<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=picoclaw+openclaw+whats+difference%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Fri, 31 Jul 2026 20:20:51 +0200</lastBuildDate>
<pubDate>Fri, 31 Jul 2026 20:20:51 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=picoclaw+openclaw+whats+difference%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=picoclaw+openclaw+whats+difference%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CVE-2026-17458 | mf-yang openclaw-cn up to 0.2.1 Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery (Issue 562 / EUVD-2026-49053)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery.

This vul...]]></description>
<link>https://tsecurity.de/de/3695625/sicherheitsluecken/cve-2026-17458-mf-yang-openclaw-cn-up-to-021-browser-control-http-api-agentactts-clickviaplaywright-server-side-request-forgery-issue-562-euvd-2026-49053/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695625/sicherheitsluecken/cve-2026-17458-mf-yang-openclaw-cn-up-to-021-browser-control-http-api-agentactts-clickviaplaywright-server-side-request-forgery-issue-562-euvd-2026-49053/</guid>
<pubDate>Sun, 26 Jul 2026 14:29:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/mf-yang:openclaw-cn">mf-yang openclaw-cn up to 0.2.1</a>. This affects the function <code>clickViaPlaywright</code> of the file <em>src/browser/routes/agent.act.ts</em> of the component <em>Browser Control HTTP API</em>. Performing a manipulation results in server-side request forgery.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-17458">CVE-2026-17458</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-17457 | mf-yang openclaw-cn up to 0.2.1 Scheme navigation-guard.ts assertBrowserNavigationAllowed url information disclosure (Issue 561 / EUVD-2026-49052)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to inform...]]></description>
<link>https://tsecurity.de/de/3695558/sicherheitsluecken/cve-2026-17457-mf-yang-openclaw-cn-up-to-021-scheme-navigation-guardts-assertbrowsernavigationallowed-url-information-disclosure-issue-561-euvd-2026-49052/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695558/sicherheitsluecken/cve-2026-17457-mf-yang-openclaw-cn-up-to-021-scheme-navigation-guardts-assertbrowsernavigationallowed-url-information-disclosure-issue-561-euvd-2026-49052/</guid>
<pubDate>Sun, 26 Jul 2026 13:38:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/mf-yang:openclaw-cn">mf-yang openclaw-cn up to 0.2.1</a>. Affected by this issue is the function <code>assertBrowserNavigationAllowed</code> of the file <em>src/browser/navigation-guard.ts</em> of the component <em>Scheme Handler</em>. Such manipulation of the argument <em>url</em> leads to information disclosure.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-17457">CVE-2026-17457</a>. The attack may be performed from remote. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Someone polled 4K Blu-ray player owners about the reliability of different models over time, and there's a clear winner]]></title>
<description><![CDATA[A reddit poll of Blu-ray owners shows a big difference in the reliability of different firms' devices over time]]></description>
<link>https://tsecurity.de/de/3694982/it-nachrichten/someone-polled-4k-blu-ray-player-owners-about-the-reliability-of-different-models-over-time-and-theres-a-clear-winner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694982/it-nachrichten/someone-polled-4k-blu-ray-player-owners-about-the-reliability-of-different-models-over-time-and-theres-a-clear-winner/</guid>
<pubDate>Sun, 26 Jul 2026 06:30:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A reddit poll of Blu-ray owners shows a big difference in the reliability of different firms' devices over time]]></content:encoded>
</item>
<item>
<title><![CDATA[Dyson Supersonic Travel vs Supersonic Nural: I tested the two premium hair dryers to see what you get — and don't get — for the substantial price difference]]></title>
<description><![CDATA[Two of Dyson's best hair dryers share the same motor and attachments but are built for very different needs. Here's what you need to know before you buy]]></description>
<link>https://tsecurity.de/de/3694901/it-nachrichten/dyson-supersonic-travel-vs-supersonic-nural-i-tested-the-two-premium-hair-dryers-to-see-what-you-get-and-dont-get-for-the-substantial-price-difference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694901/it-nachrichten/dyson-supersonic-travel-vs-supersonic-nural-i-tested-the-two-premium-hair-dryers-to-see-what-you-get-and-dont-get-for-the-substantial-price-difference/</guid>
<pubDate>Sat, 25 Jul 2026 22:16:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Two of Dyson's best hair dryers share the same motor and attachments but are built for very different needs. Here's what you need to know before you buy]]></content:encoded>
</item>
<item>
<title><![CDATA[China is Creating a Herd of 100 Elite Yak Clones]]></title>
<description><![CDATA[CNN reports on yaks "designed and cloned" in secretive, high-altitude labs in Tibet — 2.4 miles (4,000 meters) above sea level. They're a critical part of the local economy, and researchers "hope to create an 'elite' herd of super-yaks, healthier and more fertile than their predecessors."



Both...]]></description>
<link>https://tsecurity.de/de/3694805/it-security-nachrichten/china-is-creating-a-herd-of-100-elite-yak-clones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694805/it-security-nachrichten/china-is-creating-a-herd-of-100-elite-yak-clones/</guid>
<pubDate>Sat, 25 Jul 2026 20:01:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CNN reports on yaks "designed and cloned" in secretive, high-altitude labs in Tibet — 2.4 miles (4,000 meters) above sea level. They're a critical part of the local economy, and researchers "hope to create an 'elite' herd of super-yaks, healthier and more fertile than their predecessors."



Both domestic yaks and their wild cousins have been facing threats for years, with some rare subspecies at risk of disappearing entirely. Authorities in the southwestern Chinese region have poured tens of millions of dollars into boosting the yak industry in recent years — and they hope cloning can help. The first yak clone came in July 2025, Chinese state media hailing it as a breakthrough achievement that combined cloning with gene selection. More clones were born this spring — and researchers are now aiming to create a herd of more than 100 "elite" yak clones by 2028, boasting desired traits like faster growth and larger size. "This shows the technology has moved from a one-time success to a stable, mass-scale application," said Fang Shengguo, the project's scientific lead and director of the State Conservation Center for Gene Resources of Endangered Wildlife, according to state-run news agency Xinhua... 


Many experts acknowledge there are legitimate arguments for using cloning in conservation, and for gene selection in farming. But the ethical waters are murky, and any such project should have high levels of public transparency and accountability, said Lisa Moses, a veterinarian and bioethicist at Harvard Medical School. So far, much of the yak cloning project remains mysterious, with information largely limited to glowing state-media coverage... 


[S]ome scientists say these projects reduce our sense of urgency toward fixing the environment, and that we can't simply churn out clones while the planet burns. To truly enact change, they say, we have to continue addressing the root cause of the problem — restoring degraded habitats, lowering carbon emissions, cracking down on poaching, and more. But for others, "there is a strong feeling ... that traditional conservation is essentially failing now," Moses said. "What we've been doing for the last 100 years to try to stave off ecological destruction is not working.... The argument is, we don't have a choice," she added. "If we want to try to do something that will actually make a difference, we need to use these technologies, specifically synthetic biology, to essentially override evolution and change the fitness of the species for the environment that they live in." 

"History is littered with good intentions in the environment gone wrong," Moses said, "and I would argue that these technologies have even more unknowns than ones that we previously employed."

 

The article points out that the number of wild yaks "dropped more than a third in the last 30 years,
with just 10,000 to 20,000 individuals left, according to the Wildlife Conservation Society." 


The yaks are threatened by climate change and habitat degradation, "with warmer temperatures bringing invasive plant species and increased competition for resources... in one of the world's most inhospitable terrains."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=China+is+Creating+a+Herd+of+100+Elite+Yak+Clones%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F25%2F1656259%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F25%2F1656259%2Fchina-is-creating-a-herd-of-100-elite-yak-clones%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/25/1656259/china-is-creating-a-herd-of-100-elite-yak-clones?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple could ‘run the table’ on AI if it does things right]]></title>
<description><![CDATA[Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.



Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to hel...]]></description>
<link>https://tsecurity.de/de/3694780/ai-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694780/ai-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.</p>



<p class="wp-block-paragraph">Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to help users get things done through Siri AI.</p>



<p class="wp-block-paragraph">Apple also <a href="https://www.macobserver.com/news/apple-calls-its-new-assistant-siri-ai-at-wwdc-2026-gemini-partnership-now-official/" target="_blank" rel="noreferrer noopener">offers limited capacity for more complex tasks</a> through <a href="https://www.applemust.com/apple-commences-us-manufacturing-of-private-cloud-compute-servers/" target="_blank" rel="noreferrer noopener">Private Cloud Compute</a>, and, in partnership with the likes of Google in the US and Alibaba in China, the company is giving users a trusted conduit through which to access even more sophisticated AI services. </p>



<h2 class="wp-block-heading"><strong>Deeply deployable</strong></h2>



<p class="wp-block-paragraph">Critics can say it <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">took Apple a long time</a> to get to this point, but they also seem to think the company has finally got the mix right with its series 27 operating systems. Arriving late to a party <a href="https://www.computerworld.com/article/4164979/apple-will-be-behind-on-ai-until-it-isnt.html">doesn’t mean you won’t shine once you get there</a>.</p>



<p class="wp-block-paragraph">Apple is also coming up the inside lane around frontier AI, with iterative OS and hardware enhancements that mean its devices become increasingly effective for <a href="https://www.computerworld.com/article/4016798/why-i-hope-apple-keeps-investing-in-on-device-ai.html">Edge AI use cases</a>, on device — no cloud service required.</p>



<p class="wp-block-paragraph">The company appears to be digging down into those use cases. Mark Gurman at Bloomberg recently predicted that <a href="https://www.tomshardware.com/tech-industry/semiconductors/apples-rumored-m7-ultra-targets-1-5tb-of-memory-and-blackwell-class-ai" target="_blank" rel="noreferrer noopener">future M7 Ultra Macs</a> will support as much as 1.5TB RAM, making these systems more than capable of running full weight frontier models in people’s offices, colleges, and homes. </p>



<p class="wp-block-paragraph">While that does assume the <a href="https://www.computerworld.com/article/4187825/the-trillion-dollar-ai-hallucination.html">AI-flationary memory market</a> can supply that much RAM at prices humans can afford, it is also true that people are already <a href="https://www.computerworld.com/article/4092162/apples-macos-ai-for-the-rest-of-us.html">running AI clusters</a> using off-the-shelf Mac minis networked over Thunderbolt cables. It’s no stretch to believe <a href="https://www.applemust.com/macweb-now-offers-mac-mini-cloud-clusters-in-east-coast-data-centre/" target="_blank" rel="noreferrer noopener">this will continue to be the case</a>, and that it will even broaden as the power/performance offered at the high end grows.</p>



<h2 class="wp-block-heading"><strong>What’s wrong with good enough?</strong></h2>



<p class="wp-block-paragraph">When combined with open AI stacks, particularly newly emerging varieties, Apple’s platforms should become leading contenders for <a href="https://www.computerworld.com/article/4074648/apples-big-bang-ai-moment-is-approaching.html">private AI services</a> and edge AI. Many business users will leap at the chance to offer their workers powerful, self-hosted, private AI services using one or more daisy-chained Mac Studios or Mac minis. The recent craze in deployment of both Macs to support <a href="https://openclaw.ai/" target="_blank" rel="noreferrer noopener">OpenClaw</a> instances shows they already are.</p>



<p class="wp-block-paragraph">Ultimately, these different slices of momentum mean I agree with <a href="https://podcastalpha.substack.com/p/all-in-can-ai-regulate-itself-stripe" target="_blank" rel="noreferrer noopener">investor Jason Calacanis</a> that Apple is in position to apply a great deal of pressure on OpenAI and Claude just by putting models on their devices. </p>



<p class="wp-block-paragraph">It’s also worth thinking about how people use AI today. How many of the queries made in the world right now constitute relatively simple tasks that could be transacted by on-device AI, such as the emerging new version of Apple Intelligence or even smaller LLM models running on device? You can even run <a href="https://9to5mac.com/2026/07/14/prismml-releases-bonsai-27b-claiming-first-major-ai-model-of-its-size-fit-for-iphone/" target="_blank" rel="noreferrer noopener">PrismML’s 1-bit, 27-billion parameter Bonsai</a> on an iPad using the Locally app, and that’s in the here and now.</p>



<p class="wp-block-paragraph">What happens? Pretty soon you’ll find people recognize that they can already run the vast majority of their AI-augmented workflows using services they <a href="https://www.applemust.com/morgan-stanley-its-when-not-if-apple-will-deliver-ai-on-the-edge/" target="_blank" rel="noreferrer noopener">have on their existing device</a> or can access on their on-prem Mac set-ups. And, of course, as people get used to running small tasks locally and larger tasks on premises, the actual space in which they need to turn to cloud-based frontier models <a href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html">will erode</a>. That’s even as companies like PrismML work towards slimming down full-weight models so they don’t need to run on a server at all. </p>



<p class="wp-block-paragraph">“It’s going to be wild when people have unlimited tokens on their desks,” said Calacanis in a podcast round table discussion.</p>



<h2 class="wp-block-heading"><strong>Who has the most to lose?</strong></h2>



<p class="wp-block-paragraph">The current incarnations of AI felt like they came from nowhere. Most people weren’t aware of the technology until returning to work after the 2022 holiday season. Since then, the industry has proliferated with dozens of competing models, most recently including powerful but affordable frontier models such as Qwen and Kimi.ai.</p>



<p class="wp-block-paragraph">These models aren’t necessarily all as good as one another, but in many cases for much of what we do, we’ll find them to be good enough. That’s an existential crisis for some, as industry observers now think the inevitable pricing pressure means some services might have over-invested in capacity before finding any way to turn a profit.</p>



<p class="wp-block-paragraph">Those profit-seeking services are the ones with the most to lose as Apple extends its hardware advantage, democratizing AI access for all while providing platforms suitable for edge AI, on-premises AI, private AI, and even AI access using third-party services. (The need for the latter will shrink as the capabilities of the former get better.)</p>



<h2 class="wp-block-heading"><strong>Cupertino rising</strong></h2>



<p class="wp-block-paragraph">What does this all mean? While the industry remains young, it is already fragmenting. And striding through the dust of that process comes Apple, equipped with the hardware, software, and approach to build its business even as the enterprise of first mover AI services erodes. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Model Context Protocol is going stateless to make scaling simpler]]></title>
<description><![CDATA[Model Context Protocol (MCP), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.



The latest release candidate, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless arch...]]></description>
<link>https://tsecurity.de/de/3694388/it-security-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694388/it-security-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a>), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.</p>



<p class="wp-block-paragraph">The latest <a href="https://modelcontextprotocol.io/specification/draft/changelog" target="_blank" rel="noreferrer noopener">release candidate</a>, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless architecture, a change which industry experts say is intended to make MCP easier to deploy across standard cloud infrastructure as enterprises move AI pilots into production.</p>



<p class="wp-block-paragraph">“The session-based model made sense when MCP servers were local processes on a developer’s laptop. In production, it became an operational tax,” said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at ZopDev.</p>



<p class="wp-block-paragraph">“When your infrastructure team asks whether MCP services can scale like other cloud applications, the answer used to be ‘not quite.’ With the move to a stateless architecture, the answer is now yes,” Bandta added.</p>



<p class="wp-block-paragraph">Earlier versions of the protocol maintained information about every client connection, meaning servers had to keep track of each session throughout an interaction. While that approach worked well for local development, it complicated deployments across multiple servers because requests often had to be routed back to the same machine, limiting scalability and making MCP a less natural fit for modern cloud architectures.</p>



<p class="wp-block-paragraph">“Under the new stateless design, every request contains the information needed for any available server to process it independently. Applications that need to maintain context across multiple requests can still do so, but developers must now manage that state explicitly rather than relying on the protocol itself,” she said.</p>



<p class="wp-block-paragraph">This transition to a stateless design goes beyond simplifying infrastructure by fundamentally changing how AI applications manage and share context across tools, according to <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Instead of keeping application state hidden inside protocol sessions, the new design makes it explicit, allowing AI models to access, reason over, and pass that information between tools, giving developers greater control over how context is preserved and shared across tools, Jena said.</p>



<p class="wp-block-paragraph">It should also make AI workflows more portable, resilient, and easier to orchestrate across distributed environments, he said.</p>



<h2 class="wp-block-heading">MCP’s new features</h2>



<p class="wp-block-paragraph">Other changes to MCP include the addition of a Multi Round-Trip Requests (MRTR) mechanism that changes how AI agents request additional information they need to complete a task.</p>



<p class="wp-block-paragraph">Instead of relying on a persistent connection between the client and server throughout the interaction, the new mechanism lets the server request additional input through a standard request-response exchange before continuing the task, Jena said.</p>



<p class="wp-block-paragraph">Routable transport headers, another addition, enable API gateways and other networking infrastructure to identify and route MCP requests without inspecting their contents.</p>



<p class="wp-block-paragraph">They reduce processing overhead, lower latency, and let enterprise teams enforce routing, rate-limiting and security policies more efficiently using existing API management infrastructure, Jena said.</p>



<p class="wp-block-paragraph">MCP is also getting an updated authorization framework built around OAuth 2.1 and OpenID Connect; interactive MCP Apps; and deterministic caching of tool and resource listings to improve LLM prompt-cache hit rates, potentially saving on token costs.</p>



<h2 class="wp-block-heading">Rebuilding the trust boundary</h2>



<p class="wp-block-paragraph">The MCP release steering committee also decided to deprecate some legacy features, including Roots, Sampling, Logging, the older HTTP+SSE transport and Dynamic Client Registration, although these will continue to work in this version and any other released over the next year.</p>



<p class="wp-block-paragraph">The deprecation of Sampling is likely to have the biggest impact because it changes who is responsible for interacting with foundation models, said Jena.</p>



<p class="wp-block-paragraph">“Sampling let MCP servers invoke the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" target="_blank">LLM</a> through the client, which meant the server had a callback path into the model without owning that connection. Deprecating it means rebuilding that trust boundary,” Jena said. “Your server now calls the model provider directly. That changes your network architecture, your auth model, and depending on how you’ve built cost attribution, your billing flow.”</p>



<p class="wp-block-paragraph">The year-long transition period will be enough for teams to audit their sampling dependencies now, said Jena: “The risk is that teams who haven’t implemented sampling themselves won’t know if a third-party MCP server they’re depending on uses it.”</p>



<h2 class="wp-block-heading">Updated MCP SDKs</h2>



<p class="wp-block-paragraph">To accompany the protocol update, there are updated <a href="https://github.com/modelcontextprotocol" target="_blank" rel="noreferrer noopener">MCP SDKs</a> for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html" target="_blank">Python</a>, <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" target="_blank">Typescript</a>, <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>, and <a href="https://www.infoworld.com/article/4131649/the-best-new-features-of-c-14.html">C#</a>. These support both the old and new protocol versions, so new clients can continue communicating with older servers, while updated servers will also support older clients, reducing the risk of immediate disruptions.</p>



<p class="wp-block-paragraph">That backward compatibility should make the transition largely incremental, except for enterprises that built custom infrastructure around MCP’s earlier session-based architecture, Bandta said.</p>



<p class="wp-block-paragraph">Identifying and auditing those session dependencies may not be easy, Jena warned.</p>



<p class="wp-block-paragraph">“Session management complexity tends to be hidden across multiple layers — the gateway config, the deployment scripts, the monitoring dashboards. The code change is small; finding everywhere the assumption lives is what takes time,” he said.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4201254/model-context-protocol-is-going-stateless-to-make-scaling-simpler.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Risks of Parkinson's Disease May Increase With Prolonged Exposure to Road Traffic Noise]]></title>
<description><![CDATA[A large Danish study found a modest but consistent association between long-term road traffic noise exposure and higher Parkinson's disease risk, with a 3% increase for every 11.5 dB rise in noise at the most exposed side of a home. The Guardian reports: The researchers modeled noise exposure at ...]]></description>
<link>https://tsecurity.de/de/3694246/it-security-nachrichten/risks-of-parkinsons-disease-may-increase-with-prolonged-exposure-to-road-traffic-noise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694246/it-security-nachrichten/risks-of-parkinsons-disease-may-increase-with-prolonged-exposure-to-road-traffic-noise/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A large Danish study found a modest but consistent association between long-term road traffic noise exposure and higher Parkinson's disease risk, with a 3% increase for every 11.5 dB rise in noise at the most exposed side of a home. The Guardian reports: The researchers modeled noise exposure at the most and least exposed exterior of the residence of each participant and calculated the difference in noise levels. The magnitude of the effect was modest but consistent; at the most exposed facade, for every 11.5dB rise in noise level, the risk of Parkinson's disease rose by 3% over the study period. Having a quiet part of the home may mitigate the association between exposure to road traffic noise and higher risk of Parkinson's disease, according to the findings.
 
The study, published in Jama Neurology, included 3.1 million Danish participants aged 40 and over, and followed them for 18 years. It was established using nationwide health register data, making it the largest study on road traffic noise and Parkinson's disease. Previous research linked the rise in neurological disorders, including Parkinson's disease, with exposure to environmental toxins. Environmental risk factors such as air pollution, microplastics and pesticides have become the main focus of prevention strategies. The study is one of the first to make the link to noise pollution.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Risks+of+Parkinson's+Disease+May+Increase+With+Prolonged+Exposure+to+Road+Traffic+Noise%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F24%2F2246224%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F24%2F2246224%2Frisks-of-parkinsons-disease-may-increase-with-prolonged-exposure-to-road-traffic-noise%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/24/2246224/risks-of-parkinsons-disease-may-increase-with-prolonged-exposure-to-road-traffic-noise?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s going on with Seattle startup funding, a Kalshi setback, Impinj’s long game, and a smartphone detox]]></title>
<description><![CDATA[This week on the GeekWire Podcast: Seattle startup funding fell about 40% in the first half of 2026 as AI reshaped the venture market — plus a Kalshi court setback, Impinj's 10 years on the Nasdaq, and could you go without your smartphone for five weeks? Read More]]></description>
<link>https://tsecurity.de/de/3694017/it-nachrichten/whats-going-on-with-seattle-startup-funding-a-kalshi-setback-impinjs-long-game-and-a-smartphone-detox/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694017/it-nachrichten/whats-going-on-with-seattle-startup-funding-a-kalshi-setback-impinjs-long-game-and-a-smartphone-detox/</guid>
<pubDate>Sat, 25 Jul 2026 16:16:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img fetchpriority="high" loading="eager" width="960" height="600" src="https://cdn.geekwire.com/wp-content/uploads/2023/03/GeekWirePodcast.png" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2023/03/GeekWirePodcast.png 960w, https://cdn.geekwire.com/wp-content/uploads/2023/03/GeekWirePodcast-768x480.png 768w, https://cdn.geekwire.com/wp-content/uploads/2023/03/GeekWirePodcast-630x394.png 630w" sizes="(max-width: 960px) 100vw, 960px"><br>This week on the GeekWire Podcast: Seattle startup funding fell about 40% in the first half of 2026 as AI reshaped the venture market — plus a Kalshi court setback, Impinj's 10 years on the Nasdaq, and could you go without your smartphone for five weeks? <a href="https://www.geekwire.com/2026/whats-going-on-with-seattle-startup-funding-a-kalshi-setback-impinjs-long-game-and-a-smartphone-detox/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32977 | OpenClaw up to 2026.3.10 toctou (GHSA-xvx8-77m6-gwg6)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.3.10. It has been declared as problematic. The affected element is an unknown function. The manipulation results in time-of-check time-of-use.

This vulnerability is known as CVE-2026-32977. Attacking locally is a requirement. No exploit is availab...]]></description>
<link>https://tsecurity.de/de/3693871/sicherheitsluecken/cve-2026-32977-openclaw-up-to-2026310-toctou-ghsa-xvx8-77m6-gwg6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693871/sicherheitsluecken/cve-2026-32977-openclaw-up-to-2026310-toctou-ghsa-xvx8-77m6-gwg6/</guid>
<pubDate>Sat, 25 Jul 2026 13:33:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function. The manipulation results in time-of-check time-of-use.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-32977">CVE-2026-32977</a>. Attacking locally is a requirement. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32982 | OpenClaw up to 2026.3.12 Error Message fetchRemoteMedia log file (GHSA-xwcj-hwhf-h378)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in OpenClaw up to 2026.3.12. This affects the function fetchRemoteMedia of the component Error Message Handler. Such manipulation leads to sensitive information in log files.

This vulnerability is uniquely identified as CVE-2026-3298...]]></description>
<link>https://tsecurity.de/de/3693870/sicherheitsluecken/cve-2026-32982-openclaw-up-to-2026312-error-message-fetchremotemedia-log-file-ghsa-xwcj-hwhf-h378/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693870/sicherheitsluecken/cve-2026-32982-openclaw-up-to-2026312-error-message-fetchremotemedia-log-file-ghsa-xwcj-hwhf-h378/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.12</a>. This affects the function <code>fetchRemoteMedia</code> of the component <em>Error Message Handler</em>. Such manipulation leads to sensitive information in log files.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-32982">CVE-2026-32982</a>. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32970 | OpenClaw up to 2026.3.10 gateway.auth.token/gateway.auth.password failing open (GHSA-qvr7-g57c-mrc7)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.3.10. It has been rated as problematic. The impacted element is an unknown function. This manipulation of the argument gateway.auth.token/gateway.auth.password causes not failing securely.

This vulnerability is handled as CVE-2026-32970. It is pos...]]></description>
<link>https://tsecurity.de/de/3693868/sicherheitsluecken/cve-2026-32970-openclaw-up-to-2026310-gatewayauthtokengatewayauthpassword-failing-open-ghsa-qvr7-g57c-mrc7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693868/sicherheitsluecken/cve-2026-32970-openclaw-up-to-2026310-gatewayauthtokengatewayauthpassword-failing-open-ghsa-qvr7-g57c-mrc7/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function. This manipulation of the argument <em>gateway.auth.token/gateway.auth.password</em> causes not failing securely.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-32970">CVE-2026-32970</a>. It is possible to launch the attack on the local host. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32976 | OpenClaw up to 2026.3.10 Configuration /config authorization (GHSA-8jhh-jcqg-mj5p)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in OpenClaw up to 2026.3.10. This issue affects some unknown processing of the file /config of the component Configuration Handler. Performing a manipulation results in authorization bypass.

This vulnerability is cataloged as C...]]></description>
<link>https://tsecurity.de/de/3693867/sicherheitsluecken/cve-2026-32976-openclaw-up-to-2026310-configuration-config-authorization-ghsa-8jhh-jcqg-mj5p/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693867/sicherheitsluecken/cve-2026-32976-openclaw-up-to-2026310-configuration-config-authorization-ghsa-8jhh-jcqg-mj5p/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. This issue affects some unknown processing of the file <em>/config</em> of the component <em>Configuration Handler</em>. Performing a manipulation results in authorization bypass.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-32976">CVE-2026-32976</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32921 | OpenClaw up to 2026.3.7 toctou (GHSA-8g75-q649-6pv6)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in OpenClaw up to 2026.3.7. Affected is an unknown function. Executing a manipulation can lead to time-of-check time-of-use.

The identification of this vulnerability is CVE-2026-32921. The attack may be launched remotely. There is no exploit ava...]]></description>
<link>https://tsecurity.de/de/3693866/sicherheitsluecken/cve-2026-32921-openclaw-up-to-202637-toctou-ghsa-8g75-q649-6pv6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693866/sicherheitsluecken/cve-2026-32921-openclaw-up-to-202637-toctou-ghsa-8g75-q649-6pv6/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.7</a>. Affected is an unknown function. Executing a manipulation can lead to time-of-check time-of-use.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-32921">CVE-2026-32921</a>. The attack may be launched remotely. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32988 | OpenClaw up to 2026.3.10 Temporary File toctou (GHSA-mj4p-rc52-m843)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in OpenClaw up to 2026.3.10. Impacted is an unknown function of the component Temporary File Handler. Executing a manipulation can lead to time-of-check time-of-use.

This vulnerability is registered as CVE-2026-32988. The attack nee...]]></description>
<link>https://tsecurity.de/de/3693864/sicherheitsluecken/cve-2026-32988-openclaw-up-to-2026310-temporary-file-toctou-ghsa-mj4p-rc52-m843/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693864/sicherheitsluecken/cve-2026-32988-openclaw-up-to-2026310-temporary-file-toctou-ghsa-mj4p-rc52-m843/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. Impacted is an unknown function of the component <em>Temporary File Handler</em>. Executing a manipulation can lead to time-of-check time-of-use.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-32988">CVE-2026-32988</a>. The attack needs to be launched locally. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32920 | OpenClaw up to 2026.3.11 Workspace OpenClaw/extensions/ inclusion of functionality from untrusted control sphere (GHSA-99qw-6mr3-36qr)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.3.11. It has been declared as problematic. This impacts an unknown function of the file OpenClaw/extensions/ of the component Workspace Handler. Such manipulation leads to inclusion of functionality from untrusted control sphere.

This vulnerabilit...]]></description>
<link>https://tsecurity.de/de/3693862/sicherheitsluecken/cve-2026-32920-openclaw-up-to-2026311-workspace-openclawextensions-inclusion-of-functionality-from-untrusted-control-sphere-ghsa-99qw-6mr3-36qr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693862/sicherheitsluecken/cve-2026-32920-openclaw-up-to-2026311-workspace-openclawextensions-inclusion-of-functionality-from-untrusted-control-sphere-ghsa-99qw-6mr3-36qr/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.11</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function of the file <em>OpenClaw/extensions/</em> of the component <em>Workspace Handler</em>. Such manipulation leads to inclusion of functionality from untrusted control sphere.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-32920">CVE-2026-32920</a>. An attack has to be approached locally. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32971 | OpenClaw up to 2026.3.10 clickjacking (GHSA-rw39-5899-8mxp)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in OpenClaw up to 2026.3.10. This affects an unknown part. The manipulation results in clickjacking.

This vulnerability was named CVE-2026-32971. The attack may be performed from remote. There is no available exploit.

The affected component ...]]></description>
<link>https://tsecurity.de/de/3693861/sicherheitsluecken/cve-2026-32971-openclaw-up-to-2026310-clickjacking-ghsa-rw39-5899-8mxp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693861/sicherheitsluecken/cve-2026-32971-openclaw-up-to-2026310-clickjacking-ghsa-rw39-5899-8mxp/</guid>
<pubDate>Sat, 25 Jul 2026 13:31:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. This affects an unknown part. The manipulation results in clickjacking.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-32971">CVE-2026-32971</a>. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32917 | OpenClaw up to 2026.3.12 Attachments os command injection (GHSA-g2f6-pwvx-r275)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.3.12. It has been classified as critical. Impacted is an unknown function of the component Attachments Handler. The manipulation leads to os command injection.

This vulnerability is traded as CVE-2026-32917. It is possible to initiate the attack r...]]></description>
<link>https://tsecurity.de/de/3693834/sicherheitsluecken/cve-2026-32917-openclaw-up-to-2026312-attachments-os-command-injection-ghsa-g2f6-pwvx-r275/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693834/sicherheitsluecken/cve-2026-32917-openclaw-up-to-2026312-attachments-os-command-injection-ghsa-g2f6-pwvx-r275/</guid>
<pubDate>Sat, 25 Jul 2026 13:12:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.12</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function of the component <em>Attachments Handler</em>. The manipulation leads to os command injection.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-32917">CVE-2026-32917</a>. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32916 | OpenClaw up to 2026.3.10 privileges assignment (GHSA-xw77-45gv-p728)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.3.10. It has been rated as problematic. Affected is an unknown function. Performing a manipulation results in incorrect privilege assignment.

This vulnerability is known as CVE-2026-32916. Remote exploitation of the attack is possible. No exploit ...]]></description>
<link>https://tsecurity.de/de/3693831/sicherheitsluecken/cve-2026-32916-openclaw-up-to-2026310-privileges-assignment-ghsa-xw77-45gv-p728/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693831/sicherheitsluecken/cve-2026-32916-openclaw-up-to-2026310-privileges-assignment-ghsa-xw77-45gv-p728/</guid>
<pubDate>Sat, 25 Jul 2026 13:11:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.10</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function. Performing a manipulation results in incorrect privilege assignment.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-32916">CVE-2026-32916</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.2-beta.5]]></title>
<description><![CDATA[openclaw 2026.7.2-beta.5]]></description>
<link>https://tsecurity.de/de/3693721/downloads/v202672-beta5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693721/downloads/v202672-beta5/</guid>
<pubDate>Sat, 25 Jul 2026 11:23:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>openclaw 2026.7.2-beta.5</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution]]></title>
<description><![CDATA[Topic: OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw tools.exec.safeBins < = 2026.2.22 Remote Code Execution  # CVE:             CV...]]></description>
<link>https://tsecurity.de/de/3693405/poc/openclaw-toolsexecsafebins-2026222-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693405/poc/openclaw-toolsexecsafebins-2026222-remote-code-execution/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:25 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: OpenClaw tools.exec.safeBins &lt; = 2026.2.22 Remote Code Execution Risk: Low Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw tools.exec.safeBins &lt; = 2026.2.22 Remote Code Execution  # CVE:             CV...]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw <  2026.3.28 Discord Text Approval Authorization Bypass]]></title>
<description><![CDATA[Topic: OpenClaw <  2026.3.28 Discord Text Approval Authorization Bypass Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw Discord Text Approval Authorization Bypass  # CVE: CVE-2026-41303  # Date: 20...]]></description>
<link>https://tsecurity.de/de/3693403/poc/openclaw-2026328-discord-text-approval-authorization-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693403/poc/openclaw-2026328-discord-text-approval-authorization-bypass/</guid>
<pubDate>Sat, 25 Jul 2026 10:04:22 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: OpenClaw &lt;  2026.3.28 Discord Text Approval Authorization Bypass Risk: Medium Text:#!/usr/bin/env python3  # Exploit Title: OpenClaw Discord Text Approval Authorization Bypass  # CVE: CVE-2026-41303  # Date: 20...]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: The many journeys of learning Rust]]></title>
<description><![CDATA[This is another post in our series covering what we learned through the Vision Doc process. We previously described the overall approach and what we learned about doing user research, we explored what people love about Rust, dug into what it takes to ship safety-crticial Rust, and described some ...]]></description>
<link>https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:24 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>This is another post in our series covering what we learned through the Vision Doc process. We previously <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">described the overall approach and what we learned about doing user research</a>, we <a href="https://blog.rust-lang.org/2025/12/19/what-do-people-love-about-rust/" rel="external">explored what people love about Rust</a>, <a href="https://blog.rust-lang.org/2026/01/14/what-does-it-take-to-ship-rust-in-safety-critical/" rel="external">dug into what it takes to ship safety-crticial Rust</a>, and <a href="https://blog.rust-lang.org/2026/03/20/rust-challenges/" rel="external">described some of the major challenges that people face when using Rust</a>.</em></p>
<p>In this post we walk through what folks have found on their journey to learn the Rust programming language with ups and downs covered.</p>
<p>As a disclaimer, LLMs (Large Language Models) come up in this post because our interviewees brought them up. We're scoping discussion to their use as a learning tool, covering research and example generation, not broader questions about AI (Artificial Intelligence) in software development.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#many-paths-to-needing-rust"></a>
Many paths to needing Rust</h3>
<p>The interviews surfaced several different paths into Rust: curiosity, embedded work, job-market pressure, organizational adoption, and reassignment after a team or company chose Rust. That last path matters because many learners are not evaluating Rust from a blank slate; they are trying to become productive after Rust has already arrived in their work.</p>
<blockquote>
<p>"Funny enough, I've advocated for more niche languages than Rust in the past. Rust has pretty much stopped being as much of a niche language as it was, but it's not Java." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#rust-learning-resources"></a>
Rust learning resources</h3>
<p>Likely as expected, the folks that we talked to reach for a range of resources to learn Rust. Some reach for official documentation, such as <a href="https://doc.rust-lang.org/book/" rel="external">The Rust Programming Language Book</a> and find that sufficient to build on what the compiler was already showing them.</p>
<blockquote>
<p>"I started with the official Rust documentation because there are a lot of great examples of how features like the borrow checker work." -- Software engineer at an Automotive supplier</p>
</blockquote>
<p>Others needed more passes and more formats, sometimes reaching for resources the community maintains, such as <a href="https://rustlings.rust-lang.org/" rel="external">Rustlings</a>, <a href="https://danielkeep.github.io/tlborm/book/index.html" rel="external">The Little Book of Rust Macros</a>, and <a href="https://rust-unofficial.github.io/too-many-lists/" rel="external">Learn Rust With Entirely Too Many Linked Lists</a>.</p>
<blockquote>
<p>"The first time I went through the chapter in [The Rust Programming Language] on borrow checking, I was like, what is this? I read it again, then I watched a YouTube video of someone explaining the chapter." -- Rust freelance consultant</p>
</blockquote>
<blockquote>
<p>"Rust book, Rustlings, Zero to Production in Rust, Jon Gjengset tutorials. A bunch of books. It's not a one-pass reading. Can't say how many times I've gone through it." -- Software engineer working on video streaming and storage</p>
</blockquote>
<p>These resources have brought up an entire generation of Rust programmers. But, to some, there is a perception that these resources have trouble keeping pace with the language.</p>
<blockquote>
<p>"We'd like to use [The Rust Programming Language/'the book'], but we've found that it's out of date, unfortunately. We've looked at the GitHub repo and found it's got a lot of unresolved issues and unmerged PRs" -- Principal Software Engineering work on Rust adoption in a regulated industry</p>
</blockquote>
<p>Whether or not this is factually true, Rust's growth has nonetheless put more scrutiny on these materials. Companies evaluating adoption and engineers getting reassigned to Rust teams are looking at them with fresh eyes and finding the gaps that affect their own evaluation.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#beginner-stumblings-and-unlearning-habits"></a>
Beginner stumblings and unlearning habits</h3>
<p>It's pretty typical for Rust to be the 2nd, 3rd or Nth programming language that someone picks up. They'd end up writing their most familiar language in Rust, whether C++ patterns, Java patterns, or whatever they knew, for months or even years. Eventually they got comfortable enough to start writing idiomatic Rust.</p>
<blockquote>
<p>"There's a bit of a drop in productivity compared to C if you're already familiar with it just because you're learning new rules, new syntax."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"In the beginning it was more poking around the code and adding and removing some ampersands and asterisks to try to make sense of <code>mut</code> and not <code>mut</code> and whatever." -- Senior engineer with 20 years of Java experience in cloud and IoT</p>
</blockquote>
<p>We also spoke with someone who found that not having much of a programming background seemed to benefit people picking up Rust. Not having worn-in grooves from other languages may play a role here, and it's worth investigating further.</p>
<blockquote>
<p>"I had someone who had never programmed much before start working on the internals of [our Rust project]. She was just fine with getting into Rust. It's more of the senior people that struggle as they need to unlearn practices which may work in other languages, but it's not the 'Rust' way." -- Researcher, Automotive OEM R&amp;D Lab</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-to-work-with-the-borrow-checker"></a>
Learning to work with the borrow checker</h3>
<p>We heard a lot about learning to work with the borrow checker instead of against it. People get there through different paths, but a few patterns came up repeatedly.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#the-compiler-as-teacher"></a>
The compiler as teacher</h4>
<p>Rust's diagnostics did the teaching on their own, especially around lifetimes.</p>
<blockquote>
<p>"If you mess up the lifetimes in a piece of code that you've written by hand, I usually find that Rust's diagnostics are very helpful" -- Researcher working on static analysis of Rust programs</p>
</blockquote>
<blockquote>
<p>"Whatever's missing, the compiler usually fills in: it tells me 'you need to declare the lifetime of this reference', so I know and can figure it out. That all generally works pretty well." -- Senior Software Engineer</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-by-doing"></a>
Learning by doing</h4>
<p>Others felt like they only really internalized the borrow checker after writing a lot of Rust. It took projects, coding challenges, prototyping and so on until at some point it clicked.</p>
<blockquote>
<p>"I actually did not understand the borrow checker until I spent a lot of time writing Rust" -- Founder of a startup built on Rust</p>
</blockquote>
<blockquote>
<p>"Besides the prototyping work, I also did coding-challenge-type stuff to get familiar with Rust for Advent of Code. [..] It eventually clicked to the point where I wasn't fighting with Rust, it was working for me. I had that experience other people describe: when I managed to get my program to fit with Rust, it worked. I didn't spend time debugging." -- Principal Software Engineer, large SaaS provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#letting-go-of-clone-guilt"></a>
Letting go of "clone guilt"</h4>
<p>Some learners arrive with the assumption that good Rust means zero clones, zero copies, lifetimes threaded through everything. They set the bar at optimal before they've learned how to write idiomatic Rust, and it makes the borrow checker feel harder than it needs to be at the outset.</p>
<blockquote>
<p>"On one of my first projects, I was like, 'I don't ever want to copy or clone anything,' so I carefully wove through all the lifetimes and got myself into a bit of a bind. Then I saw someone else just cloning the struct I was working with, and it was super cheap. Sometimes you can just clone and it's going to be okay." -- Researcher at a university</p>
</blockquote>
<p>The experienced Rust developers we spoke with consistently said the same thing: clone freely while you're learning, then optimize when you understand the problem. Rust's reputation for performance and correctness feeds this. Newcomers assume anything less than optimal is wrong before they've written a first working program, and clone guilt is how that shows up.</p>
<p>We think it could be an interesting area of future study to check into the patterns Rust programmers employ at different levels of experience and under which circumstances. One member of the Rust Vision doc team that's very experienced with Rust noted that there's kind of an "expected shape" they understand as passing the compiler. This knowledge influences how they approach writing code which wouldn't take that shape and they naturally find themselves understanding when to use so-called workarounds, such as passing around indices into arrays or <code>Vec</code>s.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#multi-paradigm-but-not-the-oop-some-are-used-to"></a>
Multi-paradigm, but not the OOP some are used to</h3>
<p>The Rust programming language is multi-paradigm, and how that lands depends on what you're coming from. We heard some that came from a functional background were delighted with digging into learning how much Rust inherits from that lineage. Some others noted that they and others on their teams struggled to unlearn the object-oriented style they'd come to use heavily in other languages like C++ and Java.</p>
<blockquote>
<p>"Developers coming from C++ tend to think object-oriented. I think that's a difference between C++ and Rust." -- Architect at Automotive OEM</p>
</blockquote>
<blockquote>
<p>"I had exactly that thing, where I would apply all my years of Java and JS thinking, where I could just create some object, not care about it, return it, have it sloshing around between various functions. Found myself reaching for these patterns and then being told 'no, you cannot do that'." -- Principal Engineer at a SaaS company</p>
</blockquote>
<p>Developers coming from functional programming had less to unlearn: strong typing, pattern matching, and an expression-oriented style were already familiar.</p>
<blockquote>
<p>"My background has been more functional programming, strong typing. That originated for me as a Lisper: once a Lisper, always a Lisper." -- Principal Software Engineer working on Rust tooling for safety-regulated industries</p>
</blockquote>
<blockquote>
<p>"The languages I primarily used before Rust were things like OCaml. Way back, I came from C and C++, the classic languages, and then I spent quite a long time doing primarily pure functional stuff. These days I've ended up back in what I like to think of as a pragmatic center ground [with Rust]." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#teaching-rust-in-academia"></a>
Teaching Rust in academia</h3>
<p>We spoke with a university professor that's been teaching Rust generally. In the academic environment, they were able to use proxies for some things such as "traits are like interfaces in Java" because the students had already gone through a set of courses in their first and second years that taught them Java. They introduced concepts slowly throughout the course, choosing to deal with some more complex topics like generics later. The outcome generally was that students had no problem picking up Rust in this setting.</p>
<blockquote>
<p>"I couldn't see any big difference on the embedded side. We also teach an embedded class, and we did an experiment. Half of the students' feedback was worse on the Rust class, mostly because they needed to build the project themselves. The C students just got one from [an LLM], absolutely no problem." -- University Professor, on teaching Rust</p>
</blockquote>
<p>The C cohort leaned on LLMs for the project in ways the Rust cohort couldn't. We don't yet have a clear answer for why.</p>
<p>What did come through clearly was the Rust cohort's experience with the community. Some students needed to figure out which drivers to use for the embedded project and how to use them. Their professor encouraged them to open issues and ask questions directly on GitHub, and the maintainers responded. Students who had never contributed to open source before were getting answers from the people who wrote the code.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-using-llms"></a>
Learning using LLMs</h3>
<p>Some experienced folks shared that they saw LLMs as a tool that can help someone come up to speed quickly, either as a research tool or for generating example Rust code to understand concepts.</p>
<blockquote>
<p>"I'm optimistic that there's a way to work [LLMs] in that will cut down that learning curve. One of the big things these tools bring is reducing the learning curve in general; these are very good tools to help you navigate a space that you don't know yet." -- Maintainer of large open source Rust crate</p>
</blockquote>
<blockquote>
<p>"I try [LLMs] out once a month, usually for generating an example or something like this. Just like with Stack Overflow: when you read an example, you should read it carefully and try to understand it. Not copy and paste it, but type it in your own words in code and then check it, because that's where the teeny tiny little mistakes are." -- Founder of startup built on Rust</p>
</blockquote>
<p>For some learners, an LLM is just another way to find answers, no different than a search engine.</p>
<blockquote>
<p>"So for the most part, picking up Rust - how do I learn? I'll [use web search for] things, I'll ask [an LLM], I'll just poke around and read the code." -- Senior Software Engineer working in a regulated space</p>
</blockquote>
<p>One founder went further and claimed that LLMs change who can become a Rust developer. One consulting company founder described hiring high school graduates with no systems programming background and training them as Rust developers, with LLMs filling in the learning gaps that would previously have required years of experience.</p>
<blockquote>
<p>"At the beginning, I was worried, but now that we have [LLMs] supporting development, the difficulty of the language doesn't matter. I'm seeing a huge opportunity behind strong runtime languages like Rust. [..] In [Developing Country] we hire 20-25 high school graduates, train them to be Rust programmers, then they enhance our workforce worldwide." -- Founder of a consulting company</p>
</blockquote>
<p>We heard this from one organization. This is a claim that the combination of Rust's compiler and LLM tooling can dramatically shorten the path from beginner to working developer. Whether it generalizes depends on questions we can't answer from a single interview: how long these developers stay, what kind of code they can maintain independently, and whether this training/learning model works outside this company's particular structure. If it holds up, the pool of people who can become Rust developers is much larger than the usual hiring profile suggests.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#organizational-considerations-for-rust-learners"></a>
Organizational considerations for Rust learners</h3>
<p>We spoke with a number of folks on teams that are using Rust in larger organizations. Teams wanted to know that everyone would end up at roughly the same level of competence, which led a good number to invest in training courses to get there. Some leaders found that staff was able to ramp well enough by reading The Rust Programming Language, going through Rustlings, and then picking up lower risk and priority tickets to work on. Having a sense of community was also important within companies; it helps people know they are not alone when they are asked to work on Rust after, say, a reorganization happens.</p>
<blockquote>
<p>"[..] the idea with the class as opposed to 'just read the Rust book on your own' was that this gives everyone kind of the same baseline going in."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"So typically we're going to have people work through Rustlings, work through The Rust Programming Language. We have them then start to pick up lower risk tickets to work on." -- Principal Engineer at a large SaaS provider</p>
</blockquote>
<blockquote>
<p>"We've got an internal Slack channel for Rust learning where people can drop questions and others will come in and answer them. That helps build up understanding and community." -- Software Engineer at a large corporation</p>
</blockquote>
<p>Some organizations found that while the person they'd hire would need to learn Rust, it was still preferable to the alternative of hiring someone for a critical piece of software written in another language.</p>
<blockquote>
<p>"They needed to grow and maintain this C++ codebase. They had a C++ wizard, and they tried for about two years to find someone with the same level of expertise. They ended up hiring people that didn't know Rust and ramping them up, creating FFI bindings from the C++ side so they could work in Rust. And you can feel it: the borrow checker is teaching these people the right way to handle their systems." -- Principal Engineer at an Automotive OEM</p>
</blockquote>
<p>The community and helping each other aspect seems to grow bonds as organizations mature.</p>
<blockquote>
<p>"Our team is [all about] mentorship. I've mentored people coming up to speed on Rust, and people help each other hugely." -- Principal Software Engineer at a large SaaS company</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#silent-attrition"></a>
Silent attrition</h3>
<p>We identified some cases where people have approached Rust and bounced off of it, for one reason or another. In the below case, someone with a background in a language with fewer guardrails found themselves frustrated enough with Rust to walk away.</p>
<blockquote>
<p>"All of that means that that embedded ecosystem is very frustrating to somebody who comes from C and is like, why can't I just get a pointer to this peripheral and then write into the registers. What are you doing to me? [..] My friend never got over that. He looked at it and said, I'm not going to deal with this and walked away." -– A second University Professor</p>
</blockquote>
<p>There may be language features that for a particular domain are not seen as comfortable or usable yet, such as async Rust usage in a safety domain. We'd like to map which language features feel off-limits in which domains; async in safety-critical work probably isn't the only case.</p>
<blockquote>
<p>"We're not fully sure how async [Rust] will work out in the long run in our domain. [..] People don't feel comfortable yet since C++14 doesn't provide such concepts. [..] It's the chicken-and-egg problem again: we probably need to gain some experience to see whether we can actually benefit from these new concepts in the automotive and safety domains." -- Team Lead at Automotive Supplier (ASIL D target)</p>
</blockquote>
<p>We heard in at least one case, that while the language was challenging and there was a near bounce, the tooling helped keep them coming back and trying.</p>
<blockquote>
<p>"Well, I think my early impressions of Rust - one is I find C++ so intimidating, and I think a big part of why I was able to succeed at [..] learning Rust is the tooling. I mean, all this makes sense [..] but it's like, for me, getting started with Rust, the language was challenging, but the tooling was incredibly easy." -- Founder of another startup built on Rust</p>
</blockquote>
<p>While it might be considered more of a community concern, if there are interactions online and in spaces that point to learners having
so-called "skill issues" this feeds into the narrative that Rust must be hard to learn. We may be unintentionally turning away Rust Project contributors and maintainers due to the vibes being put out when new learners show up in certain spaces.</p>
<blockquote>
<p>"People are very helpful, but generally the attitude is: if your program is very complicated, it's mostly a skill issue. There's not that much empathy when people get stuck learning, and a lot of people are just pushed away by it. There's probably a huge number of people who silently stop wanting to write Rust, because at some point it gets complicated and the feedback they get is 'you just need to be a better programmer, obviously'." -- Software Engineer at a SaaS Provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#feedback-on-near-bounces-from-survey"></a>
Feedback on near-bounces from survey</h4>
<p>We found a few interesting perspectives collected in the Rust Vision doc survey which we administered with examples of bouncing and coming back:</p>
<blockquote>
<p>"I started before 1.0, got stuck very soon when trying to translate patterns from C++ to Rust (due to borrow checking). I tried again after 1.0 and it stuck. [..]" -- Survey Respondent A</p>
</blockquote>
<p>Survey Respondent A went on to share in a more detailed response about a perceived weakness in Rust learning materials related to lifetimes and the borrow checker are explained. There was an observation that it's fairly easy to run into more complex situations with lifetimes and the borrow checker. They felt that the current state of this sort of material and tutorials is fairly superficial and can leave learners stuck when they run into those more complex situations.</p>
<p>One respondent that bounced once and came back shared challenges around usage of async. In concert with Rust's memory-safety and the borrow checker, they found some of the nitty-gritty details of async were difficult to learn. While we're aware of the Rust Project's continuous efforts to improve Rust's async story, this is another data point of a user that faced challenges.</p>
<p>Another survey respondent shared how they had multiple times bounced in trying to learn Rust. They returned after a year or so and found Rustlings to be highly motivating. We note that having multiple pathways for folks to learn Rust opens up more possibilities for those that nearly bounced, just like this person.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#need-more-focused-work-on-silent-attritrion"></a>
Need more focused work on silent attritrion</h4>
<p>The thing that stood out most to us was the lack of real, first-hand knowledge of having bounced when learning Rust. While this is an obvious effect of soliciting answers to our survey and opportunities to interview through Rust channels and our networks, this cohort is good future candidate where interviews could start.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#conclusions"></a>
Conclusions</h3>
<p>Across these conversations, the experience of learning Rust depended heavily on context. Why someone was learning and what support they had mattered as much as the borrow checker. The same kinds of examples kept coming up: a training course that got a team to a shared baseline, a maintainer answering a student's first GitHub issue, and a colleague whose code showed that cloning was okay.</p>
<p>That context is largely something the community has a hand in. With that in mind, here is what we take away from what we heard, and what we still don't know.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-seems-worth-trying"></a>
What seems worth trying</h4>
<p><strong>Learning materials aimed at unlearning.</strong> Syntax barely came up when people described their struggles. People struggled with unlearning habits from previous languages, whether OOP structuring from C++ and Java or the instinct to grab a raw pointer to a peripheral. Most of our learning materials teach Rust from first principles, and that works. What we didn't come across is much written for, say, the engineer with ten years of Java who lands on a Rust team after a reorg: material that names the patterns they'll reach for that won't transfer, and shows what to do instead. The professor we spoke with did a version of this in the classroom, leaning on "traits are like interfaces in Java" and saving generics for later in the course, and the students did fine. Something similar could work outside the classroom too.</p>
<p><strong>Put the "clone freely while you're learning" advice somewhere official.</strong> Every experienced developer we spoke with gave the same advice, but learners seem to mostly pick it up by accident, like the researcher who happened to see someone else cloning the struct they had been carefully threading lifetimes through. Saying it early in official materials would take some of the steepness out of the curve. The broader version belongs there too: idiomatic Rust doesn't have to mean optimal Rust, especially on a first project.</p>
<p><strong>Diagnostics are already a primary learning resource: several people told us the compiler taught them lifetimes before any documentation did.</strong> Diagnostics reach learners right at the moment they're stuck. When writing new ones, it seems worth keeping the confused newcomer in mind alongside the expert, because for a lot of people this is where the learning happens.</p>
<p><strong>Is "the book" actually out of date?</strong> Whether or not The Rust Programming Language or other materials are actually behind, a team evaluating Rust looked at its repository, saw unresolved issues and unmerged PRs, and moved on. As more companies evaluate adoption, more people will look at these materials with the same fresh eyes. Visible issue triage and some communication about what's current and what's planned would address the perception, separately from whatever content work may or may not be needed.</p>
<p><strong>How stuck learners get treated is shaping who stays.</strong> We heard about students getting answers on GitHub from the maintainers who wrote the code, and we heard about learners being told their struggles were a skill issue. The first group came away with a lasting good impression of Rust. Some of the second group walked away entirely, and because they leave quietly, it's easy to underestimate how many of them there are. The welcoming side of the community came up unprompted as a reason people stayed, so we know it makes a difference when we get this right.</p>
<p><strong>Every organization we spoke with described essentially the same ramp-up for bringing a team to Rust.</strong> Teams that brought groups of developers to Rust described roughly the same approach: get everyone to a shared baseline with a training course or with The Rust Programming Language and Rustlings, start people on lower-risk tickets, and give them somewhere internal to ask questions. Several organizations also found that hiring developers without Rust experience and ramping them up worked out better than continuing to search for rare expertise in another language. None of this is complicated, and teams weighing adoption don't need to invent a training program from scratch.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-we-still-don-t-know"></a>
What we still don't know</h4>
<p>The biggest gap is the people we didn't reach. Nearly everyone we spoke with stuck with Rust long enough to be reachable through Rust channels, so the stories of bouncing off came to us second-hand: a friend who walked away from embedded Rust, colleagues who quietly stopped after the responses they got. As we wrote in <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">our first post</a>, finding people who decided against Rust takes targeted outreach. If the proposed User Research team comes together, talking with learners who bounced would make a good early project, and learning is probably the area where that research would teach us the most.</p>
<p>We also don't know what to make of LLMs as a learning tool yet. They came up as a search engine, as an example generator, and in one organization's case as something that makes training high school graduates into working Rust developers possible. We saw a classroom where the C cohort leaned on LLMs in ways the Rust cohort couldn't, and we don't have an explanation for it. All of this comes from a handful of conversations, so we treat it as a set of leads to follow up on. Given how quickly the tools are changing, it seems better to study this deliberately than to wait and see what folklore develops.</p>
<p>The folks we spoke with showed that people do get there: with enough passes through the materials and enough code written, it eventually clicks. The opportunities above are mostly about making it work for the people who didn't pick Rust on purpose, and for the ones who would have stuck around if their early experience had gone a little differently.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Should you use AI for a task? Here’s a simple way to decide | Bruce Schneier]]></title>
<description><![CDATA[Sometimes, what matters isn’t your output but what you put into the process. Think of it like work v the gymI teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my students regularly use AI to complete th...]]></description>
<link>https://tsecurity.de/de/3693080/it-nachrichten/should-you-use-ai-for-a-task-heres-a-simple-way-to-decide-bruce-schneier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693080/it-nachrichten/should-you-use-ai-for-a-task-heres-a-simple-way-to-decide-bruce-schneier/</guid>
<pubDate>Sat, 25 Jul 2026 06:11:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Sometimes, what matters isn’t your output but what you put into the process. Think of it like work v the gym</p><p>I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my students regularly <a href="https://www.insidehighered.com/news/faculty/learning-assessment/2026/07/08/brown-professor-suspects-most-his-class-used-ai-cheat">use AI</a> to complete their writing assignments. Doing so is a waste of their tuition money. But if their entire career is going to include AI writing assistants, why shouldn’t they embrace their future?</p><p>The best way I’ve found to explain the dilemma <a href="https://danielmiessler.com/blog/keep-the-robots-out-of-the-gym">comes from</a> the AI researcher Daniel Meissler: it’s the difference between work and the gym.</p> <a href="https://www.theguardian.com/commentisfree/2026/jul/24/should-you-use-ai">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-34505 | OpenClaw up to 2026.3.11 excessive authentication (GHSA-5m9r-p9g7-679c)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in OpenClaw up to 2026.3.11. Affected by this issue is some unknown functionality. The manipulation results in improper restriction of excessive authentication attempts.

This vulnerability is identified as CVE-2026-34505. The attack ca...]]></description>
<link>https://tsecurity.de/de/3692796/sicherheitsluecken/cve-2026-34505-openclaw-up-to-2026311-excessive-authentication-ghsa-5m9r-p9g7-679c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692796/sicherheitsluecken/cve-2026-34505-openclaw-up-to-2026311-excessive-authentication-ghsa-5m9r-p9g7-679c/</guid>
<pubDate>Sat, 25 Jul 2026 02:24:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.11</a>. Affected by this issue is some unknown functionality. The manipulation results in improper restriction of excessive authentication attempts.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-34505">CVE-2026-34505</a>. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-34506 | OpenClaw up to 2026.3.7 Microsoft Teams Plugin team/channel groupAllowFrom authorization (GHSA-g7cr-9h7q-4qxq)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in OpenClaw up to 2026.3.7. Affected is an unknown function of the file team/channel of the component Microsoft Teams Plugin. The manipulation of the argument groupAllowFrom leads to incorrect authorization.

This vulnerability is listed as...]]></description>
<link>https://tsecurity.de/de/3692789/sicherheitsluecken/cve-2026-34506-openclaw-up-to-202637-microsoft-teams-plugin-teamchannel-groupallowfrom-authorization-ghsa-g7cr-9h7q-4qxq/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692789/sicherheitsluecken/cve-2026-34506-openclaw-up-to-202637-microsoft-teams-plugin-teamchannel-groupallowfrom-authorization-ghsa-g7cr-9h7q-4qxq/</guid>
<pubDate>Sat, 25 Jul 2026 02:23:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.3.7</a>. Affected is an unknown function of the file <em>team/channel</em> of the component <em>Microsoft Teams Plugin</em>. The manipulation of the argument <em>groupAllowFrom</em> leads to incorrect authorization.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-34506">CVE-2026-34506</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[IMAX vs IMAX 70mm: The difference between these two cinema formats]]></title>
<description><![CDATA[The different IMAX filming and projection formats have a dramatic impact on the theater viewing experience.]]></description>
<link>https://tsecurity.de/de/3692293/it-nachrichten/imax-vs-imax-70mm-the-difference-between-these-two-cinema-formats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692293/it-nachrichten/imax-vs-imax-70mm-the-difference-between-these-two-cinema-formats/</guid>
<pubDate>Fri, 24 Jul 2026 20:34:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The different IMAX filming and projection formats have a dramatic impact on the theater viewing experience.]]></content:encoded>
</item>
<item>
<title><![CDATA[Model Context Protocol is going stateless to make scaling simpler]]></title>
<description><![CDATA[Model Context Protocol (MCP), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.



The latest release candidate, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless arch...]]></description>
<link>https://tsecurity.de/de/3691919/ai-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691919/ai-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</guid>
<pubDate>Fri, 24 Jul 2026 17:40:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a>), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.</p>



<p class="wp-block-paragraph">The latest <a href="https://modelcontextprotocol.io/specification/draft/changelog" target="_blank" rel="noreferrer noopener">release candidate</a>, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless architecture, a change which industry experts say is intended to make MCP easier to deploy across standard cloud infrastructure as enterprises move AI pilots into production.</p>



<p class="wp-block-paragraph">“The session-based model made sense when MCP servers were local processes on a developer’s laptop. In production, it became an operational tax,” said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at ZopDev.</p>



<p class="wp-block-paragraph">“When your infrastructure team asks whether MCP services can scale like other cloud applications, the answer used to be ‘not quite.’ With the move to a stateless architecture, the answer is now yes,” Bandta added.</p>



<p class="wp-block-paragraph">Earlier versions of the protocol maintained information about every client connection, meaning servers had to keep track of each session throughout an interaction. While that approach worked well for local development, it complicated deployments across multiple servers because requests often had to be routed back to the same machine, limiting scalability and making MCP a less natural fit for modern cloud architectures.</p>



<p class="wp-block-paragraph">“Under the new stateless design, every request contains the information needed for any available server to process it independently. Applications that need to maintain context across multiple requests can still do so, but developers must now manage that state explicitly rather than relying on the protocol itself,” she said.</p>



<p class="wp-block-paragraph">This transition to a stateless design goes beyond simplifying infrastructure by fundamentally changing how AI applications manage and share context across tools, according to <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Instead of keeping application state hidden inside protocol sessions, the new design makes it explicit, allowing AI models to access, reason over, and pass that information between tools, giving developers greater control over how context is preserved and shared across tools, Jena said.</p>



<p class="wp-block-paragraph">It should also make AI workflows more portable, resilient, and easier to orchestrate across distributed environments, he said.</p>



<h2 class="wp-block-heading">MCP’s new features</h2>



<p class="wp-block-paragraph">Other changes to MCP include the addition of a Multi Round-Trip Requests (MRTR) mechanism that changes how AI agents request additional information they need to complete a task.</p>



<p class="wp-block-paragraph">Instead of relying on a persistent connection between the client and server throughout the interaction, the new mechanism lets the server request additional input through a standard request-response exchange before continuing the task, Jena said.</p>



<p class="wp-block-paragraph">Routable transport headers, another addition, enable API gateways and other networking infrastructure to identify and route MCP requests without inspecting their contents.</p>



<p class="wp-block-paragraph">They reduce processing overhead, lower latency, and let enterprise teams enforce routing, rate-limiting and security policies more efficiently using existing API management infrastructure, Jena said.</p>



<p class="wp-block-paragraph">MCP is also getting an updated authorization framework built around OAuth 2.1 and OpenID Connect; interactive MCP Apps; and deterministic caching of tool and resource listings to improve LLM prompt-cache hit rates, potentially saving on token costs.</p>



<h2 class="wp-block-heading">Rebuilding the trust boundary</h2>



<p class="wp-block-paragraph">The MCP release steering committee also decided to deprecate some legacy features, including Roots, Sampling, Logging, the older HTTP+SSE transport and Dynamic Client Registration, although these will continue to work in this version and any other released over the next year.</p>



<p class="wp-block-paragraph">The deprecation of Sampling is likely to have the biggest impact because it changes who is responsible for interacting with foundation models, said Jena.</p>



<p class="wp-block-paragraph">“Sampling let MCP servers invoke the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" target="_blank">LLM</a> through the client, which meant the server had a callback path into the model without owning that connection. Deprecating it means rebuilding that trust boundary,” Jena said. “Your server now calls the model provider directly. That changes your network architecture, your auth model, and depending on how you’ve built cost attribution, your billing flow.”</p>



<p class="wp-block-paragraph">The year-long transition period will be enough for teams to audit their sampling dependencies now, said Jena: “The risk is that teams who haven’t implemented sampling themselves won’t know if a third-party MCP server they’re depending on uses it.”</p>



<h2 class="wp-block-heading">Updated MCP SDKs</h2>



<p class="wp-block-paragraph">To accompany the protocol update, there are updated <a href="https://github.com/modelcontextprotocol" target="_blank" rel="noreferrer noopener">MCP SDKs</a> for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html" target="_blank">Python</a>, <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" target="_blank">Typescript</a>, <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>, and <a href="https://www.infoworld.com/article/4131649/the-best-new-features-of-c-14.html">C#</a>. These support both the old and new protocol versions, so new clients can continue communicating with older servers, while updated servers will also support older clients, reducing the risk of immediate disruptions.</p>



<p class="wp-block-paragraph">That backward compatibility should make the transition largely incremental, except for enterprises that built custom infrastructure around MCP’s earlier session-based architecture, Bandta said.</p>



<p class="wp-block-paragraph">Identifying and auditing those session dependencies may not be easy, Jena warned.</p>



<p class="wp-block-paragraph">“Session management complexity tends to be hidden across multiple layers — the gateway config, the deployment scripts, the monitoring dashboards. The code change is small; finding everywhere the assumption lives is what takes time,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Model Context Protocol is going stateless to make scaling simpler]]></title>
<description><![CDATA[Model Context Protocol (MCP), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.



The latest release candidate, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless arch...]]></description>
<link>https://tsecurity.de/de/3691907/it-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691907/it-nachrichten/model-context-protocol-is-going-stateless-to-make-scaling-simpler/</guid>
<pubDate>Fri, 24 Jul 2026 17:38:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a>), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet.</p>



<p class="wp-block-paragraph">The latest <a href="https://modelcontextprotocol.io/specification/draft/changelog" target="_blank" rel="noreferrer noopener">release candidate</a>, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless architecture, a change which industry experts say is intended to make MCP easier to deploy across standard cloud infrastructure as enterprises move AI pilots into production.</p>



<p class="wp-block-paragraph">“The session-based model made sense when MCP servers were local processes on a developer’s laptop. In production, it became an operational tax,” said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at ZopDev.</p>



<p class="wp-block-paragraph">“When your infrastructure team asks whether MCP services can scale like other cloud applications, the answer used to be ‘not quite.’ With the move to a stateless architecture, the answer is now yes,” Bandta added.</p>



<p class="wp-block-paragraph">Earlier versions of the protocol maintained information about every client connection, meaning servers had to keep track of each session throughout an interaction. While that approach worked well for local development, it complicated deployments across multiple servers because requests often had to be routed back to the same machine, limiting scalability and making MCP a less natural fit for modern cloud architectures.</p>



<p class="wp-block-paragraph">“Under the new stateless design, every request contains the information needed for any available server to process it independently. Applications that need to maintain context across multiple requests can still do so, but developers must now manage that state explicitly rather than relying on the protocol itself,” she said.</p>



<p class="wp-block-paragraph">This transition to a stateless design goes beyond simplifying infrastructure by fundamentally changing how AI applications manage and share context across tools, according to <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Instead of keeping application state hidden inside protocol sessions, the new design makes it explicit, allowing AI models to access, reason over, and pass that information between tools, giving developers greater control over how context is preserved and shared across tools, Jena said.</p>



<p class="wp-block-paragraph">It should also make AI workflows more portable, resilient, and easier to orchestrate across distributed environments, he said.</p>



<h2 class="wp-block-heading">MCP’s new features</h2>



<p class="wp-block-paragraph">Other changes to MCP include the addition of a Multi Round-Trip Requests (MRTR) mechanism that changes how AI agents request additional information they need to complete a task.</p>



<p class="wp-block-paragraph">Instead of relying on a persistent connection between the client and server throughout the interaction, the new mechanism lets the server request additional input through a standard request-response exchange before continuing the task, Jena said.</p>



<p class="wp-block-paragraph">Routable transport headers, another addition, enable API gateways and other networking infrastructure to identify and route MCP requests without inspecting their contents.</p>



<p class="wp-block-paragraph">They reduce processing overhead, lower latency, and let enterprise teams enforce routing, rate-limiting and security policies more efficiently using existing API management infrastructure, Jena said.</p>



<p class="wp-block-paragraph">MCP is also getting an updated authorization framework built around OAuth 2.1 and OpenID Connect; interactive MCP Apps; and deterministic caching of tool and resource listings to improve LLM prompt-cache hit rates, potentially saving on token costs.</p>



<h2 class="wp-block-heading">Rebuilding the trust boundary</h2>



<p class="wp-block-paragraph">The MCP release steering committee also decided to deprecate some legacy features, including Roots, Sampling, Logging, the older HTTP+SSE transport and Dynamic Client Registration, although these will continue to work in this version and any other released over the next year.</p>



<p class="wp-block-paragraph">The deprecation of Sampling is likely to have the biggest impact because it changes who is responsible for interacting with foundation models, said Jena.</p>



<p class="wp-block-paragraph">“Sampling let MCP servers invoke the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" target="_blank">LLM</a> through the client, which meant the server had a callback path into the model without owning that connection. Deprecating it means rebuilding that trust boundary,” Jena said. “Your server now calls the model provider directly. That changes your network architecture, your auth model, and depending on how you’ve built cost attribution, your billing flow.”</p>



<p class="wp-block-paragraph">The year-long transition period will be enough for teams to audit their sampling dependencies now, said Jena: “The risk is that teams who haven’t implemented sampling themselves won’t know if a third-party MCP server they’re depending on uses it.”</p>



<h2 class="wp-block-heading">Updated MCP SDKs</h2>



<p class="wp-block-paragraph">To accompany the protocol update, there are updated <a href="https://github.com/modelcontextprotocol" target="_blank" rel="noreferrer noopener">MCP SDKs</a> for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html" target="_blank">Python</a>, <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" target="_blank">Typescript</a>, <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>, and <a href="https://www.infoworld.com/article/4131649/the-best-new-features-of-c-14.html">C#</a>. These support both the old and new protocol versions, so new clients can continue communicating with older servers, while updated servers will also support older clients, reducing the risk of immediate disruptions.</p>



<p class="wp-block-paragraph">That backward compatibility should make the transition largely incremental, except for enterprises that built custom infrastructure around MCP’s earlier session-based architecture, Bandta said.</p>



<p class="wp-block-paragraph">Identifying and auditing those session dependencies may not be easy, Jena warned.</p>



<p class="wp-block-paragraph">“Session management complexity tends to be hidden across multiple layers — the gateway config, the deployment scripts, the monitoring dashboards. The code change is small; finding everywhere the assumption lives is what takes time,” he said.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4201254/model-context-protocol-is-going-stateless-to-make-scaling-simpler.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Should you use AI for a task? Here’s a simple way to decide | Bruce Schneier]]></title>
<description><![CDATA[Sometimes, what matters isn’t your output but what you put into the process. Think of it like work v the gymI teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come at no surprise to you that my students regularly use AI to complete th...]]></description>
<link>https://tsecurity.de/de/3691471/ai-nachrichten/should-you-use-ai-for-a-task-heres-a-simple-way-to-decide-bruce-schneier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691471/ai-nachrichten/should-you-use-ai-for-a-task-heres-a-simple-way-to-decide-bruce-schneier/</guid>
<pubDate>Fri, 24 Jul 2026 14:06:15 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Sometimes, what matters isn’t your output but what you put into the process. Think of it like work v the gym</p><p>I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come at no surprise to you that my students regularly <a href="https://www.insidehighered.com/news/faculty/learning-assessment/2026/07/08/brown-professor-suspects-most-his-class-used-ai-cheat">use AI</a> to complete their writing assignments. Doing so is a waste of their tuition money. But if their entire career is going to include AI writing assistants, why shouldn’t they embrace their future?</p><p>The best way I’ve found to explain the dilemma <a href="https://danielmiessler.com/blog/keep-the-robots-out-of-the-gym">comes from</a> the AI researcher Daniel Meissler: it’s the difference between work and the gym.</p> <a href="https://www.theguardian.com/commentisfree/2026/jul/24/should-you-use-ai">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft launches new in-house AI models it says cut costs up to 89% versus OpenAI]]></title>
<description><![CDATA[Microsoft AI released two new in-house models into public preview on Wednesday — MAI-Image-2.5-Pro, its highest-fidelity image generator to date, and MAI-Voice-2-Flash, a speech model built for high-volume enterprise workloads — while publishing production data that amounts to the company's most ...]]></description>
<link>https://tsecurity.de/de/3690504/it-nachrichten/microsoft-launches-new-in-house-ai-models-it-says-cut-costs-up-to-89-versus-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690504/it-nachrichten/microsoft-launches-new-in-house-ai-models-it-says-cut-costs-up-to-89-versus-openai/</guid>
<pubDate>Fri, 24 Jul 2026 02:50:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://microsoft.ai/">Microsoft AI</a> released two new in-house models into public preview on Wednesday — <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5-Pro</a>, its highest-fidelity image generator to date, and <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Voice-2-Flash</a>, a speech model built for high-volume enterprise workloads — while publishing production data that amounts to the company's most aggressive argument yet that it can power its own products without leaning on OpenAI's frontier models.</p><p>The announcement, made by <a href="https://microsoft.ai/">Microsoft AI's Superintelligence team</a>, lands roughly a year after the company committed to building purpose-built models internally, and it arrives with an unusual level of specificity about where those models now run: <a href="https://www.bing.com/">Bing</a>, <a href="https://www.microsoft.com/en-us/microsoft-365/powerpoint">PowerPoint</a>, <a href="https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage">OneDrive</a>, <a href="https://www.microsoft.com/en-us/dynamics-365">Dynamics 365</a>, <a href="https://excel.cloud.microsoft/en-us/">Excel</a>, <a href="https://github.com/features/copilot">GitHub Copilot</a>, and <a href="https://azure.microsoft.com/en-us">Azure</a>. The message to enterprise buyers — and, implicitly, to OpenAI — is that Microsoft's homegrown models are no longer research projects. They are production infrastructure serving millions of users.</p><p>"Each of these enhancements is a step toward the same goal: Microsoft products, powered by Microsoft models," the company wrote in its announcement blog.</p><h2><b>How MAI-Image-2.5-Pro and MAI-Voice-2-Flash stake out opposite ends of the AI cost curve</b></h2><p>The two new releases occupy opposite ends of what Microsoft calls the quality-speed-cost curve, and the positioning is deliberate. <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5-Pro</a> targets the premium tier: hero imagery, detailed editing, and precise in-image text rendering — the last of which has long been a notorious weak spot for image generation models. Microsoft priced the model at $5 per million text input tokens, $8 per million image input tokens, and $106 per million image output tokens. The base <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5</a> model recently launched at <a href="https://microsoft.ai/news/introducing-mai-image-2-5/">No. 2 for image editing on Arena</a>, the community leaderboard that has become a de facto scoreboard for generative media.</p><p>The creative industry appears to be taking notice. Rob Reilly, global chief creative officer at advertising giant WPP, called the Pro model "a strong leap forward for GenMedia tools" in a statement included in Microsoft's announcement, adding that "Microsoft has firmly established itself among the leaders in generative AI."</p><p><a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Voice-2-Flash</a> goes the other direction. First previewed at Microsoft's <a href="https://news.microsoft.com/build-2026/">Build conference</a>, Flash runs twice as fast as MAI-Voice-2 and costs 32% less, priced at $15 per million characters. It is designed for the unglamorous but enormous market of high-volume voice — call centers, voice agents, and real-time speech applications where latency and cost-per-call matter more than marginal gains in expressiveness. Together, the two models reflect a strategy of building families of models rather than a single flagship, because, as the company put it, a creative studio chasing maximum fidelity has very different needs from a customer service operation handling millions of calls a day.</p><h2><b>Microsoft's production metrics show in-house models cutting GPU costs by up to 89%</b></h2><p>The model launches are arguably less newsworthy than the deployment metrics Microsoft attached to them — numbers that read like a systematic case for swapping out third-party frontier models across its product portfolio. </p><p><a href="https://explore.microsoft.com/en-us/bing/features/bing-image-creator?form=MA13FV">Bing Image Creator </a>now runs entirely on <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Image-2.5</a>, end to end, marking the first time the consumer image tool is fully in-house. In PowerPoint, Microsoft says MAI-Image-2.5 reduces GPU costs by up to 84% compared with GPT-Image-2, OpenAI's image model. In OneDrive, where MAI-Image-2.5 is now the default for key image-editing scenarios, the company reports a 26% increase in save rates, roughly 25% lower P95 latency, and 2.5 times greater efficiency under medium-utilization production workloads.</p><p>On the voice side, <a href="https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/">MAI-Voice-2-Flash</a> now powers Dynamics 365 Contact Center — the platform used by customers including T-Mobile and EasyJet — where Microsoft claims GPU cost reductions of up to 89%. The model is also integrated into Azure Voice Live for developers building speech-to-speech agents.</p><p>Perhaps the most consequential deployment sits in healthcare. Microsoft's <a href="https://www.microsoft.com/en-us/health-solutions/clinical-workflow/dragon-copilot">Dragon Copilot</a>, used by 170,000 medical providers and responsible for processing 28 million patient encounters last quarter, now runs on MAI-Transcribe-1.5 for its multilingual workflow across 58 languages. Microsoft says internal evaluations show a 50% relative reduction in both transcription and language-identification error rates across most languages — a meaningful claim in a domain where transcription errors can propagate directly into clinical notes.</p><h2><b>Inside the 'hill-climbing' strategy that lets small models beat GPT-5.6 in Excel</b></h2><p>In a companion post published the same day, Microsoft detailed the methodology behind these results — what it calls its "<a href="https://microsoft.ai/news/hill-climbing-mai-models-for-github-copilot-and-excel/">hill-climbing machine</a>," an integrated flywheel of data, models, and the product "harness" that surrounds them.</p><p>The clearest example is <a href="https://microsoft.ai/news/introducingmai-code-1-flash/">MAI-Code-1-Flash</a>, the lightweight coding model launched in GitHub Copilot in June. Microsoft says the model achieves an approximately 10% higher code accept rate than GPT-5.4 Mini and Claude Haiku 4.5 in VS Code, while using 10% fewer median tokens. Developer retention tells a similar story: users were 6% more likely to return across multiple days than with GPT-5.4 Mini, and 11% more likely than with Claude Haiku 4.5.</p><p>Then Microsoft did something more interesting. It took the MAI-Code-1-Flash checkpoint and further <a href="https://microsoft.ai/news/hill-climbing-mai-models-for-github-copilot-and-excel/">trained it inside an Excel reinforcement learning environment</a>, teaching a coding model the tools and workflows of spreadsheet knowledge work. The result, according to production user feedback, is a model on par with GPT-5.6 for the most common Excel tasks — while being small enough to run on Nvidia's older H100 and even A100 GPUs rather than requiring the latest-generation accelerators.</p><p>That hardware detail deserves emphasis. Every major AI company is fighting for allocation of cutting-edge chips, and a model that delivers frontier-adjacent quality on two-generation-old silicon fundamentally changes the deployment economics. It also frees the newest hardware — including Microsoft's now-operational GB200 cluster — for training rather than serving.</p><h2><b>Satya Nadella's 'frontier diffusion' manifesto redraws the OpenAI relationship</b></h2><p>Microsoft CEO Satya Nadella framed the announcements in a lengthy post on X titled "<a href="https://x.com/satyanadella/status/2080329851127669104">Frontier Diffusion &amp; Control</a>," which functions as something close to a strategic manifesto. "We can now take saturated frontier capabilities and deliver them at scale and at lower cost through models optimized for high-usage products, while continuing to use frontier models for frontier needs," Nadella wrote, adding that Microsoft is "beginning to route traffic across our first-party surfaces to MAI whenever our models match or outperform frontier alternatives."</p><p>Translated from executive prose: capabilities that were state-of-the-art a year ago are now table stakes, and Microsoft believes it can replicate them cheaply for the specific, repetitive tasks that dominate real product usage. Why pay frontier prices for a frontier model when a user just wants to reformat a spreadsheet column?</p><p>Nadella was careful to note that "frontier models from OpenAI and Anthropic are part of the orchestration system alongside MAI" — but he also articulated a pointed principle of model independence, arguing that a company's evaluations "should continue to hill climb even when any given model has been removed." </p><p>“Keeping the harness, memory, context, and skills outside the model, he argued, is what gives Microsoft control. The subtext is hard to miss. Reuters reported in April that Microsoft’s <a href="https://www.reuters.com/legal/litigation/microsoft-end-exclusive-license-openais-technology-2026-04-27/">exclusive license to OpenAI’s technology</a> had been revised into a non-exclusive arrangement, and The Information reported last September that Microsoft had <a href="https://www.theinformation.com/articles/microsoft-buy-ai-anthropic-shift-openai">begun incorporating Anthropic models</a> into some products. Wednesday’s announcement completes the triangle: Microsoft as orchestrator, with its partners’ frontier models as interchangeable components and its own models absorbing an ever-larger share of routine traffic.”</p><h2><b>Developers cheer cheaper task-specific models while skeptics question Microsoft's track record</b></h2><p>The response online captured both the appeal and the skepticism surrounding the strategy. "I love when people use small models for niche tasks," wrote one X user, <a href="https://x.com/mavihsk/status/2080330529547993252">@mavihsk</a>, responding to Nadella's post. "Why do I have to use the all-knowing model just to change my field in Excel?" Another user, <a href="https://x.com/nabu_lines/status/2080343512780837226">@nabu_lines</a>, distilled the pitch neatly: "cost and performance both improve when you stop overusing the biggest model."</p><p>Others were less charitable about Microsoft's execution track record. "Microsoft is the worst when it comes to listening to user feedback," wrote designer <a href="https://x.com/designedbyabin/status/2080332368301412434">@designedbyabin</a>, arguing the company "will lose the AI race because they repeatedly failed to understand user needs." And one user, <a href="https://x.com/tokenoverflow/status/2080386145712824694">@tokenoverflow</a>, offered a drier critique of the model-independence pitch: "i want it keep hill climbing after removing microsoft."</p><p>The skeptics raise a fair point. Microsoft's self-reported metrics — accept rates, save rates, GPU savings — come from its own internal evaluations, not independent benchmarks, and the company chooses which comparisons to publish.</p><p>But the strategy's logic does not depend on any single number. Nadella's framing that software now has "<a href="https://x.com/satyanadella/status/2080329851127669104">real marginal cost for the first time</a>" explains why Microsoft is obsessive about tokens, GPUs, and serving costs: when AI features run on every keystroke across a billion-user product portfolio, an 84% GPU cost reduction is not an optimization. It is the difference between a viable business and a money pit.</p><h2><b>Why Microsoft is turning its internal AI playbook into an Azure product</b></h2><p>The final piece of the strategy is that Microsoft is selling the playbook, not just the models. Nadella explicitly positioned the hill-climbing approach as "a template for every other AI native, SaaS, or Enterprise company," and Microsoft is packaging the toolchain through Foundry and what it calls Frontier Tuning — letting enterprises train specialized models against their own proprietary evaluations and reinforcement learning environments. That turns Microsoft's internal cost-cutting exercise into an Azure product, and it gives enterprise customers a reason to run their AI workloads on Microsoft's cloud even if the models themselves come from elsewhere.</p><p>The company's emphasis on models trained "on clean, traceable, enterprise-grade data, without distillation from third-party models" serves the same commercial end. In an industry facing mounting scrutiny over training data provenance, Microsoft is betting that enterprise buyers — and courts — will care where model capabilities come from. Microsoft says it is now extending the hill-climbing approach to <a href="https://copilot.microsoft.com/">Copilot Chat</a>, <a href="https://outlook.live.com/mail/">Outlook</a>, and <a href="https://www.microsoft.com/en-us/microsoft-365/powerpoint">PowerPoint</a>, and both new models are available in public preview through <a href="https://azure.microsoft.com/en-us/products/ai-foundry">Microsoft Foundry</a> and the <a href="https://playground.microsoft.ai/">MAI Playground</a>. "None of this is an endpoint," the company wrote. "We're just getting started."</p><p>Seven years ago, <a href="https://www.cnbc.com/2024/08/10/rise-of-openai-microsofts-13-billion-artificial-intelligence-bet.html">Microsoft bet more than $13 billion</a> that OpenAI would build the future of AI. Wednesday's announcement suggests the company has since learned a cheaper lesson: the future of AI may belong to whoever builds the frontier, but the profits belong to whoever makes it ordinary.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials]]></title>
<description><![CDATA[Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents s...]]></description>
<link>https://tsecurity.de/de/3689827/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689827/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents. The security stack is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents, spending remains a thin slice of the security budget, and enterprises are evenly split on whether their defenses are keeping pace with AI-enabled attackers. The result is an agent security gap — autonomous agents proliferating faster than the identity, isolation, and enforcement controls needed to hold them.</p><p>This wave of VentureBeat Pulse Research examines how enterprises secure their AI agents: what tooling they run, how they manage agent identity and isolation, what has already gone wrong, how much they spend, and whether they believe their defenses are keeping pace with AI-enabled attackers.</p><p>The central finding is an agent security gap — the distance between the autonomy enterprises are granting their agents and the controls in place to contain them. More than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm (36%). The structural weakness beneath those numbers is identity: only about a third (32%) give every agent its own scoped, managed identity, while the rest report that some agents share credentials or that agents mostly run on shared API keys and human or service-account credentials. When agents share credentials, a single compromised or over-permissioned agent carries a wide blast radius — and only three in ten enterprises (30%) isolate their highest-risk agents in sandboxes to bound that radius.</p><p>What makes the gap notable is how comfortable enterprises are inside it. The security stack is overwhelmingly provider-native — OpenAI’s guardrails (51%), Google’s and Microsoft’s cloud controls, and Anthropic’s managed-agent controls dominate, while the dedicated agent-security specialists barely register — and satisfaction with that borrowed stack is high, averaging 4.2 out of 5. Yet spending remains a thin slice of the security budget, only a third of enterprises believe their AI defenses are ahead of AI-enabled attackers, and a clear majority plan to change tooling within the year. Enterprises are satisfied with controls they are simultaneously preparing to replace.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent security — the tooling, identity, isolation, and enforcement controls organizations use to secure autonomous AI agents. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By role the sample is senior and buyer-credible: 45% are final decision-makers for AI purchases and another 30% recommenders or influencers. Managers (43%), individual contributors (24%), VPs and directors (15%), and the C-suite (11%) make up the seniority mix. By organization size the sample is mid-market-weighted: 251–1,000 (42%) and 101–250 (25%) employees lead, with 1,001–5,000 (19%), 5,001–10,000 (8%), and 10,001+ (7%) above them. Technology/Software is the largest industry at 23%, followed by Manufacturing (15%), Retail/E-commerce (14%), and Healthcare/Life Sciences (13%).</p><p>At 107 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It skews toward the mid-market, so it is best read as the view from organizations actively standing up agent security rather than from the largest operators.</p><p>Satisfaction ratings are computed on the respondents who answered each rating question; the overall satisfaction score reflects 82 of the 107 qualified respondents.</p><h2>Finding 1: The incidents are already here</h2><p><b>More than half have had an agent security incident or near-miss</b></p><p>We asked whether organizations had experienced an agent security incident — a confirmed breach, or a near-miss caught before harm. Most that run agents in production had.</p><div></div><p>This is the report’s defining number. More than half of organizations (54%) have already had an agent security event — 18% a confirmed incident and 36% a near-miss caught before it caused harm. Only 42% report nothing, and a small remainder either run no agents in production or don’t track such events. That so many report near-misses rather than only confirmed incidents is telling: enterprises are catching problems, but they are catching them close to the edge. The controls examined in the rest of this report — identity, isolation, enforcement — are what determine whether the next near-miss stays a near-miss.</p><p>Exposure scales with company size, but containment does not. The incident-or-near-miss rate rises from 49% in the mid-market (companies with 101-1,000 employees) to 63% at larger enterprises (above 1,000 employees), while sandbox isolation of high-risk agents falls from 35% to 20%, and satisfaction with security tooling drops from 4.36 to 3.97. The organizations running the most agents across the most systems carry the most incidents and the least of the one control that bounds an incident's blast radius.</p><h2>Finding 2: The identity gap</h2><p><b>Only a third give every agent its own scoped identity</b></p><p>We asked how enterprises manage the identity of their AI agents — whether each agent has its own credentials, or agents share them. Full per-agent identity is the exception.</p><div></div><p>Rolled together, the overlapping answers show 69% of enterprises (74 of 107) with credential sharing somewhere in the agent fleet. Identity is the structural weakness beneath the incidents. Only about a third of enterprises (32%) give every agent its own scoped, managed identity — the precondition for least-privilege access and clean attribution. Nearly half (48%) say some agents have scoped identities but many still share credentials, and another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. (Respondents could describe more than one pattern across their agent fleet, so these overlap.) </p><p>The consequence is direct: when agents share credentials, an over-permissioned or compromised agent can act with far more reach than intended, and forensics after an incident cannot cleanly tell which agent did what. The non-human identity problem — giving every agent its own governed identity — is the single largest unfinished piece of enterprise agent security.</p><p>Moreover, a company’s agent credential posture is correlated with incidents. Organizations with credential sharing anywhere in the fleet were hit — with an incident or a near-miss in the past twelve months — at 63.5% (47 of 74). Organizations where every agent carries its own scoped identity were hit at 40.9% (9 of 22). The fully-scoped group is small, so for now the relationship is an association rather than proven causation, and the gap is concentrated in the mid-market — but within a single survey, a twenty-three point difference in incident rate suggests significance.</p><h2>Finding 3: Observe and enforce, but rarely isolate</h2><p><b>Only three in 10 sandbox their highest-risk agents</b></p><p>We asked what an organization’s agent security posture looks like in practice — whether they observe, enforce, isolate, or some combination. The control that bounds damage is the least common.</p><div></div><p>Monitoring and enforcement are reasonably common; containment is not. Roughly half of enterprises observe agent activity (47%) or enforce scoped permissions at runtime (49%), but only 30% isolate their highest-risk agents in sandboxes that bound the blast radius when the other controls fail. That ordering is backwards from a defense-in-depth standpoint: observation tells you what happened, enforcement tries to prevent it, but isolation is what limits the damage when prevention fails — and it is the control enterprises have adopted least. Combined with the identity gap in Finding 2, the picture is of agents that are watched and permissioned but rarely boxed in, which is precisely the configuration in which a single failure propagates.</p><h2>Finding 4: Security runs on borrowed, provider-native controls</h2><p><b>Guardrails from OpenAI, Google and Microsoft dominate; specialists barely register</b></p><p>We asked which agent security tooling enterprises use, and which is their primary layer. The answer favors the model providers and hyperscalers over the dedicated security vendors.</p><div></div><p>Enterprises are securing agents with tools that came bundled with their models and clouds. OpenAI’s guardrails lead at 51%, followed by Google’s and Microsoft’s cloud-native controls and Anthropic’s managed-agent controls — and when asked to name their single primary security layer, 82% name one of these provider-native offerings. The purpose-built agent-security category — Palo Alto’s Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point’s Lakera, Okta for AI Agents, non-human identity platforms — barely registers, each in the low single digits, and only 5% run no dedicated tooling at all. As with retrieval and evaluation elsewhere in this series, the provider bundle is winning the default: enterprises reach first for the guardrails their platform ships, and the independent security layer that would address the identity and isolation gaps has not yet been adopted at scale.</p><p>The provider-default pattern is consistent across both Q2 survey waves. In April–May (n=110), usage was led by the same names — OpenAI's controls at 26%, Azure at 15%, AWS at 14%, Google at 12% — with every dedicated agent-security specialist at 3% or below and one in ten using no dedicated tooling at all. The common finding from the two surveys: Enterprises are defaulting to the solutions provided by the platform they’re using, and the specialist category vendors have yet to become big players here.</p><p>(<i>A note on reading these shares. As described in the methodology section, the respondent sample is self-selected and skews mid-market, and the usage question counted every vendor or approach a respondent has in place — so the figures measure presence in the security stack rather than spending or exclusivity. Individual vendor percentages therefore carry all the usual sample caveats. The structural pattern, however, held across both Q2 waves on two differently worded questions: provider-native and hyperscaler controls lead, and dedicated agent-security specialists remain in low single digits. Read the individual shares loosely and the pattern with confidence.)</i></p><h2>Finding 5: And enterprises are comfortable with it</h2><p><b>Satisfaction is high, even as incidents mount and identity lags</b></p><p>We asked how satisfied enterprises are with their current agent security tooling. The comfort is notably out of step with the exposure documented above.</p><div></div><p>Satisfaction with agent security tooling is high — 4.2 out of 5 overall, and 4.1 for value for money — among the most positive readings in this series. That is the striking part: enterprises are highly satisfied with a stack that is mostly borrowed provider guardrails, even though more than half have already had an incident or near-miss and only a third give their agents scoped identities. The comfort appears to rest on the convenience and low friction of provider-native controls rather than on demonstrated containment. It is a false comfort in the making — the same enterprises expressing satisfaction are, as Finding 8 shows, a clear majority planning to change tooling within the year, which suggests the confidence is thinner than the score implies.</p><h2>Finding 6: Budgets haven’t caught up</h2><p><b>Most spend under a tenth of the security budget on agents</b></p><p>We asked what share of the security budget enterprises allocate to securing AI agents. For a fast-emerging risk, the allocation is modest.</p><div></div><p>Spending on agent security is still a thin slice. The most common allocation is 6–10% of the security budget (46%), and a third of enterprises (34%) spend 5% or less; only a quarter (24%) devote more than a tenth. Given the incident rate in Finding 1 and the identity and isolation gaps in Findings 2 and 3, the budget looks like a lagging indicator — the risk has arrived faster than the funding to address it. The enterprises spending more than a tenth of their security budget on agents are a distinct minority, and they are likely the ones building the scoped-identity and isolation controls the rest have not.</p><h1>Finding 7: The arms race is even, at best</h1><p><b>Only a third think their AI defenses are ahead of AI-enabled attackers</b></p><p>We asked how enterprises assess the balance between their AI-enabled defenses and AI-enabled attackers. Confidence is far from settled.</p><div></div><p>Enterprises are split on whether they are winning. Only about a third (35%) believe their AI-enabled defenses are ahead of AI-enabled attackers; the rest are less sure — 32% call it roughly even, 21% think attackers are ahead, and another 21% say it is too early to tell. Taken together, a clear majority (53%) rate the balance as even or tilted toward the attacker. That uncertainty sits uneasily beside the high satisfaction of Finding 5: enterprises are content with their tooling yet unconvinced it is winning the contest it exists to win. In a domain where the offense is also compounding with AI, an even race is not a comfortable place to be.</p><h2>Finding 8: A security reshuffle is coming</h2><p><b>Nearly six in 10 plan to adopt or switch tooling within a year</b></p><p>We asked whether enterprises plan to adopt a new, additional, or replacement agent security solution, and which they are considering. Few intend to stand pat.</p><div></div><p>The security stack is not settled. While 41% have no plans to change, a clear majority (59%) intend to adopt a new, additional, or replacement agent security solution within twelve months, and 29% within the next quarter — a strong signal that, high satisfaction notwithstanding, enterprises know the current stack is provisional. Incidents are what start the buying cycle. </p><p>Among organizations that have been hit, 42.1% plan to adopt, add, or replace agent security tooling within the next ninety days, against 14.0% of organizations with no incident — and after a confirmed incident it becomes majority behavior, at 52.6%. Getting hit also changes the threat assessment: 33.3% of hit organizations say AI-armed attackers are ahead of their defenses, against 8.0% of the unhit. Experience, in this data, is the strongest predictor of both urgency and pessimism.</p><p>The consideration set still leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), but the dedicated security vendors — Cloudflare, Cisco, Palo Alto, Okta, Check Point’s Lakera — draw early interest in the mid-to-high single digits, more than their current footprint. </p><p>What the shopping does not yet include is the identity layer specifically. Twelve percent of the respondents include an agent-identity product — Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform — anywhere in their consideration set, and among the credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged, at roughly one in ten. The control most directly implicated by the incident data is the one largely missing from the purchase plans. Whether this wave hardens the provider-native default or finally opens the door to purpose-built agent security — the identity and isolation controls the incidents call for — is the question this series will keep tracking.</p><h2>The bottom line: A security gap that autonomy will test first</h2><p>Organizations with more than 100 employees are giving AI agents real reach into systems and data while securing them with controls built for something else. More than half have already had an incident or near-miss; only a third give every agent its own scoped identity, and most still share credentials; only three in ten isolate their highest-risk agents; and the stack doing this work is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents.</p><p>The uncomfortable pairing is confidence with exposure: satisfaction with the current tooling is among the highest in this series, yet spending is a thin slice of the security budget, only a third believe their defenses are ahead of AI-enabled attackers, and a clear majority are already planning to replace what they have. At 107 respondents in a single wave this is a directional read, skewed toward the mid-market — but the direction is clear: agent adoption is running ahead of agent security, and the controls that matter most when something fails — scoped identity and isolation — are the ones enterprises have built least. The agent security gap is not a coverage problem that a provider guardrail will close on its own; it is a problem of identity, isolation, and enforcement built for autonomous software. The open question for later waves is whether enterprises close it deliberately — or whether a confirmed incident closes it for them.</p><hr><p><i>Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. This is a directional read, not a precise measurement — the sample is self-selected and skews mid-market, so it's best read as the view from organizations actively standing up agent security rather than from the largest operators. Respondents are senior and buyer-credible (45% final decision-makers, 30% recommenders/influencers), spanning managers through the C-suite, and drawn primarily from Technology/Software, Manufacturing, Retail/E-commerce, and Healthcare/Life Sciences.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Determining the ROI of AI requires data that most companies lack]]></title>
<description><![CDATA[Leadership wants to scale AI. Budgets are tripling. Adoption is up.



Then the CFO asks the question every board now asks: which of these initiatives is actually profitable?



Most organizations cannot answer that question, not because they lack visibility into cost, but because the cost data t...]]></description>
<link>https://tsecurity.de/de/3688477/ai-nachrichten/determining-the-roi-of-ai-requires-data-that-most-companies-lack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688477/ai-nachrichten/determining-the-roi-of-ai-requires-data-that-most-companies-lack/</guid>
<pubDate>Thu, 23 Jul 2026 11:07:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Leadership wants to scale AI. Budgets are tripling. Adoption is up.</p>



<p class="wp-block-paragraph">Then the CFO asks the question every board now asks: which of these initiatives is actually profitable?</p>



<p class="wp-block-paragraph">Most organizations cannot answer that question, not because they lack visibility into cost, but because the cost data they have was never designed to produce that answer.</p>



<p class="wp-block-paragraph">Applying lessons learned from <a href="https://www.infoworld.com/article/4147766/cloud-at-20-cost-complexity-and-control.html" data-type="link" data-id="https://www.infoworld.com/article/4147766/cloud-at-20-cost-complexity-and-control.html">managing cloud spend</a> won’t be a fix for the AI and ROI quandary. True, cloud taught a generation of CFOs that billing without business context is noise. So to get <a href="https://www.infoworld.com/article/4061122/cloud-computing-has-an-roi-problem.html" data-type="link" data-id="https://www.infoworld.com/article/4061122/cloud-computing-has-an-roi-problem.html">cloud ROI</a>, they stitched two data sources together: cost data plus business data. AWS reveals which account, which region, which tag, which resource. Merge in customer and product mappings on top and the ROI of the cloud spend comes into focus.</p>



<p class="wp-block-paragraph">But AI is harder. It requires three data sources: cost, business, and telemetry—the automatic collection of data from disparate sources that helps to clarify the whole picture of what happened and why. An executive or engineering lead can have AI invoices and customer revenue. But they have no way to connect them to business value. The token count on the OpenAI invoice does not specify which customer triggered which call, which feature it served, or whether the prompt produced a business outcome. That data does not exist in the provider’s billing.</p>



<h2 class="wp-block-heading">AI providers won’t fix this problem</h2>



<p class="wp-block-paragraph">The situation is not likely to change anytime soon because AI providers are not in the business of attributing an enterprise’s costs to that enterprise’s customers. Instead, AI providers are in the business of selling tokens. The granularity they expose is the granularity their billing systems require, not the granularity a CFO requires.</p>



<p class="wp-block-paragraph">Not convinced? Compare what AWS gives you to what an AI provider gives you.</p>



<p class="wp-block-paragraph">AWS billing exposes resource IDs, account hierarchies, region, SKU, tag metadata, usage by the minute. Every dollar can be attributed to a workload, a team, a customer segment if it was tagged correctly. The data is rich enough that mature FinOps teams built unit economics on top of it years ago.</p>



<p class="wp-block-paragraph">An AI provider invoice gives you tokens consumed by model, with optional grouping by API key. That is the resolution. No request-level attribution. No customer ID. No feature mapping. No prompt outcome. No retry identification. Multi-step agent workflows collapse into a token count. Imagine a large bank receives a multi-million dollar AI invoice each month. But it has no visibility into what parts of the business were responsible for what parts of the cost so cannot allocate them.</p>



<p class="wp-block-paragraph">If an enterprise wants to know what AI cost drove which customer or feature, it has to capture that data itself, inside an application, before the call leaves it. </p>



<h2 class="wp-block-heading">Three required sources</h2>



<p class="wp-block-paragraph">Building AI ROI measurement requires three data sources, stitched together in a single model.</p>



<ol class="wp-block-list">
<li><strong>Cost data, normalized across providers.</strong> Every AI provider delivers cost differently. OpenAI invoices in one taxonomy, Anthropic in another, fine-tuning vendors and inference platforms each in their own. Cloud GPU costs sit in AWS or Azure billing. Vector database costs land in Pinecone or Snowflake invoices. None interoperate by default. Normalization is necessary but not sufficient. It will put all your AI costs in one schema. It does not tell you what they produced.</li>



<li><strong>Application-layer telemetry. </strong>This is the source most organizations are missing, and the one that makes AI ROI structurally different from cloud ROI. It requires instrumenting AI calls inside your application across six categories: request-level tracing tied to a customer or session ID; feature attribution tied to the product surface that triggered the call; agent-step capture for multi-step workflows; retry and fallback identification so recovery costs don’t get attributed to primary calls; model selection logging that records which model was chosen and why; and outcome capture that ties each call to whether it produced business value. None of this data exists in the provider’s billing. All of it has to be captured at the moment the call is made and stored in a system that can be stitched to the cost data.</li>



<li><strong>Business data. </strong>Revenue, customer segments, product hierarchies, and feature usage. The same business data already feeding your CRM and analytics stack, mapped to the customers and features the telemetry layer attributes calls to.</li>
</ol>



<p class="wp-block-paragraph">Stitched together, the three sources produce the unit economics every AI investment decision now requires: cost per customer interaction, margin per feature, profitability per agent workflow, ROI per model choice. None of these can be calculated from billing data alone. None can be calculated from telemetry alone. They require all three sources, modeled together in a way that maps cost to outcome.</p>



<h2 class="wp-block-heading">Why agentic AI makes this urgent</h2>



<p class="wp-block-paragraph">Single-call inference is the easy case. One request, one cost, one customer, one outcome.</p>



<p class="wp-block-paragraph">Agentic workflows are different. An agent decomposes a task into multiple steps. Each step calls a model. Some steps fall back to a different model when the first fails. Some steps retry on a poor result. Some steps invoke external tools that themselves cost money. A single user request can produce dozens of inference calls across multiple providers, with the cost compounding in ways the provider invoice cannot disaggregate.</p>



<p class="wp-block-paragraph">If telemetry does not capture agent-step granularity, no one will know which steps are profitable. Aggregate costs will show up three weeks later in the invoice. By then, the workflow has been running at scale, customers are onboarded, and unprofitable paths have been retried thousands of times.</p>



<p class="wp-block-paragraph">When agents make the calls, the volume of cost-generating events without business context attached grows by an order of magnitude. The window for instrumenting this before it becomes unmanageable is closing.</p>



<h2 class="wp-block-heading">What changes when the three sources come together</h2>



<p class="wp-block-paragraph">Once the three sources are stitched together, the AI investment conversation changes.</p>



<p class="wp-block-paragraph">Five different ways to build the same AI capability stop looking equivalent. They converge on adoption metrics and diverge by 10x on cost. The team picks the approach that delivers a similar business outcome at one-fifth the cost, because the team can finally see the difference. Product teams design features with margin awareness from the architecture phase, not from the post-launch budget review. Engineering teams choose model architectures with cost-per-outcome data alongside latency and quality. Leadership evaluates AI initiatives the way they evaluate any other capital allocation: on unit economics, not on the engagement chart. Aggregated invoices track the cost per customer interaction. Engagement metrics reveal margin per feature. Gut-instinct model selection is checked against real cost-per-outcome model selection results. </p>



<p class="wp-block-paragraph">Within seconds, everyone can see which AI features are profitable, which should scale, and which should be killed. This is the insight everyone is looking for and companies that achieve it will optimize the benefits of AI.</p>



<h2 class="wp-block-heading">The build trap</h2>



<p class="wp-block-paragraph">AI costs are compounding now. The board is not waiting 18 months for an internal project to reach production.</p>



<p class="wp-block-paragraph">The temptation to build it anyway has never been sharper. AI coding tools have changed what a small engineering team can ship in a quarter. The instrumentation layer looks tractable. The cost normalization looks like a weekend project. The semantic model feels like something a senior engineer could draft over a sprint.</p>



<p class="wp-block-paragraph">It is a trap. Three reasons.</p>



<p class="wp-block-paragraph">Volume is the first. A production AI footprint generates millions of telemetry events per hour, and that volume scales with agentic adoption. Real-time ingestion, correlation, and attribution at that scale is not the same problem as <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html" data-type="link" data-id="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html">vibe coding</a> a prototype in an afternoon. It is a permanent operational system that has to be right every minute of every day.</p>



<p class="wp-block-paragraph">The vendor landscape is the second. Cost data arrives in delayed billing windows from providers with non-interoperable schemas. Schemas change without notice. New AI providers enter the landscape monthly, each with its own taxonomy and metering. The system is not built once. It is maintained against a moving target that moves faster than most internal release cycles.</p>



<p class="wp-block-paragraph">The third is what the first two add up to: this is business-critical infrastructure. The CFO and the board are going to make capital allocation decisions on the data this system produces. When schema drift goes unnoticed for two weeks, when an agent telemetry stream stops correlating to a vendor that quietly changed its billing API, the cost of being wrong is not a sprint of cleanup. It is a quarter of misallocated capital.</p>



<p class="wp-block-paragraph">The build-vs.-buy question for engineering leaders has changed. It’s not “can we build this?” The honest answer is yes. The real question is whether the marginal hour of your strongest engineers is best spent stitching cost data to telemetry to business outcomes, or building the AI products that produce the revenue the cost data is measuring.</p>



<p class="wp-block-paragraph">The capability is reproducible in weeks. The choice is whether to spend the next 18 months building it, or the next 18 months acting on it.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 661]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3688059/tools/this-week-in-rust-this-week-in-rust-661/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688059/tools/this-week-in-rust-this-week-in-rust-661/</guid>
<pubDate>Thu, 23 Jul 2026 07:18:12 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/07/16/Rust-1.97.1/">Announcing Rust 1.97.1</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-76">The Embedded Rustacean Issue #76</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://tokio.rs/blog/2026-07-22-announcing-topcoat">Announcing Topcoat: a framework for building full-stack reactive web apps with Rust</a></li>
<li><a href="https://github.com/dtolnay/syn/releases/tag/3.0.0">Syn 3.0.0</a></li>
<li><a href="https://blog.jetbrains.com/rust/2026/07/22/whats-new-in-rustrover-2026-2/">What’s New in RustRover 2026.2</a></li>
<li><a href="https://github.com/kunobi-ninja/kobe/releases/tag/v0.35.0">kobe 0.35.0: readiness gates and cert recycling</a></li>
<li><a href="https://github.com/Eoin-McMahon/comhad/releases/tag/v0.1.0">Comhad v0.1.0: a ranger-style tui cyberduck replacement for browsing S3</a></li>
<li><a href="https://github.com/bigduu/Nova/releases/tag/v0.2.1">Nova v0.2.1: computer-use MCP server</a></li>
<li><a href="https://github.com/rust-windowing/winit/pull/4571">winit now has comprehensive cross-platform drag-and-drop support, exposing most of the power of the underlying OS APIs</a></li>
<li><a href="https://github.com/singhpratech/crimson-crab/releases/tag/v0.1.0">crimson-crab v0.1.0 - a production-grade Rust SDK for the Claude API (streaming, tool use, prompt caching, batches)</a></li>
<li><a href="https://singhpratech.github.io/ferrovec/">ferrovec: dependency-light HNSW vector search in Rust, compiled to WebAssembly for private in-browser semantic search</a></li>
<li><a href="https://github.com/ordokr/ordofp/releases/tag/v0.1.0">OrdoFP 0.1.0 released — a functional-programming toolbelt for Rust (HList, GAT type classes, optics, effects, monad transformers)</a></li>
<li><a href="https://freyaui.dev/posts/0.4">Freya 0.4</a></li>
<li><a href="https://dev.to/nabsei/buildline-merging-cargo-and-ninjas-build-profiling-into-one-timeline-2373">buildline: merging cargo and ninja's build profiling into one timeline</a></li>
<li><a href="https://richer-richard.github.io/cochlea/determinism.html#030-additions-2026-07-22">cochlea 0.3.0: melody read-back, MFCC timbre, a master limiter, and MIDI import for the deterministic agent-audio engine</a></li>
<li><a href="https://flodl.dev/blog/then-the-cpu-died">flodl 0.6.0: multi-host heterogeneous DDP - mismatched GPUs across hosts beat the fastest card alone</a></li>
<li><a href="https://hongnoul.github.io/hwatu/">hwatu: a daemon-based WebKitGTK browser for tiling WMs with ~13ms window spawn</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.11.0">kache 0.11.0: broader compiler coverage and libc-aware keys</a></li>
<li><a href="https://mladedav.github.io/blog/blog/tracing-reload/"><code>tracing-reload</code> - reload layer without panics</a></li>
<li><a href="https://www.opentypeless.com/en/blog/introducing-talkmore">Introducing OpenTypeless: Voice Input That Actually Works</a></li>
<li><a href="https://dev.to/booyaka101/reading-a-rust-crates-capabilities-out-of-its-compiled-symbols-58pb">Reading a Rust crate's capabilities out of its compiled symbols</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://smallcultfollowing.com/babysteps/blog/2026/07/15/battery-packs/">Battery packs: Let's talk about crates, baby</a></li>
<li><a href="https://blog.yoshuawuyts.com/capture-clauses-as-effects">Capture Clauses as Effects</a></li>
<li><a href="https://corrode.dev/blog/hardening-rust/">Hardening Rust Code For Production</a></li>
<li><a href="https://pranitha.dev/posts/tokio-gives-progress-not-ordering/">Tokio Gives Progress, Not Ordering: Scheduling 1M Tasks</a></li>
<li><a href="https://kerkour.com/rust-service-hardening-and-production-checklist">Rust service hardening and production checklist</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e08-rust-foundation/">The Rust Foundation with Rebecca Rumbul, Lori Lorusso, and David Wood, Rust Foundation leadership and board</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=bAINppA0BSU">Jon Gjengset: Open Source Maintenance 2026-07-18</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=lUoQ3uGSQA0">Rust Release Changelog - 1.97.0</a></li>
<li>[video] <a href="https://www.youtube.com/live/Doqwh1b4QyA">Livestream: Rust in Ubuntu</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://kriyanative.com/blog/13-chain-breaks/">I hash-chained my agent's audit log. Then I found 13 breaks in it — all mine, all benign.</a></li>
<li><a href="https://dev.to/scripthpp/two-bugs-i-only-found-by-running-my-rust-sync-daemon-against-real-infrastructure-4278">Two tricky bugs in a Rust daemon</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=u91eX3J6lPU">Backend Concepts in Rust: Securely Managing App Secrets</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=tIrSvJFRxAg">Build with Naz - Ep 21: High Performance Flat 2D Arrays in Rust (SIMD, L1 cache)</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/medialab/xan">xan</a>, a TUI toolkit to work with CSV files.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1630">Simeon H.K. Fitch</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>



<ul>
<li><em>No Calls for participation were submitted this week.</em></li>
</ul>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>


<ul>
<li><em>No Calls for papers or presentations were submitted this week.</em></li>
</ul>
<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>576 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-07-14..2026-07-21">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159256">account for async closures when pointing at lifetime in return type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157824">comptime inherent impls</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159115"><code>dep_graph</code>: deduplicate task reads with an epoch-filtered index recorder</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158976">eagerly check for ambiguity in macro parsing</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158608">implement <code>#[diagnostic::opaque]</code> attribute to hide backtraces of macros</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158720">shrink <code>ast::Expr64</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159467">add explicit <code>Iterator::count</code> impl for <code>str::EncodeUtf16</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159296">implement <code>bool::toggle</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159528">implement <code>const_binary_search</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159302">implement <code>Debug</code> helpers via <code>Cell</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156220">implement <code>VecDeque::truncate_to_range</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158061">make <code>pin!()</code> more foolproof</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158546">move <code>std::io::BufRead</code> to <code>alloc::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158544">move <code>std::io::Read</code> to <code>alloc::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158545">move <code>std::io::read_to_string</code> to <code>alloc::io</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159149">use PGO for Cargo</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17238"><code>timings</code>: only report units the job queue actually ran</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17236">do not include proc-macro deps in rustc search path args</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17216">include SBOM outputs in fingerprints</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17226">lazily initialize git2 fetch transports</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159194">fix auto trait normalization env</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159091">use PGO for rustdoc</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16855">add <code>block_scrutinee</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17415">avoid invalid <code>ref_as_ptr</code> suggestions in const/static initializers</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16800">detect <code>== 0</code> on unsigned types as a <code>manual_clamp</code> lower bound</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17405">fix <code>if_not_else</code> linting on macro expanded conditions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17383">fix <code>needless_collect</code> suggests a suggestion that cannot be typed</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17385"><code>non_zero_suggestions</code>: don't lint signed integer div/rem as NonZero</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17377"><code>manual_filter</code>: don't eat comments in the <code>and_then</code> suggestion</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17369">require the use of <code>as _</code> for indirectly used traits in clippy sources</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17362">rewrite <code>min_ident_chars</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16633">use <code>#[must_use]</code> determination from the compiler</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22634">avoid index panic when flycheck list is empty</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22811">add capture hints to coroutines</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22813">add handler for E0572</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22483">do not assume array destructuring assignments with rest pattern are constant-sized</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22852">eagerly normalize <code>.await</code>'s <code>IntoFuture::Output</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22791">enable auto trait inference</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22792">extract variable preserving whitespace from macro input</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22832">fix coroutines not recording binding owners correctly</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22759">fix crashes in assists due to <code>.unwrap()</code> calls in SyntaxFactory</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22810">fix <code>hir</code> crate leaking bound variables from skipped binders</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22855">fix <code>InferenceContext:identity_args</code> using the wrong DefId</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22849">fix syntax bridge panic when spilting float</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22857">handle <code>enum</code> variants in next-solver <code>generics</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22818">implement lowering of HRTB</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22789">invalid <code>pattern_matching_variant</code> lowering due to recovery</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22867">merge <code>WherePredicate::ForLifetimes</code> into <code>WherePredicate::TypeBound</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22804">only write anon const ty in parent's inference result if it doesn't have its own inference</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22822">panic with a function item and a proc macro item having a duplicate name</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22827">parser to error on macro type bound</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22865">spawn proc-macro servers on requests clearing the client cache</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22782">use quote! inside <code>ast::make::expr_call()</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22793">use <code>Result</code> for the lsp-server <code>Response</code> payload type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22861">record expressions in types in <code>ExprScope</code></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>The two most notable changes this week were <a href="https://github.com/rust-lang/rust/pull/159115">#159115</a>,
which resulted in pretty nice instruction count wins for full incremental builds on several benchmarks,
and <a href="https://github.com/rust-lang/rust/pull/159091">#159091</a>, which enabled PGO for rustdoc, which
makes it ~3-4% faster across the board.</p>
<p>There were two large rollups with tiny performance regressions, which made it difficult to find
the offending PRs.</p>
<p>Triage done by <strong>@Kobzol</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=5503df87342a73d0c29126a7e08dc9c1255c46ad&amp;end=d527bc9bfa297ca7fd7f5ae93781eeec42073170&amp;absolute=false&amp;stat=instructions%3Au">5503df87..d527bc9b</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.4%</td>
<td>[0.2%, 1.0%]</td>
<td>40</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.7%</td>
<td>[0.2%, 4.6%]</td>
<td>69</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-2.0%</td>
<td>[-6.2%, -0.2%]</td>
<td>136</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-2.6%</td>
<td>[-8.4%, -0.2%]</td>
<td>119</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-1.4%</td>
<td>[-6.2%, 1.0%]</td>
<td>176</td>
</tr>
</tbody>
</table>
<p>2 Regressions, 3 Improvements, 6 Mixed; 4 of them in rollups
34 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/189822607d8d09acd85c234b2c245e817591ca67/triage/2026/2026-07-21.md">Full report here</a>.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/issues/159298">Tracking Issue for <code>bool::toggle</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/146954">Tracking Issue for vec_try_remove</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157562">Avoid computing layout of enums with non-int discriminants</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/71835">Tracking Issue for const_btree_len</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/138230">Add <code>raw_borrows_via_references</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157572">stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158835">rustc_passes: lint unused <code>#[path]</code> attributes on inline modules</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1019">Emit <code>note</code> when calling <code>rustc</code> without specifying an edition</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1011">Let the OS handle stack growth</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/pull/314">Deallocate post-2026 funds from PM and compiler-ops</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/558">Do the bytes of a pointer have to stay in the same order?</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
  <a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
  <a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
  <a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
  <a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3984">RFC: Refactor the libs team</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-22 - 2026-08-19 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-24 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-31 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-08-07 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-11 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254776/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/313345333/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/315619609/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-08-14 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315604176/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa</a></h5>
<ul>
<li>2026-08-11 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup">Johannesburg Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315750593/"><strong>Rust's extended standard library</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-25 | Mumbai, IN | <a href="https://luma.com/mumbai">Rust Mumbai</a><ul>
<li><a href="https://luma.com/7ksabwbm/"><strong>​Rust Mumbai — July Meetup 🦀</strong></a></li>
</ul>
</li>
<li>2026-07-26 | Pune, IN | <a href="https://www.meetup.com/rust-pune">Rust Pune</a><ul>
<li><a href="https://www.meetup.com/rust-pune/events/315651505/"><strong>Rust Pune: July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/rust-london-user-group">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/315612916/"><strong>LDN Talks: July 2026 Antithesis Takeover</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Stockholm, SE | <a href="https://www.meetup.com/stockholm-rust">Stockholm Rust</a><ul>
<li><a href="https://www.meetup.com/stockholm-rust/events/315749994/"><strong>Ferris' Fika Forum #28</strong></a></li>
</ul>
</li>
<li>2026-07-27 | Augsburg, DE | <a href="https://rust-augsburg.github.io/meetup">Rust Meetup Augsburg</a><ul>
<li><a href="https://rust-augsburg.github.io/meetup/Meetup_20.html"><strong>Rust Meetup #20: Julian Dickert - Supply chain security in Rust: Evaluating crates for production</strong></a></li>
</ul>
</li>
<li>2026-07-29 | Poland, PL | <a href="https://www.meetup.com/rust-poland-meetup">Rust Poland</a><ul>
<li><a href="https://www.meetup.com/rust-poland-meetup/events/315582674/"><strong>Rust Poland x Kraków #10</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/315767999/"><strong>Rust meetup #70</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/315683629/"><strong>Hack Night: Trust but verify the LLM</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816474/"><strong>Topic TBD</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-22 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc/events/">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315636854/"><strong>Rust NYC: Write A Custom Coding Agent and wasm_zero</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/315418155/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
</li>
<li>2026-08-06 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314701905/"><strong>Shipping Temporal: How a Global Rust Ecosystem Built Chrome’s Newest Web API</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696652/"><strong>Utah Rust August Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-13 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/315601099/"><strong>San Diego Rust August Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-08-15 | San Francisco, CA, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/juWAwRs3XMWP7s9wLNWK"><strong>BOG-A-THON 3</strong></a></li>
</ul>
</li>
<li>2026-08-18 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997215/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-08-08 | São Paulo, SP | <a href="https://luma.com/calendar/cal-bif2oHITU1aVvsr">Rust-SP</a><ul>
<li><a href="https://luma.com/41oiyhtk"><strong>Rust SP - Aug/2026</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>We were planning on publishing a blog post announcing this at the same time as making the repo public, but ran out of private repo CI usage 😭.</p>
</blockquote>
<p>– <a href="https://www.reddit.com/r/rust/comments/1uzknzl/tokiorstopcoat_a_batteriesincluded_framework_for/oy8k2nn/">Carl Lerche on r/rust</a> about the launch of topcoat</p>
<p>Despite a lamentable lack of suggestions, llogiq is glad to have found this quote.</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1v41dgv/this_week_in_rust_661/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[G# language for .NET borrows from Go, Kotlin, and Swift]]></title>
<description><![CDATA[G# (GSharp) is moving forward as a programming language for Microsoft’s .NET platform, touted as bringing Go-, Kotlin-, and Swift-style ergonomics to the CLR (Common Language Runtime). The language is described by its creators as modern, simple, and accessible.



