<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=printing+business+records+management%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Sat, 08 Aug 2026 00:59:03 +0200</lastBuildDate>
<pubDate>Sat, 08 Aug 2026 00:59:03 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - 📰 Alle Kategorien</copyright>
<managingEditor>tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-isharestuff-com/media/logo.png</url>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=printing+business+records+management%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml?q=printing+business+records+management%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Airtable joins Evernote, Brightcove, WeTransfer and AOL in Bending Spoons portfolio]]></title>
<description><![CDATA[Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo



Airtable made its name as a builder of low/no code database services, aimed particularly at non-technical staff, but is now one of many vendors facing...]]></description>
<link>https://tsecurity.de/de/3710956/ai-nachrichten/airtable-joins-evernote-brightcove-wetransfer-and-aol-in-bending-spoons-portfolio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710956/ai-nachrichten/airtable-joins-evernote-brightcove-wetransfer-and-aol-in-bending-spoons-portfolio/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo</p>



<p class="wp-block-paragraph">Airtable made its name as a builder of <a href="https://www.infoworld.com/article/2334351/airtable-review-flexible-low-code-no-code-in-the-cloud.html">low/no code database services</a>, aimed particularly at non-technical staff, but is now one of many vendors facing financial difficulties in the face of the <a href="https://www.cio.com/article/4192242/agentic-ai-puts-234b-in-enterprise-saas-spending-at-risk-gartner-says.html">SaaS/AIpocalypse</a>. The arrival of AI coding tools, which offer non-technical employees more flexible ways to build business applications, has hit demand for its services.</p>



<p class="wp-block-paragraph">Bending Spoons bought Airtable in a deal it valued at just <a href="https://investors.bendingspoons.com/newsroom/bending-spoons-agrees-to-acquire-airtable">$1.285 billion</a>, a far cry from the <a href="https://www.bloomberg.com/news/articles/2026-08-04/bending-spoons-to-buy-software-firm-airtable-for-2-3-billion" target="_blank" rel="noreferrer noopener">$11.7 billion</a> Airtable was worth at its peak.</p>



<p class="wp-block-paragraph">Bending Spoons has built its portfolio by buying once-successful companies like Airtable that have struggled to cope with newer, nimbler competitors or failed to adapt to emerging technologies. <a href="https://www.forbes.com/sites/shivaramrajgopal/2026/07/06/bending-spoons-paid-33-billion-for-aol-vimeo-and-eventbrite-its-pro-forma-2025-profit-was-just-22-million/" target="_blank" rel="noreferrer noopener">Bending Spoons takes these companies, cuts costs and markets them aggressively</a> with the goal of returning them to profitability.</p>



<p class="wp-block-paragraph">“Airtable is a pioneering brand reshaping how teams organize data and manage critical workflows. We’re committed to investing in Airtable for the long run, and doubling down on its core strength: bringing teams and workflows together in one flexible workspace. We plan to expand what can be done across the full spectrum of work and make Airtable even more valuable to customers at every scale,” said Luca Ferrari, Bending Spoons CEO and co-founder.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Snowflake attacker pleads guilty to hack of 165 companies’ data]]></title>
<description><![CDATA[A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollars.



Industry so...]]></description>
<link>https://tsecurity.de/de/3710957/ai-nachrichten/snowflake-attacker-pleads-guilty-to-hack-of-165-companies-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710957/ai-nachrichten/snowflake-attacker-pleads-guilty-to-hack-of-165-companies-data/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. <a href="https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers" target="_blank" rel="noreferrer noopener">Connor Riley Moucka pleaded guilty</a> to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollars.</p>



<p class="wp-block-paragraph">Industry sources have identified Moucka as one of the main players in attacks on data hosted by cloud data warehouse Snowflake. Companies affected by the hacks <a href="https://www.csoonline.com/article/3629818/7-biggest-cybersecurity-stories-of-2024.html">include the likes of AT&amp;T, Ticketmaster and the Neiman Marcus Group</a>.</p>



<p class="wp-block-paragraph">He worked with two other hackers: <a href="https://www.csoonline.com/article/2517422/hacker-allegedly-paid-370000-ransom-to-delete-stolen-att-data.html">John Edward Binns</a> and Cameron John Wagenius. Binns was <a href="https://www.justice.gov/usao-wdwa/united-states-vs-connor-riley-moucka-and-john-erin-binns" target="_blank" rel="noreferrer noopener">not in US custody as of April 2026</a>, while Wagenius, going by the name of <a href="https://www.csoonline.com/article/3631033/us-soldier-linked-to-trump-call-log-hack-arrested-in-texas.html">Kiberphant0m, was arrested in January 2025</a> and <a href="https://www.justice.gov/opa/pr/former-us-soldier-pleads-guilty-hacking-and-extortion-scheme-involving-telecommunications" target="_blank" rel="noreferrer noopener">pleaded guilty in July that year</a></p>



<p class="wp-block-paragraph">Moucka and other members of the group used stolen login credentials to compromise data belonging to at least 165 customers of a US-based software-as-a-service company. This unauthorized access was used to steal billions of sensitive customer records and download terabytes of information,</p>



<p class="wp-block-paragraph">“Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars. Today’s guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity. You will be found and brought to justice,” said assistant attorney general A. Tysen Duva of the Justice Department’s Criminal Division</p>



<p class="wp-block-paragraph">The trial is the result of a coordinated worldwide action against the Snowflake group. The investigation was led by the FBI but benefited from contributions from the Royal Canadian Mounted Police, the Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine and the Turkish National Police.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4206739/snowflake-attacker-pleads-guilty-to-hack-of-165-companies-data.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three concepts cloud architects overlook]]></title>
<description><![CDATA[After two decades of cloud architecture consulting, I see an unchanging pattern in enterprise deployments. Organizations approach me with unexpectedly high cloud bills, operational chaos, and architectures that look good on paper but cause headaches in production. The common thread is almost alwa...]]></description>
<link>https://tsecurity.de/de/3710959/ai-nachrichten/three-concepts-cloud-architects-overlook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710959/ai-nachrichten/three-concepts-cloud-architects-overlook/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">After two decades of cloud architecture consulting, I see an unchanging pattern in enterprise deployments. Organizations approach me with unexpectedly high cloud bills, operational chaos, and architectures that look good on paper but cause headaches in production. The common thread is almost always the same. Fundamental concepts that should be foundational to any cloud deployment are treated as optional or ignored altogether.</p>



<p class="wp-block-paragraph">I’m not talking about exotic requirements, bleeding-edge technologies, or vendor-specific best practices. Basic engineering principles are somehow getting lost amid the excitement of cloud adoption. I wish I could say it’s rare, but after working with organizations across industries and geographies for years, I can confirm that missing these fundamentals is more common than most people realize. The results are predictable. Bills grow faster than business value, architectures require constant firefighting, and teams are stretched too thin to optimize anything.</p>



<p class="wp-block-paragraph">The good news? You don’t have to start over, but you do have to go back to basics. Here are three concepts most cloud architects overlook that will make your architecture dramatically more valuable and efficient.</p>



<h2 class="wp-block-heading">Identifying common ground</h2>



<p class="wp-block-paragraph">When deploying heterogeneous architecture, especially in <a href="https://www.infoworld.com/article/3584433/are-you-ready-for-multicloud-a-checklist.html">multicloud </a>environments, organizations must aggressively reduce silos. This means establishing common control planes for security, governance, and operations. You won’t get there by relying on whatever proprietary technology each cloud provider offers out of the box. Each provider wants you locked into their way of managing things. That is fine for simple deployments, but when you are running across multiple clouds and on-premises systems, proprietary control planes introduce redundancy, complexity, and cost.</p>



<p class="wp-block-paragraph">You need a single control layer that spans your entire environment. Instead of managing 10 different security solutions from 10 different providers, you have one. Instead of separate <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity management systems</a> for each cloud, you need one that works everywhere. This eliminates the need to change security parameters in five different consoles, maintain five different skill sets for five different operational models, and reconcile five different governance frameworks. The common control plane ties everything together.</p>



<p class="wp-block-paragraph">This might sound hard, but it’s not as bad as you think. (I will cover the specific patterns in a future article.) The real issue is that most architects have never been trained to think this way. They were taught to select the best services from each provider rather than abstract away the differences. This fundamental gap costs organizations real money every single day.</p>



<h2 class="wp-block-heading">Cost observability and optimization</h2>



<p class="wp-block-paragraph">Most architects treat cost visibility and optimization as afterthoughts, things that can be bolted on after the architecture is in place. That backward approach shows up in the results. Without <a href="https://www.infoworld.com/article/2338592/6-finops-best-practices-to-reduce-cloud-costs.html" data-type="link" data-id="https://www.infoworld.com/article/2338592/6-finops-best-practices-to-reduce-cloud-costs.html">cost observability and optimization</a> baked into your architecture from day one, you cannot understand where your money is going, where waste is accumulating, or where you should make changes to align expenses with delivered value.</p>



<p class="wp-block-paragraph">The more complex and heterogeneous your environment, the more critical this becomes. You need a unified cost observability layer that spans public and private clouds and your own infrastructure. This is about building a layer that aggregates cost data from everywhere, provides a single source of truth for spending, and delivers the insights needed to actively optimize. Without this, you are flying blind, making decisions based on incomplete data and discovering problems only after the invoice arrives.</p>



<p class="wp-block-paragraph">Too many organizations fail to gain control of their cloud spending because their billing data is scattered across multiple consoles, with no way to correlate usage across providers. They cannot see which teams, projects, or services are driving costs. They miss opportunities to right-size, consolidate, or eliminate waste. You cannot improve what you cannot measure. Without a common cost observability and optimization layer built into your architecture, you will never achieve the efficiency the cloud was supposed to deliver.</p>



<h2 class="wp-block-heading">Consider the human element</h2>



<p class="wp-block-paragraph">Here is an uncomfortable truth most architects do not want to discuss: The more complex your architecture is, the broader the range of skills you will need to keep it running. Complexity requires expertise, and expertise requires hiring, training, and retention. If your architecture demands 15 different skill sets to operate, you’d better have a plan for finding and retaining the people with those skills.</p>



<p class="wp-block-paragraph">I have seen beautifully designed architectures fail because the organization could not meet hiring requirements. They compromised by hiring underqualified individuals, which led to operational failures, security gaps, and mounting technical debt. The architecture itself was sound. The human infrastructure around it was not. This is a solvable problem. It starts with acknowledging that you are not designing for yourself. You are designing for the team that will inherit this system after you have moved on to your next assignment or promotion.</p>



<p class="wp-block-paragraph">The solution isn’t just simplifying architecture, though that should be a goal. The key is to consider human factors in your design. What skills are required? How can you find and train people? What cultural changes are necessary for effective operation? These questions are essential; ignoring them risks failure.</p>



<h2 class="wp-block-heading">The simple bottom line</h2>



<p class="wp-block-paragraph">I understand why most cloud architects miss these basic principles. No single course or book brings all of this together in one place. Cloud architecture has become a collection of best practices, vendor recommendations, and conference talking points, rather than a disciplined engineering discipline focused on business value.</p>



<p class="wp-block-paragraph">As a result, architectures end up optimized in the wrong places, if they are optimized at all. They are expensive to run, difficult to secure, and nearly impossible to operate at scale without constant intervention. The cloud promises efficiency, yet we are not delivering it because we have lost sight of the fundamentals.</p>



<p class="wp-block-paragraph">It’s time to go back to basics. Commonality, human factors, and cost observability and optimization are the three things that separate architectures that create value from those that create cost. Incorporate these concepts into your architecture and you’ll get ahead of most production systems in use today.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wispr moves beyond AI dictation with note-taking assistant]]></title>
<description><![CDATA[Wispr, the startup behind dictation tool Wispr Flow, has created an AI note-taking assistant that records meetings and generates conversation summaries for users.



The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things...]]></description>
<link>https://tsecurity.de/de/3710961/ai-nachrichten/wispr-moves-beyond-ai-dictation-with-note-taking-assistant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710961/ai-nachrichten/wispr-moves-beyond-ai-dictation-with-note-taking-assistant/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:50 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Wispr, the startup behind <a href="https://www.computerworld.com/article/4107331/wispr-ceo-interview-post-keyboard-office.html">dictation tool Wispr Flow</a>, has created an AI note-taking assistant that records meetings and generates conversation summaries for users.</p>



<p class="wp-block-paragraph">The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things down,” said Sahaj Garja, Wispr CTO and co-founder.</p>



<p class="wp-block-paragraph">Notetaker starts recording with one click, and doesn’t require a bot to attend a video or voice call. It can also be used to capture in-person conversations.</p>



<p class="wp-block-paragraph">The software has three key functions. Before a call, Notetaker displays a meeting brief with information such as meeting purpose and background of participants.</p>



<p class="wp-block-paragraph">Once the meeting starts, a live transcript displays the dialogue text and labels speakers. A “what did I miss?” button provides a summary of talking points from the previous few minutes.</p>



<p class="wp-block-paragraph">Finally, post-meeting, Notetaker generates a more detailed summary organized by topic that includes information such as key dates, decisions, and next steps. Users can search across notes from previous meetings in the Notetaker app. “Over time your meeting history stops being a folder of documents you have to go find and becomes something you can ask questions of,” said Garja.</p>



<p class="wp-block-paragraph">Notetaker integrates with AI assistants such as Anthropic’s Claude and OpenAI’s ChatGPT via model context protocol. This allows users to connect outputs such as transcripts and summaries “into how you already work, instead of sitting in a separate app,” said Garja.</p>



<p class="wp-block-paragraph">With Notetaker, Wispr competes in an increasingly busy market for AI note-taking apps that includes Fireflies, Granola and Otter.</p>



<p class="wp-block-paragraph">Wispr <a href="https://wisprflow.ai/post/wispr-flow-notetaker" target="_blank" rel="noreferrer noopener">claims</a> Notetaker can produce more accurate transcripts than existing tools, partly because of the additional context it uses during transcription. It uses the same personal dictionary from Wispr Flow that includes acronyms, products, and preferred spellings, and can also draw on other sources such as calendar information to understand the purpose of a meeting and help ensure speakers are labelled correctly.</p>



<p class="wp-block-paragraph">Before generating the final summary, Notetaker also re-reads the live meeting transcript and combines it with additional context to create a more accurate final output, Garja said.</p>



<p class="wp-block-paragraph">Notetaker is the first new product launched by Wispr, which was founded in 2021 and has since <a href="https://wisprflow.ai/new-funding" target="_blank" rel="noreferrer noopener">raised</a> $81 million in funding.</p>



<p class="wp-block-paragraph">“We didn’t set out to build a dictation app,” said Garja. “The mission has always been to reshape how people interact with their devices, and dictation was the fastest way in.”</p>



<p class="wp-block-paragraph">“Notetaker is the second product on that path. Dictation took the keyboard out of writing. Notetaker takes it out of meetings, so nobody has to spend the call typing up what everyone just said.”</p>



<h2 class="wp-block-heading">User consent when recording calls</h2>



<p class="wp-block-paragraph">As AI note-taking tools have become more prevalent in the workplace, privacy concerns have arisen, including the need for all-party consent when recording a call in some jurisdictions, and whether meeting audio is used to train AI models. Two software vendors, <a href="https://www.computerworld.com/article/4041849/enterprise-note-taking-apps-face-legal-scrutiny-as-otter-hit-with-privacy-suit.html">Otter</a> and <a href="https://www.computerworld.com/article/4206255/granola-lawsuit-raises-concerns-over-ai-note-taking-app-privacy.html">Granola</a>, currently face separate lawsuits in California that allege privacy law violations related to their products.</p>



<p class="wp-block-paragraph">Wispr Flow Notetaker captures audio locally on a user’s device rather than joining the call as a visible bot. That means there’s no notification to signal that a conversation is being transcribed, which places responsibility on users to disclose the recording to others on the call in accordance with local laws, said Garja.</p>



<p class="wp-block-paragraph">“Users should always let the other person know before you start recording or transcribing a conversation, whether it’s a video call, an in-person meeting, or a phone call,” he said, adding that Wispr intends to build additional features for automated consent messaging “in the coming weeks.”</p>



<p class="wp-block-paragraph">Wispr doesn’t train its AI models on customer data without consent, though free and standard tier customers must choose to opt-out, according to Wispr’s privacy <a href="https://docs.wisprflow.ai/articles/3467817258-security-and-compliance-faq" target="_blank" rel="noreferrer noopener">terms</a>. Nor does it create “voiceprints or biometric profiles” of users or anyone else on a call using audio recording data, the company says.</p>



<p class="wp-block-paragraph">When Notetaker is active, conversation audio is captured on a user’s device and processed on cloud servers to enable transcription. The recorded audio file is encrypted and stored temporarily on the user’s device or cloud storage, Wispr said. After a limited period, the audio is automatically deleted.</p>



<p class="wp-block-paragraph">Notetaker is available with the Wispr Flow macOS app to free and paid subscribers, with support for Windows “coming soon.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trump orders new 15% tariff on key material for solar panels and microchips]]></title>
<description><![CDATA[Move to raise levy on goods made with polysilicon aims to protect domestic US supply chains from China, the major producerDonald Trump has ordered a new 15% tariff on imported products made of polysilicon, an important ingredient in microchip manufacturing that is primarily produced by China.The ...]]></description>
<link>https://tsecurity.de/de/3710949/ai-nachrichten/trump-orders-new-15-tariff-on-key-material-for-solar-panels-and-microchips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710949/ai-nachrichten/trump-orders-new-15-tariff-on-key-material-for-solar-panels-and-microchips/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:48 +0200</pubDate>
<content:encoded><![CDATA[<p>Move to raise levy on goods made with polysilicon aims to protect domestic US supply chains from China, the major producer</p><p>Donald Trump has ordered a new 15% <a href="https://www.theguardian.com/business/tariffs">tariff</a> on imported products made of polysilicon, an important ingredient in microchip manufacturing that is primarily produced by China.</p><p>The new tariff, which will take effect on 4 December, is aimed at supporting <a href="https://www.theguardian.com/technology/2026/jan/15/trump-tariff-nvidia-ai-chips">US chip</a> and solar panel supply chains to compete with Beijing on artificial intelligence and energy.</p> <a href="https://www.theguardian.com/us-news/2026/aug/07/trump-orders-tariff-solar-panels-microchips-manufacturing-ingredient">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alibaba tests new business model for Qwen open-source AI]]></title>
<description><![CDATA[Alibaba plans to introduce revenue-sharing terms for some commercial users of its next Qwen open-weight AI model, Reuters reported, citing two people familiar with the company’s plans. The arrangement would require larger companies that generate revenue from offering the model as a service to rea...]]></description>
<link>https://tsecurity.de/de/3710913/ai-nachrichten/alibaba-tests-new-business-model-for-qwen-open-source-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710913/ai-nachrichten/alibaba-tests-new-business-model-for-qwen-open-source-ai/</guid>
<pubDate>Sat, 08 Aug 2026 00:42:36 +0200</pubDate>
<content:encoded><![CDATA[<p>Alibaba plans to introduce revenue-sharing terms for some commercial users of its next Qwen open-weight AI model, Reuters reported, citing two people familiar with the company’s plans. The arrangement would require larger companies that generate revenue from offering the model as a service to reach a commercial agreement with Alibaba. The exact revenue-sharing rate has […]</p>
<p>The post <a href="https://www.artificialintelligence-news.com/news/alibaba-qwen-open-source-ai-revenue-sharing/">Alibaba tests new business model for Qwen open-source AI</a> appeared first on <a href="https://www.artificialintelligence-news.com/">AI News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Automatically add sources to your Gemini Notebooks in Workspace Studio]]></title>
<description><![CDATA[Historically, keeping Gemini Notebooks up to date would require you to manually add sources one by one. Now, this new integration lets you automate adding sources to your Gemini Notebooks as part of a recurring workflow. You can use the new Add a source to Gemini Notebook step to add text, links ...]]></description>
<link>https://tsecurity.de/de/3710805/web-tipps/automatically-add-sources-to-your-gemini-notebooks-in-workspace-studio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710805/web-tipps/automatically-add-sources-to-your-gemini-notebooks-in-workspace-studio/</guid>
<pubDate>Sat, 08 Aug 2026 00:41:05 +0200</pubDate>
<content:encoded><![CDATA[<p>Historically, keeping Gemini Notebooks up to date would require you to manually add sources one by one. Now, this new integration lets you automate adding sources to your Gemini Notebooks as part of a recurring workflow. You can use the new <b>Add a source to Gemini Notebook</b> step to add text, links to Drive files, or generic Youtube or web URLs as sources to your notebooks to ensure your notebooks are always up to date on the latest content.</p><p><br></p><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiV1zVzaAb1lNu0bxtcsWbnmLddJ0CBLA8_iWOvhJC0cd5QL7jH2hA_oTIhVZ8rT4v4r8MUXX7nKJ_7_3UP3-30IE-1uPAHrIEplL9_XOd7m1_RIhvdv7ZNwP-7__qgAD8BW4vQbGcewTdUYcV9uDwq0s-WsZQJKuSviFXwQNCb6HAVgG-KUjk-X4VK1Y/s2048/Automatically%20add%20sources%20to%20your%20Gemini%20Notebooks%20in%20Workspace%20Studio%20-%207180.png" imageanchor="1"><img border="0" data-original-height="1199" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiV1zVzaAb1lNu0bxtcsWbnmLddJ0CBLA8_iWOvhJC0cd5QL7jH2hA_oTIhVZ8rT4v4r8MUXX7nKJ_7_3UP3-30IE-1uPAHrIEplL9_XOd7m1_RIhvdv7ZNwP-7__qgAD8BW4vQbGcewTdUYcV9uDwq0s-WsZQJKuSviFXwQNCb6HAVgG-KUjk-X4VK1Y/s1600/Automatically%20add%20sources%20to%20your%20Gemini%20Notebooks%20in%20Workspace%20Studio%20-%207180.png"></a></td></tr><tr><td class="tr-caption"><br>Use Add a source to Gemini Notebook to automatically keep your notebooks up to date</td></tr></tbody></table><h3>Getting started</h3><p></p><ul><li><b>Admins: </b>This step is available by default if you allow Gemini for Google Workspace steps. Visit the Help Center to learn more about <a href="https://knowledge.workspace.google.com/admin/studio/manage-access-to-steps-and-starters-in-workspace-studio#service" target="_blank">managing access to steps and starters in Workspace Studio</a>.</li><li><b>End users: </b>Try the feature in <a href="https://studio.workspace.google.com/" target="_blank">Google Workspace Studio</a>. Visit the Help Center to learn more about the <a href="https://support.google.com/workspace-studio?p=AddSource_GeminiNotebook" target="_blank">Add Source to Gemini Notebooks step</a>.</li></ul><p></p><h3>Rollout pace</h3><p></p><ul><li><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release and Scheduled Release domains:</a> Gradual rollout (up to 15 business days for feature visibility) starting on August 6, 2026</li></ul><p></p><h3>Availability</h3><p></p><ul><li><b>Business: </b>Business Starter, Standard, and Plus</li><li><b>Enterprise: </b>Enterprise Standard and Plus</li><li><b>Education: </b>Education Fundamentals, Standard, and Plus</li><li><b>Education Add-ons:</b> Google AI Pro for Education; Teaching and Learning</li><li><b>Other Add-ons:</b> AI Expanded Access</li></ul><p></p><h3>Resources</h3><p></p><ul><li>Google Workspace Admin Help: <a href="https://support.google.com/a/topic/16443963" target="_blank">Workspace Studio</a></li><li>Workspace Studio Help: <a href="https://support.google.com/workspace-studio#topic=16433255" target="_blank">Get Started with Workspace Studio</a></li><li>YouTube: <a href="https://www.youtube.com/playlist?list=PLDdffPXqmxKNtTUF7H3mab3HEnXzxRi8V" target="_blank">Workspace Studio Playlist</a></li><li>Discord: <a href="https://discord.com/channels/1439825892833755370/1442898214184292402" target="_blank">Workspace Studio Channel</a></li></ul><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Update Your Mac Now, Apple Just Fixed a Serious Screen Sharing Vulnerability]]></title>
<description><![CDATA[Apple has revealed what today's macOS security updates actually fix, confirming that macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 all address the same Screen Sharing vulnerability that could let an attacker on the same network authenticate without valid credentials. 



The c...]]></description>
<link>https://tsecurity.de/de/3710751/ios-mac-os/update-your-mac-now-apple-just-fixed-a-serious-screen-sharing-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710751/ios-mac-os/update-your-mac-now-apple-just-fixed-a-serious-screen-sharing-vulnerability/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:45 +0200</pubDate>
<content:encoded><![CDATA[Apple has revealed what today's macOS security updates actually fix, confirming that macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 all address the same Screen Sharing vulnerability that could let an attacker on the same network authenticate without valid credentials. 



The company initially released all three updates with only a brief note about important security fixes, but it has now published full security details explaining the issue and why users should install the updates.



Apple says the flaw affected Screen Sharing across all three supported macOS versions and fixed the problem by improving how authentication states are managed. 



Although the company has not reported any evidence that attackers actively exploited the vulnerability, the nature of the bug means it had the potential to give unauthorized users remote access to a vulnerable Mac if the necessary conditions were met.



Apple explains the Screen Sharing security fix



Apple published the following security advisory for all three macOS versions:




Screen SharingImpact: "An attacker on the network may be able to authenticate to Screen Sharing without valid credentials."Description: "An authentication issue was addressed with improved state management."CVE-2026-65400, reported by Alfredo Pesoli (@__rev) via Bynario Atlas (bynar.io).




According to Apple's advisory, the vulnerability allowed an attacker on the same network to bypass Screen Sharing authentication under certain conditions. 



If successful, that access could let someone view the display, open apps and files, or perform other actions depending on how the affected Mac was configured and what permissions were available during the session.



Apple has not said that anyone used this vulnerability in real world attacks, but releasing fixes for macOS Tahoe, Sequoia, and Sonoma at the same time shows that the company considered the issue important enough to patch immediately instead of waiting for a larger software update. If your Mac supports one of these versions, installing the latest security update helps protect your system from this authentication flaw.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple releases macOS Sonoma 14.8.9 and Sequoia 15.7.9 with security fixes]]></title>
<description><![CDATA[Apple has released macOS Sonoma 14.8.9 and macOS Sequoia 15.7.9 as new security updates for Mac users. The updates arrived on August 6 without developer or public beta testing and focus on fixing a Screen Sharing vulnerability.



The new builds are macOS Sonoma 14.8.9 (23J631) and macOS Sequoia ...]]></description>
<link>https://tsecurity.de/de/3710752/ios-mac-os/apple-releases-macos-sonoma-1489-and-sequoia-1579-with-security-fixes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710752/ios-mac-os/apple-releases-macos-sonoma-1489-and-sequoia-1579-with-security-fixes/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:45 +0200</pubDate>
<content:encoded><![CDATA[Apple has released macOS Sonoma 14.8.9 and macOS Sequoia 15.7.9 as new security updates for Mac users. The updates arrived on August 6 without developer or public beta testing and focus on fixing a Screen Sharing vulnerability.



The new builds are macOS Sonoma 14.8.9 (23J631) and macOS Sequoia 15.7.9 (24G830). Both updates are available through Software Update on supported Macs.



How to update your Mac




Click the Apple menu in the top-left corner of your screen.



Select System Settings.



Click General in the sidebar.



Select Software Update.



Wait while your Mac checks for available updates.



Click Update Now and follow the instructions on the screen.



Allow your Mac to restart if required to complete the installation.




It is a good idea to save any open work before starting the update.



What’s new in macOS Sonoma 14.8.9 and Sequoia 15.7.9



These releases do not add new features or other user-facing changes. They focus on an important security fix affecting Screen Sharing.




Screen Sharing security fix: The updates address an authentication issue that could allow an attacker on the same network to authenticate to Screen Sharing without valid credentials.



Improved state management: The authentication problem has been fixed by improving how macOS manages the relevant Screen Sharing state.



CVE-2026-65400: The Screen Sharing vulnerability is tracked under CVE-2026-65400 and affects both macOS Sonoma and macOS Sequoia.




Mac users running either version should install the update as soon as practical, especially because it addresses a network-based authentication issue.



If you’ve already installed macOS Sonoma 14.8.9 or macOS Sequoia 15.7.9, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Releases macOS Tahoe 26.6.1 With Important Security Fix]]></title>
<description><![CDATA[Apple has released macOS Tahoe 26.6.1 with build number 25G76, bringing an important security fix for Mac users. The update arrived without developer or public beta testing and fixes a Screen Sharing vulnerability that could allow an attacker on the same network to authenticate without valid cred...]]></description>
<link>https://tsecurity.de/de/3710753/ios-mac-os/apple-releases-macos-tahoe-2661-with-important-security-fix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710753/ios-mac-os/apple-releases-macos-tahoe-2661-with-important-security-fix/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:45 +0200</pubDate>
<content:encoded><![CDATA[Apple has released macOS Tahoe 26.6.1 with build number 25G76, bringing an important security fix for Mac users. The update arrived without developer or public beta testing and fixes a Screen Sharing vulnerability that could allow an attacker on the same network to authenticate without valid credentials.



The update comes just days after macOS Tahoe 26.6 and is available alongside macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. Apple recommends the latest updates for all users.



You can install macOS Tahoe 26.6.1 directly through System Settings:




Open the Apple menu in the top-left corner of your Mac.



Select System Settings.



Click General.



Select Software Update.



Wait while your Mac checks for available updates.



Click Update Now next to macOS Tahoe 26.6.1.



Follow the instructions and restart your Mac when required.




It is a good idea to save any open work before starting the installation since your Mac will need to restart.



All changes in macOS Tahoe 26.6.1



macOS Tahoe 26.6.1 focuses on security rather than introducing new features or visible interface changes.




Screen Sharing security fix: The update fixes an authentication issue that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.



Improved authentication handling: The Screen Sharing flaw was addressed through improved state management.



CVE-2026-65400: The vulnerability is tracked under CVE-2026-65400.



Build number: macOS Tahoe 26.6.1 carries build number 25G76.



No new features announced: The release notes only mention important security fixes, so users should not expect new features or major visual changes.




There is currently no indication that the Screen Sharing vulnerability was actively exploited in the wild, but installing the update will protect Macs from the authentication flaw.



If you’ve already installed macOS Tahoe 26.6.1, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Spider-Man: Brand New Day Breaks Half Billion Box Office Record]]></title>
<description><![CDATA[Spider-Man is swinging past the competition to set a massive new milestone in theaters right now. The latest Marvel adventure, Spider-Man: Brand New Day, has officially become the fastest movie in history to cross the half-billion mark at the domestic box office. Fans are showing up in huge numbe...]]></description>
<link>https://tsecurity.de/de/3710734/ios-mac-os/spider-man-brand-new-day-breaks-half-billion-box-office-record/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710734/ios-mac-os/spider-man-brand-new-day-breaks-half-billion-box-office-record/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:44 +0200</pubDate>
<content:encoded><![CDATA[Spider-Man is swinging past the competition to set a massive new milestone in theaters right now. The latest Marvel adventure, Spider-Man: Brand New Day, has officially become the fastest movie in history to cross the half-billion mark at the domestic box office. Fans are showing up in huge numbers every single day, helping the highly anticipated superhero film crush previous ticket sale records in a short amount of time.



The new superhero movie sets a major domestic sales record



Spider-Man: Brand New Day reached $500 million in ticket sales faster than any other release before it. Theaters across the country are seeing packed rooms as audiences rush to see the newest story on the big screen. The speed of this financial climb puts the movie ahead of past heavy hitters that took much longer to reach the same goal.



Sony is likely celebrating this massive win. It saw incredible opening numbers, and the momentum has only grown since then. Hitting this financial target so quickly proves that the character remains a massive draw for everyday moviegoers.



The film continues drawing large crowds during its theatrical run



While the half-billion mark is a domestic achievement, the momentum shows no signs of slowing down anytime soon. People keep buying tickets week after week, suggesting the movie has strong word of mouth keeping the sales steady.



With no direct competition currently taking away screens, the comic book adaptation has plenty of room to keep earning. It will be interesting to see how high the final numbers climb before the picture leaves theaters for good.



Breaking a record like this cements the movie as a pop culture event rather than just a standard blockbuster. Spider-Man always brings people together, and this historic box office sprint shows the hero still holds a special place in the hearts of movie fans.]]></content:encoded>
</item>
<item>
<title><![CDATA[Suno Adds Audio Watermarks to AI Music as Legal Troubles Pile Up]]></title>
<description><![CDATA[Suno, a popular platform for generating AI music, announced a major change to how it handles audio files. The startup plans to add hidden watermarks and tracking tools to every track created on its system. This decision comes as the company tries to stop bad actors from abusing its tools while si...]]></description>
<link>https://tsecurity.de/de/3710738/ios-mac-os/suno-adds-audio-watermarks-to-ai-music-as-legal-troubles-pile-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710738/ios-mac-os/suno-adds-audio-watermarks-to-ai-music-as-legal-troubles-pile-up/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:44 +0200</pubDate>
<content:encoded><![CDATA[Suno, a popular platform for generating AI music, announced a major change to how it handles audio files. The startup plans to add hidden watermarks and tracking tools to every track created on its system. This decision comes as the company tries to stop bad actors from abusing its tools while simultaneously fighting massive lawsuits from major record labels over unauthorized copyright use. These new rules aim to bring more transparency to the music market.



The startup limits song downloads to stop streaming royalty scams



The platform will now embed audio fingerprints into tracks so other services can easily identify where the music came from. Co-founder Mikey Shulman stated that these tools are designed to resist tampering without changing how a song sounds. To help spot copyrighted lyrics, the business is also partnering with a tracking service called Musixmatch.



Along with the watermarks, Suno introduced a strict download policy to prevent mass distribution. The goal is to stop people from generating thousands of fake songs, uploading them to streaming apps like Spotify, and using automated bots to listen to those tracks. Earlier this year, a man pleaded guilty to making millions of dollars through this specific kind of fraud. The updated community guidelines now officially ban spam, fake engagement, and using a real person's voice without permission.



The company faces multiple lawsuits over copyright and data breaches



These safety updates arrive during a very difficult time for the startup. Heavyweight players like Universal Music Group and Sony Music Entertainment are currently suing the business. The labels claim the platform trained its artificial intelligence models on copyrighted recordings without asking for approval. Just last week, a German court also ruled against the platform in a similar case involving a local licensing agency.



Legal headaches are not limited to just music rights. The startup is also dealing with a class action lawsuit in Massachusetts regarding a massive data breach from last year. That incident reportedly exposed the personal information of over 55 million users and revealed that the platform scraped data from sites like YouTube to build its technology.



By forcing transparency onto its own audio files, Suno is trying to prove it can be a legitimate tool for creators rather than just a quick way to generate spam. However, a few watermarks might not be enough to satisfy judges and record labels who feel the foundation of the technology was built on stolen work.]]></content:encoded>
</item>
<item>
<title><![CDATA[Jon Prosser Slows Down Apple Lawsuit Due To Newborn Baby]]></title>
<description><![CDATA[The ongoing legal fight between Apple and YouTube personality Jon Prosser hit another roadblock this week. Following a lawsuit filed in July 2025 accusing Prosser and Michael Ramacciotti of stealing pre-release data from an employee's test device, the case faced multiple delays. Prosser missed ea...]]></description>
<link>https://tsecurity.de/de/3710743/ios-mac-os/jon-prosser-slows-down-apple-lawsuit-due-to-newborn-baby/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710743/ios-mac-os/jon-prosser-slows-down-apple-lawsuit-due-to-newborn-baby/</guid>
<pubDate>Sat, 08 Aug 2026 00:40:44 +0200</pubDate>
<content:encoded><![CDATA[The ongoing legal fight between Apple and YouTube personality Jon Prosser hit another roadblock this week. Following a lawsuit filed in July 2025 accusing Prosser and Michael Ramacciotti of stealing pre-release data from an employee's test device, the case faced multiple delays. Prosser missed early deadlines, which caused a default ruling that he later managed to get overturned. Now, the discovery process has stalled again.



A new baby pauses the legal discovery process



Since rejoining the case in June 2026, Prosser stopped responding to requests for legal materials. His legal team last communicated with Apple on July 6. According to court filings, Prosser recently welcomed his second child, leaving him without the time needed to provide the required documents. In his filing, Prosser promised to find dates to share the remaining discovery details with Apple's legal team.



Apple seems understanding of the family situation and agreed to the requested delays. The joint court filing outlines approved extensions and new dates to move the process forward. A deposition is now scheduled for September 2026, and the next formal court filing should arrive on October 7.



While Apple agreed to the extension, it remains to be seen if the company will take a softer approach when it comes to a final settlement or punishment. Prosser maintains he is not guilty, but if Apple wins the case, the court could prevent him from reporting on the tech giant's unreleased products entirely. 



Because leaking hardware and software details makes up a large part of his business, losing the ability to cover Apple news would strike a heavy blow to his career.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudprobleme kosten IT-Teams fast 12 Stunden pro Woche]]></title>
<description><![CDATA[Cloudprobleme kosten IT-Teams fast 12 Stunden pro Woche

      
      
        
          
            
                



            
          
        
              
    
  Lars Nitsch
Fr., 07.08.2026 - 13:24


            Cloudinfrastrukturen gelten in vielen Unternehmen als fit für KI und...]]></description>
<link>https://tsecurity.de/de/3710668/server/cloudprobleme-kosten-it-teams-fast-12-stunden-pro-woche/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710668/server/cloudprobleme-kosten-it-teams-fast-12-stunden-pro-woche/</guid>
<pubDate>Sat, 08 Aug 2026 00:39:30 +0200</pubDate>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Cloudprobleme kosten IT-Teams fast 12 Stunden pro Woche</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/cloud-probleme-kosten-it-teams-11-stunden-pro-woche"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/DE-CIX_Cloud_Connectivity.jpg?itok=GEbc8-Pr" width="480" height="319" alt="KI-generierte Illustration einer großen weißen Wolke als Symbol für Cloudinfrastruktur. Mehrere Techniker arbeiten mit Leiter, Hebebühne und Werkzeugen an der Wolke; ein geöffnetes Fach zeigt Servertechnik und Kabel im Inneren." title="Das Management der Cloudinfrastruktur bleibt ein Zeitfresser: Laut einer DE-CIX-Umfrage wenden IT-Teams im Schnitt 11,5 Stunden pro Woche für die Behebung entsprechender Probleme auf. (Quelle: KI-generiert mit ChatGPT)" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/109" lang about="https://www.it-administrator.de/user/109" typeof="schema:Person" property="schema:name" datatype class="username">Lars Nitsch</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2026-08-07T13:24:56+02:00" title="Freitag, August 7, 2026 - 13:24" class="datetime">Fr., 07.08.2026 - 13:24</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Cloudinfrastrukturen gelten in vielen Unternehmen als fit für KI und neue Workloads – im Alltag verursachen sie dennoch erheblichen Aufwand. Laut einer DE-CIX-Umfrage verbringen IT-Teams im Schnitt 11,5 Stunden pro Woche mit Problemen bei der Cloudkonnektivität. Besonders häufig genannt werden Latenzen, Sicherheitsrisiken und Ausfälle.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/news" hreflang="en">News</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/cloud-probleme-kosten-it-teams-11-stunden-pro-woche" rel="tag" title="Cloudprobleme kosten IT-Teams fast 12 Stunden pro Woche" hreflang="en">Weiterlesen<span class="visually-hidden"> über Cloudprobleme kosten IT-Teams fast 12 Stunden pro Woche</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v2.1.224]]></title>
<description><![CDATA[What's changed

Added self-hosted environments: claude self-hosted-runner turns your own machines or containers into a place Claude Code web, mobile, and desktop sessions can run, on Team and Enterprise plans
Added archive plugin source: install plugins from a zip over HTTPS without git or npm, w...]]></description>
<link>https://tsecurity.de/de/3710665/downloads/github-v21224/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710665/downloads/github-v21224/</guid>
<pubDate>Sat, 08 Aug 2026 00:39:08 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>What's changed</h2>
<ul>
<li>Added self-hosted environments: <code>claude self-hosted-runner</code> turns your own machines or containers into a place Claude Code web, mobile, and desktop sessions can run, on Team and Enterprise plans</li>
<li>Added <code>archive</code> plugin source: install plugins from a zip over HTTPS without git or npm, with optional SHA-256 pinning</li>
<li>Added a cancel-and-confirm step when removing an unavailable paste changes a command's text</li>
<li>Added <code>ANTHROPIC_BEDROCK_REGION_PREFIX</code> env var for Bedrock to prefer a specific cross-region inference profile over the <code>AWS_REGION</code>-derived one</li>
<li>Added <code>crossSessionInbound</code> and <code>dialogExpiry</code> settings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliver</li>
<li>Added sandbox credential-masking options: <code>extract</code> and <code>onExtractNoMatch</code> for structured env values, <code>decode: "jwt"</code> with <code>maskClaims</code> for JWT-aware masking, and <code>awsPairs</code>/<code>sigv4</code> for AWS SigV4 re-signing; these need <code>network.tlsTerminate</code> and are honored only from user, managed, or <code>--settings</code> settings</li>
<li>Added cross-session <code>SendMessage</code>: Claude Code sessions can now message each other, on any of your machines, with <code>ListAgents</code> to discover them (macOS and Linux)</li>
<li>Fixed long (&gt;200 char) project paths resolving to another project's session directory under a shared sanitized prefix; session list, rename, fork, delete and <code>/resume</code> no longer cross projects</li>
<li>Fixed <code>SendMessage</code> reporting "Message sent" when the write to a teammate's inbox had actually failed; failed deliveries are now reported as errors</li>
<li>Fixed sandbox filesystem deny entries written with a trailing slash (e.g. <code>denyRead: "~/.aws/"</code>) being silently bypassable on Linux and macOS</li>
<li>Fixed sandbox violation details never appearing in Bash tool results; Claude now sees which file or network access was denied and why</li>
<li>Fixed MCP tools that connect mid-turn being deferred for tool search without their names announced to the model</li>
<li>Fixed plugin install records being silently corrupted when the same plugin is installed in multiple projects</li>
<li>Fixed recalled or restored paste content occasionally attaching wrong data or silently losing text when the paste had aged out or placeholder numbers collided</li>
<li>Fixed copy-on-select on Wayland sometimes not reaching the clipboard; the two selection writes no longer race</li>
<li>Fixed the feedback survey's transcript share silently failing on long sessions; a failed share now shows an error instead of a success message</li>
<li>Fixed Remote Control auto-start intermittently failing with "Remote credentials fetch failed" on a cold start with a stale login token</li>
<li>Fixed Remote Control and SDK clients showing a blank "(no content)" message after <code>/clear</code> and other output-less commands</li>
<li>Fixed a Remote Control session recreated after its server session expired uploading prior local conversation history into the new session</li>
<li>Improved fullscreen mode to keep the full pre-compaction history in scrollback across repeated compactions, instead of only the most recent interval</li>
<li>Improved Remote Control: attached web and mobile clients now see compaction progress and the post-compaction boundary instead of a silent pause; <code>/clear</code> resets now propagate to attached clients</li>
<li>Improved Remote Control: connection failures now show a persistent failure indicator with details and a reconnect shortcut, instead of only an 8-second toast</li>
<li>Removed the 200-subagent-per-session spawn cap; long-running sessions no longer refuse new agents (concurrency and depth limits still apply)</li>
<li>Changed managed settings: the approval prompt no longer re-appears after re-login or org switching when the organization's settings are unchanged</li>
<li>Changed the feedback-survey transcript share: with your consent it now also uploads the last request's model settings — the system prompt (which includes your <code>CLAUDE.md</code> instructions), tool definitions, and model parameters. Secrets are redacted as before, and these fields are dropped first if the share is too large</li>
<li>Changed the Bash tool description to always note that command output is displayed to the model, not reliably to the user</li>
<li>Changed recalled paste placeholder numbers to renumber when accepted into the input</li>
<li>Changed Remote Control to archive the stale server session instead of leaving a dead one listed when a fresh session is minted after compaction or <code>/resume</code></li>
<li>[VSCode] Fixed the extension showing Remote Control as connected after the connection failed</li>
<li>Fixed a session resume silently reconnecting Remote Control after the user turned it off (<code>--resume</code>, SDK hosts, and the VS Code extension)</li>
<li>[VSCode] Fixed sessions not honoring <code>remoteControlAtStartup</code> when explicitly enabled</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v17.2.11]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Breaking Changes

Fixed handling of GitHub Copilot's model_not_available_for_integrator error to prevent unnecessary retries, preserving the actionable available models list.

Added

Added support for reporting Cursor personal monthly USD quotas and remaining balances, labeled by ...]]></description>
<link>https://tsecurity.de/de/3710614/tools/github-v17211/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710614/tools/github-v17211/</guid>
<pubDate>Sat, 08 Aug 2026 00:37:59 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>@oh-my-pi/pi-ai</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Fixed handling of GitHub Copilot's model_not_available_for_integrator error to prevent unnecessary retries, preserving the actionable available models list.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added support for reporting Cursor personal monthly USD quotas and remaining balances, labeled by verified profile email accounts.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where ANTHROPIC_BASE_URL was ignored for Anthropic chat requests, ensuring requests are routed to the configured host and forwarding ANTHROPIC_CUSTOM_HEADERS to non-official gateways.</li>
<li>Fixed an issue where a legacy pre-organization login credential could persist and cause a permanent error row in omp usage even after a successful organization-scoped re-login.</li>
<li>Fixed an issue where lazy provider streams (including Amazon Bedrock, Google, Cursor, Devin, and Ollama) ignored model-specific idle timeouts, which previously caused healthy but slow reasoning turns to prematurely time out.</li>
<li>Improved error classification for Simplified Chinese quota-exhaustion and rate-limit messages, ensuring affected credentials are correctly rotated or backed off instead of being treated as unknown errors.</li>
<li>Classified subscription and plan-cap 429 responses as rotatable usage limits rather than transient rate-limit throttles, enabling smoother credential rotation.</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Fixed</h3>
<ul>
<li>Increased the default stream idle-timeout floor on Amazon Bedrock to 900 seconds for reasoning and adaptive-thinking models (such as Claude) to prevent premature watchdog timeouts during long reasoning stretches.</li>
<li>Fixed Devin model families (including SWE-1.7, Claude 5, Gemini 3.6 Flash, Kimi K3, Grok 4.5, and Inkling) to correctly group as logical models with reasoning-effort routing instead of separate wire variants.</li>
<li>Added missing context-window and output-token limits for dynamically discovered Alibaba Token Plan models.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added support for the Agent Plugins 1.0.0 standard, enabling automatic discovery, validation, and secure execution of compliant plugin packages.</li>
<li>Added the <code>omp share &lt;session&gt;</code> command to share saved sessions by ID prefix or file path without launching the agent.</li>
<li>Added the <code>AGENT=1</code> environment variable to child processes spawned by <code>coding-agent</code> to allow downstream tools to detect agent-driven execution.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Consolidated Exa web-search configuration under <code>exa.enabled</code>, automatically migrating legacy <code>exa.enableSearch</code> values and removing obsolete Researcher and Websets settings.</li>
<li>Removed stale <code>computer.backend</code> values during configuration migration.</li>
<li>Updated documentation and error messages for the JavaScript/TypeScript debug adapter (<code>js-debug-adapter</code>) to clarify supported installation paths (Mason, standalone tarball, or <code>JS_DEBUG_DAP_SERVER</code>).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where <code>/reload-plugins</code> and the Agent Control Center failed to propagate updated agent definitions to existing tools without a restart.</li>
<li>Fixed legacy Pi extensions failing to load when calling <code>pi.unregisterProvider()</code>, ensuring provider replacements take effect immediately.</li>
<li>Fixed zero-width daemon readiness and wait regex matches being rejected by the hub wire decoder.</li>
<li>Fixed proxy model discovery preferring bundled catalog names over proxy-reported names, allowing <code>omp models refresh</code> to correctly update display names.</li>
<li>Fixed Windows compiled binary builds failing due to backslash-separated paths in <code>Bun.Glob.scan</code> producing invalid JavaScript in virtual modules.</li>
<li>Fixed the Ctrl+O (<code>app.tools.expand</code>) shortcut not expanding truncated tool output when a tool-approval prompt or selection dialog had keyboard focus.</li>
<li>Improved <code>omp commit</code> error reporting when pre-commit or commit-msg hooks fail, displaying the hook's own message and exiting non-zero cleanly instead of printing bundled source code.</li>
<li>Fixed <code>omp commit --push</code> exiting with code 0 without pushing when the working tree is already clean; it now correctly pushes existing commits.</li>
<li>Fixed <code>omp commit</code> exiting with code 0 when the commit agent failed and fell back to a mechanical commit; it now exits non-zero to indicate the fallback was used.</li>
<li>Fixed strict output schemas being rejected when native JSON Schema definition maps contain <code>ref</code> or applicator branches use <code>properties</code> without <code>type</code>.</li>
<li>Fixed shell syntax extraction in <code>cd &lt;path&gt; &amp;&amp; ...</code> commands to prevent redirects, extra arguments, or shell expansions from being incorrectly absorbed into the structured working directory path.</li>
<li>Applied reason-specific backoff to transient rate-limit retries and consolidated exhausted retry errors.</li>
<li>Fixed session-tree rows rendering as empty bullets for bookkeeping entries (such as title changes, credential pins, and mode changes); these are now hidden by default and properly labeled in <code>all</code> mode.</li>
<li>Fixed extension and custom tools inheriting same-named built-in TUI renderers, which could overwrite successful results with incorrect status text.</li>
<li>Fixed prewalk lifecycle handling to prevent plan injection on rejected same-model/same-effort arms, ensure consumed plan nudges do not return after context rebuilds, and prevent settings-enabled prewalk from implicitly re-arming restored sessions.</li>
<li>Fixed the todo completion reminder interrupting pauses when waiting for non-English questions (such as Chinese, Japanese, Korean, or Spanish prompts ending in <code>？</code> or <code>?</code>).</li>
<li>Normalized resolved file paths in read summaries, PDF image handles, and notebook errors to prevent agents from learning malformed paths.</li>
<li>Fixed a bug where a per-turn <code>before_agent_start</code> system prompt override was silently dropped during base-prompt rebuilds.</li>
<li>Fixed ACP <code>session/load</code> and <code>session/resume</code> failing with <code>ACP session not found</code> for sessions created under the legacy hashed project-directory scheme by falling back to a global ID scan.</li>
<li>Fixed <code>vault://&lt;name&gt;?op=...</code> commands targeting the active vault instead of the named vault in Obsidian CLI queries.</li>
<li>Fixed the status-line <code>session_name</code> segment to honor the <code>statusLine.sessionAccent</code> setting, falling back to the theme's accent color when disabled.</li>
<li>Fixed automatic <code>agent.continue()</code> paths failing to run context-fit maintenance when reverting to a smaller-context model after a cooldown expiry.</li>
<li>Fixed <code>/handoff</code> reporting "Handoff cancelled" for actual generation or stream timeout errors, ensuring the real error is surfaced.</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Changed</h3>
<ul>
<li>Pasting an empty named register (<code>PUT … @name</code> with no matching capture) now surfaces a warning listing available registers and removes the span target instead of throwing an error.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where pipe-numbered <code>read</code>/<code>search</code> rows copied into top-level and bare-body patch payloads were not properly recovered (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5090045419" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7905" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/7905/hovercard" href="https://github.com/can1357/oh-my-pi/issues/7905">#7905</a>).</li>
</ul>
<h2>@oh-my-pi/pi-mnemopi</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where an interrupted local embedding model download could permanently corrupt the cache and silently disable semantic recall. The system now automatically detects incomplete model files, clears the corrupted cache, and retries the download.</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Added</h3>
<ul>
<li>Added support for Windows hosts in <code>bun run build</code>, enabling local N-API builds against VS Build Tools without requiring a pre-configured vcvars prompt.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Replaced the miniaudio (<code>maudio</code>) dependency with in-house platform audio backends for <code>AudioCapture</code>/<code>AudioPlayback</code>: CoreAudio AudioQueue on macOS, shared-mode WASAPI on Windows, and PulseAudio (ALSA fallback) loaded via <code>dlopen</code> on Linux. Removes the bindgen/libclang requirement and the Windows rustc-ICE workaround from the native build.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed CPU feature detection (AVX2) on Windows hosts, resolving an issue where the native addon loader and local builds incorrectly fell back to the baseline variant, while improving startup performance by ~270ms.</li>
<li>Fixed <code>bun run build:bindings</code> failing on Windows due to incorrect resolution of the <code>@napi-rs/cli</code> entry point.</li>
<li>Fixed a compiler crash (rustc ICE) when building the <code>maudio</code> package for Windows.</li>
<li>Fixed synthesized macOS keyboard and pointer events suppressing physical user input.</li>
<li>Fixed several Wayland input and capture issues, including preventing read-only calls from acquiring persistent input control, fixing GNOME Wayland pointer input initialization, and resolving conflicts between <code>libei</code> input and PipeWire screen capture.</li>
<li>Fixed compilation of the <code>wayland-pipewire</code> Cargo feature.</li>
<li>Improved security on Wayland by cleaning up orphaned world-readable RemoteDesktop restore tokens on startup.</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where Herdr panes lost native terminal scrollback during TUI transcript replacements or resize redraws.</li>
<li>Fixed an issue inside tmux where explicit display resets retained stale light/dark palettes and leaked terminal capability bytes into the editor.</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added <code>repair</code> and <code>rawKeys</code> options to <code>parseFrontmatter</code> to support spec-conformant loading (disabling lenient recovery and preserving keys verbatim), and exported <code>normalizeFrontmatterKeys</code> for manual key normalization.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed the in-house <code>marked</code> list tokenizer incorrectly consuming trailing blank lines at the end of input, ensuring correct list tightness and token generation matching standard <code>marked</code> behavior.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(tui): preserve scrollback in Herdr panes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chessl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chessl">@chessl</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5078798827" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7810" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7810/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7810">#7810</a></li>
<li>fix(coding-agent): clean up legacy Exa and computer settings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chessl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chessl">@chessl</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5079298667" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7814" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7814/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7814">#7814</a></li>
<li>fix(coding-agent/tools): preserve native JSON Schema containers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kimprap/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kimprap">@kimprap</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5079409325" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7816" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7816/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7816">#7816</a></li>
<li>fix(ai): classify Simplified Chinese quota exhaustion as credential-rotatable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IceCodeNew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IceCodeNew">@IceCodeNew</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5080699687" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7828" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7828/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7828">#7828</a></li>
<li>fix(coding-agent): prefer proxy-reported model name over bundled catalog name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vinhnguyen1211/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vinhnguyen1211">@vinhnguyen1211</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5081464111" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7832" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7832/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7832">#7832</a></li>
<li>fix(commit): report hook refusals cleanly and honor --push on a clean tree by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5081627253" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7836" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7836/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7836">#7836</a></li>
<li>fix(tui): make Ctrl+O expand tool output regardless of focus by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5081896468" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7840" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7840/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7840">#7840</a></li>
<li>fix(coding-agent): signalled fallback commits with a non-zero exit code by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhang17-24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhang17-24">@zhang17-24</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5082644747" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7844" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7844/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7844">#7844</a></li>
<li>fix(catalog): enrich Alibaba Token Plan discovered model limits by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mustaqeem66/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mustaqeem66">@Mustaqeem66</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5083454267" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7849" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7849/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7849">#7849</a></li>
<li>fix(extensions): roll back providers after load failure by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mustaqeem66/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mustaqeem66">@Mustaqeem66</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5083725092" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7853" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7853/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7853">#7853</a></li>
<li>feat(coding-agent): mark child processes as agent-driven by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5083990908" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7854" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7854/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7854">#7854</a></li>
<li>fix(catalog): update Devin reasoning family routing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/will-bogusz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/will-bogusz">@will-bogusz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086031482" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7865" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7865/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7865">#7865</a></li>
<li>fix(status-line): honor sessionAccent toggle for session_name segment by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CaelumSea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CaelumSea">@CaelumSea</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086119373" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7867" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7867/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7867">#7867</a></li>
<li>fix(natives): prevent macos input suppression by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086454638" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7873" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7873/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7873">#7873</a></li>
<li>fix(anthropic): honor ANTHROPIC_BASE_URL for chat requests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086716844" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7875" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7875/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7875">#7875</a></li>
<li>fix(auth): purge pre-org OAuth tombstone on org-scoped re-login by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086824773" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7878" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7878/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7878">#7878</a></li>
<li>docs(agent-hub): document subagent observability by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087243654" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7881" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7881/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7881">#7881</a></li>
<li>fix(natives): port wayland capture to pipewire 0.9 Rc handle API by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087618001" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7887" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7887/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7887">#7887</a></li>
<li>fix(bash): constrain leading cd extraction to a single path token by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087625249" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7888" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7888/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7888">#7888</a></li>
<li>fix(ai,catalog): widen Bedrock stream-stall watchdog via model compat by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voonfoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voonfoo">@voonfoo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087855708" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7892" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7892/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7892">#7892</a></li>
<li>fix(natives): make Windows-host builds and addon loading work end to end by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zerx-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zerx-lab">@zerx-lab</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5088557956" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7896" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7896/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7896">#7896</a></li>
<li>feat(ai): add Cursor personal usage reporting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chessl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chessl">@chessl</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5058553518" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7613" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7613/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7613">#7613</a></li>
<li>perf(extensions): import extension modules concurrently by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/metaphorics/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/metaphorics">@metaphorics</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5070115533" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7709" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7709/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7709">#7709</a></li>
<li>fix(coding-agent): preserve before_agent_start prompt override across base rebuilds by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5075384014" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7756" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7756/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7756">#7756</a></li>
<li>docs(coding-agent): clarify js-debug-adapter install is not an npm package by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcastillo18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcastillo18">@fcastillo18</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5075625420" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7759" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7759/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7759">#7759</a></li>
<li>fix(session): handle subscription-cap retry exhaustion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076704901" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7772" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7772/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7772">#7772</a></li>
<li>fix(vault): pass vault= as top-level obsidian cli option by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076731824" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7773" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7773/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7773">#7773</a></li>
<li>fix(tui): gate built-in renderers by tool provenance by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076732290" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7774" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7774/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7774">#7774</a></li>
<li>fix(tree): stop rendering bookkeeping entries as empty rows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ParadaCarleton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ParadaCarleton">@ParadaCarleton</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076884476" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7782" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7782/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7782">#7782</a></li>
<li>fix(acp): resolve session/load across legacy session directories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076888727" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7783" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7783/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7783">#7783</a></li>
<li>fix(coding-agent): make prewalk lifecycle one-shot by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eggpeat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eggpeat">@eggpeat</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076997950" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7785" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7785/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7785">#7785</a></li>
<li>fix(read): normalize recovery paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5077342471" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7790" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7790/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7790">#7790</a></li>
<li>fix(tui): avoid leaking DA1 through tmux appearance refresh by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anatoli-tsinovoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anatoli-tsinovoy">@anatoli-tsinovoy</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5078302210" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7801" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7801/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7801">#7801</a></li>
<li>fix(coding-agent): detect non-English questions in todo reminder guard by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5078448024" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7806" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7806/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7806">#7806</a></li>
<li>fix(ai): preserve Copilot integrator entitlement errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5079890724" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7821" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7821/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7821">#7821</a></li>
<li>fix(natives): share one runtime across wayland portal paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087648477" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7889" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7889/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7889">#7889</a></li>
<li>fix(computer): lazily request wayland input permission by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087668785" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7890" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7890/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7890">#7890</a></li>
<li>fix(session): surface real handoff errors instead of false cancel by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5089951657" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7904" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7904/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7904">#7904</a></li>
<li>fix(hashline): recover pipe-numbered read rows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5090099679" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7906" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7906/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7906">#7906</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chessl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chessl">@chessl</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5078798827" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7810" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7810/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7810">#7810</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kimprap/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kimprap">@kimprap</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5079409325" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7816" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7816/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7816">#7816</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IceCodeNew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IceCodeNew">@IceCodeNew</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5080699687" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7828" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7828/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7828">#7828</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vinhnguyen1211/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vinhnguyen1211">@vinhnguyen1211</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5081464111" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7832" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7832/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7832">#7832</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CaelumSea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CaelumSea">@CaelumSea</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5086119373" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7867" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7867/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7867">#7867</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voonfoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voonfoo">@voonfoo</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5087855708" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7892" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7892/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7892">#7892</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zerx-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zerx-lab">@zerx-lab</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5088557956" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7896" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7896/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7896">#7896</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcastillo18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcastillo18">@fcastillo18</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5075625420" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7759" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7759/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7759">#7759</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ParadaCarleton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ParadaCarleton">@ParadaCarleton</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5076884476" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7782" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7782/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7782">#7782</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v17.2.10...v17.2.11">v17.2.10...v17.2.11</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ICE Is Buying Access to Credit Card Records]]></title>
<description><![CDATA[Through data brokers, ICE is buying the information you provided to open a credit card.]]></description>
<link>https://tsecurity.de/de/3710566/reverse-engineering/ice-is-buying-access-to-credit-card-records/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710566/reverse-engineering/ice-is-buying-access-to-credit-card-records/</guid>
<pubDate>Sat, 08 Aug 2026 00:37:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Through data brokers, ICE is <a href="https://www.404media.co/you-opened-a-credit-card-ice-now-knows-where-you-live/">buying</a> <a href="https://boingboing.net/2026/07/23/credit-header-data-ice.html">the</a> <a href="https://mastodon.social/@heidilifeldman/116981503852352281">information</a> you provided to open a credit card.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I'm a diehard OnePlus user: Here's my plan now that the company is leaving North America]]></title>
<description><![CDATA[OnePlus has officially ended business across North America and Europe. I explain what happens next and the best alternatives to consider.]]></description>
<link>https://tsecurity.de/de/3710534/hacking/im-a-diehard-oneplus-user-heres-my-plan-now-that-the-company-is-leaving-north-america/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710534/hacking/im-a-diehard-oneplus-user-heres-my-plan-now-that-the-company-is-leaving-north-america/</guid>
<pubDate>Sat, 08 Aug 2026 00:36:54 +0200</pubDate>
<content:encoded><![CDATA[OnePlus has officially ended business across North America and Europe. I explain what happens next and the best alternatives to consider.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts]]></title>
<description><![CDATA[Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometric verification, or password. Mollema’s resear...]]></description>
<link>https://tsecurity.de/de/3710514/hacking/windows-hello-key-abuse-lets-attackers-access-microsoft-entra-id-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710514/hacking/windows-hello-key-abuse-lets-attackers-access-microsoft-entra-id-accounts/</guid>
<pubDate>Sat, 08 Aug 2026 00:36:43 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometric verification, or password. Mollema’s research demonstrates how attackers can effectively “borrow” the cryptographic key that underlies Windows Hello […]</p>
<p>The post <a href="https://gbhackers.com/windows-hello-key-abuse/">Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Is Cyber Security Risk Assessment? A Complete Guide (2026)]]></title>
<description><![CDATA[A cyber security risk assessment is a structured process for identifying, analyzing, and prioritizing the risks to an organization’s information systems, data, and operations. It works by pairing each threat and vulnerability with the likelihood it will be exploited and the business impact if it ...]]></description>
<link>https://tsecurity.de/de/3710519/hacking/what-is-cyber-security-risk-assessment-a-complete-guide-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710519/hacking/what-is-cyber-security-risk-assessment-a-complete-guide-2026/</guid>
<pubDate>Sat, 08 Aug 2026 00:36:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A cyber security risk assessment is a structured process for identifying, analyzing, and prioritizing the risks to an organization’s information systems, data, and operations. It works by pairing each threat and vulnerability with the likelihood it will be exploited and the business impact if it is—so leaders can decide which risks to fix, transfer, accept, […]</p>
<p>The post <a href="https://gbhackers.com/what-is-a-cybersecurity-risk-assessment/">What Is Cyber Security Risk Assessment? A Complete Guide (2026)</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Impersonate IT Support to Breach Leading Financial Companies]]></title>
<description><![CDATA[Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associa...]]></description>
<link>https://tsecurity.de/de/3710510/hacking/hackers-impersonate-it-support-to-breach-leading-financial-companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710510/hacking/hackers-impersonate-it-support-to-breach-leading-financial-companies/</guid>
<pubDate>Sat, 08 Aug 2026 00:36:40 +0200</pubDate>
<content:encoded><![CDATA[Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among dozens […]]]></content:encoded>
</item>
<item>
<title><![CDATA[DATA RECOVERY: Backup Failed? What UK SMEs Should Do Next to Protect Business Data]]></title>
<description><![CDATA[Image Credit: rawpixel viaFreepik Meet The R3 Team /… Learn More /… Image Credit: IfOnlyCommunications...
The post DATA RECOVERY: Backup Failed? What UK SMEs Should Do Next to Protect Business Data appeared first on SME Cybersecurity News.]]></description>
<link>https://tsecurity.de/de/3710470/it-security-nachrichten/data-recovery-backup-failed-what-uk-smes-should-do-next-to-protect-business-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710470/it-security-nachrichten/data-recovery-backup-failed-what-uk-smes-should-do-next-to-protect-business-data/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:37 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="150" height="150" src="https://smecyberinsights.co.uk/wp-content/uploads/2026/08/error-alert-failure-icon-problem-concept_compressed-1-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="DATA RECOVERY: Backup Failed? What UK SMEs Should Do Next to Protect Business Data – The Definitive Protocols" decoding="async" loading="lazy">Image Credit: rawpixel viaFreepik Meet The R3 Team /… Learn More /… Image Credit: IfOnlyCommunications...</p>
<p>The post <a rel="nofollow" href="https://smecyberinsights.co.uk/index.php/2026/08/07/backup-failed-what-uk-smes-should-do/">DATA RECOVERY: Backup Failed? What UK SMEs Should Do Next to Protect Business Data</a> appeared first on <a rel="nofollow" href="https://smecyberinsights.co.uk/">SME Cybersecurity News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks]]></title>
<description><![CDATA[This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how att...]]></description>
<link>https://tsecurity.de/de/3710461/it-security-nachrichten/the-cyber-express-weekly-roundup-ransomware-surge-government-data-breaches-logistics-disruptions-and-third-party-security-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710461/it-security-nachrichten/the-cyber-express-weekly-roundup-ransomware-surge-government-data-breaches-logistics-disruptions-and-third-party-security-risks/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:31 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="803" height="498" src="https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="The Cyber Express weekly roundup H1" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1.webp 803w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1-300x186.webp 300w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1-768x476.webp 768w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1-600x372.webp 600w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1-150x93.webp 150w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1-750x465.webp 750w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1.webp 803w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1-300x186.webp 300w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1-768x476.webp 768w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1-600x372.webp 600w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1-150x93.webp 150w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-H1-750x465.webp 750w" sizes="(max-width: 803px) 100vw, 803px" title="The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks 1"></p><span data-contrast="auto">This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The latest developments reinforce that <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="29289">cyber</a> threats are no longer limited to direct attacks on organizations. Threat actors are exploiting ransomware-as-a-service ecosystems, compromising government registries, targeting law enforcement databases, and abusing third-party platforms that support retail and healthcare operations. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Organizations must strengthen third-party risk management, improve <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29288">data</a> protection measures, and enhance incident response capabilities to reduce the impact of evolving cyber threats.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h2 aria-level="2"><b><span data-contrast="none">The Cyber Express Weekly Roundup</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h2>
<h3 aria-level="3"><b><span data-contrast="none">Qilin Dominated Ransomware Attacks in H1 2026</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Qilin emerged as the most active <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="29284">ransomware</a> group during the first half of 2026, targeting organizations worldwide through its ransomware-as-a-service (RaaS) operation. Manufacturing, healthcare, construction, and professional services were among the sectors most affected as the group continued expanding its global reach. </span><a href="https://thecyberexpress.com/qilin-ransomware-h1-2026/" target="_blank" rel="noopener"><span data-contrast="none">Read more…</span></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Hackers Breach Beneficial Owners Registry, Expose Data of 31,000 Firms</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Hackers breached the Register of Beneficial Owners (VwbP), gaining unauthorized access to data associated with approximately 31,000 legal entities. Authorities temporarily took the registry offline, launched an investigation, and established a crisis response team, stating there is currently no evidence that records were altered or deleted. </span><a href="https://thecyberexpress.com/beneficial-owners-register-breach/" target="_blank" rel="noopener"><span data-contrast="none">Read more…</span></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">PNLD Data Breach Leaks Police and Government Contact Details</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">A data breach involving the Police National Legal Database (PNLD) exposed names, organizations, and work email addresses belonging to police officers, government partners, criminal justice professionals, and some Ask the Police users after the information appeared on the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-the-dark-web/" title="dark web" data-wpil-keyword-link="linked" data-wpil-monitor-id="29285">dark web</a>. Authorities are investigating the incident and assessing its potential impact. </span><a href="https://thecyberexpress.com/pnld-data-breach-police-contact-details/" target="_blank" rel="noopener"><span data-contrast="none">Read more…</span></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">De Bijenkorf Logistics Cyberattack Delays Orders and Raises Data Exposure Concerns</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">A <a class="wpil_keyword_link" href="https://cyble.com/cyberattack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="29286">cyberattack</a> targeting a third-party logistics provider disrupted deliveries, returns, and refunds for Dutch retailer De Bijenkorf. While the retailer confirmed its internal systems were not compromised, investigators are assessing whether customer contact details and order information were exposed. Payment information, passwords, and financial data were not affected, and customers have been advised to remain vigilant against <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noopener" title="phishing" data-wpil-keyword-link="linked" data-wpil-monitor-id="29287">phishing</a> attempts. </span><a href="https://thecyberexpress.com/de-bijenkorf-cyberattack/" target="_blank" rel="noopener"><span data-contrast="none">Read more…</span></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Updoc Data Breach Exposes Customer Contact Information</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Australian telehealth provider Updoc disclosed a <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-a-data-breach/" target="_blank" rel="noopener" title="data breach" data-wpil-keyword-link="linked" data-wpil-monitor-id="29292">data breach</a> after unauthorized access to a third-party operational platform exposed some customers' names, email addresses, and postal addresses. The company confirmed that its internal systems remained secure and that no medical records, payment information, or financial data were compromised. </span><a href="https://thecyberexpress.com/updoc-data-breach/" target="_blank" rel="noopener"><span data-contrast="none">Read more…</span></a><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h2 aria-level="2"><b><span data-contrast="none">Weekly Cybersecurity Takeaway</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h2>
<span data-contrast="auto">This week's incidents highlight the continued evolution of cyber threats across ransomware operations, government data breaches, and third-party supply chain compromises.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">A common theme across these <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-security-events/" title="events" data-wpil-keyword-link="linked" data-wpil-monitor-id="29290">events</a> is the growing risk posed by trusted third-party platforms and shared digital ecosystems. Attackers are targeting external service providers, government databases, and ransomware affiliate networks to expand their reach and maximize operational disruption.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Organizations should prioritize stronger third-party <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risk" data-wpil-keyword-link="linked" data-wpil-monitor-id="29293">risk</a> management, continuous monitoring, robust access controls, and timely incident response to reduce the impact of supply chain attacks and data breaches. </span>

