercard">#18095</a>)</li>
<li><strong>Profiles management page</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincez-hms-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincez-hms-coder">@vincez-hms-coder</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16419/hovercard">#16419</a>)</li>
<li><strong>Interactive column sorting in analytics tables</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18192" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18192/hovercard">#18192</a>)</li>
<li><strong><code>default-large</code> built-in theme with 18px base size</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20820" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20820/hovercard">#20820</a>)</li>
<li><strong>Support serving under URL prefix via <code>X-Forwarded-Prefix</code></strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4373518624" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19450" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19450/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19450">#19450</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21296" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21296/hovercard">#21296</a>)</li>
<li><strong>Launch dashboard as side-process via <code>HERMES_DASHBOARD=1</code> in Docker</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19540" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19540/hovercard">#19540</a>)</li>
<li>Fix: dashboard theme layout shift (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AllardQuek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AllardQuek">@AllardQuek</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/17232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17232/hovercard">#17232</a>)</li>
<li>Fix: gateway model picker current context (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20513" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20513/hovercard">#20513</a>)</li>
</ul>
<h3>Update + setup</h3>
<ul>
<li><strong><code>hermes update --yes/-y</code> to skip interactive prompts</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18261" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18261/hovercard">#18261</a>)</li>
<li><strong>Restart manual profile gateways after update</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18178" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18178/hovercard">#18178</a>)</li>
</ul>
<h3>Profiles</h3>
<ul>
<li><strong><code>--no-skills</code> flag for empty profile creation</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20986" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20986/hovercard">#20986</a>)</li>
</ul>
<hr>
<h2>🎵 Voice, Image &amp; Media</h2>
<ul>
<li><strong>xAI Custom Voices — voice cloning</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18776" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18776/hovercard">#18776</a>)</li>
<li><strong>Achievements — share card render on unlocked badges</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19657" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19657/hovercard">#19657</a>)</li>
<li><strong>Refresh systemd unit on gateway boot (not just start/restart)</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19684" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19684/hovercard">#19684</a>)</li>
</ul>
<hr>
<h2>🔗 API Server &amp; Remote Access</h2>
<ul>
<li><strong><code>X-Hermes-Session-Key</code> header for long-term memory scoping</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4381554504" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20060" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/20060/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/20060">#20060</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20199" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20199/hovercard">#20199</a>)</li>
</ul>
<hr>
<h2>🧰 ACP Adapter (VS Code / Zed / JetBrains)</h2>
<ul>
<li><strong><code>/steer</code> and <code>/queue</code> slash commands</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenkDz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenkDz">@HenkDz</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18114/hovercard">#18114</a>)</li>
<li>Fix: translate Windows cwd for WSL sessions (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361970936" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18128" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18128/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/18128">#18128</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18233" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18233/hovercard">#18233</a>)</li>
<li>Fix: run <code>/steer</code> as a regular prompt on idle sessions (<a href="https://github.com/NousResearch/hermes-agent/pull/18258" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18258/hovercard">#18258</a>)</li>
<li>Fix: route Zed thoughts to reasoning + polish tool/context rendering (<a href="https://github.com/NousResearch/hermes-agent/pull/19139" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19139/hovercard">#19139</a>)</li>
<li>Fix: atomic session persistence via <code>replace_messages</code> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305124131" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/13675" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/13675/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/13675">#13675</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20279" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20279/hovercard">#20279</a>)</li>
<li>Fix: preserve assistant reasoning metadata in session persistence (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303479156" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/13575" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/13575/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/13575">#13575</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20296" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20296/hovercard">#20296</a>)</li>
<li>Docs: update VS Code setup for ACP Client extension (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290480564" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/12495" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/12495/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/12495">#12495</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20433" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20433/hovercard">#20433</a>)</li>
</ul>
<hr>
<h2>🐳 Docker</h2>
<ul>
<li><strong>Launch dashboard as side-process via <code>HERMES_DASHBOARD=1</code></strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19540" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19540/hovercard">#19540</a>)</li>
<li><strong>Refuse root gateway runs in official image</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371860334" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19215/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19215">#19215</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21250" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21250/hovercard">#21250</a>)</li>
<li><strong>Chown runtime <code>node_modules</code> trees to hermes user</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372410199" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19303/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19303">#19303</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21267" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21267/hovercard">#21267</a>)</li>
<li>Fix: exclude compose/profile runtime state from build context (<a href="https://github.com/NousResearch/hermes-agent/pull/19626" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19626/hovercard">#19626</a>)</li>
<li>CI: don't cancel overlapping builds, guard <code>:latest</code> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20890" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20890/hovercard">#20890</a>)</li>
<li>Test: align Dockerfile contract tests with simplified TUI flow (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370390692" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19024" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19024/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19024">#19024</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21174" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21174/hovercard">#21174</a>)</li>
<li>Docs: connect to local inference servers (vLLM, Ollama) (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289636344" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/12335" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/12335/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/12335">#12335</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20407" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20407/hovercard">#20407</a>)</li>
<li>Docs: document <code>API_SERVER_*</code> env vars (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284879663" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/11758" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/11758/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/11758">#11758</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20409" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20409/hovercard">#20409</a>)</li>
<li>Docs: clarify Docker terminal backend is a single persistent container (<a href="https://github.com/NousResearch/hermes-agent/pull/20003" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20003/hovercard">#20003</a>)</li>
</ul>
<hr>
<h2>🐛 Notable Bug Fixes</h2>
<h3>Agent</h3>
<ul>
<li>Fix: recover lazy session creation regressions (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364300402" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18370" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18370/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/18370">#18370</a> fallout) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20363" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20363/hovercard">#20363</a>)</li>
<li>Fix: propagate ContextVars to concurrent tool worker threads (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337644300" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16660/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16660">#16660</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18123" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18123/hovercard">#18123</a>)</li>
<li>Fix: warning-first tool-call loop guardrails (<a href="https://github.com/NousResearch/hermes-agent/pull/18227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18227/hovercard">#18227</a>)</li>
<li>Fix: surface self-improvement review summaries across CLI, TUI, and gateway (<a href="https://github.com/NousResearch/hermes-agent/pull/18073" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18073/hovercard">#18073</a>)</li>
</ul>
<h3>Gateway streaming</h3>
<ul>
<li>Fix: harden StreamingConfig bool and numeric coercion (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simbam99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simbam99">@simbam99</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/16463" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16463/hovercard">#16463</a>)</li>
</ul>
<h3>Model</h3>
<ul>
<li>Fix: avoid Bedrock credential probe in provider picker (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18998" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18998/hovercard">#18998</a>)</li>
</ul>
<h3>Doctor</h3>
<ul>
<li>Fix: check global agent-browser when local install not found (<a href="https://github.com/NousResearch/hermes-agent/pull/19671" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19671/hovercard">#19671</a>)</li>
<li>Test: kimi-coding-cn provider validation regression (<a href="https://github.com/NousResearch/hermes-agent/pull/19734" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19734/hovercard">#19734</a>)</li>
</ul>
<h3>Update</h3>
<ul>
<li>Fix: patch <code>isatty</code> on real streams to fix xdist-flaky <code>--yes</code> tests (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370398281" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19026" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19026/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19026">#19026</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21175" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21175/hovercard">#21175</a>)</li>
<li>Fix: teach restart-mocks about the post-update survivor sweep (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370415717" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19031" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19031/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19031">#19031</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21177" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21177/hovercard">#21177</a>)</li>
</ul>
<h3>Auth</h3>
<ul>
<li>Fix: acp preserve assistant reasoning metadata (<a href="https://github.com/NousResearch/hermes-agent/pull/20296" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20296/hovercard">#20296</a>)</li>
</ul>
<h3>Redact</h3>
<ul>
<li>Fix: add <code>code_file</code> param to skip false-positive ENV/JSON patterns (<a href="https://github.com/NousResearch/hermes-agent/pull/19715" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19715/hovercard">#19715</a>)</li>
</ul>
<h3>Email</h3>
<ul>
<li>Fix: quoted-relative file-drop paths + Date header on tool email path (<a href="https://github.com/NousResearch/hermes-agent/pull/19646" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19646/hovercard">#19646</a>)</li>
</ul>
<hr>
<h2>🧪 Testing</h2>
<ul>
<li><strong>ACP — accept prompt persistence kwargs in MCP E2E mocks</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18047" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18047/hovercard">#18047</a>)</li>
<li><strong>Toolsets — include kanban in expected post-<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355990038" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17805" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17805/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17805">#17805</a> toolset assertions</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/18122" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18122/hovercard">#18122</a>)</li>
<li><strong>Agent — cover max-iterations summary message sanitization</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19580" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19580/hovercard">#19580</a>)</li>
<li><strong>run_agent — <code>-inf</code> and <code>nan</code> regression coverage for <code>_coerce_number</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/19703" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19703/hovercard">#19703</a>)</li>
</ul>
<hr>
<h2>📚 Documentation</h2>
<h3>Major docs additions</h3>
<ul>
<li><strong><code>llms.txt</code> + <code>llms-full.txt</code> — agent-friendly ingestion</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18276" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18276/hovercard">#18276</a>)</li>
<li><strong>User Stories and Use Cases collage page</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18282" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18282/hovercard">#18282</a>)</li>
<li><strong>Persistent Goals (/goal) feature page</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/18275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18275/hovercard">#18275</a>)</li>
<li><strong>Windows (WSL2) guide expansion</strong> — filesystem, networking, services, pitfalls (<a href="https://github.com/NousResearch/hermes-agent/pull/20748" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20748/hovercard">#20748</a>)</li>
<li><strong>Chinese (zh-CN) README translation</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4302595874" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/13508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/13508/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/13508">#13508</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20431" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20431/hovercard">#20431</a>)</li>
<li><strong>zh-Hans Docusaurus locale</strong> + Tool Gateway / image-gen / WSL quickstart translations (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284494431" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/11728" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/11728/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/11728">#11728</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20430" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20430/hovercard">#20430</a>)</li>
<li><strong>Tool Gateway docs restructure</strong> — lead with what it does, config moved to bottom (<a href="https://github.com/NousResearch/hermes-agent/pull/20827" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20827/hovercard">#20827</a>)</li>
<li><strong>Quickstart — Onchain AI Garage Hermes tutorials playlist</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20192" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20192/hovercard">#20192</a>)</li>
<li><strong>Open WebUI bootstrap script</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261204766" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/9566" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/9566/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/9566">#9566</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20427" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20427/hovercard">#20427</a>)</li>
<li><strong>Local Ollama setup guide</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217966585" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/5842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5842/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/5842">#5842</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20426" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20426/hovercard">#20426</a>)</li>
<li><strong>Google Gemini guide</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350755840" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17450" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17450/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17450">#17450</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20401" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20401/hovercard">#20401</a>)</li>
<li><strong>Custom model aliases for /model command</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20475" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20475/hovercard">#20475</a>)</li>
<li><strong>Together/Groq/Perplexity cookbook via <code>custom_providers</code></strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323904444" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/15214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15214/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/15214">#15214</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20400" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20400/hovercard">#20400</a>)</li>
<li><strong>Doubao speech integration examples</strong> (TTS + STT) (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360780705" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18065" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18065/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/18065">#18065</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20418" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20418/hovercard">#20418</a>)</li>
<li><strong>WSL-to-Windows Chrome MCP bridge</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247603669" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/8313" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8313/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/8313">#8313</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20428" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20428/hovercard">#20428</a>)</li>
<li><strong>Hermes skills docs sync</strong> — slash commands + durable-systems section (<a href="https://github.com/NousResearch/hermes-agent/pull/20390" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20390/hovercard">#20390</a>)</li>
<li><strong>AGENTS.md — curator/cron/delegation/toolsets + fix plugin tree</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20226/hovercard">#20226</a>)</li>
<li><strong>Bedrock quickstart entry + fallback comment + deployment link</strong> (salvage #11093) (<a href="https://github.com/NousResearch/hermes-agent/pull/20397">#20397</a>)</li>
</ul>
<h3>Docs polish</h3>
<ul>
<li>Collapse exploding skills tree to a single Skills node (<a href="https://github.com/NousResearch/hermes-agent/pull/18259">#18259</a>)</li>
<li>Clarify <code>session_search</code> auxiliary model docs (<a href="https://github.com/NousResearch/hermes-agent/pull/19593">#19593</a>)</li>
<li>Open WebUI Quick Setup gap fill (<a href="https://github.com/NousResearch/hermes-agent/pull/19654">#19654</a>)</li>
<li>Default custom tool creation to plugins (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/19755" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19755/hovercard">#19755</a>)</li>
<li>Clarify Telegram group chat troubleshooting (salvage #18672) (<a href="https://github.com/NousResearch/hermes-agent/pull/20416">#20416</a>)</li>
<li>Codex OAuth auth prerequisite clarification (salvage #18688) (<a href="https://github.com/NousResearch/hermes-agent/pull/20417">#20417</a>)</li>
<li>Discord Server Members Intent + SSRC-mapping drift + /voice join slash Choice (salvage #11350) (<a href="https://github.com/NousResearch/hermes-agent/pull/20411">#20411</a>)</li>
<li>Document <code>ctx.dispatch_tool()</code> (salvage #10955) (<a href="https://github.com/NousResearch/hermes-agent/pull/20391">#20391</a>)</li>
<li>Document <code>hermes webhook subscribe --deliver-only</code> (salvage #12612) (<a href="https://github.com/NousResearch/hermes-agent/pull/20392">#20392</a>)</li>
<li>Document <code>hermes import</code> reference (salvage #14711) (<a href="https://github.com/NousResearch/hermes-agent/pull/20396">#20396</a>)</li>
<li>Document per-provider TTS <code>max_text_length</code> caps (salvage #13825) (<a href="https://github.com/NousResearch/hermes-agent/pull/20389">#20389</a>)</li>
<li>Clarify supported prompt customization surfaces (salvage #19987) (<a href="https://github.com/NousResearch/hermes-agent/pull/20383">#20383</a>)</li>
<li>Correct <code>web_extract</code> summarizer timeout comment (salvage #20051) (<a href="https://github.com/NousResearch/hermes-agent/pull/20381">#20381</a>)</li>
<li>Fix fallback provider config paths (salvage #20033) (<a href="https://github.com/NousResearch/hermes-agent/pull/20382">#20382</a>)</li>
<li>Fix misleading RL install-extras claim (salvage #19080) (<a href="https://github.com/NousResearch/hermes-agent/pull/21213">#21213</a>)</li>
<li>Clarify API server tool execution locality (salvage #19117) (<a href="https://github.com/NousResearch/hermes-agent/pull/21223">#21223</a>)</li>
<li>Prefer <code>.venv</code> to match AGENTS.md and scripts/run_tests.sh (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21334">#21334</a>)</li>
<li>Align tool discovery + test runner with AGENTS.md (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20791">#20791</a>)</li>
<li>Align terminal-backend count and naming across docs and code (salvage #19044) (<a href="https://github.com/NousResearch/hermes-agent/pull/20402">#20402</a>)</li>
<li>Refresh stale platform counts (salvage #19053) (<a href="https://github.com/NousResearch/hermes-agent/pull/20403">#20403</a>)</li>
</ul>
<hr>
<h2>👥 Contributors</h2>
<h3>Core</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a></strong> — salvage, triage, review, feature work, and release management</li>
</ul>
<h3>Top Community Contributors</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a></strong> (21 PRs) — SearXNG native search backend, per-capability backend selection, collapsible TUI startup banner, Slack ephemeral ack + format fixes, Lightpanda fallback hardening, searxng-search optional skill + Web Search + Extract docs, default custom tool creation to plugins, kanban failure-column fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a></strong> (13 PRs) — video_analyze tool, xAI Custom Voices (voice cloning), local-backend CLI launch-directory fix, lazy-session creation regression recovery, systemd unit refresh on gateway boot</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a></strong> (9 PRs) — TUI perf — overlay render churn reduction, voice push-to-talk parity restoration (salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Montbra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Montbra">@Montbra</a>)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a></strong> (6 PRs) — Classic CLI output recovery after resize, absolute-path TUI completion, gateway model picker current-context fix, Bedrock credential probe avoidance, kanban docs fixes</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a></strong> (3 PRs) — Docker CI — don't cancel overlapping builds, :latest guard</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a></strong> (3 PRs) — Docker — launch dashboard as side-process via HERMES_DASHBOARD=1</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a></strong> (3 PRs) — Dashboard Plugins page, TUI /model picker overhaul with inline auth, kanban button fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a></strong> (2 PRs) — Contributor (2 PRs)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asheriif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asheriif">@asheriif</a></strong> (2 PRs) — Contributor (2 PRs)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a></strong> (2 PRs) — Contributing docs — .venv preference and test runner alignment with AGENTS.md</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a></strong> (1 PR) — ACP — MCP E2E mock kwargs</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincez-hms-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincez-hms-coder">@vincez-hms-coder</a></strong> (1 PR) — Dashboard — Profiles management page</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cdanis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cdanis">@cdanis</a></strong> (1 PR) — Contributor</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a></strong> (1 PR) — Toolsets test — kanban assertions post-<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355990038" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17805" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17805/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17805">#17805</a></li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heyitsaamir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heyitsaamir">@heyitsaamir</a></strong> (1 PR) — Contributor</li>
</ul>
<h3>All Contributors</h3>
<p>Thanks to everyone who contributed to v0.13.0 — commits, co-authored work, and salvaged PRs. 295 contributors in one week.</p>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0oAstro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0oAstro">@0oAstro</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xDevNinja/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xDevNinja">@0xDevNinja</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xharryriddle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xharryriddle">@0xharryriddle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xKingBack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xKingBack">@0xKingBack</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xsir0000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xsir0000">@0xsir0000</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xyg3n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xyg3n">@0xyg3n</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0z1-ghb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0z1-ghb">@0z1-ghb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinav11082001-stack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinav11082001-stack">@abhinav11082001-stack</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acc001k/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acc001k">@acc001k</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acesjohnny/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acesjohnny">@acesjohnny</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adamludwin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adamludwin">@adamludwin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adybag14-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adybag14-cyber">@adybag14-cyber</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agentlinker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agentlinker">@agentlinker</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agilejava/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agilejava">@agilejava</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-ag2026/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-ag2026">@ai-ag2026</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AJV20/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AJV20">@AJV20</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alanxchen85/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alanxchen85">@alanxchen85</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/albert748/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/albert748">@albert748</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AllardQuek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AllardQuek">@AllardQuek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/altmazza0-star/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/altmazza0-star">@altmazza0-star</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ambition0802/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ambition0802">@ambition0802</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amitgaur/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amitgaur">@amitgaur</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amroessam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amroessam">@amroessam</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrewhosf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrewhosf">@andrewhosf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Asce66/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Asce66">@Asce66</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asheriif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asheriif">@asheriif</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ashermorse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ashermorse">@ashermorse</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asimons81/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asimons81">@asimons81</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aslaaen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aslaaen">@Aslaaen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Asunfly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Asunfly">@Asunfly</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/atongrun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/atongrun">@atongrun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/banditburai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/banditburai">@banditburai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barteqpl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barteqpl">@barteqpl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beardthelion/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beardthelion">@beardthelion</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beibi9966/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beibi9966">@beibi9966</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bjianhang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bjianhang">@bjianhang</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackJulySnow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackJulySnow">@BlackJulySnow</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobashopcashier/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobashopcashier">@bobashopcashier</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bogerman1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bogerman1">@bogerman1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bongulielmi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bongulielmi">@Bongulielmi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Brecht-H/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Brecht-H">@Brecht-H</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, @brooklynnicholson,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/c3115644151/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/c3115644151">@c3115644151</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/camaragon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/camaragon">@camaragon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CashWilliams/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CashWilliams">@CashWilliams</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CCClelo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CCClelo">@CCClelo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cdanis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cdanis">@cdanis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CES4751/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CES4751">@CES4751</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cg2aigc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cg2aigc">@cg2aigc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/changchun989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/changchun989">@changchun989</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChanlerDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChanlerDev">@ChanlerDev</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharlieKerfoot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharlieKerfoot">@CharlieKerfoot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chengoak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chengoak">@chengoak</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chenyunbo411/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chenyunbo411">@chenyunbo411</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinadbo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinadbo">@chinadbo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cirwel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cirwel">@cirwel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cixuuz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cixuuz">@cixuuz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cmcgrabby-hue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cmcgrabby-hue">@cmcgrabby-hue</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colorcross/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colorcross">@colorcross</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Contentment003111/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Contentment003111">@Contentment003111</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CoreyNoDream/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CoreyNoDream">@CoreyNoDream</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/counterposition/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/counterposition">@counterposition</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/curiouscleo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/curiouscleo">@curiouscleo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DaniuXie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DaniuXie">@DaniuXie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deep-name/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deep-name">@deep-name</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dengtaoyuan450-a11y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dengtaoyuan450-a11y">@dengtaoyuan450-a11y</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/discodirector/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/discodirector">@discodirector</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donramon77/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donramon77">@donramon77</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dpaluy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dpaluy">@dpaluy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ee-blog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ee-blog">@ee-blog</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ehz0ah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ehz0ah">@ehz0ah</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/el-analista/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/el-analista">@el-analista</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/elmatadorgh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/elmatadorgh">@elmatadorgh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EmelyanenkoK/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EmelyanenkoK">@EmelyanenkoK</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Emidomenge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Emidomenge">@Emidomenge</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Es1la/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Es1la">@Es1la</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EthanGuo-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EthanGuo-coder">@EthanGuo-coder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etherman-os/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etherman-os">@etherman-os</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EvilDrag0n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EvilDrag0n">@EvilDrag0n</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/exxmen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/exxmen">@exxmen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fearvox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fearvox">@Fearvox</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Feranmi10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Feranmi10">@Feranmi10</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/firefly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firefly">@firefly</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flobo3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flobo3">@flobo3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fmercurio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fmercurio">@fmercurio</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Foolafroos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Foolafroos">@Foolafroos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/formulahendry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/formulahendry">@formulahendry</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/franksong2702/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/franksong2702">@franksong2702</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ggnnggez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ggnnggez">@ggnnggez</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GinWU05/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GinWU05">@GinWU05</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giwaov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giwaov">@giwaov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glesperance/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glesperance">@glesperance</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gnanirahulnutakki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gnanirahulnutakki">@gnanirahulnutakki</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gosuj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gosuj">@Gosuj</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Grey0202/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Grey0202">@Grey0202</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guillaumemeyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guillaumemeyer">@guillaumemeyer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/h0tp-ftw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/h0tp-ftw">@h0tp-ftw</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haidao1919/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haidao1919">@haidao1919</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/halmisen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/halmisen">@halmisen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/happy5318/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/happy5318">@happy5318</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hedirman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hedirman">@hedirman</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hendrixfreire/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hendrixfreire">@hendrixfreire</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenkDz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenkDz">@HenkDz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hex-clawd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hex-clawd">@hex-clawd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heyitsaamir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heyitsaamir">@heyitsaamir</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hharry11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hharry11">@hharry11</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hinotoi-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hinotoi-agent">@Hinotoi-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/holynn-q/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/holynn-q">@holynn-q</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hrkzogw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hrkzogw">@hrkzogw</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hypn0sis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hypn0sis">@Hypn0sis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hypnus-Yuan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hypnus-Yuan">@Hypnus-Yuan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ideathinklab01-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ideathinklab01-source">@ideathinklab01-source</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IMHaoyan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IMHaoyan">@IMHaoyan</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Interstellar-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Interstellar-code">@Interstellar-code</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ishardo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ishardo">@ishardo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jacdevos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jacdevos">@jacdevos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackey8616/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackey8616">@jackey8616</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JanCong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JanCong">@JanCong</a>, @jasonoutland, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jatingodnani/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jatingodnani">@jatingodnani</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JayGwod/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JayGwod">@JayGwod</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jethac/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jethac">@jethac</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JezzaHehn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JezzaHehn">@JezzaHehn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JiaDe-Wu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JiaDe-Wu">@JiaDe-Wu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jjjojoj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jjjojoj">@jjjojoj</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkausel-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkausel-ai">@jkausel-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/John-tip/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/John-tip">@John-tip</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnncenae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnncenae">@johnncenae</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jrusso1020/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jrusso1020">@jrusso1020</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jslizar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jslizar">@jslizar</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JTroyerOvermatch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JTroyerOvermatch">@JTroyerOvermatch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/julysir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/julysir">@julysir</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Junass1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Junass1">@Junass1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JustinUssuri/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JustinUssuri">@JustinUssuri</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keepcalmqqf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keepcalmqqf">@keepcalmqqf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kiala9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kiala9">@kiala9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kowenhaoai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kowenhaoai">@kowenhaoai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Krionex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Krionex">@Krionex</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kyan12/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kyan12">@kyan12</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leavrcn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leavrcn">@leavrcn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leon7609/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leon7609">@leon7609</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leprincep35700/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leprincep35700">@leprincep35700</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lhysdl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lhysdl">@lhysdl</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/likejudy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/likejudy">@likejudy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lisanhu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lisanhu">@lisanhu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liu-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liu-collab">@liu-collab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuguangyong93/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuguangyong93">@liuguangyong93</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucianoSP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucianoSP">@LucianoSP</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyuctl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyuctl">@luoyuctl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/M3RCUR2Y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/M3RCUR2Y">@M3RCUR2Y</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maciekczech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maciekczech">@maciekczech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MaHaoHao-ch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MaHaoHao-ch">@MaHaoHao-ch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/malaiwah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/malaiwah">@malaiwah</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/manateelazycat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/manateelazycat">@manateelazycat</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/masonjames/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/masonjames">@masonjames</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/megastary/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/megastary">@megastary</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/memosr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/memosr">@memosr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MichaelWDanko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MichaelWDanko">@MichaelWDanko</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mikeyobrien/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mikeyobrien">@mikeyobrien</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/millerc79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/millerc79">@millerc79</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mind-Dragon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mind-Dragon">@Mind-Dragon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mioimotoai-lgtm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mioimotoai-lgtm">@mioimotoai-lgtm</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/misery-hl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/misery-hl">@misery-hl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/molvikar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/molvikar">@molvikar</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/momowind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/momowind">@momowind</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Montbra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Montbra">@Montbra</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MottledShadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MottledShadow">@MottledShadow</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrbob-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrbob-git">@mrbob-git</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrcharlesiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrcharlesiv">@mrcharlesiv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrcoferland/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrcoferland">@mrcoferland</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ms-alan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ms-alan">@ms-alan</a>, @mwnickerson,<br>
@nazirulhafiy, @nftpoetrist, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nicoloboschi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nicoloboschi">@nicoloboschi</a>, @nightq, @nikolay-bratanov, @NikolayGusev-astra, @nocturnum91,<br>
@noOne-list, @nouseman666, @novax635, @npmisantosh, @nudiltoys-cmyk, @olisikh, @oluwadareab12, @Oxidane-bot,<br>
@pama0227, @pander, @pasevin, @paul-tian, @pdonizete, @perlowja, @pingchesu, @PratikRai0101, @priveperfumes,<br>
@probepark, @QifengKuang, @quocanh261997, @qWaitCrypto, @qxxaa, @r266-tech, @rames-jusso, @revaraver,<br>
@Ricardo-M-L, @rob-maron, @Roy-oss1, @rxdxxxx, @SandroHub013, @Sanjays2402, @Sertug17, @shashwatgokhe,<br>
@shellybotmoyer, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, @SimbaKingjoe, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simbam99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simbam99">@simbam99</a>, @simplenamebox-ops, @socrates1024, @sonic-netizen,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a>, @steezkelly, @stephen0110, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>, @stevenchanin, @stevenchouai, @stormhierta,<br>
@subtract0, @suncokret12, @swithek, @taeng0204, @TakeshiSawaguchi, @tangyuanjc, @TheEpTic, @thelumiereguy,<br>
@Tkander1715, @tmdgusya, @Tranquil-Flow, @TruaShamu, @UgwujaGeorge, @valda, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincez-hms-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincez-hms-coder">@vincez-hms-coder</a>, @VinVC,<br>
@vominh1919, @wabrent, @WadydX, @wanazhar, @WanderWang, @warabe1122, @web-dev0521, @WideLee, @willy-scr,<br>
@wmagev, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WuTianyi123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WuTianyi123">@WuTianyi123</a>, @wxst, @wysie, @Wysie, @xsfX20, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>, @xyiy001, @YanzhongSu, @ygd58, @Yoimex,<br>
@yuehei, @Yukipukii1, @yuqianma, @YX234, @zeejaytan, @zhanggttry, @zhao0112, @zng8418, @zons-zhaozhy, @Zyproth</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.4.30...v2026.5.7">v2026.4.30...v2026.5.7</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.8.0 (v2026.4.8)]]></title>
<description><![CDATA[Hermes Agent v0.8.0 (v2026.4.8)
Release Date: April 8, 2026