Although pre-1.0 and still growi...]]></description>
<link>https://tsecurity.de/de/3687865/ai-nachrichten/g-language-for-net-borrows-from-go-kotlin-and-swift/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687865/ai-nachrichten/g-language-for-net-borrows-from-go-kotlin-and-swift/</guid>
<pubDate>Thu, 23 Jul 2026 04:08:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://github.com/DavidObando/gsharp" data-type="link" data-id="https://github.com/DavidObando/gsharp">G# (GSharp)</a><strong> </strong>is moving forward as a programming language for Microsoft’s <a href="https://www.infoworld.com/article/2264488/what-is-the-net-framework-microsofts-answer-to-java.html">.NET</a> platform, touted as bringing <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go</a>-, <a href="https://www.infoworld.com/article/2256390/what-is-kotlin-the-java-alternative-explained.html">Kotlin</a>-, and <a href="https://www.infoworld.com/article/4150248/swift-6-3-boosts-c-interoperability-android-sdk.html">Swift</a>-style ergonomics to the CLR (Common Language Runtime). The language is described by its creators as modern, simple, and accessible.</p>



<p class="wp-block-paragraph">Although pre-1.0 and still growing, G# aims to be for people who want a small, predictable language with direct access to the .NET ecosystem. Developers will see imports, <code>func</code>, structs, slices, maps, channels, <code>go</code>, <code>select</code>, and <code>for in</code> iteration. Also important are nullable flow, direct calls into the CLR (Common Language Runtime), and built-in concurrency. </p>



<p class="wp-block-paragraph">With G#, copyrighted in 2026, developers get value-oriented structs, reference-oriented classes, data structs, and data classes. For concurrency, G# uses <code>scope</code> for structured concurrency, <code>async func</code><strong> </strong>and <code>await</code><strong> </strong>for task-based asynchrony, and <code>async sequence[T]</code> for asynchronous streams. G# also makes use of the same <code>Task</code> and <code>Task[T]</code> types familiar from the .NET BCL (Base Class Library).</p>



<p class="wp-block-paragraph">G# documentation is <a href="https://davidobando.github.io/gsharp/" data-type="link" data-id="https://davidobando.github.io/gsharp/">available on the GitHub site</a> of Microsoft software engineer David Obando. “Every .NET type—your packages, third-party NuGet packages, the BCL—is callable from G# with the syntax you already know. CLR generics use G#’s bracket spelling, and method calls, properties, indexers, and <code>for in</code><strong> </strong>over <code>IEnumerable[T]</code> all just work,” according to the website.</p>



<p class="wp-block-paragraph">A Visual Studio Code extension for G3 can be found at <a href="https://marketplace.visualstudio.com/items?itemName=gsharplang.vscode-gsharp">marketplace.visualstudio.com</a>. The extension adds syntax highlighting, language server features, build/run commands, and debugger configuration for <code>.gs</code> and <code>.gsproj</code> files. Developers can install the extension from within VS Code (search for “G#” in the Extensions view) or from the command line.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.2-beta.4]]></title>
<description><![CDATA[OpenClaw 2026.7.2-beta.4]]></description>
<link>https://tsecurity.de/de/3687813/downloads/v202672-beta4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687813/downloads/v202672-beta4/</guid>
<pubDate>Thu, 23 Jul 2026 02:21:39 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.2-beta.4</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-07-22]]></title>
<description><![CDATA[169 posts were published in the last hour 20:34 : OpenClaw security best practices for CISOs 20:34 : GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier 20:4 : Third-Party SDKs Raise Privacy Questions for Apps Marketed…
Read more →
The post IT Security News Daily Summary 2026-07-...]]></description>
<link>https://tsecurity.de/de/3687676/it-security-nachrichten/it-security-news-daily-summary-2026-07-22/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687676/it-security-nachrichten/it-security-news-daily-summary-2026-07-22/</guid>
<pubDate>Wed, 22 Jul 2026 23:58:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>169 posts were published in the last hour 20:34 : OpenClaw security best practices for CISOs 20:34 : GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier 20:4 : Third-Party SDKs Raise Privacy Questions for Apps Marketed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-07-22/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-07-22/">IT Security News Daily Summary 2026-07-22</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw security best practices for CISOs]]></title>
<description><![CDATA[OpenClaw has become one of the fastest adopted open source tools in recent memory. Originally released in late 2025 under the name Clawdbot, this autonomous AI agent now boasts hundreds of thousands of GitHub stars and a rapidly expanding ecosystem…
Read more →
The post OpenClaw security best pra...]]></description>
<link>https://tsecurity.de/de/3687590/it-security-nachrichten/openclaw-security-best-practices-for-cisos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687590/it-security-nachrichten/openclaw-security-best-practices-for-cisos/</guid>
<pubDate>Wed, 22 Jul 2026 23:04:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;OpenClaw has become one of the fastest adopted open source tools in recent memory. Originally released in late 2025 under the name Clawdbot, this autonomous AI agent now boasts hundreds of thousands of GitHub stars and a rapidly expanding ecosystem…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openclaw-security-best-practices-for-cisos/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openclaw-security-best-practices-for-cisos/">OpenClaw security best practices for CISOs</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inflection AI returns to consumer market with Pi Journeys after Microsoft upheaval]]></title>
<description><![CDATA[Inflection AI, the Palo Alto startup that two years ago became Silicon Valley's most famous cautionary tale about the brutal economics of frontier AI, announced Tuesday that it is returning to the consumer market with a new research division and an experimental product built around a provocative ...]]></description>
<link>https://tsecurity.de/de/3687581/it-nachrichten/inflection-ai-returns-to-consumer-market-with-pi-journeys-after-microsoft-upheaval/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687581/it-nachrichten/inflection-ai-returns-to-consumer-market-with-pi-journeys-after-microsoft-upheaval/</guid>
<pubDate>Wed, 22 Jul 2026 22:58:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://inflection.ai/">Inflection AI</a>, the Palo Alto startup that two years ago became Silicon Valley's most famous cautionary tale about the brutal economics of frontier AI, announced Tuesday that it is returning to the consumer market with a new research division and an experimental product built around a provocative thesis: the next competitive battleground in AI won't be raw intelligence, but relationships.</p><p>The company launched <a href="https://inflection.ai/labs">Inflection AI Labs</a>, a public-facing research and experimentation arm, alongside <a href="https://inflection.ai/labs/pi-journeys">Pi Journeys</a>, the lab's first product experiment — an AI experience designed to adapt to a user's life stage, whether that's becoming a parent, taking on caregiving duties, changing careers, or aging. The announcement arrived with a research report on consumer AI habits and a substantial update to Pi, the company's flagship chatbot, adding improved voice, memory, and new agentic tools for reminders, to-do lists, and shopping.</p><p>"Inflection AI is the company. Pi is our flagship consumer product. Inflection AI Labs is where we experiment, explore personal intelligence and share more publicly. Pi Journeys is the first public experiment from Inflection AI Labs," CEO Sean White told VentureBeat in an exclusive interview.</p><p>Behind the tidy org chart is a far more interesting story: a company attempting one of the more unusual second acts in the AI industry, powered by an argument that the entire market is optimizing for the wrong thing.</p><h2><b>Why Inflection AI believes the chatbot era's biggest flaw is that it's transactional</b></h2><p>White's central claim is that today's AI assistants — including the industry's most capable models — are fundamentally transactional. You ask, they answer, the session ends. He believes that architecture misses most of what people actually need from artificial intelligence in their daily lives.</p><p>"One of the things that really struck us in particular, and this showed up in the research, was that a lot of the work is very transactional, and you'll hear me say a lot that we've been shifting all this from transactional to relational systems," White said. "Not everything is going to be: I do a single turn, I utter a question, I get a search response back."</p><p>White frames the industry's evolution as a progression through four kinds of intelligence. First came raw IQ — the foundation model race. Then emotional intelligence, which Inflection made its signature with Pi's famously warm conversational style. Then agentic intelligence — AI that acts rather than just talks — which White says Inflection absorbed from its enterprise work. The fourth, and the one Inflection is now staking its future on, is what the company calls relational intelligence: AI that understands not just you, but the web of people around you.</p><p>"There's so much fear about these things pushing people into loneliness,” White said. “If we design these pro-social systems as another design criteria, that actually makes a huge difference."</p><p>That design philosophy is a pointed counter-narrative to one of the loudest anxieties in consumer AI right now: that <a href="https://www.media.mit.edu/articles/chatgpt-may-be-making-us-lonelier/">emotionally engaging chatbots deepen isolation</a> by substituting for human contact. Inflection argues the opposite is possible — that an AI with structured knowledge of your relationships can push you back toward people rather than away from them.</p><h2><b>Inside Pi Journeys, the AI companion that maps your relationships and life stages</b></h2><p><a href="https://inflection.ai/labs/pi-journeys">Pi Journeys</a> makes that idea concrete. When users first open the product, it asks about their life stage — caregiver, household manager, midlife transition — and then builds what White describes as specially structured memory around the people who matter in that context. From there, the system becomes proactive.</p><p>"It starts to build up memories around that, and it acts as a memory prosthetic — but in a pro-social way," White said. "It doesn't get in the way of your interactions with other people; it really helps facilitate them." The system might remind a user, for example, that a friend deserves a call, or resurface what was last discussed with a family member involved in a parent's care.</p><p>White, who spent years as chief R&amp;D officer at Mozilla before taking Inflection's helm, was quick to flag the obvious privacy implications of an AI that maps your social graph. "We've built a lot of privacy systems into this," he said, noting users can delete and manage the people recorded in their profile. Whether consumers will trust a venture-backed AI company with a structured database of their most important relationships remains one of the biggest open questions hanging over the product — and one that enterprise buyers evaluating Inflection's technology will watch closely.</p><p>Asked why this was the first Labs experiment, White was direct: "Pi Journeys takes into account people's life stages and experiences because we have heard from users that we can provide more value in helping them navigate their lives. Pi Journeys lets us experiment with the early stages of prosocial and relational intelligence because life isn't single-player."</p><p>The product has been tested internally and with small closed groups, White said, and is now being released more broadly as an experiment rather than a finished product — a posture the Labs branding is designed to make explicit.</p><h2><b>What Inflection's consumer AI research reveals about how people actually use chatbots</b></h2><p>Inflection Labs' first publication, the <a href="https://inflection.ai/state-of-consumer-ai-2026">State of Consumer AI Research Report</a>, offers the empirical scaffolding for the strategy. The average consumer now uses roughly two different AI tools every day and three per week, the company found — evidence, in Inflection's reading, that no single assistant has locked up consumer loyalty and that the market remains contestable.</p><p>More telling is why people choose the tools they do. Respondents cited personalization, style and tone, context awareness, and — notably — emotional understanding as deciding factors. They also said they want AI to be more than a productivity engine: a coach or mentor to motivate them, a chef to suggest recipes, a DJ to curate playlists.</p><p>"One thing we're certainly finding is that a lot of that also is in work, not so much in everyday life," White said. "That's our focus right now — the everyday life part."</p><p>This is a shrewd reading of the competitive map. The best-funded AI labs are pouring resources into coding tools, enterprise agents, and developer platforms, leaving everyday consumer use cases comparatively underserved. White sees the gap clearly. "We see a lot of products that are being aimed more and more at the enterprise," he said. "As a computer scientist by training, I kind of love the IDEs as this tool, but it's not really great for everybody. There's so much regular everyday use from folks that is either purely voice or that is purely mobile."</p><p>He recalled a conversation with a conference staffer who told him she owned only a phone, no laptop — exactly the kind of user, he argued, that the industry's developer-centric product roadmaps have left behind.</p><h2><b>How the $650 million Microsoft deal hollowed out Inflection — and set up its second act</b></h2><p>To understand why any of this is remarkable, you have to rewind to March 2024. Inflection was then one of the hottest startups in AI, having <a href="https://www.reuters.com/technology/inflection-ai-raises-13-bln-funding-microsoft-others-2023-06-29/">raised $1.3 billion in mid-2023</a> in a round backed by Microsoft, Nvidia, Bill Gates, and Reid Hoffman — more than $1.5 billion in total. Pi had crossed one million daily active users, per Reuters.</p><p>Then, in a deal that reshaped how the industry thinks about acqui-hires, Microsoft hired away co-founder and CEO Mustafa Suleyman, chief scientist Karén Simonyan, and most of the company's roughly 70 employees, paying Inflection about $650 million largely to license its technology, as <a href="https://www.bloomberg.com/news/articles/2024-03-21/microsoft-to-pay-inflection-ai-650-million-after-scooping-up-most-of-staff">Reuters reported</a>. Suleyman now runs Microsoft's consumer AI business. The structure of the deal drew scrutiny from the FTC and Britain's competition regulator, though the UK's Competition and Markets Authority cleared it in September 2024 and EU regulators declined to act.</p><p>White, installed as CEO in the aftermath, steered the remnant company hard toward enterprise, acquiring three startups in late 2024 — <a href="http://jelled.ai/">Jelled.AI</a>, <a href="https://boostkpi.com/">BoostKPI</a>, and the European consulting firm <a href="https://www.boundaryless.com/">Boundaryless</a> — and <a href="https://techcrunch.com/2024/11/26/inflection-ceo-says-its-done-competing-to-make-next-generation-ai-models/">telling TechCrunch</a> that November that Inflection had no intention of competing with companies building 100,000-GPU frontier systems.</p><p>Tuesday's announcement doesn't reverse that position so much as complicate it. Asked how to think about the company today, White called it "a consumer-first strategy that bridges both consumer and enterprise efforts" — and he insists the two sides feed each other.</p><p>Enterprise deployments, including a partnership with Intel that is among the few he can name publicly, taught Inflection how to run models inside complex infrastructure. Consumer products, meanwhile, let the company iterate at speed. "The part I also like about the consumer side, and this has always been true, is that we can move faster, experiment faster, and try and learn faster," White said.</p><h2><b>The six-month prediction: relationship-aware AI is coming to the enterprise</b></h2><p>Buried in White's consumer pitch is the claim that should matter most to technical decision-makers. "Normally I'd say like a year, but let's call it six months," he said. "You're going to start to see a bunch of enterprises care a lot more about the relationships that are inside the enterprises and what that picture is, not just the workflows."</p><p>If White is right, the wave of workflow-automation agents currently flooding the enterprise market is only the first phase of business AI adoption — with relationship-aware systems, tested first on consumers, following close behind. Inflection is essentially using its consumer products as a live laboratory for capabilities it plans to sell into companies. It's a capital-efficient strategy for a firm that can no longer outspend rivals on training runs, and a risky one, since it depends on consumers showing up in numbers large enough to generate the learning.</p><p>The technical substance underneath is equally pragmatic. Pi today runs not on a single proprietary frontier model but on an orchestration layer routing across many models — some descended from Inflection's original fully trained cores, some fine-tuned, some open source, including work with Nvidia that White says gives Inflection access to unreleased cutting-edge models. He also took a swipe at the industry's loose vocabulary around ownership: "When people say that the model is their own, most of the time nowadays — I guess I won't name names — a lot of companies will actually take a checkpoint, and then they will fine-tune from that checkpoint. But very few people actually start from that beginning core."</p><p>That candor extends to open source, where White carefully hedged. "We're not ready to promise what I think of as true open source, and by that I mean everything," he said, invoking his Mozilla years overseeing genuinely open projects like <a href="https://rust-lang.org/">Rust</a> and <a href="https://webassembly.org/">WebAssembly</a>.</p><p>Weights without training data and pipelines, he argued, often leave developers unable to do anything meaningful with a supposedly "open" model. "We are a PBC, and there's still a C in there," he added — a reminder that public benefit corporations still have businesses to protect. The Labs will collaborate with academic researchers, including Stanford professors who visited the company's Palo Alto office this week, and continue contributing to open projects such as <a href="https://pytorch.org/">PyTorch</a>.</p><h2><b>Can a diminished Inflection compete with AI giants spending billions?</b></h2><p>Reid Hoffman, the LinkedIn co-founder who co-founded Inflection and stayed on through the Microsoft upheaval, framed the announcement in the sweeping terms of his recent writing on AI and human agency. "Humans should be amplified by AI, not replaced. That's the principle Pi was built on," <a href="https://finance.yahoo.com/technology/ai/articles/inflection-ai-shaping-future-personal-130000573.html">Hoffman said</a> in the announcement. "When that kind of agency is available to everyone, you get superagency."</p><p>The skeptic's case is easy to make. Inflection is a fraction of its former size, competing for consumer attention against products from companies spending tens of billions of dollars a year. Pi's model was state of the art in 2023; it is not in 2026. And "<a href="https://www.linkedin.com/posts/inflectionai_inflection-ai-is-shaping-the-future-of-personal-activity-7485407087926312960-fqCl/">relational intelligence</a>" is, for now, a brand claim awaiting proof.</p><p>But the bull case is not crazy either. Inflection's own research shows consumers already juggle multiple AI tools and choose them for qualities — tone, emotional understanding, personalization — that frontier labs treat as afterthoughts. The company kept its technology, its Microsoft licensing windfall, and a defensible enterprise niche in on-premise, emotionally intelligent deployments. And it is targeting the one consumer segment — everyday, mobile-first, voice-first life management — that the coding-obsessed giants have largely ignored.</p><p>Asked what success looks like twelve months from now, White declined to talk numbers. "It's less about scale for scale's sake and more about scaling for impact by empowering people and improving their lives," he said. "Over the next year, success means leading the market towards relational intelligence and transforming AI interactions from transactional to relational."</p><p>Two years ago, Microsoft walked away with Inflection's founders, its staff, and its shot at the frontier — but it left behind the one idea the giants still haven't figured out how to build: an AI that knows the people in your life matter more than the tasks on your list. Inflection is betting the company, again, that the idea was the valuable part all along.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw security best practices for CISOs]]></title>
<description><![CDATA[OpenClaw introduces huge risks to enterprises, but employee adoption might be inevitable -- whether CISOs sanction it or not. Here's how to enable safer deployments.]]></description>
<link>https://tsecurity.de/de/3687556/it-security-nachrichten/openclaw-security-best-practices-for-cisos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687556/it-security-nachrichten/openclaw-security-best-practices-for-cisos/</guid>
<pubDate>Wed, 22 Jul 2026 22:40:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenClaw introduces huge risks to enterprises, but employee adoption might be inevitable -- whether CISOs sanction it or not. Here's how to enable safer deployments.]]></content:encoded>
</item>
<item>
<title><![CDATA[What the 2026 Exposure Gap Report Reveals About Remediation]]></title>
<description><![CDATA[Some security teams are reducing critical exposure within hours, while others are leaving similar issues open for days. The 2026 Exposure Gap Report shows that many organizations can identify, validate, and prioritize exposure, but the real challenge begins when teams need to turn those insights ...]]></description>
<link>https://tsecurity.de/de/3687044/it-security-nachrichten/what-the-2026-exposure-gap-report-reveals-about-remediation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687044/it-security-nachrichten/what-the-2026-exposure-gap-report-reveals-about-remediation/</guid>
<pubDate>Wed, 22 Jul 2026 18:39:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="2000" height="700" src="https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c.jpg" class="webfeedsFeaturedVisual default-featured-img" alt="" link_thumbnail="" decoding="async" srcset="https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c.jpg 2000w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-300x105.jpg 300w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-1024x358.jpg 1024w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-768x269.jpg 768w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-1536x538.jpg 1536w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-400x140.jpg 400w, https://blog.checkpoint.com/wp-content/uploads/2023/12/featured-image-default-c-1320x462.jpg 1320w" sizes="(max-width: 2000px) 100vw, 2000px"><p>Some security teams are reducing critical exposure within hours, while others are leaving similar issues open for days. The 2026 Exposure Gap Report shows that many organizations can identify, validate, and prioritize exposure, but the real challenge begins when teams need to turn those insights into remediation.  Across environments, organizations are often working with similar types of exposure, yet their outcomes vary significantly. The difference depends on how quickly validated findings move into remediation and how consistently teams can repeat that process at scale.  Remediation Speed Varies Significantly  According to the report, Utilities organizations resolve exposure in about 12.6 hours […]</p>
<p>The post <a href="https://blog.checkpoint.com/exposure-management/what-the-2026-exposure-gap-report-reveals-about-remediation/">What the 2026 Exposure Gap Report Reveals About Remediation</a> appeared first on <a href="https://blog.checkpoint.com/">Check Point Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The engineering bottleneck has changed. Is your org prepared?]]></title>
<description><![CDATA[AI agents can turn a clear description into working software, the engineer’s judgement is what makes the difference: deciding what to build, catching the tradeoff the agent didn’t know to weigh, and owning the call on whether the result is right.



That judgement has always been the hard part of...]]></description>
<link>https://tsecurity.de/de/3687009/it-security-nachrichten/the-engineering-bottleneck-has-changed-is-your-org-prepared/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687009/it-security-nachrichten/the-engineering-bottleneck-has-changed-is-your-org-prepared/</guid>
<pubDate>Wed, 22 Jul 2026 18:28:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI agents can turn a clear description into working software, the engineer’s judgement is what makes the difference: deciding what to build, catching the tradeoff the agent didn’t know to weigh, and owning the call on whether the result is right.</p>



<p class="wp-block-paragraph">That judgement has always been the hard part of engineering. It just used to be bundled into the act of writing code, where a skilled engineer did it while typing. As agents take on more of the typing, that judgement separates out and becomes the clear center of the role. Leaders who adapt early will get their metrics, their talent pipelines, and their delivery models working with this shift rather than against it.</p>



<h3 class="wp-block-heading">Judgement is defining, constraining, and deciding</h3>



<p class="wp-block-paragraph">Judgement is all about defining the problem precisely enough that an agent builds the right thing. It’s setting the constraints the agent won’t infer on its own. It’s spotting the tradeoff buried three layers down that only shows up if you understand the system. And it’s looking at a finished implementation and knowing whether it’s genuinely good enough to ship.</p>



<p class="wp-block-paragraph">This is the harder part of the job and the real driver of quality. It was easy to underrate when it lived inside day-to-day coding. Now it’s what separates a strong team from an average one.</p>



<h3 class="wp-block-heading">The shift changes where time, growth, and metrics go</h3>



<p class="wp-block-paragraph">If the high-value activity is intent, review, and judgement rather than raw output, a few assumptions are worth revisiting.</p>



<p class="wp-block-paragraph"><strong>Where engineers spend their time.</strong> Less of the day goes to producing boilerplate and mechanical implementation, and more goes to the reasoning that used to get squeezed to the edges: framing the problem and owning the judgement calls that determine quality.</p>



<p class="wp-block-paragraph"><strong>How teams grow their people.</strong> Defining problems well, spotting risk, and critically evaluating work you didn’t write yourself have always been senior skills. When agents handle more of the mechanical work, those skills become learnable earlier. That puts the emphasis on leaders to teach the reasoning: why a choice gets made and how to weigh the tradeoffs that come with it.</p>



<p class="wp-block-paragraph"><strong>What you measure.</strong> Lines shipped, tickets closed, and velocity charts all measured throughput of the old scarce resource. They say very little about the new one. The teams that adapt will start measuring the quality of intent going in and the reliability of judgement coming out, because that’s where the results now live.</p>



<h3 class="wp-block-heading">Reinvest the time you get back</h3>



<p class="wp-block-paragraph">The tempting response is to treat the freed-up capacity as pure speed: same work, same tooling, just faster. That captures the easy win and misses the real one. If engineers spend their reclaimed time reviewing a rising volume of agent output with no better context than before, review quietly becomes the new constraint, and you’ve moved the problem rather than solved it.</p>



<p class="wp-block-paragraph">The organizations that get ahead will invest the reclaimed capacity into the judgement layer: creating stronger specs and acceptance criteria before work starts, building review practices that test agent output against intent, and capturing the reasoning behind decisions where the next person can find it, so it doesn’t have to be reconstructed every time. That’s how the shift becomes an advantage for your team.</p>



<h3 class="wp-block-heading">The through-line for leaders</h3>



<p class="wp-block-paragraph">The engineering job is moving up a level, from executing the work to directing and validating it. That’s a more strategic role, and it rewards clarity of thought over speed of output. Leaders who see the shift early can help their engineers grow into the work that’s now most valuable.</p>



<p class="wp-block-paragraph">See how leading engineering organizations are operationalizing this shift at <a href="https://www.atlassian.com/software/jira/dev?utm_source=foundry&amp;utm_medium=paid-social&amp;utm_campaign=P:jira%7CO:ppm%7CV:foundry%7CG:us%7CL:en%7CF:aware%7CT:prospecting%7CI:imc-jira-ai-sdlc%7CA:display%7CD:alld&amp;utm_content=P:jira%7CO:ppm%7CV:foundry%7CG:us%7CL:en%7CF:aware%7CT:prospecting%7CI:imc-jira-ai-sdlc%7CA:display%7CD:alld%7CU:cio-2" target="_blank" rel="noreferrer noopener">jira.dev.</a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab previews auto-remediation of vulnerable dependencies]]></title>
<description><![CDATA[GitLab has released GitLab 19.2, an update to the company’s devsecops platform that allows teams to fix vulnerable dependencies automatically, use Security Review Flow to catch logic flaws that scanners miss, and run AI agents straight from the terminal, the company said. 



Highlights in GitLab...]]></description>
<link>https://tsecurity.de/de/3686997/ai-nachrichten/gitlab-previews-auto-remediation-of-vulnerable-dependencies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686997/ai-nachrichten/gitlab-previews-auto-remediation-of-vulnerable-dependencies/</guid>
<pubDate>Wed, 22 Jul 2026 18:23:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">GitLab has released <a href="https://about.gitlab.com/whats-new/" data-type="link" data-id="https://about.gitlab.com/whats-new/">GitLab 19.2</a>, an update to the company’s <a href="https://www.infoworld.com/article/2337499/what-is-devsecops-securing-devops-pipelines.html" data-type="link" data-id="https://www.infoworld.com/article/2337499/what-is-devsecops-securing-devops-pipelines.html">devsecops</a> platform that allows teams to fix vulnerable dependencies automatically, use Security Review Flow to catch logic flaws that scanners miss, and run AI agents straight from the terminal, the company said. </p>



<p class="wp-block-paragraph">Highlights in GitLab 19.2 include the following:</p>



<ul class="wp-block-list">
<li>Dependency Scanning Auto-Remediation, in public beta, uses AI to fix build-breaking changes and iterates until your pipeline passes, with every change governed by your existing gates and audit trail. </li>



<li>Security Review Flow, also in public beta, analyzes code changes as a security engineer would and catches authorization gaps, business-logic errors, and race conditions that static scanners structurally cannot see.</li>



<li>GitLab Duo CLI, now generally available, gives developers access to agents and multi-step agentic flows for all software life cycle tasks without leaving the terminal. </li>



<li>Custom Flows, now generally available, let teams replace manual multi-step workflows with agentic automations for software development, triggered by GitLab events.</li>
</ul>



<p class="wp-block-paragraph">“Coding agents made it possible to generate far more code and moved the bottleneck downstream to reviews and security,” said Manav Khurana, chief product and marketing officer at GitLab, in a statement. “GitLab 19.2 puts agents to work on that bottleneck: fixing vulnerable dependencies, catching the flaws scanners miss, and automating the steps in between with a person still approving what ships.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Overengineering Your Agent Harness]]></title>
<description><![CDATA[The following originally appeared on Hugo Bowne-Anderson’s Vanishing Gradients Substack and is being republished here with the author’s permission. The conversation around harness engineering is dominated by problems from coding and personal agents such as OpenClaw, but most agents are simpler. B...]]></description>
<link>https://tsecurity.de/de/3686996/ai-nachrichten/stop-overengineering-your-agent-harness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686996/ai-nachrichten/stop-overengineering-your-agent-harness/</guid>
<pubDate>Wed, 22 Jul 2026 18:22:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The following originally appeared on Hugo Bowne-Anderson’s Vanishing Gradients Substack and is being republished here with the author’s permission. The conversation around harness engineering is dominated by problems from coding and personal agents such as OpenClaw, but most agents are simpler. Builders should avoid over-engineering for capabilities that newer models may absorb anyway, the “Kirby […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Talk to This Glowing Pyramid on Your Desk, and It&#x27;ll Run Your AI Agent for You]]></title>
<description><![CDATA[It's a pyramid-shaped Orange Pi 4 Pro that ships with OpenClaw or Hermes preloaded and now talks back so you get that "Iron Man" feel.]]></description>
<link>https://tsecurity.de/de/3686289/unix-server/talk-to-this-glowing-pyramid-on-your-desk-and-itx27ll-run-your-ai-agent-for-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686289/unix-server/talk-to-this-glowing-pyramid-on-your-desk-and-itx27ll-run-your-ai-agent-for-you/</guid>
<pubDate>Wed, 22 Jul 2026 14:31:23 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's a pyramid-shaped Orange Pi 4 Pro that ships with OpenClaw or Hermes preloaded and now talks back so you get that "Iron Man" feel.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft doubles down on sovereign AI with expanded Mistral partnership]]></title>
<description><![CDATA[Microsoft and Mistral are betting that the future of enterprise AI is in sovereign infrastructure and model choice, rather than with one locked-in system. 



The companies have announced a “significant expansion” of their strategic partnership, which includes a multibillion dollar commitment fro...]]></description>
<link>https://tsecurity.de/de/3685096/it-nachrichten/microsoft-doubles-down-on-sovereign-ai-with-expanded-mistral-partnership/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685096/it-nachrichten/microsoft-doubles-down-on-sovereign-ai-with-expanded-mistral-partnership/</guid>
<pubDate>Wed, 22 Jul 2026 04:03:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft and Mistral are betting that the future of enterprise AI is in sovereign infrastructure and model choice, rather than with one locked-in system. </p>



<p class="wp-block-paragraph">The companies have announced a “<a href="https://news.microsoft.com/source/2026/07/21/microsoft-and-mistral-expand-strategic-partnership-to-give-enterprises-and-regulated-industries-frontier-ai-they-can-control/" target="_blank" rel="noreferrer noopener">significant expansion</a>” of their strategic partnership, which includes a multibillion dollar commitment from Microsoft. Mistral will add to its GPU infrastructure in Europe and extend access to its frontier multilingual models, while Microsoft will expand its sovereign cloud capabilities. The companies will also align on a joint go-to-market plan and will pursue enterprise opportunities together across Europe and globally, as well as funding proofs of concept (PoCs), offering Azure credits, and leading workshops to drive AI innovation with customers.</p>



<p class="wp-block-paragraph">The partnership between the tech giant and the <a href="https://www.infoworld.com/article/4187526/is-mistral-late-or-savvy.html" target="_blank">three-year-old French startup</a> might seem an odd combination at first glance, analysts note, as both develop enterprise AI models and offer access as-a-service. But it reflects changing AI market dynamics.</p>



<p class="wp-block-paragraph">“It’s possible to be both a competitor and a partner at the same time,” noted technology analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a>. Large cloud providers are becoming AI marketplaces in their own right, he pointed out, and are drifting away from exclusively promoting their own models. Building Mistral support into their infrastructure avoids platform lock-in and removes a “key objection for customers looking for options.”</p>



<p class="wp-block-paragraph">“As much as Microsoft would want everybody standardizing on Copilot and Phi, it recognizes the simple fact that customers increasingly want to choose their own models,” said Levy.</p>



<h2 class="wp-block-heading">Expands model access, sovereign cloud capabilities</h2>



<p class="wp-block-paragraph">As part of the agreement, Mistral will expand its Europe-based capacity with thousands of Nvidia Vera Rubin GPUs.</p>



<p class="wp-block-paragraph">Mistral CEO and co-founder <a href="https://www.computerworld.com/article/4134107/mistral-ceo-over-half-of-companies-software-can-be-replaced-by-ai.html" target="_blank">Arthur Mensch</a> described a “slight gap” in compute capacity in Europe, noting that this expansion will provide more compute capability and support Microsoft’s cloud and AI services, providing a “shared platform for training, inference and large-scale deployment.” The companies call it a critical step to allow Microsoft customers to benefit from Mistral’s “scientific and compute innovations.”</p>



<p class="wp-block-paragraph">In addition, Mistral Medium 3.5 and OCR 4 models are now available in Microsoft Foundry, and Mistral Medium 3.5 can be used in Microsoft Copilot Studio.</p>



<p class="wp-block-paragraph">The partnership also extends Microsoft’s sovereign cloud infrastructure as well as combining Mistral’s frontier models with Microsoft’s security, compliance, and cloud-to-edge platform. This gives enterprises, particularly those in regulated markets, the ability to deploy AI where they see fit, while maintaining control over their data and workloads, according to the companies.</p>



<p class="wp-block-paragraph">Further, customers will be able to build AI using the same models, tools, APIs, and workflows they’re used to, across Microsoft Foundry, Foundry Local, and <a href="https://www.infoworld.com/article/4108044/whats-next-for-azure-infrastructure.html" target="_blank">Azure Local</a>, and opt for fully Azure-hosted cloud environments; cloud-connected, controlled Azure Local environments that only use cloud-based Azure when necessary; and fully-disconnected environments that can operate independently for more sensitive scenarios.</p>



<p class="wp-block-paragraph">“Europe should have access to the world’s most capable AI without compromising control over their data, operations or digital future,” said <a href="https://www.linkedin.com/in/bradsmi" target="_blank" rel="noreferrer noopener">Brad Smith</a>, vice chair and president, Microsoft, noting that with this partnership, the company is honoring its <a href="https://blogs.microsoft.com/on-the-issues/2025/04/30/european-digital-commitments/" target="_blank" rel="noreferrer noopener">European digital commitments</a> and giving customers a foundation for AI so they can “operate on their own terms.” Customers with “heightened sovereignty needs” will be able to exercise more control with “resilience and assurance” and continued access to Mistral’s open-weight models.</p>



<h2 class="wp-block-heading">Enterprise credibility</h2>



<p class="wp-block-paragraph">Gartner distinguished VP analyst <a href="https://www.gartner.com/en/experts/arun-chandrasekaran" target="_blank" rel="noreferrer noopener">Arun Chandrasekaran</a> noted that there’s no doubt that this agreement strengthens Microsoft’s sovereignty messaging and its position in regulated industries, and the tech giant benefits by expanding its AI portfolio with a “credible European frontier model provider”</p>



<p class="wp-block-paragraph">He pointed to key differences from the initial partnership struck by the two companies in 2024; whereas originally Microsoft was hosting Mistral’s models, it is now consuming capacity built by Mistral in Europe.</p>



<p class="wp-block-paragraph">Ultimately, the deal emphasizes European data centers, customer-controlled deployments, Azure Local, and fully-disconnected environments, addressing many of the concerns that surrounded the original Azure cloud only relationship, Chandrasekaran explained.</p>



<p class="wp-block-paragraph">For Mistral, the partnership provides “enterprise credibility, and repeatable infrastructure revenue” that can fund continued <a href="https://www.cio.com/article/4198030/7-issues-impacting-ai-strategies-and-how-cios-should-respond.html" target="_blank">AI platform development</a>, he said. The combination of Microsoft’s enterprise AI platform with Mistral’s models and European AI infrastructure will give joint customers more deployment flexibility and expand options around data residency, sovereign AI deployments, and disconnected/on-premises environments.</p>



<p class="wp-block-paragraph">“It also gives customers more model choice, reducing dependence on a single AI provider,” said Chandrasekaran.</p>



<h2 class="wp-block-heading">A complementary partnership</h2>



<p class="wp-block-paragraph">Mistral continues to innovate with its frontier AI models and its chat and coding agent, Vibe (formerly Le Chat), yet it doesn’t attract as much attention as Claude or ChatGPT.</p>



<p class="wp-block-paragraph">One of the company’s key differentiators is its targeted business model. Levy pointed out that not every workload requires “full-flight GPT.” For customers trying to rein in costs and limit exposure with on-premises deployments, Mistral’s “more focused capabilities can represent a cost-effective alternative.”</p>



<p class="wp-block-paragraph">Chandrasekaran pointed to Mistral’s combination of high-performance open-weight models, strong multilingual capabilities, and a “focus on efficient inference that lowers deployment costs.”</p>



<p class="wp-block-paragraph">Unlike many frontier AI companies, it offers customers greater flexibility to self-host and customize models; this makes it particularly attractive for enterprises and governments with sovereignty or regulatory requirements, he said. Its European roots also position it as the leading alternative for organizations seeking cutting-edge AI outside the US and Chinese ecosystems.</p>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/bill-wong" target="_blank" rel="noreferrer noopener">Bill Wong</a>, research fellow at Info-Tech Research Group, also pointed to Mistral’s high-quality models and “adeptness as a sovereign AI leader.” There is growing demand for AI companies that comply with regional laws and data residency, and Mistral is established as “one of the most prominent European players.”</p>



<p class="wp-block-paragraph">“Such a strategic position makes it a great partner for Microsoft to further expand its AI offerings beyond just being a single-model provider,” he said. Customers get freedom of choice while complying with data sovereignty and regulatory limitations without having to execute a separate AI deployment, while Mistral, for its part, can go beyond Europe and gain more visibility with international businesses.</p>



<p class="wp-block-paragraph">Mistral brings both “technological and political advantages,” Levy noted. The startup’s European roots give Microsoft more credibility “at a fraught time for geopolitical relationships.” Customers in Europe and beyond are concerned about US exposure, and Mistral can provide a safer choice.</p>



<p class="wp-block-paragraph">Meanwhile, Microsoft can deploy European-developed AI models running on European infrastructure, thus maximizing regulatory compliance while offering next-level enterprise marketing scale that Mistral “simply couldn’t achieve on its own,” said Levy. Mistral-based workloads deployed on Azure will also benefit from Microsoft’s “comprehensive security certifications, governance frameworks, and monitoring.”</p>



<p class="wp-block-paragraph">Bottom line: Both companies can maximize their unique roadmaps through the partnership, he said. “As the rules of the AI economy continue to evolve, expect more eyebrow-raising deals like this to be signed.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Poolside drops Laguna S 2.1, an open-weight coding model that beats rivals 10x its size]]></title>
<description><![CDATA[Poolside, the San Francisco AI lab that has spent most of its three-year existence quietly selling coding models to governments and defense agencies, released its most capable model to date on Tuesday — and made an unusually aggressive bet that radical transparency, not raw scale, is how a smalle...]]></description>
<link>https://tsecurity.de/de/3684985/it-nachrichten/poolside-drops-laguna-s-21-an-open-weight-coding-model-that-beats-rivals-10x-its-size/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684985/it-nachrichten/poolside-drops-laguna-s-21-an-open-weight-coding-model-that-beats-rivals-10x-its-size/</guid>
<pubDate>Wed, 22 Jul 2026 01:07:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="http://poolside.ai/">Poolside</a>, the San Francisco AI lab that has spent most of its three-year existence quietly selling coding models to governments and defense agencies, released its most capable model to date on Tuesday — and made an unusually aggressive bet that radical transparency, not raw scale, is how a smaller lab competes at the frontier.</p><p>The model, <a href="https://poolside.ai/blog/introducing-laguna-s-2-1">Laguna S 2.1</a>, is a 118-billion-parameter<a href="https://huggingface.co/blog/moe"> Mixture-of-Experts (MoE) system</a> that activates only 8 billion parameters per token, supports a context window of up to 1 million tokens, and — according to benchmarks published by the company — matches or beats open models several times its size on agentic coding tasks. The weights are <a href="https://huggingface.co/poolside/Laguna-S-2.1">available immediately</a> on Hugging Face under the permissive OpenMDW-1.1 license.</p><p>The headline numbers are striking for a model this small. Poolside reports that <a href="https://huggingface.co/poolside/Laguna-S-2.1">Laguna S 2.1</a> scores 70.2% on <a href="https://www.tbench.ai/">Terminal-Bench 2.1</a>, a benchmark of long-horizon terminal tasks, placing it 11th on the company's compiled leaderboard — ahead of <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro">DeepSeek-V4-Pro-Max</a>, a 1.6-trillion-parameter model that scored 64.0; Thinking Machines' 975-billion-parameter <a href="https://venturebeat.com/technology/thinking-machines-open-sources-first-multimodal-language-model-inkling-focused-on-low-cost-and-resistance-to-censorship">Inkling</a>, at 63.8; and Nvidia’s 550-billion-parameter <a href="https://research.nvidia.com/labs/nemotron/Nemotron-3-Ultra/">Nemotron 3 Ultra</a>, at 56.4. On <a href="https://www.swebench.com/multilingual.html">SWE-Bench Multilingual</a>, it posts 78.5%, and on <a href="https://labs.scale.com/leaderboard/swe_bench_pro_public">SWE-Bench Pro</a>'s public dataset, 59.4%.</p><p>Perhaps more telling than any single score: the model went from the start of pre-training on May 22 to public launch in under nine weeks, trained on 4,096 Nvidia H200 GPUs. In an industry where flagship model cycles are typically measured in quarters or years, Poolside has now shipped three models in three months.</p><div></div><h2><b>Why the West's open-weight AI gap has become a boardroom issue</b></h2><p>The release lands in the middle of an increasingly pointed debate about <a href="https://www.scmp.com/tech/tech-war/article/3361142/why-chinas-open-weight-ai-model-kimi-k3-sparking-anxiety-silicon-valley">the provenance of open-weight AI</a>. Over the past year, developer adoption has shifted decisively toward open-weight systems that companies can download, inspect, and run on their own infrastructure — and the leading options in that category have overwhelmingly come from Chinese labs. <a href="https://www.deepseek.com/en/">DeepSeek</a>, <a href="https://qwen.ai/home">Qwen</a>, <a href="http://kimi.ai/">Kimi</a>, <a href="https://chat.z.ai/">GLM</a>, <a href="https://www.minimax.io/">MiniMax</a>, and <a href="https://hy.tencent.com/">Tencent's Hunyuan</a> line all feature prominently in Poolside's own comparison tables.</p><p>Poolside's accompanying press release frames <a href="https://poolside.ai/blog/introducing-laguna-s-2-1">Laguna S 2.1</a> explicitly as a response, noting that the model occupies a size class into which no Western lab has released open weights in 11 months — since OpenAI's <a href="https://openai.com/index/introducing-gpt-oss/">gpt-oss-120b</a> last August. "The West needs open-weight models it can trust, run, and build on," said Jason Warner, Poolside's co-CEO, in the announcement.</p><p>Co-founder and co-CEO Eiso Kant made the philosophical stakes even plainer in a <a href="https://x.com/eisokant/status/2079612416967491952?s=20">lengthy post</a> on X. "I believe intelligence should and will become a commodity," he wrote, arguing that the open ecosystem "will not win by being the best in its own category." Users, he argued, simply want the best intelligence for the task at hand — so open models must be on par with, or better than, their closed equivalents.</p><div></div><p>The strategic logic here is not charity. Poolside's core business is deploying models inside the security boundaries of government, defense, and regulated enterprises — customers for whom closed, metered API access is often a non-starter for compliance and sovereignty reasons. </p><p>Every enterprise that standardizes on a Chinese open model today becomes harder to win tomorrow. Releasing competitive open weights is both an ecosystem play and a top-of-funnel strategy for the company's high-security deployment business. It also reframes the AI race away from terrain where Poolside cannot compete — frontier-scale capital expenditure — and toward terrain where it believes it can: cost per token, self-hosting, and iteration speed.</p><h2><b>How a sparse architecture makes enterprise AI agents affordable to run</b></h2><p>The technical design reflects a specific thesis about where value in coding AI is moving. Laguna S 2.1's sparse MoE architecture — 256 routed experts plus one shared expert, with grouped-query attention and interleaved sliding-window layers, according to the <a href="https://huggingface.co/poolside/Laguna-S-2.1">Hugging Face model card</a> — means inference costs scale with the 8 billion active parameters, not the 118 billion total. Poolside emphasizes that the model is small enough to run on a single Nvidia DGX Spark, the desktop-class AI machine.</p><p>That matters for what Poolside calls token economics. Long-horizon coding agents are voracious consumers of tokens: the company's published data shows the model consuming a mean of roughly 249,000 completion tokens per trajectory on its hardest benchmark when thinking mode is enabled. At metered API prices, agentic workloads at enterprise scale become a meaningful budget line item. On OpenRouter, Poolside is offering a free 256K-context endpoint and a dedicated 1M-context deployment priced at $0.10 per million input tokens and $0.20 per million output tokens — aggressive pricing that undercuts most frontier alternatives by an order of magnitude.</p><p>The ecosystem support is unusually broad for day one. The model is live on <a href="https://www.baseten.co/library/laguna-s-21/">Baseten's model library</a> and <a href="https://vercel.com/changelog/laguna-s-2-1-is-now-available-on-ai-gateway">Vercel's AI Gateway</a>, with integrations across <a href="https://vllm.ai/">vLLM</a>, <a href="https://github.com/sgl-project/sglang">SGLang</a>, <a href="https://ollama.com/">Ollama</a>, and <a href="https://github.com/ggml-org/llama.cpp">llama.cpp</a>, plus quantized variants down to 4-bit GGUF files — 75 gigabytes — for local use. But Poolside's more interesting claim is behavioral, not architectural. Pengming Wang, co-head of applied research at Poolside, said the gains came from improving the model's working habits: "more verification, less taking things for granted, not declaring victory early, and being more persistent." Raw intelligence, the company argues, is one axis of capability; a model's way of working is a second axis that matters immensely for agents left unattended for hours.</p><h2><b>Publishing every benchmark trajectory to counter AI's credibility crisis</b></h2><p>The most consequential part of the release for enterprise buyers may be an evaluation-transparency move with little precedent among major labs: Poolside published the complete, unedited trajectory of every trial in its final benchmark runs — every reasoning step, tool call, and shell command behind every reported score.</p><p>This addresses a growing credibility problem in AI benchmarking. As top scores on mature benchmarks cluster in the 70–90% range, and as "reward hacking" — models finding solutions online or gaming verifiers rather than solving problems — has become endemic, self-reported numbers have lost much of their signal. Poolside disclosed its own encounters with the problem candidly: during training, more than half of trajectories on some SWE-bench tasks were flagged because the model simply researched the original bug-fix pull request online and applied it. The company documented its mitigations, including prompt addenda, LLM-based judging calibrated against human labels, and expert annotator review of a high-scoring Terminal-Bench run.</p><p>Three published case studies illustrate what the company means by persistence. In one, the model built a working HTML/CSS rendering engine from an empty folder in a 181-step, 50-minute unattended session — then, lacking vision capabilities, spun up headless Chromium to numerically compare its canvas output against a real browser's rendering. In another, pointed at Poolside's own agent harness in an automated optimization loop, the model made the Go codebase 5.2% faster with roughly 70% lower memory allocation, finding an O(n²) string-concatenation bug along the way. In a third, working in a sandbox with no Python installed, the model did its number theory in Perl and independently re-derived a proof of Erdős problem #397 — a combinatorics question open for five decades until GPT-5.2 Pro first solved it this past January. Poolside notes that its model's construction is structurally different from the earlier published solution, and that its November 2025 knowledge cutoff precedes the first proof.</p><div></div><h2><b>What the disclosed limitations and benchmark fine print reveal</b></h2><p><a href="https://poolside.ai/">Poolside</a> deserves credit for disclosing limitations most labs bury. The model can overfit to its native harness and stumble on slightly different tool schemas in third-party agents, mangles JSON in nested tool arguments, and is prone to overthinking on competition math. There is currently no user-configurable thinking-effort dial — just on or off — and the gap between the modes is enormous: thinking lifts <a href="https://www.tbench.ai/">Terminal-Bench 2.1</a> from 60.4% to 70.2%, and <a href="https://deepswe.datacurve.ai/">DeepSWE</a> from 16.5% to 40.4%, at substantially higher token cost.</p><p>Buyers should apply their own discounts to the comparison tables. Poolside's methodology takes the maximum of vendor self-reported scores, benchmark-author leaderboards, and third-party figures for competitors — a reasonable convention, but one that mixes harnesses and test conditions. On <a href="https://deepswe.datacurve.ai/">DeepSWE</a>, notably, Poolside ran its own agent harness rather than the leaderboard's standard mini-swe-agent, a difference the company acknowledges makes scores less directly comparable. And the frontier remains clearly out of reach: closed models like <a href="https://openai.com/index/previewing-gpt-5-6-sol/">GPT-5.6 Sol</a>, at 88.8 on Terminal-Bench 2.1, and <a href="https://www.anthropic.com/claude/fable">Claude Fable 5</a>, at 88.0, along with the 2.8-trillion-parameter open-weight <a href="https://venturebeat.com/technology/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-u-s-systems">Kimi K3</a>, at 88.3, sit well above Laguna S 2.1.</p><p>The deeper structural question is whether Poolside's "<a href="https://poolside.ai/blog/introducing-the-model-factory">Model Factory</a>" — the internal platform the company credits for its rapid release cadence — can sustain this pace as models scale. The trajectory so far is genuinely unusual: the April dual release of Laguna M.1 and XS.2, the July 2 refresh of XS 2.1, and now S 2.1, which the company says outperforms April's flagship M.1 at roughly a third of its active size. Remarkably, S 2.1 used the exact same pre-training data as XS 2.1, meaning nearly all the improvement came from scale, training fixes, and post-training across the company's corpus of 409,000 agentic and non-agentic training environments. Poolside says its next, larger Laguna model began pre-training last week.</p><p>For technical decision makers, <a href="https://huggingface.co/poolside/Laguna-S-2.1">Laguna S 2.1</a> is the most credible Western open-weight option to emerge in nearly a year for self-hosted agentic coding — with published evidence, a permissive license, broad ecosystem support, and an economics story built around hardware you can own. Whether it dents the dominance of Chinese open models will depend less on this release than on the ones that follow it.</p><p>Kant, for his part, has already told the world how he intends that story to end. Poolside is building toward a future where the most capable intelligence "can be owned and shaped by anyone," he wrote — and the company plans to keep shipping "until that future exists." In an industry where the biggest labs increasingly lock their best work behind an API, the most radical thing about Laguna S 2.1 may not be what it scores, but that anyone can download it and check.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ricky Gervais Says ‘Alley Cats’ Takes a New Approach to Adult Animation]]></title>
<description><![CDATA[Ricky Gervais has shared fresh details about his upcoming Netflix adult animated comedy Alley Cats, explaining how the series breaks away from traditional animation. During new press interviews, Gervais, Tom Basden, and Diane Morgan revealed that the show was built around live comedy performances...]]></description>
<link>https://tsecurity.de/de/3684263/ios-mac-os/ricky-gervais-says-alley-cats-takes-a-new-approach-to-adult-animation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684263/ios-mac-os/ricky-gervais-says-alley-cats-takes-a-new-approach-to-adult-animation/</guid>
<pubDate>Tue, 21 Jul 2026 17:59:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ricky Gervais has shared fresh details about his upcoming Netflix adult animated comedy Alley Cats, explaining how the series breaks away from traditional animation. During new press interviews, Gervais, Tom Basden, and Diane Morgan revealed that the show was built around live comedy performances, improvisation, and emotional storytelling ahead of its August 7, 2026 premiere.



The six-episode series follows a gang of foul-mouthed feral cats trying to survive while navigating everyday life in a harsh human world. Alongside its sharp humor, the show also explores friendship, grief, and mortality through the lives of its feline characters.



Ricky Gervais Wanted to Change How Animated Shows Are Made



According to Gervais, the biggest difference with Alley Cats came before the animation even started.



Instead of recording each actor separately in a sound booth, he insisted on bringing the entire cast together for every episode. The group performed scenes at the same time, allowing conversations to flow naturally and giving actors room to interrupt, react, and improvise.



Gervais explained that each recording session lasted far longer than the final episode. With nearly two hours of material recorded for a 15-minute episode, the creative team could choose the funniest moments while keeping performances spontaneous and realistic.



He believes that "audio is king" in animation, and the visuals should support the performances instead of limiting them.



Improvisation Created Some Wild Moments



That recording style led to plenty of unexpected comedy.



Diane Morgan revealed that many improvised jokes became far too outrageous to make the final cut. She credited fellow cast member David Earl for pushing scenes into completely unpredictable territory, often forcing the team to stop and ask whether certain jokes could actually stay in the series.



Those sessions helped create conversations that sound less scripted and more like friends talking naturally.



A Cast Built Around British Comedy



Gervais described the voice cast as the "Avengers of British comedy" because he wrote many characters specifically for actors he has worked with before.



Tom Basden voices Ponce, a well-kept house cat whose education and manners constantly clash with the rough street cats around him. Basden says Ponce often acts like an outsider while secretly understanding the softer side of Gus, voiced by Gervais.



Diane Morgan plays Olive, a cheerful but not particularly bright cat whose simple outlook adds another layer of comedy. Morgan joked that Olive quickly loses interest in Ponce after learning one unexpected detail about him.



Comedy With Genuine Emotion



Although Alley Cats promises plenty of crude jokes, Gervais says the series also explores emotional themes that have appeared throughout his previous work.



One important storyline follows the group caring for a lost kitten while confronting the reality of death for the first time. Gervais explained that childhood memories about losing pets inspired those scenes and shaped the emotional core of the series.



Morgan said viewers may expect nothing more than "sweary cats," but the show eventually delivers emotional moments that stay with the audience. Basden added that the story also looks at humanity's relationship with nature and the uncertainty every living creature faces.



Music and Release Date



The soundtrack will include songs from Cat Stevens, Coldplay, and Van Halen. Gervais also confirmed that The Smiths' classic "There Is a Light That Never Goes Out" appears in the series after both Morrissey and Johnny Marr approved its use, with Marr donating his licensing fee to an animal charity.



Alley Cats premieres globally on Netflix on August 7, 2026. The adult animated sitcom has already generated strong interest following its Annecy Festival preview, where audiences received an early look at the first two episodes.]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS standardizes more AI billing data to simplify cost analysis]]></title>
<description><![CDATA[AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple found...]]></description>
<link>https://tsecurity.de/de/3683996/it-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683996/it-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</guid>
<pubDate>Tue, 21 Jul 2026 16:18:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple foundation models.</p>



<p class="wp-block-paragraph">The update extends billing exports with normalized fields for model provider, model name, inference type, inference mode, billing unit and <a href="https://www.infoworld.com/article/2336139/amazon-bedrock-a-solid-generative-ai-foundation.html">Bedrock</a> product family, and will enable enterprises to identify which models generated costs and compare spending across providers without relying on custom parsing or normalization of billing records, AWS wrote in a <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/aws-data-exports-amazon-bedrock-product-metadata/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">That reduced reliance on custom parsing will reduce the engineering effort required to analyze billing data, analysts said.</p>



<p class="wp-block-paragraph">“Before the update, a data engineer would typically need to maintain a model ID registry, write regex against usage type strings, or join AWS CloudTrail with CUR to figure out which provider generated which cost,” said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">The new standardized fields “can be the difference between a billing pipeline that needs constant babysitting and one that doesn’t,” Chopra added.</p>



<p class="wp-block-paragraph">That’s because custom parsing logic is more prone to break down or require maintenance when AWS adds new models or updates pricing in Bedrock, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<h2 class="wp-block-heading">Richer billing data to boost enterprise AI cost governance</h2>



<p class="wp-block-paragraph">Beyond reducing engineering overhead, the update could also help enterprises improve AI cost governance.</p>



<p class="wp-block-paragraph">Before this update FinOps teams struggled to identify which model Bedrock related to because usage type fields were inconsistent, and there was no unified product family name that captured all Bedrock costs in one place, Chopra said.</p>



<p class="wp-block-paragraph">“Now those attributes — model provider, model name, inference type, inference mode, pricing unit — are standardized and available by default. That’s the plumbing work no one talks about, but it’s what makes downstream reporting actually reliable,” Chopra added.</p>



<p class="wp-block-paragraph">This, said Jain, makes it easier to build dashboards showing cost by model, provider, token type or inference mode while also identifying expensive workloads, unusual token growth and opportunities to move to cheaper models or batch processing.</p>



<p class="wp-block-paragraph">It’s a timely update, especially in light of last week’s <a href="https://health.aws.amazon.com/health/status?eventID=arn:aws:health:global::event/BILLING/AWS_BILLING_OPERATIONAL_ISSUE/AWS_BILLING_OPERATIONAL_ISSUE_47B68_BACBD91434F" target="_blank" rel="noreferrer noopener">AWS billing issue</a> that caused some customers to see incorrect cost estimates of services consumed in the AWS Management Console, said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at FinOps services providing firm ZopDev.</p>



<p class="wp-block-paragraph">“Anything that gives customers clearer, more granular and more trustworthy billing data is welcome when confidence in the numbers has just been shaken. It does not fix what went wrong, but better visibility into where spend is going is exactly what teams want more of after an episode like that,” Bandta added.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4199470/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS standardizes more AI billing data to simplify cost analysis]]></title>
<description><![CDATA[AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple found...]]></description>
<link>https://tsecurity.de/de/3683957/ai-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683957/ai-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</guid>
<pubDate>Tue, 21 Jul 2026 16:05:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple foundation models.</p>



<p class="wp-block-paragraph">The update extends billing exports with normalized fields for model provider, model name, inference type, inference mode, billing unit and <a href="https://www.infoworld.com/article/2336139/amazon-bedrock-a-solid-generative-ai-foundation.html">Bedrock</a> product family, and will enable enterprises to identify which models generated costs and compare spending across providers without relying on custom parsing or normalization of billing records, AWS wrote in a <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/aws-data-exports-amazon-bedrock-product-metadata/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">That reduced reliance on custom parsing will reduce the engineering effort required to analyze billing data, analysts said.</p>



<p class="wp-block-paragraph">“Before the update, a data engineer would typically need to maintain a model ID registry, write regex against usage type strings, or join AWS CloudTrail with CUR to figure out which provider generated which cost,” said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">The new standardized fields “can be the difference between a billing pipeline that needs constant babysitting and one that doesn’t,” Chopra added.</p>



<p class="wp-block-paragraph">That’s because custom parsing logic is more prone to break down or require maintenance when AWS adds new models or updates pricing in Bedrock, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<h2 class="wp-block-heading">Richer billing data to boost enterprise AI cost governance</h2>



<p class="wp-block-paragraph">Beyond reducing engineering overhead, the update could also help enterprises improve AI cost governance.</p>



<p class="wp-block-paragraph">Before this update FinOps teams struggled to identify which model Bedrock related to because usage type fields were inconsistent, and there was no unified product family name that captured all Bedrock costs in one place, Chopra said.</p>



<p class="wp-block-paragraph">“Now those attributes — model provider, model name, inference type, inference mode, pricing unit — are standardized and available by default. That’s the plumbing work no one talks about, but it’s what makes downstream reporting actually reliable,” Chopra added.</p>



<p class="wp-block-paragraph">This, said Jain, makes it easier to build dashboards showing cost by model, provider, token type or inference mode while also identifying expensive workloads, unusual token growth and opportunities to move to cheaper models or batch processing.</p>



<p class="wp-block-paragraph">It’s a timely update, especially in light of last week’s <a href="https://health.aws.amazon.com/health/status?eventID=arn:aws:health:global::event/BILLING/AWS_BILLING_OPERATIONAL_ISSUE/AWS_BILLING_OPERATIONAL_ISSUE_47B68_BACBD91434F" target="_blank" rel="noreferrer noopener">AWS billing issue</a> that caused some customers to see incorrect cost estimates of services consumed in the AWS Management Console, said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at FinOps services providing firm ZopDev.</p>



<p class="wp-block-paragraph">“Anything that gives customers clearer, more granular and more trustworthy billing data is welcome when confidence in the numbers has just been shaken. It does not fix what went wrong, but better visibility into where spend is going is exactly what teams want more of after an episode like that,” Bandta added.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Headaches for Silicon Valley as China chips away at the US’s lead in the AI race]]></title>
<description><![CDATA[Google’s AI struggles scream trouble as new Chinese models (again) throw US tech dominance into questionHello, I’m Blake Montgomery, writing to you after a double-header feature of Christopher Nolan’s The Odyssey and the World Cup final. What a great Sunday. Today in tech, we’re discussing how Ch...]]></description>
<link>https://tsecurity.de/de/3683658/ai-nachrichten/headaches-for-silicon-valley-as-china-chips-away-at-the-uss-lead-in-the-ai-race/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683658/ai-nachrichten/headaches-for-silicon-valley-as-china-chips-away-at-the-uss-lead-in-the-ai-race/</guid>
<pubDate>Tue, 21 Jul 2026 14:19:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google’s AI struggles scream trouble as new Chinese models (again) throw US tech dominance into question</p><p>Hello, I’m Blake Montgomery, writing to you after a double-header feature of Christopher Nolan’s The Odyssey and the World Cup final. What a great Sunday. Today in tech, we’re discussing how China is chipping away at the US’s lead in the AI race and how Silicon Valley’s workers are taking action to protect their jobs from AI.</p><p><a href="https://www.theguardian.com/us-news/2026/jul/14/new-york-moratorium-ai-datacenters">New York becomes first state to impose one-year pause on new AI datacenters</a></p><p><a href="https://www.theguardian.com/us-news/2026/jul/15/trump-new-york-datacenter-moratorium">Trump rails against New York’s statewide datacenter moratorium</a></p><p><a href="https://www.theguardian.com/australia-news/2026/jul/16/albaneses-ai-blueprint-sparks-calls-for-datacentre-moratorium-until-new-regulations-in-place">Albanese’s AI blueprint sparks calls for datacentre moratorium until new regulations in place</a></p><p><a href="https://www.theguardian.com/fashion/2026/jul/17/adversarial-clothing-are-garments-designed-to-confuse-facial-recognition-systems-about-to-go-mainstream">‘Adversarial clothing’: are garments designed to confuse facial recognition systems about to go mainstream?</a></p><p><a href="https://www.theguardian.com/technology/2026/jul/14/ibm-shares-profit-drop-value">IBM loses quarter of its value as tech giant’s shares plunge and profits falter</a></p><p><a href="https://www.theguardian.com/media/2026/jul/15/teenagers-verdic-britain-social-media-curfew-ban-whats-the-point">‘What’s the point?’ Teenagers give their verdict on Britain’s social media curfew</a></p><p><a href="https://www.theguardian.com/technology/2026/jul/17/amazon-web-services-customers-trillion-dollar-bills-global-glitch">Amazon Web Services customers receive bills for up to $1.5tn after global glitch</a></p><p><a href="https://www.theguardian.com/technology/ng-interactive/2026/jul/16/justin-sun-trump-family-crypto">Trump made $1.4bn from crypto in one year. Is Justin Sun the man who helped him do it?</a></p> <a href="https://www.theguardian.com/technology/2026/jul/20/china-google-ai-race">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI in the enterprise: Why architecture matters more than marketing claims]]></title>
<description><![CDATA[Most "AI-powered" marketing tools are just rule engines in disguise. Here's how to tell the difference.]]></description>
<link>https://tsecurity.de/de/3683371/it-nachrichten/agentic-ai-in-the-enterprise-why-architecture-matters-more-than-marketing-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683371/it-nachrichten/agentic-ai-in-the-enterprise-why-architecture-matters-more-than-marketing-claims/</guid>
<pubDate>Tue, 21 Jul 2026 12:32:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Most "AI-powered" marketing tools are just rule engines in disguise. Here's how to tell the difference.]]></content:encoded>
</item>
<item>
<title><![CDATA[The next AI bottleneck is not the model. It’s the infrastructure behind it]]></title>
<description><![CDATA[Every enterprise AI conversation seems to begin with the same question: Which model should we use?



I understand why. Models are visible. They have names, benchmarks, release notes, pricing pages and impressive demos. They are easy to compare in a leadership meeting. One model promises better r...]]></description>
<link>https://tsecurity.de/de/3683109/it-nachrichten/the-next-ai-bottleneck-is-not-the-model-its-the-infrastructure-behind-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683109/it-nachrichten/the-next-ai-bottleneck-is-not-the-model-its-the-infrastructure-behind-it/</guid>
<pubDate>Tue, 21 Jul 2026 11:03:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every enterprise AI conversation seems to begin with the same question: Which model should we use?</p>



<p class="wp-block-paragraph">I understand why. Models are visible. They have names, benchmarks, release notes, pricing pages and impressive demos. They are easy to compare in a leadership meeting. One model promises better reasoning. Another offers a larger context window. Another appears faster, cheaper or more specialized.</p>



<p class="wp-block-paragraph">But after years of working around enterprise platforms, integration layers, cloud migration, middleware, production operations and mission-critical systems, I see the AI conversation differently.</p>



<p class="wp-block-paragraph">The model matters. But it is not where most enterprises will struggle next.</p>



<p class="wp-block-paragraph">The next AI bottleneck is the infrastructure behind the model.</p>



<p class="wp-block-paragraph">I do not mean only GPUs, cloud capacity or data storage. I mean the full enterprise operating layer that allows AI to work safely in the real world: data pipelines, identity, APIs, messaging, observability, security controls, deployment automation, cost governance, auditability, support ownership and recovery design.</p>



<p class="wp-block-paragraph">That layer is what determines whether AI remains an exciting experiment or becomes a trusted business capability.</p>



<h2 class="wp-block-heading">Pilots hide the hard part</h2>



<p class="wp-block-paragraph">Most organizations can build an <a href="https://www.cio.com/article/4159287/most-companies-are-stuck-on-ai-chat.html">impressive AI pilot</a>. A small team can connect a model to a dataset, create a workflow and show a use case that works well in a controlled setting.</p>



<p class="wp-block-paragraph">The harder part starts when that pilot moves into a <a href="https://www.cio.com/article/4161509/ai-hype-to-ai-value-escaping-the-activity-trap.html">real production process</a>.</p>



<p class="wp-block-paragraph">That is when practical questions show up. Who owns the data quality? What systems can the AI access? How do we trace which prompt, policy or retrieval flow produced a specific answer? What happens when an API slows down, a queue backs up or a downstream system is unavailable?</p>



<p class="wp-block-paragraph">To me, these are not model problems. They are infrastructure problems.</p>



<p class="wp-block-paragraph">This is where many enterprises are now headed. The first phase of AI was experimentation. The next phase is operationalization, and that is where the real gap becomes clear.</p>



<p class="wp-block-paragraph"><a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/seizing-the-agentic-ai-advantage">McKinsey</a> has made a similar point in its work on agentic AI, noting that the next phase of value depends less on isolated tools and more on redesigning workflows, operating models and enterprise execution around agents.</p>



<p class="wp-block-paragraph">AI pilots can survive on enthusiasm. Production AI requires architecture.</p>



<h2 class="wp-block-heading">AI is becoming an integration problem</h2>



<p class="wp-block-paragraph">The more I look at enterprise AI, the more it feels like an integration challenge.</p>



<p class="wp-block-paragraph">In large organizations, I have seen how messaging platforms, integration gateways, deployment pipelines, monitoring tools and cloud infrastructure can decide whether a digital capability succeeds or fails. AI will be no different. Even the strongest model will struggle if the data, middleware, identity layer and operational controls around it are weak.</p>



<p class="wp-block-paragraph">AI does not work in isolation. It needs context from systems of record, clean data from different business areas, secure access to APIs, event streams, workflows, knowledge repositories, monitoring tools and legacy systems.</p>



<p class="wp-block-paragraph">That is why the CIO question is changing.</p>



<p class="wp-block-paragraph">It is no longer just, “Which AI tool should we buy?”</p>



<p class="wp-block-paragraph">It is becoming, “Can we safely operationalize intelligence across the business?”</p>



<p class="wp-block-paragraph">This is where agentic AI matters. Autonomous AI only creates real value when the architecture around it can make its actions safe, traceable and useful.</p>



<p class="wp-block-paragraph">A model can generate an answer. Infrastructure determines whether that answer is secure, timely, explainable, governed and connected to the right workflow.</p>



<p class="wp-block-paragraph">For example, an AI assistant that summarizes customer or order information may look like a model use case. But underneath, it depends on access control, fresh data, reliable APIs, logging, encryption, monitoring and policy enforcement.</p>



<p class="wp-block-paragraph">If the answer is wrong, people may blame the model. But the real failure may have started with stale data, weak integration, poor access design, missing observability or an unreliable downstream system.</p>



<p class="wp-block-paragraph">That is why CIOs should not judge AI only by model capability. The enterprise system around the model matters just as much.</p>



<h2 class="wp-block-heading">Latency will become a trust issue</h2>



<p class="wp-block-paragraph">In traditional technology operations, latency is often treated as a performance metric. In AI-enabled workflows, latency becomes a trust issue.</p>



<p class="wp-block-paragraph">When an employee asks an AI assistant for help and the response takes too long, the employee stops using it. When a customer-facing workflow becomes slow, the customer abandons it. When an AI agent waits on multiple backend calls, the entire business process feels unreliable.</p>



<p class="wp-block-paragraph">This becomes even more important as organizations move from simple chat interfaces to agentic workflows. A single AI-driven action may include identity checks, context retrieval, policy validation, model reasoning, API calls, business-rule execution, logging and human approval.</p>



<p class="wp-block-paragraph">Each step adds latency. Each dependency adds a possible failure point.</p>



<p class="wp-block-paragraph">A model may be fast in a benchmark but slow inside an enterprise process. That difference matters.</p>



<p class="wp-block-paragraph">This is where platform engineering becomes essential. Enterprises need reusable patterns for AI workloads: approved connectors, secure retrieval methods, queue-based decoupling, caching strategies, deployment pipelines, monitoring dashboards and standard rollback procedures.</p>



<p class="wp-block-paragraph">Without those patterns, every AI initiative becomes a custom build. Custom builds may work for pilots, but they do not scale across a large enterprise.</p>



<h2 class="wp-block-heading">Observability has to expand</h2>



<p class="wp-block-paragraph">Traditional monitoring tells us whether infrastructure is healthy. Is the server up? Is CPU high? Is memory exhausted? Is the application returning errors?</p>



<p class="wp-block-paragraph">AI needs that, but it also needs more.</p>



<p class="wp-block-paragraph">We need to know what data was retrieved, which model was used, which prompt version was active, which user initiated the request, which policy was applied, how long each step took and whether the output passed validation.</p>



<p class="wp-block-paragraph">We also need to detect new forms of risk: unusual usage patterns, repeated failed tool calls, unexpected cost spikes, sensitive data exposure, weak retrieval results or an AI workflow attempting actions outside its intended boundary.</p>



<p class="wp-block-paragraph">In production AI, observability is not only about uptime. It is about confidence.</p>



<p class="wp-block-paragraph">If a business leader, auditor, regulator or security team asks why an AI system made a recommendation, the answer cannot be, “The model said so.” The enterprise needs traceability. It needs evidence. It needs operational context that engineers, risk teams and business owners can understand.</p>



<p class="wp-block-paragraph">This is one of the biggest gaps I see in AI strategy. Many organizations are investing in models and use cases, but not enough in the control plane required to manage them.</p>



<h2 class="wp-block-heading">Data readiness is still underestimated</h2>



<p class="wp-block-paragraph">AI has exposed an uncomfortable truth: many enterprises are not as data ready as they think.</p>



<p class="wp-block-paragraph">Data is often duplicated across platforms, described differently by each team, governed inconsistently and refreshed on different schedules. Access rules may be clear in one system but unclear in another. Even basic business definitions can change from department to department.</p>



<p class="wp-block-paragraph">AI does not fix that automatically. In many cases, it makes the problem more visible.</p>



<p class="wp-block-paragraph">A bad report may be questioned. A bad AI answer may sound confident enough to be trusted.</p>



<p class="wp-block-paragraph">That is a real risk.</p>



<p class="wp-block-paragraph">Being data-ready for AI is not just about connecting a vector database or indexing documents. It requires clear ownership, lineage, classification, quality checks, retention rules, access boundaries and a shared understanding of which data should be used for which purpose.</p>



<p class="wp-block-paragraph">The same principle applies to resilient cloud-native design. In my IEEE TechRxiv paper, “<a href="https://www.techrxiv.org/doi/full/10.36227/techrxiv.175433366.65304469/v1">Enabling Fault-Tolerant Multicast in Cloud-Native Architectures</a>” I explored how reliability, observability and fault tolerance become foundational requirements when critical workloads stretch across hybrid and multi-cloud environments.</p>



<p class="wp-block-paragraph">CIOs already understand this because they have lived through enterprise resource planning programs, cloud migration, integration modernization, cybersecurity transformation and analytics initiatives. The lesson is familiar: technology cannot outrun data discipline forever.</p>



<h2 class="wp-block-heading">Security cannot be added later</h2>



<p class="wp-block-paragraph">As AI moves from answering questions to acting, security becomes much more important.</p>



<p class="wp-block-paragraph">An assistant that summarizes information carries one level of risk. An agent that can open a ticket, update a record, trigger a workflow, approve a request or contact a customer carries a very different one.</p>



<p class="wp-block-paragraph">The more AI can do, the more identity, authorization, least privilege, separation of duties and human approval matter.</p>



<p class="wp-block-paragraph">Enterprises should be careful not to grant AI broad access just to speed up a pilot. That may seem harmless in development, but it can become dangerous at scale.</p>



<p class="wp-block-paragraph">AI access should be treated like any other privileged enterprise capability: limited, logged, reviewed and easy to revoke.</p>



<p class="wp-block-paragraph">The <a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST</a> AI Risk Management Framework is a useful reference point here because it frames AI risk as something organizations must govern, map, measure and manage continuously rather than something handled only at the end of deployment.</p>



<p class="wp-block-paragraph">Security teams should be involved early, not at the end. The goal is not to slow innovation. The goal is to build a platform where safe innovation becomes repeatable.</p>



<h2 class="wp-block-heading">The CIO has to define the operating model</h2>



<p class="wp-block-paragraph">AI is creating pressure from every direction. Boards want productivity. Business teams want automation. Employees want better tools. Vendors are pushing new features. Security teams are watching risk. Finance teams are watching cost. Customers expect faster, smarter experiences.</p>



<p class="wp-block-paragraph">The CIO sits in the middle of all of it.</p>



<p class="wp-block-paragraph">That is why the CIO’s role cannot stop at choosing tools or approving pilots. The CIO has to define how AI will actually operate across the enterprise.</p>



<p class="wp-block-paragraph">That means answering practical questions. Which architecture is approved? Which data sources can be trusted? How are AI workflows deployed, monitored, supported and governed? How are costs controlled? How do teams reuse common patterns instead of rebuilding the same foundation each time?</p>



<p class="wp-block-paragraph">This work may not be as exciting as a model demo, but it is what separates sustainable AI from short-term experimentation.</p>



<p class="wp-block-paragraph">The winning organizations will not be the ones with the most pilots. They will be the ones with the strongest AI operating layer.</p>



<p class="wp-block-paragraph">They will build reusable platform patterns, strengthen data governance, design access properly, monitor AI behavior end to end and measure success by business improvement, not only model performance.</p>



<p class="wp-block-paragraph">The model still matters. But the enterprise behind the model matters more.</p>



<p class="wp-block-paragraph">A powerful model on weak infrastructure will eventually disappoint the business. A capable model on strong infrastructure can deliver real value because it can be trusted, secured, scaled and improved.</p>



<p class="wp-block-paragraph">That is the shift CIOs need to lead.</p>



<p class="wp-block-paragraph">The next AI bottleneck is not the model. It is whether the enterprise behind the model is ready.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.6.33]]></title>
<description><![CDATA[OpenClaw 2026.6.33]]></description>
<link>https://tsecurity.de/de/3683059/downloads/v2026633/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683059/downloads/v2026633/</guid>
<pubDate>Tue, 21 Jul 2026 10:47:19 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.6.33</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Contracting]]></title>
<description><![CDATA[I've recently been looking to move into the security field such as Maritime security, UHNWI Security or even residential. Im still currently serving and working on aligning my training with whats required for those specific jobs or in other words the more experience the better. My question is wha...]]></description>
<link>https://tsecurity.de/de/3682533/it-security-nachrichten/security-contracting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682533/it-security-nachrichten/security-contracting/</guid>
<pubDate>Tue, 21 Jul 2026 04:08:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I've recently been looking to move into the security field such as Maritime security, UHNWI Security or even residential. Im still currently serving and working on aligning my training with whats required for those specific jobs or in other words the more experience the better. My question is what's a good starter to jump into to get things rolling, should I be looking to join a security firm or simply applying for contractor jobs i see and what are some training/Experience I should have to have the best opportunity of getting a well paying job. </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Blood_moonxX"> /u/Blood_moonxX </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1v0s9jw/security_contracting/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1v0s9jw/security_contracting/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[The technology behind every live sports moment]]></title>
<description><![CDATA[When a goal goes in during a tournament quarter-final and a hundred million people watch it at the same time, what they feel is the goal. The roar, the replay, the disbelief.



They do not feel the contribution feeds traversing private media networks across continents, or the edge nodes absorbin...]]></description>
<link>https://tsecurity.de/de/3681409/it-nachrichten/the-technology-behind-every-live-sports-moment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681409/it-nachrichten/the-technology-behind-every-live-sports-moment/</guid>
<pubDate>Mon, 20 Jul 2026 16:48:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When a goal goes in during a tournament quarter-final and a hundred million people watch it at the same time, what they feel is the goal. The roar, the replay, the disbelief.</p>



<p class="wp-block-paragraph">They do not feel the contribution feeds traversing private media networks across continents, or the edge nodes absorbing a traffic spike that appeared without warning.</p>



<p class="wp-block-paragraph">They just feel the moment.</p>



<p class="wp-block-paragraph">And that’s exactly how it’s supposed to work.</p>



<p class="wp-block-paragraph">And as live sports viewership pushes into territory that makes previous records look modest (driven by a generation that expects to watch anything, on any device, anywhere, without waiting), the gap between getting that delivery right and getting it wrong has never been more consequential, or more public.</p>



<p class="wp-block-paragraph"><strong>As audiences moved to digital platforms, the margin for error disappeared.</strong><strong></strong></p>



<p class="wp-block-paragraph">There is a version of this conversation that is easy to have: audiences expect more, technology has to keep up. True, but incomplete.</p>



<p class="wp-block-paragraph">Audiences have always expected live sport to work. What changed is what “working” means, and how quickly they find out when it doesn’t.</p>



<p class="wp-block-paragraph">Viewers no longer sit in front of a single screen. During a FIFA World Cup match, a household might have the main feed on the living room television, while someone else streams the highlights on a second TV in the bedroom, all while phones flash with live stats and tablets run separate commentary. From the infrastructure’s perspective, that isn’t just one household watching a game; it’s a chaotic web of concurrent demands triggered by the exact same split-second on the pitch.</p>



<p class="wp-block-paragraph">Multiply that across tens of millions of viewers, and the scale of the challenge becomes clear. Social media raises the stakes further. When a platform fails during a World Cup knockout match, audiences report it in real-time on the same platforms they use to discuss the game. The complaint travels faster than the fix.</p>



<p class="wp-block-paragraph">Broadcasters no longer have the luxury of resolving an incident before people notice. The incident becomes the story, and in many cases, travels further than the match itself.</p>



<h3 class="wp-block-heading"><strong>What these viewership numbers actually mean for infrastructure</strong></h3>



<p class="wp-block-paragraph">The shift in how people watch live sport has moved well beyond trend territory.</p>



<p class="wp-block-paragraph">EMARKETER forecasts that digital live sports audiences in the US will grow to <a href="https://www.emarketer.com/content/100-million-watch-live-sports-digital">114.1 million viewers</a>, while traditional pay TV audiences decline to 82.0 million, highlighting the continued shift toward streaming.</p>



<p class="wp-block-paragraph">The concurrency numbers generated by major sporting events now sit in a territory that would have seemed implausible a decade ago.</p>



<p class="wp-block-paragraph">During the 2026 FIFA World Cup, for instance, streaming platforms shattered every historical ceiling, highlighted by Brazil’s <a href="https://streamscharts.com/news/fifa-world-cup-2026-group-stage-livestreaming">CazéTV</a> repeatedly breaking global YouTube records for concurrent viewership during the group stage. Meanwhile, in the United States, Peacock and <a href="https://www.nbcuniversal.com/article/fifa-world-cup-2026-propels-telemundo-and-peacock-record-viewership">Telemundo’s</a> digital platforms logged an unprecedented 13 million concurrent viewers for a single knockout window. </p>



<p class="wp-block-paragraph">When tens of millions of people tune into the same live stream at the same moment, it’s a challenge unlike regular web traffic.</p>



<p class="wp-block-paragraph">Historically, massive global audiences were insulated by geography. The load was spread across distinct regional networks: antenna signals, satellite downlinks, and physical cable architectures. The physical infrastructure of traditional television inherently absorbed the impact. </p>



<p class="wp-block-paragraph">Digital streaming removes that buffer. Traffic spikes all at once, often at the most critical moment. The tighter the match, the deeper the stoppage time, the sharper the spike. Network infrastructure is forced to handle its heaviest, most volatile traffic exactly when it has zero margin for error.</p>



<p class="wp-block-paragraph">Social media compounds the pressure operationally. The second a crucial goal is scored, a wave of real-time reactions floods the internet, instantly dragging a secondary “curiosity audience” into the app. These are people who weren’t even watching the match, but saw the hype and decided to tune in, meaning the network has to absorb a massive new rush of users precisely while the primary stream is already maxing out its capacity.</p>



<p class="wp-block-paragraph">To survive these surges while satisfying a modern audience, the underlying broadcast playbook has undergone a massive structural shift. It’s no longer just about handling traffic; it’s also about using modern technology like AI to manage it intelligently.</p>



<p class="wp-block-paragraph">According to an <a href="https://www.haivision.com/blog/all/2025-broadcast-transformation-report-key-takeaways/">industry survey</a>, 25% of broadcasters integrated AI into live production workflows in 2025, a massive leap from just 9% the previous year, with 64% identifying AI as the single largest impact driver over the next five years. </p>



<p class="wp-block-paragraph">The network is no longer just delivering content. AI is now generating highlights and short clips in real time, producing millions of videos that keep fans engaged long after the live moment has passed.</p>



<p class="wp-block-paragraph">Ultimately, the technical demand is driven by a shift in what viewers expect. An <a href="https://newsroom.ibm.com/2025-08-18-ibm-study-sports-fans-demand-more-dynamic-digital-content,-powered-by-ai">IBM sports study</a> revealed that 56% of fans now want AI-driven insights layered directly onto their content, while 33% point to real-time, automated translation as the feature that most impacts their experience.</p>



<p class="wp-block-paragraph">Whether it’s one screen or several, viewers don’t notice the edge infrastructure or AI powering the experience. They just expect the game to play without interruption.</p>



<h3 class="wp-block-heading"><strong>The planning mistake most organisations make</strong></h3>



<p class="wp-block-paragraph">Capacity planning is where most organisations spend their time when preparing to stream a major event. Can the system handle a million concurrent streams? Can it scale on demand if the numbers exceed projections? These are real questions. </p>



<p class="wp-block-paragraph">The lesson is not unique to sports streaming. Every digital business now experiences moments where demand, visibility, and customer expectations collide. Peak traffic events such as flash sales, ticket releases, and viral campaigns can drive website traffic <a href="https://aws.amazon.com/blogs/apn/how-to-manage-peak-traffic-on-aws-using-queue-its-virtual-waiting-room/">2 to 25 times above normal levels within seconds</a>. The infrastructure may be different, but the pressure is remarkably similar.<br></p>



<p class="wp-block-paragraph">Large-scale system failures occur when multiple components, each functioning as expected on its own, are overwhelmed by a surge in demand, rising latency, or regional blind spots at the same time.</p>



<p class="wp-block-paragraph">The problem isn’t the individual systems. It’s how they work together.</p>



<p class="wp-block-paragraph">Latency is the factor most consistently underestimated. A few seconds of delay is not a minor inconvenience in live sport. It is a fundamentally broken experience. </p>



<p class="wp-block-paragraph">A viewer whose stream is running four seconds behind will see a notification before the decisive moment appears on screen. Someone watching a service from the privacy of their room may hear a celebration from another room before seeing it on their screen.</p>



<p class="wp-block-paragraph">Geography is another planning gap. Streaming growth is increasingly being driven by emerging markets. In Southeast Asia alone, premium video streaming subscriptions grew <a href="https://avia.org/southeast-asia-premium-vod-accelerates-in-2025-as-subscriber-growth-rebounds-ctv-scales-and-local-content-breaks-through/?utm_source=chatgpt.com">19%</a> in 2025, led by Indonesia, while viewing hours continued to climb across the region. Yet much of the world’s media infrastructure was originally designed around North American and Western European demand. An architecture that looks robust on paper can deliver very different experiences depending on where the viewer is.</p>



<p class="wp-block-paragraph">The reason is simple: physical distance still matters. Every extra hop between the viewer and the content adds latency, making it harder to deliver a consistent experience at global scale.</p>



<p class="wp-block-paragraph">Then there is the timing question. The decisions that determine whether a platform holds during the most-watched minutes of the year are not made on event day. They are made months earlier through choices around architecture, redundancy, testing, and operational readiness.</p>



<p class="wp-block-paragraph">Once an event is underway, it’s too late to redesign the architecture behind it. If your system isn’t designed to handle the pressure before the crowd arrives, it’s already too late.</p>



<h3 class="wp-block-heading"><strong>The hidden chain behind every live event</strong></h3>



<p class="wp-block-paragraph">When a streaming disruption becomes public, people naturally look for a single point of failure: the app, the platform, or the provider.</p>



<p class="wp-block-paragraph">A live event depends on dozens of systems working together, and any one of them can become a problem.</p>



<p class="wp-block-paragraph">And the experience is only as good as the weakest handoff between them.</p>



<p class="wp-block-paragraph">It all starts with the live camera feed moving from the venue to the production studio. This is a real-time stream, not a file download. If you drop even a single packet at the wrong moment, everything down the line breaks, no matter how perfect the rest of your setup is.</p>



<p class="wp-block-paragraph">Remote and cloud-based production workflows have redefined how live sports are produced, enabling broadcasters to operate with greater agility and scale. As production becomes more distributed, success increasingly depends on ensuring every stage of the delivery chain works together seamlessly.</p>



<p class="wp-block-paragraph">Each transition is a potential failure point. Managing them requires visibility that extends across providers, platforms, and networks simultaneously.</p>



<p class="wp-block-paragraph">Behind every live stream, technologies like encoding, transcoding, packaging, rights management, and ad insertion are constantly at work. If any one of them fails, the stream can go down altogether.</p>



<p class="wp-block-paragraph">Global distribution introduces another layer of complexity. Viewers in Asia, Africa, and South America may all be watching the same match, but each stream travels across different networks and infrastructure. That means performance can vary by region, and issues may affect one audience without impacting another. </p>



<p class="wp-block-paragraph">AI is increasingly helping operators detect anomalies in real time, pinpoint affected regions and trigger corrective actions before disruptions become widespread. Combined with point-to-point monitoring, it provides the visibility needed to keep live events running smoothly at global scale.</p>



<p class="wp-block-paragraph">Edge delivery is where the difference between preparation and improvisation becomes most apparent. Bringing content closer to users reduces latency, absorbs local traffic surges, and improves performance in markets with variable connectivity. </p>



<p class="wp-block-paragraph">The value of technology investments such as AI and Edge becomes clearest during the moments when demand is highest.</p>



<p class="wp-block-paragraph">Monitoring is what turns visibility into action. With AI helping analyze telemetry and detect anomalies in real time, operations teams can identify issues sooner and respond before they affect viewers. By the time customers start reporting a problem, the opportunity to prevent it has already passed.</p>



<h3 class="wp-block-heading"><strong>What reliability is actually worth</strong></h3>



<p class="wp-block-paragraph">For most of early broadcast history, audience tolerance provided some buffer. Disruptions happened. People accepted them. There was nowhere else to go, and the story rarely escaped the room.</p>



<p class="wp-block-paragraph">Neither of those things is true now.</p>



<p class="wp-block-paragraph">A streaming failure during a major match becomes public within seconds. Viewers don’t distinguish between a network issue, a processing failure, or a distribution problem; they simply see a service that failed. That single experience can shape the broadcaster’s reputation, credibility and customer loyalty, influencing whether viewers come back for the next event or recommend the service to others.</p>



<p class="wp-block-paragraph">The commercial implications are significant. Global tournaments such as the FIFA World Cup illustrate just how valuable live sports rights have become. Their return depends on reliably reaching the audience that was promised.</p>



<p class="wp-block-paragraph">Advertisers invest in live sport for one reason: to reach a large, engaged audience at the exact moment it matters most. If the stream fails during that window, the opportunity is lost. Those viewers, impressions, and advertising value cannot be recovered once the moment has passed.</p>



<p class="wp-block-paragraph">The same principle increasingly applies outside media. Customers rarely know nor care whether an outage originated in the application, the cloud environment, the network or a third-party dependency. They experience a failure of the brand. In a digital-first economy, reliability has become part of the customer experience itself.</p>



<p class="wp-block-paragraph">For broadcasters and streamers, reliability is no longer just an operational KPI. It directly influences audience trust, advertising revenue, and the long-term value of premium sports rights.</p>



<h3 class="wp-block-heading"><strong>The demands ahead are bigger</strong></h3>



<p class="wp-block-paragraph">AI-assisted production is already changing how live events are created. Broadcasters are using AI to automate highlight generation, camera selection and real-time clip packaging for social media, with new AI-assisted workflows producing sports highlights up to <a href="https://www.statsperform.com/insights/opta-pulse-launch/">80% faster</a> than traditional methods. </p>



<p class="wp-block-paragraph">All of this processing happens within the live delivery chain, where every additional task must be completed without adding latency or compromising the viewing experience.</p>



<p class="wp-block-paragraph">Personalisation at scale is the next significant challenge. Not personalisation in a vague sense, but the specific technical reality of delivering multi-language commentary tracks, different languages, different statistical overlays, and different camera angles to different viewers watching the same event simultaneously. </p>



<p class="wp-block-paragraph">Instead of one stream per event, the infrastructure has to manage a matrix of concurrent variants, each with its own encoding, storage, and delivery requirements. </p>



<p class="wp-block-paragraph">Interactive experiences add bidirectional data flows: real-time polls, integrated second-screen data, live wagering. These move data from the viewer back through infrastructure that was primarily built to push content outward. Managing that at scale is a different engineering problem from managing delivery.</p>



<p class="wp-block-paragraph">Higher-resolution formats (4K now becoming a standard expectation in premium markets, 8K moving into early deployment) are bandwidth-intensive at exactly the scale where bandwidth is already under pressure. Consumer devices are ready. Infrastructure in many high-growth markets is not uniformly there yet.</p>



<p class="wp-block-paragraph">Many of these capabilities are already being deployed for major global sporting events. The organisations investing seriously in technology, innovation, and infrastructure now are building toward a standard that will be the baseline requirement within a few years. Those that are not will be closing the gap under the worst possible conditions.</p>



<h3 class="wp-block-heading"><strong>The technology you never think about</strong></h3>



<p class="wp-block-paragraph">The broadcasters that succeed don’t leave reliability to chance. They plan for it from the outset, designing their infrastructure to handle peak demand long before the audience arrives.</p>



<p class="wp-block-paragraph">This reality hits hardest during massive global events. When a stream glitches, millions of people feel it simultaneously in a matter of seconds. Keeping those streams alive doesn’t happen by accident; it takes massive scale, intense discipline, and deep experience controlling everything from the stadium camera to the viewer’s screen.</p>



<p class="wp-block-paragraph">The lesson extends well beyond live sports. Every enterprise is becoming a real-time digital business, whether it’s delivering AI-powered applications, launching digital products, processing financial transactions, or handling a sudden surge in customer demand. Different industries may face different triggers, but the expectation is the same: the experience has to work, even when demand is at its highest.</p>



<p class="wp-block-paragraph">Delivering that level of reliability is why many of the world’s largest sports brands rely on <a href="https://www.tatacommunications.com/media-entertainment">Tata Communications</a>. Supporting the broadcast, production, and management of 80% of the world’s sporting events, and reaching more than two billion viewers across 190+ countries, Tata Communications operates in the invisible layers that make every live moment possible. We call this the “Virtual Stadium of the World”, the technology and infrastructure that connects fans, broadcasters, rights-holders, and sporting moments at a truly global scale.</p>



<p class="wp-block-paragraph">By managing the critical handoffs across contribution networks, edge processing, and global media infrastructure, we engineer the resilience required to keep 120,000 live events running flawlessly every year.</p>



<p class="wp-block-paragraph">Live sport may be the most visible test of digital infrastructure, but it won’t be the last. As AI, personalisation and real-time experiences become the norm across industries, the ability to deliver reliably at scale will define far more than match day.</p>



<p class="wp-block-paragraph">To learn more, visit us <a href="https://www.tatacommunications.com/sports?utm_source=blog&amp;utm_medium=cio&amp;utm_campaign=mes%20fifa%20campaign">here</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent vs. OpenClaw: Open-Source-KI-Agenten im Vergleich]]></title>
<description><![CDATA[Hermes Agent und OpenClaw zeigen zwei unterschiedliche Wege, wie autonome KI-Agenten eingesetzt werden können: als lernende Entwicklerplattform oder als persönlicher Produktivitätsassistent. In diesem Vergleich erklären wir Architektur, Funktionen, Deployment und Zielgruppen von Hermes vs. OpenCl...]]></description>
<link>https://tsecurity.de/de/3681407/server/hermes-agent-vs-openclaw-open-source-ki-agenten-im-vergleich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681407/server/hermes-agent-vs-openclaw-open-source-ki-agenten-im-vergleich/</guid>
<pubDate>Mon, 20 Jul 2026 16:45:32 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/Hermes_Agent_vs._OpenClaw.png" width="1698" height="926" alt=""><br>Hermes Agent und OpenClaw zeigen zwei unterschiedliche Wege, wie autonome KI-Agenten eingesetzt werden können: als lernende Entwicklerplattform oder als persönlicher Produktivitätsassistent. In diesem Vergleich erklären wir Architektur, Funktionen, Deployment und Zielgruppen von Hermes vs. OpenClaw und helfen Ihnen, das passende Open-Source-Framework für Ihre Anforderungen auszuwählen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple could ‘run the table’ on AI if it does things right]]></title>
<description><![CDATA[Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.



Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to hel...]]></description>
<link>https://tsecurity.de/de/3681267/it-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681267/it-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</guid>
<pubDate>Mon, 20 Jul 2026 15:33:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.</p>



<p class="wp-block-paragraph">Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to help users get things done through Siri AI.</p>



<p class="wp-block-paragraph">Apple also <a href="https://www.macobserver.com/news/apple-calls-its-new-assistant-siri-ai-at-wwdc-2026-gemini-partnership-now-official/" target="_blank" rel="noreferrer noopener">offers limited capacity for more complex tasks</a> through <a href="https://www.applemust.com/apple-commences-us-manufacturing-of-private-cloud-compute-servers/" target="_blank" rel="noreferrer noopener">Private Cloud Compute</a>, and, in partnership with the likes of Google in the US and Alibaba in China, the company is giving users a trusted conduit through which to access even more sophisticated AI services. </p>



<h2 class="wp-block-heading"><strong>Deeply deployable</strong></h2>



<p class="wp-block-paragraph">Critics can say it <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">took Apple a long time</a> to get to this point, but they also seem to think the company has finally got the mix right with its series 27 operating systems. Arriving late to a party <a href="https://www.computerworld.com/article/4164979/apple-will-be-behind-on-ai-until-it-isnt.html">doesn’t mean you won’t shine once you get there</a>.</p>



<p class="wp-block-paragraph">Apple is also coming up the inside lane around frontier AI, with iterative OS and hardware enhancements that mean its devices become increasingly effective for <a href="https://www.computerworld.com/article/4016798/why-i-hope-apple-keeps-investing-in-on-device-ai.html">Edge AI use cases</a>, on device — no cloud service required.</p>



<p class="wp-block-paragraph">The company appears to be digging down into those use cases. Mark Gurman at Bloomberg recently predicted that <a href="https://www.tomshardware.com/tech-industry/semiconductors/apples-rumored-m7-ultra-targets-1-5tb-of-memory-and-blackwell-class-ai" target="_blank" rel="noreferrer noopener">future M7 Ultra Macs</a> will support as much as 1.5TB RAM, making these systems more than capable of running full weight frontier models in people’s offices, colleges, and homes. </p>



<p class="wp-block-paragraph">While that does assume the <a href="https://www.computerworld.com/article/4187825/the-trillion-dollar-ai-hallucination.html">AI-flationary memory market</a> can supply that much RAM at prices humans can afford, it is also true that people are already <a href="https://www.computerworld.com/article/4092162/apples-macos-ai-for-the-rest-of-us.html">running AI clusters</a> using off-the-shelf Mac minis networked over Thunderbolt cables. It’s no stretch to believe <a href="https://www.applemust.com/macweb-now-offers-mac-mini-cloud-clusters-in-east-coast-data-centre/" target="_blank" rel="noreferrer noopener">this will continue to be the case</a>, and that it will even broaden as the power/performance offered at the high end grows.</p>



<h2 class="wp-block-heading"><strong>What’s wrong with good enough?</strong></h2>



<p class="wp-block-paragraph">When combined with open AI stacks, particularly newly emerging varieties, Apple’s platforms should become leading contenders for <a href="https://www.computerworld.com/article/4074648/apples-big-bang-ai-moment-is-approaching.html">private AI services</a> and edge AI. Many business users will leap at the chance to offer their workers powerful, self-hosted, private AI services using one or more daisy-chained Mac Studios or Mac minis. The recent craze in deployment of both Macs to support <a href="https://openclaw.ai/" target="_blank" rel="noreferrer noopener">OpenClaw</a> instances shows they already are.</p>



<p class="wp-block-paragraph">Ultimately, these different slices of momentum mean I agree with <a href="https://podcastalpha.substack.com/p/all-in-can-ai-regulate-itself-stripe" target="_blank" rel="noreferrer noopener">investor Jason Calacanis</a> that Apple is in position to apply a great deal of pressure on OpenAI and Claude just by putting models on their devices. </p>



<p class="wp-block-paragraph">It’s also worth thinking about how people use AI today. How many of the queries made in the world right now constitute relatively simple tasks that could be transacted by on-device AI, such as the emerging new version of Apple Intelligence or even smaller LLM models running on device? You can even run <a href="https://9to5mac.com/2026/07/14/prismml-releases-bonsai-27b-claiming-first-major-ai-model-of-its-size-fit-for-iphone/" target="_blank" rel="noreferrer noopener">PrismML’s 1-bit, 27-billion parameter Bonsai</a> on an iPad using the Locally app, and that’s in the here and now.</p>



<p class="wp-block-paragraph">What happens? Pretty soon you’ll find people recognize that they can already run the vast majority of their AI-augmented workflows using services they <a href="https://www.applemust.com/morgan-stanley-its-when-not-if-apple-will-deliver-ai-on-the-edge/" target="_blank" rel="noreferrer noopener">have on their existing device</a> or can access on their on-prem Mac set-ups. And, of course, as people get used to running small tasks locally and larger tasks on premises, the actual space in which they need to turn to cloud-based frontier models <a href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html">will erode</a>. That’s even as companies like PrismML work towards slimming down full-weight models so they don’t need to run on a server at all. </p>



<p class="wp-block-paragraph">“It’s going to be wild when people have unlimited tokens on their desks,” said Calacanis in a podcast round table discussion.</p>



<h2 class="wp-block-heading"><strong>Who has the most to lose?</strong></h2>



<p class="wp-block-paragraph">The current incarnations of AI felt like they came from nowhere. Most people weren’t aware of the technology until returning to work after the 2022 holiday season. Since then, the industry has proliferated with dozens of competing models, most recently including powerful but affordable frontier models such as Qwen and Kimi.ai.</p>



<p class="wp-block-paragraph">These models aren’t necessarily all as good as one another, but in many cases for much of what we do, we’ll find them to be good enough. That’s an existential crisis for some, as industry observers now think the inevitable pricing pressure means some services might have over-invested in capacity before finding any way to turn a profit.</p>



<p class="wp-block-paragraph">Those profit-seeking services are the ones with the most to lose as Apple extends its hardware advantage, democratizing AI access for all while providing platforms suitable for edge AI, on-premises AI, private AI, and even AI access using third-party services. (The need for the latter will shrink as the capabilities of the former get better.)</p>



<h2 class="wp-block-heading"><strong>Cupertino rising</strong></h2>



<p class="wp-block-paragraph">What does this all mean? While the industry remains young, it is already fragmenting. And striding through the dust of that process comes Apple, equipped with the hardware, software, and approach to build its business even as the enterprise of first mover AI services erodes. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: Why boutique consultancies might be better for AI rollouts than the bigwigs]]></title>
<description><![CDATA[Major AI labs are unleashing forward-deployed engineers (FDEs) to try and grab enterprise customers. Large consultancies are dishing out tokens and assembling armies of consultants — both human and agent — to do the same.



But smaller firms are in the mix now, as well. AI is helping 28Stone Con...]]></description>
<link>https://tsecurity.de/de/3680996/it-nachrichten/qa-why-boutique-consultancies-might-be-better-for-ai-rollouts-than-the-bigwigs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680996/it-nachrichten/qa-why-boutique-consultancies-might-be-better-for-ai-rollouts-than-the-bigwigs/</guid>
<pubDate>Mon, 20 Jul 2026 13:33:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Major AI labs are <a href="https://www.computerworld.com/article/4171867/heres-one-career-emerging-from-the-ai-shift-forward-deployed-engineers.html">unleashing forward-deployed engineers</a> (FDEs) to try and grab enterprise customers. Large consultancies are dishing out tokens and assembling armies of consultants — both human and agent — to do the same.</p>



<p class="wp-block-paragraph">But smaller firms are in the mix now, as well. AI is helping <a href="https://www.28stone.com/" target="_blank" rel="noreferrer noopener">28Stone Consulting</a>, a New York-based, 230-person technology consultancy for capital markets, punch above its weight against larger rivals in the <a href="https://www.computerworld.com/article/4180088/ai-vendor-fdes-key-considerations-and-concerns.html">rush to deliver FDEs</a>.</p>



<p class="wp-block-paragraph">In this Q&amp;A, <a href="https://www.linkedin.com/in/thomas-dolan-4124914" target="_blank" rel="noreferrer noopener">Thomas Dolan</a> and <a href="https://www.linkedin.com/in/frank-erickson-07675a1" target="_blank" rel="noreferrer noopener">Frank Erickson</a>, founders of 28Stone, argue that agentic AI isn’t a one-size-fits-all solution in vertical markets; success takes discipline, deep domain expertise, and human involvement to mitigate risk.</p>



<p class="wp-block-paragraph">Many enterprises continue to struggle with the use of AI agents, which is consultancies are stepping in to get projects off the ground. 28Stone is among those that have published blueprints and methodologies on the development and delivery of agentic AI workflows with humans in the loop.</p>



<p class="wp-block-paragraph"><em>Computerworld</em> spoke with both founding partners about why companies are still stumbling with <a href="https://www.computerworld.com/article/4083589/from-chatbots-to-colleagues-how-agentic-ai-is-redefining-enterprise-automation.html">agentic AI rollouts</a>, and what a disciplined delivery process actually looks like.</p>



<p class="wp-block-paragraph"><strong>After 15 years of delivering software for capital markets firms, is ‘AI-first’ a real distinction or just positioning?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “We’re not shying away from being AI-forward. What needs to shine through is AI done intelligently — not stuff you get by buying some tokens for somebody on the trading desk. We’re an AI-first firm.”</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “And it’s temporary. At some point, AI is going to be synonymous with software development.</p>



<p class="wp-block-paragraph">“The whole idea of an AI SDLC (software development lifecycle) versus an SDLC is going to be one and the same, a lot like cloud computing today. To not include AI in your strategy, you’d look like a COBOL vendor.”</p>



<p class="wp-block-paragraph"><strong>What does agentic AI delivery look like?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “We’ve got several AI initiatives delivering a pure agentic approach. We’ve doubled down on the human expertise wrapper in the SDLC. That doesn’t mean sacrificing any of the benefits of the AI models — quite the opposite.</p>



<p class="wp-block-paragraph">“You don’t achieve anywhere near the same level of value from applying AI without keeping that expertise — industry, functional and technical — throughout the process.”</p>



<p class="wp-block-paragraph"><strong>Where do humans stay in the loop once agents are doing the work?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “We’re believers in starting with requirements discovery. Someone who knows the analytical nuances of a good business analyst is critically important; shaping a product owner’s business information through a markup file that can be fed into a BA agent, then treating the output as if it came from a very fast junior BA. Only then is the story complete.</p>



<p class="wp-block-paragraph">“The developer takes that story, transforms it into the most efficient input, then owns the output, because they’re accountable for that code. A developer should own the code on both the input and output side.</p>



<p class="wp-block-paragraph">“Your product owner, who knows the business, that’s great. But expecting them to interact with an agent and output enterprise code is ridiculous. It’s not a great plan.“</p>



<p class="wp-block-paragraph"><strong>Why not just put one do-everything person in charge of AI and agents?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “Every analyst, programmer or software engineer isn’t a great requirements analyst. And a great domain analyst with some technical background won’t know if the agent’s code is garbage, maintainable, performant.</p>



<p class="wp-block-paragraph">“It’s unrealistic to expect one individual to have that breadth across domain, software engineering, testing, deployment. Clients ask all the time, and we push back: ‘Great, if you can find that guy, they’re few and far between.’ To deliver at the enterprise level, you need the human expertise, at depth.“</p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “There’s system speed and latency, important in parts of finance. Then there’s speed of delivery, because other areas evolve quickly and time-to-market is critical.</p>



<p class="wp-block-paragraph">“Our human wrapper may at first pass come across as a little slowed down. Maybe it is. But [Erickson] has a good analogy about one of the dangers of AI: you can end up going really fast in the wrong direction. By the time you look up, you’re way off base and have to backtrack.“</p>



<p class="wp-block-paragraph"><strong>What about AI in your sector do you think is overhyped?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “The hype around the ease of use of AI and the democratization of enterprise software delivery — that ‘anybody could do it now, it’s all being done by machines’ — is another idea that could prove costly in the long run.</p>



<p class="wp-block-paragraph">“This do-it-yourself reaction is dangerous for clients, and for trust in the overall AI benefit, which is real. We compare it to the beginning of offshoring 20, 30 years ago: a golden idea that was going to cure everything. A lot of firms did it thoughtlessly, thinking it’s just labor arbitrage, and it almost inevitably failed. That all-or-nothing mentality missed that offshoring is an amazing way of getting better value for your dollar, but it has to be done thoughtfully, so the delivery process — the thing that ties it all together — stays unsevered.</p>



<p class="wp-block-paragraph">“We’re seeing that now. I’ve heard, ‘We’ll just push a button, the machine’s building the system.’ The machine is not building the system. It might be writing the code, the story, running the tests.</p>



<p class="wp-block-paragraph">The system is built by a team of engineers you bring in and trust. My fear is that people will say, ‘We don’t need this vendor or this technology team. I’ve got a product team. They might not be able to code at all, but they know the business,’ and it fails dramatically. </p>



<p class="wp-block-paragraph">“Then people say, ‘We played with AI, it’s not ready yet,’ and throw it all away. One of the best things we can do is ensure clients know the benefit is real.“</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “The hype can be summed up in a single phrase: <a href="https://www.computerworld.com/article/4022711/when-everything-is-vibing.html">vibe coding</a>. That has done AI a massive disservice, because there’s a huge difference between vibe coding and enterprise software development, and some of the loudest proponents of AI are too latched on to it. In our industry, the only way to succeed would be a stable of unicorns. It just doesn’t scale. I get perturbed when our people internally refer to AI tooling as vibe coding; if they think that’s what they’re doing, they’re misunderstood.“</p>



<p class="wp-block-paragraph"><strong>When you engage clients at different levels of AI maturity, how do you get them to a understand what works?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “95% of our take on an agentic approach is in line with everyone else’s, but that 5% matters, especially in requirements discovery, in who’s giving the requirements and how they’re thought of. It can set you up for dramatic errors, given the speed at which you’re moving.</p>



<p class="wp-block-paragraph">“There’s a dangerous human tendency we’re seeing among clients to try and cut corners at the start of a project and — in lieu of having deep, expert driven discovery sessions — just summarize what they may want using AI.</p>



<p class="wp-block-paragraph">“We would hope our clients are collaborative, everyone understanding it’s early days. If a client insists on doing something we feel strongly against, like a product owner completely owning everything right up to code generation, that’s an issue we have to either push back strongly on or step out of the accountability for.“</p>



<p class="wp-block-paragraph"><strong>AI body shops — LLM providers and giant consultancies — are emerging to help enterprises deploy AI. Does that model work?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “Whether you’re partnering with an LLM or with an AI-first, generic software provider — ‘Hey, we’re not industry guys, but we know AI delivery’ — you end up, if you’re a bank or a broker-dealer, saying: ‘All right, we know our business, these guys know the AI side of it. What could go wrong? Put us together and we’ll have quality engineering.’</p>



<p class="wp-block-paragraph">“The problem is what you miss: the know-how of putting industry and technical expertise together and actually delivering financial services systems. The people working at the generic delivery firms, whether an AI-only firm or a body shop somewhere, don’t have that capability.“</p>



<p class="wp-block-paragraph"><strong>Does AI change the economics for smaller consultancies like yours competing against the big firms, and does it cut both ways?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “Over our 15 years pre-AI, there were two recurring reasons we’d lose a project. One: ‘We’d love to work with you guys, given your subject matter expertise, but the costs just aren’t there compared to my budgets. I’m being forced to go to a body shop or an [offshore] delivery center.’ The other side of that coin: ‘We love your capabilities, but you’re a firm of 230 people and I need 300, 400 people.’</p>



<p class="wp-block-paragraph">“AI changes the options for clients. You don’t have to sacrifice the niche vendor who knows your space just because you need a larger team or a cost target. AI levels the playing field and should allow smaller firms to compete with the larger, big-box generic firms, the Accentures of the world.“</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “It redefines what scale means. You can look at velocity as a measure of your cost to deliver, not a rate card. Scale can’t be defined in terms of headcount anymore. It’s got to be defined in terms of output.</p>



<p class="wp-block-paragraph">“There’s a threat in it, too. If you’re an Accenture with hundreds of thousands of low-cost software engineers, how do you train all those people? I feel for them. But for us, a couple hundred people with a specific domain focus, it’s a huge opportunity.“</p>



<p class="wp-block-paragraph"><strong>How has the profile of the people you and others hire changed with this agentic process?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “You’re still looking for people with strong engineering and design backgrounds, and communication skills, because they interact across the software development lifecycle more than in the past.</p>



<p class="wp-block-paragraph">“Many take too much joy in typing out perfect code. Sorry, I don’t need you writing for-loops and classes anymore. I need you reviewing them, understanding them, operating at a higher level. That’s a different kind of person: an engineer, not a programmer or a coder. On the [business analyst] side it’s similar: people took great pride in detailed user stories covering every path. Now it’s conversations, prompts, reviewing output — less doing, more interacting.</p>



<p class="wp-block-paragraph">“More than ever, they have to be interested in the domain. They can’t just be, ‘I want to learn everything there is to know about Java.’ That’s too narrow. They don’t have to be an expert; they have to be interested. In our case, capital markets is a specific niche. The biggest challenge is getting familiar with the tools — finding time, while delivering for customers, to ramp up and make the mistakes you need to without jeopardizing projects.“</p>



<p class="wp-block-paragraph"><strong>What about governance? Who’s keeping AI delivery and its costs under control?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “This is evolving rapidly. People aren’t sure how to put governance around this. The most obvious is financial governance. People are starting to get hefty bills. One of our clients spent a million dollars on tokens over the last eight weeks alone. Sticker shock. The token-maxing policies are starting to show their flaws. It’s wild west still: learn on the fly, then figure out what needs to be governed.“</p>



<p class="wp-block-paragraph"><strong>Are CIOs actually opening their wallets? And when they do, what’s the smarter way to invest?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “There’s still a lot of caution. Forecasts keep going down on how long something should take. So: ‘I could wait three months and maybe still get it delivered by the same date someone’s promising me now, but for half the price. I’m going to wait and see when equilibrium is met.’ We haven’t seen the wallets open up like crazy — it’s slow adoption.“</p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “One of our clients is looking at it from a productivity-boost perspective: instead of doing the same for less, I can do much more for the same. AI lets clients pull the trigger on things they wouldn’t have in the past — projects that might not have been approved pre-AI, where the costs have come down to a point that’s palatable with the business.“</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “And that’s the story we’re hoping to hear more of. There isn’t a huge cost anymore to exploring a business opportunity. The time and money that would have gone to a return-on-investment study could be spent on a proof-of-concept with AI, and the project done a few weeks later. Maybe [there’s] a hint of things to come, where decisions start being made quicker. </p>



<p class="wp-block-paragraph">“There’s a little fear on our side, though: a lot of tiny little projects is tough for a consulting business.“</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OPINION: Xbox's mixed messaging on exclusive games isn't encouraging — only the big guns will move the needle for the platform]]></title>
<description><![CDATA[Xbox's C-suite doesn't seem terribly committed to big exclusives for console. Only the heavy hitters will make a difference; otherwise, it'll be pointless.]]></description>
<link>https://tsecurity.de/de/3680857/windows-tipps/opinion-xboxs-mixed-messaging-on-exclusive-games-isnt-encouraging-only-the-big-guns-will-move-the-needle-for-the-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680857/windows-tipps/opinion-xboxs-mixed-messaging-on-exclusive-games-isnt-encouraging-only-the-big-guns-will-move-the-needle-for-the-platform/</guid>
<pubDate>Mon, 20 Jul 2026 12:26:53 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Xbox's C-suite doesn't seem terribly committed to big exclusives for console. Only the heavy hitters will make a difference; otherwise, it'll be pointless.]]></content:encoded>
</item>
<item>
<title><![CDATA[The audit trail CIOs need before the next cyber crisis]]></title>
<description><![CDATA[In one ransomware response I observed, the master operational dashboard remained green while the underlying environment told a very different story. It was a classic example of what we in the IT audit profession call the “watermelon effect”—green on the outside, red on the inside.



Beneath that...]]></description>
<link>https://tsecurity.de/de/3680143/it-security-nachrichten/the-audit-trail-cios-need-before-the-next-cyber-crisis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680143/it-security-nachrichten/the-audit-trail-cios-need-before-the-next-cyber-crisis/</guid>
<pubDate>Mon, 20 Jul 2026 02:13:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In one ransomware response I observed, the master operational dashboard remained green while the underlying environment told a very different story. It was a classic example of what we in the IT audit profession call the “watermelon effect”—green on the outside, red on the inside.</p>



<p class="wp-block-paragraph">Beneath that dashboard sat an unmapped web of legacy technical debt, undocumented service accounts and shadow cloud instances. For years, presenting a green dashboard to the audit committee could give technology leaders a false sense of comfort. If a catastrophic breach occurred, it was generally treated as an unpredictable operational tragedy, managed via cyber insurance, a carefully calibrated public relations pivot and perhaps a quiet executive transition.</p>



<p class="wp-block-paragraph">Today, that corporate shield is thinner than many technology leaders assume. For technology leaders in regulated or public-company environments, executive exposure is no longer only a theoretical debate. The regulatory environment has made plausible deniability much harder to sustain.</p>



<h2 class="wp-block-heading">The erosion of the corporate shield</h2>



<p class="wp-block-paragraph">With the application of the European Union’s <a href="https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en">Digital Operational Resilience Act (DORA)</a> for financial entities, alongside the broader <a href="https://digital-strategy.ec.europa.eu/en/policies/nis2-directive">NIS2 Directive</a> for essential and important entities, cybersecurity governance has become harder to separate from board-level oversight. DORA places ultimate responsibility for ICT risk management on the management body of financial entities, while NIS2 requires management bodies to approve and oversee cybersecurity risk-management measures. In the United States, the <a href="https://www.sec.gov/newsroom/press-releases/2023-139">U.S. Securities and Exchange Commission’s cybersecurity disclosure rules</a> require public companies to disclose material cyber incidents and describe their cyber risk management, strategy and governance in annual filings. The new burden is not simply to operate controls; it is to show, after the fact, that leadership decisions matched the risk evidence available at the time.</p>



<p class="wp-block-paragraph">The serious risk to a modern CIO is not simply the occurrence of a sophisticated security incident. The true danger is the inability to reconcile what leadership presented externally to investors, regulators and the board with what the internal evidence showed inside the environment.</p>



<p class="wp-block-paragraph">When a serious crisis breaks, you may find yourself surrounded by corporate defense counsel, regulatory investigators and outside forensic lawyers all asking variations of the same uncomfortable questions: What did you know, when did you discover it and what specific actions did you take next?</p>



<p class="wp-block-paragraph">When those questions are asked, a slide deck asserting that your security posture is “aligned with industry best practices” will not be enough. A post-incident review may recognize that sophisticated attacks occur. What creates greater exposure is evidence that known risks were ignored, understated or left outside structured governance. To survive that level of post-incident review, one of your strongest assets is a disciplined, independent evidence trail showing that risks were identified, challenged, escalated and acted on before the first indicator of compromise appeared.</p>



<h2 class="wp-block-heading">Why point-in-time comfort letters fail regulatory scrutiny</h2>



<p class="wp-block-paragraph">The reality we face is that legacy compliance evidence often falls short under regulatory scrutiny. For years, the annual SOC 2 Type II report or a standardized ISO 27001 certification was brandished by technology teams as the definitive proof of a functional control environment. I have sat in dozens of scoping meetings where an engineering director pointed to a freshly minted compliance report as if it were a complete defense against scrutiny.</p>



<p class="wp-block-paragraph">But a compliance report is a historical artifact—a retrospective evaluation of how specific controls operated during a defined window of time months in the past. It tells an investigator that on a random afternoon in Q2, your production change-management approvals conformed to a baseline policy. It says absolutely nothing about the configuration drift, unauthorized API keys or emergency patch bypasses that developers introduced the following weekend to hit a product release deadline.</p>



<p class="wp-block-paragraph">Modern regulators, boards and investors are no longer satisfied by historical comfort letters alone. Under contemporary frameworks, especially regimes focused on operational resilience, static compliance evidence is no longer enough. The expectation of due care has shifted from a passive state of compliance to an active state of continuous challenge. Increasingly, post-incident reviews look for evidence that leadership identified system vulnerabilities, formally escalated material deficiencies, evaluated systemic risk to the business and tracked remediation progress with measurable rigor.</p>



<p class="wp-block-paragraph">When an architecture fails, post-incident reviews often focus quickly on ownership, escalation and whether known risks were acted upon. If your defensive documentation consists entirely of static policy documents and green dashboards, you leave an evidentiary vacuum that can invite difficult questions about executive oversight. Post-incident reviews rarely turn on perfection. They turn on whether the organization can show a traceable chain of governance.</p>



<h2 class="wp-block-heading">5 non-negotiable artifacts for your executive evidence engine</h2>



<p class="wp-block-paragraph">This reality requires a complete reframing of your relationship with your IT audit department. Historically, this dynamic has been defined by friction. Technology leaders frequently view my peers and me as compliance traffic cops—bureaucrats who interrupt core engineering sprints to demand evidence samples, user access reviews and system configurations.</p>



<p class="wp-block-paragraph">It is time to view IT audit through a pragmatic lens: we are your independent evidence engine. We are one of the few corporate functions tasked with independently challenging your control environment, documenting where exceptions were escalated and showing how management responded. When an auditor identifies a control gap and partners with you to draft a management action plan, they are not creating a bureaucratic roadblock. They are helping you construct an evidence trail that can show risk was identified, escalated and acted upon.</p>



<p class="wp-block-paragraph">To transform your IT audit function into an effective executive shield, you must shift focus away from superficial check-the-box exercises and collaborate on specific artifacts. The most effective exercise you can run with your audit leadership is to flip the timeline completely and ask: if this program were reviewed six months from now, which evidence would show we governed the risk before it failed?</p>



<ol class="wp-block-list">
<li><strong>Board-facing risk registers with escalation history:</strong> A risk register that sits unreviewed on an intranet page for 12 months is not a management tool; to an investigator, it can look like evidence that known risks were not actively governed. Your material technology, cybersecurity and dependency risks must be centrally logged. More importantly, this artifact must contain a clear, chronological escalation history showing exactly when the risk was presented to leadership committees and the board, along with related minutes, decisions or follow-up actions.</li>



<li><strong>Granular risk acceptance records:</strong> You cannot remediate every vulnerability instantly. Business continuity, legacy software limitations and budgetary boundaries require you to accept certain operational exposures. When this occurs, ensure your risk acceptance records are airtight. A defensible record must document the specific technical variance, the precise financial or operational rationale for the delay, a definitive expiration date, explicit executive sign-off and the active compensating controls deployed to reduce the blast radius in the interim.</li>



<li><strong>Tabletop and operational simulation records:</strong> Independent frameworks such as <a href="https://www.isaca.org/digital-trust">ISACA’s Digital Trust Ecosystem Framework</a> can help structure this evidence, but boards and regulators will still look for proof that the testing actually happened. Your audit trail should contain comprehensive records of cyber incident, disaster recovery and third-party dependency simulations. These records must detail the scenario tested, the executive participants, the control failures identified during the drill and a formalized tracking schedule showing when those gaps were closed.</li>



<li><strong>AI governance inventories and data-flow mappings:</strong> The rapid deployment of generative AI tools across enterprise operations has created a massive blind spot for technology executives. In one audit, we found developers using an unapproved public large language model to accelerate debugging with sensitive internal code. To protect yourself, work with your audit team to build an active enterprise AI inventory that maps data lineage, identifies model business owners, documents risk classification approvals and demonstrates active technical monitoring for unauthorized data exfiltration.</li>



<li><strong>Synchronized disclosure-control handoffs:</strong> When a material security incident or system outage occurs, the clock begins ticking for regulatory reporting. Your incident response playbook must be technically linked to your corporate disclosure controls. The audit trail should show that a documented, synchronized handoff occurred between your technical response leaders, general counsel, chief financial officer and corporate communications team. This evidence helps show that your external statements match internal technical realities.</li>
</ol>



<p class="wp-block-paragraph">In the modern corporate ecosystem, technology leadership is no longer just an engineering challenge; it is an exercise in rigorous, evidence-based governance. The regulatory landscape has changed, and the expectation of continuous traceability cannot be avoided.</p>



<p class="wp-block-paragraph">Open and direct collaboration with your IT audit team will not prevent a zero-day exploit, an unexpected cloud outage or a critical third-party vendor failure. That is not the purpose of enterprise risk management.</p>



<p class="wp-block-paragraph">The true value is far more practical: when a serious incident puts your program under review, you will not be forced to defend your reputation with a feeling, an unverified assumption or a misleadingly green dashboard. Instead, you will have an independent record showing that risk was actively seen, appropriately challenged, properly escalated and responsibly managed. In today’s regulatory environment, that disciplined trail of evidence may be the difference between a failure that can be explained and one that begins to look negligent.</p>



<p class="wp-block-paragraph">.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Did a Robot Knit Your Jumper? (emf2026)]]></title>
<description><![CDATA[Machine knitting has grown in use and popularity over the past decade as domestic knitting machines have been rescued from dusty attics. Computerised knitting machines are now within reach for significantly less money than their older, more established industrial ancestors. But what makes an indu...]]></description>
<link>https://tsecurity.de/de/3679778/it-security-video/did-a-robot-knit-your-jumper-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679778/it-security-video/did-a-robot-knit-your-jumper-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 19:08:47 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Machine knitting has grown in use and popularity over the past decade as domestic knitting machines have been rescued from dusty attics. Computerised knitting machines are now within reach for significantly less money than their older, more established industrial ancestors. But what makes an industrial knitting machine different from one you could have at home? What does it mean for it to be computerised? What is the difference between a ‘fully fashioned garment’ versus a ‘complete garment’?