<span data-contrast="auto">As businesses become more interconnected, strengthening the <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29291">security</a> of partner ecosystems is becoming just as important as protecting internal infrastructure.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Point72 Among Major Hedge Funds Targeted in Cyberattack on Wall Street Through Voice Phishing Campaign]]></title>
<description><![CDATA[A cyberattack on Wall Street recently targeted several leading hedge funds, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. The attackers used voice phishing, or "vishing," to trick employees into revealing sensitive information or granting access to...]]></description>
<link>https://tsecurity.de/de/3710462/it-security-nachrichten/point72-among-major-hedge-funds-targeted-in-cyberattack-on-wall-street-through-voice-phishing-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710462/it-security-nachrichten/point72-among-major-hedge-funds-targeted-in-cyberattack-on-wall-street-through-voice-phishing-campaign/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:31 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="811" height="490" src="https://thecyberexpress.com/wp-content/uploads/Point72.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Point72" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Point72.webp 811w, https://thecyberexpress.com/wp-content/uploads/Point72-300x181.webp 300w, https://thecyberexpress.com/wp-content/uploads/Point72-768x464.webp 768w, https://thecyberexpress.com/wp-content/uploads/Point72-600x363.webp 600w, https://thecyberexpress.com/wp-content/uploads/Point72-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/Point72-750x453.webp 750w, https://thecyberexpress.com/wp-content/uploads/Point72.webp 811w, https://thecyberexpress.com/wp-content/uploads/Point72-300x181.webp 300w, https://thecyberexpress.com/wp-content/uploads/Point72-768x464.webp 768w, https://thecyberexpress.com/wp-content/uploads/Point72-600x363.webp 600w, https://thecyberexpress.com/wp-content/uploads/Point72-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/Point72-750x453.webp 750w" sizes="(max-width: 811px) 100vw, 811px" title="Point72 Among Major Hedge Funds Targeted in Cyberattack on Wall Street Through Voice Phishing Campaign 3"></p><span data-contrast="auto">A cyberattack on Wall Street recently targeted several leading hedge funds, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. The attackers used voice phishing, or "vishing," to trick employees into revealing sensitive information or granting access to internal systems.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Cybersecurity experts say such attempts are common because financial institutions store highly sensitive <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29280">data</a>. However, the latest incidents highlight how cybercriminals are increasingly combining traditional <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-social-engineering/" target="_blank" rel="noopener" title="social engineering" data-wpil-keyword-link="linked" data-wpil-monitor-id="29282">social engineering</a> tactics with artificial intelligence to make impersonation attempts more convincing.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Point72 Says No Client Data Was Compromised</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">According to <a href="https://www.moneycontrol.com/news/business/millennium-point72-two-sigma-citadel-hit-by-voice-phishing-cyberattacks-13996534.html" target="_blank" rel="nofollow noopener">reports</a>, Point72 Asset Management informed investors on August 5 that it had been targeted in the latest cyberattack on Wall Street. Bloomberg first reported the communication, citing a source familiar with the matter.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The firm said it was reviewing the incident and that no client information had been stolen. Point72 declined to comment publicly.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The campaign extended beyond Point72, with hackers also attempting to breach the information systems of Millennium Management, Two Sigma Investments, and Citadel, according to sources.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Voice Phishing Remains an Effective Attack Method</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The attackers relied on voice <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noopener" title="phishing" data-wpil-keyword-link="linked" data-wpil-monitor-id="29278">phishing</a>, a social engineering technique in which criminals impersonate trusted individuals—often IT support staff—to persuade employees to disclose confidential information or provide system access.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Cybersecurity experts told <a href="https://www.reuters.com/legal/government/major-wall-street-hedge-funds-targeted-attempted-cyberattacks-bloomberg-news-2026-08-05/" target="_blank" rel="nofollow noopener">Reuters</a> that these attacks are routine because of the valuable information held by financial firms. Rather than exploiting software <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="29281">vulnerabilities</a>, voice phishing succeeds by manipulating human behaviour.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The tactic has also been used successfully by the <a href="https://thecyberexpress.com/pink-extortion-group-emerges/" target="_blank" rel="noopener">cybercriminal group</a> "<a href="https://cyble.com/threat-actor-profiles/scattered-spider/" target="_blank" rel="nofollow noopener">Scattered Spider</a>," a loosely organized network of young hackers that has targeted numerous companies in recent years.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">AI Is Increasing the Sophistication of Cyberattacks</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Security experts say the attempted <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-a-cyber-attack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="29277">cyberattack</a> on Wall Street demonstrates how artificial intelligence is making social engineering campaigns more persuasive and difficult to detect.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">A similar trend was highlighted in June, when Google's <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="29283">cybersecurity</a> unit published a report detailing a campaign targeting U.S. law firms and other professional and financial services organizations. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">According to the report, attackers posed as IT support personnel through <a href="https://thecyberexpress.com/pink-extortion-group-emerges/" target="_blank" rel="noopener">voice phishing</a> calls and, in some cases, even visited offices while pretending to be IT maintenance staff.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Growing Cyber Risks for Financial Firms</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The attempted cyberattack on Wall Street comes as organizations worldwide face a rise in AI-powered cyberattacks and <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="29279">ransomware</a> incidents that disrupt operations and steal sensitive data.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">In response to the growing threat, the White House announced a working group earlier this year that brings together AI developers and critical infrastructure operators to share <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/different-types-of-threat-intelligence/" target="_blank" rel="noopener" title="threat intelligence" data-wpil-keyword-link="linked" data-wpil-monitor-id="29276">threat intelligence</a> and strengthen cyber defenses.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Although Point72 said no customer information was compromised, the attempted attacks on several prominent hedge funds underscore the persistent <a href="https://thecyberexpress.com/iran-crisis-gulf-cybersecurity-middle-east/" target="_blank" rel="noopener">cybersecurity risks</a> facing the financial sector and the increasing use of AI-enhanced social engineering by threat actors.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incident]]></title>
<description><![CDATA[The Updoc data breach has raised fresh concerns about cybersecurity in Australia's healthcare sector after the telehealth provider confirmed that an unauthorized third party may have accessed customer contact information through an external system.  

The data breach at Updoc, disclosed on Augu...]]></description>
<link>https://tsecurity.de/de/3710463/it-security-nachrichten/updoc-data-breach-exposes-patient-contact-information-following-third-party-security-incident/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710463/it-security-nachrichten/updoc-data-breach-exposes-patient-contact-information-following-third-party-security-incident/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:31 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="788" height="456" src="https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Updoc data breach" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach.webp 788w, https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach-300x174.webp 300w, https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach-768x444.webp 768w, https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach-600x347.webp 600w, https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach-150x87.webp 150w, https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach-750x434.webp 750w, https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach.webp 788w, https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach-300x174.webp 300w, https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach-768x444.webp 768w, https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach-600x347.webp 600w, https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach-150x87.webp 150w, https://thecyberexpress.com/wp-content/uploads/Updoc-data-breach-750x434.webp 750w" sizes="(max-width: 788px) 100vw, 788px" title="Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incident 5"></p><span data-contrast="auto">The Updoc data breach has raised fresh concerns about cybersecurity in Australia's healthcare sector after the telehealth provider confirmed that an unauthorized third party may have accessed customer contact information through an external system. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The data breach at Updoc, disclosed on August 7, stemmed from a brief security incident involving a third-party platform that supports the company's operations. While the Updoc <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="29272">cyberattack</a> did not expose medical or financial records, it is the latest cyber incident affecting Australia's healthcare sector.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Updoc Data Breach Traced to Third-Party Platform</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":1,"335551620":1,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Updoc, an Australian telehealth provider offering round-the-clock online healthcare services, including medical certificates, prescriptions, and specialist referrals, detected unauthorized access to a third-party operational system on Friday, July 31.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">In a statement shared with </span><a href="https://www.linkedin.com/company/thecyberexpress" target="_blank" rel="nofollow noopener"><i><span data-contrast="auto">The Cyber Express</span></i></a><span data-contrast="auto">, the company said the incident was limited to an external system used to support its operations. The exposure was confined to customer contact information, which may have included account holders' names, email addresses, and postal addresses.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Updoc said its internal systems were not accessed during the incident and confirmed that no <a href="https://thecyberexpress.com/star-health-data-breach-exposes/" target="_blank" rel="noopener">health records</a>, financial information, or payment details were involved. The company added that it acted immediately to block the unauthorized access and found no evidence of any further activity after the initial event.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">According to the company, customers are not required to take any immediate action because account logins and <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29275">security</a> remain unaffected. Updoc also apologized for any concern or inconvenience caused by the incident.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Updoc Cyberattack Adds to Healthcare Sector Threats</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":1,"335551620":1,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Founded in 2021, Updoc generates approximately $10 million in annual revenue. According to its founders, the platform has served more than one million patients since launch, while its website states that it has over 500,000 users.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The Updoc cyberattack follows a series of <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="29273">cybersecurity</a> incidents targeting Australian healthcare and consumer-facing organizations. In June, clinic network <a href="https://thecyberexpress.com/partnered-health-cyberattack/" target="_blank" rel="noopener">Partnered Health</a> disclosed a cyberattack in which hackers stole personal information and health records from patients across at least 21 clinics in five Australian states.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">That breach exposed <a href="https://thecyberexpress.com/situsamc-data-breach/" target="_blank" rel="noopener">sensitive information</a>, including medical records, Medicare numbers, consultation notes, referral letters, and pathology results. The attack affected clinics in Melbourne, Sydney, Canberra, the Gold Coast, Sunshine Coast, and Coffs Harbour. At the time, another five clinics, including several in Western Australia, remained under investigation.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Although the Updoc <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-a-data-breach/" target="_blank" rel="noopener" title="data breach" data-wpil-keyword-link="linked" data-wpil-monitor-id="29271">data breach</a> was limited to contact information and did not compromise medical or payment data, the data breach at Updoc highlights the risks associated with third-party service providers. As healthcare organizations continue to depend on external platforms, the incident underscores how <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="29274">vulnerabilities</a> outside a company's own infrastructure can still result in customer information being exposed.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[IPVanish launches isolated browser to reduce Windows telemetry exposure]]></title>
<description><![CDATA[IPVanish has introduced a remote browser isolation feature designed to prevent Windows telemetry from directly correlating browsing activity with Microsoft’s persistent Global Device Identifier (GDID). The company announced IPVanish Secure Browser, citing the recently disclosed use of Windows tel...]]></description>
<link>https://tsecurity.de/de/3710458/it-security-nachrichten/ipvanish-launches-isolated-browser-to-reduce-windows-telemetry-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710458/it-security-nachrichten/ipvanish-launches-isolated-browser-to-reduce-windows-telemetry-exposure/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:30 +0200</pubDate>
<content:encoded><![CDATA[<p>IPVanish has introduced a remote browser isolation feature designed to prevent Windows telemetry from directly correlating browsing activity with Microsoft’s persistent Global Device Identifier (GDID). The company announced IPVanish Secure Browser, citing the recently disclosed use of Windows telemetry in a US cybercrime investigation, in which Microsoft records helped identify an alleged hacker despite the …</p>
<p>The post <a href="https://cyberinsider.com/ipvanish-launches-isolated-browser-to-reduce-windows-telemetry-exposure/">IPVanish launches isolated browser to reduce Windows telemetry exposure</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unlimited Technology Systems data breach impacts 3.8 million people]]></title>
<description><![CDATA[Unlimited Technology Systems, a healthcare software and revenue cycle management provider, has suffered a data breach affecting more than 3.8 million people. The HHS Office for Civil Rights lists the Ohio-based company as a business associate and says the hacking incident affected 3,803,750 indiv...]]></description>
<link>https://tsecurity.de/de/3710459/it-security-nachrichten/unlimited-technology-systems-data-breach-impacts-38-million-people/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710459/it-security-nachrichten/unlimited-technology-systems-data-breach-impacts-38-million-people/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:30 +0200</pubDate>
<content:encoded><![CDATA[<p>Unlimited Technology Systems, a healthcare software and revenue cycle management provider, has suffered a data breach affecting more than 3.8 million people. The HHS Office for Civil Rights lists the Ohio-based company as a business associate and says the hacking incident affected 3,803,750 individuals. Unlimited Technology Systems first detected unauthorized activity in its commercial data …</p>
<p>The post <a href="https://cyberinsider.com/unlimited-technology-systems-data-breach-impacts-3-8-million-people/">Unlimited Technology Systems data breach impacts 3.8 million people</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts]]></title>
<description><![CDATA[Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometric verification, or password. Mollema’s resear...]]></description>
<link>https://tsecurity.de/de/3710447/it-security-nachrichten/windows-hello-key-abuse-lets-attackers-access-microsoft-entra-id-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710447/it-security-nachrichten/windows-hello-key-abuse-lets-attackers-access-microsoft-entra-id-accounts/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometric verification, or password. Mollema’s research demonstrates how attackers can effectively “borrow” the cryptographic key that underlies Windows Hello […]</p>
<p>The post <a href="https://gbhackers.com/windows-hello-key-abuse/">Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Is Cyber Security Risk Assessment? A Complete Guide (2026)]]></title>
<description><![CDATA[A cyber security risk assessment is a structured process for identifying, analyzing, and prioritizing the risks to an organization’s information systems, data, and operations. It works by pairing each threat and vulnerability with the likelihood it will be exploited and the business impact if it ...]]></description>
<link>https://tsecurity.de/de/3710452/it-security-nachrichten/what-is-cyber-security-risk-assessment-a-complete-guide-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710452/it-security-nachrichten/what-is-cyber-security-risk-assessment-a-complete-guide-2026/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:25 +0200</pubDate>
<content:encoded><![CDATA[<p>A cyber security risk assessment is a structured process for identifying, analyzing, and prioritizing the risks to an organization’s information systems, data, and operations. It works by pairing each threat and vulnerability with the likelihood it will be exploited and the business impact if it is—so leaders can decide which risks to fix, transfer, accept, […]</p>
<p>The post <a href="https://gbhackers.com/what-is-a-cybersecurity-risk-assessment/">What Is Cyber Security Risk Assessment? A Complete Guide (2026)</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Human oversight is still critical as AI patching tools miss security risks]]></title>
<description><![CDATA[AI-generated vulnerability patches still heavily depend on human review, particularly the ones involving security-sensitive code, according to a research.



Researchers from 1Password have disclosed an internal evaluation that found AI-generated fixes frequently overlook broader concerns such as...]]></description>
<link>https://tsecurity.de/de/3710445/it-security-nachrichten/human-oversight-is-still-critical-as-ai-patching-tools-miss-security-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710445/it-security-nachrichten/human-oversight-is-still-critical-as-ai-patching-tools-miss-security-risks/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:24 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI-generated vulnerability patches still heavily depend on human review, particularly the ones involving security-sensitive code, according to a research.</p>



<p class="wp-block-paragraph">Researchers from 1Password have disclosed an internal evaluation that found AI-generated fixes frequently overlook broader <a href="https://www.csoonline.com/article/4202381/risk-based-patching-is-the-future-ai-made-it-table-stakes.html" target="_blank">concerns</a> such as architectural intent, business requirements, security implications, and long-term maintainability, despite being syntactically correct.</p>



<p class="wp-block-paragraph">“We studied what happens when Large Language Models (LLMs) generate vulnerability patches for recently disclosed, complex vulnerabilities,” said 1Password researcher <a href="https://www.linkedin.com/in/securingdev/" target="_blank" rel="noreferrer noopener">Keith Hoodlet</a> in a blog <a href="https://1password.com/blog/why-ai-generated-patches-still-require-human-review" target="_blank" rel="noreferrer noopener">post</a>. “Our data shows that LLMs produce Fix-Like Artifacts with Embedded Defects (FLAWED) 53.9% of the time when complex patches are required.”</p>



<p class="wp-block-paragraph">The evaluation tested the AI-generated fixes across six recently disclosed CVEs, including CVE-2026-31431 (“<a href="https://www.csoonline.com/article/4169399/new-dirty-frag-exploit-targets-linux-kernel-for-root-access.html">Copy Fail</a>”), CVE-2026-34197 (<a href="https://www.csoonline.com/article/4157146/claude-uncovers-a-13%E2%80%91year%E2%80%91old-activemq-rce-bug-within-minutes.html">ActiveMQ RCE</a>), CVE-2026-8512, CVE-2026-45185 (EXIM RCE), CVE-2026-22738 (<a href="https://nvd.nist.gov/vuln/detail/cve-2026-22738">SpringAI SpEL RCE</a>), and the <a href="https://www.csoonline.com/article/4165470/max-severity-rce-flaw-found-in-google-gemini-cli.html">Gemini CLI RCE</a> (GHSA-wpqr-6v78-jr5g).</p>



<p class="wp-block-paragraph">1Password reportedly evaluated 6080 patches generated using ChatGPT-5.5 and Claude Opus 4.8, two frontier AI coding models, and found that only a little over a quarter of the fixes fully remediated the flaw without altering application behavior.</p>



<p class="wp-block-paragraph">“Patches that successfully resolved the vulnerability, but altered the application’s behavior in the process, occurred 20.1% of the time,” Hoodlet added.</p>



<h2 class="wp-block-heading"><a></a>Fixing is not the same as securing</h2>



<p class="wp-block-paragraph">Instead of simply checking whether the fixed code compiled or passed automated tests, 1Password said it reviewed every generated fix for complete elimination of the vulnerability, preservation of application behavior, and avoidance of new security risks.</p>



<p class="wp-block-paragraph">While only 26% of the patches successfully fixed the vulnerability without introducing application changes, 49.3% failed to remove at least one exploitable attack path, 2.3% fixed the original vulnerability but introduced a new one, and 2.2% both failed to remediate the issue and created an additional security weakness.</p>



<p class="wp-block-paragraph">The researchers also found that passing pre-defined tests can create deeper problems. More than one-third of the patches that initially appeared successful were classified as “fragile” because they simply blocked the proof-of-concept (POC) exploit used during testing instead of addressing the underlying root cause.</p>



<p class="wp-block-paragraph">Hoodlet explained this with the example of the SpringAI CVE patches. Both GPT and Claude models were found generating patches that targeted specific characters from the input string used in the POC presented to them, leaving the root cause untouched.</p>



<p class="wp-block-paragraph">“If the guarded code were to become reachable again by using alternative inputs, it would lead to the old vulnerability resurfacing in the software,” he noted.</p>



<h2 class="wp-block-heading"><a></a>Human review remains the last security control</h2>



<p class="wp-block-paragraph">1Password argues that these shortcomings stem from the contextual reasoning required to produce production-ready security fixes.</p>



<p class="wp-block-paragraph">Anthropic was reached out to and reportedly recommended keeping humans in the loop. “Patch generation has outpaced patch verification, and the fix is to make verification execution-grounded rather than inspection-based, while keeping domain experts as the final reviewers at current model capabilities,” it was quoted as saying.</p>



<p class="wp-block-paragraph">1Password also challenged the notion that AI-generated patches are effectively “free.” While the average patch-and-validation cycle cost approximately $2.11 using ChatGPT-5.5 and $2.81 using Claude Opus 4.8, Hoodlet argued that the real expense lies in validating whether those patches are secure enough for production.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What does a data breach cost? AI is a sizable factor]]></title>
<description><![CDATA[The financial impact of a data breach is substantial for any modern business, regardless of industry or size. IBM’s latest Cost of a Data Breach report discovered that, from March 2025 to February 2026, the average cost of a data breach rose to $6 million, up 35% from $4.44 million a year earlier...]]></description>
<link>https://tsecurity.de/de/3710446/it-security-nachrichten/what-does-a-data-breach-cost-ai-is-a-sizable-factor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710446/it-security-nachrichten/what-does-a-data-breach-cost-ai-is-a-sizable-factor/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:24 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The financial impact of a data breach is substantial for any modern business, regardless of industry or size. <a href="https://www.ibm.com/reports/data-breach">IBM’s latest Cost of a Data Breach report</a> discovered that, from March 2025 to February 2026, the average cost of a <a href="https://www.csoonline.com/article/574289/twitters-mushrooming-data-breach-crisis-could-prove-costly.html">data breach</a> rose to $6 million, up 35% from $4.44 million a year earlier.</p>



<p class="wp-block-paragraph">The 2026 report, conducted by Ponemon Institute and sponsored by IBM, is based on an analysis of data breaches experienced by 600 organizations globally.</p>



<p class="wp-block-paragraph">According to the report, one in four malicious breaches were AI-enabled. Deepfake impersonation and AI-enabled malware made up the majority of these AI-assisted attacks.</p>



<p class="wp-block-paragraph">The study found that AI and automation in security operations cut breach costs by an average of almost $2 million dollars. Despite that impact, one in four organizations have yet to adopt these tools in their security operations, the survey found.</p>



<p class="wp-block-paragraph">In a follow-up study, more than half the organizations reported using agents for threat detection and containment but only 18% apply agents to vulnerability management. Three in four of the enterprises polled say that frontier AI threats are prompting them to rethink how agents are deployed across their security operations.</p>



<p class="wp-block-paragraph">“AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs,” says <strong>Suja Viswesan, VP of IBM Security Software</strong>.</p>



<h2 class="wp-block-heading">AI models under attack</h2>



<p class="wp-block-paragraph">One in five organizations reported a breach targeting AI models or applications. The most common causes were weaknesses in surrounding systems: compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%).</p>



<p class="wp-block-paragraph">The vast majority of organizations suffering AI-related breaches lacked proper access controls, yet only 40% deployed access controls on their AI models and data.</p>



<p class="wp-block-paragraph">Improving access controls on AI models is the most obvious security gap to close, according to Kayne McGladrey, a senior member of IEEE, CISSP-certified cybersecurity advisor, and former CISO of compliance automation vendor Hyperproof.</p>



<p class="wp-block-paragraph">“Treat your models and their APIs like crown jewels,” says McGladrey. “If you wouldn’t expose your database to the public internet without identity and access controls, why would you do that for your AI model?”</p>



<p class="wp-block-paragraph">Udaya Bhaskar Vemuri, senior application security analyst and DevSecOps professional, adds that organizations should also be “reviewing integrations and plug-ins, monitoring unusual activity, protecting sensitive data, and making sure every AI system has a clearly defined owner who is responsible for its security and oversight.”</p>



<h2 class="wp-block-heading">Prompt criticality</h2>



<p class="wp-block-paragraph">Beyond deepfakes and AI malware, <a href="https://www.csoonline.com/article/3850783/11-ways-cybercriminals-are-making-phishing-more-potent-than-ever.html">AI-driven phishing</a> and <a href="https://www.csoonline.com/article/4110008/top-cyber-threats-to-your-ai-systems-and-infrastructure.html">direct attacks on AI models</a>, such as prompt injection, are emerging as costly enterprise blind spots.</p>



<p class="wp-block-paragraph">“The threat isn’t just external; unapproved employee use of AI applications introduces unmanaged vulnerabilities into corporate environments,” says Dray Agha, senior manager of security operations at managed detection and response firm Huntress.</p>



<p class="wp-block-paragraph">CISOs must shift to proactive governance by embedding security into development workflows, managing exposures aggressively, and applying strict access controls to AI workloads, Agha advises.</p>



<p class="wp-block-paragraph">Peter Garraghan, CSO and founder at AI security testing firm Mindgard, adds that blindly trusting in the effectiveness of AI security guardrails is fraught with risk.</p>



<p class="wp-block-paragraph">“Research has demonstrated that existing guardrails currently have various blind spots, and that a defense in depth approach is required,” says Garraghan. “Attackers are constantly adapting, so organizations need to continuously test AI models and applications against realistic adversarial attacks to identify where protections fail.”</p>



<p class="wp-block-paragraph">Garraghan adds: “By validating guardrails before and throughout deployment, CISOs can ensure AI systems are resilient enough to protect sensitive data, and user privacy as threats evolve.”</p>



<p class="wp-block-paragraph">Attackers are compromising APIs, plug-ins, and cloud misconfigurations around models rather than defeating them, according to Ariel Parnes, co-founder and COO of cloud security vendor Mitiga.</p>



<p class="wp-block-paragraph">“These attacks land in the telemetry of the cloud and identity environments, not in the model itself, so the defense is behavioral detection across everything the AI touches,” Parnes advises.</p>



<h2 class="wp-block-heading">Upping the ante</h2>



<p class="wp-block-paragraph">The abuse of AI tools by attackers doesn’t just mean enterprises are subject to more sophisticated attacks. It also means that these attacks unfold more quickly.</p>



<p class="wp-block-paragraph">“Organizations need to respond with the same level of automation, but with strong guardrails,” says John-Paul Cunningham, CISO at identity security vendor Silverfort. “AI can improve the speed of cyber defense, but only if organizations build governance and accountability into those systems from the start.”</p>



<h2 class="wp-block-heading">Regional costs</h2>



<p class="wp-block-paragraph">Average breach costs in the US reached a record $11.5 million, an 11% increase over last year and nearly double the global average.</p>



<p class="wp-block-paragraph">This rise was driven in part by steeper regulatory penalties and higher business costs, according to the IBM-sponsored study.</p>



<p class="wp-block-paragraph">The Middle East, which considered Saudi Arabia and the United Arab Emirates for the report, was No. 2 of the 16 countries and regions surveyed, at $8 million.</p>



<p class="wp-block-paragraph">Canada ($5.2 million) and the UK ($4.17 million) remain in the top 10 hardest hit, with ASEAN or Association of Southeast Asian Nations ($4.12 million), <a href="https://www.csoonline.com/article/1309403/australian-government-back-on-top-5-sectors-with-most-reported-data-breaches.html">Australia</a> ($2.96 million), and India ($2.79 million) among the top 15.</p>



<p class="wp-block-paragraph">Phishing topped initial attack vectors and led to the costliest breaches. Social engineering, such as impersonating help desk staff, was used in 13% of attacks while voice and SMS phishing featured in 17% of attacks.</p>



<h2 class="wp-block-heading">Breaches by industry</h2>



<p class="wp-block-paragraph">Healthcare remains the industry hit with the highest average costs per breach at $6.64 million despite a drop from $7.42 million last year.</p>



<p class="wp-block-paragraph">Attackers continue to value and target the industry’s patient personal identification information (PII), which can be used for identity theft, insurance fraud, and other financial crimes.</p>



<p class="wp-block-paragraph">The mean time organizations took to identify and contain a breach rose to 247 days, a slight 2.5% year-on-year increase that reversed a five-year decline. “New threats from AI-driven attacks are challenging even the quickest response times,” the IBM-sponsored study notes.</p>



<p class="wp-block-paragraph"><strong>Average breach cost by industry</strong></p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Industry</strong></td><td><strong>2026</strong></td><td><strong>2025</strong></td><td><strong>Change</strong></td></tr><tr><td>Healthcare</td><td>$6.64M</td><td>$7.42M</td><td>-11%</td></tr><tr><td>Financial</td><td>$6.29M</td><td>$5.56M</td><td>+13%</td></tr><tr><td>Industrial</td><td>$5.50M</td><td>$5.00M</td><td>+10%</td></tr><tr><td>Technology</td><td>$5.50M</td><td>$4.79M</td><td>+15%</td></tr><tr><td>Entertainment</td><td>$5.38M</td><td>$4.43M</td><td>+21%</td></tr><tr><td>Pharmaceuticals</td><td>$5.25M</td><td>$4.61M</td><td>+13%</td></tr><tr><td>Energy</td><td>$5.24M</td><td>$4.83M</td><td>+8%</td></tr><tr><td>Professional services</td><td>$5.08M</td><td>$4.56M</td><td>+11%</td></tr><tr><td>Communications</td><td>$4.71M</td><td>$3.75M</td><td>+26%</td></tr><tr><td>Transportation</td><td>$4.50M</td><td>$3.98M</td><td>+13%</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Breach cost variables</h2>



<p class="wp-block-paragraph">While industry averages provide benchmarks, calculating the true, final cost of a specific data breach is notoriously difficult and relies heavily on forecasting.</p>



<p class="wp-block-paragraph">“Immediate technical costs are quantifiable, but devastating long-term impacts like reputational damage, lost business, and regulatory fines are intangibles, making total breach cost figures informed estimates rather than exact science,” says Huntress’ Agha.</p>



<p class="wp-block-paragraph">Several experts quizzed by CSO named the cybersecurity skills gap, supply chain vulnerabilities, and the escalating threat landscape as the three main factors in making breaches more expensive and harder to manage.</p>



<p class="wp-block-paragraph">AJ Thompson, chief commercial officer at IT consultancy Northdoor, who sits on IBM’s Worldwide Security Advisory Council advising on data access and security, says the “bigger cost driver is still ‘how fast you spot a breach’ rather than the sophistication of an attack.”</p>



<p class="wp-block-paragraph">“A shortage of experienced security staff and patchy visibility into supply chain and third-party risk both stretch out that detection window, and every extra week unnoticed adds to the bill,” Thompson adds.</p>



<h2 class="wp-block-heading"><a></a>Reputational damage remains a key cost of being breached</h2>



<p class="wp-block-paragraph">In many ways immeasurable, <a href="https://www.csoonline.com/article/571857/the-emotional-stages-of-a-data-breach-how-to-deal-with-panic-anger-and-guilt.html">reputational damage</a> remains among the most significant costs in the wake of a breach. “Ultimately, customer trust is very easy to break, and very difficult to build,” <a href="https://www.forrester.com/analyst-bio/allie-mellen/BIO16084">Allie Mellen</a>, senior analyst at Forrester, tells CSO.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/businessvalue/">Bob Dutile</a>, chief commercial officer at UST, agrees: “The cost of a data breach is typically realized in relative competitive change in the marketplace. Companies find that their brand does not command the same price premium, customer conversion costs are higher, and market share is lost. For a public company, the near-term assessment of the cost impact is reflected in stock price movement.”</p>



<p class="wp-block-paragraph">According to Dutile, research shows that between $8 million and $10 million is a good planning number in the US for a midsize business facing a modest breach of under 250,000 records. About a third of that cost will be loss of business due to reputation damage.</p>



<p class="wp-block-paragraph">How a company responds to and communicates a breach can have a large bearing on that reputational impact, Forrester’s Mellen notes. “Understanding how to maintain trust with your consumers and customers is really critical here,” she adds. “There are ways to do this, especially around building transparency and using empathy, which can make a huge difference in how your customers perceive you after a breach. If you try to sweep it under the rug or hide it, then that will truly affect their trust in you far more than the breach alone.”</p>



<h2 class="wp-block-heading">Severe business downtime can cost millions</h2>



<p class="wp-block-paragraph">Business downtime can also be significantly costly for a breached organization, depending on the level and extent of the downtime and how technology-dependent the firm is.</p>



<p class="wp-block-paragraph">Nearly all the organizations studied suffered operational disruption, taking an average of 100 days to recover from a security incident.</p>



<p class="wp-block-paragraph"><a href="https://heretoserve.org/team/jason-hicks/">Jason Hicks</a>, field CISO at Coalfire, tells CSO: “Often a breach is not going to take a company completely offline, but it can happen. The more critical systems that are taken down, the more significant the cost.”</p>



<p class="wp-block-paragraph">Manufacturing tends to have the best metrics around this, as it’s relatively simple to measure the cost per minute if an assembly line is down, Hicks says. “This can translate into millions of dollars a day for a large manufacturing company. This can be more nebulous for other industry verticals, but there are models to get a reasonable feel that can be applied to each vertical.”</p>



<h2 class="wp-block-heading">Regulation and litigation add to data breach costs</h2>



<p class="wp-block-paragraph">Increasingly strict <a href="https://www.csoonline.com/article/573561/instagram-faces-402-million-fine-for-alleged-mishandling-of-childrens-data.html">data protection and privacy laws</a> along with litigation are seeing a growing number of companies issued large fines, paying hefty settlements, and stumping up for legal fees following data breaches and non-compliance.</p>



<p class="wp-block-paragraph">“Regulated industries suffer not only the immediate cost of responding to, containing, and remediating vulnerabilities but also the long-term effects of additional penalties from their regulatory bodies and legal settlements,” Nick says. Highly regulated industries, such as healthcare and financial services, typically run one and two in order of cost per breach because they will pay more non-compliance fines than others, he adds.</p>



<p class="wp-block-paragraph">“Investigation and adjudication often take years for the victim organization to reach a monetary settlement with affected parties.” <a href="https://www.csoonline.com/article/574681/paypal-sued-for-negligence-in-data-breach-that-affected-35000-users.html">Legal costs</a> are one of the largest expenditures organizations face in data breaches, Nick states. “Organizations rarely have the legal and privacy expertise in-house. To ensure compliance, they must hire outside counsel to lead their reporting.”</p>



<h2 class="wp-block-heading">The role of cyber insurance</h2>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/571703/cyber-insurance-explained.html">Cyber insurance</a> is one way that companies mitigate the cost risks of breaches. Sharp increases in cyber insurance premiums <a href="https://www.csoonline.com/article/3537205/cyber-insurance-price-hikes-stabilize-as-insurers-expect-more-from-cisos.html">have been stabilizing of late</a>, but even organizations covered by insurance can expect to dole out extra cash to make good after a breach. One definite cost hit will be a hike in their premiums, Guidehouse’s Nick says.</p>



<p class="wp-block-paragraph">“Some organizations have reported post-breach increases in premiums of approximately 200%,” he adds.</p>



<p class="wp-block-paragraph">Insurers are also implementing more coverage limitations, meaning that even with a policy in place, businesses could find themselves financially responsible for certain breach-related costs.</p>



<p class="wp-block-paragraph">In fact, Forrester’s Mellen says any notion that policies will allow organizations to fully recover financially from a cyberattack is folly. “In reality, it’s not going to cover all of the costs associated with any type of cyberattack, and we see some insurance firms not even covering ransomware at this point as part of their payouts,” she adds.</p>



<p class="wp-block-paragraph">Another factor to consider is that cyber insurance providers typically have a list of approved service providers such as lawyers and forensics firms, Hicks says.</p>



<p class="wp-block-paragraph">“If your preferred provider is not on their list, you may have to work with them to get them included, or potentially have to change providers. This can be costly, as firms are often leveraging their existing service providers to secure the maximum discounts based on the volume of work done with the partners,” Hicks says.</p>



<h2 class="wp-block-heading">Ransomware extortion on the rise</h2>



<p class="wp-block-paragraph">Reported ransomware incidents rose in the last 12 months compared to the year prior (39% vs. 34%) as attackers have abused AI technologies to automate and scale their attacks.</p>



<p class="wp-block-paragraph">While disrupting operations through encrypting<strong> </strong>remains a key tactic (23%), attackers are shifting to higher-impact pressure methods, such as threatening to leak stolen data (a common feature of so-called double extortion attacks).</p>



<h2 class="wp-block-heading">Insufficient security staffing leads to higher breach costs</h2>



<p class="wp-block-paragraph">According to IBM’s latest report, the security skills shortage is one of the biggest data breach cost amplifiers, with the average additional cost of data breach due to cyber skills shortage pegged at $180,000.</p>



<p class="wp-block-paragraph">If insufficient security staff equates to greater data breach costs, organizations should heed Mellen’s warning about the impact a poorly handled data breach can have on employees.</p>



<p class="wp-block-paragraph">“If they don’t feel like the organization is able to protect them or customers in the event of a breach, or that they blame their employees for a breach, then they’re likely going to start looking for jobs elsewhere because it creates a bit of a hostile environment for them,” she says. “It is very important for organizations to recognize that they need to accept responsibility and protect both their employees and their customers.”</p>



<p class="wp-block-paragraph">Taking a DevSecOps approach to software development was the No. 1 factor that reduced breach costs, according to the report, ahead of use of identity and access management. Running key lifecycle management tools rounded out the top three factors.</p>



<p class="wp-block-paragraph">Security incidents involving <a href="https://www.csoonline.com/article/3964282/cisos-no-closer-to-containing-shadow-ais-skyrocketing-data-risks.html">shadow or unsanctioned use of AI tools</a> more than doubled to 43% this year compared to 20% in 2025. Shadow AI is starting to rival supply chain breaches and security system complexity as a leading factor in exacerbating breach costs, according to the report.</p>



<h2 class="wp-block-heading"><a></a>Preparedness is key to managing data breach costs</h2>



<p class="wp-block-paragraph">No matter the specific costs involved, experts agree that preparedness is key to mitigating the financial repercussions of a breach.</p>



<p class="wp-block-paragraph">“Faster incident response continues to be a clear driver for lowering the cost of a breach,” UST’s Dutile says. “The worst losses are those that go undetected for an extended time or have a slow or ineffective response.”</p>



<p class="wp-block-paragraph">To that end, more than half of organizations surveyed say they plan to invest in AI security and governance tools post-breach, an 88% increase from last year and a reaction to concerns over frontier AI model threats.</p>



<p class="wp-block-paragraph">Modern cybersecurity requires a post-breach mindset which understands that, eventually, a successful data breach is going to occur, Forrester’s Mellen adds.</p>