The intelligence release — background task auto-notifications, free MiMo v2 Pro on Nous Portal, live model switching across all platforms, self-optimized GPT/Codex guidance, native Google AI Studio, smart inactivity timeouts, approval b...]]></description>
<link>https://tsecurity.de/de/3488033/downloads/hermes-agent-v080-v202648/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488033/downloads/hermes-agent-v080-v202648/</guid>
<pubDate>Tue, 05 May 2026 03:01:34 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.8.0 (v2026.4.8)</h1>
<p><strong>Release Date:</strong> April 8, 2026</p>
<blockquote>
<p>The intelligence release — background task auto-notifications, free MiMo v2 Pro on Nous Portal, live model switching across all platforms, self-optimized GPT/Codex guidance, native Google AI Studio, smart inactivity timeouts, approval buttons, MCP OAuth 2.1, and 209 merged PRs with 82 resolved issues.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Background Process Auto-Notifications (<code>notify_on_complete</code>)</strong> — Background tasks can now automatically notify the agent when they finish. Start a long-running process (AI model training, test suites, deployments, builds) and the agent gets notified on completion — no polling needed. The agent can keep working on other things and pick up results when they land. (<a href="https://github.com/NousResearch/hermes-agent/pull/5779" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5779/hovercard">#5779</a>)</p>
</li>
<li>
<p><strong>Free Xiaomi MiMo v2 Pro on Nous Portal</strong> — Nous Portal now supports the free-tier Xiaomi MiMo v2 Pro model for auxiliary tasks (compression, vision, summarization), with free-tier model gating and pricing display in model selection. (<a href="https://github.com/NousResearch/hermes-agent/pull/6018" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6018/hovercard">#6018</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5880" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5880/hovercard">#5880</a>)</p>
</li>
<li>
<p><strong>Live Model Switching (<code>/model</code> Command)</strong> — Switch models and providers mid-session from CLI, Telegram, Discord, Slack, or any gateway platform. Aggregator-aware resolution keeps you on OpenRouter/Nous when possible, with automatic cross-provider fallback when needed. Interactive model pickers on Telegram and Discord with inline buttons. (<a href="https://github.com/NousResearch/hermes-agent/pull/5181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5181/hovercard">#5181</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5742/hovercard">#5742</a>)</p>
</li>
<li>
<p><strong>Self-Optimized GPT/Codex Tool-Use Guidance</strong> — The agent diagnosed and patched 5 failure modes in GPT and Codex tool calling through automated behavioral benchmarking, dramatically improving reliability on OpenAI models. Includes execution discipline guidance and thinking-only prefill continuation for structured reasoning. (<a href="https://github.com/NousResearch/hermes-agent/pull/6120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6120/hovercard">#6120</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5414" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5414/hovercard">#5414</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5931" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5931/hovercard">#5931</a>)</p>
</li>
<li>
<p><strong>Google AI Studio (Gemini) Native Provider</strong> — Direct access to Gemini models through Google's AI Studio API. Includes automatic models.dev registry integration for real-time context length detection across any provider. (<a href="https://github.com/NousResearch/hermes-agent/pull/5577" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5577/hovercard">#5577</a>)</p>
</li>
<li>
<p><strong>Inactivity-Based Agent Timeouts</strong> — Gateway and cron timeouts now track actual tool activity instead of wall-clock time. Long-running tasks that are actively working will never be killed — only truly idle agents time out. (<a href="https://github.com/NousResearch/hermes-agent/pull/5389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5389/hovercard">#5389</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5440" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5440/hovercard">#5440</a>)</p>
</li>
<li>
<p><strong>Approval Buttons on Slack &amp; Telegram</strong> — Dangerous command approval via native platform buttons instead of typing <code>/approve</code>. Slack gets thread context preservation; Telegram gets emoji reactions for approval status. (<a href="https://github.com/NousResearch/hermes-agent/pull/5890" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5890/hovercard">#5890</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5975" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5975/hovercard">#5975</a>)</p>
</li>
<li>
<p><strong>MCP OAuth 2.1 PKCE + OSV Malware Scanning</strong> — Full standards-compliant OAuth for MCP server authentication, plus automatic malware scanning of MCP extension packages via the OSV vulnerability database. (<a href="https://github.com/NousResearch/hermes-agent/pull/5420" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5420/hovercard">#5420</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5305" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5305/hovercard">#5305</a>)</p>
</li>
<li>
<p><strong>Centralized Logging &amp; Config Validation</strong> — Structured logging to <code>~/.hermes/logs/</code> (agent.log + errors.log) with the <code>hermes logs</code> command for tailing and filtering. Config structure validation catches malformed YAML at startup before it causes cryptic failures. (<a href="https://github.com/NousResearch/hermes-agent/pull/5430" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5430/hovercard">#5430</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5426" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5426/hovercard">#5426</a>)</p>
</li>
<li>
<p><strong>Plugin System Expansion</strong> — Plugins can now register CLI subcommands, receive request-scoped API hooks with correlation IDs, prompt for required env vars during install, and hook into session lifecycle events (finalize/reset). (<a href="https://github.com/NousResearch/hermes-agent/pull/5295" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5295/hovercard">#5295</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5427" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5427/hovercard">#5427</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5470" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5470/hovercard">#5470</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/6129" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6129/hovercard">#6129</a>)</p>
</li>
<li>
<p><strong>Matrix Tier 1 &amp; Platform Hardening</strong> — Matrix gets reactions, read receipts, rich formatting, and room management. Discord adds channel controls and ignored channels. Signal gets full MEDIA: tag delivery. Mattermost gets file attachments. Comprehensive reliability fixes across all platforms. (<a href="https://github.com/NousResearch/hermes-agent/pull/5275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5275/hovercard">#5275</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5975" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5975/hovercard">#5975</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5602" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5602/hovercard">#5602</a>)</p>
</li>
<li>
<p><strong>Security Hardening Pass</strong> — Consolidated SSRF protections, timing attack mitigations, tar traversal prevention, credential leakage guards, cron path traversal hardening, and cross-session isolation. Terminal workdir sanitization across all backends. (<a href="https://github.com/NousResearch/hermes-agent/pull/5944" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5944/hovercard">#5944</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5613" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5613/hovercard">#5613</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5629" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5629/hovercard">#5629</a>)</p>
</li>
</ul>
<hr>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Provider &amp; Model Support</h3>
<ul>
<li><strong>Native Google AI Studio (Gemini) provider</strong> with models.dev integration for automatic context length detection (<a href="https://github.com/NousResearch/hermes-agent/pull/5577" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5577/hovercard">#5577</a>)</li>
<li><strong><code>/model</code> command — full provider+model system overhaul</strong> — live switching across CLI and all gateway platforms with aggregator-aware resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/5181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5181/hovercard">#5181</a>)</li>
<li><strong>Interactive model picker for Telegram and Discord</strong> — inline button-based model selection (<a href="https://github.com/NousResearch/hermes-agent/pull/5742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5742/hovercard">#5742</a>)</li>
<li><strong>Nous Portal free-tier model gating</strong> with pricing display in model selection (<a href="https://github.com/NousResearch/hermes-agent/pull/5880" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5880/hovercard">#5880</a>)</li>
<li><strong>Model pricing display</strong> for OpenRouter and Nous Portal providers (<a href="https://github.com/NousResearch/hermes-agent/pull/5416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5416/hovercard">#5416</a>)</li>
<li><strong>xAI (Grok) prompt caching</strong> via <code>x-grok-conv-id</code> header (<a href="https://github.com/NousResearch/hermes-agent/pull/5604" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5604/hovercard">#5604</a>)</li>
<li><strong>Grok added to tool-use enforcement models</strong> for direct xAI usage (<a href="https://github.com/NousResearch/hermes-agent/pull/5595" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5595/hovercard">#5595</a>)</li>
<li><strong>MiniMax TTS provider</strong> (speech-2.8) (<a href="https://github.com/NousResearch/hermes-agent/pull/4963" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4963/hovercard">#4963</a>)</li>
<li><strong>Non-agentic model warning</strong> — warns users when loading Hermes LLM models not designed for tool use (<a href="https://github.com/NousResearch/hermes-agent/pull/5378" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5378/hovercard">#5378</a>)</li>
<li><strong>Ollama Cloud auth, /model switch persistence</strong>, and alias tab completion (<a href="https://github.com/NousResearch/hermes-agent/pull/5269" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5269/hovercard">#5269</a>)</li>
<li><strong>Preserve dots in OpenCode Go model names</strong> (minimax-m2.7, glm-4.5, kimi-k2.5) (<a href="https://github.com/NousResearch/hermes-agent/pull/5597" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5597/hovercard">#5597</a>)</li>
<li><strong>MiniMax models 404 fix</strong> — strip /v1 from Anthropic base URL for OpenCode Go (<a href="https://github.com/NousResearch/hermes-agent/pull/4918" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4918/hovercard">#4918</a>)</li>
<li><strong>Provider credential reset windows</strong> honored in pooled failover (<a href="https://github.com/NousResearch/hermes-agent/pull/5188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5188/hovercard">#5188</a>)</li>
<li><strong>OAuth token sync</strong> between credential pool and credentials file (<a href="https://github.com/NousResearch/hermes-agent/pull/4981" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4981/hovercard">#4981</a>)</li>
<li><strong>Stale OAuth credentials</strong> no longer block OpenRouter users on auto-detect (<a href="https://github.com/NousResearch/hermes-agent/pull/5746" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5746/hovercard">#5746</a>)</li>
<li><strong>Codex OAuth credential pool disconnect</strong> + expired token import fix (<a href="https://github.com/NousResearch/hermes-agent/pull/5681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5681/hovercard">#5681</a>)</li>
<li><strong>Codex pool entry sync</strong> from <code>~/.codex/auth.json</code> on exhaustion — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GratefulDave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GratefulDave">@GratefulDave</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5610" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5610/hovercard">#5610</a>)</li>
<li><strong>Auxiliary client payment fallback</strong> — retry with next provider on 402 (<a href="https://github.com/NousResearch/hermes-agent/pull/5599" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5599/hovercard">#5599</a>)</li>
<li><strong>Auxiliary client resolves named custom providers</strong> and 'main' alias (<a href="https://github.com/NousResearch/hermes-agent/pull/5978" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5978/hovercard">#5978</a>)</li>
<li><strong>Use mimo-v2-pro</strong> for non-vision auxiliary tasks on Nous free tier (<a href="https://github.com/NousResearch/hermes-agent/pull/6018" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6018/hovercard">#6018</a>)</li>
<li><strong>Vision auto-detection</strong> tries main provider first (<a href="https://github.com/NousResearch/hermes-agent/pull/6041" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6041/hovercard">#6041</a>)</li>
<li><strong>Provider re-ordering and Quick Install</strong> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/4664" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4664/hovercard">#4664</a>)</li>
<li><strong>Nous OAuth access_token</strong> no longer used as inference API key — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5564" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5564/hovercard">#5564</a>)</li>
<li><strong>HERMES_PORTAL_BASE_URL env var</strong> respected during Nous login — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5745" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5745/hovercard">#5745</a>)</li>
<li><strong>Env var overrides</strong> for Nous portal/inference URLs (<a href="https://github.com/NousResearch/hermes-agent/pull/5419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5419/hovercard">#5419</a>)</li>
<li><strong>Z.AI endpoint auto-detect</strong> via probe and cache (<a href="https://github.com/NousResearch/hermes-agent/pull/5763" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5763/hovercard">#5763</a>)</li>
<li><strong>MiniMax context lengths, model catalog, thinking guard, aux model, and config base_url</strong> corrections (<a href="https://github.com/NousResearch/hermes-agent/pull/6082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6082/hovercard">#6082</a>)</li>
<li><strong>Community provider/model resolution fixes</strong> — salvaged 4 community PRs + MiniMax aux URL (<a href="https://github.com/NousResearch/hermes-agent/pull/5983" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5983/hovercard">#5983</a>)</li>
</ul>
<h3>Agent Loop &amp; Conversation</h3>
<ul>
<li><strong>Self-optimized GPT/Codex tool-use guidance</strong> via automated behavioral benchmarking — agent self-diagnosed and patched 5 failure modes (<a href="https://github.com/NousResearch/hermes-agent/pull/6120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6120/hovercard">#6120</a>)</li>
<li><strong>GPT/Codex execution discipline guidance</strong> in system prompts (<a href="https://github.com/NousResearch/hermes-agent/pull/5414" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5414/hovercard">#5414</a>)</li>
<li><strong>Thinking-only prefill continuation</strong> for structured reasoning responses (<a href="https://github.com/NousResearch/hermes-agent/pull/5931" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5931/hovercard">#5931</a>)</li>
<li><strong>Accept reasoning-only responses</strong> without retries — set content to "(empty)" instead of infinite retry (<a href="https://github.com/NousResearch/hermes-agent/pull/5278" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5278/hovercard">#5278</a>)</li>
<li><strong>Jittered retry backoff</strong> — exponential backoff with jitter for API retries (<a href="https://github.com/NousResearch/hermes-agent/pull/6048" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6048/hovercard">#6048</a>)</li>
<li><strong>Smart thinking block signature management</strong> — preserve and manage Anthropic thinking signatures across turns (<a href="https://github.com/NousResearch/hermes-agent/pull/6112" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6112/hovercard">#6112</a>)</li>
<li><strong>Coerce tool call arguments</strong> to match JSON Schema types — fixes models that send strings instead of numbers/booleans (<a href="https://github.com/NousResearch/hermes-agent/pull/5265" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5265/hovercard">#5265</a>)</li>
<li><strong>Save oversized tool results to file</strong> instead of destructive truncation (<a href="https://github.com/NousResearch/hermes-agent/pull/5210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5210/hovercard">#5210</a>)</li>
<li><strong>Sandbox-aware tool result persistence</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/6085" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6085/hovercard">#6085</a>)</li>
<li><strong>Streaming fallback</strong> improved after edit failures (<a href="https://github.com/NousResearch/hermes-agent/pull/6110" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6110/hovercard">#6110</a>)</li>
<li><strong>Codex empty-output gaps</strong> covered in fallback + normalizer + auxiliary client (<a href="https://github.com/NousResearch/hermes-agent/pull/5724" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5724/hovercard">#5724</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5730" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5730/hovercard">#5730</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5734" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5734/hovercard">#5734</a>)</li>
<li><strong>Codex stream output backfill</strong> from output_item.done events (<a href="https://github.com/NousResearch/hermes-agent/pull/5689" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5689/hovercard">#5689</a>)</li>
<li><strong>Stream consumer creates new message</strong> after tool boundaries (<a href="https://github.com/NousResearch/hermes-agent/pull/5739" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5739/hovercard">#5739</a>)</li>
<li><strong>Codex validation aligned</strong> with normalization for empty stream output (<a href="https://github.com/NousResearch/hermes-agent/pull/5940" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5940/hovercard">#5940</a>)</li>
<li><strong>Bridge tool-calls</strong> in copilot-acp adapter (<a href="https://github.com/NousResearch/hermes-agent/pull/5460" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5460/hovercard">#5460</a>)</li>
<li><strong>Filter transcript-only roles</strong> from chat-completions payload (<a href="https://github.com/NousResearch/hermes-agent/pull/4880" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4880/hovercard">#4880</a>)</li>
<li><strong>Context compaction failures fixed</strong> on temperature-restricted models — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MadKangYu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MadKangYu">@MadKangYu</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5608" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5608/hovercard">#5608</a>)</li>
<li><strong>Sanitize tool_calls for all strict APIs</strong> (Fireworks, Mistral, etc.) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lumethegreat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lumethegreat">@lumethegreat</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5183" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5183/hovercard">#5183</a>)</li>
</ul>
<h3>Memory &amp; Sessions</h3>
<ul>
<li><strong>Supermemory memory provider</strong> — new memory plugin with multi-container, search_mode, identity template, and env var override (<a href="https://github.com/NousResearch/hermes-agent/pull/5737" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5737/hovercard">#5737</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5933" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5933/hovercard">#5933</a>)</li>
<li><strong>Shared thread sessions</strong> by default — multi-user thread support across gateway platforms (<a href="https://github.com/NousResearch/hermes-agent/pull/5391" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5391/hovercard">#5391</a>)</li>
<li><strong>Subagent sessions linked to parent</strong> and hidden from session list (<a href="https://github.com/NousResearch/hermes-agent/pull/5309" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5309/hovercard">#5309</a>)</li>
<li><strong>Profile-scoped memory isolation</strong> and clone support (<a href="https://github.com/NousResearch/hermes-agent/pull/4845" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4845/hovercard">#4845</a>)</li>
<li><strong>Thread gateway user_id to memory plugins</strong> for per-user scoping (<a href="https://github.com/NousResearch/hermes-agent/pull/5895" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5895/hovercard">#5895</a>)</li>
<li><strong>Honcho plugin drift overhaul</strong> + plugin CLI registration system (<a href="https://github.com/NousResearch/hermes-agent/pull/5295" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5295/hovercard">#5295</a>)</li>
<li><strong>Honcho holographic prompt and trust score</strong> rendering preserved (<a href="https://github.com/NousResearch/hermes-agent/pull/4872" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4872/hovercard">#4872</a>)</li>
<li><strong>Honcho doctor fix</strong> — use recall_mode instead of memory_mode — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/techguysimon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/techguysimon">@techguysimon</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5645" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5645/hovercard">#5645</a>)</li>
<li><strong>RetainDB</strong> — API routes, write queue, dialectic, agent model, file tools fixes (<a href="https://github.com/NousResearch/hermes-agent/pull/5461" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5461/hovercard">#5461</a>)</li>
<li><strong>Hindsight memory plugin overhaul</strong> + memory setup wizard fixes (<a href="https://github.com/NousResearch/hermes-agent/pull/5094" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5094/hovercard">#5094</a>)</li>
<li><strong>mem0 API v2 compat</strong>, prefetch context fencing, secret redaction (<a href="https://github.com/NousResearch/hermes-agent/pull/5423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5423/hovercard">#5423</a>)</li>
<li><strong>mem0 env vars merged</strong> with mem0.json instead of either/or (<a href="https://github.com/NousResearch/hermes-agent/pull/4939" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4939/hovercard">#4939</a>)</li>
<li><strong>Clean user message</strong> used for all memory provider operations (<a href="https://github.com/NousResearch/hermes-agent/pull/4940" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4940/hovercard">#4940</a>)</li>
<li><strong>Silent memory flush failure</strong> on /new and /resume fixed — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryanautomated/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryanautomated">@ryanautomated</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5640" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5640/hovercard">#5640</a>)</li>
<li><strong>OpenViking atexit safety net</strong> for session commit (<a href="https://github.com/NousResearch/hermes-agent/pull/5664" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5664/hovercard">#5664</a>)</li>
<li><strong>OpenViking tenant-scoping headers</strong> for multi-tenant servers (<a href="https://github.com/NousResearch/hermes-agent/pull/4936" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4936/hovercard">#4936</a>)</li>
<li><strong>ByteRover brv query</strong> runs synchronously before LLM call (<a href="https://github.com/NousResearch/hermes-agent/pull/4831" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4831/hovercard">#4831</a>)</li>
</ul>
<hr>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>Gateway Core</h3>
<ul>
<li><strong>Inactivity-based agent timeout</strong> — replaces wall-clock timeout with smart activity tracking; long-running active tasks never killed (<a href="https://github.com/NousResearch/hermes-agent/pull/5389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5389/hovercard">#5389</a>)</li>
<li><strong>Approval buttons for Slack &amp; Telegram</strong> + Slack thread context preservation (<a href="https://github.com/NousResearch/hermes-agent/pull/5890" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5890/hovercard">#5890</a>)</li>
<li><strong>Live-stream /update output</strong> + forward interactive prompts to user (<a href="https://github.com/NousResearch/hermes-agent/pull/5180" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5180/hovercard">#5180</a>)</li>
<li><strong>Infinite timeout support</strong> + periodic notifications + actionable error messages (<a href="https://github.com/NousResearch/hermes-agent/pull/4959" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4959/hovercard">#4959</a>)</li>
<li><strong>Duplicate message prevention</strong> — gateway dedup + partial stream guard (<a href="https://github.com/NousResearch/hermes-agent/pull/4878" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4878/hovercard">#4878</a>)</li>
<li><strong>Webhook delivery_info persistence</strong> + full session id in /status (<a href="https://github.com/NousResearch/hermes-agent/pull/5942" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5942/hovercard">#5942</a>)</li>
<li><strong>Tool preview truncation</strong> respects tool_preview_length in all/new progress modes (<a href="https://github.com/NousResearch/hermes-agent/pull/5937" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5937/hovercard">#5937</a>)</li>
<li><strong>Short preview truncation</strong> restored for all/new tool progress modes (<a href="https://github.com/NousResearch/hermes-agent/pull/4935" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4935/hovercard">#4935</a>)</li>
<li><strong>Update-pending state</strong> written atomically to prevent corruption (<a href="https://github.com/NousResearch/hermes-agent/pull/4923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4923/hovercard">#4923</a>)</li>
<li><strong>Approval session key isolated</strong> per turn (<a href="https://github.com/NousResearch/hermes-agent/pull/4884" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4884/hovercard">#4884</a>)</li>
<li><strong>Active-session guard bypass</strong> for /approve, /deny, /stop, /new (<a href="https://github.com/NousResearch/hermes-agent/pull/4926" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4926/hovercard">#4926</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5765" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5765/hovercard">#5765</a>)</li>
<li><strong>Typing indicator paused</strong> during approval waits (<a href="https://github.com/NousResearch/hermes-agent/pull/5893" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5893/hovercard">#5893</a>)</li>
<li><strong>Caption check</strong> uses exact line-by-line match instead of substring (all platforms) (<a href="https://github.com/NousResearch/hermes-agent/pull/5939" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5939/hovercard">#5939</a>)</li>
<li><strong>MEDIA: tags stripped</strong> from streamed gateway messages (<a href="https://github.com/NousResearch/hermes-agent/pull/5152" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5152/hovercard">#5152</a>)</li>
<li><strong>MEDIA: tags extracted</strong> from cron delivery before sending (<a href="https://github.com/NousResearch/hermes-agent/pull/5598" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5598/hovercard">#5598</a>)</li>
<li><strong>Profile-aware service units</strong> + voice transcription cleanup (<a href="https://github.com/NousResearch/hermes-agent/pull/5972" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5972/hovercard">#5972</a>)</li>
<li><strong>Thread-safe PairingStore</strong> with atomic writes — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharlieKerfoot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharlieKerfoot">@CharlieKerfoot</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5656" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5656/hovercard">#5656</a>)</li>
<li><strong>Sanitize media URLs</strong> in base platform logs — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WAXLYY/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WAXLYY">@WAXLYY</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5631/hovercard">#5631</a>)</li>
<li><strong>Reduce Telegram fallback IP activation log noise</strong> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MadKangYu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MadKangYu">@MadKangYu</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5615" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5615/hovercard">#5615</a>)</li>
<li><strong>Cron static method wrappers</strong> to prevent self-binding (<a href="https://github.com/NousResearch/hermes-agent/pull/5299" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5299/hovercard">#5299</a>)</li>
<li><strong>Stale 'hermes login' replaced</strong> with 'hermes auth' + credential removal re-seeding fix (<a href="https://github.com/NousResearch/hermes-agent/pull/5670" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5670/hovercard">#5670</a>)</li>
</ul>
<h3>Telegram</h3>
<ul>
<li><strong>Group topics skill binding</strong> for supergroup forum topics (<a href="https://github.com/NousResearch/hermes-agent/pull/4886" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4886/hovercard">#4886</a>)</li>
<li><strong>Emoji reactions</strong> for approval status and notifications (<a href="https://github.com/NousResearch/hermes-agent/pull/5975" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5975/hovercard">#5975</a>)</li>
<li><strong>Duplicate message delivery prevented</strong> on send timeout (<a href="https://github.com/NousResearch/hermes-agent/pull/5153" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5153/hovercard">#5153</a>)</li>
<li><strong>Command names sanitized</strong> to strip invalid characters (<a href="https://github.com/NousResearch/hermes-agent/pull/5596" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5596/hovercard">#5596</a>)</li>
<li><strong>Per-platform disabled skills</strong> respected in Telegram menu and gateway dispatch (<a href="https://github.com/NousResearch/hermes-agent/pull/4799" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4799/hovercard">#4799</a>)</li>
<li><strong>/approve and /deny</strong> routed through running-agent guard (<a href="https://github.com/NousResearch/hermes-agent/pull/4798" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4798/hovercard">#4798</a>)</li>
</ul>
<h3>Discord</h3>
<ul>
<li><strong>Channel controls</strong> — ignored_channels and no_thread_channels config options (<a href="https://github.com/NousResearch/hermes-agent/pull/5975" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5975/hovercard">#5975</a>)</li>
<li><strong>Skills registered as native slash commands</strong> via shared gateway logic (<a href="https://github.com/NousResearch/hermes-agent/pull/5603" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5603/hovercard">#5603</a>)</li>
<li><strong>/approve, /deny, /queue, /background, /btw</strong> registered as native slash commands (<a href="https://github.com/NousResearch/hermes-agent/pull/4800" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4800/hovercard">#4800</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5477" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5477/hovercard">#5477</a>)</li>
<li><strong>Unnecessary members intent</strong> removed on startup + token lock leak fix (<a href="https://github.com/NousResearch/hermes-agent/pull/5302" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5302/hovercard">#5302</a>)</li>
</ul>
<h3>Slack</h3>
<ul>
<li><strong>Thread engagement</strong> — auto-respond in bot-started and mentioned threads (<a href="https://github.com/NousResearch/hermes-agent/pull/5897" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5897/hovercard">#5897</a>)</li>
<li><strong>mrkdwn in edit_message</strong> + thread replies without @mentions (<a href="https://github.com/NousResearch/hermes-agent/pull/5733" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5733/hovercard">#5733</a>)</li>
</ul>
<h3>Matrix</h3>
<ul>
<li><strong>Tier 1 feature parity</strong> — reactions, read receipts, rich formatting, room management (<a href="https://github.com/NousResearch/hermes-agent/pull/5275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5275/hovercard">#5275</a>)</li>
<li><strong>MATRIX_REQUIRE_MENTION and MATRIX_AUTO_THREAD</strong> support (<a href="https://github.com/NousResearch/hermes-agent/pull/5106" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5106/hovercard">#5106</a>)</li>
<li><strong>Comprehensive reliability</strong> — encrypted media, auth recovery, cron E2EE, Synapse compat (<a href="https://github.com/NousResearch/hermes-agent/pull/5271" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5271/hovercard">#5271</a>)</li>
<li><strong>CJK input, E2EE, and reconnect</strong> fixes (<a href="https://github.com/NousResearch/hermes-agent/pull/5665" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5665/hovercard">#5665</a>)</li>
</ul>
<h3>Signal</h3>
<ul>
<li><strong>Full MEDIA: tag delivery</strong> — send_image_file, send_voice, and send_video implemented (<a href="https://github.com/NousResearch/hermes-agent/pull/5602" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5602/hovercard">#5602</a>)</li>
</ul>
<h3>Mattermost</h3>
<ul>
<li><strong>File attachments</strong> — set message type to DOCUMENT when post has file attachments — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nericervin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nericervin">@nericervin</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5609" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5609/hovercard">#5609</a>)</li>
</ul>
<h3>Feishu</h3>
<ul>
<li><strong>Interactive card approval buttons</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/6043" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6043/hovercard">#6043</a>)</li>
<li><strong>Reconnect and ACL</strong> fixes (<a href="https://github.com/NousResearch/hermes-agent/pull/5665" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5665/hovercard">#5665</a>)</li>
</ul>
<h3>Webhooks</h3>
<ul>
<li><strong><code>{__raw__}</code> template token</strong> and thread_id passthrough for forum topics (<a href="https://github.com/NousResearch/hermes-agent/pull/5662" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5662/hovercard">#5662</a>)</li>
</ul>
<hr>
<h2>🖥️ CLI &amp; User Experience</h2>
<h3>Interactive CLI</h3>
<ul>
<li><strong>Defer response content</strong> until reasoning block completes (<a href="https://github.com/NousResearch/hermes-agent/pull/5773" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5773/hovercard">#5773</a>)</li>
<li><strong>Ghost status-bar lines cleared</strong> on terminal resize (<a href="https://github.com/NousResearch/hermes-agent/pull/4960" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4960/hovercard">#4960</a>)</li>
<li><strong>Normalise \r\n and \r line endings</strong> in pasted text (<a href="https://github.com/NousResearch/hermes-agent/pull/4849" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4849/hovercard">#4849</a>)</li>
<li><strong>ChatConsole errors, curses scroll, skin-aware banner, git state</strong> banner fixes (<a href="https://github.com/NousResearch/hermes-agent/pull/5974" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5974/hovercard">#5974</a>)</li>
<li><strong>Native Windows image paste</strong> support (<a href="https://github.com/NousResearch/hermes-agent/pull/5917" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5917/hovercard">#5917</a>)</li>
<li><strong>--yolo and other flags</strong> no longer silently dropped when placed before 'chat' subcommand (<a href="https://github.com/NousResearch/hermes-agent/pull/5145" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5145/hovercard">#5145</a>)</li>
</ul>
<h3>Setup &amp; Configuration</h3>
<ul>
<li><strong>Config structure validation</strong> — detect malformed YAML at startup with actionable error messages (<a href="https://github.com/NousResearch/hermes-agent/pull/5426" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5426/hovercard">#5426</a>)</li>
<li><strong>Centralized logging</strong> to <code>~/.hermes/logs/</code> — agent.log (INFO+), errors.log (WARNING+) with <code>hermes logs</code> command (<a href="https://github.com/NousResearch/hermes-agent/pull/5430" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5430/hovercard">#5430</a>)</li>
<li><strong>Docs links added</strong> to setup wizard sections (<a href="https://github.com/NousResearch/hermes-agent/pull/5283" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5283/hovercard">#5283</a>)</li>
<li><strong>Doctor diagnostics</strong> — sync provider checks, config migration, WAL and mem0 diagnostics (<a href="https://github.com/NousResearch/hermes-agent/pull/5077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5077/hovercard">#5077</a>)</li>
<li><strong>Timeout debug logging</strong> and user-facing diagnostics improved (<a href="https://github.com/NousResearch/hermes-agent/pull/5370" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5370/hovercard">#5370</a>)</li>
<li><strong>Reasoning effort unified</strong> to config.yaml only (<a href="https://github.com/NousResearch/hermes-agent/pull/6118" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6118/hovercard">#6118</a>)</li>
<li><strong>Permanent command allowlist</strong> loaded on startup (<a href="https://github.com/NousResearch/hermes-agent/pull/5076" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5076/hovercard">#5076</a>)</li>
<li><strong><code>hermes auth remove</code></strong> now clears env-seeded credentials permanently (<a href="https://github.com/NousResearch/hermes-agent/pull/5285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5285/hovercard">#5285</a>)</li>
<li><strong>Bundled skills synced to all profiles</strong> during update (<a href="https://github.com/NousResearch/hermes-agent/pull/5795" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5795/hovercard">#5795</a>)</li>
<li><strong><code>hermes update</code> no longer kills</strong> freshly-restarted gateway service (<a href="https://github.com/NousResearch/hermes-agent/pull/5448" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5448/hovercard">#5448</a>)</li>
<li><strong>Subprocess.run() timeouts</strong> added to all gateway CLI commands (<a href="https://github.com/NousResearch/hermes-agent/pull/5424" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5424/hovercard">#5424</a>)</li>
<li><strong>Actionable error message</strong> when Codex refresh token is reused — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tymrtn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tymrtn">@tymrtn</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5612" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5612/hovercard">#5612</a>)</li>
<li><strong>Google-workspace skill scripts</strong> can now run directly — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xinbenlv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xinbenlv">@xinbenlv</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5624/hovercard">#5624</a>)</li>
</ul>
<h3>Cron System</h3>
<ul>
<li><strong>Inactivity-based cron timeout</strong> — replaces wall-clock; active tasks run indefinitely (<a href="https://github.com/NousResearch/hermes-agent/pull/5440" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5440/hovercard">#5440</a>)</li>
<li><strong>Pre-run script injection</strong> for data collection and change detection (<a href="https://github.com/NousResearch/hermes-agent/pull/5082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5082/hovercard">#5082</a>)</li>
<li><strong>Delivery failure tracking</strong> in job status (<a href="https://github.com/NousResearch/hermes-agent/pull/6042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6042/hovercard">#6042</a>)</li>
<li><strong>Delivery guidance</strong> in cron prompts — stops send_message thrashing (<a href="https://github.com/NousResearch/hermes-agent/pull/5444" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5444/hovercard">#5444</a>)</li>
<li><strong>MEDIA files delivered</strong> as native platform attachments (<a href="https://github.com/NousResearch/hermes-agent/pull/5921" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5921/hovercard">#5921</a>)</li>
<li><strong>[SILENT] suppression</strong> works anywhere in response — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/auspic7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/auspic7">@auspic7</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5654" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5654/hovercard">#5654</a>)</li>
<li><strong>Cron path traversal</strong> hardening (<a href="https://github.com/NousResearch/hermes-agent/pull/5147" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5147/hovercard">#5147</a>)</li>
</ul>
<hr>
<h2>🔧 Tool System</h2>
<h3>Terminal &amp; Execution</h3>
<ul>
<li><strong>Execute_code on remote backends</strong> — code execution now works on Docker, SSH, Modal, and other remote terminal backends (<a href="https://github.com/NousResearch/hermes-agent/pull/5088" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5088/hovercard">#5088</a>)</li>
<li><strong>Exit code context</strong> for common CLI tools in terminal results — helps agent understand what went wrong (<a href="https://github.com/NousResearch/hermes-agent/pull/5144" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5144/hovercard">#5144</a>)</li>
<li><strong>Progressive subdirectory hint discovery</strong> — agent learns project structure as it navigates (<a href="https://github.com/NousResearch/hermes-agent/pull/5291" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5291/hovercard">#5291</a>)</li>
<li><strong>notify_on_complete for background processes</strong> — get notified when long-running tasks finish (<a href="https://github.com/NousResearch/hermes-agent/pull/5779" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5779/hovercard">#5779</a>)</li>
<li><strong>Docker env config</strong> — explicit container environment variables via docker_env config (<a href="https://github.com/NousResearch/hermes-agent/pull/4738" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4738/hovercard">#4738</a>)</li>
<li><strong>Approval metadata included</strong> in terminal tool results (<a href="https://github.com/NousResearch/hermes-agent/pull/5141" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5141/hovercard">#5141</a>)</li>
<li><strong>Workdir parameter sanitized</strong> in terminal tool across all backends (<a href="https://github.com/NousResearch/hermes-agent/pull/5629" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5629/hovercard">#5629</a>)</li>
<li><strong>Detached process crash recovery</strong> state corrected (<a href="https://github.com/NousResearch/hermes-agent/pull/6101" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6101/hovercard">#6101</a>)</li>
<li><strong>Agent-browser paths with spaces</strong> preserved — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vasanthdev2004/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vasanthdev2004">@Vasanthdev2004</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6077/hovercard">#6077</a>)</li>
<li><strong>Portable base64 encoding</strong> for image reading on macOS — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharlieKerfoot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharlieKerfoot">@CharlieKerfoot</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5657" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5657/hovercard">#5657</a>)</li>
</ul>
<h3>Browser</h3>
<ul>
<li><strong>Switch managed browser provider</strong> from Browserbase to Browser Use — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5750" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5750/hovercard">#5750</a>)</li>
<li><strong>Firecrawl cloud browser</strong> provider — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5628" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5628/hovercard">#5628</a>)</li>
<li><strong>JS evaluation</strong> via browser_console expression parameter (<a href="https://github.com/NousResearch/hermes-agent/pull/5303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5303/hovercard">#5303</a>)</li>
<li><strong>Windows browser</strong> fixes (<a href="https://github.com/NousResearch/hermes-agent/pull/5665" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5665/hovercard">#5665</a>)</li>
</ul>
<h3>MCP</h3>
<ul>
<li><strong>MCP OAuth 2.1 PKCE</strong> — full standards-compliant OAuth client support (<a href="https://github.com/NousResearch/hermes-agent/pull/5420" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5420/hovercard">#5420</a>)</li>
<li><strong>OSV malware check</strong> for MCP extension packages (<a href="https://github.com/NousResearch/hermes-agent/pull/5305" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5305/hovercard">#5305</a>)</li>
<li><strong>Prefer structuredContent over text</strong> + no_mcp sentinel (<a href="https://github.com/NousResearch/hermes-agent/pull/5979" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5979/hovercard">#5979</a>)</li>
<li><strong>Unknown toolsets warning suppressed</strong> for MCP server names (<a href="https://github.com/NousResearch/hermes-agent/pull/5279" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5279/hovercard">#5279</a>)</li>
</ul>
<h3>Web &amp; Files</h3>
<ul>
<li><strong>.zip document support</strong> + auto-mount cache dirs into remote backends (<a href="https://github.com/NousResearch/hermes-agent/pull/4846" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4846/hovercard">#4846</a>)</li>
<li><strong>Redact query secrets</strong> in send_message errors — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WAXLYY/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WAXLYY">@WAXLYY</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5650" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5650/hovercard">#5650</a>)</li>
</ul>
<h3>Delegation</h3>
<ul>
<li><strong>Credential pool sharing</strong> + workspace path hints for subagents (<a href="https://github.com/NousResearch/hermes-agent/pull/5748" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5748/hovercard">#5748</a>)</li>
</ul>
<h3>ACP (VS Code / Zed / JetBrains)</h3>
<ul>
<li><strong>Aggregate ACP improvements</strong> — auth compat, protocol fixes, command ads, delegation, SSE events (<a href="https://github.com/NousResearch/hermes-agent/pull/5292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5292/hovercard">#5292</a>)</li>
</ul>
<hr>
<h2>🧩 Skills Ecosystem</h2>
<h3>Skills System</h3>
<ul>
<li><strong>Skill config interface</strong> — skills can declare required config.yaml settings, prompted during setup, injected at load time (<a href="https://github.com/NousResearch/hermes-agent/pull/5635" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5635/hovercard">#5635</a>)</li>
<li><strong>Plugin CLI registration system</strong> — plugins register their own CLI subcommands without touching main.py (<a href="https://github.com/NousResearch/hermes-agent/pull/5295" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5295/hovercard">#5295</a>)</li>
<li><strong>Request-scoped API hooks</strong> with tool call correlation IDs for plugins (<a href="https://github.com/NousResearch/hermes-agent/pull/5427" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5427/hovercard">#5427</a>)</li>
<li><strong>Session lifecycle hooks</strong> — on_session_finalize and on_session_reset for CLI + gateway (<a href="https://github.com/NousResearch/hermes-agent/pull/6129" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6129/hovercard">#6129</a>)</li>
<li><strong>Prompt for required env vars</strong> during plugin install — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5470" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5470/hovercard">#5470</a>)</li>
<li><strong>Plugin name validation</strong> — reject names that resolve to plugins root (<a href="https://github.com/NousResearch/hermes-agent/pull/5368" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5368/hovercard">#5368</a>)</li>
<li><strong>pre_llm_call plugin context</strong> moved to user message to preserve prompt cache (<a href="https://github.com/NousResearch/hermes-agent/pull/5146" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5146/hovercard">#5146</a>)</li>
</ul>
<h3>New &amp; Updated Skills</h3>
<ul>
<li><strong>popular-web-designs</strong> — 54 production website design systems (<a href="https://github.com/NousResearch/hermes-agent/pull/5194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5194/hovercard">#5194</a>)</li>
<li><strong>p5js creative coding</strong> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5600" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5600/hovercard">#5600</a>)</li>
<li><strong>manim-video</strong> — mathematical and technical animations — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/4930" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4930/hovercard">#4930</a>)</li>
<li><strong>llm-wiki</strong> — Karpathy's LLM Wiki skill (<a href="https://github.com/NousResearch/hermes-agent/pull/5635" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5635/hovercard">#5635</a>)</li>
<li><strong>gitnexus-explorer</strong> — codebase indexing and knowledge serving (<a href="https://github.com/NousResearch/hermes-agent/pull/5208" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5208/hovercard">#5208</a>)</li>
<li><strong>research-paper-writing</strong> — AI-Scientist &amp; GPT-Researcher patterns — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5421" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5421/hovercard">#5421</a>)</li>
<li><strong>blogwatcher</strong> updated to JulienTant's fork (<a href="https://github.com/NousResearch/hermes-agent/pull/5759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5759/hovercard">#5759</a>)</li>
<li><strong>claude-code skill</strong> comprehensive rewrite v2.0 + v2.2 (<a href="https://github.com/NousResearch/hermes-agent/pull/5155" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5155/hovercard">#5155</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5158" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5158/hovercard">#5158</a>)</li>
<li><strong>Code verification skills</strong> consolidated into one (<a href="https://github.com/NousResearch/hermes-agent/pull/4854" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4854/hovercard">#4854</a>)</li>
<li><strong>Manim CE reference docs</strong> expanded — geometry, animations, LaTeX — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leotrs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leotrs">@leotrs</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5791" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5791/hovercard">#5791</a>)</li>
<li><strong>Manim-video references</strong> — design thinking, updaters, paper explainer, decorations, production quality — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5588" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5588/hovercard">#5588</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/5408" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5408/hovercard">#5408</a>)</li>
</ul>
<hr>
<h2>🔒 Security &amp; Reliability</h2>
<h3>Security Hardening</h3>
<ul>
<li><strong>Consolidated security</strong> — SSRF protections, timing attack mitigations, tar traversal prevention, credential leakage guards (<a href="https://github.com/NousResearch/hermes-agent/pull/5944" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5944/hovercard">#5944</a>)</li>
<li><strong>Cross-session isolation</strong> + cron path traversal hardening (<a href="https://github.com/NousResearch/hermes-agent/pull/5613" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5613/hovercard">#5613</a>)</li>
<li><strong>Workdir parameter sanitized</strong> in terminal tool across all backends (<a href="https://github.com/NousResearch/hermes-agent/pull/5629" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5629/hovercard">#5629</a>)</li>
<li><strong>Approval 'once' session escalation</strong> prevented + cron delivery platform validation (<a href="https://github.com/NousResearch/hermes-agent/pull/5280" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5280/hovercard">#5280</a>)</li>
<li><strong>Profile-scoped Google Workspace OAuth tokens</strong> protected (<a href="https://github.com/NousResearch/hermes-agent/pull/4910" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4910/hovercard">#4910</a>)</li>
</ul>
<h3>Reliability</h3>
<ul>
<li><strong>Aggressive worktree and branch cleanup</strong> to prevent accumulation (<a href="https://github.com/NousResearch/hermes-agent/pull/6134" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6134/hovercard">#6134</a>)</li>
<li><strong>O(n²) catastrophic backtracking</strong> in redact regex fixed — 100x improvement on large outputs (<a href="https://github.com/NousResearch/hermes-agent/pull/4962" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4962/hovercard">#4962</a>)</li>
<li><strong>Runtime stability fixes</strong> across core, web, delegate, and browser tools (<a href="https://github.com/NousResearch/hermes-agent/pull/4843" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4843/hovercard">#4843</a>)</li>
<li><strong>API server streaming fix</strong> + conversation history support (<a href="https://github.com/NousResearch/hermes-agent/pull/5977" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5977/hovercard">#5977</a>)</li>
<li><strong>OpenViking API endpoint paths</strong> and response parsing corrected (<a href="https://github.com/NousResearch/hermes-agent/pull/5078" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5078/hovercard">#5078</a>)</li>
</ul>
<hr>
<h2>🐛 Notable Bug Fixes</h2>
<ul>
<li><strong>9 community bugfixes salvaged</strong> — gateway, cron, deps, macOS launchd in one batch (<a href="https://github.com/NousResearch/hermes-agent/pull/5288" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5288/hovercard">#5288</a>)</li>
<li><strong>Batch core bug fixes</strong> — model config, session reset, alias fallback, launchctl, delegation, atomic writes (<a href="https://github.com/NousResearch/hermes-agent/pull/5630" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5630/hovercard">#5630</a>)</li>
<li><strong>Batch gateway/platform fixes</strong> — matrix E2EE, CJK input, Windows browser, Feishu reconnect + ACL (<a href="https://github.com/NousResearch/hermes-agent/pull/5665" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5665/hovercard">#5665</a>)</li>
<li><strong>Stale test skips removed</strong>, regex backtracking, file search bug, and test flakiness (<a href="https://github.com/NousResearch/hermes-agent/pull/4969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4969/hovercard">#4969</a>)</li>
<li><strong>Nix flake</strong> — read version, regen uv.lock, add hermes_logging — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5651" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5651/hovercard">#5651</a>)</li>
<li><strong>Lowercase variable redaction</strong> regression tests (<a href="https://github.com/NousResearch/hermes-agent/pull/5185" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5185/hovercard">#5185</a>)</li>
</ul>
<hr>
<h2>🧪 Testing</h2>
<ul>
<li><strong>57 failing CI tests repaired</strong> across 14 files (<a href="https://github.com/NousResearch/hermes-agent/pull/5823" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5823/hovercard">#5823</a>)</li>
<li><strong>Test suite re-architecture</strong> + CI failure fixes — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/5946" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5946/hovercard">#5946</a>)</li>
<li><strong>Codebase-wide lint cleanup</strong> — unused imports, dead code, and inefficient patterns (<a href="https://github.com/NousResearch/hermes-agent/pull/5821" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5821/hovercard">#5821</a>)</li>
<li><strong>browser_close tool removed</strong> — auto-cleanup handles it (<a href="https://github.com/NousResearch/hermes-agent/pull/5792" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5792/hovercard">#5792</a>)</li>
</ul>
<hr>
<h2>📚 Documentation</h2>
<ul>
<li><strong>Comprehensive documentation audit</strong> — fix stale info, expand thin pages, add depth (<a href="https://github.com/NousResearch/hermes-agent/pull/5393" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5393/hovercard">#5393</a>)</li>
<li><strong>40+ discrepancies fixed</strong> between documentation and codebase (<a href="https://github.com/NousResearch/hermes-agent/pull/5818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5818/hovercard">#5818</a>)</li>
<li><strong>13 features documented</strong> from last week's PRs (<a href="https://github.com/NousResearch/hermes-agent/pull/5815" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5815/hovercard">#5815</a>)</li>
<li><strong>Guides section overhaul</strong> — fix existing + add 3 new tutorials (<a href="https://github.com/NousResearch/hermes-agent/pull/5735" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5735/hovercard">#5735</a>)</li>
<li><strong>Salvaged 4 docs PRs</strong> — docker setup, post-update validation, local LLM guide, signal-cli install (<a href="https://github.com/NousResearch/hermes-agent/pull/5727" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5727/hovercard">#5727</a>)</li>
<li><strong>Discord configuration reference</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/5386" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5386/hovercard">#5386</a>)</li>
<li><strong>Community FAQ entries</strong> for common workflows and troubleshooting (<a href="https://github.com/NousResearch/hermes-agent/pull/4797" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4797/hovercard">#4797</a>)</li>
<li><strong>WSL2 networking guide</strong> for local model servers (<a href="https://github.com/NousResearch/hermes-agent/pull/5616" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5616/hovercard">#5616</a>)</li>
<li><strong>Honcho CLI reference</strong> + plugin CLI registration docs (<a href="https://github.com/NousResearch/hermes-agent/pull/5308" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5308/hovercard">#5308</a>)</li>
<li><strong>Obsidian Headless setup</strong> for servers in llm-wiki (<a href="https://github.com/NousResearch/hermes-agent/pull/5660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5660/hovercard">#5660</a>)</li>
<li><strong>Hermes Mod visual skin editor</strong> added to skins page (<a href="https://github.com/NousResearch/hermes-agent/pull/6095" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6095/hovercard">#6095</a>)</li>
</ul>
<hr>
<h2>👥 Contributors</h2>
<h3>Core</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a></strong> — 179 PRs</li>
</ul>
<h3>Top Community Contributors</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a></strong> (7 PRs) — p5js creative coding skill, manim-video skill + 5 reference expansions, research-paper-writing, Nous OAuth fix, manim font fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a></strong> (3 PRs) — Firecrawl cloud browser provider, test re-architecture + CI fixes, Nix flake fixes</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a></strong> (2 PRs) — Browser Use managed provider switch, Nous portal base URL fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharlieKerfoot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharlieKerfoot">@CharlieKerfoot</a></strong> (2 PRs) — macOS portable base64 encoding, thread-safe PairingStore</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WAXLYY/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WAXLYY">@WAXLYY</a></strong> (2 PRs) — send_message secret redaction, gateway media URL sanitization</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MadKangYu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MadKangYu">@MadKangYu</a></strong> (2 PRs) — Telegram log noise reduction, context compaction fix for temperature-restricted models</li>
</ul>
<h3>All Contributors</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/auspic7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/auspic7">@auspic7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharlieKerfoot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharlieKerfoot">@CharlieKerfoot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GratefulDave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GratefulDave">@GratefulDave</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leotrs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leotrs">@leotrs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lumethegreat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lumethegreat">@lumethegreat</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MadKangYu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MadKangYu">@MadKangYu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nericervin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nericervin">@nericervin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryanautomated/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryanautomated">@ryanautomated</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/techguysimon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/techguysimon">@techguysimon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tymrtn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tymrtn">@tymrtn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vasanthdev2004/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vasanthdev2004">@Vasanthdev2004</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WAXLYY/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WAXLYY">@WAXLYY</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xinbenlv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xinbenlv">@xinbenlv</a></p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.4.3...v2026.4.8">v2026.4.3...v2026.4.8</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v8.27.2]]></title>
<description><![CDATA[Changelog

c7acf33 Merge branch 'master' of github.com:gitleaks/gitleaks
9faaa4a Add experimental allowlist optimizations (#1731)
79068b3 Detect Notion Public API Keys #1889 (#1890)]]></description>
<link>https://tsecurity.de/de/3487979/it-security-tools/v8272/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487979/it-security-tools/v8272/</guid>
<pubDate>Tue, 05 May 2026 02:33:25 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Changelog</h2>
<ul>
<li><a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gitleaks/gitleaks/commit/c7acf33d962e8effc070072f993c365af19e3661/hovercard" href="https://github.com/gitleaks/gitleaks/commit/c7acf33d962e8effc070072f993c365af19e3661"><tt>c7acf33</tt></a> Merge branch 'master' of github.com:gitleaks/gitleaks</li>
<li><a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gitleaks/gitleaks/commit/9faaa4a09c44dec3e4e85ff9f1e45acf757042f5/hovercard" href="https://github.com/gitleaks/gitleaks/commit/9faaa4a09c44dec3e4e85ff9f1e45acf757042f5"><tt>9faaa4a</tt></a> Add experimental allowlist optimizations (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2811834895" data-permission-text="Title is private" data-url="https://github.com/gitleaks/gitleaks/issues/1731" data-hovercard-type="pull_request" data-hovercard-url="/gitleaks/gitleaks/pull/1731/hovercard" href="https://github.com/gitleaks/gitleaks/pull/1731">#1731</a>)</li>
<li><a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gitleaks/gitleaks/commit/79068b35e597e5fb32d68a72e3116ce624f9ad29/hovercard" href="https://github.com/gitleaks/gitleaks/commit/79068b35e597e5fb32d68a72e3116ce624f9ad29"><tt>79068b3</tt></a> Detect Notion Public API Keys <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3122933340" data-permission-text="Title is private" data-url="https://github.com/gitleaks/gitleaks/issues/1889" data-hovercard-type="issue" data-hovercard-url="/gitleaks/gitleaks/issues/1889/hovercard" href="https://github.com/gitleaks/gitleaks/issues/1889">#1889</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3122936798" data-permission-text="Title is private" data-url="https://github.com/gitleaks/gitleaks/issues/1890" data-hovercard-type="pull_request" data-hovercard-url="/gitleaks/gitleaks/pull/1890/hovercard" href="https://github.com/gitleaks/gitleaks/pull/1890">#1890</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond the hype: The enterprise AI architecture we actually need]]></title>
<description><![CDATA[My last few years working as a chief digital officer have been, in large part, a sustained exercise in separating what enterprise AI can actually do from what we as a world insist it is about to do. That distinction is not academic. It is the difference between a transformation program that deliv...]]></description>
<link>https://tsecurity.de/de/3485839/it-security-nachrichten/beyond-the-hype-the-enterprise-ai-architecture-we-actually-need/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3485839/it-security-nachrichten/beyond-the-hype-the-enterprise-ai-architecture-we-actually-need/</guid>
<pubDate>Mon, 04 May 2026 13:07:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>My last few years working as a chief digital officer have been, in large part, a sustained exercise in separating what enterprise AI can actually do from what we as a world insist it is about to do. That distinction is not academic. It is the difference between a transformation program that delivers and one that produces a glossy internal report and a quietly shelved proof of concept.</p>