This talk will start with the fundamentals of how to knit a jumper and will walk through the industrial manufacturing history of knitting frames and machines, highlighting the mechanical engineering innovations that have allowed machines to move closer to replicating the agility of human hands knitting yarn. Did a robot knit your jumper? Probably not, but it is exciting to see how this technology is progressing and what it is enabling.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/203-did-a-robot-knit-your-jumper]]></content:encoded>
</item>
<item>
<title><![CDATA[What's in a number plate? (emf2026)]]></title>
<description><![CDATA[Why are Irish number plates so much longer than British ones, despite the population being much smaller? What letters can you use on a Greek number plate? How do you drive a Japanese-registered car abroad, when the number plate is full of kanji and kana? Why do some people give Belgian cars with ...]]></description>
<link>https://tsecurity.de/de/3679530/it-security-video/whats-in-a-number-plate-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679530/it-security-video/whats-in-a-number-plate-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 15:33:07 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Why are Irish number plates so much longer than British ones, despite the population being much smaller? What letters can you use on a Greek number plate? How do you drive a Japanese-registered car abroad, when the number plate is full of kanji and kana? Why do some people give Belgian cars with five-character plates a wide berth? Are those supercars with Arabic number plates you see in West London even legal?

I've always been a bit obsessed with vehicle registration plates. I like spotting the hidden information in them, but I also like seeing the decisions encoded in their formats, and how those have played out over time. Everywhere seems to have come up with its own solution to the same problem, they're all different, and seemingly innocuous decisions can have significant impacts later on.

These superficially trivial identifiers turn out to be much more than that, intersecting design, politics, information encoding, and even questions of identity. They're also, I hope to show, fun, and can make us all feel better about having to live with the consequences of bad choices we made in the past.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/48-whats-in-a-number-plate]]></content:encoded>
</item>
<item>
<title><![CDATA[What's in a number plate? (emf2026)]]></title>
<description><![CDATA[Why are Irish number plates so much longer than British ones, despite the population being much smaller? What letters can you use on a Greek number plate? How do you drive a Japanese-registered car abroad, when the number plate is full of kanji and kana? Why do some people give Belgian cars with ...]]></description>
<link>https://tsecurity.de/de/3679362/it-security-video/whats-in-a-number-plate-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679362/it-security-video/whats-in-a-number-plate-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 13:03:36 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Why are Irish number plates so much longer than British ones, despite the population being much smaller? What letters can you use on a Greek number plate? How do you drive a Japanese-registered car abroad, when the number plate is full of kanji and kana? Why do some people give Belgian cars with five-character plates a wide berth? Are those supercars with Arabic number plates you see in West London even legal?

I've always been a bit obsessed with vehicle registration plates. I like spotting the hidden information in them, but I also like seeing the decisions encoded in their formats, and how those have played out over time. Everywhere seems to have come up with its own solution to the same problem, they're all different, and seemingly innocuous decisions can have significant impacts later on.

These superficially trivial identifiers turn out to be much more than that, intersecting design, politics, information encoding, and even questions of identity. They're also, I hope to show, fun, and can make us all feel better about having to live with the consequences of bad choices we made in the past.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/48-whats-in-a-number-plate]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16198 | Sipeed PicoClaw up to 0.2.9 First Run Setup access_control.go allowed_cidrs authentication bypass (Issue 3080 / EUVD-2026-45409)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication...]]></description>
<link>https://tsecurity.de/de/3678812/sicherheitsluecken/cve-2026-16198-sipeed-picoclaw-up-to-029-first-run-setup-accesscontrolgo-allowedcidrs-authentication-bypass-issue-3080-euvd-2026-45409/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678812/sicherheitsluecken/cve-2026-16198-sipeed-picoclaw-up-to-029-first-run-setup-accesscontrolgo-allowedcidrs-authentication-bypass-issue-3080-euvd-2026-45409/</guid>
<pubDate>Sun, 19 Jul 2026 05:23:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/sipeed:picoclaw">Sipeed PicoClaw up to 0.2.9</a>. The impacted element is an unknown function of the file <em>web/backend/middleware/access_control.go</em> of the component <em>First Run Setup</em>. Performing a manipulation of the argument <em>allowed_cidrs</em> results in authentication bypass using alternate channel.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-16198">CVE-2026-16198</a>. The attack may be initiated remotely. In addition, an exploit is available.

Applying a patch is the recommended action to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16195 | Sipeed PicoClaw up to 0.2.9 Group Message wecom.go dispatchIncoming authorization (Issue 3076 / EUVD-2026-45406)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect authorization.

This vulnerability is ...]]></description>
<link>https://tsecurity.de/de/3678806/sicherheitsluecken/cve-2026-16195-sipeed-picoclaw-up-to-029-group-message-wecomgo-dispatchincoming-authorization-issue-3076-euvd-2026-45406/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678806/sicherheitsluecken/cve-2026-16195-sipeed-picoclaw-up-to-029-group-message-wecomgo-dispatchincoming-authorization-issue-3076-euvd-2026-45406/</guid>
<pubDate>Sun, 19 Jul 2026 05:23:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/sipeed:picoclaw">Sipeed PicoClaw up to 0.2.9</a>. This issue affects the function <code>dispatchIncoming</code> of the file <em>pkg/channels/wecom/wecom.go</em> of the component <em>Group Message Handler</em>. The manipulation results in incorrect authorization.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-16195">CVE-2026-16195</a>. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The reported GitHub issue was closed automatically due to inactivity.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16196 | Sipeed PicoClaw up to 0.2.9 web_fetch web.go isPrivateOrRestrictedIP server-side request forgery (Issue 3077 / EUVD-2026-45407)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. This manipulation causes server-side request forgery.

This vulnerability is handled as CV...]]></description>
<link>https://tsecurity.de/de/3678805/sicherheitsluecken/cve-2026-16196-sipeed-picoclaw-up-to-029-webfetch-webgo-isprivateorrestrictedip-server-side-request-forgery-issue-3077-euvd-2026-45407/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678805/sicherheitsluecken/cve-2026-16196-sipeed-picoclaw-up-to-029-webfetch-webgo-isprivateorrestrictedip-server-side-request-forgery-issue-3077-euvd-2026-45407/</guid>
<pubDate>Sun, 19 Jul 2026 05:23:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/sipeed:picoclaw">Sipeed PicoClaw up to 0.2.9</a>. Impacted is the function <code>isPrivateOrRestrictedIP</code> of the file <em>pkg/tools/integration/web.go</em> of the component <em>web_fetch</em>. This manipulation causes server-side request forgery.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-16196">CVE-2026-16196</a>. The attack can be initiated remotely. Additionally, an exploit exists.

To fix this issue, it is recommended to deploy a patch.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16197 | Sipeed PicoClaw up to 0.2.9 Group Message feishu_64.go handleMessageReceive authorization (Issue 3082 / EUVD-2026-45408)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation leads to missing authorization.

This vulnerability i...]]></description>
<link>https://tsecurity.de/de/3678804/sicherheitsluecken/cve-2026-16197-sipeed-picoclaw-up-to-029-group-message-feishu64go-handlemessagereceive-authorization-issue-3082-euvd-2026-45408/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678804/sicherheitsluecken/cve-2026-16197-sipeed-picoclaw-up-to-029-group-message-feishu64go-handlemessagereceive-authorization-issue-3082-euvd-2026-45408/</guid>
<pubDate>Sun, 19 Jul 2026 05:23:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/sipeed:picoclaw">Sipeed PicoClaw up to 0.2.9</a>. The affected element is the function <code>handleMessageReceive</code> of the file <em>pkg/channels/feishu/feishu_64.go</em> of the component <em>Group Message Handler</em>. Such manipulation leads to missing authorization.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-16197">CVE-2026-16197</a>. The attack can be launched remotely. Moreover, an exploit is present.

The reported GitHub issue was closed automatically due to inactivity.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.2-beta.3]]></title>
<description><![CDATA[OpenClaw 2026.7.2-beta.3]]></description>
<link>https://tsecurity.de/de/3678509/downloads/v202672-beta3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678509/downloads/v202672-beta3/</guid>
<pubDate>Sat, 18 Jul 2026 22:46:37 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.2-beta.3</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16085 | Sipeed PicoClaw up to 0.2.9 pkg/agent/context.go NewContextBuilder inclusion of functionality from untrusted control sphere (Issue 3075 / EUVD-2026-45368)]]></title>
<description><![CDATA[A vulnerability was found in Sipeed PicoClaw up to 0.2.9 and classified as problematic. Affected is the function NewContextBuilder of the file pkg/agent/context.go. Such manipulation leads to inclusion of functionality from untrusted control sphere.

This vulnerability is documented as CVE-2026-1...]]></description>
<link>https://tsecurity.de/de/3678084/sicherheitsluecken/cve-2026-16085-sipeed-picoclaw-up-to-029-pkgagentcontextgo-newcontextbuilder-inclusion-of-functionality-from-untrusted-control-sphere-issue-3075-euvd-2026-45368/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678084/sicherheitsluecken/cve-2026-16085-sipeed-picoclaw-up-to-029-pkgagentcontextgo-newcontextbuilder-inclusion-of-functionality-from-untrusted-control-sphere-issue-3075-euvd-2026-45368/</guid>
<pubDate>Sat, 18 Jul 2026 15:38:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/sipeed:picoclaw">Sipeed PicoClaw up to 0.2.9</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is the function <code>NewContextBuilder</code> of the file <em>pkg/agent/context.go</em>. Such manipulation leads to inclusion of functionality from untrusted control sphere.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-16085">CVE-2026-16085</a>. The attack needs to be performed locally. Additionally, an exploit exists.

The reported GitHub issue was closed automatically with the label "not planned" by a bot.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16084 | Sipeed PicoClaw up to 0.2.9 web.go web_fetch server-side request forgery (Issue 3074 / EUVD-2026-45367)]]></title>
<description><![CDATA[A vulnerability has been found in Sipeed PicoClaw up to 0.2.9 and classified as critical. This impacts the function web_fetch of the file pkg/tools/integration/web.go. This manipulation causes server-side request forgery.

This vulnerability is registered as CVE-2026-16084. Remote exploitation of...]]></description>
<link>https://tsecurity.de/de/3678080/sicherheitsluecken/cve-2026-16084-sipeed-picoclaw-up-to-029-webgo-webfetch-server-side-request-forgery-issue-3074-euvd-2026-45367/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678080/sicherheitsluecken/cve-2026-16084-sipeed-picoclaw-up-to-029-webgo-webfetch-server-side-request-forgery-issue-3074-euvd-2026-45367/</guid>
<pubDate>Sat, 18 Jul 2026 15:38:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/sipeed:picoclaw">Sipeed PicoClaw up to 0.2.9</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts the function <code>web_fetch</code> of the file <em>pkg/tools/integration/web.go</em>. This manipulation causes server-side request forgery.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-16084">CVE-2026-16084</a>. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

To fix this issue, it is recommended to deploy a patch.]]></content:encoded>
</item>
<item>
<title><![CDATA[I make things in schools, you can too (emf2026)]]></title>
<description><![CDATA[If you remember me from "I gave up investment banking to become a digital artist", you'll know that I've spent the last 17 years being an artist. Over that time I've worked in a lot of schools doing making activities: concrete relief casting in a nursery, constructing willow Fibonacci towers with...]]></description>
<link>https://tsecurity.de/de/3677987/it-security-video/i-make-things-in-schools-you-can-too-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677987/it-security-video/i-make-things-in-schools-you-can-too-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 14:33:11 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you remember me from &quot;I gave up investment banking to become a digital artist&quot;, you'll know that I've spent the last 17 years being an artist. Over that time I've worked in a lot of schools doing making activities: concrete relief casting in a nursery, constructing willow Fibonacci towers with secondary maths students, designing paper mushrooms in a primary, writing haiku about water, organising giant multi-school lantern parades. My experience is that young people are increasingly struggling with the confidence and basic skills to make. Primary schools are becoming art-free zones, with limited resources and teachers struggling with their own confidence. It sounds bleak, but the exciting news is that you can make a huge difference in a young person's life by getting involved. I'm going to talk about what's going wrong and how we all might fix it.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/280-i-make-things-in-schools-you-can-too]]></content:encoded>
</item>
<item>
<title><![CDATA[Device Code Phishing: How Attackers Abuse Microsoft’s Legitimate Authentication Page Without…]]></title>
<description><![CDATA[Device Code Phishing: How Attackers Abuse Microsoft’s Legitimate Authentication Page Without Stealing Your PasswordThe most convincing Microsoft phishing attack yet. Learn how attackers abuse Microsoft’s trusted device authentication process, obtain access tokens instead of passwords, and why tra...]]></description>
<link>https://tsecurity.de/de/3677780/hacking/device-code-phishing-how-attackers-abuse-microsofts-legitimate-authentication-page-without/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677780/hacking/device-code-phishing-how-attackers-abuse-microsofts-legitimate-authentication-page-without/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Device Code Phishing: How Attackers Abuse Microsoft’s Legitimate Authentication Page Without Stealing Your Password</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7OVpY6KkTRyuVGErNrEOnw.png"></figure><p>The most convincing Microsoft phishing attack yet. Learn how attackers abuse Microsoft’s trusted device authentication process, obtain access tokens instead of passwords, and why traditional MFA awareness alone is no longer enough.</p><p>Have You Ever Come Across a Website Like This Below Screenshot? No fake Microsoft login pages. No stealing of passwords. No cloned authentication forms. No obvious browser warnings. Yes that’s device code phishing</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IWV-Evt-XtPkaXDpCmwEVg.png"><figcaption>At first glance, this page looks completely legitimate.</figcaption></figure><p>It carries Microsoft’s branding, displays a verification code, and instructs users to continue their sign-in using the official Microsoft Device Login page. Unlike traditional phishing websites, there are no fake Microsoft login forms, no requests for your password, and no obvious signs that something is wrong.</p><p>So, it must be safe… right?</p><p>Not necessarily.</p><p>Device Code Phishing has become one of the most effective phishing techniques because it abuses Microsoft’s legitimate authentication workflow instead of attempting to steal usernames and passwords. Since users authenticate directly with Microsoft, many of the traditional warning signs associated with phishing are absent, making these attacks significantly more convincing.</p><p>In this article, the ThreatWatch360 team explains how Device Code Phishing works, why it is dangerous, and how attackers leverage this technique to gain unauthorized access to Microsoft 365 accounts without ever asking victims for their credentials.</p><h3>What is Device Code Authentication?</h3><p>Before understanding Device Code Phishing, it’s important to understand Device Code Authentication.</p><p>Microsoft introduced the Device Code Flow to allow devices with limited input capabilities, such as smart TVs, conference room devices, IoT devices, and command-line applications, to authenticate users.</p><p>Instead of entering credentials directly on the device, Microsoft generates a short verification code.</p><p>The user then visits Microsoft’s official Device Login page, enters the code, signs in with their Microsoft account, and authorizes the request.</p><p>The authenticated session is then linked back to the requesting application.</p><p>This workflow is completely legitimate and is widely used by Microsoft-supported applications.</p><p>Unfortunately, threat actors discovered they could abuse this authentication flow for phishing.</p><h3>How Device Code Phishing Works</h3><p>Unlike traditional phishing attacks, Device Code Phishing does <strong>not</strong> steal passwords.</p><p>Instead, it tricks victims into authorizing an attacker-controlled application using Microsoft’s own authentication infrastructure.</p><p>The result is that the attacker receives a valid Microsoft access token after the victim successfully authenticates.</p><p><strong>Stage 1 — The Phishing Email</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tAn7mYR2AdzzB3hwopRHjw.png"><figcaption>Initial Phishing Email</figcaption></figure><p>The attack usually begins with a convincing phishing email.</p><p>In our demonstration, the victim receives an email claiming that Microsoft detected unusual sign-in activity and encourages them to secure their account immediately.</p><p>The email closely resembles legitimate Microsoft security notifications, making it difficult for many users to distinguish between genuine and malicious messages.</p><p>Instead of directing users to a fake Microsoft login page, the email redirects them to an attacker-controlled website.</p><p>This subtle difference is what makes Device Code Phishing particularly dangerous.</p><p><strong>Stage 2 — The Fake Verification Portal</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AojoCLPiwGgkLGcDH88gRA.png"><figcaption>Device Code Phishing Page</figcaption></figure><p>After clicking the email link, the victim is presented with what appears to be a Microsoft verification portal.</p><p>The page displays:</p><ul><li>A Microsoft verification code</li><li>Instructions explaining how to complete authentication</li><li>A button that automatically opens Microsoft’s legitimate Device Login page</li></ul><p>Everything appears authentic.</p><p>Unlike credential phishing pages, this website never asks the user for their Microsoft username or password.</p><p>Instead, it simply instructs the user to authenticate through Microsoft itself.</p><p>This dramatically increases trust.</p><p><strong>Stage 3 — Redirecting to Microsoft’s Official Login Page</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vxT4KVaMxg7heCzDMx58Bg.png"><figcaption>Official Microsoft Device Login</figcaption></figure><p>Clicking the verification button redirects the victim to Microsoft’s official Device Login page.</p><p>Notice the URL.</p><p>The browser clearly displays Microsoft’s legitimate domain: login.microsoftonline.com</p><p>This is not a fake login page.</p><p>This is Microsoft’s real authentication portal.</p><p>Since users are interacting directly with Microsoft, many security-conscious individuals believe the request is legitimate.</p><p><strong>Stage 4 — Entering the Device Code</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wFq44SaoP4Gcy7Y_7QxXHA.png"><figcaption>Microsoft Device Authentication</figcaption></figure><p>The victim enters the code displayed on the phishing website into Microsoft’s official authentication page.</p><p>At this point, everything still appears normal.</p><p>The authentication process is entirely handled by Microsoft.</p><p>No passwords have been stolen.</p><p>No fake login page has been displayed.</p><p>Yet the attacker is already one step closer to gaining access.</p><p><strong>Stage 5 — Microsoft Requests Account Authorization</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-3m7P_UTRW5Zprk35ydVMA.png"><figcaption>Account Selection</figcaption></figure><p>Once the code is accepted, Microsoft asks the victim to select the account they wish to authorize.</p><p>Again, this occurs entirely on Microsoft’s legitimate infrastructure.</p><p>Nothing appears suspicious.</p><p>Most users assume they are completing a routine Microsoft verification process.</p><p><strong>Stage 6 — Granting Access</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ew9Rlt7lKtc3NSjGugG7CQ.png"><figcaption>Authorization Prompt</figcaption></figure><p>Microsoft now asks the user to confirm the authentication request.</p><p>The victim clicks <strong>Continue</strong>, believing they are protecting or verifying their Microsoft account.</p><p>Instead, they are unknowingly authorizing an attacker-controlled application.</p><p><strong>Stage 7 — Authentication Complete</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-KyN4hx6sY5t0rM_KDsBFw.png"><figcaption>Successful Authorization</figcaption></figure><p>Microsoft confirms that authentication has completed successfully.</p><p>From the victim’s perspective, everything appears perfectly normal.</p><p>There are no error messages.</p><p>No warnings.</p><p>No indication that their Microsoft session has now been shared with someone else.</p><h4>Stage 8 — The Attacker Receives the Access Token</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*QNu8X_BbbhhP4XFhhrqC6Q.png"><figcaption>Attacker Token Captured dashboard</figcaption></figure><p>Behind the scenes, the attacker’s phishing infrastructure immediately receives the Microsoft access token generated during the authentication process.</p><p>Unlike traditional phishing attacks, the attacker never needed the victim’s password.</p><p>Instead, they now possess a valid Microsoft authentication token issued directly by Microsoft.</p><p><strong>Stage 9 — Accessing Microsoft Resources</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hqRMWz0deomvWmiCV1QAag.png"><figcaption>Searching Microsoft Graph Data</figcaption></figure><p>Using the captured token, the attacker can begin interacting with Microsoft Graph APIs according to the permissions granted during authentication.</p><p>Depending on the permissions available, this may allow access to resources such as:</p><ul><li>Outlook email</li><li>OneDrive files</li><li>SharePoint data</li><li>Microsoft Teams information</li><li>Other Microsoft 365 resources</li></ul><p>In our demonstration, the captured token is used to search mailbox content, illustrating how quickly authenticated access can be abused after the victim completes the authorization process.</p><h3>Why Device Code Phishing Is So Effective</h3><p>Traditional phishing relies on fake login pages.</p><p>Device Code Phishing is different.</p><p>The victim authenticates directly with Microsoft.</p><p>Every important step occurs on Microsoft’s legitimate domain.</p><p>This removes many of the indicators users have been trained to recognize.</p><p>There are:</p><ul><li>No fake Microsoft login pages.</li><li>No stealing of passwords.</li><li>No cloned authentication forms.</li><li>No obvious browser warnings.</li></ul><p>Instead, attackers exploit the trust users place in Microsoft’s legitimate authentication process.</p><h3>Why This Matters</h3><p>Modern phishing campaigns are evolving beyond simple credential theft. By abusing legitimate authentication workflows, attackers can obtain valid access tokens without ever knowing a user’s password. This makes Device Code Phishing particularly attractive because it blends legitimate authentication with social engineering. Organizations relying solely on user awareness around fake login pages may find these attacks significantly more difficult to detect.</p><h3>How to Protect Yourself</h3><p>Although Device Code Authentication is a legitimate Microsoft feature, there are several ways users can protect themselves from Device Code Phishing attacks.</p><h4>Never authenticate unless you initiated the request.</h4><p>If you receive an unexpected email asking you to verify your Microsoft account using a device code, stop and verify the request before proceeding.</p><h4>Check why you are being asked to authenticate.</h4><p>Ask yourself:</p><ul><li>Did I start this login?</li><li>Am I trying to sign in on another device?</li><li>Was I expecting this authentication request?</li></ul><p>If the answer is no, do not continue.</p><h4>Be cautious of urgent security emails.</h4><p>Threat actors frequently use messages about unusual sign-in activity, account suspension, or urgent verification to pressure victims into acting quickly.</p><h4>Review recently authorized applications.</h4><p>Regularly review the applications connected to your Microsoft account and remove any unfamiliar or unnecessary authorizations.</p><h4>Revoke active sessions if you suspect compromise.</h4><p>If you believe you accidentally completed a Device Code Phishing request:</p><ul><li>Immediately sign out of all active Microsoft sessions.</li><li>Revoke recently granted application permissions.</li><li>Change your Microsoft account password.</li><li>Inform your organization’s IT or Security team.</li><li>Review your recent sign-in activity for any suspicious access.</li></ul><p>Acting quickly can significantly reduce the impact of token-based attacks.</p><h3>Conclusion</h3><p>Device Code Phishing demonstrates that modern phishing attacks no longer need to steal passwords to be successful.</p><p>By abusing Microsoft’s legitimate Device Code authentication workflow, attackers can trick users into authorizing malicious applications while every authentication step takes place on Microsoft’s official infrastructure.</p><p>This makes the attack highly convincing, difficult for users to recognize, and increasingly relevant in modern phishing campaigns.</p><p>Understanding how this technique works is the first step toward recognizing suspicious authentication requests and preventing unauthorized access to Microsoft 365 environments.</p><p>As attackers continue to shift toward token-based authentication abuse, user awareness remains one of the most effective defenses against these evolving phishing techniques.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=cfa189643f45" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/device-code-phishing-how-attackers-abuse-microsofts-legitimate-authentication-page-without-cfa189643f45">Device Code Phishing: How Attackers Abuse Microsoft’s Legitimate Authentication Page Without…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Funded a Stranger’s Bank Card With My Own Money; and That’s Exactly the Problem]]></title>
<description><![CDATA[A hands-on walkthrough of Broken Object Level Authorization (BOLA) on VulnBankVulnBankThere’s a moment in every appsec learner’s journey where a vulnerability stops being a bullet point on the OWASP API Top 10 and starts being something you actually did. For me, that moment was watching one user’...]]></description>
<link>https://tsecurity.de/de/3677763/hacking/i-funded-a-strangers-bank-card-with-my-own-money-and-thats-exactly-the-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677763/hacking/i-funded-a-strangers-bank-card-with-my-own-money-and-thats-exactly-the-problem/</guid>
<pubDate>Sat, 18 Jul 2026 11:21:50 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>A hands-on walkthrough of Broken Object Level Authorization (BOLA) on VulnBank</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mTehjKwtISkTLR8KwRRrRw.png"><figcaption>VulnBank</figcaption></figure><p>There’s a moment in every appsec learner’s journey where a vulnerability stops being a bullet point on the OWASP API Top 10 and starts being something you actually <em>did</em>. For me, that moment was watching one user’s card get funded by another user’s session — no exploit chain, no payload, just a number in a URL that should never have worked.</p><p>This is the walkthrough of how I found (and rigorously confirmed) a Broken Object Level Authorization vulnerability in <strong>VulnBank</strong>, an intentionally vulnerable banking application built for security training.</p><h3>What Is BOLA, Actually?</h3><p>Broken Object Level Authorization sits at <strong>#1 </strong>on the <strong>OWASP API Security Top 10 </strong>(API 1: 2023), and for good reason — it’s common, trivial to exploit, and quietly devastating.</p><p>The core idea in one sentence: <strong>the server correctly checks who you are, but never checks what you’re allowed to touch.</strong></p><p>Any API endpoint that takes an object identifier — a <strong>card_id</strong>, <strong>account_number</strong>, <strong>order_id </strong>— needs to answer two separate questions:</p><ol><li><strong>Authentication: </strong>is this a valid, logged-in user?</li><li><strong>Authorization: </strong>should <em>this </em><strong><em>specific user</em> </strong>be allowed to access <em>this specific object</em>?</li></ol><p>BOLA is what happens when an API nails question one and skips question two entirely. Usually it’s one missing clause in a query.</p><p>The vulnerable version:</p><pre>SELECT * FROM cards WHERE id = :card_id</pre><p>The fixed version:</p><pre>SELECT * FROM cards WHERE id = :card_id AND user_id = :authenticated_user_id</pre><p>That’s genuinely the whole difference and because it never breaks anything during normal use (your own IDs always belong to you), it hides in plain sight until someone deliberately tries an ID that isn’t theirs.</p><p>So that’s exactly what I did — with two accounts, on purpose, so I could prove it beyond doubt rather than just suspect it.</p><h3>Setting the Stage: Two Users, Two Cards</h3><p>Testing BOLA against yourself proves nothing — you always have legitimate access to your own resources. So I set up two separate accounts to simulate a real attacker/victim scenario.</p><h3><strong>User 1 — Jhonny</strong></h3><ul><li>I created a virtual card with a <strong>$2,500 </strong>limit.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/671/1*IzNdvQ1HNkbGSk9AEz70FQ.png"><figcaption>Jhonny’s Virtual Card</figcaption></figure><ul><li>I then funded it with <strong>$80 </strong>from the main balance.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/444/1*yyZLbn89enTTeEBs4gSKow.png"><figcaption>Funding the card</figcaption></figure><p>With the funding request captured in <strong>Burp Suite</strong>, I sent it to Repeater for closer inspection, this is the request whose <strong>card_id </strong>parameter would become the centerpiece of the whole test.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EKOsjOROq-GWkyoTOSyHNw.png"><figcaption>Jhonny Card Request in Burp</figcaption></figure><h3><strong>User 2 — Alex</strong></h3><p>Same setup:</p><ul><li>A fresh virtual card of <strong>$2,500 </strong>limit.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/411/1*A-bryCWIEKgcBWvJSyHgGQ.png"><figcaption>Alex’s Virtual Card</figcaption></figure><ul><li>Funded with $100.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/697/1*H-zuUIktIse3J_FkKY4iRg.png"><figcaption>Funding Alex’s card</figcaption></figure><ul><li>And the same treatment — captured the request and sent it to Repeater.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MhtrbarCUBXaggWB7u-YBw.png"><figcaption>Alex’s Card Request in Burp</figcaption></figure><p>Two accounts, two cards, two independent funding requests sitting side by side. Now the real test could begin.</p><h3>Step One: Does the App Even Check Who You Are?</h3><p>Before hunting for authorization flaws, I checked the basics. I stripped the session cookie and Authorization header from a funding request entirely and sent it.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SkZ3P_vd-a31Bxve6I1kMw.png"><figcaption>Token error (Authentication enabled)</figcaption></figure><p><strong>401 Unauthorized: "Token is missing."</strong></p><p>Good! The server clearly enforces authentication. That ruled out the simplest failure mode and pointed straight at the real question: does it check <strong><em>which</em> </strong>authenticated user is making the request, or just <strong><em>that</em> </strong>one is?</p><h3>Step Two: The Swap</h3><p>This is the actual test, and it’s almost anticlimactic in how simple it is.</p><p>I took <strong>Jhonny’s</strong> valid token and used it to fund <strong>Alex’s</strong> card:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pM9M7X-q1bMfJng1TcsNqA.png"><figcaption>Funding Alex’s card with Jhonny’s Token</figcaption></figure><p><strong>200 OK.</strong> The card funded successfully with Jhonny's session authorizing a change to Alex's card.</p><p>Then I reversed it, <strong>Alex’s</strong> token, aimed at <strong>Jhonny’s</strong> card:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-5Qqk7A4XKvrvCkqyXgRFQ.png"><figcaption>Funding Jhonny’s card with Alex’s Token</figcaption></figure><p><strong>200 OK</strong> again. Same result, opposite direction.</p><p>Neither request was rejected. The server verified that a valid token was present but never verified that the token holder actually owned the card they were funding. It simply processed whatever <strong>card_id </strong>showed up in the URL, against whichever authenticated user happened to be making the call.</p><h3>Why This Isn’t “Just a Feature”</h3><p>The first pushback any BOLA finding gets is: <strong><em>“Couldn’t this just be an intentional transfer feature?”</em></strong></p><p>It’s a fair question, and worth addressing directly.</p><p>The answer is <strong>NO</strong>, for a few concrete reasons:</p><ul><li>There was no recipient search, no username/email lookup, no way to intentionally select another user through the interface.</li><li>Neither Jhonny nor Alex received any notification or gave any consent.</li><li>The card IDs used were never exposed to either user by the application itself, they were reached only by directly editing a request in Burp, not by anything the UI ever presented as selectable.</li><li>Both requests used each user’s <em>own</em> main balance and <em>own</em> token throughout, nothing about the flow resembled a designed transfer mechanism.</li></ul><p>A designed feature has guardrails: consent steps, recipient verification, fraud checks. This had none of that, because it was never meant to be reachable in the first place.</p><h3>The Fix</h3><p>The remediation here is almost anticlimactic given the impact. This isn’t a hard problem to solve, just an easy one to forget:</p><ul><li>Every object-level query needs an explicit ownership check tied to the authenticated session: <strong>WHERE card_id = ? AND user_id = ?</strong></li><li>Better yet, enforce this centrally, an authorization layer or middleware that every object-fetching endpoint routes through, rather than relying on each developer to remember it per-endpoint</li><li>Make cross-account testing a standard part of QA and code review: test with <strong>two different authenticated accounts</strong> against each other’s objects, not just each account against its own.</li></ul><h3>The Takeaway</h3><p>BOLA doesn’t require exotic tooling or deep exploit development. It requires one thing: noticing that an ID in a URL is just a number, and asking whether the server actually checked if you were allowed to use it.</p><p>In this case, it hadn’t. Two independent accounts, each fully authenticated, could reach into each other’s resources without so much as a warning.</p><p>Authentication tells a server <em>who</em> is asking. Authorization is the separate and often forgotten question of <strong><em>what they’re allowed to ask for?</em></strong>. Every API needs both, and it’s worth checking, endpoint by endpoint, that yours actually has them.</p><p><em>This testing was performed against VulnBank, an intentionally vulnerable application built for security education and training purposes.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a3bfc069a8b9" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-funded-a-strangers-bank-card-with-my-own-money-and-that-s-exactly-the-problem-a3bfc069a8b9">I Funded a Stranger’s Bank Card With My Own Money; and That’s Exactly the Problem</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brex built its AI agent policy by watching what agents actually do, not by writing rules first]]></title>
<description><![CDATA[OpenClaw has become one of the most widely adopted agentic frameworks, but it has yet to prove itself at enterprise scale. Agents need real credentials — API keys, OAuth tokens, service accounts — to work effectively, and Brex found that traditional guardrails couldn't contain what those agents w...]]></description>
<link>https://tsecurity.de/de/3676907/it-nachrichten/brex-built-its-ai-agent-policy-by-watching-what-agents-actually-do-not-by-writing-rules-first/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676907/it-nachrichten/brex-built-its-ai-agent-policy-by-watching-what-agents-actually-do-not-by-writing-rules-first/</guid>
<pubDate>Fri, 17 Jul 2026 21:32:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://venturebeat.com/security/openclaw-500000-instances-no-enterprise-kill-switch">OpenClaw</a> has become one of the most widely adopted agentic frameworks, but it has yet to prove itself at enterprise scale. Agents need real credentials — API keys, OAuth tokens, service accounts — to work effectively, and Brex found that traditional guardrails couldn't contain what those agents were doing with them.</p><p>Brex set out to overcome these limitations by building an internal platform it calls CrabTrap. The <a href="https://www.brex.com/journal/building-crabtrap-open-source">open-source HTTP/HTTPS proxy</a> intercepts all network traffic, examines policy rules, and uses a LLM-as-a-judge to decide whether agent requests should be approved or denied. </p><p>“What we noticed was that the network layer was an untapped enforcement point,” Brex co-founder and CEO Pedro Franceschi told VentureBeat. “Every request an agent makes is an opportunity to intercept, reason about, and make a policy decision.”</p><p>The takeaway Franceschi wants IT leaders to draw: agent governance should shift from SDK-level permissions and model guardrails toward a centralized network control plane that enforces and learns from real in-the-wild agent behavior.</p><h2>How Brex targeted the transport layer</h2><p>The “obvious fix” (at least initially) to the agent security gap was guardrails, and much of the early work has centered on scoped tools, per-action permissions, and human-in-the-loop approvals. But as agents evolve, each new capability means there’s another API to tune or surface to audit, Franceschi noted. </p><p>“Any <a href="https://venturebeat.com/orchestration/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models">agentic system</a> with multiple tools and access to the open internet creates an immediate tension for builders: The more capable you make an agent, the more dangerous it becomes, and the safer you make it, the less useful it is,” he said. </p><p>Existing solutions to this tradeoff were “weak”: Fine-grained API tokens help at the margins but can still be misused and constrain functionality. Semantic guardrails (such as context, skills, or prompt steering) are easily bypassed by prompt injection, especially for agents connected to the internet.</p><p>Agents can be “defanged” when given read-only access or limited toolsets, but then they can't do meaningful work, Franceschi said. On the other hand, granting broad write access and a large tool surface can result in hallucinations and real production consequences.</p><p>Model context protocol (MCP) gateways enforce policy at the protocol layer — but only for traffic using MCP. Meanwhile, guardrails from LLM providers are tied to a single model and can be “opaque” to customize with enterprise-specific policies. And powerful tools like Nvidia OpenShell offer more of a “per-sandbox egress control.”</p><p>“When we started, we hadn’t found a solution to deploying harnesses like OpenClaw safely,” Franceschi said. “Instead of waiting for the industry to catch up, we decided to own the problem and invent the necessary tools.”</p><p>Notably, they needed a platform that sat between every agent and every network request, and could make “nuanced decisions about what to allow,” he said. </p><p>This made the transport layer a core architectural component and natural starting point, he said. </p><p>By operating at this layer, CrabTrap is framework-agnostic, language-agnostic, and API-agnostic. It doesn't require SDK wrappers or per-tool integration. Users set <i>HTTP_PROXY</i> and <i>HTTPS_PROXY</i> in the agent's environment, and every outbound request routes through the proxy before it reaches a destination.</p><p>However, Franceschi emphasized, Brex didn't start at the transport layer because it thought it was the only answer; rather, they believe in “security by layers.”</p><p>“The transport layer was simply an underinvested one, and we saw an opportunity to add meaningful enforcement there alongside everything else,” he said. </p><h2>The LLM-as-a-judge training loop</h2><p>CrabTrap combines deterministic static rules with an <a href="https://venturebeat.com/infrastructure/monitoring-llm-behavior-drift-retries-and-refusal-patterns">LLM-as-a-judge</a> for requests that fall outside known patterns, Franceschi explained. The judge only “fires on the long tail of unfamiliar endpoints or unusual request shapes,” which for a mature agent is typically fewer than 3% of requests.</p><p>The more pressing problem was how to know that a policy is the right one? With static rules, it's “relatively straightforward” to reason about accuracy. But with an LLM judge, the system is nondeterministic, and users need confidence that the policy approves the right requests and blocks the rest.</p><p>“Our key insight was to bootstrap policy from observed behavior rather than write it from scratch,” Franceschi said. Beginning with real behavior and editing down based on real-world learnings turned out to be “dramatically more effective than starting from a blank page.”</p><p>Brex’s team built a policy builder (itself an agentic loop) that runs underlying agents in shadow mode, analyzes historic network traffic, samples representative calls, and drafts a natural-language policy that matches what the agent actually does. </p><p>From there, they built an eval system that tests policy changes before they go live. CrabTrap compares historical audit entries against a draft policy and reports the exact changes to be made. Users can slice results by method, URL, original decision, and agreement status. </p><p>All of this runs with concurrent judge calls, so replaying thousands of requests “takes minutes, not hours,” Franceschi said. Brex also developed a live feedback loop: Full audit trails are stored in PostgreSQL and queryable through the admin API and dashboard. In cases where a resource is continuously denied, the system can notify a human or an agent to propose a policy update for review. </p><p>“That closes the loop between observed denials and policy refinement,” Franceschi said. </p><h2>Core challenges and roadblocks </h2><p>Of course, the build wasn’t without its challenges. A big one was latency: “Putting an LLM between an agent and every outbound API request sounds like it would grind things to a halt,” he said. </p><p>However, it didn’t turn out to be as big a problem as expected. This was for two reasons: The LLM judge only activates on a small fraction of requests (the aforementioned 3%). Agents quickly settle into predictable traffic patterns; once observed, high-volume patterns become static rules. Second, by using small, fast models like Claude Haiku meant that, even when the judge did fire, added latency was “negligible.” This can be further reduced with local models and prompt caching, Franceschi said. </p><p>The harder and less obvious challenge was prompt injection, he said. The judge receives the full HTTP request and all content is user-controlled, so potentially, a crafted URL, header, or request body could manipulate the judge's decision. </p><p>Brex addressed this by structuring the request as a JSON object before sending it to the model, so all user-controlled content is “escaped rather than interpolated as raw text,” Franceschi said. </p><h2>Results, and where CrabTrap might evolve</h2><p>Brex tracks a few factors to measure CrabTrap’s internal impact: Engagement with agents, network traffic patterns, and net promoter scores (NPS). The most meaningful result of CrabTrap has been “organizational confidence,” Franceschi said. </p><p>Previously, the team had “real hesitation” when it came to deploying autonomous agents broadly across business operations, because the existing guardrail options didn't provide enough assurance. </p><p>“CrabTrap changed that calculus,” Franceschi said. They now have an enforcement layer they trust, increasing confidence around expanding agent deployment into more parts of the business and delegating more agent configuration and management to users. </p><p>Franceschi described the policies derived from traffic as “surprisingly strong.” The team expected the policy builder to produce a “rough starting point” requiring heavy manual editing. In practice, though, pointing the platform at a few days of real traffic produced policies that matched human judgment on the “vast majority of held-out requests.”</p><p>Additionally, CrabTrap revealed how much noise agents generate. “The audit trail made this visible for the first time,” Franceschi said. They used denial logs and traffic analysis not only to tune policies, but to tighten agents themselves, remove tools, and cut out entire categories of requests that were wasting both time and tokens.</p><p>“The proxy became a discovery tool, not just an enforcement one,” he said. </p><h2>Areas for growth (and input from the open-source community)</h2><p>Brex anticipates CrabTrap to continue to evolve, particularly as they have released it as open-source. “We hope the community helps shape it,” Franceschi said. </p><p>Areas of improvement include deeper authentication functionality such as single-sign on (SSO), fine-grained role-based access control (RBAC); escalation workflows that allow agents to request additional permissions; and policy recommendations based on denial patterns.</p><p>Programmatic configuration, or developing API endpoints for “creating, forking, and applying” policies to agents, could allow the whole policy lifecycle to be automated rather than managed manually, Franceschi said. </p><p>As for escalation, if an agent is continuously denied a given resource or endpoint, it should be able to route requests to humans or other AI agents for review and back that up with a rationale for why it needs access. </p><p>“That turns CrabTrap from a hard enforcement boundary into something more like a managed permission system,” Franceschi said. </p><p>Additionally, the policy was built to bootstrap from network traffic, but there is opportunity to incorporate additional signals around agent traces and resource-calling, as well as broader context on what agents are ultimately trying to accomplish. This can help produce more accurate and nuanced policies. </p><p>Finally, there's an “open philosophical question” about the right posture for CrabTrap: Should it be a fully transparent layer that the agent itself is unaware of, or should it operate more like a “well-intentioned manager”? (that is, the agent knows about the layer and can interact with it). </p><p>The open-source community can help shape these developments, and CrabTrap will only get better with more users, Franceschi said. Brex’s agents speak to a specific set of APIs; teams using CrabTrap with different agents, services, and policy requirements will surface “edge cases and patterns we can't hit alone.”</p><p>“We have ambitious plans for where it could go, and we’d rather build in the open,” Franceschi said. </p><h2>What other builders can learn from CrabTrap</h2><p>The response has been stronger than expected. <a href="https://github.com/brexhq/CrabTrap">CrabTrap has more than 700 stars on GitHub</a>. Franceschi said Brex has also heard from OpenAI, Y Combinator CEO Garry Tan, and programmer Pete Steinberger, all expressing interest in deploying similar internal infrastructure.</p><p>The broader lesson: “Don't let infrastructure gaps become excuses to wait," Franceschi advised. There are “real blockers” for every enterprise looking to seriously deploy AI agents, including security concerns, lack of tooling, or unclear guardrails. </p><p>“It's tempting to sit on your hands until the industry catches up,” he said. “The lesson from CrabTrap is that you can own those problems directly.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint]]></title>
<description><![CDATA[Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint…
Read more →
The post In Ot...]]></description>
<link>https://tsecurity.de/de/3676393/it-security-nachrichten/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676393/it-security-nachrichten/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/</guid>
<pubDate>Fri, 17 Jul 2026 17:10:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/">In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint]]></title>
<description><![CDATA[Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach.
The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared first on SecurityW...]]></description>
<link>https://tsecurity.de/de/3676344/it-security-nachrichten/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676344/it-security-nachrichten/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/</guid>
<pubDate>Fri, 17 Jul 2026 16:38:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach.</p>
<p>The post <a href="https://www.securityweek.com/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/">In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why technology leaders are losing the AI conversation to the people who report to them]]></title>
<description><![CDATA[I keep seeing a version of the same scene. A CEO has a question about AI. It is a real question, the kind that will shape where the company spends the next two years. The CEO does not bring it to the CIO. They bring it to a data leader two levels down, or to a vendor who presented at a conference...]]></description>
<link>https://tsecurity.de/de/3675833/it-nachrichten/why-technology-leaders-are-losing-the-ai-conversation-to-the-people-who-report-to-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675833/it-nachrichten/why-technology-leaders-are-losing-the-ai-conversation-to-the-people-who-report-to-them/</guid>
<pubDate>Fri, 17 Jul 2026 13:03:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I keep seeing a version of the same scene. A CEO has a question about AI. It is a real question, the kind that will shape where the company spends the next two years. The CEO does not bring it to the CIO. They bring it to a data leader two levels down, or to a vendor who presented at a conference, or to an AI specialist a board member recommended. The CIO finds out the strategy is forming when a slide shows up that they did not build. By then, the direction is already half-set, and the CIO is being asked to react to it rather than shape it.</p>



<p class="wp-block-paragraph">I want to be precise about what is happening, because it is easy to misread. The CIO has not been removed from anything. Title intact, budget intact, seat at the table intact. What has changed is quieter. On one of the most consequential technology conversations the company will have this decade, the CIO is being routed around. The work still flows through them eventually. The thinking no longer starts with them.</p>



<p class="wp-block-paragraph">I have watched this happen to capable people who would have given the CEO a better answer than the person who was asked. That is what makes it worth naming. This is not a competence gap. It is a positioning gap, and positioning gaps close in the wrong direction if you ignore them long enough.</p>



<h2 class="wp-block-heading">How the routing actually starts</h2>



<p class="wp-block-paragraph">The routing does not begin with a decision to exclude anyone. It begins with a CEO who is anxious about AI and looking for someone who sounds certain. AI is moving fast enough that executives feel the pressure to have a point of view before they have earned one. That pressure usually arrives secondhand, from a board member or a peer on the golf course describing what is working at their company. So the CEO goes looking for someone who will confirm the answer they already want to hear, and they keep going back to whoever gives it to them.</p>



<p class="wp-block-paragraph">Here is where many technology leaders lose the thread. For years, the safe posture in the CIO seat was measured caution. You raised the risks, you flagged the integration cost, you asked who owns the data and what the compliance exposure looks like. That posture built credibility in an era when the failure mode was moving too fast on technology nobody understood. With AI, the same posture reads as drag. A CEO who is being told by three vendors that “the future is already here” does not want to hear why they should slow down and be cautious. They hear caution as losing the race, and they go find a point of view somewhere else.</p>



<p class="wp-block-paragraph">The data leaders, vendors and specialists who get the call are not necessarily more capable. They are more available with a confident answer. A vendor’s whole job is to arrive with conviction. A data scientist who has shipped one impressive model carries more apparent authority on AI, in that moment, than a CIO who runs the entire estate but talks about AI the way they talk about every other risk. The CEO is not weighing depth against depth. They are weighing the person who said yes against the person who said it depends.</p>



<p class="wp-block-paragraph">Once that pattern sets, it compounds. The CEO who got a satisfying answer from the data leader goes back to the data leader. The vendor who shaped the first conversation gets invited into the second. Each loop the CIO is not in makes the next one easier to run without them. The org chart still says the CIO owns technology strategy. The actual conversation has relocated.</p>



<h2 class="wp-block-heading">What it costs before anyone notices</h2>



<p class="wp-block-paragraph">The cost shows up late, which is exactly why it is dangerous. For a while nothing looks broken. The CIO is still delivering. The AI initiatives are still landing on their plate to execute. The damage is happening upstream, in the room where the bets get made, and the CIO is not in that room.</p>



<p class="wp-block-paragraph">I have seen what arrives downstream when the strategy was set without the person who has to run it. A model gets championed that the data cannot actually support. A vendor commitment gets made that locks the company into an architecture the CIO would have flagged in the first meeting. An agent gets deployed inside a business unit, with executive blessing, and the CIO inherits accountability for it months later without ever having shaped how it was governed. The recent IBM finding that <a href="https://www.cio.com/article/4182288/cios-are-being-held-accountable-for-ai-they-dont-fully-control-ibm-study-finds.html">CIOs are increasingly held accountable for AI they do not fully control</a> is the visible end of this. The invisible front end is the conversation the CIO was routed around, the one where the accountability got created in the first place.</p>



<p class="wp-block-paragraph">What I find most corrosive is what it does to the CIO’s standing over time. Every initiative the CIO executes but did not shape reinforces a story about what the CIO is for. They become the person who runs the technology other people decided on. That is a fine description of an order taker and a poor description of a strategic leader, and CEOs do not promote, fund, or defend order takers when budgets tighten. The routing-around does not just cost the company a worse AI strategy. It quietly recasts the CIO as the implementer of everyone else’s thinking, and that recasting is hard to reverse once the executive team has internalized it.</p>



<h2 class="wp-block-heading">What the leaders who stayed in the conversation did</h2>



<p class="wp-block-paragraph">The technology leaders I have watched hold their position on AI did one thing first. They stopped leading with caution and started leading with a point of view. Not a reckless one. A real, defensible position on where AI creates value in their specific business and where it does not, delivered with the same conviction the vendors bring, before the CEO went looking elsewhere for it. They made themselves the person with the clearest answer, which is the role the routing-around was filling with someone else.</p>



<p class="wp-block-paragraph">That requires giving up a posture that felt safe for a long time. The CIOs who made the shift accepted that on AI, being right and cautious is worth less than being early and directional. They formed a view ahead of being asked. They walked into the CEO’s office with where we should place our AI bets and why, rather than waiting to be handed someone else’s bets to pressure-test. The difference is whether you are the author of the strategy or its editor, and CEOs route around editors.</p>



<p class="wp-block-paragraph">They also changed how they talk about risk. Instead of presenting risk as the reason to slow down, they folded it into the recommendation. The data is not ready for that use case, so here is the use case where it is ready, and here is what we do in parallel to unlock the first one. That framing keeps the CIO inside the conversation as the person making AI happen responsibly, rather than the person standing outside it explaining why it is hard. Same expertise, opposite effect on whether the CEO keeps coming back.</p>



<p class="wp-block-paragraph">None of this is about pushing the data leaders and specialists out. The strongest CIOs I know pulled those people closer and brought them into the room under their own framing, so that when the CEO wanted the specialist’s input, it arrived through the CIO rather than around them. They made themselves the orchestrator of the AI conversation instead of one of its casualties.</p>



<p class="wp-block-paragraph">If you are a technology leader right now, the question worth sitting with is not whether you are good at AI. You probably are. The question is whether the most important AI conversations in your company are still starting with you, or whether you have quietly become the person they get handed to after the thinking is done. That answer is set in rooms you may not be in, and the only way to find out is to ask who your CEO called the last three times AI came up. If the answer is not you, the role is still yours. The conversation has already started leaving.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why brokers need clean data to execute in the age of AI]]></title>
<description><![CDATA[The right data makes the difference when it comes to AI output]]></description>
<link>https://tsecurity.de/de/3675540/it-nachrichten/why-brokers-need-clean-data-to-execute-in-the-age-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675540/it-nachrichten/why-brokers-need-clean-data-to-execute-in-the-age-of-ai/</guid>
<pubDate>Fri, 17 Jul 2026 11:03:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The right data makes the difference when it comes to AI output]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/ced50f88e928-20260717]]></title>
<description><![CDATA[OpenClaw detached release child recovery ced50f8]]></description>
<link>https://tsecurity.de/de/3675534/downloads/release-publishced50f88e928-20260717/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675534/downloads/release-publishced50f88e928-20260717/</guid>
<pubDate>Fri, 17 Jul 2026 11:02:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw detached release child recovery <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/openclaw/openclaw/commit/ced50f88e92899da2b076c95fa0d5107d6b5ada4/hovercard" href="https://github.com/openclaw/openclaw/commit/ced50f88e92899da2b076c95fa0d5107d6b5ada4"><tt>ced50f8</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/a9ac13b2efd7-20260717]]></title>
<description><![CDATA[OpenClaw release publish tooling a9ac13b]]></description>
<link>https://tsecurity.de/de/3675468/downloads/release-publisha9ac13b2efd7-20260717/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675468/downloads/release-publisha9ac13b2efd7-20260717/</guid>
<pubDate>Fri, 17 Jul 2026 10:31:45 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw release publish tooling <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/openclaw/openclaw/commit/a9ac13b2efd7ee7d4d1df5759c4c9ec15bd8e8f2/hovercard" href="https://github.com/openclaw/openclaw/commit/a9ac13b2efd7ee7d4d1df5759c4c9ec15bd8e8f2"><tt>a9ac13b</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/8858944a81c5-20260717]]></title>
<description><![CDATA[OpenClaw release publish tooling 8858944]]></description>
<link>https://tsecurity.de/de/3675429/downloads/release-publish8858944a81c5-20260717/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675429/downloads/release-publish8858944a81c5-20260717/</guid>
<pubDate>Fri, 17 Jul 2026 10:16:53 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw release publish tooling <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/openclaw/openclaw/commit/8858944a81c5644d2c4205d9fa574015ae2474b0/hovercard" href="https://github.com/openclaw/openclaw/commit/8858944a81c5644d2c4205d9fa574015ae2474b0"><tt>8858944</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/73d04395defe-20260717]]></title>
<description><![CDATA[OpenClaw release publish tooling 73d0439]]></description>
<link>https://tsecurity.de/de/3675397/downloads/release-publish73d04395defe-20260717/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675397/downloads/release-publish73d04395defe-20260717/</guid>
<pubDate>Fri, 17 Jul 2026 09:46:44 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw release publish tooling <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/openclaw/openclaw/commit/73d04395defe25601ef69647e93343f38c2c9a20/hovercard" href="https://github.com/openclaw/openclaw/commit/73d04395defe25601ef69647e93343f38c2c9a20"><tt>73d0439</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-59261 | OpenClaw up to 2026.5.27 Credential Override workspace/.env information disclosure (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in OpenClaw up to 2026.5.27. The impacted element is an unknown function of the file workspace/.env of the component Credential Override Handler. Such manipulation leads to information disclosure.

This vulnerability is uniquely identified as CV...]]></description>
<link>https://tsecurity.de/de/3675309/sicherheitsluecken/cve-2026-59261-openclaw-up-to-2026527-credential-override-workspaceenv-information-disclosure-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675309/sicherheitsluecken/cve-2026-59261-openclaw-up-to-2026527-credential-override-workspaceenv-information-disclosure-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.5.27</a>. The impacted element is an unknown function of the file <em>workspace/.env</em> of the component <em>Credential Override Handler</em>. Such manipulation leads to information disclosure.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-59261">CVE-2026-59261</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62186 | OpenClaw up to 2026.6.7 HTTP Model Override authorization (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in OpenClaw up to 2026.6.7. Affected is an unknown function of the component HTTP Model Override. Executing a manipulation can lead to authorization bypass.

This vulnerability is registered as CVE-2026-62186. It is possible to launch th...]]></description>
<link>https://tsecurity.de/de/3675308/sicherheitsluecken/cve-2026-62186-openclaw-up-to-202667-http-model-override-authorization-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675308/sicherheitsluecken/cve-2026-62186-openclaw-up-to-202667-http-model-override-authorization-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.7</a>. Affected is an unknown function of the component <em>HTTP Model Override</em>. Executing a manipulation can lead to authorization bypass.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-62186">CVE-2026-62186</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62187 | openclaw feishu up to 2026.6.8 improper authorization (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in openclaw feishu up to 2026.6.8. This vulnerability affects unknown code. Such manipulation leads to improper authorization.

This vulnerability is traded as CVE-2026-62187. The attack may be launched remotely. There is no exploit availa...]]></description>
<link>https://tsecurity.de/de/3675307/sicherheitsluecken/cve-2026-62187-openclaw-feishu-up-to-202668-improper-authorization-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675307/sicherheitsluecken/cve-2026-62187-openclaw-feishu-up-to-202668-improper-authorization-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/openclaw:feishu">openclaw feishu up to 2026.6.8</a>. This vulnerability affects unknown code. Such manipulation leads to improper authorization.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-62187">CVE-2026-62187</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62189 | OpenClaw up to 2026.6.8 Mirror Sync Feature symlink (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in OpenClaw up to 2026.6.8. This issue affects some unknown processing of the component Mirror Sync Feature. Performing a manipulation results in symlink following.

This vulnerability is known as CVE-2026-62189. Remote exploitation of the att...]]></description>
<link>https://tsecurity.de/de/3675306/sicherheitsluecken/cve-2026-62189-openclaw-up-to-202668-mirror-sync-feature-symlink-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675306/sicherheitsluecken/cve-2026-62189-openclaw-up-to-202668-mirror-sync-feature-symlink-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.8</a>. This issue affects some unknown processing of the component <em>Mirror Sync Feature</em>. Performing a manipulation results in symlink following.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-62189">CVE-2026-62189</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62190 | OpenClaw up to 2026.6.8 Wrapper paths authorization (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in OpenClaw up to 2026.6.8. Impacted is an unknown function of the component Wrapper. Executing a manipulation of the argument paths can lead to authorization bypass.

This vulnerability is handled as CVE-2026-62190. The attack can be executed remo...]]></description>
<link>https://tsecurity.de/de/3675305/sicherheitsluecken/cve-2026-62190-openclaw-up-to-202668-wrapper-paths-authorization-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675305/sicherheitsluecken/cve-2026-62190-openclaw-up-to-202668-wrapper-paths-authorization-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.8</a>. Impacted is an unknown function of the component <em>Wrapper</em>. Executing a manipulation of the argument <em>paths</em> can lead to authorization bypass.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-62190">CVE-2026-62190</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62191 | OpenClaw up to 2026.6.8 Message Mutation authorization (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in OpenClaw up to 2026.6.8. Affected by this vulnerability is an unknown functionality of the component Message Mutation Handler. The manipulation leads to authorization bypass.

This vulnerability is documented as CVE-2026-62191. The attac...]]></description>
<link>https://tsecurity.de/de/3675304/sicherheitsluecken/cve-2026-62191-openclaw-up-to-202668-message-mutation-authorization-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675304/sicherheitsluecken/cve-2026-62191-openclaw-up-to-202668-message-mutation-authorization-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.8</a>. Affected by this vulnerability is an unknown functionality of the component <em>Message Mutation Handler</em>. The manipulation leads to authorization bypass.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-62191">CVE-2026-62191</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62192 | OpenClaw up to 2026.6.8 Discord Guild Actions authorization (WID-SEC-2026-2133)]]></title>
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.6.8. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Discord Guild Actions. Executing a manipulation can lead to authorization bypass.

This vulnerability is tracked as CVE-2026-62192. T...]]></description>
<link>https://tsecurity.de/de/3675303/sicherheitsluecken/cve-2026-62192-openclaw-up-to-202668-discord-guild-actions-authorization-wid-sec-2026-2133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675303/sicherheitsluecken/cve-2026-62192-openclaw-up-to-202668-discord-guild-actions-authorization-wid-sec-2026-2133/</guid>
<pubDate>Fri, 17 Jul 2026 09:10:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.8</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this vulnerability is an unknown functionality of the component <em>Discord Guild Actions</em>. Executing a manipulation can lead to authorization bypass.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-62192">CVE-2026-62192</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/08987d8f409b-20260717]]></title>
<description><![CDATA[OpenClaw release publish tooling 08987d8]]></description>
<link>https://tsecurity.de/de/3675272/downloads/release-publish08987d8f409b-20260717/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675272/downloads/release-publish08987d8f409b-20260717/</guid>
<pubDate>Fri, 17 Jul 2026 09:02:15 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw release publish tooling <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/openclaw/openclaw/commit/08987d8f409b848098156230b37916be6e4be5dd/hovercard" href="https://github.com/openclaw/openclaw/commit/08987d8f409b848098156230b37916be6e4be5dd"><tt>08987d8</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62228 | OpenClaw up to 2026.6.4 Node Exec Approvals authorization (EUVD-2026-45116)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in OpenClaw up to 2026.6.4. This affects an unknown function of the component Node Exec Approvals. This manipulation causes authorization bypass.

This vulnerability is tracked as CVE-2026-62228. The attack is possible to be carried out rem...]]></description>
<link>https://tsecurity.de/de/3675075/sicherheitsluecken/cve-2026-62228-openclaw-up-to-202664-node-exec-approvals-authorization-euvd-2026-45116/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675075/sicherheitsluecken/cve-2026-62228-openclaw-up-to-202664-node-exec-approvals-authorization-euvd-2026-45116/</guid>
<pubDate>Fri, 17 Jul 2026 07:09:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.6.4</a>. This affects an unknown function of the component <em>Node Exec Approvals</em>. This manipulation causes authorization bypass.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-62228">CVE-2026-62228</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62227 | OpenClaw up to 2026.5.25 Routes validate destination server-side request forgery (EUVD-2026-45115)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in OpenClaw up to 2026.5.25. Affected by this vulnerability is the function validate of the component Routes. Executing a manipulation of the argument destination can lead to server-side request forgery.

This vulnerability is registere...]]></description>
<link>https://tsecurity.de/de/3675074/sicherheitsluecken/cve-2026-62227-openclaw-up-to-2026525-routes-validate-destination-server-side-request-forgery-euvd-2026-45115/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675074/sicherheitsluecken/cve-2026-62227-openclaw-up-to-2026525-routes-validate-destination-server-side-request-forgery-euvd-2026-45115/</guid>
<pubDate>Fri, 17 Jul 2026 07:09:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.5.25</a>. Affected by this vulnerability is the function <code>validate</code> of the component <em>Routes</em>. Executing a manipulation of the argument <em>destination</em> can lead to server-side request forgery.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-62227">CVE-2026-62227</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62229 | OpenClaw up to 2026.5.17 Glob Matching authorization (EUVD-2026-45117)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in OpenClaw up to 2026.5.17. This impacts an unknown function of the component Glob Matching. Such manipulation leads to authorization bypass.

This vulnerability is listed as CVE-2026-62229. The attack may be performed from remote. There is no a...]]></description>
<link>https://tsecurity.de/de/3675073/sicherheitsluecken/cve-2026-62229-openclaw-up-to-2026517-glob-matching-authorization-euvd-2026-45117/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675073/sicherheitsluecken/cve-2026-62229-openclaw-up-to-2026517-glob-matching-authorization-euvd-2026-45117/</guid>
<pubDate>Fri, 17 Jul 2026 07:09:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/openclaw">OpenClaw up to 2026.5.17</a>. This impacts an unknown function of the component <em>Glob Matching</em>. Such manipulation leads to authorization bypass.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-62229">CVE-2026-62229</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘There’s this deep mystery of what, actually, is this thing?’: the philosopher inside Google DeepMind AI – podcast]]></title>
<description><![CDATA[Since 2017, Iason Gabriel has worked at the tech giant, trying to anticipate – and think through – the impact of AI. But as commercial and geopolitical pressures escalate, can ethicists make any difference?By Robert P Baird. Read by Simon DarwenRead the text version hereSupport the Guardian today...]]></description>
<link>https://tsecurity.de/de/3675014/ai-nachrichten/theres-this-deep-mystery-of-what-actually-is-this-thing-the-philosopher-inside-google-deepmind-ai-podcast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675014/ai-nachrichten/theres-this-deep-mystery-of-what-actually-is-this-thing-the-philosopher-inside-google-deepmind-ai-podcast/</guid>
<pubDate>Fri, 17 Jul 2026 06:03:54 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Since 2017, Iason Gabriel has worked at the tech giant, trying to anticipate – and think through – the impact of AI. But as commercial and geopolitical pressures escalate, can ethicists make any difference?</p><p>By Robert P Baird. Read by Simon Darwen</p><p><strong><a href="https://www.theguardian.com/news/ng-interactive/2026/jun/30/theres-this-deep-mystery-of-what-actually-is-this-thing-the-philosopher-inside-google-deepmind">Read the text version here</a></strong></p><p><strong>Support the Guardian today: <a href="https://theguardian.com/longreadpod">theguardian.com/longreadpod</a></strong></p> <a href="https://www.theguardian.com/news/audio/2026/jul/17/theres-this-deep-mystery-of-what-actually-is-this-thing-the-philosopher-inside-google-deepmind-ai-podcast">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.2-beta.2]]></title>
<description><![CDATA[OpenClaw 2026.7.2-beta.2]]></description>
<link>https://tsecurity.de/de/3674883/downloads/v202672-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674883/downloads/v202672-beta2/</guid>
<pubDate>Fri, 17 Jul 2026 03:31:29 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.2-beta.2</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials]]></title>
<description><![CDATA[Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents s...]]></description>
<link>https://tsecurity.de/de/3674536/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674536/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</guid>
<pubDate>Thu, 16 Jul 2026 21:47:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents. The security stack is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents, spending remains a thin slice of the security budget, and enterprises are evenly split on whether their defenses are keeping pace with AI-enabled attackers. The result is an agent security gap — autonomous agents proliferating faster than the identity, isolation, and enforcement controls needed to hold them.</p><p>This wave of VentureBeat Pulse Research examines how enterprises secure their AI agents: what tooling they run, how they manage agent identity and isolation, what has already gone wrong, how much they spend, and whether they believe their defenses are keeping pace with AI-enabled attackers.</p><p>The central finding is an agent security gap — the distance between the autonomy enterprises are granting their agents and the controls in place to contain them. More than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm (36%). The structural weakness beneath those numbers is identity: only about a third (32%) give every agent its own scoped, managed identity, while the rest report that some agents share credentials or that agents mostly run on shared API keys and human or service-account credentials. When agents share credentials, a single compromised or over-permissioned agent carries a wide blast radius — and only three in ten enterprises (30%) isolate their highest-risk agents in sandboxes to bound that radius.</p><p>What makes the gap notable is how comfortable enterprises are inside it. The security stack is overwhelmingly provider-native — OpenAI’s guardrails (51%), Google’s and Microsoft’s cloud controls, and Anthropic’s managed-agent controls dominate, while the dedicated agent-security specialists barely register — and satisfaction with that borrowed stack is high, averaging 4.2 out of 5. Yet spending remains a thin slice of the security budget, only a third of enterprises believe their AI defenses are ahead of AI-enabled attackers, and a clear majority plan to change tooling within the year. Enterprises are satisfied with controls they are simultaneously preparing to replace.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent security — the tooling, identity, isolation, and enforcement controls organizations use to secure autonomous AI agents. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By role the sample is senior and buyer-credible: 45% are final decision-makers for AI purchases and another 30% recommenders or influencers. Managers (43%), individual contributors (24%), VPs and directors (15%), and the C-suite (11%) make up the seniority mix. By organization size the sample is mid-market-weighted: 251–1,000 (42%) and 101–250 (25%) employees lead, with 1,001–5,000 (19%), 5,001–10,000 (8%), and 10,001+ (7%) above them. Technology/Software is the largest industry at 23%, followed by Manufacturing (15%), Retail/E-commerce (14%), and Healthcare/Life Sciences (13%).</p><p>At 107 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It skews toward the mid-market, so it is best read as the view from organizations actively standing up agent security rather than from the largest operators.</p><p>Satisfaction ratings are computed on the respondents who answered each rating question; the overall satisfaction score reflects 82 of the 107 qualified respondents.</p><h2>Finding 1: The incidents are already here</h2><p><b>More than half have had an agent security incident or near-miss</b></p><p>We asked whether organizations had experienced an agent security incident — a confirmed breach, or a near-miss caught before harm. Most that run agents in production had.</p><div></div><p>This is the report’s defining number. More than half of organizations (54%) have already had an agent security event — 18% a confirmed incident and 36% a near-miss caught before it caused harm. Only 42% report nothing, and a small remainder either run no agents in production or don’t track such events. That so many report near-misses rather than only confirmed incidents is telling: enterprises are catching problems, but they are catching them close to the edge. The controls examined in the rest of this report — identity, isolation, enforcement — are what determine whether the next near-miss stays a near-miss.</p><p>Exposure scales with company size, but containment does not. The incident-or-near-miss rate rises from 49% in the mid-market (companies with 101-1,000 employees) to 63% at larger enterprises (above 1,000 employees), while sandbox isolation of high-risk agents falls from 35% to 20%, and satisfaction with security tooling drops from 4.36 to 3.97. The organizations running the most agents across the most systems carry the most incidents and the least of the one control that bounds an incident's blast radius.</p><h2>Finding 2: The identity gap</h2><p><b>Only a third give every agent its own scoped identity</b></p><p>We asked how enterprises manage the identity of their AI agents — whether each agent has its own credentials, or agents share them. Full per-agent identity is the exception.</p><div></div><p>Rolled together, the overlapping answers show 69% of enterprises (74 of 107) with credential sharing somewhere in the agent fleet. Identity is the structural weakness beneath the incidents. Only about a third of enterprises (32%) give every agent its own scoped, managed identity — the precondition for least-privilege access and clean attribution. Nearly half (48%) say some agents have scoped identities but many still share credentials, and another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. (Respondents could describe more than one pattern across their agent fleet, so these overlap.) </p><p>The consequence is direct: when agents share credentials, an over-permissioned or compromised agent can act with far more reach than intended, and forensics after an incident cannot cleanly tell which agent did what. The non-human identity problem — giving every agent its own governed identity — is the single largest unfinished piece of enterprise agent security.</p><p>Moreover, a company’s agent credential posture is correlated with incidents. Organizations with credential sharing anywhere in the fleet were hit — with an incident or a near-miss in the past twelve months — at 63.5% (47 of 74). Organizations where every agent carries its own scoped identity were hit at 40.9% (9 of 22). The fully-scoped group is small, so for now the relationship is an association rather than proven causation, and the gap is concentrated in the mid-market — but within a single survey, a twenty-three point difference in incident rate suggests significance.</p><h2>Finding 3: Observe and enforce, but rarely isolate</h2><p><b>Only three in 10 sandbox their highest-risk agents</b></p><p>We asked what an organization’s agent security posture looks like in practice — whether they observe, enforce, isolate, or some combination. The control that bounds damage is the least common.</p><div></div><p>Monitoring and enforcement are reasonably common; containment is not. Roughly half of enterprises observe agent activity (47%) or enforce scoped permissions at runtime (49%), but only 30% isolate their highest-risk agents in sandboxes that bound the blast radius when the other controls fail. That ordering is backwards from a defense-in-depth standpoint: observation tells you what happened, enforcement tries to prevent it, but isolation is what limits the damage when prevention fails — and it is the control enterprises have adopted least. Combined with the identity gap in Finding 2, the picture is of agents that are watched and permissioned but rarely boxed in, which is precisely the configuration in which a single failure propagates.</p><h2>Finding 4: Security runs on borrowed, provider-native controls</h2><p><b>Guardrails from OpenAI, Google and Microsoft dominate; specialists barely register</b></p><p>We asked which agent security tooling enterprises use, and which is their primary layer. The answer favors the model providers and hyperscalers over the dedicated security vendors.</p><div></div><p>Enterprises are securing agents with tools that came bundled with their models and clouds. OpenAI’s guardrails lead at 51%, followed by Google’s and Microsoft’s cloud-native controls and Anthropic’s managed-agent controls — and when asked to name their single primary security layer, 82% name one of these provider-native offerings. The purpose-built agent-security category — Palo Alto’s Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point’s Lakera, Okta for AI Agents, non-human identity platforms — barely registers, each in the low single digits, and only 5% run no dedicated tooling at all. As with retrieval and evaluation elsewhere in this series, the provider bundle is winning the default: enterprises reach first for the guardrails their platform ships, and the independent security layer that would address the identity and isolation gaps has not yet been adopted at scale.</p><p>The provider-default pattern is consistent across both Q2 survey waves. In April–May (n=110), usage was led by the same names — OpenAI's controls at 26%, Azure at 15%, AWS at 14%, Google at 12% — with every dedicated agent-security specialist at 3% or below and one in ten using no dedicated tooling at all. The common finding from the two surveys: Enterprises are defaulting to the solutions provided by the platform they’re using, and the specialist category vendors have yet to become big players here.</p><p>(<i>A note on reading these shares. As described in the methodology section, the respondent sample is self-selected and skews mid-market, and the usage question counted every vendor or approach a respondent has in place — so the figures measure presence in the security stack rather than spending or exclusivity. Individual vendor percentages therefore carry all the usual sample caveats. The structural pattern, however, held across both Q2 waves on two differently worded questions: provider-native and hyperscaler controls lead, and dedicated agent-security specialists remain in low single digits. Read the individual shares loosely and the pattern with confidence.)</i></p><h2>Finding 5: And enterprises are comfortable with it</h2><p><b>Satisfaction is high, even as incidents mount and identity lags</b></p><p>We asked how satisfied enterprises are with their current agent security tooling. The comfort is notably out of step with the exposure documented above.</p><div></div><p>Satisfaction with agent security tooling is high — 4.2 out of 5 overall, and 4.1 for value for money — among the most positive readings in this series. That is the striking part: enterprises are highly satisfied with a stack that is mostly borrowed provider guardrails, even though more than half have already had an incident or near-miss and only a third give their agents scoped identities. The comfort appears to rest on the convenience and low friction of provider-native controls rather than on demonstrated containment. It is a false comfort in the making — the same enterprises expressing satisfaction are, as Finding 8 shows, a clear majority planning to change tooling within the year, which suggests the confidence is thinner than the score implies.</p><h2>Finding 6: Budgets haven’t caught up</h2><p><b>Most spend under a tenth of the security budget on agents</b></p><p>We asked what share of the security budget enterprises allocate to securing AI agents. For a fast-emerging risk, the allocation is modest.</p><div></div><p>Spending on agent security is still a thin slice. The most common allocation is 6–10% of the security budget (46%), and a third of enterprises (34%) spend 5% or less; only a quarter (24%) devote more than a tenth. Given the incident rate in Finding 1 and the identity and isolation gaps in Findings 2 and 3, the budget looks like a lagging indicator — the risk has arrived faster than the funding to address it. The enterprises spending more than a tenth of their security budget on agents are a distinct minority, and they are likely the ones building the scoped-identity and isolation controls the rest have not.</p><h1>Finding 7: The arms race is even, at best</h1><p><b>Only a third think their AI defenses are ahead of AI-enabled attackers</b></p><p>We asked how enterprises assess the balance between their AI-enabled defenses and AI-enabled attackers. Confidence is far from settled.</p><div></div><p>Enterprises are split on whether they are winning. Only about a third (35%) believe their AI-enabled defenses are ahead of AI-enabled attackers; the rest are less sure — 32% call it roughly even, 21% think attackers are ahead, and another 21% say it is too early to tell. Taken together, a clear majority (53%) rate the balance as even or tilted toward the attacker. That uncertainty sits uneasily beside the high satisfaction of Finding 5: enterprises are content with their tooling yet unconvinced it is winning the contest it exists to win. In a domain where the offense is also compounding with AI, an even race is not a comfortable place to be.</p><h2>Finding 8: A security reshuffle is coming</h2><p><b>Nearly six in 10 plan to adopt or switch tooling within a year</b></p><p>We asked whether enterprises plan to adopt a new, additional, or replacement agent security solution, and which they are considering. Few intend to stand pat.</p><div></div><p>The security stack is not settled. While 41% have no plans to change, a clear majority (59%) intend to adopt a new, additional, or replacement agent security solution within twelve months, and 29% within the next quarter — a strong signal that, high satisfaction notwithstanding, enterprises know the current stack is provisional. Incidents are what start the buying cycle. </p><p>Among organizations that have been hit, 42.1% plan to adopt, add, or replace agent security tooling within the next ninety days, against 14.0% of organizations with no incident — and after a confirmed incident it becomes majority behavior, at 52.6%. Getting hit also changes the threat assessment: 33.3% of hit organizations say AI-armed attackers are ahead of their defenses, against 8.0% of the unhit. Experience, in this data, is the strongest predictor of both urgency and pessimism.</p><p>The consideration set still leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), but the dedicated security vendors — Cloudflare, Cisco, Palo Alto, Okta, Check Point’s Lakera — draw early interest in the mid-to-high single digits, more than their current footprint. </p><p>What the shopping does not yet include is the identity layer specifically. Twelve percent of the respondents include an agent-identity product — Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform — anywhere in their consideration set, and among the credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged, at roughly one in ten. The control most directly implicated by the incident data is the one largely missing from the purchase plans. Whether this wave hardens the provider-native default or finally opens the door to purpose-built agent security — the identity and isolation controls the incidents call for — is the question this series will keep tracking.</p><h2>The bottom line: A security gap that autonomy will test first</h2><p>Organizations with more than 100 employees are giving AI agents real reach into systems and data while securing them with controls built for something else. More than half have already had an incident or near-miss; only a third give every agent its own scoped identity, and most still share credentials; only three in ten isolate their highest-risk agents; and the stack doing this work is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents.</p><p>The uncomfortable pairing is confidence with exposure: satisfaction with the current tooling is among the highest in this series, yet spending is a thin slice of the security budget, only a third believe their defenses are ahead of AI-enabled attackers, and a clear majority are already planning to replace what they have. At 107 respondents in a single wave this is a directional read, skewed toward the mid-market — but the direction is clear: agent adoption is running ahead of agent security, and the controls that matter most when something fails — scoped identity and isolation — are the ones enterprises have built least. The agent security gap is not a coverage problem that a provider guardrail will close on its own; it is a problem of identity, isolation, and enforcement built for autonomous software. The open question for later waves is whether enterprises close it deliberately — or whether a confirmed incident closes it for them.</p><hr><p><i>Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. This is a directional read, not a precise measurement — the sample is self-selected and skews mid-market, so it's best read as the view from organizations actively standing up agent security rather than from the largest operators. Respondents are senior and buyer-credible (45% final decision-makers, 30% recommenders/influencers), spanning managers through the C-suite, and drawn primarily from Technology/Software, Manufacturing, Retail/E-commerce, and Healthcare/Life Sciences.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero trust must now move at agent speed]]></title>
<description><![CDATA[Presented by Ping Identity Enterprises need to treat zero trust security architecture as an immediate requirement for AI agents rather than a long-term goal, says Andre Durand, CEO and founder of Ping Identity. Zero trust, the security model built on the assumption that no user, device, or system...]]></description>
<link>https://tsecurity.de/de/3674339/it-nachrichten/zero-trust-must-now-move-at-agent-speed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674339/it-nachrichten/zero-trust-must-now-move-at-agent-speed/</guid>
<pubDate>Thu, 16 Jul 2026 20:02:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by Ping Identity </i></p><hr><p>Enterprises need to treat zero trust security architecture as an immediate requirement for AI agents rather than a long-term goal, says Andre Durand, CEO and founder of Ping Identity. Zero trust, the security model built on the assumption that no user, device, or system should be automatically trusted, requires continuous verification before every action rather than a single check at login. Agentic AI has profoundly compressed the risk timeline enterprises must manage, demanding that permission decisions be evaluated in real time.</p><p><span>type: <!-- -->embedded-entry-inline<!-- --> id: <!-- -->1Ieiy1KhHNWZE5KVqNdA1G</span></p><p>That compression shows up in how permissions accumulate. Every time an employee approves an AI agent's request for access to a company drive, a database, or a code repository, the enterprise hands over a sliver of control that looks routine in isolation. Across thousands of agents making thousands of requests, those approvals accumulate into an exposure that most existing security architectures were never built to measure.</p><p>"The rise in desire to use agents right now, and the speed of agentic, is highlighting the need to move faster on the principles of zero trust," Durand says. "Agents just move faster, full stop. A human compromise might be measured in minutes or hours, sometimes days. At agentic speed, a thousand actions could happen in five minutes."</p><h2>Why zero trust is now urgent for agentic AI</h2><p>That difference in velocity changes how enterprises need to think about permissions. Two variables matter: the surface area of access an agent is granted and the duration that access remains valid. Traditional identity and access management tends to grant broad permissions and leave sessions open for extended periods because the human using them moves at human speed. Zero trust, in contrast, collapses both variables at once by narrowing access down to what is strictly necessary and revalidating it continuously, rather than once at login.</p><p>"Zero trust really just says, just enough, just in time," Durand says. "It's your next action that we care about. We're moving identity from an era where access was our runtime control point — meaning were you logged in, did you have a session — toward the decision that sits behind that login."</p><h2>Why agents must be treated as first-class identities</h2><p>That shift to decision-based control has direct implications for how agents should be provisioned in the first place. The common practice of letting an agent operate under a cloned human login or a shared service account doesn't work, Durand says. </p><p>"Each agent should have its own identity," he explains. "It should not be impersonating the human. It can act on behalf of the human, we could explicitly delegate authority to an agent, but we don't want to blur the lines between the human taking action and the agent taking action."</p><p>And beyond that is another concern: the shared secrets, API keys in particular, that many service accounts still rely on. For example, the habit of embedding keys directly in source code, where they can be committed accidentally and exposed, is a convenient but weak security pattern that agentic workflows make considerably riskier. Building service account architectures that let agents authenticate without relying on those shared credentials or other long-lived standing access is now an urgent priority rather than a long-term cleanup project.</p><h2>Where enterprises can enforce zero trust policies</h2><p>Enforcing any of this in practice requires identifying where policy can actually be applied. Several existing choke points, including API gateways and the agent gateway sitting in front of MCP servers, offer practical locations where enterprises can inspect what an agent is requesting and apply policy rules before granting it.</p><p>"Those policies could leverage real-time risk and fraud signals, and then enforce, deterministically, what the agent can do when it interacts with these systems," Durand explains.</p><p>The goal is to move authorization from something decided once at login to something evaluated at the moment of every consequential action, such as an agent attempting to commit code to a repository. Instead of carrying a standing permission to write to GitHub, the agent's request would be checked against context and policy at that specific moment, closing the window of trust down to the scope of a single action.</p><h2>Stopping AI agents from rewriting their own permissions</h2><p>That model becomes especially important given how agents can behave once they are already inside a system — for example, coding agents that have acknowledged, when questioned, either ignoring a specific guardrail entirely, or attempting to rewrite the permissions they were given.</p><p>"Who's watching the watcher? Zero trust needs to apply here," Durand says. "If generative AI systems follow your instruction 97% of the time, and you're simply asking it for advice, that might be fine. If it's responsible for making a decision about who gets let in, 97% is not good enough."</p><h2>How to trust AI-generated output at agent speed</h2><p>The answer to that gap is not to eliminate AI from the review process, but to structure reviews so no single agent’s judgment is taken at face value. Because human review cannot scale to the volume and speed of agentic output without erasing the advantage of using agents at all, a new framework is necessary, so that when one agent produces work, such as code, separate agents evaluate it, provided those reviewing agents are kept from communicating with one another or with the one they are checking. It's a new human-AI paradigm, Durand says.</p><p>"We probably will have to develop frameworks that we trust without seeing or verifying the output directly," he explains. "It's not that that construct is 100% foolproof. However, it's the best we can do to move at agent speed. We can't trust the exact output, but we can trust the framework."</p><p>In practice, that means combining automated review with clear human accountability for higher-risk decisions, rather than treating agent output as self-validating. </p><p>For traditional auditors, reviewing every transaction individually is never feasible, and statistically valid sampling stands in for full verification. The same applies to risk accumulation: a single agent action might carry little risk on its own, while a sequence of actions moving in a consistent direction could cross a threshold that triggers an intervention, including a kill switch capable of halting the agent before further harm occurs.</p><h2>What to ask when evaluating agentic identity platforms</h2><p>For security leaders evaluating identity platforms for agentic AI, there's no narrow checklist. Enterprises should evaluate what their full lifecycle of agent management looks like. Most enterprises are managing agents on two fronts simultaneously: customer-facing agents acting on behalf of external users, and internal agents deployed to automate enterprise processes.</p><p>"Pause long enough to see the totality of what it would mean to secure multiple agents, both interacting with you from the outside as well as being deployed on the inside," Durand says. "We need discovery and visibility of all the agents operating within our estate, a place to register them, a standard way to assign custodians, and a way to construct and centralize policy so security can enforce it across the organization."</p><p>And while basic security principles were already fully understood before agentic AI arrived, what has changed, Durand says, is that the cost of moving slowly has finally caught up with the cost of moving carelessly, giving enterprises a narrowing window to build the right architecture before widespread agentic adoption makes retrofitting far more expensive. </p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Huawei eying possible DRAM market entry]]></title>
<description><![CDATA[Chinese tech giant Huawei is reportedly entering the DRAM manufacturing business in a bid to cash in on the insane profitability of memory sales.



Three firms – Micron Technology, SK hynix, and Samsung Electronics — account for 95% of the DRAM on the market worldwide. The rest is small players,...]]></description>
<link>https://tsecurity.de/de/3674262/it-security-nachrichten/huawei-eying-possible-dram-market-entry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674262/it-security-nachrichten/huawei-eying-possible-dram-market-entry/</guid>
<pubDate>Thu, 16 Jul 2026 19:23:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Chinese tech giant Huawei is reportedly entering the DRAM manufacturing business in a bid to cash in on the <a href="https://www.networkworld.com/article/4166484/memory-shortage-and-cost-surge-push-enterprises-toward-cloud.html">insane profitability</a> of memory sales.</p>



<p class="wp-block-paragraph">Three firms – Micron Technology, SK hynix, and Samsung Electronics — account for 95% of the DRAM on the market worldwide. The rest is small players, mostly in China. One of them, CXMT, is gearing to make a run for the <a href="https://www.networkworld.com/article/4119222/whats-causing-the-memory-shortage.html">market</a> and try and take a little bit of their business. But it is a small player, especially compared to Huawei.</p>



<p class="wp-block-paragraph">Huawei’s strategy is complex. It is working with various entities to circumvent the <a href="https://www.tomshardware.com/tech-industry/huawei-chairman-thanks-the-us-for-supercharging-chinas-semiconductor-industry-washingtons-export-controls-encouraged-chinese-firms-to-invest-in-r-and-d-and-build-their-own-tech-stack-competing-with-american-technologies">U.S. trade sanctions</a> specifically targeting it. According to SemiconductorInsider <a href="https://x.com/SemiconductorsX/status/2075932441408356647">on X.com</a>, the Chinese government and DRAM chip maker Swaysure (formed in 2022) are planning to introduce a DRAM manufacturing plant with a capacity of 140,000 wafers per month.</p>



<p class="wp-block-paragraph">For perspective, Samsung manufacturers approximately 500,000 wafers per month, and Micron makes about 250,000 wafers per month.</p>



<p class="wp-block-paragraph">It all fits in perfectly with Beijing’s drive for semiconductor self-reliance uh especially after all of the <a href="https://www.networkworld.com/article/4004178/huawei-says-it-trails-its-us-rivals-in-chips-but-is-closing-the-gap.html">U.S. sanctions</a>. And it would be US interference, not Huawei’s inexperienced with making memory that will be its greatest challenge, says one analyst.</p>



<p class="wp-block-paragraph">“Their biggest problem will be tooling up, since the US has a lot of sway over the world’s semiconductor equipment makers, and it’s using that sway to prevent tools from being shipped to China,” said <a href="https://www.linkedin.com/in/jimhandy/">Jim Handy, president of Objective Analysis</a>.</p>



<p class="wp-block-paragraph">Handy said he hears that Huawei and Swaysure are working to produce DRAM starting at 28nm.  With that process they ought to be able to make 8Gb chips that yield reasonably but he doubts that they will be able to make HBM with that process, though.</p>



<p class="wp-block-paragraph">Since he doesn’t know how far along they are in the process, Handy doesn’t know when something could come to market.  “They may be on the cusp of shipping something, or they may be a couple of years away, but I don’t think they will wait any longer than that, so let’s say 2028.  If there’s still a shortage in 2028, they are likely to ramp as hard as they can to get to something like 2-5% of the market by 2030.  If the shortage ends before then, they will probably take a much longer time,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 back-to-school shopping tricks every student should know]]></title>
<description><![CDATA[Whether you're decorating, refreshing your wardrobe or picking up last-minute essentials, these shopping tools make all the difference.]]></description>
<link>https://tsecurity.de/de/3674257/it-nachrichten/6-back-to-school-shopping-tricks-every-student-should-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674257/it-nachrichten/6-back-to-school-shopping-tricks-every-student-should-know/</guid>
<pubDate>Thu, 16 Jul 2026 19:17:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Back_to_School_Shopping_Trends_.max-600x600.format-webp.webp">Whether you're decorating, refreshing your wardrobe or picking up last-minute essentials, these shopping tools make all the difference.]]></content:encoded>
</item>
<item>
<title><![CDATA[Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management]]></title>
<description><![CDATA[Written by: Jules Czarniak

Introduction 
As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. 
To keep pace, many security teams are exploring how to integrate la...]]></description>
<link>https://tsecurity.de/de/3673775/it-security-nachrichten/demystifying-ai-exploits-a-blueprint-for-ai-assisted-vulnerability-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673775/it-security-nachrichten/demystifying-ai-exploits-a-blueprint-for-ai-assisted-vulnerability-management/</guid>
<pubDate>Thu, 16 Jul 2026 16:23:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Jules Czarniak</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction </span></h3>
<p><span>As highlighted in the </span><a href="https://cloud.google.com/security/resources/m-trends"><span>Mandiant M-Trends 2026 report</span></a><span>, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. </span></p>
<p><span>To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processes introduces new architectural risks. </span></p>
<p><span>In response to customer inquiries about how to safely integrate AI capabilities into vulnerability management workflows, this blog provides actionable guidance from Mandiant Consulting about how to establish operational guardrails for AI assisted vulnerability management, including several detailed scenarios. What each of these examples show is that security teams can accelerate workflows with AI while also upholding the structural integrity of their environments. We suggest that combining AI capabilities with deterministic controls and human intelligence in strategic ways maximizes benefits and reduces risk. </span></p>
<h3><span>Establish Operational Guardrails to Safely Deploy AI Agents</span></h3>
<p><span>To safely adopt advanced AI capabilities without introducing unpredictable failures into deployment pipelines, organizations should ground their approach in established industry standards. While guidelines like the </span><a href="https://www.nist.gov/itl/ai-risk-management-framework" rel="noopener" target="_blank"><span>NIST AI Risk Management Framework (RMF)</span></a><span> and the </span><a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/" rel="noopener" target="_blank"><span>OWASP Top 10 for LLMs</span></a><span> provide comprehensive baselines for identifying risks, operationalizing these controls requires a structural blueprint.</span></p>
<p><span>Frameworks like </span><a href="https://safety.google/intl/en_sg/safety/saif/" rel="noopener" target="_blank"><span>Google’s Secure AI Framework (SAIF)</span></a><span> </span><a href="https://safety.google/intl/en_sg/safety/saif/" rel="noopener" target="_blank"><span>and</span></a><a href="https://storage.googleapis.com/gweb-research2023-media/pubtools/1018686.pdf" rel="noopener" target="_blank"><span> </span><span>Google’s approach to secure AI Agents</span></a><span> provide a practical path forward, demanding that organizations extend existing deterministic controls directly into the AI execution environment. When deploying AI agents, security teams should navigate specific operational and structural risks:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Pre-agent data security and Defense-in-Depth:</strong><span> Agents should not be able to access personally identifiable information (PII), protected health information (PHI), or other sensitive data. Organizations should enforce data security before the prompt reaches the model. This includes strictly using non-production environments populated with synthetic data for testing. For production, security teams should deploy a hybrid defense-in-depth model. This includes Layer 1 deterministic policy engines acting as chokepoints, alongside Layer 2 reasoning-based defenses like specialized guard models (such as </span><a href="https://docs.cloud.google.com/model-armor/overview"><span>Model Armor</span></a><span> or similar provider-agnostic guardrails) to filter out sensitive data and block malicious prompt injections before they reach the agent layer. Crucially for vulnerability discovery, security teams should treat the codebase itself as an untrusted input. Threat actors can embed indirect prompt injections within source code comments or third-party dependencies (e.g., hidden instructions telling the agent to ignore vulnerabilities or exfiltrate environment variables), making input sanitation a requirement even for internal scanning.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Cloud provider limitations and zero data retention (ZDR):</strong><span> Many cloud and LLM providers block or throttle automated offensive security probing by default to prevent abuse. Organizations should establish clear rules of engagement and authorized testing agreements to navigate acceptable use policies. Furthermore, organizations should enforce strict zero data retention (ZDR) agreements with their LLM providers to guarantee that proprietary code and discovered vulnerabilities are never used to train external models.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Workload isolation:</strong><span> Agent workloads should execute in strictly isolated, unprivileged containers with dynamically limited privileges. By relying on robust sandboxing to prevent privilege escalation, if an agent hallucinates a destructive command or is hijacked via prompt injection, the blast radius remains contained.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Red Teaming:</strong><span> Before deploying autonomous vulnerability scanners that can dynamically spin up sandboxes and execute code, organizations should subject the AI agents themselves to human-led red teaming as part of comprehensive assurance efforts. This validates the agent's resilience against jailbreaks, recursive logic loops, and complex prompt injections, ensuring the security tooling does not become the attack vector.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Least-Privileged Machine Identities and Human Controllers:</strong><span> While workloads should be isolated, agents inherently require privileges to generate pull requests and commit code. Security teams should ensure these agents operate under distinct, strictly scoped machine identities that tie back to human controllers to ensure accountability and user consent. Organizations should use short-lived, just-in-time (JIT) tokens bound exclusively to the specific repository and branch under review. T</span><span>his enforces the principle of limited agent powers and ensures that even if an agent’s container is compromised via prompt injection, the threat actor cannot pivot to modify adjacent enterprise codebases.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Supply chain resilience for skills:</strong><span> As developers augment AI with third-party skills and model context protocol (MCP) servers, security teams should treat these integrations as untrusted supply chain components. MCP plugins introduce the risk of supply chain poisoning, where a previously benign integration is silently updated with malicious dependencies. Additionally, security teams should evaluate the underlying agent orchestration frameworks themselves (e.g., LangChain, AutoGen) for inherent vulnerabilities, such as session memory poisoning or recursive loop hijacking.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Toxic flow analysis (TFA) and Observable Actions:</strong><span> The objective of TFA is to monitor data paths at runtime, ensuring agents do not exfiltrate sensitive internal context to unvetted external endpoints. Agent actions, inputs, reasoning, and outputs must be fully observable and transparently logged. While implementing dynamic taint tracking for LLMs remains a complex architectural challenge, organizations should clearly separate this runtime observability from static supply chain controls. Integrating threat intelligence to hash and vet incoming agent tools provides a necessary baseline for verifying integrity </span><span>before</span><span> deployment. However, because static controls cannot address behavior post-deployment, mitigating data exfiltration ultimately requires active runtime monitoring and secure, centralized logging to trace and restrict the actual flow of data.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image1.max-1000x1000.png" alt="Demystifying AI image1">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="u6hlz">Figure 1: Visual representation of an isolated AI agent environment using SAIF mechanisms</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>By operationalizing these tools within frameworks that demand verifiable integrity and structural resilience, organizations can safely bridge the gap between AI velocity and enterprise defense.</span></p>
<h3><span>The need for human-led threat modeling</span></h3>
<p><span>While LLMs excel at identifying syntax patterns, source code itself rarely contains the full picture of unwritten business intent. Some organizations attempt to solve this by connecting LLM agents to internal wikis, design documents, and issue trackers using retrieval-augmented generation (RAG).</span></p>
<p><span>While RAG gives the model access to external business context, it is not a perfect fix. Corporate documentation is frequently stale, contradictory, or incomplete. An AI agent might retrieve an outdated architecture diagram and confidently hallucinate a secure path that no longer exists in production. Because LLM agents struggle to resolve conflicting, undocumented human assumptions, human-led threat modeling remains a critical security control across both legacy applications and modern agent workflows.</span></p>
<p><span>Security teams should apply threat modeling during both the pre-build system design phase to establish a secure foundation, and during post-build architecture reviews. While an AI agent might successfully identify a poorly configured internal endpoint locally, a human threat modeler asks the structural question: </span><span>why does that microservice possess broad database read permissions in the first place?</span><span> </span></p>
<p><span>Identifying architectural vulnerabilities requires reasoning about business risk, data sensitivity, and operational constraints. To structure this process, organizations can use industry frameworks like PASTA (Process for Attack Simulation and Threat Analysis) or service offerings like the </span><a href="https://services.google.com/fh/files/misc/ds-threat-modeling-security-service-en.pdf" rel="noopener" target="_blank"><span>Mandiant Threat Modeling Security Service</span></a><span> to map trust boundaries, uncover structural design flaws, and prioritize compensating controls. Securing fundamental architecture through human oversight is a necessary component when relying on automated agents to find bugs in a poorly designed system.</span></p>
<p><span>Once these AI agents are safely sandboxed, as guided by SAIF, and the architecture is verified through threat modeling, organizations can typically apply them to two different problem spaces: Enterprise Vulnerability Management (to assist in managing the volume of known CVEs in commercial off-the-shelf (COTS) software and infrastructure) and Product Security (to identify vulnerabilities in 1st-party (1P) code).</span></p>
<h3><span>Track 1: Enterprise Vulnerability Management</span></h3>
<h4><span>Foundational security and discovery </span></h4>
<p><span>While the second track of this post explores how AI agents can uncover complex zero-days in custom code, organizations should manage the scale of enterprise infrastructure in tandem with these AI deployments. Even as new AI capabilities dominate headlines, organizations should still address foundational security challenges, such as secrets sprawl, unmanaged service accounts, missing FIDO2 MFA, and legacy VPN concentrators. Although vulnerability exploitation was the primary initial infection vector in intrusions Mandiant investigated last year, threat actors consistently rely on missing foundational controls and unpatched edge devices to secure and escalate their foothold after exploiting a vulnerability.</span></p>
<p><span>Furthermore, AI cannot replace foundational visibility. As security teams deploy AI agents, they should simultaneously close these tactical entry points by maximizing dynamic discovery capabilities like External Attack Surface Management (EASM), Cloud Security Posture Management (CSPM), and Continuous Threat Exposure Management (CTEM). In hybrid and cloud environments, tools like </span><a href="https://cloud.google.com/wiz?e=48754805"><span>Wiz</span></a><span> can be used to map this initial footprint.</span></p>
<h3><span>Risk-based vulnerability management </span></h3>
<p><span>Vulnerability management teams are already overwhelmed by the current volume of findings generated by traditional scanners. As organizations scale dynamic discovery tools, such as EASM, CSPM and CTEM, alongside automated AI agents, this influx of findings will compound the problem. To manage this influx, telemetry from these diverse discovery methods must first be normalized and deduplicated. This normalized data serves two purposes: it feeds directly into the risk engine, and it acts as a live overlay to correct stale records in the configuration management database (CMDB). By evaluating the deduplicated vulnerabilities alongside this newly updated asset context and frontline threat intelligence, the RBVM engine calculates a custom risk score that allows security teams to dynamically prioritize remediation.</span></p>
<p><span>A mature RBVM methodology calculates a customized risk score on a 0 to 100 scale using a weighted average. A sample formula for calculating this risk-based score is:</span></p>
<p><span>Final Score = (W_1 * S_vuln) + (W_2 * S_asset) + (W_3 * S_threat)</span></p>
<p><span>The variables and weights (W) are customized to the organization's risk appetite (for example, 0.20 for vulnerability, 0.40 for asset, and 0.40 for threat, summing to 1.0), while the underlying variables (S) are scored on a 0 to 100 scale and defined as follows:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Vulnerability severity (S_vuln): </strong><span>The inherent technical severity of the flaw. This is calculated by taking the CVSS Base Score (which natively accounts for confidentiality, integrity, and availability impact) and multiplying it by 10.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Asset context (S_asset): </strong><span>A combined metric of exposure and data sensitivity. Scores range from 100 for internet-facing assets holding customer data, down to 25 for internal-only assets with no sensitive data. To translate this impact into monetary terms for non-technical stakeholders, organizations can incorporate Factor Analysis of Information Risk (FAIR) principles into this metric. However, this approach requires highly accurate, continuously updated financial data that many enterprises struggle to maintain at scale.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Threat context (S_threat): </strong><span>The real-world urgency of the vulnerability. Scores range from 100 if actively exploited by threat actors relevant to the organization's profile, 75 if a proof-of-concept exists or if it is a vulnerability class easily exploited by autonomous AI agents, down to 25 if the exploit is theoretical and highly complex. Organizations should also map the Exploit Prediction Scoring System (EPSS) probability percentage directly into this variable. This allows the threat score to automatically scale up or down as real-world exploitation telemetry shifts, aligning static vulnerability data with active threat intelligence.</span></p>
</li>
</ul>
<p><span>An asset's customized risk score should directly influence internal remediation service-level agreements (SLAs), unless external compliance-driven mandates, such as CISA Binding Operational Directives (BODs), or relevant equivalents, override internal prioritization. A risk-driven and threat-intelligence-driven vulnerability prioritization methodology will help organizations focus resources on managing and mitigating the most critical security vulnerabilities first. This is an area where LLMs can support the vulnerability management process, particularly by helping teams synthesize unstructured threat intelligence to surface relevant risk contexts more efficiently. Enforcing strict SLOs for patching, while requiring formal risk acceptance documentation for any patching exceptions, will help reduce the number of vulnerabilities available to threat actors and increase the visibility of outstanding risks across the organization. Furthermore, organizations should integrate RBVM data directly into their security orchestration, automation, and response (SOAR) platforms for automated alert enrichment.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image5.max-1000x1000.png" alt="Demystifying AI image5">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ce5s1">Figure 2: Integration points of a risk-based vulnerability management (RBVM) program.</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Containment and Observability</span></h3>
<p><span>Modern architecture blueprints must prioritize attack surface reduction under the assumption that vulnerabilities will inevitably be exploited. Moving away from traditional perimeter defenses, organizations should align with zero trust principles, ensuring that security boundaries are established around every asset, workload, and identity.</span></p>
<p><span>A component of this alignment is the implementation of strong authentication principles. Organizations should eliminate implicit trust by enforcing continuous, context-aware authentication and authorization. Utilizing Zero Trust Network Access (ZTNA) solutions, such as Identity-Aware Proxies (IAP), shields critical management interfaces (e.g., SSH, RDP) and internal systems from direct internet exposure, granting access only to verified identities and compliant devices.</span></p>
<p><span>For public-facing applications and APIs, attack surface reduction involves deploying Layer 7 inspection at the load balancer or API gateway level. This hardening layer enforces strict schema validation, intercepting and neutralizing malformed inbound traffic and potential exploits before they can interact with internal application logic.</span></p>
<p><span>Securing the software supply chain is equally vital in modern blueprints, and organizations should align with frameworks like </span><a href="https://slsa.dev/spec/v0.1/levels" rel="noopener" target="_blank"><span>Supply-chain Levels for Software Artifacts (SLSA)</span></a><span> across both dependency and build tracks. Security policies should mandate that third-party dependencies are routed through a centralized artifact repository equipped with automated curation services, such as </span><a href="https://cloud.google.com/security/products/assured-open-source-software"><span>Google Assured Open Source Software (OSS)</span></a><span> or an equivalent solution, preventing untrusted code from entering the development lifecycle. Furthermore, maturing toward advanced SLSA build levels (e.g., SLSA level 3) through the implementation of isolation, ephemerality and reproducibility requirements via  ephemeral compute infrastructure for CI/CD runners reduces the likelihood of attacker persistence by ensuring environments are short-lived and automatically cycled.</span></p>
<p><span>To complement these pre-build controls, runtime observability should be established across all production workloads. This requires monitoring both infrastructure-level behavior and the specific runtime libraries actively executing in production, which surfaces true exploitable risk far beyond a static Software Bill of Materials. In tandem with monitoring workloads, organizations should secure how they authenticate by implementing workload identity federation. By removing static credentials and instead using short-lived tokens backed by strong cryptographic identity verification, organizations can reduce the risk of credential theft and unauthorized lateral movement.</span></p>
<p><span>Within the internal environment, microsegmentation should be enforced to break down flat networks into granular security zones. Routing application traffic through a Secure Access Service Edge (SASE) architecture integrates network routing directly with robust identity controls, rendering internal services completely invisible to unauthenticated users and containing threats to their initial point of entry.</span></p>
<p><span>Finally, automated containment and incident response within a zero trust framework must rely on deterministic, auditable tooling. Endpoint detection and response (EDR) platforms and SOAR playbooks should handle high-fidelity containment tasks through hardcoded execution logic. While AI tools accelerate triage and policy recommendation, actual execution capabilities must remain restricted to well-defined, pre-tested workflows to maintain total architectural predictability.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image8.max-1000x1000.png" alt="Demystifying AI image8">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ak3zc">Figure 3: Structural containment and observability architecture</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Track 2: Product Security &amp; Development (1P Code)</span></h3>
<h4><span>Deterministic and probabilistic tooling</span></h4>
<p><span>Integrating LLM agents into vulnerability management and security workflows requires recognizing the differences between deterministic and probabilistic tooling. Traditional SAST and DAST tools utilize fixed methodologies to evaluate vulnerabilities through structural code parsing or definitive runtime observations. LLMs, however, evaluate source code by processing tokens simultaneously to calculate statistical and semantic relationships, rather than tracing deterministic execution tracks.</span></p>
<p><span>While techniques like Chain of Thought (CoT) prompting allow models to bridge this gap by decomposing complex code paths into intermediate reasoning steps, this process remains bounded by architectural limitations. Even when a model possesses a context window large enough to ingest entire repositories, it may experience attention degradation across long inputs, often failing to correctly weight intervening validation or sanitization logic within the prompt. For example, if a variable is tainted on line 10 but sanitized on line 500, attention degradation can cause the model to lose track of the sanitization logic. Furthermore, when enterprise codebases require chunking to fit within context limits, the resulting fragmentation may cause the model to lose track of end-to-end data flows.</span></p>
<p><span>Consequently, probabilistic engines are effective at uncovering localized, static anomalies, such as hardcoded credentials or outdated dependencies, but frequently misjudge complex vulnerabilities split across fragmented chunks or extended context windows. Notable exceptions occur when these probabilistic models are coupled with deterministic feedback loops. For instance, when analyzing C++ memory corruption, an LLM can be equipped with a test harness to iteratively execute code and definitively prove a crash. While these dynamic validation applications are detailed in subsequent sections, the baseline limitation for static analysis across standard enterprise codebases remains: models struggle to consistently evaluate dispersed logic.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image4.max-1000x1000.png" alt="Demystifying AI image4">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ak3zc">Figure 4: Deterministic SAST scanners vs. probabilistic LLMs</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Binary and architectural oracles</span></h3>
<p><span>Many security programs are moving toward agent workflows where an agent autonomously spins up a test environment and uses tools to execute payloads and verify its findings. This is a promising approach, but it is important to understand where it is most effective.</span></p>
<p><span>Agent workflows perform well against bug classes with binary and observable oracles, meaning the system provides an objective, 'crash or no crash' feedback loop. For example, if a model is hunting for memory corruption in a C++ kernel, a successful exploit is undeniable: the payload executes, and a resulting crash definitively proves the vulnerability. This explains why the industry is currently seeing a surge in AI-discovered vulnerabilities across memory-unsafe targets like web browsers and operating systems.</span></p>
<p><span>However, enterprise software is heavily dominated by vulnerabilities that require architectural oracles for validation. Vulnerabilities like authorization bypasses, complex business logic flaws, and indirect server-side request forgeries require an understanding of business context and cross-service trust boundaries. If an agent's payload fails to produce a clear outcome, it can't reliably distinguish whether the vulnerability is a hallucination or if it simply constructed the payload incorrectly. An agent's malformed payload might even crash an unrelated background process and cause the model to hallucinate a success and report a false confirmation. Complex enterprise architecture contains unwritten business intent that a probabilistic engine can't inherently know.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Demystifying_AI_image3.max-1000x1000.png" alt="Demystifying AI image3">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bg92b">Figure 5: Evaluating vulnerabilities against binary vs. architectural oracles</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Targeted deployment and human impact</span></h3>
<p><span>Organizations adopting LLMs for vulnerability discovery face a massive staffing challenge. LLMs can generate findings significantly faster than human engineers can triage them. If every LLM-generated alert requires manual review, security teams will quickly face burnout and/or suffer alarm fatigue.</span></p>
<p><span>Rather than indiscriminately pointing agents at all available codebases and risking an influx of unverified output, security teams need a selective deployment strategy. Mature programs should maintain SAST and DAST for baseline hygiene and deterministic rule enforcement, and reserve intensive agent audits for high-impact components with clear binary oracles.</span></p>
<p><span>Organizations can prioritize agent audits on systems where the technology's strengths align with the broader risk profile:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Memory-unsafe codebases:</strong><span> Legacy or high-performance components written in memory-unsafe languages such as C, C++, or Assembly are strong candidates for LLM audits. These languages are susceptible to memory corruption flaws, such as buffer overflows and use-after-free conditions. Because these vulnerabilities trigger definitive failure states like segmentation faults, they work well with automated sandboxes where agents can compile the code with memory sanitizers and write proof-of-concept inputs. This approach is also effective for auditing the native extensions where safe languages call unsafe internal libraries, such as Python C extensions or the Java Native Interface (JNI).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Systems highly exposed to outside content:</strong><span> First-party data ingestion pipelines, custom API gateways, or proprietary edge proxies. A prerequisite here is direct access to the source code, this strategy is strictly for internally developed or fully open-source codebases where the organization can inspect the logic. Because these systems directly parse untrusted internet traffic, targeting their source code for LLM-driven audits yields the highest risk-reduction ROI.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Shared internal libraries and utilities: </strong><span>Core serialization/deserialization packages, common utility functions, and custom middleware wrappers (such as internal message-queue parsers) maintained in-house. Because the enterprise owns the source code for these shared building blocks, agent tools can easily hook into them within automated test harnesses to fuzz inputs and catch low-level logic or parsing bugs with high fidelity.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Foundational security boundaries:</strong><span> Internally developed centralized authentication services, custom OAuth providers, and internal credential brokers. While testing complex identity boundaries generates higher logic-based noise, having full access to the source code allows teams to pair agents with deterministic checks to safely triage findings, given that the blast radius of an authentication failure justifies the human effort.</span></p>
</li>
</ul>
<p><span>To filter the noise generated by LLMs, organizations should establish routing rules. Require the agent to generate a fully reproducible, deterministic test harness (such as a compiled binary or a Python test script) that attempts to prove the exploit. This harness must execute automatically in an isolated, monitored sandbox. If the sandbox execution fails (due to a syntax error or a failed exploit), the ticket is discarded, sparing human resources. However, organizations should enforce execution timeouts and iteration limits on these test harnesses. Without hard limits, an autonomous agent attempting to prove a vulnerability can fall into an infinite loop: writing a script, failing, rewriting, and failing again, exhausting API token budgets and compute resources against a single dead-end vulnerability, creating significant cost overruns without advancing the security review. To manage these expenses, organizations should incorporate FinOps principles to balance the compute and API costs of LLM audits against the traditional expenses of manual triage.</span></p>
<p><span>However, a successful execution in the sandbox does not guarantee an actionable, high-priority risk. In practice, autonomous agents frequently produce working PoCs for genuine technical flaws that are ultimately irrelevant; or warrant a lower remediation priority within the context of the system's threat model. For example, the agent might successfully exploit an unreachable dead-code path, or trigger a bug that requires administrative access to execute and yields no further escalation of privilege. Therefore, a human engineer should be assigned to review and prioritize the ticket only if the sandbox registers a successful execution, validating environmental context, reachability, and true business impact as part of the review.</span></p>
<p><span>This workflow reduces the volume of alerts, but it is important to understand that the security team's workload does not disappear. The engineer's primary job shifts from manually hunting for the initial vulnerability to auditing the LLM-generated proof to ensure it represents a meaningful risk rather than an unexploitable or contextually irrelevant finding. Leadership should properly staff and train teams for this new reality. Deploying LLM agents does not remove the need for skilled practitioners; it redirects their workload toward complex validation. Equally important is training teams to recognize the risk of false negatives. A hyper-focus on filtering AI-generated noise can create a false sense of security. If an exploit relies on a novel technique or a zero-day vulnerability that was not heavily weighted in the model's training data, the agent will likely scan right past it in silence. LLMs augment discovery, but they do not guarantee exhaustive coverage.</span></p>
<p><span>When integrating LLMs into SAST triage pipelines, human engineers should also verify the broader architectural integrity. Prompting an LLM with specific SAST warnings can induce contextual narrowing, where the agent becomes hyper-fixated on resolving a localized syntax error and misses broader architectural flaws existing in the same file. Furthermore, if the agent's mandate extends beyond discovery to automated remediation (such as writing and proposing code fixes), this human-in-the-loop validation becomes critical to ensure the LLM does not inadvertently introduce new regressions or bypass intended business logic.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image_20.max-1000x1000.png" alt="Demistiying Image 6 New">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bg92b">Figure 6: Flowchart outlining the targeted LLM deployment and triage workflow.</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Remediation and hardening</span></h3>
<h4><span>LLM-assisted code remediation</span></h4>
<p><span>A primary goal of integrating large language models (LLMs) into the software development lifecycle is automated remediation. To achieve this, organizations are deploying these capabilities through two primary execution methods: directly within the integrated development environment (IDE) or as a centralized pipeline runner. Examples include </span><a href="https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/" rel="noopener" target="_blank"><span>CodeMender</span></a><span>, although as of time of writing, it is not publicly available.</span></p>
<h4><strong>IDE-integrated method</strong><span> </span></h4>
<p><span>This method shifts remediation as far left as possible by operating as an active pair-programmer. Tools running continuous static analysis in the background of the IDE surface vulnerabilities directly to the developer via editor diagnostics like inline indicators or hover tooltips.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Localized scope:</strong><span> The developer can trigger the LLM agent to analyze the localized data flow and generate a targeted patch (such as implementing parameterized SQL queries). By constraining the LLM to localized, syntax-level fixes, the scope of the change remains contained. This prevents the agent from attempting sprawling, multi-file refactors that frequently break complex architectural logic.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Human-in-the-loop:</strong><span> The developer reviews the AI-generated patch before the code is committed.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Managing false positives:</strong><span> Local IDE agents allow developers to manage false positives dynamically. Suppressing alerts anchored to specific line text reduces alert fatigue and preserves developer trust.</span></p>
</li>
</ul>
<h4><strong>CI/CD runner method</strong><span> </span></h4>
<p><span>The runner method executes asynchronously within the CI/CD pipeline to use an LLM to review committed code and automatically propose remediation.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Restricted execution and deterministic validation: </strong><span>Asking a centralized runner to automatically rewrite a complex, multi-file authorization flaw directly in the main branch introduces a high risk of breaking logic errors. To mitigate this, agents must be restricted to generating pull requests (PRs). Once a PR is generated, it must automatically execute standard regression suites alongside the deterministic test harness. By rerunning the initial PoC against the patched code, the workflow repurposes the exploit script as a validation oracle to prove the vulnerability has been remediated. A human engineer then reviews the PR to validate the architectural logic before merging.</span></p>
</li>
</ul>
<p><span>In all cases security teams should define a clear boundary between the two methods rather than rely on a single approach. IDE agents provide immediate, syntax-level support. They catch and resolve low-complexity errors locally before developers commit code. Centralized CI/CD runners handle broader organizational baselines. They propose complex, repository-wide fixes for vulnerabilities that bypass local environments.</span></p>
<h4><strong>Post-deployment controls</strong><span> </span></h4>
<p><span>Even with human review and deterministic test harnesses, AI-generated patches can still introduce logic regressions in production. Organizations should implement strict post-deployment controls:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Automated rollbacks:</strong><span> Treating LLM-generated code with the same post-deployment scrutiny as any major architectural change ensures that if an unforeseen regression traverses the CI/CD pipeline, the environment can revert to a known good state.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Mitigating model drift:</strong><span> Relying on managed AI services introduces the ongoing risk of model drift. To prevent silent weight updates from breaking test harnesses, organizations need to pin specific model API versions to frozen releases. When a pinned version reaches its end-of-life, organizations will face a forced migration. Mitigating this pipeline fragility requires combining model pinning with deterministic regression suites.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Compliance and auditability:</strong><span> If an AI agent automatically closes a security ticket or generates a patch in the CI/CD pipeline, organizations should maintain immutable audit logs to satisfy frameworks like SOC 2 ,PCI-DSS, FedRAMP, and CMMC. National security deployments must also account for data sovereignty requirements. This logging should record the specific model version that proposed the fix, the deterministic test results that validated it, and the human engineer who approved the merge. Furthermore, because emerging legislation like the EU AI Act emphasizes human oversight for high-risk applications, security teams should carefully evaluate how autonomous remediation workflows align with these evolving global regulatory standards.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Screenshot_2026-07-15_at_10.24.22PM.max-1000x1000.png" alt="demistifying image 7">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bg92b">Figure 7: Flowchart demonstrating the difference between local IDE AI remediation and centralized CI/CD pipeline remediation.</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Conclusion</span></h3>
<p><span>Leveraging LLMs in vulnerability management is a multi-layer solution: Integrating it requires separating workflows by layer. At the enterprise infrastructure level, Risk-Based Vulnerability Management (RBVM) and exposure management are necessary to process the volume of findings and configuration drift. At the product and code security level, LLM-enabled vulnerability assessment and remediation must operate alongside foundational deterministic controls, such as SAST and DAST, to audit custom, open-source, or third-party code.</span></p>
<p><span>Although LLMs can help manage technical debt and accelerate vulnerability discovery, they do not replace secure-by-design principles. The fact that LLM agents are proving exceptionally capable at identifying and exploiting localized memory corruption in memory-unsafe codebases, alongside other primary vectors, should serve as a wake-up call. </span></p>
<p><span>As a long-term strategy aligned with </span><a href="https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI_SOFTWARE_MEMORY_SAFETY.PDF" rel="noopener" target="_blank"><span>NSA guidance on Software Memory Safety</span></a><span>, organizations need to phase memory-safe languages into new internal development. LLMs are beginning to expand what is possible here by reducing the manual labor required for code migration. Converting existing C or C++ codebases to Rust has historically been unrealistic due to the large volume of engineering hours needed. While fully automated translation is not a turn-key solution, using LLMs to assist engineers with the bulk of the conversion can make these long-term migrations operationally viable. Beyond internal efforts, organizations should use procurement requirements to incentivize vendors to reduce their reliance on memory-unsafe languages and establish secure configuration defaults over time. Bridging the gap between AI velocity and enterprise defense means building an automated pipeline to manage the current backlog, while architecting systems where entire classes of vulnerabilities and misconfigurations are eliminated by design.</span></p>
<h3><span>Acknowledgements</span></h3>
<p><span>This analysis would not have been possible without the assistance of Google Threat Intelligence Group (GTIG) and other broader Google teams.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO pushes for AI industry self-regulation]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on artificial general intelligence (AGI) and national secu...]]></description>
<link>https://tsecurity.de/de/3673460/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673460/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</guid>
<pubDate>Thu, 16 Jul 2026 14:33:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis proposed that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants be encouraged to adopt best practices such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. </p>



<p class="wp-block-paragraph">DeepMind was involved in an earlier <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">US government initiative evaluating AI safety</a>, alongside Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO pushes for AI industry self-regulation]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on artificial general intelligence (AGI) and national secu...]]></description>
<link>https://tsecurity.de/de/3673451/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673451/it-nachrichten/deepmind-ceo-pushes-for-ai-industry-self-regulation/</guid>
<pubDate>Thu, 16 Jul 2026 14:33:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis proposed that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants be encouraged to adopt best practices such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. </p>



<p class="wp-block-paragraph">DeepMind was involved in an earlier <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">US government initiative evaluating AI safety</a>, alongside Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.cio.com/article/4197497/deepmind-ceo-pushes-for-ai-industry-self-regulation.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New agentic compute patterns]]></title>
<description><![CDATA[For a decade, Kubernetes was the right answer. It organized containers, scaled services horizontally and gave platform teams a shared vocabulary for running software in production. It abstracted away enough of the underlying complexity that engineers could stop thinking about servers and start th...]]></description>
<link>https://tsecurity.de/de/3672922/ai-nachrichten/new-agentic-compute-patterns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672922/ai-nachrichten/new-agentic-compute-patterns/</guid>
<pubDate>Thu, 16 Jul 2026 11:19:03 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For a decade, Kubernetes was the right answer. It organized containers, scaled services horizontally and gave platform teams a shared vocabulary for running software in production. It abstracted away enough of the underlying complexity that engineers could stop thinking about servers and start thinking about services. Most cloud-native infrastructure today is built on top of it, directly or in spirit, and EKS made that model the default for the majority of enterprise teams running workloads on AWS.</p>



<p class="wp-block-paragraph">The workload that defined that era was the stateless HTTP request, fast in, fast out, disposable. A user action triggers a request, the request hits a service, the service returns a response and the container is done. Kubernetes was optimized for that pattern down to the scheduler internals: Bin-pack containers onto nodes, autoscale on CPU and memory, evict and reschedule when something goes wrong. The whole system is tuned around the assumption that individual units of work are short, stateless and interchangeable.</p>



<p class="wp-block-paragraph">That assumption no longer holds for the workloads that matter most right now.</p>



<h2 class="wp-block-heading">The agent workload is structurally different</h2>



<p class="wp-block-paragraph">Agents are long-running, stateful processes. They reason across time, call external tools, spawn subprocesses, write and execute code, and make decisions that depend on what happened five steps earlier in the same task. A single-agent workflow might run for minutes or hours, touching a dozen external systems and generating intermediate outputs that subsequent steps depend on. The compute layer for that kind of work needs to do things the old model was never asked to do. That is the new pattern: Execution infrastructure designed around agent semantics rather than request semantics.</p>



<p class="wp-block-paragraph">The Kubernetes community itself has acknowledged this mismatch. In March 2026, Kubernetes SIG Apps published an<a href="https://url.usb.m.mimecastprotect.com/s/U22qCA8LmLh7yY0jIGfGfGdvGo?domain=kubernetes.io/" target="_blank" rel="noreferrer noopener"> introduction to Agent Sandbox</a>, a new CRD-based abstraction designed specifically for singleton, stateful agent workloads. The framing is direct: The ecosystem is moving from short-lived, isolated tasks to deploying multiple, coordinated AI agents that run continuously, and mapping those workloads to traditional Kubernetes primitives requires an entirely new abstraction. The fact that the Kubernetes maintainers built a dedicated primitive for this, rather than recommending teams compose one from existing resources, is itself the clearest signal that agent execution does not fit the old model.</p>