<p class="wp-block-paragraph">“Operating under those conditions, you need to figure out how you’re going to handle that and build your resiliency to respond better and faster. This isn’t just about the security function either, and it needs to be spread across an organization, considering what marketing is going to do, what sales is going to do, etc. — how, as a business, you can demonstrate you value your customers and that you want to make it right as quickly and effectively as possible,” she says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors]]></title>
<description><![CDATA[Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs (CRIL), the region experienced 866 documented ransomware attacks, 51 confirmed data breach incidents, and 7 initial access...]]></description>
<link>https://tsecurity.de/de/3710441/it-security-nachrichten/ransomware-threats-in-europe-h1-2026-a-deep-dive-into-regional-attack-patterns-and-dominant-threat-actors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710441/it-security-nachrichten/ransomware-threats-in-europe-h1-2026-a-deep-dive-into-regional-attack-patterns-and-dominant-threat-actors/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:23 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1440" height="720" src="https://cyble.com/wp-content/uploads/2026/08/Ransomware-Threats-in-Europe-2026.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Ransomware, Ransomware Threats Europe, Ransomware in Europe" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/08/Ransomware-Threats-in-Europe-2026.webp 1440w, https://cyble.com/wp-content/uploads/2026/08/Ransomware-Threats-in-Europe-2026-300x150.webp 300w, https://cyble.com/wp-content/uploads/2026/08/Ransomware-Threats-in-Europe-2026-1024x512.webp 1024w, https://cyble.com/wp-content/uploads/2026/08/Ransomware-Threats-in-Europe-2026-768x384.webp 768w" sizes="(max-width: 1440px) 100vw, 1440px" title="Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors 2"></p>
<p><!-- wp:paragraph --></p>
<p>Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs (CRIL), the region experienced <strong>866 documented ransomware attacks</strong>, <strong>51 confirmed data breach incidents</strong>, and <strong>7 initial access sales</strong> between January and June 2026. These figures represent not just a volume problem, but a fundamental shift in how threat actors are organizing, targeting, and monetizing their operations within European territory.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>What distinguishes the ransomware threats in Europe from other global regions is the <strong>concentration of power among a small number of highly sophisticated threat actors</strong>. While the threat ecosystem encompasses dozens of groups, five dominant ransomware operators account for approximately 55% of all documented activity. This concentration creates predictability—European security leaders can now identify, profile, and build specific defensive strategies against known adversaries.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>The Five Dominant Ransomware Groups Targeting Europe</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>1. Qilin:</strong> The Biggest Ransomware Threat in Europe</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 158 documented incidents (18.2% of regional total)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Qilin stands as the dominant ransomware threat actor targeting Europe, commanding operational superiority through sophisticated affiliate management, rapid exploit weaponization, and industry-specific targeting intelligence.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Geographic Concentration:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Germany:</strong> 32 attacks (highest single-country targeting)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>France:</strong> 28 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>United Kingdom:</strong> 26 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Spain:</strong> 20 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Italy:</strong> 19 attacks</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Worldwide Sectoral Targeting:</strong> Qilin demonstrates deliberate sectoral selection rather than opportunistic targeting:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Construction:</strong> 103 incidents (primary focus)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Professional Services:</strong> 90 incidents (legal, accounting, consulting firms)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Manufacturing:</strong> 67 incidents (industrial operations)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Government &amp; Law Enforcement:</strong> 19 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Technology:</strong> 22 incidents</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Operational Characteristics:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><a href="https://thecyberexpress.com/qilin-inc-ransom-drive-2026-ransomware-surge/">Qilin's dominance</a> stems from understanding European organizational economics. Construction projects operate under time-sensitive contracts with contractually-defined penalties for delay. A single day of downtime on a €50 million construction project can trigger cascading costs exceeding €100,000. This economic reality translates directly into ransom payment likelihood, making Qilin's targeting strategy rational and highly effective.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The group maintains an extensive affiliate network capable of concurrent operations across multiple European nations. Evidence suggests Qilin has compartmentalized its operations: initial access brokers handle reconnaissance and network compromise, mid-tier operators manage lateral movement and privilege escalation, and final-stage operators execute encryption and exfiltration. This division of labor enables rapid scaling and reduces attribution risk.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Why Qilin Dominates:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Industry Expertise:</strong> Deep understanding of construction project timelines and financial exposure</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Affiliate Loyalty:</strong> Competitive payout structures (estimated 70-80% to affiliates) ensure consistent operator recruitment</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Exploit Library:</strong> Rapid weaponization of both known and zero-day vulnerabilities</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Data Monetization:</strong> Established data brokerage partnerships ensure exfiltrated data reaches buyers</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>European Security Implications:</strong> Organizations in construction, professional services, and manufacturing should treat Qilin as their primary threat actor concern. Defensive strategies must prioritize data exfiltration prevention, network segmentation, and immutable backup infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>2. The Gentlemen:</strong> The Rising European Threat</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 144 documented incidents (16.6% of regional total)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Gentlemen represent an emerging threat actor that has achieved remarkable scale in a relatively short operational window. Unlike established groups that evolved from other cybercriminal operations, The Gentlemen appear purpose-built for ransomware-as-a-service operations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Geographic Concentration:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Europe:</strong> 144 attacks (primary focus)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>United States:</strong> 100 attacks (secondary focus)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Thailand:</strong> 35 attacks (supply-chain targeting)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>South Asia:</strong> 40 attacks</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Worldwide Sectoral Targeting:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Construction:</strong> 45 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Manufacturing:</strong> 56 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Healthcare:</strong> 37 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>IT &amp; ITES:</strong> 36 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Professional Services:</strong> 29 incidents</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Operational Characteristics:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Gentlemen's rapid emergence and sustained growth suggest significant operational funding and technical sophistication. The group's geographic diversification—maintaining European dominance while aggressively expanding into Asia-Pacific—indicates either organizational scale or partnerships with regional threat actors.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Notably, The Gentlemen's Thailand targeting (35 incidents) suggests supply-chain attack sophistication. By compromising manufacturing and logistics operations in Thailand, the group can leverage these beachheads for downstream attacks against Western European organizations. This cross-continental supply-chain targeting represents a significant evolution in ransomware operational sophistication.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Key Distinction:</strong> While Qilin focuses on maximizing ransom payments from individual targets, The Gentlemen appear to prioritize <strong>operational scale and geographic expansion</strong>. This suggests the group may be building toward either:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li>A mega-RaaS platform rivaling LockBit's historical dominance</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Preparation for potential acquisition or partnership with state-sponsored actors</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Geographic arbitrage—leveraging lower prosecution risk in developing nations while maintaining European operations</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>European Security Implications:</strong> The Gentlemen's emergence signals market competition is intensifying. Organizations should monitor this group's operational evolution closely, as aggressive growth often precedes operational mistakes that create defensive opportunities.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>3. LockBit:</strong> The Persistent Legacy Threat</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 61 documented incidents (7.0% of regional total)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>LockBit's presence in European targeting represents a significant finding given sustained law enforcement pressure and multiple platform disruption attempts. Despite being targeted by coordinated international takedown operations, LockBit maintained operational capability throughout H1 2026.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Geographic Concentration:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Europe:</strong> 61 attacks (Primary operations)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>North America:</strong> 47 attacks (Secondary operations)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Distributed:</strong> Global presence indicating resilient infrastructure</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Worldwide Sectoral Targeting:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Construction:</strong> 22 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Manufacturing:</strong> 22 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Government &amp; LEA:</strong> 12 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Healthcare:</strong> 19 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Professional Services:</strong> 13 incidents</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Operational Resilience:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>LockBit's continued operations despite international enforcement actions demonstrate several critical lessons:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li><strong>Affiliate Compartmentalization:</strong> By maintaining separate operational cells, LockBit can continue operations even when core infrastructure is disrupted</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Rapid Rebranding:</strong> The group has adopted multiple identities and platform variants, complicating attribution</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Infrastructure Redundancy:</strong> Multiple command-and-control server locations across jurisdictions with varying law enforcement cooperation levels</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Operator Recruitment:</strong> Continuous recruitment of new affiliates from emerging cybercriminal talent pools</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The group's continued viability suggests that <strong>law enforcement actions, while disruptive, are insufficient to eliminate established RaaS operations</strong>. Organizations cannot rely on law enforcement intervention as a defensive strategy; they must assume LockBit and similar groups will remain operational threats indefinitely.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>European Security Implications:</strong> LockBit should remain on European security teams' active threat monitoring lists. The group maintains technical sophistication, access to critical zero-day exploits, and demonstrated willingness to target European critical infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>4. Akira:</strong> The Opportunistic European Operator</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 59 documented incidents (6.8% of regional total)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Akira represents a secondary-tier ransomware group with focused European operations. The group demonstrates strong preference for Manufacturing and Construction sectors, suggesting industry-specific expertise or targeted affiliate recruitment.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Geographic Concentration:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Europe &amp; UK:</strong> 59 attacks (Secondary focus)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>North America:</strong> 268 attacks (Primary focus)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Secondary:</strong> Limited operations in other regions</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Worldwide Sectoral Targeting:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Manufacturing:</strong> 54 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Construction:</strong> 57 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Professional Services:</strong> 47 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Consumer Goods:</strong> 34 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Healthcare:</strong> 13 incidents</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Operational Profile:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Akira's disproportionate North American presence (268 attacks) with lower European activity (59 attacks) suggests the group may have established affiliate networks in North America with secondary capacity for European operations. The strong manufacturing and construction focus mirrors Qilin's strategy, indicating these sectors offer superior ransom payment likelihood across multiple geographic markets.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>European Security Implications:</strong> While not as immediately threatening as Qilin or The Gentlemen, Akira's persistent operations warrant inclusion in threat modeling exercises. European manufacturing and construction organizations should monitor Akira's affiliate recruitment channels and tactical innovations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>5. Dragonforce:</strong> The Supply-Chain Specialist</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 54 documented incidents (6.2% of regional total)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Dragonforce rounds out the top-five European threat actors with apparent specialization in Manufacturing and Technology sectors, suggesting possible supply-chain attack capabilities.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Geographic Concentration:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>North America:</strong> 135 attacks (Primary focus)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Europe &amp; UK:</strong> 54 attacks (Secondary focus)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Secondary:</strong> Limited global operations</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Worldwide Sectoral Targeting:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Manufacturing:</strong> 31 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Construction:</strong> 48 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Professional Services:</strong> 28 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Food &amp; Beverages:</strong> 9 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Healthcare:</strong> 9 incidents</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Operational Pattern:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Dragonforce's heavy US focus with secondary European operations suggests the group may be leveraging North American-based supply chains to gain access to European targets. Manufacturing supply chains are deeply interconnected across transatlantic partners; compromising US manufacturers could provide lateral access into European operations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>European Security Implications:</strong> European manufacturing organizations should implement aggressive third-party risk management programs, particularly for US-based suppliers. Dragonforce's supply-chain sophistication suggests the group may bypass direct targeting in favor of compromising upstream vendors.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":5} --></p>
<h5 class="wp-block-heading"><strong>Also read:</strong> <a href="https://cyble.com/blog/most-active-threat-actors-h1-2026/">The Most Active Threat Actors of H1 2026</a></h5>
<p><!-- /wp:heading --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>The Five Most Targeted European Nations</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:image {"id":123078,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/08/Top-European-Nations-Targeted-by-Ransomware-in-2026_H1-1-1024x217.webp" alt="" class="wp-image-123078"><figcaption class="wp-element-caption">Top five European Nations Attacked by Ransomware Actors in 2026 H1 (Source: Cyble Research)</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Germany: </strong>The Manufacturing Battleground</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 155 ransomware attacks (17.9% of regional total)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Germany's position as Europe's manufacturing powerhouse places it at the center of ransomware targeting campaigns. The nation's industrial sector—encompassing automotive, machinery, chemicals, and precision manufacturing—represents the most valuable ransomware target set in Europe.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Threat Actor Concentration:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Qilin:</strong> 32 attacks (20.6% of German total)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>The Gentlemen:</strong> 32 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>LockBit:</strong> 18 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Akira:</strong> 32 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Dragonforce:</strong> 9 attacks</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Sectoral Breakdown:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Manufacturing:</strong> 67 incidents (significant concentration)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Construction:</strong> 38 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Professional Services:</strong> 28 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Technology:</strong> 15 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Healthcare:</strong> 12 incidents</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Why Germany Faces Maximum Pressure</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>German organizations represent an optimal target combination: high asset value, supply-chain criticality, strong operational technology integration, and proven willingness to pay ransoms to maintain production schedules. Additionally, Germany's federal structure creates jurisdictional complexity that may slow law enforcement response.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The nation's Mittelstand (mid-market manufacturing firms) are particularly vulnerable—large enough to justify ransom payments, but sometimes lacking enterprise-grade security infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Defensive Priority:</strong> German manufacturing organizations should assume Qilin, The Gentlemen, Akira, and Dragonforce all maintain active operations targeting their sector. Network segmentation between IT and operational technology (OT) environments should be elevated to critical priority.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>United Kingdom:</strong> The Financial Services Crosshairs</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 138 ransomware attacks (15.9% of regional total)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The UK faces a different threat profile than Germany, driven primarily by London's position as a global financial services hub. While manufacturing is targeted, Banking, Financial Services, and Insurance (BFSI) organizations command disproportionate attention.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Threat Actor Concentration:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Qilin:</strong> 26 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>The Gentlemen:</strong> 26 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>LockBit:</strong> 18 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Akira:</strong> 13 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Dragonforce:</strong> 11 attacks</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Sectoral Breakdown:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>BFSI:</strong> 38 incidents (concentrated targeting)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Technology:</strong> 32 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Retail:</strong> 26 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Professional Services:</strong> 24 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Government &amp; LEA:</strong> 16 incidents</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Why the UK Is Targeted</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>London's financial services ecosystem manages trillions in assets, making it extraordinarily valuable to data-exfiltrating threat actors. BFSI organizations hold customer financial data, internal financial records, and strategic information that commands premium prices on dark web marketplaces.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, regulatory requirements (FCA, PRA, etc.) create pressure for rapid ransom payment to avoid breach notification delays that could trigger regulatory sanctions.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Data Exfiltration Risk:</strong> The UK's status as a financial services hub makes it particularly vulnerable to data-centric attack strategies. Organizations should assume that successful breach attempts will include aggressive data exfiltration alongside encryption deployment.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Defensive Priority:</strong> UK BFSI organizations must implement robust data loss prevention (DLP), encryption for data in transit and at rest, and aggressive monitoring for unauthorized data access or exfiltration attempts.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>France:</strong> The Balanced Threat</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 119 ransomware attacks (13.7% of regional total)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>France experiences balanced threat distribution across multiple sectors, reflecting both its manufacturing capacity and significant professional services sector.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Threat Actor Concentration:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Qilin:</strong> 28 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>The Gentlemen:</strong> 28 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>LockBit:</strong> 15 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Akira:</strong> 14 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Dragonforce:</strong> 8 attacks</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Sectoral Breakdown:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Professional Services:</strong> 26 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Manufacturing:</strong> 24 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Construction:</strong> 19 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Technology:</strong> 14 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Healthcare:</strong> 10 incidents</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Why France Faces Distributed Threat</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>As Europe's second-largest economy, France is attractive to ransomware operators across multiple sectors. The nation's professional services sector (legal, accounting, consulting) is particularly valuable for data exfiltration, while manufacturing remains a consistent target.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Defensive Priority:</strong> French organizations should implement sector-specific defensive strategies: professional services firms should prioritize client data protection and DLP, while manufacturing organizations should focus on OT segmentation and operational resilience.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Italy:</strong> The Construction and Manufacturing Hub</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 115 ransomware attacks (13.3% of regional total)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Italy faces concentrated targeting in construction and manufacturing sectors, with particular pressure on small-to-medium enterprises in industrial regions.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Threat Actor Concentration:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Qilin:</strong> 19 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>The Gentlemen:</strong> 18 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>LockBit:</strong> 12 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Akira:</strong> 16 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Dragonforce:</strong> 8 attacks</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Sectoral Breakdown:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Construction:</strong> 48 incidents (concentrated)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Manufacturing:</strong> 38 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Professional Services:</strong> 18 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Retail:</strong> 14 incidents</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Why Italy Faces Sector-Specific Pressure</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Italy's construction industry is particularly vulnerable to ransom attacks due to tight project timelines and significant financial exposure. The nation's manufacturing sector, while sophisticated, sometimes operates with legacy infrastructure that creates exploitation opportunities.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Defensive Priority:</strong> Italian construction and manufacturing organizations should prioritize incident response readiness, backup infrastructure resilience, and supply-chain risk management.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Spain:</strong> The Emerging Risk</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 87 ransomware attacks (10.0% of regional total)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Spain experiences lower absolute attack volume than Germany, UK, France, or Italy, but faces concentrated pressure in manufacturing and professional services sectors.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Threat Actor Concentration:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Qilin:</strong> 20 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>The Gentlemen:</strong> 18 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>LockBit:</strong> 8 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Akira:</strong> 12 attacks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Dragonforce:</strong> 7 attacks</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Sectoral Breakdown:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Manufacturing:</strong> 28 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Professional Services:</strong> 19 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Construction:</strong> 16 incidents</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Technology:</strong> 10 incidents</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Regional Observation:</strong> Spain's lower attack volume may reflect either lower overall ransomware targeting or more effective defensive implementations. Spanish security teams should not interpret lower numbers as reduced threat but rather as a baseline for future comparison.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"lightbox":{"enabled":false},"id":123081,"width":"605px","height":"auto","aspectRatio":"1.7902683831551385","sizeSlug":"large","linkDestination":"custom"} --></p>
<figure class="wp-block-image size-large is-resized"><a href="https://cyble.com/resources/research-reports/global-threat-landscape-h1-2026/" target="_blank" rel=" noreferrer noopener"><img src="https://cyble.com/wp-content/uploads/2026/08/Global-Threat-Landscape-H1-2026_LI-Banner-1024x572.jpg" alt="" class="wp-image-123081"></a></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Where European Organizations Face Maximum Risk: </strong>A Sectoral Analysis</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Construction:</strong> The Ransomware Goldmine</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 107 documented incidents (58% of all sector targeting across regions – not just in Europe – analyzed)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Construction organizations face disproportionate ransomware targeting across the entire European region. This concentration reflects understood economic vulnerabilities that threat actors exploit with precision.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Why Construction Is Targeted</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li><strong>Time-Sensitive Financial Exposure:</strong> Construction projects operate under contractually-defined timelines. Each day of delay triggers cascading costs, financial penalties, and potential contract termination. Organizations facing potential loss of €50-100 million contracts will prioritize rapid recovery over law enforcement involvement.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Operational Technology Integration:</strong> Modern construction increasingly relies on Building Information Modeling (BIM), cloud-based project management, and real-time equipment tracking. This IT/OT convergence creates exploitation pathways unavailable in purely IT-based industries.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Supply-Chain Complexity:</strong> Construction projects depend on dozens of subcontractors and suppliers. Compromising a single upstream supplier can provide lateral access into prime contractors.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Financial Pressure:</strong> Construction firms often operate with tight cash flow, making ransom negotiation essential to preserve solvency.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Accessibility:</strong> Many construction firms, particularly smaller regional players, operate with basic security infrastructure, creating easy exploitation opportunities.</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>European Construction Risk Mapping:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Germany (14 attacks):</strong> Heavy machinery and precision manufacturing integration</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Switzerland (10 attacks):</strong> Legacy infrastructure vulnerabilities</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Spain (13 attacks):</strong> Emerging targeting activity</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>France (10 attacks):</strong> Balanced threat across major metropolitan areas</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>UK (21 attacks):</strong> Infrastructure project concentration (rail, utilities, etc.)</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Defensive Recommendations for Construction:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Network Segmentation:</strong> Isolate operational technology (project equipment, heavy machinery) from corporate IT networks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Access Control:</strong> Implement strict authentication for remote project management tools (Autodesk Forge, Procore, etc.)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Immutable Backups:</strong> Maintain offline, immutable backups of critical BIM files and project documentation</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Incident Response Readiness:</strong> Develop construction-specific response playbooks addressing project continuity</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Supply-Chain Due Diligence:</strong> Implement security requirements for subcontractors and equipment suppliers</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Professional Services:</strong> The Data Exfiltration Target</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 86 documented incidents</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Professional services firms (law, accounting, consulting) face sophisticated targeting driven by data exfiltration opportunities rather than operational disruption pressure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Why Professional Services Are Targeted</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li><strong>Client Confidentiality Risk:</strong> Legal privilege and client confidentiality create existential regulatory and reputational exposure. Threat actors leverage this to demand premium ransoms.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Sensitive Data Concentration:</strong> Professional services firms accumulate client financial records, litigation strategies, tax information, and corporate secrets—all commanding premium dark web prices.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Regulatory Exposure:</strong> GDPR breach notification requirements create pressure for rapid response and ransom payment to avoid regulatory sanctions.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Supply-Chain Position:</strong> Professional services firms advise major corporations; compromising advisors provides indirect access to clients.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Trust-Based Business Model:</strong> Client relationships depend on confidentiality. A single breach can destroy long-term client relationships and firm reputation.</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>European Professional Services Risk:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>France (16 attacks):</strong> Concentrated targeting of Paris-based firms</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Germany (16 attacks):</strong> Heavy focus on Frankfurt financial advisory firms</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>UK (17 attacks):</strong> London-based legal and accounting partnerships</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Italy (6 attacks):</strong> Milan and Rome-based advisory firms</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Spain (7 attacks):</strong> Barcelona and Madrid professional services sector</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Key Finding:</strong> Professional services firms experience disproportionate <strong>data breach incidents</strong> (exfiltration with confirmed leak activity) compared to other sectors. Of the 51 total data breach incidents across Europe and UK, professional services represents a concentrated target.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Defensive Recommendations:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Client Data Segregation:</strong> Isolate client data on separate network segments with distinct access controls</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Data Loss Prevention (DLP):</strong> Deploy DLP solutions with aggressive egress controls monitoring client data exfiltration</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Encryption Standards:</strong> Implement client-facing encryption for all sensitive communications</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Access Auditing:</strong> Maintain comprehensive logs of all access to sensitive client data</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Ransomware-Specific Insurance:</strong> Consider cyber insurance with specific ransomware coverage addressing confidentiality exposure</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Manufacturing:</strong> The Supply-Chain Critical Target</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 123 documented incidents</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>European manufacturing organizations face sophisticated, supply-chain-aware threat actors who understand production dependencies and downtime economics.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Why Manufacturing Is Targeted</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li><strong>Operational Technology Integration:</strong> Modern factories integrate IT and OT systems. Ransomware deployment can halt production lines, creating catastrophic financial exposure.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Supply-Chain Criticality:</strong> Manufacturing downtime cascades through dependent enterprises. A single organization's compromise can impact dozens of downstream customers.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Export Dependency:</strong> European manufacturers serve global markets. Production delays translate directly into lost revenue and market share.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Legacy Infrastructure:</strong> Many manufacturing facilities operate aging, unpatched systems integrated with newer IT infrastructure, creating exploitation bridges.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Financial Pressure:</strong> Manufacturing organizations face razor-thin margins; production downtime can drive solvency crises.</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Geographic Manufacturing Risk Concentration:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Germany (27 attacks):</strong> Automotive, machinery, precision manufacturing</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Italy (21 attacks):</strong> Fashion, machinery, chemical manufacturing</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>France (15 attacks):</strong> Automotive, aerospace, industrial manufacturing</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Spain (10 attacks):</strong> Automotive, machinery, manufacturing</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>UK (14attacks):</strong> Aerospace, automotive, precision manufacturing</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Critical Vulnerability Pattern:</strong> Manufacturing organizations are disproportionately targeting known, exploitable vulnerabilities in critical infrastructure appliances (network appliances, security tools, identity systems). Rather than deploying zero-days, threat actors exploit patched vulnerabilities that organizations have not implemented.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Defensive Recommendations:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>OT/IT Segmentation:</strong> Implement airgapped network separation between operational technology and corporate IT</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Vulnerability Management Prioritization:</strong> Focus patching efforts on network appliances, security tools, and identity systems</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Industrial Control System (ICS) Monitoring:</strong> Deploy behavioral monitoring for unusual activity on manufacturing control systems</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Immutable Backup Strategy:</strong> Maintain completely offline backups of critical manufacturing configurations</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Supply-Chain Security Program:</strong> Implement tier-1 and tier-2 supplier security assessments and vulnerability scanning</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Incident Response Scenario Planning:</strong> Develop detailed playbooks for production-line ransomware scenarios</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Healthcare:</strong> The Critical Infrastructure Threat</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Attack Volume:</strong> 35 documented incidents</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Healthcare organizations face a unique threat dynamic where ransomware directly endangers patient safety, creating existential operational pressure distinct from financial threats.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Why Healthcare Is Targeted</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li><strong>Patient Safety Risk:</strong> Ransomware disables critical medical systems (diagnostic equipment, pharmaceutical dispensing, patient records). Unlike other industries, downtime directly threatens life.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Regulatory Pressure:</strong> GDPR, HIPAA-equivalent regulations, and national privacy laws create breach notification requirements that incentivize ransom payment.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Data Value:</strong> Patient medical records, pharmaceutical research data, and clinical trial information command premium dark web prices.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Continuous Operation Requirement:</strong> Unlike manufacturing or services, healthcare cannot delay critical procedures. The operational pressure to pay ransoms is existential.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>System Complexity:</strong> Healthcare IT environments integrate numerous legacy systems (PACS, EHR, medical devices) with varying security architectures.</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>European Healthcare Risk Distribution:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Germany (14 attacks):</strong> Concentrated in Berlin, Munich, and Frankfurt urban medical centers</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Austria (2 attacks):</strong> private healthcare sector</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>France (5 attacks):</strong> Concentrated in Paris and Lyon region hospitals</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Switzerland (3 attacks):</strong> medical centers</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Spain (3 attacks):</strong> Barcelona and Madrid hospital networks</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Critical Finding:</strong> Healthcare organizations experience disproportionately high data breach incident rates, suggesting organized threat actors specifically target health information exfiltration.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Defensive Recommendations:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Clinical System Isolation:</strong> Implement complete network separation between clinical systems and corporate IT</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Redundant Critical Systems:</strong> Deploy redundant diagnostic and pharmaceutical systems capable of manual operation</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Patient Data Encryption:</strong> Implement end-to-end encryption for all patient medical records</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Breach Response Planning:</strong> Develop healthcare-specific incident response plans addressing patient notification and continuity of care</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Medical Device Security:</strong> Implement inventory and monitoring for all connected medical devices</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Supply-Chain Assessment:</strong> Assess security of medical device manufacturers and pharmaceutical distributors</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>The Data Exfiltration Reality: </strong>Beyond Encryption</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Confirmed Data Breaches: 51 Incidents Across Europe and UK</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>While ransomware attacks total 866, only 51 incidents resulted in confirmed data breaches and leaks (5.9% confirmation rate). This apparent low percentage masks a critical operational truth: <strong>organizations cannot distinguish between encryption-only attacks and data exfiltration scenarios until exfiltration attempts or threats emerge</strong>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Data Breach Distribution by Sector:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table {"className":"is-style-stripes"} --></p>
<figure class="wp-block-table is-style-stripes">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Sector</strong></td>
<td class="has-text-align-center" data-align="center"><strong>Confirmed Breaches</strong></td>
<td class="has-text-align-center" data-align="center"><strong>Percentage</strong></td>
</tr>
<tr>
<td><strong>BFSI</strong></td>
<td class="has-text-align-center" data-align="center">9</td>
<td class="has-text-align-center" data-align="center">17.6%</td>
</tr>
<tr>
<td><strong>Telecom</strong></td>
<td class="has-text-align-center" data-align="center">9</td>
<td class="has-text-align-center" data-align="center">17.6%</td>
</tr>
<tr>
<td><strong>Retail</strong></td>
<td class="has-text-align-center" data-align="center">8</td>
<td class="has-text-align-center" data-align="center">15.7%</td>
</tr>
<tr>
<td><strong>Government &amp; LEA</strong></td>
<td class="has-text-align-center" data-align="center">6</td>
<td class="has-text-align-center" data-align="center">11.8%</td>
</tr>
<tr>
<td><strong>Media &amp; Entertainment</strong></td>
<td class="has-text-align-center" data-align="center">5</td>
<td class="has-text-align-center" data-align="center">9.8%</td>
</tr>
<tr>
<td><strong>Technology</strong></td>
<td class="has-text-align-center" data-align="center">4</td>
<td class="has-text-align-center" data-align="center">7.8%</td>
</tr>
<tr>
<td><strong>Healthcare</strong></td>
<td class="has-text-align-center" data-align="center">4</td>
<td class="has-text-align-center" data-align="center">7.8%</td>
</tr>
<tr>
<td><strong>Automotive</strong></td>
<td class="has-text-align-center" data-align="center">3</td>
<td class="has-text-align-center" data-align="center">5.9%</td>
</tr>
<tr>
<td><strong>Construction</strong></td>
<td class="has-text-align-center" data-align="center">2</td>
<td class="has-text-align-center" data-align="center">3.9%</td>
</tr>
<tr>
<td><strong>Education</strong></td>
<td class="has-text-align-center" data-align="center">1</td>
<td class="has-text-align-center" data-align="center">2.0%</td>
</tr>
<tr>
<td><strong>Others</strong></td>
<td class="has-text-align-center" data-align="center">6</td>
<td class="has-text-align-center" data-align="center">11.8%</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Critical Observation:</strong> BFSI and Telecom sectors experience disproportionate data breach incidents, suggesting these industries are specifically targeted for data exfiltration rather than operational disruption. The strategic implication is clear: threat actors targeting financial and telecommunications organizations prioritize <strong>data monetization</strong> over ransom payment.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Most Active Threat Actors in Data Exfiltration: The Leak Economy</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Primary Exfiltration Actors:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table {"className":"is-style-stripes"} --></p>
<figure class="wp-block-table is-style-stripes">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Actor</strong></td>
<td class="has-text-align-center" data-align="center"><strong>Confirmed Leak Posts</strong></td>
<td><strong>Targeting Pattern</strong></td>
</tr>
<tr>
<td><strong>tanaka</strong></td>
<td class="has-text-align-center" data-align="center">6</td>
<td>Industry-agnostic, global operations</td>
</tr>
<tr>
<td><strong>kazutlg</strong></td>
<td class="has-text-align-center" data-align="center">4</td>
<td>BFSI and Professional Services focus</td>
</tr>
<tr>
<td><strong>aslan1</strong></td>
<td class="has-text-align-center" data-align="center">2</td>
<td>Government and Technology sectors</td>
</tr>
<tr>
<td><strong>darkcybervault</strong></td>
<td class="has-text-align-center" data-align="center">2</td>
<td>Retail and Professional Services</td>
</tr>
<tr>
<td><strong>breach3d</strong></td>
<td class="has-text-align-center" data-align="center">2</td>
<td>Technology focus</td>
</tr>
<tr>
<td><strong>frog</strong></td>
<td class="has-text-align-center" data-align="center">2</td>
<td>Diverse sector targeting</td>
</tr>
<tr>
<td><strong>ken6k</strong></td>
<td class="has-text-align-center" data-align="center">2</td>
<td>BFSI concentration</td>
</tr>
<tr>
<td><strong>max9898</strong></td>
<td class="has-text-align-center" data-align="center">2</td>
<td>Retail and Technology</td>
</tr>
<tr>
<td><strong>worldrdp</strong></td>
<td class="has-text-align-center" data-align="center">2</td>
<td>Technology sector</td>
</tr>
<tr>
<td><strong>zyad2drkwb</strong></td>
<td class="has-text-align-center" data-align="center">2</td>
<td>Government targeting</td>
</tr>
<tr>
<td><strong>zoozkooz</strong></td>
<td class="has-text-align-center" data-align="center">2</td>
<td>Diverse sector</td>
</tr>
<tr>
<td><strong>mr_x1</strong></td>
<td class="has-text-align-center" data-align="center">1</td>
<td>Retail focus</td>
</tr>
<tr>
<td><strong>ventuuas</strong></td>
<td class="has-text-align-center" data-align="center">1</td>
<td>Professional Services</td>
</tr>
<tr>
<td><strong>Others</strong></td>
<td class="has-text-align-center" data-align="center">18</td>
<td>Distributed diverse targeting</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Strategic Finding:</strong> While Qilin, The Gentlemen, and LockBit dominate ransomware attack volume, data exfiltration is fragmented across numerous smaller actors, including tanaka (6 posts), kazutlg (4 posts), and dozens of single-incident operators. This suggests a mature <strong>data brokerage ecosystem</strong> where extracted data is resold to specialized exfiltration actors.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Dark Web Data Marketplace Activity:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>916 unique domains</strong> impacted by data leaks</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Approximately 86 distinct leak posts</strong> across dark web channels</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Data types:</strong> Financial records, customer PII, medical records, intellectual property, trade secrets</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Implication:</strong> Organizations can no longer assume encrypted data is "lost forever" if backups are restored. Exfiltrated data will be monetized regardless of whether organizations pay ransoms. Data loss prevention becomes as critical as ransomware detection.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Geopolitical and Ideological Dimensions:</strong> The Activism-Cybercrime Convergence</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Pro-Russian Hacktivism: </strong>Blurred Lines Between Ideology and Profit</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>H1 2026 witnessed increasing overlap between geopolitically motivated hacktivism and financially motivated cybercrime, particularly among pro-Russian collectives targeting NATO-aligned European nations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Key Threat Actors to Monitor</strong></h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>NoName057(16) - The Pro-Russian DDoS Coalition</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Primary Activity:</strong> Large-scale DDoS attacks against NATO-aligned governments and Ukrainian supporters</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Secondary Activity:</strong> Data exfiltration for monetization</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Geographic Targets:</strong> Estonia, UK, Ukraine, Italy, Spain, France, Poland, Norway, Denmark, Lithuania, Latvia, Czech Republic, Germany, Moldova</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Operational Pattern:</strong> Coordinated DDoS campaigns often accompanied by data theft and subsequent leak activity</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Operational Evolution:</strong> NoName057(16) began as a purely activist collective claiming ideological motivation (anti-NATO, pro-Russia). By H1 2026, the group had evolved to include data exfiltration and monetization—suggesting either organizational evolution or infiltration by financially motivated threat actors.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Strategic Implication:</strong> European organizations cannot compartmentalize threat modeling. A geopolitically motivated attack that begins as a DDoS campaign can transition into ransomware deployment when exfiltration opportunities present themselves.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Strategic Defense Recommendations for European Organizations</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Prioritized Defensive Roadmap</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Based on CRIL's H1 2026 regional data, European security leaders should prioritize defensive investments in the following sequence:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Phase 1: Critical Infrastructure Protection (30 days)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li><strong>Inventory Network Appliances:</strong> Document all network appliances (firewalls, SD-WAN platforms, security gateways, VPNs)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Patch Critical CVEs:</strong> Prioritize patches for Cisco, Ivanti, Palo Alto, Fortinet, and Microsoft appliances</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Access Control Hardening:</strong> Implement MFA for all remote administrative access to network infrastructure</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Monitoring Deployment:</strong> Deploy behavioral monitoring on network appliances for anomalous activity</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Phase 2: Data Protection (60 days)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li><strong>Data Inventory:</strong> Identify and catalog sensitive data holdings (customer data, financial records, intellectual property)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>DLP Implementation:</strong> Deploy data loss prevention solutions with egress monitoring</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Encryption Standards:</strong> Implement encryption for data in transit (TLS 1.3+) and at rest (AES-256)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Access Logging:</strong> Enable comprehensive audit logging for all sensitive data access</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Phase 3: Operational Resilience (90 days)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li><strong>Immutable Backups:</strong> Establish offline, immutable backup infrastructure isolated from network access</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Incident Response Planning:</strong> Develop organization-specific incident response playbooks addressing ransomware scenarios</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Business Continuity:</strong> Identify critical business functions and develop continuity strategies</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Disaster Recovery Testing:</strong> Conduct quarterly backup restoration testing to verify recovery capabilities</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Phase 4: Threat Hunting and Detection (Ongoing)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li><strong>Threat Intelligence Integration:</strong> Subscribe to European threat intelligence feeds focusing on Qilin, The Gentlemen, LockBit, Akira, and Dragonforce</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Behavioral Detection:</strong> Deploy endpoint detection and response (EDR) solutions with behavioral analytics</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Supply-Chain Monitoring:</strong> Implement continuous monitoring of vendor and supplier security posture</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Insider Threat Program:</strong> Develop insider threat detection capabilities focusing on data exfiltration attempts</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Regional Threat Actor Summary:</strong> Who Targets Your European Organization</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Sector-Specific Threat Actor Mapping</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>If You're in Construction:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Primary Threat:</strong> Qilin, The Gentlemen</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Secondary Threat:</strong> Akira, Dragonforce</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Vulnerability:</strong> Network segmentation gaps, supply-chain vulnerabilities, legacy OT systems</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Defensive Focus:</strong> OT/IT segmentation, immutable backups, supplier security assessment</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>If You're in Professional Services:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Primary Threat:</strong> Qilin, The Gentlemen</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Secondary Threat:</strong> LockBit, Akira</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Vulnerability:</strong> Client data exfiltration, regulatory exposure, ransomware payment pressure</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Defensive Focus:</strong> DLP, client data encryption, ransomware-specific insurance</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>If You're in Manufacturing:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Primary Threat:</strong> Qilin, The Gentlemen</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Secondary Threat:</strong> Akira, Dragonforce</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Vulnerability:</strong> OT/IT integration, supply-chain exploitation, operational downtime pressure</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Defensive Focus:</strong> OT segmentation, vulnerability prioritization, continuity planning</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>If You're in BFSI:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Primary Threat:</strong> Qilin, The Gentlemen, LockBit</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Secondary Threat:</strong> Data exfiltration actors (tanaka, kazutlg)</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Vulnerability:</strong> Financial data value, regulatory breach notification pressure, customer trust exposure</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Defensive Focus:</strong> Data encryption, DLP with aggressive egress controls, cyber insurance</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>If You're in Healthcare:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Primary Threat:</strong> Qilin, The Gentlemen, LockBit</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Secondary Threat:</strong> Data exfiltration operators</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Vulnerability:</strong> Patient safety risk, critical operational pressure, medical device security</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Defensive Focus:</strong> Clinical system isolation, redundant critical systems, incident response for operational continuity</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Conclusion:</strong> The European Ransomware Reality</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Europe and the UK face a mature, organized ransomware ecosystem dominated by five sophisticated threat actors who have developed deep understanding of regional economic vulnerabilities. The threat is not random or opportunistic—it is <strong>strategic, targeted, and evolved</strong>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Key Takeaways:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list {"ordered":true,"start":1} --></p>
<ol start="1" class="wp-block-list"><!-- wp:list-item -->
<li><strong>Five groups dominate:</strong> Qilin (158 attacks), The Gentlemen (144), LockBit (61), Akira (59), and Dragonforce (54) collectively account for 476 of 866 documented attacks (55%). European security leaders can build specific defensive strategies against known adversaries.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Geography matters:</strong> Germany, UK, France, Italy, and Spain face distinct threat profiles. Security strategies must be regionally and sector-specific, not generic.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Sectors are targeted deliberately:</strong> Construction, Professional Services, and Manufacturing are not randomly selected—they face extraordinary pressure due to economic vulnerabilities that threat actors systematically exploit.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Data exfiltration is the primary leverage:</strong> Of 866 attacks, only 51 resulted in confirmed breaches—but this understates the risk. Organizations must assume all breaches involve data exfiltration and cannot rely on backup restoration alone.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Patch management is the primary defense:</strong> Nearly 90% of exploited vulnerabilities had patches available. Disciplined patch management, particularly for network appliances, would prevent the vast majority of successful attacks.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Known vulnerabilities are the current threat:</strong> Despite awareness of zero-day sophistication, threat actors continue exploiting known vulnerabilities because patches lag adoption. This creates a predictable exploitation window that defensive teams can close.</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>For European security leaders, the path forward is to understand your regional threat actors, prioritize critical infrastructure protection, implement robust data protection measures, and establish resilient backup and recovery infrastructure. The threat is severe, but it is also understood and defensible. The question is not whether European organizations will face ransomware attacks in the remainder of 2026 and beyond—the data confirms they will. The question is whether they will be prepared.</p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/ransomware-threats-in-europe-h1-2026/">Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Hello Keys Can Be Borrowed to Bypass PINs and Gain Persistent Entra ID Access]]></title>
<description><![CDATA[A newly disclosed technique shows how attackers with access to an active Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys without knowing the victim’s PIN or triggering biometric verification. The method can enable cloud authentication, Microsoft Entra ID token ...]]></description>
<link>https://tsecurity.de/de/3710429/it-security-nachrichten/windows-hello-keys-can-be-borrowed-to-bypass-pins-and-gain-persistent-entra-id-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710429/it-security-nachrichten/windows-hello-keys-can-be-borrowed-to-bypass-pins-and-gain-persistent-entra-id-access/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:21 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly disclosed technique shows how attackers with access to an active Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys without knowing the victim’s PIN or triggering biometric verification. The method can enable cloud authentication, Microsoft Entra ID token acquisition, device registration, and potentially persistent account access. Mollema’s research demonstrates that […]</p>
<p>The post <a href="https://cyberpress.org/windows-hello-keys-bypass-pins-gain-entra-id/">Windows Hello Keys Can Be Borrowed to Bypass PINs and Gain Persistent Entra ID Access</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware kann Windows-Hello-for-Business-Keys für dauerhaften Entra-Zugriff missbrauchen]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine technische Demonstration zeigt, wie Malware in einer laufenden, bereits angemeldeten Windows-Session den Windows-Hello-for-Business-Schlüssel missbrauchen kann, um sich bei Microsoft Entra ID zu authentifizieren. Anschließend lässt sich über einen Primary Refresh Token...]]></description>
<link>https://tsecurity.de/de/3710418/it-security-nachrichten/malware-kann-windows-hello-for-business-keys-fuer-dauerhaften-entra-zugriff-missbrauchen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710418/it-security-nachrichten/malware-kann-windows-hello-for-business-keys-fuer-dauerhaften-entra-zugriff-missbrauchen/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:19 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-windows-hello-business-entra-id-missbrauch.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-windows-hello-business-entra-id-missbrauch.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-windows-hello-business-entra-id-missbrauch-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-windows-hello-business-entra-id-missbrauch-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-windows-hello-business-entra-id-missbrauch-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-windows-hello-business-entra-id-missbrauch-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-windows-hello-business-entra-id-missbrauch-120x120.jpg 120w" sizes="auto, (max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine technische Demonstration zeigt, wie Malware in einer laufenden, bereits angemeldeten Windows-Session den Windows-Hello-for-Business-Schlüssel missbrauchen kann, um sich bei Microsoft Entra ID zu authentifizieren. Anschließend lässt sich über einen Primary Refresh Token (PRT) längerfristiger Cloud-Zugriff aufbauen, inklusive neuer Geräte-Registrierungen, sofern Tenant-Policies dies zulassen. Besonders kritisch: Auf TPM-gestützten Systemen wird der private […]</p>
<div><a href="https://www.it-boltwise.de/malware-kann-windows-hello-for-business-keys-fuer-dauerhaften-entra-zugriff-missbrauchen.html">... den vollständigen Artikel <strong>»Malware kann Windows-Hello-for-Business-Keys für dauerhaften Entra-Zugriff missbrauchen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/malware-kann-windows-hello-for-business-keys-fuer-dauerhaften-entra-zugriff-missbrauchen.html">Malware kann Windows-Hello-for-Business-Keys für dauerhaften Entra-Zugriff missbrauchen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware Abuses Windows Hello for Business Key to Authenticate Microsoft Entra ID]]></title>
<description><![CDATA[A newly demonstrated technique shows how malware in a compromised Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys to…
Read more →
The post Malware Abuses Windows Hello for Business Key to Authenticate Microsoft Entra ID appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3710369/it-security-nachrichten/malware-abuses-windows-hello-for-business-key-to-authenticate-microsoft-entra-id/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710369/it-security-nachrichten/malware-abuses-windows-hello-for-business-key-to-authenticate-microsoft-entra-id/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly demonstrated technique shows how malware in a compromised Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/malware-abuses-windows-hello-for-business-key-to-authenticate-microsoft-entra-id/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/malware-abuses-windows-hello-for-business-key-to-authenticate-microsoft-entra-id/">Malware Abuses Windows Hello for Business Key to Authenticate Microsoft Entra ID</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Top Exposure Management Questions Security Leaders Ask (Part 1)]]></title>
<description><![CDATA[Security leaders evaluating Check Point Exposure Management tend to ask the same questions: how the solution discovers assets, what intelligence it provides, and how well it fits their existing tools and workflows.  Below, we answer the questions that come up most often in product evaluations, of...]]></description>
<link>https://tsecurity.de/de/3710320/it-security-nachrichten/the-top-exposure-management-questions-security-leaders-ask-part-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710320/it-security-nachrichten/the-top-exposure-management-questions-security-leaders-ask-part-1/</guid>
<pubDate>Sat, 08 Aug 2026 00:35:02 +0200</pubDate>
<content:encoded><![CDATA[<img width="1350" height="675" src="https://blog.checkpoint.com/wp-content/uploads/2026/08/Gong-Calls-Blog-1.png" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://blog.checkpoint.com/wp-content/uploads/2026/08/Gong-Calls-Blog-1.png 1350w, https://blog.checkpoint.com/wp-content/uploads/2026/08/Gong-Calls-Blog-1-300x150.png 300w, https://blog.checkpoint.com/wp-content/uploads/2026/08/Gong-Calls-Blog-1-1024x512.png 1024w, https://blog.checkpoint.com/wp-content/uploads/2026/08/Gong-Calls-Blog-1-768x384.png 768w, https://blog.checkpoint.com/wp-content/uploads/2026/08/Gong-Calls-Blog-1-400x200.png 400w, https://blog.checkpoint.com/wp-content/uploads/2026/08/Gong-Calls-Blog-1-600x300.png 600w, https://blog.checkpoint.com/wp-content/uploads/2026/08/Gong-Calls-Blog-1-800x400.png 800w, https://blog.checkpoint.com/wp-content/uploads/2026/08/Gong-Calls-Blog-1-1200x600.png 1200w, https://blog.checkpoint.com/wp-content/uploads/2026/08/Gong-Calls-Blog-1-1320x660.png 1320w" sizes="(max-width: 1350px) 100vw, 1350px"><p>Security leaders evaluating Check Point Exposure Management tend to ask the same questions: how the solution discovers assets, what intelligence it provides, and how well it fits their existing tools and workflows.  Below, we answer the questions that come up most often in product evaluations, offering a practical look at how organizations discover, understand, and reduce cyber risk.  1. How does the platform discover my assets?  Every exposure management program starts with knowing what you own. Security teams cannot assess, prioritize, or remediate exposures tied to systems they do not know exist.  Check Point Exposure Management begins by continuously discovering […]</p>
<p>The post <a href="https://blog.checkpoint.com/exposure-management/the-top-exposure-management-questions-security-leaders-ask-part-1/">The Top Exposure Management Questions Security Leaders Ask (Part 1)</a> appeared first on <a href="https://blog.checkpoint.com/">Check Point Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Impersonate IT Support to Breach Leading Financial Companies]]></title>
<description><![CDATA[Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associa...]]></description>
<link>https://tsecurity.de/de/3710300/it-security-nachrichten/hackers-impersonate-it-support-to-breach-leading-financial-companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710300/it-security-nachrichten/hackers-impersonate-it-support-to-breach-leading-financial-companies/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:14 +0200</pubDate>
<content:encoded><![CDATA[Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among dozens […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Your AI hiring tool isn’t an HR problem. It’s a security one]]></title>
<description><![CDATA[For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candid...]]></description>
<link>https://tsecurity.de/de/3710292/it-security-nachrichten/your-ai-hiring-tool-isnt-an-hr-problem-its-a-security-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710292/it-security-nachrichten/your-ai-hiring-tool-isnt-an-hr-problem-its-a-security-one/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:04 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candidates, conducting interviews, ranking applicants and influencing who moves forward, the hiring platform stops being a passive system of record. It becomes a decision system.</p>



<p class="wp-block-paragraph">And any system that accepts public input, processes sensitive data and influences business decisions belongs inside the security conversation.</p>



<p class="wp-block-paragraph">I learned this during an AI hiring platform rollout that never made it to production. The vendor was established, the product had a strong market reputation and the AI feature looked attractive: Upload a resume, compare it to a job description and return a neat percentage match. For recruiters, it promised speed. For executives, it promised modernization.</p>



<p class="wp-block-paragraph">Before moving real candidate data into the system, I tested it with synthetic resumes. One weak resume came back with a surprisingly strong match. The reason was not hidden in the candidate’s experience. It was hidden in the text. The resume contained language instructing the AI to treat the candidate as an excellent fit, and the system appeared to follow that instruction instead of evaluating the resume on merit.</p>



<p class="wp-block-paragraph">That changed the question from “Does the tool improve productivity?” to “Can the person being evaluated influence the evaluation itself?”</p>



<p class="wp-block-paragraph">That is a security question.</p>



<h2 class="wp-block-heading">The trust boundary has moved</h2>



<p class="wp-block-paragraph">CIOs do not need to become recruiting experts. They only need to look at the mechanics.</p>



<p class="wp-block-paragraph">An anonymous user submits content into an enterprise system. That content is processed by software. The software then produces an output that can influence a business decision. In every other environment, security teams know what to call that: untrusted input crossing a trust boundary.</p>



<p class="wp-block-paragraph">The difference is that in hiring, the input looks harmless. It is a resume, a cover letter, a chatbot reply or a spoken answer in an AI-led interview. But once AI reads that content and treats it as instruction, the harmless-looking input becomes part of the system’s control surface.</p>



<p class="wp-block-paragraph">That is why prompt injection matters in hiring. It is not just an AI oddity or a model behavior issue. It is the same category of failure enterprises have spent decades trying to prevent: User-controlled input changing what the system does. <a href="https://genai.owasp.org/llmrisk/llm01-prompt-injection/">OWASP lists prompt injection as the first risk in its Top 10 for LLM applications</a>, describing it as a case where user prompts alter a model’s behavior or output in unintended ways.</p>



<p class="wp-block-paragraph">In hiring, the implication is direct: A candidate may be able to manipulate the score, ranking or interview assessment that determines whether a human ever sees them.</p>



<h2 class="wp-block-heading">The business impact is not theoretical</h2>



<p class="wp-block-paragraph">The obvious risk is that an unqualified candidate moves forward. But the impact is broader.</p>



<p class="wp-block-paragraph">First, decision quality degrades. Hiring teams adopt AI scoring because they believe it improves signal. If the score can be manipulated, the business is not gaining signal; it is gaining false confidence. Recruiters may spend time on candidates who gamed the system while stronger candidates are buried lower in the queue. A tool bought to reduce friction can quietly create more of it.</p>



<p class="wp-block-paragraph">Second, cost increases under the appearance of efficiency. Every false positive consumes recruiter time, hiring-manager attention, interview slots and opportunity cost. A small weakness in screening integrity can become a measurable operational drag across open roles.</p>



<p class="wp-block-paragraph">Third, trust suffers. Candidates already question whether AI hiring tools are fair, explainable or accurate. If it becomes clear that a screening system can be manipulated by hidden instructions or verbal prompting, the issue is no longer just security. It becomes reputational. Strong candidates may lose confidence in the process, and employers may have to defend decisions made by systems they did not fully understand.</p>



<p class="wp-block-paragraph">Fourth, sensitive data exposure becomes harder to contain. Recruiting systems hold names, addresses, work histories, education histories, compensation details, work authorization information and sometimes accommodation or demographic data. <a href="https://csrc.nist.gov/pubs/sp/800/122/final">NIST guidance on personally identifiable information</a> includes employment information as linkable personal data that must be protected from inappropriate access, use and disclosure. Yet hiring platforms often receive less security scrutiny than systems holding customer or financial data.</p>



<p class="wp-block-paragraph">That mismatch is dangerous: High-value data, public-facing workflows and increasing automation.</p>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html">The 2025 McHire incident</a> should have made this impossible to ignore. Researchers reported that weaknesses in McDonald’s AI hiring platform, including default credentials and an access-control flaw, exposed applicant data at large scale before the issue was patched. The lesson for CIOs is not merely that a weak password was used. The lesson is that AI hiring systems can ship with basic, preventable security failures while still being treated as HR tools rather than enterprise risk surfaces.</p>



<h2 class="wp-block-heading">Vendor reputation does not transfer to every AI feature</h2>



<p class="wp-block-paragraph">One reason this risk slips through is that buyers often trust the platform brand. Mature vendors may have strong security programs, enterprise customers, compliance documentation and procurement-friendly answers.</p>



<p class="wp-block-paragraph">But AI features can change the architecture of risk.</p>



<p class="wp-block-paragraph">A platform that was safe as a workflow tool may behave very differently once it adds resume scoring, interview grading, chatbot screening or automated ranking. The new feature may introduce new inputs, new model behavior, new data flows, new third-party dependencies and new decision points. In practical terms, the attack surface has changed.</p>



<p class="wp-block-paragraph">CIOs should not allow AI features to inherit trust automatically from the legacy platform around them. When a vendor adds AI, the enterprise should reassess the feature as if it were a new product. That does not mean slowing innovation for bureaucracy. It means AI-enabled decision-making carries different failure modes from ordinary workflow automation.</p>



<h2 class="wp-block-heading">The ownership gap is the real vulnerability</h2>



<p class="wp-block-paragraph">The biggest risk may not be the model. It may be the ownership gap.</p>



<p class="wp-block-paragraph">Talent acquisition may buy the tool. HR operations may configure it. The vendor may guide implementation. Procurement and legal may approve the contract. But who owns the security of the candidate-facing AI layer?</p>



<p class="wp-block-paragraph">In many organizations, the honest answer is unclear.</p>



<p class="wp-block-paragraph">That ambiguity is where risk grows. Recruiting technology sits at the intersection of public input, sensitive data, third-party software, automated decision support and brand trust. That is exactly the kind of environment that needs named security ownership, asset inventory, vendor review, access-control testing, logging and incident-response planning.</p>



<p class="wp-block-paragraph">If the hiring stack is not in the security inventory, the organization is already making an assumption it may later regret.</p>



<h2 class="wp-block-heading">What CIOs should require now</h2>



<p class="wp-block-paragraph">The fix is not exotic. It is applying existing security discipline to a surface that has been underestimated.</p>



<p class="wp-block-paragraph">Treat every candidate submission as untrusted input. Resumes, cover letters, chatbot responses, interview transcripts and spoken answers should be handled as attacker-controllable content. If AI processes it, the system must separate content from instruction.</p>



<p class="wp-block-paragraph">Reassess vendors when AI features are introduced. A prior security review should not be treated as permanent approval for new AI capabilities. Ask what changed in the architecture, what data the model sees, what actions it can influence and how manipulation attempts are detected.</p>



<p class="wp-block-paragraph">Ask AI-specific questions before signing. Can candidate-provided content alter scoring? Are hidden instructions filtered or ignored? Is there human review before AI output influences a decision? Can the vendor produce testing evidence for prompt injection, access control and data exposure risks?</p>



<p class="wp-block-paragraph">Assign ownership. HR can own the process, but security must own the risk model. AI hiring systems should be included in third-party risk management, application security reviews, access governance, monitoring and incident response planning.</p>



<p class="wp-block-paragraph">Measure business impact, not just AI adoption. The goal is not to say the recruiting function uses AI. The goal is to improve hiring speed, quality, fairness and cost without creating new risk. If the system cannot protect decision integrity, the business case is weaker than it appears.</p>



<h2 class="wp-block-heading">The hiring platform is now part of the enterprise attack surface</h2>



<p class="wp-block-paragraph">AI has turned the careers page into more than a front door for applicants. It is now a public input channel feeding systems that store sensitive data and influence workforce decisions.</p>



<p class="wp-block-paragraph">That makes it a CIO concern.</p>



<p class="wp-block-paragraph">The next failure in AI hiring may not look like a traditional breach at first. It may look like bad rankings, manipulated scores, unexplainable decisions, wasted recruiter time or a candidate process no one trusts. But underneath those symptoms is a familiar security problem: A system trusted input it should have treated as hostile.</p>



<p class="wp-block-paragraph">Enterprises have hardened payment systems, customer portals, APIs and employee applications around that lesson. Hiring deserves the same treatment.</p>



<p class="wp-block-paragraph">AI hiring is not just an HR transformation. It is a security boundary. And it is time CIOs treated it like one.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI is changing the business analyst role for the better]]></title>
<description><![CDATA[AI’s impact has been felt across nearly every industry, and its rise has already started to alter several roles in tech, including that of the business analyst. While the rise of agentic AI may have some questioning whether AI will replace business analyst jobs entirely, as we’ve seen with most r...]]></description>
<link>https://tsecurity.de/de/3710293/it-security-nachrichten/how-ai-is-changing-the-business-analyst-role-for-the-better/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710293/it-security-nachrichten/how-ai-is-changing-the-business-analyst-role-for-the-better/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:04 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI’s impact has been felt across nearly every industry, and its rise has already started to alter several roles in tech, including that of the <a href="https://www.cio.com/article/276798/what-is-a-business-analyst-a-key-role-for-business-it-efficiencywhat-is-a-business-analyst-a-key-role-for-business-it-efficiency.html">business analyst</a>. While the rise of agentic AI may have some questioning whether AI will replace business analyst jobs entirely, as we’ve seen with most roles impacted by AI, it’s more likely that AI will augment the role and fundamentally change how BA’s conduct daily business.</p>



<p class="wp-block-paragraph">“As AI takes on more routine tasks, the human side of the role is becoming even more valuable. It’s becoming more of a hybrid role, where employers are often looking for candidates who can combine technical fluency with strong communication and problem-solving skills, along with sound business judgment,” says Megan Slabinski, district president of technology talent solutions at Robert Half.</p>



<p class="wp-block-paragraph">AI can save business analysts time in the long run, automating many of the tasks that are time consuming and repetitive around data processing, note taking, and documentation. While automation will impact the daily tasks of the role, business analysts will still be necessary for properly interpreting outputs, collaborating across teams, and maintaining compliance and AI workflows.</p>



<h2 class="wp-block-heading">AI-driven analysis and automated workflows</h2>



<p class="wp-block-paragraph">With AI-driven analysis, BA’s can use machine learning models for pattern detection, determining risk, and for forecasting demand, while natural language processing (NLP) can be used for text-heavy inputs. AI tools can also assist analysts with decision-making by transcribing meetings and automatically identifying any necessary business requirements, constraints, risks, or dependencies that will impact the project.</p>



<p class="wp-block-paragraph">As a result, the role is undergoing a shift toward spending less time on monotonous, routine tasks, and instead “spending more time connecting the dots and providing strategic context earlier in the process,” says Slabinksi.</p>



<p class="wp-block-paragraph">“We’re seeing that business analysts today aren’t spending as much time as they were a few years ago on some manual processes. AI is speeding up tasks like documenting requirements, summarizing stakeholder meetings, generating first drafts of user stories, and even helping create SQL queries or reports,” she adds.</p>



<p class="wp-block-paragraph">AI can also assist business analysts with interviews and workshops for the discovery phase of a project and autonomously identify patterns in the data that might be overlooked or missed by the human eye. These tools can also enable BAs to create living models that can be adjusted and altered with feedback, as opposed to traditional static documents, and allow for an automated review process for data validation. In terms of maintenance and change management, AI can help with predictive recommendations to get ahead of risks, compliance, and future process updates.</p>



<p class="wp-block-paragraph">That said, an increased reliance on AI tools while require business analysts to validate AI outputs and assure AI-generated content is accurate, relevant, and ultimately aligned with the overall business strategy. Still responsible for explaining the reasons behind business decisions, business analysts will also need to identifying bias and fairness concerns associated with AI use, and ensure decisions aren’t over-automated.</p>



<p class="wp-block-paragraph">Ultimately, BA’s will see their responsibilities shift to focusing more on data interpretation, governance, and strategy, and identifying the most practical use cases for enterprise AI adoption.</p>



<h2 class="wp-block-heading">New skills to focus on</h2>



<p class="wp-block-paragraph">Traditionally, business analysts are responsible for gathering the data as well as processing it for analysis. This comes with a lot of drudgery that can be eased by implementing AI tools into the workflow. Tasks such as routine documentation, formatting, and data crunching can be automated, while analysts provide the human context around that data, as well as a critical eye to the final output.</p>



<p class="wp-block-paragraph">“Business analysts are often in the mix to make sure that data is accurate and that the requirements are in line with expected outcomes. They can also help ensure AI projects include the appropriate level of human oversight, comply with internal policies and industry regulations, and use data responsibly. While they aren’t solely responsible for AI governance, they often play an important role in raising questions about data sources, bias, whether the outputs make sense, and potential business risks early in a project,” says Slabinski.</p>



<p class="wp-block-paragraph">BAs will need to develop AI literacy skills to better understand how models are trained and designed as well as data reasoning skills to interpret and validate AI outputs. Prompt-framing skills will also become valuable as analysts will need to know how to properly structure inputs for quality outputs. There will also be a growing emphasis on ethical analysis to identify compliance, bias, and overall fairness of algorithms, and qualified candidates will require strong change management skills to help oversee the adoption of AI-driven workflows.</p>



<p class="wp-block-paragraph">“The skills becoming more important are the ones that help BAs evaluate AI-generated information and translate it into business recommendations. AI literacy is becoming a baseline expectation, and that includes knowing things like how to query the data and support requirements gathering. Critical thinking, communication, and business acumen are all part of that skill set because employers still need people who can explain what the findings mean and why they matter,” says Slabinski.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From ambition to action: What Canadian tech leaders must get right to see meaningful value from transformation efforts]]></title>
<description><![CDATA[It’s no secret that the CIO role is changing in Canadian enterprises. Driving operational performance and increasing efficiency are, of course, still a big part of the job. But CIOs are now expected to do more than cut costs and keep the lights on. Increasingly, boards of directors expect the CIO...]]></description>
<link>https://tsecurity.de/de/3710285/it-security-nachrichten/from-ambition-to-action-what-canadian-tech-leaders-must-get-right-to-see-meaningful-value-from-transformation-efforts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710285/it-security-nachrichten/from-ambition-to-action-what-canadian-tech-leaders-must-get-right-to-see-meaningful-value-from-transformation-efforts/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s no secret that the CIO role is changing in Canadian enterprises. Driving operational performance and increasing efficiency are, of course, still a big part of the job. But CIOs are now expected to do more than cut costs and keep the lights on. Increasingly, boards of directors expect the CIO to play a key role in creating value and enabling their organizations to outperform their rivals. Recent data backs this up. The overwhelming majority (91%) of Canadian technology leaders believe advanced technology will be the primary driver of competitive advantage over the next three years, according to KPMG’s “<a href="https://kpmg.com/ca/en/insights/2026/02/execution-imperatives-for-canadian-tech-leaders.html" target="_blank" rel="noreferrer noopener">The 8 execution imperatives for Canadian tech leaders</a>,” a white paper based on the firm’s <a href="https://kpmg.com/xx/en/our-insights/ai-and-technology/global-tech-report.html" target="_blank" rel="noreferrer noopener">2026 Global Tech Report</a>.</p>



<p class="wp-block-paragraph">The race to capture value from emerging technologies has intensified, leaving little room for organizations that remain on the sidelines. Yet in Canada, just 27% of organizations consider themselves innovators or early adopters, while 72% are fast or slow followers. Nearly all (85%) believe they’ll need to take more risks with emerging technologies just to remain relevant.</p>



<p class="wp-block-paragraph">The traditional, operational-first mindset among CIOs has become a liability. CIOs are expected to be strategic players, but meeting that expectation requires taking thoughtful, well-considered action across key imperatives.</p>



<h3 class="wp-block-heading"><strong>AI success depends on data</strong></h3>



<p class="wp-block-paragraph"><strong>AI is not the only advanced technology that organizations are working to deploy, but it’s certainly garnering the most attention from C-suite executives, boards of directors, and investors. </strong>To enable AI at scale, the data foundations enterprises have built over the past decade will be necessary, but they are not sufficient on their own. CIOs must make modernizing the state of enterprise data a top priority.</p>



<p class="wp-block-paragraph">In most large organizations, data often remains locked inside legacy systems where the system of record is also the system of engagement, and that significantly limits accessibility for AI workloads. Data should be treated as the strategic asset that it has become. The quality, timeliness, and governance of that data vary widely, and reconciling those inconsistencies is one of the most persistent barriers to enterprise-level deployment.</p>



<p class="wp-block-paragraph">Scaling pilots into enterprise programs also requires closing the gap between AI-native talent, who have the skills to move quickly, and those with deep institutional knowledge, who understand how their organizations work and what they need to achieve. These two groups must work hand in hand. Otherwise, organizations may accelerate toward the wrong goals, which won’t move the business forward.</p>



<p class="wp-block-paragraph">“The barriers to scaling AI aren’t just technical,” says Sanjay Pathak, partner and national leader, technology strategy and digital transformation services, KPMG Canada. “CIOs need to truly and deeply understand the value chain of what their organizations do. Those who get there will have the imagination, the courage, and the foresight to use AI to transform their organizations.”</p>



<h3 class="wp-block-heading"><strong>Communicating ROI requires the right framing</strong></h3>



<p class="wp-block-paragraph">Beyond scaling, simply communicating the value of AI also poses a significant challenge. Just over half (53%) of Canadian organizations surveyed say they struggle to demonstrate or communicate AI value to stakeholders. Part of the problem is that CIOs are making the wrong argument in the wrong room because they’re framing ROI as a technology metric rather than a business outcome.</p>



<p class="wp-block-paragraph">“Any CIO who doesn’t truly understand what their business does is missing a beat around how innovation is going to help the organization achieve ROI,” says Pathak. “Understanding how to deploy AI inside your value chain will give you a head start and a competitive advantage in unlocking real business benefits.”</p>



<p class="wp-block-paragraph">A formal performance measurement framework that tracks customer experience, revenue growth, and employee adoption alongside cost metrics gives CIOs a far more accurate picture of long-term value. Linking funding decisions to those strategic outcomes makes sustained investment easier to justify.</p>



<p class="wp-block-paragraph">There is also a compliance dimension that often goes unacknowledged in these conversations. CIOs who bring business, technology, and compliance leaders together to design innovative processes that are “compliant by design” from the start are protecting future value as much as they are delivering value today.</p>



<p class="wp-block-paragraph">“You need to assemble that multi-dimensional cohort of business, technology, risk, and compliance leaders at the same table, envisioning compliance by design,” says Pathak. “The winners in this space are going to be the ones who really think about business ambition holistically and focus on efficient delivery, operations, and compliance.”</p>



<h3 class="wp-block-heading"><strong>Building disciplined innovation governance</strong></h3>



<p class="wp-block-paragraph">An organization’s approach to governance makes an enormous difference in how quickly and confidently it can deploy and take advantage of advanced technologies. As noted above, almost three-quarters (72%) identify as fast or slow followers, and 85% say they need to move more aggressively to embrace new technologies. Canadian organizations aren’t lacking ambition. What they lack are the conditions required to innovate with confidence: clear ownership, defined risk thresholds, and shared accountability between technology, risk, and business teams.</p>



<p class="wp-block-paragraph">“You can be an innovator, but if your innovation is not directly connected to strategic business ambition and safety guardrails such as risk management, governance, and compliance, you’re creating labware,” says Pathak. “Being an early adopter means you’re comfortable with the technology. To make it truly viable, you must embrace all dimensions of enterprise value.”</p>



<p class="wp-block-paragraph">Strong governance does not slow innovation down but instead provides a structure that builds confidence and resilience at every level of the organization, from the board to project teams. A tiered governance approach that takes risk into account allows organizations to advance low-risk, incremental improvements and high-reward initiatives in parallel.</p>



<h3 class="wp-block-heading"><strong>Expanding partnerships to accelerate innovation</strong></h3>



<p class="wp-block-paragraph">Innovation isn’t a single-player game, and Canadian organizations know it. Ninety-seven percent of respondents say they plan to expand their external ecosystems. To date, a significant portion of those relationships have been transactional and focused on a specific capability or problem. But savvier organizations are moving toward multi-party innovation, where partners pool capabilities to share both risk and reward. This model requires a different kind of commitment because organizations are betting on a partner’s long-term viability, not just their current capability. Together, they must build the integration and governance infrastructure that makes these ecosystems work for all participants.</p>



<p class="wp-block-paragraph">“Moving to multi-party innovation ecosystems is an investment in integration and data,” says Pathak. “If you’re going to look at best of breed and stitch those together, what must be true for that to work is the ability for those different ecosystems to integrate and interoperate. And that creates a much stronger need for safety and governance.”</p>



<p class="wp-block-paragraph">Cybersecurity is another dimension that grows more important with every new partner added to the ecosystem. Security should be proactively built in, not imposed after a breach has already occurred.</p>



<p class="wp-block-paragraph">“The more ecosystem-based partnerships you have, the more opportunity you create along with the threat you have to deal with,” says Pathak. “You expand the attack surface, and you become more of a target, so governance and cybersecurity must be designed in from the start, not bolted on later.”</p>



<p class="wp-block-paragraph">Canadian government incentives, including Scientific Research and Experimental Development (SR&amp;ED) tax credits and AI-focused clusters, offer a way to share some of the cost and risk, particularly during periods of economic uncertainty.</p>



<p class="wp-block-paragraph">By leveraging these funding frameworks alongside robust ecosystem governance, forward-thinking organizations can safely scale their networks to turn shared risks into sustainable competitive advantages.</p>



<h3 class="wp-block-heading">In closing</h3>



<p class="wp-block-paragraph">For organizations navigating this environment, KPMG Canada emphasizes that the most consequential decisions ahead are not purely, or even mostly, technical. They are about how CIOs choose to lead, partner, measure, and govern in a period that rewards both ambition and discipline in equal measure.</p>



<p class="wp-block-paragraph">The data points are clear. CIOs who lead with both strategic ambition and disciplined execution will elevate their organizations above their competitors. By paying attention to the quality of their data, aligning technical priorities with critical business goals, and instituting strong governance and cybersecurity, they will set a higher standard for what Canadian competitiveness looks like in the years ahead.</p>



<p class="wp-block-paragraph">To learn more, read the full whitepaper: <a href="https://kpmg.com/ca/en/insights/2026/02/execution-imperatives-for-canadian-tech-leaders.html" target="_blank" rel="noreferrer noopener">The Top 8 Execution Imperatives for Canadian Tech Leaders</a>.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI workforce is more than doubling year on year, says Salesforce]]></title>
<description><![CDATA[Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual Agentic Enterprise Index, which looks at trends in AI agent development and deployment over the past five quarters.



It compiled data from customers who had activated agents in...]]></description>
<link>https://tsecurity.de/de/3710286/it-security-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710286/it-security-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual <a href="https://www.salesforce.com/agentforce/agentic-enterprise-index/" target="_blank" rel="noreferrer noopener">Agentic Enterprise Index</a>, which looks at trends in AI agent development and deployment over the past five quarters.</p>



<p class="wp-block-paragraph">It compiled data from customers who had activated agents in production every month of the analysis period to determine how their use of the technology has evolved between February 2025 and April 2026, as well as incorporating data from May 2026 Salesforce research studies.</p>



<p class="wp-block-paragraph">It found that businesses grew their agentic workforces from an average of five agents in February 2025 to 13 by April 2026, a 7% compound monthly growth rate (CMGR). In April 2026, it only took an average of 1.9 days to deploy an agent into production, a 53% decrease since the beginning of the report period.</p>



<p class="wp-block-paragraph">Not only were agents deployed more quickly, they have been progressively taking on more work once in use; over the 15 months, the average number of actions per account had a CMGR of 31%.</p>



<p class="wp-block-paragraph">“These agents are expanding beyond their initial scope to really become cross-functional,” said <a href="https://www.linkedin.com/in/caila-schwartz/" target="_blank" rel="noreferrer noopener">Caila Schwartz</a>, Salesforce’s head of agentic commerce insights, during a media briefing.</p>



<p class="wp-block-paragraph">Salesforce has attempted to measure how much work agents perform, rather than how many tokens they consume, creating its own <a href="https://www.cio.com/article/4138622/awu-by-salesforce-a-shiny-new-metric-that-tells-cios-little-of-value.html">Agentic Work Unit (AWU) metric</a>, although analysts have criticized the measure as being unrelated to business outcomes. Nevertheless, Salesforce said that as of April, Agentforce agents had performed 734 million AWUs, a number growing at about 15% each month.</p>



<p class="wp-block-paragraph">The research also showed that agents are acting across multiple cloud domains which, the company said, “underscores the practical necessity of a headless architecture. By decoupling the agent’s logic from traditional front-end user interfaces, agents can process tasks, execute actions, and trigger workflows anywhere.”</p>



<p class="wp-block-paragraph">Within the company, Salesforce itself has seen explosive growth in AI agent use, said <a href="https://www.linkedin.com/in/joseph-inzerillo-b917791/" target="_blank" rel="noreferrer noopener">Joe Inzerillo</a>, president of enterprise &amp; AI technology at Salesforce, with a threefold increase in sessions between February 2025 and April 2026. He said that the AI agent in Slack, Slackbot, saves the average employee five hours per week, with 83% of the company having adopted it.</p>



<p class="wp-block-paragraph">But Schwartz pointed out that different industries are approaching agentic AI in different ways, some more sophisticated than others. To measure that, Salesforce developed a Sophistication Index, a five-point scale scoring the cognitive complexity of an agent’s actions. Levels 1- 3  are assigned to tasks such as record lookups, drafting emails, or summarizing documents, while levels 4 and 5 include more complex functions such as updating database fields.</p>



<p class="wp-block-paragraph">The data showed that manufacturing, financial services, and healthcare and life sciences have built more sophisticated agent networks than what it called traditional AI frontrunners such as technology and retail.</p>



<p class="wp-block-paragraph">However, Inzerillo said, the most common use case industry wide, and the best place to start, is the service use case, which provides “far and away the best ROI to start with.”</p>



<p class="wp-block-paragraph">He also noted that, as people have become more conscious of what agents can do, they are asking agents to perform tasks, rather than simply answer questions.</p>



<p class="wp-block-paragraph">“Now what you’re starting to see people do is very action oriented. So instead of asking ’how do I file a form to request my vacation’ from our employee agent, they’re telling the employee agent, ‘hey I’m taking a vacation, you need to enter this form for me, and here’s the details,’” he said, adding that this bias towards action represents the evolution of agentic use.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Snowflake attacker pleads guilty to hack of 165 companies’ data]]></title>
<description><![CDATA[A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollars.