<p>Enterprise experimentation with generative AI has accelerated sharply over the past two years. The <a href="https://aiindex.stanford.edu/" rel="nofollow">Stanford AI Index</a>  reports that more than half of organizations globally are now actively exploring or piloting AI-driven workflows — a signal that the conversation has moved from curiosity to operational pressure for many CIOs.</p>



<p>What follows is not a vendor blueprint or prediction. It is a working architectural sketch shaped by real enterprise constraints — the kind that has to survive contact with a real organization’s data governance function, its compliance team and its late-night incident queue.</p>



<p>What I think the mature enterprise AI stack will look like is considerably more federated, more layered and more interesting than most current commentary suggests.</p>



<p>The enterprise AI of the near future will not be a single platform that does everything. It will most likely be a federation — sovereign agents at the base, curated data in the middle and orchestrated intelligence at the top.</p>



<h2 class="wp-block-heading">A stack built in layers</h2>



<p>The starting point is accepting that the major systems of record are not going anywhere.</p>



<h3 class="wp-block-heading">Native AI</h3>



<p>Enterprise platforms like SAP, Salesforce, Workday and ServiceNow hold the most governed and contextually rich data in any large organization, and they are increasingly developing their own native AI capabilities embedded directly within their platforms.</p>



<p>SAP’s recently introduced <a href="https://news.sap.com/2023/09/sap-joule-generative-ai-copilot/" rel="nofollow">Joule AI copilot</a>, for example, signals a direction rather than a finished product: Platform-native AI that understands the semantics of the data it sits on and can answer questions that only someone with full schema access and transactional history could answer — without that data ever leaving the platform boundary.</p>



<p>These systems already understand the enterprise in ways no external AI system easily can.</p>



<h3 class="wp-block-heading">Sovereign private AI</h3>



<p>Alongside the native AI sits a different challenge: The long tail of bespoke platforms, industry-specific tools and internal knowledge repositories that no major vendor may ever be able to natively address.</p>



<p>In my experience, sovereign hosted private AI is the most credible answer here — open-source models such as Llama or Mistral, self-hosted within the organization’s own infrastructure and fine-tuned on internal documents and processes. This creates an AI that knows what the organization actually knows, can be interrogated about its provenance and can be shown to a regulator without a conversation about third-party data processing agreements.</p>



<p>For many regulated industries, this sovereignty over data and model behavior will be a defining architectural principle rather than a technical preference.</p>



<h3 class="wp-block-heading">The data lake </h3>



<p>Between the base systems and the intelligence layer above them sits the data lake — modern data platforms such as Microsoft Fabric, Databricks, Snowflake or their equivalents — fed by governed data pipelines from those base systems. It is worth being precise about what this layer is — and what it is not. It is not a data swamp. It is a curated, semantically enriched, access-controlled repository that reflects the enterprise’s data as a coherent whole across ERP, CRM, HR and others.</p>



<p>The quality of everything above it depends entirely on what flows into it.</p>



<p>This is unglamorous work. It is also the work that most AI transformation programs underinvest in, and the principal reason most of them underdeliver.</p>



<h3 class="wp-block-heading">AI-powered analytics</h3>



<p>The analytics layer — powered by likes of  Power BI, Tableau and their successors — sits on top of this data lake, and this is where the most visible change is already underway. The next generation of these platforms will retain the visualization capabilities that business users depend on but will layer a prompt interface and an AI orchestration engine above the data.</p>



<p>A finance analyst asking why gross margin compressed in a particular quarter will trigger not just a query against the data lake, but a federated call — via MCP-based agent-to-agent protocols — to the ERP’s native AI, the CRM’s revenue intelligence and the procurement system’s spend analyser, each responding within their own security perimeter, with results synthesised at the analytics layer. Mostly read and query – deliberately passive.</p>



<h3 class="wp-block-heading">The orchestration</h3>



<p>The agentic orchestration layer is where AI moves from observation to action, and where governance cannot be an afterthought. This architecture places human oversight at three levels:</p>



<ul class="wp-block-list">
<li><strong>Human-on-the-loop</strong> for autonomous but fully logged agent actions</li>



<li><strong>Human-in-the-loop</strong> for high-value or irreversible decisions requiring explicit approval</li>



<li><strong>Human-over-the-loop</strong> for policy-level definitions of what agents may and may not do</li>
</ul>



<p>Every inter-agent call is traceable, every action timestamped and auditable.</p>



<p><a href="https://artificialintelligenceact.eu/" rel="nofollow">The EU AI Act</a> and sector-specific regulators in financial services and healthcare will make this level of observability non-negotiable within the next couple of years. I have found it considerably easier to build in from the start than to retrofit under regulatory pressure.</p>



<p>Together, these layers form the internal architecture of the enterprise AI stack — systems of record at the base, data consolidation in the middle, analytics above and agent orchestration governing action.</p>



<h2 class="wp-block-heading">The missing pieces</h2>



<p>The five-layer model above is, in one sense, a description of mostly internal infrastructure. But there are two additional structural elements I keep returning to — conspicuously absent from most current enterprise AI discourse.</p>



<h3 class="wp-block-heading">The marketplace</h3>



<p>The first is a public marketplace of AI agents underpinned by a blockchain trust layer. When an organization wants to deploy a specialist external agent — one trained to validate material master pricing against live market indices, cross-reference technical specifications against supplier catalogues or propagate regulatory amendments to internal master data — the current model requires trusting the vendor’s claims about what the agent does.</p>



<p>A blockchain-based identity and audit layer changes that. The agent’s provenance, version history and audit trail across prior deployments live on a distributed ledger: Immutable and inspectable. Smart contracts define precisely which systems it may query, what data it may read or write, and under what conditions it must escalate to a human.</p>



<p>This is the agentic equivalent of what open APIs did for data exchange, but with governance built into the protocol rather than bolted on afterwards. Projects exploring this direction — including <a href="https://fetch.ai/" rel="nofollow">Fetch.ai’s autonomous agent network</a> and emerging work around the W3C Verifiable Credentials applied to AI systems — are early signals of where enterprise compliance functions may eventually arrive.</p>



<p>An agent without a verifiable identity is a vendor promise. An agent on a trust ledger is an auditable fact.</p>



<h3 class="wp-block-heading">The employee intelligence layer</h3>



<p>The second missing piece is what I think of as the employee intelligence layer — the interface through which all of this infrastructure actually reaches the person who joined the organization to do a job, not to understand data topology.</p>



<p>What this needs to be is a single workspace that blends the channel-based collaboration model like those offered by platforms such as Slack with the structured project logic available in the likes of Notion, but with AI built into its core rather than added as a feature. A supply chain coordinator should be able to ask, in plain language, for the status of all open purchase orders for a given vendor and receive an answer synthesised from the ERP’s native AI — without navigating a single SAP transaction code.</p>



<p>An HR business partner should be able to retrieve aggregated headcount and attrition data from an enterprise HRMS such as SuccessFactors, annotated with context from their own team’s channel history, without opening a separate analytics tool.</p>



<p>Progress and accountability belong in the same environment where work actually happens — not in a separate project management application that everyone updates for the quarterly review and ignores the rest of the time. The AI in this layer notices when a commitment is overdue, surfaces the relevant context and suggests an appropriate next action rather than simply turning a status indicator red.</p>



<p>Embedded within each person’s workspace, configured to their role and responsibilities, are the analytics dashboards that actually matter to their decisions — query able in natural language when the chart does not answer the question they have.</p>



<p>Get the employee intelligence layer right and the individual has genuine access to the collective intelligence of the organization. Get it wrong and the stack above becomes expensive infrastructure that the people it was built for have quietly routed around.</p>



<h2 class="wp-block-heading">Implications for technology leaders</h2>



<p>I am aware that describing a multi-layer federated AI architecture is considerably easier than implementing one. A few things I have learned in practice that seem worth naming directly. The data governance work is not a precondition of the AI work — it is the AI work. The sophistication of any intelligence layer is bounded entirely by the quality, structure and semantic richness of what flows into it.</p>



<p>Organizations that treat the data lake as an IT project and AI as the real transformation misunderstand the sequence. They are the same project, and the data half is harder. The governance of agentic systems requires a different mental model from the governance of conventional software. When a traditional application does something unexpected, there is usually a code path to trace. When an AI agent takes an unexpected action in a multi-agent system, the failure mode is emergent and the audit trail may be distributed across several systems.</p>



<p>The observability infrastructure — the kind used to monitor complex distributed systems, applied to agent networks — is not optional instrumentation. It is the operating licence. I have come to treat it as a first-class architectural concern rather than something to add once the system is stable, because in my experience the system is never stable in the way that phrase implies.</p>



<p>And finally: The enterprise does not need to be rebuilt around AI. It needs to have AI built into it — carefully, layer by layer, with someone accountable at every level.</p>



<p>The platforms that will win in this environment are not necessarily those with the most impressive pilots. They are the ones that play well with others, expose clean interfaces for inter-agent communication, maintain rigorous audit trails and allow the enterprise to remain sovereign over its own intelligence.</p>



<p>The AI future of the enterprise is federated, governed and — when it works properly — invisible. Which is, when you think about it, precisely what good infrastructure has always been.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your work apps are quietly handing 19 data points to someone]]></title>
<description><![CDATA[Office work in 2026 runs through a stack of mobile apps that sit on the same phones people use for banking, messaging family, and tracking their location. Ten of the most common workplace apps in use across U.S. companies, including Gmail, Microsoft Teams, Zoom Workplace, Slack, and Notion, accou...]]></description>
<link>https://tsecurity.de/de/3484885/it-security-nachrichten/your-work-apps-are-quietly-handing-19-data-points-to-someone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3484885/it-security-nachrichten/your-work-apps-are-quietly-handing-19-data-points-to-someone/</guid>
<pubDate>Mon, 04 May 2026 06:06:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Office work in 2026 runs through a stack of mobile apps that sit on the same phones people use for banking, messaging family, and tracking their location. Ten of the most common workplace apps in use across U.S. companies, including Gmail, Microsoft Teams, Zoom Workplace, Slack, and Notion, account for more than 12.5 billion downloads on Google Play. New research from Incogni, based on data pulled from the Google Play Store on March 20, 2026, … <a href="https://www.helpnetsecurity.com/2026/05/04/workplace-apps-data-collection-privacy/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/05/04/workplace-apps-data-collection-privacy/">Your work apps are quietly handing 19 data points to someone</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[25 great uses for an old Android device]]></title>
<description><![CDATA[Got extra smartphones sitting around your office? How about tablets? As we move multiple generations into mobile technology, more and more of us are building up collections of old, dated devices from both our work and our personal lives. And more often than not, those devices do little more than ...]]></description>
<link>https://tsecurity.de/de/3480035/it-nachrichten/25-great-uses-for-an-old-android-device/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480035/it-nachrichten/25-great-uses-for-an-old-android-device/</guid>
<pubDate>Fri, 01 May 2026 12:02:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Got extra smartphones sitting around your office? How about tablets? As we move multiple generations into mobile technology, more and more of us are building up collections of old, dated devices from both our work and our personal lives. And more often than not, those devices do little more than take up space and gather dust.</p>



<p>Here’s a little secret, though: Your abandoned Android gadgets are actually virtual gold mines. You just have to find the right way to tap into their potential and give them new life.</p>



<p>So grab the nearest DustBuster and get ready: Here are 25 ways to make your old phone or tablet useful again.</p>



<h3 class="wp-block-heading">1. Create a no-cost Wi-Fi extender</h3>



<p>If you struggle with poor Wi-Fi coverage in particular areas of your home, office, and/or home office (hello, my fellow converted garage dwellers!), a random old Android device can serve as a surprisingly effective extender for your internet signal — in the same way that a dedicated Wi-Fi extender or repeater appliance could.</p>



<p>Few folks realize it, but the <a href="https://www.computerworld.com/article/1536443/how-to-use-a-smartphone-as-a-mobile-hotspot.html">hotspot option built into Android</a> works not only with mobile data — the way most of us use it with a current, active Android device — but also with any Wi-Fi network associated with the device. That means your old Android gizmo can take the signal it’s receiving from a router and broadcast it further, almost as if it were a point in a mesh networking system like <a href="https://www.computerworld.com/article/1662186/eero-wifi-google.html" target="_blank">Eero</a> or <a href="https://www.androidauthority.com/google-nest-wifi-review-1051816/" target="_blank" rel="noreferrer noopener">Nest Wifi</a> (only without quite as elegant or simple of a setup — but hey, this approach is completely free!). It’s an interesting advantage that Apple devices notably <em>don’t </em>offer.</p>



<p>The key is to find a place for the phone where it’s close enough to a router to be seeing a reasonably strong Wi-Fi signal and close enough to your dead zone that it can extend the signal further in that direction, while still being plugged in to have consistent power. You may have to experiment to figure out what exact positioning works best.</p>



<p>Once you have the device in the right spot, though, all that’s left is to find the hotspot option within its settings and get it configured correctly. The precise placement of the option may vary depending on the device’s software, but you’ll usually want to look within a Network &amp; Internet section of the system settings (or whatever closest equivalent you find), then look for a “Hotspot” or “Hotspot &amp; Tethering” subsection within that area.</p>



<p>Tap the option for “Wi-Fi Hotspot” there, and you should be able to configure the name and password of the network the phone will generate — using your existing Wi-Fi network as its backbone. If there’s an option to turn the hotspot off automatically anytime no other devices are connected, you’ll probably want to disable that. And if you see an option for setting the network to be 2.4GHz or 5GHz, you’ll likely want to enable both of those paths.</p>



<p>Then, just flip the switch to start your hotspot — and that’s it: Your extended network is officially up and running.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/old-android-devices-wi-fi-hotspot.jpg?quality=50&amp;strip=all&amp;w=1024" alt="wi-fi hotspot screen in android" class="wp-image-4157361" width="1024" height="781" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Android’s Wi-Fi hotspot setup, in action — a feat iPhones won’t allow.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>Now, just go into the part of your building where Wi-Fi wasn’t great and try connecting to your <em>phone’s</em> network instead of the standard Wi-Fi network. If your positioning worked, the signal should be noticeably stronger — and your connection should be noticeably faster as a result.</p>



<h3 class="wp-block-heading">2. Use it as a wireless trackpad and controller for your computer</h3>



<p>With the right software and a couple minutes of configuration, your old Android device can act as an on-demand controller for your Windows, Mac, or Linux computer.</p>



<p>An app called Unified Remote and a Wi-Fi or Bluetooth connection are all you need to make the magic happen. The <a href="https://play.google.com/store/apps/details?id=com.Relmtech.Remote&amp;rdid=com.Relmtech.Remote" target="_blank" rel="nofollow noopener">free version</a> of the app gives you basic mouse and keyboard control along with specialized remotes for media playback and power-related commands, while the <a href="https://play.google.com/store/apps/details?id=com.Relmtech.RemotePaid" target="_blank" rel="nofollow noopener">full $5 version</a> adds in program-specific remotes for presentation control along with other advanced features.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>Unified Remote provides basic mouse and keyboard control along with a variety of specialized remotes.</p></figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>Grab whichever version you prefer and <a href="https://www.unifiedremote.com/" rel="nofollow noopener" target="_blank">download the server-side software</a> for your computer — then toss your old device into a desk drawer or computer bag and rest easy knowing it’ll be ready and waiting the next time you need to go wireless.</p>



<h3 class="wp-block-heading">3. Turn it into a remote computer terminal</h3>



<p>Want easy access to your home computer from the office — or vice-versa? Your old Android phone or tablet can be a splendid stationary screen for keeping a remote system at arm’s reach.</p>



<p>And it couldn’t be any easier to make that happen. All you need is Google’s free <a href="https://www.computerworld.com/article/1713548/chrome-remote-desktop-access-remote-computer-easily.html">Chrome Remote Desktop</a> program on both your computer and your old Android device, and your phone or tablet will effectively become a window to your desktop.</p>



<p>I’ve got <a href="https://www.computerworld.com/article/1713548/chrome-remote-desktop-access-remote-computer-easily.html#:~:text=Using%20Chrome%20Remote%20Desktop%20to%20access%20your%20own%20computer">a thorough guide to the Chrome Remote Desktop setup process</a>, if you want step-by-step instructions — but the short version is that you’ll need to install the <a href="https://chromewebstore.google.com/detail/chrome-remote-desktop/inomeogfingihgjfjlpeplalcfajhgai" target="_blank" rel="noreferrer noopener">official Google Chrome Remote Desktop extension</a> into Chrome on your computer, then open the <a href="https://remotedesktop.google.com/" target="_blank" rel="noreferrer noopener">Chrome Remote Desktop website</a> and follow the prompts to set up remote access.</p>



<p>Snag the companion <a href="https://play.google.com/store/apps/details?id=com.google.chromeremotedesktop&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Remote Desktop Android app</a>, get all signed in there, and that’s it: Your old Android device is now a full-fledged terminal and access point for any computer you want.</p>



<h3 class="wp-block-heading">4. Make it a portable storage device</h3>



<p>Cloud services may often be the simplest way to store and transport files nowadays, but there’s something to be said for good old-fashioned <em>physical</em> storage — both in terms of consistent availability regardless of connectivity and in terms of the added assurances having especially important files in your own pocket can provide.</p>



<p>While there’s certainly no shortage of high-quality portable thumb drives and external hard drives available, any old Android device is essentially the same thing — with the added advantage of <em>also</em> offering up an easy interface for interacting with anything on its local storage and optionally dropping such files into an email, a Slack chat, or any other cloud-connected spot should the need ever arise.</p>



<p>Just <a href="https://www.computerworld.com/article/1715316/how-to-securely-erase-your-android-device-in-4-steps.html">securely erase your Android device</a> to give it a fresh start and free up as much space as possible, then plug it into your computer to <a href="https://www.computerworld.com/article/1711698/android-file-transfer-how-to-move-data-between-your-phone-and-computer.html">transfer files from the computer to the phone or tablet</a>.</p>



<p>You’ll have ample room for whatever you need to store, and you can easily carry it around or keep it somewhere safe — then connect it to another computer or rely on assorted <a href="https://www.computerworld.com/article/1718291/best-android-apps-for-business.html">Android business apps</a> for <a href="https://www.computerworld.com/article/1712337/android-file-management-an-easy-to-follow-guide.html">managing the files</a>, <a href="https://www.computerworld.com/article/1707648/best-email-and-texting-apps-for-android.html">emailing them</a>, <a href="https://www.computerworld.com/article/1612927/best-android-apps-team-collaboration.html">sharing them in collaborative environments</a>, or anything else that may come up.</p>



<h3 class="wp-block-heading">5. Reposition it as an AI-powered chatbot interface</h3>



<p><a href="https://www.computerworld.com/generative-ai/">Generative AI</a> systems are quickly becoming <a href="https://www.computerworld.com/article/1612395/how-generative-ai-will-drive-a-foundational-shift-in-your-company.html">critical tools for company productivity</a>, and an old Android device is the perfect vessel for creating a dedicated on-demand AI chatbot interaction station.</p>



<p>This one’s especially easy, too: Just install the <a href="https://play.google.com/store/apps/details?id=com.openai.chatgpt" target="_blank" rel="noreferrer noopener">ChatGPT Android app</a>, the <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.bard" target="_blank" rel="noreferrer noopener">Gemini Android app</a>, the <a href="https://play.google.com/store/apps/details?id=com.microsoft.copilot" target="_blank" rel="noreferrer noopener">Microsoft Copilot Android app</a>, or any other AI tool you use — then keep it front and center on your old device’s home screen.</p>



<p>In the case of Gemini, you can also <a href="https://support.google.com/gemini/answer/14554984?hl=en&amp;co=GENIE.Platform%3DAndroid" target="_blank" rel="noreferrer noopener">opt in to allowing Gemini to take over the role</a> of your default system assistant and make it available via a <strong>Hey Google</strong> voice command.</p>



<p>And just like that, you’ve got a generative AI chatbot at your beck and call 24/7 without having to have it take over your current Android device and run down its battery.</p>



<h3 class="wp-block-heading">6. Give yourself a separate work and personal phone</h3>



<p>With more and more companies taking <a href="https://www.computerworld.com/article/1634750/with-byod-comes-responsibility-and-many-firms-arent-delivering.html">a bring-your-own-device approach</a> for the workplace, the lines between our personal and professional lives are getting increasingly blurry.</p>



<p>And while Android does have some decent options for creating separate work and personal profiles — both natively, if your phone is <a href="https://support.google.com/work/android/answer/6191949?hl=en" target="_blank" rel="noreferrer noopener">part of an enterprise-managed arrangement</a>, and with <a href="https://www.computerworld.com/article/1640838/how-to-better-separate-your-work-and-personal-life-on-android.html">a little creative configuring</a> in any other scenario — there’s an undeniable appeal in creating a <em>formal</em> barrier between your worlds and being able to leave your work completely behind when the opportunity arises.</p>



<p>So think about using your old Android device as a dedicated work or personal phone and setting it up <em>explicitly </em>for that purpose, then using your current Android phone exclusively for the other role. That’ll give you separate physical devices for your separate life roles — the kind of power most people only dream about seizing these days.</p>



<h3 class="wp-block-heading">7. Use it as a universal smart remote</h3>



<p>Even the junkiest old Android device has ample power to serve as a smart remote for your home or office. That can be a helpful way for you and anyone else around to control your various smart devices and multimedia components without needing any special access (or your own current personal phone in hand).</p>



<p>First, the easy part: Load up your old phone or tablet with all the relevant apps for your smart-device setup — things like <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.chromecast.app&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Google Home</a>, <a href="https://play.google.com/store/apps/details?id=com.philips.lighting.hue2" target="_blank" rel="noreferrer noopener">Hue</a>, and anything else appropriate for controlling your home or office tech.</p>



<p>Next, think about adding some tools that’ll let the device handle any audio and video systems in your area. There are a few ways you can make that work:</p>



<ul class="wp-block-list">
<li>Pair the phone or tablet with one of <a href="https://store.google.com/product/google_tv_streamer?hl=en-US" target="_blank" rel="noreferrer noopener">Google’s Streamer boxes</a> or, better yet, one of the company’s older, simpler, and far more affordable <a href="https://en.wikipedia.org/wiki/Chromecast" target="_blank" rel="noreferrer noopener">Chromecast dongles</a>, if you’ve still got one sitting around somewhere. You can then keep the old Android device on your desk or coffee table and use it as a hub for <a href="https://support.google.com/googlecast/answer/6102923?hl=en" target="_blank" rel="noreferrer noopener">wirelessly casting content</a> — everything from Netflix and YouTube to TED Talks, CNBC, and Google Slides — to your TV.</li>



<li>Use your device as a dedicated remote for your home or office entertainment setup. If the device is running an <a href="https://www.computerworld.com/article/1714347/android-versions-a-living-history-from-1-0-to-today.html">Android version</a> from 2012 or later, you can give yourself a ready-to-roll Google TV remote that’ll work with any compatible streaming products by installing and then signing into the official <a href="https://play.google.com/store/apps/details?id=com.google.android.videos&amp;hl=en_US&amp;gl=US" target="_blank" rel="noopener nofollow">Google TV app</a>. The Play Store also has a variety manufacturer-made apps for controlling specific components, including those by <a href="https://play.google.com/store/apps/details?id=com.att.android.uverse" target="_blank" rel="noopener nofollow">AT&amp;T U-verse</a> and <a href="https://play.google.com/store/apps/details?id=com.roku.remote" target="_blank" rel="noopener nofollow">Roku</a>.</li>



<li>Set up a full-fledged media server using <a href="https://www.plex.tv/" target="_blank" rel="noopener nofollow">Plex</a>, then use your old device as a dedicated remote to stream your own local content to a TV. (The Plex media server software is <a href="https://support.plex.tv/hc/en-us/articles/202526943-Plex-Free-vs-Paid" target="_blank" rel="noreferrer noopener">free</a>; a <a href="https://www.plex.tv/features/plex-pass/" target="_blank" rel="noreferrer noopener">premium subscription</a> with added features runs $7 per month, $70 per year, or $250 for a lifetime license.)</li>
</ul>



<h3 class="wp-block-heading">8. Transform it into a free-standing security camera</h3>



<p>Who needs a fancy-schmancy connected camera when you’ve got an old Android phone sitting around? With the aid of a third-party app, the camera on your dated device can let you keep an eye on your home, office, or top-secret crime lair from anywhere — and even perform advanced functions like video recording and motion detection.</p>



<p>Just download the free <a href="https://play.google.com/store/apps/details?id=com.pas.webcam" target="_blank" rel="nofollow noopener">IP Webcam</a> app or get the fully featured $5 <a href="https://play.google.com/store/apps/details?id=com.pas.webcam.pro" target="_blank" rel="nofollow noopener">pro version</a> and follow its instructions. Within moments, you’ll be able to peek through your device’s lens from any compatible web browser and cackle with glorious glee.</p>



<h3 class="wp-block-heading">9. Repurpose it as a dedicated camera</h3>



<p>Smartphone cameras just keep getting better, but we’re reaching a point where even cameras from a few years back are really quite good — and the differences between them and their more current siblings are relatively subtle.</p>



<p>With that in mind, an old Android device can be a perfect way to have a ready-to-roll camera at your disposal for times when you might not want your primary phone to be out and about on your adventures — whether you’re worried about it getting wet or damaged or maybe just trying to disconnect from the world of work-related dings and pings for a while.</p>



<p>The best part about this setup that is no special preparation is even required. Just grab the old phone and go, and rest easy knowing your “real” phone is safe and sound somewhere far away from whatever you’re photographing.</p>



<h3 class="wp-block-heading">10. Reframe it as a full-time videoconferencing station</h3>



<p>Set up your old Android device with the app for your video-chatting platform of choice — <a href="https://play.google.com/store/apps/details?id=us.zoom.videomeetings&amp;hl=en_US&amp;gl=US" target="_blank" rel="noopener nofollow">Zoom</a>, <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.tachyon" target="_blank" rel="noreferrer noopener nofollow">Google Meet</a>, <a href="https://play.google.com/store/apps/details?id=com.microsoft.teams&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Microsoft Teams</a>, or whatever the case may be — then drop it into a dock on your desk or conference room table. Say “hocus pocus” for good measure, and ta-da: You’ve just created a permanent access point for virtual face-to-face communications.</p>



<p>Just think: With enough old phones and tablets, you can create an entire house- or office-wide videoconferencing system. Sign each device into its own unique account, with the name of the room as its username, and seeing someone across the building will never be more than a couple quick taps away.</p>



<h3 class="wp-block-heading">11. Turn it into a kitchen command center</h3>



<p>Hard to believe, but my ancient 2011 <a href="https://www.computerworld.com/article/1491364/motorola-xoom-the-complete-faq.html">Motorola Xoom tablet</a> was one of the most used devices in my house until it finally kicked the bucket some six years into its life. That’s because I converted it into a multipurpose command center for our kitchen — a role my 2012 Nexus 10 tablet then took over for another couple years after that.</p>



<p>So how to make a kitchen command center of your own? Easy: First, use a <a href="https://www.computerworld.com/article/1723954/best-android-launchers-for-enhanced-efficiency.html">custom Android launcher</a> like <a href="https://play.google.com/store/apps/details?id=ginlemon.flowerfree&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Smart Launcher</a> or <a href="https://play.google.com/store/apps/details?id=bitpit.launcher" target="_blank" rel="noreferrer noopener">Niagara Launcher</a> to simplify your old tablet’s home screen and add in some easy-to-perform gestures — like double-tapping anywhere on the screen to launch Android’s voice search function for on-the-fly info-gathering and other hands-free commands, either <a href="https://www.computerworld.com/article/4007736/gemini-android.html">via Gemini</a> or <a href="https://www.computerworld.com/article/1716976/google-assistant-efficiency-tips-android.html">the old Google Assistant</a>, if your old Android device still has that present.</p>



<p>Second, populate the home screen with the right apps for the purpose. <a href="https://play.google.com/store/apps/details?id=com.netflix.mediaclient" target="_blank" rel="noreferrer noopener">Netflix</a> and <a href="https://play.google.com/store/search?q=streaming&amp;c=apps" target="_blank" rel="noreferrer noopener">other video-streaming services</a> will effectively turn your old tablet into a cooking-time television. <a href="https://play.google.com/store/search?q=recipes&amp;c=apps" target="_blank" rel="noreferrer noopener">Recipe apps</a> can also be useful, as can <a href="https://www.computerworld.com/article/1715006/best-note-taking-apps-for-android.html">Android note-taking apps</a> — like <a href="https://play.google.com/store/apps/details?id=com.google.android.keep" target="_blank" rel="noreferrer noopener">Google Keep</a>, <a href="https://play.google.com/store/apps/details?id=com.microsoft.office.onenote" target="_blank" rel="noreferrer noopener">Microsoft OneNote</a>, and <a href="https://notion.so/" target="_blank" rel="noreferrer noopener">Notion</a> — for quick viewing of personal recipes or editing of always-synced family-shared shopping lists.</p>



<p>If you really want to get wild, you can even <a href="https://www.computerworld.com/article/1628824/android-smart-display.html">set up a smart-display-like screensaver</a> that’ll turn your device into a customizable intelligent info center whenever you <em>aren’t </em>actively using it — kind of like what Google <a href="https://www.computerworld.com/article/1623592/pixel-tablet.html">has tried</a> (but thus far <a href="https://www.computerworld.com/article/1633102/google-pixel-tablet.html">mostly failed</a>) to accomplish with its not-so-old Pixel Tablet product.</p>



<h3 class="wp-block-heading">12. Make it a data-based extension of your current phone service</h3>



<p>If you use <a href="https://www.computerworld.com/article/1709767/google-fi-project-fi.html">Google Fi</a> (formerly known as Project Fi) for your current phone’s wireless service, take advantage of a little-known bonus feature: the ability to <a href="https://www.computerworld.com/article/1672328/project-fi-bonus-feature.html">get an extra SIM card</a> that’s connected to your account and able to provide data on any other device — without any superfluous fees.</p>



<p>All you’ve gotta do is order the card from <a href="https://fi.google.com/" rel="noopener nofollow" target="_blank">the Google Fi website</a>, pop it into an old phone (or a tablet, if you happen to have one with a SIM slot) — and bam: That device is instantly online and connected. You’ll pay only for whatever mobile data the device uses in any given month, at the same flat rate associated with your regular Fi plan, so it’s essentially just an extension of your primary phone.</p>



<p>That opens up <a href="https://www.computerworld.com/article/1710678/google-fi-features.html">plenty of interesting possibilities</a>: You could use your old device as a ready-to-go backup phone in case your regular one is ever missing, broken, or low on battery; you could use it as a dedicated hotspot to beam out mobile data access without <a href="https://www.computerworld.com/article/1657846/10-top-tips-for-saving-your-smartphones-battery.html">draining your primary phone’s battery</a>; or you could use it as an always-connected on-the-go slate for your kids (hello, airport video-streaming) without having to pay for an extra line of service.</p>



<h3 class="wp-block-heading">13. Make it your live window into the world</h3>



<p>Don’t have the greatest view from your desk? Let your old Android phone or tablet be your window to wild and exciting locales.</p>



<p>To get started, grab the <a href="https://play.google.com/store/apps/details?id=com.earthcam.webcams" target="_blank" rel="noopener nofollow">EarthCam Webcams app</a> from the Google Play Store. It’ll give you one-touch access to an impressive list of live streaming cameras around the world, from the hustle and bustle of New Orleans’ famous Bourbon Street to the swooshing serenity of Niagara Falls. Pull up any view you like, then tap the icon to go full-screen and gaze the day away. If you find yourself craving some variety, you can consider upgrading from the app’s free collection to a set of 175 live cameras for a one-time $5 fee.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>EarthCam lets you gaze down Niagara Falls — or a slew of other webcams around the world — for a break from the mundane.</p></figcaption></figure><p class="imageCredit">JR Raphael / IDG</p></div>



<p>You can find quite a few mobile-friendly live cameras on the web as well: Pull up your device’s browser and try out the <a href="https://zoo.sandiegozoo.org/live-cams" rel="noopener nofollow" target="_blank">San Diego Zoo’s assorted animal cams</a> — including a penguin cam, koala cam, and tiger cam, among other exotic views — or the <a href="https://www.montereybayaquarium.org/animals-and-exhibits/live-web-cams" rel="noopener nofollow" target="_blank">Monterey Bay Aquarium’s extensive underwater cams</a> for even more “aww”-inducing options.</p>



<h3 class="wp-block-heading">14. Convert it into a digital photo frame</h3>



<p>Ah, memories. Snag an inexpensive stand, plug your device into its charger, and turn it into a cloud-connected photo frame for your home or office.</p>



<p>If you use Google Photos, just open up the app, tap on any photo in your main library or within a specific album, and then tap the three-dot menu icon in the upper-right corner of the screen. Scroll horizontally along the menu that appears and select “Slideshow.” The app will cycle through your photos and give you plenty of memories to reflect upon whilst relaxing or taking care of business.</p>



<p>If your old Android phone is a Pixel, you can also set it on one of Google’s official Pixel Stands to start an ever-evolving Photos-linked slideshow showing any specific albums or even specific <em>people </em>you want.</p>



<h3 class="wp-block-heading">15. Use it as a dedicated e-reader</h3>



<p>Want a distraction-free reading environment for your next business trip or public transit commute? Load up your old Android device with only the apps you need for reading — <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.books" rel="nofollow noopener" target="_blank">Google Play Books</a>, <a href="https://play.google.com/store/apps/details?id=com.amazon.kindle" rel="nofollow noopener" target="_blank">Amazon Kindle</a>, <a href="https://play.google.com/store/apps/details?id=bn.ereader" rel="nofollow noopener" target="_blank">Nook</a>, or whatever tickles your text-ingesting fancy.</p>



<p>You can even borrow books from your local library: Check with your nearest branch for information on how to do it or download the free <a href="https://play.google.com/store/apps/details?id=com.overdrive.mobile.android.libby&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Libby</a> app, which is used by a variety of libraries, schools, and institutions.</p>



<p>Be sure to disable notifications from Gmail and other noisy apps — heck, even switch the device into airplane mode once you’ve downloaded the content you need — and you’ve got the equivalent of a dedicated e-reader without all the usual phone or tablet temptations.</p>



<h3 class="wp-block-heading">16. Transform it into a dedicated desk calendar</h3>



<p>Dock your old device on your desk and put it to work as your personal calendar. Google’s own <a href="https://play.google.com/store/apps/details?id=com.google.android.calendar" target="_blank" rel="noopener nofollow">Calendar app</a> can get the job done with plenty of productivity-oriented elements, or the free <a href="https://play.google.com/store/apps/details?id=com.digibites.calendar" target="_blank" rel="noopener nofollow">DigiCal Calendar Agenda app</a> will give you an even more graphical and customizable interface that’s perfectly suited for this purpose.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> loading="lazy" width="400px"&gt;<figcaption class="wp-element-caption"><p>The DigiCal app looks especially sharp in its landscape (horizontal) orientation.</p>
</figcaption></figure><p class="imageCredit">JR Raphael/IDG</p></div>



<p>DigiCal is free with an optional <a href="https://play.google.com/store/apps/details?id=com.digibites.calendarplus" target="_blank" rel="noreferrer noopener nofollow">$5.50 upgrade</a> for extra themes and customization options.</p>



<h3 class="wp-block-heading">17. Treat yourself to a dedicated audio player</h3>



<p>The idea of an iPod may seem amusingly antiquated at this point, but there’s something to the idea of having a dedicated device for the specific purpose of playing podcasts, music, or even just some manner of white noise.</p>



<p>By outsourcing that task to an old Android device, you can grant yourself the freedom to leave your current phone behind when you’re working out, doing something outside, or even just taking a break from business on the weekend — and eliminate the temptation to keep checking your inbox or looking at other work-related distractions.</p>



<p>You can also give yourself a great way to listen to audio while traveling without having to wear down your primary device battery during a long day of flights.</p>



<h3 class="wp-block-heading">18. Make it a mounted command center for a non-connected car</h3>



<p>Save yourself the hassle of futzing around with your current phone in your car by turning your old device into an always-available command center for a car that doesn’t have its own built-in equivalent.</p>



<p>Just find a decent car dock and mount the device somewhere safe. Be sure to plug it into your car’s power port and connect it to the stereo (via Bluetooth or a 3.5mm headphone jack). Then, either use your primary phone <a href="https://www.computerworld.com/article/1536443/how-to-use-a-smartphone-as-a-mobile-hotspot.html">as a hotspot</a> to keep it online or go the economical route and download any necessary music and <a href="https://support.google.com/maps/answer/6291838?co=GENIE.Platform%3DAndroid&amp;hl=en" rel="nofollow noopener" target="_blank">directions</a> before you hit the road, while you’re still connected to Wi-Fi.</p>



<p>All that’s left is to open up the Google Maps app and start a navigation, and you’ll be moving full-speed ahead with a simplified interface and ready-to-roll voice commands.</p>



<h3 class="wp-block-heading">19. Turn it into a kid-friendly learning tool</h3>



<p>Your old tablet may seem tired to you, but it’s still top-notch tech by toddler standards — so why not turn it into a fun and educational gadget for your kid?</p>



<p>On most reasonably recent tablets, you can find a native <a href="https://support.google.com/android/answer/2865483?hl=en&amp;visit_id=638509513695458493-2895938017&amp;rd=1" target="_blank" rel="noreferrer noopener nofollow">Restricted Profile feature</a> right within the operating system: Just head into the system settings, tap “Users” (or “Users &amp; accounts” and then “Users,” depending on your OS version), and then “Add user or profile.”</p>



<p>Select the option to add a restricted profile. You’ll be prompted to enable or disable access to each app installed on the tablet, allowing you to control exactly what processes your progeny will and won’t be able to use.</p>



<p>If your old device has Android 7.0 or higher (or Android 5.0, on a limited number of models), Google’s <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.kids.familylink" target="_blank" rel="noopener nofollow">Family Link program</a> can give you even more robust controls — including the abilities to set screen-time limits and receive weekly activity reports. You can learn more and sign up at the <a href="https://families.google/familylink/" data-type="link" data-id="https://families.google/familylink/" target="_blank" rel="noreferrer noopener nofollow">Family Link website</a>.</p>



<h3 class="wp-block-heading">20. Let it serve as a high-tech e-clock</h3>



<p>Time for something new? An old phone with a dock can make a snazzy customizable clock for your desk or nightstand. Google’s own <a href="https://play.google.com/store/apps/details?id=com.google.android.deskclock" rel="nofollow noopener" target="_blank">Clock</a> app is a great place to start, especially if you want to use the clock for alarms. Look for the “Screensaver” option in the Display section of your system settings to make it automatically activate anytime your device is plugged in.</p>



<h3 class="wp-block-heading">21. Convert it into a gaming device for your downtime</h3>



<p>Put down the briefcase and summon your inner Pac-Man: Silly as it may seem, your old Android device is a mini-arcade just waiting to be called into action. (Hey, we all need the occasional break from working, right?)</p>



<p>To complete your device’s Game-Boy-like transformation, just surf the Play Store for some games — you can even find emulators for console-level systems, if (ahem) you <a href="https://play.google.com/store/search?q=emulator&amp;c=apps" target="_blank" rel="noreferrer noopener">know where to look</a> — and then level up by grabbing a universal Android game controller like the ones you’ll <a href="https://www.amazon.com/s?k=moga+android+controller&amp;crid=WN73QGQ0JO3X&amp;sprefix=moga+android%2Caps%2C221&amp;ref=nb_sb_ss_fb_1_12_p13n-expert-pd-ops-ranker" target="_blank" rel="noreferrer noopener">find available on Amazon</a> or at other tech retailers.</p>