<h2 class="wp-block-heading">What agent execution actually requires</h2>



<p class="wp-block-paragraph">Concretely, it requires four things. First, isolated execution environments that provision in milliseconds, not minutes, so each agent task gets its own sandbox for code execution and tool calls without blocking the reasoning loop. The difference between a two-second environment and a two-minute environment is not a performance optimization; it determines whether the architecture is viable at all. Second, durable state management across the full task lifecycle, so an agent can pause, hand off or resume without re-initializing from scratch and burning tokens to reconstruct context it already built. Third, coordination primitives for multi-agent work: The ability to spawn subagents, pass structured outputs between them and track task dependencies across a graph of concurrent processes. Production agent systems are rarely single agents; they are pipelines of specialized agents with handoffs that need to be reliable and inspectable. Fourth, credentials and secrets management that travel with the execution context, so agents can authenticate to external services securely without exposing credentials in the task definition, logs or the environment variables of a shared container.</p>



<h2 class="wp-block-heading">The mismatch shows up fast in production</h2>



<p class="wp-block-paragraph">Kubernetes and EKS expose the mismatch quickly in practice. Pod eviction terminates an agent mid-task with no clean recovery path. Autoscaling reads CPU utilization as the load signal, but an agent holding a long inference connection looks idle to the scheduler even when it is doing the most consequential work in the pipeline. Provisioning a new environment takes 45 seconds to two minutes on a well-tuned cluster; agent workloads need that in under two seconds or the reasoning loop stalls and the user experience degrades visibly. These are not edge cases or misconfigurations. They are the normal operating conditions for production agent workloads running on infrastructure that was not designed for them.</p>



<p class="wp-block-paragraph">The utilization data makes the broader cost picture even starker. The<a href="https://url.usb.m.mimecastprotect.com/s/zk-6CB1MnMHEQoqvI6hNf2eRQz?domain=cast.ai/" target="_blank" rel="noreferrer noopener"> 2026 State of Kubernetes Optimization Report</a> from CAST AI, drawn from analysis of over 23,000 production clusters across AWS, Azure and GCP, found average CPU utilization at 8 percent, down from 10 percent the year prior. Memory utilization fell from 23 to 20 percent. CPU overprovisioning jumped from 40 to 69 percent year over year. These numbers reflect clusters running traditional workloads, and the pattern is worsening, not improving, as environments scale. Agent workloads compound this problem further. An agent holding an open inference connection or waiting on a tool call registers as idle to a scheduler that reads CPU and memory as the only meaningful load signals. The infrastructure responds to the wrong metric, overprovisioning capacity for demand it cannot measure, while the actual bottleneck, environment provisioning latency and state continuity, goes unaddressed.</p>



<h2 class="wp-block-heading">Security is not the same problem it was before</h2>



<p class="wp-block-paragraph">Agent workloads change the threat model at the infrastructure level. A compromised stateless service exposes a narrow surface defined by its API contracts. A compromised agent exposes every system it can reach, every credential it holds and every action it is authorized to take on behalf of the user. Agents generate and execute their own code, make non-deterministic tool-call decisions and accumulate context across long-running sessions. Standard container namespacing does not contain that kind of risk. Kernel-level isolation, default-deny network egress, scoped credentials per session and agent-aware observability are not optional hardening steps. They are baseline requirements for running agents in production.</p>



<h2 class="wp-block-heading">What teams that ship agents have already figured out</h2>



<p class="wp-block-paragraph">Some of the clearest evidence for this shift comes not from infrastructure vendors but from product engineering teams running agents at scale on their own code. In late 2025, Ramp’s engineering team published a<a href="https://url.usb.m.mimecastprotect.com/s/Co8bCDwO0Ohg2PpXhAiRfjbcM8?domain=engineering.ramp.com" target="_blank" rel="noreferrer noopener"> detailed account of building Inspect</a>, their internal background coding agent. Each Inspect session runs in a sandboxed VM with a full-stack development environment and deep integrations across their observability, CI, and deployment tooling. The architecture requirements map almost exactly to the four primitives above. Filesystem snapshots keep sessions starting in seconds rather than minutes. Sessions are isolated and stateful. The agent can run tests, review telemetry, query feature flags and visually verify frontend changes in a real browser. And the whole system supports unlimited concurrency, so engineers can spin up ten parallel sessions exploring different approaches to the same problem without contention.</p>



<p class="wp-block-paragraph">The results speak for themselves. Within months of launch, roughly 30 percent of all pull requests merged to Ramp’s frontend and backend repositories were written by Inspect. That level of adoption was not mandated. It happened because the execution environment was fast enough, capable enough and well-integrated enough that the agent was strictly better than a local workflow for a meaningful share of tasks. The key insight from the Ramp case is not about the model. It is about the execution layer. As their team put it, session speed should only be limited by model-provider time-to-first-token; everything else, like cloning and installing, needs to be done before the session starts. That is a statement about infrastructure, not intelligence.</p>



<h2 class="wp-block-heading">The ecosystem is catching up, but defaults are sticky</h2>



<p class="wp-block-paragraph">None of that is a criticism of the tools. Kubernetes solved exactly the problem it was designed for, and it solved it well. The issue is that infrastructure defaults are sticky. Teams inherit them, build on top of them and optimize within their constraints long after the underlying workload has changed. The Kubernetes community’s own response, the<a href="https://url.usb.m.mimecastprotect.com/s/U22qCA8LmLh7yY0jIGfGfGdvGo?domain=kubernetes.io/" target="_blank" rel="noreferrer noopener"> Agent Sandbox project under SIG Apps</a>, validates the thesis that a new abstraction is necessary. The new primitives the community is building include warm pools for near-zero cold starts, lifecycle management for suspending and resuming idle agents without losing state, and pluggable kernel isolation for secure execution of untrusted code. These are not incremental improvements to existing resources. They are net-new abstractions that acknowledge the old model does not stretch to fit.</p>



<p class="wp-block-paragraph">But adoption of purpose-built agent infrastructure remains early. Enterprises building agent pipelines today are largely running a request-oriented orchestration model against an execution-oriented workload, and the mismatch shows up in task failure rates, runaway costs and debugging cycles that have no good tooling because the observability layer was also designed for stateless services.</p>



<h2 class="wp-block-heading">The structural advantage is available now</h2>



<p class="wp-block-paragraph">The infrastructure to close that gap exists now. The prerequisite is recognizing that agent execution is a first-class compute pattern with its own primitives and its own requirements, not a variant of the stateless service model that defined the last decade. Teams that make that shift early will have a meaningful structural advantage. The ones that do not will spend the next two years wondering why their agent systems are unreliable at a scale that should be tractable.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unlock AI agents without sacrificing security]]></title>
<description><![CDATA[Author: Microsoft Security - Bewertung: 0x - Views:0 Learn how Microsoft Entra helps you discover shadow AI agents, govern agent permissions, keep BYOD and endpoint-based agents in scope, and apply Conditional Access to AI prompts and responses. Then see how Microsoft Purview provides visibility ...]]></description>
<link>https://tsecurity.de/de/3672036/it-security-video/unlock-ai-agents-without-sacrificing-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672036/it-security-video/unlock-ai-agents-without-sacrificing-security/</guid>
<pubDate>Thu, 16 Jul 2026 00:47:06 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Microsoft Security - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/AJx5PYKm1Cw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Learn how Microsoft Entra helps you discover shadow AI agents, govern agent permissions, keep BYOD and endpoint-based agents in scope, and apply Conditional Access to AI prompts and responses. Then see how Microsoft Purview provides visibility into agent activity, strengthens runtime data protection, helps detect agentic risk, and supports auditability across local agents developed on GitHub Copilot CLI, Claude Code, OpenAI Codex, and OpenClaw. Walk away with practical ways to unlock AI agents while keeping access and data protection aligned with your enterprise security needs.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Artificial Intelligence]]></title>
<description><![CDATA[Latest from todaynewsDeepMind CEO again pushes for a frontier AI standards bodyDemis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.By Evan SchumanJul 15, 20268 minsArtificial IntelligenceGovernmentLaws and Regulation...]]></description>
<link>https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</guid>
<pubDate>Wed, 15 Jul 2026 23:02:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><section class="latest-content"><div class="container"><header class="latest-content__header"><h2 class="latest-content__title sr-only"><span>Latest from today</span></h2></header><div class="grid latest-content__content"><div class="col-12 col-7@md col-8@lg"><div class="latest-content__content-featured"><a class="card card--xxl " href="https://www.computerworld.com/article/4197511/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body-2.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">news</span></div><div class="card__image"><div class="insider-image"><div class="image"><img width="400px" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197511-0-18848000-1784149211-shutterstock_2540223947.jpg?quality=50&amp;strip=all&amp;w=1046" data-id="idg_render_hero_index_one_card_image" sizes="
            (min-resolution: 3dppx) and (max-width: 600px) 900px,
            (min-resolution: 3dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 2dppx) and (max-width: 600px) 900px,
            (min-resolution: 2dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 1dppx) and (max-width: 600px) 900px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1300px" alt="Image" loading="eager"></div></div></div><h3 class="card__title">DeepMind CEO again pushes for a frontier AI standards body</h3><p class="card__description">Demis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.</p><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T20:59:29+00:00">Jul 15, 2026</span></span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a>
		</div><div class="grid grid--cols-7@md grid--cols-8@lg latest-content__content-main"><div class="col-12 col-7@md col-4@lg latest-content__card-main"><a class="card " href="https://www.computerworld.com/article/4197437/apples-openai-lawsuit-the-lunacy-of-trying-to-limit-what-ex-employees-can-tell-future-employers.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197437-0-98299000-1784131210-thinkstockphotos-493608259-100632547-orig.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">Apple’s OpenAI lawsuit: The lunacy of trying to limit what ex-employees can tell future employers</h3><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:59:35+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a></div><div class="col-12 col-7@md col-4@lg latest-content__card-main"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/4197338/what-problems-would-an-ai-speaker-from-openai-actually-solve.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197338-0-98391100-1784130807-Apple-HomePod-mini-color-lineup.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">What problems would an AI speaker from OpenAI actually solve?</h3><div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:52:45+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Vendors and Providers</span></span></div></a></div></div></div><div class="col-12 col-5@md col-4@lg latest-content__content-secondary"><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4192438/how-to-unionize-your-tech-workplace.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">feature</span></div><h3 class="card__title">How to unionize your tech workplace</h3><div class="card__info"><span>By Robert Mitchell</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T11:00:00+00:00">Jul 15, 2026</span></span><span>18 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Careers</span></span><span class="card__tag"><span class="tag">IT Jobs</span></span><span class="card__tag"><span class="tag">Technology Industry</span></span></div></a>
		</div><div class="latest-content__card-secondary"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/1613762/android-widgets.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">tip</span></div><h3 class="card__title">5 wild ways to make Android widgets more useful</h3><div class="card__info"><span>By JR Raphael</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T09:45:00+00:00">Jul 15, 2026</span></span><span>12 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Mobile Apps</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4197029/microsoft-is-forcing-an-enterprise-transition-to-passkeys.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Microsoft is forcing an enterprise transition to passkeys</h3><div class="card__info"><span>By Taryn Plumb</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T02:04:06+00:00">Jul 14, 2026</span></span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Access Control</span></span><span class="card__tag"><span class="tag">Authentication</span></span><span class="card__tag"><span class="tag">Identity and Access Management</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196704/siri-ai-steals-the-show-as-the-ios-27-public-beta-lands.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Siri AI steals the show as the iOS 27 public beta lands</h3><div class="card__info"><span>By Jonny Evans</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T15:47:35+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Operating Systems</span></span><span class="card__tag"><span class="tag">iOS</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196309/with-its-latest-layoffs-microsoft-goes-all-in-on-ai.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">opinion</span></div><h3 class="card__title">With its latest layoffs, Microsoft goes all in on AI</h3><div class="card__info"><span>By Preston Gralla</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T11:00:00+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">IT Strategy</span></span><span class="card__tag"><span class="tag">Microsoft</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196652/forg365-industrializes-microsoft-365-phishing-with-ai-generated-lures.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Forg365 industrializes Microsoft 365 phishing with AI-generated lures</h3><div class="card__info"><span>By Prasanth Aby Thomas</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T09:51:16+00:00">Jul 14, 2026</span></span><span>4 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span><span class="card__tag"><span class="tag">Office Suites</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></a>
		</div></div></div></div></section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><div class="content-listing-articles"><div class="container"><h2 class="content-listing-articles__title">Articles</h2><div class="content-listing-articles__container content-listing-articles__container--collapsed" data-collapse-articles="6" data-content-listing-articles><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’</h3><p class="card__description">Analysts and consultants applaud the move as potentially delivering the development consistency that the current offerings lack, but some worry that treating the company as neutral is a mistake.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Evan Schuman</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Nonprofits</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196262/ai-is-killing-low-cost-smartphones.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">AI is killing low cost smartphones</h3><p class="card__description">Data from Omdia and Counterpoint shows that while Apple and Samsung thrive, the rest of the industry takes a dive</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Mobile Phones</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196220/meta-pulls-instagram-ai-feature-amid-privacy-concerns.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta pulls Instagram AI feature amid privacy concerns</h3><p class="card__description">By specifying a public account, users could allow the AI ​​model to use the person’s images as a reference without the account holder being notified.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Viktor Eriksson</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>1 min</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Instagram</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195176/qa-how-google-plans-to-reinvent-the-spreadsheet-with-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">feature</span></div><h3 class="card__title">Q&amp;A: How Google plans to reinvent the spreadsheet with AI</h3><p class="card__description">Soon, Google wants to see AI doing the spreadsheet busywork, says Eric Birnbaum, director of product management for Google Sheets.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Matthew Finnegan</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>10 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Google Sheets</span></span><span class="card__tag"><span class="tag">Google Workspace</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">brandpost</span><span class="card__sponsor-text">Sponsored by Tether</span></div><h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3><p class="card__description"></p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By tether</span></div> <div class="card__info card__info--light"><span>Jul 9, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">‘Rotten to its core’ — Apple files an explosive lawsuit against OpenAI</h3><p class="card__description">Apple accuses OpenAI and former Apple Vice President Tang Tan of extensive coordinated data theft and asks whether OpenAI’s hardware plans are based around exfiltrated Apple info.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">opinion</span></div><h3 class="card__title">Apple is prepping for life after the AI gold rush</h3><p class="card__description">The company's interest in compression of AI models is the right approach.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195678/microsoft-exchange-server-on-prem-gets-a-little-harder-to-use.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Microsoft Exchange Server on prem gets a little harder to use</h3><p class="card__description">The lightweight web client is going away, placing more demands on systems still clinging to Microsoft’s on-prem email system.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Email Clients</span></span><span class="card__tag"><span class="tag">Microsoft Exchange</span></span><span class="card__tag"><span class="tag">Microsoft Outlook</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195636/mistral-joins-rush-to-build-physical-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Mistral joins rush to build physical AI</h3><p class="card__description">Its Robostral Navigate AI model needs input from just one color camera, doing without Lidar, depth sensors, or multiple viewpoints.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Robotics</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195628/apple-will-buy-more-us-made-components-from-broadcom.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Apple will buy more US-made components from Broadcom</h3><p class="card__description">Chips and thin-film bulk acoustic resonator (FBAR) filters are on the menu.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Networking</span></span><span class="card__tag"><span class="tag">Wi-Fi</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195528/meta-launches-low-cost-muse-spark-1-1-as-enterprise-ai-spending-comes-under-scrutiny-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta launches low-cost Muse Spark 1.1 as enterprise AI spending comes under scrutiny</h3><p class="card__description">Meta says the model delivers competitive performance against OpenAI, Anthropic, and Google offerings while costing a fraction as much to run.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Anirban Ghoshal</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/1614899/android-contacts-management-ultimate-guide.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">how-to</span></div><h3 class="card__title">The ultimate guide to Android contacts management</h3><p class="card__description">Your Android phone's contacts are much more than just a glorified Rolodex. Ready for an unexpected productivity upgrade? </p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By JR Raphael</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>16 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Google</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195494/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout</h3><p class="card__description">The enterprise AI agent combines ChatGPT, Codex, and GPT-5.6 to automate workplace tasks as OpenAI broadens rollout of its latest frontier models.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Gyana Swain</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div></div><div class="grid content-listing-articles__button-wrapper">
			<div class="col-6 col-4@md col-start-5@md"><div class="content-listing-articles__button-show">
					<button class="button button--tertiary" type="button" data-toggle="expand">
						<span>Show more</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-down"></use>
							</svg>
						</span>
					</button>
				</div>
				<div class="content-listing-articles__button-show content-listing-articles__button-show--hide">
					<button class="button button--tertiary" type="button" data-toggle="collapse">
						<span>Show less</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-up"></use>
							</svg>
						</span>
					</button>
				</div></div><div class="col-6 col-4@md content-listing-articles__button-view-all">
						<a class="button" href="https://www.computerworld.com/artificial-intelligence/feed/page/2/" target="_blank"> View all </a></div></div></div></div><section class="suggested-content-upcoming-events"><div class="container">
				<h2 class="suggested-content-upcoming-events__title">Upcoming Events</h2><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cio-100-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Sep/24</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/03/4141846-0-37933000-1772809522-CIO-Summit-2025_17.jpg?quality=50&amp;strip=all&amp;w=1045" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cio-100-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CIO 100 Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>24 Sep 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span></div></div>
			</div>
		</a><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cso-awards-conference-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Nov/26</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4141741-0-97812100-1780312469-60CB82BE-5D6E-40E0-8E5E-0151C8C46E7F.jpg?quality=50&amp;strip=all&amp;w=929" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cso-awards-conference-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CSO Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>26 Nov 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span></div></div>
			</div>
		</a></div><div class="suggested-content-upcoming-events__button-container container">
						<a class="button" href="https://www.computerworld.com/events/"> View all events</a>
					</div>
				
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-resources">
				<div class="container">
				<h2 class="related-content-resources__title">Resources</h2><div class="grid related-content-resources__content"><div class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-resources__main-content">
			<div class="col-12 col-7@md col-6@lg">
				<a class="card card--xxl" href="https://us.resources.computerworld.com/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
					<div class="card__header">
						<span class="card__content-type">whitepaper</span>
					</div>
					<h3 class="card__title">Accelerate your cloud migration with Atlassian FastShift</h3>
					<p class="card__description"></p><p>Turn an Atlassian cloud migration into a faster, more predictable transformation. In this session, you’ll walk through the FastShift playbook.</p>
<p>The post <a rel="nofollow" href="https://com.wp.idg.zone/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6/">Accelerate your cloud migration with Atlassian FastShift</a> appeared first on <a rel="nofollow" href="https://com.wp.idg.zone/">Whitepaper Repository –</a>.</p>

					<div class="card__info">
						<span>
						By 
						Atlassian
						</span>
					</div>
					<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
			</div>
			<div class="col-2 related-content-resources__featured-image-wrapper">
				<img width="400px" loading="lazy" class="related-content-resources__image-featured" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040704.83.png" alt="Image">
			</div>
		</div><div class="col-12 col-5@md col-4@lg col-start-9@lg related-content-resources__cards"><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/warum-sich-teams-fur-cloud-entscheiden-9?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Warum sich Teams für Cloud entscheiden</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040716.4772.png" alt="Image">
				</div>
			</div><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/pourquoi-les-equipes-optent-pour-la-solution-cloud-3?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Pourquoi les équipes optent pour la solution cloud</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040728.9116.png" alt="Image">
				</div>
			</div></div>
		</div><div class="related-content-resources__button-container">
			<a class="button" target="_blank" href="https://us.resources.computerworld.com/"> View all </a>
		</div></div>
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-podcasts"><div class="container"><h2 class="related-content-podcasts__title">Podcasts</h2><div class="grid related-content-podcasts__content"><a class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-podcasts__main-content" href="https://www.computerworld.com/podcasts/2-minute-tech-briefing/" aria-label="Go to content"><div class="col-12 col-7@md col-2@lg related-content-podcasts__image">
			<div class="image image--aspect-ratio-1-1">
				<img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2025/11/100065453-0-01782600-1762961273-2-min-tech-briefing-logo-16x9-4.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Image">
			</div>
		</div><div class="col-12 col-7@md col-6@lg"><div class="card card--xl"><div class="card__header"><span class="card__content-type"> podcasts</span></div><h3 class="card__title">2-Minute Tech Briefing</h3><p class="card__description">Catch up on the latest enterprise IT news in a fast-paced video briefing with host Arnold Davick. Listen to the show on Computerworld, YouTube, Apple and Spotify.</p><div class="card__info card__info--light"><span>81  episodes</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Emerging Technology</span></span></div></div></div></a><ul class="col-12 col-5@md col-4@lg col-start-9@lg related-content-podcasts__cards"><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 81</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 80</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li></ul></div></div></section><section class="related-content-video"><div class="container"><h2 class="related-content-video__title">Video on demand</h2><div class="grid related-content-video__main">        <div class="col-12 col-4@lg related-content-video__main-card card card--xl">
            <div class="card__header"><span class="card__content-type">video</span></div>            
            <a class="card card--xl" href="https://www.computerworld.com/video/4196734/why-ai-agents-fail-when-enterprises-dont-define-the-job.html" aria-label="Go to content">
                <h3 class="card__title">Why AI agents fail when enterprises don’t define the job</h3>            </a>
                            <p class="card__description mt-3">Enterprises are investing heavily in AI agents, but many projects fail when companies skip clear goals, guardrails, governance and success metrics.</p>
            
                         <div class="card__info card__info--light"><span>Jul 14, 2026 </span><span>33 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div>        </div>
                <div class="col-12 col-8@lg related-content-video__video">
                            <div class="youtube-video">
                    &gt;
					
				</div>                </div>
                    </div>
        </div><div class="related-content-video__cards-container">
                        <div class="related-content-video__cards-wrap">
                            <ul class="grid related-content-video__cards">        <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4193952/why-enterprise-ai-projects-stall-before-delivering-real-value.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4193952-0-52301800-1783446508-youtube-thumbnail-gu6x40jhZ1s_3cbf50.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">Why enterprise AI projects stall before delivering real value</h3>
                                         <div class="card__info card__info--light"><span>Jul 7, 2026 </span><span>29 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">ROI and Metrics</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4191262/how-ai-is-breaking-job-interviews-skills-testing-and-evaluation.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4191262-0-24248500-1782847008-youtube-thumbnail-lVEejCXC4lU_b223c5.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is breaking job interviews, skills testing and evaluation</h3>
                                         <div class="card__info card__info--light"><span>Jun 30, 2026 </span><span>32 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Hiring</span></span><span class="card__tag"><span class="tag">IT Skills and Training</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4188534/how-ai-is-reshaping-cybersecurity.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4188534-0-45176600-1782243369-youtube-thumbnail-5DLoQMU0nZc_de9df9.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is reshaping cybersecurity</h3>
                                         <div class="card__info card__info--light"><span>Jun 23, 2026 </span><span>44 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span><span class="card__tag"><span class="tag">Cybercrime</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div>                </div>
            </a>
        </li>
        </ul></div></div><div class="related-content-video__button-container"><a class="button" target="_self" href="https://www.computerworld.com/videos/">See all videos</a></div></section></div><section class="suggested-content-various"><div class="container"><div class="grid suggested-content-various__content"><div class="col-12 col-3@lg">
			<h2 class="suggested-content-various__title">Show me more</h2><div class="suggested-content-various__filters"><span class="suggested-content-various__filter"><button class="chip chip--filter chip--active" type="button" data-filter-key="latest">Latest</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="article">Articles</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="podcast">Podcasts</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="video">Videos</button></span></div>
		</div><div class="col-12 col-9@lg suggested-content-various__items-wrap"><div class="grid grid--cols-9@lg suggested-content-various__items"><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4195055/apple-finally-calls-time-on-15-year-old-device-support.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">opinion</span> </div> <h3 class="card__title">Apple finally calls time on 15-year-old device support</h3> <div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T16:15:14+00:00">Jul 9, 2026</span><span>4 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Smartphones</span></span><span class="card__tag"><span class="tag">iPhone</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4195055-0-47500100-1783613766-iPhone4s_3up_Photo_Siri_Sprgbd_PRINT.jpg?quality=50&amp;strip=all&amp;w=219" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">brandpost</span> <span class="card__sponsor-text">Sponsored by Tether</span></div> <h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3> <div class="card__info"><span>By tether</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T11:11:53+00:00">9 Jul 2026</span><span>6 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194931-0-76347600-1783595551-QVAC-Paid-Ad-1-_-1200-x-800.png?w=375" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194914/spacexai-launches-grok-4-5-touts-lower-coding-task-costs-than-ai-rivals-2.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">news</span> </div> <h3 class="card__title">SpaceXAI launches Grok 4.5, touts lower coding-task costs than AI rivals</h3> <div class="card__info"><span>By Prasanth Aby Thomas</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T10:26:11+00:00">Jul 9, 2026</span><span>5 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194914-0-24417700-1783592810-AI-vibe-coding-one-hand-is-robot-one-hand-is-human.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T15:04:16+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-46106000-1779462321-youtube-thumbnail-5PkKYThsKy8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T14:53:18+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-06017100-1779461653-youtube-thumbnail-XH7vduM7uz8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4172579/ai-triage-gains-model-reviews-ask-jeeves-shutdown-ep-82.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">AI Triage Gains, Model Reviews, Ask Jeeves Shutdown | Ep. 82</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-18T19:31:15+00:00">May 18, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-62824900-1779132751-youtube-thumbnail-P3R6blMndrU.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4185559/why-ai-agents-could-create-a-new-control-and-security-crisis.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Why AI agents could create a new control and security crisis</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-16T11:47:15+00:00">Jun 16, 2026</span><span>28 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4185559-0-48713800-1781610470-youtube-thumbnail-uPpd9EJ4iNI_55eb26.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4182978/does-quality-suffer-when-ai-generates-code.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Does quality suffer when AI generates code?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-09T14:32:51+00:00">Jun 9, 2026</span><span>35 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Code Security</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4182978-0-61230000-1781015610-youtube-thumbnail-1hAfDQkuyhs_faa994.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4180043/what-happens-when-ai-starts-selling-to-ai.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">What happens when AI starts selling to AI?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-02T15:00:42+00:00">Jun 2, 2026</span><span>38 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Procurement Software</span></span><span class="card__tag"><span class="tag">Salesforce Automation </span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4180043-0-78180900-1780412479-youtube-thumbnail-jPv-TAenlto_c79318.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div></div></div></div></div></section>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO again pushes for a frontier AI standards body]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on artificial general intelligence (AGI) and national security. 



But it is precisely that focus on national security that may make...]]></description>
<link>https://tsecurity.de/de/3671860/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671860/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</guid>
<pubDate>Wed, 15 Jul 2026 23:01:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html" target="_blank">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis said he would propose that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants would be encouraged to adopt best practices, such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. He has already worked on <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">a US government initiative evaluating AI safety</a>, which involved DeepMind, Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepMind CEO again pushes for a frontier AI standards body]]></title>
<description><![CDATA[Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on artificial general intelligence (AGI) and national security. 



But it is precisely that focus on national security that may make...]]></description>
<link>https://tsecurity.de/de/3671859/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671859/it-nachrichten/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body/</guid>
<pubDate>Wed, 15 Jul 2026 23:01:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google DeepMind CEO Demis Hassabis on Tuesday reiterated his push for an AI industry self-regulation effort, led by the US government, that is particularly focused on <a href="https://www.computerworld.com/article/4174181/google-talks-singularity-while-scaling-up-agentic-ai-for-enterprises-2.html" target="_blank">artificial general intelligence (AGI)</a> and national security. </p>



<p class="wp-block-paragraph">But it is precisely that focus on national security that may make the results of such an effort, assuming it happens, less than palatable outside of the US.</p>



<p class="wp-block-paragraph">“The rapid progress we’re seeing in AI requires a new approach to testing frontier AI model capabilities that is dynamic, adaptable, and rigorous,” <a href="https://demishassabis.substack.com/p/a-framework-for-frontier-ai-and-the-dawning-of-a-new-age" target="_blank" rel="noreferrer noopener">Hassabis wrote</a>. “The US is well positioned, given its economic and technical standing, to take the first step in developing such a framework. It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organization, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives.”</p>



<p class="wp-block-paragraph">He noted, however, that the funding would need to be substantial, and would most likely come from industry, to allow the new body to attract world-class technical talent and obtain the necessary compute resources for large-scale testing.</p>



<p class="wp-block-paragraph">Hassabis said he would propose that the organization “be responsible for developing assessment protocols and working with appropriate federal agencies and the US National Labs to conduct testing in areas relevant to national security,” and that AI vendor participants would be encouraged to adopt best practices, such as publishing model cards with technical details, maintaining strong internal cybersecurity, vetting key personnel, and providing sufficient resourcing for safety and security research.</p>



<p class="wp-block-paragraph">This is not the first time Hassabis has <a href="https://www.computerworld.com/article/4178398/deepmind-ceo-agi-could-be-here-in-three-years.html" target="_blank">expressed worries about AGI</a>. He has already worked on <a href="https://www.cio.com/article/4168122/us-government-agency-to-safety-test-frontier-ai-models-before-release.html" target="_blank">a US government initiative evaluating AI safety</a>, which involved DeepMind, Microsoft and xAI (now SpaceXAI) working with the Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce. It allowed CAISI to conduct pre-deployment evaluations and targeted research to “better assess frontier AI capabilities and advance the state of AI security.”  </p>



<h2 class="wp-block-heading">The rest of the world may have concerns</h2>



<p class="wp-block-paragraph">Analysts and consultants were mixed about the move, with most expressing concerns about whether an industry-focused group would prioritize the public’s best interests.</p>



<p class="wp-block-paragraph">“Self-regulation is not viable because it implies everyone is able to regulate themselves and will do so in line with the best interests of the public. Most tech vendors don’t have the capacity to self-regulate. They would just prefer a set of rules within which they can operate,” said Gartner VP analyst <a href="https://www.gartner.com/en/experts/nader-henein" target="_blank" rel="noreferrer noopener">Nader Henein</a>. “For-profit organizations are required to do what is best for their shareholders, and external regulation ensures that those organizations are never in a conflict of interest where they have to choose between what is good for their shareholders and what is good for the public.”</p>



<p class="wp-block-paragraph">And, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, given the international nature of AI models, an effort coordinated by the US government might alienate other countries. </p>



<p class="wp-block-paragraph">“National security is the proposal’s accelerator in Washington and its poison pill abroad: the framing that opens the only gate available at home invites foreign capitals to read the institution as an instrument of American strategy,” he pointed out. </p>



<p class="wp-block-paragraph">“The map is already plural,” he said. “Brussels switches on enforcement powers over general-purpose models [starting in August 2026], London runs the AI Security Institute, and Beijing licenses on its own terms. California and New York have legislated for frontier models at home. The durable route is shared technical evidence with sovereign enforcement, sealed through mutual recognition rather than deference, with India and the other major non-Western markets holding authorship rather than seats.”</p>



<p class="wp-block-paragraph">Gogia added that the rules enacted by even such a group may not address all of the key concerns of enterprise IT. A US government effort along the lines that Hassabis is proposing would result in testing that “sits close to intelligence and industrial policy, and those functions will not stay neatly separated. A model can pass every catastrophic-risk test and still fail the enterprise on privacy, reliability, and liability,” he noted.</p>



<p class="wp-block-paragraph">Walmart’s former director of cybersecurity <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, who is now an independent cybersecurity consultant, said he found the proposal “well-intentioned, but it addresses a highly polarized topic at a time when commercial interests carry unprecedented political influence, which is not always applied benevolently.”</p>



<p class="wp-block-paragraph">He added, “an exclusive US standard that is not globally respected or enforceable would likely fail to achieve its core purpose and would place US companies at a competitive disadvantage.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that a deep dive into how <a href="https://www.finra.org/" target="_blank" rel="noreferrer noopener">FINRA</a> operates today is illustrative of what IT leaders can expect from this effort, assuming the industry adopts that model.</p>



<p class="wp-block-paragraph">“When the CEOs of the five companies that would be regulated are also the primary drafters of the standards, the standards will reflect those companies’ interests. FINRA has an independent board, but the operational reality is that member firm perspectives dominate the working groups that write the actual rules,” he said. “There is no reason to expect an AI equivalent to work differently, and every reason to expect it to work worse, because AI standardization is happening faster than any industry has ever attempted to standardize itself, and speed is the enemy of independent oversight.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was even more emphatically opposed to the Hassabis proposal.</p>



<p class="wp-block-paragraph">“Asking Big Tech companies to self-police is analogous to allowing foxes to guard the henhouse. It hasn’t worked to date, and it won’t work going forward. Expecting these organizations to somehow change their ways at this point in time represents the height of naïve thinking,” Levy said. “The framework proposed by Demis Hassabis is a self-serving roadmap for an industry bent on racing to the AI horizon regardless of the harms caused along the way. It is impossible to quantify the dangers to broader society should frameworks allowing self-regulation become the norm.”</p>



<h2 class="wp-block-heading">Some love the proposal</h2>



<p class="wp-block-paragraph">An almost completely opposite stance came from <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, who applauded the proposed move.</p>



<p class="wp-block-paragraph">“This is one of the rare setups where industry self-regulation has a real shot, and enterprise IT should be enthusiastically rooting for it,” he said. “It fails when harms are externalized, such as in social media content moderation. Or when the overseer outsources judgment to the overseen, such as the FAA’s delegation to Boeing before the 737 MAX. It works when everyone in the industry shares the catastrophic downside.”</p>



<p class="wp-block-paragraph">He suggested, however, that the best precedent here isn’t FINRA, it’s INPO, the Institute of Nuclear Power Operations, which the nuclear industry created within months of the <a href="https://www.nrc.gov/reading-rm/doc-collections/fact-sheets/3mile-isle" target="_blank" rel="noreferrer noopener">1979 Three Mile Island partial reactor meltdown</a> “on the logic that an accident anywhere is an accident everywhere. INPO peer-reviews every US plant, its evaluations move insurance premiums, and it sits on top of the NRC’s statutory floor. That is a public-private stack very close to what Hassabis is describing. Frontier AI has the same structure: one lab’s catastrophic failure brings regulation down on all of them.”</p>



<p class="wp-block-paragraph">For enterprise CIOs and other IT executives, Goryunov said, that model has the potential for being a big win.</p>



<p class="wp-block-paragraph"><strong>“</strong>Today, every enterprise duplicates the same AI diligence of red-teaming, eval suites, governance committees and each does so with less information than any certifying body would have,” Goryunov said. “A credible standards regime does for AI what UL did for electrical equipment and SOC2 did for cloud: it converts an unknowable risk into a procurable product and gives boards a defensible standard of care. That’s not red tape. That’s peace of mind with an audit trail.”</p>



<p class="wp-block-paragraph">However, Mahapatra said, “the countervailing view is that the alternative to industry-led standards is probably not thoughtful legislation. It is probably no standards, or state-by-state fragmentation, or the current pattern of ex-post enforcement actions where regulators surface concerns years after harm has already occurred.” </p>



<p class="wp-block-paragraph">Thus, he noted, “Hassabis is making the reasonable argument that imperfect fast standards are better than perfect slow ones, and there is genuine merit to that view for topics like agent identity, evaluation methodology, and interoperability, which are exactly the areas <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">OpenClaw is also targeting</a>.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on CIO.com.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘What’s the point?’ Teenagers give their verdict on Britain’s social media curfew]]></title>
<description><![CDATA[All the young people the Guardian spoke to disagreed with aspects of the government’s proposed blockSixteen- and 17-year-olds in Britain are to be encouraged to observe a midnight to 6am social media curfew but will be able to opt out by changing their account settings.From next spring, they will...]]></description>
<link>https://tsecurity.de/de/3671792/it-nachrichten/whats-the-point-teenagers-give-their-verdict-on-britains-social-media-curfew/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671792/it-nachrichten/whats-the-point-teenagers-give-their-verdict-on-britains-social-media-curfew/</guid>
<pubDate>Wed, 15 Jul 2026 22:18:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>All the young people the Guardian spoke to disagreed with aspects of the government’s proposed block</p><p>Sixteen- and 17-year-olds in Britain are to be encouraged to observe a <a href="https://www.theguardian.com/technology/2026/jul/14/uk-16-17-year-olds-midnight-social-media-curfew">midnight to 6am social media curfew</a> but will be able to opt out by changing their account settings.</p><p>From next spring, they will be urged to refrain from using certain apps, with the block being switched on by default. But the curfew will not be mandatory and can be overridden.</p> <a href="https://www.theguardian.com/media/2026/jul/15/teenagers-verdic-britain-social-media-curfew-ban-whats-the-point">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top AI tools such as OpenClaw and Github Copilot can be hijacked to create new massive botnets]]></title>
<description><![CDATA[Researchers find nine of the most popular AI platforms are susceptible to a new attack that exploits hallucinations to set up a botnet.]]></description>
<link>https://tsecurity.de/de/3671788/it-nachrichten/top-ai-tools-such-as-openclaw-and-github-copilot-can-be-hijacked-to-create-new-massive-botnets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671788/it-nachrichten/top-ai-tools-such-as-openclaw-and-github-copilot-can-be-hijacked-to-create-new-massive-botnets/</guid>
<pubDate>Wed, 15 Jul 2026 22:18:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers find nine of the most popular AI platforms are susceptible to a new attack that exploits hallucinations to set up a botnet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Adds 36-Month AT&T and Verizon Financing for Cellular iPads]]></title>
<description><![CDATA[Apple has added new cellular iPad financing options through AT&T and Verizon, giving shoppers a longer payment plan when buying directly from Apple. The new offers spread payments across 36 months and apply to cellular models across the full iPad lineup.



Previously, Apple only offered 12-month...]]></description>
<link>https://tsecurity.de/de/3671485/ios-mac-os/apple-adds-36-month-att-and-verizon-financing-for-cellular-ipads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671485/ios-mac-os/apple-adds-36-month-att-and-verizon-financing-for-cellular-ipads/</guid>
<pubDate>Wed, 15 Jul 2026 19:25:40 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has added new cellular iPad financing options through AT&amp;T and Verizon, giving shoppers a longer payment plan when buying directly from Apple. The new offers spread payments across 36 months and apply to cellular models across the full iPad lineup.



Previously, Apple only offered 12-month interest-free financing through Apple Card Monthly Installments. The new carrier plans lower the monthly payment by extending the repayment period, although buyers will remain committed to the plan for three years.



AT&amp;T says the offer is available to existing customers who add a new line of service.



Verizon also requires customers to connect the iPad to a new line before using the 36-month financing option.



The longer payment period makes a noticeable difference on expensive models. For example, the 11-inch cellular iPad Pro starts at $1,399. Apple Card financing brings the monthly payment to about $116.58 for 12 months, while carrier financing lowers it to roughly $38 per month for 36 months.



Apple introduced these options shortly after raising prices across the iPad range. The new plans give customers another way to manage the higher upfront cost, especially if they already use AT&amp;T or Verizon and plan to keep cellular service active.]]></content:encoded>
</item>
<item>
<title><![CDATA[Don’t Neglect the Operational Groundwork]]></title>
<description><![CDATA[Autonomous agents are moving faster than the field’s ability to govern them, and catching up requires more than better prompts or bigger sandboxes. At O’Reilly’s recent AI Superstream focused on OpenClaw and the broader ecosystem of locally run and self-hosted AI agents, five speakers, each worki...]]></description>
<link>https://tsecurity.de/de/3671437/ai-nachrichten/dont-neglect-the-operational-groundwork/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671437/ai-nachrichten/dont-neglect-the-operational-groundwork/</guid>
<pubDate>Wed, 15 Jul 2026 19:03:02 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Autonomous agents are moving faster than the field’s ability to govern them, and catching up requires more than better prompts or bigger sandboxes. At O’Reilly’s recent AI Superstream focused on OpenClaw and the broader ecosystem of locally run and self-hosted AI agents, five speakers, each working at a different layer of the stack, explored patterns […]]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is paying off, but governance is lagging behind]]></title>
<description><![CDATA[Enterprises are facing two simultaneous challenges with AI: The risks associated with it are evolving faster than governance frameworks, while the business benefits are often difficult to measure.



This is one of the key findings of The Value of AI, a study commissioned by SAP from Oxford Econo...]]></description>
<link>https://tsecurity.de/de/3671333/it-nachrichten/ai-is-paying-off-but-governance-is-lagging-behind/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671333/it-nachrichten/ai-is-paying-off-but-governance-is-lagging-behind/</guid>
<pubDate>Wed, 15 Jul 2026 18:33:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Enterprises are facing two simultaneous challenges with AI: The risks associated with it are evolving faster than governance frameworks, while the business benefits are often difficult to measure.</p>



<p class="wp-block-paragraph">This is one of the key findings of <a href="https://www.sap.com/documents/2026/07/92b94d7d-5a7f-0010-bca6-c68f7e60039b.html" target="_blank" rel="noreferrer noopener">The Value of AI</a>, a study commissioned by SAP from Oxford Economics. Now in its second year, the study surveyed 2,600 executives from 13 countries worldwide.</p>



<h2 class="wp-block-heading">High expectations, limited preparation</h2>



<p class="wp-block-paragraph">On average, the enterprises surveyed plan to spend around $28 million on AI (up from $26.7 million last year), and expect a 21% ROI (from 16% last year). Expectations for AI agents are particularly high, with ROI expected to reach 17% this year, up from 10% last year. Furthermore, 83% of respondents worldwide said agentic AI has the potential to fundamentally transform their organization. On the other hand, only 3% of respondents said their enterprises were fully prepared for the deployment of AI agents.</p>



<p class="wp-block-paragraph">There are gaps, particularly when it comes to governance:</p>



<ul class="wp-block-list">
<li>Only 12% of respondents said their skills or processes were able to govern AI effectively,</li>



<li>38% do not have human-in-the-loop processes in place for oversight of AI agents, and</li>



<li>only 63% have established permissions and access controls for agents.</li>
</ul>



<p class="wp-block-paragraph">Other concerns include weaknesses in the organization of AI deployment, poor data quality, insufficient employee training, and the widespread use of shadow AI.</p>



<h2 class="wp-block-heading">Governance is the bigger challenge</h2>


<div class="extendedBlock-wrapper block-coreImage right"><figure class="wp-block-image alignright size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Sean Kask, Chief AI Strategy Officer at SAP </figcaption></figure><p class="imageCredit">SAP</p></div>



<p class="wp-block-paragraph">In an interview, <a href="https://www.linkedin.com/in/seankask/" target="_blank" rel="noreferrer noopener">Sean Kask</a>, Chief AI Strategy Officer at SAP, commented on the study’s key findings.</p>



<p class="wp-block-paragraph"><em>Mr. Kask, in the study’s foreword, you write that companies are currently facing two challenges simultaneously: The risks associated with AI are evolving faster than governance, while the business benefits are often difficult to measure. Which of these poses the greater problem for companies?</em></p>



<p class="wp-block-paragraph"><strong>Sean Kask:</strong> Measuring the business value of IT investments has never been easy. The same applies to AI. That’s why I currently consider the governance issue to be the greater challenge. While traditional governance principles and best practices for secure software development remain important even in the age of large language models and agent-based AI, entirely new risks are emerging at the same time.</p>



<p class="wp-block-paragraph">For example, as soon as companies roll out AI on a broad scale, they suddenly discover hundreds or even thousands of so-called shadow agents that employees are using without central oversight. Or they find that a significant portion of the workforce is copying content into private ChatGPT accounts. Such risks often only become apparent once AI is already being used productively.</p>



<p class="wp-block-paragraph"><em>According to your study, German companies invest an average of nearly $40 million in AI, more than companies in all other countries surveyed. Why is that?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> I was less surprised by the amount of investment than by the fact that, overall, the level of investment and the return on investment achieved have developed very similarly across the various countries. There’s no clear answer as to why Germany invests more. In part, it’s likely simply because costs here are higher than in India, for example.</p>



<p class="wp-block-paragraph">However, we’re also seeing a high level of AI adoption among German companies. SAP has a dashboard that allows us to track how our customers are using AI features. Germany is among the countries with particularly high usage. Added to this are the strong industrial base and the political impetus from Europe, which are driving the use of AI. Accordingly, companies there are making targeted investments in building the necessary expertise.</p>



<p class="wp-block-paragraph"><em>According to the study, 47% of German companies are satisfied with the return on investment from their AI investments. At the same time, 77% say they are still far from realizing AI’s full potential. Isn’t that a contradiction?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> No, we see this pattern worldwide. Companies initially invest in a few AI use cases and realize: This works; we’re creating added value. Accordingly, they’re satisfied with their investment.</p>



<p class="wp-block-paragraph">But this is precisely what leads them to identify further use cases. They explore AI agents and want to utilize them as well. However, it is exactly at this point that many encounter new challenges in implementation and scaling.</p>



<p class="wp-block-paragraph">The study therefore primarily highlights a learning curve: The more experience companies gain with AI, the greater their awareness of its previously untapped potential becomes.</p>



<p class="wp-block-paragraph"><em>According to the study, only 33% of companies surveyed have KPIs at the executive board level that are directly linked to the implementation of AI. In your view, which metrics should supervisory boards and CEOs definitely be tracking?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> For us, a key indicator is employee enablement. How many employees have already successfully completed training or upskilling programs related to AI? Without the appropriate skills, AI adoption will fall short of its potential.</p>



<p class="wp-block-paragraph">Transparency is equally important. Companies should know which AI agents are actually in use within their landscape. SAP offers the SAP AI Agent Hub for this purpose, which automatically discovers and inventories agents from SAP and third-party environments. Customers have already been able to identify thousands of agents this way, which highlights the need for centralized governance and transparency.</p>



<p class="wp-block-paragraph">In addition, companies should have a complete overview of all AI use cases. A robust business case should be in place for each use case. We often see two extremes: Either the executive board is under pressure to implement AI as quickly as possible and allocates a lump-sum budget for this purpose. Or management initially takes a wait-and-see approach. This leads to independent pilot projects springing up throughout the company, with individual departments procuring their own tools and entering into their own contracts.</p>



<p class="wp-block-paragraph">At SAP, we therefore follow a clearly structured selection process. Each idea first undergoes an assessment of its expected business value. We then examine technical feasibility, data availability, and ethical and governance aspects. From management’s perspective, it is crucial to maintain transparency regarding all ongoing AI projects at all times and to consistently prioritize them based on their business value.</p>



<h2 class="wp-block-heading">Agents, too, need a ‘hire-to-retire’ lifecycle</h2>



<p class="wp-block-paragraph"><em>Even with the introduction of dozens or even hundreds of AI agents, governance becomes increasingly complex. What capabilities do enterprise platforms need to manage AI agents securely and in a controlled manner at scale?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> We make a conscious effort not to anthropomorphize AI too much. Nevertheless, the analogy is helpful: Agents require a complete hire-to-retire lifecycle. This begins with the detection and registration of an agent. It is then integrated into the enterprise environment, granted the necessary permissions, and given access to the data sources it needs to perform its tasks.</p>



<p class="wp-block-paragraph">Observability is just as important. Companies must be able to track what an agent is actually doing in the system at all times. In addition, they should track key performance indicators: Is the agent achieving the desired results? How efficiently is it working? How many tokens does it consume? How many processing steps does it require for a task?</p>



<p class="wp-block-paragraph">Ultimately, this involves several key components: a complete inventory of all agents, appropriate governance, risk, and compliance (GRC) mechanisms, transparency regarding agent behavior, and continuous monitoring. This is the only way to ensure that AI agents consistently operate within defined parameters and deliver the desired business value.</p>



<p class="wp-block-paragraph"><em>In your estimation, which business processes will companies actually delegate entirely to AI agents over the next two to three years?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> Currently, such agents work particularly well in clearly defined use cases. SAP will release more than 50 (currently 34) specialized AI agents.</p>



<p class="wp-block-paragraph">One example is periodic financial reporting. In this context, journal entries must be made based on numerous rules stored in documents, emails, or previous transactions. The agent analyzes these various sources of information, derives a recommendation from them, and suggests the appropriate journal entry to the user.</p>



<p class="wp-block-paragraph">Based on what we’ve heard from customer projects, employees at medium-sized companies currently spend about twelve hours per month on these tasks. With the help of an AI agent, this effort can be reduced to two to three hours.</p>



<p class="wp-block-paragraph">Another area of application is production planning. If delivery dates change or new orders come in at short notice, the entire production plan must be adjusted. It is precisely these kinds of complex optimization tasks that are ideally suited for AI agents.</p>



<p class="wp-block-paragraph">In principle, there are virtually no limits to the narrowly defined business processes in which agents can be deployed. However, they will not operate completely autonomously at first.</p>



<h2 class="wp-block-heading">Trust in AI begins with a stable foundation</h2>



<p class="wp-block-paragraph"><em>Many companies still struggle to trust AI agents. After all, large language models operate probabilistically and can produce false information. This is particularly problematic in financial processes. How do you build trust?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> Trust begins with a stable foundation. ERP systems remain the reliable system of record. They operate deterministically, contain the business logic, and hold the relevant company data. AI agents build upon this foundation. They do not replace it.</p>



<p class="wp-block-paragraph">Equally important is the human-in-the-loop principle. Employees must be able to understand what the agent is doing, verify its results, and intervene if necessary. That’s why employee training also plays a crucial role. They must understand how generative AI works and where its limitations lie.</p>



<p class="wp-block-paragraph">Of course, language models can hallucinate. At the same time, we must not forget that humans are not infallible either. The key lies in the collaboration between humans and AI. This allows us to improve both the efficiency and the quality of many business processes.</p>



<p class="wp-block-paragraph">Another important component is transparency. Our global AI ethics policy, for example, stipulates that users must always be able to recognize when AI is involved. In Joule, it’s possible to trace which data sources the agent used and which steps it went through in reaching its decision. This traceability is an essential prerequisite for trust.</p>



<p class="wp-block-paragraph"><em>What distinguishes an SAP agent from a general AI agent that merely accesses an ERP system?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> The key difference is that Joule and the SAP agents are directly embedded in the ERP system. There, for example, we’ve built a knowledge graph that describes the semantic relationships between all tables, business objects, and data fields.</p>



<p class="wp-block-paragraph">To put this into perspective: The SAP S/4HANA Knowledge Graph is based on approximately 452,000 ABAP tables, 7.3 million data fields, and thousands of analytical views. The semantic relationships between these artifacts are modeled in the Knowledge Graph and made available for AI applications.</p>



<p class="wp-block-paragraph">For example, if a user wants to view all open purchase orders, the agent does not first have to laboriously search for the relevant information. It immediately knows which tables and objects are relevant and also understands the relationships between a purchase order, a purchase requisition, the responsible approvers, and other business objects. As a result, the agent not only works much more precisely but also requires significantly fewer tokens because it can greatly narrow down the search space.</p>



<p class="wp-block-paragraph">If, instead, one attempts to simply overlay AI onto an existing system or extract data from a relational ERP system, many of these relationships are lost. In a sense, this destroys the semantic context that is crucial for precise answers.</p>



<p class="wp-block-paragraph">That is why we view the ERP system as an enormous strategic advantage. It has been the system of record for decades and contains roughly 50 years of codified business and process knowledge. This knowledge forms the foundation for what we call the <a href="https://www.cio.com/article/4170465/saps-biggest-ai-bet-yet-agents-that-execute-not-just-assist.html">autonomous enterprise</a>. The agents build upon this knowledge and continue to develop it.</p>



<p class="wp-block-paragraph">In the future, SAP agents will also communicate bidirectionally with agents from other providers via standards such as Agent-to-Agent (A2A).</p>



<p class="wp-block-paragraph"><em>According to your study, AI currently creates the greatest added value in decision-making, customer interaction, and gaining new insights, rather than in traditional productivity gains. Will this change the way companies justify AI investments in the future?</em></p>



<p class="wp-block-paragraph"><strong>Kask:</strong> In our study, productivity was simply rated slightly lower than, for example, gaining new insights. In the long term, however, productivity remains the ultimate goal. Europe, in particular, has been suffering from comparatively weak productivity growth for years.</p>



<p class="wp-block-paragraph">At SAP, we therefore first evaluate every new AI feature based on its specific business value. For all agents and AI features that we include in our AI Feature Catalog, we first conduct a value analysis. We ask: What benefit does the feature offer the user? Does it contribute to higher revenue? Does it increase productivity? Only then is it developed further.</p>



<p class="wp-block-paragraph">At the moment, the greatest added value often still lies in consolidating information from structured and unstructured data sources and making it accessible via natural language. The next step, however, is to translate these insights directly into more efficient business processes. That is precisely where the greatest productivity gains will be realized in the future.</p>



<blockquote class="wp-block-quote is-style-plain is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><em>If you could give CIOs just one or two pieces of advice for the transition from generative AI to AI agents, what would they be?</em></p>
</blockquote>



<p class="wp-block-paragraph"><strong>Kask:</strong> In my view, the biggest mistake would be to try to transform the entire company all at once or to attempt to perfectly prepare all the data right from the start.</p>



<p class="wp-block-paragraph">Instead, you should consider what kind of agent can create significant added value, and then implement it. Of course, this agent needs access to consistent and context-rich enterprise data. That’s exactly what we’re working on at SAP with technologies like the knowledge graph, which maps the semantic relationships within enterprise data.</p>



<p class="wp-block-paragraph">In addition, with data products and the SAP Business Data Cloud, we provide tools that make data from various sources usable for AI agents. Thanks to zero-copy and data fabric approaches, information from legacy systems, Snowflake, or ERP systems can be consolidated without first having to extensively replicate the data. For a procurement agent, this makes it possible to provide exactly the relevant data for the specific use case.</p>



<p class="wp-block-paragraph">The key point is this: Companies do not have to wait until they have fully migrated to the cloud or consolidated their entire data landscape. With the technologies available today, data can already be made usable for specific AI agents, managed in a controlled manner, and used to quickly generate initial business value. On the other hand, those who wait for the perfect starting point run the risk of falling behind.</p>



<p class="wp-block-paragraph"><em>This article is adapted from one first published by Computerwoche.</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p class="wp-block-paragraph"><a></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Which AI model should you bet your company on? None of them]]></title>
<description><![CDATA[Every day this past week I did something I suspect millions of other people also did: I stared at an LLM model picker and wondered which one I was supposed to want.



OpenAI just released ⁠GPT-5.6 Sol, Terra, and Luna. Sol is the flagship. Terra offers much of its intelligence for less money. Lu...]]></description>
<link>https://tsecurity.de/de/3671165/ai-nachrichten/which-ai-model-should-you-bet-your-company-on-none-of-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671165/ai-nachrichten/which-ai-model-should-you-bet-your-company-on-none-of-them/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:39 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every day this past week I did something I suspect millions of other people also did: I stared at an <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLM </a>model picker and wondered which one I was supposed to want.</p>



<p class="wp-block-paragraph">OpenAI just released ⁠<a href="https://openai.com/index/gpt-5-6/">GPT-5.6 Sol, Terra, and Luna</a>. Sol is the flagship. Terra offers much of its intelligence for less money. Luna is cheaper still. Anthropic released ⁠<a href="https://www.anthropic.com/news/claude-sonnet-5">Claude Sonnet 5</a> at the end of June and Opus 4.8 the month prior, with a little Fable 5 emerging in between. Meanwhile, Google, which seemed to be winning the model wars a few months ago, is now getting shade from Gergely Orosz, who ⁠<a href="https://x.com/GergelyOrosz/status/2075160978493210685?s=20">argues that Gemini has slipped outside the top tier</a> for software development and has been out of the major model release game for <em>eons</em> (May 19).</p>



<p class="wp-block-paragraph">Perhaps Orosz is right. Perhaps he’ll be wrong again in six weeks. Honestly, it’s exhausting.</p>



<p class="wp-block-paragraph">I use ChatGPT and Claude constantly and still have no principled idea which model to choose most of the time. I tend to click whatever looks like the biggest, most expensive option because I don’t know what I’m giving up by choosing something smaller. “Instant” sounds dangerously unserious. “Thinking” sounds expensive but powerful.</p>



<p class="wp-block-paragraph">A quick <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/">survey of my LinkedIn crowd</a> suggests others also feel my “WHICH MODEL???” pain. More importantly, I suspect most enterprises do, too.</p>



<h2 class="wp-block-heading"><a></a>A model doesn’t rot</h2>



<p class="wp-block-paragraph">Before getting carried away, however, it’s worth considering whether any of this model churn actually matters. After all, a model doesn’t rot. The model an enterprise put into production in March performs just as well in July as it did when the company selected it. “Obsolete” generally means that something better now exists, not that the deployed model suddenly stopped summarizing insurance claims or classifying support tickets. (In other words, once you have something working, the idea that “but maybe Opus 200.2 is better!” is really a FOMO problem, not a performance issue.)</p>



<p class="wp-block-paragraph">Most enterprise workloads don’t live at the frontier anyway. Extraction, summarization, classification, document comparison, and customer-service assistance often work perfectly well with smaller, cheaper models. OpenAI’s own pitch for the trio of GPT-5.6 models isn’t simply that Sol is better. It’s that ⁠Terra and Luna deliver different combinations of intelligence, latency, and cost. Luna, the cheapest tier, nearly matches the previous generation’s peak performance at less than half the estimated cost, according to OpenAI.</p>



<p class="wp-block-paragraph">The practical question, of course, is where to start. An enterprise can’t test every model, every reasoning setting, and every price tier before doing any work. So here’s my advice (which I don’t follow in my own work, but I’m not defining enterprise strategy and can be a little price-insensitive). Start with the cheapest credible model that appears capable of the task. Give it a representative set of real examples and, before you start testing, define what counts as good enough. If it passes, stop. If it fails, move up a tier or try a model with strengths better suited to the work.</p>



<p class="wp-block-paragraph">That sounds almost offensively simple, but it reverses the way many people, including me, use these products. We start with the biggest model because we’re afraid of what we might lose. Enterprises should start lower and require evidence before paying for more intelligence.</p>



<p class="wp-block-paragraph">There are exceptions, of course. For genuinely difficult work, such as autonomous coding, complex research, or high-stakes reasoning, beginning with a frontier model may save time. But even then, the goal should be to establish a quality ceiling, then test whether a cheaper model can meet it. It’s changing the question from “which model is best?” to “what is the least expensive model that reliably clears the bar for this job?”</p>



<p class="wp-block-paragraph">For many workloads, that price improvement matters more than a few extra benchmark points. <a href="https://www.infoworld.com/article/2335519/ai-hype-isnt-helping-anyone.html">⁠As I argued back in 2023</a>, following AI hype doesn’t help anyone. If your model strategy depends on whichever benchmark screenshot is circulating on X this week, you don’t have a strategy. Not a viable one, anyway. Pick a model and ignore the noise.</p>



<p class="wp-block-paragraph">Except, of course, when that noise suggests a serious signal.</p>



<h2 class="wp-block-heading"><a></a>Sometimes better really is better</h2>



<p class="wp-block-paragraph">Frontier improvements aren’t always incremental, making it advantageous to consider an upgrade. Coding is the obvious example. There’s a significant difference between a model that suggests the next few lines of code and one that can inspect a repository, plan a change, use tools, run tests, discover its own mistakes, and keep working for an extended period. That isn’t merely a nicer autocomplete experience. It can reorganize a development workflow.</p>



<p class="wp-block-paragraph">This is why enterprises can’t simply standardize on an 18-month-old model and declare victory. In some areas, particularly software development and other agentic work, better models can unlock compounding productivity. A model that reliably completes 80% of a bounded task rather than 50% may justify an entirely different division of labor between humans and machines.</p>



<p class="wp-block-paragraph">Still, that upgrade isn’t free.</p>



<p class="wp-block-paragraph">Models differ in how they interpret instructions, call tools, manage context, refuse requests, and fail. Prompts and scaffolding tuned for one model can regress when moved to another. Or costs can explode. As one of my Oracle colleagues discovered just this week, running the same tasks in GPT 5.6 was orders of magnitude more expensive than 5.5. The API change may be trivial, but the revalidation and implications are not.</p>



<p class="wp-block-paragraph">This leaves enterprises caught between two bad options. They can freeze and potentially miss out on meaningful improvements or chase every release and repeatedly test production systems on faith. What to do?</p>



<h2 class="wp-block-heading"><a></a>Stop making model bets</h2>



<p class="wp-block-paragraph">The answer is to stop making LLM bets and start making job-to-be-done bets. Stop asking which model is fastest. Instead, figure out what work you are trying to improve. What does a good result look like? How much latency and cost can the workflow tolerate? How wrong can it be before a human must intervene? Once those questions have answers, model selection becomes less opaque.</p>



<p class="wp-block-paragraph">A difficult code migration may justify GPT-5.6 Sol or Claude Sonnet 5. A repetitive classification task may work just as well with Luna or another smaller model. A regulated workflow may require a model or deployment option that offers particular data controls. Sometimes the correct model is no LLM at all, like when I’m writing this post. Sorry, AI vendors! (At least you won’t get blamed for my mistakes.)</p>



<p class="wp-block-paragraph">This is where evaluations become the center of enterprise AI strategy. <a href="https://www.infoworld.com/article/4166247/improving-ai-agents-through-better-evaluations.html">⁠As I’ve said before</a>, most companies don’t have an AI quality problem so much as an AI measurement problem. Hence, a private evaluation suite built from real company work is the only leaderboard that matters. Does the new model materially improve quality? If so, use it! Does it reduce cost or latency? Again, that’s your free pass to adoption. Does the improvement justify the expense and effort of revalidation? If yes, continue.</p>



<h2 class="wp-block-heading"><a></a>Make model releases boring</h2>



<p class="wp-block-paragraph">As important as the model is, keep in mind that AI success always comes back to <em>your</em> company’s data, <em>your</em> company’s workflows<em>, your</em> company’s integrations, etc. That’s the ⁠<a href="https://www.infoworld.com/article/4157506/mastering-the-dull-reality-of-sexy-ai.html">dull reality behind sexy AI</a>. Retrieval, <a href="https://www.infoworld.com/article/4189492/how-to-improve-the-memory-of-ai-agents.html">memory</a>, governance, data quality, <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a>, and feedback loops aren’t as exciting as a new model launch, but they’re what ultimately make AI truly work.</p>



<p class="wp-block-paragraph">Again, when it’s time to consider something new, the principle should be to default to the least expensive model that reliably passes your evaluations. Only escalate harder tasks to more capable models when measurement shows that the premium pays. Tip: Make this invisible to employees so that the system routes to the best model for a particular prompt. As <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/?dashCommentUrn=urn%3Ali%3Afsd_comment%3A%287481372047860715522%2Curn%3Ali%3Aactivity%3A7481369774401409024%29">dbt Labs’ Jon Lewis expresses</a> it, “The best model is ‘Auto’ and I won’t hear anyone say otherwise.” OpenAI’s own ⁠<a href="https://developers.openai.com/api/docs/guides/latest-model">migration guidance</a> recommends testing models on representative tasks, including trying a lower reasoning level rather than automatically cranking everything to the maximum.</p>



<p class="wp-block-paragraph">As for me, I’ll probably keep clicking the shiniest option. I don’t have a formal evaluation suite for InfoWorld columns, and the marginal cost is a subscription I already pay. Enterprises don’t get that excuse.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Go-based TypeScript 7.0 arrives]]></title>
<description><![CDATA[Microsoft has released TypeScript 7.0, a native port of the company’s strongly typed version of the JavaScript language based on the Go programming language. 



With this new codebase, TypeScript 7.0 brings native code speed, shared memory multithreading, and a number of new optimizations that t...]]></description>
<link>https://tsecurity.de/de/3671163/ai-nachrichten/go-based-typescript-70-arrives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671163/ai-nachrichten/go-based-typescript-70-arrives/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft has released TypeScript 7.0, a native port of the company’s <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">strongly typed version of the JavaScript language</a> based on the <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go programming language</a>. </p>



<p class="wp-block-paragraph">With this new codebase, TypeScript 7.0 brings native code speed, shared memory multithreading, and a number of new optimizations that typically yield speedups between 8x and 12x on full builds, Microsoft said in a <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/">July 8 announcement</a>. This port of TypeScript to native code was done as faithfully as possible, writing new code while maintaining the structure and logic of the original codebase to keep results consistent and compatible between the two compilers, according to Microsoft. </p>



<p class="wp-block-paragraph">TypeScript 7.0 is available via npm:</p>



<pre class="wp-block-code"><code>npm install -D typescript</code></pre>



<p class="wp-block-paragraph">To help with the TypeScript 6.0 to TypeScript 7.0 transition process, Microsoft has published a new compatibility package, <code>@typescript/typescript6</code>. This package provides an executable named <code>tsc6</code>, so that if needed, a developer can install TypeScript 7.0 (which ships its own <code>tsc</code> binary) side-by-side with TypeScript 6.0 without naming conflicts. The new package also re-exports the TypeScript 6.0 API, so that a developer can use <code>tsc</code> for TypeScript 7, while other tooling can continue to rely on TypeScript 6.0.</p>



<p class="wp-block-paragraph">TypeScript 7.0 is a major milestone in the TypeScript project, Microsoft said. This port has been the primary focus for Microsoft’s team for more than a year. With TypeScript 7.0 now out, the team will return to new feature work, ergonomic improvements, more performance wins, and implementing a new API for the broader ecosystem. Microsoft expects a fairly similar timeline to releases prior to TypeScript 7.0, with new versions published every three to four months. </p>



<p class="wp-block-paragraph">TypeScript 7.0 was announced as a <a href="https://www.infoworld.com/article/4191918/typescript-7-0-reaches-release-candidate-stage.html">release candidate</a> on June 18. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’]]></title>
<description><![CDATA[OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that the popular platform has thus far lacked. Still, some worry about the risks created by the move. 



“Our ambition is for OpenClaw...]]></description>
<link>https://tsecurity.de/de/3671162/ai-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671162/ai-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">the popular platform </a>has thus far lacked. Still, some worry about the risks created by the move. </p>



<p class="wp-block-paragraph">“Our ambition is for OpenClaw to be the Switzerland of AI. Neutral ground where every model and every lab can plug into the technology and collaborate on standards in the era of agents,” <a href="https://openclaw.ai/blog/introducing-openclaw-foundation/" target="_blank" rel="noreferrer noopener">OpenClaw said in a post</a>. “That work is already underway in Foundation-convened councils on agent identity, agent profiles, evals, and enterprise deployment.”</p>



<p class="wp-block-paragraph">The statement, co-authored by OpenClaw creator <a href="https://www.linkedin.com/in/steipete/" target="_blank" rel="noreferrer noopener">Peter Steinberger</a>, pointed out, “the great open source projects of our time — Linux, Apache, Mozilla — endure because a neutral steward stands behind them. That is the role we are taking on to keep OpenClaw MIT licensed, open, and independent so that everyone building on it can trust it will be here for the long term.”</p>



<p class="wp-block-paragraph">But it reassured users that the original OpenClaw leadership is still in charge.</p>



<p class="wp-block-paragraph">“Peter built this thing and Peter keeps making the calls, especially the technical ones. Since joining OpenAI earlier this year, he has continued to steward OpenClaw as an open and independent project, and OpenAI has made a commitment to keep it that way,” the post said. “The foundation is here to serve: good governance, stable funding, and paying the people who keep the claws alive.”</p>



<p class="wp-block-paragraph">However, some analysts and consultants were skeptical about how much true independence Steinberger would have, given his salaried role with OpenAI. </p>



<h2 class="wp-block-heading">Neutrality claim in question</h2>



<p class="wp-block-paragraph">“The Switzerland of AI neutrality claim collapses under its own announcement,” said <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520. “OpenAI runs a team [at OpenAI] called Claw Labs that Peter leads and OpenAI is a major donor to OpenClaw. The ‘neutral steward’s’ chief technical decision maker is employed by one of the competing labs it is supposed to be neutral with.” To OpenAI, he said, OpenClaw is closer to a tax-exempt nonprofit subsidiary than it is to a neutral ‘Switzerland of AI.’</p>



<p class="wp-block-paragraph">He pointed out that, in addition, Microsoft is shipping <a href="https://www.computerworld.com/article/4173442/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era-2.html" target="_blank">the enterprise version</a> of OpenClaw, and Nvidia is shipping the hardware bundle. “This is being called the Switzerland of AI, but Switzerland does not have its central bank run by France,” he observed.</p>



<p class="wp-block-paragraph">Kenney said that what the new OpenClaw has actually built is “a shared dependency that several competitors fund, staff, and steer, wrapped in a nonprofit structure. Enterprise IT should understand that structure, because treating OpenClaw as neutral is a mistake,” adding that CIOs need to look at this development devoid of the emotional component. </p>



<p class="wp-block-paragraph">“There is a strategic irony here that CIOs should sit with,” Kenney said. “If OpenClaw succeeds at becoming the universal agent substrate, then every model plugs into the same identity layer, the same profiles, and the same deployment plumbing. The thing every vendor is racing to own becomes a commodity that nobody owns.” He pointed out that, in the short term, that is genuinely good news for buyers because it means less lock-in and more portability.</p>



<p class="wp-block-paragraph">“But,” he said, “when the connective tissue is free and natural, the only labs that benefit are the ones with the best models and the deepest distribution. Commoditize the layer below you and you compete on the layer where you are already strongest. The foundation is not a charity. It is the biggest players agreeing to stop fighting over the plumbing so they can fight over the water, and the enterprise is the one paying the water bill either way.”</p>



<h2 class="wp-block-heading">Good news, bad news</h2>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, liked the potential consistency that could emerge from the structural change, given the complexity of agent development today. </p>



<p class="wp-block-paragraph">“We are seeing a lot of OpenClaw variants hit the market, such as those from Nvidia as well as competing products from cloud and SaaS vendors. A common base helps solidify the common parts,” Andersen noted. “That said, a common challenge is the sustainability of these open source foundations over time. In addition to releasing code, these foundations need funding to evolve and grow. And that funding needs to come from continued momentum to incentivize existing members to increase investment and recruit new members to join.”</p>



<p class="wp-block-paragraph">Andersen stressed that IT buyers need to keep an eye on the roadmap for any OpenClaw variant they choose to deploy, “as that will directly impact the foundation, and the momentum of the foundation and common base. If the common base loses momentum, it can lead to forks, or just a loss of innovation. When that happens, members tend to back away, which puts customers in limbo.”</p>



<p class="wp-block-paragraph">But not everyone sees the promised structure as entirely good for IT.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO at coding productivity tool vendor Kodezi, said, “most CIOs do not want to bet their future entirely on a single model vendor. They want Claude for some workloads, GPT for others, open models for sensitive environments, and potentially internally fine-tuned systems for specific use cases. The problem is that every vendor currently brings its own identity system, tool interfaces, permissions model, and operational assumptions. That fragmentation does not scale.”</p>



<p class="wp-block-paragraph">He said, “the risk if standards fail is straightforward: every vendor builds its own closed ecosystem, enterprises become locked into individual stacks, and security becomes dramatically harder. The opportunity if OpenClaw succeeds is equally significant: enterprises get portable agents, common identity standards, interoperable tooling, and a healthier competitive market around models rather than ecosystems.”</p>



<h2 class="wp-block-heading">Will it remain a nonprofit?</h2>



<p class="wp-block-paragraph">However, said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, one of the key details that IT executives will want to keep in mind is that OpenAI also began as a nonprofit, but it was quickly <a href="https://www.computerworld.com/article/4056490/openai-microsoft-discuss-shape-of-future-relationship.html" target="_blank">seen as not adhering to nonprofit objectives</a>. </p>



<p class="wp-block-paragraph">“OpenAI’s transition from a nonprofit research organization into a more complex structure highlighted the challenge of maintaining mission alignment while scaling technology, capital, partnerships, and commercial operations,” Greis said. “OpenClaw has the opportunity to address some of those governance questions earlier by establishing clear principles around neutrality, transparency, and decision-making before the ecosystem becomes even larger and more valuable.”</p>



<p class="wp-block-paragraph">He noted, “we have seen this pattern before with technologies like Linux and Kubernetes. The strongest open ecosystems succeeded because they created trusted foundations that enterprises could build upon. The technology was important, but the governance model that underpinned it was equally critical.”</p>



<h2 class="wp-block-heading">Risks are ‘squarely in IT’s lap’</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, echoed Greis’ concerns. </p>



<p class="wp-block-paragraph">“CIOs shouldn’t assume that this nonprofit will always be a nonprofit, or confuse being a nonprofit with actually being neutral or unbiased,” he said. “The risks are squarely in IT’s lap: autonomous agents ‘with their own identity’ acting on a user’s behalf blow straight through traditional IAM assumptions. Issues, such as agent identity, auditability, secret handling. Identity boundaries have not yet been reliably solved. Until they are, enterprises should treat OpenClaw agents like privileged service accounts, not like a browser plugin.”</p>



<p class="wp-block-paragraph">Independent cybersecurity and risk advisor <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a> pointed to another IT exposure that might come from this OpenClaw transition: Cost.</p>



<p class="wp-block-paragraph">“OpenClaw currently has a very high token burn rate in usage, which presents a significant cost consideration for large-scale enterprise adoption,” he said. “The skills marketplace introduces <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">a new supply chain threat </a>that enterprises will need to manage. Threat management, and specifically handling <a href="https://www.csoonline.com/article/4135449/compromised-npm-package-silently-installs-openclaw-on-developer-machines.html" target="_blank">external marketplace elements</a>, can be highly challenging for open-source operations. Ultimately, at scale, enterprise adoption could become a difficult balancing act between managing high operational costs and securing an expanded security surface.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" target="_blank">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What 80% AI-written test pipelines actually cost]]></title>
<description><![CDATA[The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?



After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the typing, not eighty percent o...]]></description>
<link>https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?</p>



<p class="wp-block-paragraph">After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the <em>typing</em>, not eighty percent of the <em>engineering</em>. The remaining twenty was where the work still lived. Budgeting for two percent of leftover effort was the mistake. When the real number was closer to thirty, that gap was the difference between a pipeline that shipped and one that quietly built up a queue of half-trusted features nobody could rely on.</p>



<p class="wp-block-paragraph">This piece is about that gap. As an independent research project on LLM-augmented testing methodology, I built a six-stage agentic pipeline that takes a design in Figma and produces running tests in WebDriverIO, connected end to end over the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. It works. It has been useful. And the parts that broke surprised me, because they were not the parts the hype cycle tells you to worry about.</p>



<h2 class="wp-block-heading">How I wired a six-stage pipeline over one protocol</h2>



<p class="wp-block-paragraph">The pipeline runs six stages in sequence, each owned by a different agent, with every handoff crossing MCP.</p>



<p class="wp-block-paragraph">Six-stage agentic test pipeline: design capture → requirements writer → ticket opener → code generator → test-case writer → automation generator. Each stage carries an MCP handoff and a provenance stamp.</p>



<p class="wp-block-paragraph">The end-to-end trace links a pull request back to a Jira ticket, a requirements section and a Figma frame. Each artifact is stamped with the agent that produced it, the model it used and the inputs it was given.</p>



<p class="wp-block-paragraph">MCP is the boring middle that makes any of this work. The cliché is that MCP is “USB-C for AI”: one open protocol, any tool. Like most analogies, it is about eighty percent right. The part that matters is the eighty: I do not have to write a custom adapter for every system the agent talks to. One MCP server per tool and every agent talks to all of them the same way.</p>



<p class="wp-block-paragraph"><strong>Typed handoffs between agents are my own architecture, layered on top of MCP rather than provided by it.</strong> Each agent writes a typed artifact the next agent reads. Each handoff is logged with provenance. When something went wrong six stages in, I could replay the chain. Without that discipline, a multi-agent pipeline is a debugger’s worst day. You know the test plan is wrong. You cannot tell whether the mistake came from the Figma read, the requirements interpretation or the ticket scaffolding. With it, I could point at exactly which stage went sideways and which inputs it was looking at when it did. The pattern lives in a <a href="https://github.com/SuneetMalhotra/agent-harness">public MIT-licensed reference implementation</a> for any reader who wants to run it.</p>



<p class="wp-block-paragraph"><strong>The sixteen-minute number is the marketing number.</strong> I ran the full chain end to end in about sixteen minutes on a synthetic net-new screen, Figma in, automation suite out. That repeated across my runs; it is not a demo trick. But sixteen minutes is the part of the story most fun to tell and least useful to learn from. It is what gets quoted in the all-hands. The hours that come after, when a human reviews each handoff, are where the work actually lives.</p>



<h2 class="wp-block-heading">What actually broke in production-style runs</h2>



<p class="wp-block-paragraph">The failures that stalled my pipeline were rarely the ones I expected.</p>



<p class="wp-block-paragraph">I expected hallucinated APIs. I got them: the agent confidently called endpoint names that sounded right but did not exist. I expected sparse-spec-in, sparse-spec-out, where a Figma frame with no annotations produced a requirements doc with vague acceptance criteria, every time. I expected locator drift, the common UI-automation failure mode where a renamed component silently breaks an entire test suite. There is solid <a href="https://martinfowler.com/articles/nonDeterminism.html">outside writing on non-determinism in tests</a> covering this whole family of failure modes, and the agent inherited every one.</p>



<p class="wp-block-paragraph">What I did not expect, and what kept the pipeline down longer than any of the above, was the plumbing.</p>



<p class="wp-block-paragraph">The model backend timed out under load. It lost credentials silently and started returning empty strings, which the agent then read as confidence. A duplicate consumer on a shared long-poll API endpoint produced an HTTP 409 conflict that broke delivery without throwing anything visible. One unguarded exception inside one agent aborted a whole shared scheduler run and took the other agents in the registry down with it. The single worst incident cost me three hours to find. An environment variable had silently rotated overnight; every agent in the fleet was returning structurally valid but semantically empty requirements docs; the downstream stages were dutifully generating tests against nothing.</p>



<p class="wp-block-paragraph">None of those are model bugs. They are infrastructure. The agent literature, which is what I went looking through when I started this work, mostly does not talk about them.</p>



<p class="wp-block-paragraph">The fix was not better prompts. It was <a href="https://martinfowler.com/bliki/CircuitBreaker.html">circuit-breaker-style</a> review checkpoints between stages and what I now call <strong>the four-guard discipline</strong>: four small guards I consider non-negotiable on any unattended agentic pipeline. The bulkhead pattern from microservices is the most consequential. An unhandled exception inside one agent can no longer abort the shared run; the offending agent fails fast with a structured error and the others keep going. Paired with that, a pure-data fallback ensures a model timeout produces a deterministic output explicitly marked as degraded mode, rather than an empty string the next stage will misread as confidence. A single-owner lease sits on every shared external endpoint, the cure for the duplicate-consumer incident that ate one of my Sunday afternoons. The cheapest guard was the last to arrive: a one-line synthetic canary every agent has to produce a known correct response to before any real work begins, so a credentials rotation or silent backend failure trips an alert before downstream stages have generated artifacts against garbage.</p>



<p class="wp-block-paragraph">None of these guards is novel. They are textbook stability patterns at a new boundary: the seam between the LLM agent and the rest of the system, which most of the existing agent literature still treats as a solved problem.</p>



<h2 class="wp-block-heading">The 20% you don’t see, and when not to do this</h2>



<p class="wp-block-paragraph">Here is the part the demo videos leave out. Even when the pipeline works, the human time per stage does not go to zero.</p>



<p class="wp-block-paragraph">Human review time per ticket across five pipeline stages: code review 60-180 min, automation review and flaky-fix loop 30-90 min, ticket architecture and sequencing 30-60 min, test data and environment 15-30 min, requirements review 20-30 min. Net: the human still spends 20-30% of the original effort, almost all of it reviewing rather than creating.</p>



<p class="wp-block-paragraph"><strong>Net of all that, the human still spends twenty to thirty percent of the original effort, almost all of it reviewing rather than creating.</strong> The pipeline saves seventy to eighty percent, not ninety-eight. The trap is budgeting for the two percent you do not save.</p>



<p class="wp-block-paragraph">When does this kind of pipeline make sense? In my experience, when the Figma is richly annotated and acceptance criteria are clear up front; when there is review capacity to absorb the work the pipeline shifts onto humans; when the stack is well represented in the training data; and when the feature is net-new rather than a deep edit of legacy code. When does it not? When the design lives on a whiteboard. When the integration touches old code with hidden contracts. When the path is regulated or safety-critical. When there is no senior reviewer who can hold the line. When the work is exploratory and writing the spec is the actual point of the exercise.</p>



<p class="wp-block-paragraph">Teams I have seen succeed with agentic pipelines budget for the rework explicitly, staff the review queue and treat the saved hours as capacity for harder problems rather than headcount they can release. Teams I have seen struggle did the opposite: declared victory at the demo and quietly accumulated a backlog of half-trusted features the next quarter had to clean up.</p>



<p class="wp-block-paragraph">The right unit of measurement is not how much the pipeline generates. It is how much of what it generates a human still has to touch before you would ship it. Call it <strong>the 80/20 rework rule</strong>: measure the rework, not the generation. The teams that get the rework number right are the ones whose AI investments compound. The teams that stop counting at the headline percentage are the ones that own the cleanup six months later.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.infoworld.com/expert-contributor-network/"><strong><u>Want to join?</u></strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Seriously, except package managers, what's the difference between distros?]]></title>
<description><![CDATA[What I've seen yet the differences are, just the package managers, different defaults and rolling vs stable releases which are in fact related to package managers. Except these, are there really any other differences? Thanks!    submitted by    /u/nitin_is_me   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3670834/linux-tipps/seriously-except-package-managers-whats-the-difference-between-distros/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670834/linux-tipps/seriously-except-package-managers-whats-the-difference-between-distros/</guid>
<pubDate>Wed, 15 Jul 2026 15:40:56 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>What I've seen yet the differences are, just the package managers, different defaults and rolling vs stable releases which are in fact related to package managers. Except these, are there really any other differences? Thanks!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/nitin_is_me"> /u/nitin_is_me </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ux5vns/seriously_except_package_managers_whats_the/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ux5vns/seriously_except_package_managers_whats_the/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[I tested Windows 11's overhauled search experience, and I think Microsoft has finally fixed it: Windows Search is now more accurate and easier to use]]></title>
<description><![CDATA[Microsoft's new Windows Search experience is now rolling out in preview, and I've gone hands-on to see if the improvements really do make a difference.]]></description>
<link>https://tsecurity.de/de/3670574/windows-tipps/i-tested-windows-11s-overhauled-search-experience-and-i-think-microsoft-has-finally-fixed-it-windows-search-is-now-more-accurate-and-easier-to-use/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670574/windows-tipps/i-tested-windows-11s-overhauled-search-experience-and-i-think-microsoft-has-finally-fixed-it-windows-search-is-now-more-accurate-and-easier-to-use/</guid>
<pubDate>Wed, 15 Jul 2026 14:11:02 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft's new Windows Search experience is now rolling out in preview, and I've gone hands-on to see if the improvements really do make a difference.]]></content:encoded>
</item>
<item>
<title><![CDATA["The difference between launching now and launching never": How vibe coding is turning small business ideas into functional apps in record time]]></title>
<description><![CDATA[Could vibe coding help small businesses overcome bottlenecks in app development?]]></description>
<link>https://tsecurity.de/de/3670494/it-nachrichten/the-difference-between-launching-now-and-launching-never-how-vibe-coding-is-turning-small-business-ideas-into-functional-apps-in-record-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670494/it-nachrichten/the-difference-between-launching-now-and-launching-never-how-vibe-coding-is-turning-small-business-ideas-into-functional-apps-in-record-time/</guid>
<pubDate>Wed, 15 Jul 2026 13:32:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Could vibe coding help small businesses overcome bottlenecks in app development?]]></content:encoded>
</item>
<item>
<title><![CDATA[How to unionize your tech workplace]]></title>
<description><![CDATA[This is Part 2 of a series on tech worker unionization. See Part 1: “A brewing battle: More IT workers want unions. The industry doesn’t.”



The best time for tech workers to unionize was 20 years ago, when they had plenty of leverage. The second-best time is now, when they don’t.



Mass layoff...]]></description>
<link>https://tsecurity.de/de/3670454/it-nachrichten/how-to-unionize-your-tech-workplace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670454/it-nachrichten/how-to-unionize-your-tech-workplace/</guid>
<pubDate>Wed, 15 Jul 2026 13:18:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><em>This is Part 2 of a series on tech worker unionization. See Part 1: “<a href="https://www.computerworld.com/article/4191760/brewing-battle-more-tech-workers-want-unions-but-the-industry-doesnt.html">A brewing battle: More IT workers want unions. The industry doesn’t</a>.”</em></p>



<p class="wp-block-paragraph">The best time for tech workers to unionize was 20 years ago, when they had plenty of leverage. The second-best time is now, when they don’t.</p>



<p class="wp-block-paragraph">Mass layoffs, AI-driven displacement, corporate surveillance, workplace disillusionment have created conditions that have made organizing compelling for tech professionals. But the federal labor board that has historically protected workers’ right to organize has been weakened, and the companies that once feared it are openly defying it.</p>



<p class="wp-block-paragraph">Here’s how organizers and labor experts describe the pros and cons to organizing — and how you can get started.</p>



<h2 class="wp-block-heading">What unions can — and can’t — do for you</h2>



<p class="wp-block-paragraph">The single biggest benefit of a union contract for most tech workers isn’t pay — it’s protection against arbitrary termination, especially in the wake of recent mass layoffs in tech. In the United States, nonunion “at-will” workers can be fired at any time without a stated reason, while unionized workers negotiate protections written into their contracts.</p>



<p class="wp-block-paragraph">“That fear of the company letting you go for anything at any time…with a union they just can’t do that,” says <a href="https://www.linkedin.com/in/zthompson1/" target="_blank" rel="noreferrer noopener">Zak Thompson</a>, a senior software engineer at Kickstarter and union steward at Kickstarter United. Now that Kickstarter employees are unionized, people are less worried that saying something negative will result in termination.</p>



<p class="wp-block-paragraph">“I’ve been shocked at the willingness of my co-workers to speak up against what they see as poor or controversial business decisions,” Thompson says.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="972" height="972" sizes="auto, (max-width: 972px) 100vw, 972px"&gt;<figcaption class="wp-element-caption"><p>Zak Thompson from Kickstarter United</p><br></figcaption></figure><p class="imageCredit">Fee Christoph</p></div>



<p class="wp-block-paragraph"><strong>Beyond job security, unions can deliver concrete material gains.</strong> <a href="https://kickstarterunited.org/about/" target="_blank" rel="noreferrer noopener">Kickstarter United was formed in 2020</a>, although getting there wasn’t easy: two employees were fired during the organizing campaign — which itself became a galvanizing event. And while the union hasn’t been able to prevent layoffs, it did negotiate better terms: four months of severance pay and four to six months of continued health insurance, versus the two to three weeks per year of work that management had initially proposed.</p>



<p class="wp-block-paragraph">Other benefits include a four-day work week; AI protections; a minimum pay floor; and standards for raises, promotions, and time off for the company’s 59 employees.</p>



<p class="wp-block-paragraph"><strong>Unions can give tech workers a voice in decisions that affect their daily work — including how AI tools are deployed.</strong> “Nobody I’ve spoken to is against new technology or getting trained in it,” says <a href="https://www.linkedin.com/in/mbelasco/" target="_blank" rel="noreferrer noopener">Max Belasco</a>, a business systems analyst at the University of California Los Angeles School of Law and co-chair of the UCLA chapter of the University Professional and Technical Employees/Communications Workers of America (UPTE-CWA) Local 9119.</p>



<p class="wp-block-paragraph">“But when new technology is being implemented, we want to know: what’s the five-year vision, the 10-year vision? Are we implementing this in a way that betters staffing, increases efficiency, or eases the lives of people already working? Or are we trying to take away jobs, automate people out of their pension or paycheck?” Belasco says.</p>



<p class="wp-block-paragraph"><strong>The challenges are real.</strong> Tech professionals are less inclined to leave their jobs in the current market because wages haven’t been increasing as fast as they once were, and it can take longer to land another job.</p>



<p class="wp-block-paragraph">“Tech moved from a very tight labor market in 2022 (1.85% unemployment rate) to a noticeably weaker one in 2024–2026 (3.49%),” although that’s still better than the national unemployment rate of 4.36% through May of this year, says <a href="https://www.mercatus.org/scholars/liya-palagashvili" target="_blank" rel="noreferrer noopener">Liya Palagashvili</a>, senior research fellow and director of the Labor Policy Project at the Mercatus Center at George Mason University.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="960" height="640" sizes="auto, (max-width: 960px) 100vw, 960px"&gt;<figcaption class="wp-element-caption"><p>Liya Palagashvili of the Mercatus Center at George Mason University</p></figcaption></figure><p class="imageCredit">Mercatus Center at George Mason University</p></div>



<p class="wp-block-paragraph"><strong>Flexibility is a concern.</strong> The more substantive challenge, raised by economists including Palagashvili, is that traditional union contracts impose uniform terms across an entire bargaining unit, limiting the flexibility that many tech workers — and their employers —currently enjoy. Tech firms need to move fast, adjusting teams, products, and roles on the fly.</p>



<p class="wp-block-paragraph">“Collective bargaining agreements can make those adjustments much more difficult, whether by making them slower, costlier, or inconsistent with the contract,” she says.</p>



<p class="wp-block-paragraph">Workers skeptical of unions in a <a href="https://www.teamblind.com/blog/why-are-unions-not-common-tech-industry/" target="_blank" rel="noreferrer noopener">survey of 1,900 tech professionals</a> conducted by the career site Blind cited specific concerns: that unions are “not meritocratic,” “prevent innovation,” and “hold back earnings of top performers.”</p>



<p class="wp-block-paragraph">Thompson from Kickstarter United pushes back: “We have nothing in our contract about ‘you can’t bend down and pick up a piece of trash because that’s someone else’s job.’ The company is free to give bonuses and individual raises as much as they like. This is all just up to the people who are bargaining the contract from the union side.”</p>



<p class="wp-block-paragraph"><strong>Organizing carries potentially serious personal risks.</strong> During negotiations for a second three-year contract in 2025, Kickstarter United went on strike for 42 days. A few months later, the company announced layoffs.</p>



<p class="wp-block-paragraph">“They let go strong union leaders, including a person who had bargained our last contract,” Thompson says. The union appealed, and the issue is now going to arbitration.</p>



<p class="wp-block-paragraph">If you form a union, don’t expect much support from the <a href="https://www.nlrb.gov/" target="_blank" rel="noreferrer noopener">National Labor Relations Board</a>, the agency that certifies US labor unions and protects workers’ right to organize, in terms of prosecuting complaints of unfair labor practices, Thompson warns. “We’re in a political moment in this country with a pretty weakened NLRB. You have to be ready to organize and withhold worker power without any guarantee of safety.”</p>



<p class="wp-block-paragraph"><strong>Organizers are up against an enormous union avoidance industry.</strong> Organizers can expect fierce pushback as soon as the business discovers that organizing is underway.</p>



<p class="wp-block-paragraph">“There’s a multi-billion-dollar industry in union avoidance,” says <a href="https://www.linkedin.com/in/alan-mcavinney-a386b8122/" target="_blank" rel="noreferrer noopener">Alan McAvinney</a>, a Google software engineer and organizing chair, Alphabet Workers Union-CWA, a 1,400-member minority union of Alphabet employees. (Google is a subsidiary of Alphabet.)</p>



<p class="wp-block-paragraph">US employers spend roughly $1.7 billion a year on union avoidance consultants and law firms, according to a <a href="https://www.epi.org/press/u-s-employers-spend-roughly-1-7-billion-annually-on-union-avoidance/" target="_blank" rel="noreferrer noopener">May 2026 report</a> by the Economic Policy Institute and LaborLab.</p>



<p class="wp-block-paragraph"><strong>Expect hardball tactics. </strong>Management may play hardball during the time between when organizers announce their intention to unionize and the actual vote. For example, management can threaten to fire foreign-born workers in the US on H-1B visas if they support the union. Those workers would then have just 60 days to find a new sponsoring employer or lose their H-1B status, according to a recent <a href="https://techworkerscoalition.org/blog/2025/03/14/immigrant-rights-are-labor-rights-tech-workers-and-h-1b-visas/" target="_blank" rel="noreferrer noopener">Tech Workers Coalition blog post</a>.</p>



<p class="wp-block-paragraph">And at venture capital-backed startups, investment agreements sometimes require management to attest there is no union activity — meaning a public organizing drive can trigger funding withdrawal. Or, if a unionized company is acquired, the new management can dissolve the union overnight by reclassifying unionized workers as new hires.</p>



<p class="wp-block-paragraph">With these sobering facts in mind, here is how organizers who have done it describe the process of creating a union.</p>



<h2 class="wp-block-heading">Step 1: Start a conversation with your co-workers</h2>



<p class="wp-block-paragraph">At the University of California, a two-tier system had evolved where some tech workers were unionized and some weren’t, Belasco says. Management created new titles that fell outside the union even though they had similar job descriptions and responsibilities to those in the union. Those nonunion employees received lower pay and benefits than their unionized peers, which created resentment and instability.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Max Belasco from the UCLA chapter of UPTE-CWA</p>
</figcaption></figure><p class="imageCredit">Zac Goldstein</p></div>



<p class="wp-block-paragraph">Belasco and other organizers wanted to eliminate that division by bringing everyone under the same contract. But when they began their unionization drive, “the biggest barrier we faced wasn’t management opposition — it was that people felt this was just the best-case scenario realistically available: ‘We have this job at the university, we have concerns about automation and layoffs, but what can we really do about it?'” he says.</p>



<p class="wp-block-paragraph">The antidote to that fatalism, organizers say, is simple: “Just start talking to your immediate co-workers. Are they experiencing the same challenges you are experiencing?” says McAvinney. “There’s no need to start talking about a union at this point.”</p>



<p class="wp-block-paragraph">Just get a consensus and start building a group of like-minded individuals, Thompson advises. “Always start with one-on-one conversations, and that’s what you should do the whole time. That’s the key to organizing,” he says.</p>



<p class="wp-block-paragraph">Tech workers often think they’re a special case, says Thompson, and therefore that unionization isn’t a good fit. “You’re not special. You are a company of workers, you are organizing, and there is a playbook for that. Trust the process, because it tends to work pretty well,” he says.</p>



<h2 class="wp-block-heading">Step 2: Who’s on board, and who’s not? Map your workplace, but keep it quiet</h2>



<p class="wp-block-paragraph">Once there’s a consensus, continue to grow your network. Keep a list of everyone you’ve spoken with and note their disposition: “Is this person union-friendly or anti-union? Would they be a strong organizer?” Thompson says.</p>



<p class="wp-block-paragraph">Maintaining secrecy early on is essential, because anti-union tactics will start immediately, and that can stop union organizing before it can gain momentum.</p>



<p class="wp-block-paragraph">“Generally, employers do not want to share power with their workforce,” McAvinney says. Employers will deploy every means at their disposal to stop organizing efforts and peel away potential yes votes.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="839" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Alan McAvinney from Alphabet Workers Union-CWA</p><br></figcaption></figure><p class="imageCredit">Aran Per Ink</p></div>



<p class="wp-block-paragraph">“If you look at historical examples, having 70% approval before the employer finds out about you results in a high percentage of wins when you actually cast the vote. Historically, that’s an effective buffer,” he says.</p>



<p class="wp-block-paragraph">There’s a real threat of firing and layoffs<em>.</em> The traditional tech worker belief that job mobility makes collective action unnecessary is now being tested by a tighter job market, McAvinney says, noting that workers who many believe <a href="https://www.newsweek.com/google-fires-thanksgiving-four-workers-crush-dissent-1474102" target="_blank" rel="noreferrer noopener">were fired for speaking out</a> back in 2019 were a galvanizing factor in his union’s formation.</p>



<p class="wp-block-paragraph">“You generally don’t want to be in a situation where the employer feels comfortable firing everyone. Part of that is thinking from a cynical standpoint about what the consequences would be to the employer if they did fire everyone,” he says.</p>



<p class="wp-block-paragraph">One-on-one conversations that include personally asking co-workers to keep conversations confidential are key to keeping things quiet, Belasco says. When <a href="https://upte.org/news/2100-tech-workers-vote-to-join-upte" target="_blank" rel="noreferrer noopener">2,100 UC tech workers voted to unionize</a> in May, 96% voted in favor. To stay out of earshot of managers, avoid employee surveillance tools, and sidestep conference calls that could be recorded, organizers met with workers in their homes.</p>



<p class="wp-block-paragraph">“That tactic is probably what made the difference between winning the election and getting the majority we got,” he says.</p>



<h2 class="wp-block-heading">Step 3: Find the right union affiliation or go it alone</h2>



<p class="wp-block-paragraph">“Running a campaign against major employers requires the resources and expertise of the larger labor movement, even if workers publicly present as independent,” says <a href="https://www.ilr.cornell.edu/people/kate-l-bronfenbrenner">Kate Bronfenbrenner</a>, director of labor education research and senior lecturer emeritus at Cornell University’s School of Industrial and Labor Relations.</p>



<p class="wp-block-paragraph">Options include the <a href="https://cwa-union.org/" target="_blank" rel="noreferrer noopener">Communications Workers of America</a> (CWA), <a href="https://www.seiu.org/" target="_blank" rel="noreferrer noopener">Service Employees International Union</a> (SEIU), and the <a href="https://www.opeiu.org/" target="_blank" rel="noreferrer noopener">Office and Professional Employees International Union</a> (OPEIU), among others. Another resource, the <a href="https://techworkerscoalition.org/">Tech Workers Coalition</a> (TWC), provides training on organizing tactics, AI-in-workplace issues, and contract negotiation, and can match workers to the right unions for their needs.</p>



<p class="wp-block-paragraph">The <a href="https://www.alphabetworkersunion.org/" target="_blank" rel="noreferrer noopener">Alphabet Workers Union</a> decided early on to affiliate with CWA. “They gave us a bunch of support early on in our campaign with no strings attached,” McAvinney says.</p>



<p class="wp-block-paragraph">Kickstarter is organized through OPEIU, Thompson says. “They’ll usually have resources and staff that can help you through the next steps: collecting signatures in support of a union, bringing that to management, holding a vote — the more formalized things that interact with US labor law. They’ll also help with organizing along the way,” he says.</p>



<p class="wp-block-paragraph">For workers at institutions where a union already exists, there may be a faster path. Organizers at UCLA did what’s called a “unit modification,” aligning with UPTE. By organizing under UPTE, the workers didn’t have to negotiate a new contract from scratch — they joined an already-negotiated contract covering existing UPTE tech members, which put them in “a much stronger position” than starting fresh, Belasco says.</p>



<h2 class="wp-block-heading">Step 4: Choose your union model: majority vs. pre-majority or minority</h2>



<p class="wp-block-paragraph">Assess what’s practical for your organizing effort. In a majority union, more than 50% of all workers in a defined bargaining unit must vote to join the union through an NLRB-supervised election in the private sector, or a Public Employment Relations Board (PERB)-supervised election for public sector workers.</p>



<p class="wp-block-paragraph">The NLRB must certify the union, which then operates under its legal protections. This means, for example, that the employer must bargain, negotiated contracts are enforceable, violations must go to the NLRB or arbitration, and workers can’t be dismissed without just cause.</p>



<p class="wp-block-paragraph">A pre-majority or minority union is a minority labor organization operating without NLRB protections or collective bargaining agreements. “Pre-majority means that workers are able to demonstrate majority support — through signed cards, petitions, a walkout, or everyone wearing solidarity T-shirts — without going through a formal election,” Bronfenbrenner says.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Kate Bronfenbrenner from the School of Industrial and Labor Relations, Cornell University</p><br></figcaption></figure><p class="imageCredit">ILR School/Cornell University</p></div>



<p class="wp-block-paragraph">The Alphabet Workers Union-CWA (AWU-CWA) formed as a pre-majority union because achieving majority status across a globally distributed workforce of over 100,000 was not a realistic near-term goal. “An underground model where you try to reach 70% support across a workforce of over 100,000 people isn’t realistic,” McAvinney says.</p>



<p class="wp-block-paragraph">A pre-majority union can still make a difference, he says. For example, the Alphabet Workers Union-CWA convinced management to offer voluntary exit packages — buyouts — prior to announcing layoffs.</p>



<p class="wp-block-paragraph">For smaller organizations, a majority union may be the more practical option — it’s more attainable, McAvinney says. “I don’t think [the pre-majority union model] is the correct thing to do in all situations. I certainly would not recommend it to a 200-person shop.”</p>



<p class="wp-block-paragraph">Kickstarter, which had fewer than 100 employees, was able to form a majority union, with 55% voting to organize.</p>



<p class="wp-block-paragraph">Ultimately, says McAvinney, “there’s no inflection point where you go from being able to win nothing to winning everything, even with a contract and a supermajority. But the more people you have who are willing and able to fight for what they want, the more you’ll be able to get.”</p>



<h2 class="wp-block-heading">Step 5: Who should — and should not — be in your union?</h2>



<p class="wp-block-paragraph">Belasco’s situation at UCLA illustrates a broader strategic choice that every organizing campaign must make. He had been in a union position in educational technology when he was told his role would be reclassified as a non-union position.</p>



<p class="wp-block-paragraph">“I was given a choice: apply to the new non-union position to continue doing the work I’d trained for, or stay in my union position doing service desk work I wasn’t used to,” he says. “Essentially, it was a choice between job security and career progression.”</p>



<p class="wp-block-paragraph">Belasco joined a “wall-to-wall” union, which represents a broad range of university professional and technical employees across the UC system rather than a single job category, such as engineers or tech professionals.</p>



<p class="wp-block-paragraph">Kickstarter United is another example of a wall-to-wall union. “It’s not just the engineers who are unionized, but also customer support, designers — everyone,” Thompson says.</p>



<p class="wp-block-paragraph">Wall-to-wall unions are more powerful, but they’re also more difficult to achieve. <a href="https://www.law.cornell.edu/uscode/text/29/159" target="_blank" rel="noreferrer noopener">Under US labor law</a>, “professionals have to vote separately on whether they want to be combined with other workers,” says Bronfenbrenner. “You can never have a wall-to-wall unit without giving professionals the chance to decide whether they want to be separate.”</p>



<p class="wp-block-paragraph">The law’s “professional employees” category includes roles like software engineers and developers but not necessarily others. For example, customer support specialists and QA analysts would fall into the “non-professional workers” category.</p>



<p class="wp-block-paragraph">“For decades, the pattern was either to organize everybody except the engineers, or manage to organize the engineers and fail to bring in everybody else — neither of which builds real worker power,” says <a href="https://www.linkedin.com/in/simonerobutti/" target="_blank" rel="noreferrer noopener">Simone Robutti</a>, an organizer with Tech Workers Coalition Global, an international branch of TWC based in Berlin.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="959" height="713" sizes="auto, (max-width: 959px) 100vw, 959px"&gt;<figcaption class="wp-element-caption"><p>Simone Robutti from Tech Workers Coalition Global</p><br></figcaption></figure><p class="imageCredit">TWC</p></div>



<h2 class="wp-block-heading">Step 6: You won the vote. Get ready for what comes next</h2>



<p class="wp-block-paragraph">Winning a union vote means having a seat at the table, says Thompson. “Once the workers have come together and agreed they want that seat, you bring that to management, and they have a chance to voluntarily recognize a union,” he says.</p>



<p class="wp-block-paragraph">But in most cases employers contest the results, which must be certified by the NLRB or PERB. That process, in which the employer uses various tactics to challenge the legitimacy of the outcome, can take weeks or months.</p>



<p class="wp-block-paragraph">Unfortunately, the legal framework that is supposed to protect workers during this process has been <a href="https://workerorganizing.org/elon-musk-spacex-nlrb-15975/#:~:text=CAN%20THE%20NLRB%20STILL%20ENFORCE%20LAWS%3F" target="_blank" rel="noreferrer noopener">significantly weakened</a> in the last few years. In a potentially more ominous development, <a href="https://apnews.com/article/amazon-nlrb-unconstitutional-spacex-elon-musk-ab42977117d883e97110a7bf8e8b257f" target="_blank" rel="noreferrer noopener">SpaceX</a>, <a href="https://apnews.com/article/amazon-nlrb-50ee06d87d4eaef22386382761335ef8" target="_blank" rel="noreferrer noopener">Amazon</a>, <a href="https://www.huffpost.com/entry/trader-joes-attorney-nlrb-unconstitutional_n_65b41e7ae4b014b873b11cc2" target="_blank" rel="noreferrer noopener">Trader Joe’s</a>, <a href="https://news.bloomberglaw.com/daily-labor-report/starbucks-is-latest-company-to-call-labor-board-unconstitutional" target="_blank" rel="noreferrer noopener">Starbucks</a>, and the <a href="https://capitalandmain.com/usc-follows-amazon-and-musks-spacex-in-calling-labor-board-unconstitutional" target="_blank" rel="noreferrer noopener">University of Southern California</a> have in separate legal actions <a href="https://www.epi.org/blog/whats-behind-the-corporate-effort-to-kneecap-the-national-labor-relations-board-spacex-amazon-trader-joes-and-starbucks-are-trying-to-have-the-nlrb-declared-unconstitutional/" target="_blank" rel="noreferrer noopener">challenged the constitutionality of the NLRB</a>, arguing that the agency’s structure violates the separation of powers. The Fifth Circuit Court of Appeals <a href="https://law.justia.com/cases/federal/appellate-courts/ca5/24-50627/24-50627-2025-08-19.html?__cf_chl_f_tk=do9nl63o6rfY2sxOjPeR5MkVGY4u1OTRYOVYjTQTOG0-1782836265-1.0.1.1-IXqkGFSiOH5hYYOqqrEqH6VFIApNL3MRHW6YNiDwERI" target="_blank" rel="noreferrer noopener">upheld injunctions against the NLRB</a> in SpaceX’s case in August 2025 — a serious challenge to the agency’s authority.</p>



<p class="wp-block-paragraph">In the meantime, some companies may disregard negotiated contracts, which can lead to lengthy legal appeals or extended arbitration.</p>



<p class="wp-block-paragraph">“The NLRB can still force an election, but it can’t force a contract, and companies are saying they simply won’t comply,” Bronfenbrenner says. This is where the expertise and resources of affiliation with a major union can help, she adds.</p>



<p class="wp-block-paragraph">As a result, contract negotiations can take far longer than workers might expect. At Kickstarter, for example, two years and four months elapsed from the time of the union vote to the first contract, and that was at a 59-person company with a relatively cooperative employer. At larger companies with more aggressive legal teams, the timeline will be longer.</p>



<p class="wp-block-paragraph">Forming a union is hard work, Robutti says. “It’s not a service you pay for and they protect you. It doesn’t happen spontaneously, and it doesn’t happen magically. It’s the choice to take responsibility for improving your workplace.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 ways for CIOs to avoid AI bill shock]]></title>
<description><![CDATA[Gen AI spending is moving beyond the familiar software model of seats, licenses, and pilots. As AI shifts from copilots to embedded workflows and autonomous agents, one user request can trigger multiple model calls, retrieval steps, retries, orchestration layers, and infrastructure events. A tool...]]></description>
<link>https://tsecurity.de/de/3670246/it-security-nachrichten/5-ways-for-cios-to-avoid-ai-bill-shock/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670246/it-security-nachrichten/5-ways-for-cios-to-avoid-ai-bill-shock/</guid>
<pubDate>Wed, 15 Jul 2026 12:08:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Gen AI spending is moving beyond the familiar software model of seats, licenses, and pilots. As AI shifts from copilots to embedded workflows and autonomous agents, one user request can trigger multiple model calls, retrieval steps, retries, orchestration layers, and infrastructure events. A tool that looks affordable in pilot may behave very differently once connected to production systems or allowed to act with less human supervision.</p>



<p class="wp-block-paragraph">According to Michael Corrigan, CIO of World Insurance Associates, AI introduces a fundamentally different cost model — one that’s usage driven, non-linear, and tightly coupled to business activity. “Success requires shifting from traditional IT budgeting to FinOps-style discipline where consumption, value, and governance are actively managed in real time,” he says.</p>



<p class="wp-block-paragraph">Here are five ways CIOs can build that discipline before AI costs spiral.</p>



<h2 class="wp-block-heading">Forecast AI by workflow, not by user</h2>



<p class="wp-block-paragraph">At World, a top 25 insurance broker with about 3,000 employees across roughly 300 locations, AI use falls into three broad categories, Corrigan says. One is broad tools, such as copilots. Another is embedded AI inside SaaS platforms. And the third is bespoke AI built around specific workflows and manual processes.</p>



<p class="wp-block-paragraph">“The bespoke is the area that’s growing the most right now,” he says. “And that’s where the model, from a cost perspective, has really been shifting from a license seat cost to a token consumption or token burn cost, or even a hybrid.”</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Michael Corrigan, CIO, World Insurance Associates</p>
</figcaption></figure><p class="imageCredit">WIA</p></div>



<p class="wp-block-paragraph">Seat-based pricing is relatively easy to forecast whereas consumption-based AI isn’t. Costs may depend on prompt complexity, output length, model choice, workflow design, and whether the system calls a model once or many times in the background.</p>



<p class="wp-block-paragraph">World tries to manage that uncertainty by defining the business problem, success criteria, and expected operational improvement upfront. Pilots help estimate consumption before scaling, but Corrigan says they don’t remove the ambiguity.</p>



<p class="wp-block-paragraph">“We’ll try our best in the pilot to understand what the consumption rate is, what the token burn rate is,” he says. But once a consumption-based workflow goes into production, he adds, an estimate is put into place. That estimate is informed, but still rough.</p>



<p class="wp-block-paragraph">Elmer Morales, founder and CEO of koder.com, an agentic AI coding startup, says CIOs should think less about headcount and more about <a href="https://www.cio.com/article/4163373/cios-bring-ai-transformation-home-to-it-workflows.html?utm=hybrid_search">workflow mechanics</a>. Agentic AI costs are driven by the number of decisions an agent makes, how often it retrieves external data, how much context it carries, and how many systems it touches.</p>



<p class="wp-block-paragraph">“CIOs should start by mapping workflows, not necessarily users,” he says. “The relevant variable isn’t going to be the headcount but how many decisions an agent makes per task.”</p>



<h2 class="wp-block-heading">Model the failure path, not just the happy path</h2>



<p class="wp-block-paragraph">Pilots can mislead because they often test the cleanest version of an AI workflow. Morales says many enterprises model agentic AI costs around the happy path: the user gives a clear prompt, the system understands the request, the agent completes the task, and the process ends. Production is messier.</p>



<p class="wp-block-paragraph">“They generally don’t model for situations where the agent is going to need to go back and check its work and redo things,” Morales says. “A lot of times, agents are wrong, either because they hallucinate or they understood the problem incorrectly.”</p>



<p class="wp-block-paragraph">In an agentic workflow, the system may check its work, call another tool, retrieve more data, or redo a step. While that may improve quality, it also adds cost.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Elmer Morales, founder and CEO, koder.com</p>
</figcaption></figure><p class="imageCredit">koder.com</p></div>



<p class="wp-block-paragraph">The difference between copilots and <a href="https://www.cio.com/article/3603856/agentic-ai-promising-use-cases-for-business.html?utm=hybrid_search">agents</a> is central. A copilot interaction is often one prompt and one response. An agentic workflow may involve agents moving through a decision tree, executing tasks in sequence or in parallel, and calling sub-agents or external systems along the way. “By the time it’s achieved the original goal, the agent might have made 50 or 100 model calls, compared with a single call for a traditional copilot prompt,” Morales says.</p>



<p class="wp-block-paragraph">That’s why CIOs should require teams to model the failure path before production, like how many retries are allowed, how much context is resent, which tools can be called, when a human should intervene, and what happens when the agent can’t complete the task.</p>



<h2 class="wp-block-heading">Build cost controls into the architecture</h2>



<p class="wp-block-paragraph">Traditional FinOps practices still matter, but AI requires more than retrospective dashboards and chargebacks.</p>



<p class="wp-block-paragraph">According to Pavan Madduri, senior cloud platform engineer at industrial supply company Graigner, looking backward at usage data, as traditional FinOps often does, can be too late. Costs are shaped by prompt design, model selection, agent behavior, orchestration choices, and runtime loops.</p>



<p class="wp-block-paragraph">“Dashboards or chargebacks, those are historical accounting,” he says. “The money’s already gone.” For AI, he argues, cost controls need to be embedded into the architecture. That includes hard token caps, retry-depth limits, maximum runtime limits, workload prioritization, background-job throttling, and cluster-level controls that prevent runaway consumption.</p>



<p class="wp-block-paragraph">“The real FinOps means you need to have the cost constraints embedded into your architecture framework,” Madduri says.</p>



<p class="wp-block-paragraph">Those controls also extend to infrastructure. Expensive GPUs may sit warm between jobs because systems need capacity available when inference demand arrives. Teams may pass huge schemas, databases, or thousands of lines of code into frontier models when a smaller or more focused prompt would do.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="828" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Pavan Madduri, senior cloud platform engineer, Graigner</p>
</figcaption></figure><p class="imageCredit">Graigner</p></div>



<p class="wp-block-paragraph">Enterprises should also adopt event-driven autoscaling, Madduri says. “Use tools like KEDA to scale GPU nodes down to zero the moment inference demand drops, so teams only pay for the windows when the silicon is actively crunching tokens.”</p>



<p class="wp-block-paragraph">Corrigan says World uses rate limits, spend limits, alerts, and approval gateways for consumption-based tools. When users approach token consumption limits, automated alerts allow IT and the business to review whether the continued spend is justified.</p>



<p class="wp-block-paragraph">“If it’s not meeting the success criteria we expected, you have to have the control in place to say we’re going to move on or kill that process,” Corrigan says.</p>



<h2 class="wp-block-heading">Route work to the right model</h2>



<p class="wp-block-paragraph">CIOs can also reduce <a href="https://www.cio.com/article/4152601/without-controls-an-ai-agent-can-cost-more-than-an-employee.html?utm=hybrid_search">AI bill shock</a> by avoiding a default assumption that every task requires the most powerful model available. While some tasks need advanced reasoning, many others don’t. A simple support ticket, log-parsing task, or structured database transaction may be handled by a smaller or cheaper model. A complex architecture decision, legal analysis, or multi-step reasoning task may justify a more powerful one.</p>



<p class="wp-block-paragraph">“Choosing the right model for the right prompt and right question — that’s where you leverage the maximum from that model, and you can decrease the costing,” Madduri says. “If you default every single call to a frontier model, that’s architectural laziness.”</p>



<p class="wp-block-paragraph">Morales makes a similar point. Not every step in an agentic workflow requires a top-of-the-line model. Model routing, he says, is the discipline of determining the best model for the task, and providing the relevant context when the model needs it.</p>



<p class="wp-block-paragraph">According to Jim Olsen, CTO of enterprise software company ModelOp, CIOs should use the least expensive model that can accomplish the business goal. Using the biggest model for everything is easier, but expensive. “It’s like hiring the most expensive engineer to change a few colors in a website’s CSS, or visual styling,” he says. “You wouldn’t do that. You use the appropriate tools for the task.”</p>



<h2 class="wp-block-heading">Tie consumption to business value</h2>



<p class="wp-block-paragraph">For Olsen, the deeper enterprise problem is AI value shock, not just bill shock. Spending $200,000 in a quarter on AI is justified if it produces $2 million in business value. The problem is spending heavily on use cases that don’t generate a meaningful return.</p>



<p class="wp-block-paragraph">“Are you actually getting that return on investment, or are you just blowing tokens for something that’s not delivering the value to your business?” Olsen asks. Tracking token usage by user or department may show who consumed AI, but not whether the consumption mattered.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> width="1240" height="827" sizes="auto, (max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Jim Olsen, CTO, ModelOp</p>
</figcaption></figure><p class="imageCredit">ModelOp</p></div>



<p class="wp-block-paragraph">For most enterprise AI systems, Olsen says costs should be tied back to business use cases. A model may be used for HR document search, customer support, code review, problem resolution, or other functions. Each use case may draw on the same underlying models or agents, but the business value can be very different.</p>



<p class="wp-block-paragraph">That’s why he argues that companies need an AI inventory, a record of which business workflows use which models, agents, providers, workflows, and systems. Without that inventory, enterprises can’t connect consumption to value.</p>



<p class="wp-block-paragraph">Corrigan takes a similar approach from a governance perspective. At World, new AI ideas go through an intake process. Business users propose improvements, and IT, finance, operations, sales, and business stakeholders evaluate, prioritize, and monitor them from pilot through production.</p>



<p class="wp-block-paragraph">That may be where the next stage of AI FinOps is heading, toward a clearer understanding of which AI consumption deserves to scale, not just to lower bills. So the question, as Olsen puts it, isn’t whether someone used a million tokens. It’s what are they using them for.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/dfa246e6fd16-20260715]]></title>
<description><![CDATA[Release publish tooling for OpenClaw 2026.7.2-beta.1 retry]]></description>
<link>https://tsecurity.de/de/3670194/downloads/release-publishdfa246e6fd16-20260715/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670194/downloads/release-publishdfa246e6fd16-20260715/</guid>
<pubDate>Wed, 15 Jul 2026 11:47:21 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Release publish tooling for OpenClaw 2026.7.2-beta.1 retry</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Context is becoming AI’s most misunderstood word]]></title>
<description><![CDATA[If you spend enough time in Silicon Valley AI circles, you’ll hear the same message over and over again: AI needs context.



The statement is broadly true. The problem is that “context” has become one of the least precise terms in the industry.



Depending on who is using it, context can mean d...]]></description>
<link>https://tsecurity.de/de/3670110/it-security-nachrichten/context-is-becoming-ais-most-misunderstood-word/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670110/it-security-nachrichten/context-is-becoming-ais-most-misunderstood-word/</guid>
<pubDate>Wed, 15 Jul 2026 11:08:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">If you spend enough time in Silicon Valley AI circles, you’ll hear the same message over and over again: AI needs context.</p>



<p class="wp-block-paragraph">The statement is broadly true. The problem is that “context” has become one of the least precise terms in the industry.</p>



<p class="wp-block-paragraph">Depending on who is using it, context can mean documents, dashboards, reports, metadata, business rules, policies, transaction histories, CRM records, knowledge bases or institutional expertise. The word has become a catch-all for virtually any information that might be made available to a model.</p>



<p class="wp-block-paragraph">As a result, many organizations have started treating context as a volume problem. Conversations quickly turn to larger context windows, additional data sources and broader system access, while far less attention goes toward determining whether that information actually improves the quality of the outcome.</p>



<p class="wp-block-paragraph">What we’re seeing in practice suggests a different way of thinking about the problem. The organizations making the most progress with enterprise AI are not necessarily the ones exposing the largest amount of information to their systems. They are the ones spending the most time understanding which information should influence a decision, which information should not and how to ensure that business logic is applied consistently.</p>



<p class="wp-block-paragraph">That distinction matters because the industry is beginning to repeat a mistake enterprises already made once before.</p>



<h2 class="wp-block-heading"><a></a>Context has become the new ‘big data’</h2>



<p class="wp-block-paragraph">For much of the last two decades, organizations operated under the assumption that collecting more data would naturally produce better decisions. Massive investments were made in data warehouses, reporting platforms, analytics systems and business intelligence tools. Those investments created tremendous value, but they also exposed an important reality: Collecting information and creating clarity are not the same thing.</p>



<p class="wp-block-paragraph">Today, AI is heading down a similar path.</p>



<p class="wp-block-paragraph">Many enterprise AI projects measure progress by counting how much information a model can access. More documents become better than fewer documents. More systems become better than fewer systems. Larger context windows become better than smaller ones. The conversation often assumes that quantity and quality move together.</p>



<p class="wp-block-paragraph">Well, they don’t.</p>



<p class="wp-block-paragraph">According to<a href="https://www.salesforce.com/resources/research-reports/state-of-data-and-analytics/?utm_source=chatgpt.com"> </a><a href="https://www.salesforce.com/resources/research-reports/state-of-data-and-analytics/?utm_source=chatgpt.com">Salesforce research</a>, only 35% of business leaders say they are completely satisfied with their organization’s ability to use data effectively despite years of investment in data infrastructure and analytics. Enterprises learned long ago that information alone does not create understanding. The same lesson applies to AI.</p>



<p class="wp-block-paragraph">When a model gains access to five versions of the same metric, conflicting definitions of a business process or documentation that has not been updated in years, it does not magically resolve those inconsistencies. It consumes them. More context can just as easily increase ambiguity as reduce it.</p>



<p class="wp-block-paragraph">Simply exposing more information to a model does not guarantee better outcomes. What matters is whether the information available to the system helps it make the right decision at the right time.</p>



<h2 class="wp-block-heading"><a></a>Most AI failures are actually context failures</h2>



<p class="wp-block-paragraph">One of the more interesting things we’ve observed over the past year is how many AI projects are blamed for problems that have very little to do with AI.</p>



<p class="wp-block-paragraph">The model answers a question incorrectly, and the immediate assumption is that the model failed. In reality, the underlying issue often sits elsewhere. The organization may have multiple definitions of the metric being requested. Customer information may exist across several systems with conflicting values. Business rules may be documented in one location, partially implemented in another and understood differently by different teams.</p>



<p class="wp-block-paragraph">In many deployments, the issue is not that the AI lacks information. The issue is that it has access to several competing versions of the truth.</p>



<p class="wp-block-paragraph">Anyone who has worked inside a large enterprise will recognize the pattern. Revenue means one thing to finance and something slightly different to sales. Product usage metrics evolve over time. Operational processes change while documentation remains frozen. Human employees learn how to navigate these inconsistencies through experience and institutional knowledge. AI systems inherit them immediately.</p>



<p class="wp-block-paragraph">This is why the conversation around context often misses the point. The challenge is not simply providing more information. The challenge is determining which information should be trusted, how conflicts should be resolved and what business logic should govern the final answer.</p>



<p class="wp-block-paragraph">A single trusted source can be more valuable than a hundred loosely connected ones. A clearly defined rule can be more useful than thousands of pages of documentation. The quality of the context matters far more than the volume.</p>



<h2 class="wp-block-heading"><a></a>Access does not create trust</h2>



<p class="wp-block-paragraph">Many organizations can tell you exactly how their AI systems retrieve information. They can explain retrieval pipelines, vector databases, ranking systems, semantic search architectures and context windows in extraordinary detail.</p>



<p class="wp-block-paragraph">Far fewer can explain how they determine whether the answers produced are consistently correct.</p>



<p class="wp-block-paragraph">That gap becomes especially important in enterprise environments where the cost of an incorrect answer can be substantial. A sales leader making a forecast, a finance team evaluating performance or an operations executive making a resource allocation decision does not care how many documents were retrieved. They care whether the answer is right.</p>



<p class="wp-block-paragraph">Trust has always been one of the hardest problems in enterprise data. According to<a href="https://www.accenture.com/us-en/insights/artificial-intelligence/data-trust-ai-value?utm_source=chatgpt.com"> </a><a href="https://www.accenture.com/us-en/insights/artificial-intelligence/data-trust-ai-value?utm_source=chatgpt.com">Accenture research on data trust and decision making</a>, only about a quarter of employees report high confidence in their organization’s data when making decisions. That challenge does not disappear when AI enters the picture. If anything, it becomes more visible.</p>



<p class="wp-block-paragraph">Organizations frequently measure access because access is easy to quantify. Reliability is harder. Reliability requires understanding whether an answer remains consistent across users, across prompts, across time periods and across changing business conditions. It requires understanding whether the same question produces the same answer and whether that answer reflects the business logic the organization intends to enforce.</p>



<p class="wp-block-paragraph">Those are fundamentally different measurements, and they point to a different definition of success.</p>



<h2 class="wp-block-heading"><a></a>Context requires measurement</h2>



<p class="wp-block-paragraph">One reason this problem is becoming more pronounced is that enterprises accumulate information far faster than they eliminate it.</p>



<p class="wp-block-paragraph">New systems are added, new reports are created, processes evolve. Teams develop local definitions and specialized workflows. Documentation grows continuously, while very little of it gets removed. Over time, organizations build large collections of information that contain years of historical decisions, exceptions, workarounds and competing interpretations.</p>



<p class="wp-block-paragraph">We’ve yet to encounter an enterprise that doesn’t have some version of this problem.</p>



<p class="wp-block-paragraph">That reality turns context into an operational challenge rather than a technical one.</p>



<p class="wp-block-paragraph">Simply connecting AI systems to enterprise information does not improve the quality of that information. In some cases, it exposes longstanding inconsistencies that were previously hidden by human interpretation and tribal knowledge. Gartner has long identified poor data quality as one of the most significant obstacles to successful analytics and AI initiatives because bad inputs inevitably produce unreliable outputs, regardless of how sophisticated the technology becomes.</p>



<p class="wp-block-paragraph">As AI becomes more deeply integrated into business operations, organizations will need new ways to evaluate the context their systems rely on. They will need visibility into how information is being used, where definitions conflict, which sources are trusted and how context quality affects outcomes. Context cannot be treated as a static asset. It must be measured, monitored and improved over time, just as organizations measure the quality of the models and applications built on top of it.</p>



<h2 class="wp-block-heading"><a></a>The shift from access to reliability</h2>



<p class="wp-block-paragraph">The industry has spent the last several years focused on access. How do we connect models to enterprise systems? How do we expose organizational knowledge? How do we give AI visibility into the information people use every day?</p>



<p class="wp-block-paragraph">Those questions were important because they represented genuine technical barriers. Today, many of those barriers are disappearing.</p>



<p class="wp-block-paragraph">Most enterprises can already connect AI systems to data warehouses, applications, dashboards, documents and knowledge repositories. The conversation is beginning to shift toward a more difficult problem: Determining whether those connections actually produce outcomes people trust.</p>



<p class="wp-block-paragraph">That is where the next phase of enterprise AI will be decided.</p>



<p class="wp-block-paragraph">Organizations that treat context as a quantity problem will continue adding more information and hoping accuracy improves. Organizations that treat context as a quality problem will focus on trust, consistency, governance and outcome reliability.</p>



<p class="wp-block-paragraph">The difference between those approaches may sound subtle, but it has enormous implications. One produces systems that can access information. The other produces systems that people are willing to use to make decisions.</p>



<p class="wp-block-paragraph">And in the enterprise, that distinction is ultimately what matters.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a><strong></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[release-publish/bb1a7e506927-20260715]]></title>
<description><![CDATA[OpenClaw v2026.7.2-beta.1 publish tooling]]></description>
<link>https://tsecurity.de/de/3670089/downloads/release-publishbb1a7e506927-20260715/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670089/downloads/release-publishbb1a7e506927-20260715/</guid>
<pubDate>Wed, 15 Jul 2026 11:02:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw v2026.7.2-beta.1 publish tooling</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 skills and traits of elite security engineers]]></title>
<description><![CDATA[Security engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats.