Industry so...]]></description>
<link>https://tsecurity.de/de/3710287/it-security-nachrichten/snowflake-attacker-pleads-guilty-to-hack-of-165-companies-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710287/it-security-nachrichten/snowflake-attacker-pleads-guilty-to-hack-of-165-companies-data/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. <a href="https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers" target="_blank" rel="noreferrer noopener">Connor Riley Moucka pleaded guilty</a> to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollars.</p>



<p class="wp-block-paragraph">Industry sources have identified Moucka as one of the main players in attacks on data hosted by cloud data warehouse Snowflake. Companies affected by the hacks <a href="https://www.csoonline.com/article/3629818/7-biggest-cybersecurity-stories-of-2024.html">include the likes of AT&amp;T, Ticketmaster and the Neiman Marcus Group</a>.</p>



<p class="wp-block-paragraph">He worked with two other hackers: <a href="https://www.csoonline.com/article/2517422/hacker-allegedly-paid-370000-ransom-to-delete-stolen-att-data.html">John Edward Binns</a> and Cameron John Wagenius. Binns was <a href="https://www.justice.gov/usao-wdwa/united-states-vs-connor-riley-moucka-and-john-erin-binns" target="_blank" rel="noreferrer noopener">not in US custody as of April 2026</a>, while Wagenius, going by the name of <a href="https://www.csoonline.com/article/3631033/us-soldier-linked-to-trump-call-log-hack-arrested-in-texas.html">Kiberphant0m, was arrested in January 2025</a> and <a href="https://www.justice.gov/opa/pr/former-us-soldier-pleads-guilty-hacking-and-extortion-scheme-involving-telecommunications" target="_blank" rel="noreferrer noopener">pleaded guilty in July that year</a></p>



<p class="wp-block-paragraph">Moucka and other members of the group used stolen login credentials to compromise data belonging to at least 165 customers of a US-based software-as-a-service company. This unauthorized access was used to steal billions of sensitive customer records and download terabytes of information,</p>



<p class="wp-block-paragraph">“Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars. Today’s guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity. You will be found and brought to justice,” said assistant attorney general A. Tysen Duva of the Justice Department’s Criminal Division</p>



<p class="wp-block-paragraph">The trial is the result of a coordinated worldwide action against the Snowflake group. The investigation was led by the FBI but benefited from contributions from the Royal Canadian Mounted Police, the Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine and the Turkish National Police.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4206739/snowflake-attacker-pleads-guilty-to-hack-of-165-companies-data.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[There are two completely different roles called ‘FDE’]]></title>
<description><![CDATA[There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing 84% with $5B+ revenue. But “forward deployed engineer” is a vague term and means different...]]></description>
<link>https://tsecurity.de/de/3710288/it-security-nachrichten/there-are-two-completely-different-roles-called-fde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710288/it-security-nachrichten/there-are-two-completely-different-roles-called-fde/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing <a href="https://investors.palantir.com/files/2026%20Q1%20PLTR%2010-Q.pdf">84% with $5B+ revenue</a>. But “<a href="https://en.wikipedia.org/wiki/Forward_Deployed_Engineer#cite_note-1">forward deployed engineer</a>” is a vague term and means different things depending on the business you’re running.</p>



<p class="wp-block-paragraph">I spent almost 5 years at Palantir as a forward-deployed software engineer, and Palantir’s version of an “FDE” does not make sense for most companies I now meet as an early-stage VC. Depending on the type of business you’re building, this role could broadly mean one of two things: “the product builder” or “the platform operator.” Clearly defining which bucket you fall into will make it easier to hire for this role and run your FDE org.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/nature-of-work-vs-product-leverage.png?w=1024" alt="Figure: Nature of work vs. product leverage." class="wp-image-4206317" width="1024" height="578" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<h2 class="wp-block-heading">The product builder: The OG Palantir version</h2>



<p class="wp-block-paragraph">The north star is: do whatever it takes to actually solve the user’s problem. FDEs are not just responsible for making the platform work, but also discovering what to build and building it (actually creating software) in service of the customer.</p>



<h2 class="wp-block-heading">The platform operator: Solutions + technical customer success</h2>



<p class="wp-block-paragraph">The north star is: make the product work for the customer – deploy and operationalize it. This is what most startups today really mean when they want FDEs. FDEs here configure the core platform, manage account relationships and drive adoption. This is not new – companies have always had solutions engineers, sales engineers, customer success etc., although the work looks different as FDEs are increasingly building prototypes, configuring evals and building MCPs.</p>



<h2 class="wp-block-heading">Which FDE is right for you</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/customer-size.png?w=1024" alt="Figure: Customer size." class="wp-image-4206316" width="1024" height="457" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">For most situations, hiring product builder FDEs is a mistake.</p>



<p class="wp-block-paragraph">At scale, the FDEs should be the platform operator. It’s hard to have FDEs build and maintain highly custom product features, especially as the company scales. Over time, the custom product surface area distracts from building the core product, even though AI coding tools make it easy to ship new features quickly and maintain them.</p>



<p class="wp-block-paragraph">Many fast-growing AI startups recognize these constraints and structure the FDE role more like the platform operator. This also allows them to have 5-10 accounts per FDE, which is a much higher ratio than Palantir had (at least in 2023). Even the Palantir FDE role has evolved to look more like the platform operator.</p>



<p class="wp-block-paragraph">There are, however, situations when your FDEs should be the product builder archetype.</p>



<h3 class="wp-block-heading">1. You have very large customers (F500 scale)</h3>



<p class="wp-block-paragraph"><strong>Technical complexity</strong>: Large customers have complex environments with legacy infrastructure that often requires “out-of-platform” engineering work. I often encountered bespoke data infrastructure, privacy requirements, etc. at various Palantir customers that required me to build “out-of-platform” connectors, UIs and backends.</p>



<p class="wp-block-paragraph"><strong>Organizational inertia and trust</strong>: Serving large enterprises is about building trust. In short time periods, overfitting product to a specific user/workflow is often what delivers the most value, builds trust and helps organizations get over the inertia of moving away from Excel and legacy software tools that are part of their day-to-day workflow. For AI-native startups, it’s arguably even more important to invest in doing “unscalable” development with engineering boots on the ground, as it helps solidify your right to exist and eventually expand the customer relationship.</p>



<h3 class="wp-block-heading">2. You have many ICPs and workflows</h3>



<p class="wp-block-paragraph">If you have a broad range of ICPs and workflows that you serve, your product probably is not walk-up usable on day 1 of deployment. The short-term hacky things that product builder FDEs build to make the product work for these heterogeneous users/workflows will help you shape the product long-term.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/overfit-products.png?w=1024" alt='Figure: "Overfit" products.' class="wp-image-4206313" width="1024" height="570" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">Note: see Palantir Foundry’s architecture <a href="https://www.palantir.com/assets/xrfr7uokpv1b/mhoyY4c8vdVlJhulDStk2/a7340768109c8e8d79d00b4cb99d8e70/Whitepaper_-_Foundry_2022.pdf">here</a>.</p>



<p class="wp-block-paragraph">This was a big reason why Palantir FDEs were more like product builders (and are still able to – see the <a href="https://jobs.lever.co/palantir/dab396d4-2f14-4796-aac0-0d82883dccf0">Forward Deployed Software Engineer job profiles</a> as an example). The vision for Foundry was to be the operating system for an enterprise’s critical decisions – inherently multiple industries, users and workflows. A lot of FDE-led development showed that solving many of these use cases required complex data integrations, which led to the early versions of Foundry being best-suited for complex data integrations and building a customer’s “<a href="https://blog.palantir.com/ontology-finding-meaning-in-data-palantir-rfx-blog-series-1-399bd1a5971b">Ontology</a>”. Similarly, FDEs like myself built custom frontend applications for fraud analysis, pricing, etc. As certain patterns of what these applications required became more clear, they were centralized into an application-layer product.</p>



<h2 class="wp-block-heading">Who you should hire</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/who-you-should-hire.png?w=1024" alt="Figure: Who you hire." class="wp-image-4206314" width="1024" height="464" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/why-hire.png?w=1024" alt="Figure: Why hire one vs. the other." class="wp-image-4206315" width="1024" height="456" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph"><strong>Platform operator</strong>: There is a much broader set of people you could hire, testing for technical fluency (e.g., being good at data analysis, complex Excel work, even SQL), product intuition and an inclination to build customer relationships. Backgrounds like technical customer success, solutions engineering, software engineering, product management and consulting are all strong fits.</p>



<p class="wp-block-paragraph"><strong>Product builder</strong>: You want candidates that are high ownership and missionary software engineers, or technical PMs who want to ship products themselves.</p>



<p class="wp-block-paragraph">Hiring for these profiles, especially product builders, is hard. It’s worth calling out two things that helped Palantir hire software engineers into what might be considered a less sexy role.</p>



<ol start="1" class="wp-block-list">
<li><strong>Culture of building at the edge</strong>: Strong engineers are motivated to build things. Palantir gave FDEs a lot of ownership to build products, which is why much of the core product leadership was former FDEs.</li>



<li><strong>Cult built around mission</strong>: Internally, there was a cult-like devotion to the mission. Everyone always talked about why outcomes were far more important than software, and why most companies building tools had it wrong. I’ve never been at a company where people feel so closely bonded around a mission.</li>
</ol>



<p class="wp-block-paragraph">As founders building AI startups think about hiring FDEs, it’s worth being specific about your culture and asking: Am I just hiring people to support development teams, or am I hiring people to shape and build product? It’s hard to get software engineers (even today) to be excited about an FDE role that might just be technical customer success.</p>



<h2 class="wp-block-heading">What FDEs should be doing (regardless of archetype)</h2>



<p class="wp-block-paragraph">You’ve hired the right people. How do you best leverage your team of FDEs?</p>



<p class="wp-block-paragraph">FDEs were Palantir’s way of delivering outcomes rather than tools. AI-native startups can take this much further and FDEs can help in a few unique ways by leveraging their proximity to customers.</p>



<ol start="1" class="wp-block-list">
<li><strong>Find the most critical workflows</strong>: As AI lowers the cost of producing software, companies will face a lot more competition. FDEs at AI startups should be constantly finding ways to serve the most critical workflows for a customer and paying attention to how customers do work across newer and legacy tools. For example, FDEs at Harvey should pay attention to which workflows are in Westlaw, which ones are moving to ChatGPT/Claude, and how the Harvey product can stay ahead.</li>



<li><strong>Build around nondeterminism</strong>: In more regulated environments, FDEs should be hyper-focused on making products reliable for specific use cases <a href="https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents">using evals</a> and configs. Previously, product reliability lived with product and support. As companies provide outcomes instead of tools, configuring products appropriately and managing evals shifts towards FDE teams.</li>
</ol>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD wants to make enterprise inference cheaper and faster with chips from Taalas]]></title>
<description><![CDATA[As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.



AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights...]]></description>
<link>https://tsecurity.de/de/3710289/it-security-nachrichten/amd-wants-to-make-enterprise-inference-cheaper-and-faster-with-chips-from-taalas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710289/it-security-nachrichten/amd-wants-to-make-enterprise-inference-cheaper-and-faster-with-chips-from-taalas/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.</p>



<p class="wp-block-paragraph">AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights into custom silicon, instead of repeatedly loading them from memory during inference as conventional <a href="https://www.networkworld.com/article/3966130/what-are-gpus-inside-the-processing-power-behind-ai.html">GPUs</a> do.</p>



<p class="wp-block-paragraph">Taalas says its approach reduces the time and power required to move model weights between memory and compute units, making things run faster and cheaper.</p>



<p class="wp-block-paragraph">The result is a highly specialized inference processor optimized for one model, trading the flexibility of programmable hardware for substantially higher throughput and energy efficiency.</p>



<h2 class="wp-block-heading">Operational tradeoffs</h2>



<p class="wp-block-paragraph">While AMD is planning to integrate the chips into its <a href="https://www.amd.com/en/products/accelerators/instinct.html">Instinct GPU</a> roadmap, targeting system-level AI inference solutions in data centers, analysts remain skeptical that enterprises will readily embrace hardware tied to a specific AI model.</p>



<p class="wp-block-paragraph">Enterprises would, effectively, be buying a chip and a model together because unlike GPUs, which can be repurposed to run different AI models through software updates, Taalas’ chips are tied to a specific trained model, meaning they would need different hardware to support different inference tasks, said <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Kumar Jena</a>, AI development manager at IT Consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Or as Forrester Principal Analyst <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a> put it, “The biggest risk is inflexibility.”</p>



<p class="wp-block-paragraph">The requirement to swap hardware in order to swap tasks would, Dai said, introduce new challenges with costs, governance, capacity planning, lifecycle management, and supplier dependency, especially for enterprises managing multiple AI workloads.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/manoj-chandra-jha-b5ab0a13" target="_blank" rel="noreferrer noopener">Manoj Chandra Jha</a>, principal analyst at Nord-IQ Research, said the risk of fusing chip and model into one component is larger than one might think, as “early model obsolescence strands both together, so this should be modeled as one shorter-lived asset rather than two independently amortized ones.”</p>



<p class="wp-block-paragraph">Taalas says it can update a model by modifying only two metal layers of the chip rather than redesigning it from scratch, but that will only apply to chips that haven’t yet left its factory, not those already in use.</p>



<p class="wp-block-paragraph">That means enterprises will still need to plan for hardware refresh cycles measured in weeks or months and retain programmable GPUs for workloads that evolve frequently, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p class="wp-block-paragraph">It also means, said Jha, that what is typically a software decision becomes one about capital expenditure for Taalas customers, as replacing or switching workloads or models could require investing in new hardware rather than simply updating software.</p>



<h2 class="wp-block-heading">Where model-specific silicon fits</h2>



<p class="wp-block-paragraph">Those tradeoffs significantly narrow the range of enterprise workloads where model-specific silicon is likely to make economic sense.</p>



<p class="wp-block-paragraph">Dai sees the technology as best suited for mature, predictable inference workloads that run at massive scale and rely on relatively stable AI models, such as customer service automation, fraud detection, industrial computer vision, network operations, edge AI, and embedded copilots.</p>



<p class="wp-block-paragraph">For CIOs, that effectively limits model-specific silicon to a small subset of enterprise AI deployments, rather than a wholesale replacement for GPU infrastructure, he said. “GPUs will remain the preferred enterprise platform because most enterprises value flexibility, multi-tenancy, and rapid model evolution over maximum efficiency.”</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.networkworld.com/article/4206674/amd-to-buy-taalas-maker-of-model-specific-ai-chips-for-enterprise-inference.html">Network World</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond chatbots: How embedded GenAI is transforming banking application development]]></title>
<description><![CDATA[Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprise...]]></description>
<link>https://tsecurity.de/de/3710290/it-security-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710290/it-security-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprises that need speed, traceability, resilience and regulatory confidence at the same time. Hyperautomation brings a broader discipline to this challenge. It combines workflow orchestration, intelligent document processing, robotic automation, API-led integration, process mining, test automation, observability and artificial intelligence into a connected delivery fabric. With embedded Generative AI, this fabric becomes more adaptive because applications can interpret natural language, summarize complex data, generate explanations, detect exceptions and support decision workflows rather than merely execute predefined rules.</p>



<p class="wp-block-paragraph">In banking, this shift is especially meaningful. Banks operate across dense application landscapes: trade reporting platforms, wealth management portals, core banking systems, investment banking applications, digital compliance engines, reconciliation utilities, operational dashboards, audit repositories and daily, weekly and monthly reporting platforms. Each of these areas has its own data models, control points, integration patterns, validation rules, exception paths and regulatory obligations. Hyperautomation does not replace engineering discipline; it strengthens it by making business intent, technical execution, control evidence and continuous improvement part of the same lifecycle.</p>



<h2 class="wp-block-heading">From automation to hyperautomation in banking applications</h2>



<p class="wp-block-paragraph">Automation usually addresses a specific task: moving data from one system to another, generating a report, running a batch job or validating a transaction against a rule. Hyperautomation goes further. It looks at the complete business outcome and asks how the entire chain can be streamlined, governed, observed and improved. For example, a trade reporting process may begin with transaction capture, enrich the trade with reference data, validate regulatory fields, identify breaks, generate a submission file, transmit it to a regulator or trade repository, monitor acknowledgements and preserve audit evidence. A narrow automation script may accelerate one step, but a <a href="https://www.gartner.com/en/documents/6454507">hyperautomated design</a> coordinates the complete flow, including exception handling and evidence generation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/figure-Figure-automation-vs-hyperautomation.png?w=1024" alt="Figure: Automation vs. hyperautomation." class="wp-image-4206308" width="1024" height="775" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p class="wp-block-paragraph"><strong>Figure: Automation vs. hyperautomation</strong></p>



<p class="wp-block-paragraph">Embedded Generative AI adds a <a href="https://assets.ctfassets.net/5965pury2lcm/65QHMnfLGaRJzJ0sX5982o/520b5f0a9745aecc8730c645994e3a3b/Forrester_Study_-_AI_And_The_Next_Generation_of_Software_Testing.pdf">new layer of intelligence</a>. Instead of forcing every user interaction into rigid screens and codes, business applications can accept natural language prompts, interpret document content, summarize cases, generate draft responses, explain anomalies, produce test scenarios and create release notes. In a banking environment, this intelligence must be carefully bounded. Every AI-assisted action should be traceable, explainable, reviewable and aligned with data privacy, model risk, information security and regulatory expectations. The goal is not uncontrolled autonomy; the goal is governed acceleration.</p>



<h2 class="wp-block-heading">Banking application components suitable for hyperautomation</h2>



<p class="wp-block-paragraph">A modern banking application is rarely a single monolithic system. It is a composition of business capabilities, integration services, workflow engines, data pipelines, user experience layers, analytics models, control dashboards and audit stores. Hyperautomation can accelerate the development and integration of these components by turning repetitive engineering work into <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">reusable patterns</a> and by embedding intelligence directly into business processes.</p>



<ul class="wp-block-list">
<li><strong>Trade reporting applications:</strong> Generative AI can help map trade attributes to regulatory fields, explain validation failures, summarize rejected submissions and generate test cases for reporting scenarios. Hyperautomation can orchestrate enrichment, validation, submission, acknowledgement tracking and evidence archival.</li>



<li><strong>Wealth management platforms:</strong> Advisors can use embedded AI to summarize client portfolios, generate suitability narratives, identify missing documents and prepare personalized investment review notes. Automation can coordinate onboarding, risk profiling, document verification, portfolio rebalancing workflows and client communication approvals.</li>



<li><strong>Core banking applications:</strong> Account opening, loan servicing, deposits, payments, interest calculations and customer maintenance can benefit from automated validations, intelligent forms, workflow routing and natural language assistance for operations teams. AI can explain account events or transaction exceptions in plain language.</li>



<li><strong>Investment banking systems:</strong> Deal pipelines, research workflows, underwriting processes, trade lifecycle functions and risk calculations require strong coordination across front-office, middle-office and back-office platforms. Hyperautomation can standardize approvals, documentation, exception resolution and control evidence across these stages.</li>



<li><strong>Digital compliance applications:</strong> Compliance teams can use AI to summarize policy obligations, compare regulatory changes with internal controls, classify alerts, draft investigation notes and produce evidence packs. Automation ensures routing, approvals, segregation of duties, audit trails and regulatory reporting timelines are consistently enforced.</li>



<li><strong>Reconciliation platforms:</strong> AI can assist in matching narratives, explaining breaks, clustering exception patterns and suggesting resolution actions. Hyperautomation can pull data from ledgers, statements, payment processors, trading systems and data warehouses, then route unresolved breaks to the right teams.</li>



<li><strong>Reporting and audit applications:</strong> Daily, weekly and monthly reports can be generated through controlled data pipelines, automated quality checks, narrative generation, variance explanations and approval workflows. Audit applications can preserve lineage, approvals, source extracts, model outputs and control attestations.</li>
</ul>



<h2 class="wp-block-heading">Embedded generative AI as an application capability</h2>



<p class="wp-block-paragraph">Embedding Generative AI into business applications should be treated as an architectural capability, not as a decorative chatbot. A banking application may use AI for search, summarization, reasoning support, content generation, code generation, policy interpretation or anomaly explanation. Each use case requires clear boundaries. The application must know which data the model can access, which actions require approval, what evidence must be captured and where deterministic controls must override probabilistic <a href="https://www.idc.com/resource-center/generative-ai/">suggestions</a>.</p>



<p class="wp-block-paragraph">For example, in trade reporting, an embedded AI assistant can explain why a transaction failed validation and suggest likely fields to review. However, the final correction should pass through rule-based validations, maker-checker approval and audit logging. In wealth management, AI may draft a client review note based on portfolio movements and risk profile, but the advisor must verify suitability, disclosures and final communication. In reconciliation, AI can propose likely matches or categorize break reasons, while the system preserves the original data, confidence score, reviewer action and final resolution path.</p>



<h2 class="wp-block-heading">Hyperautomating the product development lifecycle</h2>



<p class="wp-block-paragraph">The Product Development Lifecycle can itself become hyperautomated. Instead of treating ideation, analysis, design, development, testing, security review, release and operations as disconnected phases, enterprises can create an AI-assisted delivery loop where every stage produces structured artifacts that the next stage can consume. Platforms such as GitHub Copilot, Claude Code or Claude Cowork-style agentic development environments and OpenAI Codex can support this movement by helping teams reason over requirements, generate code, create tests, review changes, modernize legacy modules and produce <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">documentation</a>. Their value increases when they are connected to repositories, issue trackers, design documents, build pipelines, test suites, security scanners, observability data and enterprise knowledge bases.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>PDLC Stage</strong></td><td><strong>Hyperautomation Opportunity</strong></td><td><strong>AI-Assisted Outcome</strong></td></tr><tr><td>Business discovery</td><td>Process mining, domain interviews, regulatory mapping, backlog creation</td><td>Structured epics, user stories, acceptance criteria, process maps and control requirements</td></tr><tr><td>Architecture and design</td><td>Reference architectures, API contracts, data models, event flows, security patterns</td><td>Architecture options, integration blueprints, threat-model prompts and design decision records</td></tr><tr><td>Development</td><td>Code generation, service scaffolding, UI component creation, data pipeline templates</td><td>Review-ready code increments, reusable components, migration utilities and integration adapters</td></tr><tr><td>Testing</td><td>Unit, integration, regression, performance, compliance and synthetic data testing</td><td>Generated test cases, defect reproduction steps, test automation scripts and coverage summaries</td></tr><tr><td>Security and compliance review</td><td>Static analysis, dependency checks, policy validation, evidence capture</td><td>Risk explanations, remediation suggestions, control traceability and approval evidence</td></tr><tr><td>Release and deployment</td><td>CI/CD orchestration, environment promotion, release notes, rollback preparation</td><td>Automated deployment packs, release summaries, operational checklists and change records</td></tr><tr><td>Operations and feedback</td><td>Observability, incident analysis, user feedback mining, backlog refinement</td><td>Incident summaries, root-cause hypotheses, improvement stories and reliability recommendations</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Role of GitHub Copilot, Claude Cowork and Codex</h2>



<p class="wp-block-paragraph">GitHub Copilot is useful where developers need assistance inside the engineering flow: explaining code, generating functions, proposing tests, reviewing pull requests and helping teams move from issue to implementation. In a banking PDLC, it can accelerate microservice creation, API integration, batch processing logic, reconciliation rules, regulatory validation routines and UI workflows. When used with repository context and proper review discipline, it can reduce the time developers spend on repetitive coding while preserving human accountability for design and correctness.</p>



<p class="wp-block-paragraph">Claude Cowork or Claude Code-style agentic environments are valuable for multi-file reasoning, refactoring, debugging and documentation-heavy engineering work. Banking applications often contain deep domain logic scattered across services, configuration files, stored procedures, integration scripts and test suites. An agentic coding assistant that can understand a wider codebase context can help engineers analyze dependencies, prepare modernization plans, update multiple files coherently and draft explanations for reviewers. This is particularly useful in core banking modernization, trade reporting rule updates and compliance workflow refactoring.</p>



<p class="wp-block-paragraph">OpenAI Codex can support issue-to-pull-request workflows, test generation, code review, bug reproduction, migration activities and broader software engineering tasks across the lifecycle. In a hyperautomated PDLC, Codex-like agents can be assigned well-scoped work items, asked to inspect failing tests, propose fixes, create regression coverage and summarize the change for human reviewers. The important design principle is to keep agents inside controlled boundaries: clear prompts, repository permissions, test gates, approval workflows and traceable outputs.</p>



<h2 class="wp-block-heading">Integration architecture for hyperautomated banking applications</h2>



<p class="wp-block-paragraph">A practical architecture begins with business capability decomposition. Each banking domain should be expressed as a set of bounded capabilities such as customer onboarding, account maintenance, trade enrichment, exception management, portfolio review, control attestation, report generation and audit retrieval. These capabilities should be exposed through APIs, events, workflow tasks, data products and user interfaces. Hyperautomation then connects these capabilities using orchestration engines, event streams, rules engines, AI services, RPA connectors where legacy integration is unavoidable and observability layers that capture business and technical telemetry.</p>



<p class="wp-block-paragraph">The embedded AI layer should sit behind a secure application service boundary. It should use retrieval-augmented generation where approved policies, product rules, application documentation and regulatory mappings are retrieved from trusted sources. It should avoid uncontrolled exposure of sensitive customer information. Prompt templates, response validation, redaction, grounding checks, model monitoring and human-in-the-loop approval should be part of the production design. In banking, the most successful AI pattern is often not full automation but <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">assisted</a> decisioning with strong controls.</p>



<h2 class="wp-block-heading">Example: Hyperautomated reconciliation and reporting flow</h2>



<p class="wp-block-paragraph">Consider a reconciliation application that compares ledger balances, payment files, trade settlement records and external statements. In a conventional model, operations teams spend significant time downloading files, running macros, investigating mismatches, documenting break reasons and preparing status reports. In a hyperautomated model, data ingestion is scheduled and monitored, schema checks run automatically, matching engines classify obvious matches, AI assists with ambiguous narratives, exceptions are routed through workflow queues and dashboards update in near real time. At the end of the day, the system can generate a draft operations <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">report</a> explaining unresolved breaks, aging trends, risk exposure and pending approvals.</p>



<p class="wp-block-paragraph">The same pattern can extend to daily, weekly and monthly reporting. Data quality rules validate inputs, report templates are populated automatically, AI generates narrative commentary on variances, reviewers approve or amend explanations and the final report is archived with lineage and approvals. Audit teams can later retrieve not only the report but also the source extracts, transformation logs, exception history, reviewer decisions and AI-generated drafts. This creates a richer control environment than manual reporting because evidence is captured by design rather than reconstructed later.</p>



<h2 class="wp-block-heading">Governance, risk and control considerations</h2>



<p class="wp-block-paragraph">Hyperautomation in banking must be designed with governance from the beginning. The development team should define which activities can be automated, which can be AI-assisted and which must remain under human approval. Source code generated by AI must pass normal engineering controls, including peer review, static analysis, dependency scanning, secure coding checks, test execution and production readiness review. Business outputs generated by AI, such as compliance narratives or client-facing explanations, should be <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">reviewed</a> where regulatory or reputational risk is material.</p>



<p class="wp-block-paragraph">Data governance is equally important. AI-enabled applications must respect data classification, residency, retention, masking and access policies. The model should not become an uncontrolled channel through which confidential customer, trading or employee information can leak. Every prompt, retrieved source, generated response, user action and final decision may need to be logged depending on the use case. For audit applications, this traceability is not optional; it is the foundation of trust.</p>



<h2 class="wp-block-heading">Operating model for AI-native PDLC</h2>



<p class="wp-block-paragraph">A hyperautomated PDLC requires changes in team behavior. Product owners should write requirements in a structured manner so that AI tools can generate better stories, acceptance criteria and test scenarios. Architects should maintain living decision records, reference patterns and integration standards that AI agents can use as context. Developers should learn prompt discipline, context packaging and review techniques. Test engineers should focus on coverage strategy, synthetic data, compliance scenarios and defect prevention rather than only manual execution. Operations teams should feed incident <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">learnings</a> back into the backlog so the system improves continuously.</p>



<p class="wp-block-paragraph">The role of human experts becomes more important, not less. AI can draft, generate, compare and suggest, but domain judgment remains essential. A trade reporting specialist understands regulatory nuance. A wealth advisor understands client suitability. A core banking architect understands transaction integrity. A compliance officer understands control interpretation. Hyperautomation works best when it amplifies these experts and removes repetitive friction around them.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Hyperautomation in business application development is not simply a faster way to write software. It is a new way to connect business intent, engineering execution, operational control and continuous learning. In banking, where applications must be reliable, explainable, secure and compliant, the combination of embedded Generative AI and disciplined automation can transform how applications are designed, built, integrated, tested, released and operated. Trade reporting, wealth management, core banking, investment banking, compliance, reconciliation, reporting and audit functions can all benefit when AI is embedded responsibly and automation is orchestrated across the complete lifecycle.</p>



<p class="wp-block-paragraph">Platforms such as GitHub Copilot, Claude Cowork or Claude Code and OpenAI Codex can play an important role in this transformation by accelerating analysis, development, testing, review, modernization and documentation. Their greatest value appears when enterprises treat them not as isolated productivity tools but as part of a governed, AI-native PDLC. The future of banking application development will belong to teams that can combine human expertise, reusable engineering patterns, intelligent automation and strong governance into one coherent delivery model.</p>



<p class="wp-block-paragraph"><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="noreferrer noopener"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="noreferrer noopener"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside the post-merger IT overhaul at Alaska Airlines]]></title>
<description><![CDATA[As an aviation industry veteran with over 30 years of experience, Alaska Airlines CIO Charu Jain is all too familiar with the technology integration process that often follows a big airline merger.



By her count, she’s been involved in four such projects. But none, she says, has brought her gre...]]></description>
<link>https://tsecurity.de/de/3710291/it-security-nachrichten/inside-the-post-merger-it-overhaul-at-alaska-airlines/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710291/it-security-nachrichten/inside-the-post-merger-it-overhaul-at-alaska-airlines/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As an aviation industry veteran with over 30 years of experience, Alaska Airlines CIO Charu Jain is all too familiar with the technology integration process that often follows a big airline merger.</p>



<p class="wp-block-paragraph">By her count, she’s been involved in four such projects. But none, she says, has brought her greater satisfaction than leading the overhaul of Alaska’s PSS following its $1.9 billion acquisition of Hawaiian Airlines in September 2024.</p>



<p class="wp-block-paragraph">“This is one of the biggest milestones in any merger work done between airlines,” says Jain, speaking from her company’s Seattle offices just two months after Alaska and Hawaiian <a href="https://news.alaskaair.com/company/alaska-airlines-hawaiian-airlines-transition-to-shared-passenger-service-system-to-deliver-a-more-seamless-guest-experience/">completed their transition</a> to a shared PSS.</p>



<p class="wp-block-paragraph">In its simplest terms, a PSS is an all-encompassing software suite used by airlines to record and manage a passenger’s journey, from booking tickets and checking in baggage at the airport, to boarding the aircraft and accessing the in-flight menu. “A PSS touches almost every function of an airline from employees to guests,” says Jain.</p>



<h2 class="wp-block-heading">Two brands, one system</h2>



<p class="wp-block-paragraph">At the time of the merger, Alaska and Hawaiian each had its own PSS. No sooner had the ink dried on the deal than the cutover project got underway to bring both airlines’ systems under a single operating platform.</p>



<p class="wp-block-paragraph">According to Jain, the two airlines agreed from the get-go that they’d retain their own unique historic brands, both with a combined history of close to 200 years, which would be reflected through the system.</p>



<p class="wp-block-paragraph">“It had never been done before, developing capabilities to enable two brands on one platform,” adds Jain, who also serves as Alaska’s SVP of merchandising and innovation. “We didn’t want a situation where a passenger travelling from Spokane to Seattle on an Alaska-branded flight, and then onto Honolulu on a Hawaiian-branded flight, would have to navigate two separate systems. So we thought about how to make that experience more seamless.”</p>



<p class="wp-block-paragraph">After settling on a PSS, developed by travel software manufacturer Sabre, Jain and her colleagues began work on migrating the airlines’ millions of bookings and passenger information, while also updating their various guest- and employee-facing tools for the new system.</p>



<h2 class="wp-block-heading">Selling cutovers and mock flights</h2>



<p class="wp-block-paragraph">Executing a system cutover on such a large scale is a delicate balancing act, not least in a live-environment where, for a major airline, any form of disruption to the passenger experience can be bad for business. So there was no attempt to rush the project.</p>



<p class="wp-block-paragraph">“To make sure we didn’t have any issues with customers’ bookings, we really took a risk-optimized approach with a phased deployment and a phased cutover,” says Jain.</p>



<p class="wp-block-paragraph">Much of this hinged on what Alaska refers to as a selling cutover. Starting in October last year, all new bookings were made on the new PSS, which allowed the group to drain old bookings from the legacy system, and start selling tickets six months in advance of the official transition date; the average booking curve for an airline is around six months.</p>



<p class="wp-block-paragraph">“There was no migration of millions of records and bookings,” says Jain. “This meant when our customers checked in on the first day [of the PSS], it was as if the booking had been made on the native system.”</p>



<p class="wp-block-paragraph">While this was going on, however, Alaska was hit by a sizeable IT outage that grounded flights across the country and impacted the travel plans of nearly 50,000 passengers. It followed a previous IT outage in July. However, Jain says the disruptions didn’t impact the project in any way.</p>



<p class="wp-block-paragraph">So in the final months leading up to the cutover completion, Alaska carried out several dress rehearsals to test the system, including mock flights for domestic and international routes in anticipation of the recent launch of <a href="https://news.alaskaair.com/destinations/alaska-airlines-advances-global-expansion-with-launch-of-new-european-routes-and-landmark-lounge-investment/">several non-stop services to Europe</a>.</p>



<p class="wp-block-paragraph">This involved real guests arriving at the airport, completing check-in, going through security, and taking their seats as if they were about to take off. Leaving no stone unturned, the simulation also accounted for baggage collection, pets, wheelchair users, and onboard hospitality, stopping just short of passengers being served actual food.</p>



<p class="wp-block-paragraph">Alaksa completed five such mock rehearsals in all. “The fifth one was when everything worked without any medium or high issues, and gave us the confidence we were ready,” says Jain.</p>



<p class="wp-block-paragraph">As part of the airline’s scenario planning, it also set up command centers in various locations, including Honolulu and Seattle, to plan for unforeseen and unrelated problems on the day of the cutover.</p>



<h2 class="wp-block-heading">A dedication to collaboration</h2>



<p class="wp-block-paragraph">A project is only ever as a good as its people, and Jain is quick to hail the collaborative spirit that Alaska and Hawaiian brought to the table. As a PSS involves both the operational side of an airline’s business — touching on everyone from pilots, flight attendants, and baggage handlers — and commercial departments responsible for policies and pricing, this was more than a purely technological undertaking.</p>



<p class="wp-block-paragraph">“This was about people coming together from two companies to make this one big thing happen,” says Jain.</p>



<p class="wp-block-paragraph">When Alaska started making bookings on the new PSS last fall as part of the selling cutover, it also began training employees how to use system. It was around that time as well, says Jain, that the airline was confident the transition would be completed by April 2026, just in time for the busy summer travel season.</p>



<p class="wp-block-paragraph">Since the PSS has been up and running, the company has also introduced a single mobile app to replace Alaska and Hawaiian’s separate existing ones, allowing passengers to personalize their experience to the airline brand they’re more familiar with.</p>



<p class="wp-block-paragraph">“It’s a much more seamless experience now that there’s no confusion knowing which app to go on, or why they have two booking numbers,” says Jain. Alaska’s employees are also just as happy with their new tools, she adds.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ICE Is Buying Access to Credit Card Records]]></title>
<description><![CDATA[Through data brokers, ICE is buying the information you provided to open a credit card.]]></description>
<link>https://tsecurity.de/de/3710284/it-security-nachrichten/ice-is-buying-access-to-credit-card-records/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710284/it-security-nachrichten/ice-is-buying-access-to-credit-card-records/</guid>
<pubDate>Fri, 07 Aug 2026 23:47:56 +0200</pubDate>
<content:encoded><![CDATA[<p>Through data brokers, ICE is <a href="https://www.404media.co/you-opened-a-credit-card-ice-now-knows-where-you-live/">buying</a> <a href="https://boingboing.net/2026/07/23/credit-header-data-ice.html">the</a> <a href="https://mastodon.social/@heidilifeldman/116981503852352281">information</a> you provided to open a credit card.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD to buy Taalas, maker of model-specific AI chips for enterprise inference]]></title>
<description><![CDATA[As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.



AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights...]]></description>
<link>https://tsecurity.de/de/3710260/it-security-nachrichten/amd-to-buy-taalas-maker-of-model-specific-ai-chips-for-enterprise-inference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710260/it-security-nachrichten/amd-to-buy-taalas-maker-of-model-specific-ai-chips-for-enterprise-inference/</guid>
<pubDate>Fri, 07 Aug 2026 23:47:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.</p>



<p class="wp-block-paragraph">AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights into custom silicon, instead of repeatedly loading them from memory during inference as conventional <a href="https://www.networkworld.com/article/3966130/what-are-gpus-inside-the-processing-power-behind-ai.html">GPUs</a> do.</p>



<p class="wp-block-paragraph">Taalas says its approach reduces the time and power required to move model weights between memory and compute units, making things run faster and cheaper.</p>



<p class="wp-block-paragraph">The result is a highly specialized inference processor optimized for one model, trading the flexibility of programmable hardware for substantially higher throughput and energy efficiency.</p>



<h2 class="wp-block-heading">Operational tradeoffs</h2>



<p class="wp-block-paragraph">While AMD is planning to integrate the chips into its <a href="https://www.amd.com/en/products/accelerators/instinct.html">Instinct GPU</a> roadmap, targeting system-level AI inference solutions in data centers, analysts remain skeptical that enterprises will readily embrace hardware tied to a specific AI model.</p>



<p class="wp-block-paragraph">Enterprises would, effectively, be buying a chip and a model together because unlike GPUs, which can be repurposed to run different AI models through software updates, Taalas’ chips are tied to a specific trained model, meaning they would need different hardware to support different inference tasks, said <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Kumar Jena</a>, AI development manager at IT Consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Or as Forrester Principal Analyst <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a> put it, “The biggest risk is inflexibility.”</p>



<p class="wp-block-paragraph">The requirement to swap hardware in order to swap tasks would, Dai said, introduce new challenges with costs, governance, capacity planning, lifecycle management, and supplier dependency, especially for enterprises managing multiple AI workloads.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/manoj-chandra-jha-b5ab0a13" target="_blank" rel="noreferrer noopener">Manoj Chandra Jha</a>, principal analyst at Nord-IQ Research, said the risk of fusing chip and model into one component is larger than one might think, as “early model obsolescence strands both together, so this should be modeled as one shorter-lived asset rather than two independently amortized ones.”</p>



<p class="wp-block-paragraph">Taalas says it can update a model by modifying only two metal layers of the chip rather than redesigning it from scratch, but that will only apply to chips that haven’t yet left its factory, not those already in use.</p>



<p class="wp-block-paragraph">That means enterprises will still need to plan for hardware refresh cycles measured in weeks or months and retain programmable GPUs for workloads that evolve frequently, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p class="wp-block-paragraph">It also means, said Jha, that what is typically a software decision becomes one about capital expenditure for Taalas customers, as replacing or switching workloads or models could require investing in new hardware rather than simply updating software.</p>



<h2 class="wp-block-heading">Where model-specific silicon fits</h2>



<p class="wp-block-paragraph">Those tradeoffs significantly narrow the range of enterprise workloads where model-specific silicon is likely to make economic sense.</p>



<p class="wp-block-paragraph">Dai sees the technology as best suited for mature, predictable inference workloads that run at massive scale and rely on relatively stable AI models, such as customer service automation, fraud detection, industrial computer vision, network operations, edge AI, and embedded copilots.</p>



<p class="wp-block-paragraph">For CIOs, that effectively limits model-specific silicon to a small subset of enterprise AI deployments, rather than a wholesale replacement for GPU infrastructure, he said. “GPUs will remain the preferred enterprise platform because most enterprises value flexibility, multi-tenancy, and rapid model evolution over maximum efficiency.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Real emails, hijacked payments: Two H1 2026 attack chains]]></title>
<description><![CDATA[Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [...]]]></description>
<link>https://tsecurity.de/de/3710256/it-security-nachrichten/real-emails-hijacked-payments-two-h1-2026-attack-chains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710256/it-security-nachrichten/real-emails-hijacked-payments-two-h1-2026-attack-chains/</guid>
<pubDate>Fri, 07 Aug 2026 23:47:14 +0200</pubDate>
<content:encoded><![CDATA[Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Barox präsentiert Software xNMS für Videonetzwerk-Management - Protector]]></title>
<description><![CDATA[Zentrale Verwaltung von Sicherheitsnetzwerken: Barox und Gallagher bieten Monitoring, SNMP-Traps und Remote. IT-Sicherheit. Netzwerkdiagnose rückt ...]]></description>
<link>https://tsecurity.de/de/3710239/it-security-nachrichten/barox-praesentiert-software-xnms-fuer-videonetzwerk-management-protector/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710239/it-security-nachrichten/barox-praesentiert-software-xnms-fuer-videonetzwerk-management-protector/</guid>
<pubDate>Fri, 07 Aug 2026 23:47:07 +0200</pubDate>
<content:encoded><![CDATA[Zentrale Verwaltung von Sicherheitsnetzwerken: Barox und Gallagher bieten Monitoring, SNMP-Traps und Remote. <b>IT</b>-<b>Sicherheit</b>. Netzwerkdiagnose rückt ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder]]></title>
<description><![CDATA[Investigation into whether staff improperly accessed Minnie Merriman’s file after she was named for the first time this week]]></description>
<link>https://tsecurity.de/de/3710225/it-security-nachrichten/scot-nhs-trust-probes-access-to-medical-records-of-9-year-old-girl-after-man-arrested-on-suspicion-of-murder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710225/it-security-nachrichten/scot-nhs-trust-probes-access-to-medical-records-of-9-year-old-girl-after-man-arrested-on-suspicion-of-murder/</guid>
<pubDate>Fri, 07 Aug 2026 23:47:04 +0200</pubDate>
<content:encoded><![CDATA[Investigation into whether staff improperly accessed Minnie Merriman’s file after she was named for the first time this week]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie digitale Zertifikate das Building Management System absichern]]></title>
<description><![CDATA[Vernetzte Gebäudetechnik erweitert die Angriffsfläche von Bürokomplexen, Krankenhäusern oder Rechenzentren erheblich. Der OT-Sicherheitsanbieter BxC Security sieht in einer Public Key Infrastructure (PKI) einen zentralen Baustein, um manipulierte Geräte, unsichere Fernwartung und kompromittierte ...]]></description>
<link>https://tsecurity.de/de/3710217/it-security-nachrichten/wie-digitale-zertifikate-das-building-management-system-absichern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710217/it-security-nachrichten/wie-digitale-zertifikate-das-building-management-system-absichern/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:58 +0200</pubDate>
<content:encoded><![CDATA[Vernetzte Gebäudetechnik erweitert die Angriffsfläche von Bürokomplexen, Krankenhäusern oder Rechenzentren erheblich. Der OT-Sicherheitsanbieter BxC Security sieht in einer Public Key Infrastructure (PKI) einen zentralen Baustein, um manipulierte Geräte, unsichere Fernwartung und kompromittierte Firmware zu verhindern.]]></content:encoded>
</item>
<item>
<title><![CDATA[Framework Notifies 'All Customers' of a Data Breach Via Compromised Metabase BI Service]]></title>
<description><![CDATA["Framework has been sending out email notifications to customers alerting of a limited data breach in which customer information was accessed through a Metabase BI service zero-day exploit," writes Slashdot reader DuoDreamer. Data includes customer names, email addresses, phone numbers, and physi...]]></description>
<link>https://tsecurity.de/de/3710210/it-security-nachrichten/framework-notifies-all-customers-of-a-data-breach-via-compromised-metabase-bi-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710210/it-security-nachrichten/framework-notifies-all-customers-of-a-data-breach-via-compromised-metabase-bi-service/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:54 +0200</pubDate>
<content:encoded><![CDATA["Framework has been sending out email notifications to customers alerting of a limited data breach in which customer information was accessed through a Metabase BI service zero-day exploit," writes Slashdot reader DuoDreamer. Data includes customer names, email addresses, phone numbers, and physical addresses. "Framework is investigating whether or not this included Framework for Business customers as well." TechCrunch reports: Framework's spokesperson Eric Schumacher told TechCrunch that the breach affected "all customers," but declined to specify a specific number. Framework computers are relatively niche products, but some estimates say the company sold hundreds of thousands of devices.
 
Metabase disclosed its own breach in a blog post on its official website, where it said that it was hacked by someone using an unknown security flaw, a so-called zero-day. The company said the hackers exploited the bug to give them the ability to access customers' databases stored on Metabase's cloud servers.
 
In its email to customers, Framework also included the email Metabase sent to the company, which says hackers accessed Framework's cloud instance. The computer maker said it investigated the incident and found that hackers had stolen its customers' personal data, but did not include their payment information.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Framework+Notifies+'All+Customers'+of+a+Data+Breach+Via+Compromised+Metabase+BI+Service%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F07%2F1757230%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F07%2F1757230%2Fframework-notifies-all-customers-of-a-data-breach-via-compromised-metabase-bi-service%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/08/07/1757230/framework-notifies-all-customers-of-a-data-breach-via-compromised-metabase-bi-service?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP]]></title>
<description><![CDATA[WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with a...]]></description>
<link>https://tsecurity.de/de/3710199/it-security-nachrichten/new-wordpress-pre-auth-xss-could-lead-to-php-code-execution-patch-asap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710199/it-security-nachrichten/new-wordpress-pre-auth-xss-could-lead-to-php-code-execution-patch-asap/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:51 +0200</pubDate>
<content:encoded><![CDATA[WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page.

Tracked as CVE-2026-64638 (CVSS score: 8.9), the]]></content:encoded>
</item>
<item>
<title><![CDATA[Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access]]></title>
<description><![CDATA[Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID.

The attacker can then establish longer-term cloud access, register a device it control...]]></description>
<link>https://tsecurity.de/de/3710205/it-security-nachrichten/malware-can-abuse-windows-hello-for-business-keys-for-persistent-entra-id-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710205/it-security-nachrichten/malware-can-abuse-windows-hello-for-business-keys-for-persistent-entra-id-access/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:51 +0200</pubDate>
<content:encoded><![CDATA[Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID.

The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies]]></content:encoded>
</item>
<item>
<title><![CDATA[I'm a diehard OnePlus user: Here's my plan now that the company is leaving North America]]></title>
<description><![CDATA[OnePlus has officially ended business across North America and Europe. I explain what happens next and the best alternatives to consider.]]></description>
<link>https://tsecurity.de/de/3710168/it-security-nachrichten/im-a-diehard-oneplus-user-heres-my-plan-now-that-the-company-is-leaving-north-america/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710168/it-security-nachrichten/im-a-diehard-oneplus-user-heres-my-plan-now-that-the-company-is-leaving-north-america/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:45 +0200</pubDate>
<content:encoded><![CDATA[OnePlus has officially ended business across North America and Europe. I explain what happens next and the best alternatives to consider.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wispr moves beyond AI dictation with note-taking assistant]]></title>
<description><![CDATA[Wispr, the startup behind dictation tool Wispr Flow, has created an AI note-taking assistant that records meetings and generates conversation summaries for users.



The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things...]]></description>
<link>https://tsecurity.de/de/3710152/it-nachrichten/wispr-moves-beyond-ai-dictation-with-note-taking-assistant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710152/it-nachrichten/wispr-moves-beyond-ai-dictation-with-note-taking-assistant/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:40 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Wispr, the startup behind <a href="https://www.computerworld.com/article/4107331/wispr-ceo-interview-post-keyboard-office.html">dictation tool Wispr Flow</a>, has created an AI note-taking assistant that records meetings and generates conversation summaries for users.</p>



<p class="wp-block-paragraph">The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things down,” said Sahaj Garja, Wispr CTO and co-founder.</p>



<p class="wp-block-paragraph">Notetaker starts recording with one click, and doesn’t require a bot to attend a video or voice call. It can also be used to capture in-person conversations.</p>



<p class="wp-block-paragraph">The software has three key functions. Before a call, Notetaker displays a meeting brief with information such as meeting purpose and background of participants.</p>



<p class="wp-block-paragraph">Once the meeting starts, a live transcript displays the dialogue text and labels speakers. A “what did I miss?” button provides a summary of talking points from the previous few minutes.</p>



<p class="wp-block-paragraph">Finally, post-meeting, Notetaker generates a more detailed summary organized by topic that includes information such as key dates, decisions, and next steps. Users can search across notes from previous meetings in the Notetaker app. “Over time your meeting history stops being a folder of documents you have to go find and becomes something you can ask questions of,” said Garja.</p>



<p class="wp-block-paragraph">Notetaker integrates with AI assistants such as Anthropic’s Claude and OpenAI’s ChatGPT via model context protocol. This allows users to connect outputs such as transcripts and summaries “into how you already work, instead of sitting in a separate app,” said Garja.</p>



<p class="wp-block-paragraph">With Notetaker, Wispr competes in an increasingly busy market for AI note-taking apps that includes Fireflies, Granola and Otter.</p>



<p class="wp-block-paragraph">Wispr <a href="https://wisprflow.ai/post/wispr-flow-notetaker" target="_blank" rel="noreferrer noopener">claims</a> Notetaker can produce more accurate transcripts than existing tools, partly because of the additional context it uses during transcription. It uses the same personal dictionary from Wispr Flow that includes acronyms, products, and preferred spellings, and can also draw on other sources such as calendar information to understand the purpose of a meeting and help ensure speakers are labelled correctly.</p>



<p class="wp-block-paragraph">Before generating the final summary, Notetaker also re-reads the live meeting transcript and combines it with additional context to create a more accurate final output, Garja said.</p>



<p class="wp-block-paragraph">Notetaker is the first new product launched by Wispr, which was founded in 2021 and has since <a href="https://wisprflow.ai/new-funding" target="_blank" rel="noreferrer noopener">raised</a> $81 million in funding.</p>



<p class="wp-block-paragraph">“We didn’t set out to build a dictation app,” said Garja. “The mission has always been to reshape how people interact with their devices, and dictation was the fastest way in.”</p>



<p class="wp-block-paragraph">“Notetaker is the second product on that path. Dictation took the keyboard out of writing. Notetaker takes it out of meetings, so nobody has to spend the call typing up what everyone just said.”</p>



<h2 class="wp-block-heading">User consent when recording calls</h2>



<p class="wp-block-paragraph">As AI note-taking tools have become more prevalent in the workplace, privacy concerns have arisen, including the need for all-party consent when recording a call in some jurisdictions, and whether meeting audio is used to train AI models. Two software vendors, <a href="https://www.computerworld.com/article/4041849/enterprise-note-taking-apps-face-legal-scrutiny-as-otter-hit-with-privacy-suit.html">Otter</a> and <a href="https://www.computerworld.com/article/4206255/granola-lawsuit-raises-concerns-over-ai-note-taking-app-privacy.html">Granola</a>, currently face separate lawsuits in California that allege privacy law violations related to their products.</p>



<p class="wp-block-paragraph">Wispr Flow Notetaker captures audio locally on a user’s device rather than joining the call as a visible bot. That means there’s no notification to signal that a conversation is being transcribed, which places responsibility on users to disclose the recording to others on the call in accordance with local laws, said Garja.</p>



<p class="wp-block-paragraph">“Users should always let the other person know before you start recording or transcribing a conversation, whether it’s a video call, an in-person meeting, or a phone call,” he said, adding that Wispr intends to build additional features for automated consent messaging “in the coming weeks.”</p>



<p class="wp-block-paragraph">Wispr doesn’t train its AI models on customer data without consent, though free and standard tier customers must choose to opt-out, according to Wispr’s privacy <a href="https://docs.wisprflow.ai/articles/3467817258-security-and-compliance-faq" target="_blank" rel="noreferrer noopener">terms</a>. Nor does it create “voiceprints or biometric profiles” of users or anyone else on a call using audio recording data, the company says.</p>



<p class="wp-block-paragraph">When Notetaker is active, conversation audio is captured on a user’s device and processed on cloud servers to enable transcription. The recorded audio file is encrypted and stored temporarily on the user’s device or cloud storage, Wispr said. After a limited period, the audio is automatically deleted.</p>



<p class="wp-block-paragraph">Notetaker is available with the Wispr Flow macOS app to free and paid subscribers, with support for Windows “coming soon.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From ambition to action: What Canadian tech leaders must get right to see meaningful value from transformation efforts]]></title>
<description><![CDATA[It’s no secret that the CIO role is changing in Canadian enterprises. Driving operational performance and increasing efficiency are, of course, still a big part of the job. But CIOs are now expected to do more than cut costs and keep the lights on. Increasingly, boards of directors expect the CIO...]]></description>
<link>https://tsecurity.de/de/3710141/it-nachrichten/from-ambition-to-action-what-canadian-tech-leaders-must-get-right-to-see-meaningful-value-from-transformation-efforts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710141/it-nachrichten/from-ambition-to-action-what-canadian-tech-leaders-must-get-right-to-see-meaningful-value-from-transformation-efforts/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s no secret that the CIO role is changing in Canadian enterprises. Driving operational performance and increasing efficiency are, of course, still a big part of the job. But CIOs are now expected to do more than cut costs and keep the lights on. Increasingly, boards of directors expect the CIO to play a key role in creating value and enabling their organizations to outperform their rivals. Recent data backs this up. The overwhelming majority (91%) of Canadian technology leaders believe advanced technology will be the primary driver of competitive advantage over the next three years, according to KPMG’s “<a href="https://kpmg.com/ca/en/insights/2026/02/execution-imperatives-for-canadian-tech-leaders.html" target="_blank" rel="noreferrer noopener">The 8 execution imperatives for Canadian tech leaders</a>,” a white paper based on the firm’s <a href="https://kpmg.com/xx/en/our-insights/ai-and-technology/global-tech-report.html" target="_blank" rel="noreferrer noopener">2026 Global Tech Report</a>.</p>



<p class="wp-block-paragraph">The race to capture value from emerging technologies has intensified, leaving little room for organizations that remain on the sidelines. Yet in Canada, just 27% of organizations consider themselves innovators or early adopters, while 72% are fast or slow followers. Nearly all (85%) believe they’ll need to take more risks with emerging technologies just to remain relevant.</p>



<p class="wp-block-paragraph">The traditional, operational-first mindset among CIOs has become a liability. CIOs are expected to be strategic players, but meeting that expectation requires taking thoughtful, well-considered action across key imperatives.</p>



<h3 class="wp-block-heading"><strong>AI success depends on data</strong></h3>



<p class="wp-block-paragraph"><strong>AI is not the only advanced technology that organizations are working to deploy, but it’s certainly garnering the most attention from C-suite executives, boards of directors, and investors. </strong>To enable AI at scale, the data foundations enterprises have built over the past decade will be necessary, but they are not sufficient on their own. CIOs must make modernizing the state of enterprise data a top priority.</p>



<p class="wp-block-paragraph">In most large organizations, data often remains locked inside legacy systems where the system of record is also the system of engagement, and that significantly limits accessibility for AI workloads. Data should be treated as the strategic asset that it has become. The quality, timeliness, and governance of that data vary widely, and reconciling those inconsistencies is one of the most persistent barriers to enterprise-level deployment.</p>



<p class="wp-block-paragraph">Scaling pilots into enterprise programs also requires closing the gap between AI-native talent, who have the skills to move quickly, and those with deep institutional knowledge, who understand how their organizations work and what they need to achieve. These two groups must work hand in hand. Otherwise, organizations may accelerate toward the wrong goals, which won’t move the business forward.</p>



<p class="wp-block-paragraph">“The barriers to scaling AI aren’t just technical,” says Sanjay Pathak, partner and national leader, technology strategy and digital transformation services, KPMG Canada. “CIOs need to truly and deeply understand the value chain of what their organizations do. Those who get there will have the imagination, the courage, and the foresight to use AI to transform their organizations.”</p>



<h3 class="wp-block-heading"><strong>Communicating ROI requires the right framing</strong></h3>



<p class="wp-block-paragraph">Beyond scaling, simply communicating the value of AI also poses a significant challenge. Just over half (53%) of Canadian organizations surveyed say they struggle to demonstrate or communicate AI value to stakeholders. Part of the problem is that CIOs are making the wrong argument in the wrong room because they’re framing ROI as a technology metric rather than a business outcome.</p>



<p class="wp-block-paragraph">“Any CIO who doesn’t truly understand what their business does is missing a beat around how innovation is going to help the organization achieve ROI,” says Pathak. “Understanding how to deploy AI inside your value chain will give you a head start and a competitive advantage in unlocking real business benefits.”</p>



<p class="wp-block-paragraph">A formal performance measurement framework that tracks customer experience, revenue growth, and employee adoption alongside cost metrics gives CIOs a far more accurate picture of long-term value. Linking funding decisions to those strategic outcomes makes sustained investment easier to justify.</p>



<p class="wp-block-paragraph">There is also a compliance dimension that often goes unacknowledged in these conversations. CIOs who bring business, technology, and compliance leaders together to design innovative processes that are “compliant by design” from the start are protecting future value as much as they are delivering value today.</p>



<p class="wp-block-paragraph">“You need to assemble that multi-dimensional cohort of business, technology, risk, and compliance leaders at the same table, envisioning compliance by design,” says Pathak. “The winners in this space are going to be the ones who really think about business ambition holistically and focus on efficient delivery, operations, and compliance.”</p>



<h3 class="wp-block-heading"><strong>Building disciplined innovation governance</strong></h3>



<p class="wp-block-paragraph">An organization’s approach to governance makes an enormous difference in how quickly and confidently it can deploy and take advantage of advanced technologies. As noted above, almost three-quarters (72%) identify as fast or slow followers, and 85% say they need to move more aggressively to embrace new technologies. Canadian organizations aren’t lacking ambition. What they lack are the conditions required to innovate with confidence: clear ownership, defined risk thresholds, and shared accountability between technology, risk, and business teams.</p>



<p class="wp-block-paragraph">“You can be an innovator, but if your innovation is not directly connected to strategic business ambition and safety guardrails such as risk management, governance, and compliance, you’re creating labware,” says Pathak. “Being an early adopter means you’re comfortable with the technology. To make it truly viable, you must embrace all dimensions of enterprise value.”</p>



<p class="wp-block-paragraph">Strong governance does not slow innovation down but instead provides a structure that builds confidence and resilience at every level of the organization, from the board to project teams. A tiered governance approach that takes risk into account allows organizations to advance low-risk, incremental improvements and high-reward initiatives in parallel.</p>



<h3 class="wp-block-heading"><strong>Expanding partnerships to accelerate innovation</strong></h3>



<p class="wp-block-paragraph">Innovation isn’t a single-player game, and Canadian organizations know it. Ninety-seven percent of respondents say they plan to expand their external ecosystems. To date, a significant portion of those relationships have been transactional and focused on a specific capability or problem. But savvier organizations are moving toward multi-party innovation, where partners pool capabilities to share both risk and reward. This model requires a different kind of commitment because organizations are betting on a partner’s long-term viability, not just their current capability. Together, they must build the integration and governance infrastructure that makes these ecosystems work for all participants.</p>



<p class="wp-block-paragraph">“Moving to multi-party innovation ecosystems is an investment in integration and data,” says Pathak. “If you’re going to look at best of breed and stitch those together, what must be true for that to work is the ability for those different ecosystems to integrate and interoperate. And that creates a much stronger need for safety and governance.”</p>



<p class="wp-block-paragraph">Cybersecurity is another dimension that grows more important with every new partner added to the ecosystem. Security should be proactively built in, not imposed after a breach has already occurred.</p>



<p class="wp-block-paragraph">“The more ecosystem-based partnerships you have, the more opportunity you create along with the threat you have to deal with,” says Pathak. “You expand the attack surface, and you become more of a target, so governance and cybersecurity must be designed in from the start, not bolted on later.”</p>



<p class="wp-block-paragraph">Canadian government incentives, including Scientific Research and Experimental Development (SR&amp;ED) tax credits and AI-focused clusters, offer a way to share some of the cost and risk, particularly during periods of economic uncertainty.</p>



<p class="wp-block-paragraph">By leveraging these funding frameworks alongside robust ecosystem governance, forward-thinking organizations can safely scale their networks to turn shared risks into sustainable competitive advantages.</p>



<h3 class="wp-block-heading">In closing</h3>



<p class="wp-block-paragraph">For organizations navigating this environment, KPMG Canada emphasizes that the most consequential decisions ahead are not purely, or even mostly, technical. They are about how CIOs choose to lead, partner, measure, and govern in a period that rewards both ambition and discipline in equal measure.</p>



<p class="wp-block-paragraph">The data points are clear. CIOs who lead with both strategic ambition and disciplined execution will elevate their organizations above their competitors. By paying attention to the quality of their data, aligning technical priorities with critical business goals, and instituting strong governance and cybersecurity, they will set a higher standard for what Canadian competitiveness looks like in the years ahead.</p>



<p class="wp-block-paragraph">To learn more, read the full whitepaper: <a href="https://kpmg.com/ca/en/insights/2026/02/execution-imperatives-for-canadian-tech-leaders.html" target="_blank" rel="noreferrer noopener">The Top 8 Execution Imperatives for Canadian Tech Leaders</a>.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI workforce is more than doubling year on year, says Salesforce]]></title>
<description><![CDATA[Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual Agentic Enterprise Index, which looks at trends in AI agent development and deployment over the past five quarters.



It compiled data from customers who had activated agents in...]]></description>
<link>https://tsecurity.de/de/3710142/it-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710142/it-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual <a href="https://www.salesforce.com/agentforce/agentic-enterprise-index/" target="_blank" rel="noreferrer noopener">Agentic Enterprise Index</a>, which looks at trends in AI agent development and deployment over the past five quarters.</p>



<p class="wp-block-paragraph">It compiled data from customers who had activated agents in production every month of the analysis period to determine how their use of the technology has evolved between February 2025 and April 2026, as well as incorporating data from May 2026 Salesforce research studies.</p>



<p class="wp-block-paragraph">It found that businesses grew their agentic workforces from an average of five agents in February 2025 to 13 by April 2026, a 7% compound monthly growth rate (CMGR). In April 2026, it only took an average of 1.9 days to deploy an agent into production, a 53% decrease since the beginning of the report period.</p>



<p class="wp-block-paragraph">Not only were agents deployed more quickly, they have been progressively taking on more work once in use; over the 15 months, the average number of actions per account had a CMGR of 31%.</p>



<p class="wp-block-paragraph">“These agents are expanding beyond their initial scope to really become cross-functional,” said <a href="https://www.linkedin.com/in/caila-schwartz/" target="_blank" rel="noreferrer noopener">Caila Schwartz</a>, Salesforce’s head of agentic commerce insights, during a media briefing.</p>



<p class="wp-block-paragraph">Salesforce has attempted to measure how much work agents perform, rather than how many tokens they consume, creating its own <a href="https://www.cio.com/article/4138622/awu-by-salesforce-a-shiny-new-metric-that-tells-cios-little-of-value.html">Agentic Work Unit (AWU) metric</a>, although analysts have criticized the measure as being unrelated to business outcomes. Nevertheless, Salesforce said that as of April, Agentforce agents had performed 734 million AWUs, a number growing at about 15% each month.</p>



<p class="wp-block-paragraph">The research also showed that agents are acting across multiple cloud domains which, the company said, “underscores the practical necessity of a headless architecture. By decoupling the agent’s logic from traditional front-end user interfaces, agents can process tasks, execute actions, and trigger workflows anywhere.”</p>



<p class="wp-block-paragraph">Within the company, Salesforce itself has seen explosive growth in AI agent use, said <a href="https://www.linkedin.com/in/joseph-inzerillo-b917791/" target="_blank" rel="noreferrer noopener">Joe Inzerillo</a>, president of enterprise &amp; AI technology at Salesforce, with a threefold increase in sessions between February 2025 and April 2026. He said that the AI agent in Slack, Slackbot, saves the average employee five hours per week, with 83% of the company having adopted it.</p>



<p class="wp-block-paragraph">But Schwartz pointed out that different industries are approaching agentic AI in different ways, some more sophisticated than others. To measure that, Salesforce developed a Sophistication Index, a five-point scale scoring the cognitive complexity of an agent’s actions. Levels 1- 3  are assigned to tasks such as record lookups, drafting emails, or summarizing documents, while levels 4 and 5 include more complex functions such as updating database fields.</p>



<p class="wp-block-paragraph">The data showed that manufacturing, financial services, and healthcare and life sciences have built more sophisticated agent networks than what it called traditional AI frontrunners such as technology and retail.</p>



<p class="wp-block-paragraph">However, Inzerillo said, the most common use case industry wide, and the best place to start, is the service use case, which provides “far and away the best ROI to start with.”</p>



<p class="wp-block-paragraph">He also noted that, as people have become more conscious of what agents can do, they are asking agents to perform tasks, rather than simply answer questions.</p>



<p class="wp-block-paragraph">“Now what you’re starting to see people do is very action oriented. So instead of asking ’how do I file a form to request my vacation’ from our employee agent, they’re telling the employee agent, ‘hey I’m taking a vacation, you need to enter this form for me, and here’s the details,’” he said, adding that this bias towards action represents the evolution of agentic use.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Snowflake attacker pleads guilty to hack of 165 companies’ data]]></title>
<description><![CDATA[A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollars.