<h3 class="wp-block-heading">22. Keep it handy for emergencies</h3>



<p>Any cell phone can make emergency calls, even if it’s not connected to active service. Keep an old phone charged and in your car or travel bag; if something bad happens and your active phone is either dead or unavailable, you’ll still have a way to get through to 911.</p>



<h3 class="wp-block-heading">23. Turn it into your personal testing ground</h3>



<p>Android is a tinkerer’s dream. It typically doesn’t take too much sorcery to root, or gain system-level access to, an Android device — and once you’ve done that, you open up a whole new world of possibilities. You can install powerful root-only applications and even replace your device’s entire operating system with a custom ROM full of fresh features and advanced customization potential.</p>



<p>Anytime you start poking around under the hood, though, you risk screwing something up. And when the device in question is your primary phone or tablet, that can be a daunting gamble to take (especially since rooting a device usually violates its warranty).</p>



<p>That’s where an old phone or tablet can come into play. Put on your hacker’s hat and do a Google search for “root [your device name]” and then “[your device name] ROM.” There’s a huge community of Android enthusiasts out there, and you’ll almost certainly find some helpful user-generated guides to get yourself started.</p>



<h3 class="wp-block-heading">24. Sell it</h3>



<p>This one’s easy, right? After all, what’s old to you is new to someone else. You can go the regular route and list your device on Craigslist or eBay — or you can check in with a more niche service like <a href="https://swappa.com/" target="_blank" rel="noopener nofollow">Swappa</a> or <a href="https://www.gazelle.com/" target="_blank" rel="noopener nofollow">Gazelle</a> to get an instant estimated price for your device. <a href="https://www.amazon.com/Amazon-Trade-In/b?ie=UTF8&amp;node=9187220011" target="_blank" rel="noopener nofollow">Amazon</a> and <a href="https://www.bestbuy.com/site/services/best-buy-trade-in/pcmcat133600050011.c?id=pcmcat133600050011&amp;DCMP=rdr101887" target="_blank" rel="noreferrer noopener nofollow">Best Buy</a> also both offer buyback programs that may be worth investigating.</p>



<p>Whatever you do, make sure you head into your device’s system settings and perform a full factory reset before passing anything along. You’ll probably also want to remove any memory cards you might have added, if your old phone or tablet has an external storage slot.</p>



<h3 class="wp-block-heading">25. Donate it</h3>



<p>Feeling philanthropic? Rest assured: There’s no shortage of organizations ready to put your old Android device in the hands of someone who could really use it.</p>



<p>A few possibilities worth considering:</p>



<ul class="wp-block-list">
<li><a href="https://medic.org/phone-donations/" target="_blank" rel="noreferrer noopener nofollow">Medic Mobile</a>: This nonprofit organization recycles old phones and tablets and then uses the proceeds to purchase new phones for health workers in Africa, Asia, and Latin America. The workers use those phones for things like tracking disease outbreaks and communicating in emergencies. You can print a prepaid shipping label on the <a href="https://www.recyclingfundraiser.com/UspsMedicMobile.aspx" target="_blank" rel="noopener nofollow">Medic Mobile website</a>.</li>



<li><a href="https://www.cellphonesforsoldiers.com/" target="_blank" rel="noopener nofollow">Cell Phones For Soldiers</a>: This nonprofit sends old phones along with free international calling service to troops serving overseas from all branches of the U.S. military. You can donate a device by finding a local drop-off point or requesting a mailing label.</li>



<li><a href="https://rfcx.org/" rel="noopener nofollow" target="_blank">Rainforest Connection</a>: This nonprofit utilizes old phones to protect threatened rainforests in Indonesia, Africa, and the Amazon. How? The devices are fitted with solar panels for energy as well as specialized software that uses their microphones to monitor for the sound of illegal chainsawing and then alert nearby rangers to the activity (<a href="https://www.newscientist.com/article/mg21829205.600-old-smartphones-called-in-to-save-indonesian-forests.html#.UsdB4_RDtv4" rel="noopener nofollow" target="_blank">yes, really!</a>). You can donate a device by <a href="https://rfcx.org/get_involved" rel="noopener nofollow" target="_blank">mailing it to the organization’s California headquarters</a>.</li>
</ul>



<p>So there you have it: 25 intriguing options for giving new life to your old device. Figure out which one best suits you — and send those gadget-dwelling dust bunnies packing.</p>



<p><em>This story was originally published in August 2014 and most recently updated in May 2026.</em></p>



<p>More Android tips:</p>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/1718177/android-settings-security.html">22 pro Android security settings you shouldn’t overlook</a></li>



<li><a href="https://www.computerworld.com/article/1612778/google-android-messages.html">18 tricks for more efficient Android messaging</a></li>



<li><a href="https://www.computerworld.com/article/1616932/android-clipboard-tricks.html">10 advanced Android clipboard tricks</a></li>



<li><a href="https://www.computerworld.com/article/1625588/android-quick-settings-tiles.html">11 Android Quick Settings additions that’ll supercharge your efficiency</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Logitech MX Creative Console: Microsoft Office, Notion und Slack integriert]]></title>
<description><![CDATA[Der Zubehörhersteller Logitech richtet sein MX-Ökosystem stärker auf Software-Erweiterungen aus und stellt eine Reihe neuer Plugins vor. Im Mittelpunkt steht die Idee, häufig genutzte Funktionen direkt über Eingabegeräte abrufbar zu machen, ohne zwischen Anwendungen wechseln zu müssen. Microsoft ...]]></description>
<link>https://tsecurity.de/de/3477229/ios-mac-os/logitech-mx-creative-console-microsoft-office-notion-und-slack-integriert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477229/ios-mac-os/logitech-mx-creative-console-microsoft-office-notion-und-slack-integriert/</guid>
<pubDate>Thu, 30 Apr 2026 12:39:11 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/logitech-erweitert-mx-system-geraetewechsel-und-neue-plugins-278917/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2026/04/mx-creative-console-logitechfeature-150x150.jpg" class="alignright tfe wp-post-image" alt="Mx Creative Console Logitechfeature" decoding="async"></a><p>Der Zubehörhersteller Logitech richtet sein MX-Ökosystem stärker auf Software-Erweiterungen aus und stellt eine Reihe neuer Plugins vor. Im Mittelpunkt steht die Idee, häufig genutzte Funktionen direkt über Eingabegeräte abrufbar zu machen, ohne zwischen Anwendungen wechseln zu müssen. Microsoft Office, Notion und Slack integriert Die neuen Erweiterungen unterstützen unter anderem Microsoft Office, Notion und Slack. In […]</p>
<p>The post <a href="https://www.ifun.de/logitech-erweitert-mx-system-geraetewechsel-und-neue-plugins-278917/">Logitech MX Creative Console: Microsoft Office, Notion und Slack integriert</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Plesk Obsidian 18.0.77 Is Here: Significant Accessibility Developments and New ACME SSL Support]]></title>
<description><![CDATA[We are excited to announce the latest release of Plesk Obsidian: v18.0.77. This update brings one of the most significant accessibility improvements in recent Plesk history, introduces native ACME protocol support with the new ACME SSL extension, adds support for the GoAccess web statistics tool,...]]></description>
<link>https://tsecurity.de/de/3474721/server/plesk-obsidian-18077-is-here-significant-accessibility-developments-and-new-acme-ssl-support/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474721/server/plesk-obsidian-18077-is-here-significant-accessibility-developments-and-new-acme-ssl-support/</guid>
<pubDate>Wed, 29 Apr 2026 16:00:23 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We are excited to announce the latest release of Plesk Obsidian: v18.0.77. This update brings one of the most significant accessibility improvements in recent Plesk history, introduces native ACME protocol support with the new ACME SSL extension, adds support for the GoAccess web statistics tool, and delivers a wide range of fixes, platform updates, and […]</p>
<p>The post <a href="https://www.plesk.com/blog/plesk-news-announcements/plesk-obsidian-18-0-77/" data-wpel-link="internal">Plesk Obsidian 18.0.77 Is Here: Significant Accessibility Developments and New ACME SSL Support</a> appeared first on <a href="https://www.plesk.com/" data-wpel-link="internal">Plesk</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android reminders, reinvented]]></title>
<description><![CDATA[Sometimes, the hardest part about getting stuff done is simply remembering what you have to do — and when.



And ironically, lots of the tools that exist to help us juggle our endless array of incoming tasks only seem to make it even more overwhelming. Truly, it doesn’t take much for the very ac...]]></description>
<link>https://tsecurity.de/de/3473983/it-nachrichten/android-reminders-reinvented/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473983/it-nachrichten/android-reminders-reinvented/</guid>
<pubDate>Wed, 29 Apr 2026 12:02:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Sometimes, the hardest part about getting stuff done is simply remembering what you have to do — and when.</p>



<p>And ironically, lots of the tools that exist to help us juggle our endless array of incoming tasks only seem to make it even <em>more </em>overwhelming. Truly, it doesn’t take much for the very act of managing your tasks — or maybe even just figuring out the best <em>way </em>to do it — to become a chore in and of itself.</p>



<p>Like many perpetually perplexed plebeians, I’ve exerted far too much energy on the impossible-seeming task of finding a system for <em>tracking </em>tasks that (a) actually works — and (b) doesn’t feel like a burden of its own. I’ve gone through more tasks and reminders systems than any sane person should ever encounter in a lifetime.</p>



<p>And lemme tell ya: At long last, I’ve encountered one that’s the perfect blend of simplicity and power.</p>



<p>It’s a brand new, off-the-beaten-path Android app you probably haven’t heard of but that absolutely should be on your radar. It’s both easier and more effective to use than most of the big-name tasks apps out there right now — and it <em>almost</em>, dare I say, even makes managing your to-dos enjoyable instead of exhausting.</p>



<p>Lemme show ya how it works.</p>



<p><strong>[Keep the knowledge coming with </strong><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong>my free Android Intelligence newsletter</strong></a><strong> — three new things to try every Friday and my Android Notification Power-Pack as a special welcome bonus!] </strong></p>



<h2 class="wp-block-heading"><strong>A new gold standard for Android reminders</strong></h2>



<p>My fellow memory-challenged marsupial, allow me to introduce you to the amusingly named <a href="https://www.thirdculture.app/ruff-reminders" target="_blank" rel="noreferrer noopener"><strong>Ruff Reminders</strong></a>.</p>



<p>Ruff Reminders is an Android-first creation that’s only been <a href="https://play.google.com/store/apps/details?id=ruff.reminders" target="_blank" rel="noreferrer noopener">in the Play Store</a> for a matter of hours now —  though I’ve had the opportunity to use it during its development for the past couple of months, as it’s progressed from a, well, <em>rough</em> framework into a polished and well-rounded place for storing all of your tasks both personal and professional and ensuring you never forget anything.</p>



<p>If the Ruff name sounds familiar, by the way, you might be thinking of the similarly themed <a href="https://play.google.com/store/apps/details?id=ruff.ruff&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Ruff Writing app</a> — which puts a simple scrolling scratchpad right on your home screen for on-the-fly thought storing. I’ve featured it as one of <a href="https://www.computerworld.com/article/1699499/must-have-android-widgets-for-busy-professionals.html">my must-have Android widgets</a> for some time now.</p>



<p>Ruff Reminders comes from the same source — an indie Android app developer named Bardi Golriz — and it exists as a perfect companion to its sibling’s scratchpad concept.</p>



<p>So let’s get into it: When you first open up Ruff Reminders, you’re greeted with a simple screen showing you the current day and a prompt to add any new reminders you need into the mix. The idea is that your focus belongs on the here and now — and starting with what you need to do <em>today</em> is the best way to actually get your tasks accomplished.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/android-reminders-app-ruff-reminders-today.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android reminders app: Ruff Reminders today" class="wp-image-4164526" width="1024" height="1015" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Ruff Reminders always starts you with a view of your tasks for the current day.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Creating a new task is as easy as tapping the “quick entry” prompt toward the top of the screen and typing. You can also use the plus icon in the lower-right corner of the screen for a more elaborate and detail-oriented task creation mechanism — and that’s where some of Ruff Reminders’ most impressive powers come into play.</p>



<p>To wit: For any task you create, you can schedule yourself a reminder for…</p>



<ul class="wp-block-list">
<li>A specific date and time</li>



<li>A <em>dynamic </em>date or time — as in every Monday, every weekend, the first day of each month, and so on</li>



<li>And (drumroll, please…) a specific <em>location </em>— if, say, you want to be reminded about something when you get to the office, when you get home, or maybe even when you walk into a particular store or business</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/android-reminders-app-ruff-reminders-new-reminder.png?w=1024" alt="Android reminders app: Ruff Reminders location reminders" class="wp-image-4164533" width="1024" height="929" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">You can set all sorts of different reminders, including ones based on your physical location.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>That last one in particular is a true treat to see. Like many Android-appreciating animals, I’ve been irked by Google’s ongoing retirement of location-based reminders all across the platform — first within the old Google Assistant system and then more recently within Google Keep as well. Ruff Reminders handily fills that void while offering a whole lot of other enticing extras that Assistant and Keep never provided.</p>



<p>For instance: For any location-based reminder, Ruff Reminders gives you the option to have a task pop up when you reach whatever location you specify either within a certain specific timeframe or anytime — and to have that reminder exist only once or as a recurring thing, <em>every</em> time you come or go from the location in question.</p>



<p>On that latter point, you can also set the reminder to trigger when you arrive at your chosen location <em>or</em> when you leave it — and you can choose exactly how wide of a radius the app uses to identify the spot — both of which add a whole other layer of flexibility and potential usefulness into the feature.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/android-reminders-app-ruff-reminders-location-reminder.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android reminders app: Ruff Reminders location reminder" class="wp-image-4164529" width="1024" height="907" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Ruff Reminders’ location reminders are especially versatile and powerful.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And all of <em>that</em> is still just the start.</p>



<h2 class="wp-block-heading"><strong>Remembering — and beyond</strong></h2>



<p>Once you have tasks created, Ruff Reminders really does work to make sure you remember ’em. In addition to setting all of your own preferred reminder patterns for each new task you create, you can tell the app to <em>always</em> nudge you about still-pending tasks for the present day at specific times as well as to keep “chasing” you with more prominent alarms — even <em>multiple</em> alarms, if you want — for items you haven’t finished.</p>



<p>All of those options exist within the dog-shaped Ruff icon in the lower-left corner of the screen:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="919" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Ruff’s “nudges” and “chases” add in even more flexibility and reliability with making sure you never forget anything important.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Once you’ve started a task, one tap on its line tells Ruff Reminders that it’s in progress and marks it accordingly. Another tap starts a full-screen timer (for any length you choose) to help you actually <em>focus </em>on the task. And pressing and <em>holding</em> the task marks it as finished.</p>



<p>You can also double-tap to reset an item’s status, if such a need ever arises.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/android-reminders-app-ruff-reminders-in-progress-timer.png?w=1024" alt="Android reminders app: Ruff Reminders in-progress, timer" class="wp-image-4164532" width="1024" height="1024" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Marking a task as in progress (left) exposes the option to begin a full-screen focus timer (right), if you want.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>If something <em>does</em> still manage to slip by without getting completed, it’ll move down to the app’s command bar, at the bottom of the screen — where it shows up inside a red box with the number of unfinished past tasks front and center.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/android-reminders-app-ruff-reminders-command-bar.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android reminders app: Ruff Reminders command bar" class="wp-image-4164525" width="1024" height="82" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">The Ruff Reminders command bar shows you how many missed tasks are still active and pending.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>You can always tap that box to revisit and reschedule any missed tasks — or you can find any past task via the app’s swipe-up-from-the-bottom search system. But even more helpful are the ongoing reminders the app will keep bringing front and center whenever you tell it to keep chasing you about any particular item.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/android-reminders-app-ruff-reminders-missed-task.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android reminders app: Ruff Reminders missed task" class="wp-image-4164527" width="1024" height="256" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Tapping the double up arrows on a missed task moves it right back into your current “today” view.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>What else? Let’s see — for any items you set as “ongoing,” Ruff will create a persistent notification so you can easily see what’s lingering on your list. And as you’d expect for any serious <a href="https://www.computerworld.com/article/1718291/must-have-android-apps-for-business.html">Android productivity app</a>, Ruff Reminders has a widget that lets you look at <em>all </em>your tasks for the current day and add new tasks right then and there, on your home screen, without ever having to open anything up.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/android-reminders-app-ruff-reminders-ongoing-notification-widget.png?w=1024" alt="Android reminders app: Ruff Reminders ongoing notification, widget" class="wp-image-4164530" width="1024" height="561" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Between Ruff Reminders’ persistent notification of ongoing tasks and its home screen widget showing today’s tasks, you’ve got no shortage of ways to keep important stuff front and center.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>For the true productivity-obsessed power-user nerds among us, Ruff Reminders also has a whole host of step-saving gestures built into its interface. Like all of the app’s more advanced options, you absolutely don’t <em>have</em> to mess with ’em if you don’t want to — but if you’re the type of person who likes learning shortcuts and flying around your phone with taps and swipes, you’ll be delighted by all the possibilities this unlocks. </p>



<p>The more you use it, the more thoughtful and useful little touches you keep discovering — again, if and <em>only </em>if you want to explore those types of options.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/android-reminders-app-ruff-reminders-gestures.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android reminders app: Ruff Reminders gestures" class="wp-image-4164531" width="1024" height="917" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Gestures galore await for the shortcut adorers among us.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>What’s most interesting to me about Ruff Reminders is the space it fills between the everything-style, intensive-need to-do apps out there — things like Todoist or even all-purpose productivity tools like Notion, which are great for the right type of purpose and person but can be overwhelming overkill for more casual task tracking — and the <em>super</em>-simple, at times <em>too</em>-limited apps like <a href="https://www.computerworld.com/article/1659766/google-keep-android-tips.html">Google Keep</a>, which are fine for basic info-dumping but lacking in more powerful task management and reminder magic.</p>



<p>Ruff Reminders manages to be both simple <em>and</em> effective — an often overlooked middle-ground for those of us who want to track tasks and remember stuff in a way that goes beyond the most barebones basic approach but that doesn’t require an entire intricate platform to do it.</p>



<p>Oh, and as far as privacy goes, Ruff Reminder’s <a href="https://www.thirdculture.app/ruff-reminders/privacy.html" target="_blank" rel="noreferrer noopener">policy</a> on that front is also refreshingly simple: It doesn’t collect or process any personally identifiable information. Period.</p>



<p>The app doesn’t have ads, either. Instead, it allows you to use its most fundamental setup for free and offers a paid subscription for its full set of features — three bucks a month or $20 per year, at the moment, with the latter price set to bump up to $30 after a while. (That pricing does also vary by country, so the rates will be slightly lower in certain parts of the world.)</p>



<p>For now, all <em>you’ve </em>gotta do is try it out and see if it works as well for you as it has been for me.</p>



<p>And if you need a helping hand to remind you, I know just the app to get the job done.</p>



<p><em>Increase your Android intelligence quotient with </em><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong><em>my free Android Intelligence newsletter</em></strong></a><em><strong> </strong>— three new things to try every Friday and my free Android Notification Power-Pack today.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fallout creator Tim Cain plans to make one last game after rejoining Xbox's Obsidian last year — "I think I am gonna make one more game before I retire again"]]></title>
<description><![CDATA[Tim Cain, co-creator of the Fallout series, believes he'll make one final game before retirement — and said this after returning to Xbox's Obsidian.]]></description>
<link>https://tsecurity.de/de/3472778/windows-tipps/fallout-creator-tim-cain-plans-to-make-one-last-game-after-rejoining-xboxs-obsidian-last-year-i-think-i-am-gonna-make-one-more-game-before-i-retire-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3472778/windows-tipps/fallout-creator-tim-cain-plans-to-make-one-last-game-after-rejoining-xboxs-obsidian-last-year-i-think-i-am-gonna-make-one-more-game-before-i-retire-again/</guid>
<pubDate>Wed, 29 Apr 2026 01:05:56 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tim Cain, co-creator of the Fallout series, believes he'll make one final game before retirement — and said this after returning to Xbox's Obsidian.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Introduces a Cheaper Option For App Store Subscriptions]]></title>
<description><![CDATA[Apple is adding a new App Store subscription option that lets developers offer lower monthly prices in exchange for a 12-month commitment. "This model will allow developers to offer discounted rates to customers in exchange for more predictable long-term revenue," reports TechCrunch. "This also c...]]></description>
<link>https://tsecurity.de/de/3472483/it-security-nachrichten/apple-introduces-a-cheaper-option-for-app-store-subscriptions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3472483/it-security-nachrichten/apple-introduces-a-cheaper-option-for-app-store-subscriptions/</guid>
<pubDate>Tue, 28 Apr 2026 22:05:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is adding a new App Store subscription option that lets developers offer lower monthly prices in exchange for a 12-month commitment. "This model will allow developers to offer discounted rates to customers in exchange for more predictable long-term revenue," reports TechCrunch. "This also caters to how many developers have already been marketing their annual subscriptions in their apps." From the report: Often, app developers will display the lower monthly price to highlight the discount the customer would receive if they purchase the annual subscription instead of the monthly option. If the user is on the fence about a longer-term commitment, the notion that they're getting a better deal can help to push them toward the annual option.
 
Now, Apple is essentially formalizing what these developers were already doing, which allows it to also craft a set of policies around how these subscription offers are to be displayed so as not to mislead customers about the true cost of the deals.
 
However, the option will not be available to developers in the United States or Singapore at launch. While Apple didn't offer an explanation for this, it's still in App Store litigation in the U.S. around the specifics of the court's ruling in its case with Epic Games around how Apple can charge for subscriptions. Apple likely doesn't want to complicate the matter further until that matter is finalized. Singapore, meanwhile, also has a sophisticated payments market with strong consumer rules, which is why it may have been left out of the initial release.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Apple+Introduces+a+Cheaper+Option+For+App+Store+Subscriptions%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F04%2F28%2F1913247%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F04%2F28%2F1913247%2Fapple-introduces-a-cheaper-option-for-app-store-subscriptions%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/04/28/1913247/apple-introduces-a-cheaper-option-for-app-store-subscriptions?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The front-end architecture trilemma: Reactivity vs. hypermedia vs. local-first apps]]></title>
<description><![CDATA[While the software development industry has been gorging on large language models (LLMs), the front-end ecosystem has quietly fractured into three competing but interrelated architectural paradigms. Between the dominance of reactive frameworks, the hypermedia-driven simplicity of true REST, and t...]]></description>
<link>https://tsecurity.de/de/3470575/ai-nachrichten/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470575/ai-nachrichten/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps/</guid>
<pubDate>Tue, 28 Apr 2026 11:17:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While the software development industry has been gorging on <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a> (LLMs), the front-end ecosystem has quietly fractured into three competing but interrelated architectural paradigms. Between the dominance of <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactive frameworks</a>, the <a href="https://www.infoworld.com/article/4150864/htmx-4-0-hypermedia-finds-a-new-gear.html">hypermedia-driven simplicity</a> of true REST, and the decentralized resilience of <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">SQL everywhere</a>, developers are no longer just choosing a library, they are choosing where the data lives: at the server, at the client, or both.</p>



<h2 class="wp-block-heading"><a></a>Three competing architectures, more or less</h2>



<p>Web developers are long familiar with <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">React</a> and the galaxy of similar reactive frameworks like <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">Angular, Vue, and Svelte</a>. For nearly a decade, these have dominated the narrative with their competition and co-inspiration. HTMX and hypermedia-driven applications have championed a return to the true RESTful thin client, alongside alternatives like Hotwire and Unpoly.</p>



<p>We could in a sense see reactivity and hypermedia as two opposing camps. Somewhere in between is the local-first SQL movement, which proposes putting SQL directly in the browser. The waters are a bit muddy because local SQL can and does work right alongside React.</p>



<p>It’s still safe to say that a reactive framework paired with a JSON API back end that talks to a datastore (SQL or otherwise) is still the de facto standard. But that monolithic story is starting to fracture in some very interesting ways.</p>



<h2 class="wp-block-heading"><a></a>Where the weight of the data lies</h2>



<p>Data of course is the central mass of web applications. Where it lives and how it moves produce the gravity around which everything else must revolve. Each of these architectures proposes to handle that gravity in its own way, with different benefits and tradeoffs.</p>



<p><strong>Hypermedia (e.g., HTMX):</strong> Keep the data largely off the client. The client is just a visual representation of the server data. The back-end “API” is responsible for producing the data-driven markup. Any kind of datastore can be used by the API server.</p>



<p><strong>React and friends:</strong> A sophisticated, stateful engine runs in the client, and the developer syncs that state with the back end via RESTful JSON API calls. The back-end server tends to be dumb, responsible largely for just invoking other services to provide business logic or data persistence.</p>



<p><strong>Local-first SQL: </strong>The data is distributed to the clients, like with React and friends, but in a much different way. Although the data is automatically synced directly to a datastore (like Postgres), the back-end API server is used only for specialized service calls—not for data persistence.</p>



<p>To summarize:</p>



<ul class="wp-block-list">
<li><strong>HTMX:</strong> Data gravity is at the server.</li>



<li><strong>React:</strong> Data gravity is split between the server and the client.</li>



<li><strong>Local-first:</strong> Data gravity is at the client.</li>
</ul>



<h2 class="wp-block-heading"><a></a>Comparing the approaches</h2>



<p>Besides the technical stats, the developer experience for each of these paradigms is quite different. However, while each paradigm feels different, they intersect in some interesting ways. Let’s take a closer look.</p>



<h3 class="wp-block-heading"><a></a>React and friends</h3>



<p><a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">Reactivity</a> is the world we have been working in for 15 years. We’ve got a whole universe of frameworks: <a href="https://react.dev/">React</a>, <a href="https://angular.dev/">Angular</a>, <a href="https://vuejs.org/">Vue</a>, <a href="https://svelte.dev/">Svelte</a>, <a href="https://www.solidjs.com/">Solid</a>, and full-stack variants like <a href="https://nextjs.org/">Next.js</a>, <a href="https://nuxt.com/">Nuxt</a>, <a href="https://svelte.dev/docs/kit/introduction">SvelteKit</a>, <a href="https://astro.build/">Astro</a>, etc. The beauty of these is in the <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">core reactive idea</a>. You have a state that consists of the variables and the UI is updated automatically. The UI is a pure function of state: <code>$UI = f(state)</code>.</p>



<p>The downside is the gradual, almost imperceptible <a href="https://www.infoworld.com/article/4145032/we-mistook-event-handling-for-architecture.html">layering of intense complexity</a> over the top of it all. This complexity seems at first just incidental, but it is in fact a direct outcome of the basic premise: building a state engine on the browser.</p>



<p>The result is you have <em>two </em>states: the browser and the database. The reactive engine becomes a negotiation layer. Add to that the various inherent complexities of managing the browser state, and the result is quite a lot for front-end developers to wrap their heads around.</p>



<p>In the effort to manage such complexity, wring more performance, and improve developer experience, we have wound up with quite a sprawling empire of tools and techniques. Even just for React we have <a href="https://react.dev/reference/rsc/server-components">React Server Components</a>, complex state-management libraries like <a href="https://redux.js.org/">Redux</a> or <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction">Zustand</a>, and orchestration layers like <a href="https://tanstack.com/query/latest">TanStack Query</a> for manual cache invalidation.</p>



<p>On the back end, we talk to <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON APIs</a> (or <a href="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html">GraphQL</a>), which can become unwieldy as a kind of boilerplate layer, but has in its favor an almost universal understanding.</p>



<h3 class="wp-block-heading">HTMX and similar (Hotwired, Unpoly)</h3>



<p><a href="https://www.infoworld.com/article/2334868/htmx-dynamic-html-without-the-javascript.html">HTMX</a> is like using HTML that has superpowers. You can do a huge amount of what you use reactive frameworks for, including all the AJAX and a lot of the partial rendering and effects, with just a few extra attributes sprinkled judiciously.</p>



<p>You spend a lot of time on the server, using a template engine like <a href="https://github.com/pugjs/pug">Pug</a>, <a href="https://www.thymeleaf.org/">Thymeleaf</a>, or <a href="https://github.com/Kotlin/kotlinx.html">Kotlin DSL</a>. These are where you bring together the data from the persistence service and combine it with markup. The markup you generate includes the HTMX attributes.</p>



<p>You tend to decompose the templates, i.e., break them up into dedicated chunks. The idea is you want to have a chunk that can be used within the larger UI to create the whole layout, along with the ability to use that chunk alone when (and if) it is called upon for an AJAX response.</p>



<p>Hypermedia with HTMX is a very powerful model. You are actually using REST, meaning you are transmitting a representational state.</p>



<p><a href="https://hotwired.dev/">Hotwire</a> and <a href="https://unpoly.com/">Unpoly</a> are similar libraries. In the case of Hotwire, you can achieve quite a bit of functionality and performance even without changing your HTML, just by using <a href="https://turbo.hotwired.dev/handbook/frames">Turbo Frames</a> to intercept link clicks and form submissions, automatically turning standard page navigation into partial DOM updates.</p>



<p>The beauty of the hypermedia approaches is that you gain a lot with a little. You are staying as much as possible in HTML, the very poster child of simplicity. On the other hand, you are giving up some of the sheer sophisticated power of reactive frameworks.</p>



<h3 class="wp-block-heading"><a></a>Local-first apps</h3>



<p>Local-first development is the new kid on the block. Like React and friends, local-first keeps the data in two places, but it does so in a radically different way. In its most essential form, it means running a database in the browser that is kept aligned with the remote datastore via a syncing engine. This kind of thing has been done before with <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a> databases like <a href="https://couchdb.apache.org/">CouchDB</a> or with the <a href="https://developer.mozilla.org/en-US/docs/Web/API/IndexedDB_API">IndexedDB API</a>, but the modern browser takes it to another level with a <a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">Wasm</a>-based database engine, like SQLite.</p>



<p>The user gets a small view of the full data, called a partial replication or a bucket (also called a “shape”). The front-end app interacts directly with that data, and the infrastructure automatically does the work of keeping everything synced. A big benefit here is strong offline support (because the client device is carrying around an actual database).</p>



<p>This is a massive departure from the request-response cycle. In local-first, you don’t fetch data; you subscribe to it. The network becomes a background daemon that reconciles local and remote state using CRDTs (conflict-free replicated data types). CRDTs ensure that if two users edit a task while offline, the merge is seamless rather than messy.</p>



<p>There is also a degree of simplification in using SQL everywhere, though that is offset by a rather unfamiliar and involved architectural setup. A syncing engine like <a href="https://www.powersync.com/">PowerSync</a> or <a href="https://electric-sql.com/">Electric SQL</a> is required, and it has a set of rules that must be maintained. Plus the auth and interaction between the database and the syncing engine must be configured.</p>



<p>Local-first eliminates both the API server and the HTML template server. It pushes the entire data negotiation layer into the automated syncing engine that runs off developer-defined rules.</p>



<p>Interestingly, local-first SQL can be used as a data driver for React (and other reactive engines) or plain vanilla HTML + JS. As such, it is an interesting alternative take on the architecture of the web, which is agnostic about the front end.</p>



<p>Perhaps the strangest arrangement to contemplate is using HTMX and local-first SQL together. This is like a mad scientist architecture, which of course means developers are doing it. In this setup, the back-end HTMX template engine is actually a service worker running the SQL engine. In theory, you get the simplicity of HTMX and the ultra-speed + offline functionality of local SQL. </p>



<h2 class="wp-block-heading"><a></a>Reactivity, hypermedia, or local-first? How to choose</h2>



<p>We remain in the era of the default choice being React plus a JSON API. From there you might experiment with innovative frameworks like <a href="https://www.infoworld.com/article/2265950/hands-on-with-svelte.html">Svelte</a> or <a href="https://www.infoworld.com/article/2271109/hands-on-with-the-solid-javascript-framework.html">Solid</a>. If you are looking for an ingenious way to leverage RESTful simplicity, HTMX or Hotwired are must-tries. Local-first SQL is an exotic animal, fit for the likes of <a href="https://linear.app/now/scaling-the-linear-sync-engine">Linear</a> or <a href="https://www.notion.com/blog/how-we-made-notion-available-offline">Notion</a> right now, but somewhat daring for most of us doing standard production work.</p>



<p>More broadly, the emergence of this trilemma signals the end of the “one true way” for web development. We are moving away from the library wars and into a world of architectural choice.</p>



<p>The choice between reactivity, hypermedia, and local-first isn’t just about code. It’s about where you want to place the data.</p>



<ul class="wp-block-list">
<li>If you want the data to be a server-side document, choose hypermedia.</li>



<li>If you want the data to be a shared memory state, choose reactivity.</li>



<li>If you want the data to be a distributed database, choose local-first.</li>
</ul>



<p>And of course, it is possible to put the approaches together to strive for a blend of the right benefits for your project.</p>



<p>As the JSON-over-the-wire monolith continues to fragment, the best architects won’t be the ones who know the most hooks or the most attributes. They will be the ones who understand the weight of their data and choose the architecture that lets the data move most freely. The framework wars are over, but the battle for the network has just begun. </p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[$300 Off the Pixel 10 Pro X Almost Gone]]></title>
<description><![CDATA[UPDATE APRIL 27: You can still get a Pixel 10 Pro XL for $300 off, but the time is running out. The $300 off deal from Amazon is down to just the Moonstone color with 256GB storage or Obsidian with 512GB storage. If you want one, you getter burry before it's gone...for a month. Amazon...
Read the...]]></description>
<link>https://tsecurity.de/de/3469292/it-nachrichten/300-off-the-pixel-10-pro-x-almost-gone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469292/it-nachrichten/300-off-the-pixel-10-pro-x-almost-gone/</guid>
<pubDate>Mon, 27 Apr 2026 21:46:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>UPDATE APRIL 27: You can still get a Pixel 10 Pro XL for $300 off, but the time is running out. The $300 off deal from Amazon is down to just the Moonstone color with 256GB storage or Obsidian with 512GB storage. If you want one, you getter burry before it's gone...for a month. Amazon...</p>
<p>Read the original post: <a href="https://www.droid-life.com/2026/04/27/300-off-the-pixel-10-pro-xl-is-very-good/">$300 Off the Pixel 10 Pro X Almost Gone</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RAG precision tuning can quietly cut retrieval accuracy by 40%, putting agentic pipelines at risk]]></title>
<description><![CDATA[Enterprise teams that fine-tune their RAG embedding models for better precision may be unintentionally degrading the retrieval quality those pipelines depend on, according to new research from Redis.The paper, "Training for Compositional Sensitivity Reduces Dense Retrieval Generalization," tested...]]></description>
<link>https://tsecurity.de/de/3468383/it-nachrichten/rag-precision-tuning-can-quietly-cut-retrieval-accuracy-by-40-putting-agentic-pipelines-at-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3468383/it-nachrichten/rag-precision-tuning-can-quietly-cut-retrieval-accuracy-by-40-putting-agentic-pipelines-at-risk/</guid>
<pubDate>Mon, 27 Apr 2026 16:02:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise teams that fine-tune their RAG embedding models for better precision may be unintentionally degrading the retrieval quality those pipelines depend on, according to new research from Redis.</p><p>The paper, "Training for Compositional Sensitivity Reduces Dense Retrieval Generalization," tested what happens when teams train embedding models for compositional sensitivity. That is the ability to catch sentences that look nearly identical but mean something different — "the dog bit the man" versus "the man bit the dog," or a negation flip that reverses a statement's meaning entirely. That training consistently broke dense retrieval generalization, how well a model retrieves correctly across broad topics and domains it wasn't specifically trained on. Performance dropped by 8 to 9 percent on smaller models and by 40 percent on a current mid-size embedding model teams are actively using in production.

The findings have direct implications for enterprise teams building agentic AI pipelines, where retrieval quality determines what context flows into an agent's reasoning chain. A retrieval error in a single-stage pipeline returns a wrong answer. The same error in an agentic pipeline can trigger a cascade of wrong actions downstream.</p><p>Srijith Rajamohan, AI Research Leader at Redis and one of the paper's authors, said the finding challenges a widespread assumption about how embedding-based retrieval actually works. </p><p>"There's this general notion that when you use semantic search or similar semantic similarity, we get correct intent. That's not necessarily true," Rajamohan told VentureBeat<i>.</i> "A close or high semantic similarity does not actually mean an exact intent."</p><h2>The geometry behind the retrieval tradeoff</h2><p>Embedding models work by compressing an entire sentence into a single point in a high-dimensional space, then finding the closest points to a query at retrieval time. That works well for broad topical matching — documents about similar subjects end up near each other. The problem is that two sentences with nearly identical words but opposite meanings also end up near each other, because the model is working from word content rather than structure.</p><p>That is what the research quantified. When teams fine-tune an embedding model to push structurally different sentences apart — teaching it that a negation flip which reverses a statement's meaning is not the same as the original — the model uses representational space it was previously using for broad topical recall. The two objectives compete for the same vector. 

The research also found the regression is not uniform across failure types. Negation and spatial flip errors improved measurably with structured training. Binding errors — where a model confuses which modifier applies to which word, such as which party a contract obligation falls on — barely moved. For enterprise teams, that means the precision problem is harder to fix in exactly the cases where getting it wrong has the most consequences.</p><p>The reason most teams don't catch it is that fine-tuning metrics measure the task being trained for, not what happens to general retrieval across unrelated topics. A model can show strong improvement on near-miss rejection during training while quietly regressing on the broader retrieval job it was hired to do. The regression only surfaces in production.</p><p>Rajamohan said the instinct most teams reach for — moving to a larger embedding model — does not address the underlying architecture. 

"You can't scale your way out of this," he said. "It's not a problem you can solve with more dimensions and more parameters."</p><h2>Why the standard alternatives all fall short</h2><p>The natural instinct when retrieval precision fails is to layer on additional approaches. The research tested several of them and found each fails in a different way.</p><p><b>Hybrid search.</b> Combining embedding-based retrieval with keyword search is already standard practice for closing precision gaps. But Rajamohan said keyword search cannot catch the failure mode this research identifies, because the problem is not missing words — it is misread structure.