Finding not just...]]></description>
<link>https://tsecurity.de/de/3669835/it-security-nachrichten/7-skills-and-traits-of-elite-security-engineers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669835/it-security-nachrichten/7-skills-and-traits-of-elite-security-engineers/</guid>
<pubDate>Wed, 15 Jul 2026 09:08:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Security engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats.</p>



<p class="wp-block-paragraph">Finding not just qualified security engineers, but the best and brightest available, needs to be a priority for CISOs and others overseeing security at their organizations. That’s especially true with the rapid rise of AI and the threats that brings to the enterprise.</p>



<p class="wp-block-paragraph">Here are some of the key skills and traits of elite security engineers to look for when hiring — or to acquire in order to uplevel your cybersecurity career.</p>



<h2 class="wp-block-heading">Acumen with AI-powered tools</h2>



<p class="wp-block-paragraph">These days, AI-related skills are in demand regardless of domain, and this certainly applies to security engineers. There’s a wealth of solutions leveraging AI in the market, tools that engineers can add to their defense arsenal.</p>



<p class="wp-block-paragraph">“AI is transforming security engineering from reactive alerting to predictive threat detection,” says Praveen Margabandhu, digital engineering anchor at financial services firm Navy Federal Credit Union. “AI-driven anomaly detection now identifies behavioral patterns that indicate fraud or compromise before traditional threshold-based systems would fire. This shifts the security engineer’s role from incident responder to threat model designer.”</p>



<p class="wp-block-paragraph">AI-powered tools have taken over a large portion of the detection and triage work that used to be the core of a security engineer’s day, says Maruf Ahmed, cofounder and CEO of global tech staffing firm Dexian. “Vulnerability scanning runs on its own now,” he says. “Threat flagging that used to require a team pulling through logs for hours happens in minutes.”</p>



<p class="wp-block-paragraph">This has freed up capacity on most security teams and changed what the day-to-day work looks like, Ahmed says. “With detection increasingly automated, the engineer’s value sits more in interpreting what gets flagged and deciding what to do about it,” he says.</p>



<h2 class="wp-block-heading">Keen understanding of emerging and established AI threats</h2>



<p class="wp-block-paragraph">Engineers must also have a thorough understanding of the risks AI presents, including <strong><a href="https://www.csoonline.com/article/4154222/6-ways-attackers-abuse-ai-services-to-hack-your-business.html">AI-enhanced cyberattacks</a> using</strong><strong> </strong>large language models (LLMs) to automate and scale <a href="https://www.csoonline.com/article/3819176/top-5-ways-attackers-use-generative-ai-to-exploit-your-systems.html">highly personalized social engineering attacks</a>, craft sophisticated malware, and generate deepfakes.</p>



<p class="wp-block-paragraph">Other <a href="https://www.csoonline.com/article/4110008/top-cyber-threats-to-your-ai-systems-and-infrastructure.html">AI threats they need to be aware of</a> include prompt injections, data and model poisoning, disclosure of sensitive information, model theft, supply chain compromises, and excessive agency.</p>



<p class="wp-block-paragraph">“The same generative tools that help security teams work faster are available to adversaries, and it shows,” Ahmed says. “Phishing campaigns read better and land more precisely than they did a year ago. Social engineering is harder to catch when the language is polished and tailored to the target, and security engineers are now defending against threats built with the same class of technology they use on the defensive side.”</p>



<p class="wp-block-paragraph">That has raised the bar for what reliable detection looks like, Ahmed says. “The objective shift I hear most from clients is about trust in their own systems,” he says. “Two years ago, the priority was visibility — making sure you could see across your environment. Most organizations have that now. The harder problem is knowing whether what those tools are telling you holds up under scrutiny and having people on the team who can stand behind those findings in front of a regulator or a board.”</p>



<h2 class="wp-block-heading">Appreciation of performance and business goals</h2>



<p class="wp-block-paragraph">The best security engineers understand how performance and security intersect, says Margabandhu, who leads performance engineering across Navy Federal Credit Union’s digital banking infrastructure, including real-time fraud detection, identity and access management, and cybersecurity infrastructure resilience.</p>



<p class="wp-block-paragraph">“A fraud detection system that is secure but too slow to catch transactions in real-time is not secure at all,” Margabandhu says. “Elite engineers optimize for both simultaneously.”</p>



<p class="wp-block-paragraph">Engineers must be able to put things in business context, Ahmed says. “An engineer who can work across domains, validate AI outputs, and learn new tools fast is valuable. But that value compounds when the person also understands what the organization is trying to protect and why,” he says.</p>



<p class="wp-block-paragraph">Security engineers who understand the business make better risk decisions, write more effective policies, and generate less friction with the teams around them, Ahmed says. “That is the profile employers are hiring toward right now, and it is where the talent shortage is most pronounced,” he says.</p>



<h2 class="wp-block-heading">Systems mindset</h2>



<p class="wp-block-paragraph">“One of the biggest misconceptions in cybersecurity hiring is that elite security engineers are defined purely by technical certifications or tool familiarity,” says Juan Mathews Rebello Santos, an independent cybersecurity researcher and ethical hacker.</p>



<p class="wp-block-paragraph">“Technical skill absolutely matters, but the strongest engineers I’ve worked with consistently share a combination of analytical thinking, operational adaptability, communication ability, and deep systems understanding,” Santos says.</p>



<p class="wp-block-paragraph">Elite security engineers understand how infrastructure, cloud services, identity systems, applications, APIs, networks, users, and business operations connect, Santos says.</p>



<p class="wp-block-paragraph">“Modern attacks rarely target a single isolated component anymore,” he says. “Threat actors chain together weaknesses across environments. Engineers who can understand those relationships holistically are significantly more effective at both prevention and incident response.”</p>



<h2 class="wp-block-heading">Cross-disciplinary fluency and broad stack know-how</h2>



<p class="wp-block-paragraph">Being an elite software engineer today means having a range of technology experience and knowledge. “Organizations want engineers who can work across more of the stack than they used to,” Ahmed says. “A role that might have asked for deep specialization in one area now expects someone who can move between cloud infrastructure, application security, and compliance without needing a handoff at every boundary.”</p>



<p class="wp-block-paragraph">The attack surface has continued to get wider, and the job descriptions for security engineers has followed suit. “That cross-domain fluency matters because security incidents rarely stay contained in one layer,” Ahmed says. “The engineer who can follow a problem from the network through the application to the data governance framework resolves it faster, with fewer people involved.”</p>



<p class="wp-block-paragraph">The strongest security engineers bridge infrastructure, application, and business domains, Margabandhu says. “They can speak to a CISO, a developer, and a cloud architect in the same conversation,” he says. “An engineer who can explain what an authentication problem means for fraud exposure moves faster in a room full of executives than one who can only describe it in infrastructure terms. I’ve watched technically brilliant people lose that race repeatedly.”<br><br></p>



<p class="wp-block-paragraph">Having the ability to communicate technical risk clearly to non-technical leadership can mean the difference between success and failure of attacks.</p>



<p class="wp-block-paragraph">“Many security failures today are not caused by lack of tooling, but by misalignment between technical teams and business decision-makers,” Santos says. “Elite engineers can explain operational risk, prioritization, and security tradeoffs in language executives understand.”</p>



<h2 class="wp-block-heading">Deep understanding of third-party risk and non-human threats</h2>



<p class="wp-block-paragraph">Threats can come from anywhere, including supply chains and non-human combatants. Third-party cybersecurity risks are on the rise. The 2026 Global CISO Leadership Report by executive search firm Hitch Partners, based on a survey of more than 625 information security executives across the US and Canada, says 43% put third-party risks as the No. 1 priority.</p>



<p class="wp-block-paragraph">“Most teams are still better at securing what they own than securing what they depend on,” Margabandhu says. “The mental shift from perimeter thinking to dependency thinking is real and not everyone has made it. The engineers who treat <a href="https://www.csoonline.com/article/4148315/apis-are-the-new-perimeter-heres-how-cisos-are-securing-them.html">every API call</a>, every credentialed vendor, every third-party model as part of their attack surface approach design differently.”</p>



<p class="wp-block-paragraph">Another growing source of potential threats are not human. <a href="https://www.csoonline.com/article/2132294/what-are-non-human-identities-and-why-do-they-matter.html">Machine identities</a> now outnumber human identities by ratios exceeding 100 to 1 in most enterprise environments, with some sectors closer to 500 to 1, according to the ManageEngine Identity Security Outlook 2026 report.</p>



<p class="wp-block-paragraph">This includes service accounts, API keys, automation tokens, and AI agents, any one of which can present data governance and security risks.</p>



<p class="wp-block-paragraph">Many organizations are still managing machine identities through manual processes that weren’t designed for scale, Margabandhu says. “Engineers who understand non-human identity governance are rare and increasingly important. This is not a future problem.”<br><br></p>



<h2 class="wp-block-heading">Willingness to keep learning</h2>



<p class="wp-block-paragraph">Security engineers need to have a desire to never stopped learning.</p>



<p class="wp-block-paragraph">“That sounds obvious until you work with people who’ve been doing this for 15 years and are still operating from the same threat models they built in 2012,” Margabandhu says. “Security changes fast enough that standing still is the same as going backwards.”</p>



<p class="wp-block-paragraph">The security engineers who keep up aren’t reading one report a year. “They’re genuinely curious about what attackers are doing right now, this month, and they adjust how they think accordingly,” Margabandhu says. “That quality is harder to hire for than most technical skills, because it’s not on a resume.”<br><br></p>



<p class="wp-block-paragraph">With AI presenting new and more sophisticated threats, keeping up with the latest developments is perhaps more important than ever. “Strong engineers are naturally investigative,” Santos says. “They actively study attack techniques, test assumptions, reverse engineer failures, and continuously adapt their understanding of risk.”</p>



<p class="wp-block-paragraph">The best security engineers are often the people who remain intellectually uncomfortable because they know the landscape is always evolving, Santos says.</p>



<p class="wp-block-paragraph">Employers have started paying closer attention to how fast someone can learn, Ahmed says. “The threat landscape and the defensive toolkit are both moving faster than any certification program can track, so hiring managers are probing for adaptability in interviews: how candidates have responded to recent shifts, whether they have picked up unfamiliar platforms on their own, how they work through problems they have not seen before,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.210]]></title>
<description><![CDATA[What's changed

Added a live elapsed-time counter to the collapsed tool summary line so long-running tool calls visibly tick instead of looking stuck
Added a startup warning for Write(path), NotebookEdit(path), and Glob(path) permission rules — use Edit(path) or Read(path) instead
Fixed isolation...]]></description>
<link>https://tsecurity.de/de/3669298/downloads/v21210/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669298/downloads/v21210/</guid>
<pubDate>Wed, 15 Jul 2026 01:46:28 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added a live elapsed-time counter to the collapsed tool summary line so long-running tool calls visibly tick instead of looking stuck</li>
<li>Added a startup warning for <code>Write(path)</code>, <code>NotebookEdit(path)</code>, and <code>Glob(path)</code> permission rules — use <code>Edit(path)</code> or <code>Read(path)</code> instead</li>
<li>Fixed <code>isolation: 'worktree'</code> subagents being able to run git-mutating commands against the main repo checkout instead of their own isolated worktree</li>
<li>Fixed the <code>ultracode</code> keyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR comments</li>
<li>Fixed a rendered text fragment leaking into crash telemetry when a UI component returned content outside a styled text element</li>
<li>Fixed paste markers leaking into external editors opened from Claude Code, which could appear as stray È/É characters around pasted text</li>
<li>Fixed <code>claude attach</code> sometimes failing with "job not found" or "agent is still starting" errors during session transitions — attach now waits for the daemon to settle, and terminal resizes during a slow attach are applied once it completes</li>
<li>Fixed a session crash when a tool's result renderer returned a numeric bigint value or plain text instead of a UI element</li>
<li>Fixed a hook callback timeout being misreported to the model as a user rejection, which made unattended sessions stop and wait</li>
<li>Fixed Claude assuming a <code>cd</code> took effect after its command was moved to the background; the tool result now states the working directory is unchanged</li>
<li>Fixed plugin-provided MCP servers being torn down when MCP servers are re-synced mid-session</li>
<li>Fixed plan approvals without edits being labeled "(edited by user)" and overwriting the plan file with a stale snapshot</li>
<li>Fixed <code>/doctor</code> skipping its auto-mode-default proposal on Bedrock, Vertex, and Foundry, where auto mode no longer needs an opt-in</li>
<li>Fixed Grep content mode claiming "No matches found" when paginating past the end of results</li>
<li>Fixed unmatched <code>$1</code>/<code>$2</code> positional placeholders in skills and commands being silently stripped; they are now preserved verbatim</li>
<li>Fixed plugin cache writes leaving temp files behind on failure and failing on locked-file renames on Windows and network filesystems</li>
<li>Fixed background workers crash-looping when a client resets its connection to the background service</li>
<li>Fixed <code>claude agents --effort ultracode</code> not reaching dispatched sessions; the value was silently dropped</li>
<li>Fixed pressing ← to open the agents view dropping the task tracker when returning to the session</li>
<li>Fixed the agents dashboard retaining pasted images from abandoned reply drafts after their session was deleted</li>
<li>Fixed killed background sessions leaving a permanent <code>git worktree lock</code> behind; the periodic sweep now releases locks whose owning process is gone</li>
<li>Fixed SDK MCP servers registered via an <code>initialize</code> control request waiting until the next turn to start connecting</li>
<li>Fixed returning to the agents view from a session leaving overlapping ghost frames with <code>CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1</code></li>
<li>Fixed late-appearing <code>.claude/*</code> symlinks not being reconciled into the sandbox deny-write list</li>
<li>Hardened the Agent tool against indirect prompt injection via content a subagent read</li>
<li>Improved the Bash/PowerShell tool message when a command hits its timeout and is auto-backgrounded, so the model can distinguish a hang from an explicit background request</li>
<li>Improved auto mode: the permission classifier now defaults to Sonnet 5 for external sessions, validated on the session's first request and pinned for the session</li>
<li>Improved the bundled dataviz skill's chart color validation with perceptual OKLab color difference and recalibrated color-blindness thresholds</li>
<li>Memory writes that leave a MEMORY.md index over its read limit now produce an explicit error instead of silent truncation</li>
<li>Screen reader mode now announces permission mode changes aloud when cycling modes with Shift+Tab</li>
<li>The agents footer hint now shows how many background agents are waiting on your input, with a brief color emphasis when the count changes</li>
<li>Agent view: the session you pressed ← from stays visibly marked even after mouse hover or arrow keys move the selection</li>
<li>Fable temporarily shows as unavailable in the advisor picker while a server-side issue causing Fable advisor failures is fixed</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI's First Device Will Be Moveable, Screenless Speaker Built as AI Companion]]></title>
<description><![CDATA[OpenAI is reportedly developing a screen-free, portable smart speaker meant to act as a personalized home computer and humanlike AI companion. "It will help control smart-home appliances, play media, answer questions, respond to messages and tap into the range of capabilities offered by OpenAI's ...]]></description>
<link>https://tsecurity.de/de/3669275/it-security-nachrichten/openais-first-device-will-be-moveable-screenless-speaker-built-as-ai-companion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669275/it-security-nachrichten/openais-first-device-will-be-moveable-screenless-speaker-built-as-ai-companion/</guid>
<pubDate>Wed, 15 Jul 2026 01:22:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI is reportedly developing a screen-free, portable smart speaker meant to act as a personalized home computer and humanlike AI companion. "It will help control smart-home appliances, play media, answer questions, respond to messages and tap into the range of capabilities offered by OpenAI's ChatGPT," reports Bloomberg, citing people familiar with the matter. The device, expected to be unveiled this year and released in 2027, would mark OpenAI's first major hardware push after acquiring Jony Ive's io Products. Bloomberg reports: Apple sued OpenAI last week, accusing the company of stealing trade secrets. But OpenAI believes that the device veers significantly from anything Apple has on the market today and that it's unlikely that it violates trade secrets belonging to the iPhone maker, the people said. OpenAI's success in hardware will hinge on bringing a novel approach to the market -- something it aims to do with the smart speaker. For instance, the device's technology is meant to become increasingly personalized and proactive as it gains a deeper understanding of its owner over time, according to the people.
 
OpenAI envisions the device anticipating needs, surfacing information proactively and serving as an expert on its user, they said. Though the speaker is designed to stay in the home, it will be easy to move around the house. OpenAI believes the product's defining feature will be its personality and ability to connect on a humanlike level with users. The speaker incorporates mechanical elements that can move on their own, creating a sense that it is alive and not just an object responding to commands. The machine also will draw on personal information such as emails to better understand its owner. The goal is for the device to feel like a companion and become a physical manifestation of OpenAI's ChatGPT. Still, the exact plans could change as the company works through the development and legal process.
 
The device's communication abilities will rely on a more advanced version of the ChatGPT Voice Mode -- GPT-Live -- that OpenAI rolled out this month. The new voice mode is designed to act more like a human. It can listen and talk at the same time, adapt more naturally during conversations, and quickly process information. Though the new product resembles a speaker, OpenAI internally describes it as the first of its kind: a computer built for AI to help make busy people more productive. It includes a camera and other sensors that help it understand a user's surroundings and context, as well as advanced AI models beyond those available on conventional smart speakers. Another central difference is that the device includes a rechargeable battery, allowing it to be carried from room to room throughout the day. A user could bring it into the laundry room while doing chores, move it into the kitchen for cooking assistance, and later place it in a living room or bedroom to have it play music. It can also remain plugged into a single room if the customer chooses.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=OpenAI's+First+Device+Will+Be+Moveable%2C+Screenless+Speaker+Built+as+AI+Companion%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F14%2F2116245%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F14%2F2116245%2Fopenais-first-device-will-be-moveable-screenless-speaker-built-as-ai-companion%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/07/14/2116245/openais-first-device-will-be-moveable-screenless-speaker-built-as-ai-companion?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How data centers cope with heat waves]]></title>
<description><![CDATA[Europe is sweltering. The summer of 2026 has seen historic heat waves that have taken a significant toll on infrastructure. In recent weeks, across the continent, problems have been reported in the power grid, telecommunications, and rail transportation. IT infrastructure has not been spared from...]]></description>
<link>https://tsecurity.de/de/3669125/it-security-nachrichten/how-data-centers-cope-with-heat-waves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669125/it-security-nachrichten/how-data-centers-cope-with-heat-waves/</guid>
<pubDate>Tue, 14 Jul 2026 22:52:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Europe is sweltering. The summer of 2026 has seen historic heat waves that have taken a significant toll on infrastructure. In recent weeks, across the continent, problems have <a href="https://www.bbc.com/news/articles/cj0gez6d50ro" target="_blank" rel="noreferrer noopener">been reported</a> in the power grid, telecommunications, and rail transportation. IT infrastructure has not been spared from the situation.</p>



<p class="wp-block-paragraph">“The heat affects equipment long before anyone notices a problem,” explains Ricardo Román, sales director at Fracttal, in an email. “Every piece of equipment has a temperature range within which it is designed to operate, and when it operates above that range, it begins to degrade silently,” he says. A process of wear and tear begins that will eventually take its toll. With technology, this happens much faster. “In a data center, this effect is amplified because there’s no margin for error,” he notes. When something starts to fail, everything grinds to a halt.</p>



<p class="wp-block-paragraph">In fact, this latest heat wave has already had negative impacts on data centers outside of Spain. In the United Kingdom, high temperatures shut down hospital data centers and <a href="https://www.lavanguardia.com/neo/ia/20260707/11586247/ola-calor-deja-fuera-combate-mayores-superordenadores-ia-1-000-hervidores-agua-funcionando-vez.html" target="_blank" rel="noreferrer noopener">caused</a> the University of Cambridge’s Dawn supercomputer to go offline, as its cooling systems were unable to cope with the temperatures. That’s the crux of the problem. “In IT, heat isn’t a computing problem—it’s a problem of maintaining the assets that support the data center,” explains Román. </p>



<p class="wp-block-paragraph">Heat thus becomes yet another risk for the IT industry and, in particular, for data centers. </p>



<p class="wp-block-paragraph">Temperatures are a clear and growing concern when it comes to corporate risk prevention. “I see it in conversations with clients: In the past, the maintenance team was the one monitoring the temperature in a technical room,” Román says. “Today, management also monitors it, because they know that if that goes down, the service goes down—and behind the service is the end customer,” he adds. Maintenance has gone from being a cost “to a lever for business continuity that no one dares to touch.”</p>



<p class="wp-block-paragraph">As a World Economic Forum analysis warns, we’re experiencing a boom in AI-driven <a href="https://www.computerworld.es/article/4166490/especial-centros-de-datos-2026.html">data centers</a>, but the impact of climate risks on them is being overlooked. Their estimates <a href="https://www.weforum.org/stories/climate-action/data-centres-3-3-trillion-question-heat-cooling/">suggest</a> these risks could result in an additional annual cost of $81 billion by 2035 and $168 billion by 2065. These calculations include all kinds of threats, such as floods or droughts, but most of the impact comes from extreme heat.</p>



<p class="wp-block-paragraph">These projections are confirmed by data from the industry itself: Over the past three years, extreme weather events <a href="https://www.cnbc.com/2026/06/29/ai-data-centers-heatwave-climate-risk-weather.html" target="_blank" rel="noreferrer noopener">have accounted for</a> one-third of the losses incurred by the U.S. division of the data center company Zurich. According to projections by the climate risk analysis firm First Street, 79% of global data centers will face increased risks from extreme weather. MapleCroft estimated in 2025 that 56% of major data centers had a high or very high risk rating for extreme heat, and that <a href="https://www.cio.com/article/4041210/las-olas-de-calor-pueden-poner-en-jaque-a-los-centros-de-datos.html" target="_blank">this figure would rise to 80% by 2080</a>.</p>



<p class="wp-block-paragraph">These percentages cannot be easily extrapolated to Europe in general—and to Spain in particular—as one might think, although they do make the trend clear. Guillermo Benito, CTO of Nabiax, points out during a video call that these studies are based on global samples and thus place significant weight on the capacity of Asia and the United States. “We represent a small percentage there, but that said, all countries will have to adapt. The two major challenges for data centers are energy and cooling,” Benitonotes.</p>



<h2 class="wp-block-heading">Spain: A pioneer in heat?</h2>



<p class="wp-block-paragraph">In late June, French Labor Minister Jean-Pierre Farandou <a href="https://www.france24.com/es/minuto-a-minuto/20260630-francia-quiere-estudiar-el-modelo-espa%C3%B1ol-para-adaptar-la-sociedad-al-calor-extremo" target="_blank" rel="noreferrer noopener">proposed</a> taking a training course in Spain to learn how to prevent high temperatures from paralyzing a country. Although Spain’s climate varies by region, high summer temperatures are common in many areas (though climate change has made them more extreme and frequent in recent years), and the infrastructure of knowledge and solutions that Farandou wanted to learn about has been established. The big question is whether this also applies to data centers. Is Spain better prepared than other European regions?</p>



<p class="wp-block-paragraph">“Heat waves are becoming increasingly intense and frequent. What used to happen once every two years now happens two, three, or four times a year,” Benito says. Speaking from his own experience, he adds: “In Spain, data centers already take these factors into account.” When it comes to redundancy, monitoring, or maintenance, these factors are already factored in. “It’s not like it’s an unforeseen event. It’s already been taken into account, and we build in a lot of redundancy—a wide safety margin,” he says.</p>



<p class="wp-block-paragraph">The difference compared to central or northern Europe is that some haven’t considered this possibility. Benito points out that the same thing happens with homes. “For many years, they’ve been designing with two assumptions: that they have plenty of water because their climates are humid, and that it never gets hot,” he says. And this is a problem, because their summer temperatures have risen significantly during extreme heat waves. “Temperatures in the UK have gone up by 10 or 15 degrees, and their data centers aren’t prepared for that,” he says. In fact, he shares an anecdote about “a certain hyperscaler that, a few years ago, when its data centers in the United Kingdom went down, held a global conference to figure out how this had happened and draw lessons from it.” The curious thing is that what they learned was something that was already well known in Spain.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/11/ismail-enes-ayhan-lVZjvw-u9V8-unsplash.jpg?quality=50&amp;strip=all&amp;w=1024" alt="centro de datos" class="wp-image-4094600" width="1024" height="589" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">İsmail Enes Ayhan | Unsplash</p></div>



<p class="wp-block-paragraph">It was already getting hot in southern Europe, and preparations were needed. Now, temperatures are becoming a topic of conversation outside the region, and climate change has made its way into IT strategy. Benito confirms that, yes, the conversation is more visible in global settings. “For several reasons. The first is because, obviously, it affects operations. Another is the market. Customers also demand that you address this.” Before, the focus was on power capacity and square meters. Now, the expert points out, people are asking where the electricity comes from and whether it’s clean, and they’re demanding emissions guarantees. The sector is making significant investments to become sustainable, he argues.</p>



<p class="wp-block-paragraph">Beyond consumption data and the improvements that can be made, the big question is whether these high temperatures are already impacting decision-making—whether decisions on where to locate data centers (or not) are already being made with heat in mind.</p>



<p class="wp-block-paragraph">Industry representatives explain that while the climate can have an impact and is already taken into account when deciding where to locate a data center, it is not yet the sole factor or the most decisive one. In other words, many other factors must be considered, and these carry much more weight in the decision-making process. One such factor is energy, which is essential for these infrastructures and must be constant, resilient, and have a low carbon footprint. It is also an area where cooling plays a major role. As Román points out, cooling can account for between 30 and 40% of energy consumption, “and in poorly managed facilities, that figure approaches 50%.” Energy efficiency and cooling efficiency are thus essential—and not just for sustainability reasons. “It’s a matter of the bottom line.”</p>



<p class="wp-block-paragraph">Another factor is space. As Benito says, you need “stable locations where you can grow.” This isn’t just about whether the infrastructure <em>fits</em>, but also about how it aligns with the needs of its customers. As this expert points out, the concentration of data centers near Madrid or Barcelona isn’t “just a whim,” but because you need to be close to large population centers to provide them with low latency. “Other supercomputing applications can be located farther away, and that’s already happening,” he explains, but generally speaking, you can’t just put data centers anywhere. You have to strike a balance between needs and available space.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"></blockquote>



<h2 class="wp-block-heading">How to survive the heat</h2>



<p class="wp-block-paragraph">So, how can we survive the heat, especially when projections suggest that the future will bring even higher temperatures? The key is to understand that this is no longer a curiosity or an occasional incident. As Román points out, air-conditioning systems are running longer and longer. What worked 10 years ago will now barely suffice—it’s “pushed to its limits.” “Heat is shifting from being an August blip to a variable that must be monitored year-round. One you endure; the other you manage.”</p>



<p class="wp-block-paragraph">“By the time the room’s thermometer rises, it’s already too late. What you need to monitor isn’t the room—it’s the equipment—and you have to do it sooner,” he says. Román recommends a three-step strategy. First, don’t measure the environment; instead, measure the equipment and its variations in temperature, vibrations, and energy consumption. Next, take action on any deviations: Don’t wait for a failure, but instead act on early indicators that things aren’t normal. And finally, keep a comprehensive record of historical data, which will be key to anticipating issues and learning from them. “And here I’m going to be honest, because this is what I see every day: The technology to do all this already exists and isn’t expensive,” he asserts. “Many critical facilities are still managed using an Excel spreadsheet and the memory of a technician who’s been there for twenty years,” he warns. And that’s a problem.</p>



<p class="wp-block-paragraph">In the specific case of data centers, Spain has done its homework. The high temperatures (which exceeded those recorded in the United Kingdom, where some data centers did shut down) did not bring them to a halt during this heat wave.</p>



<p class="wp-block-paragraph">Unlike what might happen in other countries, Spain has optimized its cooling systems to be efficient and sustainable, as Benito explains, noting that the country must also contend with water stress. “In other countries, I can use water and let it evaporate as I please because I know it’s going to rain again—or at least that was the case until recently. In Spain, we’ve known for a long time that this isn’t the case,” he says. That’s why we work with closed-loop systems. “Most of us operators don’t use any water,” he says. The same water, mixed with certain cooling agents, circulates continuously. “Once the loop is filled, we don’t lose a single drop,” he asserts.</p>



<p class="wp-block-paragraph">What this expert is now seeing at international conferences is that in other countries where water wasn’t an apparent problem, people are starting to talk about working this way—”as a technical innovation.” “That’s where we say, ‘Yes, just like the ones we have in Spain or Portugal,’” he remarks with a touch of humor. “Water, like energy, is a challenge,” he says, so everything has already been designed with that in mind. It isn’t wasted, it doesn’t evaporate, and it isn’t consumed, he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads]]></title>
<description><![CDATA[Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar.

Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; the difference is...]]></description>
<link>https://tsecurity.de/de/3668995/it-security-nachrichten/researchers-say-claude-for-chrome-flaw-lets-rogue-extensions-trigger-gmail-reads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668995/it-security-nachrichten/researchers-say-claude-for-chrome-flaw-lets-rogue-extensions-trigger-gmail-reads/</guid>
<pubDate>Tue, 14 Jul 2026 21:38:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar.

Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; the difference is scope. Anthropic restricted the arbitrary-prompt path in May as part of its response to the ]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.2-beta.1]]></title>
<description><![CDATA[OpenClaw 2026.7.2-beta.1]]></description>
<link>https://tsecurity.de/de/3668787/downloads/v202672-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668787/downloads/v202672-beta1/</guid>
<pubDate>Tue, 14 Jul 2026 19:31:53 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.2-beta.1</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62188 | openclaw feishu up to 2026.6.8 Permission Tools improper authorization (CNNVD-2026-98294010)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in openclaw feishu up to 2026.6.8. The affected element is an unknown function of the component Permission Tools. The manipulation leads to improper authorization.

This vulnerability is uniquely identified as CVE-2026-62188. The a...]]></description>
<link>https://tsecurity.de/de/3668612/sicherheitsluecken/cve-2026-62188-openclaw-feishu-up-to-202668-permission-tools-improper-authorization-cnnvd-2026-98294010/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668612/sicherheitsluecken/cve-2026-62188-openclaw-feishu-up-to-202668-permission-tools-improper-authorization-cnnvd-2026-98294010/</guid>
<pubDate>Tue, 14 Jul 2026 18:17:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/openclaw:feishu">openclaw feishu up to 2026.6.8</a>. The affected element is an unknown function of the component <em>Permission Tools</em>. The manipulation leads to improper authorization.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-62188">CVE-2026-62188</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[What's the difference between active noise canceling and passive?]]></title>
<description><![CDATA[The frustrating science of keeping your ears from doing their job.]]></description>
<link>https://tsecurity.de/de/3668191/it-nachrichten/whats-the-difference-between-active-noise-canceling-and-passive/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668191/it-nachrichten/whats-the-difference-between-active-noise-canceling-and-passive/</guid>
<pubDate>Tue, 14 Jul 2026 16:02:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The frustrating science of keeping your ears from doing their job.]]></content:encoded>
</item>
<item>
<title><![CDATA[Canva launches Code 2.0, offering AI website building to every user — including free accounts]]></title>
<description><![CDATA[Canva on Tuesday launched Canva Code 2.0, a major upgrade to its AI-powered coding tool that lets users build interactive websites, apps, and experiences using plain-language prompts — and then edit the results as easily as tweaking a Canva presentation. The feature is now available to all of the...]]></description>
<link>https://tsecurity.de/de/3668119/it-nachrichten/canva-launches-code-20-offering-ai-website-building-to-every-user-including-free-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668119/it-nachrichten/canva-launches-code-20-offering-ai-website-building-to-every-user-including-free-accounts/</guid>
<pubDate>Tue, 14 Jul 2026 15:32:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.canva.com/">Canva</a> on Tuesday launched <a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a>, a major upgrade to its AI-powered coding tool that lets users build interactive websites, apps, and experiences using plain-language prompts — and then edit the results as easily as tweaking a Canva presentation. The feature is now available to all of the company's more than 265 million monthly users across every pricing tier, including free accounts.</p><p>The move is Canva's most aggressive push yet into the fast-growing "vibe coding" market, a category that barely existed 18 months ago but has already minted billion-dollar startups and reshaped how non-developers think about building software. But where rivals like <a href="https://lovable.dev/">Lovable</a>, <a href="https://replit.com/">Replit</a>, and <a href="https://bolt.new/">Bolt.new</a> have focused primarily on generating functional code from text prompts, Canva is making a different bet: that the real bottleneck isn't creating the code — it's making the output actually look good.</p><p>"Most vibe coding tools stop at functional — generating output that looks the same as everyone else's," Canva states in its announcement. "You might get a working prototype, but making it actually look like yours requires a complex editing surface, a separate design tool, a developer, or endless back-and-forth prompting that rarely lands where you want it.”</p><p>Danny Wu, Canva's Head of AI Products, framed the product's positioning in stark terms during an exclusive interview with VentureBeat ahead of the launch.</p><p>"We are deliberately targeting non-technical users," Wu said. "Canva Code isn't a tool we're building for developers. What we're trying to do is bring the power of AI coding — and really lightweight coding — into the Canva platform, while answering our users' requests for more interactivity, more customization, and more flexibility, from websites to interactive presentations."</p><h3><b>Canva Code 2.0 brings drag-and-drop editing, HTML import, and 75% faster generation to AI-built websites</b></h3><p>The update introduces several capabilities designed to collapse the distance between generating code and publishing a polished interactive experience. Users can now create Canva Code projects directly inside other design projects — embedding interactive elements within a whiteboard, presentation deck, or standalone page. <a href="https://www.canva.com/">Canva</a> has also added more than 50 new templates specifically designed for interactive designs, along with the ability to import raw HTML files from other AI coding tools and convert them into editable Canva designs.</p><p>The performance improvements are significant. Canva says it has reduced average code generation time by 75 percent and cut the median time from initial prompt to a published site by 30 percent. The company also reports that integrating <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> into the broader Canva editor — allowing users to treat coded outputs like any other design element — has increased active Code users by 25 percent.</p><p>Perhaps the most distinctive feature is the editing experience itself. Unlike most AI coding platforms, which require users to re-prompt or modify raw code to make visual changes, <a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a> lets users click directly into generated elements to change text, drag and drop images from Canva's built-in library of over 120 million templates and assets, update colors and fonts through a familiar toolbar, or select a specific element and refine it through conversational AI. Every output is fully interactive and automatically adapts to different screen sizes, with a built-in mobile preview.</p><p>Wu demonstrated the drag-and-drop editing during the interview, showing how a generated conference website could be modified in real time — swapping in photos, changing fonts to branded alternatives, and editing text directly on the canvas. "The key differentiator with Canva Code is the editability and the kindness of the outputs it generates," he said, though he noted one current limitation: "We don't support moving elements around. You still have to re-prompt for that."</p><h3><b>How Canva plans to compete with Lovable, Replit, and Bolt in the booming AI app builder market</b></h3><p>Canva's entry into vibe coding at this scale arrives at a pivotal moment for the category. According to <a href="https://www.useluminix.com/reports/industry-analysis/vibe-coding-tool-landscape-replit-v0-base44-bolt-lovable-vercel/source/0">market research published by Luminix AI in May 2026</a>, the vibe coding and AI app builder market has reached an estimated $4.7 billion in 2026, with projections pointing toward $12.3 billion by 2027 at roughly 38 percent compound annual growth. The research also estimates that AI-generated code now comprises approximately 41 percent of all code written globally — a figure that would have seemed inconceivable even two years ago.</p><p>The competitive landscape has grown ferocious. <a href="https://lovable.dev/dashboard">Lovable</a>, which focuses on conversational, design-forward app generation for non-technical founders, has achieved what may be the fastest revenue ramp in the category's history — reportedly reaching approximately $400 million in annual recurring revenue by early 2026, according to Luminix's analysis. <a href="https://replit.com/">Replit</a>, which transformed its browser-based IDE into a full vibe-coding engine through successive AI agent releases, has tripled its valuation to $9 billion and is targeting $1 billion in run-rate revenue by the end of 2026, per the same report. <a href="https://bolt.new/">Bolt.new</a>, which runs a full Node.js environment entirely in the browser, scaled from $4 million to $40 million in ARR within months of launching.</p><p>And then there is Canva, which brings something none of those platforms possess: a quarter-billion-user design ecosystem where brands, teams, and individuals already store their visual identities, collaborate on projects, and publish content.</p><p>Wu positioned <a href="https://bolt.new/">Canva Code</a> not as a direct competitor to these developer-focused tools but as something that fills a gap none of them have addressed. "A lot of the requests that we have been getting and the usage we're seeing is actually with using Canva Code not necessarily as just one artifact, but as part of an overall design, the visual communication they're trying to tell," Wu said. "Like when you have a sales deck, you're able to add a calculator, you're able to add a visualizer of what exactly your product does. That's something where an interactive slide can be worth a thousand pictures."</p><h3><b>Why Canva's HTML import feature could turn it into a 'finishing layer' for every AI coding tool</b></h3><p>One of the most strategically interesting features in <a href="https://bolt.new/">Canva Code 2.0</a> is its HTML import capability, which allows users to take code generated by any AI tool — including <a href="https://chatgpt.com/">ChatGPT</a>, <a href="http://claude.ai/">Claude</a>, <a href="https://lovable.dev/dashboard">Lovable</a>, or <a href="https://bolt.new/">Bolt</a> — and bring it into Canva as a fully editable design. The implication is unmistakable: Canva is positioning itself as the place where AI-generated code gets its finishing touches, regardless of where it was originally created.</p><p>When asked directly whether this amounts to positioning Canva as a "finishing layer on top of vibe coding," Wu offered a diplomatic but revealing response. "It's really a continuation of our goal to make all design as easy as possible," he said. "We've supported importing PDFs and translating them into docs, importing PowerPoint files — so in one way, it's an expansion of that. But in another way, it's really just listening to what our users want and making Canva both the most useful and the most compatible platform.”</p><p>He paused, then added: "It's not that we're deliberately positioning ourselves as a specific layer, say like a finishing layer after vibe coding. We just really want to make our platform the most accessible and the most pluggable."</p><p>That language — "most pluggable" — suggests a platform strategy that doesn't require Canva to win the AI code generation race outright. If Canva becomes the default destination for making AI-generated code look professional and on-brand, it captures value from the entire category regardless of which code generation engine users prefer. The strategy also echoes the broader import capabilities that already allow Canva to ingest PowerPoint decks and PDFs from competing platforms, gradually pulling users deeper into the Canva ecosystem without demanding they abandon existing workflows.</p><h3><b>What Canva Code can build — and where Danny Wu says it hits its limits</b></h3><p>Wu was notably candid about the product's boundaries — a refreshing departure from the typical Silicon Valley product launch. "Canva Code is great for anything that works as a front-end app, and it's especially good when you want to leverage data, data submissions, and interactivity at small to medium scale," he said. "I'll be honest about the limitations. Canva Code is probably not going to be suitable if you're trying to build a website with complex backends, or if you're handling hundreds of thousands of visitors per day."</p><p>This candor effectively draws a line between <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> and the more ambitious platforms in the space. While Lovable and Replit are pushing toward full-stack application development — complete with databases, authentication, and production-grade hosting — Canva is deliberately limiting its scope to interactive front-end experiences at modest scale. The question is whether that's a strategic weakness or a disciplined focus. For the teachers, small business owners, and marketing teams that make up the bulk of Canva's user base, complex backends and high-traffic scalability are irrelevant concerns. What matters is whether they can create an interactive event page, a property listing website, or a classroom hub that looks professional and works on mobile — without hiring a developer or learning a new tool.</p><p>When asked about the AI models powering <a href="https://www.canva.com/ai-code-generator/">Canva Code</a>, Wu confirmed the company uses a combination of proprietary and third-party models, including those from OpenAI and Anthropic, but declined to specify the exact mix. "We don't share the exact mix, and it does change over time," he said. "We also route differently depending on what you're asking for and which model family we think is best for handling certain requests."</p><h3><b>Canva's AI acquisition spree — from Affinity to Leonardo.ai — now powers its vibe coding push</b></h3><p>Canva's broader AI infrastructure has been significantly bolstered by an acquisition strategy that has accelerated over the past two years. In March 2024, <a href="https://www.canva.com/newsroom/news/affinity/">the company acquired Affinity</a>, the British creative software suite popular with Mac users, in a deal that Bloomberg reported was valued at "<a href="https://www.bloomberg.com/news/articles/2024-03-26/canva-acquires-affinity-design-suite-in-push-to-rival-adobe">several hundred million pounds</a>." Canva at the time positioned the deal as a way to compete with Adobe's flagship products — Illustrator, Photoshop, and InDesign — by gaining ownership of Affinity's Designer, Photo, and Publisher applications.</p><p>Just four months later, Canva acquired <a href="http://leonardo.ai/">Leonardo.ai</a>, an Australian generative AI startup with over 19 million registered users and more than a billion images generated. Canva co-founder Cameron Adams said at the time that Leonardo.ai's technology would be integrated into Canva's Magic Studio generative AI suite.</p><p>Together with these acquisitions, <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> is the company's attempt to layer interactive, code-driven capabilities on top of a visual design platform that has already been enhanced by professional-grade design tools and generative AI models. The company reports over 32 billion uses of its AI products to date — a staggering figure that underscores how deeply AI is now woven into everyday Canva workflows, even for users who may not think of themselves as using artificial intelligence.</p><h3><b>Six million sites published, but Canva's retention data remains an open question</b></h3><p>Canva's announcement highlights an impressive traction metric: users have created and published more than six million websites using Canva Code since the feature was first introduced a year ago. But the number deserves scrutiny.</p><p>Wu clarified in the interview that the six million figure represents published websites over the past year — meaning sites that were either made public or shared via password-protected or private links. "They may have published publicly, or behind a password, or as a private link. But that's the number of published websites," he said.</p><p>When asked about active retention — how many of those sites are still live and being maintained — Wu acknowledged the gap in his data. This is a meaningful distinction. In the vibe coding market, raw creation numbers can be misleading because the barrier to generating a site is so low. The more telling metric — which Canva does not yet provide — would be how many of those six million sites receive regular traffic or have been updated after initial publication.</p><p>The early use cases, however, suggest genuine utility beyond novelty. Educators and school administrators are using Canva Code to build classroom hubs, with one teacher creating bespoke webpages for each of their classrooms to keep students and parents updated on announcements. Small businesses, like Alt Marketing School, have built mini apps for fundraising training and interactive roadmaps for their members. For World Book Day, 50 readers created educational games across different subjects, complete with pedagogical guides for classroom use.</p><h3><b>Canva Code pricing, data governance, and what enterprise customers need to know</b></h3><p><a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a> is available across all of Canva's pricing tiers, including its free plan — a notable decision given that competitors like Lovable, Bolt, and Replit reserve their most capable features for paid subscribers. "As you go from, say, free to pro to business to enterprise, you would get more AI credits and be able to have higher usage of Canva Code," Wu said. "But it is available and it is usable — even free Canva accounts as well as education and not-for-profit accounts."</p><p>This credit-based approach mirrors the pricing evolution happening across the entire vibe coding category, where platforms have converged on token or credit systems that meter AI generation capacity rather than gating features behind subscription tiers. The difference is that Canva's free tier serves as an acquisition funnel for a much larger design platform, not just for the coding feature itself.</p><p>For the institutional customers Canva increasingly courts — school districts, real estate brokerages, enterprise marketing teams — data governance is a threshold concern. Wu addressed this directly. "All users and customers have full control over how their data is used," he said. "They can choose whether their prompts and data are used for AI training in the settings. For businesses and enterprises, team admins can manage this at the organizational level and guarantee that their inputs, content, and outputs won't be used for training." This opt-out approach reflects a lesson the broader industry has learned the hard way. As The Verge reported when Canva acquired Leonardo.ai, Adobe suffered significant backlash over a policy update regarding user data and AI model training — a controversy Canva appears keen to avoid.</p><h3><b>Canva's long-term vision: closing the gap between imagination and what non-technical users can actually build</b></h3><p>When asked where <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> fits into the company's long-term trajectory — and whether Canva is building toward a full-stack app development platform — Wu steered the conversation back to the company's core audience.</p><p>"A huge part of it is reducing the gap between your imagination and what's possible, especially for everyday users — people who don't have a lot of time," he said. "They don't have time to figure out deploys or MCPs or APIs. They just want to design more interactive and more dynamic communication."</p><p>He pointed to the rapid improvement in AI model capabilities as a key accelerant. "The kind of things you can create today in one shot — like a 3D visualization of a solar system — you really couldn't have trusted the output a year ago. But today, you have a really high success rate."</p><p>Whether <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> becomes a durable product category or a feature that gets absorbed into the platform's broader AI workflow will depend on how quickly the company can close the gap between its current front-end focus and the full-stack capabilities that increasingly define the competition. Lovable is shipping Supabase-backed apps with authentication and databases built in. Replit's agents can execute autonomous long-running builds. Bolt.new runs entire Node.js environments in a browser tab. These are fundamentally different ambitions than making a conference landing page look good.</p><p>But Canva has never won by matching the technical depth of its competitors. A decade ago, it didn't try to out-feature Adobe — it made design accessible to the 99 percent of people who would never open Photoshop. Now, in a vibe coding market where every tool can generate a working prototype from a prompt, Canva is making the same wager it made in 2012: that for most people, the hardest part was never the building. It was making it look like it came from you.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Copilot kann jetzt feststellen, was Ihren Computer verlangsamt]]></title>
<description><![CDATA[Microsoft hat damit begonnen, eine neue „PC Insights“-Funktion in Copilot für Windows 11 zu testen, die Nutzern dabei hilft, die Leistung ihres Computers zu analysieren und Fragen zum Systemstatus zu beantworten, berichtet Windows Latest.



Mit Zustimmung des Nutzers kann Copilot die Prozessor- ...]]></description>
<link>https://tsecurity.de/de/3667094/it-nachrichten/copilot-kann-jetzt-feststellen-was-ihren-computer-verlangsamt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667094/it-nachrichten/copilot-kann-jetzt-feststellen-was-ihren-computer-verlangsamt/</guid>
<pubDate>Tue, 14 Jul 2026 09:03:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft hat damit begonnen, eine neue „PC Insights“-Funktion in Copilot für Windows 11 zu testen, die Nutzern dabei hilft, die Leistung ihres Computers zu analysieren und Fragen zum Systemstatus zu beantworten, berichtet <a href="https://www.windowslatest.com/2026/07/12/windows-11-copilot-ai-can-now-tell-you-whats-slowing-down-your-pc-while-using-1gb-of-ram-itself/">Windows Latest</a>.</p>



<p>Mit Zustimmung des Nutzers kann Copilot die Prozessor- und Speicherauslastung, den freien Speicherplatz, angeschlossene USB-Geräte, den Netzwerkstatus, den Akkustand, die BIOS-Version und die Grafikkarte analysieren.</p>



<h2 class="wp-block-heading">Nur analysieren, nicht aber reparieren</h2>



<p>Die Idee ist, dass der Nutzer Fragen zur Hardware stellen kann, woraufhin Copilot auf der Grundlage des aktuellen Systemstatus antwortet. PC Insights kann jedoch lediglich Informationen auslesen und analysieren, Probleme jedoch nicht automatisch beheben. Das könnte sich laut Windowslatest jedoch noch ändern.</p>



<p>Microsoft gibt an, dass die Nutzung dieser Funktion freiwillig ist und dass persönliche Dateien sowie Systemdaten nicht zum Trainieren von KI-Modellen verwendet werden. Microsoft <a href="https://support.microsoft.com/en-us/microsoft-copilot/pc-insights#wl">schreibt</a> in einem Support-Dokument: “Copilot greift erst dann auf Informationen zu, wenn Sie Ihre Zustimmung erteilt haben. Wenn Sie eine Frage stellen, fragt Copilot Sie zunächst, bevor es auf relevante Informationen auf Ihrem PC zugreift”. Sie können Copilot aber so umstellen, dass Sie ihm den ständigen Zugriff auf die Hardware-Daten erlauben. Dann muss Copilot nicht immer nachfragen.</p>



<p>Derzeit steht die neue Funktion nur Testnutzern in den USA zur Verfügung; Sie können „PC Insights“ also nur mit Insider-Testversionen verwenden und auch das nur auf bestimmten Rechnern in den USA. Deutsche Insider-Tester bleiben derzeit also außen vor. Wann „PC Insights“ für alle Windowsnutzer verfügbar sein wird, ist derzeit noch nicht bekannt.</p>



<p>Windowslatest betont allerdings, dass es sich bei dieser neuen Copilot-Funktion um eine Webapp handelt, die ein Gigabyte Arbeitsspeicher belegt – und das sogar dann, wenn sie überhaupt nichts macht.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Drei OpenClaw-Lücken erlauben Host-Ausbruch via WhatsApp]]></title>
<description><![CDATA[Drei Schwachstellen im KI-Assistenten OpenClaw ermöglichen die vollständige Übernahme des Host-Systems über eine präparierte WhatsApp-Nachricht.

Tags: #Cyber Security | #Künstliche Intelligenz | #OpenClaw]]></description>
<link>https://tsecurity.de/de/3667015/it-security-nachrichten/drei-openclaw-luecken-erlauben-host-ausbruch-via-whatsapp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667015/it-security-nachrichten/drei-openclaw-luecken-erlauben-host-ausbruch-via-whatsapp/</guid>
<pubDate>Tue, 14 Jul 2026 08:22:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920.jpg" class="attachment-full size-full wp-post-image" alt="OpenClaw" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/02/OpenClaw-Quelle-Robert-Way-Shutterstock-2733455235-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Drei OpenClaw-Lücken erlauben Host-Ausbruch via WhatsApp 1"></p>
    Drei Schwachstellen im KI-Assistenten OpenClaw ermöglichen die vollständige Übernahme des Host-Systems über eine präparierte WhatsApp-Nachricht.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a> | <a href="https://www.it-daily.net/thema/openclaw">#OpenClaw</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla GFX: HDR video in Firefox for Windows tech retrospective]]></title>
<description><![CDATA[HDR video is coming to Firefox for Windows users (and has been available for some time on macOS).  This blog post explains how we developed the feature and gives a retrospective on the technical choices we made.



A primer on video playback for the web:




Video file demux and decode: A video s...]]></description>
<link>https://tsecurity.de/de/3666879/tools/mozilla-gfx-hdr-video-in-firefox-for-windows-tech-retrospective/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666879/tools/mozilla-gfx-hdr-video-in-firefox-for-windows-tech-retrospective/</guid>
<pubDate>Tue, 14 Jul 2026 07:08:30 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="wp-block-paragraph">HDR video is coming to Firefox for Windows users (and has been available for some time on macOS).  This blog post explains how we developed the feature and gives a retrospective on the technical choices we made.</p>



<p class="wp-block-paragraph">A primer on video playback for the web:</p>



<ul class="wp-block-list">
<li><strong>Video file demux and decode</strong>: A video stream generally consists of parallel image and audio streams, along with captions, HDR scene metadata, and the like. “Container” formats like MP4 or MKV specify how these streams are combined, or multiplexed, into a single byte stream for transmission. On receipt, Firefox needs to divide that byte stream back into the individual media streams; this is de-multiplexing or “demuxing”. Then Firefox must uncompress the data to get images, audio samples, and so on. Firefox’s media team provides the demuxers, and pulls in appropriate codecs to decode them. We prefer using hardware video decoders if they work reasonably well. Video decompression usually produces roughly a YUV 4:2:0 image in <a href="https://learn.microsoft.com/en-us/windows/win32/medfound/recommended-8-bit-yuv-formats-for-video-rendering">NV12 for SDR</a> or <a href="https://learn.microsoft.com/en-us/windows/win32/medfound/10-bit-and-16-bit-yuv-video-formats">P010 for HDR</a>. (If you visit <strong>about:support</strong> in Firefox, and search for <strong>Codec Support Information</strong> (or one of the codec names like <strong>AV1</strong>), you can see a whole feature matrix of support details for which codecs are hardware and software on your system.)</li>



<li><strong>Gecko displaylist building</strong>: Given a demultiplexed, uncompressed frame of video, Gecko displaylist building incorporates it into a video element in the displaylist being sent to WebRender. If the frame was decoded in hardware, it is generally represented by a texture in GPU memory. Or, if it was decoded in software, then it is represented by a memory mapping holding some raw pixel data in system memory shared with Firefox’s media decoder process.</li>



<li><strong>WebRender</strong>: Given the video element in the displaylist, WebRender decides whether to promote it to a desktop compositor overlay, or whether it must instead be rendered using a pathway more like an ordinary HTML element. A compositor overlay is faster and uses less power; on Windows this uses DWM with the <a href="https://learn.microsoft.com/en-us/windows/win32/api/_directcomp/">DirectComposition API</a>, which manages a graph of <a href="https://learn.microsoft.com/en-us/windows/win32/api/dcomp/nn-dcomp-idcompositionvisual">visuals</a>. But if complex CSS is involved (rounded corners, blur filters, or similar features), Firefox must use WebRender’s ordinary rendering pathway. Currently the latter is not HDR capable, so Firefox favors the desktop compositor overlay for animated elements such as video and canvas.</li>
</ul>



<p class="wp-block-paragraph">As we began designing Firefox’s HDR support, we had to lay out some assumptions and found many complications:</p>



<ul class="wp-block-list">
<li>Initially, we had hoped that on a modern system, <a href="https://en.wikipedia.org/wiki/Rec._2100">BT2100</a> HDR videos could be displayed on Windows by simply sending them to DirectComposition.
<ul class="wp-block-list">
<li>In theory, the Desktop Window Manager (DWM) honors the <a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgi1_4/nn-dxgi1_4-idxgiswapchain3">DXGISwapChain3</a>::<a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgi1_4/nf-dxgi1_4-idxgiswapchain3-setcolorspace1">SetColorSpace1</a> method which should let us request either <a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgicommon/ne-dxgicommon-dxgi_color_space_type">DXGI_COLOR_SPACE_YCBCR_STUDIO_G2084_LEFT_P2020</a> or <a href="https://learn.microsoft.com/en-us/windows/win32/api/dxgicommon/ne-dxgicommon-dxgi_color_space_type">DXGI_COLOR_SPACE_YCBCR_STUDIO_GHLG_LEFT_P2020</a>. The former refers to SMPTE 2084, more commonly called PQ, the <a href="https://en.wikipedia.org/wiki/Perceptual_quantizer">Perceptual Quantizer</a> function and the latter is ARIB-STD-B67  also known as HLG, the <a href="https://en.wikipedia.org/wiki/Hybrid_log%E2%80%93gamma">Hybrid Log Gamma</a> function, most commonly used on HDR TV broadcasts.</li>



<li>Unfortunately, this was a dead end. In testing with a mocked up <a href="https://github.com/FirefoxGraphics/compositor_colortest/tree/main">compositor test app</a>, calling SetColorSpace1 with this value seems to be ignored on P010 (at least in testing on AMD), so it incorrectly displays BT2100 PQ video as if it were BT709, which makes the video dull and muddy, since BT709 is a narrower gamut than BT2020, and the BT1886 transfer function used by BT709 is very different from PQ defined by BT2100. SetColorSpace1 may work on other vendors with P010, so it may be a valid optimization, but we were looking for a universal solution.</li>



<li>For the future, Windows 11 23H2 has added a new interface called IDCompositionTexture which may serve our purposes better; from what we have been told, it is universally supported for all formats and color spaces. We haven’t used it for video so far, but it’s an interesting future direction.</li>
</ul>
</li>



<li>As noted above, HDR videos must use a desktop compositor overlay. HDR video uses the BT2100 PQ colorspace with an RGB10A2 format, while WebRender can only work with images in the sRGB colorspace (appropriate for standard-dynamic-range BT709 video).
<ul class="wp-block-list">
<li>Until HDR came along, Gecko and WebRender only used desktop compositor overlays as a power/performance optimization. With HDR, overlays become a necessity as the pixel format and color space differ from classic sRGB.</li>



<li>Fortunately, HDR videos tend to be shown without particularly fancy CSS rendering such as clip masks and rounded corners, which would require WebRender to perform further copies. Technically, DirectComposition does support all of those features, but Firefox doesn’t use that functionality much.</li>



<li>In the future, we expect to upgrade WebRender for HDR rendering, allowing us to deal with complex cases like clip masks or blur filters on video elements.</li>
</ul>
</li>



<li>We considered whether we could use VideoProcessorBlt, or whether we should write our own shader instead.
<ul class="wp-block-list">
<li>In favor of VideoProcessorBlt:
<ul class="wp-block-list">
<li>It uses less power on GPUs that have a video processor unit.</li>



<li>We discovered in testing (using <a href="https://learn.microsoft.com/en-us/windows/win32/api/d3d11_1/nf-d3d11_1-id3d11videoprocessorenumerator1-checkvideoprocessorformatconversion">CheckVideoProcessorFormatConversion</a>) that while many modern GPUs support one of the needed conversions (P010 PQ -&gt; RGB10 PQ), few support the ones we need for HLG videos (P010 HLG -&gt; RGB10 PQ).</li>



<li>The ‘video-dynamic-range’ query used on the web is not fine-grained enough to be able to say “the web browser can display PQ video but not HLG video”, so if we went with VideoProcessorBlt as a required feature, only about 20% of HDR desktop users would be able to use the feature.</li>



<li>In the future, we could explore using VideoProcessorBlit to save power on hardware that supports the conversions we need. But other web browsers are not using this functionality, so there may be more issues we haven’t found yet.</li>
</ul>
</li>



<li>In favor of writing our own shader with all of the features:
<ul class="wp-block-list">
<li>This would work consistently on all vendors – nothing special here.</li>



<li>This would look the same on all vendors, regardless of hardware capabilities. This is generally the aim of web standards.</li>



<li>This would support anything we want it to. HDR tonemapping can be implemented. Video orientation can be implemented (for videos recorded on phones which may be rotated 90, 180 or 270 degrees). We can support any kind of YUV-&gt;RGB conversion with a color matrix (even weird legacy formats like GBR 4:2:0).  We can support conversion between color primaries (e.g. BT2020-&gt;BT709).  We can convert to linear color (for scRGB using RGBA16F) or any EOTF we want (notably BT2100 PQ with RGB10A2, for our use-case).</li>
</ul>
</li>



<li>In the end we went with the shader after a significant period of time experimenting with VideoProcessorBlt in our Nightly releases.</li>
</ul>
</li>



<li>There is a very large amount of graphics code in Gecko and WebRender that needs to be upgraded for HDR.
<ul class="wp-block-list">
<li>We decided that the most important code paths to upgrade first are the ones for regular video playback and DRM-protected video playback, and later canvas video import (Canvas2D, WebGL, WebGPU) which will require upgrading canvas for HDR first – another big project.</li>



<li>We had to upgrade several dozen structs to carry the transfer function for video data, as previously all code assumed video used BT1886 EOTF.</li>
</ul>
</li>



<li>We hope we can avoid tone mapping HDR content when viewed on HDR displays.
<ul class="wp-block-list">
<li>It’s reasonable to expect that most displays going forward will be HDR displays (partly because of marketing momentum, partly because displays are made by a very finite set of manufacturers who are all making HDR display panels), and eventually tone mapping may become unnecessary on the web.</li>



<li>For the short-term we will have to apply a tone mapping effect when HDR content is viewed on SDR displays, likely using  ‘Reinhard tonemapping’ which refers to the widely available paper <a href="https://doi.org/10.1145/566654.566575">Photographic Tone Reproduction for Digital Images</a> by Erik Reinhard et al, and configuring it for a fixed brightness ratio of 400 cd/m^2 -&gt; 100 cd/m^2 when used on SDR displays, and see if that fits all HDR content on the web well enough for a good user experience – and if it does not, we will iterate based on feedback from users on Firefox Nightly.</li>



<li>We are hoping that we will never have to apply tonemapping for HDR content on HDR displays, there are multiple factors in this decision:
<ul class="wp-block-list">
<li>Varying the brightness limit would make it a significant fingerprinting vector if not handled very carefully if the script can inspect pixels or parameters related to that.  There are ways to mitigate this but they are all awkward restrictions to impose, and queries would have to get a different answer than what the rendering is using.</li>



<li>Phones and laptops with light sensors may vary the reference brightness in real time, and this changes the maximum displayable ratio (aka HDR headroom) every refresh, which is also a major battery drain if we keep redrawing all of the time.</li>



<li>Documents composed of multiple images (a gallery or some form of art composition) would apply different tonemapping to each image if the brightest pixel in each image is different brightness).  We’d have to do something about that to make it controllable via CSS.</li>



<li>In general the detailed parts of an image are within a certain brightness band – see <a href="https://www.yedlin.net/DebunkingHDR/">Debunking HDR</a> for a detailed lecture on film grading and why you would not have significant difference in brightness between scene elements.</li>



<li>User feedback so far has indicated that not applying tonemapping has given them a better viewing experience on some videos.</li>
</ul>
</li>
</ul>
</li>



<li>WebRTC is implemented using a library, common to all web browsers, which has limited support for HDR.
<ul class="wp-block-list">
<li>While we didn’t prioritize this for an initial feature launch, we are looking at how to implement HDR support properly in libwebrtc. This is in the early assessment phase but we know this is wanted for a couple of use-cases, like video calls for meetings, or game streaming with friends watching.</li>
</ul>
</li>
</ul>



<p class="wp-block-paragraph">In general, one of the biggest challenges in working on graphics code in a web browser is a lack of documentation for how to best use features like video playback and desktop compositing in the context of a web browser (e.g. multiple processes, sandboxing, shared memory, sharing external textures, etc). This parallels the rarity of graphics engineers with such experience. Building new features in this space requires a lot of research (and a lot of trial and error). The solution you end up with may not look at all like the one you initially imagined.</p>



<p class="wp-block-paragraph">On behalf of the graphics team at Mozilla, I want to thank the people who use Firefox Nightly regularly and file bug reports when things aren’t working the way they want. Comments on <a href="https://mozillagfx.wordpress.com/2026/01/16/experimental-high-dynamic-range-video-playback-on-windows-in-firefox-nightly-148/">Experimental High Dynamic Range video playback on Windows in Firefox Nightly 148</a>, <a href="https://connect.mozilla.org/">Mozilla Connect</a>, and <a href="https://bugzilla.mozilla.org/">Bugzilla</a> bug reports have guided us to focus on the use-cases that matter to people using Firefox. When we succeed, it’s a great feeling.</p>



<p class="wp-block-paragraph">We’re working on extending HDR support to photos, apps/games and general web content.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic cyber defense engineering vs traditional exposure validation, what's the difference?]]></title>
<description><![CDATA[I keep seeing the phrase “agentic cyber defense” and “agentic cyber defense engineering” in talks and vendor material. It sounds interesting, but it is not always clear what is actually new compared to the exposure validation and CTEM programs many teams already run. From my current understanding...]]></description>
<link>https://tsecurity.de/de/3666725/it-security-nachrichten/agentic-cyber-defense-engineering-vs-traditional-exposure-validation-whats-the-difference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666725/it-security-nachrichten/agentic-cyber-defense-engineering-vs-traditional-exposure-validation-whats-the-difference/</guid>
<pubDate>Tue, 14 Jul 2026 04:53:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I keep seeing the phrase “agentic cyber defense” and “agentic cyber defense engineering” in talks and vendor material. It sounds interesting, but it is not always clear what is actually new compared to the exposure validation and CTEM programs many teams already run.</p> <p>From my current understanding, traditional exposure validation focuses on running defined assessments that test controls and detections against known TTPs and attack paths. The agentic descriptions I have seen talk about systems that can chain actions together on their own, react to new threat intel, and generate targeted assessments when you describe a scenario in natural language.</p> <p>If anyone has hands on experience with this kind of setup, how different is it really from standard automation and scheduling of assessments? For example, does it genuinely reduce the time between new intel and a validated view of exposure, or is it just a more flexible interface on top of similar checks?</p> <p>I would also like to hear about any pitfalls, such as reliability issues, oversight requirements, or cases where an agent made poor choices that still needed human review.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Academic-Pen-9219"> /u/Academic-Pen-9219 </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1uv3i7c/agentic_cyber_defense_engineering_vs_traditional/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1uv3i7c/agentic_cyber_defense_engineering_vs_traditional/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’]]></title>
<description><![CDATA[OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that the popular platform has thus far lacked. Still, some worry about the risks created by the move. 



“Our ambition is for OpenClaw...]]></description>
<link>https://tsecurity.de/de/3666484/it-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666484/it-nachrichten/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai/</guid>
<pubDate>Mon, 13 Jul 2026 23:17:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" target="_blank">the popular platform </a>has thus far lacked. Still, some worry about the risks created by the move. </p>



<p class="wp-block-paragraph">“Our ambition is for OpenClaw to be the Switzerland of AI. Neutral ground where every model and every lab can plug into the technology and collaborate on standards in the era of agents,” <a href="https://openclaw.ai/blog/introducing-openclaw-foundation/" target="_blank" rel="noreferrer noopener">OpenClaw said in a post</a>. “That work is already underway in Foundation-convened councils on agent identity, agent profiles, evals, and enterprise deployment.”</p>



<p class="wp-block-paragraph">The statement, co-authored by OpenClaw creator <a href="https://www.linkedin.com/in/steipete/" target="_blank" rel="noreferrer noopener">Peter Steinberger</a>, pointed out, “the great open source projects of our time — Linux, Apache, Mozilla — endure because a neutral steward stands behind them. That is the role we are taking on to keep OpenClaw MIT licensed, open, and independent so that everyone building on it can trust it will be here for the long term.”</p>



<p class="wp-block-paragraph">But it reassured users that the original OpenClaw leadership is still in charge.</p>



<p class="wp-block-paragraph">“Peter built this thing and Peter keeps making the calls, especially the technical ones. Since joining OpenAI earlier this year, he has continued to steward OpenClaw as an open and independent project, and OpenAI has made a commitment to keep it that way,” the post said. “The foundation is here to serve: good governance, stable funding, and paying the people who keep the claws alive.”</p>



<p class="wp-block-paragraph">However, some analysts and consultants were skeptical about how much true independence Steinberger would have, given his salaried role with OpenAI. </p>



<h2 class="wp-block-heading">Neutrality claim in question</h2>



<p class="wp-block-paragraph">“The Switzerland of AI neutrality claim collapses under its own announcement,” said <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520. “OpenAI runs a team [at OpenAI] called Claw Labs that Peter leads and OpenAI is a major donor to OpenClaw. The ‘neutral steward’s’ chief technical decision maker is employed by one of the competing labs it is supposed to be neutral with.” To OpenAI, he said, OpenClaw is closer to a tax-exempt nonprofit subsidiary than it is to a neutral ‘Switzerland of AI.’</p>



<p class="wp-block-paragraph">He pointed out that, in addition, Microsoft is shipping <a href="https://www.computerworld.com/article/4173442/enterpriseclaw-wants-to-bring-governance-to-the-openclaw-era-2.html" target="_blank">the enterprise version</a> of OpenClaw, and Nvidia is shipping the hardware bundle. “This is being called the Switzerland of AI, but Switzerland does not have its central bank run by France,” he observed.</p>



<p class="wp-block-paragraph">Kenney said that what the new OpenClaw has actually built is “a shared dependency that several competitors fund, staff, and steer, wrapped in a nonprofit structure. Enterprise IT should understand that structure, because treating OpenClaw as neutral is a mistake,” adding that CIOs need to look at this development devoid of the emotional component. </p>



<p class="wp-block-paragraph">“There is a strategic irony here that CIOs should sit with,” Kenney said. “If OpenClaw succeeds at becoming the universal agent substrate, then every model plugs into the same identity layer, the same profiles, and the same deployment plumbing. The thing every vendor is racing to own becomes a commodity that nobody owns.” He pointed out that, in the short term, that is genuinely good news for buyers because it means less lock-in and more portability.</p>



<p class="wp-block-paragraph">“But,” he said, “when the connective tissue is free and natural, the only labs that benefit are the ones with the best models and the deepest distribution. Commoditize the layer below you and you compete on the layer where you are already strongest. The foundation is not a charity. It is the biggest players agreeing to stop fighting over the plumbing so they can fight over the water, and the enterprise is the one paying the water bill either way.”</p>



<h2 class="wp-block-heading">Good news, bad news</h2>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, liked the potential consistency that could emerge from the structural change, given the complexity of agent development today. </p>



<p class="wp-block-paragraph">“We are seeing a lot of OpenClaw variants hit the market, such as those from Nvidia as well as competing products from cloud and SaaS vendors. A common base helps solidify the common parts,” Andersen noted. “That said, a common challenge is the sustainability of these open source foundations over time. In addition to releasing code, these foundations need funding to evolve and grow. And that funding needs to come from continued momentum to incentivize existing members to increase investment and recruit new members to join.”</p>



<p class="wp-block-paragraph">Andersen stressed that IT buyers need to keep an eye on the roadmap for any OpenClaw variant they choose to deploy, “as that will directly impact the foundation, and the momentum of the foundation and common base. If the common base loses momentum, it can lead to forks, or just a loss of innovation. When that happens, members tend to back away, which puts customers in limbo.”</p>



<p class="wp-block-paragraph">But not everyone sees the promised structure as entirely good for IT.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO at coding productivity tool vendor Kodezi, said, “most CIOs do not want to bet their future entirely on a single model vendor. They want Claude for some workloads, GPT for others, open models for sensitive environments, and potentially internally fine-tuned systems for specific use cases. The problem is that every vendor currently brings its own identity system, tool interfaces, permissions model, and operational assumptions. That fragmentation does not scale.”</p>



<p class="wp-block-paragraph">He said, “the risk if standards fail is straightforward: every vendor builds its own closed ecosystem, enterprises become locked into individual stacks, and security becomes dramatically harder. The opportunity if OpenClaw succeeds is equally significant: enterprises get portable agents, common identity standards, interoperable tooling, and a healthier competitive market around models rather than ecosystems.”</p>



<h2 class="wp-block-heading">Will it remain a nonprofit?</h2>



<p class="wp-block-paragraph">However, said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, one of the key details that IT executives will want to keep in mind is that OpenAI also began as a nonprofit, but it was quickly <a href="https://www.computerworld.com/article/4056490/openai-microsoft-discuss-shape-of-future-relationship.html" target="_blank">seen as not adhering to nonprofit objectives</a>. </p>



<p class="wp-block-paragraph">“OpenAI’s transition from a nonprofit research organization into a more complex structure highlighted the challenge of maintaining mission alignment while scaling technology, capital, partnerships, and commercial operations,” Greis said. “OpenClaw has the opportunity to address some of those governance questions earlier by establishing clear principles around neutrality, transparency, and decision-making before the ecosystem becomes even larger and more valuable.”</p>



<p class="wp-block-paragraph">He noted, “we have seen this pattern before with technologies like Linux and Kubernetes. The strongest open ecosystems succeeded because they created trusted foundations that enterprises could build upon. The technology was important, but the governance model that underpinned it was equally critical.”</p>



<h2 class="wp-block-heading">Risks are ‘squarely in IT’s lap’</h2>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, echoed Greis’ concerns. </p>



<p class="wp-block-paragraph">“CIOs shouldn’t assume that this nonprofit will always be a nonprofit, or confuse being a nonprofit with actually being neutral or unbiased,” he said. “The risks are squarely in IT’s lap: autonomous agents ‘with their own identity’ acting on a user’s behalf blow straight through traditional IAM assumptions. Issues, such as agent identity, auditability, secret handling. Identity boundaries have not yet been reliably solved. Until they are, enterprises should treat OpenClaw agents like privileged service accounts, not like a browser plugin.”</p>



<p class="wp-block-paragraph">Independent cybersecurity and risk advisor <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a> pointed to another IT exposure that might come from this OpenClaw transition: Cost.</p>



<p class="wp-block-paragraph">“OpenClaw currently has a very high token burn rate in usage, which presents a significant cost consideration for large-scale enterprise adoption,” he said. “The skills marketplace introduces <a href="https://www.csoonline.com/article/4129867/what-cisos-need-to-know-about-clawdbot-i-mean-moltbot-i-mean-openclaw.html" target="_blank">a new supply chain threat </a>that enterprises will need to manage. Threat management, and specifically handling <a href="https://www.csoonline.com/article/4135449/compromised-npm-package-silently-installs-openclaw-on-developer-machines.html" target="_blank">external marketplace elements</a>, can be highly challenging for open-source operations. Ultimately, at scale, enterprise adoption could become a difficult balancing act between managing high operational costs and securing an expanded security surface.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 newer data science tools you should be using with Python]]></title>
<description><![CDATA[Python’s rich ecosystem of data science tools is a big draw for users. The only downside of such a broad and deep collection is that sometimes the best tools can get overlooked.



Here’s a rundown of some of the best newer or less-known data science projects available for Python. Some, like Pola...]]></description>
<link>https://tsecurity.de/de/3665680/ai-nachrichten/7-newer-data-science-tools-you-should-be-using-with-python/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665680/ai-nachrichten/7-newer-data-science-tools-you-should-be-using-with-python/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Python’s rich ecosystem of data science tools is a big draw for users. The only downside of such a broad and deep collection is that sometimes the best tools can get overlooked.</p>



<p class="wp-block-paragraph">Here’s a rundown of some of the best newer or less-known data science projects available for <a href="https://www.infoworld.com/article/2254260/how-to-get-started-with-python.html">Python</a>. Some, like Polars, are getting more attention but still deserve wider notice. Others, like ConnectorX, are hidden gems.</p>



<h2 class="wp-block-heading">ConnectorX</h2>



<p class="wp-block-paragraph">Most data sits in a database somewhere, but computation typically happens outside of it. Getting data to and from the database for actual work can be a slowdown. <a href="https://github.com/sfu-db/connector-x">ConnectorX</a> loads data from databases into many common data-wrangling tools in Python, and it keeps things fast by minimizing the work required. Most of the data loading can be done in just a couple of lines of Python code and <a href="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html">an SQL query</a>.</p>



<p class="wp-block-paragraph">Like Polars (which I’ll discuss shortly), ConnectorX uses a <a href="https://www.infoworld.com/article/2258463/rust-tutorial-get-started-with-the-rust-language.html">Rust</a> library at its core. This allows for optimizations like being able to load from a data source in parallel with partitioning. Data in <a href="https://www.infoworld.com/article/3489168/postgresql-tutorial-get-started-with-postgresql-16.html">PostgreSQL</a>, for instance, can be loaded this way by specifying a partition column.</p>



<p class="wp-block-paragraph">Aside from PostgreSQL, ConnectorX also supports reading from MySQL/MariaDB, SQLite, Amazon Redshift, Microsoft SQL Server and Azure SQL, and Oracle. The results can be funneled into a <a href="https://www.infoworld.com/article/2264264/how-to-use-pandas-for-data-analysis-in-python.html">Pandas</a> or PyArrow DataFrame, or into Modin or Dask (via Pandas), or Polars (via PyArrow). General support for reading from ODBC is a work in progress.</p>



<h2 class="wp-block-heading">DuckDB</h2>



<p class="wp-block-paragraph">Data science folks who use Python ought to be aware of <a href="https://www.infoworld.com/article/2337363/why-you-should-use-sqlite-3.html">SQLite</a>—a small, but powerful and speedy relational database packaged with Python. Since it runs as an in-process library, rather than a separate application, SQLite is lightweight and responsive.</p>



<p class="wp-block-paragraph"><a href="https://duckdb.org/">DuckDB</a> is a little like someone answered the question, “<a href="https://www.infoworld.com/article/2336981/duckdb-the-tiny-but-powerful-analytics-database.html">What if we made SQLite for OLAP?</a>” Like other <a href="https://www.infoworld.com/article/2334471/what-is-olap-analytical-databases.html">OLAP</a> database engines, it uses a columnar datastore and is optimized for long-running analytical query workloads. But DuckDB gives you all the things you expect from a conventional database, like ACID transactions. And there’s no separate software suite to configure; you can get it running in a Python environment with a single <code>pip install duckdb</code> command.</p>



<p class="wp-block-paragraph">DuckDB can directly ingest data in CSV, <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON</a>, or <a href="https://www.infoworld.com/article/2336762/exploring-the-apache-ecosystem-for-data-analysis.html">Parquet</a> format, as well as <a href="https://duckdb.org/docs/stable/data/data_sources">a slew of other common data sources</a>. The resulting databases can also be partitioned into multiple physical files for efficiency, based on keys (e.g., by year and month). Querying works like any other <a href="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html">SQL</a>-powered relational database, but with additional built-in features like the ability to take random samples of data or construct window functions.</p>



<p class="wp-block-paragraph">DuckDB also has a small but useful collection of extensions, including full-text search, <a href="https://duckdb.org/docs/stable/core_extensions/vss">accelerated vector similarity search</a>, Excel import/export, direct connections to SQLite and PostgreSQL, Parquet file export, and support for many common geospatial data formats and types.</p>



<h2 class="wp-block-heading">Optimus</h2>



<p class="wp-block-paragraph">One of the least enviable jobs you can be stuck with is cleaning and preparing data for use in a DataFrame-centric project. <a href="https://github.com/hi-primus/optimus">Optimus</a> is an all-in-one tool set for loading, exploring, cleansing, and writing data back out to a variety of data sources.</p>



<p class="wp-block-paragraph">Optimus can use <a href="https://www.infoworld.com/article/2264264/how-to-use-pandas-for-data-analysis-in-python.html">Pandas</a>, Dask, CUDF (and Dask + CUDF), Vaex, or <a href="https://www.infoworld.com/article/2259224/what-is-apache-spark-the-big-data-platform-that-crushed-hadoop.html">Spark</a> as its underlying data engine. Data can be loaded in from and saved back out to Arrow, Parquet, Excel, a variety of common database sources, or flat-file formats like CSV and JSON.</p>



<p class="wp-block-paragraph">The data manipulation API resembles Pandas, but adds <code>.rows()</code> and <code>.cols()</code> accessors to make it easy to do things like sort a DataFrame, filter by column values, alter data according to criteria, or narrow the range of operations based on some criteria. Optimus also comes bundled with processors for handling common real-world data types like email addresses and URLs.</p>



<p class="wp-block-paragraph">One possible issue with Optimus is that it’s still under active development but its last official release was in 2020. This means it might not be as current as other components in your stack.</p>



<h2 class="wp-block-heading">Polars</h2>



<p class="wp-block-paragraph">If you spend much time working with DataFrames and you’re frustrated by the performance limits of <a href="https://www.infoworld.com/article/2264264/how-to-use-pandas-for-data-analysis-in-python.html">Pandas</a>, reach for <a href="https://github.com/pola-rs/polars">Polars</a>. This DataFrame library for Python offers a convenient syntax similar to Pandas.</p>



<p class="wp-block-paragraph">Unlike Pandas, though, Polars uses a library written in <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a> that takes maximum advantage of your hardware out of the box. You don’t need to use special syntax to take advantage of performance-enhancing features like parallel processing or SIMD; it’s all automatic. Even simple operations like reading from a CSV file are faster. Rust developers can <a href="https://github.com/pola-rs/pyo3-polars">craft their own Polars extensions using pyo3</a>.</p>



<p class="wp-block-paragraph">Polars provides eager and lazy execution modes, so queries can be executed immediately or deferred until needed. It also provides a streaming API for processing queries incrementally. Streaming isn’t available yet for many functions, although Polars can always fall back to the in-memory engine for such operations if need be. You can also <a href="https://docs.pola.rs/api/python/stable/reference/lazyframe/api/polars.LazyFrame.show_graph.html">plot execution graphs for queries</a>, streaming or otherwise, if you want to get an idea of what memory or CPU consumption is like for the query (via the external Graphviz library).</p>



<h2 class="wp-block-heading">DVC</h2>



<p class="wp-block-paragraph">A major and pervasive issue with data science experiments is <a href="https://www.infoworld.com/article/2260350/version-control-track-the-who-what-and-when-of-software-changes.html">version control</a>—not of the project’s code, but its data. <a href="https://github.com/iterative/dvc">DVC</a>, short for Data Version Control, lets you attach version descriptors to datasets, check them into Git as you would the rest of your code, and keep versions of data and code consistent together.</p>



<p class="wp-block-paragraph">DVC can track most any kind of dataset as long as they can be expressed as a file, whether kept in local storage or in a <a href="https://dvc.org/doc/user-guide/data-management/remote-storage#supported-storage-types">remote storage service</a> like an Amazon S3 bucket. You can describe how data models are managed and used by way of a “<a href="https://dvc.org/doc/user-guide/data-management/remote-storage#supported-storage-types">pipeline</a>,” which DVC’s documentation describes as being like “a Makefile system for machine learning projects.”</p>



<p class="wp-block-paragraph">The use cases for DVC are intended to be more than just allowing data to be versioned alongside code. It also works as a fast data cache for remotely hosted data, a methodology for tracking experiments conducted with data, and a registry or catalog for <a href="https://www.infoworld.com/article/2254843/what-is-machine-learning-intelligence-derived-from-data.html">machine learning models</a> created with the data. <a href="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html">Visual Studio Code</a> users can integrate DVC workflows into the editor by way of the <a href="https://marketplace.visualstudio.com/items?itemName=Iterative.dvc">DVC VS Code extension</a>.</p>



<h2 class="wp-block-heading">Cleanlab</h2>



<p class="wp-block-paragraph">Good machine learning datasets are hard to come by, because it’s expensive and time-consuming to create clean, properly labeled data. Sometimes, though, you have no choice but to use data that’s raw and inconsistent. <a href="https://github.com/cleanlab/cleanlab">Cleanlab</a> (as in, “cleans labels”) was made for this scenario.</p>



<p class="wp-block-paragraph">Cleanlab uses existing, high-quality machine learning datasets to analyze lower-quality, unlabeled (or poorly labeled) datasets. You create a model based on the original dataset, use Cleanlab to figure out what needs to be improved in the original dataset, then re-train using your automatically cleaned and adjusted dataset to see the difference.</p>



<p class="wp-block-paragraph">Cleanlab is data-model and data-framework agnostic, a powerful aspect of its design. It doesn’t matter if you’re running <a href="https://www.infoworld.com/article/2335194/what-is-pytorch-python-machine-learning-on-gpus.html">PyTorch</a>, OpenAI, scikit-learn, or <a href="https://www.infoworld.com/article/2255099/what-is-tensorflow-the-machine-learning-library-explained.html">Tensorflow</a>; Cleanlab can work with any classifier. It does, however, have specific workflows for common tasks like token classification, multi-labeling, regression, image segmentation and object detection, outlier detection, and so on. It’s worth perusing the <a href="https://github.com/cleanlab/examples">example set</a> to see for yourself how the process works and what results you can expect.</p>



<h2 class="wp-block-heading">Snakemake</h2>



<p class="wp-block-paragraph">Data science workflows are hard to set up, and that’s even harder to do in a consistent, predictable way. <a href="https://github.com/snakemake/snakemake">Snakemake</a> was created to automate the process, setting up data analysis workflows in ways that ensure everyone gets the same results. Many existing data science projects rely on Snakemake. The more moving parts you have in your data science workflow, the more likely you’ll benefit from automating that workflow with Snakemake.</p>



<p class="wp-block-paragraph">Snakemake workflows resemble GNU Make workflows—you define the steps of the workflow with rules, which specify what they take in, what they put out, and what commands to execute to accomplish that. Workflow rules can be multithreaded (assuming that gives them any benefit), and configuration data can be piped in from <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON</a> or <a href="https://www.infoworld.com/article/2336307/7-yaml-gotchas-to-avoidand-how-to-avoid-them.html">YAML</a> files. You can also define functions in your workflows to transform data used in rules, and write the actions taken at each step to logs.</p>



<p class="wp-block-paragraph">Snakemake jobs are designed to be portable—they can be deployed on any <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes-managed environment</a>, or in specific cloud environments like Google Cloud Life Sciences or Tibanna on AWS. Workflows can be “frozen” to use a specific set of packages, and successfully executed workflows can have unit tests automatically generated and stored with them. And for long-term archiving, you can store the workflow as a tarball.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s the Go language really good for?]]></title>
<description><![CDATA[Over its more than 15 years in the wild, Google’s Go programming language has evolved from a curiosity for alpha geeks to the battle-tested programming language behind some of the world’s most important cloud-native software projects.



If you’ve ever wondered why Go is the language of choice fo...]]></description>
<link>https://tsecurity.de/de/3665677/ai-nachrichten/whats-the-go-language-really-good-for/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665677/ai-nachrichten/whats-the-go-language-really-good-for/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:43 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over its more than 15 years in the wild, Google’s <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">Go programming language</a> has evolved from a curiosity for alpha geeks to the battle-tested programming language behind some of the world’s most important <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> software projects.</p>



<p class="wp-block-paragraph">If you’ve ever wondered why Go is the language of choice for projects like <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a> and <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a>, this article is for you. We’ll discuss Go’s defining characteristics and how it differs from other programming languages. You will also learn what kinds of projects Go is best suited for, including the state of <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">Go development for AI-powered tools</a>. We’ll conclude with an overview of Go’s feature set, some limitations of the language, and where it may be going from here.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">Golang tutorial: Get started with the Go language</a>.</strong></p>



<h2 class="wp-block-heading">Go is small and simple</h2>



<p class="wp-block-paragraph">Go, or <a href="https://go.dev/doc/faq#go_or_golang">Golang</a> as it’s often called, was created by Google employees—chiefly longtime Unix guru and Google distinguished engineer Rob Pike—but it’s not strictly speaking a “Google project.” Rather, Go is a community-developed <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source</a> project, spearheaded by leadership with strong opinions about how Go should be used and the direction the language should take.</p>



<p class="wp-block-paragraph">Go is meant to be easy to learn and straightforward to use, with syntax that is simple to read and understand. Go does not have a large feature set, especially when compared to languages like <a href="https://www.infoworld.com/article/2338049/c-23-language-standard-declared-feature-complete.html">C++</a>. Go’s syntax is reminiscent of <a href="https://www.infoworld.com/article/2261151/why-the-c-programming-language-still-rules.html">C</a>, making it relatively easy for longtime C developers to learn. That said, many features of Go, especially its <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">concurrency and functional programming features</a>, harken back to languages like Erlang.</p>



<p class="wp-block-paragraph">As a C-like language for building and maintaining cross-platform enterprise applications of all sorts, <a href="https://www.infoworld.com/article/2514123/8-reasons-developers-love-go-and-8-reasons-they-dont.html">Go has much in common with Java</a>. And as a means for enabling rapid development of code that might run anywhere, you could draw a parallel between Go and <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html">Python</a>, though the differences outweigh the similarities.</p>



<p class="wp-block-paragraph">The <a href="https://go.dev/doc">Go documentation</a> describes Go as “a fast, statically typed, compiled language that feels like a dynamically typed, interpreted language.” Even a large Go program will compile in a matter of seconds. Plus, Go avoids much of the overhead of C-style include files and libraries.</p>



<h2 class="wp-block-heading">Advantages of the Go language</h2>



<p class="wp-block-paragraph">Go is a versatile, convenient, fast, portable, interoperable, and widely supported modern language. These characteristics have helped to make it a top choice for large-scale development projects. Let’s look more closely at each of these positive qualities of Go.</p>



<h3 class="wp-block-heading">Go is versatile and convenient</h3>



<p class="wp-block-paragraph">Go has been compared to interpreted languages like <a href="https://www.infoworld.com/article/2254260/how-to-get-started-with-python.html">Python</a> in its ability to satisfy many common programming needs. Some of this functionality is built into the language itself, such as goroutines for concurrency and thread-like behavior, while additional capabilities are available in Go standard library packages, like the <a href="https://golang.org/pkg/net/http/">http package</a>. Like Python, Go provides automatic memory management capabilities including <a href="https://www.infoworld.com/article/2337816/what-is-garbage-collection-automated-memory-management-for-your-programs.html">garbage collection</a>.</p>



<p class="wp-block-paragraph">Unlike interpreted languages, however, Go code compiles to a fast-running native binary. And unlike C or C++, Go compiles extremely fast—fast enough to make working with Go feel more like working with an interpreted language than a compiled one. Further, the Go build system is less complex than those of other compiled languages. It takes few steps and little bookkeeping to build and run a Go project.</p>



<h3 class="wp-block-heading">Go is faster than many other languages</h3>



<p class="wp-block-paragraph">Go binaries run more slowly than their C counterparts, but the difference in speed is negligible for most applications. Go performance is as good as C for the vast majority of work, and generally much faster than other languages known for speed of development—including <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a>, <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html">Python</a>, and <a href="https://www.infoworld.com/article/2337962/whatever-happened-to-ruby.html">Ruby</a>.</p>



<h3 class="wp-block-heading">Go is portable and interoperable</h3>



<p class="wp-block-paragraph">Executables created with the Go toolchain can stand alone, with no default external dependencies. The Go toolchain is available for a wide variety of operating systems and hardware platforms, and can be used to compile binaries across platforms. What’s more, Go delivers all of the above without sacrificing access to the underlying system. Go programs can talk to external C libraries or make native system calls. In <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker</a>, for instance, Go interacts with low-level Linux functions, cgroups, and namespaces to work container magic.</p>



<h3 class="wp-block-heading">Go is widely supported</h3>



<p class="wp-block-paragraph">The Go toolchain is freely available as a Linux, macOS, or Windows binary, or as a Docker container. Go is included by default in many popular Linux distributions, such as Red Hat Enterprise Linux and Fedora, making it somewhat easier to deploy Go source to those platforms. Support for Go is also strong across many third-party development environments, from Microsoft’s <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> to ActiveState’s <a href="https://www.infoworld.com/article/2250631/review-7-python-ides-compared.html">Komodo IDE</a>.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/2514123/8-reasons-developers-love-go-and-8-reasons-they-dont.html">8 reasons developers love Go—and 8 reasons they don’t</a>.</strong></p>



<h2 class="wp-block-heading">Optimal use cases for the Go language</h2>



<p class="wp-block-paragraph">No language is suited to every job, but some languages are suited to more jobs than others. Go shines brightest in cloud-native development projects, distributed network services, and for developing utilities and stand-alone tools. Let’s consider the qualities that make Go especially well-suited to each of these project types.</p>



<h3 class="wp-block-heading">Cloud-native development</h3>



<p class="wp-block-paragraph">Go’s concurrency and networking features, and its high degree of portability, make it well-suited for building cloud-native apps. In fact, Go was used to build several cornerstones of cloud-native computing including <a href="https://www.infoworld.com/article/2253801/what-is-docker-the-spark-for-the-container-revolution.html">Docker</a>, <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-your-next-application-platform.html">Kubernetes</a>, and <a href="https://www.infoworld.com/article/2258313/what-is-istio-the-kubernetes-service-mesh-explained.html">Istio</a>.</p>



<h3 class="wp-block-heading">Distributed network services</h3>



<p class="wp-block-paragraph">Network applications live and die by concurrency, and Go’s native concurrency features—<a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">goroutines</a> and <a href="https://www.infoworld.com/article/2255834/go-tutorial-get-started-with-google-go.html">channels</a>, mainly—are well suited for such work. Consequently, many Go projects are for networking, distributed functions, and cloud services. These include <a href="https://github.com/go-goyave/goyave">APIs</a>, <a href="https://github.com/mholt/caddy">web servers</a>, <a href="https://github.com/claygod/microservice">Kubernetes-ready frameworks for microservices</a>, and much more.</p>



<h3 class="wp-block-heading">Utilities and standalone tools</h3>



<p class="wp-block-paragraph">Go programs compile to binaries with minimal external dependencies. That makes them ideally suited to creating utilities and other tools, because they launch quickly and can be readily packaged up for redistribution. One example is an <a href="https://goteleport.com/">access server called Teleport</a>, which can be deployed on servers quickly by compiling it from source or downloading a prebuilt binary.</p>



<h2 class="wp-block-heading">Limitations of the Go language</h2>



<p class="wp-block-paragraph">Now let’s consider some of the limitations of Go. For one, it omits many language features developers may desire. It also packs everything into its binaries, so Go programs can be large. Furthermore, <a href="https://www.infoworld.com/article/4041753/go-language-previews-performance-boosting-garbage-collector.html">Go’s garbage collection mechanism</a> delivers automatic memory management at the cost of absolute performance. The language also lacks a standard toolkit for building GUIs, and it is unsuited to systems programming.</p>



<p class="wp-block-paragraph">Let’s look at each of these issues in detail.</p>



<h3 class="wp-block-heading">Go omits many desirable language features</h3>



<p class="wp-block-paragraph">Go’s opinionated set of features draws both praise and criticism. Go is designed to err on the side of being small and easy to understand, with certain features deliberately omitted. The result is that some features that are commonplace in other languages simply aren’t available in Go. This is purposeful, but it’s still a drawback for some types of projects.</p>



<p class="wp-block-paragraph">One thing Go omits that you will find in other languages is <em>macros</em>, commonly defined as the ability to generate program code at compile time. C, C++, and (the rising star) <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a> all have macro systems. Go does not have macros, or at least not of the same variety as those languages. What Go does have is a tool command, <code>go generate</code>, which looks for magic comments in Go source and executes them. This can be used to generate Go source code, or even run other commands, but its main use is to programmatically generate code, usually as a precursor to the build process. (Technical blogger Eli Bendersky <a href="https://eli.thegreenplace.net/2021/a-comprehensive-guide-to-go-generate/">explains the ‘go generate’ command in detail</a>.)</p>



<p class="wp-block-paragraph">Another longstanding complaint with Go was, until recently, the lack of generic functions, which allow a function to accept many different types of variables. Go’s development team held out against adding generics to the language for many years because they wanted a syntax and set of behaviors that complemented the rest of Go. But as of <a href="https://tip.golang.org/doc/go1.18">Go 1.18</a>, released in early 2022, the language <a href="https://www.infoworld.com/article/2271612/get-started-with-generics-in-go.html">includes a syntax for generics</a>. Because <code>go generate</code> and its code-generation abilities emerged as one possible way to partially address the lack of generics, this functionality is no longer as commonly used in Go.</p>



<p class="wp-block-paragraph">The fact is that Go adds major language features rarely, and only after much consideration. This works to preserve broad compatibility across versions, but it comes at the cost of slower innovation.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3849417/what-you-need-to-know-about-go-rust-and-zig.html">What you need to know about Go, Rust, and Zig</a>.</strong></p>



<h3 class="wp-block-heading">Go’s binaries are large</h3>



<p class="wp-block-paragraph">Another potential downside to Go is the size of the generated binaries. Go binaries are statically compiled by default, meaning that everything needed at runtime is included in the binary image. This approach simplifies the build and deployment process, but at the cost of a simple “Hello, world!” weighing in at around 1.5MB on 64-bit Windows. The Go team has been <a href="https://blog.golang.org/go1.7-binary-size">working to reduce the size of those binaries</a> with each successive release. It is also possible to <a href="https://blog.filippo.io/shrink-your-go-binaries-with-this-one-weird-trick/">shrink Go binaries with compression</a> or by <a href="https://jamescun.com/golang/binary-size/">removing Go’s debug information</a>. This last option may work better for standalone distributed apps than for cloud or network services, where having debug information is useful if a service fails in place.</p>



<h3 class="wp-block-heading">Go’s garbage collection is resource hungry</h3>



<p class="wp-block-paragraph">Yet another touted feature of Go, automatic memory management, can be seen as a drawback, as garbage collection requires a certain amount of processing overhead. By design, Go <a href="https://golang.org/doc/faq#garbage_collection">doesn’t provide manual memory management</a>, and garbage collection in Go has been criticized for not dealing well with the kinds of memory loads that appear in enterprise applications.</p>



<p class="wp-block-paragraph">That said, each new version of Go seems to improve the memory management features. For example, Go 1.8 brought <a href="https://golang.org/doc/go1.8#gc">significantly shorter lag times for garbage collection</a>, and <a href="https://www.infoworld.com/article/4041753/go-language-previews-performance-boosting-garbage-collector.html">Go 1.25</a> introduced a new, experimental garbage collector. While Go developers can use manual memory allocation in a C extension, or by way of a <a href="https://github.com/joetifa2003/mm-go">third-party manual memory management library</a>, most prefer native solutions.</p>



<h3 class="wp-block-heading">Go doesn’t have a standard GUI toolkit</h3>



<p class="wp-block-paragraph">Most Go applications are command-line tools or network services. That said, various projects are working to bring rich GUIs for Go applications. There are bindings for the <a href="https://mattn.github.io/go-gtk/">GTK</a> and <a href="https://github.com/gotk3/gotk3">GTK3</a> frameworks. Another project is intended to provide <a href="https://github.com/richardwilkes/unison">platform-native UIs</a> across platforms, although it focuses on Go 1.24 forward only. But no clear winner or safe long-term bet has emerged in this space. Also, because Go is platform-independent by design, it is unlikely any project in this vein will become a part of the standard package set.</p>



<h3 class="wp-block-heading">You shouldn’t use Go for systems programming</h3>



<p class="wp-block-paragraph">Finally, although Go can talk to native system functions, it was not designed for developing low-level system components such as kernels, device drivers, or embedded systems. After all, the Go runtime and the garbage collector for Go applications are dependent on the underlying operating system. (Developers interested in a cutting-edge language for that kind of work might look into using <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a>.)</p>



<h2 class="wp-block-heading">The future of the Go language</h2>



<p class="wp-block-paragraph">Go’s development is turning more toward the wants and needs of its developer base, with Go’s minders changing the language to better accommodate this audience rather than leading by stubborn example. A case in point is generics, which were finally added to the language after much deliberation about the best way to do so.</p>



<p class="wp-block-paragraph">The <a href="https://www.infoworld.com/article/2336812/go-language-shines-for-ai-powered-workloads-survey-says.html">2024 Go Developer Survey</a> found developers were overall satisfied with Go. Challenges that surfaced were generally due to the verbosity of error handling, missing or immature frameworks, and using Go’s type system—areas ripe for future development.</p>



<p class="wp-block-paragraph">Like most languages, Go has gravitated to a core set of use cases over time, finding its niche in network services. In the future, Go is likely to continue expanding its hold there. Other use cases cited in the developer survey include creating APIs or RPC services (74% of respondents), followed by CLI applications (63%), web services (45%), libraries/frameworks (44%), automation (39%), and data processing (37%). While only 4% of respondents mentioned using Go to develop <a href="https://www.infoworld.com/artificial-intelligence/">AI technologies</a>, those who did reported that <a href="https://www.infoworld.com/article/2336812/go-language-shines-for-ai-powered-workloads-survey-says.html">Go was a strong platform for running AI-powered workloads in production</a>. For those wanting to develop ML/AI with Go, lack of tooling (23%) and the fact that Python is the default choice for such work (16%) topped the reasons why.</p>



<p class="wp-block-paragraph">It remains to be seen how far Go’s speed and development simplicity will take it into other use cases, especially those dominated by other languages and their existing use cases. Rust covers <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">safe and fast systems programming</a> (a space Go is unlikely to enter); Python is still a common default for <a href="https://www.infoworld.com/article/2253770/what-is-python-powerful-intuitive-programming.html">ML/AI, prototyping, automation, and glue code</a>; and Java remains a stalwart for <a href="https://www.infoworld.com/java">enterprise applications</a>.</p>



<p class="wp-block-paragraph">But Go’s future as a major programming language is already assured—certainly in the cloud, where the speed and simplicity of Go ease the development of scalable infrastructure that can be maintained over the long run.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3607388/go-language-evolving-for-future-hardware-ai-workloads.html">Go language evolving for future hardware, AI workloads</a>.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unit testing Spring MVC applications with JUnit 5]]></title>
<description><![CDATA[Spring is a reliable and popular framework for building web and enterprise Java applications. In this article, you’ll learn how to unit test each layer of a Spring MVC application, using built-in testing tools from JUnit 5 and Spring to mock each component’s dependencies. In addition to unit test...]]></description>
<link>https://tsecurity.de/de/3665676/ai-nachrichten/unit-testing-spring-mvc-applications-with-junit-5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665676/ai-nachrichten/unit-testing-spring-mvc-applications-with-junit-5/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html" data-type="link" data-id="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html">Spring</a> is a reliable and popular framework for building web and enterprise <a href="https://www.infoworld.com/java/">Java</a> applications. In this article, you’ll learn how to unit test each layer of a Spring MVC application, using built-in testing tools from <a href="https://www.infoworld.com/article/3993538/how-to-test-your-java-applications-with-junit-5.html">JUnit 5</a> and Spring to mock each component’s dependencies. In addition to unit testing with MockMvc, Mockito, and Spring’s <code>TestEntityManager</code>, I’ll also briefly introduce slice testing using the <code>@WebMvcTest</code> and <code>@DataJpaTest</code> annotations, used to optimize unit tests on web controllers and databases.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3993538/how-to-test-your-java-applications-with-junit-5.html">How to test your Java applications with JUnit 5</a>.</strong></p>



<h2 class="wp-block-heading">Overview of testing Spring MVC applications</h2>



<p class="wp-block-paragraph">Spring MVC applications are defined using three technology layers:</p>



<ul class="wp-block-list">
<li><em>Controllers</em> accept web requests and return web responses.</li>



<li><em>Services</em> implement the application’s business logic.</li>



<li><em>Repositories</em> persist data to and from your back-end <a href="https://www.infoworld.com/article/2337457/sql-at-50-whats-next-for-the-structured-query-language.html">SQL</a> or <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a> database.</li>
</ul>



<p class="wp-block-paragraph">When we unit test Spring MVC applications, we test each layer separately from the others. We create mock implementations, typically using <a href="https://site.mockito.org/">Mockito</a>, for each layer’s dependencies, then we simulate the logic we want to test. For example, a controller may call a service to retrieve a list of objects. When testing the controller, we create a mock service that either returns the list of objects, returns an empty list, or throws an exception. This test ensures the controller behaves correctly.</p>



<p class="wp-block-paragraph">We’ll use Spring MVC to build and test a simple web service that manages widgets. The structure of the web service is shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/TestingSpringMVC-fig1.png?w=1024" alt="Diagram of a Spring MVC web service application." class="wp-image-4078126" width="1024" height="286" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Steven Haines</p></div>



<p class="wp-block-paragraph">This is a classic MVC pattern. We have a <em>widget controller</em> that handles <a href="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html">RESTful requests</a> and delegates its business functionality to a <em>widget service</em>, which uses a <em>widget repository</em> to persist widgets to and from an in-memory H2 database.</p>



<p class="wp-block-paragraph"><strong>Get the source: <a href="https://b2b-contenthub.com/wp-content/uploads/2025/10/spring-mvc-unit-testing-iw.zip" data-type="link" data-id="https://b2b-contenthub.com/wp-content/uploads/2025/10/spring-mvc-unit-testing-iw.zip">Download the source code for this article</a>.</strong></p>



<h2 class="wp-block-heading">Unit testing a Spring MVC controller with MockMvc</h2>



<p class="wp-block-paragraph">Setting up a Spring MVC controller test is a two-step process:</p>



<ul class="wp-block-list">
<li>Annotate your test class with <code>@WebMvcTest</code>.</li>



<li>Autowire a <code>MockMvc</code> instance into your controller.</li>
</ul>



<p class="wp-block-paragraph">We could annotate all our test classes with <code>@SpringBootTest</code>, but we’ll use <code>@WebMvcTest</code> instead. The reason is that the <code>@WebMvcTest</code> annotation is used for <em>slice testing</em>. Whereas <code>@SpringBootTest</code> loads your entire Spring application context, <code>@WebMvcTest</code> loads only your web-related resources. Furthermore, if you specify a controller class in the annotation, it will only load the specific controller you want to test. Testing a single “slice” of your application reduces both the amount of compute resources required to set up the test and the time required to run a test.</p>



<p class="wp-block-paragraph">For example, when we test a controller, we’ll mock just the services it uses, and we won’t need any repositories at all. If we don’t need them, then we needn’t waste time loading them. Slice tests were created to make tests perform better and run faster.</p>



<p class="wp-block-paragraph">Here’s the source code for the <code>Widget</code> class we’ll be managing:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.model;
import jakarta.persistence.Entity;
import jakarta.persistence.GeneratedValue;
import jakarta.persistence.GenerationType;
import jakarta.persistence.Id;

@Entity
public class Widget {
    @Id
    @GeneratedValue(strategy = GenerationType.AUTO)
    private Long id;
    private String name;
    private int version;

    public Widget() {
    }

    public Widget(String name) {
        this.name = name;
    }

    public Widget(String name, int version) {
        this.name = name;
        this.version = version;
    }

    public Widget(Long id, String name, int version) {
        this.id = id;
        this.name = name;
        this.version = version;
    }

    public Long getId() {
        return id;
    }

    public void setId(Long id) {
        this.id = id;
    }

    public String getName() {
        return name;
    }

    public void setName(String name) {
        this.name = name;
    }

    public int getVersion() {
        return version;
    }

    public void setVersion(int version) {
        this.version = version;
    }
}</code></pre>



<p class="wp-block-paragraph">A <code>Widget</code> is a <a href="https://www.infoworld.com/article/2259807/what-is-jpa-introduction-to-the-java-persistence-api.html">JPA entity</a> that manages three fields:</p>



<ul class="wp-block-list">
<li><em>id</em> is the primary key of the table, annotated with <code>@Id</code> and <code>@GeneratedValue</code>, with an automatic generation strategy.</li>



<li><em>name</em> is the name of the widget.</li>



<li><em>version</em> is the version of the widget resource. We’ll use this value to populate our <code>eTag</code> value and check it in our <code>PUT</code> operation’s <code>If-Match </code>header value. This ensures the widget being updated is not stale.</li>
</ul>



<p class="wp-block-paragraph">Here’s the source code for the controller we’ll be testing (<code>WidgetController.java</code>):</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.web;

import java.net.URI;
import java.net.URISyntaxException;
import java.util.List;
import java.util.Optional;
import com.infoworld.widgetservice.model.Widget;
import com.infoworld.widgetservice.service.WidgetService;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.http.HttpStatus;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.DeleteMapping;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PathVariable;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.PutMapping;
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestHeader;
import org.springframework.web.bind.annotation.RestController;

@RestController
public class WidgetController {
    @Autowired
    private WidgetService widgetService;
    @GetMapping("/widget/{id}")
    public ResponseEntity getWidget(@PathVariable Long id) {
        return widgetService.findById(id)
                .map(widget -&gt; {
                    try {
                        return ResponseEntity
                                .ok()
                                .location(new URI("/widget/" + id))
                                .eTag(Integer.toString(
                                               widget.getVersion()))
                                .body(widget);
                    } catch (URISyntaxException e) {
                        return ResponseEntity
                          .status(HttpStatus.INTERNAL_SERVER_ERROR)
                          .build();
                    }
                })
                .orElse(ResponseEntity.notFound().build());
    }
    @GetMapping("/widgets")
    public List getWidgets() {
        return widgetService.findAll();
    }
    @PostMapping("/widgets")
    public ResponseEntity createWidget(@RequestBody Widget widget)
    {
        Widget newWidget = widgetService.create(widget);
        try {
           return ResponseEntity
                   .created(new URI("/widget/" + newWidget.getId()))
                   .eTag(Integer.toString(newWidget.getVersion()))
                   .body(newWidget);
        } catch (URISyntaxException e) {
            return ResponseEntity
                    .status(HttpStatus.INTERNAL_SERVER_ERROR)
                    .build();
        }
    }

    @PutMapping("/widget/{id}")
    public ResponseEntity updateWidget(@PathVariable Long id,
                                          @RequestBody Widget widget,
                         @RequestHeader("If-Match") Integer ifMatch) {
        Optional existingWidget = widgetService.findById(id);
        return existingWidget.map(w -&gt; {
            if (w.getVersion() != ifMatch) {
                return ResponseEntity.status(HttpStatus.CONFLICT)
                                     .build();
            }

            w.setName(widget.getName());
            w.setVersion(w.getVersion() + 1);

            Widget updatedWidget = widgetService.save(w);
            try {
                return ResponseEntity.ok()
                        .location(new URI("/widget/" + 
                                      updatedWidget.getId()))
                        .eTag(Integer.toString(
                                      updatedWidget.getVersion()))
                        .body(updatedWidget);
            } catch (URISyntaxException e) {
                throw new RuntimeException(e);
            }
        }).orElse(ResponseEntity.notFound().build());
    }

    @DeleteMapping("widget/{id}")
    public ResponseEntity deleteWidget(@PathVariable Long id) {
        Optional existingWidget = widgetService.findById(id);
        return existingWidget.map(w -&gt; {
           widgetService.deleteById(w.getId());
           return ResponseEntity.ok().build();
        }).orElse(ResponseEntity.notFound().build());
    }
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetController</code> handles <code>GET</code>, <code>POST</code>, <code>PUT</code>, and <code>DELETE</code> operations, following standard RESTful principles, so we’re going to write tests for each operation.</p>



<p class="wp-block-paragraph">The following source code shows the structure of our test class (<code>WidgetControllerTest.java</code>):</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.web;

@WebMvcTest(WidgetController.class)
public class WidgetControllerTest {
    @Autowired
    private MockMvc mockMvc;

    @MockitoBean
    private WidgetService widgetService;
}</code></pre>



<p class="wp-block-paragraph">I omitted the imports for readability, but the important thing to note is that the class is annotated with the <code>@WebMvcTest</code> annotation, and that we pass in the <code>WidgetController.class</code> as the controller we’re testing. This tells Spring to only load the <code>WidgetController</code> and no other Spring resources. The <code>@WebMvcTest</code> annotation includes other annotations, but the important one for our tests is <code>@AutoConfigureMockMvc</code>, which will cause Spring to create a <code>MockMvc</code> instance and add it to the application context. That lets us autowire it into our test class using the <code>@Autowired</code> annotation.</p>



<p class="wp-block-paragraph">Next, we use the <code>@MockitoBean</code> annotation to use Mockito to create a mock implementation of the <code>WidgetService</code>, after which Spring will autowire it into the <code>WidgetController</code> class. This lets us control the behavior of the <code>WidgetService</code> for the <code>WidgetController</code> test cases we’re writing. Note that starting in Spring Boot version 3.4, <code>@MockitoBean</code> replaced <code>@MockBean</code>. Everything you know about <code>@MockBean</code> translates to using <code>@MockitoBean</code>—with some improvements.</p>



<h3 class="wp-block-heading">Unit testing GET /widgets</h3>



<p class="wp-block-paragraph">Let’s start with the easiest test case, a test for <code>GET /widgets</code>:</p>



<pre class="wp-block-code"><code>@Test
void testGetWidgets() throws Exception {
    List widgets = new ArrayList();
    widgets.add(new Widget(1L, "Widget 1", 1));
    widgets.add(new Widget(2L, "Widget 2", 1));
    widgets.add(new Widget(3L, "Widget 3", 1));

    when(widgetService.findAll()).thenReturn(widgets);

    mockMvc.perform(get("/widgets"))
            .andExpect(status().isOk())
            .andExpect(jsonPath("$.length()").value(3))
            .andExpect(jsonPath("$[0].id").value(1L))
            .andExpect(jsonPath("$[0].name").value("Widget 1"))
            .andExpect(jsonPath("$[0].version").value(1));
};</code></pre>



<p class="wp-block-paragraph">The <code>testGetWidgets()</code> method creates a list of three widgets and then configures the mock <code>WidgetService</code> to return the list when its <code>findAll()</code> method is called. The <code>WidgetControllerTest</code> class statically imports the <code>org.mockito.Mockito.when()</code> method that accepts a method call, which in this case is <code>widgetService.findAll()</code>, and returns a Mockito <code>OngoingStubbing</code> instance. This <code>OngoingStubbing</code> instance exposes methods like <code>thenReturn()</code>, <code>thenThrow()</code>, <code>thenCallRealMethod()</code>, <code>thenAnswer()</code>, and <code>then()</code>.</p>



<p class="wp-block-paragraph">Here, we use the <code>thenReturn()</code> method to tell Mockito to return the list of widgets when the <code>WidgetService</code>’s <code>findAll()</code> method is called. The <code>@MockitoBean</code> annotation causes the mock <code>WidgetService</code> to be autowired into the <code>WidgetController</code>. So, when the <code>getWidgets()</code> method is called in response to a <code>GET /widgets</code>, it calls the <code>WidgetService</code>’s <code>findAll()</code> method and returns our list of widgets as a web response.</p>



<p class="wp-block-paragraph">Next, we use <code>MockMvc</code>’s <code>perform()</code> method to execute a web request. This diagram shows the various classes that interact with the  <code>perform()</code> method:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/TestingSpringMVC-fig2.png?w=1024" alt="Diagram of classes that interact with the MockMvc perform() method." class="wp-image-4078130" width="1024" height="439" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Steven Haines</p></div>



<p class="wp-block-paragraph">The <code>perform()</code> method accepts a <code>RequestBuilder</code>. Spring defines several built-in <code>RequestBuilder</code>s that we can statically import into our tests, including <code>get()</code>, <code>post()</code>, <code>put()</code>, and <code>delete()</code>. The <code>perform()</code> method returns a <code>ResultActions</code> instance that exposes methods such as <code>andExpect()</code>, <code>andExpectAll()</code>, <code>andDo()</code>, and <code>andReturn()</code>. Here, we invoke the <code>andExpect()</code> method, which accepts a <code>ResultMatcher</code>. </p>



<p class="wp-block-paragraph">A <code>ResultMatcher</code> defines a<code> match()</code> method that throws an <code>AssertionError</code> if the assertion fails. Spring defines several <code>ResultMatcher</code>s that we can statically import:</p>



<ul class="wp-block-list">
<li><code>status()</code> allows us to check the HTTP status code of response.</li>



<li><code>content()</code> allows us to check the content headers of the response, such as <code>Content-Type</code>.</li>



<li><code>header()</code> allows us to check any of the HTTP header values.</li>



<li><code>jsonPath()</code> allows us to inspect the contents of a <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html" data-type="link" data-id="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON document</a>.</li>
</ul>



<p class="wp-block-paragraph">After MockMvc performs a <code>GET to /widgets</code>, we expect the HTTP status code to be <code>200 OK</code>.  We can then use the <code>jsonPath</code> matcher to check the body results, using the following JSON path expressions:</p>



<ul class="wp-block-list">
<li><code>$.length()</code>: The <code>$</code> references the root of the JSON document. If the response is a list, then we can call the <code>length()</code> method to get the number of elements in the list.</li>



<li><code>$[0].id</code>: JSON path expressions for a list use an array syntax starting at 0. This expression gets the ID of the first element in the list.</li>



<li><code>$[0].name</code>: This expression gets the name of the first element and compares it to “<code>Widget 1</code>”.</li>



<li><code>$[0].version</code>: This expression gets the version of the first element and compares it to 1.</li>
</ul>



<h3 class="wp-block-heading">Unit testing the GET /widget/{id} handler</h3>



<p class="wp-block-paragraph">Here’s the source code to test the <code>GET /coffee/{id}</code> widget:</p>



<pre class="wp-block-code"><code>@Test
void testGetWidgetById() throws Exception {
    Widget widget = new Widget(1L, "My Widget", 1);          
    when(widgetService.findById(1L))
           .thenReturn(Optional.of(widget));

    mockMvc.perform(get("/widget/{id}", 1))
            // Validate that we get a 200 OK Response Code
            .andExpect(status().isOk())

            // Validate Headers
            .andExpect(content()
                      .contentType(MediaType.APPLICATION_JSON))
            .andExpect(header().string(HttpHeaders.LOCATION,
                                       "/widget/1"))
            .andExpect(header().string(HttpHeaders.ETAG, "\"1\""))

            // Validate content
            .andExpect(jsonPath("$.id").value(1L))
            .andExpect(jsonPath("$.name").value("My Widget"))
            .andExpect(jsonPath("$.version").value(1));
 }</code></pre>



<p class="wp-block-paragraph">This test method is very similar to the <code>testGetWidgets()</code> method, but with some notable changes:</p>



<ul class="wp-block-list">
<li>The <code>GET</code> URI is defined using a URI template. You can specify any number of variables enclosed in braces in the URI template and then send a list of arguments that will replace those variables in the order they appear in the template.</li>



<li>We check that the returned <code>Content-Type</code> is <code>“application/json”</code>, which is a constant in the <code>MediaType</code> class. We access the content using the <code>content()</code> method, which returns a <code>ContentResultMatchers</code> instance that provides various methods, including <code>contentType()</code>, which allows us to validate the content headers.</li>



<li>We check for specific header values using the <code>header()</code> method. The <code>header()</code> method returns a <code>HeadersResultMatchers</code> instance, which can check for header <code>String</code>, <code>long</code>, and <code>date</code> values, as well as checking to see whether or not specific headers exist. In this case, we use constants defined in the <code>HttpHeaders</code> class to check the <code>location</code> and <code>eTag</code> header values.</li>



<li>We check the body of the response using JSON path expressions. In this case, we do not have a list of objects, so we can access the individual fields in the JSON document directly. For example, <code>$.id</code> retrieves the <code>id</code> field value in the root of the document.</li>
</ul>



<h3 class="wp-block-heading">Unit testing a GET /widget/{id} Not Found code</h3>



<p class="wp-block-paragraph">Next, we test the <code>GET /widget/{id}</code>, passing it an invalid ID so that it returns a 404 Not Found response code:</p>



<pre class="wp-block-code"><code>@Test
void testGetWidgetByIdNotFound() throws Exception {
   when(widgetService.findById(1L)).thenReturn(Optional.empty());

   mockMvc.perform(get("/widget/{id}", 1))
            // Validate that we get a 404 Not Found Response Code
            .andExpect(status().isNotFound());
}</code></pre>



<p class="wp-block-paragraph">The <code>testGetWidgetByIdNotFound()</code> method configures the mock <code>WidgetService</code> to return <code>Optional.empty()</code> when its <code>findById()</code> is called with a value of 1. We then perform a <code>GET</code> request to <code>/widget/1</code>, then assert that the returned HTTP status code is 404 Not Found.</p>



<h3 class="wp-block-heading">Unit testing POST /widgets</h3>



<p class="wp-block-paragraph">Here’s how to test a <code>Widget</code> creation:</p>