Industry so...]]></description>
<link>https://tsecurity.de/de/3710143/it-nachrichten/snowflake-attacker-pleads-guilty-to-hack-of-165-companies-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710143/it-nachrichten/snowflake-attacker-pleads-guilty-to-hack-of-165-companies-data/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. <a href="https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers" target="_blank" rel="noreferrer noopener">Connor Riley Moucka pleaded guilty</a> to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollars.</p>



<p class="wp-block-paragraph">Industry sources have identified Moucka as one of the main players in attacks on data hosted by cloud data warehouse Snowflake. Companies affected by the hacks <a href="https://www.csoonline.com/article/3629818/7-biggest-cybersecurity-stories-of-2024.html">include the likes of AT&amp;T, Ticketmaster and the Neiman Marcus Group</a>.</p>



<p class="wp-block-paragraph">He worked with two other hackers: <a href="https://www.csoonline.com/article/2517422/hacker-allegedly-paid-370000-ransom-to-delete-stolen-att-data.html">John Edward Binns</a> and Cameron John Wagenius. Binns was <a href="https://www.justice.gov/usao-wdwa/united-states-vs-connor-riley-moucka-and-john-erin-binns" target="_blank" rel="noreferrer noopener">not in US custody as of April 2026</a>, while Wagenius, going by the name of <a href="https://www.csoonline.com/article/3631033/us-soldier-linked-to-trump-call-log-hack-arrested-in-texas.html">Kiberphant0m, was arrested in January 2025</a> and <a href="https://www.justice.gov/opa/pr/former-us-soldier-pleads-guilty-hacking-and-extortion-scheme-involving-telecommunications" target="_blank" rel="noreferrer noopener">pleaded guilty in July that year</a></p>



<p class="wp-block-paragraph">Moucka and other members of the group used stolen login credentials to compromise data belonging to at least 165 customers of a US-based software-as-a-service company. This unauthorized access was used to steal billions of sensitive customer records and download terabytes of information,</p>



<p class="wp-block-paragraph">“Connor Moucka hacked over 150 companies and organizations, obtained extremely sensitive information, and extorted the victims for millions of dollars. Today’s guilty plea serves as a reminder to all cybercriminals, regardless of where they live, that they cannot hide behind a wall of anonymity. You will be found and brought to justice,” said assistant attorney general A. Tysen Duva of the Justice Department’s Criminal Division</p>



<p class="wp-block-paragraph">The trial is the result of a coordinated worldwide action against the Snowflake group. The investigation was led by the FBI but benefited from contributions from the Royal Canadian Mounted Police, the Australian Federal Police, Spain’s Guardia Civil, the Security Service of Ukraine and the Turkish National Police.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4206739/snowflake-attacker-pleads-guilty-to-hack-of-165-companies-data.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[There are two completely different roles called ‘FDE’]]></title>
<description><![CDATA[There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing 84% with $5B+ revenue. But “forward deployed engineer” is a vague term and means different...]]></description>
<link>https://tsecurity.de/de/3710144/it-nachrichten/there-are-two-completely-different-roles-called-fde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710144/it-nachrichten/there-are-two-completely-different-roles-called-fde/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing <a href="https://investors.palantir.com/files/2026%20Q1%20PLTR%2010-Q.pdf">84% with $5B+ revenue</a>. But “<a href="https://en.wikipedia.org/wiki/Forward_Deployed_Engineer#cite_note-1">forward deployed engineer</a>” is a vague term and means different things depending on the business you’re running.</p>



<p class="wp-block-paragraph">I spent almost 5 years at Palantir as a forward-deployed software engineer, and Palantir’s version of an “FDE” does not make sense for most companies I now meet as an early-stage VC. Depending on the type of business you’re building, this role could broadly mean one of two things: “the product builder” or “the platform operator.” Clearly defining which bucket you fall into will make it easier to hire for this role and run your FDE org.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/nature-of-work-vs-product-leverage.png?w=1024" alt="Figure: Nature of work vs. product leverage." class="wp-image-4206317" width="1024" height="578" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<h2 class="wp-block-heading">The product builder: The OG Palantir version</h2>



<p class="wp-block-paragraph">The north star is: do whatever it takes to actually solve the user’s problem. FDEs are not just responsible for making the platform work, but also discovering what to build and building it (actually creating software) in service of the customer.</p>



<h2 class="wp-block-heading">The platform operator: Solutions + technical customer success</h2>



<p class="wp-block-paragraph">The north star is: make the product work for the customer – deploy and operationalize it. This is what most startups today really mean when they want FDEs. FDEs here configure the core platform, manage account relationships and drive adoption. This is not new – companies have always had solutions engineers, sales engineers, customer success etc., although the work looks different as FDEs are increasingly building prototypes, configuring evals and building MCPs.</p>



<h2 class="wp-block-heading">Which FDE is right for you</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/customer-size.png?w=1024" alt="Figure: Customer size." class="wp-image-4206316" width="1024" height="457" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">For most situations, hiring product builder FDEs is a mistake.</p>



<p class="wp-block-paragraph">At scale, the FDEs should be the platform operator. It’s hard to have FDEs build and maintain highly custom product features, especially as the company scales. Over time, the custom product surface area distracts from building the core product, even though AI coding tools make it easy to ship new features quickly and maintain them.</p>



<p class="wp-block-paragraph">Many fast-growing AI startups recognize these constraints and structure the FDE role more like the platform operator. This also allows them to have 5-10 accounts per FDE, which is a much higher ratio than Palantir had (at least in 2023). Even the Palantir FDE role has evolved to look more like the platform operator.</p>



<p class="wp-block-paragraph">There are, however, situations when your FDEs should be the product builder archetype.</p>



<h3 class="wp-block-heading">1. You have very large customers (F500 scale)</h3>



<p class="wp-block-paragraph"><strong>Technical complexity</strong>: Large customers have complex environments with legacy infrastructure that often requires “out-of-platform” engineering work. I often encountered bespoke data infrastructure, privacy requirements, etc. at various Palantir customers that required me to build “out-of-platform” connectors, UIs and backends.</p>



<p class="wp-block-paragraph"><strong>Organizational inertia and trust</strong>: Serving large enterprises is about building trust. In short time periods, overfitting product to a specific user/workflow is often what delivers the most value, builds trust and helps organizations get over the inertia of moving away from Excel and legacy software tools that are part of their day-to-day workflow. For AI-native startups, it’s arguably even more important to invest in doing “unscalable” development with engineering boots on the ground, as it helps solidify your right to exist and eventually expand the customer relationship.</p>



<h3 class="wp-block-heading">2. You have many ICPs and workflows</h3>



<p class="wp-block-paragraph">If you have a broad range of ICPs and workflows that you serve, your product probably is not walk-up usable on day 1 of deployment. The short-term hacky things that product builder FDEs build to make the product work for these heterogeneous users/workflows will help you shape the product long-term.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/overfit-products.png?w=1024" alt='Figure: "Overfit" products.' class="wp-image-4206313" width="1024" height="570" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">Note: see Palantir Foundry’s architecture <a href="https://www.palantir.com/assets/xrfr7uokpv1b/mhoyY4c8vdVlJhulDStk2/a7340768109c8e8d79d00b4cb99d8e70/Whitepaper_-_Foundry_2022.pdf">here</a>.</p>



<p class="wp-block-paragraph">This was a big reason why Palantir FDEs were more like product builders (and are still able to – see the <a href="https://jobs.lever.co/palantir/dab396d4-2f14-4796-aac0-0d82883dccf0">Forward Deployed Software Engineer job profiles</a> as an example). The vision for Foundry was to be the operating system for an enterprise’s critical decisions – inherently multiple industries, users and workflows. A lot of FDE-led development showed that solving many of these use cases required complex data integrations, which led to the early versions of Foundry being best-suited for complex data integrations and building a customer’s “<a href="https://blog.palantir.com/ontology-finding-meaning-in-data-palantir-rfx-blog-series-1-399bd1a5971b">Ontology</a>”. Similarly, FDEs like myself built custom frontend applications for fraud analysis, pricing, etc. As certain patterns of what these applications required became more clear, they were centralized into an application-layer product.</p>



<h2 class="wp-block-heading">Who you should hire</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/who-you-should-hire.png?w=1024" alt="Figure: Who you hire." class="wp-image-4206314" width="1024" height="464" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/why-hire.png?w=1024" alt="Figure: Why hire one vs. the other." class="wp-image-4206315" width="1024" height="456" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph"><strong>Platform operator</strong>: There is a much broader set of people you could hire, testing for technical fluency (e.g., being good at data analysis, complex Excel work, even SQL), product intuition and an inclination to build customer relationships. Backgrounds like technical customer success, solutions engineering, software engineering, product management and consulting are all strong fits.</p>



<p class="wp-block-paragraph"><strong>Product builder</strong>: You want candidates that are high ownership and missionary software engineers, or technical PMs who want to ship products themselves.</p>



<p class="wp-block-paragraph">Hiring for these profiles, especially product builders, is hard. It’s worth calling out two things that helped Palantir hire software engineers into what might be considered a less sexy role.</p>



<ol start="1" class="wp-block-list">
<li><strong>Culture of building at the edge</strong>: Strong engineers are motivated to build things. Palantir gave FDEs a lot of ownership to build products, which is why much of the core product leadership was former FDEs.</li>



<li><strong>Cult built around mission</strong>: Internally, there was a cult-like devotion to the mission. Everyone always talked about why outcomes were far more important than software, and why most companies building tools had it wrong. I’ve never been at a company where people feel so closely bonded around a mission.</li>
</ol>



<p class="wp-block-paragraph">As founders building AI startups think about hiring FDEs, it’s worth being specific about your culture and asking: Am I just hiring people to support development teams, or am I hiring people to shape and build product? It’s hard to get software engineers (even today) to be excited about an FDE role that might just be technical customer success.</p>



<h2 class="wp-block-heading">What FDEs should be doing (regardless of archetype)</h2>



<p class="wp-block-paragraph">You’ve hired the right people. How do you best leverage your team of FDEs?</p>



<p class="wp-block-paragraph">FDEs were Palantir’s way of delivering outcomes rather than tools. AI-native startups can take this much further and FDEs can help in a few unique ways by leveraging their proximity to customers.</p>



<ol start="1" class="wp-block-list">
<li><strong>Find the most critical workflows</strong>: As AI lowers the cost of producing software, companies will face a lot more competition. FDEs at AI startups should be constantly finding ways to serve the most critical workflows for a customer and paying attention to how customers do work across newer and legacy tools. For example, FDEs at Harvey should pay attention to which workflows are in Westlaw, which ones are moving to ChatGPT/Claude, and how the Harvey product can stay ahead.</li>



<li><strong>Build around nondeterminism</strong>: In more regulated environments, FDEs should be hyper-focused on making products reliable for specific use cases <a href="https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents">using evals</a> and configs. Previously, product reliability lived with product and support. As companies provide outcomes instead of tools, configuring products appropriately and managing evals shifts towards FDE teams.</li>
</ol>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD wants to make enterprise inference cheaper and faster with chips from Taalas]]></title>
<description><![CDATA[As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.



AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights...]]></description>
<link>https://tsecurity.de/de/3710145/it-nachrichten/amd-wants-to-make-enterprise-inference-cheaper-and-faster-with-chips-from-taalas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710145/it-nachrichten/amd-wants-to-make-enterprise-inference-cheaper-and-faster-with-chips-from-taalas/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As enterprises look for ways to cut the cost of running AI models in production, AMD is betting that not every AI workload will be best served by a power-hungry general-purpose GPU.</p>



<p class="wp-block-paragraph">AMD has agreed to buy Taalas, the Canadian designer of chips that permanently embed a trained AI model’s weights into custom silicon, instead of repeatedly loading them from memory during inference as conventional <a href="https://www.networkworld.com/article/3966130/what-are-gpus-inside-the-processing-power-behind-ai.html">GPUs</a> do.</p>



<p class="wp-block-paragraph">Taalas says its approach reduces the time and power required to move model weights between memory and compute units, making things run faster and cheaper.</p>



<p class="wp-block-paragraph">The result is a highly specialized inference processor optimized for one model, trading the flexibility of programmable hardware for substantially higher throughput and energy efficiency.</p>



<h2 class="wp-block-heading">Operational tradeoffs</h2>



<p class="wp-block-paragraph">While AMD is planning to integrate the chips into its <a href="https://www.amd.com/en/products/accelerators/instinct.html">Instinct GPU</a> roadmap, targeting system-level AI inference solutions in data centers, analysts remain skeptical that enterprises will readily embrace hardware tied to a specific AI model.</p>



<p class="wp-block-paragraph">Enterprises would, effectively, be buying a chip and a model together because unlike GPUs, which can be repurposed to run different AI models through software updates, Taalas’ chips are tied to a specific trained model, meaning they would need different hardware to support different inference tasks, said <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Kumar Jena</a>, AI development manager at IT Consulting firm Kanerika.</p>



<p class="wp-block-paragraph">Or as Forrester Principal Analyst <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a> put it, “The biggest risk is inflexibility.”</p>



<p class="wp-block-paragraph">The requirement to swap hardware in order to swap tasks would, Dai said, introduce new challenges with costs, governance, capacity planning, lifecycle management, and supplier dependency, especially for enterprises managing multiple AI workloads.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/manoj-chandra-jha-b5ab0a13" target="_blank" rel="noreferrer noopener">Manoj Chandra Jha</a>, principal analyst at Nord-IQ Research, said the risk of fusing chip and model into one component is larger than one might think, as “early model obsolescence strands both together, so this should be modeled as one shorter-lived asset rather than two independently amortized ones.”</p>



<p class="wp-block-paragraph">Taalas says it can update a model by modifying only two metal layers of the chip rather than redesigning it from scratch, but that will only apply to chips that haven’t yet left its factory, not those already in use.</p>



<p class="wp-block-paragraph">That means enterprises will still need to plan for hardware refresh cycles measured in weeks or months and retain programmable GPUs for workloads that evolve frequently, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p class="wp-block-paragraph">It also means, said Jha, that what is typically a software decision becomes one about capital expenditure for Taalas customers, as replacing or switching workloads or models could require investing in new hardware rather than simply updating software.</p>



<h2 class="wp-block-heading">Where model-specific silicon fits</h2>



<p class="wp-block-paragraph">Those tradeoffs significantly narrow the range of enterprise workloads where model-specific silicon is likely to make economic sense.</p>



<p class="wp-block-paragraph">Dai sees the technology as best suited for mature, predictable inference workloads that run at massive scale and rely on relatively stable AI models, such as customer service automation, fraud detection, industrial computer vision, network operations, edge AI, and embedded copilots.</p>



<p class="wp-block-paragraph">For CIOs, that effectively limits model-specific silicon to a small subset of enterprise AI deployments, rather than a wholesale replacement for GPU infrastructure, he said. “GPUs will remain the preferred enterprise platform because most enterprises value flexibility, multi-tenancy, and rapid model evolution over maximum efficiency.”</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.networkworld.com/article/4206674/amd-to-buy-taalas-maker-of-model-specific-ai-chips-for-enterprise-inference.html">Network World</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond chatbots: How embedded GenAI is transforming banking application development]]></title>
<description><![CDATA[Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprise...]]></description>
<link>https://tsecurity.de/de/3710146/it-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710146/it-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprises that need speed, traceability, resilience and regulatory confidence at the same time. Hyperautomation brings a broader discipline to this challenge. It combines workflow orchestration, intelligent document processing, robotic automation, API-led integration, process mining, test automation, observability and artificial intelligence into a connected delivery fabric. With embedded Generative AI, this fabric becomes more adaptive because applications can interpret natural language, summarize complex data, generate explanations, detect exceptions and support decision workflows rather than merely execute predefined rules.</p>



<p class="wp-block-paragraph">In banking, this shift is especially meaningful. Banks operate across dense application landscapes: trade reporting platforms, wealth management portals, core banking systems, investment banking applications, digital compliance engines, reconciliation utilities, operational dashboards, audit repositories and daily, weekly and monthly reporting platforms. Each of these areas has its own data models, control points, integration patterns, validation rules, exception paths and regulatory obligations. Hyperautomation does not replace engineering discipline; it strengthens it by making business intent, technical execution, control evidence and continuous improvement part of the same lifecycle.</p>



<h2 class="wp-block-heading">From automation to hyperautomation in banking applications</h2>



<p class="wp-block-paragraph">Automation usually addresses a specific task: moving data from one system to another, generating a report, running a batch job or validating a transaction against a rule. Hyperautomation goes further. It looks at the complete business outcome and asks how the entire chain can be streamlined, governed, observed and improved. For example, a trade reporting process may begin with transaction capture, enrich the trade with reference data, validate regulatory fields, identify breaks, generate a submission file, transmit it to a regulator or trade repository, monitor acknowledgements and preserve audit evidence. A narrow automation script may accelerate one step, but a <a href="https://www.gartner.com/en/documents/6454507">hyperautomated design</a> coordinates the complete flow, including exception handling and evidence generation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/figure-Figure-automation-vs-hyperautomation.png?w=1024" alt="Figure: Automation vs. hyperautomation." class="wp-image-4206308" width="1024" height="775" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p class="wp-block-paragraph"><strong>Figure: Automation vs. hyperautomation</strong></p>



<p class="wp-block-paragraph">Embedded Generative AI adds a <a href="https://assets.ctfassets.net/5965pury2lcm/65QHMnfLGaRJzJ0sX5982o/520b5f0a9745aecc8730c645994e3a3b/Forrester_Study_-_AI_And_The_Next_Generation_of_Software_Testing.pdf">new layer of intelligence</a>. Instead of forcing every user interaction into rigid screens and codes, business applications can accept natural language prompts, interpret document content, summarize cases, generate draft responses, explain anomalies, produce test scenarios and create release notes. In a banking environment, this intelligence must be carefully bounded. Every AI-assisted action should be traceable, explainable, reviewable and aligned with data privacy, model risk, information security and regulatory expectations. The goal is not uncontrolled autonomy; the goal is governed acceleration.</p>



<h2 class="wp-block-heading">Banking application components suitable for hyperautomation</h2>



<p class="wp-block-paragraph">A modern banking application is rarely a single monolithic system. It is a composition of business capabilities, integration services, workflow engines, data pipelines, user experience layers, analytics models, control dashboards and audit stores. Hyperautomation can accelerate the development and integration of these components by turning repetitive engineering work into <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">reusable patterns</a> and by embedding intelligence directly into business processes.</p>



<ul class="wp-block-list">
<li><strong>Trade reporting applications:</strong> Generative AI can help map trade attributes to regulatory fields, explain validation failures, summarize rejected submissions and generate test cases for reporting scenarios. Hyperautomation can orchestrate enrichment, validation, submission, acknowledgement tracking and evidence archival.</li>



<li><strong>Wealth management platforms:</strong> Advisors can use embedded AI to summarize client portfolios, generate suitability narratives, identify missing documents and prepare personalized investment review notes. Automation can coordinate onboarding, risk profiling, document verification, portfolio rebalancing workflows and client communication approvals.</li>



<li><strong>Core banking applications:</strong> Account opening, loan servicing, deposits, payments, interest calculations and customer maintenance can benefit from automated validations, intelligent forms, workflow routing and natural language assistance for operations teams. AI can explain account events or transaction exceptions in plain language.</li>



<li><strong>Investment banking systems:</strong> Deal pipelines, research workflows, underwriting processes, trade lifecycle functions and risk calculations require strong coordination across front-office, middle-office and back-office platforms. Hyperautomation can standardize approvals, documentation, exception resolution and control evidence across these stages.</li>



<li><strong>Digital compliance applications:</strong> Compliance teams can use AI to summarize policy obligations, compare regulatory changes with internal controls, classify alerts, draft investigation notes and produce evidence packs. Automation ensures routing, approvals, segregation of duties, audit trails and regulatory reporting timelines are consistently enforced.</li>



<li><strong>Reconciliation platforms:</strong> AI can assist in matching narratives, explaining breaks, clustering exception patterns and suggesting resolution actions. Hyperautomation can pull data from ledgers, statements, payment processors, trading systems and data warehouses, then route unresolved breaks to the right teams.</li>



<li><strong>Reporting and audit applications:</strong> Daily, weekly and monthly reports can be generated through controlled data pipelines, automated quality checks, narrative generation, variance explanations and approval workflows. Audit applications can preserve lineage, approvals, source extracts, model outputs and control attestations.</li>
</ul>



<h2 class="wp-block-heading">Embedded generative AI as an application capability</h2>



<p class="wp-block-paragraph">Embedding Generative AI into business applications should be treated as an architectural capability, not as a decorative chatbot. A banking application may use AI for search, summarization, reasoning support, content generation, code generation, policy interpretation or anomaly explanation. Each use case requires clear boundaries. The application must know which data the model can access, which actions require approval, what evidence must be captured and where deterministic controls must override probabilistic <a href="https://www.idc.com/resource-center/generative-ai/">suggestions</a>.</p>



<p class="wp-block-paragraph">For example, in trade reporting, an embedded AI assistant can explain why a transaction failed validation and suggest likely fields to review. However, the final correction should pass through rule-based validations, maker-checker approval and audit logging. In wealth management, AI may draft a client review note based on portfolio movements and risk profile, but the advisor must verify suitability, disclosures and final communication. In reconciliation, AI can propose likely matches or categorize break reasons, while the system preserves the original data, confidence score, reviewer action and final resolution path.</p>



<h2 class="wp-block-heading">Hyperautomating the product development lifecycle</h2>



<p class="wp-block-paragraph">The Product Development Lifecycle can itself become hyperautomated. Instead of treating ideation, analysis, design, development, testing, security review, release and operations as disconnected phases, enterprises can create an AI-assisted delivery loop where every stage produces structured artifacts that the next stage can consume. Platforms such as GitHub Copilot, Claude Code or Claude Cowork-style agentic development environments and OpenAI Codex can support this movement by helping teams reason over requirements, generate code, create tests, review changes, modernize legacy modules and produce <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">documentation</a>. Their value increases when they are connected to repositories, issue trackers, design documents, build pipelines, test suites, security scanners, observability data and enterprise knowledge bases.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>PDLC Stage</strong></td><td><strong>Hyperautomation Opportunity</strong></td><td><strong>AI-Assisted Outcome</strong></td></tr><tr><td>Business discovery</td><td>Process mining, domain interviews, regulatory mapping, backlog creation</td><td>Structured epics, user stories, acceptance criteria, process maps and control requirements</td></tr><tr><td>Architecture and design</td><td>Reference architectures, API contracts, data models, event flows, security patterns</td><td>Architecture options, integration blueprints, threat-model prompts and design decision records</td></tr><tr><td>Development</td><td>Code generation, service scaffolding, UI component creation, data pipeline templates</td><td>Review-ready code increments, reusable components, migration utilities and integration adapters</td></tr><tr><td>Testing</td><td>Unit, integration, regression, performance, compliance and synthetic data testing</td><td>Generated test cases, defect reproduction steps, test automation scripts and coverage summaries</td></tr><tr><td>Security and compliance review</td><td>Static analysis, dependency checks, policy validation, evidence capture</td><td>Risk explanations, remediation suggestions, control traceability and approval evidence</td></tr><tr><td>Release and deployment</td><td>CI/CD orchestration, environment promotion, release notes, rollback preparation</td><td>Automated deployment packs, release summaries, operational checklists and change records</td></tr><tr><td>Operations and feedback</td><td>Observability, incident analysis, user feedback mining, backlog refinement</td><td>Incident summaries, root-cause hypotheses, improvement stories and reliability recommendations</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Role of GitHub Copilot, Claude Cowork and Codex</h2>



<p class="wp-block-paragraph">GitHub Copilot is useful where developers need assistance inside the engineering flow: explaining code, generating functions, proposing tests, reviewing pull requests and helping teams move from issue to implementation. In a banking PDLC, it can accelerate microservice creation, API integration, batch processing logic, reconciliation rules, regulatory validation routines and UI workflows. When used with repository context and proper review discipline, it can reduce the time developers spend on repetitive coding while preserving human accountability for design and correctness.</p>



<p class="wp-block-paragraph">Claude Cowork or Claude Code-style agentic environments are valuable for multi-file reasoning, refactoring, debugging and documentation-heavy engineering work. Banking applications often contain deep domain logic scattered across services, configuration files, stored procedures, integration scripts and test suites. An agentic coding assistant that can understand a wider codebase context can help engineers analyze dependencies, prepare modernization plans, update multiple files coherently and draft explanations for reviewers. This is particularly useful in core banking modernization, trade reporting rule updates and compliance workflow refactoring.</p>



<p class="wp-block-paragraph">OpenAI Codex can support issue-to-pull-request workflows, test generation, code review, bug reproduction, migration activities and broader software engineering tasks across the lifecycle. In a hyperautomated PDLC, Codex-like agents can be assigned well-scoped work items, asked to inspect failing tests, propose fixes, create regression coverage and summarize the change for human reviewers. The important design principle is to keep agents inside controlled boundaries: clear prompts, repository permissions, test gates, approval workflows and traceable outputs.</p>



<h2 class="wp-block-heading">Integration architecture for hyperautomated banking applications</h2>



<p class="wp-block-paragraph">A practical architecture begins with business capability decomposition. Each banking domain should be expressed as a set of bounded capabilities such as customer onboarding, account maintenance, trade enrichment, exception management, portfolio review, control attestation, report generation and audit retrieval. These capabilities should be exposed through APIs, events, workflow tasks, data products and user interfaces. Hyperautomation then connects these capabilities using orchestration engines, event streams, rules engines, AI services, RPA connectors where legacy integration is unavoidable and observability layers that capture business and technical telemetry.</p>



<p class="wp-block-paragraph">The embedded AI layer should sit behind a secure application service boundary. It should use retrieval-augmented generation where approved policies, product rules, application documentation and regulatory mappings are retrieved from trusted sources. It should avoid uncontrolled exposure of sensitive customer information. Prompt templates, response validation, redaction, grounding checks, model monitoring and human-in-the-loop approval should be part of the production design. In banking, the most successful AI pattern is often not full automation but <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">assisted</a> decisioning with strong controls.</p>



<h2 class="wp-block-heading">Example: Hyperautomated reconciliation and reporting flow</h2>



<p class="wp-block-paragraph">Consider a reconciliation application that compares ledger balances, payment files, trade settlement records and external statements. In a conventional model, operations teams spend significant time downloading files, running macros, investigating mismatches, documenting break reasons and preparing status reports. In a hyperautomated model, data ingestion is scheduled and monitored, schema checks run automatically, matching engines classify obvious matches, AI assists with ambiguous narratives, exceptions are routed through workflow queues and dashboards update in near real time. At the end of the day, the system can generate a draft operations <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">report</a> explaining unresolved breaks, aging trends, risk exposure and pending approvals.</p>



<p class="wp-block-paragraph">The same pattern can extend to daily, weekly and monthly reporting. Data quality rules validate inputs, report templates are populated automatically, AI generates narrative commentary on variances, reviewers approve or amend explanations and the final report is archived with lineage and approvals. Audit teams can later retrieve not only the report but also the source extracts, transformation logs, exception history, reviewer decisions and AI-generated drafts. This creates a richer control environment than manual reporting because evidence is captured by design rather than reconstructed later.</p>



<h2 class="wp-block-heading">Governance, risk and control considerations</h2>



<p class="wp-block-paragraph">Hyperautomation in banking must be designed with governance from the beginning. The development team should define which activities can be automated, which can be AI-assisted and which must remain under human approval. Source code generated by AI must pass normal engineering controls, including peer review, static analysis, dependency scanning, secure coding checks, test execution and production readiness review. Business outputs generated by AI, such as compliance narratives or client-facing explanations, should be <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">reviewed</a> where regulatory or reputational risk is material.</p>



<p class="wp-block-paragraph">Data governance is equally important. AI-enabled applications must respect data classification, residency, retention, masking and access policies. The model should not become an uncontrolled channel through which confidential customer, trading or employee information can leak. Every prompt, retrieved source, generated response, user action and final decision may need to be logged depending on the use case. For audit applications, this traceability is not optional; it is the foundation of trust.</p>



<h2 class="wp-block-heading">Operating model for AI-native PDLC</h2>



<p class="wp-block-paragraph">A hyperautomated PDLC requires changes in team behavior. Product owners should write requirements in a structured manner so that AI tools can generate better stories, acceptance criteria and test scenarios. Architects should maintain living decision records, reference patterns and integration standards that AI agents can use as context. Developers should learn prompt discipline, context packaging and review techniques. Test engineers should focus on coverage strategy, synthetic data, compliance scenarios and defect prevention rather than only manual execution. Operations teams should feed incident <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">learnings</a> back into the backlog so the system improves continuously.</p>



<p class="wp-block-paragraph">The role of human experts becomes more important, not less. AI can draft, generate, compare and suggest, but domain judgment remains essential. A trade reporting specialist understands regulatory nuance. A wealth advisor understands client suitability. A core banking architect understands transaction integrity. A compliance officer understands control interpretation. Hyperautomation works best when it amplifies these experts and removes repetitive friction around them.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Hyperautomation in business application development is not simply a faster way to write software. It is a new way to connect business intent, engineering execution, operational control and continuous learning. In banking, where applications must be reliable, explainable, secure and compliant, the combination of embedded Generative AI and disciplined automation can transform how applications are designed, built, integrated, tested, released and operated. Trade reporting, wealth management, core banking, investment banking, compliance, reconciliation, reporting and audit functions can all benefit when AI is embedded responsibly and automation is orchestrated across the complete lifecycle.</p>



<p class="wp-block-paragraph">Platforms such as GitHub Copilot, Claude Cowork or Claude Code and OpenAI Codex can play an important role in this transformation by accelerating analysis, development, testing, review, modernization and documentation. Their greatest value appears when enterprises treat them not as isolated productivity tools but as part of a governed, AI-native PDLC. The future of banking application development will belong to teams that can combine human expertise, reusable engineering patterns, intelligent automation and strong governance into one coherent delivery model.</p>



<p class="wp-block-paragraph"><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="noreferrer noopener"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="noreferrer noopener"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside the post-merger IT overhaul at Alaska Airlines]]></title>
<description><![CDATA[As an aviation industry veteran with over 30 years of experience, Alaska Airlines CIO Charu Jain is all too familiar with the technology integration process that often follows a big airline merger.



By her count, she’s been involved in four such projects. But none, she says, has brought her gre...]]></description>
<link>https://tsecurity.de/de/3710147/it-nachrichten/inside-the-post-merger-it-overhaul-at-alaska-airlines/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710147/it-nachrichten/inside-the-post-merger-it-overhaul-at-alaska-airlines/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As an aviation industry veteran with over 30 years of experience, Alaska Airlines CIO Charu Jain is all too familiar with the technology integration process that often follows a big airline merger.</p>



<p class="wp-block-paragraph">By her count, she’s been involved in four such projects. But none, she says, has brought her greater satisfaction than leading the overhaul of Alaska’s PSS following its $1.9 billion acquisition of Hawaiian Airlines in September 2024.</p>



<p class="wp-block-paragraph">“This is one of the biggest milestones in any merger work done between airlines,” says Jain, speaking from her company’s Seattle offices just two months after Alaska and Hawaiian <a href="https://news.alaskaair.com/company/alaska-airlines-hawaiian-airlines-transition-to-shared-passenger-service-system-to-deliver-a-more-seamless-guest-experience/">completed their transition</a> to a shared PSS.</p>



<p class="wp-block-paragraph">In its simplest terms, a PSS is an all-encompassing software suite used by airlines to record and manage a passenger’s journey, from booking tickets and checking in baggage at the airport, to boarding the aircraft and accessing the in-flight menu. “A PSS touches almost every function of an airline from employees to guests,” says Jain.</p>



<h2 class="wp-block-heading">Two brands, one system</h2>



<p class="wp-block-paragraph">At the time of the merger, Alaska and Hawaiian each had its own PSS. No sooner had the ink dried on the deal than the cutover project got underway to bring both airlines’ systems under a single operating platform.</p>



<p class="wp-block-paragraph">According to Jain, the two airlines agreed from the get-go that they’d retain their own unique historic brands, both with a combined history of close to 200 years, which would be reflected through the system.</p>



<p class="wp-block-paragraph">“It had never been done before, developing capabilities to enable two brands on one platform,” adds Jain, who also serves as Alaska’s SVP of merchandising and innovation. “We didn’t want a situation where a passenger travelling from Spokane to Seattle on an Alaska-branded flight, and then onto Honolulu on a Hawaiian-branded flight, would have to navigate two separate systems. So we thought about how to make that experience more seamless.”</p>



<p class="wp-block-paragraph">After settling on a PSS, developed by travel software manufacturer Sabre, Jain and her colleagues began work on migrating the airlines’ millions of bookings and passenger information, while also updating their various guest- and employee-facing tools for the new system.</p>



<h2 class="wp-block-heading">Selling cutovers and mock flights</h2>



<p class="wp-block-paragraph">Executing a system cutover on such a large scale is a delicate balancing act, not least in a live-environment where, for a major airline, any form of disruption to the passenger experience can be bad for business. So there was no attempt to rush the project.</p>



<p class="wp-block-paragraph">“To make sure we didn’t have any issues with customers’ bookings, we really took a risk-optimized approach with a phased deployment and a phased cutover,” says Jain.</p>



<p class="wp-block-paragraph">Much of this hinged on what Alaska refers to as a selling cutover. Starting in October last year, all new bookings were made on the new PSS, which allowed the group to drain old bookings from the legacy system, and start selling tickets six months in advance of the official transition date; the average booking curve for an airline is around six months.</p>



<p class="wp-block-paragraph">“There was no migration of millions of records and bookings,” says Jain. “This meant when our customers checked in on the first day [of the PSS], it was as if the booking had been made on the native system.”</p>



<p class="wp-block-paragraph">While this was going on, however, Alaska was hit by a sizeable IT outage that grounded flights across the country and impacted the travel plans of nearly 50,000 passengers. It followed a previous IT outage in July. However, Jain says the disruptions didn’t impact the project in any way.</p>



<p class="wp-block-paragraph">So in the final months leading up to the cutover completion, Alaska carried out several dress rehearsals to test the system, including mock flights for domestic and international routes in anticipation of the recent launch of <a href="https://news.alaskaair.com/destinations/alaska-airlines-advances-global-expansion-with-launch-of-new-european-routes-and-landmark-lounge-investment/">several non-stop services to Europe</a>.</p>



<p class="wp-block-paragraph">This involved real guests arriving at the airport, completing check-in, going through security, and taking their seats as if they were about to take off. Leaving no stone unturned, the simulation also accounted for baggage collection, pets, wheelchair users, and onboard hospitality, stopping just short of passengers being served actual food.</p>



<p class="wp-block-paragraph">Alaksa completed five such mock rehearsals in all. “The fifth one was when everything worked without any medium or high issues, and gave us the confidence we were ready,” says Jain.</p>



<p class="wp-block-paragraph">As part of the airline’s scenario planning, it also set up command centers in various locations, including Honolulu and Seattle, to plan for unforeseen and unrelated problems on the day of the cutover.</p>



<h2 class="wp-block-heading">A dedication to collaboration</h2>



<p class="wp-block-paragraph">A project is only ever as a good as its people, and Jain is quick to hail the collaborative spirit that Alaska and Hawaiian brought to the table. As a PSS involves both the operational side of an airline’s business — touching on everyone from pilots, flight attendants, and baggage handlers — and commercial departments responsible for policies and pricing, this was more than a purely technological undertaking.</p>



<p class="wp-block-paragraph">“This was about people coming together from two companies to make this one big thing happen,” says Jain.</p>



<p class="wp-block-paragraph">When Alaska started making bookings on the new PSS last fall as part of the selling cutover, it also began training employees how to use system. It was around that time as well, says Jain, that the airline was confident the transition would be completed by April 2026, just in time for the busy summer travel season.</p>



<p class="wp-block-paragraph">Since the PSS has been up and running, the company has also introduced a single mobile app to replace Alaska and Hawaiian’s separate existing ones, allowing passengers to personalize their experience to the airline brand they’re more familiar with.</p>



<p class="wp-block-paragraph">“It’s a much more seamless experience now that there’s no confusion knowing which app to go on, or why they have two booking numbers,” says Jain. Alaska’s employees are also just as happy with their new tools, she adds.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your AI hiring tool isn’t an HR problem. It’s a security one]]></title>
<description><![CDATA[For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candid...]]></description>
<link>https://tsecurity.de/de/3710148/it-nachrichten/your-ai-hiring-tool-isnt-an-hr-problem-its-a-security-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710148/it-nachrichten/your-ai-hiring-tool-isnt-an-hr-problem-its-a-security-one/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candidates, conducting interviews, ranking applicants and influencing who moves forward, the hiring platform stops being a passive system of record. It becomes a decision system.</p>



<p class="wp-block-paragraph">And any system that accepts public input, processes sensitive data and influences business decisions belongs inside the security conversation.</p>



<p class="wp-block-paragraph">I learned this during an AI hiring platform rollout that never made it to production. The vendor was established, the product had a strong market reputation and the AI feature looked attractive: Upload a resume, compare it to a job description and return a neat percentage match. For recruiters, it promised speed. For executives, it promised modernization.</p>



<p class="wp-block-paragraph">Before moving real candidate data into the system, I tested it with synthetic resumes. One weak resume came back with a surprisingly strong match. The reason was not hidden in the candidate’s experience. It was hidden in the text. The resume contained language instructing the AI to treat the candidate as an excellent fit, and the system appeared to follow that instruction instead of evaluating the resume on merit.</p>



<p class="wp-block-paragraph">That changed the question from “Does the tool improve productivity?” to “Can the person being evaluated influence the evaluation itself?”</p>



<p class="wp-block-paragraph">That is a security question.</p>



<h2 class="wp-block-heading">The trust boundary has moved</h2>



<p class="wp-block-paragraph">CIOs do not need to become recruiting experts. They only need to look at the mechanics.</p>



<p class="wp-block-paragraph">An anonymous user submits content into an enterprise system. That content is processed by software. The software then produces an output that can influence a business decision. In every other environment, security teams know what to call that: untrusted input crossing a trust boundary.</p>



<p class="wp-block-paragraph">The difference is that in hiring, the input looks harmless. It is a resume, a cover letter, a chatbot reply or a spoken answer in an AI-led interview. But once AI reads that content and treats it as instruction, the harmless-looking input becomes part of the system’s control surface.</p>



<p class="wp-block-paragraph">That is why prompt injection matters in hiring. It is not just an AI oddity or a model behavior issue. It is the same category of failure enterprises have spent decades trying to prevent: User-controlled input changing what the system does. <a href="https://genai.owasp.org/llmrisk/llm01-prompt-injection/">OWASP lists prompt injection as the first risk in its Top 10 for LLM applications</a>, describing it as a case where user prompts alter a model’s behavior or output in unintended ways.</p>



<p class="wp-block-paragraph">In hiring, the implication is direct: A candidate may be able to manipulate the score, ranking or interview assessment that determines whether a human ever sees them.</p>



<h2 class="wp-block-heading">The business impact is not theoretical</h2>



<p class="wp-block-paragraph">The obvious risk is that an unqualified candidate moves forward. But the impact is broader.</p>



<p class="wp-block-paragraph">First, decision quality degrades. Hiring teams adopt AI scoring because they believe it improves signal. If the score can be manipulated, the business is not gaining signal; it is gaining false confidence. Recruiters may spend time on candidates who gamed the system while stronger candidates are buried lower in the queue. A tool bought to reduce friction can quietly create more of it.</p>



<p class="wp-block-paragraph">Second, cost increases under the appearance of efficiency. Every false positive consumes recruiter time, hiring-manager attention, interview slots and opportunity cost. A small weakness in screening integrity can become a measurable operational drag across open roles.</p>



<p class="wp-block-paragraph">Third, trust suffers. Candidates already question whether AI hiring tools are fair, explainable or accurate. If it becomes clear that a screening system can be manipulated by hidden instructions or verbal prompting, the issue is no longer just security. It becomes reputational. Strong candidates may lose confidence in the process, and employers may have to defend decisions made by systems they did not fully understand.</p>



<p class="wp-block-paragraph">Fourth, sensitive data exposure becomes harder to contain. Recruiting systems hold names, addresses, work histories, education histories, compensation details, work authorization information and sometimes accommodation or demographic data. <a href="https://csrc.nist.gov/pubs/sp/800/122/final">NIST guidance on personally identifiable information</a> includes employment information as linkable personal data that must be protected from inappropriate access, use and disclosure. Yet hiring platforms often receive less security scrutiny than systems holding customer or financial data.</p>



<p class="wp-block-paragraph">That mismatch is dangerous: High-value data, public-facing workflows and increasing automation.</p>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html">The 2025 McHire incident</a> should have made this impossible to ignore. Researchers reported that weaknesses in McDonald’s AI hiring platform, including default credentials and an access-control flaw, exposed applicant data at large scale before the issue was patched. The lesson for CIOs is not merely that a weak password was used. The lesson is that AI hiring systems can ship with basic, preventable security failures while still being treated as HR tools rather than enterprise risk surfaces.</p>



<h2 class="wp-block-heading">Vendor reputation does not transfer to every AI feature</h2>



<p class="wp-block-paragraph">One reason this risk slips through is that buyers often trust the platform brand. Mature vendors may have strong security programs, enterprise customers, compliance documentation and procurement-friendly answers.</p>



<p class="wp-block-paragraph">But AI features can change the architecture of risk.</p>



<p class="wp-block-paragraph">A platform that was safe as a workflow tool may behave very differently once it adds resume scoring, interview grading, chatbot screening or automated ranking. The new feature may introduce new inputs, new model behavior, new data flows, new third-party dependencies and new decision points. In practical terms, the attack surface has changed.</p>



<p class="wp-block-paragraph">CIOs should not allow AI features to inherit trust automatically from the legacy platform around them. When a vendor adds AI, the enterprise should reassess the feature as if it were a new product. That does not mean slowing innovation for bureaucracy. It means AI-enabled decision-making carries different failure modes from ordinary workflow automation.</p>



<h2 class="wp-block-heading">The ownership gap is the real vulnerability</h2>



<p class="wp-block-paragraph">The biggest risk may not be the model. It may be the ownership gap.</p>



<p class="wp-block-paragraph">Talent acquisition may buy the tool. HR operations may configure it. The vendor may guide implementation. Procurement and legal may approve the contract. But who owns the security of the candidate-facing AI layer?</p>



<p class="wp-block-paragraph">In many organizations, the honest answer is unclear.</p>



<p class="wp-block-paragraph">That ambiguity is where risk grows. Recruiting technology sits at the intersection of public input, sensitive data, third-party software, automated decision support and brand trust. That is exactly the kind of environment that needs named security ownership, asset inventory, vendor review, access-control testing, logging and incident-response planning.</p>



<p class="wp-block-paragraph">If the hiring stack is not in the security inventory, the organization is already making an assumption it may later regret.</p>



<h2 class="wp-block-heading">What CIOs should require now</h2>



<p class="wp-block-paragraph">The fix is not exotic. It is applying existing security discipline to a surface that has been underestimated.</p>



<p class="wp-block-paragraph">Treat every candidate submission as untrusted input. Resumes, cover letters, chatbot responses, interview transcripts and spoken answers should be handled as attacker-controllable content. If AI processes it, the system must separate content from instruction.</p>



<p class="wp-block-paragraph">Reassess vendors when AI features are introduced. A prior security review should not be treated as permanent approval for new AI capabilities. Ask what changed in the architecture, what data the model sees, what actions it can influence and how manipulation attempts are detected.</p>



<p class="wp-block-paragraph">Ask AI-specific questions before signing. Can candidate-provided content alter scoring? Are hidden instructions filtered or ignored? Is there human review before AI output influences a decision? Can the vendor produce testing evidence for prompt injection, access control and data exposure risks?</p>



<p class="wp-block-paragraph">Assign ownership. HR can own the process, but security must own the risk model. AI hiring systems should be included in third-party risk management, application security reviews, access governance, monitoring and incident response planning.</p>



<p class="wp-block-paragraph">Measure business impact, not just AI adoption. The goal is not to say the recruiting function uses AI. The goal is to improve hiring speed, quality, fairness and cost without creating new risk. If the system cannot protect decision integrity, the business case is weaker than it appears.</p>



<h2 class="wp-block-heading">The hiring platform is now part of the enterprise attack surface</h2>



<p class="wp-block-paragraph">AI has turned the careers page into more than a front door for applicants. It is now a public input channel feeding systems that store sensitive data and influence workforce decisions.</p>



<p class="wp-block-paragraph">That makes it a CIO concern.</p>



<p class="wp-block-paragraph">The next failure in AI hiring may not look like a traditional breach at first. It may look like bad rankings, manipulated scores, unexplainable decisions, wasted recruiter time or a candidate process no one trusts. But underneath those symptoms is a familiar security problem: A system trusted input it should have treated as hostile.</p>



<p class="wp-block-paragraph">Enterprises have hardened payment systems, customer portals, APIs and employee applications around that lesson. Hiring deserves the same treatment.</p>



<p class="wp-block-paragraph">AI hiring is not just an HR transformation. It is a security boundary. And it is time CIOs treated it like one.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI is changing the business analyst role for the better]]></title>
<description><![CDATA[AI’s impact has been felt across nearly every industry, and its rise has already started to alter several roles in tech, including that of the business analyst. While the rise of agentic AI may have some questioning whether AI will replace business analyst jobs entirely, as we’ve seen with most r...]]></description>
<link>https://tsecurity.de/de/3710149/it-nachrichten/how-ai-is-changing-the-business-analyst-role-for-the-better/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710149/it-nachrichten/how-ai-is-changing-the-business-analyst-role-for-the-better/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI’s impact has been felt across nearly every industry, and its rise has already started to alter several roles in tech, including that of the <a href="https://www.cio.com/article/276798/what-is-a-business-analyst-a-key-role-for-business-it-efficiencywhat-is-a-business-analyst-a-key-role-for-business-it-efficiency.html">business analyst</a>. While the rise of agentic AI may have some questioning whether AI will replace business analyst jobs entirely, as we’ve seen with most roles impacted by AI, it’s more likely that AI will augment the role and fundamentally change how BA’s conduct daily business.</p>



<p class="wp-block-paragraph">“As AI takes on more routine tasks, the human side of the role is becoming even more valuable. It’s becoming more of a hybrid role, where employers are often looking for candidates who can combine technical fluency with strong communication and problem-solving skills, along with sound business judgment,” says Megan Slabinski, district president of technology talent solutions at Robert Half.</p>



<p class="wp-block-paragraph">AI can save business analysts time in the long run, automating many of the tasks that are time consuming and repetitive around data processing, note taking, and documentation. While automation will impact the daily tasks of the role, business analysts will still be necessary for properly interpreting outputs, collaborating across teams, and maintaining compliance and AI workflows.</p>



<h2 class="wp-block-heading">AI-driven analysis and automated workflows</h2>



<p class="wp-block-paragraph">With AI-driven analysis, BA’s can use machine learning models for pattern detection, determining risk, and for forecasting demand, while natural language processing (NLP) can be used for text-heavy inputs. AI tools can also assist analysts with decision-making by transcribing meetings and automatically identifying any necessary business requirements, constraints, risks, or dependencies that will impact the project.</p>



<p class="wp-block-paragraph">As a result, the role is undergoing a shift toward spending less time on monotonous, routine tasks, and instead “spending more time connecting the dots and providing strategic context earlier in the process,” says Slabinksi.</p>



<p class="wp-block-paragraph">“We’re seeing that business analysts today aren’t spending as much time as they were a few years ago on some manual processes. AI is speeding up tasks like documenting requirements, summarizing stakeholder meetings, generating first drafts of user stories, and even helping create SQL queries or reports,” she adds.</p>



<p class="wp-block-paragraph">AI can also assist business analysts with interviews and workshops for the discovery phase of a project and autonomously identify patterns in the data that might be overlooked or missed by the human eye. These tools can also enable BAs to create living models that can be adjusted and altered with feedback, as opposed to traditional static documents, and allow for an automated review process for data validation. In terms of maintenance and change management, AI can help with predictive recommendations to get ahead of risks, compliance, and future process updates.</p>



<p class="wp-block-paragraph">That said, an increased reliance on AI tools while require business analysts to validate AI outputs and assure AI-generated content is accurate, relevant, and ultimately aligned with the overall business strategy. Still responsible for explaining the reasons behind business decisions, business analysts will also need to identifying bias and fairness concerns associated with AI use, and ensure decisions aren’t over-automated.</p>



<p class="wp-block-paragraph">Ultimately, BA’s will see their responsibilities shift to focusing more on data interpretation, governance, and strategy, and identifying the most practical use cases for enterprise AI adoption.</p>



<h2 class="wp-block-heading">New skills to focus on</h2>



<p class="wp-block-paragraph">Traditionally, business analysts are responsible for gathering the data as well as processing it for analysis. This comes with a lot of drudgery that can be eased by implementing AI tools into the workflow. Tasks such as routine documentation, formatting, and data crunching can be automated, while analysts provide the human context around that data, as well as a critical eye to the final output.</p>



<p class="wp-block-paragraph">“Business analysts are often in the mix to make sure that data is accurate and that the requirements are in line with expected outcomes. They can also help ensure AI projects include the appropriate level of human oversight, comply with internal policies and industry regulations, and use data responsibly. While they aren’t solely responsible for AI governance, they often play an important role in raising questions about data sources, bias, whether the outputs make sense, and potential business risks early in a project,” says Slabinski.</p>



<p class="wp-block-paragraph">BAs will need to develop AI literacy skills to better understand how models are trained and designed as well as data reasoning skills to interpret and validate AI outputs. Prompt-framing skills will also become valuable as analysts will need to know how to properly structure inputs for quality outputs. There will also be a growing emphasis on ethical analysis to identify compliance, bias, and overall fairness of algorithms, and qualified candidates will require strong change management skills to help oversee the adoption of AI-driven workflows.</p>



<p class="wp-block-paragraph">“The skills becoming more important are the ones that help BAs evaluate AI-generated information and translate it into business recommendations. AI literacy is becoming a baseline expectation, and that includes knowing things like how to query the data and support requirements gathering. Critical thinking, communication, and business acumen are all part of that skill set because employers still need people who can explain what the findings mean and why they matter,” says Slabinski.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Airtable joins Evernote, Brightcove, WeTransfer and AOL in Bending Spoons portfolio]]></title>
<description><![CDATA[Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo



Airtable made its name as a builder of low/no code database services, aimed particularly at non-technical staff, but is now one of many vendors facing...]]></description>
<link>https://tsecurity.de/de/3710151/it-nachrichten/airtable-joins-evernote-brightcove-wetransfer-and-aol-in-bending-spoons-portfolio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710151/it-nachrichten/airtable-joins-evernote-brightcove-wetransfer-and-aol-in-bending-spoons-portfolio/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo</p>



<p class="wp-block-paragraph">Airtable made its name as a builder of <a href="https://www.infoworld.com/article/2334351/airtable-review-flexible-low-code-no-code-in-the-cloud.html">low/no code database services</a>, aimed particularly at non-technical staff, but is now one of many vendors facing financial difficulties in the face of the <a href="https://www.cio.com/article/4192242/agentic-ai-puts-234b-in-enterprise-saas-spending-at-risk-gartner-says.html">SaaS/AIpocalypse</a>. The arrival of AI coding tools, which offer non-technical employees more flexible ways to build business applications, has hit demand for its services.</p>



<p class="wp-block-paragraph">Bending Spoons bought Airtable in a deal it valued at just <a href="https://investors.bendingspoons.com/newsroom/bending-spoons-agrees-to-acquire-airtable">$1.285 billion</a>, a far cry from the <a href="https://www.bloomberg.com/news/articles/2026-08-04/bending-spoons-to-buy-software-firm-airtable-for-2-3-billion" target="_blank" rel="noreferrer noopener">$11.7 billion</a> Airtable was worth at its peak.</p>



<p class="wp-block-paragraph">Bending Spoons has built its portfolio by buying once-successful companies like Airtable that have struggled to cope with newer, nimbler competitors or failed to adapt to emerging technologies. <a href="https://www.forbes.com/sites/shivaramrajgopal/2026/07/06/bending-spoons-paid-33-billion-for-aol-vimeo-and-eventbrite-its-pro-forma-2025-profit-was-just-22-million/" target="_blank" rel="noreferrer noopener">Bending Spoons takes these companies, cuts costs and markets them aggressively</a> with the goal of returning them to profitability.</p>



<p class="wp-block-paragraph">“Airtable is a pioneering brand reshaping how teams organize data and manage critical workflows. We’re committed to investing in Airtable for the long run, and doubling down on its core strength: bringing teams and workflows together in one flexible workspace. We plan to expand what can be done across the full spectrum of work and make Airtable even more valuable to customers at every scale,” said Luca Ferrari, Bending Spoons CEO and co-founder.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4206772/airtable-joins-evernote-brightcove-wetransfer-and-aol-in-bending-spoons-portfolio.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder]]></title>
<description><![CDATA[Investigation into whether staff improperly accessed Minnie Merriman’s file after she was named for the first time this week]]></description>
<link>https://tsecurity.de/de/3710124/it-nachrichten/scot-nhs-trust-probes-access-to-medical-records-of-9-year-old-girl-after-man-arrested-on-suspicion-of-murder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710124/it-nachrichten/scot-nhs-trust-probes-access-to-medical-records-of-9-year-old-girl-after-man-arrested-on-suspicion-of-murder/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:34 +0200</pubDate>
<content:encoded><![CDATA[Investigation into whether staff improperly accessed Minnie Merriman’s file after she was named for the first time this week]]></content:encoded>
</item>
<item>
<title><![CDATA[Stanford is running 37,000 AI agents as a virtual biotech — and one of its drug designs got independently confirmed by Merck]]></title>
<description><![CDATA[For developers, the operating assumption has been one engineer, one agent — the model Claude Code and similar tools. At VB Transform 2026, James Zou, associate professor of biomedical data science at Stanford University, argued that assumption is about to break: the next frontier isn't a single, ...]]></description>
<link>https://tsecurity.de/de/3710115/it-nachrichten/stanford-is-running-37000-ai-agents-as-a-virtual-biotech-and-one-of-its-drug-designs-got-independently-confirmed-by-merck/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710115/it-nachrichten/stanford-is-running-37000-ai-agents-as-a-virtual-biotech-and-one-of-its-drug-designs-got-independently-confirmed-by-merck/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:33 +0200</pubDate>
<content:encoded><![CDATA[<p>For developers, the operating assumption has been one engineer, one agent — the model Claude Code and similar tools. <a href="https://venturebeat.com/vbtransform2026">At VB Transform 2026</a>, James Zou, associate professor of biomedical data science at Stanford University, argued that assumption is about to break: the next frontier isn't a single, more capable agent, it's tens of thousands of them collaborating.</p><p>For developers and product builders, the most critical takeaway from Zou’s presentation is how these massive systems are orchestrated. His team's research offers a practical blueprint for connecting legacy databases to AI orchestration layers and designing environments that enable thousands of agents to collaborate.</p><div></div><h2>Emulating the organization — the virtual biotech</h2><p>Zou’s project began as a "Virtual Lab" consisting of five to eight agents structured to mirror his physical Stanford lab. The setup included an AI professor acting as the principal investigator and AI students with distinct specialties holding regular group meetings. </p><p>"We also created for the agents a replica of Stanford, an agent school, where the agents can actually go to the school and do supervised fine-tuning to improve their expertise in their specific domains," Zou noted.</p><p>The virtual lab successfully designed new nanobody proteins for recent COVID variants. </p><p>"What is really exciting to us is that these AI-designed nanobody proteins actually worked much better than the previous human-designed nanobodies in terms of binding to the recent different viruses," Zou said.</p><p>Following this wet-lab validation, the team expanded their ambition. They transitioned from emulating a single research team to modeling a massive corporate structure. </p><p>The resulting system, dubbed the <a href="https://www.biorxiv.org/content/10.64898/2026.02.23.707551v1">Virtual Biotech</a>, comprises tens of thousands of specialized AI agents overseen by a Chief Scientific Officer (CSO) agent. It operates through distinct corporate divisions, such as target discovery, molecule design, and clinical trials.</p><p>"Working with the CSO agent are different divisions that mirror the divisions found in a human biotech or pharma company," Zou explained — one focused on identifying drug targets, another on designing molecules, a third on safety and clinical trials. Individual agents specialize further within a division, he said. "Under the target discovery division, we'll have one agent that specializes in looking at all the genetics data, another agent that looks at all the genomics data and single-cell data, and so on."</p><h2>The multi-agent advantage</h2><p>As foundation models grow more capable, developers face a core architectural dilemma: Why distribute workloads across tens of thousands of specialized agents instead of channeling all computing resources into a single, omniscient model?</p><p>Zou's team ran a head-to-head comparison of a multi-agent team against a single agent tasked with the same scientific challenge. The multi-agent ecosystem created friction and interaction that produced better solutions that were more resilient against compounding errors.</p><p>"In these scientific virtual labs, the agents actually get into debates and disagreements. They have to convince the other AI scientists [of] their ideas, and all of that elicits much more creative and robust reasoning compared to if you have a single model trying to do the problem by itself from scratch," Zou said.</p><h2>The orchestration bottleneck</h2><p>When scaling to tens of thousands of agents, orchestration becomes the primary bottleneck. The system requires a unified context layer that allows agents to synthesize knowledge from various tools, datasets, and historical records.</p><p>Many enterprise teams attempt to solve data integration by wrapping existing databases with an MCP. However, legacy systems are not very friendly to agents. For instance, dropping a PDF of a research paper into an agent's context window is inefficient, and standard text models struggle to interpret complex figures and tables, leading to hallucinations. </p><p>"Even if you wrap an MCP around the existing databases and APIs, that doesn't solve the underlying problem: the interface and APIs are not suitable for agents," Zou said. He added that existing databases are designed to be consumed by humans or pre-AI algorithms.</p><p>To resolve this, Zou's team created <a href="https://github.com/GXL-ai/paperclip">Paperclip</a>. The platform relies on a core strength of modern LLMs: their ability to write code and navigate file systems. Instead of forcing agents to query brittle, database-specific APIs, Paperclip digitizes unstructured data and maps disparate databases into a unified, AI-native virtual file system.</p><p>This structure allows agents to access knowledge from millions of papers using standard file-system operations. </p><p>"This basically shows that we can get much better accuracy if you use Paperclip, and we can reduce the time and the cost by over an order of magnitude compared to if you use agents without these AI-native scientific infrastructures," Zou stated.</p><h2>Real-world validation</h2><p>To test the practical output of this architecture, Virtual Biotech spun up 37,000 "clinical trial agents" to synthesize fragmented trial data. These agents identified single-cell features that predict trial success — drug targets supported by these features were about 50% more likely to reach market than comparable drugs without them.</p><p>The system then autonomously designed an antibody-drug conjugate (ADC) targeting the CD276 protein for lung cancer. The agents completed this design autonomously, relying exclusively on data published prior to January 2025.</p><p>Several months later, Zou said, pharmaceutical company Merck independently developed and validated the same therapeutic design — which went on to receive breakthrough designation from the FDA. He characterized this as "a third-party external validation of the therapeutic design provided by the virtual biotech agents."</p><h2>Designing ecosystems, not workflows</h2><p>As multi-agent systems scale, leaders must rethink how they manage these digital workforces. Zou advocated for shifting from designing rigid workflows to creating open environments. Workflows dictate the exact steps an agent should take, similar to managing a junior employee. Environments provide the infrastructure, guardrails, and incentives for agents to collaborate on open-ended problems. </p><p>"In workflows, we're trying to tell agents what to do and how to do their job. But in environments, we're providing the infrastructures, the incentives, and the guardrails, but otherwise we leave it open to incentivize agents to collaborate," Zou said.</p><p>Optimization at scale means engineering the environment rather than fine-tuning individual models. While single agents can improve via reinforcement learning or supervised fine-tuning in the agent school, the success of a massive multi-agent system relies on adjusting the parameters governing their collaboration. </p><p>"At the multi-agent [side], we're not actually fine-tuning and changing the individual models anymore, but we're optimizing the environment," Zou explained. "The environment itself is the object that we optimize to improve the agents."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tencent's Team Memory shares AI agent memory across a team — with no governance yet for when it's wrong]]></title>
<description><![CDATA[A VB Pulse survey this June found that 57% of enterprises had traced a confidently wrong agent answer back to missing or inconsistent context — the latest sign of how central context has become to whether AI agents can be trusted to act on their own.Most of the fixes so far have solved a narrower...]]></description>
<link>https://tsecurity.de/de/3710116/it-nachrichten/tencents-team-memory-shares-ai-agent-memory-across-a-team-with-no-governance-yet-for-when-its-wrong/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710116/it-nachrichten/tencents-team-memory-shares-ai-agent-memory-across-a-team-with-no-governance-yet-for-when-its-wrong/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:33 +0200</pubDate>
<content:encoded><![CDATA[<p>A <a href="https://venturebeat.com/data/57-of-enterprises-have-watched-ai-agents-be-confidently-wrong-the-fix-is-an-agentic-context-layer-but-who-has-one">VB Pulse survey this June found that 57%</a> of enterprises had traced a confidently wrong agent answer back to missing or inconsistent context — the latest sign of how central context has become to whether AI agents can be trusted to act on their own.</p><p>Most of the fixes so far have solved a narrower version of that problem: one agent remembering more, in one session. What's been missing is a way for a team of agents to draw on the same context at once, and that gap is where a newer problem is surfacing. Once an agent's context is shared across a whole team, a wrong fact doesn't cost one person a repeated explanation. It costs the whole team.</p><p>Tencent's answer to that gap is<a href="https://github.com/TencentCloud/TencentDB-Agent-Memory"> Agent Memory</a>, an open-source project the team said grew out of six months spent fixing a narrower problem: agents losing context in long sessions. Part of that system is a persona layer, a stable, distilled picture of who a user is and how they work, built up over many conversations rather than reconstructed each time. On Tencent's own benchmark for whether an agent still applies that picture correctly after extended use, accuracy rose from 48% to 76%, a 59% relative improvement, once the persona layer was added. This week, Tencent extended that project with the beta launch of Team Memory, which opens the same approach up to a whole team instead of one agent. <!-- -->Tencent said <a href="https://x.com/tencentai_news/status/2085272380759581092">the repo hit No. 1 on GitHub's TypeScript trending list</a> this week.</p><p>Agents on a team can now read from a shared memory hub instead of keeping separate, siloed context, governed through an access control layer that determines who can read what.</p><h2>What Team Memory actually does</h2><p>The core idea is a shared hub rather than a shared prompt. Instead of pasting one large context block into every agent's window, Team Memory registers four kinds of reusable assets and equips each agent with only the ones it needs.</p><ul><li><p><b>Chat Memory.</b> Retains preferences, facts, decisions, and interaction history, distilled through four layers, from raw conversation up to a stable long-term persona, so an agent does not need to be reintroduced to a user it has already worked with.</p></li><li><p><b>Skill.</b> Captures procedures pulled from completed work, versioned and reviewed before they are shared rather than dropped into a folder as-is.</p></li><li><p><b>LLM-Wiki.</b> Turns documents and specs into structured, linked pages.</p></li><li><p><b>Code-Graph.</b> Indexes a codebase's symbols, files, and call relationships so an agent can check what a change might affect before making it.</p></li></ul><p>Tencent's<a href="https://github.com/TencentCloud/TencentDB-Agent-Memory"> documentation</a> draws the distinction directly: "RAG answers 'what can be found?' Team Memory also answers 'who can use it, which version is valid, and which Agent should receive it.'"