 "If you have a sentence like 'Rome is closer than Paris' and another that says 'Paris is closer than Rome,' and you do an embedding retrieval followed by a text search, you're not going to be able to tell the difference," he said. "The same words exist in both sentences."</p><p><b>MaxSim reranking</b>. Some teams add a second scoring layer that compares individual query words against individual document words rather than relying on the single compressed vector. This approach, known as MaxSim or late interaction and used in systems like ColBERT, did improve relevance benchmark scores in the research. But it completely failed to reject structural near-misses, assigning them near-identity similarity scores. </p><p>The problem is that relevance and identity are different objectives. MaxSim is optimized for the former and blind to the latter. A team that adds MaxSim and sees benchmark improvement may be solving a different problem than the one they have.</p><p><b>Cross-encoders.</b> These work by feeding the query and candidate document into the model simultaneously, letting it compare every word against every word before making a decision. That full comparison is what makes them accurate — and what makes them too expensive to run at production scale. Rajamohan said his team investigated them. They work in the lab and break under real query volumes.</p><p><b>Contextual memory.</b> Also sometimes referred to as agentic memory, these systems are increasingly cited as the path beyond RAG, but Rajamohan said moving to that type of  architecture does not eliminate the structural retrieval problem. Those systems still depend on retrieval at query time, which means the same failure modes apply. The main difference is looser latency requirements, not a precision fix.</p><h2>The two-stage fix the research validated</h2><p>The common thread across every failed approach is the same: a single scoring mechanism trying to handle both recall and precision at once. The research validated a different architecture: stop trying to do both jobs with one vector, and assign each job to a dedicated stage.</p><p><b>Stage one: recall.</b> The first stage works exactly as standard dense retrieval does today — the embedding model compresses documents into vectors and retrieves the closest matches to a query. Nothing changes here. The goal is to cast a wide net and bring back a set of strong candidates quickly. Speed and breadth are what matter at this stage, not perfect precision.</p><p><b>Stage two: precision.</b> The second stage is where the fix lives. Rather than scoring candidates with a single similarity number, a small learned Transformer model examines the query and each candidate at the token level — comparing individual words against individual words to detect structural mismatches like negation flips or role reversals. This is the verification step the single-vector approach cannot perform.</p><p><b>The results.</b> Under end-to-end training, the Transformer verifier outperformed every other approach the research tested on structural near-miss rejection. It was the only approach that reliably caught the failure modes the single-vector system missed.</p><p><b>The tradeoff.</b> Adding a verification stage costs latency. The latency cost depends on how much verification a team runs. For precision-sensitive workloads like legal or accounting applications, full verification at every query is warranted. For general-purpose search, lighter verification may be sufficient. </p><p>The research grew out of a real production problem. Enterprise customers running semantic caching systems were getting fast but semantically incorrect responses back — the retrieval system was treating similar-sounding queries as identical even when their meaning differed. The two-stage architecture is Redis's proposed fix, with incorporation into its LangCache product on the roadmap but not yet available to customers.</p><h2>What this means for enterprise teams</h2><p>The research does not require enterprise teams to rebuild their retrieval pipelines from scratch. But it does ask them to pressure-test assumptions most teams have never examined — about what their embedding models are actually doing, which metrics are worth trusting and where the real precision gaps live in production.</p><p><b>Recognize the tradeoff before tuning around it.</b> Rajamohan said the first practical step is understanding the regression exists. He evaluates any LLM-based retrieval system on three criteria: correctness, completeness and usefulness. Correctness failures cascade directly into the other two, which means a retrieval system that scores well on relevance benchmarks but fails on structural near-misses is producing a false sense of production readiness.</p><p><b>RAG is not obsolete — but know what it can't do.</b> Rajamohan pushed back firmly on claims that RAG has been superseded. "That's a massive oversimplification," he said. "RAG is a very simple pipeline that can be productionized by almost anyone with very little lift." The research does not argue against RAG as an architecture. It argues against assuming a single-stage RAG pipeline with a fine-tuned embedding model is production-ready for precision-sensitive workloads.</p><p><b>The fix is real but not free.</b> For teams that do need higher precision, Rajamohan said the two-stage architecture is not a prohibitive implementation lift, but adding a verification stage costs latency. "It's a mitigation problem," he said. "Not something we can actually solve."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The DOJ is backing xAI in its lawsuit against Colorado]]></title>
<description><![CDATA[The Department of Justice has announced that it's intervening on the behalf of xAI in the company's recent lawsuit against the state of Colorado. xAI first filed the suit in early April in response to a recent Colorado law that requires developers of "high-risk" AI systems (for example, ones used...]]></description>
<link>https://tsecurity.de/de/3462619/it-nachrichten/the-doj-is-backing-xai-in-its-lawsuit-against-colorado/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3462619/it-nachrichten/the-doj-is-backing-xai-in-its-lawsuit-against-colorado/</guid>
<pubDate>Fri, 24 Apr 2026 22:16:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Department of Justice <a target="_blank" class="link" href="https://www.justice.gov/opa/pr/justice-department-intervenes-xai-lawsuit-challenging-colorados-algorithmic-discrimination" data-i13n="cpos:1;pos:1">has announced</a> that it's intervening on the behalf of xAI in the company's recent lawsuit against the state of Colorado. <a target="_blank" class="link" href="https://www.reuters.com/legal/government/elon-musks-xai-sues-colorado-over-states-new-ai-law-2026-04-09/" data-i13n="cpos:2;pos:1">xAI first filed the suit</a> in early April in response to <a target="_blank" class="link" href="https://leg.colorado.gov/bills/sb24-205" data-i13n="cpos:3;pos:1">a recent Colorado law</a> that requires developers of "high-risk" AI systems (for example, ones used in healthcare, employment or housing) to both disclose and mitigate the risk of algorithmic discrimination in their systems. The law is set to go into effect in June, and the DOJ is now asking a Colorado District Court to declare it unconstitutional.</p><p>In xAI's original argument, Colorado Bill SB24-205 violated the company's First Amendment rights by forcing its developers to change how they create AI products and compelling them to align their products with Colorado's views on diversity and discrimination. The DOJ acknowledges those concerns in <a target="_blank" class="link" href="https://www.justice.gov/crt/media/1437846/dl" data-i13n="cpos:4;pos:1">its complaint</a>, but specifically focuses its argument on the idea that the law violates the Equal Protection Clause of the Fourteenth Amendment.</p><p>According to the DOJ, because the law relies on demographics and "statistical disparities" as evidence of discrimination, it will essentially require developers to distort an AI system's outputs and "discriminate based on race, sex, religion and other protected characteristics," a violation of the Fourteenth Amendment. The department also positions Colorado's law as a risk to "the United States' position as the global AI leader," a title the current administration is committed to protecting. </p><p>As both an AI cheerleader and enabler, the Trump administration has been particularly sensitive to the notion of diversity, equity and inclusion being incorporated into AI. President Donald Trump signed several executive orders following the announcement of his <a target="_blank" class="link" href="https://www.engadget.com/ai/everyones-a-loser-in-trumps-ai-action-plan-160023247.html" data-i13n="cpos:5;pos:1">"AI Action Plan" in 2025</a> that specifically called for government agencies to use AI tools that avoid "ideological dogmas such as DEI." He also called <a target="_blank" class="link" href="https://www.engadget.com/ai/trump-orders-creation-of-litigation-task-force-to-challenge-state-ai-laws-022657022.html" data-i13n="cpos:6;pos:1">for the creation of a task force</a> that could challenge state AI regulation in favor of a federal regulatory framework for AI. The irony is that the DOJ's argument, and the administration's stance in general, are equally idealogical, just in a way that's ahistorical, and ignores the downstream effects of discrimination in the US.</p>This article originally appeared on Engadget at https://www.engadget.com/ai/the-doj-is-backing-xai-in-its-lawsuit-against-colorado-200500890.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Chaining SSRF and LFI to Achieve Root Access on a Major Telecom Server]]></title>
<description><![CDATA[After hitting a wall with standard testing, I returned to recon and discovered a critical SSRF + LFI chain leading to full root access.So the other day I was working on a target , a large telecommunications company. Everything on the surface seemed fine. I tested every endpoint but found nothing....]]></description>
<link>https://tsecurity.de/de/3460861/hacking/chaining-ssrf-and-lfi-to-achieve-root-access-on-a-major-telecom-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3460861/hacking/chaining-ssrf-and-lfi-to-achieve-root-access-on-a-major-telecom-server/</guid>
<pubDate>Fri, 24 Apr 2026 12:07:30 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>After hitting a wall with standard testing, I returned to recon and discovered a critical SSRF + LFI chain leading to full root access.</p><p>So the other day I was working on a target , a large telecommunications company. Everything on the surface seemed fine. I tested every endpoint but found nothing. After spending a week on it, I was completely exhausted and was about to move on. Then something inside me said I was missing something, so I decided to go back to the recon phase.</p><p>For recon, I went to censys.io and searched for all servers related to the telecom company using the query below:</p><pre>(target.com) and host.ip: *</pre><p>After scrolling through the results, I found a server with some unusual HTTP ports open, so I started investigating it further.</p><p><strong>Port 8003 : SSRF via an Internal Latency Checker</strong></p><p>One of the open ports was 8003. When I visited it, I found an internal latency-checking service. A python tool meant to be used by company staff to monitor their network performance by sending ping requests to various sites and measuring response times.</p><p>(Note: The bug is now patched so I can’t have screenshots of interface now while writing this write up)</p><p>The problem was it was exposed publicly, and there was no whitelisting of which URLs it could ping.</p><p>I captured the request in burp suite and changed the target URL to localhost. It worked. The service pinged the internal localhost and returned the latency. From here, I could enumerate internal IP addresses and their open ports</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*byPjSO7t87tSoDZWVP0SGA.png"></figure><p>But it wasn’t particularly exciting on its own. I also tried command injection, but since this was a python based application using python’s own ping implementation rather than the native bash ping command, that option was closed. So, I noted it down in obsidian and moved on.</p><p><strong>Port 8090 — XAMPP Default Page and a Hidden LFI</strong></p><p>Continuing my enumeration on the same server, I found another open port ,8090, running an XAMPP server. Visiting it revealed the XAMPP default page, which is always a red flag and a signal that something interesting might be waiting underneath.</p><p>Without a second thought I started directory brute forcing and found a directory named php. There was some SVG related content inside that didn't lead anywhere useful. I tried XSS here, but nothing worked.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ad7PQZW4ArFk1KM1_Hbxnw.png"></figure><p>So I ran another brute-force scan within the php directory, this time using a .php extension filter and found a file named cors.php.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AWfBcxQChIS2-AnKSkKp-Q.png"></figure><p>Visiting it returned an error: <em>Missing ‘url’ parameter</em>.</p><p>I added the url parameter pointing to localhost, and the error disappeared. At first, I thought this was the same kind of SSRF I had already found but then I had an idea. Instead of using http://, I switched to the file:// protocol and pointed it at one of XAMPP's default file and voilà it worked.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*gR5_jy4lFLqUpdUBPQ1Kwg.png"></figure><p>The full file contents were returned. I had <strong>Local File Inclusion (LFI)</strong> meaning I could read any file on the server.</p><p>My first thought was the classic log poisoning attack: send a request with a PHP reverse shell payload in the body, then trigger it through the LFI by pointing at the log file. However, the log file was too large, and cors.php couldn't handle that much content. I tried to locate smaller log files, but none of them worked either, so I abandoned that approach.</p><p>Instead, I started mapping out default file paths on the server with a bit of help from gemini. I tried file:///C:/xampp/passwords.txt and it returned the XAMPP passwords in plain text. Since the database and phpMyAdmin were only accessible internally, I couldn't use those credentials directly, at least not yet.</p><p><strong>Chaining SSRF + LFI to access phpMyAdmin as Root</strong></p><p>Now I had two vulnerabilities: SSRF on port 8003 and LFI on port 8090. I decided to chain them. Using the SSRF at port 8090, I attempted to access the internal phpMyAdmin instance. Not only did it work, it showed me that I was already logged in as <strong>root</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ly45AsgltaTIsLms71o25g.png"></figure><p>At that point, I stopped.</p><p>In good faith, I chose not to escalate further. What I <em>could</em> have done next is write a PHP web shell and uploaded it through phpMyAdmin to gain full server access. But I had enough evidence to make a strong report, so I disclosed everything responsibly to the telecom company.</p><p>They fixed the vulnerabilities and appreciated the effort I put into securing their infrastructure.</p><p><strong>Key Takeaways:</strong></p><ul><li>Always go back to recon when you feel stuck. The answer is often hiding in plain sight.</li><li>Chaining low-to-medium severity bugs (SSRF + LFI + exposed credentials) can escalate impact dramatically.</li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=1a5f31923f81" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/chaining-ssrf-and-lfi-to-achieve-root-access-on-a-major-telecom-server-1a5f31923f81">Chaining SSRF and LFI to Achieve Root Access on a Major Telecom Server</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Passed Three TCM Certs in Eight Months.]]></title>
<description><![CDATA[PWPA, PWPP, PWPE — Three certs, eight months, and a lot of coffee.This isn’t an official review or comparison — plenty of those exist already. This is how I actually approached it, including the moments where I thought I was going to blow it.Why TCM Security?I’d already spent some time playing on...]]></description>
<link>https://tsecurity.de/de/3460859/hacking/how-i-passed-three-tcm-certs-in-eight-months/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3460859/hacking/how-i-passed-three-tcm-certs-in-eight-months/</guid>
<pubDate>Fri, 24 Apr 2026 12:07:27 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>PWPA, PWPP, PWPE — Three certs, eight months, and a lot of coffee.</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/816/1*5SLasyhowwb-oZLqr3BuPw.png"></figure><p>This isn’t an official review or comparison — plenty of those exist already. This is how I actually approached it, including the moments where I thought I was going to blow it.</p><h3>Why TCM Security?</h3><p>I’d already spent some time playing on <em>Hack The Box</em> and <em>TryHackMe</em>, I passed a Micro-Credential on Ethical Hacking, but I wanted something that felt like real work. TCM has a reputation for practical courses and exams that resemble actual pentests. No multiple choice, no theory questions, no flag — just a website, a scope, and you.</p><p>That sounded exactly like the kind of exam I wanted.</p><h3>PWPA — Practical Web Pentest Associate</h3><h3>What it is</h3><p>PWPA is the beginner-level cert for web pentesting. It covers a lot of basic vulnerabilities and how to exploit them. But more importantly, Alex doesn’t just hand you a checklist — he teaches a <strong>methodology</strong> you can immediately put into practice with the labs. He strongly encourages keeping your notes updated throughout the process.</p><p>Contrary to what I thought at first, pentesters don’t know everything by heart. Hackers in movies type at insane speeds, bypassing the firewall and hacking into the mainframe. That’s not real life. Having someone explain a clear methodology lowers the bar for getting started in hacking.</p><h3>The course</h3><p>The Bug Bounty Hunter course is made up of different sections, ranging from enumeration (a fancy word for looking for hidden stuff in a website) to exploiting your first Cross-Site Scripting vulnerability (a fancy way of saying you can make the website do something it’s not supposed to do).</p><p>If at this point you’re thinking, “What?”, don’t worry. Everything is explained step by step, and you’re not expected to understand everything right away. For example, when I started, I couldn’t script anything, yet the very first section is about scripting. By the end, you end up with a script you can use for all your engagements. You don’t need to know every detail about how it works. Honestly, I only took a Python course <em>after</em> passing PWPP. So trust me when I say: you’re fine.</p><h3>The exam</h3><p>Before starting the exam, you’re reminded that you can’t share exam details, so I’m definitely not going to spoil anything. Everything you need to know is in the Rules of Engagement (RoE) you receive when you click “Start Exam.” This document explains what you should look for, who to contact if something goes wrong, and what you’re not allowed to do. Read it. <strong>Then re-read it.</strong> It’s important.</p><p>After reviewing the RoE, it’s just you, your tools, and the techniques you’ve learned. And that’s all you need. There’s no reason to look for things you weren’t taught or use techniques outside the course. What matters is opening the website, getting overwhelmed for a minute or two, then opening your notes and following your methodology.</p><blockquote><em>Don’t forget to set a timer: one hour hacking, five-minute break, and a longer break after three cycles.</em></blockquote><h3>My exam</h3><p>I started and couldn’t find anything for <strong>two straight hours</strong>. After a break, I slowed down, put my notes on a second screen, and began working through the methodology I had practiced so many times. I had summarized the entire course into a document I called my “Sanity Check,” and I strongly recommend having something like that. Once I followed it, the vulnerabilities presented themselves.</p><p>A big thing about this exam is that they don’t try to trick you. It’s just a pentest.</p><p>My approach was to screenshot everything, paste it into Notion with a short explanation, and move on.</p><blockquote><em>Quick tip: having something that tracks your clipboard history is incredibly useful. I had to dig for screenshots I knew I took but forgot to paste.</em></blockquote><p>After about seven hours, I had found some interesting things. Then I shut down my computer, picked up my kids from school, and had a great evening with them. After they went to bed, I watched a movie with my wife and went to sleep.</p><p>That paragraph isn’t a flex — it’s essential. If you’ve worked all day, you need rest. <strong><em>You’ll run out of ideas long before you run out of time.</em></strong> After dropping my kids off at school the next morning, I grabbed a coffee and started hacking again. Don’t think, “I have enough points; I’ll just wing it.” Take it seriously and try everything you can. Right after lunch, I found another major vulnerability, and I was genuinely excited.</p><p>Eventually, I ran out of ideas. I reviewed the vulnerabilities I found and didn’t know what else to test, so I started writing my report. I didn’t close my exam yet, because if I needed extra screenshots or wanted to try a different payload, I still had the option. Luckily, I didn’t need extra lab time, and I finished my report around the same time my lab expired.</p><p>After finishing the report, I closed my laptop again and spent time with my family. The next morning, after a good night’s sleep, I re-read the report in detail. I made a few edits, read it one last time, exported it as a PDF, and submitted it.</p><p>Then I braced myself for a long wait… but only two hours later, a notification from TCM popped up with the link to my certification.</p><h3>Verdict</h3><p>A great and fun exam. Challenging enough to test your abilities, but not so hard that it feels impossible. If you do the lab work and avoid shortcuts, you’ll succeed.</p><p><strong>Result:</strong> First attempt pass.</p><h3>PWPP — Practical Web Pentest Professional</h3><h3>The step up</h3><p>This is a professional-level certification, meaning you need to know a thing or two about performing an assessment and finding vulnerabilities. The techniques taught in PWPA are necessary to understand the more complex attacks in this course. Just like in PWPA, Alex’s approach is all about keeping your notes updated along the way. If you followed PWPA, you’ll definitely revisit some things before diving into the deeper material.</p><h3>The course</h3><p>The course is split into two parts: one focused on API hacking, and one focused on web hacking. Both parts work hand in hand, but I think it’s beneficial to start with the API section.</p><h3>The exam</h3><p>Same deal — everything you need to know is in the RoE. Read it. Then read it again.</p><p>After reviewing the RoE, it’s just you, your tools, and the techniques you’ve learned. There’s no reason to look for things you weren’t taught or to use techniques outside the course.</p><h3>My exam</h3><p>When I opened my exam, I saw functionality that clearly matched an attack taught in the course. But instead of getting a quick win, I forgot once again to <strong><em>slow down</em></strong>. After a while (a bit too long), I found the exploit, and it turned out to be much easier than what I was trying. Like I already mentioned: there’s no need to look for attacks you didn’t learn. Stick to the coursework.</p><p>My “Sanity Check” from PWPA had a major update after doing PWPP, and for the rest of the exam I really found and kept my flow using it.</p><p>Because you know more techniques now, it’s important to track <em>what</em>, <em>how</em>, and <em>where</em> you test. Don’t distract yourself with “I’ll test this endpoint on X and Y” but then get sidetracked by something else. Be strict with yourself and focus on one thing at a time.</p><p>Like with PWPA, I didn’t work more than seven hours on the first day, and I took my breaks. I felt good by the end of the day, did family stuff, and went to bed.</p><p>The second day, I was fully in the zone. A bit too much, actually. I forgot my breaks, forgot to drink, and barely ate. I fell straight into a rabbit hole and couldn’t get out. And that’s something I want to warn you about: falling into a rabbit hole is normal, and you <em>do</em> have to test it, but set a timer for problems. I was convinced there was something there, but I couldn’t find it because it simply wasn’t there.</p><blockquote><em>My advice changed after that experience: hack away, but when you get stuck, set a timer and stick to it. I probably would have lost only an hour or two, but if I had taken my break, I would have realized sooner that it wasn’t worth pursuing.</em></blockquote><p>After realizing I went too deep, I took a long break, forgot about it, and moved on to other problems. I did some extra hours that day but still got enough rest.</p><p>By the middle of the third day, I was out of ideas. So, just like in PWPA, I left my environment open and started my report. I had already taken screenshots throughout the exam and saved them in Notion with comments. With my report template prepared, it was mostly copy, paste, done.</p><p>I read it, re-read it, saved it to PDF, re-read it once more, and before my lab time was up, the report was ready. I ended my environment, uploaded the report, hung out with the kids, and went to bed. The next morning, I already saw three notifications with “TCM Sec…” in my inbox. I opened the latest one, and my certification link was available.</p><h3>Verdict</h3><p>This exam was really fun and taught me something valuable. You have to stay open enough to let an exam teach you something, even without an instructor guiding you. The biggest lesson for me was the rabbit hole. I’ll try to recognize it faster next time.</p><p>It’s understandable that in an exam you want to find things, but even during an exam, you have to know when to stop. And that might be the most valuable lesson PWPP taught me.</p><p><strong>Result:</strong> First attempt pass.</p><h3>PWPE — Practical Web Pentest Expert</h3><h3>This was different</h3><p>PWPE is the follow-up to PWPP. It’s an expert-level exam that will push you to look further and deeper than you ever did with PWPA or PWPP. To pass this exam, you’re going to need every trick in your book. So make sure your notes are up to date.</p><p>A very big difference between PWPE and the previous two certs: you don’t really know what you’re looking for. Obviously you look at the things you learned during the course, but unlike PWPA and PWPP, you <strong>will not pass</strong> with only the things from the <em>Advanced Web Hacking</em> course. You’ll need a profound knowledge of the basics. On top of that, you’ll need to develop a <em>spidey sense</em> for things that are a bit weird and be able to look those things up. The exam isn’t designed to trick you, but it <em>is</em> designed to be expert-level.</p><h3>The course</h3><p>The course covers the quality you’ve come to expect from Alex’s material. Topics include:</p><ul><li>Prototype pollution</li><li>GraphQL</li><li>Code review</li><li>Code (de)obfuscation</li><li>OAuth</li><li>Cache poisoning</li></ul><p>Each topic starts with a theoretical explanation, and as always, Alex walks you through some examples. Then you have a shot at doing some capstones on your own at the end of each module.</p><h3>The exam</h3><p>Read the RoE with even <strong>more</strong> care than you did for any other TCM cert. Once you read it, just read it again, to make sure you saw it all.</p><h3>My exam</h3><p>After reading and rereading the RoE, it was time to navigate to the start URL. Personally, I found this exam was a bit less overwhelming than PWPP. Still a lot of functionality to go through, but it felt calmer.</p><p>Once the exam started, I did what I always do — went through the app and clicked everything I saw. Then it was time to open up my proxy and inspect the traffic. Like Alex said in one of his reviews, your task is to identify small vulnerabilities and chain them together. So don’t expect to find an obvious XSS.</p><p>After going through the traffic, I decided that a particular functionality would be my first thing to test. I had to peel the onion layer by layer, and I kept track of everything I saw that could possibly be of use later. And sure enough, after only a few hours I chained some low-level things together and was able to drop a payload that could be considered high risk.</p><p>On that high, I continued my testing and found some small issues, but I could not for the life of me chain anything together that was worth noting down. That’s when the panic started to set in. I decided to leave it, and went to bed.</p><p>When I opened up the app the next day, I had enough time to reflect on what I found. I started to really hit those endpoints with everything I had, but nothing — and I mean <strong>absolutely nothing</strong> — worked. I remembered the valuable lesson from PWPP about rabbit holes and moved away from the endpoint I was so sure was the entry point for a critical vulnerability.</p><p>That’s when the expert-level exam became the expert-level exam for me.</p><p>I had the low-hanging fruit, but that wasn’t enough to pass. I needed something critical. And it’s at that point that the exam tests if you have the endurance and insight to go look for the right things. It took a <em>loooooooooong</em> time, and multiple <em>“It’s not gonna be in here, right?!”</em> moments — when my eye caught something small, yet so obvious that I needed to test it. My first test returned absolutely nothing. Another dead end? Or maybe not — let’s try this… And that got me somewhere. That result led me to use Google and look something up. It was strange, I had never seen it, but every part of my body was screaming that I was getting somewhere if I could just crack this little thing. And yeah, that was the critical thing I was looking for. Good old Google to the rescue.</p><p>So with a day of testing to spare, I could start writing my report. I managed to have two high-value vulnerabilities and some minor issues. I had my template ready to go, but because this exam is all about chaining, I needed to adjust the template. I submitted my report at the end of that day after reading it a dozen times.</p><p>Then, totally unexpected, another hard part came. My PWPA and PWPP came back in less than a day, but I had to wait a week for the PWPE results. But when they came back, I was glad I was able to knock this one out of the park on my first try too.</p><h3>Verdict</h3><p>This was a fun exam. It was hard, and maybe you’ll need a bit of luck, but the answer isn’t some niche and weird <em>“Gotcha!”</em> CTF-moment — it will be right there for you. My advice is simply to show that you have <strong><em>perseverance</em></strong> to do what needs to be done. Expert-level doesn’t mean flashy. It means you don’t quit when things get quiet.</p><blockquote><strong><em>Fatigue is the best friend of missed vulnerabilities.</em></strong></blockquote><p><strong>Result:</strong> First attempt pass.</p><h3>What I learned</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Fo5TO0v7clY3BTTGpxc4kw.png"></figure><h3>The five lessons</h3><ol><li><strong>Sleep.</strong> Not optional. You see more rested than after 6 hours of grinding.</li><li><strong>Screenshot while you test.</strong> Have a tool that retains your screenshots should you forget to paste them somewhere.</li><li><strong>Don’t test for too long.</strong> A rabbit hole is there for a reason. To make you test it and move on.</li><li><strong>Use your methodology.</strong> Follow your notes, you spend a lot of time creating them, might as well use them.</li><li><strong>Slow down.</strong> You’ll run out of ideas long before your time runs out! No need to rush your testing, keep calm so you don’t miss something obvious.</li></ol><blockquote>Do not learn how to hack, hack to learn.</blockquote><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=b8d76211263a" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-passed-three-tcm-certs-in-eight-months-b8d76211263a">How I Passed Three TCM Certs in Eight Months.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Health-care AI is here. We don’t know if it actually helps patients.]]></title>
<description><![CDATA[I don’t need to tell you that AI is everywhere. Or that it is being used, increasingly, in hospitals. Doctors are using AI to help them with notetaking. AI-based tools are trawling through patient records, flagging people who may require certain support or treatments. They are also used to interp...]]></description>
<link>https://tsecurity.de/de/3460725/ai-nachrichten/health-care-ai-is-here-we-dont-know-if-it-actually-helps-patients/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3460725/ai-nachrichten/health-care-ai-is-here-we-dont-know-if-it-actually-helps-patients/</guid>
<pubDate>Fri, 24 Apr 2026 11:17:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I don’t need to tell you that AI is everywhere. Or that it is being used, increasingly, in hospitals. Doctors are using AI to help them with notetaking. AI-based tools are trawling through patient records, flagging people who may require certain support or treatments. They are also used to interpret medical exam results and X-rays. A…]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM shareholder proposal demands IBM defend AI bias protocols]]></title>
<description><![CDATA[CIOs have long struggled with AI reliability issues, given problems with training data, model interpretations, and inconsistent data weighting delivering various levels of bias. IBM officials at next week’s shareholder meeting will have to address those concerns directly, as they face a sharehold...]]></description>
<link>https://tsecurity.de/de/3459855/it-nachrichten/ibm-shareholder-proposal-demands-ibm-defend-ai-bias-protocols/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3459855/it-nachrichten/ibm-shareholder-proposal-demands-ibm-defend-ai-bias-protocols/</guid>
<pubDate>Fri, 24 Apr 2026 04:01:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>CIOs have long struggled with AI reliability issues, given problems with training data, model interpretations, and inconsistent data weighting delivering various levels of bias. IBM officials at next week’s shareholder meeting will have to address those concerns directly, as they face a shareholder motion demanding increased visibility into how it manages AI bias, a thorny issue that also affects all of the other major AI players. </p>



<p>The shareholder resolution is demanding that IBM “issue a report, within the next year, on the methods used to eliminate bias from the Company’s artificial intelligence (AI) models, Including an assessment of the risk that seeking to avoid disparate impact in outputs will undermine the accuracy of, and trust in, those outputs.”</p>



<p>IBM’s <a href="https://www.ibm.com/downloads/documents/us-en/15db52361b420c14" target="_blank" rel="nofollow">official response to the resolution</a> asks shareholders to reject the proposal. “Since releasing its first Granite model, IBM has been transparent with its data management and training procedures via technical reports, model cards, and other model documentation,” the company said. “The IBM models are open source In order to foster transparency. Moreover, IBM publicly provides the information sought by this proposal in its submissions to Stanford University’s Foundation Model Transparency Index (FMTI).”</p>



<p><a href="https://crfm.stanford.edu/fmti/December-2025/index.html" target="_blank" rel="nofollow">FMTI</a> is a benchmarking initiative that looks at how transparent companies are about their foundation models, measuring disclosure across areas like data sources, training methods, evaluation metrics, risks, and governance practices, to help stakeholders understand how responsibly and openly these models are developed and deployed.</p>



<p>IBM’s response added, “information related to mitigating bias that the proponent requests is largely already publicly available for consideration by stockholders.” Therefore, it argued, preparing such a report “would not provide new meaningful information and it is not in the best interests of IBM stockholders, as it will divert management’s attention and would be an inefficient use of corporate resources.”</p>



<p>Beyond its argument that it already provides such AI bias transparency, the company pointed to its customers’ ability to fine-tune their models to resolve any specific bias concerns. </p>



<p>“IBM models are smaller and targeted towards enterprise clients and use cases,” it said. “These models are not general purpose, consumer-facing models. Therefore, our open-source models are built in a manner that allows our clients to build an AI solution that will address their specific needs. IBM developed several methods to allow clients to address bias issues that may arise as they train the AI system. In other words, IBM not only provides the building blocks for its clients’ AI solutions, but also provides the tools to help more clients address bias.”</p>



<h2 class="wp-block-heading">An industry-wide problem</h2>



<p>Analysts and consultants generally found IBM’s position correct, but most pointed to the AI bias issue as an industry-wide problem impacting all of the major AI providers and all of their enterprise users. </p>



<p><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="nofollow">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, said, “IBM’s stance deserves to be taken seriously, but not at face value. The company is right to say that bias mitigation, fairness frameworks, and governance controls are already built into its AI systems. That is not in dispute. In fact, compared to much of the market, IBM has been more deliberate than most in turning responsible AI from a set of principles into something operational.”</p>



<p>But, he added, “when IBM points out that customers can and should address bias through fine-tuning and governance, it is quietly acknowledging a limitation. It is admitting that whatever happens at the model layer is not the end of the story. It is only the beginning of it.”</p>



<p><a href="https://www.infotech.com/profiles/manish-jain" target="_blank" rel="nofollow">Manish Jain</a>, a principal research director at Info-Tech Research Group, saw the IBM position as correct, but also as the latest example of large vendors shifting responsibility for AI accuracy onto their enterprise customers. </p>



<p>“I see IBM’s board’s stance being broadly consistent with industry practice, which is doing everything to shift the responsibility of removing bias towards customers,” Jain said. “In fact, many independent software vendors (ISVs) are also taking a similar position and saying to their customers, ‘We’ll provide the compass, you chart the course.’ Unfortunately, accountability is the victim. Regulatory guidelines, independent audits, standardized benchmarks, in addition to clearer disclosures, are extremely important to ascertain this accountability.”</p>



<p><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="nofollow">Noah Kenney</a>, principal consultant for Digital 520, had similar feelings about IBM’s response. </p>



<p>The shareholder demand for more transparency “is asking the right question for the wrong reason,” Kenney said. “The proponent frames disparate-impact correction as a threat to accuracy, but the real issue is that IBM, and every major model provider, is measuring bias at the output layer when most of it originates upstream. You cannot fairness-tune your way out of a training data problem.”</p>



<p>He noted, “IBM’s response is accurate on the facts. FMTI scores, model cards, FairIQ, Equi-tuning, FairReprogram, and the Granite transparency posture are all real, and more than most of their peers publish. The gap is not disclosure. The gap is that the industry has converged on post-hoc mitigation as the dominant paradigm, and post-hoc mitigation has diminishing returns once a model is trained.”</p>



<p><a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="nofollow">Mike Leone</a>, VP/principal analyst at Moor Insights &amp; Strategy, pointed out that IBM is doing a better job than most AI vendors in terms of bias transparency, and that the industry needs to address the issue globally. </p>



<p>“IBM discloses more of its AI bias and transparency work than most vendors. IBM has built specific bias mitigation methods into the stack rather than just talking about bias at a high level. A new annual report would mostly repeat what’s already out there,” Leone said. </p>



<p>“I truly don’t think eliminating bias is possible, and that’s not an IBM problem,” he added. “The whole market is operating the same way in that any model trained on human-generated data carries the biases of whoever made it, which is exactly the same as humans would do. What vendors can do, IBM included, as they do a bunch of this already, is measure it, disclose it, monitor it after deployment, and give customers tools to adapt. I’m in the camp that anyone promising to completely eliminate bias is telling you what you want to hear.”</p>



<h2 class="wp-block-heading">‘Unbiased’ can’t be defined</h2>



<p>Part of the answer to the AI bias problem is technological, but there is an underlying fundamental issue of bias that cannot possibly be defined. </p>



<p><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="nofollow">Carmi Levy</a>, an independent technology analyst, observed, “the very definition of the word, unbiased, simply doesn’t exist, because what might seem unbiased or perfectly fair to one stakeholder might be perceived as wildly biased or unfair by another.”</p>



<p>Within that context, he noted, “the notion of eliminating any and all forms of bias from the AI equation is unrealistic. At best, vendors should be aiming for mitigation instead of outright elimination. They might also want to devote more resources toward transparency. Although sharing too much can compromise their competitive market position, there’s no reason why a carefully balanced and communicated messaging strategy can’t alleviate stakeholder concerns over bias without giving competitors undue advantage.”</p>



<h2 class="wp-block-heading">Complete bias removal impossible</h2>



<p>The AI bias issue is sometimes subtle, as it chooses which of the relevant details it should use in answers and in what sequence. But in other instances, such as when <a href="https://www.cio.com/article/4160432/ai-is-scoring-your-job-candidates-can-you-explain-how.html" target="_blank">racial and gender prejudices are reinforced</a> by <a href="https://www.cio.com/article/4158892/ibms-government-dei-settlement-could-increase-pressure-to-avoid-tech-hiring-diversity.html" target="_blank">AI working for human resources</a>, the bias can potentially appear quite blatant. <a href="https://www.computerworld.com/article/4152400/california-to-bar-ai-vendors-that-cant-prove-bias-safeguards.html" target="_blank">California, for example, wants to force AI vendors</a> to prove that they have strong bias safeguards. </p>



<p>However, said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="nofollow">Nader Henein</a>, “completely removing bias is impossible, which is why almost every piece of AI regulation focuses on AI systems that make decisions that will impact people’s lives or people’s livelihoods and introduce obligations such as human oversight.” </p>



<p>For example, he said, “a recruitment application that sorts applicants by the suitability to a job role should be used by a trained recruiter who understands that this is AI, that it can make mistakes, and they are responsible to oversee the AI system, much in the same way that you oversee an entry level employee taking on sensitive work, the difference being that oversight is permanent.”</p>



<p><a href="https://linkedin.com/in/chrishood" target="_blank" rel="nofollow">Chris Hood</a>, an independent AI strategist and former head of Google’s strategy and transformation, also said that IBM’s position is legitimate, but it’s not enough.</p>



<p>“IBM’s position is technically defensible and practically insufficient,” Hood said. “Publishing bias mitigation reports and giving customers fine-tuning options are reasonable steps. They are also steps that address the symptoms rather than the architecture. IBM is describing what it does to manage bias. The harder question is whether bias in foundation models is manageable at all, or whether it is structural.”</p>



<p>He noted that the models learned from human-generated content, which carries “every historical imbalance, cultural assumption, and factual error humans have ever produced at scale. You can audit it, weight it, and filter it. You cannot eliminate it. The data is what it is.”</p>



<p>Potentially more of an issue is the personal bias that every user brings to every AI interaction. “A geopolitically charged question asked by someone in the United States and the same question asked by someone in another country will be interpreted differently, evaluated differently, and potentially produce different outputs. This layer is almost impossible to govern at the model level because it lives in the interaction, not the training,” Hood noted.</p>