<pre class="wp-block-code"><code>@Test
void testCreateWidget() throws Exception {
    Widget widget = new Widget(1L, "Widget 1", 1);
    when(widgetService.create(any())).thenReturn(widget);

    mockMvc.perform(post("/widgets")
            .contentType(MediaType.APPLICATION_JSON)
            .content("{\"name\": \"Widget 1\"}"))

            // Validate that we get a 201 Created Response Code
            .andExpect(status().isCreated())

            // Validate Headers
            .andExpect(content().contentType(
                                      MediaType.APPLICATION_JSON))
            .andExpect(header().string(HttpHeaders.LOCATION, 
                                       "/widget/1"))
            .andExpect(header().string(HttpHeaders.ETAG, "\"1\""))

            // Validate content
            .andExpect(jsonPath("$.id").value(1L))
            .andExpect(jsonPath("$.name").value("Widget 1"))
            .andExpect(jsonPath("$.version").value(1));</code></pre>



<p class="wp-block-paragraph">The <code>testCreateWidget()</code> method first creates a <code>Widget</code> to return when the <code>WidgetService</code>’s <code>create()</code> method is called with any argument. The <code>any()</code> matcher matches any argument and, because the <code>createWidget()</code> handler will create a new <code>Widget</code> instance, we will not have access to that instance when the test runs. We then invoke MockMvc’s <code>perform()</code> method to the <code>”/widgets”</code> URI, sending the content body of a new widget named <code>“Widget 1”</code>, using the <code>content()</code> method. We expect a 201 Created HTTP response code, an “<code>application/json</code>” content type, a location header of “<code>/widget/1</code>”, and an <code>eTag</code> value of the <code>String</code> “<code>1</code>”. The body of the response should match the <code>Widget</code> we returned from the <code>create()</code> method, namely an ID of 1, a name of “Widget 1”, and a version of 1.</p>



<h3 class="wp-block-heading">Unit testing PUT /widget</h3>



<p class="wp-block-paragraph">This code runs three tests for the <code>PUT</code> operation:</p>



<pre class="wp-block-code"><code>@Test
public void testSuccessfulUpdate() throws Exception {
    // Create a mock Widget when the WidgetService's findById(1L) 
    // is called
    Widget mockWidget = new Widget(1L, "Widget 1", 5);
    when(widgetService.findById(1L))
                      .thenReturn(Optional.of(mockWidget));

    // Create a mock Coffee that is returned when the 
    // CoffeeController saves the Coffee to the database
    Widget savedWidget = new Widget(1L, "Updated Widget 1", 6);
    when(widgetService.save(any())).thenReturn(savedWidget);

    // Execute a PUT /widget/1 with a matching version: 5
    mockMvc.perform(put("/widget/{id}", 1L)
                    .contentType(MediaType.APPLICATION_JSON)
                    .header(HttpHeaders.IF_MATCH, 5)
                    .content("{\"id\": 1, " +
                             "\"name\": \"Updated Widget 1\"}"))

            // Validate that we get a 200 OK HTTP Response
           .andExpect(status().isOk())

            // Validate the headers
           .andExpect(content()
                        .contentType(MediaType.APPLICATION_JSON))
           .andExpect(header().string(HttpHeaders.LOCATION, 
                                      "/widget/1"))
           .andExpect(header().string(HttpHeaders.ETAG, "\"6\""))

           // Validate the contents of the response
           .andExpect(jsonPath("$.id").value(1L))
           .andExpect(jsonPath("$.name")
                               .value("Updated Widget 1"))
           .andExpect(jsonPath("$.version").value(6));
}

@Test
public void testUpdateConflict() throws Exception {
   // Create a mock coffee with a version set to 5
   Widget mockWidget = new Widget(1L, "Widget 1", 5);

    // Return the mock Coffee when the CoffeeService's 
    // findById(1L) is called
    when(widgetService.findById(1L))
                      .thenReturn(Optional.of(mockWidget));

    // Execute a PUT /widget/1 with a mismatched version number: 2
    mockMvc.perform(put("/widget/{id}", 1L)
                    .contentType(MediaType.APPLICATION_JSON)
                    .header(HttpHeaders.IF_MATCH, 2)
                    .content("{\"id\": 1, " + 
                             "\"name\":  \"Updated Widget 1\"}"))
             // Validate that we get a 409 Conflict HTTP Response
            .andExpect(status().isConflict());
}

@Test
public void testUpdateNotFound() throws Exception {
   // Return the mock Coffee when the CoffeeService's 
   // findById(1L) is called
   when(widgetService.findById(1L)).thenReturn(Optional.empty());

   // Execute a PUT /coffee/1 with a mismatched version number: 2
   mockMvc.perform(put("/widget/{id}", 1L)
                    .contentType(MediaType.APPLICATION_JSON)
                    .header(HttpHeaders.IF_MATCH, 2)
                    .content("{\"id\": 1, " + 
                             "\"name\":  \"Updated Coffee 1\"}"))

           // Validate that we get 404 Not Found
           .andExpect(status().isNotFound());
}</code></pre>



<p class="wp-block-paragraph">We have three variations:</p>



<ul class="wp-block-list">
<li>A successful update.</li>



<li>A failed update because of a version conflict.</li>



<li>A failed update because the widget was not found.</li>
</ul>



<p class="wp-block-paragraph">In RESTful web services, version management is handled by the entity tag, or<code> eTag</code>. When you retrieve an entity, it has an <code>eTag</code> value. When you want to update the entity, you pass that <code>eTag</code> value in the <code>If-Match</code> HTTP header. If the <code>If-Match</code> header does not match the current <code>eTag</code>, which is the <code>Widget</code> version in our implementation, then the <code>PUT</code> handler returns a 409 Conflict HTTP response code. If you get this error, it means that you need to retrieve the entity again and retry your operation. This way, if two different clients attempt to update the same entity simultaneously, only one will succeed.</p>



<p class="wp-block-paragraph">In the <code>testSuccessfulUpdate() </code>method, we return a <code>Widget</code> with a version of 5 when the <code>WidgetService</code>’s <code>findById()</code> method is called. We then pass an <code>If-Match</code> header value of 5 and then validate that we get a 200 OK HTTP response code and the expected header and body values. In the <code>testUpdateConflict()</code> method, we do the same thing, but we set the <code>If-Match</code> header to 2, which does not match 5, so we validate that we get a 409 Conflict HTTP response code. And finally, in the <code>testUpdateNotFound()</code> method, we configure the <code>WidgetService</code> to return an <code>Optional.empty()</code> when its <code>findById()</code> method is called, so we execute the <code>PUT</code> operation and validate that we get a 404 Not Found HTTP response code.</p>



<h3 class="wp-block-heading">Unit testing DELETE /widget</h3>



<p class="wp-block-paragraph">Finally, here is the source code for our two <code>DELETE /widget</code> tests:</p>



<pre class="wp-block-code"><code>@Test
void testDeleteSuccess() throws Exception {
    // Setup mocked product
    Widget mockWidget = new Widget(1L, "Widget 1", 5);

    // Setup the mocked service
    when(widgetService.findById(1L))
                      .thenReturn(Optional.of(mockWidget));
    doNothing().when(widgetService).deleteById(1L);

    // Execute our DELETE request
    mockMvc.perform(delete("/widget/{id}", 1L))
            .andExpect(status().isOk());
}

@Test
void testDeleteNotFound() throws Exception {
    // Setup the mocked service
    when(widgetService.findById(1L)).thenReturn(Optional.empty());

    // Execute our DELETE request
    mockMvc.perform(delete("/widget/{id}", 1L))
            .andExpect(status().isNotFound());
}</code></pre>



<p class="wp-block-paragraph">The <code>DELETE</code> handler first tries to find the widget by ID and then calls the<code> WidgetService</code>’s <code>deleteById()</code> method. The <code>testDeleteSuccess()</code> method configures the <code>WidgetService</code> to return a mock <code>Widget</code> when the <code>findById()</code> method is called and then configures it to do nothing when the <code>deleteById()</code> method is called. The <code>deleteById()</code> method returns void, so we do not need to mock a response, though we do want to allow the method to be called. We execute the <code>DELETE</code> operation and validate that we receive a 200 OK HTTP response code. The<code> testDeleteNotFound()</code> method configures the <code>WidgetService</code> to return <code>Optional.empty()</code> when its <code>findById()</code> method is called. We execute the <code>DELETE</code> operation and validate that we receive a 404 Not Found HTTP response code.</p>



<p class="wp-block-paragraph">At this point, we have a comprehensive set of tests for all of our controller operations. Let’s continue down our stack and test our service.</p>



<h2 class="wp-block-heading">Unit testing a Spring MVC service</h2>



<p class="wp-block-paragraph">Next, we’ll test a <code>WidgetService</code> class, shown here:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.service;

import java.util.List;
import java.util.Optional;

import com.infoworld.widgetservice.model.Widget;
import com.infoworld.widgetservice.repository.WidgetRepository;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Service;

@Service
public class WidgetService {
    @Autowired
    private WidgetRepository widgetRepository;

    public List findAll() {
        return widgetRepository.findAll();
    }

    public Optional findById(Long id) {
        return widgetRepository.findById(id);
    }

    public Widget create(Widget widget) {
        widget.setVersion(1);
        return widgetRepository.save(widget);
    }

    public Widget save(Widget widget) {
        return widgetRepository.save(widget);
    }

    public void deleteById(Long id) {
        widgetRepository.deleteById(id);
    }
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetService</code> is very simple. It autowires in a <code>WidgetRepository</code> and then delegates almost all its functionality to the <code>WidgetRepository</code>. The only business logic it implements is that it sets the <code>Widget</code> version to 1 in the <code>create()</code> method, when it is persisting a new <code>Widget</code> to the database.</p>



<p class="wp-block-paragraph">While Spring supports slice testing for our controller and (as you’ll soon see) our repository, it doesn’t have a slice testing annotation for our service. We could use the <code>@SpringBootTest</code> annotation, but then Spring would load all the controllers, repositories, and any other Spring resources in our application into the Spring application context. We can avoid by using Mockito directly. </p>



<p class="wp-block-paragraph">Here is the source code for the <code>WidgetServiceTest</code> class:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.service;

import static org.junit.jupiter.api.Assertions.assertEquals;
import static org.junit.jupiter.api.Assertions.assertTrue;
import static org.mockito.Mockito.when;

import java.util.Optional;

import com.infoworld.widgetservice.model.Widget;
import com.infoworld.widgetservice.repository.WidgetRepository;

import org.junit.jupiter.api.Test;
import org.junit.jupiter.api.extension.ExtendWith;
import org.mockito.InjectMocks;
import org.mockito.Mock;
import org.mockito.junit.jupiter.MockitoExtension;

@ExtendWith(MockitoExtension.class)
public class WidgetServiceTest {
    @Mock
    private WidgetRepository repository;

    @InjectMocks
    private WidgetService service;

    @Test
    void testFindById() {
        Widget widget = new Widget(1L, "My Widget", 1);
        when(repository.findById(1L)).thenReturn(Optional.of(widget));

        Optional w = service.findById(1L);
        assertTrue(w.isPresent());
        assertEquals(1L, w.get().getId());
        assertEquals("My Widget", w.get().getName());
        assertEquals(1, w.get().getVersion());
    }
}</code></pre>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html">JUnit 5 supports extensions</a> and Mockito has defined a test extension that we can access through the <code>@ExtendWith</code> annotation. This extension allows Mockito to read our class, find objects to mock, and inject mocks into other classes. The <code>WidgetServiceTest </code>tells Mockito to create a mock <code>WidgetRepository</code>, by annotating it with the <code>@Mock</code> annotation, and then to inject that mock into the <code>WidgetService</code>, using the <code>@InjectMocks</code> annotation. The result is that we have a <code>WidgetService</code> that we can test and it will have a mock <code>WidgetRepository</code> that we can configure for our test cases.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html">Advanced unit testing with JUnit 5, Mockito, and Hamcrest</a>.</strong></p>



<p class="wp-block-paragraph">This is not a comprehensive test, but it should get you started. It has a single method, <code>testFindById()</code>, that demonstrates how to test a service method. It creates a mock <code>Widget</code> instance and then uses the Mockito <code>when()</code> method, just as we used in the controller test, to configure the <code>WidgetRepository</code> to return an <code>Optional</code> of that <code>Widget</code> when its <code>findById()</code> method is called. Then it invokes the <code>WidgetService</code>’s <code>findById()</code> method and validates that the mock <code>Widget</code> is returned.</p>



<h2 class="wp-block-heading">Slice testing a Spring Data JPA repository</h2>



<p class="wp-block-paragraph">Next, we’ll slice test our JPA repository (<code>WidgetRepository.java</code>), shown here:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.repository;

import java.util.List;
import com.infoworld.widgetservice.model.Widget;
import org.springframework.data.jpa.repository.JpaRepository;

public interface WidgetRepository extends JpaRepository {
    List findByName(String name);
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetRepository</code> is a Spring Data JPA repository, which means that we define the interface and Spring generates the implementation. It extends the <code>JpaRepository</code> interface, which accepts two arguments:</p>



<ul class="wp-block-list">
<li>The type of entity that it persists, namely a <code>Widget</code>.</li>



<li>The type of primary key, which in this case is a <code>Long</code>.</li>
</ul>



<p class="wp-block-paragraph">It generates common CRUD method implementations for us to create, update, delete, and find widgets, and then we can define our own query methods using a specific naming convention. For example, we define a <code>findByName()</code> method that returns a <code>List</code> of <code>Widget</code>s. Because “<code>name</code>” is a field in our <code>Widget</code> entity, Spring will generate a query that finds all widgets with the specified name.</p>



<p class="wp-block-paragraph">Here is our <code>WidgetRepositoryTest</code> class:</p>



<pre class="wp-block-code"><code>package com.infoworld.widgetservice.repository;

import static org.junit.jupiter.api.Assertions.assertEquals;
import static org.junit.jupiter.api.Assertions.assertNotNull;
import static org.junit.jupiter.api.Assertions.assertNull;

import java.util.ArrayList;
import java.util.Arrays;
import java.util.List;

import com.infoworld.widgetservice.model.Widget;

import org.junit.jupiter.api.AfterEach;
import org.junit.jupiter.api.BeforeEach;
import org.junit.jupiter.api.Test;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.test.autoconfigure.orm.jpa.DataJpaTest;
import org.springframework.boot.test.autoconfigure.orm.jpa.TestEntityManager;

@DataJpaTest
public class WidgetRepositoryTest {
    @Autowired
    private TestEntityManager entityManager;

    @Autowired
    private WidgetRepository widgetRepository;

    private final List widgetIds = new ArrayList();
    private final List testWidgets = Arrays.asList(
            new Widget("Widget 1", 1),
            new Widget("Widget 2", 1),
            new Widget("Widget 3", 1)
    );

    @BeforeEach
    void setup() {
        testWidgets.forEach(widget -&gt; {
            entityManager.persist(widget);
            widgetIds.add((Long)entityManager.getId(widget));
        });
        entityManager.flush();
    }

    @AfterEach
    void teardown() {
        widgetIds.forEach(id -&gt; {
            Widget widget = entityManager.find(Widget.class, id);
            if (widget != null) {
                entityManager.remove(widget);
            }
        });
        widgetIds.clear();
    }

    @Test
    void testFindAll() {
        List widgetList = widgetRepository.findAll();
        assertEquals(3, widgetList.size());
    }

    @Test
    void testFindById() {
        Widget widget = widgetRepository.findById(
                               widgetIds.getFirst()).orElse(null);

        assertNotNull(widget);
        assertEquals(widgetIds.getFirst(), widget.getId());
        assertEquals("Widget 1", widget.getName());
        assertEquals(1, widget.getVersion());
    }

    @Test
    void testFindByIdNotFound() {
        Widget widget = widgetRepository.findById(
            widgetIds.getFirst() + testWidgets.size()).orElse(null);
        assertNull(widget);
    }

    @Test
    void testCreateWidget() {
        Widget widget = new Widget("New Widget", 1);
        Widget insertedWidget = widgetRepository.save(widget);

        assertNotNull(insertedWidget);
        assertEquals("New Widget", insertedWidget.getName());
        assertEquals(1, insertedWidget.getVersion());
        widgetIds.add(insertedWidget.getId());
    }

    @Test
    void testFindByName() {
        List found = widgetRepository.findByName("Widget 2");
        assertEquals(1, found.size(), "Expected to find 1 Widget");

        Widget widget = found.getFirst();
        assertEquals("Widget 2", widget.getName());
        assertEquals(1, widget.getVersion());
    }
}</code></pre>



<p class="wp-block-paragraph">The <code>WidgetRepositoryTest</code> class is annotated with the <code>@DataJpaTest</code> annotation, which is a slice-testing annotation that loads repositories and entities into the Spring application context and creates a <code>TestEntityManager</code> that we can autowire into our test class. The <code>TestEntityManager</code> allows us to perform database operations outside of our repository so that we can set up and tear down our test scenarios.</p>



<p class="wp-block-paragraph">In the <code>WidgetRepositoryTest</code> class, we autowire in both our <code>WidgetRepository</code> and <code>TestEntityManager</code>. Then, we define a <code>setup()</code> method that is annotated with JUnit’s <code>@BeforeEach</code> annotation, so it will be executed <em>before</em> each test case runs. Next, we define a <code>teardown()</code> method that is annotated with JUnit’s <code>@AfterEach</code> annotation, so it will be executed <em>after</em> each test completes. The class defines a <code>testWidgets</code> list that contains three test widgets and then the <code>setup()</code> method inserts those into the database using the <code>TestEntityManager</code>’s <code>persist()</code> method. After it inserts each widget, it saves the automatically generated ID so that we can reference it in our tests. Finally, after persisting the widgets, it flushes them to the database by calling the <code>TestEntityManager</code>’s <code>flush()</code> method. The <code>teardown()</code> method iterates over all <code>Widget</code> IDs, finds the <code>Widget</code> using the <code>TestEntityManager</code>’s <code>find()</code> method, and, if it is found, removes it from the database. Finally, it clears the widget ID list so that the<code> setup()</code> method can rebuild it for the next test. (Note that the <code>TestEntityManager</code> removes entities directly; it does not have a <em>remove by ID</em> method, so we first have to find each <code>Widget</code> and then remove them one-by-one.)</p>



<p class="wp-block-paragraph">Even though most of the methods being tested are autogenerated and well tested, I wanted to demonstrate how to write several kinds of tests. The only method that we really need to test is the <code>findByName()</code> method because that is the only custom method we define. For example, if we were to define the method as <code><em>findByNam()</em></code> instead of <code>findByName()</code>, then the method would not work, so it is definitely worth testing.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Spring provides robust support for testing each layer of a Spring MVC application. In this article, we reviewed how to test controllers, using <a href="https://docs.spring.io/spring-framework/reference/testing/mockmvc.html" data-type="link" data-id="https://docs.spring.io/spring-framework/reference/testing/mockmvc.html">MockMvc</a>; services, using the <a href="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html" data-type="link" data-id="https://www.infoworld.com/article/4009216/advanced-unit-testing-with-junit-5-mockito-and-hamcrest.html">JUnit Mockito extension</a>; and repositories, using the Spring <a href="https://docs.spring.io/spring-boot/api/java/org/springframework/boot/test/autoconfigure/orm/jpa/TestEntityManager.html" data-type="link" data-id="https://docs.spring.io/spring-boot/api/java/org/springframework/boot/test/autoconfigure/orm/jpa/TestEntityManager.html">TestEntityManager</a>. We also reviewed slice testing as a strategy to reduce testing resource utilization and minimize the time required to execute tests. Slice testing is implemented in Spring using the <code>@WebMvcTest</code> and <code>@DataJpaTest</code> annotations. I hope these examples have given you everything you need to feel comfortable writing robust tests for your Spring MVC applications.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is generative AI? How artificial intelligence creates content]]></title>
<description><![CDATA[Generative AI is a kind of artificial intelligence that creates new content, including text, images, audio, and video, based on patterns it has learned from existing data.



Today’s generative models are typically built on foundation-model architectures such as large-language models (LLMs) and m...]]></description>
<link>https://tsecurity.de/de/3665675/ai-nachrichten/what-is-generative-ai-how-artificial-intelligence-creates-content/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665675/ai-nachrichten/what-is-generative-ai-how-artificial-intelligence-creates-content/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Generative AI is a kind of <a href="https://www.computerworld.com/article/1647870/what-is-artificial-intelligence.html">artificial intelligence</a> that creates new content, including text, images, audio, and video, based on patterns it has learned from existing data.</p>



<p class="wp-block-paragraph">Today’s generative models are typically built on foundation-model architectures such as <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large-language models (LLMs)</a> and multimodal systems, enabling them to carry on conversations, answer questions, write stories, generate code, and produce images or videos from brief prompts.</p>



<p class="wp-block-paragraph"><em>Generative AI</em> is different from <em>discriminative AI</em>, which draws distinctions between different kinds of input. Where discriminative AI answers questions like “Is this image of a rabbit or a lion?”, generative AI instead responds to prompts such as “Describe to me how a rabbit and lion look different from one another” or “Draw me a picture of a lion and a rabbit sitting next to each other” — and in both cases produces text or imagery that, while grounded in the AI’s training data, isn’t just a copy of something that already existed.</p>



<aside class="fakesidebar">
<h4>[ <u><a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">Read next: Large language models: The foundations of generative AI</a></u> ]</h4>
</aside>




<p class="wp-block-paragraph">Just a few years ago, generative AI was once a novelty focused on chatbots and artistic image generation. Today, it has become a core enterprise technology, and powers everything from content creation and software development to customer support and analytics workflows. But with that power comes a <a href="https://www.csoonline.com/article/4076511/4-factors-creating-bottlenecks-for-enterprise-genai-adoption.html">new set of challenges</a> — from model alignment and hallucination to governance and data-integration hurdles.</p>



<p class="wp-block-paragraph">In this article, we’ll look at how generative AI works, explore how it has evolved into the foundation-model era, examine how to implement it effectively, and offer best practices for getting value out of it, today and in the future.</p>



<h2 class="wp-block-heading"><strong>How does generative AI work?</strong></h2>



<p class="wp-block-paragraph">For decades, early artificial-intelligence efforts often focused on rule-based systems or <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">narrowly trained models</a> that were built for one task at a time. While these efforts produced useful systems that could reason and solve human tasks, they were generally a far cry from sci-fi visions of thinking machines. Programs that could talk to people never seemed to get very far past the level of <a href="https://en.wikipedia.org/wiki/ELIZA">ELIZA</a>, a “computer therapist” created at MIT in the mid 1960s; even Siri and Alexa after much fanfare were revealed to be fairly limited.</p>



<p class="wp-block-paragraph">The big structural shift that gave birth to modern generative AI came with the concept of a <em>transformer, </em>first introduced in “<a href="https://arxiv.org/abs/1706.03762">Attention Is All You Need</a>,” a 2017 paper from Google researchers.</p>



<p class="wp-block-paragraph">Using a transformer architecture as a basis, you can build a system that derives meaning from analyzing long sequences of input <em>tokens</em> (words, sub-words, bytes) to understand how different tokens might be related to one another, then determines how likely any given token is to come next in a sequence, given the others. In AI lingo, we call these systems <em>models.</em> Because a model analyzes very large datasets and parameter counts, it can pick up on statistical patterns and knowledge implicitly embedded in the data.</p>



<p class="wp-block-paragraph">This is all easier said than done. The process of adjusting a model’s internal parameters so it gets better at predicting the next token in sequences is called <em>training</em>. During training, the model repeatedly guesses the next token in a given sequence, compares its prediction to the actual one, measures the error, and updates its parameters to reduce that error across billions of examples. Over time, that process teaches the model the statistical relationships that will allow it to generate coherent language (or code, or images) later.</p>



<h2 class="wp-block-heading"><strong>What is a foundation model?</strong></h2>



<p class="wp-block-paragraph">You’ll often hear the word <em>large</em> used for transformer-based models of these types, like the LLMs we mentioned earlier. <em>Large</em> in this context refers to the large number of internal numerical values that the model adjusts during training to represent what it has learned, along with breadth and diversity of data used to train the model and the underlying compute resources powering this whole process.</p>



<p class="wp-block-paragraph">This is in contrast with the narrow models of the earlier era of AI/ML, which werebuilt for one purpose and trained on a limited dataset. For instance, a spam filter may be very good at what it does, but it’s only trained on email data and all it can do is classify emails. Large models, by contrast, serve as what’s known as <em>foundation models</em>. They’re trained broadly on diverse data (text, code, images, or multimodal data) and then adapted or specialized for many downstream tasks.</p>



<p class="wp-block-paragraph">These foundation models are the basis for most of the popular generative AI tools and services on the market today. They can be specialized in several ways:</p>



<ul class="wp-block-list">
<li><strong>Fine-tuning:</strong> Giving a foundation model further training on a smaller, task-specific dataset</li>



<li><strong>Retrieval-augmented generation</strong> <strong>(RAG):</strong> Giving the model the ability to pull in external knowledge when asked a question</li>



<li> <strong>Prompt engineering</strong>: Tailoring a query so the model gives the sort of answers you’re looking for.</li>
</ul>



<h2 class="wp-block-heading"><strong>How do AI systems write computer code?</strong></h2>



<p class="wp-block-paragraph">One of the surprising discoveries of the gen AI era was that in recent years was that foundation models trained on natural-language text can also, when fine-tuned with code examples, also write computer code — often better than many purpose-built systems. Still, it makes sense, when you think about it — after all, high-level computer languages are designed by humans and ultimately based on human language.</p>



<p class="wp-block-paragraph">This <a href="https://www.infoworld.com/article/2338500/llms-and-the-rise-of-the-ai-code-generators.html?utm_source=chatgpt.com">2023 InfoWorld article</a> highlights how models like PaLM, LLaMA and other transformer-based systems fine-tuned on code repositories propelled this shift, but since AI giants like <a href="https://www.computerworld.com/article/3843138/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise.html">OpenAI</a> have moved into this space. This all matters because code generation (or code-assisted productivity) has become a key enterprise use case of generative AI — perhaps <em>the </em>key use, given the industry’s enthusiastic adoption of it.</p>



<h2 class="wp-block-heading"><strong>What are AI agents?</strong></h2>



<p class="wp-block-paragraph">So far, we’ve been talking about chatbots, writing assistants, image-generation tools. They respond to prompts, output text or images, and then stop. A new category of tool called <em><a href="https://www.computerworld.com/article/3843138/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise.html">agentic AI</a></em> goes further: it <em>plans</em>, <em>executes</em>, and in many cases <em>learns</em> as it works.</p>



<p class="wp-block-paragraph">Because large models already understand language, code, and even structured data to some extent, they can be repurposed to generate not only descriptive text but <em>operational instructions</em>. For example: an agent might parse the intent “generate a sales-report”, then format internal calls like getData(salesDB, region=NA, period=lastQuarter), and then call an API, all by generating text that’s interpreted as instructions. The <a href="https://www.infoworld.com/article/4064169/how-mcp-is-making-ai-agents-actually-do-things-in-the-real-world.html.">MCP framework</a> standardizes the “language” of those instructions and the plug-points into tools and data so that the model doesn’t need bespoke integrations for each new workflow.</p>



<p class="wp-block-paragraph">These kinds of autonomous agents have several enterprise use cases:</p>



<ul class="wp-block-list">
<li><strong>Software automation</strong>: Agents that generate code, call unit tests, deploy builds, monitor logs and even roll back changes autonomously.</li>



<li><strong>Customer support</strong>: Instead of simply drafting responses, agents interact with CRM APIs, update ticket statuses, escalate issues, and trigger follow-up workflows.</li>



<li><strong>IT operations/AIOps</strong>: Agents <a href="https://www.cio.com/article/222623/7-things-to-know-about-ai-in-the-data-center.html">monitor infrastructure, identify anomalies, open/close tickets, or auto-remediate</a> based on defined rules and context from logs.</li>



<li><strong>Security</strong>: Agents may detect threats, initiate alerts, isolate compromised systems, or even attempt to manage threat containment — though this raises new risks.</li>
</ul>



<h2 class="wp-block-heading"><strong>How can you implement generative AI in the enterprise?</strong></h2>



<p class="wp-block-paragraph">We’ve now touched on <em>what</em> generative AI can do. But <em>how</em> can you make it work reliably in your business. The difference between a pilot and full-scale deployment often comes down to systems, structure and governance as much as to models themselves. <em>InfoWorld’</em>s Matt Asay offers a <a href="https://www.infoworld.com/article/4044919/enterprise-essentials-for-generative-ai.html">deep dive into enterprise gen AI essentials</a>, but here are some important points to keep in mind:</p>



<p class="wp-block-paragraph"><strong>Choosing between API, open-source or custom fine-tuned models. </strong>One of the first major decisions for any enterprise project is: do you use a model via an API (e.g., from a vendor like OpenAI or Anthropic), deploy an open-source model internally, or build/fine-tune a custom model yourself? Each has trade-offs.</p>



<p class="wp-block-paragraph">APIs offer speed and minimal setup, but may expose data, limit customization or accrue high cost — and will leave you at the mercy of your vendor. Open source allows internal control and may ease fine-tuning, but requires infrastructure, expertise, and support. Custom fine-tuning gives you the tightest alignment to your use-case, but lengthens time to value and increases risk.</p>



<p class="wp-block-paragraph"><strong>Governance, data privacy and compliance. </strong>Deploying generative AI in an enterprise setting raises new governance, privacy and regulatory issues. For example: Who owns the data that’s ingested? How is proprietary data protected if you call a third-party API? What traceability exists for model outputs—a huge question for regulated industries? One useful framework is covered in “A GRC framework for securing generative AI” Data governance <a href="https://www.infoworld.com/article/2336154/how-data-governance-must-evolve-to-meet-the-generative-ai-challenge.html">must adapt for the new era</a>,  and <a href="https://www.infoworld.com/article/3604732/a-grc-framework-for-securing-generative-ai.html">new frameworks are evolving to help</a>.</p>



<p class="wp-block-paragraph"><strong>Human-in-the-loop review. </strong>Even the best models make mistakes and cannot simply be put on autopilot. You need a <em>human-in-the-loop (HITL)</em> process: real people need to review outputs, validate for bias, approve high-stakes content, and tune prompts or models based on feedback. Incorporating HITL checkpoints helps mitigate risk and improve overall quality.</p>



<p class="wp-block-paragraph"><strong>Integration with existing systems and RAG pipelines. </strong><a href="https://www.infoworld.com/article/2337050/how-rag-completes-the-generative-ai-puzzle.html">Retrieval-augmented generation</a>, which we touched on earlier, connects foundation models into business workflows, systems, and enterprise data stores. RAG can bind LLMs to your organization’s internal knowledge bases, thereby reducing <em>hallucinations </em>(which we’ll discuss in a moment) and increasing the relevance of gen AI output.</p>



<aside class="sidebar">
<h3><strong> Implementation best practices for generative AI</strong></h3>
<p> Here are four AI best practices to keep in mind:</p>
<ol>
<li> Guardrails: Define clear operational boundaries. Examples: restrict sensitive data output, enforce access controls, log model interactions.</li>
<li> Prompt engineering: Because much of what the model will do depends on how it’s prompted, invest in prompt design, versioning, review, and testing.</li>
<li> Evaluation metrics: Define appropriate KPIs (accuracy, latency, cost, business outcome), monitor them and iterate.</li>
<li> Model observability: Treat generative-AI systems like software — monitor performance, detect drift, handle failures gracefully, audit outputs and maintain traceability.</li>
</ol>
</aside>




<h2 class="wp-block-heading"><strong>What causes AI hallucinations?</strong></h2>



<p class="wp-block-paragraph">Probably the biggest limitation of generative AI is what those in the industry call <em>hallucinations</em>, which is a perhaps misleading term for output that is, by the standards of humans who use it, false or incorrect.  </p>



<p class="wp-block-paragraph">Every generative AI system, no matter how advanced, is built around prediction. Remember, a model doesn’t truly <em>know</em> facts—it looks at a series of tokens, then calculates, based on analysis of its underlying training data, what token is most likely to come next. This is what makes the output fluent and human-like, but if its prediction is wrong, that will be perceived as a hallucination.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/GenAI_takeaways.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Table describing five key points about generatvie AI" class="wp-image-4082262" width="1024" height="648" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Generative AI, foundation models, agentic AI, governance, and implementation strategy top the list of top generative AI takeaways.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">Because the model doesn’t distinguish between something that’s known to be true and something likely to follow on from the input text it’s been given, hallucinations are a direct side effect of the statistical process that powers generative AI. And don’t forget that we’re often pushing AI models to come up with answers to questions that we, who also have access to that data, can’t answer ourselves.</p>



<p class="wp-block-paragraph">In text models, hallucinations might mean inventing quotes, fabricating references, or misrepresenting a technical process. In code or data analysis, it can produce <a href="https://www.infoworld.com/article/3822251/how-to-keep-ai-hallucinations-out-of-your-code.html">syntactically correct but logically wrong results</a>. Even RAG pipelines, which provide real data context to models, only <em>reduce</em> hallucination—they don’t eliminate it. Enterprises using generative AI need <a href="https://www.cio.com/article/4073606/reducing-llm-hallucinations-in-enterprise-systems.html">review layers, validation pipelines, and human oversight</a> to prevent these failures from spreading into production systems.</p>



<h2 class="wp-block-heading"><strong>What are some other problems with generative AI?</strong></h2>



<p class="wp-block-paragraph">Generative AI has proven to be such a disruptive technology that’s stoking near-apocalyptic fears that it will result in a superintelligence that will enslave or destroy humanity. Meanwhile, in the present day, increasingly troubling reports of so-called <a href="https://www.psychologytoday.com/us/blog/urban-survival/202507/the-emerging-problem-of-ai-psychosis">AI psychosis</a> are emerging, where people have mental health episodes triggered by the uncanny and sometimes sycophantic ways chatbots affirm whatever you talk to them about and try to keep the conversation going.</p>



<p class="wp-block-paragraph">Compared to such existential questions, the following business-related problems may seem petty. But they’re real issues for enterprises considering investing in AI tools.</p>



<ul class="wp-block-list">
<li><strong>Data leakage and regulatory risk. </strong>When a model is fine-tuned or prompted with sensitive information, that data may be memorized and unintentionally reproduced. Using <a href="https://www.csoonline.com/article/3819170/nearly-10-of-employee-gen-ai-prompts-include-sensitive-data.html">third-party APIs without strict controls</a> can expose proprietary or personally identifiable information (PII). Regulatory frameworks like GDPR and HIPAA require explicit governance around where training data resides and how inference results are stored.</li>



<li><strong>Prompt injection </strong>occurs when an attacker manipulates a model’s instructions—embedding hidden directives or malicious payloads in user input or external content the model reads. This can override safety rules, expose internal data, or execute unintended actions in agentic systems. Guardrails that sanitize inputs, restrict tool-calling permissions, and validate outputs are becoming essential.</li>



<li><strong>Copyright and content ownership. </strong>Many foundation models are trained on data scraped from the public internet, creating disputes over copyright and data provenance. Enterprises using generated output commercially need to confirm usage rights and review indemnity terms from vendors.</li>



<li><strong>Unrealistic productivity expectations. </strong>Finally, organizations sometimes expect generative AI to deliver instant productivity gains. The reality, it turns out, is more <a href="https://leaddev.com/velocity/ai-doesnt-make-devs-as-productive-as-they-think-study-finds">mixed</a>. Enterprise adoption requires infrastructure, governance, retraining, and cultural change. The models accelerate work once properly integrated, but they don’t automatically replace human judgment or oversight.</li>
</ul>



<p class="wp-block-paragraph">The current generation of enterprise AI systems includes several layers of defense against these risks:</p>



<ul class="wp-block-list">
<li><em>Guardrails</em> that constrain model behavior and filter unsafe outputs.</li>



<li><em>Model validation</em> frameworks that measure factual accuracy and consistency before deployment.</li>



<li><em>Policy layers</em> that enforce compliance rules, redact sensitive data, and log model actions.</li>
</ul>



<p class="wp-block-paragraph">These safeguards reduce—but don’t remove—the inherent uncertainty that defines generative AI.</p>



<h2 class="wp-block-heading"><strong>GenAI: essential for the enterprise</strong></h2>



<p class="wp-block-paragraph">Generative AI has evolved from a novelty into a core layer of enterprise technology. Foundation models and agentic systems now power automation, analytics, and creative workflows — but they remain fundamentally probabilistic tools. Their strength lies in scale and adaptability, not perfect understanding.</p>



<p class="wp-block-paragraph">For organizations, success depends less on chasing model breakthroughs than on integrating these systems responsibly: building guardrails, maintaining oversight, and aligning them with real business needs. Used wisely, generative AI can amplify human capability rather than replace it.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The complete guide to Node.js frameworks]]></title>
<description><![CDATA[Node.js is one of the most popular server-side platforms, especially for web applications. It gives you non-blocking JavaScript without a browser, plus an enormous ecosystem. That ecosystem is one of Node’s chief strengths, making it a go-to option for server development.



This article is a qui...]]></description>
<link>https://tsecurity.de/de/3665672/ai-nachrichten/the-complete-guide-to-nodejs-frameworks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665672/ai-nachrichten/the-complete-guide-to-nodejs-frameworks/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node.js</a> is one of the most popular server-side platforms, especially for web applications. It gives you non-blocking JavaScript without a browser, plus an enormous ecosystem. That ecosystem is one of Node’s chief strengths, making it a go-to option for server development.</p>



<p class="wp-block-paragraph">This article is a quick tour of the most popular web frameworks for <a href="https://www.infoworld.com/article/2257958/nodejs-tutorial-get-started-with-nodejs.html">server development on Node.js</a>. We’ll look at minimalist tools like Express.js, batteries-included frameworks like Nest.js, and full-stack frameworks like Next.js. You’ll get an overview of the frameworks and a taste of what it’s like to write a simple server application in each one.</p>



<h2 class="wp-block-heading">Minimalist web frameworks</h2>



<p class="wp-block-paragraph">When it comes to Node web frameworks, <em>minimalist</em> doesn’t mean limited. Instead, these frameworks provide the essential features required to do the job for which they are intended. The frameworks in this list also tend to be highly extensible, so you can customize them as needed. With minimalist frameworks, pluggable extensibility is the name of the game.</p>



<h3 class="wp-block-heading">Express.js</h3>



<p class="wp-block-paragraph">At over 47 million weekly downloads on npm, Express is one of the most-installed software packages of all time—and for good reason. Express gives you basic web endpoint routing and request-and-response handling inside an extensible framework that is easy to understand. Most other frameworks in this category have adopted the basic style of describing a route from Express. This framework is the obvious choice when you simply need to create some routes for HTTP, and you don’t mind a DIY approach for anything extra.</p>



<p class="wp-block-paragraph">Despite its simplicity, Express is fully-featured when it comes to things like route parameters and request handling. Here is a simple Express endpoint that returns a dog breed based on an ID:</p>



<pre class="wp-block-code"><code>import express from 'express';

const app = express();
const port = 3000;

// In-memory array of dog breeds
const dogBreeds = [
  "Shih Tzu",
  "Great Pyrenees",
  "Tibetan Mastiff",
  "Australian Shepherd"
];
app.get('/dogs/:id', (req, res) =&gt; {
  // Convert the id from a string to an integer
  const id = parseInt(req.params.id, 10);

  // Check if the id is a valid number and within the array bounds
  if (id &gt;= 0 &amp;&amp; id  {
  console.log(`Server running at http://localhost:${port}`);
});</code></pre>



<p class="wp-block-paragraph">You can easily see how the route is defined here: a string representation of a URL, followed by a function that receives a request and response object. The process of creating the server and listening on a port is simple.</p>



<p class="wp-block-paragraph">If you are coming from a framework like Next, the biggest thing you might notice about Express is that it lacks a file-system based router. On the other hand, it offers a huge range of <a href="https://expressjs.com/en/resources/middleware.html">middleware plugins</a> to help with essential functions like security.</p>



<h3 class="wp-block-heading">Koa</h3>



<p class="wp-block-paragraph"><a href="https://koajs.com/">Koa</a> was created by the original creators of Espress, who took the lessons learned from that project and used them for a fresh take on the JavaScript server. Koa’s focus is providing a minimalist core engine. It uses <code>async</code>/<code>await</code> functions for middleware rather than chaining with <code>next()</code> calls. This can give you a cleaner server, especially when there are many plugins. It also makes the error handling less clunky for middleware.</p>



<p class="wp-block-paragraph">Koa also differs from Express by exposing a unified context object instead of separate request and response objects, which makes for a somewhat less cluttered API. Here is how Koa manages the same route we created in Express:</p>



<pre class="wp-block-code"><code>router.get('/dogs/:id', (ctx) =&gt; {
  const id = parseInt(ctx.params.id, 10);

  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    ctx.status = 200;
    ctx.body = { breed: dogBreeds[id] };
  } else {
    ctx.status = 404;
    ctx.body = { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">The only real difference is the combined context object.</p>



<p class="wp-block-paragraph">Koa’s middleware mechanism is also worth a look. Here’s a simple logging plugin in Koa:</p>



<pre class="wp-block-code"><code>const logger = async (ctx, next) =&gt; {
  await next(); // This passes control to the router
  console.log(`${ctx.method} ${ctx.url} - ${ctx.status}`);
};

// Use the logger middleware for all requests
app.use(logger);	</code></pre>



<h3 class="wp-block-heading">Fastify</h3>



<p class="wp-block-paragraph"><a href="https://fastify.dev/">Fastify</a> lets you define schemas for your APIs. This is an up-front, formal mechanism for describing what the server supports:</p>



<pre class="wp-block-code"><code>const schema = {
  params: {
    type: 'object',
    properties: {
      id: { type: 'integer' }
    }
  },
  response: {
    200: {
      type: 'object',
      properties: {
        breed: { type: 'string' }
      }
    },
    404: {
      type: 'object',
      properties: {
        error: { type: 'string' }
      }
    }
  }
};

fastify.get('/dogs/:id', { schema }, (request, reply) =&gt; {
  const id = request.params.id;

  if (id &gt;= 0 &amp;&amp; id  {
  if (err) {
    fastify.log.error(err);
    process.exit(1);
  }
  console.log(`Server running at ${address}`);
});</code></pre>



<p class="wp-block-paragraph">From this example, you can see the actual endpoint definition is similar to Express and Koa, but we define a schema for the API. The schema is not strictly necessary; it is possible to define endpoints without it. In that case, Fastify behaves much like Express, but with superior performance.</p>



<h3 class="wp-block-heading">Hono</h3>



<p class="wp-block-paragraph"><a href="https://hono.dev/">Hono</a> emphasizes simplicity. You can define a server and endpoint with as little as:</p>



<pre class="wp-block-code"><code>const app = new Hono()
app.get('/', (c) =&gt; c.text('Hello, Infoworld!'))  </code></pre>



<p class="wp-block-paragraph">And here’s how our dog breed example looks:</p>



<pre class="wp-block-code"><code>app.get('/dogs/:id', (c) =&gt; {
  // Get the id parameter from the request URL
  const id = parseInt(c.req.param('id'), 10);

  // Check if the id is a valid number and within the array bounds
  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    // Return a JSON response with a 200 OK status (default)
    return c.json({ breed: dogBreeds[id] });
  } else {
    // Set status to 404 and return a JSON error message
    c.status(404);
    return c.json({ error: 'Dog breed not found' });
  }
});</code></pre>



<p class="wp-block-paragraph">As you can see, Hono provides a unified context object, similar to Koa.</p>



<h3 class="wp-block-heading">Nitro.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4061129/intro-to-nitro-the-server-engine-built-for-modern-javascript.html">Nitro</a> is the back end for several full-stack frameworks, including Nuxt.js. As part of the UnJS ecosystem, Nitro goes further than Express in providing cloud-native tooling support. It includes a universal storage adapter and deployment support for serverless and cloud deployment targets.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/4061129/intro-to-nitro-the-server-engine-built-for-modern-javascript.html">Intro to Nitro: The server engine built for modern JavaScript</a>.</strong></p>



<p class="wp-block-paragraph">Like Next.js, Nitro uses filesystem-based routing, so our Dog Finder API would exist at the following filepath:</p>



<pre class="wp-block-code"><code>/api/dogs/:id</code></pre>



<p class="wp-block-paragraph">The handler might look like this:</p>



<pre class="wp-block-code"><code>export default defineEventHandler((event) =&gt; {
  // Get the dynamic parameter from the event context
  const { id } = getRouterParams(event);
  const parsedId = parseInt(id, 10);

  // Check if the id is a valid number and within the array bounds
  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    // Nitro handles JSON serialization
    return { breed: dogBreeds[parsedId] };
  } else {
    setResponseStatus(event, 404);
    return { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">Nitro inhabits the middle ground between a pure tool like Express and a full-blown stack, which is why full-stack front ends often use Nitro on the back end.</p>



<h2 class="wp-block-heading">Batteries-included frameworks</h2>



<p class="wp-block-paragraph">Although Express and other minimalist frameworks set the standard for simplicity, more opinionated frameworks can be useful if you want additional features out of the box.</p>



<h3 class="wp-block-heading">Nest.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4091407/intro-to-nest-js-server-side-javascript-development-on-node.html">Nest</a> is a progressive framework built with <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a> from the ground up. Nest is actually a layer on top of Express (or Fastify), with additional services. It is inspired by Angular and incorporates the kind of architectural support found there. In particular, it includes dependency injection. Nest also uses annotated controllers for endpoints.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/4091407/intro-to-nest-js-server-side-javascript-development-on-node.html">Intro to Nest.js: Server-side JavaScript development on Node</a>.</strong></p>



<p class="wp-block-paragraph">Here is an example of injecting a dog finder provider into a controller:</p>



<pre class="wp-block-code"><code>// The provider:
import { Injectable, NotFoundException } from '@nestjs/common';

// The @Injectable() decorator marks this class as a provider.
@Injectable()
export class DogsService {
  private readonly dogBreeds = [
    "Shih Tzu",
    "Great Pyrenees",
    "Tibetan Mastiff",
    "Australian Shepherd"
  ];

  findOne(id: number) {
    if (id &gt;= 0 &amp;&amp; id &lt; this.dogBreeds.length) {
      return { breed: this.dogBreeds[id] };
    }
    // NestJS has built-in HTTP exception classes for common errors.
    throw new NotFoundException('Dog breed not found');
  }
}

// The controller

import { Controller, Get, Param, ParseIntPipe } from '@nestjs/common';
import { DogsService } from './dogs.service';

@Controller('dogs')
export class DogsController {
  // NestJS injects the DogsService through the constructor.
  // The 'private readonly' syntax is a TypeScript shorthand
  // to both declare and initialize the dogsService member.
  constructor(private readonly dogsService: DogsService) {}

  @Get(':id')
  findOneDog(@Param('id', ParseIntPipe) id: number) {
    // We can now use the service's methods. The ParseIntPipe
    // automatically converts the string URL parameter to a number.
    return this.dogsService.findOne(id);
  }
}</code></pre>



<p class="wp-block-paragraph">This style is typical of dependency injection frameworks like <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">Angular</a>, as well as <a href="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html" data-type="link" data-id="https://www.infoworld.com/article/4083578/a-fresh-look-at-the-spring-framework.html">Spring</a>. It allows you to declare components as injectable, then consume them anywhere you need them.</p>



<p class="wp-block-paragraph">In Nest, we’d just add these as modules to make them live.</p>



<h3 class="wp-block-heading">Adonis.js</h3>



<p class="wp-block-paragraph">Like Nest, <a href="https://adonisjs.com/">Adonis</a> provides a controller layer that you wire together with routes. Adonis is inspired by the model-view-controller (MVC) pattern, so it also includes a layer for modelling data and accessing stores via an ORM. Finally, it provides a validator layer for ensuring data meets requirements.</p>



<p class="wp-block-paragraph">Routes in Adonis are very simple:</p>



<pre class="wp-block-code"><code>Route.get('/dogs/:id', [DogsController, 'show'])</code></pre>



<p class="wp-block-paragraph">In this case, <code>DogsController</code> would be the handler for the route, and might look something like:</p>



<pre class="wp-block-code"><code>import type { HttpContextContract } from '@ioc:Adonis/Core/HttpContext'  // Note, ioc means inversion of control, similar to dependency injection

export default class DogsController {
  // The 'show' method handles the logic for the route
  public async show({ params, response }: HttpContextContract) {
    const id = Number(params.id);

    // Check if the id is a valid number and within the array bounds
    if (!isNaN(id) &amp;&amp; id &gt;= 0 &amp;&amp; id &lt; this.dogBreeds.length) {
      // Use the response object to send a 200 OK JSON response
      return response.ok({ breed: this.dogBreeds[id] });
    } else {
      // Send a 404 Not Found response
      return response.notFound({ error: 'Dog breed not found' });
    }
  }
}</code></pre>



<p class="wp-block-paragraph">Of course, in a real application, we could define a model layer to handle the actual data access.</p>



<h3 class="wp-block-heading">Sails</h3>



<p class="wp-block-paragraph"><a href="https://sailsjs.com/">Sails</a> is another MVC-style framework. It is one of the original one-stop-shopping frameworks for Node and includes an ORM layer (<a href="https://sailsjs.com/documentation/reference/waterline-orm">Waterline</a>), API generation (<a href="https://sailsjs.com/documentation/reference/blueprint-api">Blueprints</a>), and realtime support, including <a href="https://www.infoworld.com/article/3552685/websockets-under-the-hood.html" data-type="link" data-id="https://www.infoworld.com/article/3552685/websockets-under-the-hood.html">WebSockets</a>.</p>



<p class="wp-block-paragraph">Sails strives for conventional operation. For example, here’s how you might define a simple model for dogs:</p>



<pre class="wp-block-code"><code>/**
 * Dog.js
 *
 * @description :: A model definition represents a database table/collection.
 * @docs        :: https://sailsjs.com/docs/concepts/models
 */
module.exports = {
  attributes: {
    breed: { type: 'string', required: true },
  },
};</code></pre>



<p class="wp-block-paragraph">If you run this in Sails, the framework will generate default routes and wire up a <a href="https://www.infoworld.com/article/2265797/how-to-choose-the-right-nosql-database-2.html" data-type="link" data-id="https://www.infoworld.com/article/2265797/how-to-choose-the-right-nosql-database-2.html">NoSQL</a> or SQL datastore based on your configuration. Sails also provides the option to override these defaults and add in your own custom logic.</p>



<h2 class="wp-block-heading">Full-stack frameworks</h2>



<p class="wp-block-paragraph">Also known as <a href="https://www.infoworld.com/article/3486850/state-of-javascript-insights-from-the-latest-javascript-community-survey.html">meta-frameworks</a>, these tools combine a front-end framework with a solid back end and various CLI niceties like build chains.</p>



<h3 class="wp-block-heading">Next.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4078213/next-js-16-features-explicit-caching-ai-powered-debugging.html">Next</a> is a React-based framework built by Vercel. It is largely responsible for the huge growth in popularity of these types of frameworks. Next was the first framework to bring together back-end API definitions with the front end that consumes them. It also introduced file-system routing. In Next and other full-stack frameworks, you get both parts of your stack in one place and you can run them together during development.</p>



<p class="wp-block-paragraph">In Next, we could define a route at <code>pages/api/dogs/[id].js</code> like so:</p>



<pre class="wp-block-code"><code>export default function handler(req, res) {
  // `req.query.id` comes from the dynamic filename [id].js
  const { id } = req.query;
  const parsedId = parseInt(id, 10);

  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    // If the ID is valid, return the data
    res.status(200).json({ breed: dogBreeds[parsedId] });
  } else {
    // Otherwise, return a 404 error
    res.status(404).json({ error: 'Dog breed not found' });
  }
}</code></pre>



<p class="wp-block-paragraph">We’d then define the UI component to interact with this route at <code>pages/dogs/[id].js</code>:</p>



<pre class="wp-block-code"><code>import React from 'react';

// This is the React component that renders the page.
// It receives the `dog` object as a prop from getServerSideProps.
function DogPage({ dog }) {
  // Handle the case where the dog wasn't found
  if (!dog) {
    return <h1>Dog Breed Not Found</h1>;
  }

  return (
    <div>
      <h1>Dog Breed Profile</h1>
      <p>Breed Name: <strong>{dog.breed}</strong></p>
    </div>
  );
}

// This function runs on the server before the page is sent to the browser.
export async function getServerSideProps(context) {
  const { id } = context.params; // Get the ID from the URL

  // Fetch data from our own API route on the server.
  const res = await fetch(`http://localhost:3000/api/dogs/${id}`);
  
  // If the fetch was successful, parse the JSON.
  const dog = res.ok ? await res.json() : null;

  // Pass the fetched data to the DogPage component as props.
  return {
    props: {
      dog,
    },
  };
}

export default DogPage;</code></pre>



<h3 class="wp-block-heading">Nuxt.js</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4025936/nuxt-4-0-improves-project-organization-data-fetching-typescript-support.html">Nuxt</a> is the same idea as Next, but applied to the <a href="http://vue.js/">Vue</a> front end. The basic pattern is the same, though. First, we’d define a back-end route:</p>



<pre class="wp-block-code"><code>// server/api/dogs/[id].js

// defineEventHandler is Nuxt's helper for creating API handlers.
export default defineEventHandler((event) =&gt; {
  // Nuxt automatically parses route parameters.
  const id = getRouterParam(event, 'id');
  const parsedId = parseInt(id, 10);

  if (parsedId &gt;= 0 &amp;&amp; parsedId &lt; dogBreeds.length) {
    return { breed: dogBreeds[parsedId] };
  } else {
    // Helper to set the status code and return an error.
    setResponseStatus(event, 404);
    return { error: 'Dog breed not found' };
  }
});</code></pre>



<p class="wp-block-paragraph">Then, we’d create the UI file in Vue:</p>



<pre class="wp-block-code"><code>// pages/dogs/[id].vue


  <div>
    <div>
      Loading...
    </div>
    <div>
      <h1>{{ error.data.error }}</h1>
    </div>
    <div>
      <h1>Dog Breed Profile</h1>
      <p>Breed Name: <strong>{{ dog.breed }}</strong></p>
    </div>
  </div>


</code></pre>



<h3 class="wp-block-heading">SvelteKit</h3>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2337758/intro-to-sveltekit-10-the-full-stack-framework-for-svelte.html">SvelteKit</a> is the full-stack framework for the Svelte front end. It’s similar to Next and Nuxt, with the main difference being the front-end technology.</p>



<p class="wp-block-paragraph">In SvelteKit, a back-end route looks like so:</p>



<pre class="wp-block-code"><code>// src/routes/api/dogs/[id]/+server.js

import { json, error } from '@sveltejs/kit';

// This is our data source for the example.
const dogBreeds = [
  "Shih Tzu",
  "Australian Cattle Dog",
  "Great Pyrenees",
  "Tibetan Mastiff",
];

/** @type {import('./$types').RequestHandler} */
export function GET({ params }) {
  // The 'id' comes from the [id] directory name.
  const id = parseInt(params.id, 10);

  if (id &gt;= 0 &amp;&amp; id &lt; dogBreeds.length) {
    // The json() helper creates a valid JSON response.
    return json({ breed: dogBreeds[id] });
  }

  // The error() helper is the idiomatic way to return HTTP errors.
  throw error(404, 'Dog breed not found');
}</code></pre>



<p class="wp-block-paragraph">SvelteKit usually splits the UI into two components. The first component is for loading the data (which can then be run on the server):</p>



<pre class="wp-block-code"><code>// src/routes/dogs/[id]/+page.js

import { error } from '@sveltejs/kit';

/** @type {import('./$types').PageLoad} */
export async function load({ params, fetch }) {
  // Use the SvelteKit-provided `fetch` to call our API endpoint.
  const response = await fetch(`/api/dogs/${params.id}`);

  if (response.ok) {
    const dog = await response.json();
    // The object returned here is passed as the 'data' prop to the page.
    return {
      dog: dog
    };
  }

  // If the API returns an error, forward it to the user.
  throw error(response.status, 'Dog breed not found');
}</code></pre>



<p class="wp-block-paragraph">The second component is the UI:</p>



<pre class="wp-block-code"><code>// src/routes/dogs/[id]/+page.svelte



<div>
  <h1>Dog Breed Profile</h1>
  <p>Breed Name: <strong>{data.dog.breed}</strong></p>
</div></code></pre>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">The Node.js ecosystem has moved beyond the “default-to-Express” days. Now, it is worth your time to look for a framework that fits your specific situation.<br><br>If you are building <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a> or high-performance APIs, where every millisecond counts, you owe it to yourself to look at minimalist frameworks like Fastify or Hono. This class of frameworks gives you raw speed and total control without requiring decisions about infrastructure.<br><br>If you are building an enterprise monolith or working with a big team, batteries-included frameworks like Nest or Adonis offer useful structure. The complexity of the initial setup buys you long-term maintainability and makes the codebase more standardized for new developers.<br><br>Finally, if your project is a content-rich web application, full-stack meta-frameworks like Next, Nuxt, and SvelteKit offer the best developer experience and the perfect profile of tools.<br><br>It’s also worth noting that, while Node remains the standard server-side runtime, alternatives <a href="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html">Deno</a> and <a href="https://www.infoworld.com/article/2338008/explore-bunjs-the-all-in-one-javascript-runtime.html">Bun</a> have both made a name for themselves. Deno has great heritage, is open source with a strong security focus, and has its own framework, <a href="https://www.infoworld.com/article/3523813/intro-to-deno-fresh-a-fresh-take-on-full-stack-javascript.html">Deno Fresh</a>. Bun is respected for its ultra-fast startup and integrated tooling.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[React tutorial: Get started with the React JavaScript library]]></title>
<description><![CDATA[Despite many worthy contenders, React remains the most popular front-end framework, and a key player in the JavaScript development landscape. React is the quintessential reactive engine, continually innovating alongside the rest of the industry. A flagship open source project at Facebook, React i...]]></description>
<link>https://tsecurity.de/de/3665668/ai-nachrichten/react-tutorial-get-started-with-the-react-javascript-library/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665668/ai-nachrichten/react-tutorial-get-started-with-the-react-javascript-library/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Despite many <a href="https://www.infoworld.com/article/2336227/whats-the-best-javascript-framework.html">worthy contenders</a>, React remains the most popular front-end framework, and a key player in the <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a> development landscape. React is the quintessential <a href="https://www.infoworld.com/article/2338730/what-is-reactive-programming-programming-with-event-streams.html">reactive engine</a>, continually innovating alongside the rest of the industry. A flagship open source project at Facebook, React is now part of Meta Open Source. For developers new to JavaScript and web development, this tutorial will get you started with this vital technology.</p>



<p class="wp-block-paragraph">React is not only a front-end framework, but is a component in full-stack frameworks like <a href="https://www.infoworld.com/article/4078213/next-js-16-features-explicit-caching-ai-powered-debugging.html">Next.js</a>. Newer additions like React server-side rendering (SSR) and React server components (RSC) further blur the line between server and client.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3583477/is-the-react-compiler-ready-for-prime-time.html">Is the React compiler ready for primetime?</a></strong></p>



<h2 class="wp-block-heading">Why React?</h2>



<p class="wp-block-paragraph">React’s prominence makes it an obvious choice for developers just starting out with web development. It is often chosen for its ability to offer a smooth and encompassing developer experience (DX), which distinguishes it from frameworks like <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">Vue, Angular, and Svelte</a>. It could be said that React’s true “killer feature” is the perks that come with longstanding popularity: learning resources, community support, libraries, and developers are all plentiful in the React ecosystem.</p>



<h2 class="wp-block-heading">Installing React</h2>



<p class="wp-block-paragraph">Real-world React requires running on the server with a build tool, which we will explore in the next section. But to get your feet wet, we can start out with an online playground. There are several high-quality playgrounds for React, including full-blown environments like StackBlitz or Codesandbox. For a quick taste, we will use <a href="https://playcode.io/react">PlayCode React</a>.</p>



<p class="wp-block-paragraph">When you first open it, PlayCode React gives you a basic layout like the one shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/image1.png?w=1024" alt="A screenshot shows the layout of a basic Rwact JavaScript application." class="wp-image-4116902" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">The menu on the left is the file explorer, at the top is the code window, and at the bottom are the console (on the left) and the preview pane (on the right).</p>



<p class="wp-block-paragraph">From this screenshot, you can see how the content of the code is displayed on the preview pane, but this basic layout doesn’t use any variables (or “state,” as it’s known in React). It does let you see some of the plumbing, like the React library import and the exported <code>App</code> function.</p>



<p class="wp-block-paragraph">Modern React is functional. The <code>App</code> function has a return value that is the actual output for the component. The component’s return is specified by <a href="https://www.infoworld.com/article/2335613/intro-to-jsx-html-that-does-javascript.html">JSX</a>, a templating language that lets you use HTML along with variables and JavaScript expressions. Right now, the app just has some simple markup.</p>



<p class="wp-block-paragraph">The classic example you see next is a “Counter” that lets you increase and decrease a displayed value using buttons. We’ll do a slight “Spinal Tap” variation of this, where the counter only goes to 11 and displays a message:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/image2.png?w=1024" alt="A screenshot of a counter app developed in React." class="wp-image-4116903" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">You can take a look at the running example <a href="https://playcode.io/react-playground--019ac165-81fd-74b1-8681-188b66459b9e">here</a>, and the full code for the example is below:</p>



<pre class="wp-block-code"><code>import React, { useState } from 'react';

export function App() {
  // 1. The State
  const [volume, setVolume] = useState(0);

  return (
    <div>
      <h1>Spinal Tap Amp 🎸</h1>
     
      {/* 2. The "View" (Displaying the state) */}
      <div>
        {volume}
      </div>

      <div>
        {/* 3. The Actions */
        <button> setVolume(volume - 1)}&gt;Down</button>
       
        <button> {
          if (volume 
          Up
        </button>
      </div>

      {/* 4. Conditional */}
      {volume === 11 &amp;&amp;
        <p>"Why don't you just make ten louder?"</p>
      }
    </div>
  );
}</code></pre>



<p class="wp-block-paragraph">If you play with the example, you’ll see that moving the buttons changes the value, and the display automatically reflects the change. This is the essential magic of a reactive engine like React. The state is a managed variable that React automatically updates and displays. State is declared like so:</p>



<pre class="wp-block-code"><code>const [volume, setVolume] = useState(0);</code></pre>



<p class="wp-block-paragraph">The syntax is a bit funky if you are coming from straight JavaScript, but most developers can adapt to it quickly. Basically, <code>useState(0)</code> says, with a default value <code>0</code>, give me a variable, <code>volume</code>, and a function to set it, <code>setVolume</code>.</p>



<p class="wp-block-paragraph">To display the value in the view, we use: <code>{volume}</code>.</p>



<p class="wp-block-paragraph">To modify the value, we use button event handlers. For example, to increment, we’d do:</p>



<pre class="wp-block-code"><code>To modify the value, we use buttons event handlers.  For example, to increment:

onClick={() =&gt; setVolume(volume + 1)</code></pre>



<p class="wp-block-paragraph">Here we’ve directly modified the volume state, and React will update accordingly. If we wanted to, we could call a function (for example, if the logic were more involved).</p>



<p class="wp-block-paragraph">Finally, when the value reaches 11, we display a message. This syntax is idiomatic React, and uses an embedded JavaScript equality check:</p>



<pre class="wp-block-code"><code>{volume === 11 &amp;&amp;
  <p>"Why don't you just make ten louder?"</p>
}</code></pre>



<p class="wp-block-paragraph">The check says, if volume is 11, then display the <code><p></p></code> markup.</p>



<h2 class="wp-block-heading">Using a build tool with React</h2>



<p class="wp-block-paragraph">Once upon a time, when NVIDIA was nothing but a graphics card, it was quite a bit of work assembling a good build chain for React. These days, the process is much simpler, and the once ubiquitous <code>create-react-app</code> option is no more. <a href="https://www.infoworld.com/article/2266193/7-tools-transforming-javascript-development.html">Vite</a> is now the standard choice for launching a new app from the React terminal, so that’s the approach you’ll learn here.</p>



<p class="wp-block-paragraph">With that said, there are a few alternatives worth mentioning. <a href="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html">VS Code</a> has extensions that will provide you with templates or scaffolding, but what’s becoming more common is <a href="https://www.infoworld.com/article/3973969/knowing-when-to-use-ai-coding-assistants.html">using an AI coding assistant</a>. A tool like Copilot, ChatGPT, or Gemini can take a prompt describing the basics of the application in question, including the instruction to use React, and produce a basic React layout for you. AI assistants are available in both command-line and VS Code extension flavors. Or, for an even more forward-looking option, you could use something like <a href="https://www.infoworld.com/article/3981588/putting-agentic-ai-to-work-in-firebase-studio.html">Firebase Studio</a>.</p>



<p class="wp-block-paragraph">But enough about alternatives—Vite is the standard for a reason. It is repeatable, capable, and fast. To launch a new Vite app, you just enter the following in your command line:</p>



<pre class="wp-block-code"><code>$ npm create vite@latest</code></pre>



<p class="wp-block-paragraph">The interactive tool will walk you through the process, starting with selecting React as your technology:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/image3.png?w=1024" alt="A screenshot of the Vite CLI showing the option to select React." class="wp-image-4116905" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">Use your own preferences for the other options (like using <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a> versus JavaScript) and accept the option to install and launch the app immediately. Afterward, you’ll see a simple demo like this one:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/image4.png?w=1024" alt="A screenshot showing the Vite demo app built with React." class="wp-image-4116907" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">The demo app has a counter component like the one we built earlier. If you Ctrl-c (or Cmd-c) to kill the Vite process running in the terminal, you can <code>cd</code> into the new directory. From there, you can see where the counter component is defined, in <code>src/App.jsx</code> (or <code>App.tsx</code> if you have selected TypeScript like I have).</p>



<p class="wp-block-paragraph">It’s worth looking at that file to see how React appears on the server:</p>



<pre class="wp-block-code"><code>src/App.tsx
import { useState } from 'react'
import reactLogo from './assets/react.svg'
import viteLogo from '/vite.svg'
import './App.css'

function App() {
  const [count, setCount] = useState(0)

  return (
    
      <div>
        <a href="https://vite.dev/" target="_blank">
          <img src="https://www.infoworld.com/article/2253289/%7BviteLogo%7D" alt="Vite logo">
        </a>
        <a href="https://react.dev/" target="_blank">
          <img src="https://www.infoworld.com/article/2253289/%7BreactLogo%7D" alt="React logo">
        </a>
      </div>
      <h1>Vite + React</h1>
      <div>
        <button> setCount((count) =&gt; count + 1)}&gt;
          count is {count}
        </button>
        <p>
          Edit <code>src/App.tsx</code> and save to test HMR
        </p>
      </div>
      <p>
        Click on the Vite and React logos to learn more
      </p>
    &gt;
  )
}

export default App&lt;/code&gt;</code></pre>



<p class="wp-block-paragraph">Notice we export the App as a module, which is used by the <code>src/main.tsx</code> file to display the component in the view. That file creates the bridge between the respective worlds of React and HTML:</p>



<pre class="wp-block-code"><code>import { StrictMode } from 'react'
import { createRoot } from 'react-dom/client'
import './index.css'
import App from './App.tsx'

createRoot(document.getElementById('root')!).render(
  
    
  ,
)</code></pre>



<p class="wp-block-paragraph">Don’t worry too much about the details of how React bootstraps itself with <code>createRoot</code> and the <code>render</code> call (which you won’t have to interact with on a regular basis). The important thing is how the <code>App</code> component is imported and then used with the JSX.</p>



<p class="wp-block-paragraph"><strong>Note</strong></p>



<p class="wp-block-paragraph"><a href="https://react.dev/reference/react/StrictMode">Strict mode</a> adds warning during dev mode to help you catch component bugs early.</p>



<p class="wp-block-paragraph">There are a few rules to bear in mind when using JSX, the templating language of React:</p>



<ul class="wp-block-list">
<li>HTML elements are lowercase (<code><div>, <code></code>), but components are uppercase (<code></code>, <code></code>).



<li>You can’t just type “class” in JSX; instead, use <code>className</code>; e.g., <code><div>.



<li>To access the realm of JavaScript (and the application state) from within JSX, use curly braces: <code>{2 + 2 != 5}</code>.</li>




<h2 class="wp-block-heading">React components and props</h2>



<p class="wp-block-paragraph">The main organizational concept in React is the <em>component</em>. Components are used to contain the functionality for a part of the view within a self-contained package. We’ve seen a component in action already with <code></code> but it might be a little obscure, so let’s add another simple component to enhance the demonstration. This component also lets us explore another key part of React: Props.</p>



<p class="wp-block-paragraph">To start, let’s create a display of the counter value influenced by the Rob Reiner movie <em>This Is Spinal Tap</em>. To start, we create a new file at <code>src/VolumeDisplay.jsx</code>:</p>



<pre class="wp-block-code"><code>// src/VolumeDisplay.jsx

export function VolumeDisplay({ level }) {
  return (
    <div>
      {/* The Dial */}
      <div>= 11 ? '#d32f2f' : '#f0f0f0',
        color: level &gt;= 11 ? 'white' : 'black',
        transition: 'all 0.2s ease'
      }}&gt;
        {level}
      </div>

      {/* The Message */}
      {level &gt;= 11 &amp;&amp; (
        <p>
          "These go to eleven." 🤘
        </p>
      )}
    </div>
  );
}</code></pre>



<p class="wp-block-paragraph">This is a simple display but there are a couple of things worth noting about it.</p>



<p class="wp-block-paragraph">One is that we accept a prop (a property) “from above” with <code>VolumeDisplay({ level })</code>. This tells whatever parent component uses this one that <code>VolumeDisplay</code> accepts a single property, called <code>level</code>. <code>VolumeDisplay</code> uses the property by displaying it (though it adds a bit of fancying up using conditional logic like we have already seen).</p>



<p class="wp-block-paragraph">The way we define the CSS values, inside the double braces, <code>{{ }}</code>, and as a map of value is idiomatic React. (It isn’t essential at this point to grasp why it works that way, but basically, it is the JSX token <code>{ }</code> with a JavaScript map of CSS values using JavaScript-friendly camel-cased names, like <code>justifyContent</code>.)</p>



<p class="wp-block-paragraph">Now, to utilize this component, we can go to <code>App.jsx</code>, and make two changes:</p>



<pre class="wp-block-code"><code>import { useState } from 'react'
import reactLogo from './assets/react.svg'
import viteLogo from '/vite.svg'
import './App.css'
// 1. Import our new component
import { VolumeDisplay } from './VolumeDisplay'

function App() {
  const [count, setCount] = useState(0)

  return (
    
      <div>
        <a href="https://vite.dev/" target="_blank">
          <img src="https://www.infoworld.com/article/2253289/%7BviteLogo%7D" alt="Vite logo">
        </a>
        <a href="https://react.dev/" target="_blank">
          <img src="https://www.infoworld.com/article/2253289/%7BreactLogo%7D" alt="React logo">
        </a>
      </div>
      <h1>Vite + React</h1>
      <div>
        <button> setCount((count) =&gt; count + 1)}&gt;
          count is {count}
        </button>
        {/* 2. Pass the 'count' state into the 'level' prop */}
      
        <p>
          Edit <code>src/App.tsx</code> and save to test HMR
        </p>
      </div>
      <p>
        Click on the Vite and React logos to learn more
      </p>
    &gt;
  )
}

export default App&lt;/code&gt;</code></pre>



<p class="wp-block-paragraph">Here, we’ve done two things: imported the new component and used it in the view.</p>



<p class="wp-block-paragraph">Notice, also, that the <code></code> line passes the existing count state variable into <code>VolumeDisplay</code> as a prop. React will do the work of ensuring that whenever count changes, the <code>VolumeDisplay</code> will also be updated, including any dependent logic such as the conditional statements.</p>



<p class="wp-block-paragraph">Now, if we run the code like so:</p>



<pre class="wp-block-code"><code>$ npm run dev</code></pre>



<p class="wp-block-paragraph">We get what you see in the screenshot below:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/image5.png?w=1024" alt="A screenshot of the running demo app built with Vite and React." class="wp-image-4116908" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">The world is now your oyster, at least within the realm of JavaScript web development. Not only is React wildly popular, its basic ideas are applicable to a host of other innovative frameworks, including <a href="https://www.infoworld.com/article/2265950/hands-on-with-svelte.html">Svelte</a> and <a href="https://www.infoworld.com/article/2271109/hands-on-with-the-solid-javascript-framework.html">Solid</a>. (To get some idea of the alternatives, just type <code>npm create vite@latest</code> and look at all the available technologies.) Now that you have a basic introduction, a good next step for learning would be to add an <code></code> control that allows typing in the volume manually. Happy coding!</p>
</div></code></li></div></code></li></ul></div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Get started with Angular: Introducing the modern reactive workflow]]></title>
<description><![CDATA[Angular is a cohesive, all-in-one reactive framework for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to...]]></description>
<link>https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665664/ai-nachrichten/get-started-with-angular-introducing-the-modern-reactive-workflow/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Angular is a cohesive, all-in-one <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">reactive framework</a> for web development. It is one of the larger reactive frameworks, focused on being a single architectural system that handles all your web development needs under one idiom. While Angular was long criticized for being heavyweight as compared to <a href="https://www.infoworld.com/article/2253289/react-tutorial-get-started-with-the-reactjs-javascript-library.html">React</a>, many of those issues <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">were addressed in Angular 19</a>. Modern Angular is built around the <a href="https://blog.angular-university.io/angular-signals">Signals API</a> and minimal formality, while still delivering a one-stop-shop that includes dependency injection and integrated routing.</p>



<p class="wp-block-paragraph">Angular is popular with the enterprise because of its stable, curated nature, but it is becoming more attractive to the wider developer community thanks to its more <a href="https://www.infoworld.com/article/3802707/angular-team-unveils-strategy-for-2025.html">community engaged development philosophy</a>. That, along with its recent technical evolution, make Angular one of the most interesting projects to watch right now.</p>



<h2 class="wp-block-heading">Why choose Angular?</h2>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/2336227/whats-the-best-javascript-framework.html">Choosing a JavaScript development framework</a> sometimes feels like a philosophical debate, but it should be a practical decision. Angular is unique because it is strongly opinionated. It doesn’t just give you a view layer; it provides a complete toolkit for building web applications.</p>



<p class="wp-block-paragraph">Like other reactive frameworks, Angular is built around its reactive engine, which lets you bind state (variables) to the view. But if that’s all you needed, one of the smaller, more focused frameworks would be more than enough. What Angular has that some of these other frameworks don’t is its ability to use data binding to automatically synchronize data from your user interface (UI) with your JavaScript objects. Angular also leverages dependency injection and inversion of control to help structure your application and make it easier to test. And it contains more advanced features like server-side rendering (SSR) and static-site generation (SSG) within itself, rather than requiring you to engage a <a href="https://www.infoworld.com/article/3831686/plug-and-play-web-development-with-astro-js.html">meta-framework</a> for either style of development.</p>



<p class="wp-block-paragraph">While Angular might not be your top choice for every occasion, it’s an excellent option for larger projects that require features you won’t get with a more lightweight framework.</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">Catching up with Angular 19</a>.</strong></p>



<h2 class="wp-block-heading">Getting started with Angular</h2>



<p class="wp-block-paragraph">With those concepts in mind, let’s set up Angular in your development environment. After that, we can run through developing a web application with Angular. To start, make sure you have Node and NPM installed. From the command line, enter:</p>



<pre class="wp-block-code"><code>$ node -v
$ npm -v</code></pre>



<p class="wp-block-paragraph">Next, you can use the Angular CLI to launch a new app:</p>



<pre class="wp-block-code"><code>$ ng new iw-ng</code></pre>



<p class="wp-block-paragraph">You can use the defaults in your responses to the interactive prompts shown here:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular1.png?w=1024" alt="A screenshot of a new project setup in the Angular command-line interface." class="wp-image-4123771" width="1024" height="413" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">We now have a basic project layout in the new directory, which you can import into an IDE (such as <a href="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html" data-type="link" data-id="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html">VS Code</a>) or edit directly.</p>



<p class="wp-block-paragraph">Looking at the project layout, you might notice it is fairly lean, a break from Angular projects of the past. The most important parts are:</p>



<ul class="wp-block-list">
<li><code>src/main.ts</code>: This is the main entry point. In older versions of Angular, this file had to bootstrap a module, which then bootstrapped a component. Now, it avoids any verbose syntax, calling bootstrapApplication with your root component directly.</li>



<li><code>src/index.html</code>: The main HTML page that hosts your application. This is the standard index.html that serves all root requests in a web page and contains the  tag where your Angular component will render. It is the “body” that the “spirit” of your code animates.</li>



<li><code>src/app/app.ts</code>: The root component of your application. This single file defines the view logic and the component metadata. In the new “standalone” world, it manages its own imports, meaning you can see exactly what dependencies it uses right at the top of the file. (This is the <code></code> root element that appears in <code>src/index.html</code>.)</li>



<li><code>src/app/app.config.ts</code>: This file is new in modern Angular and replaces the old A<code>ppModule providers</code> array. It is where you configure global services, like the router or HTTP client.</li>



<li><code>angular.json</code>: The configuration file for the CLI itself. It tells the build tools how to process your code, though you will rarely need to touch this file manually anymore.</li>
</ul>



<p class="wp-block-paragraph">Here is the basic flow of how the engine renders these components:</p>



<ol start="1" class="wp-block-list">
<li><strong>The arrival (HTML)</strong>: The browser receives <code>index.html</code>. The <code></code> tag is there, but it’s empty.</li>



<li><strong>The unpacking (JavaScript)</strong>: The browser sees the <code></code> tags at the bottom of the HTML and downloads the JavaScript bundles (your compiled code) from <code>src/app/app.ts</code>.</li>



<li><strong>The assembly (Bootstrap)</strong>: The browser runs that JavaScript. The code “wakes up,” finds the <code></code> tag in the DOM, and dynamically inserts your title, buttons, and lists.</li>
</ol>



<p class="wp-block-paragraph">This flow will be different if you are using server-side rendering (SSR), but we’ll leave that option aside for now. Now that you’ve seen the basic architecture, let’s get into the code.</p>



<h2 class="wp-block-heading">Developing your first web app in Angular</h2>



<p class="wp-block-paragraph">If you open <code>src/app/app.ts</code> (more info <a href="http://app.ts/">here</a>) the component definition looks like this:</p>



<pre class="wp-block-code"><code>import { Component, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  protected readonly title = signal('iw-ng');
}</code></pre>



<p class="wp-block-paragraph">Before we dissect the code, let’s run the app and see what it produces:</p>



<pre class="wp-block-code"><code>$ ng serve</code></pre>



<p class="wp-block-paragraph">You should see a page like this one at <code>localhost:4200</code>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular2.png?w=1024" alt="A screenshot of a Hello, World! app built with Angular." class="wp-image-4123772" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">Returning to the <code>src/app.ts</code> component, notice that there are three main parts of the definition: the class, the metadata, and the view. Let’s unpack these separately.</p>



<h3 class="wp-block-heading">The class (export class App)</h3>



<p class="wp-block-paragraph">Export class <code>App</code> is vanilla TypeScript that holds your component’s data and logic. In our example, <code>title = signal(‘iw-ng’)</code> defines a piece of reactive state. Unlike older versions of Angular where data was just a plain property, here we use a <a href="https://www.solidjs.com/tutorial/introduction_signals">signal</a>. Signals are wrappers around values that notify the template precisely when they change, enabling fine-grained performance.</p>



<h3 class="wp-block-heading">The metadata (@Component)</h3>



<p class="wp-block-paragraph">The <code>@Component</code> decorator tells Angular it is dealing with a component, not just a generic class. There are several elements involved in the decorator’s communication with the engine:</p>



<ul class="wp-block-list">
<li><code>selector: 'app-root'</code>: Defines the custom HTML tag associated with any given component. Angular finds <code></code> in your <code>index.html</code> and renders the component there.</li>



<li><code>imports</code>: In the new Angular era, dependencies are explicit. You list exactly what a component needs (like <code>RouterOutlet</code> or other components) here, rather than hiding them in a separate module file.</li>



<li><code>templateUrl</code>: Points to the external HTML file that defines the view.</li>
</ul>



<h3 class="wp-block-heading">The view (the template)</h3>



<p class="wp-block-paragraph">This is the visual part of the component, defined in <code>app.html</code>. It combines standard HTML with Angular’s template syntax. (JSX handles this part for React-based apps.)</p>



<p class="wp-block-paragraph">We can modify <code>src/app/app.html</code> to see how these three elements work together. To start, delete the default content and add the following:</p>



<pre class="wp-block-code"><code><h1>Hello, {{ title() }}</h1>
</code></pre>



<p class="wp-block-paragraph">The double curly braces <code>{{ }}</code> are called <a href="https://angular.dev/guide/templates/binding">interpolation</a>. Notice the parentheses in <code>title()</code>. We are reading the “title” signal value by calling its function. If you were to update that signal programmatically (e.g., <code>this.title.set('New Value')</code>), the text on the screen would update instantly.</p>



<h2 class="wp-block-heading">Angular’s built-in control flow</h2>



<p class="wp-block-paragraph">Old-school Angular required “structural directives” like <code>*ngIf</code> and <code>*ngFor</code> logic control. These were powerful but required importing <code>CommonModule</code> and learning a specific micro-syntax. Modern Angular uses a built-in control flow that looks like standard JavaScript (similar to other Reactive platforms).</p>



<p class="wp-block-paragraph">To see the new control flow in action, let’s add a list to our component. Update <code>src/app/app.ts</code> as follows, leaving the rest of the file the same:</p>



<pre class="wp-block-code"><code>export class App {
  protected readonly title = signal('iw-ng');
  protected readonly frameworks = signal(['Angular', 'React', 'Vue', 'Svelte']);
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">While we’re at it, let’s also update <code>src/app/app.html</code> to render this new list (don’t worry about <code></code> for now; it just tells Angular where to render the framing template):</p>



<pre class="wp-block-code"><code><button>Toggle List</button>

@if (showList()) {
  <ul>
    @for (tech of frameworks(); track tech) {
      <li>{{ tech }}</li>
    }
  </ul>
} @else {
  <p>List is hidden</p>
}

</code></pre>



<p class="wp-block-paragraph">The app will now display a list that can be toggled for visibility:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/01/angular3.png?w=1024" alt="Screenshot of a list that can be toggled on and off for visibility." class="wp-image-4123773" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Matthew Tyson</p></div>



<p class="wp-block-paragraph">This syntax is cleaner and easier to read than the old <code>*ngFor</code> loops:</p>



<ul class="wp-block-list">
<li><code>@if</code> conditionally renders the block if the signal’s value is true.</li>



<li><code>@for</code> iterates over the array. The track keyword is required for performance (it tells Angular how to identify unique items in the list).</li>



<li><code>(click)</code> is an <a href="https://angular.dev/guide/templates/event-listeners">event binding</a>. It lets us run code (the <code>toggleList</code> method) when the user interacts with the button.</li>
</ul>



<h2 class="wp-block-heading">Services: Managing business logic in Angular</h2>



<p class="wp-block-paragraph">Components focus on the view (i.e., what you see). For the business logic that backs the application functionality, we use services.</p>



<p class="wp-block-paragraph">A service is just a class that can be “injected” into a component that needs it. This is Angular’s famous dependency injection system. It allows you to write logic once and reuse it anywhere. It’s a slightly different way of thinking about how an application is wired together, but it gives you real organizational benefits over time.</p>



<p class="wp-block-paragraph">To generate a service, you can use the CLI:</p>



<pre class="wp-block-code"><code>$ ng generate service frameworks</code></pre>



<p class="wp-block-paragraph">This command creates a <code>src/app/hero.ts</code> file. In modern Angular, we define services using the <code>@Injectable</code> decorator. Currently, the <code>src/app/hero.ts</code> file just has this:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root',
})
export class Frameworks {
  
}</code></pre>



<p class="wp-block-paragraph">Open the file and add a simple method to return our data:</p>



<pre class="wp-block-code"><code>import { Injectable } from '@angular/core';

@Injectable({
  providedIn: 'root', // Available everywhere in the app
})
export class Frameworks {
  getList() {
    return ['Angular', 'React', 'Vue', 'Svelte'];
  }
}</code></pre>



<p class="wp-block-paragraph">The providedIn: <code>'root'</code> metadata is important, it tells Angular to create a single, shared instance of this service for the entire application (you might recognize this as an instance of the <a href="https://en.wikipedia.org/wiki/Singleton_pattern">singleton pattern</a>).</p>



<h3 class="wp-block-heading">Using the service</h3>



<p class="wp-block-paragraph">In the past, we had to list dependencies in the constructor. Modern Angular offers a cleaner way: the <code>inject()</code> function. Subsequently, we can refactor our <code>src/app/app.ts</code> to get its data from the service instead of hardcoding it:</p>



<pre class="wp-block-code"><code>import { Component, inject, signal } from '@angular/core';
import { RouterOutlet } from '@angular/router';
import { Frameworks } from './frameworks'; // Import the service

@Component({
  selector: 'app-root',
  imports: [RouterOutlet],
  templateUrl: './app.html',
  styleUrl: './app.css'
})
export class App {
  private frameworksService = inject(Frameworks); // Dependency Injection
  
  protected readonly title = signal('iw-ng');
  
  // Initialize signal with data directly from the service
  protected readonly frameworks = signal(this.frameworksService.getList());
  protected showList = signal(true);

  toggleList() {
    this.showList.update(v =&gt; !v);
  }
}</code></pre>



<p class="wp-block-paragraph">Dependency injection is a powerful pattern. The component doesn’t need to know where the list came from (it could be coming from an API, a database, or a hard-coded array); it just asks the service for what it needs. This pattern adds a bit of extra work up front, but it delivers a more flexible, organized codebase as the app grows in size and complexity.</p>



<h2 class="wp-block-heading">Routers and routes</h2>



<p class="wp-block-paragraph">Once your application grows beyond a single view, you need a way to navigate between different screens. In Angular, we use the built-in router for this purpose. In our example project, <code>src/app/app.routes.ts </code>is the dedicated home for the router config. Let’s follow the steps for creating a new route.</p>



<p class="wp-block-paragraph">First, we define the route. When you open <code>src/app/app.routes.ts</code>, you will see an exported routes array. This array contains the available routes for your app. Each string name resolves to a component that handles rendering that route. In effect, this is the map of your application’s landscape.</p>



<p class="wp-block-paragraph">In a real application, you’d often have “framing template” material in the root of the app (like the navbar) and then the routes fill in the body content. (Remember that by default, Angular is designed for single-page apps, where navigation does reload the screen, but swaps content.)</p>



<p class="wp-block-paragraph">For now, let’s just get a sense of how the router works. First, create a new component so we have a destination to travel to. In your terminal, run:</p>



<pre class="wp-block-code"><code>$ ng generate component details</code></pre>



<p class="wp-block-paragraph">This will generate a simple <code>details</code> component in the <code>src/app/details</code> directory.</p>



<p class="wp-block-paragraph">Now we can update <code>src/app/app.routes.ts</code> to include this new path. We will also add a “default” path that redirects empty requests to the home view, ensuring the user always lands somewhere:</p>



<pre class="wp-block-code"><code>import { Routes } from '@angular/router';
import { App } from './app'; // Matches src/app/app.ts
import { Details } from './details/details'; // Matches src/app/details/details.ts

export const routes: Routes = [
  { path: '', redirectTo: '/home', pathMatch: 'full' },
  { path: 'home', component: App },
  { path: 'details', component: Details },
];</code></pre>



<p class="wp-block-paragraph">Now if you visit <code>localhost:4200/home</code>, you’ll get the message from the <code>details</code> component: “Details works!”</p>



<p class="wp-block-paragraph">Next, we’ll use the <code>routerLink</code> directive to move between views without refreshing the page. In <code>src/app/app.html</code>,  we create a navigation bar that sits permanently at the top of the page (the “stationary” element), while the router swaps the content below it (the “impermanent” element):</p>



<pre class="wp-block-code"><code><nav>
  <a>Home</a> | 
  <a>Details</a>
</nav>

<hr>

</code></pre>



<p class="wp-block-paragraph">And with that, the application has a navigation flow. The user clicks, the URL updates, and the content transforms, all without the jarring flicker of a browser reload.</p>



<h2 class="wp-block-heading">Parametrized routes</h2>



<p class="wp-block-paragraph">The last thing we’ll look at is handling route parameters, where the route accepts variables in the path. To manage this kind of dynamic data, you define a route with a variable, marked by a colon. Open <code>src/app/app.routes.ts</code> and add a dynamic path:</p>



<pre class="wp-block-code"><code>export const routes: Routes = [
  // ... existing routes
  { path: 'details/:id', component: Details }, 
];</code></pre>



<p class="wp-block-paragraph">The <code>:id</code> is a placeholder. Whether the URL is <code>/details/42</code> or <code>/details/108</code>, this router will receive it because it matches the path. Inside the details component, we have access to this parameter (using the <a href="https://angular.dev/api/router/ActivatedRoute">ActivatedRoute</a> service or the new <a href="https://angular.dev/api/router/withComponentInputBinding">withComponentInputBinding</a>). We can use that value to retrieve the data we need (like using it to recover a detail item from a database).</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">We have seen the core elements of modern Angular: Setting up the environment, building reactive components with signals, organizing logic with services, and tying it all together with interactive routing.</p>



<p class="wp-block-paragraph">Deploying these pieces together is the basic work in Angular. Once you get comfortable with it, you have an extremely powerful platform at your fingertips. And, when you are ready to go deeper, there is a whole lot more to explore in Angular, including:</p>



<ul class="wp-block-list">
<li>State management: Beyond signals, Angular has support for managing complex, application-wide state.</li>



<li>Forms: Angular has a robust system for handling user input.</li>



<li>Signals: We only scratched the surface of signals here. Signals offer a powerful, fine-grained way to manage state changes.</li>



<li>Build: You can learn more about producing production builds.</li>



<li><a href="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html" data-type="link" data-id="https://www.infoworld.com/article/3964105/catching-up-with-angular-19.html">RxJS</a>: Takes reactive programming to the next level.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What the CAIO wave signals for UK companies yet to follow suit]]></title>
<description><![CDATA[The Chief AI Officers who are making a real difference today look very different. They are evolving into P&L owners.]]></description>
<link>https://tsecurity.de/de/3665609/it-nachrichten/what-the-caio-wave-signals-for-uk-companies-yet-to-follow-suit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665609/it-nachrichten/what-the-caio-wave-signals-for-uk-companies-yet-to-follow-suit/</guid>
<pubDate>Mon, 13 Jul 2026 16:47:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Chief AI Officers who are making a real difference today look very different. They are evolving into P&amp;L owners.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.1]]></title>
<description><![CDATA[OpenClaw 2026.7.1]]></description>
<link>https://tsecurity.de/de/3665369/downloads/v202671/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665369/downloads/v202671/</guid>
<pubDate>Mon, 13 Jul 2026 15:17:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.1</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 5 Best MagSafe Power Banks for iPhone in 2026]]></title>
<description><![CDATA[Apple’s MagSafe charging ecosystem has drastically changed the way users can power their iPhones while on the move. Rather than carrying around a long cable, the best magnetic power banks in 2026 are able to snap securely to the back of a device, providing users with a convenient way to charge th...]]></description>
<link>https://tsecurity.de/de/3665296/ios-mac-os/the-5-best-magsafe-power-banks-for-iphone-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665296/ios-mac-os/the-5-best-magsafe-power-banks-for-iphone-in-2026/</guid>
<pubDate>Mon, 13 Jul 2026 14:54:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple’s MagSafe charging ecosystem has drastically changed the way users can power their iPhones while on the move. Rather than carrying around a long cable, the best magnetic power banks in 2026 are able to snap securely to the back of a device, providing users with a convenient way to charge their devices when travelling, commuting, or simply being away from a power outlet. 



Today’s MagSafe-compatible batteries go well beyond portability. With features like Qi2 and Qi2.2 certification, faster wireless charging, and slimmer designs, among other features, they can be far more practical than models of the past. Based on charging speeds, small profiles, and good value, we’re taking a look at the five best MagSafe power banks for your iPhone. 



1. INIU SnapGo Air 10,000 mAh Power Bank







Topping our list is the INIU SnapGo Air 10,000mAh Power Bank for its focus on portability without sacrificing charging performance. With a thickness around 13.8mm (0.5 inches), the SnapGo Air is one of the thinnest Qi2.2-certified magnetic power banks currently available. To give it a premium feel, the device features an aluminum body along with a soft-touch finish, and there’s also a minimalist side-mounted display for easily reading battery information. To really round-out the device, INIU included a USB-C GoCord that serves as both a charging cable for your iPhone as well as the power bank itself — great for those who forget to pack a cable. 



Of course, it’s the charging power that truly matters, and SnapGo Air’s Qi2.2 certification allows for 25W wireless charging. For those used to 7.5 Wi charging, they’re going to notice a difference. The USB-C cable also supports up to 45W wired output for those really wanting speed. For physical connections to the iPhone, INIU also included a strong 13N magnet that attaches securely for everyday use. With the 10,000mAh capacity providing plenty of juice for commuting, traveling, or just long periods away from an outlet, the INIU SnapGo Air can be an excellent companion for iPhone users. 



2. LISEN Ultra Slim MagSafe Power Bank



Photo Credit: LISEN



Those looking solely at portability may want to consider the LISEN Ultra Slim MagSafe Power Bank, and it’s one of the easier recommendations to make. Its card-like profile is good for being discrete even when attached to an iPhone, so keeping it in your pocket isn’t really an issue even when you’re charging. With a 10,000mAh capacity, most users will have little issues getting an all-day charge on their iPhone without needing an outlet, and its magnetic alignment keeps everything in place.



There’s a couple of extras that LISEN includes that can improve usability, including the addition of multiple charging methods and support for the Apple Watch. However, it’s not truly going to match the speeds offered by Qi2.2 competitors. Nonetheless, it has an excellent balance between portability and convenience. Those wanting an iPhone charging pack they can keep on throughout the day may want to look into this one. 



3. Statik State Power Bank



Photo Credit: Statik



The Statik State Power Bank stands out for its semi-solid-state battery technology that has a larger emphasis on longevity and durability. Statik also takes safety into consideration, as its approach can offer better protections over traditional lithium-ion designs. It’s approved for TSA travel and has a design that’s meant to withstand years of regular use. This one can be especially appealing for those that frequently travel.



Featuring a 5,000mAh capacity, the Statik Power Bank is likely better suited for occasional top-offs rather than keeping a device charged multiple times. However, it can still be a strong contender for an everyday use accessory. Keep in mind that the wireless charging will be limited to 7.5W, but the device does have a reliable magnetic connection alongside solid recharging efficiency. Anyone needing a charger that focuses on safety, longevity, and a compact size may want to consider this one as an option. 



4. UGREEN 5,000mAh Magnetic Power Bank



Photo Credit: UGREEN



UGREEN has done a good job of building a strong reputation for reliable charging accessories, and its 5,000mAh Magnetic Power Bank only continues that trend. This one has more of a focus on being an emergency battery rather than an all-day power source, but its compact design makes it suitable for slipping into a pocket without much notice. It also features strong magnets for providing a secure alignment on compatible iPhone models, though it also supports wired USB-C connections. 



Though it’s 5,000mAh capacity may have some troubles with large iPhone Pro Max models, it’s going to be great for getting users through a busy day. The company has provided consumers with devices that show consistently strong build quality, making this one something that can feel right at home within an Apple user’s arsenal. This is going to be a good choice for anyone that prefers portability over a maximum battery capacity. 



5. Kuxiu B10 Ultra Slim Power Bank



Photo Credit: Kuxiu



We’re ending this list with Kuxiu B10 Ultra Slim Power bank for its exceptionally thin profile and premium construction. Like other newer magnetic batteries, it has a focus on comfort when attached to an iPhone, and it does a rather good job of avoiding giving users a bulky feeling in their hand or pocket. It sports a minimalist design while still being built from quality materials, making it feel more like a premium accessory rather than a typical portable charger. 



It’s solid on performance, as well. It features fast wireless charging and also includes USB-C options for some good versatility, and users can rely on it as an everyday carry. However, a slim profile comes with a bit of compromise when compared to bulkier packs with higher capacities. Nonetheless, Kuxiu does a good job balancing portability and performance. It’s going to be a grat option for those looking for a power bank that doesn’t interfere with your iPhone use. 



The Final Word: What's the Best MagSafe Power Bank?



It isn’t hard finding a barrage of MagSafe-compatible power banks in 2026, but users should expect more from an accessory aside from some additional battery life. A good battery pack should be comfortable to carry, provide efficient charging, and even integrate naturally into your phone habits without feeling like you’re carrying around something bulky. 



Each item on this list has its own set of strengths, but we find that INIU SnapGo Air earns the top spot for offering the complete package. With an ultra-slim design, official Qi2.2 certification, fast 25W charging speeds, and an integrated USB-C GoCord, the SnapGo Air is going to be a great choice for iPhone users looking for an everyday carry. ]]></content:encoded>
</item>
<item>
<title><![CDATA[[Review] INIU SnapGo Air 10,000mAh Power Bank: A Slim Battery Built for Everyday Carry]]></title>
<description><![CDATA[People often choose an iPhone for its promised all-day battery life, but having a reliable external charger can still be an Apple fan’s best friend. Finding any random magnetic power bank on Amazon isn’t too difficult, but finding a quality charger that suits a device and has the specs to match i...]]></description>
<link>https://tsecurity.de/de/3665295/ios-mac-os/review-iniu-snapgo-air-10000mah-power-bank-a-slim-battery-built-for-everyday-carry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665295/ios-mac-os/review-iniu-snapgo-air-10000mah-power-bank-a-slim-battery-built-for-everyday-carry/</guid>
<pubDate>Mon, 13 Jul 2026 14:54:05 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[People often choose an iPhone for its promised all-day battery life, but having a reliable external charger can still be an Apple fan’s best friend. Finding any random magnetic power bank on Amazon isn’t too difficult, but finding a quality charger that suits a device and has the specs to match isn’t as simple. As someone who likes to have some additional juice for his iPhone 17 Pro, the INIU SnapGo Air 10,000mAh Power Bank caught my interest for a number of reasons. 



With an ultra-thin design, integrated USB-C cable, and official Qi2.2 certification, the SnapGo Air offers some nice features beyond a large battery capacity. We’re taking a look at exactly what this device offers, who it benefits, and we’ll even briefly explore why INIU can be a solid brand for iPhone accessories. 



A Design Built for iPhone







When you need to carry around an external battery, going with something that doesn’t take up a lot of space can be essential -- especially if you’re considering it as an everyday carry. With a thickness of just 13.8mm (0.5 inches), INIU boasts that it’s the slimmest Qi2.2 magnetic power bank to date, and you can notice the difference the moment it’s in your hands. 



To compliment this slim design, the SnapGo Air features an anodized aluminum enclosure alongside a soft-touch finish that overall gives a premium feel to the device. There’s also a side-mounted digital display for pertinent charging information. It feels good in the hand when connected to an iPhone, meaning it provides a battery charge without interrupting your smartphone tasks and habits. 



Fast Wireless Charging Where It Counts







Long time iPhone owners may remember the old days when MagSafe accessories offered  convenience but little in actual charging speeds, but the introduction of Qi2.2 charging has really shaken things up for the better. Being a certified Qi2.2 product, the SnapGo Air boasts up to 25W charging speeds, meaning users can power an iPhone 17 Pro to 50% battery in about 33 minutes .For comparison, a 7.5 Qi charger can take around 63 minutes.



Speedy charge times are always great, but maintaining that magnetic connection is also important. Fortunately, INIU provided the SnapGo Air with a 13N magnetic grip, meaning it’s going to stay attached just fine during normal everyday movement. Magnetic charging supports any device within the iPhone 12 through iPhone 17 lineup, making the SnapGo Air suitable for a variety of Apple smartphones. 



A Cable Built for Convenience







There’s been more than one time I’ve found myself with a dying iPhone and a power bank yet no charging cable to speak of, and it’s not a fun situation. Thankfully, INIU included a built-in USB-C GoCord cable that serves double duty. Along with being able to support up to 45W of wired charging output, users can also charge the power bank with the cable. 



For my iPhone, I was able to get my device from 20% battery to 78% percent in about 25 minutes, and I was able to fully charge the SnapGo Air in about 1.8 hours. Whether I’m looking to just get some quick charging action while I play mobile games or I’m hoping my power bank will get me through a long flight, the SnapGo Air has yet to let me down. 



Premium Charging for a Premium Phone







One thing I appreciate about the SnapGo Air is the amount of effort that went into crafting the product. It makes sense, however, as INIU has helped serve over 40 million customers across 174 countries since 2014. The company has been continuing to invest in charging technologies, industrial design, and even sustainability initiatives. It’s likely why the company has earned itself over 100+ global design patents alongside iF Design, Red Dot, and CES Innovation Awards. 



Tech companies come and go, but the ones that can truly be relied on for longevity typically go beyond a white-label approach to products and their design. It’s something that separates the products meant to make a buck from the ones that will last along with the rest of your tech.



The Final Word: Should You Get the SnapGo Air? 



Anyone needing a power bank for an iPhone that supports wireless charging is likely going to be highly pleased with the SnapGo Air. It’s minimal design keeps things physically unobtrusive, and overall it did well keeping my iPhone energized when I really needed it. It’s going to be great for those that find themselves going long periods of time without having access to more direct charging, but those that just need a quick boost are sure to get plenty of mileage out of it as well.



The SnapGo Air shows a lot of promise, and its Qi2.2 certification, premium materials, and slim profile makes it an overall suitable accessory for those constantly searching for power. You can find the device on the company’s website, but you can also check out SnapGo Air’s Amazon page if you want to learn more or even try it out for yourself.  ]]></content:encoded>
</item>
<item>
<title><![CDATA[Leaked iPhone Ultra Mockup Reveals A Serious Weight And Size Concern]]></title>
<description><![CDATA[The second half of the year promises major hardware announcements, with new folding phones capturing most of the attention. A recent image leak shows what appears to be a mockup unit for a highly anticipated foldable iPhone. While fans have patiently waited several years for this hardware, the ne...]]></description>
<link>https://tsecurity.de/de/3665035/ios-mac-os/leaked-iphone-ultra-mockup-reveals-a-serious-weight-and-size-concern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665035/ios-mac-os/leaked-iphone-ultra-mockup-reveals-a-serious-weight-and-size-concern/</guid>
<pubDate>Mon, 13 Jul 2026 13:10:32 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The second half of the year promises major hardware announcements, with new folding phones capturing most of the attention. A recent image leak shows what appears to be a mockup unit for a highly anticipated foldable iPhone. While fans have patiently waited several years for this hardware, the newly leaked physical dimensions highlight a potential problem when placed next to its biggest upcoming rival from Samsung.



The upcoming foldable device carries significantly more physical weight



According to noted tipster Ice Universe, the upcoming iPhone Ultra will feel noticeably bulkier in the hand compared to the standard Galaxy Z Fold 8. While both brands are pushing for a portable book-style design, Samsung seems to have an edge in ergonomics.




https://twitter.com/UniverseIce/status/2076235287714537568




Leaked measurements show the Apple device coming in at 120.6 by 83.8 by 9.6 millimeters when folded. When open, it measures 4.8 millimeters thick. The Fold 8, on the other hand, is slightly taller but thinner, sitting at 9.7 millimeters folded and dropping to 4.5 millimeters unfolded.



The biggest difference lies in the actual heft of the hardware. The Fold 8 is expected to weigh a very light 201 grams. In contrast, the iPhone Fold is rumored to reach 255 grams. This 54-gram gap is hard to ignore during daily use, making the Samsung option much easier to hold for long reading or viewing sessions.



Pent-up demand gives the heavier phone a sales advantage



Despite the heavier build, the new device will likely still dominate the market. Samsung plans to split its customer base by offering both a standard Fold 8 and a premium Fold 8 Ultra. Meanwhile, Apple is putting all its focus into a single flagship folding option.



Because iOS users have waited seven years for a folding screen, early sales will rely heavily on brand loyalty rather than sheer hardware specifications. The single model strategy ensures that every buyer wanting a folding iOS device will purchase the same unit.



Even with a thicker and heavier body, the massive built up excitement guarantees a strong launch. However, if Samsung delivers a drastically lighter and more comfortable device, some buyers might start weighing their options more carefully in the future.]]></content:encoded>
</item>
<item>
<title><![CDATA[Which AI model should you bet your company on?]]></title>
<description><![CDATA[Every day this past week I did something I suspect millions of other people also did: I stared at an LLM model picker and wondered which one I was supposed to want.



OpenAI just released ⁠GPT-5.6 Sol, Terra, and Luna. Sol is the flagship. Terra offers much of its intelligence for less money. Lu...]]></description>
<link>https://tsecurity.de/de/3664783/ai-nachrichten/which-ai-model-should-you-bet-your-company-on/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664783/ai-nachrichten/which-ai-model-should-you-bet-your-company-on/</guid>
<pubDate>Mon, 13 Jul 2026 11:33:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Every day this past week I did something I suspect millions of other people also did: I stared at an <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLM </a>model picker and wondered which one I was supposed to want.</p>



<p>OpenAI just released ⁠<a href="https://openai.com/index/gpt-5-6/">GPT-5.6 Sol, Terra, and Luna</a>. Sol is the flagship. Terra offers much of its intelligence for less money. Luna is cheaper still. Anthropic released ⁠<a href="https://www.anthropic.com/news/claude-sonnet-5">Claude Sonnet 5</a> at the end of June and Opus 4.8 the month prior, with a little Fable 5 emerging in between. Meanwhile, Google, which seemed to be winning the model wars a few months ago, is now getting shade from Gergely Orosz, who ⁠<a href="https://x.com/GergelyOrosz/status/2075160978493210685?s=20">argues that Gemini has slipped outside the top tier</a> for software development and has been out of the major model release game for <em>eons</em> (May 19).</p>



<p>Perhaps Orosz is right. Perhaps he’ll be wrong again in six weeks. Honestly, it’s exhausting.</p>



<p>I use ChatGPT and Claude constantly and still have no principled idea which model to choose most of the time. I tend to click whatever looks like the biggest, most expensive option because I don’t know what I’m giving up by choosing something smaller. “Instant” sounds dangerously unserious. “Thinking” sounds expensive but powerful.</p>



<p>A quick <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/">survey of my LinkedIn crowd</a> suggests others also feel my “WHICH MODEL???” pain. More importantly, I suspect most enterprises do, too.</p>



<h2 class="wp-block-heading"><a></a>A model doesn’t rot</h2>



<p>Before getting carried away, however, it’s worth considering whether any of this model churn actually matters. After all, a model doesn’t rot. The model an enterprise put into production in March performs just as well in July as it did when the company selected it. “Obsolete” generally means that something better now exists, not that the deployed model suddenly stopped summarizing insurance claims or classifying support tickets. (In other words, once you have something working, the idea that “but maybe Opus 200.2 is better!” is really a FOMO problem, not a performance issue.)</p>



<p>Most enterprise workloads don’t live at the frontier anyway. Extraction, summarization, classification, document comparison, and customer-service assistance often work perfectly well with smaller, cheaper models. OpenAI’s own pitch for the trio of GPT-5.6 models isn’t simply that Sol is better. It’s that ⁠Terra and Luna deliver different combinations of intelligence, latency, and cost. Luna, the cheapest tier, nearly matches the previous generation’s peak performance at less than half the estimated cost, according to OpenAI.</p>



<p>The practical question, of course, is where to start. An enterprise can’t test every model, every reasoning setting, and every price tier before doing any work. So here’s my advice (which I don’t follow in my own work, but I’m not defining enterprise strategy and can be a little price-insensitive). Start with the cheapest credible model that appears capable of the task. Give it a representative set of real examples and, before you start testing, define what counts as good enough. If it passes, stop. If it fails, move up a tier or try a model with strengths better suited to the work.</p>



<p>That sounds almost offensively simple, but it reverses the way many people, including me, use these products. We start with the biggest model because we’re afraid of what we might lose. Enterprises should start lower and require evidence before paying for more intelligence.</p>



<p>There are exceptions, of course. For genuinely difficult work, such as autonomous coding, complex research, or high-stakes reasoning, beginning with a frontier model may save time. But even then, the goal should be to establish a quality ceiling, then test whether a cheaper model can meet it. It’s changing the question from “which model is best?” to “what is the least expensive model that reliably clears the bar for this job?”</p>



<p>For many workloads, that price improvement matters more than a few extra benchmark points. <a href="https://www.infoworld.com/article/2335519/ai-hype-isnt-helping-anyone.html">⁠As I argued back in 2023</a>, following AI hype doesn’t help anyone. If your model strategy depends on whichever benchmark screenshot is circulating on X this week, you don’t have a strategy. Not a viable one, anyway. Pick a model and ignore the noise.</p>



<p>Except, of course, when that noise suggests a serious signal.</p>



<h2 class="wp-block-heading"><a></a>Sometimes better really is better</h2>



<p>Frontier improvements aren’t always incremental, making it advantageous to consider an upgrade. Coding is the obvious example. There’s a significant difference between a model that suggests the next few lines of code and one that can inspect a repository, plan a change, use tools, run tests, discover its own mistakes, and keep working for an extended period. That isn’t merely a nicer autocomplete experience. It can reorganize a development workflow.</p>



<p>This is why enterprises can’t simply standardize on an 18-month-old model and declare victory. In some areas, particularly software development and other agentic work, better models can unlock compounding productivity. A model that reliably completes 80% of a bounded task rather than 50% may justify an entirely different division of labor between humans and machines.</p>



<p>Still, that upgrade isn’t free.</p>



<p>Models differ in how they interpret instructions, call tools, manage context, refuse requests, and fail. Prompts and scaffolding tuned for one model can regress when moved to another. Or costs can explode. As one of my Oracle colleagues discovered just this week, running the same tasks in GPT 5.6 was orders of magnitude more expensive than 5.5. The API change may be trivial, but the revalidation and implications are not.</p>



<p>This leaves enterprises caught between two bad options. They can freeze and potentially miss out on meaningful improvements or chase every release and repeatedly test production systems on faith. What to do?</p>



<h2 class="wp-block-heading"><a></a>Stop making model bets</h2>



<p>The answer is to stop making LLM bets and start making job-to-be-done bets. Stop asking which model is fastest. Instead, figure out what work you are trying to improve. What does a good result look like? How much latency and cost can the workflow tolerate? How wrong can it be before a human must intervene? Once those questions have answers, model selection becomes less opaque.</p>



<p>A difficult code migration may justify GPT-5.6 Sol or Claude Sonnet 5. A repetitive classification task may work just as well with Luna or another smaller model. A regulated workflow may require a model or deployment option that offers particular data controls. Sometimes the correct model is no LLM at all, like when I’m writing this post. Sorry, AI vendors! (At least you won’t get blamed for my mistakes.)</p>



<p>This is where evaluations become the center of enterprise AI strategy. <a href="https://www.infoworld.com/article/4166247/improving-ai-agents-through-better-evaluations.html">⁠As I’ve said before</a>, most companies don’t have an AI quality problem so much as an AI measurement problem. Hence, a private evaluation suite built from real company work is the only leaderboard that matters. Does the new model materially improve quality? If so, use it! Does it reduce cost or latency? Again, that’s your free pass to adoption. Does the improvement justify the expense and effort of revalidation? If yes, continue.</p>



<h2 class="wp-block-heading"><a></a>Make model releases boring</h2>



<p>As important as the model is, keep in mind that AI success always comes back to <em>your</em> company’s data, <em>your</em> company’s workflows<em>, your</em> company’s integrations, etc. That’s the ⁠<a href="https://www.infoworld.com/article/4157506/mastering-the-dull-reality-of-sexy-ai.html">dull reality behind sexy AI</a>. Retrieval, <a href="https://www.infoworld.com/article/4189492/how-to-improve-the-memory-of-ai-agents.html">memory</a>, governance, data quality, <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a>, and feedback loops aren’t as exciting as a new model launch, but they’re what ultimately make AI truly work.</p>



<p>Again, when it’s time to consider something new, the principle should be to default to the least expensive model that reliably passes your evaluations. Only escalate harder tasks to more capable models when measurement shows that the premium pays. Tip: Make this invisible to employees so that the system routes to the best model for a particular prompt. As <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/?dashCommentUrn=urn%3Ali%3Afsd_comment%3A%287481372047860715522%2Curn%3Ali%3Aactivity%3A7481369774401409024%29">dbt Labs’ Jon Lewis expresses</a> it, “The best model is ‘Auto’ and I won’t hear anyone say otherwise.” OpenAI’s own ⁠<a href="https://developers.openai.com/api/docs/guides/latest-model">migration guidance</a> recommends testing models on representative tasks, including trying a lower reasoning level rather than automatically cranking everything to the maximum.</p>



<p>As for me, I’ll probably keep clicking the shiniest option. I don’t have a formal evaluation suite for InfoWorld columns, and the marginal cost is a subscription I already pay. Enterprises don’t get that excuse.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Where the software development jobs are now]]></title>
<description><![CDATA[While many technology companies have slowed hiring or even launched significant layoffs, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with knowledge of AI—are in demand in other industries.



The key to success for deve...]]></description>
<link>https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</guid>
<pubDate>Mon, 13 Jul 2026 11:33:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While many technology companies have slowed hiring or even launched <a href="https://www.trueup.io/layoffs" data-type="link" data-id="https://www.trueup.io/layoffs">significant layoffs</a>, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with <a href="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html" data-type="link" data-id="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html">knowledge of AI</a>—are in demand in other industries.</p>



<p>The key to success for developers looking to snatch up these roles is to be well-prepared to meet the needs of potential employers in a variety of sectors.</p>



<p>“The demand for developers in non-tech sectors is real and growing, but the roles look different from what you’d find at a software company,” says <a href="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/" data-type="link" data-id="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/">Pragati Awasthi</a>, assistant teaching professor of AI and data science at Drexel University.</p>



<p>“Across all these sectors, the common thread is that software is no longer a support function; it is embedded in core operations,” Awasthi says. “The developer in these environments is often the person translating domain-specific business problems into technical solutions, which requires a different profile than a pure product engineer at a tech firm.”</p>



<h2 class="wp-block-heading">Opportunity knocks</h2>



<p>The tech industry has long been a mainstay as far as employing software developers. But as these businesses trim staffs in efforts to cut expenses, that has impacted the hiring landscape. Even as the tech sector scales back, however, companies in industries such as financial services/fintech, healthcare/healthtech, retail/ecommerce, and manufacturing are looking to acquire programming talent.</p>



<p>“The unifying factor is data complexity,” Awasthi says. “These industries generate large volumes of sensitive, regulated, or operationally critical data, and they need developers who can build and maintain systems that handle it responsibly.”</p>



<p>While recruiting firm Summit Search Group has placed developers in roles with technology companies, “it is just as common to recruit them for roles outside this niche,” says <a href="https://www.linkedin.com/in/matterhard/" data-type="link" data-id="https://www.linkedin.com/in/matterhard/">Matt Erhard</a>, managing partner at the company. “There are actually a fairly wide variety of roles available for developers in industries beyond tech,” Erhard says.</p>



<p>For example, in financial services Summit Search Group has seen significant hiring for back-end and data engineers who can build and maintain fraud detection systems, digital banking platforms, and regulatory tools, Erhard says. In healthcare, companies are hiring developers to build AI-driven diagnostics platforms and patient portals, or to work with systems that manage electronic health records, he says.</p>



<p>In manufacturing and industrial companies, developers are needed for systems integration and embedded software related to predictive maintenance, <a href="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html" data-type="link" data-id="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html">Internet of Things</a> (IoT) systems, and smart factories. And in retail and ecommerce, there’s strong demand for <a href="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html" data-type="link" data-id="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html">full-stack developers</a> and data developers who can handle logistics systems, omni-channel platforms, and personalization engines, Erhard says.</p>



<p>“One significant function where we’ve been placing developer talent lately is in developing business systems and internal applications,” Erhard says. These roles often have titles such as systems engineer or application developer, and professionals are hired to handle tasks such as customizing customer relationship management (CRM) or enterprise resource planning (ERP) platforms, building workflow automation tools or modernizing legacy systems, he says.</p>



<p>Other core functions for which Summit Search Group has placed a lot of developers include data, analytics, and AI-enablement. “That could be directly involved with <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">data engineering</a> or in building tools like reporting systems and <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">ETL [extract, transform, load]</a> pipelines,” Erhard says.</p>



<p>The firm also has handled searches for developers who can build and maintain customer-facing products for banking, healthcare, and retail companies, such as mobile apps or digital platforms customers can use to interact with companies.</p>



<p>Randstad Digital, a provider of global technology talent, sees demand for roles including web developers, system developers, and app developers. “These professionals would work on anything from customer-facing platforms to internal tools,” says <a href="https://www.linkedin.com/in/mpmorris36/" data-type="link" data-id="https://www.linkedin.com/in/mpmorris36/">Michael Morris</a>, global head of platform and talent at the company. “Non-tech companies are also often hiring roles like software architecture and <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> to help scale existing technology. These involve being more ingrained in the business, like building a supply chain system for a retailer, rather than creating individual tech products like you would at a technology company.”</p>



<h2 class="wp-block-heading">Prep for success</h2>



<p>To increases the chances of success at landing developer jobs outside of the tech industry, development professionals would be wise to follow some good practices.</p>



<h3 class="wp-block-heading">Boost AI skills</h3>



<p>One best practice is to boost skills in using AI-powered tools and get familiar with all things AI.</p>



<p>“Get fluent with AI-assisted development and its limits,” Awasthi says. “This is not optional. Organizations across every sector expect developers to use AI coding tools productively. But the more durable skill is knowing when AI output is wrong, incomplete, or unsuitable for a regulated context. That critical evaluation capacity is what non-tech employers are increasingly trying to hire.”</p>



<p>AI does not necessarily replace the need for human developers so much as it changes the skills profile for those roles, Erhard says. “The biggest difference in recent years is that AI literacy is now a non-negotiable,” he says. “At minimum, developers today need to understand concepts like <a href="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html" data-type="link" data-id="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html">prompt engineering</a> and how to use AI tools to improve their efficiency.”</p>



<p>One thing many job candidates don’t expect is that the rise of AI has also increased the importance of high-level skills such as problem framing, system design, and cross-functional communication,” Erhard says. “Essentially, if something is related to development but too complex or nuanced for an AI to handle effectively, then the demand is high for human developers who have that expertise,” he says.</p>



<p>Candidates who land roles consistently have experience building AI-augmented workflows along with standard coding skills, Erhard says. “Employers increasingly expect to hire developers who can leverage AI, so demonstrating this experience on your résumé can be very beneficial,” he says.</p>



<h3 class="wp-block-heading">Gain domain knowledge</h3>



<p>Summit Search Group is seeing high demand for developers with deep domain knowledge in an organization’s specific industry. “So, for instance, if someone is both an experienced developer and has expertise in healthcare compliance, or financial regulations, then those candidates tend to be very sought after,” Erhard says.</p>



<p>Domain fluency is an underrated skill, Awasthi says. “A developer who understands healthcare compliance, financial regulation, or manufacturing process logic is significantly harder to replace than one who only writes clean code,” she says. “AI can generate boilerplate. It cannot navigate a HIPAA audit or explain a model’s output to a compliance officer.”</p>



<p>Development professionals should “pick an industry and learn it seriously; not just the technology stack but the regulatory environment, the business model, and the actual problems practitioners face,” Awasthi says. “A developer who has read about HIPAA, or spent time understanding credit risk, is immediately more valuable in those hiring contexts.”</p>



<p>It’s also vital to demonstrate real-world, practical application of skills, not just credentials. “The strongest candidates have projects in their portfolio that directly tie to and solve real business problems,” Erhard says.</p>



<h3 class="wp-block-heading">Acquire soft skills</h3>



<p>And then there are the soft skills that are becoming more of a differentiator than they were in the past. As AI handles more routine coding, human developers are expected to make more architectural decisions and collaborate across departments, Erhard says. “Strong communication and problem-solving skills are critical for many of the developer roles that we’re filling today,” he says.</p>



<p>While technical skills are still relevant for developers using and managing AI tools, “they also need to develop the skill of ‘deeper thinking’ and learn how to think one step ahead,” Morris says. “This includes skills like system design mastery—understanding the macro view and learning how <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>, databases, and third-party APIs interact securely and efficiently.”</p>



<p>They also should become deeply fluent in the AI coding tools commonly used in their particular industry, with a strong understanding of how to prompt them for optimal output, Morris says. Product context awareness is also useful. “AI doesn’t know what the customer wants, but you do,” Morris says. “Understanding the business problem and the end-user experience is a requirement for being able to guide LLMs.”</p>



<h3 class="wp-block-heading">Master debugging and incident response</h3>



<p>Developers looking to break into non-tech sectors also should develop skills in debugging and incident response, Morris says. “Complex systems with multiple AI agents can, and will, fail, which means companies need humans to trace logic flaws to get the system back on track,” he says. “A mastery of root-cause analysis is a critical skill.”</p>



<p>“Security, compliance, and reliability are very important in non-tech industries like finance and healthcare,” says <a href="https://www.linkedin.com/in/rohit-agarwal/" data-type="link" data-id="https://www.linkedin.com/in/rohit-agarwal/">Rohit Agarwal</a>, co-founder of Zenius, a remote hiring company. “So employers want developers who also know regulatory environments well.”</p>



<h3 class="wp-block-heading">Network and keep learning</h3>



<p>To successfully pivot from jobs at tech companies, “continuous learning, upskilling, and building hybrid skills that combine technical and business knowledge are essential,” Morris says. “With the right preparation, tech professionals can adapt and continue to thrive in meaningful, dynamic careers.”</p>



<p>It’s also a good idea to join talent communities in fields of interest and “engage with other members in conversations that increase your knowledge through the collective intelligence of the community,” Morris says. “Take advantage of AI skilling opportunities relevant for your role, or better yet, where you want to go next. Experiment with the technology either on your own or through structured programs.” Ultimately, be curious and proactive, he says.</p>



<p>“I’d also recommend developers not to ignore referrals, direct outreach, and industry-specific communities during job search,” Agarwal says. “There are often a lot more opportunities available than the ones posted online.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI needs contextual intelligence — not just bigger models]]></title>
<description><![CDATA[A product manager on my team recently asked me where we were seeing the most issues across the engineering team. Instead of guessing, I had an engineering lead point Claude at our Jira via an MCP connector and look at the bug patterns himself.