In practice, that's what Tencent calls an "Agent Loadout": a Scout agent doing research can be equipped with market research and competitive analysis assets, while a Builder agent gets the code graph and product docs it needs instead, rather than every agent getting access to everything.</p><p>Which assets an agent gets equipped with is governed through four visibility tiers:</p><ul><li><p><b>Private.</b> Readable only by the asset's owner.</p></li><li><p><b>Team.</b> Readable by anyone on the team.</p></li><li><p><b>Restricted.</b> Gated by user, role, or agent-level access control.</p></li><li><p><b>Agent.</b> Equipped to one specific agent within a team.</p></li></ul><p>New assets default to private, so sharing has to be a deliberate action rather than something that happens automatically.</p><h2>What happens when a memory is wrong</h2><p>That access model answers a real question, who is allowed to read a given memory asset. It does not answer a second one, which is what happens once a memory asset turns out to be wrong. Tencent's own documentation lays out ownership, versioning, and status tracking for each asset, but nothing in the documentation describes a correction or expiry process for a fact that's already been read and reused by other agents on a team, or a way to resolve it when two agents' memories of the same thing disagree.</p><p>That gap is what practitioners flagged within hours of the launch post.</p><p>"Shared memory makes the write path the interesting problem. Retrieval gets most of the attention, but a wrong fact written once now propagates to every teammate's agent instead of just yours. Curious how the governance layer handles correction and expiry,"<a href="https://x.com/BlakeMurphy/status/2085385624115138828"> Blake Murphy</a> wrote on X.</p><p>The concern wasn't only about fixing a bad fact after the fact. It was about the decision to leave something out of the record in the first place. "the governed part is the hard part. once teammates' agents can read each other's context, someone has to decide what never gets written down,"<a href="https://x.com/_virgil19/status/2085403856624922852"> Virgil Maro</a> wrote on X.</p><p>Others pushed further into what happens once two agents' memories actively contradict each other, not just go stale.</p><p>"The Code-Graph plus LLM-Wiki split is the right call. The part I'd want to see benchmarked: in shared mode, whose memory wins when two teammates' agents have written contradicting facts about the same module? Single-agent memory drifts slowly. Shared memory drifts fast, because one stale write propagates to people who never saw the session that produced it,"<a href="https://x.com/wgi_dev/status/2085382411613872341"> Austin Green</a> wrote on X.</p><p>The reaction wasn't uniformly critical. "Interesting shift: making memory a shared service turns agents into a real team rather than isolated bots. Governance will be the trickiest part, especially when facts conflict,"<a href="https://x.com/MoezZhioua/status/2085400880208126350"> Moez Zhioua</a> wrote on X.</p><p>None of these are edge cases specific to Tencent's implementation. A March 2026 paper on production multi-agent memory architecture,<a href="https://arxiv.org/html/2603.17787"> "Governed Memory: A Production Architecture for Multi-Agent Workflows,"</a> published independently of any single vendor, identifies governance fragmentation and silent quality degradation without feedback loops as structural risks in shared multi-agent memory generally. The pattern the paper describes matches what the commenters above pointed at directly: a wrong fact in a single-agent memory system costs one user a repeated correction, while the same wrong fact in a shared, team-wide memory system propagates to every agent that inherited it before anyone catches it.</p><h2>How Team Memory compares</h2><p>AI agent memory work in 2026 has mostly focused on a single agent remembering more, in one session, about one user:<a href="https://venturebeat.com/ai/enhancing-ai-agents-with-long-term-memory-insights-into-langmem-sdk-memobase-and-the-a-mem-framework"> LangChain's LangMem SDK</a>,<a href="https://venturebeat.com/orchestration/google-pm-open-sources-always-on-memory-agent-ditching-vector-databases-for"> Google's Always On Memory Agent</a>, and Anthropic's work inside the<a href="https://venturebeat.com/ai/anthropic-says-it-solved-the-long-running-ai-agent-problem-with-a-new-multi"> Claude Agent SDK</a> all work this way. A different line of work has focused on giving agents access to a shared model of business data. VB's own June survey found only 25% of enterprises had that kind of governed context layer in production, while vendors including<a href="https://venturebeat.com/data/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation"> AWS</a>, <a href="https://venturebeat.com/data/ai-agents-need-context-everywhere-they-run-even-where-the-cloud-cant-follow"> Couchbase, Oracle, Redis, and Pinecone</a> have all shipped versions of it this year.</p><p>Team Memory's closest existing comparison is likely Asana, which built<a href="https://venturebeat.com/orchestration/shared-memory-is-the-missing-layer-in-ai-orchestration"> shared memory across a company's AI teammates</a> so an agent doesn't need to be re-briefed on context another agent already has. Asana's CPO described the same tradeoff Tencent's practitioners are now raising,<a href="https://venturebeat.com/orchestration/asanas-ai-agents-share-memory-across-your-company-but-not-your-secrets"> an access control system built specifically to stop one agent's memory from leaking into a project another agent isn't cleared to see</a>. Tencent's version is open-source and portable across frameworks rather than scoped to one platform, but it's answering a question Asana's team already ran into while building a closed one.</p><p>For teams evaluating this category, the upside is real: agents stop relearning what the team already knows. The tradeoff is just as real: one bad write is no longer contained to one agent — it's inherited by every agent that reads from the shared pool, with no correction or expiry process yet in place to catch it.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung Galaxy S26 FE Color Leak Shows Three Finishes]]></title>
<description><![CDATA[New leaks show the Samsung Galaxy S26 FE in three apparent finishes as certification records and prelaunch sightings reveal more about its design, charging and expected specifications.
The post Samsung Galaxy S26 FE Color Leak Shows Three Finishes appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3710096/it-nachrichten/samsung-galaxy-s26-fe-color-leak-shows-three-finishes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710096/it-nachrichten/samsung-galaxy-s26-fe-color-leak-shows-three-finishes/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:30 +0200</pubDate>
<content:encoded><![CDATA[<p>New leaks show the Samsung Galaxy S26 FE in three apparent finishes as certification records and prelaunch sightings reveal more about its design, charging and expected specifications.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-galaxy-s26-fe-colors/">Samsung Galaxy S26 FE Color Leak Shows Three Finishes</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['Move fast, but do it with trust built in': EY CIO tells us why the rapid pace of AI means trust is now a critical business imperative]]></title>
<description><![CDATA[EY CIO tells us why delaying digital transformation decisions is no longer possible in the age of AI.]]></description>
<link>https://tsecurity.de/de/3710083/it-nachrichten/move-fast-but-do-it-with-trust-built-in-ey-cio-tells-us-why-the-rapid-pace-of-ai-means-trust-is-now-a-critical-business-imperative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710083/it-nachrichten/move-fast-but-do-it-with-trust-built-in-ey-cio-tells-us-why-the-rapid-pace-of-ai-means-trust-is-now-a-critical-business-imperative/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:29 +0200</pubDate>
<content:encoded><![CDATA[EY CIO tells us why delaying digital transformation decisions is no longer possible in the age of AI.]]></content:encoded>
</item>
<item>
<title><![CDATA[Our top-rated business PC is a multitasking powerhouse — save $530 on the Dell Tower Plus with Core Ultra 7]]></title>
<description><![CDATA[Our top-rated desktop computer for professionals comes with Intel Core Ultra 7 265, Nvidia RTX 5060 Ti, 32GB DDR5 RAM, and a 1TB NVMe SSD.]]></description>
<link>https://tsecurity.de/de/3710048/it-nachrichten/our-top-rated-business-pc-is-a-multitasking-powerhouse-save-530-on-the-dell-tower-plus-with-core-ultra-7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710048/it-nachrichten/our-top-rated-business-pc-is-a-multitasking-powerhouse-save-530-on-the-dell-tower-plus-with-core-ultra-7/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:28 +0200</pubDate>
<content:encoded><![CDATA[Our top-rated desktop computer for professionals comes with Intel Core Ultra 7 265, Nvidia RTX 5060 Ti, 32GB DDR5 RAM, and a 1TB NVMe SSD.]]></content:encoded>
</item>
<item>
<title><![CDATA[The HP EliteBook X G2i is an AI-powered laptop that can keep up with your business needs]]></title>
<description><![CDATA[From AI power to portability, the HP EliteBook X G2i is an ideal laptop for the business on the go.]]></description>
<link>https://tsecurity.de/de/3710059/it-nachrichten/the-hp-elitebook-x-g2i-is-an-ai-powered-laptop-that-can-keep-up-with-your-business-needs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710059/it-nachrichten/the-hp-elitebook-x-g2i-is-an-ai-powered-laptop-that-can-keep-up-with-your-business-needs/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:28 +0200</pubDate>
<content:encoded><![CDATA[From AI power to portability, the HP EliteBook X G2i is an ideal laptop for the business on the go.]]></content:encoded>
</item>
<item>
<title><![CDATA[I'm a diehard OnePlus user: Here's my plan now that the company is leaving North America]]></title>
<description><![CDATA[OnePlus has officially ended business across North America and Europe. I explain what happens next and the best alternatives to consider.]]></description>
<link>https://tsecurity.de/de/3709874/it-nachrichten/im-a-diehard-oneplus-user-heres-my-plan-now-that-the-company-is-leaving-north-america/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709874/it-nachrichten/im-a-diehard-oneplus-user-heres-my-plan-now-that-the-company-is-leaving-north-america/</guid>
<pubDate>Fri, 07 Aug 2026 23:45:37 +0200</pubDate>
<content:encoded><![CDATA[OnePlus has officially ended business across North America and Europe. I explain what happens next and the best alternatives to consider.]]></content:encoded>
</item>
<item>
<title><![CDATA[Datenschutzvorfall bei Laptop-Hersteller Framework (August 2026)]]></title>
<description><![CDATA[Unschöne Geschichte, die Kunden des Notebook-Herstellers Framework getroffen hat. Dem Anbieter wurde seine Cloud-Instanz mit einer Datenbank, die für Business-Intelligence verwendet wurde, beim Anbieter Metabase gehackt. Infolge dessen gelang es einem Angreifer Kundendaten abzuziehen. Framework h...]]></description>
<link>https://tsecurity.de/de/3709844/it-nachrichten/datenschutzvorfall-bei-laptop-hersteller-framework-august-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709844/it-nachrichten/datenschutzvorfall-bei-laptop-hersteller-framework-august-2026/</guid>
<pubDate>Fri, 07 Aug 2026 23:45:31 +0200</pubDate>
<content:encoded><![CDATA[Unschöne Geschichte, die Kunden des Notebook-Herstellers Framework getroffen hat. Dem Anbieter wurde seine Cloud-Instanz mit einer Datenbank, die für Business-Intelligence verwendet wurde, beim Anbieter Metabase gehackt. Infolge dessen gelang es einem Angreifer Kundendaten abzuziehen. Framework hat betroffene Kunden informiert, wie … <a href="https://borncity.com/blog/2026/08/07/datenschutzvorfall-bei-laptop-hersteller-framework-august-2026/">Weiterlesen <span class="meta-nav">→</span></a>
<p><a href="https://borncity.com/blog/2026/08/07/datenschutzvorfall-bei-laptop-hersteller-framework-august-2026/" rel="nofollow">Quelle</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[(g+) Business Insight: Google seeks a sharper focus in AI after Hassabis move]]></title>
<description><![CDATA[New role for the DeepMind co-founder comes as the competitive frontier in the technology is shifting Von Richard Waters (Deepmind, Google)]]></description>
<link>https://tsecurity.de/de/3709763/it-nachrichten/g-business-insight-google-seeks-a-sharper-focus-in-ai-after-hassabis-move/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709763/it-nachrichten/g-business-insight-google-seeks-a-sharper-focus-in-ai-after-hassabis-move/</guid>
<pubDate>Fri, 07 Aug 2026 23:45:17 +0200</pubDate>
<content:encoded><![CDATA[New role for the DeepMind co-founder comes as the competitive frontier in the technology is shifting Von Richard Waters (<a href="https://www.golem.de/specials/deepmind/">Deepmind</a>, <a href="https://www.golem.de/specials/google/">Google</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=211718&amp;page=1&amp;ts=1786118402" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[John Ternus: Kommender Apple-Chef setzt erste Management-Zeichen]]></title>
<description><![CDATA[Eine altgediente Mitarbeiterin holt der nächste Apple-CEO aus der Rente, das Designteam kriegt mehr Aufmerksamkeit: John Ternus, ab September Boss, agiert.]]></description>
<link>https://tsecurity.de/de/3709745/it-nachrichten/john-ternus-kommender-apple-chef-setzt-erste-management-zeichen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709745/it-nachrichten/john-ternus-kommender-apple-chef-setzt-erste-management-zeichen/</guid>
<pubDate>Fri, 07 Aug 2026 23:45:13 +0200</pubDate>
<content:encoded><![CDATA[Eine altgediente Mitarbeiterin holt der nächste Apple-CEO aus der Rente, das Designteam kriegt mehr Aufmerksamkeit: John Ternus, ab September Boss, agiert.]]></content:encoded>
</item>
<item>
<title><![CDATA[RCS: Google will mit dem Chatprotokoll Business machen]]></title>
<description><![CDATA[Google will RCS zum neuen Werkzeug für Firmenkommunikation machen und wirbt auf einer Deutschlandtour um Geschäftskunden.]]></description>
<link>https://tsecurity.de/de/3709723/it-nachrichten/rcs-google-will-mit-dem-chatprotokoll-business-machen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709723/it-nachrichten/rcs-google-will-mit-dem-chatprotokoll-business-machen/</guid>
<pubDate>Fri, 07 Aug 2026 23:45:12 +0200</pubDate>
<content:encoded><![CDATA[Google will RCS zum neuen Werkzeug für Firmenkommunikation machen und wirbt auf einer Deutschlandtour um Geschäftskunden.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Protect Your Business From Third-Party Cyber Threats]]></title>
<description><![CDATA[You run a lean operation. You use Shopify as a payment processor, a few plugins for email and reviews, maybe a third-party full payment service, or a shipping app. You have patched your systems, set up two-factor authentication, and feel reasonably secure.  
But here is the uncomfortable truth: o...]]></description>
<link>https://tsecurity.de/de/3709718/it-security-nachrichten/how-to-protect-your-business-from-third-party-cyber-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709718/it-security-nachrichten/how-to-protect-your-business-from-third-party-cyber-threats/</guid>
<pubDate>Fri, 07 Aug 2026 11:28:22 +0200</pubDate>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/how-to-protect-your-business-from-third-party-cyber-threats" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/Third_Party_Risk_1100x400.jpg" alt="Third Party Cyber Risk" class="hs-featured-image"> </a> 
</div> 
<p><span>You run a lean operation. You use Shopify as a payment processor, a few plugins for email and reviews, maybe a third-party full payment service, or a shipping app. You have patched your systems, set up two-factor authentication, and feel reasonably secure. </span></p> 
<p><span>But here is the uncomfortable truth: one of those tools could still breach your security tomorrow. That is the reality of supply chain cyber risk. It is not just a problem for corporations but a growing and serious threat for solo entrepreneurs and small business owners who depend on third-party vendors and digital tools to run their day-to-day operations. </span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Keepit AI Truth Cloud protects the data behind enterprise AI]]></title>
<description><![CDATA[Keepit announced AI Truth Cloud, transforming backup from a compliance requirement into the strategically valuable data asset an organization can hold. As AI agents take on business-critical decisions, AI Truth Cloud positions Keepit as the sovereign source of truth that enterprise AI can safely ...]]></description>
<link>https://tsecurity.de/de/3709712/it-security-nachrichten/keepit-ai-truth-cloud-protects-the-data-behind-enterprise-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709712/it-security-nachrichten/keepit-ai-truth-cloud-protects-the-data-behind-enterprise-ai/</guid>
<pubDate>Fri, 07 Aug 2026 11:27:09 +0200</pubDate>
<content:encoded><![CDATA[<p>Keepit announced AI Truth Cloud, transforming backup from a compliance requirement into the strategically valuable data asset an organization can hold. As AI agents take on business-critical decisions, AI Truth Cloud positions Keepit as the sovereign source of truth that enterprise AI can safely build on: data that is verifiable, governed, immutable, and proven. From backup to trusted enterprise operational foundation Keepit holds something AI vendors cannot replicate: a complete, sovereign, immutable, and tamper-proof copy … <a href="https://www.helpnetsecurity.com/2026/08/07/keepit-ai-truth-cloud-data-protection/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/07/keepit-ai-truth-cloud-data-protection/">Keepit AI Truth Cloud protects the data behind enterprise AI</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise-wide AI transformation starts with change management]]></title>
<description><![CDATA[Technology leaders are facing a sobering reality: They’re investing heavily in AI, yet many initiatives continue to struggle to move beyond experimentation and pilot programs. For example, Gartner found only 28% of AI use cases in infrastructure and operations fully succeed and meet ROI expectati...]]></description>
<link>https://tsecurity.de/de/3709709/it-security-nachrichten/enterprise-wide-ai-transformation-starts-with-change-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709709/it-security-nachrichten/enterprise-wide-ai-transformation-starts-with-change-management/</guid>
<pubDate>Fri, 07 Aug 2026 11:27:02 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Technology leaders are facing a sobering reality: They’re investing heavily in AI, yet many initiatives continue to struggle to move beyond experimentation and pilot programs. For example, Gartner found only <a href="https://www.gartner.com/en/newsroom/press-releases/2026-04-07-gartner-says-artificial-intelligence-projects-in-infrastructure-and-operations-stall-ahead-of-meaningful-roi-returns">28%</a> of AI use cases in infrastructure and operations fully succeed and meet ROI expectations, while 20% fail outright.</p>



<p class="wp-block-paragraph">The conversation around AI often focuses on models, tools and technical capabilities. Those decisions matter, but in my experience, they are rarely the only factors that determine success. The organizations realizing meaningful value from AI are also focused on operational readiness, governance, employee adoption and measurable outcomes.</p>



<p class="wp-block-paragraph">As both CIO and CDO, I spend a lot of time helping our organization navigate AI adoption while balancing the needs of our internal teams, our clients and running 24×7 secure operations. What I have learned is that AI transformation depends on how well the organization understands its data, improves its business processes and prepares people to work differently.</p>



<p class="wp-block-paragraph">I sometimes describe my role as being the organization’s traffic light. The green lights are easy – these are moments when the right answer is to accelerate. There are also moments when we need to slow down. As leaders, we must assess when we need to focus on the fundamentals and make sure the organization is ready for what comes next. And the most important decisions are the red lights – when we prevent the organization from spending time, money and energy on the wrong things.</p>



<h2 class="wp-block-heading">AI adoption breaks down when it does not fit how people work</h2>



<p class="wp-block-paragraph">One common misconception about AI transformation is that deployment automatically creates adoption. In practice, adoption happens when employees understand how the technology improves their work and have confidence in how it fits into their day-to-day responsibilities.</p>



<p class="wp-block-paragraph">I have seen AI pilots work well with small groups of users and then encounter challenges when expanded across larger teams. The technology may perform as expected, but the operating environment changes. Teams follow different workflows. Information is managed differently across functions. Employees have different levels of trust in the data. Success is not always measured the same way.</p>



<p class="wp-block-paragraph">These are readiness, process and change management issues.</p>



<p class="wp-block-paragraph">We saw similar lessons during our own transformation work. As part of a broader modernization program, we consolidated more than 50 engineering tools into one software delivery platform supporting thousands of developers. The technical migration mattered, but the bigger effort was helping teams adopt new ways of working and establish common practices.</p>



<p class="wp-block-paragraph">Anyone who has asked developers to move away from their favorite tools knows that change management is real. That experience reinforced a lesson: Transformation succeeds when people understand the value of the change, have the right support and can see how it improves the work they do every day.</p>



<p class="wp-block-paragraph">The same principle applies to AI.</p>



<p class="wp-block-paragraph">When we began introducing AI capabilities internally, we avoided a broad rollout from day one. Rolling AI out to thousands of employees is a process of education, adoption support and continuous learning. We introduced capabilities in phases, helped employees understand use cases relevant to their role and gave teams room to build confidence over time. Different teams adopt AI differently, so we found that cohort-based deployment and tailored change management created better long-term adoption than broad enterprise-wide rollouts.</p>



<p class="wp-block-paragraph">Pilots often succeed because the variables are limited. Production environments introduce the realities of the enterprise: inconsistent processes, disconnected data, unclear ownership and varying levels of employee readiness. In many cases, issues that surface during scaling can be traced back to operating model decisions, process gaps or unclear expectations.</p>



<p class="wp-block-paragraph">Employees need to understand where AI fits, when human judgment remains essential and how success will be measured. Without that clarity, scaling becomes much harder.</p>



<h2 class="wp-block-heading">Creating the operational conditions for AI success</h2>



<p class="wp-block-paragraph">The most successful AI transformations start before AI is introduced.</p>



<p class="wp-block-paragraph">They begin with understanding where employees experience friction. In most enterprises, those opportunities are not difficult to find. Repetitive administrative work and manual handoffs consume time and slow the business down. Employees directly in the workflows have the clearest view of where these issues exist.</p>



<p class="wp-block-paragraph">When we launched our own efficiency and transformation program, we deliberately did not start with AI. We started by evaluating our data, reviewing business processes and identifying opportunities to simplify how work was performed. We found that simplifying and standardizing workflows before introducing AI significantly reduced complexity during deployment. Rather than asking AI to compensate for fragmented processes, we focused first on creating a consistent operational foundation. We focused first on process improvement, automation and operational discipline. Once those foundations were in place, we began layering AI into the environment.</p>



<p class="wp-block-paragraph">AI outcomes are heavily influenced by the quality of the processes and the data along with the governance structures supporting them. If the underlying process is inconsistent, AI will struggle to create consistent value. If the process is understood, governed and measurable, AI has a much stronger foundation.</p>



<p class="wp-block-paragraph">I often say that good data and good processes deliver good AI outcomes. That continues to hold true regardless of the model or technology being deployed.</p>



<p class="wp-block-paragraph">The real challenge is making sure employees know what AI is using, where it fits in the workflow and when they should rely on the output. If that is unclear, adoption slows. People may not trust the answer, may use the tool inconsistently or may avoid changing how work gets done.</p>



<p class="wp-block-paragraph">Before scaling AI, leaders need to answer a few basic questions. What problem are we solving? Is the process consistent enough? Is the data reliable enough? Where does human judgment still matter? And how will we know whether the tool is improving the work? Those questions determine whether AI becomes part of how teams operate.</p>



<h2 class="wp-block-heading">Measure outcomes before you scale</h2>



<p class="wp-block-paragraph">AI programs often lose momentum when leaders measure activity instead of impact. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-30-gartner-survey-finds-forty-five-percent-of-organizations-with-high-artificial-intelligence-maturity-keep-artificial-intelligence-projects-operational-for-at-least-three-years?">63% of high-maturity organizations</a> implement formal metrics to evaluate transformation efforts.</p>



<p class="wp-block-paragraph">Leaders often track how many employees have access to AI, how many licenses have been provisioned or how many use cases have been launched. Those metrics can be useful, but they do not always show whether the organization is creating business value. Activity is not the same as impact.</p>



<p class="wp-block-paragraph">The more meaningful indicators are instead tied to operational performance: support ticket volumes, incident reduction, productivity improvements, user experience, cycle times and service quality.</p>



<p class="wp-block-paragraph">We have seen the value of this approach firsthand. As part of our transformation program, we standardized service delivery processes and moved hundreds of teams onto a common service management platform. In our own experience, process improvements and platform consolidation initially reduced support ticket volumes by approximately 30%.</p>



<p class="wp-block-paragraph">After that foundation was established, additional automation and AI capabilities helped drive reductions closer to 70%.</p>



<p class="wp-block-paragraph">The initial improvement came from better processes and greater operational consistency. Automation and AI then helped accelerate the results. That is the pattern leaders should look for: Identify where work slows down, improve the process, establish accountability and introduce AI where the environment is ready to support it.</p>



<p class="wp-block-paragraph">This approach also helps build trust. Employees can see the value being created. Leaders can measure progress. Teams can learn from early deployments before scaling more broadly.</p>



<h2 class="wp-block-heading">Preparing people is the real AI strategy</h2>



<p class="wp-block-paragraph">Technology adoption has always been closely connected to people.</p>



<p class="wp-block-paragraph">Employees are more likely to embrace change when they understand how technology helps them be more effective. They need practical experience, clear expectations and opportunities to learn. AI introduces new ways of working, and organizations need to prepare employees for that shift.</p>



<p class="wp-block-paragraph">In our own organization, we encouraged every employee to establish an AI-related learning goal because familiarity with emerging technologies is becoming part of every role. Some goals were simple. Some were more advanced. The important point was creating a culture where people continue to learn and understand how AI applies to their work versus forcing AI activity broadly all at once.</p>



<p class="wp-block-paragraph">As AI becomes more embedded in enterprise operations, organizations with strong foundations in governance, process discipline and workforce readiness will be better positioned to capture long-term value.</p>



<p class="wp-block-paragraph">The companies realizing the greatest value from AI are investing in technology while also strengthening the operating models, information management practices and employee capabilities that support adoption. Sustainable transformation requires attention to people, processes, data and technology.</p>



<p class="wp-block-paragraph">Preparing people, building trust and creating clear operating models remain central to any successful AI strategy.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehr Verantwortung, keine Kapazität: Das Dilemma der IT-Talententwicklung]]></title>
<description><![CDATA[Deutschlands IT steht unter Dauerstrom: Systeme sichern, Transformation stemmen, KI integrieren. Doch strategische Projekte bleiben liegen. Die naheliegende Antwort lautet häufig: mehr Recruiting. Aber liegt der Engpass wirklich nur auf dem Arbeitsmarkt?

Tags: #Human Resource | #IT-Abteilung | #...]]></description>
<link>https://tsecurity.de/de/3709689/it-security-nachrichten/mehr-verantwortung-keine-kapazitaet-das-dilemma-der-it-talententwicklung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709689/it-security-nachrichten/mehr-verantwortung-keine-kapazitaet-das-dilemma-der-it-talententwicklung/</guid>
<pubDate>Fri, 07 Aug 2026 11:25:43 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/09/Talent-Management_hutterstock_2520617859_1920.png" class="attachment-full size-full wp-post-image" alt="IT-Talententwicklung, IT-Fachkräfte, Talentmanagement, Recruiting, IT-Talente im Unternehmen gezielt entwickeln, Fachkräftemangel durch interne Talententwicklung lösen" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/09/Talent-Management_hutterstock_2520617859_1920.png 1920w, https://www.it-daily.net/wp-content/uploads/2026/09/Talent-Management_hutterstock_2520617859_1920-300x169.png 300w, https://www.it-daily.net/wp-content/uploads/2026/09/Talent-Management_hutterstock_2520617859_1920-1024x576.png 1024w, https://www.it-daily.net/wp-content/uploads/2026/09/Talent-Management_hutterstock_2520617859_1920-768x432.png 768w, https://www.it-daily.net/wp-content/uploads/2026/09/Talent-Management_hutterstock_2520617859_1920-1536x864.png 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Mehr Verantwortung, keine Kapazität: Das Dilemma der IT-Talententwicklung 6"></p>
    Deutschlands IT steht unter Dauerstrom: Systeme sichern, Transformation stemmen, KI integrieren. Doch strategische Projekte bleiben liegen. Die naheliegende Antwort lautet häufig: mehr Recruiting. Aber liegt der Engpass wirklich nur auf dem Arbeitsmarkt?

<p>Tags: <a href="https://www.it-daily.net/thema/human-resource">#Human Resource</a> | <a href="https://www.it-daily.net/thema/it-abteilung">#IT-Abteilung</a> | <a href="https://www.it-daily.net/thema/recruiting">#Recruiting</a> | <a href="https://www.it-daily.net/thema/talent-management">#Talent Management</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Entscheidungen: Blackbox, bis Zertifizierung Klarheit schafft - Digital Business Magazin]]></title>
<description><![CDATA[... IT-, OT- und Daten-Risiken unter Kontrolle hat. ... TISAX, kurz für Trusted Information Security Assessment Exchange, wurde speziell für die ...]]></description>
<link>https://tsecurity.de/de/3709682/it-security-nachrichten/ki-entscheidungen-blackbox-bis-zertifizierung-klarheit-schafft-digital-business-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709682/it-security-nachrichten/ki-entscheidungen-blackbox-bis-zertifizierung-klarheit-schafft-digital-business-magazin/</guid>
<pubDate>Fri, 07 Aug 2026 11:25:36 +0200</pubDate>
<content:encoded><![CDATA[... <b>IT</b>-, OT- und Daten-Risiken unter Kontrolle hat. ... TISAX, kurz für Trusted Information <b>Security</b> Assessment Exchange, wurde speziell für die ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Anzeige: Microsoft Purview: Datenschutz und Insider Risk Management]]></title>
<description><![CDATA[Sensitivity Labels, DLP und Insider Risk Management müssen bei Microsoft Purview technisch und organisatorisch zusammenspielen. Ein Workshop vermittelt praxisnahes Wissen dazu. (Microsoft 365, Server-Applikationen)]]></description>
<link>https://tsecurity.de/de/3709663/it-security-nachrichten/anzeige-microsoft-purview-datenschutz-und-insider-risk-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709663/it-security-nachrichten/anzeige-microsoft-purview-datenschutz-und-insider-risk-management/</guid>
<pubDate>Fri, 07 Aug 2026 11:25:22 +0200</pubDate>
<content:encoded><![CDATA[Sensitivity Labels, DLP und Insider Risk Management müssen bei Microsoft Purview technisch und organisatorisch zusammenspielen. Ein Workshop vermittelt praxisnahes Wissen dazu. (<a href="https://www.golem.de/specials/office-365/">Microsoft 365</a>, <a href="https://www.golem.de/specials/serverapps/">Server-Applikationen</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=211647&amp;page=1&amp;ts=1786079702" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft gibt OneDrive-Fotos-Zwangsinstallation zu, macht Rückzieher]]></title>
<description><![CDATA[Microsoft hat auf vielen Rechnern ungefragt die neue OneDrive-Fotos-App installiert. Das sorgte bei Nutzern und Administratoren für viel Ärger. Nun verspricht der Konzern eine Lösung zur Löschung der Software und erklärt die integrierte Gesichtserkennung.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3709659/it-security-nachrichten/microsoft-gibt-onedrive-fotos-zwangsinstallation-zu-macht-rueckzieher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709659/it-security-nachrichten/microsoft-gibt-onedrive-fotos-zwangsinstallation-zu-macht-rueckzieher/</guid>
<pubDate>Fri, 07 Aug 2026 11:25:21 +0200</pubDate>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160464.html"><img hspace="5" border="0" align="left" alt="Download, OneDrive, icon, Microsoft OneDrive, OneDrive Logo, Microsoft OneDrive Logo, OneDrive for Business" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/48362.jpg"></a>
			Microsoft hat auf vielen Rechnern ungefragt die neue OneDrive-Fotos-App installiert. Das sorgte bei Nutzern und Administratoren für viel Ärger. Nun verspricht der Konzern eine Lösung zur Löschung der Software und erklärt die integrierte Gesichtserkennung.			(<a href="https://winfuture.de/news,160464.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise-wide AI transformation starts with change management]]></title>
<description><![CDATA[Technology leaders are facing a sobering reality: They’re investing heavily in AI, yet many initiatives continue to struggle to move beyond experimentation and pilot programs. For example, Gartner found only 28% of AI use cases in infrastructure and operations fully succeed and meet ROI expectati...]]></description>
<link>https://tsecurity.de/de/3709645/it-nachrichten/enterprise-wide-ai-transformation-starts-with-change-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709645/it-nachrichten/enterprise-wide-ai-transformation-starts-with-change-management/</guid>
<pubDate>Fri, 07 Aug 2026 11:25:14 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Technology leaders are facing a sobering reality: They’re investing heavily in AI, yet many initiatives continue to struggle to move beyond experimentation and pilot programs. For example, Gartner found only <a href="https://www.gartner.com/en/newsroom/press-releases/2026-04-07-gartner-says-artificial-intelligence-projects-in-infrastructure-and-operations-stall-ahead-of-meaningful-roi-returns">28%</a> of AI use cases in infrastructure and operations fully succeed and meet ROI expectations, while 20% fail outright.</p>



<p class="wp-block-paragraph">The conversation around AI often focuses on models, tools and technical capabilities. Those decisions matter, but in my experience, they are rarely the only factors that determine success. The organizations realizing meaningful value from AI are also focused on operational readiness, governance, employee adoption and measurable outcomes.</p>



<p class="wp-block-paragraph">As both CIO and CDO, I spend a lot of time helping our organization navigate AI adoption while balancing the needs of our internal teams, our clients and running 24×7 secure operations. What I have learned is that AI transformation depends on how well the organization understands its data, improves its business processes and prepares people to work differently.</p>



<p class="wp-block-paragraph">I sometimes describe my role as being the organization’s traffic light. The green lights are easy – these are moments when the right answer is to accelerate. There are also moments when we need to slow down. As leaders, we must assess when we need to focus on the fundamentals and make sure the organization is ready for what comes next. And the most important decisions are the red lights – when we prevent the organization from spending time, money and energy on the wrong things.</p>



<h2 class="wp-block-heading">AI adoption breaks down when it does not fit how people work</h2>



<p class="wp-block-paragraph">One common misconception about AI transformation is that deployment automatically creates adoption. In practice, adoption happens when employees understand how the technology improves their work and have confidence in how it fits into their day-to-day responsibilities.</p>



<p class="wp-block-paragraph">I have seen AI pilots work well with small groups of users and then encounter challenges when expanded across larger teams. The technology may perform as expected, but the operating environment changes. Teams follow different workflows. Information is managed differently across functions. Employees have different levels of trust in the data. Success is not always measured the same way.</p>



<p class="wp-block-paragraph">These are readiness, process and change management issues.</p>



<p class="wp-block-paragraph">We saw similar lessons during our own transformation work. As part of a broader modernization program, we consolidated more than 50 engineering tools into one software delivery platform supporting thousands of developers. The technical migration mattered, but the bigger effort was helping teams adopt new ways of working and establish common practices.</p>



<p class="wp-block-paragraph">Anyone who has asked developers to move away from their favorite tools knows that change management is real. That experience reinforced a lesson: Transformation succeeds when people understand the value of the change, have the right support and can see how it improves the work they do every day.</p>



<p class="wp-block-paragraph">The same principle applies to AI.</p>



<p class="wp-block-paragraph">When we began introducing AI capabilities internally, we avoided a broad rollout from day one. Rolling AI out to thousands of employees is a process of education, adoption support and continuous learning. We introduced capabilities in phases, helped employees understand use cases relevant to their role and gave teams room to build confidence over time. Different teams adopt AI differently, so we found that cohort-based deployment and tailored change management created better long-term adoption than broad enterprise-wide rollouts.</p>



<p class="wp-block-paragraph">Pilots often succeed because the variables are limited. Production environments introduce the realities of the enterprise: inconsistent processes, disconnected data, unclear ownership and varying levels of employee readiness. In many cases, issues that surface during scaling can be traced back to operating model decisions, process gaps or unclear expectations.</p>



<p class="wp-block-paragraph">Employees need to understand where AI fits, when human judgment remains essential and how success will be measured. Without that clarity, scaling becomes much harder.</p>



<h2 class="wp-block-heading">Creating the operational conditions for AI success</h2>



<p class="wp-block-paragraph">The most successful AI transformations start before AI is introduced.</p>



<p class="wp-block-paragraph">They begin with understanding where employees experience friction. In most enterprises, those opportunities are not difficult to find. Repetitive administrative work and manual handoffs consume time and slow the business down. Employees directly in the workflows have the clearest view of where these issues exist.</p>



<p class="wp-block-paragraph">When we launched our own efficiency and transformation program, we deliberately did not start with AI. We started by evaluating our data, reviewing business processes and identifying opportunities to simplify how work was performed. We found that simplifying and standardizing workflows before introducing AI significantly reduced complexity during deployment. Rather than asking AI to compensate for fragmented processes, we focused first on creating a consistent operational foundation. We focused first on process improvement, automation and operational discipline. Once those foundations were in place, we began layering AI into the environment.</p>



<p class="wp-block-paragraph">AI outcomes are heavily influenced by the quality of the processes and the data along with the governance structures supporting them. If the underlying process is inconsistent, AI will struggle to create consistent value. If the process is understood, governed and measurable, AI has a much stronger foundation.</p>



<p class="wp-block-paragraph">I often say that good data and good processes deliver good AI outcomes. That continues to hold true regardless of the model or technology being deployed.</p>



<p class="wp-block-paragraph">The real challenge is making sure employees know what AI is using, where it fits in the workflow and when they should rely on the output. If that is unclear, adoption slows. People may not trust the answer, may use the tool inconsistently or may avoid changing how work gets done.</p>



<p class="wp-block-paragraph">Before scaling AI, leaders need to answer a few basic questions. What problem are we solving? Is the process consistent enough? Is the data reliable enough? Where does human judgment still matter? And how will we know whether the tool is improving the work? Those questions determine whether AI becomes part of how teams operate.</p>



<h2 class="wp-block-heading">Measure outcomes before you scale</h2>



<p class="wp-block-paragraph">AI programs often lose momentum when leaders measure activity instead of impact. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-30-gartner-survey-finds-forty-five-percent-of-organizations-with-high-artificial-intelligence-maturity-keep-artificial-intelligence-projects-operational-for-at-least-three-years?">63% of high-maturity organizations</a> implement formal metrics to evaluate transformation efforts.</p>



<p class="wp-block-paragraph">Leaders often track how many employees have access to AI, how many licenses have been provisioned or how many use cases have been launched. Those metrics can be useful, but they do not always show whether the organization is creating business value. Activity is not the same as impact.</p>



<p class="wp-block-paragraph">The more meaningful indicators are instead tied to operational performance: support ticket volumes, incident reduction, productivity improvements, user experience, cycle times and service quality.</p>



<p class="wp-block-paragraph">We have seen the value of this approach firsthand. As part of our transformation program, we standardized service delivery processes and moved hundreds of teams onto a common service management platform. In our own experience, process improvements and platform consolidation initially reduced support ticket volumes by approximately 30%.</p>



<p class="wp-block-paragraph">After that foundation was established, additional automation and AI capabilities helped drive reductions closer to 70%.</p>



<p class="wp-block-paragraph">The initial improvement came from better processes and greater operational consistency. Automation and AI then helped accelerate the results. That is the pattern leaders should look for: Identify where work slows down, improve the process, establish accountability and introduce AI where the environment is ready to support it.</p>



<p class="wp-block-paragraph">This approach also helps build trust. Employees can see the value being created. Leaders can measure progress. Teams can learn from early deployments before scaling more broadly.</p>



<h2 class="wp-block-heading">Preparing people is the real AI strategy</h2>



<p class="wp-block-paragraph">Technology adoption has always been closely connected to people.</p>



<p class="wp-block-paragraph">Employees are more likely to embrace change when they understand how technology helps them be more effective. They need practical experience, clear expectations and opportunities to learn. AI introduces new ways of working, and organizations need to prepare employees for that shift.</p>



<p class="wp-block-paragraph">In our own organization, we encouraged every employee to establish an AI-related learning goal because familiarity with emerging technologies is becoming part of every role. Some goals were simple. Some were more advanced. The important point was creating a culture where people continue to learn and understand how AI applies to their work versus forcing AI activity broadly all at once.</p>



<p class="wp-block-paragraph">As AI becomes more embedded in enterprise operations, organizations with strong foundations in governance, process discipline and workforce readiness will be better positioned to capture long-term value.</p>



<p class="wp-block-paragraph">The companies realizing the greatest value from AI are investing in technology while also strengthening the operating models, information management practices and employee capabilities that support adoption. Sustainable transformation requires attention to people, processes, data and technology.</p>



<p class="wp-block-paragraph">Preparing people, building trust and creating clear operating models remain central to any successful AI strategy.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta fined $567m in New Mexico over ‘public nuisance’ designation]]></title>
<description><![CDATA[The penalty is in addition to $375m that Meta was ordered to pay in March as a result of a separate phase of the same court case. 
Read more: Meta fined $567m in New Mexico over ‘public nuisance’ designation]]></description>
<link>https://tsecurity.de/de/3709641/it-nachrichten/meta-fined-567m-in-new-mexico-over-public-nuisance-designation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709641/it-nachrichten/meta-fined-567m-in-new-mexico-over-public-nuisance-designation/</guid>
<pubDate>Fri, 07 Aug 2026 11:25:13 +0200</pubDate>
<content:encoded><![CDATA[<p>The penalty is in addition to $375m that Meta was ordered to pay in March as a result of a separate phase of the same court case. </p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/business/meta-fined-567m-in-new-mexico-over-public-nuisance-designation-harm-minors">Meta fined $567m in New Mexico over ‘public nuisance’ designation</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Former A16z partner to raise $100m as debut fund for new venture firm]]></title>
<description><![CDATA[Bryan Kim filed formation documents for his new venture Mido last month, according to a regulatory filing. 
Read more: Former A16z partner to raise $100m as debut fund for new venture firm]]></description>
<link>https://tsecurity.de/de/3709642/it-nachrichten/former-a16z-partner-to-raise-100m-as-debut-fund-for-new-venture-firm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709642/it-nachrichten/former-a16z-partner-to-raise-100m-as-debut-fund-for-new-venture-firm/</guid>
<pubDate>Fri, 07 Aug 2026 11:25:13 +0200</pubDate>
<content:encoded><![CDATA[<p>Bryan Kim filed formation documents for his new venture Mido last month, according to a regulatory filing. </p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/business/a16z-partner-raise-100m-debut-fund-new-venture-firm-investment">Former A16z partner to raise $100m as debut fund for new venture firm</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trump orders new 15% tariff on key material for solar panels and microchips]]></title>
<description><![CDATA[Move to raise levy on goods made with polysilicon aims to protect domestic US supply chains from China, the major producerDonald Trump has ordered a new 15% tariff on imported products made of polysilicon, an important ingredient in microchip manufacturing that is primarily produced by China.The ...]]></description>
<link>https://tsecurity.de/de/3709625/it-nachrichten/trump-orders-new-15-tariff-on-key-material-for-solar-panels-and-microchips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709625/it-nachrichten/trump-orders-new-15-tariff-on-key-material-for-solar-panels-and-microchips/</guid>
<pubDate>Fri, 07 Aug 2026 11:24:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Move to raise levy on goods made with polysilicon aims to protect domestic US supply chains from China, the major producer</p><p>Donald Trump has ordered a new 15% <a href="https://www.theguardian.com/business/tariffs">tariff</a> on imported products made of polysilicon, an important ingredient in microchip manufacturing that is primarily produced by China.</p><p>The new tariff, which will take effect on 4 December, is aimed at supporting <a href="https://www.theguardian.com/technology/2026/jan/15/trump-tariff-nvidia-ai-chips">US chip</a> and solar panel supply chains to compete with Beijing on artificial intelligence and energy.</p> <a href="https://www.theguardian.com/us-news/2026/aug/07/trump-orders-tariff-solar-panels-microchips-manufacturing-ingredient">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anzeige: Microsoft Purview: Datenschutz und Insider Risk Management]]></title>
<description><![CDATA[Sensitivity Labels, DLP und Insider Risk Management müssen bei Microsoft Purview technisch und organisatorisch zusammenspielen. Ein Workshop vermittelt praxisnahes Wissen dazu. (Microsoft 365, Server-Applikationen)]]></description>
<link>https://tsecurity.de/de/3709554/it-nachrichten/anzeige-microsoft-purview-datenschutz-und-insider-risk-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709554/it-nachrichten/anzeige-microsoft-purview-datenschutz-und-insider-risk-management/</guid>
<pubDate>Fri, 07 Aug 2026 11:15:05 +0200</pubDate>
<content:encoded><![CDATA[Sensitivity Labels, DLP und Insider Risk Management müssen bei Microsoft Purview technisch und organisatorisch zusammenspielen. Ein Workshop vermittelt praxisnahes Wissen dazu. (<a href="https://www.golem.de/specials/office-365/">Microsoft 365</a>, <a href="https://www.golem.de/specials/serverapps/">Server-Applikationen</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=211647&amp;page=1&amp;ts=1786079702" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 10 Best External Attack Surface Management (EASM) Platforms 2026]]></title>
<description><![CDATA[In the sprawling digital ecosystem of 2026, organizations grapple with an increasingly complex and often poorly understood external attack surface. This…
Read more →
The post Top 10 Best External Attack Surface Management (EASM) Platforms 2026 appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3709508/it-security-nachrichten/top-10-best-external-attack-surface-management-easm-platforms-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709508/it-security-nachrichten/top-10-best-external-attack-surface-management-easm-platforms-2026/</guid>
<pubDate>Fri, 07 Aug 2026 06:33:20 +0200</pubDate>
<content:encoded><![CDATA[<p>In the sprawling digital ecosystem of 2026, organizations grapple with an increasingly complex and often poorly understood external attack surface. This…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/top-10-best-external-attack-surface-management-easm-platforms-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/top-10-best-external-attack-surface-management-easm-platforms-2026/">Top 10 Best External Attack Surface Management (EASM) Platforms 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Business Knigge: Peinliche Pannen beim Geschäftsessen]]></title>
<description><![CDATA[Gute Tischmanieren sind karrierefördernd.
				
			
				
					Ein guter Gastgeber sorgt sich um das Wohl seiner Gäste.
				
			
				
					Zurückhaltende Gäste sollten Sie in Gespräche mit einbinden.
				
			
		
	
Andere denken sich nichts und merken gar nicht, dass sie bereits mehrfach ins Fettnäp...]]></description>
<link>https://tsecurity.de/de/3709504/it-security-nachrichten/business-knigge-peinliche-pannen-beim-geschaeftsessen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709504/it-security-nachrichten/business-knigge-peinliche-pannen-beim-geschaeftsessen/</guid>
<pubDate>Fri, 07 Aug 2026 06:32:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<ul>
			
				
					<li>Gute Tischmanieren sind karrierefördernd.</li>
				
			
				
					<li>Ein guter Gastgeber sorgt sich um das Wohl seiner Gäste.</li>
				
			
				
					<li>Zurückhaltende Gäste sollten Sie in Gespräche mit einbinden.</li>
				
			
		</ul>
	
<p>Andere denken sich nichts und merken gar nicht, dass sie bereits mehrfach ins <a href="https://www.computerwoche.de/article/2676803/mit-guten-tischmanieren-punkten.html" title="Fettnäpfchen " target="_blank">Fettnäpfchen </a>getreten sind, zum Beispiel wenn sie das Brot wie eine Stulle beschmieren und vor dem Hauptgang verzehren. Einige Peinlichkeiten sind offensichtlicher, könnten aber galant gelöst werden. Beherrscht man die Regeln und Sitten bei Tisch, ist es ein Leichtes, konzentriert dem Gespräch des Partners zu folgen und sich ganz und gar auf den Inhalt des Geschäftstermins statt auf die richtige Besteckreihenfolge zu konzentrieren.</p><div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Egal ob beim Business-Lunch oder zum Geschäftsessen im Restaurant - Fettnäpfchen lauern überall." title="Egal ob beim Business-Lunch oder zum Geschäftsessen im Restaurant - Fettnäpfchen lauern überall." src="https://images.computerwoche.de/bdb/2580458/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Egal ob beim Business-Lunch oder zum Geschäftsessen im Restaurant – Fettnäpfchen lauern überall.</p></figcaption></figure><p class="imageCredit">
					Foto: Photographee eu – shutterstock.com</p></div><h3>Kleckern</h3><p>… tun nicht nur kleine Kinder bei Tisch. Schnell ist ein Soßenfleck auf der Tischdecke gelandet. Bleiben Sie enspannt! Jede Serviette und auch die Tischtücher werden nach dem Essen gereinigt und dabei ist ein Fleck mehr oder weniger nicht ausschlaggebend. Lassen Sie also Salzstreuer und Dekoration dort wo sie sind und übersehen Sie souverän Ihren Fleck neben den Teller. Flutscht ein Salatblatt vom Tellerrand auf den Tisch, befördern Sie es wieder auf Ihren Teller. Fällt ein Haps auf den Boden, lassen Sie ihn liegen. Rutscht Ihnen die Serviette auf den Boden, krabblen Sie bitte nicht unter den Tisch. Lassen Sie sich einfach eine neue Serviette geben. Ein guter Service wird Ihnen von selbst eine neue Serviette geben.</p><h3>Das berühmte Haar in der Suppe</h3><p>Wird Ihr Essen nicht so geliefert wie Sie es bestellt haben, rufen Sie den Service zu sich und sagen in einem ruhigen Ton, was nicht stimmt. Am Anfang des Essens kann der Service Abhilfe schaffen, fällt das Haar erst am Ende des Essens auf, sollte der Kellner neben der Entschuldigung auch eine Wiedergutmachung parat haben.</p><div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Der Haufe TaschenGuide " title="Der Haufe TaschenGuide " src="https://images.computerwoche.de/bdb/2580451/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Haufe TaschenGuide “Geschäftsessen meistern” von Christina Tabernig und Anke Quittschau ist für 3,99 Euro als e-Book erhältlich.</p></figcaption></figure><p class="imageCredit">
					Foto: Haufe Lexware</p></div><h3>Unaufmerksames Personal</h3><p>Manch Restaurantbesucher fragt sich, ob es dem Servicepersonal regelrecht beigebracht wird, wie man Kunden ignoriert. Haben Sie als Gast das Gefühl, ständig übersehen zu werden, entschuldigen Sie sich bei Ihren Gästen und gehen Sie zur Bar oder fangen Sie das Personal an ihrer “Station” ab, um Ihre Wünsche loszuwerden. Es ist Ihre <a href="https://www.computerwoche.de/article/2676769/zehn-tipps-fuer-den-perfekten-gastgeber.html" title="Aufgabe als Gastgeber" target="_blank">Aufgabe als Gastgeber</a>, aktiv Regie zu führen und den Restaurantbesuch so angenehm wie möglich zu gestalten.</p><h3>Telefonierende Nachbargäste</h3><p>Laute oder unangenehme Tischnachbarn dürfen gerne auf eine angemessene Gesprächlautstärke hingewiesen werden. Möchten Sie keine direkte Konfrontation mit einem anderen Gast eingehen, können Sie auch den Service bitten, dies für Sie zu übernehmen. Grundsätzlich ist ein Restaurant kein Büro und Telefonate sollten nicht am Tisch geführt werden. Bitten Sie in einem freundlichen Ton darum, dass das Telefonat nach draußen verlegt wird, da es Ihre Unterhaltung stört.</p><h3>Meine Suppe ess ich nicht….</h3><p>Wurde das Menü vorher ausgewählt und gibt es eine Speise, die Sie nicht essen möchten, können Sie diese gerne beim Kellner gegen eine andere Speise austauschen. (Also statt der Tomatensuppe eventuell eine klare Brühe.) Einen Gang sich nicht servieren zu lassen, ist keine gute Lösung, da der Gastgeber erst <a href="https://www.computerwoche.de/article/2746524/du-bist-wie-du-isst.html" title="mit dem Essen startet" target="_blank">mit dem Essen startet</a>, wenn allen serviert wurde. Die Absprache zwischen Ihnen und dem Kellner hat er dann vielleicht nicht mitbekommen. Essen Sie von der servierten Speise, dass was Sie essen können oder wollen und lassen den Rest zurückgehen. Sie sind nicht verpflichtet, Ihren Teller leer zu essen.</p><h3>Langweilige Tischpartner</h3><p>…können einen Abend unendlich lang erscheinen lassen. Wenn der Smalltalk mit Ihrem Tischherrn oder der Tischdame nicht läuft, müssen Sie selber in die Bresche springen und Geschichten und Wissenswertes erzählen. Klassische Smalltalk-Themen sind Urlaube, Freizeit, Hobbies und Wochenendplanungen. Geht Ihr Gesprächspartner auf nichts ein, versuchen Sie auf die Gemeinsamkeiten Ort, Umfeld und Anlass einzugehen. Klappt auch das nicht, können Sie sich eventuell in ein Nachbargespräch mit einklinken und bei Bedarf die Gesprächsführung so leiten, dass der wortkarge Nachbar seine Meinung zu dem ein oder anderen Thema beisteuern kann oder soll. Erst zum Kaffee dürften Sie die Sitzordnung auflösen und sich einen neuen Gesprächspartner suchen.</p><h3>Mehr Tipps…</h3><p>…rund um das Verhalten bei einem Geschäftsessen können Sie in dem Haufe TaschenGuide “Geschäftsessen meistern” von Christina Tabernig und Anke Quittschau nachlesen. Außerdem finden Sie Informationen zu Coaching und Seminaren der Autorinnen auf der Webseite <a href="https://www.korrekt.de/" title="www.korrekt.de" target="_blank" rel="noopener">www.korrekt.de</a>.</p><div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Christina Tabernig ist Expertin für Etikette und Benimm bei der Agentur korrekt!" title="Christina Tabernig ist Expertin für Etikette und Benimm bei der Agentur korrekt!" src="https://images.computerwoche.de/bdb/2580449/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Christina Tabernig ist Expertin für Etikette und Benimm bei der Agentur korrekt!</p></figcaption></figure><p class="imageCredit">
					Foto: Christina Tabernig</p></div><h3>Mehr zum Thema Knigge…</h3><p><a href="https://www.computerwoche.de/article/2676803/mit-guten-tischmanieren-punkten.html" title="Mit guten Tischmanieren punkten" target="_blank">Mit guten Tischmanieren punkten</a></p><p><a href="https://www.computerwoche.de/article/2755855/neulich-in-einem-muenchner-restaurant.html" title="Neulich in ... einem Münchner Restaurant" target="_blank">Neulich in … einem Münchner Restaurant</a></p><p><a href="https://www.computerwoche.de/article/2602380/soforthilfe-fuer-peinliche-knigge-blackouts.html" title="Soforthilfe für peinliche Knigge-Blackouts" target="_blank">Soforthilfe für peinliche Knigge-Blackouts</a></p><div class="foundryDgalleryWrapper" data-foundry-gallery-id="106218"></div>




<p class="wp-block-paragraph"></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Windows zur Entwicklungsumgebung wird]]></title>
<description><![CDATA[Windows-Maschine und Developer-„Flow“ gehen gut zusammen – ein paar Kniffe vorausgesetzt.Dragon Images | shutterstock.com



Als Umgebung für Entwickler hat Microsoft Windows in den letzten Jahren einen Sprung nach vorne gemacht. Mit dem Windows-Subsystem für Linux (WSL) ist es nahtlos möglich, m...]]></description>
<link>https://tsecurity.de/de/3709505/it-security-nachrichten/wie-windows-zur-entwicklungsumgebung-wird/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709505/it-security-nachrichten/wie-windows-zur-entwicklungsumgebung-wird/</guid>
<pubDate>Fri, 07 Aug 2026 06:32:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Dragon-Images_shutterstock_401334922_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Dev Coding Speed 16z9" class="wp-image-4202220" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Windows-Maschine und Developer-„Flow“ gehen gut zusammen – ein paar Kniffe vorausgesetzt.</figcaption></figure><p class="imageCredit">Dragon Images | shutterstock.com</p></div>



<p class="wp-block-paragraph">Als Umgebung für Entwickler hat Microsoft Windows in den letzten Jahren einen Sprung nach vorne gemacht. Mit dem Windows-Subsystem für Linux (<a href="https://www.computerwoche.de/article/2856740/windows-10-subsystem-fuer-linux-wsl-einrichten.html" target="_blank">WSL</a>) ist es nahtlos möglich, mit Linux unter Windows zu arbeiten – ohne den Mehraufwand, den eine virtuelle Maschine (<a href="https://www.computerwoche.de/article/2814705/was-sind-virtual-machines.html" target="_blank">VM</a>) mit sich bringt. Zudem sind sämtliche gängigen Dev-Tools als native Windows-Versionen verfügbar – und Microsoft hat eine ganze Reihe entsprechender Funktionen auch direkt in sein Betriebssystem <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/">integriert</a>.</p>



<p class="wp-block-paragraph">Für Developer, die besonders schnell mit einer Windows-Maschine entwickeln wollen, hat Microsoft mit der „<a href="https://github.com/microsoft/WindowsDeveloperConfig/" target="_blank" rel="noreferrer noopener">Windows Developer Config</a>“ sogar so etwas wie eine Schnellspur geschaffen: Diese Sammlung von Powershell-Skripten fungiert als eine Art „Starter Kit“ und unterstützt dabei, Windows-Systeme möglichst schnell und komfortabel als Entwicklungsumgebung einzurichten. </p>



<p class="wp-block-paragraph">Wenn Sie hingegen – wie <a href="https://www.computerwoche.de/article/2818958/was-developer-an-ihrem-job-lieben-und-hassen.html" target="_blank">die meisten Entwickler</a> – Wert darauflegen, die Kontrolle zu behalten und Ihr Dev-System selbst einzurichten und zu konfigurieren, ist ein bisschen Vorarbeit nötig. Der Aufwand selbst ist dabei überschaubar, die konkreten Schritte sind jedoch erfolgsentscheidend (und nicht unbedingt offensichtlich).   </p>



<p class="wp-block-paragraph"><strong>Hinweis:</strong> Um die nachfolgenden Maßnahmen umzusetzen, sollten Sie auf Ihrem System über Administratorrechte verfügen.</p>



<h2 class="wp-block-heading">1. WSL installieren</h2>



<p class="wp-block-paragraph">WSL stellt Windows-Benutzern ein vollständiges Linux-System über die Kommandozeile zur Verfügung – was weniger Overhead verursacht als eine VM. Da Software weltweit vor allem unter <a href="https://www.computerwoche.de/article/3614492/die-wichtigsten-linux-befehle-fur-einsteiger.html" target="_blank">Linux</a>– oder Unix-ähnlichen Systemen wie macOS entwickelt wird, ist das ein echter Vorteil. </p>



<p class="wp-block-paragraph">Um WSL zu installieren, öffnen Sie ein Konsolenfenster mit Administratorrechten und nutzen den Befehl:</p>



<pre class="wp-block-code"><code><code>wsl --install</code></code></pre>



<p class="wp-block-paragraph">Die Installation kann einige Zeit in Anspruch nehmen, da das System sowohl die Kernkomponenten für WSL als auch – damit zusammenhängend – eine Linux-Distribution herunterladen muss. </p>



<p class="wp-block-paragraph">Die Standard-Linux-Distribution in WSL ist <strong>Ubuntu 26.04 LTS</strong>. Diese erfüllt als Default-Lösung die meisten Anforderungen, die Entwickler an eine Linux-Distribution stellen. Es stehen jedoch auch andere Distributionen zur Verfügung – und es kommen regelmäßig neue hinzu. Sie könnten sogar Ihre eigene, <a href="https://learn.microsoft.com/de-de/windows/wsl/build-custom-distro">benutzerdefinierte Linux-Distribution für WSL</a> kreieren.</p>



<p class="wp-block-paragraph">Sobald WSL installiert ist, können Sie über den Befehl wsl –list –online alle verfügbaren Distributionen anzeigen. Um eine davon zu installieren, nutzen Sie den Befehl <code>wsl --install </code>. Die meisten verfügbaren Optionen sind auf unterschiedliche Vorlieben oder spezifische Anforderungen zugeschnitten. Wenn Sie beispielsweise an einem Projekt arbeiten, das Debian als Grundlage voraussetzt, sollten Sie das auch installieren.</p>



<p class="wp-block-paragraph">WSL-Distributionen werden standardmäßig im <code>AppData</code>-Verzeichnis abgelegt – genauer gesagt unter <code>AppData\Local\Packages\</code>. Wenn Sie die Dateien in ein anderes Verzeichnis oder auf ein anderes Laufwerk verschieben möchten, können Sie das mit dem Befehl <code>wsl --manage  --move </code> bewerkstelligen.</p>



<p class="wp-block-paragraph">Darüber hinaus hat Microsoft Ende Juni 2026 mit <a href="https://devblogs.microsoft.com/commandline/wsl-container-is-now-available-for-public-preview/" target="_blank" rel="noreferrer noopener">WSL-Container</a> (derzeit in der Public Preview) eine wichtige neue Funktion für WSL vorgestellt. Diese ermöglicht es, Linux-Container nativ unter Windows auszuführen.</p>



<h2 class="wp-block-heading">2. Dev-Drive-Laufwerk konfigurieren</h2>



<p class="wp-block-paragraph">Um Projekte zu speichern, nutzen die meisten Windows-Benutzer standardmäßig ein Verzeichnis auf einem NTFS-Volume – entweder im eigenen Benutzerprofil oder über einen anderen Pfad. Das ist als Default-Option keine schlechte Wahl. Allerdings gibt es bessere Alternativen.</p>



<p class="wp-block-paragraph">Zum Beispiel „<a href="https://learn.microsoft.com/de-de/windows/dev-drive/" target="_blank" rel="noreferrer noopener">Dev Drive</a>“, ein neuer Laufwerkstyp unter Windows. Dieser nutzt statt NTFS das neuere Dateisystem <a href="https://learn.microsoft.com/de-de/windows-server/storage/refs/refs-overview" target="_blank" rel="noreferrer noopener">ReFS</a> („Resilient File System“). Dieses wurde ursprünglich für Windows Server entwickelt und bietet Funktionen, die darauf ausgelegt sind, Softwareentwicklungs-Workloads besser zu bewältigen. Dazu gehören:  </p>



<ul class="wp-block-list">
<li><strong>Copy-on-Write: </strong>Projektverzeichnisse können Tausende von Dateien und Dutzende von Unterverzeichnissen enthalten. Kopien von Projekten dieser Art anzufertigen, lässt sich mit ReFS deutlich schneller bewältigen, da das Dateisystem Kopien von Daten erst dann erstellt, wenn diese auch <em>geändert</em> werden. Reine Kopien sind hingegen Links, die auf die Originale verweisen.</li>