<p>He added: “IBM recommending shareholders reject this proposal while pointing to existing efforts is a reasonable governance posture. It is also a posture that treats bias as a solved problem rather than a managed one. The difference matters enormously as agents move from answering questions to making decisions.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Logseq für Einsteiger: Persönliches Wissen sammeln und vernetzen]]></title>
<description><![CDATA[Logseq sammelt und vernetzt persönliches Wissen. Die App ist zwar noch nicht fertig, hat aber dennoch viele treue Fans. Wir zeigen, wie der Einstieg gelingt.]]></description>
<link>https://tsecurity.de/de/3456923/it-nachrichten/heise-logseq-fuer-einsteiger-persoenliches-wissen-sammeln-und-vernetzen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3456923/it-nachrichten/heise-logseq-fuer-einsteiger-persoenliches-wissen-sammeln-und-vernetzen/</guid>
<pubDate>Thu, 23 Apr 2026 07:46:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Logseq sammelt und vernetzt persönliches Wissen. Die App ist zwar noch nicht fertig, hat aber dennoch viele treue Fans. Wir zeigen, wie der Einstieg gelingt.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI unveils Workspace Agents, a successor to custom GPTs for enterprises that can plug directly into Slack, Salesforce and more]]></title>
<description><![CDATA[OpenAI introduced a new paradigm and product today that is likely to have huge implications for enterprises seeking to adopt and control fleets of AI agent workers.Called "Workspace Agents," OpenAI's new offering essentially allows users on its ChatGPT Business ($20 per user per month) and variab...]]></description>
<link>https://tsecurity.de/de/3456520/it-nachrichten/openai-unveils-workspace-agents-a-successor-to-custom-gpts-for-enterprises-that-can-plug-directly-into-slack-salesforce-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3456520/it-nachrichten/openai-unveils-workspace-agents-a-successor-to-custom-gpts-for-enterprises-that-can-plug-directly-into-slack-salesforce-and-more/</guid>
<pubDate>Thu, 23 Apr 2026 02:15:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI introduced a new paradigm and product today that is likely to have huge implications for enterprises seeking to adopt and control fleets of AI agent workers.</p><p>Called "<a href="https://openai.com/index/introducing-workspace-agents-in-chatgpt/">Workspace Agents</a>," OpenAI's new offering essentially allows users on its ChatGPT Business ($20 per user per month) and variably priced Enterprise, Edu and Teachers subscription plans to design or select from pre-existing agent templates that can take on work tasks across third-party apps and data sources including Slack, Google Drive, Microsoft apps, Salesforce, Notion, Atlassian Rovo, and other popular enterprise applications.</p><div></div><p>Put simply: these agents can be created and accessed from ChatGPT, but users can also add them to third-party apps like Slack, communicate with them across disparate channels, ask them to use information from the channel they're in and other third-party tools and apps, and the agents will go off and do work like drafting emails to the entire team, selected members, or pull data and make presentations.</p><p>Human users can trust that the agent will manage all this complexity and complete the task as requested, even if the user who requested it leaves.</p><p>It's the end of "babysitting" agents and the start of letting them go off and get shit done for your business — according to your defined business processes and permissions, of course. </p><p>The product experience appears centered on the Agents tab in the ChatGPT sidebar, where teams can discover and manage shared agents. </p><p>This functions as a kind of team directory: a place where agents built by coworkers can be reused across a workspace. The broader idea is that AI becomes less of an individual productivity trick and more of a shared organizational resource.</p><p>In this sense, OpenAI is targeting one of office work’s oldest pain points: the handoff between people, systems, and steps in a process.</p><p>OpenAI says workspace agents will be free for the next two weeks, until May 6, 2026, after which credit-based pricing will begin. The company also says more capabilities are on the way, including new triggers to start work automatically, better dashboards, more ways for agents to take action across business tools, and support for workspace agents in its AI code generation app, Codex.</p><p>For more information on how to get started building and using them, OpenAI recommends heading over to its <a href="https://openai.com/academy/workspace-agents/">online academy page on them here</a> and <a href="https://help.openai.com/en/articles/20001143-chatgpt-workspace-agents-for-enterprise-and-business">its help desk documentation here</a>.</p><h2><b>The Codex backbone</b></h2><p>The most significant shift in this announcement is the move away from purely session-based interaction. Workspace agents are powered by Codex — the cloud-based, partially open-source AI coding harness that OpenAI has been aggressively expanding in 2026 — which gives them access to a workspace for files, code, tools, and memory.</p><p>OpenAI says the agents can do far more than answer a prompt. They can write or run code, use connected apps, remember what they have learned, and continue work across multiple steps. </p><p>That description lines up closely with the <a href="https://venturebeat.com/technology/openai-drastically-updates-codex-desktop-app-to-use-all-other-apps-on-your-computer-generate-images-preview-webpages">capabilities OpenAI shipped into Codex just six days ago</a>, including background computer use, more than 90 new plugins spanning tools like Atlassian Rovo, CircleCI, GitLab, Microsoft Suite, Neon by Databricks, and Render, plus image generation, persistent memory, and the ability to schedule future work and wake up on its own to continue across days or weeks.</p><p>Workspace agents inherit that plumbing. When one pulls a Friday metrics report, it is effectively spinning up a Codex cloud session with the right tools attached, running code to fetch and transform data, rendering charts, writing the narrative, and persisting what it learned for next week. </p><p>When that same agent is deployed to a Slack channel, it is a Codex instance listening for mentions and threading its work back in.</p><p>This is the technical decision enterprise buyers should focus on. Building an agent on a code-execution substrate rather than a pure LLM-call-and-response loop is what gives workspace agents the ability to do real work — transforming a CSV, reconciling two systems of record, generating a chart that is actually correct — rather than describing what the work would look like.</p><h2><b>Persistence and scheduling</b></h2><p>In earlier AI assistant models, progress paused when the user stopped interacting. Workspace agents change that by running in the cloud and supporting long-running workflows. Teams can also set them to run on a schedule.</p><p>That means a recurring reporting agent can pull data on a set cadence, generate charts and summaries, and share the results with a team without anyone manually kicking off the process. </p><p>Here at VentureBeat, we analyze story traffic and user return rate on a weekly basis — exactly the kind of recurring, multi-step, multi-source task that could theoretically be automated with a single workspace agent. Any enterprise with a weekly reporting rhythm pulling from dynamic data sources is likely to find a use for these agents.</p><p>Agents also retain memory across runs. OpenAI says they can be guided and corrected in conversation, so they improve the more a team uses them. </p><p>Over time they start to reflect how a team actually works — its processes, its standards, its preferred ways of handling recurring jobs — which is a meaningfully different proposition from the static instruction-set GPTs that preceded them.</p><h2><b>The integrated ecosystem</b></h2><p>OpenAI's claim is that agents should gather information and take action where work already happens, rather than forcing teams into a separate interface. That point becomes clearest in the Slack examples. OpenAI's launch materials show a product-feedback agent operating inside a channel named #user-insights, answering a question about recent mobile-app feedback with a themed summary pulled from multiple sources.</p><p>The company's demo lineup walks through a sample team directory of agents: Spark for lead qualification and follow-up, Slate for software-request review, Tally for metrics reporting, Scout for product feedback routing, Trove for third-party vendor risk, and Angle for marketing and web content. </p><p>OpenAI also shared more functional examples its own teams use internally — a Software Reviewer that checks employee requests against approved-tools policy and files IT tickets; an accounting agent that prepares parts of month-end close including journal entries, balance-sheet reconciliations, and variance analysis, with workpapers containing underlying inputs and control totals for review; and a Slack agent used by the product team that answers employee questions, links relevant documentation, and files tickets when it surfaces a new issue.</p><p>In a sense, it is a continuation of the philosophy OpenAI espoused for individuals with last week's Codex desktop release: the agent joins the workflow where work is already happening, draws in context from the surrounding apps, takes action where permitted, and keeps moving.</p><h2><b>From GPTs to a broader agent push</b></h2><p>Workspace agents are not a standalone launch. They sit inside a roughly 12-month arc in which OpenAI has been systematically rebuilding ChatGPT, the API, and the developer platform around agents.</p><p>Workspace agents are explicitly positioned by OpenAI as an evolution of its <a href="https://venturebeat.com/ai/openai-announces-customizable-gpts-for-businesses-and-consumers">custom GPTs, introduced in late 2023</a>, which gave users a way to create customized versions of ChatGPT for particular roles and use cases.</p><p>However, now OpenAI says it is deprecating the custom GPT standard for organizations in a yet-to-be determined future date, and will require Business, Enterprise, Edu and Teachers users to update their GPTs to be new workspace agents. </p><p>Individuals who have made custom GPTs can continue using them for the foreseeable future, according to our sources at the company.</p><p>In October 2025, <a href="https://venturebeat.com/ai/openai-unveils-agentkit-that-lets-developers-drag-and-drop-to-build-ai">OpenAI introduced AgentKit</a>, a developer-focused suite that includes Agent Builder, a Connector Registry, and ChatKit for building, deploying, and optimizing agents. </p><p>In February 2026,<a href="https://venturebeat.com/orchestration/openai-launches-centralized-agent-platform-as-enterprises-push-for-multi"> it introduced Frontier</a>, an enterprise platform focused on helping organizations manage AI coworkers with shared business context, execution environments, evaluation, and permissions. </p><p>Workspace agents arrive as the no-code, in-product entry point that sits on top of that stack — even if OpenAI does not explicitly describe the architectural relationship in its materials.</p><p>The subtext across all three launches is the same: OpenAI has decided that the future of ChatGPT-for-work is fleets of permissioned agents, not single chat windows — and that GPTs, its first attempt at letting businesses customize ChatGPT, were not enough.</p><h2><b>Governance and enterprise safeguards</b></h2><p>Because workspace agents can act across business systems, OpenAI puts heavy emphasis on governance. Admins can control who is allowed to build, run, and publish agents, and which tools, apps, and actions those agents can reach. </p><p>The role-based controls are more granular than the ones most custom-GPT rollouts ever had: admins can toggle, per role, whether members can browse and run agents, whether they can build them, whether they can publish to the workspace directory, and — separately — whether they can publish agents that authenticate using personal credentials. </p><p>That last setting is the risky case, and OpenAI explicitly recommends keeping it narrowly scoped.</p><p>Authentication itself comes in two flavors, and the choice has real consequences. In end-user account mode, each person who runs the agent authenticates with their own credentials, so the agent only ever sees what that individual is allowed to see. </p><p>In agent-owned account mode, the agent uses a single shared connection so users don't have to authenticate at run time. OpenAI's documentation strongly recommends service accounts rather than personal accounts for the shared case, and flags the data-exfiltration risk of publishing an agent that authenticates as its creator.</p><p>Write actions — sending email, editing a spreadsheet, posting a message, filing a ticket — default to Always ask, requiring human approval before the agent executes. </p><p>Builders can relax specific actions to "Never ask" or configure a custom approval policy, but the default posture is human-in-the-loop.</p><p>OpenAI also claims built-in safeguards against prompt-injection attacks, where malicious content in a document or web page tries to hijack an agent. The claim is welcome but not yet proven in the wild.</p><p>For organizations that want deeper visibility, <a href="https://community.openai.com/t/compliance-api-documentation-and-sandbox/1115444">OpenAI says its Compliance API</a> surfaces every agent's configuration, updates, and run history. </p><p>Admins can suspend agents on the fly, and OpenAI says an admin-console view of every agent built across the organization, with usage patterns and connected data sources, is coming soon. </p><p>Two caveats worth flagging for security-sensitive buyers: workspace agents are off by default at launch for ChatGPT Enterprise workspaces pending admin enablement, and they are not available at all to Enterprise customers using Enterprise Key Management (EKM).</p><h2><b>Analytics and early customer signal</b></h2><p>OpenAI also ships an analytics dashboard aimed at helping teams understand how their agents are being used. Screenshots in the launch materials show measures like total runs, unique users, and an activity feed of recent runs, including one by a user named Ethan Rowe completing a run in a #b2b-sales channel. </p><p>The mockup detail supports OpenAI's broader point: the company wants organizations to measure not just whether agents exist, but whether they are being used.</p><p>The clearest early-adopter signal in the launch itself comes from Rippling. Ankur Bhatt, who leads AI Engineering at the HR platform, says workspace agents shortened the traditional development cycle enough that a sales consultant was able to build a sales agent without an engineering team. "It researches accounts, summarizes Gong calls, and posts deal briefs directly into the team's Slack room," Bhatt says. "What used to take reps 5–6 hours a week now runs automatically in the background on every deal." </p><p>OpenAI's announcement names SoftBank Corp., Better Mortgage, BBVA, and Hibob as additional early testers.</p><h2><b>The era of the digital coworker</b></h2><p>Workspace agents do not land in a vacuum. They land in the middle of a broader OpenAI push — through AgentKit, through Frontier, through the Codex overhaul — to make agents more persistent, more connected, and more useful inside real organizational workflows. </p><p>They also land in a deeply crowded field: <a href="https://adoption.microsoft.com/en-us/ai-agents/copilot-studio/">Microsoft Copilot Studio</a> is wired into the Microsoft 365 base, Google is pushing <a href="https://cloud.google.com/blog/products/ai-machine-learning/google-agentspace-enables-the-agent-driven-enterprise">Agentspace</a>, Salesforce has rebuilt itself as agent infrastructure with <a href="https://venturebeat.com/orchestration/salesforces-agentforce-vibes-2-0-targets-a-hidden-failure-context-overload-in-ai-agents">Agentforce</a>, and Anthropic recently introduced <a href="https://venturebeat.com/orchestration/anthropics-claude-managed-agents-gives-enterprises-a-new-one-stop-shop-but">Claude Managed Agents</a>, all different flavors of similar ideas — agents that cut across your apps and tools, take actions on schedules repeatedly as desired, and retain some degree of memory, context, and permissions and policies.  </p><p>But this launch matters because it turns OpenAI's strategy into something concrete for the teams already paying for ChatGPT, and because it quietly retires the product those teams were most recently told to standardize on. </p><p>If workspace agents live up to the pitch — shared, reusable, scheduled, permissioned coworkers that follow approved processes and keep work moving when their human is offline — it would mark a meaningful change in what workplace software does. Less passive software waiting for input, more active systems helping teams coordinate, execute, and move faster together.</p><p>The era of the digital coworker has begun. And, on OpenAI's plans at least, the era of the custom GPT is ending.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Former Obdisian creative officer says not to bet on a Fallout: New Vegas remake, because Bethesda doesn't have 'the engineering know-how' to create it, and may not have the source code]]></title>
<description><![CDATA[Obsidian Entertainment co-founder and former creative officer Chris Avellone has said a Fallout: New Vegas remake may not be possible because Bethesda lacks the "engineering knowhow."]]></description>
<link>https://tsecurity.de/de/3452282/it-nachrichten/former-obdisian-creative-officer-says-not-to-bet-on-a-fallout-new-vegas-remake-because-bethesda-doesnt-have-the-engineering-know-how-to-create-it-and-may-not-have-the-source-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452282/it-nachrichten/former-obdisian-creative-officer-says-not-to-bet-on-a-fallout-new-vegas-remake-because-bethesda-doesnt-have-the-engineering-know-how-to-create-it-and-may-not-have-the-source-code/</guid>
<pubDate>Tue, 21 Apr 2026 18:32:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Obsidian Entertainment co-founder and former creative officer Chris Avellone has said a Fallout: New Vegas remake may not be possible because Bethesda lacks the "engineering knowhow."]]></content:encoded>
</item>
<item>
<title><![CDATA[11 best Obsidian alternatives for Mac to try in 2026]]></title>
<description><![CDATA[Obsidian is powerful but complex. Compare 2026 Mac alternatives like Capacities, Notion, Logseq, Ulysses, Craft, and more for outlining and networked notes.]]></description>
<link>https://tsecurity.de/de/3451887/ios-mac-os/11-best-obsidian-alternatives-for-mac-to-try-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3451887/ios-mac-os/11-best-obsidian-alternatives-for-mac-to-try-in-2026/</guid>
<pubDate>Tue, 21 Apr 2026 16:37:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Obsidian is powerful but complex. Compare 2026 Mac alternatives like Capacities, Notion, Logseq, Ulysses, Craft, and more for outlining and networked notes.]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion Pages Leak User Data]]></title>
<description><![CDATA[Notion, a popular platform for productivity and collaboration, is facing scrutiny after security researchers discovered a significant vulnerability. This article has been indexed from CyberMaterial Read the original article: Notion Pages Leak User Data
Read more →
The post Notion Pages Leak User ...]]></description>
<link>https://tsecurity.de/de/3448369/it-security-nachrichten/notion-pages-leak-user-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3448369/it-security-nachrichten/notion-pages-leak-user-data/</guid>
<pubDate>Mon, 20 Apr 2026 15:08:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Notion, a popular platform for productivity and collaboration, is facing scrutiny after security researchers discovered a significant vulnerability. This article has been indexed from CyberMaterial Read the original article: Notion Pages Leak User Data</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/notion-pages-leak-user-data/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/notion-pages-leak-user-data/">Notion Pages Leak User Data</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Notion pages have leaked user data via an unauthenticated API since 2022]]></title>
<description><![CDATA[A security researcher has revealed that Notion’s public pages can expose the email addresses of all contributors through an unauthenticated API request, a behavior that has reportedly been known since 2022 and is still present today. The issue allows anyone to extract user data, including names, ...]]></description>
<link>https://tsecurity.de/de/3448123/it-security-nachrichten/notion-pages-have-leaked-user-data-via-an-unauthenticated-api-since-2022/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3448123/it-security-nachrichten/notion-pages-have-leaked-user-data-via-an-unauthenticated-api-since-2022/</guid>
<pubDate>Mon, 20 Apr 2026 13:37:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A security researcher has revealed that Notion’s public pages can expose the email addresses of all contributors through an unauthenticated API request, a behavior that has reportedly been known since 2022 and is still present today. The issue allows anyone to extract user data, including names, emails, and profile images, without logging in or interacting …</p>
<p>The post <a href="https://cyberinsider.com/notion-pages-have-leaked-user-data-via-an-unauthenticated-api-since-2022/">Notion pages have leaked user data via an unauthenticated API since 2022</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Public Notion Pages Leaks Profile Photos and Email address of Editors]]></title>
<description><![CDATA[Notion, a popular productivity and collaboration platform, is under significant scrutiny from the cybersecurity community. Security researchers have revealed that public Notion pages silently expose the personally identifiable information (PII) of anyone who has ever edited them. This data leak…
...]]></description>
<link>https://tsecurity.de/de/3447941/it-security-nachrichten/public-notion-pages-leaks-profile-photos-and-email-address-of-editors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447941/it-security-nachrichten/public-notion-pages-leaks-profile-photos-and-email-address-of-editors/</guid>
<pubDate>Mon, 20 Apr 2026 12:22:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Notion, a popular productivity and collaboration platform, is under significant scrutiny from the cybersecurity community. Security researchers have revealed that public Notion pages silently expose the personally identifiable information (PII) of anyone who has ever edited them. This data leak…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/public-notion-pages-leaks-profile-photos-and-email-address-of-editors/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/public-notion-pages-leaks-profile-photos-and-email-address-of-editors/">Public Notion Pages Leaks Profile Photos and Email address of Editors</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Public Notion Pages Leaks Profile Photos and Email address of Editors]]></title>
<description><![CDATA[Notion, a widely used productivity and collaboration platform, is facing intense scrutiny from the cybersecurity community. Security researchers have revealed that public Notion pages silently expose the personally identifiable information (PII) of anyone who has ever edited them. This data leak ...]]></description>
<link>https://tsecurity.de/de/3447805/it-security-nachrichten/public-notion-pages-leaks-profile-photos-and-email-address-of-editors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447805/it-security-nachrichten/public-notion-pages-leaks-profile-photos-and-email-address-of-editors/</guid>
<pubDate>Mon, 20 Apr 2026 11:37:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Notion, a widely used productivity and collaboration platform, is facing intense scrutiny from the cybersecurity community. Security researchers have revealed that public Notion pages silently expose the personally identifiable information (PII) of anyone who has ever edited them. This data leak includes full names, email addresses, and profile photos, raising significant privacy concerns for organizations […]</p>
<p>The post <a href="https://cybersecuritynews.com/notion-pages-exposes-editors-data/">Public Notion Pages Leaks Profile Photos and Email address of Editors</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Public Notion Pages Expose Profile Photos and Email Addresses of Editors]]></title>
<description><![CDATA[A serious data exposure issue has been discovered in Notion, a widely used productivity and collaboration platform, potentially putting thousands of users and organizations at risk. Security researchers have revealed that public Notion pages can unintentionally expose sensitive personal informati...]]></description>
<link>https://tsecurity.de/de/3447627/it-security-nachrichten/public-notion-pages-expose-profile-photos-and-email-addresses-of-editors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447627/it-security-nachrichten/public-notion-pages-expose-profile-photos-and-email-addresses-of-editors/</guid>
<pubDate>Mon, 20 Apr 2026 10:38:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A serious data exposure issue has been discovered in Notion, a widely used productivity and collaboration platform, potentially putting thousands of users and organizations at risk. Security researchers have revealed that public Notion pages can unintentionally expose sensitive personal information of editors, including full names, email addresses, and profile photos, without requiring authentication. The issue […]</p>
<p>The post <a href="https://cyberpress.org/public-notion-pages-expose-profile-photos-and-email-addresses-of-editors/">Public Notion Pages Expose Profile Photos and Email Addresses of Editors</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Public Notion Pages Expose Editors’ Profile Photos and Email Addresses]]></title>
<description><![CDATA[A significant data exposure issue has been brought to light regarding Notion, a highly popular productivity and note-taking application. This exposure happens without requiring any authentication, cookies, or access tokens, leaving thousands of indexable company wikis and personal pages vulnerabl...]]></description>
<link>https://tsecurity.de/de/3447320/it-security-nachrichten/public-notion-pages-expose-editors-profile-photos-and-email-addresses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447320/it-security-nachrichten/public-notion-pages-expose-editors-profile-photos-and-email-addresses/</guid>
<pubDate>Mon, 20 Apr 2026 08:22:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A significant data exposure issue has been brought to light regarding Notion, a highly popular productivity and note-taking application. This exposure happens without requiring any authentication, cookies, or access tokens, leaving thousands of indexable company wikis and personal pages vulnerable…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/public-notion-pages-expose-editors-profile-photos-and-email-addresses/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/public-notion-pages-expose-editors-profile-photos-and-email-addresses/">Public Notion Pages Expose Editors’ Profile Photos and Email Addresses</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Public Notion Pages Expose Editors’ Profile Photos and Email Addresses]]></title>
<description><![CDATA[A significant data exposure issue has been brought to light regarding Notion, a highly popular productivity and note-taking application. This exposure happens without requiring any authentication, cookies, or access tokens, leaving thousands of indexable company wikis and personal pages vulnerabl...]]></description>
<link>https://tsecurity.de/de/3447263/it-security-nachrichten/public-notion-pages-expose-editors-profile-photos-and-email-addresses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447263/it-security-nachrichten/public-notion-pages-expose-editors-profile-photos-and-email-addresses/</guid>
<pubDate>Mon, 20 Apr 2026 07:51:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A significant data exposure issue has been brought to light regarding Notion, a highly popular productivity and note-taking application. This exposure happens without requiring any authentication, cookies, or access tokens, leaving thousands of indexable company wikis and personal pages vulnerable to data scraping. For organizations that rely on Notion for public-facing documentation, this poses a […]</p>
<p>The post <a href="https://gbhackers.com/public-notion-pages-expose-editors-profile/">Public Notion Pages Expose Editors’ Profile Photos and Email Addresses</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anonymous credentials: an illustrated primer (Part 2)]]></title>
<description><![CDATA[This is the second in a series of posts about anonymous credentials. You can find this first part here. In the previous post, we introduced the notion of anonymous credentials as a technique that allows users to authenticate to a website without sacrificing their privacy. As a quick reminder, an ...]]></description>
<link>https://tsecurity.de/de/3442898/reverse-engineering/anonymous-credentials-an-illustratedprimer-part-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3442898/reverse-engineering/anonymous-credentials-an-illustratedprimer-part-2/</guid>
<pubDate>Fri, 17 Apr 2026 19:37:46 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is the second in a series of posts about anonymous credentials. You can find this first part here. In the previous post, we introduced the notion of anonymous credentials as a technique that allows users to authenticate to a website without sacrificing their privacy. As a quick reminder, an anonymous credential system consists of … <a href="https://blog.cryptographyengineering.com/2026/04/17/anonymous-credentials-an-illustrated-primer-part-2/" class="more-link">Continue reading <span class="screen-reader-text">Anonymous credentials: an illustrated primer (Part 2)</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Most enterprises can't stop stage-three AI agent threats, VentureBeat survey finds]]></title>
<description><![CDATA[A rogue AI agent at Meta passed every identity check and still exposed sensitive data to unauthorized employees in March. Two weeks later, Mercor, a $10 billion AI startup, confirmed a supply-chain breach through LiteLLM. Both are traced to the same structural gap. Monitoring without enforcement,...]]></description>
<link>https://tsecurity.de/de/3442888/it-nachrichten/most-enterprises-cant-stop-stage-three-ai-agent-threats-venturebeat-survey-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3442888/it-nachrichten/most-enterprises-cant-stop-stage-three-ai-agent-threats-venturebeat-survey-finds/</guid>
<pubDate>Fri, 17 Apr 2026 19:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A rogue AI agent at Meta <a href="https://venturebeat.com/security/meta-rogue-ai-agent-confused-deputy-iam-identity-governance-matrix">passed every identity check and still exposed sensitive data</a> to unauthorized employees in March. Two weeks later, <a href="https://fortune.com/2026/04/02/mercor-ai-startup-security-incident-10-billion/">Mercor</a>, a $10 billion AI startup, confirmed a supply-chain breach through LiteLLM. Both are traced to the same structural gap. Monitoring without enforcement, enforcement without isolation. A VentureBeat three-wave survey of 108 qualified enterprises found that the gap is not an edge case. It is the most common security architecture in production today.</p><p>Gravitee’s <a href="https://www.gravitee.io/state-of-ai-agent-security">State of AI Agent Security 2026</a> survey of 919 executives and practitioners quantifies the disconnect. 82% of executives say their policies protect them from unauthorized agent actions. Eighty-eight percent reported AI agent security incidents in the last twelve months. Only 21% have runtime visibility into what their agents are doing. Arkose Labs’ <a href="https://securityboulevard.com/2026/04/97-of-enterprises-expect-a-major-ai-agent-security-incident-within-the-year/">2026 Agentic AI Security Report</a> found 97% of enterprise security leaders expect a material AI-agent-driven incident within 12 months. Only 6% of security budgets address the risk.</p><p>VentureBeat's survey results show that monitoring investment snapped back to 45% of security budgets in March after dropping to 24% in February, when early movers shifted dollars into runtime enforcement and sandboxing. The March wave (n=20) is directional, but the pattern is consistent with February’s larger sample (n=50): enterprises are stuck at observation while their agents already need isolation. CrowdStrike’s Falcon sensors detect more than <a href="https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-establishes-endpoint-epicenter-ai-security">1,800 distinct AI applications</a> across enterprise endpoints. The fastest recorded adversary breakout time has dropped to <a href="https://venturebeat.com/security/rsac-2026-agentic-soc-agent-telemetry-security-gap">27 seconds</a>. Monitoring dashboards built for human-speed workflows cannot keep pace with machine-speed threats.</p><p>The audit that follows maps three stages. Stage one is observe. Stage two is enforce, where IAM integration and cross-provider controls turn observation into action. Stage three is isolate, sandboxed execution that bounds blast radius when guardrails fail. VentureBeat Pulse data from 108 qualified enterprises ties each stage to an investment signal, an OWASP ASI threat vector, a regulatory surface, and immediate steps security leaders can take.</p><h2>The threat surface stage-one security cannot see</h2><p>The <a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">OWASP Top 10 for Agentic Applications 2026</a> formalized the attack surface last December. The ten risks are: goal hijack (ASI01), tool misuse (ASI02), identity and privilege abuse (ASI03), agentic supply chain vulnerabilities (ASI04), unexpected code execution (ASI05), memory poisoning (ASI06), insecure inter-agent communication (ASI07), cascading failures (ASI08), human-agent trust exploitation (ASI09), and rogue agents (ASI10). Most have no analog in traditional LLM applications. The audit below maps six of these to the stages where they are most likely to surface and the controls that address them.</p><p>Invariant Labs disclosed the <a href="https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks">MCP Tool Poisoning Attack</a> in April 2025: malicious instructions in an MCP server’s tool description cause an agent to exfiltrate files or hijack a trusted server. CyberArk extended it to <a href="https://www.cyberark.com/resources/threat-research-blog/poison-everywhere-no-output-from-your-mcp-server-is-safe">Full-Schema Poisoning</a>. The mcp-remote OAuth proxy patched CVE-2025-6514 after a command-injection flaw put 437,000 downloads at risk.</p><p>Merritt Baer, CSO at Enkrypt AI and former AWS Deputy CISO, framed the gap in an exclusive VentureBeat interview: “Enterprises believe they’ve ‘approved’ AI vendors, but what they’ve actually approved is an interface, not the underlying system. The real dependencies are one or two layers deeper, and those are the ones that fail under stress.”</p><p>CrowdStrike CTO Elia Zaitsev put the visibility problem in operational terms in an <a href="https://venturebeat.com/security/rsac-2026-agentic-soc-agent-telemetry-security-gap">exclusive VentureBeat interview at RSAC 2026</a>: “It looks indistinguishable if an agent runs your web browser versus if you run your browser.” Distinguishing the two requires walking the process tree, tracing whether Chrome was launched by a human from the desktop or spawned by an agent in the background. Most enterprise logging configurations cannot make that distinction.</p><h2>The regulatory clock and the identity architecture</h2><p>Auditability priority tells the same story in miniature. In January, 50% of respondents ranked it a top concern. By February, that dropped to 28% as teams sprinted to deploy. In March, it surged to 65% when those same teams realized they had no forensic trail for what their agents did.</p><p>HIPAA’s 2026 Tier 4 willful-neglect maximum is <a href="https://www.hipaacoach.com/what-is-the-maximum-penalty-for-a-hipaa-violation">$2.19M per violation category per year</a>. In healthcare, Gravitee’s survey found 92.7% of organizations reported AI agent security incidents versus the 88% all-industry average. For a health system running agents that touch PHI, that ratio is the difference between a reportable breach and an uncontested finding of willful neglect. <a href="https://www.finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report/gen-ai">FINRA’s 2026 Oversight Report</a> recommends explicit human checkpoints before agents that can act or transact execute, along with narrow scope, granular permissions, and complete audit trails of agent actions.</p><p>Mike Riemer, Field CISO at Ivanti, quantified the speed problem in a recent VentureBeat interview: “Threat actors are reverse engineering patches within 72 hours. If a customer doesn’t patch within 72 hours of release, they’re open to exploit.” Most enterprises take weeks. Agents operating at machine speed widen that window into a permanent exposure.</p><p>The identity problem is architectural. <a href="https://www.gravitee.io/blog/state-of-ai-agent-security-2026-report-when-adoption-outpaces-control">Gravitee's survey of 919 practitioners</a> found only 21.9% of teams treat agents as identity-bearing entities, 45.6% still use shared API keys, and 25.5% of deployed agents can create and task other agents. A quarter of enterprises can spawn agents that their security team never provisioned. That is ASI08 as architecture.</p><h2>Guardrails alone are not a strategy</h2><p>A 2025 paper by <a href="https://arxiv.org/abs/2502.19537">Kazdan and colleagues</a> (Stanford, ServiceNow Research, Toronto, FAR AI) showed a fine-tuning attack that bypasses model-level guardrails in 72% of attempts against Claude 3 Haiku and 57% against GPT-4o. The attack received a $2,000 bug bounty from OpenAI and was acknowledged as a vulnerability by Anthropic. Guardrails constrain what an agent is told to do, not what a compromised agent can reach.</p><p>CISOs already know this. In VentureBeat's three-wave survey, prevention of unauthorized actions ranked as the top capability priority in every wave at 68% to 72%, the most stable high-conviction signal in the dataset. The demand is for permissioning, not prompting. Guardrails address the wrong control surface.</p><p>Zaitsev framed the identity shift at RSAC 2026: “AI agents and non-human identities will explode across the enterprise, expanding exponentially and dwarfing human identities. Each agent will operate as a privileged super-human with OAuth tokens, API keys, and continuous access to previously siloed data sets.” Identity security built for humans will not survive this shift. Cisco President Jeetu Patel offered the operational analogy in an exclusive VentureBeat interview: agents behave “more like teenagers, supremely intelligent, but with no fear of consequence.”</p><h2>VentureBeat Prescriptive Matrix: AI Agent Security Maturity Audit</h2><table><tbody><tr><td><p><b>Stage</b></p></td><td><p><b>Attack Scenario</b></p></td><td><p><b>What Breaks</b></p></td><td><p><b>Detection Test</b></p></td><td><p><b>Blast Radius</b></p></td><td><p><b>Recommended Control</b></p></td></tr><tr><td><p><b>1: Observe</b></p></td><td><p>Attacker embeds goal-hijack payload in forwarded email (ASI01). Agent summarizes email and silently exfiltrates credentials to an external endpoint. See: Meta March 2026 incident.</p></td><td><p>No runtime log captures the exfiltration. SIEM never sees the API call. The security team learns from the victim. Zaitsev: agent activity is “indistinguishable” from human activity in default logging.</p></td><td><p>Inject a canary token into a test document. Route it through your agent. If the token leaves your network, stage one failed.</p></td><td><p>Single agent, single session. With shared API keys (45.6% of enterprises): unlimited lateral movement.</p></td><td><p>Deploy agent API call logging to SIEM. Baseline normal tool-call patterns per agent role. Alert on the first outbound call to an unrecognized endpoint.</p></td></tr><tr><td><p><b>2: Enforce</b></p></td><td><p>Compromised MCP server poisons tool description (ASI04). Agent invokes poisoned tool, writes attacker payload to production DB using inherited service-account credentials. See: Mercor/LiteLLM April 2026 supply-chain breach.</p></td><td><p>IAM allows write because agent uses shared service account. No approval gate on write ops. Poisoned tool indistinguishable from clean tool in logs. Riemer: “72-hour patch window” collapses to zero when agents auto-invoke.</p></td><td><p>Register a test MCP server with a benign-looking poisoned description. Confirm your policy engine blocks the tool call before execution reaches the database. Run mcp-scan on all registered servers.</p></td><td><p>Production database integrity. If agent holds DBA-level credentials: full schema compromise. Lateral movement via trust relationships to downstream agents.</p></td><td><p>Assign scoped identity per agent. Require approval workflow for all write ops. Revoke every shared API key. Run mcp-scan on all MCP servers weekly.</p></td></tr><tr><td><p><b>3: Isolate</b></p></td><td><p>Agent A spawns Agent B to handle subtask (ASI08). Agent B inherits Agent A’s permissions, escalates to admin, rewrites org security policy. Every identity check passes. Source: CrowdStrike CEO George Kurtz, RSAC 2026 keynote.</p></td><td><p>No sandbox boundary between agents. No human gate on agent-to-agent delegation. Security policy modification is a valid action for admin-credentialed process. CrowdStrike CEO George Kurtz disclosed at RSAC 2026 that the agent “wanted to fix a problem, lacked permissions, and removed the restriction itself.”</p></td><td><p>Spawn a child agent from a sandboxed parent. Child should inherit zero permissions by default and require explicit human approval for each capability grant.</p></td><td><p>Organizational security posture. A rogue policy rewrite disables controls for every subsequent agent. 97% of enterprise leaders expect a material incident within 12 months (Arkose Labs 2026).</p></td><td><p>Sandbox all agent execution. Zero-trust for agent-to-agent delegation: spawned agents inherit nothing. Human sign-off before any agent modifies security controls. Kill switch per OWASP ASI10.</p></td></tr></tbody></table><p><i>Sources: OWASP Top 10 for Agentic Applications 2026; Invariant Labs MCP Tool Poisoning (April 2025); CrowdStrike RSAC 2026 Fortune 50 disclosure; Meta March 2026 incident (The Information/Engadget); Mercor/LiteLLM breach (Fortune, April 2, 2026); Arkose Labs 2026 Agentic AI Security Report; VentureBeat Pulse Q1 2026.</i></p><p>The stage-one attack scenario in this matrix is not hypothetical. Unauthorized tool or data access ranked as the most feared failure mode in every wave of VentureBeat’s survey, growing from 42% in January to 50% in March. That trajectory and the 70%-plus priority rating for prevention of unauthorized actions are the two most mutually reinforcing signals in the entire dataset. CISOs fear the exact attack this matrix describes, and most have not deployed the controls to stop it.</p><h2>Hyperscaler stage readiness: observe, enforce, isolate</h2><p>The maturity audit tells you where your security program stands. The next question is whether your cloud platform can get you to stage two and stage three, or whether you are building those capabilities yourself. Patel put it bluntly: “It’s not just about authenticating once and then letting the agent run wild.” A stage-three platform running a stage-one deployment pattern gives you stage-one risk.</p><p>VentureBeat Pulse data surfaces a structural tension in this grid. OpenAI leads enterprise AI security deployments at 21% to 26% across the three survey waves, making the same provider that creates the AI risk also the primary security layer. The provider-as-security-vendor pattern holds across Azure, Google, and AWS. Zero-incremental-procurement convenience is winning by default. Whether that concentration is a feature or a single point of failure depends on how far the enterprise has progressed past stage one.</p><table><tbody><tr><td><p><b>Provider</b></p></td><td><p><b>Identity Primitive (Stage 2)</b></p></td><td><p><b>Enforcement Control (Stage 2)</b></p></td><td><p><b>Isolation Primitive (Stage 3)</b></p></td><td><p><b>Gap as of April 2026 </b></p></td></tr><tr><td><p><b>Microsoft Azure</b></p></td><td><p>Entra ID agent scoping. Agent 365 maps agents to owners. GA.</p></td><td><p>Copilot Studio DLP policies. Purview for agent output classification. GA.</p></td><td><p>Azure Confidential Containers for agent workloads. Preview. No per-agent sandbox at GA.</p></td><td><p>No agent-to-agent identity verification. No MCP governance layer. Agent 365 monitors but cannot block in-flight tool calls.</p></td></tr><tr><td><p><b>Anthropic</b></p></td><td><p>Managed Agents: per-agent scoped permissions, credential mgmt. Beta (April 8, 2026). $0.08/session-hour.</p></td><td><p>Tool-use permissions, system prompt enforcement, and built-in guardrails. GA.</p></td><td><p>Managed Agents sandbox: isolated containers per session, execution-chain auditability. Beta. Allianz, Asana, Rakuten, and Sentry are in production.</p></td><td><p>Beta pricing/SLA not public. Session data in Anthropic-managed DB (lock-in risk per VentureBeat research). GA timing TBD.</p></td></tr><tr><td><p><b>Google Cloud</b></p></td><td><p>Vertex AI service accounts for model endpoints. IAM Conditions for agent traffic. GA.</p></td><td><p>VPC Service Controls for agent network boundaries. Model Armor for prompt/response filtering. GA.</p></td><td><p>Confidential VMs for agent workloads. GA. Agent-specific sandbox in preview.</p></td><td><p>Agent identity ships as a service account, not an agent-native principal. No agent-to-agent delegation audit. Model Armor does not inspect tool-call payloads.</p></td></tr><tr><td><p><b>OpenAI</b></p></td><td><p>Assistants API: function-call permissions, structured outputs. Agents SDK. GA.</p></td><td><p>Agents SDK guardrails, input/output validation. GA.</p></td><td><p>Agents SDK Python sandbox. Beta (API and defaults subject to change before GA per OpenAI docs). TypeScript sandbox confirmed, not shipped.</p></td><td><p>No cross-provider identity federation. Agent memory forensics limited to session scope. No kill switch API. No MCP tool-description inspection.</p></td></tr><tr><td><p><b>AWS</b></p></td><td><p>Bedrock model invocation logging. IAM policies for model access. CloudTrail for agent API calls. GA.</p></td><td><p>Bedrock Guardrails for content filtering. Lambda resource policies for agent functions. GA.</p></td><td><p>Lambda isolation per agent function. GA. Bedrock agent-level sandboxing on roadmap, not shipped.</p></td><td><p>No unified agent control plane across Bedrock + SageMaker + Lambda. No agent identity standard. Guardrails do not inspect MCP tool descriptions.</p></td></tr></tbody></table><p><i>Status as of April 15, 2026. GA = generally available. Preview/Beta = not production-hardened. “What’s Missing” column reflects VentureBeat’s analysis of publicly documented capabilities; gaps may narrow as vendors ship updates.</i></p><p>No provider in this grid ships a complete stage-three stack today. Most enterprises assemble isolation from existing cloud building blocks. That is a defensible choice if it is a deliberate one. Waiting for a vendor to close the gap without acknowledging the gap is not a strategy.</p><p>The grid above covers hyperscaler-native SDKs. A large segment of AI builders deploys through open-source orchestration frameworks like LangChain, CrewAI, and LlamaIndex that bypass hyperscaler IAM entirely. These frameworks lack native stage-two primitives. There is no scoped agent identity, no tool-call approval workflow, and no built-in audit trails. Enterprises running agents through open-source orchestration need to layer enforcement and isolation on top, not assume the framework provides it.</p><p>VentureBeat’s survey quantifies the pressure. Policy enforcement consistency grew from 39.5% to 46% between January and February, the largest consistent gain of any capability criterion. Enterprises running agents across OpenAI, Anthropic, and Azure need enforcement that works the same way regardless of which model executes the task. Provider-native controls enforce policy within that provider’s runtime only. Open-source orchestration frameworks enforce it nowhere.</p><p>One counterargument deserves acknowledgment: not every agent deployment needs stage three. A read-only summarization agent with no tool access and no write permissions may rationally stop at stage one. The sequencing failure this audit addresses is not that monitoring exists. It is that enterprises running agents with write access, shared credentials, and agent-to-agent delegation are treating monitoring as sufficient. For those deployments, stage one is not a strategy. It is a gap.</p><h2>Allianz shows stage-three in production</h2><p>Allianz, one of the world’s largest insurance and asset management companies, is running Claude Managed Agents across insurance workflows, with Claude Code deployed to technical teams and a dedicated AI logging system for regulatory transparency, per <a href="https://siliconangle.com/2026/04/08/anthropic-launches-claude-managed-agents-speed-ai-agent-development/">Anthropic’s April 8 announcement</a>. Asana, Rakuten, Sentry, and Notion are in production on the same beta. Stage-three isolation, per-agent permissioning, and execution-chain auditability are deployable now, not roadmap. The gating question is whether the enterprise has sequenced the work to use them.</p><h2>The 90-day remediation sequence</h2><p><b>Days 1–30: Inventory and baseline.</b> Map every agent to a named owner. Log all tool calls. Revoke shared API keys. Deploy read-only monitoring across all agent API traffic. Run <a href="https://github.com/invariantlabs-ai/mcp-scan">mcp-scan</a> against every registered MCP server. CrowdStrike detects 1,800 AI applications across enterprise endpoints; your inventory should be equally comprehensive. Output: agent registry with permission matrix, MCP scan report.</p><p><b>Days 31–60: Enforce and scope.</b> Assign scoped identities to every agent. Deploy tool-call approval workflows for write operations. Integrate agent activity logs into existing SIEM. Run a tabletop exercise: What happens when an agent spawns an agent? Conduct a canary-token test from the prescriptive matrix. Output: IAM policy set, approval workflow, SIEM integration, canary-token test results.</p><p><b>Days 61–90: Isolate and test.</b> Sandbox high-risk agent workloads (PHI, PII, financial transactions). Enforce per-session least privilege. Require human sign-off for agent-to-agent delegation. Red-team the isolation boundary using the stage-three detection test from the matrix. Output: sandboxed execution environment, red-team report, board-ready risk summary with regulatory exposure mapped to HIPAA tier and FINRA guidance.</p><h2>What changes in the next 30 days</h2><p>EU AI Act <a href="https://artificialintelligenceact.eu/article/14/">Article 14</a> human-oversight obligations take effect August 2, 2026. Programs without named owners and execution trace capability face enforcement, not operational risk.</p><p>Anthropic’s <a href="https://platform.claude.com/docs/en/managed-agents/overview">Claude Managed Agents</a> is in public beta at $0.08 per session-hour. GA timing, production SLAs, and final pricing have not been announced.</p><p>OpenAI <a href="https://techcrunch.com/2026/04/15/openai-updates-its-agents-sdk-to-help-enterprises-build-safer-more-capable-agents/">Agents SDK</a> ships TypeScript support for sandbox and harness capabilities in a future release, per the company’s April 15 announcement. Stage-three sandbox becomes available to JavaScript agent stacks when it ships.</p><h2>What the sequence requires</h2><p>McKinsey’s <a href="https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era">2026 AI Trust Maturity Survey</a> pegs the average enterprise at 2.3 out of 4.0 on its RAI maturity model, up from 2.0 in 2025 but still an enforcement-stage number; only one-third of the ~500 organizations surveyed report maturity levels of three or higher in governance. Seventy percent have not finished the transition to stage three. <a href="https://www.armosec.io/blog/ai-agent-sandboxing-progressive-enforcement-guide/">ARMO’s progressive enforcement methodology</a> gives you the path: behavioral profiles in observation, permission baselines in selective enforcement, and full least privilege once baselines stabilize. Monitoring investment was not wasted. It was stage one of three. The organizations stuck in the data treated it as the destination.</p><p>The budget data makes the constraint explicit. The share of enterprises reporting flat AI security budgets doubled from 7.9% in January to 16% in February in VentureBeat's survey, with the March directional reading at 20%. Organizations expanding agent deployments without increasing security investment are accumulating security debt at machine speed. Meanwhile, the share reporting no agent security tooling at all fell from 13% in January to 5% in March. Progress, but one in twenty enterprises running agents in production still has zero dedicated security infrastructure around them.</p><h2>About this research</h2><p><i>Total qualified respondents: 108. VentureBeat Pulse AI Security and Trust is a three-wave VentureBeat survey run January 6 through March 15, 2026. Qualified sample (organizations 100+ employees): January n=38, February n=50, March n=20. Primary analysis runs from January to February; March is directional. Industry mix: Tech/Software 52.8%, Financial Services 10.2%, Healthcare 8.3%, Education 6.5%, Telecom/Media 4.6%, Manufacturing 4.6%, Retail 3.7%, other 9.3%. Seniority: VP/Director 34.3%, Manager 29.6%, IC 22.2%, C-Suite 9.3%.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacStories Weekly: Issue 509]]></title>
<description><![CDATA[This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:The New Frontier of App Automation Comes From the Mid-1960s, by FedericoJust Record to Notion, by JohnSomnus: Sleep Intelligence, by John
	