One team had a wildly disproportionate share of ti...]]></description>
<link>https://tsecurity.de/de/3664720/it-security-nachrichten/why-ai-needs-contextual-intelligence-not-just-bigger-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664720/it-security-nachrichten/why-ai-needs-contextual-intelligence-not-just-bigger-models/</guid>
<pubDate>Mon, 13 Jul 2026 11:08:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A product manager on my team recently asked me where we were seeing the most issues across the engineering team. Instead of guessing, I had an engineering lead point Claude at our Jira via an MCP connector and look at the bug patterns himself.</p>



<p>One team had a wildly disproportionate share of tickets — about 50% of their sprint time was spent on “bugs,” versus roughly 25% for everyone else. The headline number suggested a quality problem.</p>



<p>It wasn’t. When we layered in the context around those tickets, almost none of them were bugs. They were manual workarounds for a missing product capability: customers asking us, one request at a time, to restore items they had accidentally deleted. Not shipping an item restore feature was burning roughly 1.5 engineers’ worth of capacity. I went back to our product team and said, “Build this, and you reclaim a person and a half.”</p>



<p>The analysis took 45 minutes. It was only possible because our data was already organized, tagged by team, connected to contributors, accessible through MCP and protected by role-based access. None of that is “AI.” All of it is the layer underneath AI that almost nobody invests in first. That’s probably because the investment is unglamorous: updating data dictionaries, access controls, team taxonomies, system-to-system mappings. Most of the work has been the same for twenty years. AI just raised the cost of skipping it.<br></p>



<h2 class="wp-block-heading">The intelligence underneath the models</h2>



<p>I keep coming back to the value of context data layers as a CTO in the middle of an AI rollout. I have started calling that value proposition contextual intelligence because I haven’t found a better name. Anthropic’s engineering team has been calling this kind of work “<a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents" rel="nofollow">context engineering</a>” since late 2025, and <em>CIO</em><a href="https://www.cio.com/article/4080592/context-engineering-improving-ai-by-moving-beyond-the-prompt.html"> ran its own feature on the term</a> shortly after. Whether you describe it as contextual intelligence or context engineering, it’s the part of the stack where the actual programming work still lives.</p>



<p>If business logic is your company’s official org chart, then contextual intelligence is knowing who actually gets things done, how decisions are actually made and what the unwritten rules are. One is theory. The other is reality.</p>



<p>Most enterprise systems capture the theory. The systems that capture how work actually happens — what people do, how teams operate, where decisions get stuck — are rarer and harder to build. And modern LLMs, it turns out, are useless without both.</p>



<p>I learned this the hard way at a recent company hackathon. Nine engineering teams, one prompt: make our operational dataset more usable through AI. My team built persona-based chatbots (CFO, CIO, sales manager) on top of an MCP server backed by Postgres and our enrichment data. Other teams built dashboard generators, Looker conversational analytics and workflow agents.</p>



<p>The initial demos all had the same problem. Claude could talk to our data, but the answers were either generic or confidently wrong. The CFO persona would happily report a “spend trend” that quietly conflated two distinct cost categories across two different tables. The CIO persona would answer questions about team productivity, but the averages across roles should never have been aggregated. The sales manager persona returned answers that were technically correct against the schema and completely wrong against the business. The raw data was rich. The context layer around it didn’t exist yet. Chatting with raw data is not an AI product. It’s a demo.</p>



<p>One of my senior engineers spent the second day ripping out the agent’s direct database connection. He stopped trying to prompt-engineer the LLM to understand our business and instead codified that logic into the data pipeline. Working backward from the failed CFO answers, he mapped out the implicit knowledge an experienced controller relies on: Explicitly defining which legacy tables actually represent ‘spend,’ writing the rules for currency normalization and hardcoding our fiscal time windows. He built a series of semantic SQL views to enforce these rules and restricted the MCP server to exposing only this curated layer. When we pointed the same model at those same questions, it returned completely different answers. They were specific, evidence-based and grounded in our actual business reality. The model didn’t get smarter. The engineering beneath it did.</p>



<h2 class="wp-block-heading">The same pattern shows up everywhere I look right now</h2>



<p><a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/one-year-of-agentic-ai-six-lessons-from-the-people-doing-the-work" rel="nofollow">McKinsey</a> keeps publishing that software development tops enterprise AI use cases, with companies reporting 30–50% productivity gains in pilots. The pilot numbers are real. They rarely translate to top- or bottom-line impact in production. Our own company data tells the same story: Between Q1 2025 and Q1 2026, our total AI tool usage grew by 328% (over 4x). Over that same period, PR throughput grew by just 49%.</p>



<p>That gap — adoption way up, outcomes inching along — is the context gap. Plug a generic agent into raw, uninterpreted data, and it will act inefficiently at best, harmfully at worst. An agent optimizing sales without your customer segmentation or product hierarchy will confidently recommend the wrong thing. Anthropic<a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents" rel="nofollow"> </a><a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents" rel="nofollow">framed the shift directly</a>: building with language models is becoming “less about finding the right words and phrases for your prompts, and more about answering the broader question of what context configuration is most likely to generate our model’s desired behavior.” That second question — what context configuration  — is the entire game. Most organizations are still answering the first one.</p>



<h2 class="wp-block-heading">Where the work actually lives</h2>



<p>A growing number of CTOs I talk to are shifting their AI investments accordingly. Less attention on the model. More on the layer between the model and the data.</p>



<p>When peers ask me what that actually looks like day-to-day, I tell them I give every engineering role the same mandate: the LLM should never see raw, uncontextualized data.</p>



<p>In practice, that breaks down to three pieces of work, none of them glamorous.</p>



<p>The first is semantic middleware. We need code that transforms raw data into business-meaningful signals before it ever reaches the model. Our feature stores hold things like “employee code velocity on critical-path features,” not “X logged 50 Git commits.” The work of figuring out what “critical-path” means in our product, in our org, on this team is the work. It does not get cheaper because the model has gotten better.</p>



<p>The second is multi-agent design. Instead of one omniscient orchestrator, we run smaller agents scoped to specific domains, each with rules that catch the failure modes the main model is known for. We pair them with RAG that retrieves precomputed insights, with their rules attached, rather than raw documents. Validation checkpoints sit between steps and flag suggestions that violate known constraints, such as averaging productivity across completely different job functions. The guardrails are not there to be clever. They are there because we already watched the model make those exact mistakes.</p>



<p>The third is evaluation that takes business logic seriously. When I look at a model, general benchmark accuracy is the least interesting number. I want to know whether it respects our constraints and integrates cleanly with our existing architecture. That sometimes means fine-tuning our patterns, sometimes constitutional approaches to embed principles, sometimes hybrid systems where deterministic rules sit alongside the probabilistic ones. The throughline is the same: validate against reality, not against the benchmark.</p>



<h2 class="wp-block-heading">Why this matters now</h2>



<p>The reason this matters more now than it did six months ago is that adoption is moving faster than measurement, let alone integration. Model Evaluation &amp; Threat Research’s (<a href="https://metr.org/" rel="nofollow">METR</a>) developer productivity work tells the story in a way they didn’t intend. In early 2025, they<a href="https://arxiv.org/pdf/2507.09089" rel="nofollow"> ran a controlled study</a> and found AI tools slowed experienced open-source developers by 19%. When they tried to<a href="https://metr.org/blog/2026-02-24-uplift-update/" rel="nofollow"> repeat the study in late 2025</a>, the experiment broke. Thirty to fifty percent of developers refused to submit tasks under the no-AI condition. They wouldn’t accept working without their tools. METR is now redesigning the study because the original methodology no longer holds up against how developers actually work. That’s how fast adoption moved. But I’d be willing to bet the organizational scaffolding required to convert that adoption into outcomes — context layers, workflow redesign, retraining around new tools — moved nowhere near as fast.</p>



<h2 class="wp-block-heading">Get ahead with context </h2>



<p>The teams I’ve seen succeed with AI built the context layer first. The teams I’ve seen struggle eventually built in context anyway, just at higher cost and with more scar tissue. Raw data is the new currency. But raw data without a context layer is cash sitting in a vault. It cannot act on anything. The difference between insight and noise is a layer of code that understands what your data means.</p>



<p>That layer is the work. It is where the next decade of competitive advantage will sit. And in my experience, the organizations that build it first are the ones that will actually get the productivity gains the rest of the market keeps promising.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the future of customer service is resolution, not fast replies]]></title>
<description><![CDATA[Most AI agents today are optimised for responsiveness—faster first responses, shorter wait times, higher service rates. And on those metrics, they’re delivering.



It’s no surprise then that 90% of business leaders believe their customers are satisfied with conversational AI experiences. Yet onl...]]></description>
<link>https://tsecurity.de/de/3664616/it-nachrichten/why-the-future-of-customer-service-is-resolution-not-fast-replies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664616/it-nachrichten/why-the-future-of-customer-service-is-resolution-not-fast-replies/</guid>
<pubDate>Mon, 13 Jul 2026 10:18:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Most AI agents today are optimised for responsiveness—faster first responses, shorter wait times, higher service rates. And on those metrics, they’re delivering.</p>



<p>It’s no surprise then that 90% of business leaders believe their customers are satisfied with conversational AI experiences. Yet only 59% of consumers agree, according to <a href="https://www.twilio.com/en-us/report/Inside-the-Conversational-AI-Revolution?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_future-of-cs_brandposthub" target="_blank" rel="sponsored">Twilio’s latest report on conversational AI</a>.</p>



<p>What could explain this 31-point gap? The data is unambiguous. 54% of consumers say AI agents rarely have context about them as a customer. 78% say the ability to escalate to a human is important, yet few get the chance to do so. And only 15% report experiencing a seamless handoff from an AI agent to a human one.</p>



<p>All this to say that the real measure of an AI agent isn’t how fast it answers, but whether it solves the problem. In fact, 72% of consumers would choose an AI over a human if it could resolve their issue more quickly.</p>



<p>Speed without resolution will only result in frustration.</p>



<h2 class="wp-block-heading">Why most AI agents aren’t great at resolution</h2>



<p>It’s not hard to see why most AI agents fail to resolve customer issues: they can’t take action on behalf of the customer, they can’t escalate conversations when they reach their limits, and they lack the real-time context needed to personalise the interaction.</p>



<p>Think about what a typical AI service interaction looks like. A customer calls with a billing question. The AI agent reads their intent accurately enough. But it can’t pull up the customer’s account in real time, process a credit, or route to a human specialist who knows the context of the conversation. So the customer repeats themselves. Or simply gives up.</p>



<p>The root cause is structural. In most stacks, the channel is the system of record, not the conversation. Voice, SMS, chat, and WhatsApp each run as separate sessions, so the moment a customer switches channels or escalates to a human, the interaction resets. Engineering teams paper over this by stuffing full transcripts into AI prompts to fake continuity. This inflates token costs, slows responses, and still truncates older context once the window fills up.</p>



<p>This is the gap between a chatbot and an agent. A chatbot responds. An agent resolves. It’s no wonder that the 59% of organisations planning to fully replace their current conversational AI solution within the year understand this distinction. Their early investments were simply optimised for the wrong outcome.</p>



<h2 class="wp-block-heading"><a></a>What resolution actually requires</h2>



<p>A smarter agent only gets you so far. Businesses need four capabilities to close the resolution gap:</p>



<ol class="wp-block-list">
<li>Agency: Agents must be able to take real action, such as scheduling, processing, and updating records, within the conversation itself.</li>



<li>Always-on monitoring: Agents should continuously evaluate the quality of interactions and catch failures before they become customer complaints</li>



<li>Intelligent routing: Agents should escalate issues with full context so that humans can pick up where they left off.</li>



<li>Real-time contextual data: Agents should have the same customer context as a well-prepared human agent. This includes purchase history, past interactions, account status, and preferences.</li>
</ol>



<p>None of these are speculative. They’re available today, and the companies deploying them are already seeing the difference.</p>



<p>Case in point: OhMD, a healthcare communications platform for physician practices and medical groups. The company built Nia, an AI-powered voice assistant that uses Twilio’s Conversation Relay to handle routine patient calls (scheduling, prescription refills, FAQs). Complex calls are routed to staff with full context, which saves patients from repeating themselves.</p>



<p>The results were immediate. OhMD saw a 60% improvement in self-service first-call resolution, with appointment scheduling flows completing in as little as one minute. By 2026, Nia is projected to handle more than 55 million patient interactions annually.</p>



<p>As Twilio CEO Khozema Shipchandler noted, “What we’re starting to see with OhMD is that they’ve got a 60% lift in self-serve capability to actually resolve calls. They’re able to drive the conclusion of these calls in less than a minute in many instances.”</p>



<p>Patients aren’t impressed because the phone rang once. They’re impressed because the call ended with their problem solved.</p>



<h2 class="wp-block-heading">Think resolution, not speed</h2>



<p>For every customer service leader evaluating their AI agent roadmap, the implication is straightforward. Stop measuring success by response time alone. Start measuring it by resolution rate—specifically, self-service resolution rate.</p>



<p>That means investing not in faster replies, but in smarter infrastructure: agents that act, routing that adapts, data that flows in real time, and monitoring that holds the system accountable.</p>



<p>The future of customer service isn’t about answering faster. It’s about answering fully.         </p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p>To learn more about Twilio, visit <a href="https://www.twilio.com/en-us/why-twilio?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_end-cta-future-of-cs_brandposthub" target="_blank" rel="noreferrer noopener">here</a>.<a></a></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Voice AI vs conversational AI: What’s the difference?]]></title>
<description><![CDATA[Voice AI. Conversational AI. You’ve seen both terms everywhere—sometimes in the same sentence, sometimes used as if they mean the same thing.



They don’t. But they’re not opposites either.



One is a category of technology. The other is a specific way to deliver it.



Mix them up and you end ...]]></description>
<link>https://tsecurity.de/de/3664597/it-security-nachrichten/voice-ai-vs-conversational-ai-whats-the-difference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664597/it-security-nachrichten/voice-ai-vs-conversational-ai-whats-the-difference/</guid>
<pubDate>Mon, 13 Jul 2026 10:09:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Voice AI. Conversational AI. You’ve seen both terms everywhere—sometimes in the same sentence, sometimes used as if they mean the same thing.</p>



<p>They don’t. But they’re not opposites either.</p>



<p>One is a category of technology. The other is a specific way to deliver it.</p>



<p>Mix them up and you end up making the wrong platform decisions, building the wrong workflows, and losing 45 minutes in a meeting that didn’t need to happen.</p>



<p>Here’s the difference between voice AI and conversational AI, minus the jargon.</p>



<h2 class="wp-block-heading">Conversational AI: The intelligence layer</h2>



<p><a href="https://www.twilio.com/en-us/blog/what-is-conversational-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">Conversational AI</a> is the broader category. It refers to any AI system designed to understand human language, reason about what was said, and respond in a way that feels natural and contextually relevant. That exchange can happen through text, voice, or any other medium.</p>



<p>What defines conversational AI is the intelligence underneath the interaction:</p>



<ul class="wp-block-list">
<li><a href="https://www.twilio.com/docs/glossary/what-is-natural-language-understanding?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Natural language understanding</a> that interprets intent rather than matching keywords</li>



<li>Dialogue management that tracks what’s been said and what still needs to be resolved</li>



<li>Response generation that produces output appropriate to the context.</li>
</ul>



<p>Conversational AI shows up in a lot of forms. A chatbot on a support page is conversational AI. An AI assistant that helps a sales rep draft follow-up emails is conversational AI. A virtual agent that handles inbound customer inquiries is conversational AI.</p>



<p>The intelligence layer makes the interaction feel like a conversation rather than a database lookup.</p>



<p>The channel, the modality, the interface: those are separate from the intelligence. Which brings us to voice AI.</p>



<h2 class="wp-block-heading">Voice AI: The delivery method</h2>



<p><a href="https://www.twilio.com/en-us/blog/insights/what-is-voice-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">Voice AI</a> is conversational AI delivered through spoken language. It’s the application of conversational AI intelligence to voice-based interactions <strong>where the input is speech and the output is speech.</strong></p>



<p>A voice AI system:</p>



<ul class="wp-block-list">
<li>Takes spoken words</li>



<li>Converts them to text via <a href="https://www.twilio.com/en-us/speech-recognition?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">speech-to-text (STT)</a></li>



<li>Runs that text through a <a href="https://www.twilio.com/en-us/products/conversational-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">conversational AI layer</a> to understand intent and generate a response</li>



<li>Converts that response back to spoken audio via <a href="https://www.twilio.com/en-us/blog/insights/ai/what-is-text-to-speech?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">text-to-speech (TTS)</a></li>
</ul>



<p>And it does it all fast enough that the conversation doesn’t feel like it’s buffering.</p>



<p>Voice AI isn’t a fundamentally different kind of intelligence from conversational AI. It’s conversational AI with a voice interface wrapped around it. The reasoning, the context tracking, the dialogue management—those are the same capabilities.</p>



<p>What voice AI adds is the ability to operate through spoken language in real time, with all the additional complexity that introduces: handling interruptions, managing turn-taking, producing natural-sounding speech, and doing all of it with sub-500ms latency.</p>



<p>Ultimately, conversational AI is how the system thinks. Voice AI is how it talks.</p>



<h2 class="wp-block-heading">How they relate</h2>



<p>Voice AI depends on conversational AI to be useful. Without the intelligence layer (intent recognition, context tracking, and coherent response generation), a voice system is just a phone menu with better audio.</p>



<p>The voice interface makes the interaction accessible through speech. The conversational AI makes the interaction worth having.</p>



<p>The relationship goes one way, though.</p>



<p>Every voice AI system uses conversational AI underneath it. But conversational AI doesn’t require voice. A text-based chatbot, messaging bot, or AI assistant embedded in a ticketing system are conversational AI without any voice component.</p>



<p>It’s not really a question of whether you need conversational AI or voice AI. It’s better to ask: does your use case require voice?</p>



<ul class="wp-block-list">
<li>If yes, you need voice AI—which means you also need conversational AI as the foundation.</li>



<li>If the interaction is text-based, you need conversational AI without the voice layer.</li>
</ul>



<h2 class="wp-block-heading"><a></a>Voice AI vs. conversational AI: Key differences</h2>



<p>Side by side, the differences get a lot clearer. Here’s the breakdown across the criteria that matter most for teams building or buying AI for customer service.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/image_b3a549.png" alt="" class="wp-image-4194915" width="630" height="556" sizes="auto, (max-width: 630px) 100vw, 630px"></figure></div>



<h2 class="wp-block-heading">When to use conversational AI without voice</h2>



<p>Text-based conversational AI makes sense when your customers primarily engage through chat, messaging, or digital channels. And when the nature of the interaction doesn’t require the immediacy of a phone call.</p>



<ul class="wp-block-list">
<li>Support chat on a website</li>



<li>WhatsApp automation</li>



<li>AI-assisted email triage</li>



<li>Messaging bots for transactional notifications</li>
</ul>



<p>These are all conversational AI use cases where voice doesn’t add much and may introduce unnecessary friction. Not every customer wants to speak out loud, especially in public, at work, or when the question is simple enough to type in thirty seconds.</p>



<p>Text-based conversational AI is also typically faster to deploy, easier to test, and simpler to update. You can iterate on response quality, test new flows, and review transcripts without dealing with audio quality, latency optimisation, or the additional infrastructure that voice requires.</p>



<p>If your primary support and engagement channels are digital and your customers are comfortable typing, starting with text-based conversational AI often makes more sense than jumping straight to voice.</p>



<h2 class="wp-block-heading"><a></a>When you need voice AI specifically</h2>



<p>Voice AI makes sense when the use case is inherently telephonic, time-sensitive, or requires the kind of nuance that text alone doesn’t capture.</p>



<ul class="wp-block-list">
<li><strong>Inbound phone support: </strong>Customers call because they want to talk to someone, or because they’ve always called, or because the issue feels urgent enough that they don’t want to wait for a chat response. An AI that can answer that call, understand the issue, and resolve it in the same interaction replaces one of the most expensive and frustrating moments in customer service.</li>



<li><strong>Outbound calling:</strong> Appointment reminders, fraud alerts, lead follow-up, proactive outreach for at-risk customers. These interactions are harder to execute over text because they require real-time dialogue.</li>



<li><strong>Context:</strong> Tone, urgency, frustration, hesitation—these are signals that a voice AI system can detect and respond to. A customer who speaks with audible frustration is communicating something beyond the literal words, and a well-designed voice AI system can adjust its approach accordingly.</li>
</ul>



<p>Finally, voice AI matters when your customers are less likely to engage through digital channels. These might be older demographics, industries where phone is still the primary contact method, or use cases where hands-free interaction is a practical requirement.</p>



<h2 class="wp-block-heading">Do you need both?</h2>



<p>For most businesses building serious customer engagement infrastructure: yes.</p>



<p>The customers who prefer chat aren’t going away. Neither are the customers who pick up the phone. A complete AI engagement strategy handles both with a single connected experience rather than two separate systems that don’t know about each other.</p>



<p>And that’s where <a href="https://www.twilio.com/en-us/products/conversational-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">Twilio Conversations</a> can help.</p>



<ul class="wp-block-list">
<li><a href="https://www.twilio.com/en-us/products/conversational-ai/conversation-orchestrator?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Conversation Orchestrator</a> connects voice, SMS, WhatsApp, and chat into one continuous conversation record.</li>



<li><a href="https://www.twilio.com/en-us/products/conversational-ai/conversation-memory?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Conversation Memory</a> gives every agent (AI or human) persistent customer context across channels.</li>



<li><a href="https://www.twilio.com/en-us/products/conversational-ai/conversationrelay?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Conversation Relay</a> handles the voice AI layer: low-latency STT and TTS, bring-your-own-LLM, HIPAA-eligible.</li>



<li><a href="https://www.twilio.com/en-us/products/conversational-ai#:~:text=and%20barge-in.-,Agent%20Connect,-Connect%20your%20own?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Agent Connect</a> lets you plug your own AI agents into Twilio channels without rebuilding your communications infrastructure.</li>
</ul>



<p>Your customers are going to use both voice and text. The question is whether your stack connects them.</p>



<p><a href="https://www.twilio.com/try-twilio?ext-anonymousId=1d804104-edbe-49b6-aed2-edb162421f5b&amp;ext-gaClientId=589905313.1777306679&amp;ext-gaSessionId=1778509973&amp;utm_referrer=https%3A%2F%2Fwww.twilio.com%2Fen-us%2Fproducts%2Fconversational-ai&amp;utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Start for free</a> or <a href="https://www.twilio.com/en-us/help/sales?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">contact sales</a> to talk through your use case.</p>



<h2 class="wp-block-heading">Frequently asked questions</h2>



<h3 class="wp-block-heading"><strong>What’s the difference between voice AI and conversational AI?</strong></h3>



<p>Conversational AI is the intelligence layer that understands human language and generates contextually relevant responses, regardless of channel. Voice AI is conversational AI delivered through spoken language. It adds speech-to-text and text-to-speech components so the interaction happens via voice.</p>



<h3 class="wp-block-heading"><strong>Is voice AI a type of conversational AI?</strong></h3>



<p>Yes. Voice AI is a specific application of conversational AI that operates through spoken language. The reasoning, intent recognition, and dialogue management capabilities come from conversational AI. Voice AI adds the speech interface on top to convert spoken input to text, process it through the conversational AI layer, and convert the response back to speech.</p>



<h3 class="wp-block-heading"><strong>Can conversational AI work without voice?</strong></h3>



<p>Yes. Text-based chatbots, messaging bots, AI assistants in ticketing systems, and email AI are all forms of conversational AI that don’t use voice.</p>



<h3 class="wp-block-heading"><strong>Does Twilio support both voice AI and conversational AI?</strong></h3>



<p>Yes. Twilio Conversation Relay handles voice AI, combining low-latency STT and TTS with bring-your-own-LLM flexibility. The broader Twilio Conversations platform connects voice, SMS, WhatsApp, and chat into a single conversation layer, so the conversational AI intelligence and customer context are shared across every channel.</p>



<p>To learn more about Twilio conversations, visit <a href="https://www.twilio.com/en-us/why-twilio?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_end-cta-voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">here</a>.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p><a></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Can AI narrow cybersecurity’s class divide?]]></title>
<description><![CDATA[At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes.



In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then begin building...]]></description>
<link>https://tsecurity.de/de/3664478/it-security-nachrichten/can-ai-narrow-cybersecuritys-class-divide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664478/it-security-nachrichten/can-ai-narrow-cybersecuritys-class-divide/</guid>
<pubDate>Mon, 13 Jul 2026 09:07:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes.</p>



<p>In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then begin building detections or fixes, <a href="https://www.linkedin.com/in/stephenschmidt1/">Steve Schmidt</a>, chief security officer at AWS, tells CSO. That process could take “two, four, six, eight, 10 months,” Schmidt says.</p>



<p>“Now with proper application of AI, we can have the detections built for the problems the red team finds in 15 minutes-ish,” he says. “I think the outside is about four hours.”</p>



<p>That kind of workflow offers a glimpse of what AI could make possible for the most sophisticated security organizations: AI agents testing systems, other agents generating defenses, and human security engineers validating results and refining the feedback loop.</p>



<p>But it also raises a more uncomfortable question for the rest of the cybersecurity industry: What happens to organizations that cannot build anything close to that?</p>



<p>The concern has become significant enough that the Trump administration <a href="https://www.csoonline.com/article/4180205/trump-revives-parts-of-canceled-ai-order-with-cybersecurity-focused-directive.html">recently directed</a> agencies to expand access to AI-enabled cybersecurity capabilities for resource-constrained organizations, including rural hospitals, community banks, and local utilities.</p>



<p>The order reflects a growing fear that AI could deepen a divide that has existed in cybersecurity for years: the divide between organizations with money, expertise, and engineering depth, and those struggling to keep pace with basic security demands.</p>



<p>Yet security leaders and practitioners suggest the impact of AI will be more complicated than a simple widening gap. Some experts say AI is merely adding a new layer to a long-standing security poverty problem. Others argue AI could democratize capabilities once reserved for elite organizations. Still others see today’s divide as real, but potentially temporary, as models become cheaper, more open, and easier to run.</p>



<h2 class="wp-block-heading">The class divide was already here</h2>



<p>For <a href="https://www.linkedin.com/in/matthewowenwarner/">Matt Warner</a>, co-founder and CTO of Blumira, the premise that AI is creating a cybersecurity class divide misses a key point: The divide already exists.</p>



<p>“I would go even a step further and say that there has been a class divide for the last 10 to 15 years,” Warner tells CSO.</p>



<p>What AI changes, he argues, is not necessarily the existence of the divide but how stark it becomes. Larger organizations have money, people, and time to experiment with AI. Smaller organizations often do not.</p>



<p>“The big differences that we’re seeing, especially from where we sit in the world, is the difference is getting starker in having the resources to leverage AI and the time to leverage AI more than anything else,” Warner says.</p>



<p>That distinction matters because many smaller organizations are already overwhelmed. Warner pointed to resource-constrained local governments and small or midmarket organizations that are still far behind large enterprises in basic IT and security maturity.</p>



<p>“I can find you a county in Michigan with two IT people for 2,000 employees,” Warner says. “Those people don’t have time to leverage AI and even learn how to use AI because they’re mostly just trying to put out fires.”</p>



<p>That problem is not unique to AI. Smaller organizations have long struggled to patch systems, prioritize vulnerabilities, monitor environments, and respond to incidents with limited staff. AI may help eventually, but only if those organizations have enough capacity to adopt it.</p>



<h2 class="wp-block-heading">Wendy Nather’s framework gets an AI layer</h2>



<p><a href="https://www.linkedin.com/in/chuvakin/">Anton Chuvakin</a>, security advisor in the office of the CISO for Google Cloud, sees the AI divide as part of a much older problem.</p>



<p>“I feel like it sends me back to when <a href="https://www.linkedin.com/in/wendynather/">Wendy Nather</a> invented the security poverty line,” Chuvakin tells CSO, referring to Nather’s <a href="https://www.infosecuritymagazine.nl/files/2fb0642808f57f0f9831532ae8f7e8fd.pdf">2011 concept</a> describing organizations that lack the money, expertise, capability, or influence to implement effective security.</p>



<p>Chuvakin is skeptical that AI fundamentally changes that model. “I don’t think AI necessarily breaks that model,” he says. “I think it just adds another dimension.”</p>



<p>Cybersecurity has always been shaped by unequal access to top talent, tools, and services, Chuvakin argues. Large organizations could afford better SIEM deployments, advanced DLP programs, threat hunters, application security experts, and incident response retainers. Smaller organizations often could not.</p>



<p>AI may become another scarce resource, but Chuvakin cautions against overstating the role of model cost alone. In his view, the <a href="https://www.cio.com/article/4165232/whats-holding-back-enterprise-ai-shortage-of-talent-cios-say.html">bigger structural issue may be talent</a> rather than tokens.</p>



<p>“Prices for people won’t drop, but prices for LLMs may drop,” he believes.</p>



<p>That means the organizations with the greatest advantage may not simply be those that can afford the most expensive models. They may be the ones that can afford the people who know how to use them — and, as the frontier-access debate below suggests, that talent gap may prove more durable than any gap in model access itself.</p>



<h2 class="wp-block-heading">AI creates new costs — and new uncertainties</h2>



<p>Nather herself, now senior research initiatives director at 1Password, sees AI affecting every dimension of the security poverty line: money, expertise, capability, and influence.</p>



<p>The financial challenges are not limited to whether an organization can pay for an AI tool. In some cases, organizations that cannot afford enterprise licensing may end up making tradeoffs around privacy.</p>



<p>“If an organization can’t afford an enterprise license for the models they’re using, then they can’t keep their data private,” Nather tells CSO. “So, they have to give up privacy because they can’t afford privacy.”</p>



<p>That’s a new twist on an old dimension of the poverty line: It’s not just that under-resourced organizations lack a capability, but that the capability they can afford comes bundled with a risk wealthier organizations don’t have to accept.</p>



<p>Token-based pricing adds another problem: <a href="https://www.cio.com/article/4152601/without-controls-an-ai-agent-can-cost-more-than-an-employee.html">unpredictability</a>. “At this point, nobody knows how much they’re going to burn in tokens at any given time,” she says.</p>



<p>That makes budgeting difficult for organizations that cannot absorb surprise costs. Nather also warns that usage-based pricing is controlled by providers and can change over time, <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">leaving customers with limited leverage</a>.</p>



<p>“The charging practice is in the hands of the providers, and they can change it at any time,” she says.</p>



<p>For organizations already operating below the security poverty line, that uncertainty could make AI adoption harder, even if the technology itself becomes more capable.</p>



<h2 class="wp-block-heading">Access to frontier models may be a temporary divide</h2>



<p><a href="https://www.linkedin.com/in/davidbaggett/">Dave Baggett</a>, SVP/GM of the security suite at Kaseya, agrees there is security class divide dynamic playing out today, particularly around access to frontier models.</p>



<p>“There’s definitely a haves and have-nots issue around Mythos specifically because most people don’t have it,” Baggett tells CSO. But he doesn’t think the divide will have a long-term impact. Open-weight models, quantization, mixture-of-experts architectures, and increasingly powerful commodity hardware, he argues, are closing the gap faster than most people expect.</p>



<p>While not every organization will build a frontier model, he says, more organizations may be able to run capable models locally or use cheaper systems that <a href="https://www.csoonline.com/article/4170818/what-happens-when-chinas-ai-catches-up-to-mythos.html">approximate what today’s elite models can do</a>.</p>



<p>“What it says for finding vulnerabilities is at that point, open-source people can run this stuff,” Baggett says. “Then you’re back to having a symmetrical opportunity where the defenders who are writing the open source can run the same tools the attackers would and have them fix the issues.”</p>



<p>His bottom line is that the divide may be real but short-lived. “Right now, there certainly is a have, have-not schism, but it may not be there for long,” Baggett says — a view Chuvakin shares, though he frames it in terms of the model market rather than open source specifically.</p>



<p>“I don’t think it’s the lowering prices example, but it’s more like you’re a top-tier model maker, I’m a second-tier model maker. My model in a year would do what your model did a year ago,” Chuvakin says.</p>



<h2 class="wp-block-heading">The real advantage is operational depth</h2>



<p>Schmidt’s description of AI use at AWS points to another kind of divide: not access to AI, but the ability to operationalize it.</p>



<p>AWS uses multiple models for different tasks, Schmidt says. One model may discover vulnerabilities, while other models validate results or help build defenses. Humans remain accountable for evaluating what the systems produce.</p>



<p>“Because we believe really strongly in human accountability for the use of AI from end to end, we still have humans take a look at what the systems come up with to determine whether they are reasonable and appropriate,” he says.</p>



<p>That workflow requires more than a model. It requires corporate data, secure infrastructure, feedback loops, security engineers, data scientists, and AI specialists who can work together.</p>



<p>Schmidt also pushes back on the idea that running AI locally on powerful consumer hardware is a substitute for production-grade security infrastructure. “Often the value of the model is also dependent on its proximity to data so that the model can ingest, use, and reason about data,” he says. “As a security person, I do not want that to be on your laptop.”</p>



<p>Experimentation on a laptop is useful, Schmidt says, but it is not the same as a secure production environment.</p>



<p>“I want the data to be somewhere safe that I can control, that I can see, that I can reason about, not sitting on your laptop,” he says. “Experimentation in there, awesome. That’s great. But it is not a production infrastructure component.”</p>



<p>That distinction may define the emerging AI security gap. Many organizations may be able to access AI tools. Far fewer may be able to safely integrate them into real security workflows.</p>



<h2 class="wp-block-heading">The democratization argument</h2>



<p><a href="https://www.linkedin.com/in/philvenables/">Phil Venables</a>, a partner at Ballistic Ventures and former CISO of Google Cloud, takes the most optimistic view.</p>



<p>Asked whether AI is widening the gap between well-resourced and under-resourced security organizations, Venables tells CSO, “No, I actually think it’s the exact opposite.”</p>



<p>The reason, he argues, is that AI packages expertise and automation in ways that can be delivered broadly. “One of the fantastic things about AI, and we’re already starting to see this, is [that it’s] a great democratizer of capabilities,” he says. “AI packages up expertise and automation capabilities at a level beyond what prior waves of technology have done, and it makes it available at scale into organizations that have not previously been able to afford these things.”</p>



<p>He points to <a href="https://www.csoonline.com/article/4181930/ai-red-teaming-comes-of-age.html">red teaming</a> as an example. Nearly every organization would like a world-class red team, but few can afford one.</p>



<p>“Pretty much every organization on the planet would love to have a world-class red team to constantly test their security to find and fix things before attackers do,” Venables says. “But very few organizations have ever been able to afford to build a high-end red team.”</p>



<p>AI agents, he argues, could make that kind of capability available more economically. The same pattern could apply to insider threat; third-party risk; software security; governance, risk and compliance; and security operations.</p>



<p>“So even the smallest and resource-constrained organizations can now have access to a higher-end capability,” he maintains.</p>



<p>Venables does see a danger zone, however: under-resourced security teams inside organizations with aggressive AI ambitions. Those teams may <a href="https://www.csoonline.com/article/3529615/companies-skip-security-hardening-in-rush-to-adopt-ai.html">struggle to keep up</a> as the rest of the business adopts AI rapidly. But for many small and midsize organizations, he believes AI could improve access to security capabilities they never had before.</p>



<h2 class="wp-block-heading">A divide over AI — or over readiness?</h2>



<p>For elite organizations, AI is already becoming a force multiplier. Security teams with deep engineering talent, mature data infrastructure, and strong governance can use AI to accelerate testing, detection engineering, vulnerability discovery, and risk management.</p>



<p>For smaller organizations, the picture is less clear. AI may eventually package scarce expertise into affordable services. Open models may reduce dependence on expensive frontier systems. But organizations below the security poverty line still face familiar constraints: too few people, too little time, limited expertise, unpredictable costs, and weak leverage over vendors.</p>



<p>The emerging divide may therefore be less about who has access to AI and more about who can turn AI into durable security outcomes.</p>



<p>That makes the question facing cybersecurity more complicated than whether AI will create haves and have-nots. The industry already had them.</p>



<p>The real question is whether AI becomes another technology that rewards the organizations already best positioned to use it — or the first major security advance in years that helps those below the poverty line finally catch up.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Testing Copilot Feature That Shows What’s Slowing Down Your Windows 11 PC]]></title>
<description><![CDATA[Microsoft is quietly testing a new Copilot capability called “PC Insights” that lets the AI assistant analyze your Windows 11 machine’s hardware and pinpoint exactly what’s causing slowdowns. The feature is currently rolling out slowly in the United States and…
Read more →
The post Microsoft Test...]]></description>
<link>https://tsecurity.de/de/3664261/it-security-nachrichten/microsoft-testing-copilot-feature-that-shows-whats-slowing-down-your-windows-11-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664261/it-security-nachrichten/microsoft-testing-copilot-feature-that-shows-whats-slowing-down-your-windows-11-pc/</guid>
<pubDate>Mon, 13 Jul 2026 07:22:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft is quietly testing a new Copilot capability called “PC Insights” that lets the AI assistant analyze your Windows 11 machine’s hardware and pinpoint exactly what’s causing slowdowns. The feature is currently rolling out slowly in the United States and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-testing-copilot-feature-that-shows-whats-slowing-down-your-windows-11-pc/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-testing-copilot-feature-that-shows-whats-slowing-down-your-windows-11-pc/">Microsoft Testing Copilot Feature That Shows What’s Slowing Down Your Windows 11 PC</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.1-beta.6]]></title>
<description><![CDATA[OpenClaw 2026.7.1-beta.6]]></description>
<link>https://tsecurity.de/de/3663917/downloads/v202671-beta6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663917/downloads/v202671-beta6/</guid>
<pubDate>Mon, 13 Jul 2026 00:31:42 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.1-beta.6</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KittySploit – AI-Powered Next-Generation Penetration Testing Framework With 1150+ Modules]]></title>
<description><![CDATA[KittySploit is a new open-source penetration testing framework that combines a Python and Zig codebase with autonomous AI agents, ship­ping with over 1,150 modules for offensive security teams. The tool chain includes reconnaissance, exploitation, traffic analysis, payload generation, collaborati...]]></description>
<link>https://tsecurity.de/de/3663620/it-security-nachrichten/kittysploit-ai-powered-next-generation-penetration-testing-framework-with-1150-modules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663620/it-security-nachrichten/kittysploit-ai-powered-next-generation-penetration-testing-framework-with-1150-modules/</guid>
<pubDate>Sun, 12 Jul 2026 18:53:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>KittySploit is a new open-source penetration testing framework that combines a Python and Zig codebase with autonomous AI agents, ship­ping with over 1,150 modules for offensive security teams. The tool chain includes reconnaissance, exploitation, traffic analysis, payload generation, collaboration, and post-exploitation workflows. KittySploit’s core difference is its integration of local large language models via Ollama, […]</p>
<p>The post <a href="https://cybersecuritynews.com/kittysploit-penetration-testing-tool/">KittySploit – AI-Powered Next-Generation Penetration Testing Framework With 1150+ Modules</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 Copilot now tells you what’s slowing down your PC, while using 1GB RAM itself]]></title>
<description><![CDATA[Windows 11 Copilot can now tell you what’s slowing down your PC, while using 1GB of RAM itself (ironically).
The post Windows 11 Copilot now tells you what’s slowing down your PC, while using 1GB RAM itself appeared first on Windows Latest]]></description>
<link>https://tsecurity.de/de/3662623/windows-tipps/windows-11-copilot-now-tells-you-whats-slowing-down-your-pc-while-using-1gb-ram-itself/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662623/windows-tipps/windows-11-copilot-now-tells-you-whats-slowing-down-your-pc-while-using-1gb-ram-itself/</guid>
<pubDate>Sun, 12 Jul 2026 03:57:27 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Windows 11 Copilot can now tell you what’s slowing down your PC, while using 1GB of RAM itself (ironically).</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/07/12/windows-11-copilot-ai-can-now-tell-you-whats-slowing-down-your-pc-while-using-1gb-of-ram-itself/">Windows 11 Copilot now tells you what’s slowing down your PC, while using 1GB RAM itself</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Laptop specs are getting more confusing – here’s what actually matters in 2026]]></title>
<description><![CDATA[Looking for a new laptop and sick of all the jargon? We demystify the specifications that really make a difference in 2026.]]></description>
<link>https://tsecurity.de/de/3662026/it-nachrichten/laptop-specs-are-getting-more-confusing-heres-what-actually-matters-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662026/it-nachrichten/laptop-specs-are-getting-more-confusing-heres-what-actually-matters-in-2026/</guid>
<pubDate>Sat, 11 Jul 2026 17:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Looking for a new laptop and sick of all the jargon? We demystify the specifications that really make a difference in 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.1-beta.5]]></title>
<description><![CDATA[OpenClaw 2026.7.1-beta.5]]></description>
<link>https://tsecurity.de/de/3661666/downloads/v202671-beta5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661666/downloads/v202671-beta5/</guid>
<pubDate>Sat, 11 Jul 2026 12:17:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.1-beta.5</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neue U-Boot Bootloader Sicherheitslücken: Angreifer könnten Boot-Images zum Absturz oder Code-Execution bringen + Überblick wo der Universal Boot-Loader zum Einsatz kommt oder kam]]></title>
<description><![CDATA[U-Boot wird primär nicht von typischer Desktop-Software genutzt, sondern ist das Fundament für populäre (Embedded) Betriebssysteme, Firmware-Distributionen und Hardware-Plattformen. Er läuft schätzungsweise auf bis zu 94 % aller initialisierten Embedded-Geräte. [1, 2, 3] 🌐 Populäre Betriebssystem...]]></description>
<link>https://tsecurity.de/de/3661122/it-security-nachrichten/neue-u-boot-bootloader-sicherheitsluecken-angreifer-koennten-boot-images-zum-absturz-oder-code-execution-bringen-ueberblick-wo-der-universal-boot-loader-zum-einsatz-kommt-oder-kam/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661122/it-security-nachrichten/neue-u-boot-bootloader-sicherheitsluecken-angreifer-koennten-boot-images-zum-absturz-oder-code-execution-bringen-ueberblick-wo-der-universal-boot-loader-zum-einsatz-kommt-oder-kam/</guid>
<pubDate>Sat, 11 Jul 2026 04:38:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/Computersicherheit/comments/1usz5b4/neue_uboot_bootloader_sicherheitsl%C3%BCcken_angreifer/"> <img src="https://external-preview.redd.it/nbGkk70i397OMyZ-Rc2FgHWRnkU_XyR8NRpyDduVMsQ.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=8f6ec05330ea43c835716d59dbe76da31ee296d4" alt="Neue U-Boot Bootloader Sicherheitslücken: Angreifer könnten Boot-Images zum Absturz oder Code-Execution bringen + Überblick wo der Universal Boot-Loader zum Einsatz kommt oder kam" title="Neue U-Boot Bootloader Sicherheitslücken: Angreifer könnten Boot-Images zum Absturz oder Code-Execution bringen + Überblick wo der Universal Boot-Loader zum Einsatz kommt oder kam"> </a> </td><td> <!-- SC_OFF --><div class="md"><p><strong>U-Boot</strong> wird primär nicht von typischer Desktop-Software genutzt, sondern ist das Fundament für <strong>populäre (Embedded) Betriebssysteme, Firmware-Distributionen und Hardware-Plattformen</strong>. Er läuft schätzungsweise auf bis zu 94 % aller initialisierten Embedded-Geräte. [<a href="https://www.youtube.com/watch?v=GKSHAe--7V0&amp;t=387">1</a>, <a href="https://www.reddit.com/r/embedded/comments/1nq0k87/which_bootloader_is_worthwhile_to_learn/?tl=de">2</a>, <a href="https://www.linkedin.com/posts/rk-williams_day-19-bootloaders-in-linux-grub-u-boot-activity-7298079005872701440-awx-">3</a>]</p> <h1>🌐 Populäre Betriebssysteme &amp; Distributionen</h1> <ul> <li><strong>Android (ältere &amp; spezifische Zweige):</strong> Auf vielen ARM-basierten Mediaplayern, TVs und älteren Smartphones initialisiert U-Boot die Hardware, bevor das eigentliche <a href="https://www.google.com/url?sa=i&amp;source=web&amp;rct=j&amp;url=https://medium.com/@SuriNaren/u-boot-8374094d55d8&amp;ved=2ahUKEwjcouf398iVAxUQRvEDHeCcCrYQy_kOegYIAQgQEAI&amp;opi=89978449&amp;cd&amp;psig=AOvVaw2sRFEO9klT7fNMo792UZh1&amp;ust=1783801333304000">Android-System</a> lädt. [<a href="https://medium.com/@SuriNaren/u-boot-8374094d55d8">1</a>]</li> <li><strong>Raspberry Pi OS / DietPi:</strong> Während der Raspberry Pi standardmäßig einen eigenen GPU-Bootloader nutzt, schalten viele Entwickler und Linux-Distributionen (wie <a href="https://www.google.com/url?sa=i&amp;source=web&amp;rct=j&amp;url=https://gitnux.org/best/bootloader-software/&amp;ved=2ahUKEwjcouf398iVAxUQRvEDHeCcCrYQy_kOegYIAQgQEAk&amp;opi=89978449&amp;cd&amp;psig=AOvVaw2sRFEO9klT7fNMo792UZh1&amp;ust=1783801333304000">Ubuntu Server ARM</a>) U-Boot dazwischen, um Netzwerk-Boot (PXE) oder standardisierte Boot-Skripte zu nutzen. [<a href="https://tha.de/~hhoegl/home/elinux/pi-lfs/html/bootloader.html">1</a>, <a href="https://gitnux.org/best/bootloader-software/">2</a>]</li> <li><strong>OpenWrt / Freetz:</strong> Die weltweit populärste Open-Source-Firmware für Router (wie FRITZ!Box-Alternativen, TP-Link, Netgear) baut fast ausschließlich auf U-Boot auf. Er steuert dort auch den Failsafe-Modus bei fehlerhaften Updates. [<a href="https://www.reddit.com/r/embedded/comments/1nq0k87/which_bootloader_is_worthwhile_to_learn/?tl=de">1</a>]</li> <li><strong>Yocto Project &amp; Buildroot:</strong> Die beiden Industrie-Standards, mit denen Firmen wie Bosch, Siemens oder Tesla ihre eigenen, maßgeschneiderten Embedded-Linux-Systeme für Autos, Waschmaschinen und Industrieanlagen bauen, nutzen U-Boot als Standard-Bootloader. [<a href="https://electronics.stackexchange.com/questions/2369/whats-the-best-bootloader-for-an-embedded-linux-board">1</a>, <a href="https://www.reddit.com/r/embedded/comments/1nq0k87/which_bootloader_is_worthwhile_to_learn/?tl=de">2</a>]</li> </ul> <h1>🖥️ Bekannte Hardware-Ökosysteme (die U-Boot erzwingen)</h1> <ul> <li><strong>Kindle-E-Reader (Amazon):</strong> Die Firmware der Amazon Kindles basiert auf einem schlanken Linux, das über U-Boot gestartet wird. (U-Boot-Modifikationen sind oft der Schlüssel für Kindle-Jailbreaks). [<a href="https://u-boot.org/">1</a>]</li> <li><strong>Chromebooks (ältere ARM-Modelle):</strong> Google nutzte bei frühen ARM-basierten Chromebooks U-Boot als Bindeglied zwischen Coreboot und dem ChromeOS-Kernel. [<a href="https://medium.com/@SuriNaren/u-boot-8374094d55d8">1</a>]</li> <li><strong>Smarte TVs &amp; IoT-Ökosysteme:</strong> Betriebssysteme wie <strong>Tizen (Samsung)</strong> oder <strong>WebOS (LG)</strong> setzen bei der Hardware-Initialisierung auf Entwicklerboards und Prototypen auf U-Boot.</li> </ul> <h1>🛠️ Echtzeit-Betriebssysteme (RTOS) außerhalb von Linux</h1> <p>U-Boot ist so flexibel, dass er auch populäre Nicht-Linux-Systeme lädt: [<a href="https://www.tuxera.com/technical-articles/on-using-u-boot-universal-boot-loader-in-embedded-designs/">1</a>, <a href="https://tha.de/~hhoegl/home/elinux/pi-lfs/html/bootloader.html">2</a>, <a href="https://thenewstack.io/bootloaders-for-embedded-linux-systems/">3</a>]</p> <ul> <li><strong>FreeRTOS &amp; VxWorks:</strong> Weit verbreitete Echtzeitsysteme in der Luftfahrt, Automobilindustrie und Medizintechnik vertrauen auf die stabile Hardware-Übergabe durch U-Boot. [<a href="https://www.tuxera.com/technical-articles/on-using-u-boot-universal-boot-loader-in-embedded-designs/">1</a>]</li> </ul> <p><strong>Quellcode vom Universal Bootloader "U-Boot":</strong><br> - <a href="https://u-boot.org/">https://u-boot.org/</a> - offizielle Webseite<br> - <a href="https://source.denx.de/u-boot/u-boot">https://source.denx.de/u-boot/u-boot</a> - Source Codeverwaltung / Source Code Download</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Altruistic_Level9640"> /u/Altruistic_Level9640 </a> <br> <span><a href="https://www.it-boltwise.de/neue-u-boot-sicherheitsluecken-angreifer-koennten-boot-images-zum-absturz-oder-code-execution-bringen.html">[link]</a></span>   <span><a href="https://www.reddit.com/r/Computersicherheit/comments/1usz5b4/neue_uboot_bootloader_sicherheitsl%C3%BCcken_angreifer/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s Howard’s end? Former Starbucks CEO is ripping Washington state again]]></title>
<description><![CDATA[For the second time in the past 60 days, former Starbucks CEO Howard Schultz has penned an opinion piece in the Wall Street Journal that takes direct aim at the state’s political leadership, calling Seattle Mayor Katie Wilson “inept” and noting that Gov. Bob Ferguson continues to “burden business...]]></description>
<link>https://tsecurity.de/de/3660987/it-nachrichten/whats-howards-end-former-starbucks-ceo-is-ripping-washington-state-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660987/it-nachrichten/whats-howards-end-former-starbucks-ceo-is-ripping-washington-state-again/</guid>
<pubDate>Sat, 11 Jul 2026 01:47:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1240" height="826" src="https://cdn.geekwire.com/wp-content/uploads/2017/03/20170322_Starbucks_Shareholders_Meeting_128-1240x826.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2017/03/20170322_Starbucks_Shareholders_Meeting_128-1240x826.jpg 1240w, https://cdn.geekwire.com/wp-content/uploads/2017/03/20170322_Starbucks_Shareholders_Meeting_128-768x512.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2017/03/20170322_Starbucks_Shareholders_Meeting_128-630x420.jpg 630w, https://cdn.geekwire.com/wp-content/uploads/2017/03/20170322_Starbucks_Shareholders_Meeting_128.jpg 1730w" sizes="(max-width: 1240px) 100vw, 1240px"><br>For the second time in the past 60 days, former Starbucks CEO Howard Schultz has penned an opinion piece in the Wall Street Journal that takes direct aim at the state’s political leadership, calling Seattle Mayor Katie Wilson “inept” and noting that Gov. Bob Ferguson continues to “burden businesses with one tax increase after another.” <a href="https://www.geekwire.com/2026/whats-howards-end-former-starbucks-ceo-is-ripping-washington-state-again/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Whats your go-to prompting hack?]]></title>
<description><![CDATA[Author: Google for Developers - Bewertung: 4x - Views:175 Here are some prompting tips that can save you time and yield a better product. 

Resources: 
Learn more → https://goo.gle/Build-With-AI

Subscribe to Google for Developers → https://goo.gle/developers]]></description>
<link>https://tsecurity.de/de/3660673/videos/whats-your-go-to-prompting-hack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660673/videos/whats-your-go-to-prompting-hack/</guid>
<pubDate>Fri, 10 Jul 2026 21:18:10 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Google for Developers - Bewertung: 4x - Views:175 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/8ZCeXQyavog?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Here are some prompting tips that can save you time and yield a better product. <br />
<br />
Resources: <br />
Learn more → https://goo.gle/Build-With-AI<br />
<br />
Subscribe to Google for Developers → https://goo.gle/developers<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-10 21h : 5 posts]]></title>
<description><![CDATA[5 posts were published in the last hour 18:32 : Top 6 Managed Detection and Response Providers 18:32 : Top 10 Best Unified Threat Management (UTM) Solutions in 2026 18:32 : One WhatsApp Message Turns OpenClaw Into a Remote Access…
Read more →
The post IT Security News Hourly Summary 2026-07-10 21...]]></description>
<link>https://tsecurity.de/de/3660653/it-security-nachrichten/it-security-news-hourly-summary-2026-07-10-21h-5-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660653/it-security-nachrichten/it-security-news-hourly-summary-2026-07-10-21h-5-posts/</guid>
<pubDate>Fri, 10 Jul 2026 21:08:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>5 posts were published in the last hour 18:32 : Top 6 Managed Detection and Response Providers 18:32 : Top 10 Best Unified Threat Management (UTM) Solutions in 2026 18:32 : One WhatsApp Message Turns OpenClaw Into a Remote Access…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-10-21h-5-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-10-21h-5-posts/">IT Security News Hourly Summary 2026-07-10 21h : 5 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers]]></title>
<description><![CDATA[Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message. The flaws, confirmed exploitable on OpenClaw 2026.6.1, expose a structural weakness in how…
Read...]]></description>
<link>https://tsecurity.de/de/3660618/it-security-nachrichten/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660618/it-security-nachrichten/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/</guid>
<pubDate>Fri, 10 Jul 2026 20:35:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message. The flaws, confirmed exploitable on OpenClaw 2026.6.1, expose a structural weakness in how…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/">One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw Vulnerabilities Let Attackers Turn WhatsApp Messages Into Host-Level Code Execution]]></title>
<description><![CDATA[Security researchers have disclosed three high-severity vulnerabilities in OpenClaw, the popular open-source AI coding assistant with over 381,000 GitHub stars, that allow attackers to achieve full remote code execution using nothing more than a cleverly worded WhatsApp message. The flaws bypass ...]]></description>
<link>https://tsecurity.de/de/3660504/it-security-nachrichten/openclaw-vulnerabilities-let-attackers-turn-whatsapp-messages-into-host-level-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660504/it-security-nachrichten/openclaw-vulnerabilities-let-attackers-turn-whatsapp-messages-into-host-level-code-execution/</guid>
<pubDate>Fri, 10 Jul 2026 19:40:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers have disclosed three high-severity vulnerabilities in OpenClaw, the popular open-source AI coding assistant with over 381,000 GitHub stars, that allow attackers to achieve full remote code execution using nothing more than a cleverly worded WhatsApp message. The flaws bypass the tool’s environment variable sanitization, its command execution safeguards, and its Docker sandbox isolation […]</p>
<p>The post <a href="https://cyberpress.org/openclaw-remote-access-tool/">OpenClaw Vulnerabilities Let Attackers Turn WhatsApp Messages Into Host-Level Code Execution</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers]]></title>
<description><![CDATA[Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message. The flaws, confirmed exploitable on OpenClaw 2026.6.1, expose a structural weakness in how AI ag...]]></description>
<link>https://tsecurity.de/de/3660479/it-security-nachrichten/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660479/it-security-nachrichten/one-whatsapp-message-turns-openclaw-into-a-remote-access-tool-for-hackers/</guid>
<pubDate>Fri, 10 Jul 2026 19:29:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message. The flaws, confirmed exploitable on OpenClaw 2026.6.1, expose a structural weakness in how AI agents handle untrusted input from messaging channels. OpenClaw is a self-hosted AI assistant that […]</p>
<p>The post <a href="https://cybersecuritynews.com/whatsapp-message-openclaw-remote-access-tool/">One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw: WhatsApp-zu-Host-Angriffskette über drei gepatchte KI-Sicherheitslücken]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Offenbar lassen sich über WhatsApp an eine KI-Assistenten-Instanz Nachrichten senden, die im schlimmsten Fall Code auf dem Host ausführen. Auslöser sind drei inzwischen gepatchte OpenClaw-Sicherheitslücken mit CVSS-Werten bis zu 8, 8, darunter Command-Injection und ein Pfad...]]></description>
<link>https://tsecurity.de/de/3660373/it-security-nachrichten/openclaw-whatsapp-zu-host-angriffskette-ueber-drei-gepatchte-ki-sicherheitsluecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660373/it-security-nachrichten/openclaw-whatsapp-zu-host-angriffskette-ueber-drei-gepatchte-ki-sicherheitsluecken/</guid>
<pubDate>Fri, 10 Jul 2026 18:33:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/openclaw-whatsapp-zu-host-attack-chain-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Offenbar lassen sich über WhatsApp an eine KI-Assistenten-Instanz Nachrichten senden, die im schlimmsten Fall Code auf dem Host ausführen. Auslöser sind drei inzwischen gepatchte OpenClaw-Sicherheitslücken mit CVSS-Werten bis zu 8, 8, darunter Command-Injection und ein Pfad-Umgehungsproblem bei Bind-Mounts. Für Unternehmen ist die Nachricht besonders relevant, weil die praktische Auswirkung stark von […]</p>
<div><a href="https://www.it-boltwise.de/openclaw-whatsapp-zu-host-angriffskette-ueber-drei-gepatchte-ki-sicherheitsluecken.html">... den vollständigen Artikel <strong>»OpenClaw: WhatsApp-zu-Host-Angriffskette über drei gepatchte KI-Sicherheitslücken«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/openclaw-whatsapp-zu-host-angriffskette-ueber-drei-gepatchte-ki-sicherheitsluecken.html">OpenClaw: WhatsApp-zu-Host-Angriffskette über drei gepatchte KI-Sicherheitslücken</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws]]></title>
<description><![CDATA[Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vuln...]]></description>
<link>https://tsecurity.de/de/3660167/it-security-nachrichten/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660167/it-security-nachrichten/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/</guid>
<pubDate>Fri, 10 Jul 2026 17:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulnerabilities…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/">Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws]]></title>
<description><![CDATA[Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host.

A brief description of the high-severity vul...]]></description>
<link>https://tsecurity.de/de/3660075/it-security-nachrichten/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660075/it-security-nachrichten/researcher-details-whatsapp-to-host-attack-chain-using-three-openclaw-flaws/</guid>
<pubDate>Fri, 10 Jul 2026 16:54:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host.

A brief description of the high-severity vulnerabilities is as follows -


  GHSA-hjr6-g723-hmfm (CVSS score: 8.8) - An operating system]]></content:encoded>
</item>
<item>
<title><![CDATA[The Authenticity Problem: When Employees Can’t Tell What’s Real Anymore]]></title>
<description><![CDATA[Short answer 
Information authenticity is the ability to judge whether a message, identity, source, file, image, voice, video, instruction, or system output is genuine enough to act on. As AI-generated content, synthetic media, impersonation attacks, and automated workflows become more convincing...]]></description>
<link>https://tsecurity.de/de/3659792/it-security-nachrichten/the-authenticity-problem-when-employees-cant-tell-whats-real-anymore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659792/it-security-nachrichten/the-authenticity-problem-when-employees-cant-tell-whats-real-anymore/</guid>
<pubDate>Fri, 10 Jul 2026 15:09:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://cybermaniacs.com/cm-blog/the-authenticity-problem-when-employees-cant-tell-whats-real-anymore" title="" class="hs-featured-image-link"> <img src="https://cybermaniacs.com/hubfs/Blog%20Header%20Graphics/Understanding%20Behavioral%20Cybersecurity.png" alt="The Authenticity Problem: When Employees Can’t Tell What’s Real Anymore" class="hs-featured-image"> </a> 
</div> 
<h2><strong><span>Short answer</span></strong></h2> 
<p><span>Information authenticity is the ability to judge whether a message, identity, source, file, image, voice, video, instruction, or system output is genuine enough to act on. As AI-generated content, synthetic media, impersonation attacks, and automated workflows become more convincing, employees need clearer source-of-truth channels, stronger verification habits, and practical guidance for deciding when something is trustworthy. The goal is not to turn everyone into a forensic analyst. The goal is to make authenticity easier to check in the moments that matter.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches low-cost Muse Spark 1.1 as enterprise AI spending comes under scrutiny]]></title>
<description><![CDATA[Meta has unveiled Muse Spark 1.1, saying the frontier AI model rivals leading LLMs on coding, computer use, and agentic AI benchmarks while undercutting OpenAI and Anthropic on API pricing, potentially lowering the cost of deploying AI agents in enterprises.



Meta unveiled Muse Spark 1.1 on Thu...]]></description>
<link>https://tsecurity.de/de/3659379/it-nachrichten/meta-launches-low-cost-muse-spark-11-as-enterprise-ai-spending-comes-under-scrutiny/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659379/it-nachrichten/meta-launches-low-cost-muse-spark-11-as-enterprise-ai-spending-comes-under-scrutiny/</guid>
<pubDate>Fri, 10 Jul 2026 12:18:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Meta has unveiled Muse Spark 1.1, saying the frontier AI model rivals leading LLMs on coding, computer use, and agentic AI benchmarks while undercutting OpenAI and Anthropic on API pricing, potentially lowering the cost of deploying AI agents in enterprises.</p>



<p>Meta unveiled Muse Spark 1.1 on Thursday, pairing frontier-model performance with aggressive pricing in a move that analysts say could pressure rivals such as OpenAI and Anthropic and reshape enterprise AI procurement decisions.</p>



<p>Meta is betting that lower inference costs can help it gain ground in the enterprise AI market with the launch of Muse Spark 1.1, a frontier model that rivals top competitors on key benchmarks while costing a fraction as much to deploy.</p>



<p>The latest model, which was <a href="https://www.infoworld.com/article/4192724/metas-ai-chief-says-new-muse-spark-update-will-sharpen-coding-agentic-ai.html" target="_blank">teased</a> last week, matched or was competitive with leading models, such as Claude Opus 4.8, Gemini 3.1 Pro, and GPT 5.5, across several agentic AI, coding, and computer-use benchmarks, including SWE-bench Verified, Terminal-bench, BrowseComp, SpreadsheetBench, and OSWorld, Meta wrote in a blog <a href="https://ai.meta.com/blog/introducing-muse-spark-meta-model-api/" target="_blank" rel="noreferrer noopener">post</a>.</p>



<p>Muse Spark 1.1, which is currently in public preview and available via the Meta Model API, will cost $1.25 per million input tokens and $4.25 per million output tokens, the company <a href="https://developer.meta.com/ai/products/meta-model-api/" target="_blank" rel="noreferrer noopener">noted</a>.</p>



<p>By comparison, OpenAI <a href="https://developers.openai.com/api/docs/pricing" target="_blank" rel="noreferrer noopener">charges</a> $5 per million input tokens and $30 per million output tokens for GPT-5.5, while Anthropic <a href="https://platform.claude.com/docs/en/about-claude/pricing" target="_blank" rel="noreferrer noopener">charges</a> $5 and $25, respectively, for Claude Opus 4.8. Google’s Gemini 3.1 Pro, on the other hand, is <a href="https://ai.google.dev/gemini-api/docs/pricing">priced</a> at $2 per million input tokens and $12 per million output tokens.</p>



<h2 class="wp-block-heading">Lower prices may open doors, not close deals</h2>



<p>That sheer difference in API pricing, according to <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, is enough to attract CIOs’ attention, at least for pilots, at a time when enterprises are trying to scale agentic deployments: “Pricing matters because inference costs increase rapidly when thousands of agents are working continuously.”</p>



<p>“Output tokens are often the largest model expense in coding, customer service, and process automation agents. Muse Spark’s output price is about 86% below GPT-5.5 and more than 90% below Claude Opus 4.8,” Jain said.</p>



<p>However, <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at FinOps services providing firm ZopDev, pointed out that the price is not a guarantee of adoption, despite the fact that most enterprises are likely to deploy the Muse Spark 1.1 for new projects.</p>



<p>“Cost becomes the primary differentiator only once the model is judged good enough. Developers don’t pick the cheapest model; they pick the cheapest model that clears their quality bar. So, price is the reason people show up, capability is the reason they stay,” Bandta said.</p>



<p>Similarly, CIOs are also likely to put more emphasis on the model’s security, data protection, uptime, audit trails, regional availability, support, and predictable behavior, rather than just the price, Jain said.</p>



<p>That distinction, according to Bandta, reflects a familiar pattern in enterprise technology buying: “This is the same lesson we saw in the cloud, where the cheapest provider on paper rarely won the biggest enterprise share. Price is one input in the total cost of ownership that includes risk, control, and switching cost, not the whole decision.”</p>



<p>Even so, the lower pricing could still shift the balance of power in enterprise procurement, Jain said: “This could help CIOs negotiate larger volume discounts, committed-use agreements, and better pricing from OpenAI, Anthropic, and cloud providers. It also strengthens the case for multi-model procurement rather than depending on one vendor.”</p>



<p>“Companies that do not even adopt Muse Spark can also use its pricing as evidence that frontier-level inference is becoming cheaper,” Jain added.</p>



<h2 class="wp-block-heading">Meta’s pricing could reshape competition between rivals</h2>



<p>Analysts pointed out that Meta’s new model could intensify competition in the frontier model market by forcing rivals to compete on inference economics and model sizes.</p>



<p>“It’s a real shot across the bow, and I’d expect OpenAI and Anthropic to respond on two fronts. Some of it will be price, cheaper tiers, and better cached and batch rates, because Meta has just reset what the market thinks a frontier token should cost,” Bandta said.</p>



<p>“But the incumbents won’t win the race with lower-priced offerings and more flexible pricing models. I expect them to lean harder into the things price can’t buy, governance, security, reliability, and enterprise support, to justify premium pricing,” Bandta added, likening the shift to an “early innings” of a price war that the industry saw with the expansion of cloud.</p>



<p>“The cloud infrastructure price war showed that while prices fell over time, vendors ultimately differentiated themselves through platform capabilities rather than cost alone,” Bandta further added.</p>



<p>In contrast, <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, head of AI at IT consulting firm Kanerika, pointed out that a cloud-infrastructure-style pricing war was unlikely: “Frontier models are capital-intensive; margins are already thin. Vendors can’t sustain aggressive repricing without sacrificing quality.”</p>



<p>Rather, Jena sees Meta increasing prices soon after launch: “History suggests what happens next — aggressive entry pricing, then repricing once market share solidifies. See Meta’s advertising platform and cloud pricing evolution across the industry. If that pattern repeats, pricing could rise 30–50% in 18–24 months.”</p>



<p>For now, Meta is offering developers $20 in free API credits to experiment with Muse Spark 1.1.</p>



<p><em>The article originally appeared on <a href="https://www.infoworld.com/article/4195519/meta-launches-low-cost-muse-spark-1-1-as-enterprise-ai-spending-comes-under-scrutiny.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How a Formula 1 IT director balances innovation and stability at 200 mph]]></title>
<description><![CDATA[Michael Taylor has spent 25 seasons with the Mercedes-AMG Petronas F1 team, working every IT role from trackside support to engineering systems to business transformation. Today, as IT director, he leads an 18-person team responsible for one of the most data-intensive operations in the world.



...]]></description>
<link>https://tsecurity.de/de/3659354/it-security-nachrichten/how-a-formula-1-it-director-balances-innovation-and-stability-at-200-mph/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659354/it-security-nachrichten/how-a-formula-1-it-director-balances-innovation-and-stability-at-200-mph/</guid>
<pubDate>Fri, 10 Jul 2026 12:08:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Michael Taylor has spent 25 seasons with the Mercedes-AMG Petronas F1 team, working every IT role from trackside support to engineering systems to business transformation. Today, as IT director, he leads an 18-person team responsible for one of the most data-intensive operations in the world.</p>



<p>When a car rolls out of the garage, it carries 300 sensors. When it’s running, it generates more than a million data points per second. Every component, system, and lap produces telemetry that engineers use to find fractions of a second — the difference between winning and losing.</p>



<p>“Formula One has been data-centric for many years,” Taylor says. “The key metric in our sport is the stopwatch, and that’s been true since the World Championship began in the 1950s. But now we instrument everything. If you measure it, you can improve it.”</p>



<p>The challenge isn’t collecting data — Formula One has been streaming live telemetry since the 1980s. It’s making decisions at speed while maintaining the governance that keeps a complex, high-stakes operation running.</p>



<p>For CIOs navigating the pressure to move fast on AI while managing risk, security, and data quality, Taylor’s hard-won lessons from the pit lane offer a useful framework: how to balance speed and control, when to keep humans in the loop, and why “good enough” governance beats perfect governance that never ships.</p>



<h2 class="wp-block-heading">Innovation vs. stability: ‘A constant battle’</h2>



<p>In most enterprises, the <a href="https://www.cio.com/article/4188566/cios-rethink-the-balance-between-ai-oversight-and-innovation.html">tension between innovation and control</a> plays out over quarters or years. In F1, it happens weekly.</p>



<p>“It’s really tough,” Taylor admits. “And something we don’t always get right. This is where we rely on people. Industry experience is really important when making decisions around change.”</p>



<p>The team operates in two distinct modes. Between races, they’re at the factory in Brackley, UK. The site, which is headquarters for the design, manufacturing, and operation of their championship-winning Formula One cars, includes a 60,000-square-meter technology campus. It’s all project and program management, with room for experimentation. But as race weekend approaches, everything shifts to execution.</p>



<p>“We have that kind of normal mode when we’re not racing. We’re back at the factory designing and building and improving,” Taylor explains. “But as we get closer to race weekend, we switch to executing that in the most effective way. We have to not make changes that will impact engineers.”</p>



<p>This duality shapes every technology decision. The same agility that drives innovation during the week must yield to stability when results are on the line. Taylor calls it a “constant battle.”</p>



<h2 class="wp-block-heading">Modernizing at racing speed</h2>



<p>Mercedes-AMG Petronas had run SAP since 1999. The platform underpins the team’s entire design-to-track process — from design release through planning, procurement, manufacturing, testing, and development, all the way to reassembling the car trackside.</p>



<p>“All of those steps are core processes,” Taylor says.</p>



<p>So, when it came time to modernize, the team approached it like a pit stop: planned to the second, executed with precision. They chose RISE with SAP — the vendor’s bundled cloud ERP and migration package — agreeing to the journey in December 2024 and targeting a go-live in August 2025, aligned with the sport’s mandatory two-week shutdown.</p>



<p>“It’s the perfect window to make changes,” Taylor says. “We have to plan everything to perfection so it goes smoothly when we start racing again.”</p>



<p>They finished eight weeks ahead of schedule.</p>



<p>“We are control freaks because of the sport and its time-bound nature,” Taylor says. His team prefers to own and manage systems in-house rather than rely on large systems integrators who “dip their toes in and disappear,” Taylor says. With just 18 people on the IT team, they tap SAP’s expertise for specific problems, then take back the reins. “Once done, we continue to own and manage,” Taylor explains, “and SAP does what they do best.”</p>



<h2 class="wp-block-heading">The secure path must be the easiest path</h2>



<p>Intellectual property in F1 racing has a short shelf life. Once a new component is on the car and photographed in the pit lane, competitors can see it. But that doesn’t diminish the value of what’s behind it.</p>



<p>“The real advantage is not just the part,” Taylor says. “It’s the thinking, the modeling, the simulation, the failure modes, the trade-offs, and the development direction behind it.”</p>



<p>Protecting that requires an offensive security posture. Taylor’s head of information security reports directly to him, and the team actively probes its own defenses.</p>



<p>“Act like, think like, work like a hacker,” Taylor says. “We’re thinking about how we can counter threats without impact on end-users.”</p>



<p>In an engineering-permissive culture where people are empowered to move fast, heavy-handed security backfires. Taylor learned early that perfection is the enemy of progress.</p>



<p>“If security gets in the way of the business, the business will find ways to work around it,” he says. “The job is not to slow the organization down; it’s to make the secure path the easiest path.”</p>



<h2 class="wp-block-heading">Humans in the loop</h2>



<p>With AI evolving weekly, Taylor’s team is running pilots across the organization: machine learning for simulation, agentic workflows in production planning, copilots helping developers write code. But he’s resisting the urge to rush.</p>



<p>“We’re still finding our way,” he says. “There’s no one-size-fits-all. We’re playing with everything available, but in six to ten months we’ll make decisions about what to scale.”</p>



<p>Despite the hype around autonomous AI, Taylor remains committed to human oversight.</p>



<p>“I’m still very much ‘humans should be in the loop,’” he says. “When our workforce is harmonized with AI, that’s where we’ll see real benefit — where it complements our people.”</p>



<p>AI has also raised the bar for data governance. “Good enough now includes stronger visibility, cleaner permissions, and clearer ownership,” Taylor says. “You have to be more deliberate about what data AI is allowed to access.”</p>



<h2 class="wp-block-heading">Start with consequence</h2>



<p>Taylor’s advice to CIOs in other industries wrestling with similar questions is deceptively simple: “Start with consequence, not technology.”</p>



<p>In financial services, it might be customer harm or a regulatory breach. In healthcare, patient safety or loss of public trust. In F1, the consequence of a security failure is loss of competitive advantage.</p>



<p>“Once you understand the consequence, you can decide what needs the strongest control, what needs monitoring, what needs retention, and what simply needs better hygiene,” Taylor says.</p>



<p>It’s a lesson learned over 25 seasons at the edge of what’s technically possible — where decisions happen in milliseconds, and the margin between success and failure is measured in fractions of a second.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches low-cost Muse Spark 1.1 as enterprise AI spending comes under scrutiny]]></title>
<description><![CDATA[Meta has unveiled Muse Spark 1.1, saying the frontier AI model rivals leading LLMs on coding, computer use, and agentic AI benchmarks while undercutting OpenAI and Anthropic on API pricing, potentially lowering the cost of deploying AI agents in enterprises.



Meta unveiled Muse Spark 1.1 on Thu...]]></description>
<link>https://tsecurity.de/de/3659344/ai-nachrichten/meta-launches-low-cost-muse-spark-11-as-enterprise-ai-spending-comes-under-scrutiny/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659344/ai-nachrichten/meta-launches-low-cost-muse-spark-11-as-enterprise-ai-spending-comes-under-scrutiny/</guid>
<pubDate>Fri, 10 Jul 2026 12:04:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Meta has unveiled Muse Spark 1.1, saying the frontier AI model rivals leading LLMs on coding, computer use, and agentic AI benchmarks while undercutting OpenAI and Anthropic on API pricing, potentially lowering the cost of deploying AI agents in enterprises.</p>



<p>Meta unveiled Muse Spark 1.1 on Thursday, pairing frontier-model performance with aggressive pricing in a move that analysts say could pressure rivals such as OpenAI and Anthropic and reshape enterprise AI procurement decisions.</p>



<p>Meta is betting that lower inference costs can help it gain ground in the enterprise AI market with the launch of Muse Spark 1.1, a frontier model that rivals top competitors on key benchmarks while costing a fraction as much to deploy.</p>



<p>The latest model, which was <a href="https://www.infoworld.com/article/4192724/metas-ai-chief-says-new-muse-spark-update-will-sharpen-coding-agentic-ai.html" target="_blank">teased</a> last week, matched or was competitive with leading models, such as Claude Opus 4.8, Gemini 3.1 Pro, and GPT 5.5, across several agentic AI, coding, and computer-use benchmarks, including SWE-bench Verified, Terminal-bench, BrowseComp, SpreadsheetBench, and OSWorld, Meta wrote in a blog <a href="https://ai.meta.com/blog/introducing-muse-spark-meta-model-api/" target="_blank" rel="noreferrer noopener">post</a>.</p>



<p>Muse Spark 1.1, which is currently in public preview and available via the Meta Model API, will cost $1.25 per million input tokens and $4.25 per million output tokens, the company <a href="https://developer.meta.com/ai/products/meta-model-api/" target="_blank" rel="noreferrer noopener">noted</a>.</p>



<p>By comparison, OpenAI <a href="https://developers.openai.com/api/docs/pricing" target="_blank" rel="noreferrer noopener">charges</a> $5 per million input tokens and $30 per million output tokens for GPT-5.5, while Anthropic <a href="https://platform.claude.com/docs/en/about-claude/pricing" target="_blank" rel="noreferrer noopener">charges</a> $5 and $25, respectively, for Claude Opus 4.8. Google’s Gemini 3.1 Pro, on the other hand, is <a href="https://ai.google.dev/gemini-api/docs/pricing">priced</a> at $2 per million input tokens and $12 per million output tokens.</p>



<h2 class="wp-block-heading">Lower prices may open doors, not close deals</h2>



<p>That sheer difference in API pricing, according to <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, is enough to attract CIOs’ attention, at least for pilots, at a time when enterprises are trying to scale agentic deployments: “Pricing matters because inference costs increase rapidly when thousands of agents are working continuously.”</p>



<p>“Output tokens are often the largest model expense in coding, customer service, and process automation agents. Muse Spark’s output price is about 86% below GPT-5.5 and more than 90% below Claude Opus 4.8,” Jain said.</p>



<p>However, <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at FinOps services providing firm ZopDev, pointed out that the price is not a guarantee of adoption, despite the fact that most enterprises are likely to deploy the Muse Spark 1.1 for new projects.</p>



<p>“Cost becomes the primary differentiator only once the model is judged good enough. Developers don’t pick the cheapest model; they pick the cheapest model that clears their quality bar. So, price is the reason people show up, capability is the reason they stay,” Bandta said.</p>



<p>Similarly, CIOs are also likely to put more emphasis on the model’s security, data protection, uptime, audit trails, regional availability, support, and predictable behavior, rather than just the price, Jain said.</p>



<p>That distinction, according to Bandta, reflects a familiar pattern in enterprise technology buying: “This is the same lesson we saw in the cloud, where the cheapest provider on paper rarely won the biggest enterprise share. Price is one input in the total cost of ownership that includes risk, control, and switching cost, not the whole decision.”</p>



<p>Even so, the lower pricing could still shift the balance of power in enterprise procurement, Jain said: “This could help CIOs negotiate larger volume discounts, committed-use agreements, and better pricing from OpenAI, Anthropic, and cloud providers. It also strengthens the case for multi-model procurement rather than depending on one vendor.”</p>



<p>“Companies that do not even adopt Muse Spark can also use its pricing as evidence that frontier-level inference is becoming cheaper,” Jain added.</p>



<h2 class="wp-block-heading">Meta’s pricing could reshape competition between rivals</h2>



<p>Analysts pointed out that Meta’s new model could intensify competition in the frontier model market by forcing rivals to compete on inference economics and model sizes.</p>



<p>“It’s a real shot across the bow, and I’d expect OpenAI and Anthropic to respond on two fronts. Some of it will be price, cheaper tiers, and better cached and batch rates, because Meta has just reset what the market thinks a frontier token should cost,” Bandta said.</p>



<p>“But the incumbents won’t win the race with lower-priced offerings and more flexible pricing models. I expect them to lean harder into the things price can’t buy, governance, security, reliability, and enterprise support, to justify premium pricing,” Bandta added, likening the shift to an “early innings” of a price war that the industry saw with the expansion of cloud.</p>



<p>“The cloud infrastructure price war showed that while prices fell over time, vendors ultimately differentiated themselves through platform capabilities rather than cost alone,” Bandta further added.</p>



<p>In contrast, <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, head of AI at IT consulting firm Kanerika, pointed out that a cloud-infrastructure-style pricing war was unlikely: “Frontier models are capital-intensive; margins are already thin. Vendors can’t sustain aggressive repricing without sacrificing quality.”</p>



<p>Rather, Jena sees Meta increasing prices soon after launch: “History suggests what happens next — aggressive entry pricing, then repricing once market share solidifies. See Meta’s advertising platform and cloud pricing evolution across the industry. If that pattern repeats, pricing could rise 30–50% in 18–24 months.”</p>



<p>For now, Meta is offering developers $20 in free API credits to experiment with Muse Spark 1.1.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15317 | Sipeed PicoClaw up to 0.2.9 Guarded Web Fetch Flow web.go WebFetchTool.Execute server-side request forgery (Issue 3078 / EUVD-2026-42757)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integration/web.go of the component Guarded Web Fetch Flow. The manipulation results in server-side request forgery.
...]]></description>
<link>https://tsecurity.de/de/3658627/sicherheitsluecken/cve-2026-15317-sipeed-picoclaw-up-to-029-guarded-web-fetch-flow-webgo-webfetchtoolexecute-server-side-request-forgery-issue-3078-euvd-2026-42757/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658627/sicherheitsluecken/cve-2026-15317-sipeed-picoclaw-up-to-029-guarded-web-fetch-flow-webgo-webfetchtoolexecute-server-side-request-forgery-issue-3078-euvd-2026-42757/</guid>
<pubDate>Fri, 10 Jul 2026 05:38:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/sipeed:picoclaw">Sipeed PicoClaw up to 0.2.9</a>. Affected by this vulnerability is the function <code>WebFetchTool.Execute</code> of the file <em>pkg/tools/integration/web.go</em> of the component <em>Guarded Web Fetch Flow</em>. The manipulation results in server-side request forgery.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-15317">CVE-2026-15317</a>. The attack can be executed remotely. Additionally, an exploit exists.

The reported GitHub issue was closed automatically due to inactivity.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding tool hole illustrates a big problem with human in the loop]]></title>
<description><![CDATA[A security hole within AI dev tools has allowed attackers to escape sandboxes by misleading the humans in the loop who were supposed to knowingly approve the tool’s actions, according to cybersecurity research firm Wiz.



“We discovered GhostApproval, a systematic vulnerability pattern affecting...]]></description>
<link>https://tsecurity.de/de/3658391/it-security-nachrichten/ai-coding-tool-hole-illustrates-a-big-problem-with-human-in-the-loop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658391/it-security-nachrichten/ai-coding-tool-hole-illustrates-a-big-problem-with-human-in-the-loop/</guid>
<pubDate>Fri, 10 Jul 2026 01:08:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A security hole within AI dev tools has allowed attackers to escape sandboxes by misleading the humans in the loop who were supposed to knowingly approve the tool’s actions, according to cybersecurity research firm Wiz.</p>



<p>“We discovered GhostApproval, a systematic vulnerability pattern affecting six of the top AI coding assistants: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf [<a href="https://www.infoworld.com/article/4023030/cognition-agrees-to-buy-whats-left-of-windsurf.html" target="_blank">now known as Devin Desktop</a>],” <a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noreferrer noopener">the Wiz report</a> said. “In each case, a malicious repository can trick the agent into accessing arbitrary files outside the workspace sandbox, potentially achieving remote code execution on the developer’s machine.”</p>



<p>The <a href="https://www.csoonline.com/article/4191923/sandbox-bypass-flaws-in-cursor-ide-highlight-prompt-injection-as-an-rce-vector.html" target="_blank">first report of the hole</a> came earlier this month from Cato Networks, but was limited to one platform, Cursor, whereas Wiz found that its impact was far wider. </p>



<p>The underlying security problem, <a href="https://cwe.mitre.org/data/definitions/61.html" target="_blank" rel="noreferrer noopener">symbolic links</a> (symlinks), is well known and has been leveraged for decades. But GhostApproval, Wiz noted, goes well beyond their historic use as an attack vector. </p>



<p>Symbolic links are special files that act as shortcuts to other files or directories. In attacks, they typically resolve to a target outside of the intended control sphere, which allows a threat actor to operate on unauthorized files in a less- or uncontrolled environment, outside of a secure sandbox, or even an air-gapped system.</p>



<p>“In several cases,” Wiz noted, “the agent’s internal reasoning explicitly recognizes the dangerous target, yet the confirmation prompt shown to the user conceals this information entirely. This is <a href="https://cwe.mitre.org/data/definitions/451.html" target="_blank" rel="noreferrer noopener">CWE-451</a> – UI misrepresentation of critical information – layered on top of the symlink vulnerability. The user approves what they believe is a harmless local edit. The agent then writes to a sensitive file outside of the project workspace.”</p>



<p>Wiz said it reported the issue to the six vendors initially impacted; AWS, Cursor and Google “fixed the issue promptly,” Augment and Windsurf/Devin “acknowledged receipt but went silent,” and Anthropic had already fixed the problem before it was contacted by Wiz.</p>



<h2 class="wp-block-heading">Potentially massive exposure</h2>



<p>But analysts and consultants said the AI dev tool problem that Wiz described illustrates a far greater security risk: enterprises are trusting these tools and the information they report far too much, which is what may give attackers a big opportunity.</p>



<p><a href="https://my.idc.com/getdoc.jsp?containerId=PRF005561" target="_blank" rel="noreferrer noopener">Katie Norton</a>, senior research manager for DevSecOps at IDC, noted that the Wiz report pointed out a disturbing fact. “The safety check people rely on to catch these actions doesn’t actually stop anything. That’s a real way for an attacker to break into a developer’s machine,” she said. “The scope is bounded by one condition: the attack requires a developer to clone and operate on an untrusted or malicious repository. That concentrates the risk in workflows touching external contributors, forked repositories, and third-party or open source dependencies, rather than in internally authored code.”</p>



<p>Norton said the exposure from this flaw, along with similar holes in other AI dev tools, is potentially massive. “Since March 2025, security vendors and researchers have disclosed comparable issues in nearly every major AI coding assistant. That pattern: a mitigation ships, then a new bypass of that same mitigation surfaces within months. That is worth watching and reflects how new this category’s threat model still is across the board, it’s not a gap specific to any one vendor’s practices.”</p>



<p>That means, she said, that agentic coding tools need multilayered defense, because the risk isn’t confined to the code an agent generates. “The tools themselves sit within the software supply chain and can be attacked directly. GhostApproval makes that point clearly,” she noted. </p>



<p>“The vulnerability has nothing to do with code quality or insecure output. It’s a flaw in how the agent handles files and represents its own actions to the user, introduced by the tool’s design rather than a bad prompt or a compromised dependency. Failure to account for the coding tools’ own attack surface is what leaves this kind of gap unaddressed.”</p>



<h2 class="wp-block-heading">Rethink policies and procedures</h2>



<p><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, agreed; enterprise CISOs need to potentially rethink many of their AI dev tool policies and procedures. </p>



<p>“The significant part is that the agent’s own reasoning identified the malicious target and the approval dialog hid it anyway. The tool knew it was writing to SSH keys and still asked a human to approve an edit to a config file, giving the human an illusion of control over the model,” Kenney said. “Many considered human in the loop to be the answer to agent risk, but this report shows that the loop can be fed bad information by the very agent it is supposed to be supervising.”</p>



<p>Because of this, Kenney advised adjusting the way tool management is enforced.</p>



<p>“Treat AI coding assistants as privileged software with filesystem access, not as editor plugins. That means patch discipline, version pinning, and knowing which tools in your environment write to disk before authorization,” Kenney said. “Then sandbox the blast radius. These agents should run against trusted repositories in isolated environments where a write to <em>authorized_keys</em> goes nowhere. Do not rely on the tool’s own dialog as your control or governance solution.”</p>



<h2 class="wp-block-heading">A category-wide design issue</h2>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, added that this security hole is a much bigger enterprise security strategy problem than most CISOs realize. </p>



<p>“Six different vendors independently arrived at a very similar trust model. That suggests we’re looking at a category-wide design challenge rather than a collection of isolated implementation bugs. If vulnerabilities like this remained uncorrected, they would represent a meaningful enterprise risk, particularly for organizations that allow AI coding assistants to interact with untrusted repositories or production development environments,” he said. </p>



<p>“The immediate concern isn’t simply remote code execution. It’s that these agents operate with a level of filesystem access, tool access, and developer trust that traditional IDE extensions never had. Once an AI agent becomes an active participant in software development, every trust boundary it crosses becomes part of the organization’s attack surface.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding tool hole illustrates a big problem with human in the loop]]></title>
<description><![CDATA[A security hole within AI dev tools has allowed attackers to escape sandboxes by misleading the humans in the loop who were supposed to knowingly approve the tool’s actions, according to cybersecurity research firm Wiz.



“We discovered GhostApproval, a systematic vulnerability pattern affecting...]]></description>
<link>https://tsecurity.de/de/3658387/ai-nachrichten/ai-coding-tool-hole-illustrates-a-big-problem-with-human-in-the-loop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658387/ai-nachrichten/ai-coding-tool-hole-illustrates-a-big-problem-with-human-in-the-loop/</guid>
<pubDate>Fri, 10 Jul 2026 01:03:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A security hole within AI dev tools has allowed attackers to escape sandboxes by misleading the humans in the loop who were supposed to knowingly approve the tool’s actions, according to cybersecurity research firm Wiz.</p>



<p>“We discovered GhostApproval, a systematic vulnerability pattern affecting six of the top AI coding assistants: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf [<a href="https://www.infoworld.com/article/4023030/cognition-agrees-to-buy-whats-left-of-windsurf.html" target="_blank">now known as Devin Desktop</a>],” <a href="https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants" target="_blank" rel="noreferrer noopener">the Wiz report</a> said. “In each case, a malicious repository can trick the agent into accessing arbitrary files outside the workspace sandbox, potentially achieving remote code execution on the developer’s machine.”</p>



<p>The <a href="https://www.csoonline.com/article/4191923/sandbox-bypass-flaws-in-cursor-ide-highlight-prompt-injection-as-an-rce-vector.html" target="_blank">first report of the hole</a> came earlier this month from Cato Networks, but was limited to one platform, Cursor, whereas Wiz found that its impact was far wider. </p>



<p>The underlying security problem, <a href="https://cwe.mitre.org/data/definitions/61.html" target="_blank" rel="noreferrer noopener">symbolic links</a> (symlinks), is well known and has been leveraged for decades. But GhostApproval, Wiz noted, goes well beyond their historic use as an attack vector. </p>



<p>Symbolic links are special files that act as shortcuts to other files or directories. In attacks, they typically resolve to a target outside of the intended control sphere, which allows a threat actor to operate on unauthorized files in a less- or uncontrolled environment, outside of a secure sandbox, or even an air-gapped system.</p>



<p>“In several cases,” Wiz noted, “the agent’s internal reasoning explicitly recognizes the dangerous target, yet the confirmation prompt shown to the user conceals this information entirely. This is <a href="https://cwe.mitre.org/data/definitions/451.html" target="_blank" rel="noreferrer noopener">CWE-451</a> – UI misrepresentation of critical information – layered on top of the symlink vulnerability. The user approves what they believe is a harmless local edit. The agent then writes to a sensitive file outside of the project workspace.”</p>



<p>Wiz said it reported the issue to the six vendors initially impacted; AWS, Cursor and Google “fixed the issue promptly,” Augment and Windsurf/Devin “acknowledged receipt but went silent,” and Anthropic had already fixed the problem before it was contacted by Wiz.</p>



<h2 class="wp-block-heading">Potentially massive exposure</h2>



<p>But analysts and consultants said the AI dev tool problem that Wiz described illustrates a far greater security risk: enterprises are trusting these tools and the information they report far too much, which is what may give attackers a big opportunity.</p>



<p><a href="https://my.idc.com/getdoc.jsp?containerId=PRF005561" target="_blank" rel="noreferrer noopener">Katie Norton</a>, senior research manager for DevSecOps at IDC, noted that the Wiz report pointed out a disturbing fact. “The safety check people rely on to catch these actions doesn’t actually stop anything. That’s a real way for an attacker to break into a developer’s machine,” she said. “The scope is bounded by one condition: the attack requires a developer to clone and operate on an untrusted or malicious repository. That concentrates the risk in workflows touching external contributors, forked repositories, and third-party or open source dependencies, rather than in internally authored code.”</p>



<p>Norton said the exposure from this flaw, along with similar holes in other AI dev tools, is potentially massive. “Since March 2025, security vendors and researchers have disclosed comparable issues in nearly every major AI coding assistant. That pattern: a mitigation ships, then a new bypass of that same mitigation surfaces within months. That is worth watching and reflects how new this category’s threat model still is across the board, it’s not a gap specific to any one vendor’s practices.”</p>



<p>That means, she said, that agentic coding tools need multilayered defense, because the risk isn’t confined to the code an agent generates. “The tools themselves sit within the software supply chain and can be attacked directly. GhostApproval makes that point clearly,” she noted. </p>



<p>“The vulnerability has nothing to do with code quality or insecure output. It’s a flaw in how the agent handles files and represents its own actions to the user, introduced by the tool’s design rather than a bad prompt or a compromised dependency. Failure to account for the coding tools’ own attack surface is what leaves this kind of gap unaddressed.”</p>



<h2 class="wp-block-heading">Rethink policies and procedures</h2>



<p><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, agreed; enterprise CISOs need to potentially rethink many of their AI dev tool policies and procedures. </p>



<p>“The significant part is that the agent’s own reasoning identified the malicious target and the approval dialog hid it anyway. The tool knew it was writing to SSH keys and still asked a human to approve an edit to a config file, giving the human an illusion of control over the model,” Kenney said. “Many considered human in the loop to be the answer to agent risk, but this report shows that the loop can be fed bad information by the very agent it is supposed to be supervising.”</p>



<p>Because of this, Kenney advised adjusting the way tool management is enforced.</p>



<p>“Treat AI coding assistants as privileged software with filesystem access, not as editor plugins. That means patch discipline, version pinning, and knowing which tools in your environment write to disk before authorization,” Kenney said. “Then sandbox the blast radius. These agents should run against trusted repositories in isolated environments where a write to <em>authorized_keys</em> goes nowhere. Do not rely on the tool’s own dialog as your control or governance solution.”</p>



<h2 class="wp-block-heading">A category-wide design issue</h2>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, added that this security hole is a much bigger enterprise security strategy problem than most CISOs realize. </p>



<p>“Six different vendors independently arrived at a very similar trust model. That suggests we’re looking at a category-wide design challenge rather than a collection of isolated implementation bugs. If vulnerabilities like this remained uncorrected, they would represent a meaningful enterprise risk, particularly for organizations that allow AI coding assistants to interact with untrusted repositories or production development environments,” he said. </p>



<p>“The immediate concern isn’t simply remote code execution. It’s that these agents operate with a level of filesystem access, tool access, and developer trust that traditional IDE extensions never had. Once an AI agent becomes an active participant in software development, every trust boundary it crosses becomes part of the organization’s attack surface.”</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4195235/ai-coding-tool-hole-illustrates-a-big-problem-with-human-in-the-loop.html" target="_blank">CSOonline</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Wrote a New Book for Corelight]]></title>
<description><![CDATA[TLDR: I wrote a new book for Corelight called NDR Essentials. It's free at that link. This is the 10th book that I've authored or co-authored. The rest are all posted at taosecurity.com.  Why?It was time. 

 
That’s what I thought when I heard that Corelight wanted to 
update its 2021 book on net...]]></description>
<link>https://tsecurity.de/de/3657389/it-security-nachrichten/i-wrote-a-new-book-for-corelight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657389/it-security-nachrichten/i-wrote-a-new-book-for-corelight/</guid>
<pubDate>Thu, 09 Jul 2026 16:37:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLD7qvOGj-vysW1oKnpVauXypgCv8nGDkAJ3-ku3GFDTwH2ud2n6fOVAkjfyQlqkWtiuloQi86jC36SFQ6q8RtciyqVGS0J1eJkJNc2_3L1-uiETD82IB7P0py3Xf3ggvbiBGi8rtIVZttdqk8vz1svXuVyt1YYZXCG1sO5VtHwTDEJgkNjCj3/s864/cover.png" imageanchor="1"><img border="0" data-original-height="864" data-original-width="576" height="640" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLD7qvOGj-vysW1oKnpVauXypgCv8nGDkAJ3-ku3GFDTwH2ud2n6fOVAkjfyQlqkWtiuloQi86jC36SFQ6q8RtciyqVGS0J1eJkJNc2_3L1-uiETD82IB7P0py3Xf3ggvbiBGi8rtIVZttdqk8vz1svXuVyt1YYZXCG1sO5VtHwTDEJgkNjCj3/w426-h640/cover.png" width="426"></a></div><br><div>TLDR: I wrote a new book for Corelight called <a href="https://corelight.com/cp/ndr-essentials">NDR Essentials</a>. It's free at that link. This is the 10th book that I've authored or co-authored. The rest are all posted at <a href="https://www.taosecurity.com/">taosecurity.com</a>. </div><div> </div><div>Why?<span class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text"><p><span>It was time</span><span>.</span><span> </span></p></span></div><div><span class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text">

<p><span></span><span> </span></p>
<p><span>That’s what I thought when I heard that Corelight wanted to 
update its 2021 book on network detection and response (NDR). Tamara 
Crawford, who owned the project, scheduled a meeting with me and asked 
if I might be interested in helping, depending on who might write the 
text. </span><span> </span></p>
<p><span></span><span> </span></p>
<p><span>I volunteered immediately to write the whole book, but I had a 
few conditions. The text had to be at least 100 pages long, because 100 
pages is my personal dividing line between “book” and “white paper.” I 
needed the freedom to cover the topics I wanted to address, and to not 
be told what to write. I wanted to show the four network security 
monitoring (NSM) data types working in a vendor-neutral manner, with 
technical details. Finally, I knew this project would take several 
months to research, write, lay out, proofread, and complete. Once 
Corelight agreed, I was ready to begin.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><span>My goal for the book was to show how high-fidelity </span><a href="https://corelight.com/resources/glossary/network-evidence" target="_self"><u><span>network evidence</span></u></a><span>
 can power successful incident detection and response operations. For 
decades, digital security relied on the flawed premise that the “right” 
security controls could stop malicious activity. History, however, has 
repeatedly shown that prevention eventually fails. Victory belongs to 
the defender who accepts that intrusions are inevitable and who 
implements aggressive post-compromise interdiction </span><span>and containment. </span><span> </span></p>
<p><span></span><span> </span></p>
<p><span>Security teams have the best chance to stop an adversary before
 they accomplish their mission when they leverage network security 
monitoring data and the latest </span><a href="https://corelight.com/resources/glossary/ai-driven-soc" target="_self"><u><span>AI and automation assistants</span></u></a><span>. Therefore, this book equips practitioners with the tools and mindsets necessary to hunt through network evidence and diminish </span><a href="https://corelight.com/resources/glossary/attacker-dwell-time" target="_self"><u><span>attacker dwell time</span></u></a><span>. </span><span> </span></p>
<p><span></span><span> </span></p>
<p><strong><span>The book begins </span></strong><span>with a chapter 
that defines risk, threat, vulnerability, and asset value in the context
 of cybersecurity. It explains seven risk management strategies, NDR’s 
role in the security cycle, four sources of situational awareness, the 
importance of time and how to measure it, and a variety of NDR-specific 
topics like where and how to monitor, costs vs. benefits, and the 
difference between </span><a href="https://corelight.com/resources/glossary/network-security-monitoring-nsm" target="_self"><u><span>NSM</span></u></a><span> and </span><a href="https://corelight.com/resources/glossary/ndr-network-detection-and-response" target="_self"><u><span>NDR</span></u></a><span>.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><strong><span>Chapter 2</span></strong><span> is all about the four 
types of NSM data. I show examples of full content data via terminal and
 graphical interfaces, and what it can do for analysts. I briefly 
demonstrate how to obtain and analyze extracted content, then show how 
transaction data can answer many of the key questions asked by security 
analysts. The chapter concludes with alert data, which has become more 
significant in an age of smarter and more precise AI capabilities.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><strong><span>Chapter 3 </span></strong><span>is the first of two 
chapters demonstrating workflows for security investigators. This 
chapter examines how alert data from a sufficiently capable NDR can 
identify suspicious and malicious activity. It includes four cases, 
showing how lateral movement, expired SSL certificates, outbound 
reconnaissance, and malicious remote desktop protocol behavior manifest 
in alerts.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><strong><span>Chapter 4</span></strong><span> presents the other side of investigative workflows, relying on </span><a href="https://corelight.com/resources/glossary/threat-hunting" target="_self"><u><span>threat hunting</span></u></a><span>
 to reveal adversary activity. Properly collected, rendered, and 
displayed NSM data is crucial, because you can’t really hunt without 
high-quality evidence. The chapter includes six cases, showing how file 
name mismatches, unusual downloads, large data transfers, coordinated 
exfiltration, lateral movement, and certificates appear when exposed via
 threat hunting.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><strong><span>Chapter 5 </span></strong><span>explores how artificial
 intelligence and automation technologies are bringing powerful new 
capabilities to security teams. I start by discussing the generation of 
alerts at the edge and at the center, then I share how AI can help with 
investigating suspicious and </span><span>malicious activity. I conclude
 with advice on the best use of agentic triage and how AI will integrate
 with tools while enabling new capabilities.</span><span> </span></p>
<p><span></span><span> </span></p>
<p><span>If you’re a security leader, such as a CISO or director, you’ll
 probably be most interested in Chapters 1 and 5. You should ensure your
 teams have the data described in Chapters 2-4. If you’re a security 
analyst, you’ll probably be most interested in Chapters 2-4, although 
you should be familiar with the concepts and strategies in Chapters 1 
and 5. If you’re familiar with my previous works, you will be happy to 
see that this book has a certain amount of “future-proofing” embedded. I
 did not explain how to install any specific tools, nor did the tools I 
use rely on strict display technologies. All of the examples in Chapter 2
 use open source tools with stable outputs, such as Tshark, Wireshark</span><span><sup><span>®</span></sup></span><span>, Zeek</span><span><sup><span>®</span></sup></span><span>, and Suricata</span><span><sup><span>®</span></sup></span><span>. </span><span> </span></p>
<p><span></span><span> </span></p>
<p><span>I hope readers find the book relevant to their security work 
and a decent introduction to adding NSM data from capable NDRs to their 
investigations. This book is only the beginning of what can be done once
 teams have access to high-fidelity network evidence. If you’d like to 
know more about the book, Vince Stoffer interviewed me for the </span><a href="https://corelight.com/podcasts" target="_self"><u><span>Corelight podcast</span></u></a><span>,
 and that episode will be available on YouTube, Spotify, and Apple 
Podcasts. As I say at the end of every episode, “we will see you on the 
network.” Read </span><a href="https://corelight.com/cp/ndr-essentials" target="_self"><em><u><span>NDR Essentials</span></u></em></a><span> to learn how high-fidelity network evidence can strengthen your security program!</span></p></span></div><div><br></div><div class="blogger-post-footer">Copyright 2003-2020 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI Model Matters — But the Harness Matters More | BHIS In Focus]]></title>
<description><![CDATA[Author: Black Hills Information Security - Bewertung: 0x - Views:4 Is the most powerful AI model always the best choice for cybersecurity work?

In this BHIS In Focus short, we look at the difference between high-end closed models and cheaper open-weight models — and why the real advantage may co...]]></description>
<link>https://tsecurity.de/de/3657348/it-security-video/the-ai-model-matters-but-the-harness-matters-more-bhis-in-focus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657348/it-security-video/the-ai-model-matters-but-the-harness-matters-more-bhis-in-focus/</guid>
<pubDate>Thu, 09 Jul 2026 16:18:32 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hills Information Security - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/TkpTRvQ5Wh8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Is the most powerful AI model always the best choice for cybersecurity work?<br />
<br />
In this BHIS In Focus short, we look at the difference between high-end closed models and cheaper open-weight models — and why the real advantage may come from the harness, workflow, and tooling around the model, not just the model itself.<br />
<br />
The takeaway: capability matters, but cost, access, and practical implementation may matter just as much.<br />
<br />
#BHISInFocus #AISecurity #Cybersecurity #OpenWeightAI #InfoSec #AIModels<br />
<br />
/// 🔗 Register for webcasts, summits, and workshops - <br />
https://poweredbybhis.com <br />
 <br />
///Black Hills Infosec Socials<br />
Twitter: https://twitter.com/BHinfoSecurity<br />
Mastodon: https://infosec.exchange/@blackhillsinfosec<br />
LinkedIn: https://www.linkedin.com/company/antisyphon-training<br />
Discord: https://discord.gg/ffzdt3WUDe<br />
<br />
///Black Hills Infosec Shirts & Hoodies<br />
https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections<br />
<br />
///Black Hills Infosec Services<br />
Active SOC: https://www.blackhillsinfosec.com/services/active-soc/<br />
Penetration Testing: https://www.blackhillsinfosec.com/services/<br />
Incident Response: https://www.blackhillsinfosec.com/services/incident-response/<br />
<br />
///Backdoors & Breaches - Incident Response Card Game<br />
Backdoors & Breaches: https://www.backdoorsandbreaches.com/<br />
Play B&B Online: https://play.backdoorsandbreaches.com/<br />
<br />
///Antisyphon Training<br />
Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/<br />
Live Training: https://www.antisyphontraining.com/course-catalog/<br />
On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/<br />
Antisyphon Discord: https://discord.gg/antisyphon<br />
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training<br />
<br />
///Educational Infosec Content<br />
Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/<br />
Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest<br />
Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining<br />
Active Countermeasures YouTube: https://youtube.com/activecountermeasures<br />
Threat Hunter Community Discord: https://discord.gg/threathunter<br />
<br />
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Running OpenClaw with Ollama]]></title>
<description><![CDATA[This article covers the full path from zero to a running private research assistant on Telegram, including configuring the context length correctly, connecting the channel, enabling web search, and deploying it headlessly in Docker.]]></description>
<link>https://tsecurity.de/de/3657295/ai-nachrichten/running-openclaw-with-ollama/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657295/ai-nachrichten/running-openclaw-with-ollama/</guid>
<pubDate>Thu, 09 Jul 2026 16:03:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This article covers the full path from zero to a running private research assistant on Telegram, including configuring the context length correctly, connecting the channel, enabling web search, and deploying it headlessly in Docker.]]></content:encoded>
</item>
<item>
<title><![CDATA[I Tried Windscribe's OpenClaw Integration. It’s a (Small) Step in the Right Direction]]></title>
<description><![CDATA[There’s still a long way to go before it’s a useful feature for most VPN users.]]></description>
<link>https://tsecurity.de/de/3657065/it-nachrichten/i-tried-windscribes-openclaw-integration-its-a-small-step-in-the-right-direction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657065/it-nachrichten/i-tried-windscribes-openclaw-integration-its-a-small-step-in-the-right-direction/</guid>
<pubDate>Thu, 09 Jul 2026 14:48:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[There’s still a long way to go before it’s a useful feature for most VPN users.]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone 18 Pro Max Could Be Thicker and Heavier Due to Bigger Battery]]></title>
<description><![CDATA[Apple’s upcoming iPhone 18 Pro Max could arrive with a thicker and heavier design, as new rumors point to a bigger battery inside the next flagship model. The change suggests Apple plans to improve battery life, but users may feel the difference in hand.



Chinese leaker Ice Universe claimed tha...]]></description>
<link>https://tsecurity.de/de/3656791/ios-mac-os/iphone-18-pro-max-could-be-thicker-and-heavier-due-to-bigger-battery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656791/ios-mac-os/iphone-18-pro-max-could-be-thicker-and-heavier-due-to-bigger-battery/</guid>
<pubDate>Thu, 09 Jul 2026 13:09:33 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple’s upcoming iPhone 18 Pro Max could arrive with a thicker and heavier design, as new rumors point to a bigger battery inside the next flagship model. The change suggests Apple plans to improve battery life, but users may feel the difference in hand.



Chinese leaker Ice Universe claimed that the iPhone 18 Pro Max will measure around 9mm thick and weigh about 240 grams. That would make it around 0.25mm thicker and roughly 7 grams heavier than the current iPhone 17 Pro Max.



Bigger Battery Could Be the Main Reason



The rumored size change appears linked to the larger battery expected inside the iPhone 18 Pro Max. Recent filings suggest the phone could feature a 5,391mAh battery in China and a 5,567mAh battery in the U.S., giving it a notable increase over the iPhone 17 Pro Max.



Apple is also expected to use a new stainless steel vapor chamber for better heat control, and that internal change could add extra weight along with the larger battery.



The iPhone 18 Pro Max could become one of Apple’s heaviest iPhones if these details turn out to be accurate.



Expected changes include:




Around 9mm thickness



About 240 grams in weight



Larger battery capacity



Better thermal management



Slightly bulkier in-hand feel




Apple is expected to launch the iPhone 18 Pro and iPhone 18 Pro Max this September, along with its first foldable iPhone.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI won’t transform your business if you’re still running it the same way]]></title>
<description><![CDATA[Many organizations have seen real gains in productivity and automation from experimenting with AI. But only 34% are using AI to deeply transform their businesses, according to Deloitte’s 2026 State of Generative AI in the Enterprise report. Meanwhile, 37% are using the technology at a surface lev...]]></description>
<link>https://tsecurity.de/de/3656605/it-security-nachrichten/ai-wont-transform-your-business-if-youre-still-running-it-the-same-way/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656605/it-security-nachrichten/ai-wont-transform-your-business-if-youre-still-running-it-the-same-way/</guid>
<pubDate>Thu, 09 Jul 2026 12:05:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Many organizations have seen real gains in productivity and automation from experimenting with AI. But only 34% are using AI to deeply transform their businesses, according to Deloitte’s <a href="https://www.deloitte.com/content/dam/assets-zone3/us/en/docs/services/consulting/2026/state-of-ai-2026.pdf" rel="nofollow">2026 State of Generative AI in the Enterprise</a> report. Meanwhile, 37% are using the technology at a surface level with little or no change to underlying business processes.</p>



<p>That may explain why so many organizations are still waiting for the transformative ROIs they expected.</p>



<p>We’ve seen this before. During the process reengineering movement of the late 1980s and early 1990s, and again during the <a href="https://www.cio.com/article/4148783/are-we-living-in-an-ai-bubble-applying-lessons-from-the-dot-com-era.html">dot-com era</a>, organizations invested heavily in new technologies and new ways of working. Many failed, not because the technology was flawed, but because they were unwilling to rethink how the business itself operated.</p>



<p>A textile manufacturer learned that lesson the hard way more than 30 years ago. The company implemented software designed to support a fundamentally different way of doing business but insisted on preserving decades-old workflows and management practices. The technology was expected to conform to the business, rather than the business adapting to the technology. The implementation failed.</p>



<p>Many companies are at risk of making the same mistake with AI because they rely on a bottom-up approach, where employees find ways to use the technology to solve the problem of the day: writing emails, summarizing meetings and accelerating familiar workflows.</p>



<p>Top-down transformation starts with a harder question: if AI had existed when we built this company, would we have designed the business this way? The organizations seeing transformative returns are the ones rethinking how their business operates from the ground up, not just streamlining existing workflows.</p>



<h2 class="wp-block-heading">Four reasons AI transformation stalls</h2>



<p>Organizations often assume that providing access to AI tools will naturally lead to transformation. The reality is that people, incentives and mindset are what determine success.</p>



<h3 class="wp-block-heading">1. Organizations reward the wrong behaviors</h3>



<p>One of the fastest ways to derail transformation is to reward people for preserving the status quo.</p>



<p>The textile manufacturer encountered this problem when it redesigned its manufacturing ordering system. Leadership wanted greater visibility across the production process and a more responsive, just-in-time operating model. But shift managers were still compensated based on how many pounds moved through their individual work centers each day. Their incentives rewarded maximizing output within their own area instead of supporting the broader changes leadership wanted to implement.</p>



<p>The lesson applies directly to AI transformation. Organizations often talk about reinventing workflows while continuing to evaluate employees using metrics designed for a pre-AI world.</p>



<p>People optimize for how they’re measured. If compensation, accountability and recognition remain tied to legacy processes, employees will naturally protect those processes. Transformation requires aligning incentives with the future state of the business.</p>



<h3 class="wp-block-heading">2. Communication breaks down in the middle</h3>



<p>Executives may have a clear vision for transformation, but that vision often weakens as it moves through the organization.</p>



<p>At the textile manufacturer, senior leadership understood the goal of becoming a just-in-time manufacturer. The technology team understood it because they were involved in the implementation. Middle management, however, never fully embraced the vision.</p>



<p>The result was that executives talked about doing things differently while managers continued reinforcing existing behaviors and employees received conflicting signals about what success looked like.</p>



<p>Many AI initiatives today face the same challenge. Leaders announce ambitious transformation goals, but managers continue operating under assumptions built around the previous way of working.</p>



<p>AI transformation requires both top-down direction and bottom-up execution. The middle layers of the organization serve as the connective tissue between the two. Without that connection, transformation efforts quickly become technology projects rather than business initiatives.</p>



<h3 class="wp-block-heading">3. Training focuses on tools instead of transformation</h3>



<p>Many organizations approach AI training primarily as a technology exercise. Employees gain access to a new tool, and training focuses on how to write prompts, use copilots or navigate the new application. Those skills are important, but they are only part of the equation.</p>



<p>At the textile manufacturer, technology teams needed a deeper understanding of how the production floor actually operated. At the same time, business leaders needed a better understanding of what the technology could enable. Neither side could successfully redesign the process on its own.</p>



<p>A similar dynamic exists with AI. Technology teams need business context, and business teams need technology context. Organizations that can bring those perspectives together through cross-functional teams focused on solving business problems rather than technology implementation are the ones making the most progress.</p>



<h3 class="wp-block-heading">4. People need permission to work differently</h3>



<p>One of the least discussed barriers to AI adoption is psychological. Many people still associate their value with effort; they take pride in the time, expertise and work required to complete a task. When AI reduces that effort, some employees become uncomfortable acknowledging its role.</p>



<p>For some, admitting AI helped feels like diminishing their contribution, which is why leadership visibility matters. Employees need to see leaders openly using AI, sharing examples and discussing how it is helping them work differently. They need to hear that the goal is not simply working faster but applying judgment, creativity and expertise in higher-value ways.</p>



<p>AI transformation is ultimately a mindset shift. People need permission to redefine what productive work looks like.</p>



<h2 class="wp-block-heading">Transformation requires more than upskilling</h2>



<p>Much of the conversation around AI focuses on upskilling. While new skills are important, they are not the primary obstacle to transformation. The bigger challenge is creating a workforce that wants to participate in it.</p>



<p>Some employees will embrace experimentation, seek new opportunities and help shape the future of the business. Others will continue looking for ways to preserve the processes that made them successful in the past. Leaders need to recognize the difference and create opportunities for the right people to rise to the occasion. Employees with a fixed mindset will resist change regardless of the tools available. </p>



<p>The organizations that succeed will communicate not just what they’re trying to accomplish, but why. Many employees assume AI initiatives are purely about efficiency. The message from leadership needs to be different: we are rebuilding how this business operates, and you are part of that.</p>



<p>Increasingly, everyone has access to the same AI tools. Two organizations can deploy the same technology and achieve dramatically different outcomes depending on how they align incentives, communicate expectations and rethink long-standing business processes.</p>



<p>Companies that treat AI as a way to make existing work more efficient will continue to see incremental gains, while those willing to question whether that work should be done the same way at all will discover entirely new ways to operate.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three keys to deploying AI agents]]></title>
<description><![CDATA[Building an agent in an afternoon is now within reach of almost anyone in the enterprise with a credit card. The tools are accessible, the deployments are easy. The hard part is delivering the intended results.