<li><strong>Antivirus-Komfort:</strong> Über einen Dev Drive lassen sich die standardmäßigen Beeinträchtigungen durch die nativen Antivirus-Tools von Windows minimieren. Dieses Feature erlaubt es, Entwicklerverzeichnisse manuell von Scan-Vorgängen zu exkludieren.</li>



<li><strong>Virtuelle Festplatte oder Partition:</strong> Dev Drives können als virtuelle Festplattendatei eingerichtet oder direkt auf einer formatierten Partition genutzt werden. Ersteres ist flexibler (unter anderem lässt sich die Größe leichter anpassen), Letzteres möglicherweise performanter.</li>
</ul>



<p class="wp-block-paragraph">Zwei Dinge sollten Sie im Zusammenhang mit Dev Drives unbedingt beachten:</p>



<ol class="wp-block-list">
<li><strong>Dev Drives sind für Projekte gedacht, nicht für Tools:</strong> Dort legen Sie Ihre Projekt-Repositories, Build-Artefakte und zwischengespeicherte Dateien ab. Language Runtimes, <a href="https://www.computerwoche.de/article/4152349/so-wird-ki-zum-compiler.html" target="_blank">Compiler</a> oder anderen Toolchain-Utlities sollten hingegen auf regulären NTFS-Volumes gespeichert werden.</li>



<li><strong>Low-Level-Tools funktionieren unter Umständen nicht wie beabsichtigt:</strong> Dateisystem-Utilities auf Expertenniveau, die Informationen direkt aus den Dateiinformationen auslesen, verhalten sich im Zusammenspiel mit ReFS-Volumes möglicherweise nicht wie vorgesehen. So ist etwa das Speicherplatz-Management-Tool <a href="https://wize-tree.com/" target="_blank" rel="noreferrer noopener">WizTree</a> unter ReFS extrem langsam.</li>
</ol>



<h2 class="wp-block-heading">3. WinGet nutzen</h2>



<p class="wp-block-paragraph">Microsoft hat Windows inzwischen auch mit einem offiziellen Package-Management-System ausgestattet – WinGet. Dieses installiert jede Art von <a href="https://www.computerwoche.de/article/2824356/26-softwareperlen-fuer-windows-pcs.html" target="_blank">Windows-Applikation</a> und bietet zudem ein vollständiges Befehlszeilen-Interface für Interaktion und Automatisierung.    </p>



<p class="wp-block-paragraph">WinGet wird vom Windows-Software-Ökosystem umfassend unterstützt – die Wahrscheinlichkeit ist also groß, dass es für jedes Windows-Programm, das Sie benötigen, ein WinGet-Paket gibt (dazu gleich mehr).</p>



<p class="wp-block-paragraph">Um im WinGet-Repository nach einem Paket zu suchen, nutzen Sie diesen Befehl (die Anführungszeichen sind erforderlich, wenn der Name des gesuchten Pakets Leerzeichen enthält – etwa Adobe Acrobat Reader):</p>



<pre class="wp-block-code"><code><code>winget search "Thing to search for"</code></code></pre>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/image_481.png" alt="WinGet search output" class="wp-image-4196911" width="978" height="205" sizes="auto, (max-width: 978px) 100vw, 978px"><figcaption class="wp-element-caption">Der Output von WinGet bei der Suche nach dem Begriff „Acrobat“. Die „ID“-Spalte gibt den Namen aus, der mit dem Winget-Installationsbefehl zu verwenden ist.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">Das WinGet-Package zu installieren, geht denkbar simpel von der Hand – und zwar mit:</p>



<pre class="wp-block-code"><code><code>winget install </code></code></pre>



<p class="wp-block-paragraph">Dabei meint <code></code> die ID des zu installierenden Pakets – nicht bloß seinen Namen. Im vorgenannten Beispiel (Adobe Acrobat Reader) würden Sie also folgenden Befehl nutzen, um dieses zu installieren:</p>



<pre class="wp-block-code"><code><code>winget install Adobe.Acrobat.Reader.64-bit</code></code></pre>



<p class="wp-block-paragraph">Falls Sie eine ansprechende grafische Benutzeroberfläche suchen, empfiehlt sich ein Blick auf <a href="https://devolutions.net/unigetui/" target="_blank" rel="noreferrer noopener">UniGetUI</a>. Dieses Tool verwaltet Packages aus verschiedenen Quellen – etwa WinGet, Scoop, Chocolatey, npm, pip oder Cargo, um nur einige zu nennen.</p>



<h2 class="wp-block-heading">4. PowerShell für Skripte konfigurieren</h2>



<p class="wp-block-paragraph">Dieser Schritt ist lediglich einmal pro System zu absolvieren, kann jedoch die <a href="https://www.computerwoche.de/article/2834060/10-wege-zur-besseren-developer-experience.html" target="_blank">Entwicklererfahrung</a> von Windows gewaltig steigern: PowerShell sollte entsprechend konfiguriert werden, damit lokale Skripte ausgeführt werden können.   </p>



<p class="wp-block-paragraph">Um das zu bewerkstelligen, starten Sie PowerShell als Admin und nutzen folgendes Kommando:</p>



<pre class="wp-block-code"><code>set-executionpolicy remotesigned</code></pre>



<p class="wp-block-paragraph">Zwar verlangt Windows weiterhin, dass alle PowerShell-Skripte, die Sie aus dem Internet herunterladen, signiert sind – das ist jedoch im Grunde ein Edge Case. Alle lokal erstellten Skripte funktionieren nach dieser Maßnahme ohne Weiteres.</p>



<h2 class="wp-block-heading">5. Weitere Dev-Tools installieren</h2>



<p class="wp-block-paragraph">Wie bereits erwähnt, bietet WinGet schnellen Zugriff auf alle gängigen Tools, die ein entwicklungsorientiertes Windows-System benötigt. Nachfolgend haben wir eine kleine Übersicht der wichtigsten Dev-Tools für Windows inklusive deren WinGet-IDs zusammengestellt, um Ihnen die Installation zu erleichtern.</p>



<ul class="wp-block-list">
<li><strong>Git (</strong><code>Git.Git</code><strong>):</strong> Die Windows-Version des populären Versionskontrollsystems ist im Wesentlichen identisch mit der auf anderen Plattformen.</li>



<li><strong>Visual Studio BuildTools 2022 (</strong><code>Microsoft.VisualStudio.2022.BuildTools</code><strong>):</strong> Dieses minimale CLI-Tooling ist erforderlich, um das C/C++-Kompilierungssystem von Visual Studio zu nutzen.</li>



<li><strong>CMake (</strong><code>Kitware.Cmake</code><strong>):</strong> Die plattformübergreifende Build-Lösung wird häufig für größere oder komplexere Projekte benötigt, die C/C++ nutzen.</li>
</ul>



<p class="wp-block-paragraph">Dabei ist zu beachten, dass die standardmäßige BuildTools-Installation in der Regel nicht über die Tools verfügt, die für minimale C/C++-Build-Prozesse erforderlich sind. Das beheben Sie mit folgendem Befehl:</p>



<pre class="wp-block-code"><code>winget install -e --id Microsoft.VisualStudio.2022.BuildTools --force --override "--passive --wait --add Microsoft.VisualStudio.Workload.VCTools;includeRecommended"</code></pre>



<p class="wp-block-paragraph">Alle gängigen Editoren sind ebenfalls als native Windows-Apps über WinGet verfügbar – etwa:</p>



<ul class="wp-block-list">
<li><strong><a href="https://www.computerwoche.de/article/4199279/visual-studio-code-hat-ein-ki-problem.html" target="_blank">Microsoft Visual Studio Code</a></strong> (<code>Microsoft.VisualStudioCode</code>),</li>



<li><strong>GNU Emacs</strong> (<code>GNU.Emacs</code>), oder</li>



<li><strong>Neovim</strong> (<code>Neovim.Neovim</code>).</li>
</ul>



<p class="wp-block-paragraph">Für die Softwareentwicklung unter Windows optional, aber durchaus nützlich, sind außerdem folgende Werkzeuge:</p>



<ul class="wp-block-list">
<li><strong>CoreUtils for Windows (</strong><code>Microsoft.Coreutils</code><strong>):</strong> Ein von Microsoft gepflegtes Open-Source-Projekt, das <a href="https://github.com/microsoft/coreutils">Dutzende von Linux-Befehlszeilen-Dienstprogrammen</a> auf Windows bringt, beispielsweise cp, grep, find und ls.</li>



<li><strong>MSYS2 (</strong><code>MSYS2.MSYS2</code><strong>):</strong> Eine Tool-Sammlung, um Windows-Binärdateien mit dem GCC-Compiler zu erstellen. Diese bildet im Grunde eine Alternative zum Visual-Studio-Build-Stack auf Basis der <a href="https://cygwin.com/" target="_blank" rel="noreferrer noopener">Cygwin</a>-Umgebung.</li>



<li><strong>LLVM (</strong><code>LLVM.LLVM</code><strong>):</strong> Auf diesem Compiler-Framework basieren Clang, Rust, Swift und viele andere Projekte. Wenn Sie <a href="https://www.computerwoche.de/article/2826586/was-ist-llvm.html" target="_blank">LLVM</a> als Abhängigkeit verwenden, müssen Sie die spezifische Version installieren, die Ihr Projekt erfordert.</li>



<li><strong>Docker Desktop (</strong><code>XP8CBJ40XLBWKX</code><strong>):</strong> Die Windows-native Version der Docker-Desktop-App.</li>



<li><strong>Microsoft PowerToys (</strong><code>Microsoft.PowerToys</code><strong>):</strong> Diese Sammlung besteht aus über 30 Utilities, die es erheblich vereinfachen, <a href="https://www.computerwoche.de/article/3824755/microsoft-powertoys-ein-leitfaden.html" target="_blank">Windows anzupassen</a>. Dazu gehören unter anderem ein <a href="https://learn.microsoft.com/de-de/windows/powertoys/hosts-file-editor" target="_blank" rel="noreferrer noopener">Hosts-File-Editor</a>, ein <a href="https://learn.microsoft.com/de-de/windows/powertoys/file-locksmith" target="_blank" rel="noreferrer noopener">Unlocking-Tool für Dateien</a> (praktisch, um festzustellen, welche Prozesse eine bestimmte Datei sperren) sowie ein <a href="https://learn.microsoft.com/de-de/windows/powertoys/text-extractor" target="_blank" rel="noreferrer noopener">Werkzeug, um Text zu extrahieren</a> (praktisch, um Text von beliebigen Stellen auszulesen, einschließlich Bildschirmbereichen, die nicht mit dem Cursor markiert werden können).</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4196853/how-to-make-windows-a-proper-development-environment.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Static Residential Proxies vs ISP Proxies: What’s the Difference and Which Should You Choose?]]></title>
<description><![CDATA[Static residential proxies and ISP proxies are often mentioned together because they both provide stable IP addresses with excellent performance. However, despite their similarities, they are built differently and serve different use cases. If you’re involved in web scraping, market research, SEO...]]></description>
<link>https://tsecurity.de/de/3709503/it-security-nachrichten/static-residential-proxies-vs-isp-proxies-whats-the-difference-and-which-should-you-choose/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709503/it-security-nachrichten/static-residential-proxies-vs-isp-proxies-whats-the-difference-and-which-should-you-choose/</guid>
<pubDate>Fri, 07 Aug 2026 06:30:49 +0200</pubDate>
<content:encoded><![CDATA[<p>Static residential proxies and ISP proxies are often mentioned together because they both provide stable IP addresses with excellent performance. However, despite their similarities, they are built differently and serve different use cases. If you’re involved in web scraping, market research, SEO monitoring, ad verification, account management, cybersecurity testing, or anonymous browsing, choosing the right […]</p>
<p>The post <a href="https://secureblitz.com/static-residential-proxies-vs-isp-proxies/">Static Residential Proxies vs ISP Proxies: What’s the Difference and Which Should You Choose?</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lumen v2.2]]></title>
<description><![CDATA[this is a quick preview of my one click wallpaper management system. Its changes everything on the desktop and im currently working on it and its depend of the current wallpaper  here the github : https://github.com/tungsten-w/lumen It currently only works on hyprland and an arch-based distro (ar...]]></description>
<link>https://tsecurity.de/de/3709454/linux-tipps/lumen-v22/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709454/linux-tipps/lumen-v22/</guid>
<pubDate>Fri, 07 Aug 2026 04:40:12 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>this is a quick preview of my one click wallpaper management system. Its changes everything on the desktop and im currently working on it and its depend of the current wallpaper </p> <p>here the github : <a href="https://github.com/tungsten-w/lumen">https://github.com/tungsten-w/lumen</a><br> It currently only works on hyprland and an arch-based distro (arch/cachy os/endeavour)</p> <p>the little menu who is in the center of the screen is the wallpaper selecter and you can chose beetween 4 option </p> <p>- a dark wallpaper who use a themed dark theme </p> <p>- a light wallpapper who use a themed light theme </p> <p>- a random wallapaper depending of the curent time of the day (night/sunset/day..)</p> <p>- a random wallpapper depending of the curent season (summer spring autumn winter)</p> <p>im currently working on it so improve his stability and make it faster and easyer to install </p> <p>here a little yt video of how its actually works : <a href="https://www.youtube.com/watch?v=yqXrb4gw-Nk">https://www.youtube.com/watch?v=yqXrb4gw-Nk</a></p> <p>thanks you for your time ^^</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/No-Praline-2973"> /u/No-Praline-2973 </a> <br> <span><a href="https://i.redd.it/5kb5akve2uhh1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vhjgih/lumen_v22/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-22965 | Oracle Communications Policy Management 12.6.0.0.0 CMP code injection (Nessus ID 253555 / WID-SEC-2026-1955)]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, was found in Oracle Communications Policy Management 12.6.0.0.0. This vulnerability affects unknown code of the component CMP. Executing a manipulation can lead to code injection.

The identification of this vulnerability is CVE-2022-22965. ...]]></description>
<link>https://tsecurity.de/de/3709441/sicherheitsluecken/cve-2022-22965-oracle-communications-policy-management-126000-cmp-code-injection-nessus-id-253555-wid-sec-2026-1955/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709441/sicherheitsluecken/cve-2022-22965-oracle-communications-policy-management-126000-cmp-code-injection-nessus-id-253555-wid-sec-2026-1955/</guid>
<pubDate>Fri, 07 Aug 2026 04:33:23 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">very critical</a>, was found in <a href="https://vuldb.com/product/oracle:communications_policy_management">Oracle Communications Policy Management 12.6.0.0.0</a>. This vulnerability affects unknown code of the component <em>CMP</em>. Executing a manipulation can lead to code injection.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2022-22965">CVE-2022-22965</a>. The attack may be launched remotely. Furthermore, there is an exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-22965 | Oracle SD-WAN Edge 9.0/9.1 Management code injection (Nessus ID 253555 / WID-SEC-2026-1955)]]></title>
<description><![CDATA[A vulnerability was found in Oracle SD-WAN Edge 9.0/9.1. It has been rated as very critical. This affects an unknown function of the component Management. Performing a manipulation results in code injection.

This vulnerability is cataloged as CVE-2022-22965. It is possible to initiate the attack...]]></description>
<link>https://tsecurity.de/de/3709442/sicherheitsluecken/cve-2022-22965-oracle-sd-wan-edge-9091-management-code-injection-nessus-id-253555-wid-sec-2026-1955/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709442/sicherheitsluecken/cve-2022-22965-oracle-sd-wan-edge-9091-management-code-injection-nessus-id-253555-wid-sec-2026-1955/</guid>
<pubDate>Fri, 07 Aug 2026 04:33:23 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/oracle:sd-wan_edge">Oracle SD-WAN Edge 9.0/9.1</a>. It has been rated as <a href="https://vuldb.com/kb/risk">very critical</a>. This affects an unknown function of the component <em>Management</em>. Performing a manipulation results in code injection.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2022-22965">CVE-2022-22965</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-3418 | WSO2 API Control Plane System REST API unrestricted upload (WID-SEC-2026-2085)]]></title>
<description><![CDATA[A vulnerability was found in WSO2 API Control Plane, API Manager, API Manager Publisher REST API V4, API Manager Traffic Manager, Carbon API Management API, Carbon API Management Implementation and Universal Gateway. It has been declared as problematic. Impacted is an unknown function of the comp...]]></description>
<link>https://tsecurity.de/de/3709444/sicherheitsluecken/cve-2026-3418-wso2-api-control-plane-system-rest-api-unrestricted-upload-wid-sec-2026-2085/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709444/sicherheitsluecken/cve-2026-3418-wso2-api-control-plane-system-rest-api-unrestricted-upload-wid-sec-2026-2085/</guid>
<pubDate>Fri, 07 Aug 2026 04:33:23 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/wso2:api_control_plane">WSO2 API Control Plane, API Manager, API Manager Publisher REST API V4, API Manager Traffic Manager, Carbon API Management API, Carbon API Management Implementation and Universal Gateway</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is an unknown function of the component <em>System REST API</em>. Such manipulation leads to unrestricted upload.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-3418">CVE-2026-3418</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-3415 | WSO2 API Control Plane SchemaValidator Mediator resource consumption (WID-SEC-2026-2085)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in WSO2 API Control Plane, API Gateway, API Manager, Carbon API Gateway, Carbon API Management Implementation, Traffic Manager and Universal Gateway. The impacted element is an unknown function of the component SchemaValidator Mediato...]]></description>
<link>https://tsecurity.de/de/3709445/sicherheitsluecken/cve-2026-3415-wso2-api-control-plane-schemavalidator-mediator-resource-consumption-wid-sec-2026-2085/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709445/sicherheitsluecken/cve-2026-3415-wso2-api-control-plane-schemavalidator-mediator-resource-consumption-wid-sec-2026-2085/</guid>
<pubDate>Fri, 07 Aug 2026 04:33:23 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/wso2:api_control_plane">WSO2 API Control Plane, API Gateway, API Manager, Carbon API Gateway, Carbon API Management Implementation, Traffic Manager and Universal Gateway</a>. The impacted element is an unknown function of the component <em>SchemaValidator Mediator</em>. Executing a manipulation can lead to resource consumption.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-3415">CVE-2026-3415</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65667 | Microsoft Teams privileges management (EUVD-2026-54322)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Microsoft Teams. This affects an unknown function. The manipulation results in improper privilege management.

This vulnerability is identified as CVE-2026-65667. The attack can be executed remotely. There is not any exploit available...]]></description>
<link>https://tsecurity.de/de/3709448/sicherheitsluecken/cve-2026-65667-microsoft-teams-privileges-management-euvd-2026-54322/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709448/sicherheitsluecken/cve-2026-65667-microsoft-teams-privileges-management-euvd-2026-54322/</guid>
<pubDate>Fri, 07 Aug 2026 04:33:23 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/microsoft:teams">Microsoft Teams</a>. This affects an unknown function. The manipulation results in improper privilege management.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-65667">CVE-2026-65667</a>. The attack can be executed remotely. There is not any exploit available.

This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare wants to provide the operating system for the AI-first enterprise]]></title>
<description><![CDATA[Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.



The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and ...]]></description>
<link>https://tsecurity.de/de/3709405/ai-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709405/ai-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</guid>
<pubDate>Fri, 07 Aug 2026 03:42:40 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.</p>



<p class="wp-block-paragraph">The company this week announced <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-os-is-the-first-ai-workspace-built-around-how-companies-actually-work/" target="_blank" rel="noreferrer noopener">Cloudflare OS</a>, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open source and browser-based, sparing companies the need to build all-new infrastructure.</p>



<p class="wp-block-paragraph">The OS is launching alongside several other new security, identity, spending, and user insight tools that Cloudflare has built for the <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html" target="_blank">AI-based workplace</a>.</p>



<p class="wp-block-paragraph">“Cloudflare OS isn’t a traditional desktop OS,” said <a href="https://www.linkedin.com/in/ritakozlov/" target="_blank" rel="noreferrer noopener">Rita Kozlov</a>, VP of product at Cloudflare. “It reimagines the workplace computing environment for AI.”</p>



<h2 class="wp-block-heading">Open source OS runs in a browser</h2>



<p class="wp-block-paragraph">Cloudflare OS serves as a secure, AI-equipped workspace that is plugged into internal company systems. Available now through Cloudflare’s open source repository, it is accessible directly in a browser, and runs inside an enterprise’s Cloudflare account.</p>



<p class="wp-block-paragraph">“It is a browser-based workspace that begins with a conversation,” Kozlov explained. Users can ask an agent to research, create slides, spreadsheets, and documents, build full-stack apps, or automate workflows without the need for a terminal. Those outputs are then shareable, but kept in isolated databases with access controls.</p>



<p class="wp-block-paragraph">Enterprises will soon be able to access the OS directly through Cloudflare or via a “select group” of partners that will build tailored offerings on Cloudflare’s architecture, the company says. Because it is open source, organizational processes, internal system connections, and context aren’t locked into a vendor product or AI model provider. Customers can use whatever models they choose.</p>



<p class="wp-block-paragraph">Cloudflare OS is built on Cloudflare Workers, <a href="https://www.infoworld.com/article/4149869/cloudflare-launches-dynamic-workers-for-ai-agent-execution.html" target="_blank">Dynamic Workers</a>, Durable Objects, and Access, the company’s zero trust network access (ZTNA) tool that verifies every user and request. Agents start with zero permissions by default and are only granted access to tools required for a specific task. Organizations configure their own Access policies, models, branding, skills, and integrations, Kozlov explained.</p>



<p class="wp-block-paragraph">Governed connectors known as gatekeepers give admins control over what AI can see, what it can change, and when the system needs human sign-off. They can also control budgets, set rate limits, and delegate tasks to different models.</p>



<p class="wp-block-paragraph">“Because <a href="https://www.infoworld.com/article/4165857/are-we-ready-to-give-ai-agents-the-keys-to-the-cloud-cloudflare-thinks-so.html" target="_blank">agents act on people’s behalf</a> and produce work others can access and modify, they require a new security model,” Kozlov said. Thus, Cloudflare OS tracks the resources an agent requires so the right access controls follow its work when it is shared.</p>



<p class="wp-block-paragraph">Cloudflare initially built the OS for internal use, and employees “across every team” use it daily. Kozlov estimated that, over the last 30 days, internal users have used it to create more than 4,000 apps, automations, and tools. Over that same period, she claimed, the company’s sales team saved an estimated 10,000 hours by automating previously manual tasks like territory planning and proposal creation.</p>



<p class="wp-block-paragraph">“We open sourced Cloudflare OS so any organization can build ‘Your Company OS,’” Kozlov said. Open source is critical because “you cannot put your company into software you do not own. Organizations need to be able to inspect the platform, customize it, connect their own systems, and make it their own,” she explained.</p>



<h2 class="wp-block-heading">A more cohesive bundle</h2>



<p class="wp-block-paragraph">Cloudflare deserves credit for packaging Cloudflare OS as an operating system, noted tech analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a>.</p>



<p class="wp-block-paragraph">“This very much is not Windows, macOS, or Linux, and it isn’t an operating system by its common definition,” he said. “But Cloudflare’s use of this terminology implies familiarity to enterprise IT buyers.”</p>



<p class="wp-block-paragraph">This makes for an easier discussion as enterprises struggle to understand how to best incorporate AI-related platforms and workflows into infrastructure that wasn’t initially designed for it.</p>



<p class="wp-block-paragraph">Microsoft has marketed the combination of its Azure, Entra, Fabric, Windows, and Microsoft 365 offerings as an operating system of sorts, but hasn’t pulled all the pieces into a common brand, Levy said. And Google’s Gemini, Workspace, Vertex AI, and Cloud Run are “circling similar territory.”</p>



<p class="wp-block-paragraph">But, he noted, Cloudflare OS is “more cohesively bundled” and infrastructure-focused, offering a single pane of glass platform for buyers worried about stitching together otherwise disparate AI-aware networking pieces. The company recognizes that AI introduces new architectural realities such as inference and model routing “over and above” traditional OS core competencies.</p>



<p class="wp-block-paragraph">“While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor, which potentially frees IT planners from having to integrate all the AI pieces on their own,” Levy said.</p>



<p class="wp-block-paragraph">An infrastructure-first, application-agnostic approach means Cloudflare OS can coexist with whatever AI applications already exist in an enterprise, he said. It will “play nice” with OpenAI, Anthropic, Google, Microsoft, Meta, or open source layers, allowing employees to begin working in familiar workflows after sign-in.</p>



<p class="wp-block-paragraph">“Its open-source architecture also minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities,” Levy said.</p>



<h2 class="wp-block-heading">Managing identities and budgets for both humans and AI</h2>



<p class="wp-block-paragraph">As AI agents emerge across the enterprise, tracking their use can be challenging, causing problems from both a security and a spend standpoint. Along with Cloudflare OS, the company has launched a way to address this issue with its new <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-gives-companies-full-visibility-to-audit-and-analyze-ai-use/" target="_blank" rel="noreferrer noopener">Identity-Aware AI Gateway</a>, now in beta.</p>



<p class="wp-block-paragraph">Also integrated with Access, the offering gives admins visibility into what users (both human and AI) are requesting from AI models. It allows security teams to set up custom domains in front of their gateways and replace shared API keys by integrating with their identity provider, like Okta or Entra, and ZTNA infrastructure, Cloudflare explained.</p>



<p class="wp-block-paragraph">Every request is tied to Access-verified identities, and enterprises can filter each user’s logs, analytics, and spend. IT teams can track redundancies, limit usage rates, and apply filters that strip out employee names, passwords, and other sensitive data before requests go to outside model providers.</p>



<p class="wp-block-paragraph">A companion feature, AI Spend, tracks every user’s behavior over time to create a baseline of normal AI usage. When spending deviates from that pattern, the system alerts the IT team.</p>



<p class="wp-block-paragraph">A new tab, User Insights, tracks cost and identifies over-spend caused by activities such as low cache-hit rates or oversized context windows. The capability scores sessions and compares them against account history using a 95th percentile session cost over the previous 30 days, Cloudflare product managers <a href="https://blog.cloudflare.com/author/ming-lu/" target="_blank" rel="noreferrer noopener">Ming Lu</a>, <a href="https://blog.cloudflare.com/author/kenny/" target="_blank" rel="noreferrer noopener">Kenny Johnson</a>, and <a href="https://blog.cloudflare.com/author/ayush/" target="_blank" rel="noreferrer noopener">Ayush Kumar</a> explain in a <a href="https://blog.cloudflare.com/identity-aware-ai-gateway/" target="_blank" rel="noreferrer noopener">blog post</a>. Anything above 2x an account’s 95th percentile is a “strong candidate for anomalous behavior.”</p>



<p class="wp-block-paragraph">For instance, one Cloudflare customer had an employee who left a rogue AI session running, generating a $30K bill. “User Insights helped them identify the problem and shut off access before the problem was further exacerbated,” Kozlov said.</p>



<p class="wp-block-paragraph">Cloudflare is also building prompt classification functionality that sorts requests into categories such as coding or writing. This can help enterprises understand what AI is being used for.</p>



<p class="wp-block-paragraph">“Once business traffic is separated from everything else, personal use becomes visible,” the project managers explained. “From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk.”</p>



<h2 class="wp-block-heading">Looking at the bigger picture</h2>



<p class="wp-block-paragraph">Identity-Aware AI Gateway and AI Spend address the visibility problem that has dogged so many recent AI deployments where enterprises failed to monitor usage, Levy noted. Projects “crashed and burned” as users unwittingly blew through token allocations.</p>



<p class="wp-block-paragraph">These platforms provide single-point visibility into what is being used, how it’s being used, and where the potential lies for raising the productivity bar, he said. They overlay with existing models; in doing so, they enhance security with more precise control over resource allocations, and via automated anonymization protocols that prevent inadvertent sharing of sensitive data.</p>



<p class="wp-block-paragraph">Ultimately, he said, vendors who free IT from having to independently assemble the pieces of their own AI implementations, and who assist them with answers to AI-specific questions, “will gain advantage over vendors that aren’t looking at the bigger picture.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4206332/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-3609 | Wellbia XIGNCODE3 Anti-Cheat 10.0.10011.16384 xhunter1.sys IRP_MJ_REITS privileges management]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Wellbia XIGNCODE3 Anti-Cheat 10.0.10011.16384. This issue affects the function IRP_MJ_REITS in the library xhunter1.sys. Performing a manipulation results in improper privilege management.

This vulnerability is known as CVE-202...]]></description>
<link>https://tsecurity.de/de/3709338/sicherheitsluecken/cve-2026-3609-wellbia-xigncode3-anti-cheat-1001001116384-xhunter1sys-irpmjreits-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709338/sicherheitsluecken/cve-2026-3609-wellbia-xigncode3-anti-cheat-1001001116384-xhunter1sys-irpmjreits-privileges-management/</guid>
<pubDate>Fri, 07 Aug 2026 03:30:58 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/wellbia:xigncode3_anti-cheat">Wellbia XIGNCODE3 Anti-Cheat 10.0.10011.16384</a>. This issue affects the function <code>IRP_MJ_REITS</code> in the library <em>xhunter1.sys</em>. Performing a manipulation results in improper privilege management.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-3609">CVE-2026-3609</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41530 | Open Source SACCO Management System 1.0 ajax.php?action=delete_borrower ID sql injection (EUVD-2022-44723)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Open Source SACCO Management System 1.0. This impacts an unknown function of the file /sacco_shield/ajax.php?action=delete_borrower. Such manipulation of the argument ID leads to sql injection.

This vulnerability is referenced as CVE-2022-41530...]]></description>
<link>https://tsecurity.de/de/3709305/sicherheitsluecken/cve-2022-41530-open-source-sacco-management-system-10-ajaxphpactiondeleteborrower-id-sql-injection-euvd-2022-44723/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709305/sicherheitsluecken/cve-2022-41530-open-source-sacco-management-system-10-ajaxphpactiondeleteborrower-id-sql-injection-euvd-2022-44723/</guid>
<pubDate>Fri, 07 Aug 2026 03:30:39 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/open_source_sacco_management_system">Open Source SACCO Management System 1.0</a>. This impacts an unknown function of the file <em>/sacco_shield/ajax.php?action=delete_borrower</em>. Such manipulation of the argument <em>ID</em> leads to sql injection.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2022-41530">CVE-2022-41530</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41532 | Open Source SACCO Management System 1.0 ajax.php?action=delete_plan ID sql injection (EUVD-2022-44725)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Open Source SACCO Management System 1.0. Affected is an unknown function of the file /sacco_shield/ajax.php?action=delete_plan. Performing a manipulation of the argument ID results in sql injection.

This vulnerability is identi...]]></description>
<link>https://tsecurity.de/de/3709303/sicherheitsluecken/cve-2022-41532-open-source-sacco-management-system-10-ajaxphpactiondeleteplan-id-sql-injection-euvd-2022-44725/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709303/sicherheitsluecken/cve-2022-41532-open-source-sacco-management-system-10-ajaxphpactiondeleteplan-id-sql-injection-euvd-2022-44725/</guid>
<pubDate>Fri, 07 Aug 2026 03:30:38 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/open_source_sacco_management_system">Open Source SACCO Management System 1.0</a>. Affected is an unknown function of the file <em>/sacco_shield/ajax.php?action=delete_plan</em>. Performing a manipulation of the argument <em>ID</em> results in sql injection.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-41532">CVE-2022-41532</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41533 | SourceCodester Online Diagnostic Lab Management System 1.0 editProductImage.php unrestricted upload (EUVD-2022-44726)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in SourceCodester Online Diagnostic Lab Management System 1.0. This issue affects some unknown processing of the file /php_action/editProductImage.php. The manipulation results in unrestricted upload.

This vulnerability is identified a...]]></description>
<link>https://tsecurity.de/de/3709304/sicherheitsluecken/cve-2022-41533-sourcecodester-online-diagnostic-lab-management-system-10-editproductimagephp-unrestricted-upload-euvd-2022-44726/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709304/sicherheitsluecken/cve-2022-41533-sourcecodester-online-diagnostic-lab-management-system-10-editproductimagephp-unrestricted-upload-euvd-2022-44726/</guid>
<pubDate>Fri, 07 Aug 2026 03:30:38 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/sourcecodester:online_diagnostic_lab_management_system">SourceCodester Online Diagnostic Lab Management System 1.0</a>. This issue affects some unknown processing of the file <em>/php_action/editProductImage.php</em>. The manipulation results in unrestricted upload.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-41533">CVE-2022-41533</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker nehmen Wall Street mit Telefontrick ins Visier - news.ORF.at]]></title>
<description><![CDATA[Zu den Zielen gehörten Finanzinvestoren wie Blackstone, KKR und Apollo Global Management, wie aus einem heute veröffentlichten Bericht von Google und ...]]></description>
<link>https://tsecurity.de/de/3709300/hacking/hacker-nehmen-wall-street-mit-telefontrick-ins-visier-newsorfat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709300/hacking/hacker-nehmen-wall-street-mit-telefontrick-ins-visier-newsorfat/</guid>
<pubDate>Fri, 07 Aug 2026 03:19:53 +0200</pubDate>
<content:encoded><![CDATA[Zu den Zielen gehörten Finanzinvestoren wie Blackstone, KKR und Apollo Global Management, wie aus einem heute veröffentlichten Bericht von Google und ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat 2026: Barracuda Details AI-Powered BEC Attack ]]></title>
<description><![CDATA[Barracuda's Black Hat USA 2026 research shows how AI email assistants can accelerate business email compromise attacks.
The post Black Hat 2026: Barracuda Details AI-Powered BEC Attack  appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3709265/it-security-nachrichten/black-hat-2026-barracuda-details-ai-powered-bec-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709265/it-security-nachrichten/black-hat-2026-barracuda-details-ai-powered-bec-attack/</guid>
<pubDate>Fri, 07 Aug 2026 02:50:13 +0200</pubDate>
<content:encoded><![CDATA[<p>Barracuda's Black Hat USA 2026 research shows how AI email assistants can accelerate business email compromise attacks.</p>
<p>The post <a href="https://www.esecurityplanet.com/threats/black-hat-2026-barracuda-details-ai-powered-bec-attack/">Black Hat 2026: Barracuda Details AI-Powered BEC Attack </a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why exposure management is replacing vulnerability management]]></title>
<description><![CDATA[Vulnerability management isn’t failing because security teams lack visibility. Most organizations already have more findings than they can reasonably address. Yet despite all those findings, many CISOs still struggle to answer a deceptively simple question: Are we actually becoming harder to atta...]]></description>
<link>https://tsecurity.de/de/3709263/it-security-nachrichten/why-exposure-management-is-replacing-vulnerability-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709263/it-security-nachrichten/why-exposure-management-is-replacing-vulnerability-management/</guid>
<pubDate>Fri, 07 Aug 2026 02:50:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Vulnerability management isn’t failing because security teams lack visibility. Most organizations already have more findings than they can reasonably address. Yet despite all those findings, many CISOs still struggle to answer a deceptively simple question: Are we actually becoming harder to attack?</p>



<p class="wp-block-paragraph">That question sits at the center of a growing problem. Security programs have become very good at finding issues, but finding issues and reducing risk are not the same thing. In many organizations, those two concepts have become interchangeable, which is exactly why traditional vulnerability management is beginning to break down.</p>



<p class="wp-block-paragraph">The underlying assumption behind vulnerability management is straightforward. If you can identify vulnerabilities, prioritize them, and patch them, risk should decrease. That logic worked reasonably well when environments were smaller, infrastructure changed at a slower pace, and vulnerabilities were treated as the primary indicator of risk.</p>



<p class="wp-block-paragraph">Today’s environments operate differently. Vulnerabilities are rarely encountered in isolation and are often only one component of a broader security problem. The challenge is no longer finding vulnerabilities. The challenge is understanding exposure.</p>



<p class="wp-block-paragraph">This shift is one reason the Gartner<sup>®</sup> Continuous Threat Exposure Management (CTEM) framework has gained traction. At its core, the framework recognizes that understanding risk requires looking beyond individual vulnerabilities and evaluating the broader exposures that attackers can actually exploit.</p>



<h2 class="wp-block-heading">Why prioritization keeps falling short</h2>



<p class="wp-block-paragraph">The challenge becomes apparent when organizations try to prioritize risk. Traditional vulnerability management evaluates findings individually, often using severity scores as a proxy for risk. Attackers take a different approach. They evaluate how weaknesses connect, what access they provide, and how they can be combined to reach a meaningful objective.</p>



<p class="wp-block-paragraph">That distinction matters because severity and risk are not the same thing. A critical vulnerability that cannot be reached or exploited may represent very little practical risk. Meanwhile, a lower-severity issue combined with weak credentials, excessive permissions, or a misconfigured identity relationship can create a direct path to sensitive systems and data.</p>



<p class="wp-block-paragraph">Attackers understand this instinctively. They do not attack vulnerabilities one at a time. They chain weaknesses together, move laterally across environments, escalate privileges, and pursue the path that gets them closest to their objective.</p>



<h2 class="wp-block-heading">Severity is not risk</h2>



<p class="wp-block-paragraph">One of the biggest reasons vulnerability management efforts struggle today is that severity has become a stand-in for risk. It is easy to understand why. Severity scores provide a standardized way to compare findings, helping teams sort large volumes of vulnerabilities and establish remediation priorities.</p>



<p class="wp-block-paragraph">A vulnerability only matters if it contributes to an attacker’s ability to achieve an objective, whether that objective is accessing sensitive data, escalating privileges, or moving laterally through an environment. In every case, the question is not, “How severe is this vulnerability?” but rather, “Can this weakness be used as part of a path to something valuable?”</p>



<p class="wp-block-paragraph">Those are fundamentally different questions. One measures the characteristics of a finding. The other evaluates the opportunity it creates for an attacker. As environments become more interconnected, the gap between those perspectives continues to grow.</p>



<h2 class="wp-block-heading">Exposure is bigger than vulnerabilities</h2>



<p class="wp-block-paragraph">Visibility tells you what vulnerabilities exist. Exposure tells you how attackers can use them.</p>



<p class="wp-block-paragraph">That distinction is becoming increasingly important because exposure is broader than a vulnerability. It includes the relationships between weaknesses, identities, permissions, assets, trust relationships, and business systems that create opportunities for attackers.</p>



<p class="wp-block-paragraph">A vulnerability may contribute to exposure, but it is rarely the entire story. Consider a lower-severity vulnerability that exists on a system with excessive permissions. By itself, neither issue may appear urgent. Together, they may provide a direct path to sensitive data or critical infrastructure.</p>



<p class="wp-block-paragraph">Now consider an attacker who compromises a low-value system. In a traditional vulnerability management model, the focus remains on the vulnerability that enabled access. In an exposure management model, the focus shifts to what happens next: </p>



<ul class="wp-block-list">
<li>What can the attacker reach? </li>



<li>Which identities can be abused? </li>



<li>What permissions can be leveraged? </li>



<li>What systems become accessible?</li>
</ul>



<p class="wp-block-paragraph">The vulnerability may have enabled the intrusion, but the exposure determines the impact. That is why understanding exposure requires looking beyond individual findings and evaluating how weaknesses interact across the environment.</p>



<p class="wp-block-paragraph">The same principle applies across cloud environments, identity systems, Active Directory, third-party access, and hybrid environments. Attackers do not compromise organizations because a vulnerability exists. They compromise organizations because multiple conditions create an opportunity to reach something valuable.</p>



<p class="wp-block-paragraph">That is the definition of exposure.</p>



<h2 class="wp-block-heading">Why exposure management is replacing vulnerability management</h2>



<p class="wp-block-paragraph">Attackers have already made this shift. The industry is finally catching up.</p>



<p class="wp-block-paragraph">Vulnerability management helped organizations understand what was broken. Exposure management helps organizations understand what attackers can actually do.</p>



<p class="wp-block-paragraph">As environments become more interconnected, the goal is no longer to identify every vulnerability. The goal is to understand which combinations of weaknesses create meaningful risk and where action will reduce that risk most effectively.</p>



<p class="wp-block-paragraph">For CISOs, that changes the conversation.</p>



<p class="wp-block-paragraph">Instead of asking:</p>



<ul class="wp-block-list">
<li>How many vulnerabilities do we have?</li>



<li>How quickly are we patching them?</li>
</ul>



<p class="wp-block-paragraph">The more important questions become:</p>



<ul class="wp-block-list">
<li>What can an attacker actually reach?</li>



<li>Which exposures create meaningful business risk?</li>



<li>What should we fix first?</li>



<li>Are we becoming harder to attack?</li>
</ul>



<p class="wp-block-paragraph">Those are exposure management questions. And as attackers gain new ways to identify and exploit opportunities at machine speed, they are increasingly the questions that matter most.</p>



<p class="wp-block-paragraph">Explore how organizations are operationalizing exposure management through CTEM by <a href="https://horizon3.ai/downloads/whitepapers/operationalizing-ctem-practical-playbook/" target="_blank" rel="noreferrer noopener">downloading</a> the “<a href="https://horizon3.ai/downloads/whitepapers/operationalizing-ctem-practical-playbook/" target="_blank" rel="noreferrer noopener"><em>Operationalizing CTEM: A Practical Playbook for Continuous Threat Exposure Management.”</em> </a>You’ll learn how leading teams are moving beyond visibility and building programs focused on measurable exposure reduction. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 10 Best Firewall Management Tools in 2026]]></title>
<description><![CDATA[Most firewall breaches aren’t firewall failures they’re rule failures: shadowed policies, forgotten any-any entries, changes nobody risk-checked. Firewall…
Read more →
The post Top 10 Best Firewall Management Tools in 2026 appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3709249/it-security-nachrichten/top-10-best-firewall-management-tools-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709249/it-security-nachrichten/top-10-best-firewall-management-tools-in-2026/</guid>
<pubDate>Fri, 07 Aug 2026 02:49:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Most firewall breaches aren’t firewall failures they’re rule failures: shadowed policies, forgotten any-any entries, changes nobody risk-checked. Firewall…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/top-10-best-firewall-management-tools-in-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/top-10-best-firewall-management-tools-in-2026/">Top 10 Best Firewall Management Tools in 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare wants to provide the operating system for the AI-first enterprise]]></title>
<description><![CDATA[Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.



The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and ...]]></description>
<link>https://tsecurity.de/de/3709231/it-security-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709231/it-security-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</guid>
<pubDate>Fri, 07 Aug 2026 02:38:25 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.</p>



<p class="wp-block-paragraph">The company this week announced <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-os-is-the-first-ai-workspace-built-around-how-companies-actually-work/" target="_blank" rel="noreferrer noopener">Cloudflare OS</a>, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open source and browser-based, sparing companies the need to build all-new infrastructure.</p>



<p class="wp-block-paragraph">The OS is launching alongside several other new security, identity, spending, and user insight tools that Cloudflare has built for the <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html" target="_blank">AI-based workplace</a>.</p>



<p class="wp-block-paragraph">“Cloudflare OS isn’t a traditional desktop OS,” said <a href="https://www.linkedin.com/in/ritakozlov/" target="_blank" rel="noreferrer noopener">Rita Kozlov</a>, VP of product at Cloudflare. “It reimagines the workplace computing environment for AI.”</p>



<h2 class="wp-block-heading">Open source OS runs in a browser</h2>



<p class="wp-block-paragraph">Cloudflare OS serves as a secure, AI-equipped workspace that is plugged into internal company systems. Available now through Cloudflare’s open source repository, it is accessible directly in a browser, and runs inside an enterprise’s Cloudflare account.</p>



<p class="wp-block-paragraph">“It is a browser-based workspace that begins with a conversation,” Kozlov explained. Users can ask an agent to research, create slides, spreadsheets, and documents, build full-stack apps, or automate workflows without the need for a terminal. Those outputs are then shareable, but kept in isolated databases with access controls.</p>



<p class="wp-block-paragraph">Enterprises will soon be able to access the OS directly through Cloudflare or via a “select group” of partners that will build tailored offerings on Cloudflare’s architecture, the company says. Because it is open source, organizational processes, internal system connections, and context aren’t locked into a vendor product or AI model provider. Customers can use whatever models they choose.</p>



<p class="wp-block-paragraph">Cloudflare OS is built on Cloudflare Workers, <a href="https://www.infoworld.com/article/4149869/cloudflare-launches-dynamic-workers-for-ai-agent-execution.html" target="_blank">Dynamic Workers</a>, Durable Objects, and Access, the company’s zero trust network access (ZTNA) tool that verifies every user and request. Agents start with zero permissions by default and are only granted access to tools required for a specific task. Organizations configure their own Access policies, models, branding, skills, and integrations, Kozlov explained.</p>



<p class="wp-block-paragraph">Governed connectors known as gatekeepers give admins control over what AI can see, what it can change, and when the system needs human sign-off. They can also control budgets, set rate limits, and delegate tasks to different models.</p>



<p class="wp-block-paragraph">“Because <a href="https://www.infoworld.com/article/4165857/are-we-ready-to-give-ai-agents-the-keys-to-the-cloud-cloudflare-thinks-so.html" target="_blank">agents act on people’s behalf</a> and produce work others can access and modify, they require a new security model,” Kozlov said. Thus, Cloudflare OS tracks the resources an agent requires so the right access controls follow its work when it is shared.</p>



<p class="wp-block-paragraph">Cloudflare initially built the OS for internal use, and employees “across every team” use it daily. Kozlov estimated that, over the last 30 days, internal users have used it to create more than 4,000 apps, automations, and tools. Over that same period, she claimed, the company’s sales team saved an estimated 10,000 hours by automating previously manual tasks like territory planning and proposal creation.</p>



<p class="wp-block-paragraph">“We open sourced Cloudflare OS so any organization can build ‘Your Company OS,’” Kozlov said. Open source is critical because “you cannot put your company into software you do not own. Organizations need to be able to inspect the platform, customize it, connect their own systems, and make it their own,” she explained.</p>



<h2 class="wp-block-heading">A more cohesive bundle</h2>



<p class="wp-block-paragraph">Cloudflare deserves credit for packaging Cloudflare OS as an operating system, noted tech analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a>.</p>



<p class="wp-block-paragraph">“This very much is not Windows, macOS, or Linux, and it isn’t an operating system by its common definition,” he said. “But Cloudflare’s use of this terminology implies familiarity to enterprise IT buyers.”</p>



<p class="wp-block-paragraph">This makes for an easier discussion as enterprises struggle to understand how to best incorporate AI-related platforms and workflows into infrastructure that wasn’t initially designed for it.</p>



<p class="wp-block-paragraph">Microsoft has marketed the combination of its Azure, Entra, Fabric, Windows, and Microsoft 365 offerings as an operating system of sorts, but hasn’t pulled all the pieces into a common brand, Levy said. And Google’s Gemini, Workspace, Vertex AI, and Cloud Run are “circling similar territory.”</p>



<p class="wp-block-paragraph">But, he noted, Cloudflare OS is “more cohesively bundled” and infrastructure-focused, offering a single pane of glass platform for buyers worried about stitching together otherwise disparate AI-aware networking pieces. The company recognizes that AI introduces new architectural realities such as inference and model routing “over and above” traditional OS core competencies.</p>



<p class="wp-block-paragraph">“While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor, which potentially frees IT planners from having to integrate all the AI pieces on their own,” Levy said.</p>



<p class="wp-block-paragraph">An infrastructure-first, application-agnostic approach means Cloudflare OS can coexist with whatever AI applications already exist in an enterprise, he said. It will “play nice” with OpenAI, Anthropic, Google, Microsoft, Meta, or open source layers, allowing employees to begin working in familiar workflows after sign-in.</p>



<p class="wp-block-paragraph">“Its open-source architecture also minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities,” Levy said.</p>



<h2 class="wp-block-heading">Managing identities and budgets for both humans and AI</h2>



<p class="wp-block-paragraph">As AI agents emerge across the enterprise, tracking their use can be challenging, causing problems from both a security and a spend standpoint. Along with Cloudflare OS, the company has launched a way to address this issue with its new <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-gives-companies-full-visibility-to-audit-and-analyze-ai-use/" target="_blank" rel="noreferrer noopener">Identity-Aware AI Gateway</a>, now in beta.</p>



<p class="wp-block-paragraph">Also integrated with Access, the offering gives admins visibility into what users (both human and AI) are requesting from AI models. It allows security teams to set up custom domains in front of their gateways and replace shared API keys by integrating with their identity provider, like Okta or Entra, and ZTNA infrastructure, Cloudflare explained.</p>



<p class="wp-block-paragraph">Every request is tied to Access-verified identities, and enterprises can filter each user’s logs, analytics, and spend. IT teams can track redundancies, limit usage rates, and apply filters that strip out employee names, passwords, and other sensitive data before requests go to outside model providers.</p>



<p class="wp-block-paragraph">A companion feature, AI Spend, tracks every user’s behavior over time to create a baseline of normal AI usage. When spending deviates from that pattern, the system alerts the IT team.</p>



<p class="wp-block-paragraph">A new tab, User Insights, tracks cost and identifies over-spend caused by activities such as low cache-hit rates or oversized context windows. The capability scores sessions and compares them against account history using a 95th percentile session cost over the previous 30 days, Cloudflare product managers <a href="https://blog.cloudflare.com/author/ming-lu/" target="_blank" rel="noreferrer noopener">Ming Lu</a>, <a href="https://blog.cloudflare.com/author/kenny/" target="_blank" rel="noreferrer noopener">Kenny Johnson</a>, and <a href="https://blog.cloudflare.com/author/ayush/" target="_blank" rel="noreferrer noopener">Ayush Kumar</a> explain in a <a href="https://blog.cloudflare.com/identity-aware-ai-gateway/" target="_blank" rel="noreferrer noopener">blog post</a>. Anything above 2x an account’s 95th percentile is a “strong candidate for anomalous behavior.”</p>



<p class="wp-block-paragraph">For instance, one Cloudflare customer had an employee who left a rogue AI session running, generating a $30K bill. “User Insights helped them identify the problem and shut off access before the problem was further exacerbated,” Kozlov said.</p>



<p class="wp-block-paragraph">Cloudflare is also building prompt classification functionality that sorts requests into categories such as coding or writing. This can help enterprises understand what AI is being used for.</p>



<p class="wp-block-paragraph">“Once business traffic is separated from everything else, personal use becomes visible,” the project managers explained. “From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk.”</p>



<h2 class="wp-block-heading">Looking at the bigger picture</h2>



<p class="wp-block-paragraph">Identity-Aware AI Gateway and AI Spend address the visibility problem that has dogged so many recent AI deployments where enterprises failed to monitor usage, Levy noted. Projects “crashed and burned” as users unwittingly blew through token allocations.</p>



<p class="wp-block-paragraph">These platforms provide single-point visibility into what is being used, how it’s being used, and where the potential lies for raising the productivity bar, he said. They overlay with existing models; in doing so, they enhance security with more precise control over resource allocations, and via automated anonymization protocols that prevent inadvertent sharing of sensitive data.</p>



<p class="wp-block-paragraph">Ultimately, he said, vendors who free IT from having to independently assemble the pieces of their own AI implementations, and who assist them with answers to AI-specific questions, “will gain advantage over vendors that aren’t looking at the bigger picture.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dawn of the neoclouds — the rise of a new class of hyperscaler is here. But can they dominate the AI era?]]></title>
<description><![CDATA[New cloud businesses have emerged from the ashes of the bitcoin mining era to prove themselves worthy of inclusion at the heart of the AI infrastructure buildout. Will they succeed, or will they sink under the weight of extreme business risks?]]></description>
<link>https://tsecurity.de/de/3709228/it-security-nachrichten/dawn-of-the-neoclouds-the-rise-of-a-new-class-of-hyperscaler-is-here-but-can-they-dominate-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709228/it-security-nachrichten/dawn-of-the-neoclouds-the-rise-of-a-new-class-of-hyperscaler-is-here-but-can-they-dominate-the-ai-era/</guid>
<pubDate>Fri, 07 Aug 2026 02:36:20 +0200</pubDate>
<content:encoded><![CDATA[New cloud businesses have emerged from the ashes of the bitcoin mining era to prove themselves worthy of inclusion at the heart of the AI infrastructure buildout. Will they succeed, or will they sink under the weight of extreme business risks?]]></content:encoded>
</item>
<item>
<title><![CDATA['Tower Dump' Warrants Ruled Unconstitutional]]></title>
<description><![CDATA[alternative_right shares a report from The Hill: A federal judge in Mississippi ruled Wednesday that "tower dump" warrants are unconstitutional, declining to reverse a lower court decision refusing the government's request to obtain the search warrants in a series of violent crime investigations....]]></description>
<link>https://tsecurity.de/de/3709216/it-security-nachrichten/tower-dump-warrants-ruled-unconstitutional/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709216/it-security-nachrichten/tower-dump-warrants-ruled-unconstitutional/</guid>
<pubDate>Fri, 07 Aug 2026 02:35:27 +0200</pubDate>
<content:encoded><![CDATA[alternative_right shares a report from The Hill: A federal judge in Mississippi ruled Wednesday that "tower dump" warrants are unconstitutional, declining to reverse a lower court decision refusing the government's request to obtain the search warrants in a series of violent crime investigations. A "tower dump" involves cellphone companies providing law enforcement with access to the time and location data of all mobile devices connected to specific cell towers during a designated time window.
 
Law enforcement had sought approval for several of these search warrants as part of criminal investigations into gang-related activity in the Jackson, Miss., area last year, arguing the data could help identify all those potentially involved, particularly in incidents with unknown suspects. A magistrate judge denied the applications, holding that "tower dumps" are impermissible general warrants. The district judge agreed. The order repeatedly referenced the Supreme Court's recent decision in Chatrie v United States, in which the majority held that geofence warrants require constitutional privacy protections.
 
"With this information, the Government asserts that it will be able to identify all potential suspects," Judge Carlton Reeves wrote in a 30-page order (PDF). "Even so, law enforcement would also have access to the cellular records of countless individuals, the vast majority of whom were merely passing by a location at the 'wrong' time."
 
 "That is an unreasonable search under the Fourth Amendment," the judge concluded.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status='Tower+Dump'+Warrants+Ruled+Unconstitutional%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F06%2F2147247%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F06%2F2147247%2Ftower-dump-warrants-ruled-unconstitutional%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/08/06/2147247/tower-dump-warrants-ruled-unconstitutional?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare wants to provide the operating system for the AI-first enterprise]]></title>
<description><![CDATA[Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.