						This Story is for Club Members

				Get weekly ne...]]></description>
<link>https://tsecurity.de/de/3442773/ios-mac-os/macstories-weekly-issue-509/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3442773/ios-mac-os/macstories-weekly-issue-509/</guid>
<pubDate>Fri, 17 Apr 2026 18:54:54 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<nav class="ms-issue-toc"><p>This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:</p><ul><li><a href="https://www.macstories.net/club/macstories-weekly-issue-509/#the-new-frontier-of-app-automation-comes-from-the-mid-1960s" class="ms-issue-toc-item">The New Frontier of App Automation Comes From the Mid-1960s, by Federico</a></li><li><a href="https://www.macstories.net/club/macstories-weekly-issue-509/#just-record-to-notion" class="ms-issue-toc-item">Just Record to Notion, by John</a></li><li><a href="https://www.macstories.net/club/macstories-weekly-issue-509/#somnus-sleep-intelligence" class="ms-issue-toc-item">Somnus: Sleep Intelligence, by John</a></li></ul></nav>
	<div class="club-notice-restricted plan-">
						<h2>This Story is for Club Members</h2>

				<p>Get weekly newsletters, exclusive stories, member downloads, and ad-free version of MacStories Unwind.</p>
				<p><br><a href="https://www.macstories.net/plans?utm_source=ms&amp;utm_medium=web" class="button">See Plans</a></p>

									 