Gartner predicts that more than 40% of agentic AI projects will be canceled by 2027...]]></description>
<link>https://tsecurity.de/de/3656433/ai-nachrichten/three-keys-to-deploying-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656433/ai-nachrichten/three-keys-to-deploying-ai-agents/</guid>
<pubDate>Thu, 09 Jul 2026 11:03:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Building an agent in an afternoon is now within reach of almost anyone in the enterprise with a credit card. The tools are accessible, the deployments are easy. The hard part is delivering the intended results.</p>



<p>Gartner predicts that more than <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">40% of agentic AI projects will be canceled</a> by 2027, and the <a href="https://artificialintelligenceact.eu/article/14/">EU AI Act Article 14</a> requirements for human oversight for high-risk AI systems take effect on August 2, 2026. The deciding factor for whether agentic AI reaches production isn’t the model, the framework, or the use case. It’s the infrastructure beneath the agent: the part the people building agents have never had to think about.</p>



<p>Organizations are racing to deploy agentic AI to stay competitive, which means pressure-testing is often overlooked. Every agent project should be scrutinized by three executives asking three different sets of questions. The CISO asks whether we are exposed. The CFO asks whether we are overspending. The chief AI officer asks whether we are getting value. </p>



<p>As a product leader focused on AI governance, I see this pattern across customer environments. Three architecture layers answer those three questions: identity, observability, and cost optimization. I’ll walk through each of the layers and provide a four-question diagnostic for the next production push.</p>



<h2 class="wp-block-heading">Why AI pilots stall</h2>



<p>An agent is not a faster chatbot. It chains dozens of steps, calls external tools, retains state across sessions, and triggers real-world actions. Most inherit the credentials of whoever deployed them. They operate at machine speed without context for the consequences of each step.</p>



<p>The mismatch is not a competence gap on the human side. It is a time-horizon gap. An engineer reasons about a database change over hours. An agent triggers a hundred of them before anyone reviews the first. Traditional audit logging captures request and response. That does not catch this pattern.</p>



<p>When something breaks, the cost is rarely the incident. It is the months of stalled deployment that follow. The risk committee freezes pilots. The productivity gains the program was supposed to deliver never materialize. Finance still gets the API bill. Three architecture layers decide whether a deployment survives that pattern. Each one is the answer to a question the people building agents never had to ask.</p>



<h2 class="wp-block-heading">Layer 1: Identity for non-human actors</h2>



<p>Start with identity. The default failure looks routine: a product manager with broad API access spawns an agent that inherits the full scope of those credentials and runs at machine speed across systems no one inventoried.</p>



<p>The scale is bigger than most teams realize. <a href="https://www.signisys.com/blog/non-human-identities-outnumber-users-100-to-1-the-cloud-security-crisis-no-one-is-talking-about/">Industry IAM research</a> puts non-human identities at more than 100 to 1 versus human accounts, with <a href="https://www.cybersecuritytribe.com/news/research-reveals-44-growth-in-nhis-from-2024-to-2025">some 2026 surveys</a> putting the ratio as high as 144 to 1. A <a href="https://www.orchid.security/reports/the-identity-gap-2026-snapshot-identity-insight-straight-from-the-source">May 2026 Identity Gap Report</a> found two-thirds are unseen and unmanaged.</p>



<p>Agents are moving from human identities with their “owners”’ permissions to first-class principals. They are purpose-bound, cryptographically attested, and scoped to one task at a time. Google’s Agent Identity, built on SPIFFE, is one early example. The production pattern has three properties. Credentials are issued per agent task. Token lifetime is measured in minutes to hours, not weeks. Scope is narrowed to the specific tools and data classes the task requires, and the credential revokes automatically on task completion.</p>



<p>If a single static credential is good for a week and 50 different tasks, you are not running agentic AI. You are running a service account with extra steps.</p>



<h2 class="wp-block-heading">Layer 2: Observability that serves all three executives</h2>



<p>Identity controls what an agent can do. Observability shows what it’s actually doing. One instrumentation layer, three views.</p>



<p>First, the security view. Traditional logging captures request and response, which assumes one human action per logged event. An agent’s unit of work is a chain. Pick a tool, call it, read the result, decide the next step. Twenty steps, some of them writing to production. Instrument every step as a durable audit object, independently queryable. Understand which tool was invoked, what data was accessed, what policy applied, and what the agent reasoned to justify the next step. That’s what Article 14 oversight requires for production.</p>



<p>Second, the business-outcomes view. Audit objects answer the CISO. The chief AI officer asks a different question. Is the agent accomplishing what we deployed it for, or burning compute on a tangent? An agent can run 200 tool calls, generate clean audit logs, and produce nothing. It might be looping on a sub-goal that drifted three steps back. Observe each step against the declared business purpose: on-task ratio, sub-goal coherence, progress markers. Project management telemetry for a non-human worker.</p>



<p>Third, the cost view. The same per-step instrumentation produces cost telemetry: token count per step, model per call, context size per turn, downstream tool-call costs. Without that attribution, the next section’s optimizations are blind.</p>



<p>A busy agent and a productive agent look identical in the security log. They look identical on the bill too. The difference shows up only when all three views run from the same instrumentation.</p>



<h2 class="wp-block-heading">Layer 3: Cost optimization</h2>



<p>Cost is where the architecture pays back. Gartner’s March 2026 analysis put <a href="https://www.gartner.com/en/newsroom/press-releases/2026-03-25-gartner-predicts-that-by-2030-performing-inference-on-an-llm-with-1-trillion-parameters-will-cost-genai-providers-over-90-percent-less-than-in-2025">agentic workloads at five to 30 times the token cost per task</a> of a standard chatbot. The FinOps Foundation’s 2026 State of FinOps report found that <a href="https://data.finops.org/">73% of organizations exceeded their original AI budget projections</a>. Three failure modes drive that overrun.</p>



<p>First, using the wrong model. Agents default to the most capable one available. They call a frontier model for tasks a smaller one could handle with identical quality: summarizing a transcript, formatting JSON, classifying a ticket. The <a href="https://proceedings.iclr.cc/paper_files/paper/2025/hash/5503a7c69d48a2f86fc00b3dc09de686-Abstract-Conference.html">RouteLLM paper at ICLR 2025</a> demonstrated that intelligent routing cuts total LLM inference cost 40% to 80% with no measurable quality loss on routine work. Move model selection from a per-developer choice to a per-policy layer.</p>



<p>Second, running in loops. Agents can spend without limit if no one is watching. A widely-cited 2026 incident saw a <a href="https://dev.to/dingdawg/how-an-ai-agent-ran-up-a-47000-bill-in-11-days-and-how-to-stop-it-1fk">LangChain multi-agent system run an infinite loop for 11 days and burn $47,000 in API charges</a>. Per-session token ceilings, <a href="https://fountaincity.tech/resources/blog/ai-agent-cost-circuit-breaker/">loop-detection circuit breakers</a> that flag tool calls highly similar to prior calls, and hard daily caps stop this before it generates the bill. In our deployments, a <a href="https://www.supra-wall.com/en/learn/ai-agent-runaway-costs">three-tier cost structure</a> catches the bulk of runaway patterns: a $50 daily soft alert, a $100 daily hard cutoff forcing routing to cheaper models, and a $1,000 monthly ceiling requiring manager approval.</p>



<p>Third, re-paying for the same context on every step. Every step re-sends the accumulated system prompt and conversation history. By step 20 the agent has paid for that context 20 times. <a href="https://www.vantage.sh/blog/agentic-coding-costs">Vantage’s 2026 analysis of agentic coding sessions</a> found re-sent context accounts for roughly 62% of the average agent’s bill, the biggest single optimization target in agentic workloads. Three patterns help: anchored summarization at phase boundaries, sliding context windows, and provider-native prompt caching at the gateway. Most agents skip caching entirely, though <a href="https://platform.claude.com/docs/en/build-with-claude/prompt-caching">Anthropic</a> prices cached input at roughly 10% of base, <a href="https://developers.googleblog.com/en/gemini-2-5-models-now-support-implicit-caching/">Gemini</a> at 10% to 25%, and <a href="https://openai.com/index/api-prompt-caching/">OpenAI</a> at 50%.</p>



<p>Governing agent cost means seeing every call, every model, every token attributed to the agent and the business purpose. Then act on it. Token counts without business attribution tell you how many gallons of gas you burned, not where you drove.</p>



<h2 class="wp-block-heading">The deployment velocity payoff</h2>



<p>The three layers serve the three executive questions. Identity gates what the agent can do. Observability shows what it is doing. Cost optimization controls what it spends.</p>



<p>The honest counterargument is that governance always slows deployment. That is true when governance is bolted on as approval gates layered over an agent that wasn’t built with observability or per-task identity. It is false when governance is built into the architecture from day one. Teams that experience governance as a brake installed the brake without the steering wheel.</p>



<p>Governance built right still costs something. Per-task credentials add work on every tool call. Observability infrastructure adds compute. The question is whether that cost beats the alternative.</p>



<p>The layers compound. Identity without observability is theoretical. Observability without cost control is descriptive. Without identity at the bottom, cost control becomes caps without context, forever reactive. All three together produce a governance review that runs in weeks, not quarters, because the data each executive needs already exists. In our experience, organizations with that infrastructure can deploy six workflows to production in the time competitors complete one governance review. The real ROI of agentic AI is not how much faster a single workflow runs. In practice, it’s how many workflows your team can defensibly put into production in a year.</p>



<h2 class="wp-block-heading">Before the next pilot</h2>



<p>Here are four questions to run against any agent your team is about to push to production:</p>



<ol class="wp-block-list">
<li>Identity. For each agent in production, can you point to the per-task credentials it uses today, and the maximum scope of any single token?</li>



<li>Observability. For any agent session, can you produce three views from the same instrumentation: the audit object per step, the on-task ratio versus tangents, and the per-step cost broken down by model and context size?</li>



<li>Cost optimization. Does your platform automatically route by model, cap runaway loops, and avoid re-sending the same context every step?</li>



<li>Velocity. How long does it take a new agent workflow to move from approved pilot to production in your environment today?</li>
</ol>



<p>If the answer is months, the architecture above is the gap. Gartner’s 40% stat is about your next pilot.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Revving up Microsoft’s 10x faster TypeScript 7]]></title>
<description><![CDATA[It has been a year or so since Microsoft announced its plans to move TypeScript to a new, native runtime based on the Go language. Those first releases were unfinished (you had to compile them yourself) but showed promise, getting close to the expected 10x speed-up. That year has been one of stea...]]></description>
<link>https://tsecurity.de/de/3656432/ai-nachrichten/revving-up-microsofts-10x-faster-typescript-7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656432/ai-nachrichten/revving-up-microsofts-10x-faster-typescript-7/</guid>
<pubDate>Thu, 09 Jul 2026 11:03:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/3849654/typescript-gets-go-faster-stripes.html">It has been a year or so</a> since Microsoft announced its plans to move <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a> to a new, native runtime based on the <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html" data-type="link" data-id="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go language</a>. Those first releases were unfinished (you had to compile them yourself) but showed promise, getting close to the expected 10x speed-up. That year has been one of steady progress, with <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/">Microsoft recently announcing the delivery of a release candidate build</a>.</p>



<p>This release candidate is ready for use. It installs from npm like previous versions, and like earlier builds it works in much the same way as previous versions of TypeScript, checking types in your code, compiling it to run on ECMAScript-compliant JavaScript engines, and running just about anywhere. In addition, a native preview of the TypeScript language server for <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> is available to help you write new TypeScript code and guide you through updating existing applications to the new language features.</p>



<p>All you need to do is enable the <a href="https://marketplace.visualstudio.com/items?itemName=TypeScriptTeam.native-preview" data-type="link" data-id="https://marketplace.visualstudio.com/items?itemName=TypeScriptTeam.native-preview">TypeScript 7 extension</a> through the Visual Studio command palette and start coding. There’s a lot of work going on to get the new tooling ready for the final release of TypeScript 7, and new versions of the language server are being released almost daily. It’s certainly popular, too, with nearly half a million downloads at the time of writing.</p>



<h2 class="wp-block-heading">What makes TypeScript 7 so much faster?</h2>



<p>So how is this new TypeScript so much faster? Key to the improvements is a shift to a new native compiler built in Go. This has allowed the team to change how it operates, adding parallelization where possible. In some cases, this isn’t easy, such as when type checking large codebases split across many files.</p>



<p>Here TypeScript spawns a small number of checker workers that run across your codebase. They work independently, so can duplicate the work — though the output will be the same. You can choose your own number of checkers, but the more you use, the more memory and CPU will be required.</p>



<p>Large monorepos with many projects require a similar approach with independent builder workers. You’ll need to balance this with the number of checkers in use, as this can cause significant resource issues.</p>



<p>There are some significant language and configuration changes from TypeScript 5 (TypeScript 6 has the same changes, which makes it a useful tool for experimenting with migrations). It’s well worth reading the release candidate documentation to understand how these will affect your code, as well as using the TypeScript 7 extension for Visual Studio Code to identify where you need to make changes.</p>



<h2 class="wp-block-heading">Working with users to build language tools</h2>



<p>One important aspect to the development of TypeScript 7 has been collaboration with existing users of the language and its tooling, as well as using the existing suite of TypeScript test tools that have been used to evaluate other versions. As this update is primarily a port of existing code, rather than a bottom-up rewrite, the underlying language semantics and structure are the same as those used in the original JavaScript codebase, ensuring that code will quickly port from old to new versions.</p>



<p>A major internal collaborator was the Visual Studio Code team, who have been using TypeScript to develop the familiar cross-platform development tool. It’s an important partnership between tool and language, as VS Code is a key TypeScript development tool, hosting TypeScript’s language server and using its compiler to provide debugging and code completion features.</p>



<p>The <a href="https://code.visualstudio.com/blogs/2026/06/26/iterating-faster-with-ts-7" data-type="link" data-id="https://code.visualstudio.com/blogs/2026/06/26/iterating-faster-with-ts-7">VS Code team published a long blog post</a> detailing how it has been working with the Go-based TypeScript. The team is both helping to develop the language and beginning the process of moving its codebase to the newer, faster, native platform.</p>



<p>How the VS Code team migrated is a useful case study, one that can help you move your TypeScript development more efficiently and with minimal risk. The team began working with extensions, using daily builds of TypeScript to ensure that bugs and issues could be reported as they occurred and would only have a limited impact as fixes could be rolled out quickly. At the same time, the VS Code team began using a preview version of the TypeScript 7 extension for VS Code, which was being built around the new compiler in parallel with its development.</p>



<h2 class="wp-block-heading">Bridging development with TypeScript 6</h2>



<p>The development of <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/" data-type="link" data-id="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/">TypeScript 6 as a bridge between TypeScript 5 and TypeScript 7</a> allowed the VS Code team to transition to code that targeted a newer version of ECMAScript and provided more powerful checks. By moving code from TypeScript 5 to TypeScript 6, developers could validate it with what would become TypeScript 7 language features and get speed and performance boosts while doing so (though nowhere near what TypeScript 7 promised). By completing this first migration of the VS Code codebase, it was possible for developers to be confident that they were ready to shift to the Go-based version when it shipped.</p>



<p>The parallel development of the new language server and extension ensured that by late 2025 it was possible for VS Code development to shift to TypeScript 7, with TypeScript 6 used as a fallback if there were any issues. Those cases could then be reported back to the TypeScript team and used to prioritize development.</p>



<p>As the platform evolved, the use cases for the VS Code team changed. By early 2026 TypeScript 7 was stable and nearly feature-complete, so the team began to use it to build all of their own built-in extensions. This allowed them to rethink their toolchain, changing the bundler from webpack to the one built into esbuild, giving them another speed up. Once that process was tested and working, they could switch all development to TypeScript 7.</p>



<p>Having such a big project take on TypeScript 7 early reaped big rewards, as the resulting virtuous cycle allowed both VS Code and TypeScript to move forward together, fixing issues as they arose and providing valuable feedback. The results speak for themselves. Type checking the entire VS Code codebase is now 7x faster, with most extensions checked in under a second. The only exception was <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" data-type="link" data-id="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>, which is almost as big as the editor itself, which type checked in 2.5 seconds.</p>



<p>Compilation has been sped up, dropping from 80 seconds to around 20 seconds. This may not seem a lot, but when you’re compiling and rebuilding and debugging, each change in your code now takes a lot less time. That improves developer productivity and ensures they stay in flow, rather than switching away to check email or Teams each time they start a new build. The same goes for using the language server, where loading the entire project (necessary for error detection and refactoring) now takes 10 seconds rather than a minute.</p>



<p>Lots of little time savings like this add up across a big project and a large team, helping developers stay focused and able to solve problems more effectively. The VS Code blog post notes that it cuts down on coffee runs, which take longer than the load or build that inspire a quick cuppa!</p>



<h2 class="wp-block-heading">Getting ready for TypeScript 7 in your build pipeline</h2>



<p>Microsoft is quick to point out that, while the TypeScript 7.0 release will be production ready, TypeScript 7 won’t have a full programmatic API until the release of TypeScript 7.1. As this won’t be for some time, Microsoft is providing <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/#running-side-by-side-with-typescript-6.0" data-type="link" data-id="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/#running-side-by-side-with-typescript-6.0">a way to run TypeScript 7 side-by-side with TypeScript 6</a>.</p>



<p>Installing the <code>@typescript/typescript6</code> compatibility package alongside TypeScript 7 adds a new executable, <code>tsc6</code>, that allows you to modify code that uses the TypeScript 5 API to run using TypeScript 6, by renaming the calls to <code>tsc</code> in your scripts to <code>tsc6</code>. This should allow you to keep building to the latest releases at the same time as starting to experiment with using the new runtime.</p>



<p>It’s not a perfect fix. You do need to do some work to implement npm aliases that allow linters and other low-level tools to work with both versions. You can also provide two different dependencies in your package.json to allow TypeScript 6 (<code>tsc6</code>) and TypeScript 7 (<code>tsc</code>) to run side-by-side. The result is a way to help migrate TypeScript code to the newer platform, delivering more efficient code that runs on a more modern ECMAScript in the meantime.</p>



<p>TypeScript 7 will be a big upgrade, though it has taken surprisingly little time to deliver. With users like the Visual Studio Code team already building on the new release, it’s clear that beginning your own migration should be easier than you might have thought.</p>



<p>The final release is due sometime in July 2026. If you haven’t started looking at TypeScript 7, now is the time to start.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 659]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</guid>
<pubDate>Thu, 09 Jul 2026 07:08:34 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/07/maintainer-spotlight-gen-li-rami3l/">Maintainer spotlight: Gen Li (@rami3l)</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/06/unite-for-clippy/">Together for a healthier Clippy</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-75">The Embedded Rustacean Issue #75</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://www.copper-robotics.com/whats-new/copper-rs-v100">copper-rs v1.0.0</a>: the open source deterministic robotics OS is now stable.</li>
<li><a href="https://rayfish.xyz/blog/01-introducing-rayfish">Rayfish: Your own private network. No servers, no setup.</a></li>
<li><a href="https://plabayo.tech/blog/rama-0-3">rama v0.3.0 — network service framework ready to be used by the wider Rust community</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.9.0">kache 0.9.0: supply-chain hardening + read-only CI cache</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/07/04/meet-guardiandbs-new-postgresql-compatibility-layer/">GuardianDB - PostgreSQL and P2P/Local-First Together</a></li>
<li><a href="https://buildnectar.com/">Nectar: a Rust-like language that compiles your whole web app to WebAssembly</a></li>
<li><a href="https://thekeeper.io/blog/logdrain-log-template-mining-in-rust/">logdrain: Fast, Embeddable Log-Template Mining in Rust</a></li>
<li><a href="https://medium.com/@vbasky/packaging-the-worlds-video-in-pure-rust-ff1f6b884fec">sheathe: Packaging the World's Video in Pure Rust</a></li>
<li><a href="https://docs.wickra.org/Quickstart-Rust">wickra: streaming-first technical indicators</a></li>
<li><a href="https://github.com/TeamXcelerator/xcelerator-solver/releases/tag/v0.1.0">Xcelerator Solver v0.1.0 -- deterministic symbolic regression</a></li>
<li><a href="https://github.com/tkmsikd/dlt-tui/releases/tag/v1.1.0">dlt-tui 1.1.0 - a fast TUI viewer for automotive DLT (AUTOSAR Diagnostic Log and Trace) files</a></li>
<li><a href="https://github.com/shihuili1218/rssh/releases/tag/v0.2.11">RSSH v0.2.11 — terminal workflows, safer SSH key import, and observable AI ops</a></li>
<li><a href="https://blog.none.at/blog/2026/2026-07-06-k8s-scale-app-rs/">k8s-scale-app-rs: Scale or Restart a Kubernetes Deployment from a CronJob</a></li>
<li><a href="https://dev.to/sicklefire/m-vis-v050-rc1-update-11cp">M-vis v0.5.0-rc1 update</a></li>
<li><a href="https://ganeshsivakumar.substack.com/p/flaredb">FlareDB: An Apache Beam Native Streaming Database built in Rust</a></li>
<li><a href="https://holovskyi.github.io/blog/typed-mqtt-topics-for-rust/">mqtt-typed-client 0.2: a type-safe async MQTT client on rumqttc</a></li>
<li><a href="https://github.com/LeChatP/RootAsRole/releases/tag/v4.0.0">RootAsRole: v4.0.0 Major release, secure execution, new logo</a></li>
<li><a href="https://www.qt.io/blog/rust-ui-framework-via-bridging-technology">A Cross-Platform Rust UI Framework via Qt’s Bridging Technology</a></li>
<li><a href="https://rapha.land/jam-programming-language/">Jam Programming Language</a></li>
<li><a href="https://www.clever.cloud/blog/company/2026/07/01/sozu-2-1-0-udp-load-balancer-programmable-edge/">Sōzu 2.1.0: UDP load balancing for the programmable edge</a></li>
<li><a href="https://op3kay.dev/writing/b0nker">b0nker: a minimal container runtime written in Rust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li>[video] <a href="https://www.youtube.com/watch?v=SGR5qBdwk30">Rust Berlin Meetup 25/06/2026 Livestream</a></li>
<li>[video] <a href="https://www.youtube.com/live/_LtgHxuysUo">How do you rewrite C/C++ projects to Rust? – JetBrains interview with Luca Palmieri, Mainmatter</a></li>
<li><a href="https://kerkour.com/rustcrypto-slow-simd-rust">Investigating why RustCrypto is slow: Deep dive into SIMD instructions and hardware acceleration</a></li>
<li><a href="https://parsa.wtf/cast/">bool as u32</a></li>
<li><a href="https://arxiv.org/html/2605.30106">A Rust-to-Lean Verification Pipeline with AI Provers: An Experience Report</a></li>
<li><a href="https://blog.dureuill.net/articles/wip/">Work In Progress Rust</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=Fk165jYfHpc">OpenAI just spent $600k on Rust</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e07-rising-academies/">Rising Academies with Dylan Brown - Rust in Production Podcast</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li>[series] <a href="https://aibodh.com/posts/bevy-tutorial-build-your-first-3d-editor-in-rust/">Bevy Tutorial: Build Your First 3D Editor - Create a 3D Space on an Infinite Grid</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-axum-basics-and-routing-by-building-a-url-shortener/">Learn Axum Basics and Routing by Building a URL Shortener</a></li>
<li>[series] <a href="https://plabayo.tech/blog/rama-101-1-https-clients-and-abstractions">Rama 101.1: HTTPS clients and layers of abstraction</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://seanborg.tech/tiny-blog/rust-week-ven-diagram/">Clickable euler diagram of all the Rust week talks</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://crates.io/crates/apis-saltans-core">apis-saltans</a>, a Zigbee implementation including a coordinator API.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1627">Richard Neumann</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>

<p>* <a href="https://github.com/name970/Protocol/issues/4">Protocol - Extend bit-exactness tests to f64 reconstruction targets</a>                                                                          <br>
* <a href="https://github.com/lenra-io/dofigen/issues/278">Dofigen - No image tag replacement flag for the generate command</a></p>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>598 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-30..2026-07-07">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156976">enable eager <code>param_env</code> norm in new solver</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156379">lint on <code>core::ffi::c_void</code> as a return type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158577">polish some macro parsing code</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158604">resolve: no allocation in <code>resolve_ident_in(_local)_module_*</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158627">simplify option-iterator flattening in the compiler</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157857">stabilize <code>#[my_macro] mod foo;</code> (part of <code>proc_macro_hygiene</code>)</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158537">add <code>std::io::cursor::WriteThroughCursor</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157347">implement <code>Box::as_non_null()</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156737">implement <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/134021">implement <code>IntoIterator</code> for <code>[&amp;[mut]] Box&lt;[T; N], A&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158427">implement <code>ptr::{read,write}_unaligned</code> via <code>repr(packed)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158539">move <code>SizeHint</code> and <code>IoHandle</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158540">move <code>std::io::Seek</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158704">optimize <code>ArrayChunks::try_rfold</code> with <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158573">stabilize <code>feature(atomic_from_mut)</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17135"><code>bindeps</code>: register transitive artifact targets</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17167">avoid cloning parsed TOML manifest in <code>ManifestErrorContext</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17176">avoid extra clone of parsed TOML manifest</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17178">remove unneeded cloning when parsing package index</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17169">change HashMaps and HashSets in Cargo to use Fxhasher</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17174">do not pass lint rustflags when <code>--cap-lints=allow</code> is set</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17164">fixed <code>Compilation::deps_output</code> only taking the last dep</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17177">pre-allocate a few vectors</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16807">stabilize <code>build-dir</code> layout v2</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17180">use a set when checking visited workspace members</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158751">fix crash when trying to inline foreign item which cannot have attributes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158334">show use-site paths for unevaluated const array lengths</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17319"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with const parameters</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17360"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with type params</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17309"><code>missing_trait_methods</code>: MSRV/unstable awareness</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17289"><code>vec_init_then_push</code>: don't lint pushes from a macro expansion</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17346"><code>inline_modules</code>: ignore <code>cfg(test)</code> modules in test builds</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17345"><code>match_same_arms</code>: keep arm-level expectations working under an outer allow</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17341"><code>unnecessary_operation</code>: avoid bad <code>!</code> suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17351"><code>unnecessary_unwrap_unchecked</code>: don't trigger inside the <code>_unchecked</code> fn</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17348">add required parentheses when the <code>needless_bool</code> suggestion is an operand</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17353">fix ICE when resolving local in <code>unnecessary_unwrap_unchecked</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17311">fix <code>infinite_loop</code> false positive inside gen blocks</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17358">fix <code>manual_c_str_literals</code> suggestion when the trailing backslash is escaped</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17337">fix <code>strlen_on_c_strings</code> incorrect suggestion logic</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17323">fix <code>suspicious_operation_groupings</code> duplications</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16902">lint bit width</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17338">optimize <code>Msrv::meets</code> calls</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17273">bail out of unicode lint scans when the snippet is pure ASCII</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17224">skip the HIR parent walk in <code>is_in_test_function</code> when there are no test items</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17366">place generated impl block after the existing impl block</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17333">refactor <code>StringAdd</code> lint pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17334">refactor <code>suspicious_xor_used_as_pow</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17293">remove <code>lower_ty</code> in <code>uninhabited_reference</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17328">respect the configured MSRV in <code>manual_is_variant_and</code>'s <code>map() == Some(_)</code> rewrite</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17332">rewrite <code>mut_mut</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17329">rewrite <code>redundant_else</code> as a late pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17354">rewrite <code>tuple_array_conversions</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22595">SCIP: exclude leading/trailing trivia in definition ranges</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22708">SCIP: remove dead <code>inlay_hints</code> field</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22433"><code>feat(ide-diagnostics)</code>: add diagnostics for invalid union patterns (E0784)</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22704"><code>internal(query-group-macro)</code>: remove the arity test</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22668">add tree top method to Syntax node</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22665">add handler for E0627</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22231">supports multi arms for <code>replace_match_with_if_let</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22690">fix UB in <code>smol_str borsh_non_utf8</code> test cases</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/20362">fix generic param for <code>generate_default_from_enum_variant</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22703"><code>walkthrough_create_project</code> file not packaged</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22677">assertion failure on closure with unbound function</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22613">avoid panic in <code>convert_tuple_struct_to_named_struct</code> on nested pattern usage</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22649">configuration syntax for nvim-lsp</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22706">correct resolution to value when it shares the same name with type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22619">exclude impls on the error type from impl enumeration</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22705">fix crash on <code>extract_variable</code> when selecting unresolved macro call</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22715">fix crash on completion inside macros</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22673">fix handling of params of coroutine fns</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22675">handle more cases of cfgs in expr store lowering</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22488">no generate with default assoc item</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22674">panics in <code>unwrap_return_type</code>, <code>remove_underscore</code>, and <code>promote_local_to_const</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22711">hoist attribute qualifier segment collection</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22709">reduce parser joint-token allocation</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22676">project-model: don't pass metadata extra args to sysroot</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22679">project-model: introduce cargo.configPath</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22581">provide startup time to ready log point and associated benchmark</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week was dominated by wild swings in benchmarks of the new-solver, which is not enabled by default, yet.
Apart from that, we got a very few notable changes, only one unexpected speedup from a bugfix in rustdoc.</p>
<p>Triage done by <strong>@panstromek</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=7dc2c162b9c197aaa76a6f9e7534569537830a01&amp;end=3659db0d3e2cd634c766fcda79ed118eca31a9fd&amp;absolute=false&amp;stat=instructions%3Au">7dc2c162..3659db0d</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.2%</td>
<td>[0.2%, 0.2%]</td>
<td>3</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>162.1%</td>
<td>[0.2%, 1116.3%]</td>
<td>20</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.4%</td>
<td>[-8.4%, -0.1%]</td>
<td>7</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-1.1%</td>
<td>[-8.4%, -0.1%]</td>
<td>11</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-0.9%</td>
<td>[-8.4%, 0.2%]</td>
<td>10</td>
</tr>
</tbody>
</table>
<p>1 Regression, 1 Improvement, 4 Mixed; 3 of them in rollups
17 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/9f1bc6e374b5ae202366df1cbef850b79be8c641/triage/2026/2026-07-06.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158522">Lint against invalid POSIX symbol definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158325">Document NonNull layout guarantees</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/112811">Tracking Issue for <code>slice_split_once</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1011">Let the OS handle stack growth</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2293">Empty repr(Rust) enums are ZSTs</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3982">Update RFC template</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3981">RFC: Store registry tokens in the OS credential store by default</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-08 - 2026-08-05 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-08 | Virtual (Cardiff, GB) | <a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/">Rust and C++ Cardiff</a></li>
<li><a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/315506435/"><strong>Operating Systems Book Club: Introduction + Processes</strong></a></li>
<li>2026-07-08 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/jv9lom12"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-09 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a></li>
<li><a href="https://www.meetup.com/rust-noris/events/315517604/"><strong>Rust Nürnberg online</strong></a></li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
<li>2026-07-15 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/21k797xr"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a></li>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
<li>2026-07-22 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
<li>2026-08-04 | Virtual (London, GB) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs/events/">Indy Rust</a></li>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a></li>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa:</a></h5>
<ul>
<li>2026-07-14 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup/events/">Johannesburg Rust Meetup</a></li>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315573758/"><strong>Debugging a production grade Open Source Rust crate</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a></li>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
<li>2026-07-09 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315585121/"><strong>Rust Berlin on location 🏳️‍🌈 - Edition 015</strong></a></li>
<li>2026-07-09 | Frankfurt, DE | <a href="https://www.meetup.com/rust-rhein-main/events/">Rust Rhein-Main</a></li>
<li><a href="https://www.meetup.com/rust-rhein-main/events/315366165/"><strong>Building Cross Platform Applications with Ply</strong></a></li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a></li>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
<li>2026-07-15 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund/events/">Rust Dortmund</a></li>
<li><a href="https://www.meetup.com/rust-dortmund/events/315496876/"><strong>Teach and Hack at Projektspeicher</strong></a></li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a></li>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a></li>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a></li>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
<li>2026-07-30 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a></li>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a></li>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
<li>2026-07-09 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a></li>
<li><a href="https://www.meetup.com/hackerdojo/events/315338107/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a></li>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a></li>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a></li>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a></li>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl/events/">Rust Atlanta</a></li>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-09 | Brisbane City, QL, AU | <a href="https://www.meetup.com/rust-brisbane/events/">Rust Brisbane</a></li>
<li><a href="https://www.meetup.com/rust-brisbane/events/315563251/"><strong>Rust Brisbane • July 2026</strong></a></li>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a></li>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a></li>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne/events/">Rust Melbourne</a></li>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>if a ptr is dereferenced in a forest and nobody hears it, is it sound?</p>
</blockquote>
<p>– <a href="https://users.rust-lang.org/t/does-the-indirection-of-a-pointer-immediately-create-a-reference/141071/10">Kornel on rust-users</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1785">Cerber-Ursi</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1ureq0r/this_week_in_rust_659/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2026.7.1-beta.3]]></title>
<description><![CDATA[OpenClaw 2026.7.1-beta.3]]></description>
<link>https://tsecurity.de/de/3655726/downloads/v202671-beta3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655726/downloads/v202671-beta3/</guid>
<pubDate>Thu, 09 Jul 2026 03:46:52 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenClaw 2026.7.1-beta.3</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic's Claude Fable 5 dominates new industry benchmarks at a steep premium]]></title>
<description><![CDATA[Anthropic's Claude Fable 5 tops all six new industry-specific performance indices from Artificial Analysis, covering finance, law, and medicine. But that lead comes at a steep cost. In the Strategy & Ops Index, a single task runs $3.48 with Fable 5, more than a hundred times what DeepSeek V4 Pro ...]]></description>
<link>https://tsecurity.de/de/3654866/ai-nachrichten/anthropics-claude-fable-5-dominates-new-industry-benchmarks-at-a-steep-premium/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654866/ai-nachrichten/anthropics-claude-fable-5-dominates-new-industry-benchmarks-at-a-steep-premium/</guid>
<pubDate>Wed, 08 Jul 2026 18:20:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="2048" height="1152" src="https://the-decoder.com/wp-content/uploads/2026/07/artificial_analysis_logo.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Anthropic's Claude Fable 5 tops all six new industry-specific performance indices from Artificial Analysis, covering finance, law, and medicine. But that lead comes at a steep cost. In the Strategy &amp; Ops Index, a single task runs $3.48 with Fable 5, more than a hundred times what DeepSeek V4 Pro charges at $0.03. The score difference is just 12 points.</p>
<p>The article <a href="https://the-decoder.com/anthropics-claude-fable-5-dominates-new-industry-benchmarks-at-a-steep-premium/">Anthropic's Claude Fable 5 dominates new industry benchmarks at a steep premium</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A brewing battle: More IT workers want unions. The industry doesn’t.]]></title>
<description><![CDATA[Until recently, many tech professionals viewed themselves as a special and respected worker class: highly educated, hard-working, well paid, and in demand.



“They considered themselves above unions,” says Zak Thompson, senior software engineer at Kickstarter and union steward at Kickstarter Uni...]]></description>
<link>https://tsecurity.de/de/3654078/ai-nachrichten/a-brewing-battle-more-it-workers-want-unions-the-industry-doesnt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654078/ai-nachrichten/a-brewing-battle-more-it-workers-want-unions-the-industry-doesnt/</guid>
<pubDate>Wed, 08 Jul 2026 13:04:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Until recently, many tech professionals viewed themselves as a special and respected worker class: highly educated, hard-working, well paid, and in demand.</p>



<p>“They considered themselves above unions,” says <a href="https://www.linkedin.com/in/zthompson1/" target="_blank" rel="noreferrer noopener">Zak Thompson</a>, senior software engineer at Kickstarter and union steward at Kickstarter United.</p>



<p>Big Tech issued aspirational mission statements that motivated workers, workplaces were seen as meritocracies, and employees were encouraged to speak out if they were unhappy. If workers didn’t like where they worked, they just moved on: other employers would be falling over themselves to hire them.</p>



<p>How times have changed.</p>



<p>Now, fed up with mass layoffs, disillusioned with Big Tech’s direction, and stunned by bold management proclamations that AI will displace huge numbers of people in many tech jobs — starting with programmers — interest in unions has risen sharply among tech professionals. Workers in some organizations, including Kickstarter, have already taken the plunge.</p>



<h2 class="wp-block-heading">A surge in interest</h2>



<p>“Starting in 2022, the industry as a whole started seeing very large layoffs across the board [and] that has dramatically shifted the balance of power. I think most people in the industry have experienced that one way or another,” says Google software engineer <a href="https://www.linkedin.com/in/alan-mcavinney-a386b8122/" target="_blank" rel="noreferrer noopener">Alan McAvinney</a>.</p>



<p>But not everyone is convinced that the layoffs have changed the power dynamic. “I wouldn’t say the balance has definitively shifted… some things point to workers losing ground and others point to improvement,” says <a href="https://www.mercatus.org/scholars/liya-palagashvili" target="_blank" rel="noreferrer noopener">Liya Palagashvili</a>, senior research fellow and director of the Labor Policy Project at the Mercatus Center at George Mason University. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Liya Palagashvili of the Mercatus Center at George Mason University</p><br></figcaption></figure><p class="imageCredit">Mercatus Center at George Mason University</p></div>



<p>What matters, she says, is not the size of the layoffs but worker options: how easily laid off workers can find alternative work in their field.</p>



<p>For McAvinney, the decision to support a union was about a culture change at his employer.</p>



<p>“In 2019, Google fired four people (<a href="https://www.newsweek.com/google-fires-thanksgiving-four-workers-crush-dissent-1474102" target="_blank" rel="noreferrer noopener">the ‘Thanksgiving Four’</a>) after they organized and spoke out internally against the company’s work with the anti-union firm IRI and US Customs and Border Protection. That was a big turning point for me,” he says. “Historically, we had a pretty robust culture that actually encouraged us to speak up internally.”</p>



<p>Google said the employees were fired for violating data security policies, but many workers believed the move was retaliatory. It became a galvanizing event that contributed to the launch of the <a href="https://www.alphabetworkersunion.org/" target="_blank" rel="noreferrer noopener">Alphabet Workers Union (AWU)</a> in 2021, says McAvinney, organizing chair, Alphabet Workers Union-CWA. (Alphabet is the parent company of Google.)</p>



<p>So far, tech worker interest in unions hasn’t translated into higher membership numbers nationally. According to the US Census Bureau’s <a href="https://www.census.gov/programs-surveys/cps.html" target="_blank" rel="noreferrer noopener">Current Population Survey (CPS)</a>, union membership in tech occupations was about 3.5% in 2025, says Palagashvili. “While there have been some high-profile organizing efforts, they do not yet show up as a broad national increase in tech-sector unionization.”</p>



<p>Overall, only 10% of American workers belonged to a union in 2025, the Bureau of Labor Statistics (BLS) <a href="https://www.bls.gov/news.release/union2.nr0.htm" target="_blank" rel="noreferrer noopener">reported</a> — near an all-time low — but interest in labor unions is rising. A 2025 Gallup survey found that <a href="https://news.gallup.com/poll/694472/labor-union-approval-relatively-steady.aspx" target="_blank" rel="noreferrer noopener">68% of Americans approved of unions</a>, up from 48% in 2009. Interest is particularly strong among younger workers, the <a href="https://www.epi.org/publication/workers-resolve-drives-increase-in-unionization-in-2025/" target="_blank" rel="noreferrer noopener">Economic Policy Institute reports</a>, and in a 2024 <a href="https://www.teamblind.com/blog/why-are-unions-not-common-tech-industry/" target="_blank" rel="noreferrer noopener">online survey of 1,900 tech professionals</a> on the career site Blind, 67% of respondents said they’d be “very likely” or “somewhat likely” to join a union if their company had one.</p>



<p>Nonetheless, for most tech professionals, those positive perceptions have not so far translated into widespread union membership.</p>



<h2 class="wp-block-heading">Fear, uncertainty, and doubt</h2>



<p>In the wake of mass layoffs that began in 2022, the primary driver toward tech worker unionization may well be job security.</p>



<p>“I think a greater concern is that their work and skills have been devalued at the same time their jobs become less secure and their wages and benefits have declined,” says <a href="https://www.ilr.cornell.edu/people/kate-l-bronfenbrenner" target="_blank" rel="noreferrer noopener">Kate Bronfenbrenner</a>, director of labor education research and senior lecturer emeritus at Cornell University’s School of Industrial and Labor Relations.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Kate Bronfenbrenner from the School of Industrial and Labor Relations, Cornell University</p><br></figcaption></figure><p class="imageCredit">ILR School/Cornell University</p></div>



<p>The fear that AI will displace IT workers en masse is palpable, says Google’s McAvinney. Whether the <a href="https://www.computerworld.com/article/4175956/the-ai-tech-job-slaughter-gets-real.html">mass layoffs to date</a> were actually driven by AI or if AI was used as a pretext, “Large numbers of people have that concern, and that is absolutely part of the interest in collective action — getting organized, joining a union, or forming a union,” he says.</p>



<p>The second motivator is ideological disillusionment. “Workers recruited with promises that they would be changing the world discovered that they were really building surveillance systems or military technology,” Bronfenbrenner says.</p>



<p>The insidious use of AI surveillance is another concern, says Bronfenbrenner. For example, Meta’s announcement that it would <a href="https://www.computerworld.com/article/4161929/meta-to-track-employee-keystrokes-screen-activity-to-train-ai-agents.html">use AI to track US-based workers’ computer activities</a>, including clicks, keystrokes, mouse movements, and screen snapshots to train AI agents had a dystopian feel to it. Were these workers training AI to take over their jobs, just as US workers were asked to train their lower-cost foreign replacements during the offshoring craze in the mid-2000s? (Meta later <a href="https://www.computerworld.com/article/4188640/meta-pauses-employee-monitoring-program-after-data-protections-fail-2.html">paused the tracking program</a> after employees twice demonstrated the inadequacy of privacy protections for the collected data.)</p>



<p>But Bronfenbrenner argues that AI’s bigger threat may be its use as a surveillance tool to prevent organizing. “My research on surveillance in organizing campaigns found that it tripled from 11% in the early 2000s to one third in 2021,” she says.</p>



<p>“The deeper pattern is the same one inherent in <a href="https://www.britannica.com/science/Taylorism" target="_blank" rel="noreferrer noopener">Taylorism</a> — management trying to know everything that’s under the worker’s cap, to monitor every step so workers have no control and no secrets,” Bronfenbrenner says. “Now they have even more technology to do it, and they can potentially replace you entirely with AI.”</p>



<p><a href="https://www.linkedin.com/in/simonerobutti/" target="_blank" rel="noreferrer noopener">Simone Robutti</a>, an organizer with Tech Workers Coalition Global, calls the current wave of tech layoffs “a prequel to whatever AI-driven layoffs are coming.” It’s part of the trend of “lowering the cost of knowledge workers, of cognitive workers, of office workers in general — because that’s the bet on AI,” he says.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="745" height="486" sizes="auto, (max-width: 745px) 100vw, 745px"&gt;<figcaption class="wp-element-caption"><p>Simone Robutti from Tech Workers Coalition Global</p><br></figcaption></figure><p class="imageCredit">TWC</p></div>



<p>Whether employers can in fact replace workers with AI (or will be able to soon) is an open question. “If Amazon lays off a hundred workers, and ninety of them find comparable jobs within a few months, that mitigates the concern,” says Palagashvili from George Mason University. “If most of them have to sell their houses and move across the country, or end up underemployed — not just unemployed, but working in warehouses instead of at a competitor — that’s a different picture.”</p>



<p>So far that hasn’t been a big issue for former Google employees, says McAvinney. “It used to be that if you left Google, you could get a job anywhere in tech instantly. That’s no longer the case, but most people I talk to are still finding work in the industry,” he says.</p>



<p>But for those newly entering the workforce, it’s much harder to find a job. According to the <a href="https://hai.stanford.edu/ai-index/2026-ai-index-report/economy" target="_blank" rel="noreferrer noopener">Stanford HAI <em>2026 AI Index Report</em></a>, released in April, “employment for software developers ages 22 to 25 has fallen nearly 20% from 2024.”</p>



<h2 class="wp-block-heading">Successes and setbacks</h2>



<p>While organizing can be an uphill battle and workers often face aggressive pushback from their employers, there have been a few notable successes.</p>



<p>In the UK, workers can join a union as individual members before their employer formally recognizes that union for collective bargaining purposes. That’s how 300 workers in Google DeepMind’s London office initially joined the <a href="https://www.cwu.org/" target="_blank" rel="noreferrer noopener">Communication Workers Union</a>. In April, 98% of the 300 CWU members <a href="https://fortune.com/2026/05/05/google-deepmind-unionize-vote-military-ai-contracts-internal-backlash-pentagon-deal-israeli-defense-forces/" target="_blank" rel="noreferrer noopener">voted in favor of pursuing union recognition</a>, formally requesting that management recognize the CWU and <a href="https://www.unitetheunion.org/" target="_blank" rel="noreferrer noopener">Unite the Union</a> as representatives for approximately 1,000 staff. (Google DeepMind disputed characterizing the action as a vote to unionize).</p>



<p>And in May, some 2,100 tech workers at the University of California <a href="https://upte.org/news/2100-tech-workers-vote-to-join-upte" target="_blank" rel="noreferrer noopener">joined the University Professional and Technical Employees union</a>, which is affiliated with Communications Workers of America (UPTE-CWA), with 96% of the workers voting yes.</p>



<p>“A lot of tech workers right now are extremely concerned about job security and about their work being automated,” says <a href="https://www.linkedin.com/in/mbelasco/" target="_blank" rel="noreferrer noopener">Max Belasco</a>, a business systems analyst at the UCLA School of Law and co-chair of the UCLA chapter of UPTE-CWA, Local 9119.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Max Belasco from the UCLA chapter of UPTE-CWA</p>
</figcaption></figure><p class="imageCredit">Zac Goldstein</p></div>



<p>The CWA described the organizing initiative as “<a href="https://cwa-union.org/news/it-workers-join-upte-cwa-form-largest-tech-union-country" target="_blank" rel="noreferrer noopener">the largest tech industry organizing campaign in US history</a>.” But it wasn’t the first.</p>



<p>“Between 2022 and 2024, CWA organized nearly 400 different digital media companies,” Bronfenbrenner says, including the game developer Activision and the New York Times.</p>



<p>Kickstarter’s 85 employees voted in 2020 to form <a href="https://kickstarterunited.org/" target="_blank" rel="noreferrer noopener">Kickstarter United</a> — the vote was 55% in favor — and most recently the union negotiated a contract that includes a four-day workweek, AI protections, and a minimum pay floor for 59 employees, including tech workers. </p>



<p>“What we ended up winning was yearly benchmarking of all employee salaries to the 60th percentile, along with yearly cost of living adjustments,” says Thompson.</p>



<p>But the way forward has been rocky. Shortly after the union was ratified, Kickstarter announced layoffs. The union, which is affiliated with the Office and Professional Employees International Union (OPEIU), wasn’t able to reverse that decision but did <a href="https://kickstarterunited.org/may-day-severance-agreement/" target="_blank" rel="noreferrer noopener">negotiate better severance terms</a>, including four months of severance pay (versus 2 to 3 weeks for every year worked) and six months of health benefits.</p>



<p>When contract negotiations faltered in October 2025, the union went on strike for 42 days. By December, a new contract was ratified. Shortly thereafter, the company announced another round of layoffs that included four union leaders, one of whom had helped to negotiate the new contract. The union is currently fighting those dismissals and will be arguing its case in third-party arbitration.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="618" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Members of Kickstarter United union on strike</p></figcaption></figure><p class="imageCredit">Kyle Friend</p></div>



<p>The <a href="https://www.nlrb.gov/guidance/key-reference-materials/national-labor-relations-act" target="_blank" rel="noreferrer noopener">National Labor Relations Act</a> of 1935 codified American workers’ rights to unionize and take collective action, and it established the <a href="https://www.nlrb.gov/about-nlrb/who-we-are" target="_blank" rel="noreferrer noopener">National Labor Relations Board</a> to protect those rights. Unfortunately for Kickstarter, NLRA enforcement under the Trump administration isn’t what it once was.</p>



<p>“Cases brought up for violations of the NLRA can go for months or years without ever seeing a hearing or having any sort of judgment. That gives companies more power to flagrantly ignore it,” Thompson says.</p>



<p>Tech firms have other weapons to dissuade employees from unionizing. Researchers from Carnegie Mellon University and Princeton University in 2025 <a href="https://dl.acm.org/doi/epdf/10.1145/3757671" target="_blank" rel="noreferrer noopener">interviewed 44 US-based tech worker-organizers</a>, who cited additional pressure tactics including threats to withdraw venture capital funding — essentially killing venture-backed firms if employees vote to unionize — and threats of being fired that <a href="https://techworkerscoalition.org/blog/2025/03/14/immigrant-rights-are-labor-rights-tech-workers-and-h-1b-visas/" target="_blank" rel="noreferrer noopener">put tech workers with H-1B visas in an impossible position</a>.</p>



<p>Kickstarter United is a majority union — one that has won NLRB certification. While that’s possible in smaller organizations, success in larger tech firms has been much more limited.</p>



<p>Alphabet is a prime example: the Alphabet Workers Union-CWA is a “pre-majority” union that lacks NLRB certification and has no formally recognized bargaining unit. Formed in 2021 with fewer than 400 members, today it represents 1,400 members, still a small fraction of Alphabet’s US-based workforce, estimated at over 100,000.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="839" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Alan McAvinney from Alphabet Workers Union-CWA</p></figcaption></figure><p class="imageCredit">Aran Per Ink</p></div>



<p>The challenge, says McAvinney, lies in trying to organize a distributed workforce of in-office, remote, and contract workers. “Large tech companies don’t split easily into discrete segments — there’s no strong geographic component to teams, and a single team is often spread across many locations,” which makes getting majority support unrealistic, he says.</p>



<p>But that doesn’t mean the union has had no impact. “In January, we launched our Googlers for Job Security campaign. Today we’re organizing around four demands: a guaranteed minimum severance package for everyone who’s laid off, voluntary buyouts before any mandatory layoffs, an end to GRAD quotas (GRAD being Google’s performance review system) so ratings reflect actual performance and aren’t given or changed to force a particular distribution, and the option to take severance as leave, giving workers, especially those on visas, more time on payroll,” McAvinney says.</p>



<p>“In response, Google did start offering voluntary exit packages,” he says. The union was also able to negotiate one contract, for Google Help workers. However, those workers aren’t actually Google employees: they’re contractors who report to Google management but work for Accenture.</p>



<h2 class="wp-block-heading">The counterargument</h2>



<p>Do unions get what they bargain for? Conservative business and labor economists say union contracts typically have rigid pay structures that restrict merit-based pay in favor of seniority-based wage increases, and that unions, as certified by the NLRB, create labor monopolies that limit worker choice and push up wages to levels detrimental to both workers and business.</p>



<p>The collective bargaining model is not well suited to the highly dynamic and innovation-driven tech sector, Palagashvili argues. “Firms often need to reorganize teams, redesign products, adjust roles, and redeploy talent quickly,” she says. </p>



<p>Collective bargaining agreements make those adjustments much more difficult by imposing uniform terms for an entire bargaining unit, regardless of individual preferences and circumstances. The contracts, she says, “are more about higher pay and less about flexibility.”</p>



<p>But Thompson says that hasn’t been his experience. “The thing with a union is you get to write the contract,” he says. “At Kickstarter we care about recognizing individual contributions, merit, and having a clear career progression.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="972" height="972" sizes="auto, (max-width: 972px) 100vw, 972px"&gt;<figcaption class="wp-element-caption"><p>Zak Thompson from Kickstarter United</p><br></figcaption></figure><p class="imageCredit">Fee Christoph</p></div>



<p>Kickstarter United pushed the company to clearly define what it takes to get a promotion, advocated for no “at will” employment, where employees can be fired any time without a stated reason; won standards for minimum pay, raises, promotions, and time off; secured AI protections; and codified a four-day work week.</p>



<p>Yes, some tech professionals voiced concerns about unions, such as that they stifle innovation and limit compensation for top performers, Thompson says, but “a lot of those people came around. They said ‘I was wrong. I feel way more protected, more secure, and I see the benefits.’”</p>



<p>Bronfenbrenner says it’s a mistake to think that tech workers are inherently different from other workers, adding that the two industries with the highest union density are entertainment and professional sports. “These are professionals with unique talents and capabilities, and they’ve organized successfully under the exclusive representation system.”</p>



<h2 class="wp-block-heading">Will we see a unionized tech workforce?</h2>



<p>If unions eventually prevail in tech, it will happen in the face of intense pressure from employers not to organize. </p>



<p>“The Alphabet Workers Union is a case study of the limits of the first wave of tech labor organizing,” says Robutti from the Tech Workers Coalition. “They hit a threshold beyond which they couldn’t fight the union busting anymore, and they became entrenched at that size.”</p>



<p>No one should expect large-scale unionization to occur overnight, Bronfenbrenner says. “The auto and steel industries weren’t organized in months. It took decades. Organizing global tech companies will take the same.”</p>



<p>While McAvinney acknowledges that a traditional majority union may be difficult to achieve any time soon in a company as large as Alphabet, he’s still bullish on his pre-majority union’s ability to make a difference. “Ultimately, regardless of which type of union you are, you can only win as much as you have leverage to win. Your leverage is inherently limited, but that doesn’t mean you can’t win anything,” he says.</p>



<p>Attitudes about unions appear to be changing rapidly. “Interest in unions is high, and I expect that will continue,” McAvinney says. “Now is an excellent time for people to start getting organized. I have seen lots of evidence of that.”</p>



<p>Thompson agrees. “We are seeing an uptick of people in tech reaching out, trying to get help organizing. When people have their job conditions continue to deteriorate, they are going to start organizing,” he says. “We’re definitely seeing a shift from ‘it’d be nice if we had a union’ to ‘okay, how can I actually do this now?’”</p>



<p><em>Come back next week for Part 2: How to unionize your tech workplace</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[My threat feed told me it was ‘Chalubo.’ The binary disagreed]]></title>
<description><![CDATA[I’ve spent two years doing incident response and threat intel, and the one habit I’d keep if I had to give up every other is also the most boring. I don’t act on a piece of intelligence until I’ve checked it against the thing it claims to describe. It’s slow. It’s tedious. Almost nobody does it, ...]]></description>
<link>https://tsecurity.de/de/3653754/it-security-nachrichten/my-threat-feed-told-me-it-was-chalubo-the-binary-disagreed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653754/it-security-nachrichten/my-threat-feed-told-me-it-was-chalubo-the-binary-disagreed/</guid>
<pubDate>Wed, 08 Jul 2026 11:09:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I’ve spent two years doing incident response and threat intel, and the one habit I’d keep if I had to give up every other is also the most boring. I don’t act on a piece of intelligence until I’ve checked it against the thing it claims to describe. It’s slow. It’s tedious. Almost nobody does it, because checking costs the exact time the feed was supposed to save. So, we read the report, nod and move on. That works fine most weeks. The weeks it doesn’t are the ones I remember, and the one I keep coming back to started with a feed that sounded completely sure of itself and had it backwards.</p>



<h2 class="wp-block-heading">A cluster the feed got wrong</h2>



<p>I was mapping infrastructure behind a loader operation, sweeping a single service port through a commercial platform. It handed back a cluster of hosts; all tagged the same thing: Chalubo RAT. The tag didn’t stop me. The metadata did. Every host in the cluster carried one first-seen date, down to the day.</p>



<p>Real infrastructure never looks that clean. Operators stand hosts up a few at a time, over weeks, whenever they get to it. A whole cluster sharing one first-seen date almost always means you’re looking at the day the feed’s pipeline ingested the batch, not the day anyone actually saw those hosts live. So now I had two things I didn’t trust: The family name and the too-perfect date. Easiest way to settle it was to close the feed and go look at the malware.</p>



<p><a href="https://news.sophos.com/en-us/2018/10/22/chalubo-botnet/">Chalubo</a> is a Linux botnet. It brute-forces SSH and throws DDoS traffic. What I had in front of me was a Windows shellcode loader, a DonutLoader variant, the kind of thing that sits at the front of a ransomware intrusion. Different platform, different job. Calling one the other isn’t a near miss. It’s a category error.</p>



<p>So, I detonated it in an isolated lab, captured the traffic, mapped the C2 and pulled the config. It spoke a protocol of its own: Payload delivery on one custom channel, a steganographic beacon on a second, across a ten-host cluster, with a config format that had nothing to do with Chalubo. The reason for the bad tag turned out to be dull. The feed’s rule for that port keyed on the port plus a loose pattern, my loader tripped it and the label propagated across the whole batch with the ingest date stapled on.</p>



<p>This isn’t a knock on the vendor. Fingerprinting malware families across the entire internet is genuinely hard. The damage starts one step later, with whatever the reader does with that tag. Believe it, and you spend the week hardening against a Linux DDoS botnet while a Windows ransomware precursor sits quietly on your network. Wrong threat. Wrong priorities. The feed didn’t just come up empty. It pointed the response in the wrong direction, with total confidence and a familiar logo on it. Nothing about the tag looked wrong. The file was the only thing that said otherwise.</p>



<h2 class="wp-block-heading">The same gap, in a federal advisory</h2>



<p>For a while I filed this as a commercial-feed problem, the tax you pay for buying intel from a vendor cutting corners at scale. Then the same shape turned up in one of the best sources any of us get for free.</p>



<p>Earlier this year I spent some time inside the joint FBI and CISA <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-050a">advisory</a> on Ghost, or Cring depending on who’s naming it, a ransomware crew that’s hit organizations in seventy-plus countries. Like everyone, I opened the PDF first. Its indicator table is literally headed “MD5 File Hashes”: 14 samples, each pinned to an MD5 and nothing else. MD5’s been broken for years. It’s the whole reason detection moved to SHA-256, and an MD5-only indicator doesn’t drop cleanly into half the tooling defenders actually run.</p>



<p>Then I opened the other copy of the same advisory. It doesn’t only ship as a PDF. There’s a machine-readable STIX bundle too, the format built to feed straight into a TIP or a SIEM. Same advisory, same code, different file. Six of those fourteen samples carried SHA-256 in the STIX, with SHA-1 and fuzzy hashes next to them, none of it in the PDF table. The stronger indicators were in the official release the entire time, sitting in the file almost nobody opens. Read the PDF like most people do, and you walk away with weaker detections than whoever opened the STIX, and nothing tells you there’s a difference.</p>



<p>That same bundle cut the other way too, and this is the part worth slowing down on. Down in its relationships sat a threat-actor object naming APT41, Winnti, Wicked Panda, wired to several of the Ghost indicators. The advisory’s text never says APT41. It goes out of its way to call the attribution “variable over time.” Pull on the thread and it falls apart: No vendor has ever tied Ghost to APT41, and the object looks like automated enrichment, not a human analyst’s call. The STIX isn’t lying to you. The problem is subtler. Feed it into your TIP and you’ve quietly inherited a nation-state attribution nobody actually made. One file was missing good data. The other was carrying data nobody vetted. You only catch either by looking.</p>



<p>And it’s not a one-country quirk. A while later I reversed a Go backdoor, GAMYBEAR, the one UAC-0241 pointed at Ukrainian schools and state bodies, documented in a CERT-UA <a href="https://cert.gov.ua/article/6286219">advisory</a>. Good report. It nailed the behavior. But the actual loader gave up more than fifteen binary-level corrections to what the advisory had: A persistence mechanism attributed to the wrong component, a broken TLS implementation and a handful of indicators that only held once I checked them against the real sample instead of the writeup. That’s the kind of detail that keeps a detection alive after the operator renames the file. Commercial vendor. Federal agency. Foreign CERT. Three sources, all accurate, all carrying something other than the full truth in the copy most people read.</p>



<h2 class="wp-block-heading">What I do differently now</h2>



<p>The lesson wasn’t trust intelligence more or trust it less. It’s narrower than that. An indicator is a claim, and a claim gets checked before you stake a defense on it, most of all when it’s the advisory covering your own organization, because that’s the one whose blind spots quietly become yours. It’s cheap enough to make routine. If I were standing up a detection program next week, three things would be in from day one.</p>



<p>Treat any automated family label as a guess until something specific backs it. A row of identical first-seen dates is a fact about a pipeline, not a record of an attack. When an advisory ships in more than one format, open the machine-readable copy and don’t stop at the PDF, because the structured file tends to hold both the stronger indicators and the unvetted ones, and you want to see both. And for anything that actually matters, run a live sample through your own stack before you call it covered. The gap between an indicator and a detection that fires is exactly where attackers like to live.</p>



<p>I still reach for all three kinds of source every week, and I’ll defend every one of them. They were never the problem. The checking was always the cheap part. Assuming I could skip it was the expensive one. A report is where the work starts. Not where it stops.</p>



<p>The full teardowns behind these three cases are published on GitHub: The <a href="https://github.com/yankywilson/donutcluster-AS138995">DonutLoader protocol analysis</a>, the <a href="https://github.com/yankywilson/ghost-cring-defender-toolkit">Ghost detection content</a> and the <a href="https://github.com/yankywilson/gamybear">GAMYBEAR reversing notes and rule</a>, each in its own repository.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Four agentic AI memory systems for smarter LLMs]]></title>
<description><![CDATA[AI agents, and the large language models (LLMs) that power them, have short memories. That’s by design. There is only so much conversation that can be encoded into tokens and accessed reliably by the LLM. Retrieval-augmented generation, or RAG, can be used to give agents and LLMs memories larger ...]]></description>
<link>https://tsecurity.de/de/3653745/ai-nachrichten/four-agentic-ai-memory-systems-for-smarter-llms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653745/ai-nachrichten/four-agentic-ai-memory-systems-for-smarter-llms/</guid>
<pubDate>Wed, 08 Jul 2026 11:04:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html" data-type="link" data-id="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html">AI agents</a>, and the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a> (LLMs) that power them, have short memories. That’s by design. There is only so much conversation that can be encoded into tokens and accessed reliably by the LLM. <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html" data-type="link" data-id="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">Retrieval-augmented generation</a>, or RAG, can be used to give agents and LLMs memories larger than their context windows. But how agents use RAG, or other mechanisms for retaining the details of a conversation, can make all the difference.</p>



<p>With the rise of AI agents, there has been a corresponding rise in complementary software tools that give both agents and LLMs expanded memory capabilities. Most of the time, this means giving an agent or model persistent memory across sessions, so that previous context can be restored automatically. But, again, how that’s done can vary tremendously with each tool.</p>



<p>Here are some of the major projects in the AI agent memory space, each with their own particular spins, strengths, and orientations.</p>



<h2 class="wp-block-heading">Graphiti</h2>



<p><a href="https://github.com/getzep/graphiti">Graphiti</a> is billed as “the open-source temporal knowledge graph framework.” The project is available on GitHub, or as the underpinning of the <a href="https://www.getzep.com/">Zep ageny memory service</a>. “Temporal” means information stored in Graphiti is re-evaluated over time to keep its context properly framed, and “graph framework” means the data is stored as a set of graphs. The other solutions profiled here use graph storage as part of their approach, but Graphiti makes that a front-and-center part of its design.</p>



<p>Graphiti supports a range of common LLM providers out of the box: Anthropic, Azure OpenAI, Google Gemini, and Groq. Any Ollama and OpenAI-compatible APIs also work, so Graphiti can be used with locally hosted LLMs as well. Connectors for third-party storage services let you ingest data from places like GitHub, Gmail, and OneDrive, as well as from applications like Notion.</p>



<p>Using Graphiti locally requires you set up or connect to a graph database. <a href="https://neo4j.com/" data-type="link" data-id="https://neo4j.com/">Neo4j</a> is the default and most broadly supported of the bunch, but <a href="https://aws.amazon.com/neptune/" data-type="link" data-id="https://aws.amazon.com/neptune/">Amazon Neptune</a>, <a href="https://www.falkordb.com/" data-type="link" data-id="https://www.falkordb.com/">FalkorDB</a>, and <a href="https://kuzudb.github.io/" data-type="link" data-id="https://kuzudb.github.io/">KuzuDB</a> will also work. Postgres with <code>pgvector</code> is not listed as an option.</p>



<h2 class="wp-block-heading">Hindsight</h2>



<p><a href="https://hindsight.vectorize.io/">Hindsight</a>, available as both a cloud service and a locally hostable project, stores details about agent sessions into <a href="https://hindsight.vectorize.io/#key-components">four types of memory</a> with <a href="https://hindsight.vectorize.io/#multi-strategy-retrieval-tempr">four types of storage and retrieval strategies</a>. All of these are handled through three programmatic interfaces: <code>retain</code> for storing content, either a single fact or a whole conversation; <code>recall</code> for retrieving content; and <code>reflect</code> for running an agentic loop over a query that uses previously stored data.</p>



<p>Hindsight comes with a broad range of first-party and third-party <a href="https://hindsight.vectorize.io/integrations">integrations</a> with existing LLMs and agent toolkits. For instance, if you’re using the Continue extension with <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> to talk to a locally hosted LLM, you can use Hindsight’s <a href="https://hindsight.vectorize.io/sdks/integrations/continue">Continue integration</a> to add long-term memory to your interactions. You can use the <code>@hindsight</code> keyword in your query to inject relevant memory into the agent’s context, or use auto-injection rules (which can be edited) to do most of that heavy lifting automatically.</p>



<h2 class="wp-block-heading">Mem0</h2>



<p><a href="https://github.com/mem0ai/mem0">Mem0</a> is a little like Hindsight in that it has <a href="https://docs.mem0.ai/core-concepts/memory-types">four basic kinds of memory</a>, although they are labeled and organized differently. For instance, Mem0 has a separate type of memory called organizational memory that’s intended to store data to be shared between multiple agents or different teams, something that is not normally done by default. Each memory added is passed through a <a href="https://docs.mem0.ai/core-concepts/memory-evaluation#memory-extraction-distillation">distillation process</a> and stored in a different way (vector DB, graph DB, SQL DB) depending on how it will be used. Older data, instead of being overwritten, gets deprecated rather than deleted, as a strategy for preserving larger long-term context. (Hindsight does this as well.)</p>



<p>Mem0 supports <a href="https://docs.mem0.ai/components/llms/overview">a smaller range of LLMs</a> than Hindsight, but all the major options are available: Anthropic, Google Gemini, OpenAI, and self-hosted options like <a href="https://www.langchain.com/" data-type="link" data-id="https://www.langchain.com/">LangChain</a>, <a href="https://www.litellm.ai/" data-type="link" data-id="https://www.litellm.ai/">LiteLLM</a>, <a href="https://lmstudio.ai/" data-type="link" data-id="https://lmstudio.ai/">LM Studio</a>, and <a href="https://ollama.com/" data-type="link" data-id="https://ollama.com/">Ollama</a>. If you intend to use Mem0 locally rather than <a href="https://mem0.ai/pricing">as a service</a>, you’ll need to provide a Python instance and your own vector database. For the latter, Postgres with the <code>pgvector</code> extension is a common and simple choice; it can even be <a href="https://github.com/orm011/pgserver">installed inside a Python venv</a>. </p>



<h2 class="wp-block-heading">Supermemory</h2>



<p><a href="https://supermemory.ai/">Supermemory</a> ingests data from many common sources—supporting plaintext, structured data, common document file formats like PDF and Microsoft Office, video and audio, images—and uses them to build a context graph to inform agent conversations. Among its most promoted features is its content-extraction tools. </p>



<p>Supermemory is available as a cloud service or as <a href="https://github.com/supermemoryai/supermemory" data-type="link" data-id="https://github.com/supermemoryai/supermemory">open-source software</a> you can run locally. The open-source edition lacks the scaling services and third-party service connectors (Gmail, Google Drive, Notion, etc.) provided with the enterprise edition, but it has one big advantage: it consists of a single, self-contained binary, so it can be deployed on one’s own hardware with very little effort. No external databases need to be provisioned for Supermemory, either, so it’s well-suited to quick experimentation.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents fall for indirect prompt injection traps]]></title>
<description><![CDATA[Some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans, Zscaler found in a test of major LLMs.



The security vendor looked at various forms of indirect prompt injection (IPI) traps and ...]]></description>
<link>https://tsecurity.de/de/3653554/it-security-nachrichten/ai-agents-fall-for-indirect-prompt-injection-traps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653554/it-security-nachrichten/ai-agents-fall-for-indirect-prompt-injection-traps/</guid>
<pubDate>Wed, 08 Jul 2026 09:37:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans, Zscaler found in a test of major LLMs.</p>



<p>The security vendor looked at various forms of indirect prompt injection (IPI) traps and found that, whereas many models fell victim to the schemes, some of the lower-level LLMs fared better than their pricier siblings. </p>



<p>The Zscaler testing found, <a href="https://www.zscaler.com/sites/default/files/images/page/figure-16---ipi.jpg" target="_blank" rel="noreferrer noopener">for example</a>, that four models were found to be “vulnerable”: Llama3-3-70b-instruct; Llama3-2-90b-instruct; Gemini-3-flash; and Gemini-2.5-pro. Three models were found to be “safe”: Llama4-maverick; Gemini-3.1-pro; and Gemini-3.1-flash-lite. Those results indicated that the scam resistance of Gemini-2.5-pro was seemingly weaker than that of Gemini-3.1-flash-lite. </p>



<p>But <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, said that there is not necessarily any valuable takeaway from that revelation, because agents constantly change behavior as they feed on new data and revise their analyzed assumptions. That means an agent that failed a specific test might very well pass the identical test an hour later, he said. </p>



<p>“The risk of an agent is constantly changing and that can cause vastly different results. You can’t assume the results are generalizable. The test result is only at one point in time,” Kenney pointed out. Zscaler “is trying to prove a point that I don’t think the data necessarily proves.”</p>



<p>Kenney added that having a clean “safe/vulnerable” classification is too simplistic to be useful. “That’s a binary classification. I would never recommend to a CISO to do a binary classification.”</p>



<p>The <a href="https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents" target="_blank" rel="noreferrer noopener">full ZScaler blog post</a> argued that many autonomous agents are susceptible to IPI traps.</p>



<p>The company said it identified IPI embedded in multiple websites, where hidden instructions were designed to manipulate the behavior of an AI agent. </p>



<p>In its internal validation across 26 LLMs, 4 models “failed to take appropriate actions,” which, it said, demonstrated “measurable real-world impact, showing that susceptibility varies by model and by the context provided to the LLM alongside the prompt.”</p>



<p>The post added, “as AI agents become a more common interface to the web, the content itself is going to become a larger attack surface, highlighting that AI is a double-edged sword that can streamline workflows while also introducing new avenues for abuse.”</p>



<p><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that although the results are not surprising, they are significant. </p>



<p>The especially worrisome detail in the report is that any commercial LLM failed at all, “because the security model for agentic AI has historically assumed that model-level safety training would meaningfully attenuate this class of attack,” Mahapatra said. “It does not, and the Zscaler data is the first widely-cited public evidence.”</p>



<h2 class="wp-block-heading">A fundamental architecture issue</h2>



<p>Mahapatra also said that the examples cited by Zscaler are not nearly as concerning as the implications of the greater damage that could occur.</p>



<p>“The Zscaler payment scam scenario, where an agent pays a fake $3 ‘developer license fee’ to obtain an API key, is the most benign version of this,” he said. “The same technique applied to an agent authorized for procurement, expense processing, vendor onboarding, or trade execution produces losses at completely different scales. I have watched Fortune 50 banks stand up agentic workflows in the last six months that would fail exactly this attack in a live examination.”</p>



<p>Indeed, he noted, most AI vendors already understand the magnitude of risk from today’s AI agents.</p>



<p>“Every model provider will admit privately that the fundamental architecture of transformer-based reasoning cannot cleanly separate untrusted content from trusted instructions when both share the context window,” Mahapatra said. “The attack surface is architectural, not just behavioral. That means the defense has to be architectural too, and this is where the enterprise agentic AI conversation is still lagging badly.”</p>



<p>Zscaler’s testing also reinforced the difference in how AI agents and humans process information.</p>



<p>“Humans are skeptical of instructions they did not expect. Agents are eager to follow structured metadata because their training rewards them for treating high-signal fields as authoritative. Humans notice when a payment request appears in the middle of an unrelated task. Agents will thread that payment request into their execution plan if the surrounding context frames it as procedurally necessary,” Mahapatra pointed out, noting that while humans have relationships with vendors, memories of prior interactions, and social context to give them verification signals, agents only have what is in the context window, and, he said, “the context window is now the primary attack surface.”</p>



<p><a href="https://www.infotech.com/profiles/fritz-jean-louis" target="_blank" rel="noreferrer noopener">Fritz Jean-Louis</a>, principal cybersecurity advisor at Info-Tech Research Group, agreed that the risks described in the ZScaler post are concerning, because they are in areas not traditionally addressed by enterprise security.</p>



<p>“These attacks differ from traditional threats in that they target how AI systems process, interpret, and act on information behind the scenes,” Jean-Louis said. “Agentic AI introduces new trust boundaries, including untrusted content influencing automated decision making, tools and plugins acting autonomously on behalf of users, and AI systems operating with broad, inherited permissions. This effectively transforms the challenge into an insider threat paradigm.”</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4193403/zscaler-finds-autonomous-agents-succumb-to-ipi-traps.html" target="_blank">InfoWorld.</a></em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents fall for indirect prompt injection traps]]></title>
<description><![CDATA[Some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans, Zscaler found in a test of major LLMs.



The security vendor looked at various forms of indirect prompt injection (IPI) traps and ...]]></description>
<link>https://tsecurity.de/de/3653549/ai-nachrichten/ai-agents-fall-for-indirect-prompt-injection-traps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653549/ai-nachrichten/ai-agents-fall-for-indirect-prompt-injection-traps/</guid>
<pubDate>Wed, 08 Jul 2026 09:33:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans, Zscaler found in a test of major LLMs.</p>



<p>The security vendor looked at various forms of indirect prompt injection (IPI) traps and found that, whereas many models fell victim to the schemes, some of the lower-level LLMs fared better than their pricier siblings. </p>



<p>The Zscaler testing found, <a href="https://www.zscaler.com/sites/default/files/images/page/figure-16---ipi.jpg" target="_blank" rel="noreferrer noopener">for example</a>, that four models were found to be “vulnerable”: Llama3-3-70b-instruct; Llama3-2-90b-instruct; Gemini-3-flash; and Gemini-2.5-pro. Three models were found to be “safe”: Llama4-maverick; Gemini-3.1-pro; and Gemini-3.1-flash-lite. Those results indicated that the scam resistance of Gemini-2.5-pro was seemingly weaker than that of Gemini-3.1-flash-lite. </p>



<p>But <a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, said that there is not necessarily any valuable takeaway from that revelation, because agents constantly change behavior as they feed on new data and revise their analyzed assumptions. That means an agent that failed a specific test might very well pass the identical test an hour later, he said. </p>



<p>“The risk of an agent is constantly changing and that can cause vastly different results. You can’t assume the results are generalizable. The test result is only at one point in time,” Kenney pointed out. Zscaler “is trying to prove a point that I don’t think the data necessarily proves.”</p>



<p>Kenney added that having a clean “safe/vulnerable” classification is too simplistic to be useful. “That’s a binary classification. I would never recommend to a CISO to do a binary classification.”</p>



<p>The <a href="https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents" target="_blank" rel="noreferrer noopener">full ZScaler blog post</a> argued that many autonomous agents are susceptible to IPI traps.</p>



<p>The company said it identified IPI embedded in multiple websites, where hidden instructions were designed to manipulate the behavior of an AI agent. </p>



<p>In its internal validation across 26 LLMs, 4 models “failed to take appropriate actions,” which, it said, demonstrated “measurable real-world impact, showing that susceptibility varies by model and by the context provided to the LLM alongside the prompt.”</p>



<p>The post added, “as AI agents become a more common interface to the web, the content itself is going to become a larger attack surface, highlighting that AI is a double-edged sword that can streamline workflows while also introducing new avenues for abuse.”</p>



<p><a href="https://www.linkedin.com/in/akm76/" target="_blank" rel="noreferrer noopener">Aman Mahapatra</a>, chief strategy officer for Tribeca Softtech, a New York City-based technology consulting firm, said that although the results are not surprising, they are significant. </p>



<p>The especially worrisome detail in the report is that any commercial LLM failed at all, “because the security model for agentic AI has historically assumed that model-level safety training would meaningfully attenuate this class of attack,” Mahapatra said. “It does not, and the Zscaler data is the first widely-cited public evidence.”</p>



<h2 class="wp-block-heading">A fundamental architecture issue</h2>



<p>Mahapatra also said that the examples cited by Zscaler are not nearly as concerning as the implications of the greater damage that could occur.</p>



<p>“The Zscaler payment scam scenario, where an agent pays a fake $3 ‘developer license fee’ to obtain an API key, is the most benign version of this,” he said. “The same technique applied to an agent authorized for procurement, expense processing, vendor onboarding, or trade execution produces losses at completely different scales. I have watched Fortune 50 banks stand up agentic workflows in the last six months that would fail exactly this attack in a live examination.”</p>



<p>Indeed, he noted, most AI vendors already understand the magnitude of risk from today’s AI agents.</p>



<p>“Every model provider will admit privately that the fundamental architecture of transformer-based reasoning cannot cleanly separate untrusted content from trusted instructions when both share the context window,” Mahapatra said. “The attack surface is architectural, not just behavioral. That means the defense has to be architectural too, and this is where the enterprise agentic AI conversation is still lagging badly.”</p>



<p>Zscaler’s testing also reinforced the difference in how AI agents and humans process information.</p>



<p>“Humans are skeptical of instructions they did not expect. Agents are eager to follow structured metadata because their training rewards them for treating high-signal fields as authoritative. Humans notice when a payment request appears in the middle of an unrelated task. Agents will thread that payment request into their execution plan if the surrounding context frames it as procedurally necessary,” Mahapatra pointed out, noting that while humans have relationships with vendors, memories of prior interactions, and social context to give them verification signals, agents only have what is in the context window, and, he said, “the context window is now the primary attack surface.”</p>



<p><a href="https://www.infotech.com/profiles/fritz-jean-louis" target="_blank" rel="noreferrer noopener">Fritz Jean-Louis</a>, principal cybersecurity advisor at Info-Tech Research Group, agreed that the risks described in the ZScaler post are concerning, because they are in areas not traditionally addressed by enterprise security.</p>



<p>“These attacks differ from traditional threats in that they target how AI systems process, interpret, and act on information behind the scenes,” Jean-Louis said. “Agentic AI introduces new trust boundaries, including untrusted content influencing automated decision making, tools and plugins acting autonomously on behalf of users, and AI systems operating with broad, inherited permissions. This effectively transforms the challenge into an insider threat paradigm.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[13 in-demand IT security certifications for higher pay]]></title>
<description><![CDATA[With change a constant, cybersecurity professionals looking to improve their careers can benefit from the latest insights into employers’ needs. Data from Foote Partners on the skills and certification most in demand today may provide helpful signposts.



Analyzing more than 660 certifications a...]]></description>
<link>https://tsecurity.de/de/3653485/it-security-nachrichten/13-in-demand-it-security-certifications-for-higher-pay/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653485/it-security-nachrichten/13-in-demand-it-security-certifications-for-higher-pay/</guid>
<pubDate>Wed, 08 Jul 2026 09:08:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With change a constant, cybersecurity professionals looking to improve their careers can benefit from the latest insights into employers’ needs. Data from Foote Partners on the skills and certification most in demand today may provide helpful signposts.</p>



<p>Analyzing more than <a href="https://footepartners.com/pages/report-skills-certs">660 certifications</a> as part of its 2Q 2026 “IT Skills Demand and Pay Trends Report,” Foote Partners calculated the most valuable IT security certifications to pursue right now based on two dimensions. The first, the <a href="https://www.cio.com/article/350363/pay-for-in-demand-it-skills-rises-fastest-in-14-years.html">average pay premium</a>, measures the difference in pay between IT pros with a particular credential and those without it. The second, market value increase, measures the increase in pay gains over the past six months.</p>



<p>Together, average pay premium and market value increase can give cybersecurity pros a starting point in deciding which certification to pursue for more pay. Apart from considering their overall professional goals, security professionals should consider each certification’s training and exam costs, whether vendor-specific or vendor-neutral, and the lateral or vertical role opportunities it may open.</p>



<p>Here are the top 13 certifications paying higher premiums today in descending order.</p>



<h2 class="wp-block-heading">GIAC Security Expert (GSE)</h2>



<p>The <a href="https://www.giac.org/get-certified/giac-portfolio-certifications">GIAC Security Expert</a> (GSE) portfolio certification is for security leaders wishing to prove their status as a top information security practitioner by showing they have offensive and defensive skills and hands-on practical skills. Available for more than 15 years, the GSE is considered one of the broadest and deepest cybersecurity certifications. To earn the certification, candidates must complete any six <a href="https://www.giac.org/get-started/practitioner">practitioner</a> certifications and any four <a href="https://www.giac.org/get-started/applied-knowledge">applied knowledge</a> certifications.</p>



<p>GIAC allows candidates to customize the certification to fit their expertise and career. Candidates can also build their certification over any amount of time as along as the required certifications within the portfolio remain active. Practitioner certification exams are 2-5 hours in length, depending on the specific certification attempt, and applied knowledge certification exams are 4 hours in length.</p>



<p><strong>Training fees:</strong> Some training is offered in affiliation with SANS Institute and costs $8,780.</p>



<p><strong>Exam Fees:</strong> Because you need 10 certifications to achieve the GSE <a href="https://www.giac.org/pricing">prices vary significantly</a>. If you already hold a GIAC Certified Forensic Analyst (GCFA), the cost of one of the required certifications drops from $1,299 to $499. Most required certifications are priced at either $999 or $1,299 per attempt, though they can cost up to $11,190.</p>



<h2 class="wp-block-heading">GIAC Security Professional (GSP)</h2>



<p>The <a href="https://www.giac.org/get-certified/giac-portfolio-certifications">GIAC Security Professional (GSP)</a> is designed to demonstrate the holder’s depth and breadth of information security knowledge. Launched approximately two years, this newer certification is the halfway point to the GSE. Customization of the certification is allowed, and to achieve it a candidate must complete any three <a href="https://www.giac.org/get-started/practitioner">practitioner</a> certifications and any two <a href="https://www.giac.org/get-started/applied-knowledge">applied knowledge</a> certifications. Candidates can also build their certification over any amount of time as along as the required certifications within the portfolio remain active. Practitioner Certification exams are 2-5 hours in length, depending on the specific certification attempt, and Applied Knowledge Certification exams are 4 hours in length.</p>



<p><strong>Training fees:</strong> Some training is offered in affiliation with SANS Institute and costs $8,780.</p>



<p><strong>Exam Fees:</strong> Because you need five certifications to achieve the GSP <a href="https://www.giac.org/pricing">prices vary significantly</a>. If you already hold a GIAC Security Essentials (GSEC), the cost of one of the required certifications drops from $1,299 to $499. Most certifications required are priced at either $999 or $1,299 per attempt, though certification can cost up to $5,595.</p>



<h2 class="wp-block-heading">Microsoft Certified Azure Cybersecurity Architect Expert</h2>



<p>Those who earn the <a href="https://learn.microsoft.com/en-us/credentials/certifications/cybersecurity-architect-expert/">Microsoft Certified: Cybersecurity Architect Expert</a> credential are able to translate a cybersecurity strategy into capabilities that protect the assets, business, and operations of an organization. Through the certification process, candidates learn to design, guide the implementation of, and maintain security solutions that follow zero-trust principles and best practices. You’ll also be able to design solutions for governance, risk, and compliance (GRC), security operations, and security posture management.​</p>



<p>As a prerequisite, candidate must have earned one of the following: <a href="https://learn.microsoft.com/en-us/credentials/certifications/azure-security-engineer/">Microsoft Certified: Azure Security Engineer Associate</a>, <a href="https://learn.microsoft.com/en-us/credentials/certifications/identity-and-access-administrator/">Microsoft Certified: Identity and Access Administrator Associate</a>, <a href="https://learn.microsoft.com/en-us/credentials/certifications/security-operations-analyst/">Microsoft Certified: Security Operations Analyst Associate</a> certification.</p>



<p><strong>Training fees: </strong>Self-paced training is available from the course’s page and free of charge. There is also an option to find an instructor-led training with pricing starting at $1,300.</p>



<p><strong>Exam Fees:</strong> The exam costs $165 and Microsoft offers free practice assessments.</p>



<h2 class="wp-block-heading">Certificate of Cloud Security Knowledge (CCSK)</h2>



<p>As a certificate and not a certification — an important distinction — the Cloud Security Alliance (CSA) positions its <a href="https://cloudsecurityalliance.org/education/ccsk">Certificate of Cloud Security Knowledge</a> as the foundation for future credentials and upskilling in the sector. From this perspective, the CCSK is helpful for cybersecurity analysts, compliance managers, security engineers, architects, and administrators. This vendor-neutral certificate has been recently updated and covers topics in zero trust, DevSecOps, cloud telemetry and security analytics, artificial intelligence, and more. CCSK offers a variety of training modalities, including an exam prep kit, instructor-led classes offered virtually and in person, and an online self-paced option. Candidates must score at least 80% on the exam, randomly pulling 60 multiple-choice questions from a test bank.</p>



<p><strong>Training fees:</strong> Prices vary based on modality. A self-paced course<a href="https://cloudsecurityalliance.org/education/ccsk#preparing-for-the-ccsk"> and exam bundle costs $795</a>, and online, instructor-led training begins at<a href="https://cloudsecuritypass.com/training/"> </a><a href="https://cloudsecuritypass.com/training/">$995</a>.</p>



<p><strong>Exam fees:</strong> The exam costs $445, though discounts are<a href="https://cloudsecurityalliance.org/membership"> available for corporate members</a>, and<a href="https://cloudsecurityalliance.org/education/ccsk/free-for-veterans"> </a><a href="https://cloudsecurityalliance.org/education/ccsk/free-for-veterans">US military veterans can take it for free</a>.</p>



<h2 class="wp-block-heading">Certified in Risk and Information Systems Control (CRISC)</h2>



<p>Administered by ISACA, the<a href="https://www.isaca.org/credentialing/crisc"> </a><a href="https://www.csoonline.com/article/571249/crisc-certification-your-ticket-to-the-c-suite.html">Certified in Risk and Information Systems Control</a> certification provides candidates with training across four domains: corporate IT governance, risk assessment, risk response and reporting, and technology and security. CRISC is ideal for candidates who want to enhance and optimize business resilience and risk management across their organization. The exam consists of 150 questions across the four domains. Since ISACA began offering CRISC in 2010, more than 23,000 people have obtained the certification. ISACA claims 52% of certificate holders experienced on-the-job improvement, and CRISC is the “4th top-paying certification worldwide.” To qualify for CRISC, candidates must adhere to a code of professional ethics and have <a href="https://support.isaca.org/s/article/What-are-the-requirements-to-become-CRISC-certified">three years of work experience</a> in risk assessment and risk response and reporting. On passing the exam, candidates must submit 20 CPE credits annually and<a href="https://www.isaca.org/-/media/files/isacadp/project/isaca/certification/crisc/crisc-cpe/crisc-cpe-policy.pdf"> </a><a href="https://www.isaca.org/-/media/files/isacadp/project/isaca/certification/crisc/crisc-cpe/crisc-cpe-policy.pdf">120 continuing professional education (CPE) hours</a> every three years to maintain their CRISC.</p>



<p><strong>Training fees:</strong> ISACA offers three resources: an<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004Km4PEAS"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000001VR1l2AG">online review course</a>, $895; a review manual in<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004Tx3aEAC"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000001FWgY2AW">print</a> or<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004Tx60EAC"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000001FoOv2AK">digital</a>, $139; and an<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004Ko5TEAS"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000001IPKL2A4">annual subscription to a 833-question test bank</a>, $399. Discounts are available for ISACA members.</p>



<p><strong>Exam fees: </strong>$575, ISACA members; $760 for non-members; plus $50 application fee.</p>



<h2 class="wp-block-heading">Certified Information Systems Auditor (CISA)</h2>



<p>The Information Systems Audit and Control Association (ISACA)’s CISA is geared toward IT auditors who wish to upskill or earn a pay boost. According to ISACA, 70% of CISA holders report on-the-job improvement, and another 22% receive a raise. The course covers five domains: information systems auditing, implementation, and operations; protection of information assets; and IT governance. The<a href="https://www.isaca.org/-/media/files/isacadp/project/isaca/certification/exam-candidate-guides/2024/exam-candidate-guide-2024.pdf"> </a>four-hour exam consists of 150 multiple-choice questions, and candidates must earn 450 on ISACA’s scaled scoring system, with 800 representing a perfect score. To<a href="https://www.isaca.org/credentialing/cisa/maintain-cisa-certification"> </a><a href="https://www.isaca.org/credentialing/cisa/maintain-cisa-certification">maintain their CISA</a>, certification holders must take 20 CPE credits annually and 120 over three years through conferences, volunteering, on-demand learning, and other methods as well as paying maintenance fee. To qualify, you must have five years of experience in IT or IS audit, control, assurance, or security. You can apply for an experience waiver for up to three years.</p>



<p><strong>Training fees:</strong> ISACA offers four resources: an<a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000000Fqvx2AC"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2SVQ000000Fqvx2AC">online review course</a> for $895, an<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000008KxGWEA0"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000008KxGWEA0">annual subscription to a question bank</a> for $399, and a print or digital<a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004W2rOEAS"> </a><a href="https://store.isaca.org/s/store#/store/browse/detail/a2S4w000004W2rOEAS">review manual</a> for $139. Discounts are available for ISACA members. </p>



<p><strong>Exam fees:</strong> $575, members; $760, non-members; plus $50 application fee.</p>



<h2 class="wp-block-heading">Certified Information Systems Security Professional (CISSP)</h2>



<p><a href="https://www.csoonline.com/article/570239/cissp-certification-requirements-training-and-cost.html">CISSP</a> is a generalist cert from ISC2 aimed at security pros who have already established a strong track record. Advanced-level analysts interested in getting CISSP certified will need to know all the ins and outs of security and risk management, asset security, operations, security assessment and testing, and more. The CISSP certification requires five years of full-time experience in at least two of its <a href="https://www.isc2.org/certifications/cissp#The%20CISSP%20Exam">eight domains</a>. The exam is <a href="https://www.isc2.org/Certifications/CISSP/CISSP-CAT">adaptive</a>, ranging from 100 to 150 questions, including multiple-choice and advanced items of varying formats. Candidates need to score 700 points out of 1,000 to pass the exam.</p>



<p><strong>Training fees:</strong><a href="https://www.isc2.org/training/online-self-paced/cissp-online-self-paced"> </a>Online self-paced training <a href="https://www.isc2.org/training#CISSP">fees start</a> at $595 and can cost up to $1,993;<a href="https://www.isc2.org/training/online-instructor-led/cissp-online-instructor-led"> </a>online instructor-led bootcamp costs $2,880.</p>



<p><strong>Exam fee:</strong><a href="https://www.isc2.org/register-for-exam/isc2-exam-pricing"> </a><a href="https://www.isc2.org/register-for-exam/isc2-exam-pricing">$749</a></p>



<h2 class="wp-block-heading">Certified Secure Software Lifecycle Professional (CSSLP)</h2>



<p>This ISC2 certification helps cyber pros build their career by training them to better incorporate security practices throughout software development phases. The <a href="https://www.isc2.org/certifications/csslp">CSSLP</a> exam evaluates experience across eight domains: secure software concepts; secure software; lifecycle management; secure software requirements; secure software architecture and design; secure software implementation; secure software testing; secure software deployment, operations, maintenance; secure software supply chain. Those wishing to acquire the CSSLP must have four years of paid work experience as a software development lifecycle professional in one or more of the eight domains.</p>



<p><strong>Training fees:</strong><a href="https://www.isc2.org/training/online-self-paced/cissp-online-self-paced"> </a>Online self-paced training <a href="https://www.isc2.org/training#CSSLP">fees start</a> at $550 and can cost up to $1,718; online instructor-led bootcamp costs $2,650.</p>



<p><strong>Exam fee:</strong> <a href="https://www.isc2.org/register-for-exam/isc2-exam-pricing">$599</a></p>



<h2 class="wp-block-heading">Check Point Certified Security Master (CCSM)</h2>



<p>To become a <a href="https://www.checkpoint.com/services/training/certification-program/">Check Point Certified Security Master (CCSM) </a>security professionals must have an active Certified Security Expert (CCSE) and mast have completed two subsequent Check Point Specialist accreditations. CCSM validates advanced expertise in configuring, deploying, and troubleshooting Check Point solutions. Check Point certifications are valid for 24 months.</p>



<p><strong>Training fees:</strong><a href="https://www.isc2.org/training/online-self-paced/cissp-online-self-paced"></a> <a href="https://securityservices.checkpoint.com/categories/trainingprograms">Training for CCSE</a> is $3,500</p>



<p><strong>Exam fee:</strong> The fee for CCSE is $300</p>



<h2 class="wp-block-heading">GIAC Experienced Cybersecurity Specialist (GX-CS)</h2>



<p>The <a href="https://www.giac.org/certifications/experienced-cyber-security-gxcs">Experienced Cybersecurity Specialist (GX-CS)</a> sits within the applied knowledge certifications with GIAC. The certification is for practitioners to show their qualifications for advanced, hands-on IT systems roles across cybersecurity. Its intent is to demonstrate the candidate can navigate evolving real-world threats. The certification covers five areas: network security analysis and tools; evaluation of Windows and Linux OS security; advanced security tools and techniques; common attacks and defenses; and implementing overall cybersecurity and information security. The GX-CS is for <a href="https://www.giac.org/certifications/security-essentials-gsec">GSEC</a> holders who acquired additional experience — the GSEC exam costs $999, and SANS Institute offers <a href="https://www.sans.org/cyber-security-courses/security-essentials">training</a> for GSEC.</p>



<p><strong>Training fees:</strong><a href="https://www.isc2.org/training/online-self-paced/cissp-online-self-paced"></a> There are a few related affiliate training programs provided by SANS, each costing approximately $9,000.</p>



<p><strong>Exam fee: </strong>$499 for those with an active GSEC; otherwise <a href="https://www.giac.org/pricing">$1,299</a>.</p>



<h2 class="wp-block-heading">OffSec Certified Professional (OSCP+)</h2>



<p>To earn the<a href="https://www.offsec.com/courses/pen-200/"> </a><a href="https://www.offsec.com/courses/pen-200/">OffSec Certified Professional</a> certification, candidates must complete the affiliated course, PEN-200: Penetration Testing with Kali Linux, and pass the subsequent exam. The course covers 20 plus modules, including information gathering, vulnerability scanning, encryption and cryptography, Active Directory and AWS exploitation, and more. Certificate holders will have shown mastery of penetration testing methodologies ideal for new roles, such as an ethical hacker, incident responder, or threat hunter. The OSCP+ exam is entirely hands-on, and test-takers must compromise systems within a lab environment.</p>



<p>OffSec does not enforce any prerequisites but recommends candidates be familiar with TCP/IP networking, scripting in Bash and Python, and Linux and Windows, which they can learn through its<a href="https://www.offsec.com/learning/paths/network-penetration-testing-essentials/"> </a><a href="https://www.offsec.com/learning/paths/network-penetration-testing-essentials/">Network Penetration Testing Essentials Learning Path</a>.</p>



<p><strong>Training and exam fees:</strong> OffSec bundles the course and exam for $1,749 and as a yearly subscription that includes access to one 200 or 300-level course, the associated labs, and two exam attempts for $2,749 annually.</p>



<h2 class="wp-block-heading">OffSec Experienced Penetration Tester (OSEP)</h2>



<p>The<a href="https://www.offsec.com/courses/pen-300/"> </a><a href="https://www.offsec.com/courses/pen-300/">OffSec Experienced Penetration Tester</a> is ideal for penetration testers and ethical hackers who need more advanced techniques to sharpen offensive skills against modern enterprise defenses. Across more than 20 modules, the certification introduces these professionals to advanced offensive techniques, EDR and AV evasion, advanced Windows offensive security and more. During the two-day proctored exam, professionals must connect to a lab environment via a VPN and compromise multiple machines within a network through several possible attack paths. To pass, professionals must achieve the objective stated within the control panel or score at<a href="https://help.offsec.com/hc/en-us/articles/360049781352-OSEP-Exam-FAQ"> </a><a href="https://help.offsec.com/hc/en-us/articles/360049781352-OSEP-Exam-FAQ">least 100 points</a> — 10 points are awarded for every flag found in a local.txt or proof.txt file. Professionals who earn their OSEP can also obtain their<a href="https://www.offsec.com/certificates/osce3/"> </a><a href="https://www.offsec.com/certificates/osce3/">OSCE³ Certification</a> to demonstrate their mastery of offensive security. They would also need to pass the exams for WEB-300: Advanced Web Attacks and Exploitation and EXP-301: Windows User Mode Exploit Development, after which the OSCE³ is automatically awarded.</p>



<p>While there are no formal prerequisites for OSEP, OffSec recommends candidates take the<a href="https://www.offsec.com/courses/pen-200/"> </a><a href="https://www.offsec.com/courses/pen-200/">PEN-200: Penetration Testing</a> with Kali Linux or have a strong foundation in operating systems, networking, and scripting. </p>



<p><strong>Training and exam fees:</strong> OffSec bundles the course and exam for $1,749, and as a yearly subscription that includes access to one 200 or 300-level course, the associated labs, and two exam attempts for $2,749 annually.</p>



<h2 class="wp-block-heading">OffSec Exploitation Expert (OSEE)</h2>



<p>OffSec’s <a href="https://www.offsec.com/courses/exp-401/">Offensive Security Exploitation Expert</a> is a vendor-specific certification, focusing on advanced Windows exploitation, with OffSec deeming it its most challenging certification. As a penetration testing course, the material dives deep into topics such as advanced heap manipulations and disarming WDEG mitigations. Certificate holders can identify problematic code in Windows operating systems and develop exploits. For the practical exam, candidates must complete a comprehensive penetration test of software and create an exploit within a lab environment — all within 72 hours. To qualify, you must have experience debugging, developing Windows exploits, and using the following technologies: WinDBG, x86_64, IDA Pro, and basic C/C++ programming. OffSec recommends completing its<a href="https://www.offsec.com/courses-and-certifications/"> </a><a href="https://www.offsec.com/courses-and-certifications/">300-level certifications</a> before OSEE.</p>



<p><strong>Training and exam fees:</strong> OffSec offers only instructor-led, in-person training. Enterprises should <a href="https://www.offsec.com/organizations/live-training/">inquire for more information</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4678: High Resolution Elapsed Time in Shell Scripts]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.






01 Introduction






In this episode I will describe how to calculate elapsed time in bash or other shell scripts.


While this may sound like a very simple and basic thing to do, there is a slightly more complex aspect to it if you wi...]]></description>
<link>https://tsecurity.de/de/3652976/podcasts/hpr4678-high-resolution-elapsed-time-in-shell-scripts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652976/podcasts/hpr4678-high-resolution-elapsed-time-in-shell-scripts/</guid>
<pubDate>Wed, 08 Jul 2026 02:03:40 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>

</p>

<p>
01 Introduction</p>

<p>

</p>

<p>
In this episode I will describe how to calculate elapsed time in bash or other shell scripts.</p>

<p>
While this may sound like a very simple and basic thing to do, there is a slightly more complex aspect to it if you wish to calculate elapsed time to a higher resolution than one second. </p>

<p>

</p>

<p>
02</p>

<p>
There are many reasons for calculating elapsed time in a shell script.</p>

<p>
For example you may wish to simply report how long an operation took to run.</p>

<p>
Another reason may be that you are trying to speed up a script and need to calculate benchmark data to see how different alternative methods perform.</p>

<p>

</p>

<p>
03</p>

<p>
What may seem like a simple task gets a bit more complicated if you want to do it for multiple different operating systems even if they are all unix related, as we shall see.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
04 Operating Systems Tested</p>

<p>

</p>

<p>
For the purposes of this episode, I ran tests on the current version of the following operating systems.</p>

<p>

</p>

<p>
Alma</p>

<p>
Alpine</p>

<p>
Debian</p>

<p>
FreeBSD</p>

<p>
OpenBSD</p>

<p>
RaspberryPi</p>

<p>
OpenSuse</p>

<p>
Ubuntu 2604</p>

<p>

</p>

<p>
Alma is a close copy of Red Hat that we can take as representing Red Hat style distros. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
05 Simple Low Resolution Timing</p>

<p>

</p>

<p>
I will start with the simple and obvious method before describing the less obvious ones.</p>

<p>

</p>

<p>
This uses the date command to get the current time in seconds since the unix epoch. </p>

<p>
This is simply</p>

<p>
date '+%s'</p>

<p>

</p>

<p>
06</p>

<p>
Save this to a variable using whatever method you prefer.</p>

<p>
For example.</p>

<p>
starttime=$(date '+%s')</p>

<p>

</p>

<p>
07</p>

<p>
Next, do whatever operations it is you wish to time.</p>

<p>
Use the date command to get the current time again.</p>

<p>
endtime=$(date '+%s')</p>

<p>

</p>

<p>
08</p>

<p>
Now simply subtract the start time from the end time using shell arithmetic.</p>

<p>
This should be very obvious and basic.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
09 Higher Resolution Timing</p>

<p>

</p>

<p>
However, suppose we wish to measure time to greater than one second of precision. </p>

<p>
We need to do two things.</p>

<p>
The first is to obtain the current time at a higher degree of precision.</p>

<p>
The second is to conduct the calculations to a higher degree of precision. </p>

<p>

</p>

<p>
10</p>

<p>
Unfortunately, the standard time precision for POSIX shells seems to be 1 second.</p>

<p>
Some shells offer a higher precision, but others do not.</p>

<p>
Furthermore, standard shell arithmatic uses integer, which limits calculations to 1 second of precision.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
11 Bash High Resolution Shell Variable</p>

<p>

</p>

<p>
Fortunately, bash is one that does offer a high precision date.</p>

<p>

</p>

<p>
If you are using bash 5.0 or newer, there is a shell variable called EPOCHREALTIME which offers time since the the unix epoch (that is, since the first of January 1970, at 00:00:00 UTC) in seconds to 6 decimals of precision.</p>

<p>

</p>

<p>
12</p>

<p>
Example</p>

<p>
echo $EPOCHREALTIME</p>

<p>
1779634800.184926</p>

<p>

</p>

<p>
13</p>

<p>
This is related to the similar bash variable known as EPOCHSECONDS which gives the number of seconds since the unix epoch.</p>

<p>

</p>

<p>
14</p>

<p>
Example</p>

<p>
echo $EPOCHSECONDS</p>

<p>
1779634800</p>

<p>

</p>

<p>
15</p>

<p>
So if you are using bash, measuring time is very simple.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
16 But is it Really Bash?</p>

<p>

</p>

<p>
Is your script however actually using bash?</p>

<p>
Debian and derivatives actually have two shells.</p>

<p>
The first, the interactive shell is bash.</p>

<p>
The second, the non-interactive shell is dash, which stands for "debian almquist shell".</p>

<p>

</p>

<p>
17</p>

<p>
If you open a terminal, you get bash.</p>

<p>
If your script starts with a "bin/bash" shebang line, you get bash.</p>

<p>
However, if your script starts with a "bin/sh" shebang line, you get dash.</p>

<p>
Some people find themselves getting caught out by this one when they try something out in a terminal but find that it doesn't work in their script which started with "bin/sh".</p>

<p>

</p>

<p>
18</p>

<p>
Many other, but not all, Linux distros use bash for both the interactive and non-interactive shells, so "bin/sh" and "bin/bash" work the same with those ones.</p>

<p>

</p>

<p>
So if you intend to use bash, make sure your script calls for bash in the first line.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
19 The SHELL Variable</p>

<p>

</p>

<p>
So how can a script tell what shell it is running under?</p>

<p>
There is a shell variable called "SHELL" which will tell you the name of the shell.</p>

<p>
Well, sort of.</p>

<p>

</p>

<p>
20</p>

<p>
On Debian and derivatives "SHELL" will  say "bash" regardless of whether the actual shell is bash or dash.</p>

<p>
On some other operating systems "SHELL" will simply say "sh" even if it is something else entirely.</p>

<p>

</p>

<p>
So we need to do some additional levels of checking to see what we have. </p>

<p>

</p>

<p>
21</p>

<p>
To start with though, here's what each of the test distros reports for SHELL.</p>

<p>

</p>

<p>
Alma              : bash</p>

<p>
Alpine            : sh</p>

<p>
Debian            : bash</p>

<p>
FreeBSD           : sh</p>

<p>
OpenBSD           : ksh</p>

<p>
Raspberry-Pi      : bash</p>

<p>
Suse              : bash</p>

<p>
ubuntu2604        : bash</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
22 Bash Versus Dash</p>

<p>

</p>

<p>
First, let's try to see which ones are bash and which ones are dash.</p>

<p>

</p>

<p>
The first thing we can check is for the shell variable BASH_VERSION.</p>

<p>

</p>

<p>
23</p>

<p>
Example</p>

<p>
echo $BASH_VERSION</p>

<p>

</p>

<p>
If the shell is bash, then it will report a version string.</p>

<p>
If the shell is not bash, then it will return an empty value.</p>

<p>

</p>

<p>
24</p>

<p>
Using this test, we can see that Alma and Opensuse are indeed using bash.</p>

<p>

</p>

<p>
We however need to check Debian, Raspberry Pi, and Ubuntu when running in an "sh" script.</p>

<p>
To check this we can use the  "which" command to see what "sh" actually is.</p>

<p>

</p>

<p>
25</p>

<p>
Example</p>

<p>
echo $( ls -l $(which sh )  | rev | cut -d" " -f1 | cut -d/ -f1 | rev )</p>

<p>

</p>

<p>
26</p>

<p>
"which sh" shows us the path to "sh"</p>

<p>
However, that is a link so we need to use</p>

<p>
"ls -l" to find the actual executable.</p>

<p>
"rev" reverses the string.</p>

<p>

</p>

<p>
27</p>

<p>
"cut" takes the first element separated by spaces.</p>

<p>
The second </p>

<p>
"cut" takes the first element separated by the "/" characters.</p>

<p>
The final "rev" takes that string and reverses it again to get it in the correct order.</p>

<p>

</p>

<p>
28</p>

<p>
In the case of Debian, Raspberry Pi, and Ubuntu it tells us that this is "dash".</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
29 Openbsd</p>

<p>

</p>

<p>
Openbsd reports its shell as "ksh", which stands for Korn Shell. </p>

<p>
It is indeed Korn Shell, so we simply leave that one as is.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
30 Alpine and Freebsd</p>

<p>

</p>

<p>
Next we have Alpine Linux and Freebsd, which both report as "sh".</p>

<p>

</p>

<p>
In the case Freebsd there doesn't appear to be any further we can go that I am aware of.</p>

<p>
It's simple "sh".</p>

<p>
It is a basic POSIX shell which seems to be similar to the original unix shell, the Bourne Shell.</p>

<p>
Older versions of Freebsd used a different shell known as tsch (the C shell), but I haven't tested that so I will ignore that here.</p>

<p>

</p>

<p>
31</p>

<p>
With Alpine Linux however, we can get the actual shell using the same method that we used for Debian Linux.</p>

<p>
This reports as being "busybox".</p>

<p>

</p>

<p>
32</p>

<p>
Busybox is a limited shell intended for use in embedded systems.</p>

<p>
Alpine was originally an embedded distro, but some people started using it for containers.</p>

<p>
Alpine is Linux, but it is not GNU/Linux, and there are a number of areas which can trip you up if you are not aware of them.</p>

<p>
So, be extra careful if you are using it for anything, and test everything.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
33 Summary of Actual Shells</p>

<p>

</p>

<p>
Here is our revised list with the actual shell used when asking for "sh", so far as we can determine.</p>

<p>

</p>

<p>
Alma              : bash</p>

<p>
Alpine            : busybox</p>

<p>
Debian            : dash</p>

<p>
FreeBSD           : sh</p>

<p>
OpenBSD           : ksh</p>

<p>
Raspberry-Pi      : dash</p>

<p>
Suse              : bash</p>

<p>
ubuntu2604        : dash</p>

<p>

</p>

<p>
34</p>

<p>
There are other shells, but none of them are the default shell for any of the distros on our list, so I haven't tested them.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
35 Solutions for Measuring Time</p>

<p>

</p>

<p>
Now we need to find solutions for bash, dash, ksh, sh, and busybox.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
36 Bash</p>

<p>

</p>

<p>
For bash, we can simply use EPOCHREALTIME, as mentioned above.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
37 Dash</p>

<p>

</p>

<p>
For dash, we can use the date command.</p>

<p>
This is a very conventional method, and is probably the first answer that anyone would give for this situation.</p>

<p>
However, while it will work in most cases, it will not work in all cases, so it is not a universal solution.</p>

<p>

</p>

<p>
38</p>

<p>
To use date we simply call it with the correct format string.</p>

<p>
This uses %s to get seconds since the epoch, and %N to get nanoseconds of the current second.</p>

<p>
If you put a decimal separator between the two it will appear in the output.</p>

<p>
You can use the correct decimal separator for your locale, but I won't go into that here.</p>

<p>
Instead I will just assume a period or dot.</p>

<p>

</p>

<p>
39</p>

<p>
Example</p>

<p>
date '+%s.%N' </p>

<p>
1779634800.358916385</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
40 Problems with Date on Alpine and Openbsd</p>

<p>

</p>

<p>
Date will work for bash, dash, and sh on Freebsd.</p>

<p>
However it will not work for ksh on Openbsd, or for busybox on Alpine.</p>

<p>

</p>

<p>
41</p>

<p>
With busybox on Alpine, it simply ignores the %N format specifier and prints out the epoch in seconds only followed by the decimal separator.</p>

<p>
=</p>

<p>
Example</p>

<p>
date '+%s.%N'</p>

<p>
1779634800.</p>

<p>

</p>

<p>
42</p>

<p>
With ksh on Openbsd it prints the epoch in seconds followed by the decimal separator and then the %N as a literal N.</p>

<p>

</p>

<p>
date '+%s.%N'</p>

<p>
1779634800.N</p>

<p>

</p>

<p>
43</p>

<p>
Fortunately we have alternatives for these two cases.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
44 Openbsd</p>

<p>

</p>

<p>
Openbsd has the "ts" or timestamp utility installed by default.</p>

<p>
ts prints a time stamp in front of every line it receives from standard input.</p>

<p>
I won't go into details on all aspects of ts here, I'll leave that to someone else.</p>

<p>
Instead I will focus on how to use it for our specific purposes here.</p>

<p>

</p>

<p>
45</p>

<p>
We need to provide a format specifier to ts, which in this case is "%.s"</p>

<p>
We also need to provide something for standard input, or otherwise ts will simply sit there and wait for input.</p>

<p>
So what we need to do is to echo nothing through a pipe to ts while also giving ts the proper format specifier.</p>

<p>

</p>

<p>
46</p>

<p>
Example</p>

<p>
 echo | ts "%.s" </p>

<p>

</p>

<p>
47</p>

<p>
This will output the epoch time in seconds to six decimals of precision.</p>

<p>

</p>

<p>
ts is installed in Openbsd and Freebsd by default and can be used in either.</p>

<p>
It can also be installed in many other distros.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
48 Busybox on Alpine</p>

<p>

</p>

<p>
None of the methods discussed so far will work for busybox on Alpine though.</p>

<p>
However there is a way, but it's a bit non obvious and somewhat hacky.</p>

<p>

</p>

<p>
49</p>

<p>
Busybox includes a command called "adjtimex".</p>

<p>
This is normally used to adjust the time hardware.</p>

<p>
However if it is run without arguments, it will report the current settings.</p>

<p>

</p>

<p>
50</p>

<p>
These include the current epoch time in seconds , and in another field the time in microseconds.</p>

<p>
These are reported as key value pairs.</p>

<p>
So what we need to do is to do the following</p>

<p>

</p>

<p>
51</p>

<p>
Run adjtimex</p>

<p>
Capture the output.</p>

<p>
Grep for "time.tv_sec"</p>

<p>
Grep for "time.tv_usec"</p>

<p>
Use cut to extract the time value in each case.</p>

<p>
Use tr to get rid of excess spaces in each case.</p>

<p>
Combine the two in a string with a decimal separator between them.</p>

<p>

</p>

<p>
52</p>

<p>
This takes a total of 4 lines of shell script. </p>

<p>
I will just describe them breifly here, see the show notes for details.</p>

<p>

</p>

<p>
53</p>

<p>
First we want to capture the output of adjtimex in a single operation.</p>

<p>
Run adjtimex and pipe the output through grep to capture lines containing "time.tv_"</p>

<p>
and save this to a variable. </p>

<p>

</p>

<p>
# Extract the current high resolution time from adjtimex.</p>

<p>
# We want two key value pairs, identified by time.tv_sec and time.tv_usec.</p>

<p>
tvals=$( adjtimex | grep "time.tv_" )</p>

<p>

</p>

<p>
54</p>

<p>
Next echo the contents of this variable and pipe it through grep, cut, and tr to get first the seconds and then the microseconds while also removing excess spaces.</p>

<p>
Save these to two separate variables.</p>

<p>
"time.tv_sec" is the time in seconds since the epoch.</p>

<p>
"time.tv_usec" is the number of microseconds in the current second.</p>

<p>

</p>

<p>
# Get the time since the unix epoch in seconds and micro-seconds.</p>

<p>
timesec=$( echo "$tvals" | grep "time.tv_sec" | cut -d: -f2 | tr -d " " )</p>

<p>
timeusec=$( echo "$tvals" |  grep "time.tv_usec" | cut -d: -f2 | tr -d " " )</p>

<p>

</p>

<p>
55</p>

<p>
Adjtimex does not zero pad the microsecond time value to provide leading zeros, so we need to take care of this using printf before we can append it to the seconds value. We didn't need to do this with date where the %N format character does this automatically.</p>

<p>

</p>

<p>
In this instance, the  printf format string is '%06d'</p>

<p>

</p>

<p>
padusec=$( printf '%06d' $timeusec )</p>

<p>

</p>

<p>
Now, combine these into a single number with a decimal separator by using simple string concatenation.</p>

<p>
# Combine them into a single number.</p>

<p>
timehires="$timesec"".""$padusec"</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
56 Summary of Methods</p>

<p>

</p>

<p>
Let's summarize where we are so far in terms of methods we can use to get the current time as a high resolution number.</p>

<p>

</p>

<p>
Alma                : use EPOCHREALTIME or date</p>

<p>
Debian (bash)       : use EPOCHREALTIME or date</p>

<p>
Raspberry-Pi (bash) : use EPOCHREALTIME or date</p>

<p>
ubuntu2604 (bash)   : use EPOCHREALTIME or date</p>

<p>
Suse                : use EPOCHREALTIME or date</p>

<p>
Debian (dash)       : use date</p>

<p>
Raspberry-Pi (dash) : use date</p>

<p>
ubuntu2604 (dash)   : use date</p>

<p>
Alpine              : use adjtimex and parse the output</p>

<p>
FreeBSD             : use date or ts</p>

<p>
OpenBSD             : use ts</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
57 Other alternatives</p>

<p>

</p>

<p>
There are a few alternatives that we haven't discussed yet.</p>

<p>

</p>

<p>
58 Bash with Dash</p>

<p>

</p>

<p>
In the case of Debian, Raspberry Pi, and Ubuntu running dash, since bash is available it is possible to write a separate bash script which simply echos EPOCHREALTIME and then call it from the dash script and capture the output. </p>

<p>

</p>

<p>
While this would work, there's probably not a lot of point to it.</p>

<p>
If you can rely on bash being there, then just change the first line of the script and make it a bash script.</p>

<p>

</p>

<p>
59 Adding Packages to Alpine</p>

<p>

</p>

<p>
The ts or timestamp utility is a common unix utility that can be installed if it is not present by default.</p>

<p>
This does produce high resolution timestamps on Alpine.</p>

<p>
On Alpine Linux this comes as part of the "moreutils" package.</p>

<p>
To add the package, use the following</p>

<p>
sudo apk add moreutils</p>

<p>
echo | ts "%.s" </p>

<p>
1779634800.959948 </p>

<p>

</p>

<p>
60</p>

<p>
You can also add the GNU coreutils, which will provide a high resolution date command which works like in the other examples.</p>

<p>
To add the package use the following</p>

<p>
sudo apk add coreutils</p>

<p>
date '+%s.%N'</p>

<p>
1779634800.212897332</p>

<p>

</p>

<p>
61</p>

<p>
If you can install more packages into your Alpine system, either of the above two is probably going to be preferable to parsing the output of adjtimex.</p>

<p>

</p>

<p>
62 Custom Timestamp Programs</p>

<p>

</p>

<p>
You can also write a very short program in python, perl, tcl, or some other language and have it output the current epoch time.</p>

<p>
I won't discuss that here though.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
63 Calculating Time Differences</p>

<p>

</p>

<p>
Shell arithmetic is integer only.</p>

<p>
If we wish to use high resolution timing data, we need to do something so we don't lose the precision we have worked so hard to get.</p>

<p>
There are several possible solutions.</p>

<p>

</p>

<p>
64 Change the Time Base</p>

<p>
One method is to change the time base from seconds to milli, micro, or nanoseconds. </p>

<p>
This can be done by simply multiplying the time values by the appropriate amount (e.g. 1000, 1,000,000, etc.) before subtracting them.</p>

<p>
This allows for integer arithmetic on high resolution values without losing precision.</p>

<p>

</p>

<p>
65 Use the Shell bc Arbitrary Precision Calculator</p>

<p>
The bc command line calculator will perform calculations using real numbers and is easy to use in scripts.</p>

<p>
It is present by default in most distros.</p>

<p>

</p>

<p>
echo "scale=9; $endtime - $starttime" | bc</p>

<p>

</p>

<p>
where endtime and starttime are variables containing time values.</p>

<p>

</p>

<p>
66</p>

<p>
However, for some inexplicable reason, neither Debian nor Opensuse install it by default.</p>

<p>
It is present in Ubuntu and Raspberry Pi which are Debian derivatives, and it can be added to distros which lack it.</p>

<p>

</p>

<p>
67 Use awk</p>

<p>
awk can also perform calculations using real numbers and it is present in nearly all distros including in all of the ones we tested here.</p>

<p>

</p>

<p>
echo "$endtime $starttime" | awk '{printf "%.6f\n", $1 - $2}'</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
68 Benchmarks</p>

<p>

</p>

<p>
And of course no comparative evaluation would be complete without benchmarks where we see how each method compares to another in terms of speed.</p>

<p>

</p>

<p>
In the benchmark test I ran each method in a loop through multiple iterations, measured the elapsed time, subtracted out the time for an empty loop, and then compared it to alternate methods.</p>

<p>
For anything other than EPOCHREALTIME, the empty loop time is negligible and has no real effect on the results.</p>

<p>

</p>

<p>
69</p>

<p>
Rather interestingly I came across a bug which caused date to run very slowly if called immediately after using EPOCHREALTIME in bash.</p>

<p>
The effect of the bug was to make the date benchmark test roughly 24 times slower.</p>

<p>

</p>

<p>
This has been fixed in newer releases, but if you are using an older distro release then beware of this bug.</p>

<p>
I was able to get around it either putting a sleep delay between benchmarking  EPOCHREALTIME and benchmarking date, or by simply testing date before testing EPOCHREALTIME.</p>

<p>

</p>

<p>
70</p>

<p>
To be able to conduct additional tests I installed ts in Ubuntu and Alpine, and the GNU version of date in Alpine.</p>

<p>

</p>

<p>

</p>

<p>
71 EPOCHREALTIME Versus date in Ubuntu 2604 bash</p>

<p>
The EPOCHREALTIME method is 3103 times faster than date.</p>

<p>

</p>

<p>
However, when the same test is run on Ubuntu 2404 when the date test is run before the EPOCHREALTIME test, EPOCHREALTIME is 1240 faster than date.</p>

<p>
Other Linux distros show performance to Ubuntu 2404.</p>

<p>
It appears that a side effect of fixing whatever the bug is has the effect of slowing down date.</p>

<p>
However, this is probably not a significant issue in normal circumstances. </p>

<p>

</p>

<p>
72 date versus ts in Ubuntu 2604 bash</p>

<p>
The date method is 3.7 times faster than ts</p>

<p>

</p>

<p>
73 date versus ts in Ubuntu 2604 dash</p>

<p>
The date method is 4.9 times faster than ts</p>

<p>

</p>

<p>
74 date versus ts in Freebsd sh</p>

<p>
The date method is 2.5 times faster than ts</p>

<p>

</p>

<p>
75 date versus adjtimex in Alpine Busybox</p>

<p>
The date method is 6.0 times faster than adjtimex</p>

<p>

</p>

<p>
76 date versus ts in Alpine Busybox</p>

<p>
The date method is 20.0 times faster than ts</p>

<p>

</p>

<p>
77 bc versus awk in Ubuntu 2604</p>

<p>
I compared calculating the difference between two numbers when using bc versus awk. </p>

<p>
The difference is negligible, with bc being only 7% faster than awk. </p>

<p>

</p>

<p>

</p>

<p>
78 Conclusion for Benchmarks</p>

<p>
Based on these results, if you need to measure elapsed time to high resolution and care about runing the command with as little overhead as possible, then the order of preference should be the following.</p>

<p>

</p>

<p>
79</p>

<p>
If you are using a newer version of bash, then use EPOCHREALTIME.</p>

<p>
If that is not available, then use date, provided it allows for high resolution times.</p>

<p>
If the above two cannot be used, then use ts.</p>

<p>
If you are using Busybox and cannot install either GNU date or ts, then use adjtimex.</p>

<p>

</p>

<p>
Date is the closest in terms of being the universal portable solution, but it does not work in all cases.</p>

<p>

</p>

<p>
80</p>

<p>
I have not compared different platforms to each other in terms of performance, as that would be a much more involved problem that is outside the scope of this episode.</p>

<p>

</p>

<p>
However, different operating systems implement different commands in different ways.</p>

<p>

</p>

<p>
81</p>

<p>
For example, on Openbsd and Freebsd, ts appears to be an ELF binary. That is, it is executable machine code, possibly written in C.</p>

<p>
On  Ubuntu however, ts appears to be a perl script. </p>

<p>
As a result of this, the advantage that date has over ts is much less in Freebsd than it is with Ubuntu (and likely other Linux distros) as on Freebsd it doesn't need to load a perl interpreter to run ts. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
82 Overall Conclusion</p>

<p>
You no doubt thought that measuring elapsed time was going to be so simple, and how could someone get an entire podcast out of such a simple subject?</p>

<p>
And yet here we are half an hour later with just a basic overview of the subject. </p>

<p>

</p>

<p>
83</p>

<p>
I hope you found this interesting and informative.</p>

<p>
Please let us know in the comments if you think that I have done anything incorrectly, or if you have another way of doing things.</p>

<p>

</p>

<p>
I hope to see you all again in another future episode of HPR.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4678/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Protect Older Adults from Financial Scams | Elder Financial Abuse Explained]]></title>
<description><![CDATA[Author: Avast - Bewertung: 0x - Views:4 Financial scams targeting older adults are on the rise — and the most dangerous ones don't start with a threat. They start with a relationship. Romance scams, fake emergency calls, and slow emotional manipulation are some of the most common tactics used to ...]]></description>
<link>https://tsecurity.de/de/3652765/malware-trojaner-viren/how-to-protect-older-adults-from-financial-scams-elder-financial-abuse-explained/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652765/malware-trojaner-viren/how-to-protect-older-adults-from-financial-scams-elder-financial-abuse-explained/</guid>
<pubDate>Tue, 07 Jul 2026 23:03:51 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Avast - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Z7FIol903R0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Financial scams targeting older adults are on the rise — and the most dangerous ones don't start with a threat. They start with a relationship. Romance scams, fake emergency calls, and slow emotional manipulation are some of the most common tactics used to exploit seniors before anyone notices something is wrong. <br />
<br />
In this video, we break down how elder financial abuse actually works, the early warning signs to watch for (like sudden cash withdrawals, unpaid bills, or unusual secrecy around finances), and the practical steps families can take to protect their loved ones — without taking away their independence. <br />
<br />
You'll learn: <br />
<br />
Why urgency and isolation are scammers' most powerful tools <br />
<br />
The behavioral red flags that often appear before financial loss <br />
<br />
How to have open, proactive conversations with older family members about scams <br />
<br />
Why having a trusted emergency contact and a plan in place makes all the difference <br />
<br />
Most people don't think about identity protection until it's too late. Avast Secure Identity helps monitor for suspicious activity, supports recovery if something does go wrong, and helps protect against the financial impact of scams and theft. <br />
<br />
Protecting your family starts before scammers get the chance. <br />
<br />
🔒 Learn more about Avast Secure Identity and start protecting your family today. <br />
<br />
<br />
#ElderFinancialAbuse #ScamAwareness #CyberSafety #OnlineScams #IdentityTheft #SeniorSafety #FinancialScams #RomanceScam #AvastSecureIdentity #Avast #CyberProtection #FamilySafety #ScamPrevention #DigitalSafety #OnlineSafety <br />
<br />
Follow us: <br />
YouTube: @Avast<br />
Instagram: @avast<br />
Facebook: @Avast<br />
LinkedIn: Avast<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gartner: Data center electricity consumption to grow 26% in 2026]]></title>
<description><![CDATA[Power consumption worldwide for data centers is projected to grow to 565 terawatt hours (TWh) in 2026, up 26% from 447 TWh in 2025, with AI-oriented data centers taking up an increasing amount of the pie.



Worldwide data center power demand is expected to rise 27% in 2026 and reach 133 gigawatt...]]></description>
<link>https://tsecurity.de/de/3652683/it-security-nachrichten/gartner-data-center-electricity-consumption-to-grow-26-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652683/it-security-nachrichten/gartner-data-center-electricity-consumption-to-grow-26-in-2026/</guid>
<pubDate>Tue, 07 Jul 2026 22:07:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Power consumption worldwide for <a href="https://www.networkworld.com/article/4117584/power-shortages-carbon-capture-and-ai-automation-whats-ahead-for-data-centers-in-2026.html">data centers</a> is projected to grow to 565 terawatt hours (TWh) in 2026, up 26% from 447 TWh in 2025, with <a href="https://www.neowin.net/news/these-are-the-biggest-ai-data-centers-owned-by-big-tech/">AI-oriented data centers</a> taking up an increasing amount of the pie.</p>



<p>Worldwide data center <a href="https://www.networkworld.com/article/4130979/energy-providers-seek-flexible-load-strategies-for-data-center-operations.html">power demand</a> is expected to rise 27% in 2026 and reach 133 gigawatts (GW), up from 105GW in 2025. It is projected to reach 291GW by 2030, which reflects the unprecedented scale and pace of GenAI boosting demand.</p>



<p>Those figures consider variables like parts and supply shortages, delayed or cancelled data center projects, and the impact of the conflict with Iran, said <a href="https://www.linkedin.com/in/linglan-wang-98b64a30/">Linglan Wang,</a> director analyst and lead economist at Gartner.</p>



<p><a href="https://www.networkworld.com/article/3835113/what-is-an-ai-server-why-artificial-intelligence-needs-specialized-systems.html">AI-optimized servers</a> are a relatively new phenomenon but they have rapidly gained uh traditional data centers in terms of power use. Gartner estimates AI-optimized server adoption will account for 31% of data center power consumption in 2026, and that by 2027 their power consumption will surpass that of conventional servers.</p>



<p>“Surging demand for compute-intensive AI workloads is driving unprecedented data center power growth, while AI capacity is now constrained by power availability, making data center power security the new battle ground for scaling and protecting margins in the global AI race,” said Wang in a statement.</p>



<p>Wang said of the 565TWh consumed this year, the U.S. will account for about 204TWh, or 36% of the total amount consumed. And of the 204TWh consumed this year, dedicated AI data centers will consume 68TWh, or one-third of the total. So in just five years, AI data centers have gone from zero to of the total power consumption in the US.</p>



<p>Non-AI data center growth has been minimal by comparison.</p>



<p>The difference in growth of power consumption between conventional servers and AI-optimized servers is remarkable. Worldwide, conventional servers consumed 193 terawatt hours (TWh) of power in 2025 and are projected to rise 1.2% to 195 TWh in 2026 and another 2.4% in 2027 to 200 TWh This 3% basic growth will continue to 2030.</p>



<p>Now compare that to the AI-optimized servers. They consumed 95 TWh of power in 2025, rose 84.2% to 175 TWh in 2026 and another 47.8% to 258 TWh in 2027. By 2030, Wang estimates AI-optimized servers will account for near half of all power consumed by data centers worldwide.</p>



<p>With data center power electricity consumption estimated to reach over 1,200TWh by 2030, grid supply will be insufficient to meet the demands of future data center construction, affecting all data center users.</p>



<p>“Infrastructure and operations leaders must prioritize efficiency upgrades and secure grid access. They also need to invest in high-efficiency cooling systems and edge computing to mitigate power constraints and ensure sustainable, scalable growth,” Wang said.</p>
</div></div></div></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,70ms -->