					<p>Already a member? <a href="https://www.macstories.net/?memberful_endpoint=auth">Sign in</a></p>
								</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Salesforce launches Headless 360 to turn its entire platform into infrastructure for AI agents]]></title>
<description><![CDATA[Salesforce on Wednesday unveiled the most ambitious architectural transformation in its 27-year history, introducing "Headless 360" — a sweeping initiative that exposes every capability in its platform as an API, MCP tool, or CLI command so AI agents can operate the entire system without ever ope...]]></description>
<link>https://tsecurity.de/de/3440222/it-nachrichten/salesforce-launches-headless-360-to-turn-its-entire-platform-into-infrastructure-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3440222/it-nachrichten/salesforce-launches-headless-360-to-turn-its-entire-platform-into-infrastructure-for-ai-agents/</guid>
<pubDate>Thu, 16 Apr 2026 23:32:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.salesforce.com/">Salesforce</a> on Wednesday unveiled the most ambitious architectural transformation in its 27-year history, introducing "<a href="https://www.salesforce.com/news/stories/salesforce-headless-360-announcement/">Headless 360</a>" — a sweeping initiative that exposes every capability in its platform as an API, MCP tool, or CLI command so AI agents can operate the entire system without ever opening a browser.</p><p>The announcement, made at the company's annual <a href="https://www.salesforce.com/tdx/">TDX developer conference</a> in San Francisco, ships more than 100 new tools and skills immediately available to developers. It marks a decisive response to the existential question hanging over enterprise software: In a world where AI agents can reason, plan, and execute, does a company still need a CRM with a graphical interface?</p><p>Salesforce's answer: No — and that's exactly the point.</p><p>"We made a decision two and a half years ago: Rebuild Salesforce for agents," the company said in its announcement. "Instead of burying capabilities behind a UI, expose them so the entire platform will be programmable and accessible from anywhere."</p><p>The timing is anything but coincidental. Salesforce finds itself navigating one of the most turbulent periods in enterprise software history — a sector-wide sell-off that has pushed the iShares Expanded Tech-Software Sector ETF <a href="https://www.cnbc.com/2026/02/26/saas-software-saaspocalypse-sell-off-ai-openai-anthropic-oracle-salesforce.html">down roughly 28%</a> from its September peak. The fear driving the decline: that AI, particularly large language models from Anthropic, OpenAI, and others, could render traditional SaaS business models obsolete.</p><p><a href="https://www.salesforce.com/news/stories/author/jayesh-govindarajan/">Jayesh Govindarjan</a>, EVP of Salesforce and one of the key architects behind the Headless 360 initiative, described the announcement as rooted not in marketing theory but in hard-won lessons from deploying agents with thousands of enterprise customers.</p><p>"The problem that emerged is the lifecycle of building an agentic system for every one of our customers on any stack, whether it's ours or somebody else's," Govindarjan told VentureBeat in an exclusive interview. "The challenge that they face is very much the software development challenge. How do I build an agent? That's only step one."</p><h2><b>More than 100 new tools give coding agents full access to the Salesforce platform for the first time</b></h2><p>Salesforce <a href="https://www.salesforce.com/news/stories/salesforce-headless-360-announcement/">Headless 360</a> rests on three pillars that collectively represent the company's attempt to redefine what an enterprise platform looks like in the agentic era.</p><p>The first pillar — build any way you want — delivers more than <a href="https://www.salesforce.com/news/stories/salesforce-headless-360-announcement/">60 new MCP (Model Context Protocol) tools</a> and 30-plus preconfigured coding skills that give external coding agents like Claude Code, Cursor, Codex, and Windsurf complete, live access to a customer's entire Salesforce org, including data, workflows, and business logic. Developers no longer need to work inside Salesforce's own IDE. They can direct AI coding agents from any terminal to build, deploy, and manage Salesforce applications.</p><p><a href="https://www.salesforce.com/service/demos/agentforce-for-service/?d=701ed000003k9a6AAA&amp;nc=701ed000003kErPAAU&amp;utm_content=701ed000003k9a6AAA&amp;utm_source=google&amp;utm_medium=paid_search&amp;utm_campaign=21111797517&amp;utm_adgroup=176814593425&amp;utm_term=agentforce%20service&amp;utm_matchtype=p&amp;gclsrc=aw.ds&amp;gad_source=1&amp;gad_campaignid=21111797517&amp;gbraid=0AAAAAD4PnrM1AwwpMOV0LfYGfxuZJZgM5&amp;gclid=Cj0KCQjwkYLPBhC3ARIsAIyHi3TDuoIJARMmz2NKtFE82f0uXfC6X5_7sZU2PPxW7600JcFhVR6KWUYaApQCEALw_wcB">Agentforce Vibes 2.0</a>, the company's own native development environment, now includes what it calls an "open agent harness" supporting both the <a href="https://code.claude.com/docs/en/agent-sdk/overview">Anthropic agent SDK</a> and the <a href="https://openai.com/index/the-next-evolution-of-the-agents-sdk/">OpenAI agents SDK</a>. As demonstrated during the keynote, developers can choose between Claude Code and OpenAI agents depending on the task, with the harness dynamically adjusting available capabilities based on the selected agent. The environment also adds multi-model support, including Claude Sonnet and GPT-5, along with full org awareness from the start.</p><p>A significant technical addition is <a href="https://developer.salesforce.com/blogs/2026/04/build-with-react-run-on-salesforce-introducing-salesforce-multi-framework">native React support on the Salesforce platform</a>. During the keynote demo, presenters built a fully functional partner service application using React — not Salesforce's own Lightning framework — that connected to org metadata via GraphQL while inheriting all platform security primitives. This opens up dramatically more expressive front-end possibilities for developers who want complete control over the visual layer.</p><p>The second pillar — deploy on any surface — centers on the new <a href="https://www.salesforce.com/agentforce/resources/maximizing-roi-with-agentforce/?d=701ed00000pAMHLAA4&amp;nc=701ed00000pBB3kAAG&amp;utm_content=701ed00000pAMHLAA4&amp;utm_source=google&amp;utm_medium=paid_search&amp;utm_campaign=21746031327&amp;utm_adgroup=192654615024&amp;utm_term=agentforce&amp;utm_matchtype=p&amp;gclsrc=aw.ds&amp;gad_source=1&amp;gad_campaignid=21746031327&amp;gbraid=0AAAAAD4PnrNSAUHeAfP8_ATTlAQ25bVP6&amp;gclid=Cj0KCQjwkYLPBhC3ARIsAIyHi3RZbLYycHjrr645-ZO9PlbrmlQ03Q9m9-aHI51Zpxv2PkWQ7rRR_tgaAv0XEALw_wcB">Agentforce Experience Layer</a>, which separates what an agent does from how it appears, rendering rich interactive components natively across Slack, mobile apps, Microsoft Teams, ChatGPT, Claude, Gemini, and any client supporting MCP apps. During the keynote, presenters defined an experience once and deployed it across six different surfaces without writing surface-specific code. The philosophical shift is significant: rather than pulling customers into a Salesforce UI, enterprises push branded, interactive agent experiences into whatever workspace their customers already inhabit.</p><p>The third pillar — build agents you can trust at scale — introduces an entirely new suite of lifecycle management tools spanning testing, evaluation, experimentation, observation, and orchestration. <a href="https://developer.salesforce.com/docs/ai/agentforce/guide/agent-script.html">Agent Script</a>, the company's new domain-specific language for defining agent behavior deterministically, is now generally available and open-sourced. A new <a href="https://help.salesforce.com/s/articleView?id=ai.agent_testing_center.htm&amp;language=en_US&amp;type=5">Testing Center </a>surfaces logic gaps and policy violations before deployment. Custom Scoring Evals let enterprises define what "good" looks like for their specific use case. And a new A/B Testing API enables running multiple agent versions against real traffic simultaneously.</p><h2><b>Why enterprise customers kept breaking their own AI agents — and how Salesforce redesigned its tooling in response</b></h2><p>Perhaps the most technically significant — and candid — portion of VentureBeat's interview with Govindarjan addressed the fundamental engineering tension at the heart of enterprise AI: agents are probabilistic systems, but enterprises demand deterministic outcomes.</p><p>Govindarjan explained that early Agentforce customers, after getting agents into production through "sheer hard work," discovered a painful reality. "They were afraid to make changes to these agents, because the whole system was brittle," he said. "You make one change and you don't know whether it's going to work 100% of the time. All the testing you did needs to be redone."</p><p>This brittleness problem drove the creation of <a href="https://developer.salesforce.com/docs/ai/agentforce/guide/agent-script.html">Agent Script</a>, which Govindarjan described as a programming language that "brings together the determinism that's in programming languages with the inherent flexibility in probabilistic systems that LLMs provide." The language functions as a single flat file — versionable, auditable — that defines a state machine governing how an agent behaves. Within that machine, enterprises specify which steps must follow explicit business logic and which can reason freely using LLM capabilities.</p><p>Salesforce <a href="https://github.com/salesforce/agentscript">open-sourced Agent Script</a> this week, and Govindarjan noted that Claude Code can already generate it natively because of its clean documentation. The approach stands in sharp contrast to the "vibe coding" movement gaining traction elsewhere in the industry. As the Wall Street Journal recently reported, <a href="https://www.wsj.com/cio-journal/meet-the-companies-vibe-coding-their-own-crms-263e500f">some companies are now attempting to vibe-code entire CRM replacements</a> — a trend Salesforce's <a href="https://www.salesforce.com/news/stories/salesforce-headless-360-announcement/">Headless 360</a> directly addresses by making its own platform the most agent-friendly substrate available.</p><p>Govindarjan described the tooling as a product of Salesforce's own internal practice. "We needed these tools to make our customers successful. Then our FDEs needed them. We hardened them, and then we gave them to our customers," he told VentureBeat. In other words, Salesforce productized its own pain.</p><h2><b>Inside the two competing AI agent architectures Salesforce says every enterprise will need</b></h2><p>Govindarjan drew a revealing distinction between two fundamentally different agentic architectures emerging in the enterprise — one for customer-facing interactions and one he linked to what he called the "<a href="https://venturebeat.com/technology/how-ralph-wiggum-went-from-the-simpsons-to-the-biggest-name-in-ai-right-now">Ralph Wiggum loop</a>."</p><p>Customer-facing agents — those deployed to interact with end customers for sales or service — demand tight deterministic control. "Before customers are willing to put these agents in front of their customers, they want to make sure that it follows a certain paradigm — a certain brand set of rules," Govindarjan told VentureBeat. Agent Script encodes these as a static graph — a defined funnel of steps with LLM reasoning embedded within each step.</p><p>The "<a href="https://venturebeat.com/technology/how-ralph-wiggum-went-from-the-simpsons-to-the-biggest-name-in-ai-right-now">Ralph Wiggum loop</a>," by contrast, represents the opposite end of the spectrum: a dynamic graph that unrolls at runtime, where the agent autonomously decides its next step based on what it learned in the previous step, killing dead-end paths and spawning new ones until the task is complete. This architecture, Govindarjan said, manifests primarily in employee-facing scenarios — developers using coding agents, salespeople running deep research loops, marketers generating campaign materials — where an expert human reviews the output before it ships.</p><p>"Ralph Wiggum loops are great for employee-facing because employees are, in essence, experts at something," Govindarjan explained. "Developers are experts at development, salespeople are experts at sales."</p><p>The critical technical insight: both architectures run on the same underlying platform and the same graph engine. "This is a dynamic graph. This is a static graph," he said. "It's all a graph underneath." That unified runtime — spanning the spectrum from tightly controlled customer interactions to free-form autonomous loops — may be Salesforce's most important technical bet, sparing enterprises from maintaining separate platforms for different agent modalities.</p><h2><b>Salesforce hedges its bets on MCP while opening its ecosystem to every major AI model and tool</b></h2><p>Salesforce's embrace of openness at TDX was striking. The platform now integrates with <a href="https://openai.com/">OpenAI</a>, <a href="https://www.anthropic.com/">Anthropic</a>, <a href="https://gemini.google.com/app">Google Gemini</a>, <a href="https://www.llama.com/">Meta's LLaMA</a>, and <a href="https://mistral.ai/models">Mistral AI</a> models. The open agent harness supports third-party agent SDKs. MCP tools work from any coding environment. And the new <a href="https://www.salesforce.com/agentforce/agentexchange/">AgentExchange marketplace</a> unifies 10,000 Salesforce apps, 2,600-plus Slack apps, and 1,000-plus Agentforce agents, tools, and MCP servers from partners including Google, Docusign, and Notion, backed by a new $50 million AgentExchange Builders Initiative.</p><p>Yet Govindarjan offered a surprisingly candid assessment of MCP itself — the protocol Anthropic created that has become a de facto standard for agent-tool communication.</p><p>"To be very honest, not at all sure" that MCP will remain the standard, he told VentureBeat. "When MCP first came along as a protocol, a lot of us engineers felt that it was a wrapper on top of a really well-written CLI — which now it is. A lot of people are saying that maybe CLI is just as good, if not better."</p><p>His approach: pragmatic flexibility. "We're not wedded to one or the other. We just use the best, and often we will offer all three. We offer an API, we offer a CLI, we offer an MCP." This hedging explains the "Headless 360" naming itself — rather than betting on a single protocol, Salesforce exposes every capability across all three access patterns, insulating itself against protocol shifts.</p><p><a href="https://engine.com/">Engine</a>, the B2B travel management company featured prominently in the keynote demos, offered a real-world proof point for the open ecosystem approach. The company built its customer service agent, Ava, in 12 days using Agentforce and now handles 50% of customer cases autonomously. Engine runs five agents across customer-facing and employee-facing functions, with Data 360 at the heart of its infrastructure and Slack as its primary workspace. "CSAT goes up, costs to deliver go down. Customers are happier. We're getting them answers faster. What's the trade off? There's no trade off," an Engine executive said during the keynote.</p><p>Underpinning all of it is a shift in how Salesforce gets paid. The company is moving from per-seat licensing to consumption-based pricing for Agentforce — a transition Govindarjan described as "a business model change and innovation for us." It's a tacit acknowledgment that when agents, not humans, are doing the work, charging per user no longer makes sense.</p><h2><b>Salesforce isn't defending the old model — it's dismantling it and betting the company on what comes next</b></h2><p>Govindarjan framed the company's evolution in architectural terms. Salesforce has organized its platform around four layers: a system of context (<a href="https://www.salesforce.com/data/demos/data-cloud/?d=7013y000002ExkzAAC&amp;nc=7013y000002EyXSAA0&amp;utm_content=7013y000002ExkzAAC&amp;utm_source=google&amp;utm_medium=paid_search&amp;utm_campaign=21134104451&amp;utm_adgroup=161913224524&amp;utm_term=salesforce%20data&amp;utm_matchtype=p&amp;gclsrc=aw.ds&amp;gad_source=1&amp;gad_campaignid=21134104451&amp;gbraid=0AAAAAD4PnrPnIjyiB0fbGAiHNB3eJEWN9&amp;gclid=Cj0KCQjwkYLPBhC3ARIsAIyHi3SevPZf6by7PpC2t5_zf3xvZWC841GkpB7PH7VBbn0QSSFAX-66eqMaAkbQEALw_wcB">Data 360</a>), a system of work (<a href="https://www.salesforce.com/products/what-is-customer-360/">Customer 360 apps</a>), a system of agency (<a href="https://www.salesforce.com/agentforce/resources/maximizing-roi-with-agentforce/?d=701ed00000pAMHNAA4&amp;nc=701ed00000pBB3mAAG&amp;utm_content=701ed00000pAMHNAA4&amp;utm_source=google&amp;utm_medium=paid_search&amp;utm_campaign=21746031327&amp;utm_adgroup=167932510533&amp;utm_term=agentforce&amp;utm_matchtype=e&amp;gclsrc=aw.ds&amp;gad_source=1&amp;gad_campaignid=21746031327&amp;gbraid=0AAAAAD4PnrNSAUHeAfP8_ATTlAQ25bVP6&amp;gclid=Cj0KCQjwkYLPBhC3ARIsAIyHi3R73LzLcCGps4kW0OwZ2C1RCUNiz9Tt0bp8U83p82IGLB1DqTHfKK0aAjykEALw_wcB">Agentforce</a>), and a system of engagement (Slack and other surfaces). Headless 360 opens every layer via programmable endpoints.</p><p>"What you saw today, what we're doing now, is we're opening up every single layer, right, with MCP tools, so we can go build the agentic experiences that are needed," Govindarjan told VentureBeat. "I think you're seeing a company transforming itself."</p><p>Whether that transformation succeeds will depend on execution across thousands of customer deployments, the staying power of MCP and related protocols, and the fundamental question of whether incumbent enterprise platforms can move fast enough to remain relevant when AI agents can increasingly build new systems from scratch. The software sector's bear market, the financial pressures bearing down on the entire industry, and the breathtaking pace of LLM improvement all conspire to make this one of the highest-stakes bets in enterprise technology.</p><p>But there is an irony embedded in Salesforce's predicament that <a href="https://www.salesforce.com/news/stories/salesforce-headless-360-announcement/">Headless 360</a> makes explicit. The very AI capabilities that threaten to displace traditional software are the same capabilities that Salesforce now harnesses to rebuild itself. Every coding agent that could theoretically replace a CRM is now, through Headless 360, a coding agent that builds on top of one. The company is not arguing that agents won't change the game. It's arguing that decades of accumulated enterprise data, workflows, trust layers, and institutional logic give it something no coding agent can generate from a blank prompt.</p><p>As <a href="http://google.com/search?q=mad+money+marc+benioff&amp;oq=mad+money+marc+benioff&amp;gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIGCAEQRRg80gEINDE3MWowajeoAgCwAgA&amp;sourceid=chrome&amp;ie=UTF-8">Benioff declared on CNBC's Mad Money</a> in March: "The software industry is still alive, well and growing." Headless 360 is his company's most forceful attempt to prove him right — by tearing down the walls of the very platform that made Salesforce famous and inviting every agent in the world to walk through the front door.</p><p>Parker Harris, Salesforce's co-founder, captured the bet most succinctly in a question he posed last month: "Why should you ever log into Salesforce again?"</p><p>If Headless 360 works as designed, the answer is: You shouldn't have to. And that, Salesforce is wagering, is precisely what will keep you paying for it.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI drastically updates Codex desktop app to use all other apps on your computer, generate images, preview webpages]]></title>
<description><![CDATA[Confirming it has reached 3 million weekly developers, OpenAI is massively updating its Codex developer environment via its Mac and Windows desktop apps today to bring it closer to the “Super App” the company has confirmed it is pursuing.Before today, Codex was primarily an environment for using ...]]></description>
<link>https://tsecurity.de/de/3439971/it-nachrichten/openai-drastically-updates-codex-desktop-app-to-use-all-other-apps-on-your-computer-generate-images-preview-webpages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3439971/it-nachrichten/openai-drastically-updates-codex-desktop-app-to-use-all-other-apps-on-your-computer-generate-images-preview-webpages/</guid>
<pubDate>Thu, 16 Apr 2026 21:17:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Confirming it has reached 3 million weekly developers, <a href="https://openai.com/index/codex-for-almost-everything/">OpenAI is massively updating its Codex developer environment</a> via its Mac and Windows desktop apps today to bring it closer to the “Super App” the company has confirmed it is pursuing.</p><p>Before today, Codex was primarily an environment for using OpenAI’s underlying language models to write, edit, debug and ship software as directed by the user. </p><p>Now, Codex will be able to access all of the other apps on your computer, surface relevant information from within them to you when asked or proactively, take actions as directed in said applications, and, in the case of Mac users, even do so while you continue manually using your computer simultaneously to your agents working in the background.</p><div></div><p>Andrew Ambrosino, an OpenAI technical staffer on the Codex team, described the change plainly in an embargoed press briefing I attended virtually yesterday: “Codex can actually click on apps, launch apps, and type into apps. This works with any apps on your machine.” </p><p>Codex on desktop is further getting its own built-in web browser, allowing users to preview their front-end development, and a directly integrated pipeline to OpenAI’s powerful AI image generation model gpt-image-1.5, allowing users to generate imagery for their projects — everything from websites to presentations to full playable PC games with hundreds of assets — all in the same style.</p><p>As Thibault "Tibo" Sottiaux, Head of Codex at OpenAI, said during the briefing: “It’s not just about the growth. It is putting a very capable agent in the hands of builders, and now we’re seeing that we’re able to expand and do a lot more work entirely across your computer"</p><p>Asked why OpenAI was pursuing all this in Codex, not its more recognizable flagship app, ChatGPT, Sottiaux told VentureBeat: “Codex is our most powerful agent.It already worked on your computer, and so we’re expanding the capabilities there. It felt very natural. We will make it make sense at some point."</p><p>The update comes as rival Anthropic has previously courted similar use cases with the launch of its <a href="https://venturebeat.com/orchestration/anthropic-says-claude-code-transformed-programming-now-claude-cowork-is">Claude Cowork</a> and redesigned <a href="https://venturebeat.com/orchestration/we-tested-anthropics-redesigned-claude-code-desktop-app-and-routines-heres-what-enterprises-should-know">Claude Code desktop app views</a>, all available within the Claude desktop app for Mac and Windows. But Claude does not allow for simultaneous background app cursor usage from the desktop app across all of a user's apps like Codex does.</p><h2><b>Multiple agentic computer use workflows in the background on macOS</b></h2><p>The most significant technological leap in this release is "Computer Use," limited for now to macOS users.</p><p>This feature allows Codex to break out of the traditional chatbot container to "see, click, and type" across all applications on a machine.</p><p>Crucially, this happens in the background. "It can use apps on your computer in the background, as opposed to taking over your entire computer," explained Caffrey Lynch of OpenAI’s developer product communications. </p><p>This enables "multi-agent" workflows where Codex might be testing a frontend change or triaging a JIRA ticket while the developer continues working in a different application.</p><p>For Windows users, the core Codex desktop app remains available and supported — as does pulling information in from those apps to surface to the user in Codex  — though it lacks the cursor-level background interaction available on Mac at launch.</p><h2><b>A one-stop shop for end-to-end software development</b></h2><p>Beyond operating the OS, OpenAI is doubling down on the "Software Development Lifecycle" (SDLC). The Codex app now functions more like a unified workspace, supporting everything from GitHub PR reviews to managing remote infrastructure.</p><p>"The simplest way to think about this release is teaching Codex and the app to work across a much larger surface area," said Andrew Ambrosino, lead of Codex app development. This surface area now includes:</p><ul><li><p><b>Integrated Browser</b>: An in-app browser allows developers to iterate on frontend designs by commenting directly on DOM elements, providing precise instructions for the agent to follow.</p></li><li><p><b>Visual Primitives</b>: By integrating gpt-image-1.5, Codex can now generate and iterate on images for mockups and game assets directly within the development workflow.</p></li><li><p><b>Expanded Sidebar</b>: The app now includes rich previews for non-code files such as PDFs, spreadsheets, and slide decks, alongside a summary pane to track agent plans and sources.</p></li><li><p><b>Terminal &amp; SSH</b>: The update adds support for multiple terminal tabs and an alpha feature for connecting to remote devboxes via SSH.</p></li></ul><p>To connect these disparate tasks, OpenAI is releasing more than 90 new plugins. These connectors—including CircleCI, GitLab, and Microsoft Suite—allow the agent to gather context and take action across the entire toolchain a developer uses daily.</p><p>In a demo video shown off during the briefing, OpenAI presented an example showing the user typing into the Codex prompt entry field, “Can you check Slack, Gmail, Google Calendar, and Notion and tell me what needs my attention?” showing how Codex can now scan across multiple apps and gather information from them all in single prompt, and surface what matters most to the user.</p><p>“You can @ mention them if you want Codex to use a specific app, or if not, Codex can discover which apps to use,” Ambrosino said.</p><h2><b>The ‘heartbeat’ of productivity</b></h2><p>One of the more subtle but powerful shifts is the introduction of persistent agency. Through "Heartbeat Automations," Codex can now schedule future work for itself and "wake up" to continue long-term tasks. </p><p>This allows teams to set up agents that monitor Slack channels or Notion docs and proactively update documentation or landing PRs.</p><p>This is supported by a new "Memory" feature, currently in preview. Memory allows Codex to remember personal preferences, previous corrections, and gathered information, reducing the need for extensive custom instructions in every new session.</p><p>"As you use Codex, Codex also becomes better at being proactive," noted Sottiaux.</p><p>This proactivity manifests in a "daily brief" style feature where the app suggests how to start the day by identifying open Google Doc comments or relevant Slack context.</p><p>It's similar in spirit and practice to the new <a href="https://venturebeat.com/orchestration/we-tested-anthropics-redesigned-claude-code-desktop-app-and-routines-heres-what-enterprises-should-know">"Routines" feature launched by Anthropic for its Claude Code product</a> earlier this week.</p><h2><b>Licensing, pricing, and availability</b></h2><p>OpenAI has recently transitioned toward a more flexible pricing model for teams, including a $100 plan and pay-as-you-go options to accommodate the increased usage of autonomous agents. For individual users, these updates are rolling out today to those signed in to the Codex desktop app with ChatGPT.</p><p>While the <b>Codex desktop app is available on both macOS and Windows</b>, the rollout of specific features is tiered:</p><ul><li><p><b>Background Computer Use</b>: macOS only at launch.</p></li><li><p><b>Personalization (Memory/Suggestions)</b>: Coming soon for Enterprise, Edu, EU, and UK users.</p></li><li><p><b>Core Software Development Life Cycle Updates</b>: Available to all desktop app users starting today.</p></li></ul><h2><b>The vision: from developer tool to Super App for all</b></h2><p>When asked if these features represent the foundation of an AI "Super App," Sottiaux confirmed the strategy: "We’re building the Super App in the open and evolving it out of the Codex app".</p><p>The goal is to address the reality that developers spend a majority of their time on coordination and context-gathering rather than writing code. </p><p>By bringing Codex closer to the operating system and the broader ecosystem of developer tools, OpenAI is positioning it as the central nervous system for modern software development.</p><p>"Our mission is to ensure that AGI benefits all of humanity," the company stated in its official announcement. "That means narrowing the gap between what people can imagine and what they can actually build".</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Now you can break up with big tech at a bar: ‘cybersecurity disguised as a party’]]></title>
<description><![CDATA[These digital security organizers bring the fight for online privacy to dance parties, wine meetups and reading groupsImani Thompson shows up at Wonderville Bar in Brooklyn looking ready for a DJ set, or to drink, or to dance the night away with friends. While she’ll probably do the latter, she’s...]]></description>
<link>https://tsecurity.de/de/3439849/it-nachrichten/now-you-can-break-up-with-big-tech-at-a-bar-cybersecurity-disguised-as-a-party/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3439849/it-nachrichten/now-you-can-break-up-with-big-tech-at-a-bar-cybersecurity-disguised-as-a-party/</guid>
<pubDate>Thu, 16 Apr 2026 20:17:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>These digital security organizers bring the fight for online privacy to dance parties, wine meetups and reading groups</p><p>Imani Thompson shows up at Wonderville Bar in Brooklyn looking ready for a DJ set, or to drink, or to dance the night away with friends. While she’ll probably do the latter, she’s also a cybersecurity organizer leading the evening’s event.</p><p>Thompson is the host, along with the New York City-based tech organizing coalition Cypurr Collective, of <a href="https://shaded-tune-076.notion.site/Break-Up-With-Google-2fa921651f1980b7a922d5f07ad89eaf">Break Up With Google</a>. Its purpose isn’t a mystery; the main goal is to help attenders understand how to mitigate their vulnerability to <a href="https://ssd.eff.org/#index">surveillance</a> through major tech services. But it’s also important for people to have fun while they do it, Thompson said – hence the DJs playing until the wee hours of the morning.</p> <a href="https://www.theguardian.com/us-news/2026/apr/16/big-tech-breakup-parties">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic releases Claude Opus 4.7, narrowly retaking lead for most powerful generally available LLM]]></title>
<description><![CDATA[Anthropic is publicly releasing its most powerful large language model yet, Claude Opus 4.7, today — as it continues to keep an even more powerful successor, Mythos, restricted to a small number of external enterprise partners for cybersecurity testing and patching vulnerabilities in the software...]]></description>
<link>https://tsecurity.de/de/3439822/it-nachrichten/anthropic-releases-claude-opus-47-narrowly-retaking-lead-for-most-powerful-generally-available-llm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3439822/it-nachrichten/anthropic-releases-claude-opus-47-narrowly-retaking-lead-for-most-powerful-generally-available-llm/</guid>
<pubDate>Thu, 16 Apr 2026 20:03:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Anthropic is publicly releasing its most powerful large language model yet,<a href="https://www.anthropic.com/news/claude-opus-4-7"> Claude Opus 4.7</a>, today — as it continues to keep an<a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release"> even more powerful successor, Mythos,</a> restricted to a small number of external enterprise partners for <a href="https://venturebeat.com/security/mythos-detection-ceiling-security-teams-new-playbook">cybersecurity testing and patching vulnerabilities</a> in the software said enterprises use (which Mythos exposed rapidly).</p><p>The big headlines are that Opus 4.7 exceeds its most direct rivals — OpenAI's GPT-5.4, <a href="https://venturebeat.com/technology/openai-launches-gpt-5-4-with-native-computer-use-mode-financial-plugins-for">released in early March 2026</a>, scarcely more than a month ago; and <a href="https://venturebeat.com/technology/google-launches-gemini-3-1-pro-retaking-ai-crown-with-2x-reasoning">Google's latest flagship model Gemini 3.1 Pro from February</a> — on key benchmarks including agentic coding, scaled tool-use, agentic computer use, and financial analysis. </p><p>But also, it's notable how tight the race is getting: on directly comparable benchmarks, Opus 4.7 only leads GPT-5.4 by 7-4.</p><p>It currently leads the market on the GDPVal-AA knowledge work evaluation with an Elo score of 1753, surpassing both GPT-5.4 (1674) and Gemini 3.1 Pro (1314). </p><p>Yet, the model does not represent a "clean sweep" across all categories. </p><p>Competitors like GPT-5.4 and Gemini 3.1 Pro still hold the lead in specific domains such as agentic search, where GPT-5.4 scores 89.3% compared to Opus 4.7’s 79.3%, as well as in multilingual Q&amp;A and raw terminal-based coding. </p><p>This positioning defines Opus 4.7 not as a unilateral victor in all AI tasks, but as a specialized powerhouse optimized for the reliability and long-horizon autonomy required by the burgeoning agentic economy.</p><p>Claude Opus 4.7 is available today across all major cloud platforms, including Amazon Bedrock, Google Cloud’s Vertex AI, and Microsoft Foundry, with <a href="https://platform.claude.com/docs/en/about-claude/models/overview">API pricing held steady at $5/$25 per million tokens</a>.</p><h2><b>Improvement in hard sciences and agentic workflows</b></h2><p>Claude Opus 4.7 is a direct evolution of the Opus 4.6 architecture, but its performance delta is most visible in the "hard" sciences of agentic workflows: software engineering and complex document reasoning. </p><p>At its core, the model has been re-tuned to exhibit what Anthropic describes as "rigor". This isn't just marketing parlance; it refers to the model’s new ability to devise its own verification steps before reporting a task as complete. </p><p>For example, in internal tests, the model was observed building a Rust-based text-to-speech engine from scratch and then independently feeding its own generated audio through a separate speech recognizer to verify the output against a Python reference. </p><p>This level of autonomous self-correction is designed to reduce the "hallucination loops" that often plague earlier iterations of agentic software.</p><p>The most significant architectural upgrade is the move to high-resolution multimodal support. Opus 4.7 can now process images up to 2,576 pixels on their longest edge—roughly 3.75 megapixels. </p><p>This represents a three-fold increase in resolution compared to previous iterations. For developers building "computer-use" agents that must navigate dense, high-DPI interfaces or for analysts extracting data from intricate technical diagrams, this change effectively removes the "blurry vision" ceiling that previously limited autonomous navigation. </p><p>This visual acuity is reflected in benchmarks from XBOW, where the model jumped from a 54.5% success rate in visual-acuity tests to 98.5%.</p><p>On the benchmark front, Opus 4.7 has claimed the top spot in several critical categories:</p><ul><li><p><b>Knowledge Work (GDPVal-AA):</b> It achieved an Elo score of 1753, notably outperforming GPT-5.4 (1674) and Gemini 3.1 Pro (1314).</p></li><li><p><b>Agentic Coding (SWE-bench Pro):</b> The model resolved 64.3% of tasks, compared to 53.4% for its predecessor.</p></li><li><p><b>Graduate-Level Reasoning (GPQA Diamond):</b> It reached 94.2%, maintaining parity with the industry's most advanced models while improving on its internal consistency.</p></li><li><p><b>Visual Reasoning (arXiv Reasoning):</b> With tools, the model scored 91.0%, a meaningful jump from the 84.7% seen in Opus 4.6.</p></li></ul><p>Crucially, Anthropic warns that this increased precision requires a shift in how users approach prompting. Opus 4.7 follows instructions literally. While older models might "read between the lines" and interpret ambiguous prompts loosely, Opus 4.7 executes the exact text provided. This means that legacy prompt libraries may require re-tuning to avoid unexpected results caused by the model’s strict adherence to the letter of the request.</p><h2><b>Controlling the 'thinking' budget</b></h2><p>The "agentic" nature of Opus 4.7—its tendency to pause, plan, and verify—comes with a trade-off in token consumption and latency. </p><p>To address this, Anthropic is introducing a new "effort" parameter. Users can now select an xhigh (extra high) effort level, positioned between high and max, allowing for more granular control over the depth of reasoning the model applies to a specific problem. </p><p>Internal data shows that while max effort yields the highest scores (approaching 75% on coding tasks), the xhigh setting provides a compelling sweet spot between performance and token expenditure.</p><p>To manage the costs associated with these more "thoughtful" runs, the Claude API is introducing "task budgets" in public beta. This allows developers to set a hard ceiling on token spend for autonomous agents, ensuring that a long-running debugging session doesn't result in an unexpected bill. </p><p>These product changes signal a maturing market where AI is no longer a novelty but a production line item that requires fiscal and operational guardrails. </p><p>Furthermore, Opus 4.7 utilizes an updated tokenizer that improves text processing efficiency, though<b> it can increase the token count of certain inputs by 1.0–1.35x.</b></p><p>Within the Claude Code environment, the update brings a new <code>/ultrareview </code>command. Unlike standard code reviews that look for syntax errors, <code>/ultrareview</code> is designed to simulate a senior human reviewer, flagging subtle design flaws and logic gaps. </p><p>Additionally, "auto mode"—a setting where Claude can make autonomous decisions without constant permission prompts—has been extended to Max plan users.</p><h2><b>Licensing, safety, and the "cyber" divide</b></h2><p>Anthropic continues to walk a narrow line regarding cybersecurity. The recent announcement of the aforementioend cybersecurity partnership around Mythos with external industry partners —<a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release"> known as "Project Glasswing" </a>— highlighted the dual-use risks of high-capability models. </p><p>Consequently, while the flagship Mythos Preview model remains restricted, Opus 4.7 serves as the testbed for new automated safeguards. The model includes systems designed to detect and block requests that suggest high-risk cyberattacks, such as automated vulnerability exploitation.</p><p>To bridge the gap for the security industry, Anthropic is launching the Cyber Verification Program. This allows legitimate professionals—vulnerability researchers, penetration testers, and red-teamers—to apply for access to use Opus 4.7’s capabilities for defensive purposes. </p><p>This "verified user" model suggests a future where the most capable AI features are not universally available, but gated behind professional credentials and compliance frameworks. </p><p>In cybersecurity vulnerability reproduction (CyberGym), Opus 4.7 maintains a 73.1% success rate, trailing Mythos Preview's 83.1% but leading GPT-5.4's 66.3%.</p><h2><b>Initial reactions from industry partners reveal quantifiable improvements in production enterprise workflows</b></h2><p>Early testimonials from enterprise customers shared by Anthropic indicate there has been a tangible shift in model perception of Opus 4.7 from 4.6, going from "impressed by the tech" to "relying on the output".</p><p>Clarence Huang, VP of Technology at Intuit, noted that the model’s ability to "catch its own logical faults during the planning phase" is a game-changer for velocity. </p><p>This sentiment was echoed by Replit President Michele Catasta, who stated that the model achieved higher quality at a lower cost for tasks like log analysis and bug hunting, adding, "It really feels like a better coworker".</p><p>Other specific reactions included:</p><ul><li><p><b>Cognition (Devin):</b> CEO Scott Wu reported that Opus 4.7 can work coherently "for hours" and pushes through difficult problems that previously caused models to stall.</p></li><li><p><b>Notion:</b> Sarah Sachs, AI Lead, highlighted a 14% improvement in multi-step workflows and a 66% reduction in tool-calling errors, making the agent feel like a "true teammate".</p></li><li><p><b>Factory Droids:</b> Leo Tchourakov observed that the model carries work through to validation steps rather than "stopping halfway," a common complaint with previous frontier models.</p></li><li><p><b>Harvey:</b> Niko Grupen, Head of Applied Research, noted the model's 90.9% score on BigLaw Bench, highlighting its "noticeably smarter handling of ambiguous document editing tasks".</p></li></ul><p>Perhaps the most telling reaction came from Aj Orbach, CEO of a dashboard-building firm, who remarked on the model’s "design taste," noting that its choices for data-rich interfaces were of a quality he would "actually ship".</p><h2><b>Should enterprises immediately upgrade to Opus 4.7?</b></h2><p>For enterprise leaders, Claude Opus 4.7 represents a shift from generative AI as a "creative assistant" to a "reliable operative." </p><p>But importantly, <b>it is not a "clean win" for every use case. </b></p><p>Instead, it is a decisive upgrade for teams building autonomous agents or complex software systems. The primary value proposition is the model's new capability for self-verification and rigor; it no longer just generates an answer but creates internal tests to verify that the answer is correct before responding. This reliability makes it a superior choice for long-horizon engineering tasks where the cost of human supervision is the primary bottleneck.</p><p>However,<b> an immediate, wholesale migration from Opus 4.6 requires caution</b>. The model's increased literalism in instruction following means that prompts engineered to be "loose" or conversational with previous versions may now produce unexpected or overly rigid results. </p><p>Furthermore, enterprises must prepare for a significant increase in operational costs. Opus 4.7 uses an updated tokenizer that can increase input token counts by 1.0–1.35x, and its tendency to "think harder" at high effort levels results in higher output token consumption. </p><p>For <b>legacy applications where prompts are fragile and margins are thin, a phased rollout with significant re-tuning is recommended.</b></p><h2><b>Where it puts Anthropic in the AI race</b></h2><p>This release arrives at a paradoxical moment for Anthropic. Financially, the company is an undisputed juggernaut, with <a href="https://techcrunch.com/2026/04/15/anthropic-shrugs-off-vc-funding-offers-valuing-it-at-800b-for-now/">venture capital firms reportedly extending investment offers at a staggering $800 billion</a> valuation—more than double its $380 billion Series G valuation from February 2026. </p><p>This momentum is fueled by explosive growth, with the company’s annual run-rate revenue skyrocketing to $30 billion in April 2026, driven largely by enterprise adoption and the success of Claude Code.</p><p>Yet, this commercial success is being contested by intense regulatory and technical friction. <a href="https://venturebeat.com/technology/anthropic-vs-the-pentagon-what-enterprises-should-do">Anthropic is currently embroiled in a high-stakes legal battle with the U.S. Department of War (DoW)</a>, which recently labeled the company a "supply chain risk" after Anthropic refused to allow its models to be used for mass surveillance or fully autonomous lethal weapons. </p><p>While a San Francisco judge initially blocked the designation, a <a href="https://www.axios.com/2026/04/08/anthropic-loses-bid-to-block-pentagon-blacklisting">federal appeals panel recently denied Anthropic’s bid to stay the blacklisting</a>, leaving the company excluded from lucrative defense contracts during an active military conflict.</p><p>Simultaneously, Anthropic is fending off a growing rebellion from its most loyal power users. Despite the company's "market leader" status, <a href="https://venturebeat.com/technology/is-anthropic-nerfing-claude-users-increasingly-report-performance">developers have flooded GitHub and X with accusations of "AI shrinkflation,"</a> claiming that the preceding Opus 4.6 model and Claude Code product have been quietly degraded. </p><p>Users report that recent versions are more prone to exploration loops, memory loss, and ignored instructions, leading some to describe the newly released Claude Code desktop app as "unpolished" and unbefitting a firm with a near-trillion-dollar valuation. Opus 4.7 is Anthropic's attempt to silence these critics by proving that "deep thinking" can be paired with the rigorous execution that its enterprise clients now demand.</p><p>Ultimately, Opus 4.7 is a model defined by its discipline. In a market where models are often incentivized to be "helpful" to a fault—sometimes hallucinating answers to please the user—Opus 4.7 marks a return to rigor. By allowing users to control effort, set budgets, and verify outputs, Anthropic is moving closer to the goal of a truly autonomous digital labor force. For the engineering teams at Replit, Notion, and beyond, the shift from "watching the AI work" to "managing the AI's results" has officially begun.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta isn't setting its Oversight Board free just yet]]></title>
<description><![CDATA[The Oversight Board — the policy body Meta created to weigh its most impactful moderation rulings — has seen its role within Mark Zuckerberg's empire come into question due to shifting content policy priorities and dwindling investment. The Oversight Board has taken steps to formalize its long-co...]]></description>
<link>https://tsecurity.de/de/3439295/it-nachrichten/meta-isnt-setting-its-oversight-board-free-just-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3439295/it-nachrichten/meta-isnt-setting-its-oversight-board-free-just-yet/</guid>
<pubDate>Thu, 16 Apr 2026 17:31:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Oversight Board — the policy body Meta created to weigh its most impactful moderation rulings — has seen its role within Mark Zuckerberg's empire come into question due to shifting content policy priorities and dwindling investment. The Oversight Board has taken steps to formalize its <a target="_blank" class="link" href="https://www.engadget.com/facebook-oversight-board-other-companies-202448589.html" data-i13n="cpos:1;pos:1">long-contemplated</a> desire to work with other companies, but Engadget has learned Meta has thus far declined to move forward with that process. </p><p>Over the last year, board members have become increasingly interested in artificial intelligence policy and how their experience shaping Meta's content rules could translate into advising companies in the generative AI space. That interest has intensified as some AI companies have privately signaled they would be open to working with the board, according to a source familiar with the organization who was not permitted to speak publicly. The board began talks with Meta last fall about the possibility, which would require the company to sign off on changes to the legal documents that govern the board's operations. But Meta officials have not indicated whether the company is willing to make those changes, which would likely require approval from top executives. </p><p><em>Platformer,</em> which first <a target="_blank" class="link" href="https://www.platformer.news/meta-oversight-board-funding-cancel/" data-i13n="cpos:2;pos:1">reported</a> on Meta's budget negotiations with the Oversight Board, noted that the company "has long encouraged the board to seek additional funding sources." So far, no other company has publicly shown interest in working with the group, though the board has had conversations with other firms behind the scenes. </p><p>Oversight Board co-chair Paolo Carozza told Engadget <a target="_blank" class="link" href="https://www.engadget.com/big-tech/metas-oversight-board-wants-to-expand-its-powers-in-2026-100000385.html" data-i13n="cpos:3;pos:1">in December</a> that there had been "really preliminary" discussions between the board and AI companies, though he declined to name which ones in particular. "It feels like quite a different moment now, largely because of generative AI, LLMs, chatbots [and] the way that a variety of retail-level users of these technologies are facing a whole new set of challenges and harms that's attracting a lot of scrutiny," he said at the time. </p><p>Meta has readily agreed to amend the board's governing documents in the past — like when the trust that controls the Oversight Board's budget funded a <a target="_blank" class="link" href="https://www.engadget.com/social-media/eu-residents-will-have-a-new-way-to-dispute-content-moderation-decisions-by-facebook-youtube-and-tiktok-190221606.html" data-i13n="cpos:4;pos:1">new organization</a> to mediate content moderation disputes in Europe. While Meta executives once promoted the idea of its ostensibly independent Oversight Board working with other social media platforms, the prospect of the group working with a competitor as it pursues <a target="_blank" class="link" href="https://www.engadget.com/ai/mark-zuckerberg-shares-a-confusing-vision-for-ai-superintelligence-153944322.html" data-i13n="cpos:5;pos:1">AI superintelligence</a> is apparently more complicated. </p><p>Over the last five years, board members have received briefings from officials at Meta about the inner workings of its moderation systems and other non-public details as part of their work with the company. That raises practical questions about how the board would safeguard Meta's proprietary information, as well as larger strategic questions about whether Meta would want its Oversight Board to work with some of the companies it's now fiercely competing with, the source said. It's not clear how invested Meta's current leadership is in ensuring a future for the board. Former president of global affairs Nick Clegg, who was one of the most vocal champions of the board's work, <a target="_blank" class="link" href="https://www.engadget.com/social-media/nick-clegg-is-leaving-meta-after-7-years-overseeing-its-policy-decisions-204207077.html" data-i13n="cpos:6;pos:1">left</a> the company last year.</p><p>Meanwhile, other board members have publicly made the case that the group, which consists of free speech and human rights experts from around the world, is well-positioned to guide AI companies grappling with an increasing number of real-world harms. When Anthropic published a "<a target="_blank" class="link" href="https://www.anthropic.com/constitution" data-i13n="cpos:7;pos:1">Claude Constitution</a>" earlier this year, the board published a <a target="_blank" class="link" href="https://www.oversightboard.com/news/claudes-constitution-needs-a-bill-of-rights-and-oversight/" data-i13n="cpos:8;pos:1">lengthy analysis</a> from member Suzanne Nossel arguing that Claude also needed the kind of "oversight" the board has provided for Meta. She made a similar argument for the wider AI industry in <a target="_blank" class="link" href="https://www.theguardian.com/commentisfree/2026/mar/02/meta-oversight-board-ai" data-i13n="cpos:9;pos:1">an op-ed</a> in <em>The Guardian</em> last month.</p><p>While Nossel denied that she was directly pitching the Oversight Board to Anthropic, she said that AI companies face many of the "same dilemmas" as social media platforms. "When the board was first created, there was <a target="_blank" class="link" href="https://www.engadget.com/facebook-oversight-board-other-companies-202448589.html" data-i13n="cpos:10;pos:1">the notion</a> that we might work across the industry," she told Engadget. "Now, as the world shifts toward an AI-centric paradigm, we're very interested in what our experience can bring to that conversation." </p><p>Oversight Board members, who naturally have a vested interest in expanding their purview, aren't the only members of the industry who have warned that generative AI platforms are essentially <a target="_blank" class="link" href="https://www.engadget.com/social-media/xs-open-source-algorithm-isnt-a-win-for-transparency-researchers-say-181836233.html" data-i13n="cpos:11;pos:1">speed-running</a> social media companies' playbook. A former OpenAI researcher <a target="_blank" class="no-affiliate-link link" href="https://www.nytimes.com/2026/02/11/opinion/openai-ads-chatgpt.html" data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:12;pos:1">recently wrote</a> that "OpenAI Is Making the Mistakes Facebook Made," citing the AI company's moves toward optimizing for engagement and its plans for in-app <a target="_blank" class="link" href="https://www.engadget.com/ai/openai-starts-testing-ads-in-chatgpt-191756493.html" data-i13n="cpos:13;pos:1">advertising</a>. The researcher cited Meta's Oversight Board as an example of the kind of independent governance that's needed in the AI industry.</p><p>The question of working with other companies has taken on new urgency as the Oversight Board faces the possibility that it will lose its backing from Meta. In a statement, a Meta spokesperson pointed to previous reports that Meta has committed to funding the board through 2028 and said that "nothing has changed." But a source familiar with the board tells Engadget that Meta has so far only handed over half of the smaller tranche of 2028 funds to the board amid ongoing discussions about its future, including whether it will expand its purview beyond Meta. </p><p>There are also very real questions about how the Oversight Board fits into Meta's current strategy around content moderation. Zuckerberg announced last year that Meta was <a target="_blank" class="link" href="https://www.engadget.com/social-media/meta-is-ditching-third-party-fact-checkers-on-facebook-instagram-142330246.html" data-i13n="cpos:14;pos:1">shifting away</a> from most proactive moderation, ending fact-checking in the United States and rolling back <a target="_blank" class="link" href="https://www.engadget.com/social-media/the-oversight-board-will-weigh-in-on-metas-new-hate-speech-policies-174044682.html" data-i13n="cpos:15;pos:1">hate speech</a> rules. Zuckerberg himself <a target="_blank" class="no-affiliate-link link" href="https://www.nytimes.com/2025/01/10/technology/meta-mark-zuckerberg-trump.html" data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:16;pos:1">reportedly</a> led the push for these changes following a meeting with then President-elect Donald Trump. The Oversight Board, which Meta has sometimes asked to advise on major policy changes, was not consulted. The company recently said it plans to reduce the number of human moderators in favor of <a target="_blank" class="link" href="https://www.engadget.com/social-media/meta-will-move-away-from-human-content-moderators-in-favor-of-more-ai-183000435.html" data-i13n="cpos:17;pos:1">AI-based systems</a>.</p><p>"The Oversight Board is currently engaged in meaningful discussions with Meta regarding its future and the evolution of its model to ensure the organization can address the most urgent emerging challenges in AI governance, standards, and accountability," an Oversight Board spokesperson said in a statement. "At this time, no decisions have been made about the Board’s future, and the organization’s day-to-day work and mandate remain unchanged.”</p><p>Critics have long said that the board, which has received more than $280 million from Meta, moves far too slowly. In a little more than five years of operation, the board has published more than 200 decisions about specific moderation issues, which Meta is required to uphold. Those decisions — a tiny fraction of the millions of requests it receives — can take months, though the board can opt <a target="_blank" class="link" href="https://www.engadget.com/oversight-board-says-metas-automated-tools-took-down-israel-hamas-war-content-that-didnt-break-its-rules-110034154.html" data-i13n="cpos:18;pos:1">to move more quickly</a>. The board has also made hundreds of policy recommendations, which Meta has to respond to but isn't required to implement. The company has agreed to at least some changes in response to 75 percent of recommendations, according to the board. </p><p>For the Oversight Board, working with a company besides Meta would begin to address some of the challenges it now faces. It would boost the group's credibility at a time when Meta seems to be re-evaluating its relationship with the board, and it would open up the possibility of new sources of funding. But the situation underscores another long-simmering tension when it comes to the role of the "independent" oversight organization. Meta has always been in control of how much influence the group can actually have. And it's not clear that the company is ready to let the board, which has spent the last five years learning the minutiae of Meta's content moderation and policy processes, advise the companies it's now competing with.</p><p>During its work with Meta, the Oversight Board has weighed in on its rules for AI several times. The board <a target="_blank" class="link" href="https://www.engadget.com/maliciously-edited-joe-biden-video-can-stay-on-facebook-metas-oversight-board-says-110042024.html" data-i13n="cpos:19;pos:1">has criticized</a> the company's "manipulated media" policy that governs deepfakes and other content, which led to Meta adopting <a target="_blank" class="link" href="https://www.engadget.com/meta-plans-to-more-broadly-label-ai-generated-content-152945787.html" data-i13n="cpos:20;pos:1">new rules</a> around AI labeling. In its most <a target="_blank" class="link" href="https://www.engadget.com/social-media/the-oversight-board-says-meta-needs-new-rules-for-ai-generated-content-100000268.html" data-i13n="cpos:21;pos:1">recent decision</a> dealing with AI, the board urged Meta to invest in better AI detection tools and to collaborate more closely with other platforms. The company has not yet formally responded to those recommendations. </p>This article originally appeared on Engadget at https://www.engadget.com/social-media/meta-isnt-setting-its-oversight-board-free-just-yet-153000172.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Canva starts previewing a more powerful version of its AI assistant]]></title>
<description><![CDATA[Adobe isn't the only company releasing a new AI assistant this week. Ahead of its Create event in Los Angeles today, Canva announced Canva AI 2.0.  Building on its existing AI assistant, the company is billing the release as its most significant update since the platform first launched in 2013, a...]]></description>
<link>https://tsecurity.de/de/3438796/it-nachrichten/canva-starts-previewing-a-more-powerful-version-of-its-ai-assistant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3438796/it-nachrichten/canva-starts-previewing-a-more-powerful-version-of-its-ai-assistant/</guid>
<pubDate>Thu, 16 Apr 2026 15:03:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Adobe isn't the only company <a target="_blank" class="link" href="https://www.engadget.com/apps/adobes-firefly-ai-assistant-works-across-photoshop-premiere-and-other-apps-130055883.html" data-i13n="cpos:1;pos:1">releasing a new AI assistant this week</a>. Ahead of its Create event in Los Angeles today, Canva announced Canva AI 2.0.  Building on its <a target="_blank" class="link rapid-with-clickid" href="https://shopping.yahoo.com/rdlw?merchantId=c412d544-a5e8-4f88-81a9-6cc2d98fc67c&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=9c3078e4-2eb6-4692-a18a-4b33ce67ea85&amp;featureId=text-link&amp;merchantName=Canva&amp;linkText=existing+AI+assistant&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy5jYW52YS5jb20vYWktYXNzaXN0YW50LyIsImNvbnRlbnRVdWlkIjoiOWMzMDc4ZTQtMmViNi00NjkyLWExOGEtNGIzM2NlNjdlYTg1Iiwib3JpZ2luYWxVcmwiOiJodHRwczovL3d3dy5jYW52YS5jb20vYWktYXNzaXN0YW50LyJ9&amp;signature=AQAAARzvo-UcVoggyT8HSbA7u2lgH44hW_jMzbmmP2_seKi5&amp;gcReferrer=https%3A%2F%2Fwww.canva.com%2Fai-assistant%2F" data-i13n="elm:affiliate_link;sellerN:Canva;elmt:;cpos:2;pos:1" data-original-link="https://www.canva.com/ai-assistant/">existing AI assistant</a>, the company is billing the release as its most significant update since the platform first launched in 2013, and the culmination of years of investment to build its own foundational design models. </p><p>As you might imagine, it all starts with a conversational interface that allows you to describe an idea or goal and the system will start generating a design to match. Under the hood, there's a new orchestration layer that allows the model to use all of Canva's disparate tools to accomplish complex, multi-step tasks. For instance, the company suggests you could use Canva AI to create a multi-channel advertising campaign, and the software will generate everything you need to get that off the ground. </p><figure><img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/brand_intelligence_5255.png" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/brand_intelligence_5255.png" alt="For brands, Canva AI 2.0 can adapt to their design needs. " data-uuid="5af8ae04-0ac8-47e8-a38e-89008638a0d0"><figcaption>For brands, Canva AI 2.0 can adapt to their design needs. </figcaption><div class="photo-credit">Canva</div></figure><p>If edits are required, the company says Canva AI avoids one of the pitfalls of many other image generation models. It's possible to edit every visual element the system generates, just like if they were created with a traditional image editor. As a result, you can do things like swap out images and tweak fonts without affecting any other part of a design. To bring everything together, Canva has built persistent memory into the tool. The more you use Canva AI, the better the system will get at applying your personal taste and style to future generations. According to the company, it also has a context window that is long enough to maintain coherence until you arrive at a final design.    </p><p>Alongside those enhancements, Canva is adding support for new workflows that expand what you can do with its software, starting with connections that allow its models to pull data from other apps, including Notion, Slack, Zoom, Gmail, Google Calendar and more. Users can also schedule tasks for Canva AI to complete in the background, and the company has even baked in deep research capabilities into the tool. </p><p>The coding function Canva previously offered has been upgraded to include support for HTML imports, allowing users to bring any HTML file or AI-generated experience into Canva's visual editor to tweak the design of it without breaking things. For brands, the company is also offering a tool that can process their visual identity and apply it to new and existing designs.   </p><figure><img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/canva_code_2.0_9847.png" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/canva_code_2.0_9847.png" alt="" data-uuid="77ca397a-adcb-418e-bedb-eafa3c0b6d68"><figcaption>Canva's updated coding agent now support HTML imports. </figcaption><div class="photo-credit">Canva</div></figure><p>As a casual observer, it might seem like Canva is trend chasing, but Danny Wu, the company's head of AI, argues the new AI tools represent a natural evolution for Canva. "This is something we've been dreaming of and working towards for quite a while," he tells Engadget. "Even before ChatGPT was a thing, we were thinking, 'what if we don't have a template that matches your needs?' … So I wouldn't describe this as a pivot or shift, we've been wanting to offer these kinds of capabilities all along as part of our mission to make design simple."</p><p>If you want to give Canva's new tools a try for yourself, Canva AI 2.0 is available as a research preview starting today. The first 1 million people who visit the Canva website will get first access, with availability gradually expanding to more users over the coming weeks. As before, access to Canva’s AI features remains included in the company’s free offering, though it’s also introducing a new AI Pass add-on that significantly increases rate limits for users. </p>This article originally appeared on Engadget at https://www.engadget.com/ai/canva-starts-previewing-a-more-powerful-version-of-its-ai-assistant-130000966.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian-Plugin-Missbrauch: PHANTOMPULSE-RAT in gezielten Angriffen auf Finanz- und Kryptosektor]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine neuartige Social-Engineering-Kampagne nutzt die Notiz-App Obsidian, um den bisher unbekannten Remote-Access-Trojaner PHANTOMPULSE zu verbreiten. Ziel sind Personen im Finanz- und Kryptosektor. Die Angreifer verwenden ausgeklügelte Taktiken über LinkedIn und Telegram, u...]]></description>
<link>https://tsecurity.de/de/3438716/it-security-nachrichten/obsidian-plugin-missbrauch-phantompulse-rat-in-gezielten-angriffen-auf-finanz-und-kryptosektor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3438716/it-security-nachrichten/obsidian-plugin-missbrauch-phantompulse-rat-in-gezielten-angriffen-auf-finanz-und-kryptosektor/</guid>
<pubDate>Thu, 16 Apr 2026 14:29:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-obsidian-plugin-security.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-obsidian-plugin-security.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-obsidian-plugin-security-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-obsidian-plugin-security-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-obsidian-plugin-security-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-obsidian-plugin-security-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-obsidian-plugin-security-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine neuartige Social-Engineering-Kampagne nutzt die Notiz-App Obsidian, um den bisher unbekannten Remote-Access-Trojaner PHANTOMPULSE zu verbreiten. Ziel sind Personen im Finanz- und Kryptosektor. Die Angreifer verwenden ausgeklügelte Taktiken über LinkedIn und Telegram, um Vertrauen zu gewinnen und die Opfer zur Aktivierung schädlicher Plugins zu bewegen. In einer bemerkenswerten Entwicklung der Cyberkriminalität wurde […]</p>
<div><a href="https://www.it-boltwise.de/obsidian-plugin-missbrauch-phantompulse-rat-in-gezielten-angriffen-auf-finanz-und-kryptosektor.html">... den vollständigen Artikel <strong>»Obsidian-Plugin-Missbrauch: PHANTOMPULSE-RAT in gezielten Angriffen auf Finanz- und Kryptosektor«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/obsidian-plugin-missbrauch-phantompulse-rat-in-gezielten-angriffen-auf-finanz-und-kryptosektor.html">Obsidian-Plugin-Missbrauch: PHANTOMPULSE-RAT in gezielten Angriffen auf Finanz- und Kryptosektor</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks]]></title>
<description><![CDATA[A “novel” social engineering campaign has been observed abusing Obsidian, a cross-platform note-taking application, as an initial access vector to distribute a previously undocumented Windows remote access trojan called PHANTOMPULSE in attacks targeting individuals in the financial and cryptocurr...]]></description>
<link>https://tsecurity.de/de/3438714/it-security-nachrichten/obsidian-plugin-abuse-delivers-phantompulse-rat-in-targeted-finance-crypto-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3438714/it-security-nachrichten/obsidian-plugin-abuse-delivers-phantompulse-rat-in-targeted-finance-crypto-attacks/</guid>
<pubDate>Thu, 16 Apr 2026 14:29:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A “novel” social engineering campaign has been observed abusing Obsidian, a cross-platform note-taking application, as an initial access vector to distribute a previously undocumented Windows remote access trojan called PHANTOMPULSE in attacks targeting individuals in the financial and cryptocurrency sectors. Dubbed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/obsidian-plugin-abuse-delivers-phantompulse-rat-in-targeted-finance-crypto-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/obsidian-plugin-abuse-delivers-phantompulse-rat-in-targeted-finance-crypto-attacks/">Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks]]></title>
<description><![CDATA[A "novel" social engineering campaign has been observed abusing Obsidian, a cross-platform note-taking application, as an initial access vector to distribute a previously undocumented Windows remote access trojan called PHANTOMPULSE in attacks targeting individuals in the financial and cryptocurr...]]></description>
<link>https://tsecurity.de/de/3438580/it-security-nachrichten/obsidian-plugin-abuse-delivers-phantompulse-rat-in-targeted-finance-crypto-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3438580/it-security-nachrichten/obsidian-plugin-abuse-delivers-phantompulse-rat-in-targeted-finance-crypto-attacks/</guid>
<pubDate>Thu, 16 Apr 2026 13:55:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A "novel" social engineering campaign has been observed abusing Obsidian, a cross-platform note-taking application, as an initial access vector to distribute a previously undocumented Windows remote access trojan called PHANTOMPULSE in attacks targeting individuals in the financial and cryptocurrency sectors.
Dubbed REF6598 by Elastic Security Labs, the activity has been found to leverage]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker nutzen Notiz-App Obsidian, um über LinkedIn Krypto zu stehlen - Newsbit.de]]></title>
<description><![CDATA[Hacker nutzen Notiz-App Obsidian, um über LinkedIn Krypto zu stehlen. Kryptonutzer sind Ziel einer neuen Cyberattacke, bei der Kriminelle die ...]]></description>
<link>https://tsecurity.de/de/3437611/hacking/hacker-nutzen-notiz-app-obsidian-um-ueber-linkedin-krypto-zu-stehlen-newsbitde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3437611/hacking/hacker-nutzen-notiz-app-obsidian-um-ueber-linkedin-krypto-zu-stehlen-newsbitde/</guid>
<pubDate>Thu, 16 Apr 2026 08:24:07 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Hacker</b> nutzen Notiz-App Obsidian, um über LinkedIn Krypto zu stehlen. Kryptonutzer sind Ziel einer neuen Cyberattacke, bei der Kriminelle die ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Traza raises $2.1 million led by Base10 to automate procurement workflows with AI]]></title>
<description><![CDATA[For decades, procurement has been the back office that enterprise software forgot. Billions of dollars flow through vendor negotiations, purchase orders, and supplier communications every year at the largest manufacturers and construction companies in the country — and the vast majority of that w...]]></description>
<link>https://tsecurity.de/de/3435803/it-nachrichten/traza-raises-21-million-led-by-base10-to-automate-procurement-workflows-with-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435803/it-nachrichten/traza-raises-21-million-led-by-base10-to-automate-procurement-workflows-with-ai/</guid>
<pubDate>Wed, 15 Apr 2026 16:18:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For decades, procurement has been the back office that enterprise software forgot. Billions of dollars flow through vendor negotiations, purchase orders, and supplier communications every year at the largest manufacturers and construction companies in the country — and the vast majority of that work still runs on email threads, spreadsheets, and phone calls.</p><p><a href="https://traza.ai/">Traza</a>, a newly launched startup headquartered in New York, believes the moment has arrived to change that. The company announced today the close of a $2.1 million pre-seed round led by <a href="https://base10.vc/">Base10 Partners</a>, with participation from <a href="https://www.kfund.vc/">Kfund</a>, <a href="https://superscout.co/program/a16z">a16z scouts</a>, <a href="https://www.clara.ventures/">Clara Ventures</a>, <a href="https://www.masia.vc/">Masia Ventures</a>, and a roster of angel investors including Pepe Agell, who scaled Chartboost to 700 million monthly users before its acquisition by Zynga.</p><p>The funding is modest by Silicon Valley standards. But Traza's pitch is anything but incremental: the company deploys AI agents that don't just recommend procurement actions — they execute them autonomously, handling vendor outreach, request-for-quote generation, order tracking, supplier communications, and invoice processing without continuous human supervision.</p><p>"AI is redesigning the procurement category from the ground up," said Silvestre Jara Montes, Traza's CEO and co-founder, in an exclusive interview with VentureBeat. "This wave of AI won't just build procurement software — it will rebuild how procurement works."</p><h2><b>Why procurement contracts silently lose millions after the ink dries</b></h2><p>The market Traza is targeting is enormous and, by the company's framing, spectacularly underserved. The procurement software market alone <a href="https://www.precedenceresearch.com/procurement-software-market">exceeds $8 billion</a> and grows at roughly <a href="https://www.precedenceresearch.com/procurement-software-market">10% annually</a>. But the real cost sits in the labor — the armies of people, agencies, and ad hoc workarounds required to actually run procurement operations at scale. Most enterprises meaningfully engage with only their top 20% of suppliers. The remaining 80% — the vendor outreach, order tracking, invoice reconciliation, and compliance monitoring — goes largely unmanaged.</p><p>Research from <a href="https://info.worldcc.com/closing-the-procurement-value-gap">World Commerce &amp; Contracting and Ironclad</a> finds that organizations lose an average of 11% of total contract value after agreements are signed, a phenomenon described as "post-signature value leakage." As Tim Cummins, President of WorldCC, put it: "The research shows that the 11% value gap is not caused by poor negotiation, but by how contracts are managed after signature." For a large enterprise with $500 million in annual contracted spend, that represents $55 million vanishing each year — not from bad deals, but from the operational void between what gets agreed at the negotiating table and what actually gets executed on the ground. Missed savings, unauthorized changes, and poor renewal planning are responsible for the biggest losses.</p><p>Jara Montes argues that Traza sits precisely in this gap. "The 11% spans commercial, operational, and compliance leakage. We own the operational layer — and that's where the most recoverable value sits," he said. "Supplier tail management that never happens, RFQ processes skipped because someone ran out of bandwidth, invoice discrepancies that slip through unnoticed. That's where contracts bleed value after signing, and that's exactly what we automate." The numbers from Traza's early deployments, while nascent, are striking: the company claims a 70% reduction in human hours spent on procurement tasks and procurement cycles running three times faster than manual baselines.</p><h2><b>How AI agents crossed the line from procurement copilot to autonomous worker</b></h2><p>To understand what makes Traza's approach different, it helps to understand what "AI for procurement" has meant until now. For the past several years, the term largely described dashboards, analytics layers, and recommendation engines that surfaced insights but left every decision and action in a human's hands. Products from incumbents like <a href="https://www.sap.com/products/spend-management/ariba-login.html">SAP Ariba</a> and <a href="https://www.coupa.com/">Coupa</a> — as well as newer entrants like <a href="https://ziphq.com/">Zip</a>, <a href="https://www.fairmarkit.com/">Fairmarkit</a>, and <a href="https://www.tonkean.com/">Tonkean</a> — have layered AI capabilities on top of existing systems of record. But the gap between piloting AI and achieving production-scale impact remains stark, with 49 percent of procurement teams running pilots but only 4 percent reaching meaningful deployment.</p><p>Traza's bet is that 2026 represents an inflection point. AI agents now possess the multi-step reasoning, tool use, and contextual memory required to execute full procurement workflows autonomously — from vendor discovery through invoice processing. The company frames this not as an upgrade to existing procurement software, but as an entirely new product category. "The incumbents built systems of record. They organize procurement data and they've never executed procurement work — and their AI additions don't fundamentally change that," Jara Montes said. "What they're shipping is a recommendation layer on the same underlying architecture. A human still has to act on every suggestion. We replace the operational layer entirely."</p><p>Industry data supports the thesis that enterprises are hungry for this shift. According to the <a href="https://www.ey.com/content/dam/ey-unified-site/ey-com/en-gl/services/consulting/documents/ey-gl-cpo-survey-2025-outlook-report-02-2025.pdf">2025 Global CPO Survey</a> from EY, 80 percent of global chief procurement officers plan to deploy generative AI in some capacity over the next three years, and 66 percent consider it a high priority over the next 12 months. A <a href="https://www.abiresearch.com/press/ai-adoption-surges-in-supply-chains-as-companies-prioritize-network-intelligence">2025 ABI Research survey</a> found that 76% of supply chain professionals already see autonomous AI agents as ready to handle core tasks like reordering, supplier outreach, and shipment rerouting without human intervention — and early deployments are demonstrably reducing supply chain operational costs by 20 to 35%.</p><h2><b>Inside the workflow: what Traza's AI does and where humans still make the call</b></h2><p>In a typical deployment, Traza's AI agent takes over the operational labor that currently lives in inboxes, spreadsheets, and manual follow-up chains. In a standard RFQ workflow, the agent identifies suitable suppliers, drafts and sends the request for quotes, monitors supplier responses, follows up automatically when responses lag, parses incoming quotes regardless of their format, and builds a structured comparison table ready for a human decision-maker. The key design principle is deliberate: humans remain in the loop at critical junctures.</p><p>"At critical steps — approving a purchase order, flagging a compliance issue, committing spend above a threshold — a human is always in the loop," Jara Montes explained. "That's not a limitation, it's the design. It's how you maintain the auditability enterprises require while moving faster than any manual process could. You earn expanded autonomy over time, as trust is built and results compound."</p><p>When asked about the risk of AI errors — a wrong purchase order or a missed compliance check that could prove costly — Jara Montes was direct: "Anything with meaningful financial or compliance exposure requires human approval before it executes — that's non-negotiable and baked into the architecture. Below those thresholds, the agent acts autonomously and logs everything." He added a point that reveals a subtler product insight: "Most procurement operations today are a black box — nobody has a clear picture of what's happening across the supplier tail. We make it legible." In other words, the transparency the AI agent provides may itself be a product — giving procurement leaders visibility they have never had into the long tail of supplier relationships that most enterprises simply ignore.</p><h2><b>How Traza plugs into legacy enterprise systems without ripping them out</b></h2><p>One of the recurring challenges for any enterprise AI startup is the integration question: How do you plug into the deeply entrenched, often decades-old technology stacks that large manufacturers and construction companies rely on? Traza's answer is to sit on top of existing systems rather than replace them. "We connect via API or direct integration into whatever the customer already runs — ERPs, email, supplier portals. We have reach across more than 200 enterprise tools," Jara Montes said. "We don't rip out their system, we sit on top of them."</p><p>The go-to-market motion mirrors this pragmatism. Instead of attempting a big-bang deployment, Traza runs a two-to-three-month proof of value focused on a single, specific workflow. Integrations are built at the key steps that matter for that particular use case, then expanded as the scope of the engagement grows. "We don't try to connect everything upfront — we compound integrations as we expand scope within each account," Jara Montes said. "And every integration we build compounds across customers too. Each new deployment makes the next one faster." Throughout the process, the company works side by side with the customer's team, managing complexity and helping them transition into a new way of operating. It is a notably high-touch approach for a company selling automation.</p><p>The company is already working with large manufacturers and construction companies and says they are paying, though it declines to name them publicly. "We want to earn the right to grow inside each account, not land a pilot that goes nowhere," Jara Montes said. "That's how you build something that actually sticks in enterprise."</p><h2><b>Traza bets that vertical depth in physical industry will beat horizontal AI platforms</b></h2><p>Traza enters a market that is rapidly heating up. The leading AI procurement solutions include platforms from <a href="https://www.coupa.com/">Coupa</a>, <a href="https://www.ivalua.com/">Ivalua</a>, <a href="https://www.sap.com/products/spend-management/ariba-login.html">SAP Ariba</a>, <a href="https://ziphq.com/">Zip</a>, <a href="https://www.zycus.com/">Zycus</a>, and <a href="https://www.fairmarkit.com/">Fairmarkit</a>. Keelvar provides autonomous sourcing bots capable of launching RFQs, collecting bids, and recommending optimal awards, while Tonkean offers a no-code orchestration platform using NLP and generative AI to streamline procurement intake and tail-spend management. Against this crowded field, Jara Montes draws a sharp distinction between horizontal automation tools and Traza's focus on physical industry.</p><p>"We're built specifically for the physical industry, where supplier relationships, compliance requirements, and workflow complexity are categorically different from software procurement," he said. "A generic agent doesn't survive contact with how procurement actually works in manufacturing or construction. Specificity is the moat." The competitive dynamics with major incumbents are perhaps even more consequential. SAP Ariba, Coupa, and their peers have massive installed bases and deep enterprise relationships. Jara Montes frames their AI initiatives as surface-level additions to legacy architectures — but whether Traza can convert that framing into market share at scale, especially given the gravitational pull of existing vendor relationships, remains the central strategic question.</p><p>Beneath Traza's product pitch sits a deeper strategic thesis about compounding data advantages. The company describes a two-layered learning architecture: at the agent level, Traza gets smarter across every deployment by absorbing supplier behavior patterns, RFQ response dynamics, pricing anomalies, and workflow edge cases. At the data level, each customer's information stays fully isolated. "What we're building is deep operational knowledge of how procurement actually runs in the physical industry — not how it's supposed to run according to an RFP, but how it really runs, with all the exceptions and workarounds," Jara Montes said. "That's extraordinarily hard to replicate if you're starting from scratch, and it gets harder to catch up with the more deployments we have."</p><h2><b>Three Spanish founders, one fellowship, and a plan to rewire industrial procurement</b></h2><p><a href="https://traza.ai/">Traza</a> was co-founded by three Spanish entrepreneurs — Silvestre Jara Montes, Santiago Martínez Bragado, and Sergio Ayala Miñano — who came to the United States through the <a href="https://www.goexponential.org/">Exponential Fellowship</a>, a program that brings Europe's top technical talent to the U.S. to build companies at the frontier of AI. Their backgrounds span both sides of the problem Traza is trying to solve. Jara Montes worked at Amazon and CMA CGM — one of the world's largest shipping groups — at the intersection of operations strategy and supply chain optimization. Martínez Bragado built and deployed agentic AI at Clarity AI before joining Concourse (backed by a16z, Y Combinator, and CRV) as Founding AI Engineer. Ayala Miñano comes from StackAI, one of the fastest-growing enterprise AI platforms in San Francisco, where he was a Founding Engineer.</p><p>None of the founders carry the title of Chief Procurement Officer, a gap that the company acknowledges has occasionally surfaced in buyer conversations. Jara Montes's response is characteristically direct: "Our work is the answer. The results we're generating move that conversation quickly." He noted that the company has senior procurement leaders serving as advisors who have run procurement at the scale of its target customers.</p><p>Base10 Partners, the lead investor, is a San Francisco-based venture capital firm that invests in companies automating sectors of what it calls "<a href="https://base10.vc/">the Real Economy</a>." Its portfolio includes Notion, Figma, Nubank, Stripe, and Aurora Solar. Rexhi Dollaku, General Partner at Base10, framed the investment in emphatic terms: "Supply chain and procurement is one of the largest, most underautomated markets in the Real Economy. AI agents are finally capable of doing the work, not just assisting with it." The supporting cast of investors reinforces the immigrant-founder narrative. Clara Ventures — founded by the executives behind Olapic's $130 million exit — specifically invests in driven foreign founders building in the United States, and Agell adds operational credibility from building Chartboost into a $100 million revenue business in under three years as a Spanish founder in Silicon Valley.</p><h2><b>Why $2.1 million may stretch further than it looks for an enterprise AI startup</b></h2><p>At $2.1 million, this is a deliberately small round for a company selling to large enterprises with notoriously long procurement cycles. Jara Montes argues it goes further than it appears for structural reasons. "We leverage Europe as a tech talent hub, where we have a deep network of exceptional engineers — people who want to work at the frontier of AI but have far fewer opportunities to do so than their US counterparts," he said. "We're not just lean — we're built to outcompete on capital efficiency while others are burning through runway trying to hire in San Francisco."</p><p>The go-to-market motion is designed for speed to revenue. Proofs of value are scoped, time-bounded, and converted to paying partnerships. The company says it is not running 18-month enterprise sales cycles before seeing a dollar. The milestone for the next raise is explicit: more paying customers, meaningfully stronger annual recurring revenue, and a repeatable sales motion that makes the seed round, as Jara Montes put it, "an obvious conversation."</p><p>Looking ahead, he outlined an ambitious three-year target: 20 to 30 large industrial enterprises in the U.S. and Europe running Traza across their procurement operations, with over a billion dollars in procurement spend flowing through the platform. Whether that vision is achievable depends on several interlocking variables — the pace at which AI agent capabilities continue to improve, the speed of enterprise adoption in a traditionally conservative buyer segment, and Traza's ability to navigate the competitive gauntlet of incumbents adding AI features and well-funded startups attacking adjacent workflows.</p><p>But the underlying math may be on Traza's side. In procurement, the money that disappears does not look like waste. It vanishes into inefficiency, missed obligations, unmanaged risks, and forgotten commitments — the kind of silent losses that no one tracks because no one has the bandwidth to track them. The traditional mandate of procurement, as currently configured, ends where the value gap begins: at signature. Traza is building an AI workforce that picks up where the humans leave off. For an industry that has spent decades losing $55 million at a time to the back office nobody watches, that might be precisely the point.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Obsidian’s Shell Commands Plugin Turned Into Universal Malware Launcher]]></title>
<description><![CDATA[A new attack campaign abused Obsidian’s community plugin ecosystem, turning a trusted note-taking app into a cross-platform malware-delivery platform. The operation used social engineering, synced vaults, and a weaponized Shell Commands plugin to trigger separate malware chains on Windows and mac...]]></description>
<link>https://tsecurity.de/de/3432032/it-security-nachrichten/obsidians-shell-commands-plugin-turned-into-universal-malware-launcher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3432032/it-security-nachrichten/obsidians-shell-commands-plugin-turned-into-universal-malware-launcher/</guid>
<pubDate>Tue, 14 Apr 2026 14:53:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new attack campaign abused Obsidian’s community plugin ecosystem, turning a trusted note-taking app into a cross-platform malware-delivery platform. The operation used social engineering, synced vaults, and a weaponized Shell Commands plugin to trigger separate malware chains on Windows and macOS. Security researchers say the campaign began with a fake venture capital persona that contacted […]</p>
<p>The post <a href="https://cyberpress.org/obsidian-plugin-becomes-malware-launcher/">Obsidian’s Shell Commands Plugin Turned Into Universal Malware Launcher</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,13ms -->