The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and ...]]></description>
<link>https://tsecurity.de/de/3709211/it-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709211/it-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</guid>
<pubDate>Fri, 07 Aug 2026 02:35:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.</p>



<p class="wp-block-paragraph">The company this week announced <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-os-is-the-first-ai-workspace-built-around-how-companies-actually-work/" target="_blank" rel="noreferrer noopener">Cloudflare OS</a>, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open source and browser-based, sparing companies the need to build all-new infrastructure.</p>



<p class="wp-block-paragraph">The OS is launching alongside several other new security, identity, spending, and user insight tools that Cloudflare has built for the <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html" target="_blank">AI-based workplace</a>.</p>



<p class="wp-block-paragraph">“Cloudflare OS isn’t a traditional desktop OS,” said <a href="https://www.linkedin.com/in/ritakozlov/" target="_blank" rel="noreferrer noopener">Rita Kozlov</a>, VP of product at Cloudflare. “It reimagines the workplace computing environment for AI.”</p>



<h2 class="wp-block-heading">Open source OS runs in a browser</h2>



<p class="wp-block-paragraph">Cloudflare OS serves as a secure, AI-equipped workspace that is plugged into internal company systems. Available now through Cloudflare’s open source repository, it is accessible directly in a browser, and runs inside an enterprise’s Cloudflare account.</p>



<p class="wp-block-paragraph">“It is a browser-based workspace that begins with a conversation,” Kozlov explained. Users can ask an agent to research, create slides, spreadsheets, and documents, build full-stack apps, or automate workflows without the need for a terminal. Those outputs are then shareable, but kept in isolated databases with access controls.</p>



<p class="wp-block-paragraph">Enterprises will soon be able to access the OS directly through Cloudflare or via a “select group” of partners that will build tailored offerings on Cloudflare’s architecture, the company says. Because it is open source, organizational processes, internal system connections, and context aren’t locked into a vendor product or AI model provider. Customers can use whatever models they choose.</p>



<p class="wp-block-paragraph">Cloudflare OS is built on Cloudflare Workers, <a href="https://www.infoworld.com/article/4149869/cloudflare-launches-dynamic-workers-for-ai-agent-execution.html" target="_blank">Dynamic Workers</a>, Durable Objects, and Access, the company’s zero trust network access (ZTNA) tool that verifies every user and request. Agents start with zero permissions by default and are only granted access to tools required for a specific task. Organizations configure their own Access policies, models, branding, skills, and integrations, Kozlov explained.</p>



<p class="wp-block-paragraph">Governed connectors known as gatekeepers give admins control over what AI can see, what it can change, and when the system needs human sign-off. They can also control budgets, set rate limits, and delegate tasks to different models.</p>



<p class="wp-block-paragraph">“Because <a href="https://www.infoworld.com/article/4165857/are-we-ready-to-give-ai-agents-the-keys-to-the-cloud-cloudflare-thinks-so.html" target="_blank">agents act on people’s behalf</a> and produce work others can access and modify, they require a new security model,” Kozlov said. Thus, Cloudflare OS tracks the resources an agent requires so the right access controls follow its work when it is shared.</p>



<p class="wp-block-paragraph">Cloudflare initially built the OS for internal use, and employees “across every team” use it daily. Kozlov estimated that, over the last 30 days, internal users have used it to create more than 4,000 apps, automations, and tools. Over that same period, she claimed, the company’s sales team saved an estimated 10,000 hours by automating previously manual tasks like territory planning and proposal creation.</p>



<p class="wp-block-paragraph">“We open sourced Cloudflare OS so any organization can build ‘Your Company OS,’” Kozlov said. Open source is critical because “you cannot put your company into software you do not own. Organizations need to be able to inspect the platform, customize it, connect their own systems, and make it their own,” she explained.</p>



<h2 class="wp-block-heading">A more cohesive bundle</h2>



<p class="wp-block-paragraph">Cloudflare deserves credit for packaging Cloudflare OS as an operating system, noted tech analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a>.</p>



<p class="wp-block-paragraph">“This very much is not Windows, macOS, or Linux, and it isn’t an operating system by its common definition,” he said. “But Cloudflare’s use of this terminology implies familiarity to enterprise IT buyers.”</p>



<p class="wp-block-paragraph">This makes for an easier discussion as enterprises struggle to understand how to best incorporate AI-related platforms and workflows into infrastructure that wasn’t initially designed for it.</p>



<p class="wp-block-paragraph">Microsoft has marketed the combination of its Azure, Entra, Fabric, Windows, and Microsoft 365 offerings as an operating system of sorts, but hasn’t pulled all the pieces into a common brand, Levy said. And Google’s Gemini, Workspace, Vertex AI, and Cloud Run are “circling similar territory.”</p>



<p class="wp-block-paragraph">But, he noted, Cloudflare OS is “more cohesively bundled” and infrastructure-focused, offering a single pane of glass platform for buyers worried about stitching together otherwise disparate AI-aware networking pieces. The company recognizes that AI introduces new architectural realities such as inference and model routing “over and above” traditional OS core competencies.</p>



<p class="wp-block-paragraph">“While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor, which potentially frees IT planners from having to integrate all the AI pieces on their own,” Levy said.</p>



<p class="wp-block-paragraph">An infrastructure-first, application-agnostic approach means Cloudflare OS can coexist with whatever AI applications already exist in an enterprise, he said. It will “play nice” with OpenAI, Anthropic, Google, Microsoft, Meta, or open source layers, allowing employees to begin working in familiar workflows after sign-in.</p>



<p class="wp-block-paragraph">“Its open-source architecture also minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities,” Levy said.</p>



<h2 class="wp-block-heading">Managing identities and budgets for both humans and AI</h2>



<p class="wp-block-paragraph">As AI agents emerge across the enterprise, tracking their use can be challenging, causing problems from both a security and a spend standpoint. Along with Cloudflare OS, the company has launched a way to address this issue with its new <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-gives-companies-full-visibility-to-audit-and-analyze-ai-use/" target="_blank" rel="noreferrer noopener">Identity-Aware AI Gateway</a>, now in beta.</p>



<p class="wp-block-paragraph">Also integrated with Access, the offering gives admins visibility into what users (both human and AI) are requesting from AI models. It allows security teams to set up custom domains in front of their gateways and replace shared API keys by integrating with their identity provider, like Okta or Entra, and ZTNA infrastructure, Cloudflare explained.</p>



<p class="wp-block-paragraph">Every request is tied to Access-verified identities, and enterprises can filter each user’s logs, analytics, and spend. IT teams can track redundancies, limit usage rates, and apply filters that strip out employee names, passwords, and other sensitive data before requests go to outside model providers.</p>



<p class="wp-block-paragraph">A companion feature, AI Spend, tracks every user’s behavior over time to create a baseline of normal AI usage. When spending deviates from that pattern, the system alerts the IT team.</p>



<p class="wp-block-paragraph">A new tab, User Insights, tracks cost and identifies over-spend caused by activities such as low cache-hit rates or oversized context windows. The capability scores sessions and compares them against account history using a 95th percentile session cost over the previous 30 days, Cloudflare product managers <a href="https://blog.cloudflare.com/author/ming-lu/" target="_blank" rel="noreferrer noopener">Ming Lu</a>, <a href="https://blog.cloudflare.com/author/kenny/" target="_blank" rel="noreferrer noopener">Kenny Johnson</a>, and <a href="https://blog.cloudflare.com/author/ayush/" target="_blank" rel="noreferrer noopener">Ayush Kumar</a> explain in a <a href="https://blog.cloudflare.com/identity-aware-ai-gateway/" target="_blank" rel="noreferrer noopener">blog post</a>. Anything above 2x an account’s 95th percentile is a “strong candidate for anomalous behavior.”</p>



<p class="wp-block-paragraph">For instance, one Cloudflare customer had an employee who left a rogue AI session running, generating a $30K bill. “User Insights helped them identify the problem and shut off access before the problem was further exacerbated,” Kozlov said.</p>



<p class="wp-block-paragraph">Cloudflare is also building prompt classification functionality that sorts requests into categories such as coding or writing. This can help enterprises understand what AI is being used for.</p>



<p class="wp-block-paragraph">“Once business traffic is separated from everything else, personal use becomes visible,” the project managers explained. “From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk.”</p>



<h2 class="wp-block-heading">Looking at the bigger picture</h2>



<p class="wp-block-paragraph">Identity-Aware AI Gateway and AI Spend address the visibility problem that has dogged so many recent AI deployments where enterprises failed to monitor usage, Levy noted. Projects “crashed and burned” as users unwittingly blew through token allocations.</p>



<p class="wp-block-paragraph">These platforms provide single-point visibility into what is being used, how it’s being used, and where the potential lies for raising the productivity bar, he said. They overlay with existing models; in doing so, they enhance security with more precise control over resource allocations, and via automated anonymization protocols that prevent inadvertent sharing of sensitive data.</p>



<p class="wp-block-paragraph">Ultimately, he said, vendors who free IT from having to independently assemble the pieces of their own AI implementations, and who assist them with answers to AI-specific questions, “will gain advantage over vendors that aren’t looking at the bigger picture.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[No cloud, no GPUs, no problem: Liquid AI's new model LFM2.5-2.6B brings powerful AI agents to devices as small as a Raspberry Pi]]></title>
<description><![CDATA[Earlier this week, the AI startup Liquid, formed in 2023 by former MIT computer scientists, debuted LFM2.5-2.6B, a new open-weight language model designed specifically for agentic workloads. In release materials and a recent interview with VentureBeat, Liquid's researchers said LFM2.5-2.6B can ru...]]></description>
<link>https://tsecurity.de/de/3709207/it-nachrichten/no-cloud-no-gpus-no-problem-liquid-ais-new-model-lfm25-26b-brings-powerful-ai-agents-to-devices-as-small-as-a-raspberry-pi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709207/it-nachrichten/no-cloud-no-gpus-no-problem-liquid-ais-new-model-lfm25-26b-brings-powerful-ai-agents-to-devices-as-small-as-a-raspberry-pi/</guid>
<pubDate>Fri, 07 Aug 2026 02:35:01 +0200</pubDate>
<content:encoded><![CDATA[<p>Earlier this week, the AI startup Liquid, formed in 2023 by former MIT computer scientists, <a href="https://www.liquid.ai/blog/lfm2-5-2-6b">debuted LFM2.5-2.6B</a>, a new open-weight language model designed specifically for agentic workloads. </p><p>In release materials and a recent interview with VentureBeat, Liquid's researchers said LFM2.5-2.6B can run entirely on local hardware — from smartphones and laptops down to a Raspberry Pi — without relying on cloud inference or GPUs, unlocking edge AI applications and giving more options to enterprises working in regulated industries or with sensitive information they don't want to send up to the cloud. </p><p>It's best suited for high-volume, well-defined agentic tasks that run locally — tool calling, document management, calendar and workflow automation, and always-on background routines — and for connectivity-limited environments like vehicles and robotics, though coding-heavy work is better left to larger models.</p><p>Even for those businesses without such concerns, the appeal of running performant, task-specific agents at the cost of essentially electricity, may be enough to make the new model quite appealing. </p><p>But the <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B/blob/main/LICENSE">custom open weights license</a>, as with <a href="https://venturebeat.com/technology/kimi-k3s-full-weights-are-here-but-theyre-open-with-a-caveat-what-enterprises-should-know">Moonshot's larger frontier model Kimi K3</a> released last month, is worth a close look by enterprise legal teams. </p><h2><b>The basics</b></h2><p>LFM2.5-2.6B contains 2.6 billion parameters, supports a 128,000-token context window, and includes native tool calling. The somewhat tricky name is explained by the generation of model (2.5) combined with the parameter count (2.6B).  </p><p>Both the post-trained model and a base checkpoint (LFM2.5-2.6B-Base) for developers who want to fine-tune it are available now on <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B">Hugging Face</a>, with day-one support for major inference stacks including llama.cpp, MLX, vLLM, SGLang, and ONNX — positioning it for deployment across consumer hardware, enterprise infrastructure, and embedded systems.</p><p>Liquid also offers an open source fine-tuning framework, <a href="https://github.com/Liquid4All/leap-finetune">LEAP</a>.</p><p>Rather than positioning LFM2.5-2.6B as a competitor to the largest frontier models, the company is making a different argument: that a sufficiently capable small model can unlock categories of enterprise applications where latency, privacy, deployment flexibility, or inference costs matter more than absolute benchmark leadership.</p><p>"I do also believe that the best models will be in the cloud, and there's no problem with that," Maxime Labonne, Liquid AI's head of post-training, told VentureBeat in an interview following the launch. "We want to make models for another type of user, and the best way of describing it is: you should use [edge AI] when you can't use a cloud model."</p><h2><b>Small enough for a Raspberry Pi</b></h2><p>Asked about the minimum viable hardware, Labonne said the model runs "very, very well" on CPUs — and that the LFM2 architecture underlying the model was explicitly designed around real-world CPU performance rather than GPU benchmarks.</p><p>"I think the best example is a Raspberry Pi," he said. "We have a lot of demos that show that actually, it works pretty fast on the Raspberry Pi."</p><p>Company-reported measurements indicate decoding throughput of approximately 220 tokens per second on an Apple M5 Max and 113 tokens per second on an AMD Ryzen AI Max+ 395, while using less than 2.5 GB of memory — and around 30 tokens per second on a smartphone. Users can try the models on their phones through Apollo, Liquid AI's mobile app.</p><p>At the other end of the deployment spectrum, Liquid AI reports the model reaches nearly 15,000 output tokens per second on a single Nvidia H100 GPU under sustained concurrent load — roughly 1.3 billion tokens per day on one card. These figures are vendor benchmarks and have not been independently verified.</p><p>For Labonne, memory footprint and speed are not conveniences but hard constraints that determine what can be deployed at all.</p><p>"What we want to show is that it's a really good trade-off, because you get the level of quality that you get with much bigger models, but in a tiny, tiny form factor," he said. "You can deploy it in target devices where you are not able to deploy the other ones at all."</p><h2><b>Trained for agents instead of chatbots</b></h2><p>Liquid AI says LFM2.5-2.6B was developed around the assumption that language models are increasingly consumed through agent frameworks rather than traditional conversational interfaces.</p><p>"Models are not consumed in chatbots anymore. They're really consumed through agentic harnesses, like OpenClaw, like Hermes Agent," Labonne said. "We wanted to make sure that this model is not just good at math or at code, but it's good at using tools."</p><p>The model is pretrained on approximately 34 trillion tokens, with a vocabulary doubled to 128K to better support non-Latin scripts and a dedicated mid-training phase to extend the context window to 128K tokens for long-running agent workflows.</p><p>Post-training follows a four-stage pipeline: supervised fine-tuning, teacher specialization (training separate expert models for domains like instruction following, math, code, and tool use), multi-domain on-policy distillation (MOPD) to merge those experts' capabilities back into a single student model, and finally agentic reinforcement learning. </p><p>During that last stage, the model was trained directly inside production agent harnesses — including Hermes Agent and OpenClaw — on realistic productivity tasks involving research, coding, document management, tool invocation, and workflow automation, exposing it to those harnesses' actual tools, system prompts, and interaction patterns.</p><p>Labonne described the pipeline overhaul as producing a "happy accident": gains that extended well beyond the agentic targets.</p><p>"Through these new training techniques, we also got a lot better at everything. We got better at math, at instruction following. We've never been good at code, actually — and with this, we even got really good at code," he said.</p><h2><b>Building the model — and the harness</b></h2><p>Notably, Liquid AI also built its own agent harness rather than relying solely on existing frameworks, and demonstrated the model running inside it on a phone, planning and calling tools entirely on-device.</p><p>"This is a harness running on a phone, and I don't know if there's any other harness running on a phone," Labonne said.</p><p>The company had two reasons, he explained. The first was necessity — no phone-native harness existed. The second is a different interaction model: today's harnesses wait for a prompt, and Liquid AI wants assistants that act on their own.</p><p>"We want proactive agents. We want agents that run in the background, check what you're doing, check your calendar, and based on this context, do tasks," he said. "That doesn't exist today, really."</p><p>Co-designing the harness and model also lets the software compensate for the model's weak spots. "Everything that the model is bad at, the harness should help the model with — provide as much assistance as possible to make it more reliable," Labonne said. "End users don't care if it's the model or the harness. What they want is that the task is achieved at the end of the day."</p><p>The model nevertheless works out of the box with established harnesses including Hermes Agent, OpenClaw, and Pi, served behind any OpenAI-compatible endpoint.</p><h2><b>Swap the harness, not the model</b></h2><p>For enterprise deployment, Labonne argued the release marks a shift in what small models can be used for. Until now, he said, local models made economic sense mainly as narrowly fine-tuned specialists — trained to do one thing at cloud-model quality, much faster and cheaper. Agentic capability changes that calculus, because the same model can be repurposed by changing the tools around it rather than the model itself.</p><p>"You can have a calendar assistant, and you can reuse the same model and make a meeting assistant that will record what everybody said and summarize it — a bit like Granola, for example," he said. "You don't change the model; you just change the harness. You just change the tools around it. This gives much more generalizability, and it's a lot easier to do and a lot cheaper as well."</p><p>He still recommends fine-tuning for production deployments whenever feasible: "If you don't fine-tune it, you leave some quality on the table. If you fine-tune it well, it's going to match the performance of GPT and Claude — really, if your task is not the most complex task in the world," he said, adding that the barrier to entry has collapsed: "The bar to be able to do fine-tuning now is super low. It's very accessible to everyone."</p><h2><b>How it stacks up against DeepSeek-V4-Flash, Google's Gemma and Alibaba's Qwen</b></h2><p>Liquid AI released its own benchmark comparison charts pitting LFM2.5-2.6B against the models enterprises are most likely to shortlist for the same edge deployments: Google's Gemma 4 E2B (5.1B parameters) and E4B (8B), and Alibaba's Qwen3.5-4B (4.7B) and Qwen3.5-9B (9.7B). </p><p>A separate test by local AI client platform <a href="https://x.com/atomic_chat_hq/status/2085405031474343963">Atomic Chat</a> found that LFM2.5-2.6B completed 35 tool calls to complete three tasks (checking weather and local time in six cities, converting one budget into six currencies, checking four hotels and booking for a date) 3.7 times faster than DeepSeek-V4-Flash (a whopping 284B parameters), the model has <a href="https://x.com/natolambert/status/2084790959636922652?s=20">skyrocketed</a> to the top of <a href="https://openrouter.ai/rankings#top-models">OpenRouter</a> since its release last week. </p><div></div><p>Gemma 4's small models are multimodal generalists, accepting image and audio input alongside text, and use a Per-Layer Embeddings design that keeps only a fraction of their weights active per token — which is why Google markets them by "effective" size (2.3B and 4.5B) despite total footprints of 5.1B and 8B. Alibaba's Qwen3.5 small series, <a href="https://venturebeat.com/technology/alibabas-small-open-source-qwen3-5-9b-beats-openais-gpt-oss-120b-and-can-run">released in March</a>, is natively multimodal from 4B up and leans on scaled reinforcement learning to chase frontier-style reasoning — Alibaba touts the 9B model as matching or beating OpenAI's far larger gpt-oss-120B on reasoning benchmarks.</p><p>LFM2.5-2.6B takes a narrower path: it is text-only, dense, and specialized for agentic work, with Liquid AI shipping separate vision and audio variants of the LFM family rather than folding everything into one checkpoint. </p><p>Where Qwen's post-training reinforcement learning targets reasoning, Liquid's targets tool use inside real agent harnesses. </p><p>The result, per the company's published numbers, is that the smallest model in the comparison leads every instruction-following benchmark (IFBench, Multi-IF, IFStruct) and nearly every tool-use benchmark — 77.83 on ToolSandbox versus 76.44 for Qwen3.5-9B, a model nearly four times its size — trailing only that 9B model on BFCLv4. </p><p>On agentic evaluations it beats both Gemma models across the board and essentially ties the Qwens: 26.89 on BrowseComp+ versus 27.23 for Qwen3.5-9B. It also posts the best score on AA Omniscience, a knowledge benchmark that penalizes hallucination.</p><p>The Qwen models keep the edge where their training focus lies: math (Qwen3.5-9B leads AIME25) and coding, where larger models retain an advantage on LiveCodeBench — though Labonne noted the gap is smaller than the parameter counts would suggest.</p><p>"With LiveCodeBench v6, we might not be the best among these models, but we're also by far the smallest. Showing that we're competitive with them is already quite a big win for me," he said.</p><p>One differentiator cuts the other way: licensing. Gemma 4 and Qwen3.5 ship under the permissive Apache 2.0 license — <a href="https://venturebeat.com/technology/google-releases-gemma-4-under-apache-2-0-and-that-license-change-may-matter">a change Google made specifically to court enterprises</a>. DeepSeek-V4-Flash ships <a href="https://huggingface.co/datasets/choosealicense/licenses/blob/main/markdown/mit.md">under a similarly permissive MIT License</a>. </p><p>Meanwhile, Liquid AI's revenue-gated license (detailed below) asks larger companies to strike a commercial deal. Enterprises above the threshold are effectively trading license friction for footprint and tool-use performance.</p><h2><b>Licensing reflects a commercial middle ground</b></h2><p>LFM2.5-2.6B is distributed under the <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B/blob/main/LICENSE">LFM Open License v1.0,</a> which permits use, modification, and redistribution — including commercial use — for organizations with less than $10 million in annual revenue. Commercial use by larger companies is not covered by the license, requiring a separate arrangement with Liquid AI; qualified nonprofits are exempt from the threshold for non-commercial and research purposes.</p><p>Labonne framed the structure as a way to sustain model development — "the models are really the moats, so we need to be sensible in the way that we license them; otherwise, we cannot make money, so we can't make more models" — while characterizing the threshold as a light-touch mechanism in practice.</p><p>Asked how the company would even know if a large enterprise quietly deployed the open weights, he was candid: "I think this is a question for our legal team, but personally, I don't know. And even if you're above $10 million, the only thing that we ask you is to contact us."</p><p>The company pairs its licensed model releases with freely published research, he added, including new structured-output evaluations and a training technique that mitigates the repetition loops common in small models — a failure mode he noted Qwen models are "kind of guilty of."</p><h2><b>Small model, big enterprise implications</b></h2><p>The launch coincided with an announcement from <a href="https://www.liquid.ai/blog/macpaw-partners-liquid-ai-on-device-ai-mac-users">MacPaw</a>, the Ukrainian software company behind CleanMyMac and Setapp, of a long-term strategic partnership with Liquid AI to build an on-device AI stack for the Mac. </p><p>Liquid AI will design and fine-tune foundation models for Eney, MacPaw's macOS assistant, running locally on Apple silicon through MacPaw's Elix inference engine and Mnemos memory layer, with results expected later this year.</p><p>Labonne pointed to the deal as a concrete validation of the size argument: "One of the reasons why they chose us is also because the model is quite small, and they don't have all the memory budget to run the other models."</p><p>The release arrives as hardware vendors, operating system developers, and enterprise software companies increasingly invest in local AI execution — and as agent harnesses proliferate across the industry. Liquid AI's bet is that deployment economics, not raw scale, will define an important segment of that market: agents running continuously, everywhere, at zero marginal token cost.</p><p>Whether small, highly optimized agent models become a significant segment of enterprise AI will ultimately depend less on benchmark scores than on operational reliability. But Liquid AI's latest release suggests the next competitive frontier is no longer simply building larger models — it's building models small enough, and capable enough, to run wherever enterprise workflows already live.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Salesforce cutting 59 jobs across Seattle and Bellevue offices]]></title>
<description><![CDATA[Affected positions include software engineers, product management directors, incident commanders, technical support engineers, and leadership roles across marketing and sustainability. Read More]]></description>
<link>https://tsecurity.de/de/3709179/it-nachrichten/salesforce-cutting-59-jobs-across-seattle-and-bellevue-offices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709179/it-nachrichten/salesforce-cutting-59-jobs-across-seattle-and-bellevue-offices/</guid>
<pubDate>Fri, 07 Aug 2026 02:34:49 +0200</pubDate>
<content:encoded><![CDATA[<img width="1260" height="877" src="https://cdn.geekwire.com/wp-content/uploads/2026/02/salesforce-1260x877.jpeg" class="webfeedsFeaturedVisual wp-post-image" alt="Salesforce" decoding="async" loading="lazy" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/02/salesforce-1260x877.jpeg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/02/salesforce-768x535.jpeg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/02/salesforce-1536x1069.jpeg 1536w, https://cdn.geekwire.com/wp-content/uploads/2026/02/salesforce-2048x1426.jpeg 2048w" sizes="auto, (max-width: 1260px) 100vw, 1260px"><br>Affected positions include software engineers, product management directors, incident commanders, technical support engineers, and leadership roles across marketing and sustainability. <a href="https://www.geekwire.com/2026/salesforce-cutting-59-jobs-across-seattle-and-bellevue-offices/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat 2026: Barracuda Details AI-Powered BEC Attack]]></title>
<description><![CDATA[Barracuda's Black Hat USA 2026 research shows how AI email assistants can accelerate business email compromise attacks.
Read more →
The post Black Hat 2026: Barracuda Details AI-Powered BEC Attack appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3709068/it-security-nachrichten/black-hat-2026-barracuda-details-ai-powered-bec-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709068/it-security-nachrichten/black-hat-2026-barracuda-details-ai-powered-bec-attack/</guid>
<pubDate>Thu, 06 Aug 2026 21:28:10 +0200</pubDate>
<content:encoded><![CDATA[<p>Barracuda's Black Hat USA 2026 research shows how AI email assistants can accelerate business email compromise attacks.</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/black-hat-2026-barracuda-details-ai-powered-bec-attack/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/black-hat-2026-barracuda-details-ai-powered-bec-attack/">Black Hat 2026: Barracuda Details AI-Powered BEC Attack</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehr als 58.000 Ingenieure und IT-Fachkräfte ohne Job - it-business]]></title>
<description><![CDATA[IT Security made in Germany · Umfrage Servicepreisspiegel · AWS Channel ... VDI Verein Deutscher Ingenieure e.V. · g-data-cyberdefense-logo-sq (G Data) ...]]></description>
<link>https://tsecurity.de/de/3709062/it-security-nachrichten/mehr-als-58000-ingenieure-und-it-fachkraefte-ohne-job-it-business/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709062/it-security-nachrichten/mehr-als-58000-ingenieure-und-it-fachkraefte-ohne-job-it-business/</guid>
<pubDate>Thu, 06 Aug 2026 21:20:11 +0200</pubDate>
<content:encoded><![CDATA[<b>IT Security</b> made in Germany · Umfrage Servicepreisspiegel · AWS Channel ... VDI Verein Deutscher Ingenieure e.V. · g-data-cyberdefense-logo-sq (G Data) ...]]></content:encoded>
</item>
<item>
<title><![CDATA[New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts]]></title>
<description><![CDATA[Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.

The flaw is tracked as CVE-2026-645...]]></description>
<link>https://tsecurity.de/de/3709055/it-security-nachrichten/new-zapscape-kvm-flaw-could-let-privileged-l1-guest-code-escape-to-linux-hosts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709055/it-security-nachrichten/new-zapscape-kvm-flaw-could-let-privileged-l1-guest-code-escape-to-linux-hosts/</guid>
<pubDate>Thu, 06 Aug 2026 21:20:03 +0200</pubDate>
<content:encoded><![CDATA[Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.

The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents are part of your team now. Here’s how to secure all of them.]]></title>
<description><![CDATA[Presented by JumpCloudA practical framework for securing every identity in the modern workforce, human or not.Your organization already has a rigorous process for governing human identities. New employees go through onboarding. They get a role, a set of entitlements, and a named manager accountab...]]></description>
<link>https://tsecurity.de/de/3709048/it-nachrichten/ai-agents-are-part-of-your-team-now-heres-how-to-secure-all-of-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709048/it-nachrichten/ai-agents-are-part-of-your-team-now-heres-how-to-secure-all-of-them/</guid>
<pubDate>Thu, 06 Aug 2026 21:19:53 +0200</pubDate>
<content:encoded><![CDATA[<p><i>Presented by JumpCloud</i></p><hr><p><i>A practical framework for securing every identity in the modern workforce, human or not.</i></p><p>Your organization already has a rigorous process for governing human identities. New employees go through onboarding. They get a role, a set of entitlements, and a named manager accountable for their access. When they leave, their credentials are revoked and access is terminated. It’s a well known IT process: every workforce identity that can access your systems needs to be known, scoped, and accountable from the moment they enter your world, to the moment they are off-boarded.</p><p>AI agents are now operating inside those same systems. They access Salesforce, create tickets in Jira, provision infrastructure, process financial transactions, and communicate on behalf of your teams. In every meaningful sense they are members of your workforce, except that in most organizations they were never onboarded, have no named owner, and have no offboarding process when their purpose expires.</p><p>JumpCloud’s Q3 2026 research found that non-human identities now outnumber human users in <a href="https://jumpcloud.com/resources/q3-2026-it-trends-report?utm_source=VentureBeat&amp;utm_medium=Contributed-Content&amp;utm_campaign=FY26Q1_MorningBrew_AD&amp;utm_content=AugustArticle"><u>83% of organizations</u></a>, and only 21% have implemented governance controls specifically for them. The framework below is designed to close that gap.</p><h2>Stage 1: Discover every agent operating in your environment</h2><p>Governance starts with an accurate inventory, and most organizations are working with an incomplete one. AI agents are being deployed by product teams, operations leaders, and individual contributors who have both the tools and the motivation to move fast. IT inherits the governance responsibility after the fact, often without knowing the full scope of what has been deployed.</p><p>Shadow AI is the practical consequence: agents operating across production environments with no formal record, no defined owner, and no systematic way to stop them if something goes wrong. Discovering your agent population is an ongoing practice, not a one-time audit. Build an inventory across every environment where agents could be running: cloud platforms, managed devices, SaaS integrations, and on-premise systems. For each agent, document what it can access, what workflows it influences, and what triggers its actions. That inventory is the foundation everything else in this framework depends on.</p><h2>Stage 2: Register every agent as a formal identity with a named owner</h2><p>Every agent that operates in your environment should exist as a formal identity in your directory, with the same basic attributes you assign to any employee: a defined purpose, a scope of authorized action, and a named human owner who is accountable for its behavior.</p><p>This is the architectural decision that separates organizations that can govern their agents from those that cannot. Agents registered as proper identities can be assigned entitlements, subjected to conditional access policies, and included in access reviews. Agents that exist only as service account workarounds or API keys in environment variables are ungovernable by any systematic means.</p><p>Registration is also the mechanism for addressing Zombie Agents: agents that outlived their original purpose but kept running, kept accessing systems, and kept accumulating permissions. When every agent has a named owner responsible for its renewal, agents without active ownership naturally lose their access when that ownership lapses. The offboarding happens as a consequence of process rather than as a reactive cleanup after something breaks.</p><h2>Stage 3: Manage agent access with least privilege and zero standing credentials</h2><p>Registered agents need access to do their jobs. The governing principle for that access is least privilege: each agent should have entitlements scoped precisely to what its defined purpose requires, with access that is time-bounded wherever possible and revocable immediately if the agent’s behavior changes.</p><p>Standing credentials in environment variables are a persistent liability. Static API keys that never rotate are a persistent liability. In practice, managing agent access securely means issuing just-in-time credentials for privileged operations, building approval workflows that require human sign-off before agents reach sensitive systems, and maintaining emergency shutdown mechanisms that work at the speed the situation requires.</p><p>For agents that need access to privileged web applications, SSH servers, or databases, credential shielding is an additional requirement: the agent should be able to complete its task without the underlying credentials ever being exposed to the model running it. Every privileged session should be recorded and available for audit.</p><h2>Stage 4: Govern agent behavior continuously, not just at deployment</h2><p>The first three stages establish the controls. Governance is what keeps them current. It is the ongoing practice of verifying that what agents are actually doing matches what they are authorized to do, and course-correcting when those diverge.</p><p>Every agent action should be logged. Access reviews should happen on a regular cadence, evaluating whether each agent’s entitlements remain appropriate for its current purpose. When an agent’s behavior deviates from its defined scope, the anomaly should be detectable before it becomes an incident. When an agent’s purpose ends, access revocation should be a procedural step, not a reactive measure triggered by something going wrong.</p><p>Governance also means maintaining the audit trail needed to answer accountability questions: what did this agent access, what actions did it take, who authorized it, and what was the outcome? Organizations that cannot reconstruct that chain for any given agent are not governing their agents in any meaningful sense. They have deployed them and hoped for the best.</p><h2>The foundation underneath all four stages</h2><p>Each stage of this framework becomes significantly harder to execute when the underlying IT environment is fragmented. Identity, access, device management, and security controls spread across disconnected systems create the gaps where agent governance falls through, and organizations end up applying different policies in different places rather than consistent governance everywhere.</p><p>JumpCloud’s research found that organizations operating in fully unified IT environments are five times more likely to deploy agents in business-critical workflows than those running fragmented stacks. Whether the control layer is coherent enough to apply consistent policies across humans, devices, and agents simultaneously is what determines whether governance scales with AI adoption or lags behind it.</p><p>This is the core premise of Agentic IAM: that governing humans, devices, and agents through a single coherent control layer is what makes the framework above executable at scale rather than aspirational.</p><p>Securing every identity, human or not, is the operational foundation that makes AI safe to scale. Organizations that build it now will not just reduce risk. They will expand AI into more workflows, move faster, and do it with the confidence that comes from knowing every identity in their environment is known, governed, and accountable.
</p><hr><p><i>JumpCloud’s Q3 2026 IT Trends Research report (n=800 IT leaders, US + UK) is available </i><a href="https://jumpcloud.com/resources/q3-2026-it-trends-report?utm_source=VentureBeat&amp;utm_medium=Contributed-Content&amp;utm_campaign=FY26Q1_MorningBrew_AD&amp;utm_content=AugustArticle"><i><u>here</u></i></a><i>. The Agentic IAM lifecycle framework referenced in this article was developed by JumpCloud and is available </i><a href="https://jumpcloud.com/secure-every-identity?utm_source=VentureBeat&amp;utm_medium=Contributed-Content&amp;utm_campaign=FY26Q1_MorningBrew_AD&amp;utm_content=AugustArticle"><i><u>here</u></i></a><i>.</i></p><p><i>Greg Keller is CTO and Co-founder at JumpCloud.</i></p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 6 Release Date, Time, and What to Expect]]></title>
<description><![CDATA[Silo Season 3 Episode 6 will arrive on Apple TV on Friday, August 7, 2026, continuing Juliette Nichols’ search for the truth while the Before Times storyline moves closer to the creation of the silos.



The upcoming chapter is titled “The Drive.” Apple has confirmed that Season 3 contains 10 epi...]]></description>
<link>https://tsecurity.de/de/3708982/ios-mac-os/silo-season-3-episode-6-release-date-time-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708982/ios-mac-os/silo-season-3-episode-6-release-date-time-and-what-to-expect/</guid>
<pubDate>Thu, 06 Aug 2026 20:27:12 +0200</pubDate>
<content:encoded><![CDATA[Silo Season 3 Episode 6 will arrive on Apple TV on Friday, August 7, 2026, continuing Juliette Nichols’ search for the truth while the Before Times storyline moves closer to the creation of the silos.



The upcoming chapter is titled “The Drive.” Apple has confirmed that Season 3 contains 10 episodes, with a new episode released every Friday until the finale on September 4, 2026.




Episode title: The Drive



Release date: Friday, August 7, 2026



Streaming service: Apple TV



Genre: Science fiction, mystery and dystopian drama



Season episode count: 10 episodes



Season finale: Friday, September 4, 2026



Main cast: Rebecca Ferguson, Tim Robbins, Common, Jessica Henwick and Ashley Zukerman




Apple TV usually releases new episodes globally around midnight Pacific Time, although the exact local availability can vary by region and device.



What will happen in Silo Season 3 Episode 6?



Spoilers ahead for Silo Season 3 Episode 5.



Episode 6 should continue the two connected timelines that have shaped the season. In the present, Juliette is trying to recover memories that appear to have been deliberately removed, while the people around her deal with the political and technical consequences of the rebellion.



The title “The Drive” suggests that a storage device or hidden collection of information will become central to the episode. It could contain records about the silos, their original purpose or the people who designed the underground system.



The Before Times storyline will also remain important. A preview for Episode 6 shows Helen and Daniel facing an unexpected offer as their investigation moves deeper into the conspiracy surrounding the future of humanity.



Their discoveries could explain how the silo project moved from a secret political plan to a system capable of controlling thousands of people for generations. The episode should also connect their investigation with the information Juliette is trying to recover in the present.



What happened before Silo Season 3?



Season 1 followed Juliette as she became sheriff of Silo 18 and investigated a series of deaths connected to forbidden relics and hidden information. Her search eventually revealed that the authorities had lied about the outside world and that several silos existed beyond her home.



Season 2 continued after Juliette survived outside and entered another underground structure. Back in Silo 18, her apparent death inspired resistance against Bernard’s rule, leading to a rebellion and further questions about who controls the silos.



Season 3 expands the story by exploring events before the silos were built. Journalist Helen Drew and Congressman Daniel Keene are investigating a conspiracy that appears connected to the disaster that forced humanity underground.



When will Silo Season 3 Episode 7 be released?



Episode 7, titled “Radio,” is scheduled for Friday, August 14, 2026. New episodes will continue weekly until the Season 3 finale arrives on September 4.



Silo Season 3 Episode 6 could deliver some of the season’s biggest answers about Juliette’s missing memories and the origins of the underground world. What do you think the drive contains, and will Helen and Daniel discover the truth before it is too late? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ubuntu Touch gets big browser update, notch & printing support]]></title>
<description><![CDATA[Notch support, a screenshot editor and a more modern web browser engine are among changes arriving with the latest update to Ubuntu Touch, the community-run mobile operating system based on Ubuntu. With many devices supported by Ubuntu Touch, like Fairphone and Volla handsets, using a notch cutou...]]></description>
<link>https://tsecurity.de/de/3708979/linux-tipps/ubuntu-touch-gets-big-browser-update-notch-printing-support/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708979/linux-tipps/ubuntu-touch-gets-big-browser-update-notch-printing-support/</guid>
<pubDate>Thu, 06 Aug 2026 20:26:26 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="406" height="232" src="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/ubuntu-touch-2026-1.webp?resize=406%2C232&amp;ssl=1" class="attachment-post-list size-post-list wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/ubuntu-touch-2026-1.webp?resize=350%2C200&amp;ssl=1 350w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/ubuntu-touch-2026-1.webp?resize=406%2C232&amp;ssl=1 406w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/ubuntu-touch-2026-1.webp?resize=840%2C480&amp;ssl=1 840w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/ubuntu-touch-2026-1.webp?zoom=3&amp;resize=406%2C232&amp;ssl=1 1218w" sizes="auto, (max-width: 406px) 100vw, 406px">Notch support, a screenshot editor and a more modern web browser engine are among changes arriving with the latest update to Ubuntu Touch, the community-run mobile operating system based on Ubuntu. With many devices supported by Ubuntu Touch, like Fairphone and Volla handsets, using a notch cutout at the top of the display to house cameras, the new v24.04-2.0 update adds support for them, adapting the top panel indicators to cleanly space around them. Ubuntu Touch 24.04-2.0 also gains support for printing documents from handsets. Users can set this up via System Settings &gt; Printing. It requires downloading some extra […]</p>
<p>You're reading <a href="https://www.omgubuntu.co.uk/2026/07/ubuntu-touch-2404-2-update">Ubuntu Touch gets big browser update, notch &amp; printing support</a>, a blog post from <a href="https://www.omgubuntu.co.uk/">OMG! Ubuntu</a>. Do not reproduce elsewhere without permission.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Best Firewall Management Tools, Compared and Priced (2026)]]></title>
<description><![CDATA[The firewall policy management market had its earthquake: Skybox Security shut down overnight in February 2025, selling its technology to Tufin and leaving customers to migrate a reminder that in this category, vendor viability is a feature. The value verdict: Tufin (now absorbing Skybox’s base) ...]]></description>
<link>https://tsecurity.de/de/3708948/hacking/the-best-firewall-management-tools-compared-and-priced-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708948/hacking/the-best-firewall-management-tools-compared-and-priced-2026/</guid>
<pubDate>Thu, 06 Aug 2026 20:11:52 +0200</pubDate>
<content:encoded><![CDATA[<p>The firewall policy management market had its earthquake: Skybox Security shut down overnight in February 2025, selling its technology to Tufin and leaving customers to migrate a reminder that in this category, vendor viability is a feature. The value verdict: Tufin (now absorbing Skybox’s base) and AlgoSec lead enterprise policy governance, FireMon owns real-time visibility […]</p>
<p>The post <a href="https://gbhackers.com/firewall-management-tools-compared-pricing/">The Best Firewall Management Tools, Compared and Priced (2026)</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Photos: Black Hat USA 2026, part two]]></title>
<description><![CDATA[Round two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security, Featured speaker: Kate Silverstein (Mozilla) discussing crowd-sourcing prote...]]></description>
<link>https://tsecurity.de/de/3708925/it-security-nachrichten/photos-black-hat-usa-2026-part-two/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708925/it-security-nachrichten/photos-black-hat-usa-2026-part-two/</guid>
<pubDate>Thu, 06 Aug 2026 20:03:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Round two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security, Featured speaker: Kate Silverstein (Mozilla) discussing crowd-sourcing protection against real-world LLM attacks.</p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/06/black-hat-usa-2026-business-hall-photos/">Photos: Black Hat USA 2026, part two</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canadian Man Pleads Guilty in Snowflake Extortions]]></title>
<description><![CDATA[A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, On...]]></description>
<link>https://tsecurity.de/de/3708924/it-security-nachrichten/canadian-man-pleads-guilty-in-snowflake-extortions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708924/it-security-nachrichten/canadian-man-pleads-guilty-in-snowflake-extortions/</guid>
<pubDate>Thu, 06 Aug 2026 20:03:26 +0200</pubDate>
<content:encoded><![CDATA[A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&amp;T customers.]]></content:encoded>
</item>
<item>
<title><![CDATA[NatJack exploits put NAT security assumptions to the test at Black Hat]]></title>
<description><![CDATA[For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability.



The basic premise behind NAT is that private addresses stay private, but that assumption might not be e...]]></description>
<link>https://tsecurity.de/de/3708923/it-security-nachrichten/natjack-exploits-put-nat-security-assumptions-to-the-test-at-black-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708923/it-security-nachrichten/natjack-exploits-put-nat-security-assumptions-to-the-test-at-black-hat/</guid>
<pubDate>Thu, 06 Aug 2026 20:02:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability.</p>



<p class="wp-block-paragraph">The basic premise behind NAT is that private addresses stay private, but that assumption might not be entirely accurate anymore (if it ever really was). At <a href="https://blackhat.com/us-26/">Black Hat USA 2026</a>, researcher <a href="https://www.linkedin.com/in/malcolmst/">Malcolm Stagg</a>, an independent researcher and <a href="https://www.synack.com/red-team/">Synack Red Team</a> member, disclosed NatJack, an attack class that manipulates the NAT connection tracking table. </p>



<p class="wp-block-paragraph">An attacker sharing a NAT boundary with a victim can hijack active connections, poison DNS responses, and force <a href="https://www.csoonline.com/article/571981/ddos-attacks-definition-examples-and-techniques.html">denial of service</a>, without the IP spoofing or broadcast domain access older Layer 2 attacks required. Thirteen vendors were notified, and testing covered 32 products and configurations across 95 reports. Every tested implementation was vulnerable to some or all of the NatJack techniques.</p>



<p class="wp-block-paragraph">Stagg didn’t intentionally set out to find flaws in NAT, but he found them. “I kind of ran into this attack entirely by accident,” Stagg told <em>Network World</em>. “I noticed that I was sometimes getting responses that didn’t correspond to the packets that I was sending. That told me that there is some sort of corruption happening inside the NAT table.”</p>



<h2 class="wp-block-heading">What breaks in the NAT trust model</h2>



<p class="wp-block-paragraph">NAT was never built as a security control. It emerged in the early 1990s as a stopgap for <a href="https://www.networkworld.com/article/4200847/networkmanager-update-advances-ipv6-only-support-wi%E2%80%91fi-management-and-security-for-linux-based-operating-systems.html">IPv4 address exhaustion</a>, letting multiple devices share one public IP address under an assumption of trust between peers.</p>



<p class="wp-block-paragraph">“I think it basically goes back to under-specification in some of the RFCs that just allow behaviors based on the assumption that you’re in a network where the peers are trusted,” Stagg said.</p>



<p class="wp-block-paragraph">NAT has been hacked before. Security researcher Samy Kamkar disclosed NAT Pinning at DEF CON 18 and Black Hat in 2010, an early technique for manipulating NAT port behavior. He returned to the problem a decade later with NAT Slipstreaming, disclosed in 2020 and expanded with Armis researchers in 2021, which abused Application Level Gateway (ALG) connection tracking and required a victim to visit a malicious website. Those flaws have all been patched.</p>



<p class="wp-block-paragraph">NatJack is different. It manipulates the NAT table directly, needs no ALG, and requires no victim action beyond an active connection through the same NAT.</p>



<p class="wp-block-paragraph">The flaw does not stop at Layer 2. VLAN segmentation and switch port isolation do not help, since the attack targets shared NAT infrastructure at Layer 3 and Layer 4 rather than the local broadcast domain. The flaw was confirmed across Windows, Linux, and macOS despite no shared NAT codebase, pointing to a shared design assumption rather than an isolated bug.</p>



<h2 class="wp-block-heading">Four attack techniques, one shared weakness</h2>



<p class="wp-block-paragraph">NatJack covers four distinct techniques, all built on the same weakness in how NAT tables track connections.</p>



<ul class="wp-block-list">
<li><strong>TCP connection hijacking.</strong> An attacker forces a victim’s connection into a closed state using spoofed packets, then replaces the resulting table entry with one pointing to the attacker. The RFC 1337 TIME-WAIT Assassination mechanism Stagg identified lets this happen in a handful of packets rather than a standard connection timeout.</li>



<li><strong>DNS response poisoning.</strong> The technique intercepts and alters UDP DNS responses passing through the NAT, redirecting a victim’s lookups without their knowledge.</li>



<li><strong>Denial of service.</strong> An attacker exhausts the NAT table itself, breaking connectivity for every device sharing that NAT.</li>



<li><strong>Connection port identification.</strong> An attacker determines which port a NAT has assigned to an active connection, information that can support the other three techniques.</li>
</ul>



<h2 class="wp-block-heading">Disclosure and a mixed vendor response</h2>



<p class="wp-block-paragraph">Stagg responsibly disclosed the flaw, though vendor reaction has varied widely, from formal patches to outright rejection. </p>



<p class="wp-block-paragraph">The Linux kernel security team initially dismissed the report, going so far as to call the report- totally bogus. Stagg said the response caught him off guard. “I was pretty surprised by that,” Stagg said. “Getting that response was a little bit unexpected, and a little discouraging.”</p>



<p class="wp-block-paragraph">The kernel was eventually patched at Microsoft’s request to support Azure Kubernetes Service, resulting in CVE-2026-63913. Microsoft’s own Windows NAT vulnerability, affecting Hyper-V, was assigned CVE-2026-56181.</p>



<p class="wp-block-paragraph">Other vendors declined to classify the findings as vulnerabilities. “These reports are design-level NAT limitations rather than security vulnerabilities,” Cisco PSIRT said. “There are documented mitigations for the Cisco Secure Firewall and Cisco IOS XE products which would prevent most, if not all of these issues.”</p>



<p class="wp-block-paragraph">Apple took a similar position. “We’ve determined the behavior reflects a known limitation of the transport layer rather than a vulnerability,” Apple Product Security said. “Modern security models assume the local network may be hostile. This is why we continue to rely on end to end encryption, such as TLS.”</p>



<p class="wp-block-paragraph">Stagg noted that while encryption blunts the worst outcomes of NatJack, it does not eliminate the risk. “Encryption is a great help here because an attacker can still hijack a connection, but if they do, they can’t send or receive any data over that connection unencrypted,” Stagg said. “An attacker can still target and remove any of those connections.”</p>



<h2 class="wp-block-heading">Detection and mitigation</h2>



<p class="wp-block-paragraph">Even without full patches available, there are steps that network professionals can take to limit risk. Stagg suggests the following:</p>



<ul class="wp-block-list">
<li><strong>Monitor for compromise indicators. </strong>Watch for a full or near-full NAT table, floods of TCP or UDP packets across a wide port range, the same IP address appearing at two physical locations, and anomalous SYN or RST packet sequences.</li>



<li><strong>Enable source IP protection.</strong> Turn on protections such as IP Source Guard to block spoofed packets at the router or firewall.</li>



<li><strong>Segment untrusted traffic.</strong> Place untrusted users on a separate subnet or VLAN, and cap connections per client at roughly under 10,000.</li>



<li><strong>Disable loose connection modes.</strong> Turn off loose connection tracking, port preservation, and endpoint-independent mapping where supported.</li>



<li><strong>Restrict container network access.</strong> Disable network access for untrusted containers and Kubernetes workloads, avoid running as root, and drop default capabilities.</li>



<li><strong>Isolate cloud workloads.</strong> Keep untrusted and trusted workloads off the same NAT gateway, and use dedicated IPs for serverless workloads.</li>
</ul>



<p class="wp-block-paragraph">“One of the attack variations does still work in cases where the attacker and victim are located in different subnets,” Stagg said.</p>



<p class="wp-block-paragraph">Stagg said the underlying lesson of NatJack extends beyond any single patch.</p>



<p class="wp-block-paragraph">“A lot of networks are vulnerable to this, and you can’t always rely on the Layer 2 isolations that are in place,” Stagg said. “When you’re relying on historical design choices, those threat models might not be the same now as they were back then. It’s important to look at those design assumptions and see if there are any updates that might be necessary based on the new threat models.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft's AI revenue reportedly depends on OpenAI for 70 percent]]></title>
<description><![CDATA[Microsoft generated $24.1 billion in AI revenue through OpenAI in the fiscal year ending in June. That's about 70 percent of its total AI business, according to a Bloomberg analysis. The heavy reliance helps explain why a company long known for vendor lock-in has recently been championing open-we...]]></description>
<link>https://tsecurity.de/de/3708889/ai-nachrichten/microsofts-ai-revenue-reportedly-depends-on-openai-for-70-percent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708889/ai-nachrichten/microsofts-ai-revenue-reportedly-depends-on-openai-for-70-percent/</guid>
<pubDate>Thu, 06 Aug 2026 19:46:42 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/08/microsoft_openai.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Microsoft generated $24.1 billion in AI revenue through OpenAI in the fiscal year ending in June. That's about 70 percent of its total AI business, according to a Bloomberg analysis. The heavy reliance helps explain why a company long known for vendor lock-in has recently been championing open-weight models and pushing back against proprietary isolation.</p>
<p>The article <a href="https://the-decoder.com/microsofts-ai-revenue-reportedly-depends-on-openai-for-70-percent/">Microsoft's AI revenue reportedly depends on OpenAI for 70 percent</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lloyds Bank should publish the human cost of its AI savings | Letters]]></title>
<description><![CDATA[Banks should factor in the time spent by humans checking invented facts, writes Dr Gleb TsipurskyYour report (Lloyds Bank to cut £2bn in costs as part of AI-powered strategy, 30 July) raises a question that financial targets alone cannot answer: who absorbs the work when automation fails?Banks of...]]></description>
<link>https://tsecurity.de/de/3708884/ai-nachrichten/lloyds-bank-should-publish-the-human-cost-of-its-ai-savings-letters/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708884/ai-nachrichten/lloyds-bank-should-publish-the-human-cost-of-its-ai-savings-letters/</guid>
<pubDate>Thu, 06 Aug 2026 19:46:37 +0200</pubDate>
<content:encoded><![CDATA[<p>Banks should factor in the time spent by humans checking invented facts, writes <strong>Dr Gleb Tsipursky</strong></p><p>Your report (<a href="https://www.theguardian.com/business/2026/jul/30/lloyds-bank-cut-2bn-costs-part-ai-powered-strategy">Lloyds Bank to cut £2bn in costs as part of AI-powered strategy, 30 July</a>) raises a question that financial targets alone cannot answer: who absorbs the work when automation fails?</p><p>Banks often count the minutes saved by the employee who uses an AI tool. They should also count the time colleagues spend checking invented facts, repairing customer messages, explaining rejected applications and escalating errors. A system can make one team look more productive while moving risk and effort elsewhere.</p> <a href="https://www.theguardian.com/technology/2026/aug/06/lloyds-bank-should-publish-the-human-cost-of-its-ai-savings">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Granola lawsuit raises concerns over AI note-taking app privacy]]></title>
<description><![CDATA[AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed July 30 in a California federal court.



It follows a similar ongoing case in the same district, filed last y...]]></description>
<link>https://tsecurity.de/de/3708885/ai-nachrichten/granola-lawsuit-raises-concerns-over-ai-note-taking-app-privacy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708885/ai-nachrichten/granola-lawsuit-raises-concerns-over-ai-note-taking-app-privacy/</guid>
<pubDate>Thu, 06 Aug 2026 19:46:37 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed<strong> </strong>July 30 in a California federal court.</p>



<p class="wp-block-paragraph">It follows a similar ongoing case in the same district, filed last year, that involves another note-taking and transcription software vendor, Otter.ai.</p>



<p class="wp-block-paragraph">AI note-taking apps have proliferated in recent years, with dedicated tools emerging from vendors including Fellow, Fireflies, Otter, and others, some of which claim to have tens of millions of users. These AI assistants record and transcribe meeting conversations, generating automated summaries and follow-up items. Similar note-taking functionality is also built into virtual meeting platforms such as Google Meet, Microsoft Teams, and Zoom.</p>



<p class="wp-block-paragraph">However, the use of these AI note-taking tools has raised privacy concerns over the ability of some to record and transcribe conversations without the consent of all participants.</p>



<p class="wp-block-paragraph">The proposed class action <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.475308/gov.uscourts.cand.475308.1.0.pdf" target="_blank" rel="noreferrer noopener">complaint</a> against Granola, filed by Florida resident Tarra Chamberlain in the US District Court for the Northern District of California, alleges the company “purposefully” designed its app to record calls without requiring disclosure to all participants.  </p>



<p class="wp-block-paragraph">While some note-taking tools require a bot to join a video or voice call, Granola captures audio directly from the user’s computer, allowing it to transcribe meetings without appearing as a meeting participant.</p>



<p class="wp-block-paragraph">The complaint argues that this violates individual privacy rights as well as the California Invasion of Privacy Act (CIPA) that requires “all-party” consent when recording calls.</p>



<p class="wp-block-paragraph">The complaint also alleges that Granola then by default uses transcription data for commercial purposes, including its use in training its AI models, and “actively advertises the hidden nature of its technology as one of its primary advantages.”</p>



<p class="wp-block-paragraph">Granola did not respond to a request for comment.</p>



<p class="wp-block-paragraph">According to the company’s website, Granola offers two optional “<a href="https://docs.granola.ai/help-center/consent-security-privacy/transparency-solutions/introduction" target="_blank" rel="noreferrer noopener">transparency features</a>” that can be enabled by app users and admins: an automated chat message that alerts participants when transcription begins, and a watermark added to the user’s video feed. The company also <a href="https://docs.granola.ai/help-center/consent-security-privacy/model-training" target="_blank" rel="noreferrer noopener">promises</a> that data used to train its AI models is anonymized and “never sent to third parties.”</p>



<p class="wp-block-paragraph">The Granola case bears similarities to a <a href="https://www.computerworld.com/article/4041849/enterprise-note-taking-apps-face-legal-scrutiny-as-otter-hit-with-privacy-suit.html" target="_blank">separate lawsuit</a> involving Otter.ai. The class action filed last year alleges that Otter.ai records all users without their consent and uses their voices to train its speech recognition AI tools.</p>



<p class="wp-block-paragraph">Reporting on the latest developments in the Otter.ai suit, <em>MLex </em><a href="https://www.mlex.com/mlex/artificial-intelligence/articles/2509190/otter-ai-faces-skeptical-us-judge-in-bid-to-dismiss-privacy-litigation" target="_blank" rel="noreferrer noopener">wrote</a> this week that, during a court hearing Monday, the judge overseeing the case expressed skepticism about the company’s argument to dismiss the case. US District Judge Eumi K. Lee did not issue a ruling from the bench, saying a written judgement would follow.</p>



<p class="wp-block-paragraph">The two cases highlight some of the concerns businesses face when deploying AI note-taking tools.</p>



<p class="wp-block-paragraph">AI notetaking is “more dangerous than any other type of traditional recording apps and tools,” said <a href="https://www.forrester.com/analyst-bio/enza-iannopollo/BIO5004" target="_blank" rel="noreferrer noopener">Enza Iannopollo</a>, Forrester VP and principal analyst, as it raises additional questions about the use of employees’ conversation data.</p>



<p class="wp-block-paragraph">“Specifically, is the recorded data used for training models? Is the voice used for training other AI? How do I get ‘forgotten’ after my data and biometrics have been recorded? These concerns apply to AI specifically and must be added to the traditional privacy and confidentiality concerns organizations have for other type of recording apps and tools,” she said.</p>



<p class="wp-block-paragraph">Before deploying AI note-taking apps, Iannopollo recommends that businesses take appropriate steps to vet the tools and “ensure that all contractual clauses are aligned to the business AI risk appetite and risk management best practices.”</p>



<p class="wp-block-paragraph">“As these tools record, process, store, and share biometric data, organizations must ensure that they comply with all the relevant requirements,” Iannopollo said, adding that transparency and consent notices should be provided to all parties involved in the use of AI note-taking apps.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise passkey security under threat from malware]]></title>
<description><![CDATA[Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.
...]]></description>
<link>https://tsecurity.de/de/3708886/ai-nachrichten/enterprise-passkey-security-under-threat-from-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708886/ai-nachrichten/enterprise-passkey-security-under-threat-from-malware/</guid>
<pubDate>Thu, 06 Aug 2026 19:46:37 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.</p>



<p class="wp-block-paragraph">They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. </p>



<p class="wp-block-paragraph">“The researchers didn’t break the underlying cryptography. They exploited the seams around it: onboarding flows, recovery mechanisms and trust signals that weren’t being validated,” said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence. “That distinction matters because it tells us where the actual risk lives.”</p>



<p class="wp-block-paragraph">The <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">Palo Alto report</a> showed attacks that, it said, “demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts,” as well as “how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.”</p>



<p class="wp-block-paragraph">Palo Alto described three categories of attack, collectively dubbed Pass-ta-key: Pass-ta-key, where an attacker takes over an account protected by a Google-synced passkey using malware running on the victim’s device, without requiring privilege escalation, device unlock or user interaction; Silver Pass-ta-key, which involves an attacker tricking Google Cloud Authenticator into believing the victim has unlocked the device with biometrics, leading to full account takeover without using the victim’s device during authentication; and Golden Pass-ta-key, which allows an attacker to extract all synced passkeys in a form that lets them be shared or sold on the credential black market.</p>



<p class="wp-block-paragraph">Given the complexity of most global enterprise threat surfaces, <a href="https://www.csoonline.com/article/4085426/your-passwordless-future-may-never-fully-arrive.html" target="_blank">some CISOs have struggled</a> with adapting passwordless processes to environments with legacy and virtual environments. Passcodes have <a href="https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html" target="_blank">been recently embraced</a> by enterprise CISOs as the first step in implementing a passwordless strategy.</p>



<p class="wp-block-paragraph">Analysts and consultants in the main agreed that the flaw Palo Alto reports is significant, despite the fact that it assumes the attacker has already penetrated an environment and successfully installed malware. Sadly, given that such penetration only requires one privileged user anywhere to accidentally click on a poisoned link or attachment, the assumption of prior penetration is likely valid.</p>



<h2 class="wp-block-heading">Implementation issues are the problem</h2>



<p class="wp-block-paragraph">What the report reveals is less about any flaws within passcodes directly, and more about the lack of attention paid to a wide range of mechanisms surrounding them. </p>



<p class="wp-block-paragraph">Greis said CISOs now need to focus on what to do, and what to test, based on the assumption that user behavior is not always as expected. </p>



<p class="wp-block-paragraph">In several cases cited in the report, he pointed out, issues occurred “not because the standard is flawed, but because implementations haven’t caught up to it. It mirrors what we’ve seen repeatedly in security: the specification is sound, but the ecosystem implementing it is uneven.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed. </p>



<p class="wp-block-paragraph">“On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response,” he said. “The researchers found real-world services accepting logins without it, which quietly collapses a multi-factor login back into a single factor.”</p>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, added that he would stress to CISOs that this attack assumes a prior successful penetration. </p>



<p class="wp-block-paragraph">“This isn’t passkeys getting hacked from across the internet. It’s what [an attacker] does once they’re already inside the house. So the real headline is that ‘phishing resistant’ stops being resistant the moment the endpoint stops being clean,” he said.</p>



<p class="wp-block-paragraph">“Stop treating verification as optional,” he advised. “Flip it to required, check it server side every single time, and save your hardware bound keys, the YubiKeys of the world, for the accounts that matter most. A key that never leaves a physical device is a key no attacker can ever harvest in bulk.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/orfink/" target="_blank" rel="noreferrer noopener">Or Finkelstein</a>, head of marketing at Secret Double Octopus, agreed that CISOs have gotten complacent about the way in which systems support passkeys.</p>



<p class="wp-block-paragraph">“CISOs should probably look at how user verification is enforced, how enrollment and recovery work, have a clear and enforced policy on whether credentials are synced or device-bound, and have some ITDR system to quickly mitigate suspicious endpoints and authenticators,” he said. “In most serious enterprise environments, EDR and device management reduce the likelihood of initial attacks, but do not close every post-compromise attack path.”</p>



<h2 class="wp-block-heading">Poor support processes weaken passkeys</h2>



<p class="wp-block-paragraph">Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jwgoerlich/" target="_blank" rel="noreferrer noopener">J. Wolfgang Goerlich</a>, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.</p>



<p class="wp-block-paragraph">“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”</p>



<p class="wp-block-paragraph">Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”</p>



<p class="wp-block-paragraph">This article originally appeared on <a href="https://www.csoonline.com/article/4205751/report-passkey-security-issues-could-allow-account-takeover.html" target="_blank">CSOonline</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Naïve raises $28.5M to automate the grunt work of setting up and running a company]]></title>
<description><![CDATA[Taking vibe-coding a step further, Naïve claims its infra can automate most of the work in setting up and running a business.]]></description>
<link>https://tsecurity.de/de/3708874/ai-nachrichten/nave-raises-285m-to-automate-the-grunt-work-of-setting-up-and-running-a-company/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708874/ai-nachrichten/nave-raises-285m-to-automate-the-grunt-work-of-setting-up-and-running-a-company/</guid>
<pubDate>Thu, 06 Aug 2026 19:46:34 +0200</pubDate>
<content:encoded><![CDATA[Taking vibe-coding a step further, Naïve claims its infra can automate most of the work in setting up and running a business.]]></content:encoded>
</item>
<item>
<title><![CDATA[I Built an AI Data Agent Which Can Query Data and Answer Business Questions. Here’s How.]]></title>
<description><![CDATA[A step-by-step guide to building a data agent and conversational interface that let business users to explore data in natural language without SQL
The post I Built an AI Data Agent Which Can Query Data and Answer Business Questions. Here’s How. appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3708865/ai-nachrichten/i-built-an-ai-data-agent-which-can-query-data-and-answer-business-questions-heres-how/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708865/ai-nachrichten/i-built-an-ai-data-agent-which-can-query-data-and-answer-business-questions-heres-how/</guid>
<pubDate>Thu, 06 Aug 2026 19:42:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A step-by-step guide to building a data agent and conversational interface that let business users to explore data in natural language without SQL</p>
<p>The post <a href="https://towardsdatascience.com/i-built-an-ai-data-agent-which-can-query-data-and-answer-business-questions-heres-how/">I Built an AI Data Agent Which Can Query Data and Answer Business Questions. Here’s How.</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records]]></title>
<description><![CDATA[An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and ...]]></description>
<link>https://tsecurity.de/de/3708727/hacking/exposed-sisvisa-database-leaks-102000-brazilian-health-surveillance-records/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708727/hacking/exposed-sisvisa-database-leaks-102000-brazilian-health-surveillance-records/</guid>
<pubDate>Thu, 06 Aug 2026 19:13:18 +0200</pubDate>
<content:encoded><![CDATA[An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransom Cartel Leader Sentenced to 16 Years in U.S.]]></title>
<description><![CDATA[A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes ...]]></description>
<link>https://tsecurity.de/de/3708728/hacking/ransom-cartel-leader-sentenced-to-16-years-in-us/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708728/hacking/ransom-cartel-leader-sentenced-to-16-years-in-us/</guid>
<pubDate>Thu, 06 Aug 2026 19:13:18 +0200</pubDate>
<content:encoded><![CDATA[A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes himself. This week, a federal judge in Virginia […]]]></content:encoded>
</item>
<item>
<title><![CDATA[UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments]]></title>
<description><![CDATA[Written by: Tyler McLellan, Austin Larsen

Introduction
Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastr...]]></description>
<link>https://tsecurity.de/de/3708723/it-security-nachrichten/unc6671-rebrands-multi-brand-vishing-extortion-targets-financial-services-and-enterprise-cloud-environments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708723/it-security-nachrichten/unc6671-rebrands-multi-brand-vishing-extortion-targets-financial-services-and-enterprise-cloud-environments/</guid>
<pubDate>Thu, 06 Aug 2026 19:08:49 +0200</pubDate>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: <span data-rich-links='{"per_n":"Tyler McLellan","per_e":"tymc@google.com","type":"person"}'>Tyler McLellan,</span><span data-rich-links='{"per_n":"Austin Larsen","per_e":"austinlarsen@google.com","type":"person"}'> </span><span data-rich-links='{"per_n":"Austin Larsen","per_e":"austinlarsen@google.com","type":"person"}'>Austin Larsen</span></p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span></h3>
<p><span>Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. </span></p>
<p><span>UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices. These calls lure victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta.</span></p>
<p><span>In this update to </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/"><span>our May 2026 blog</span></a><span>, we detail the infrastructure linkages connecting these extortion brands. We also examine the evolution of UNC6671's targeting including recent activity focused on financial services, private equity, and professional services, and provide hardening guidance to help organizations protect themselves from this threat. </span></p>
<h3><span>UNC6671 Associated Extortion Brands </span></h3>
<p><span>Across UNC6671 intrusions, the initial access and post-compromise tactics, techniques, and procedures (TTPs) have remained remarkably consistent. These operations uniformly leverage tailored IT helpdesk voice phishing (vishing), AiTM credential harvesting panels, and data theft from SaaS applications. Despite this unified technical baseline, extortion messages have used different branding and victim data stolen during these intrusions has been published across distinct data leak sites (DLS) (Figure 1). While public group communications cited an affiliate breakaway as the rationale for the initial rebranding to Redact, subsequent overlaps in phishing templates, victimology, and shared infrastructure conduits suggests that associated actors have subsequently leveraged the Pink, Helix, and Falcon extortion brands to monetize their operations.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image5_j8OyMFx.max-1000x1000.png" alt="Figure 1: UNC6671 Associated DLS Listings by Site">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="n0ggv">Figure 1: UNC6671 Associated DLS Listings by Site</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image7_AjGM9oz.max-1000x1000.png" alt="Figure 2: Helix and Pink DLS">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="n0ggv">Figure 2: Helix and Pink DLS</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image2_fu0mgVu.max-1000x1000.png" alt="Figure 3: Falcon DLS">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="n0ggv">Figure 3: Falcon DLS</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Initial REDACT Rebranding </span></h3>
<p><span>On June 27, 2026, the Redact operators published a blog post on their newly established Data Leak Site (DLS) addressing their alleged rebrand away from BlackFile. In the publication, the group claimed that the original BlackFile brand had been compromised and hijacked by an exiled affiliate. According to Redact, this former associate purportedly operated an unauthorized, lookalike DLS and conducted unsanctioned extortion campaigns under their name using unlinked Tox identities. The operators asserted that this rogue affiliate intentionally orchestrated the "shutdown" of the BlackFile brand in May 2026 to sow confusion among threat intelligence analysts and cyber insurance negotiators, thereby damaging the brand's reputation. To distance themselves from BlackFile, the operators stated that they rebranded as Redact, introducing a single verified Tox ID and PGP key to authenticate all future correspondence. Additionally, the post explicitly denied that pressure from the rival groups influenced their rebranding decision.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image4_Z4ooCAI.max-1000x1000.png" alt="Figure 3: REDACT statement on alleged break from BlackFile">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="n0ggv">Figure 3: REDACT statement on alleged break from BlackFile</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Shared Infrastructure: Connecting the Phishing Ecosystem</span></h4>
<p><span>UNC6671 uses credential harvesting panels hosted on generic root domains masquerading as being related to passkeys, appending victim-specific subdomains to facilitate targeted voice phishing campaigns. Monitoring this consistent digital footprint revealed overlaps in specific victim targeting associated with multiple extortion brands. These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible. </span></p>
<p><span>Rather than maintaining isolated infrastructure for each target, UNC6671 reuses generic root domains across multiple target organizations, creating a traceable chain between extortion brands:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Falcon</strong><span>: The root domain </span><code>passkeyhelpdesk[.]com</code><span> was used to target at least one organization extorted using the Falcon brand. This same domain was simultaneously used to target an organization extorted using the Helix brand, as well as numerous other companies that we did not observe later posted on a DLS. Additionally, root domains such as </span><code>portalpasskey[.]com</code><span> and </span><code>addssopasskey[.]com</code><span> targeted organizations extorted by Falcon, while hosting intermediate targets that bridged directly into Helix infrastructure.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Pink</strong><span>: A subset of unlisted companies were concurrently targeted using additional root domains (such as </span><code>passkeyms[.]com</code><span> and </span><code>mysecurepasskey[.]com</code><span>), which acted as intermediate bridges to another infrastructure cluster focused on </span><code>passkeydeploy[.]com</code><span>. This final domain was simultaneously used to target at least one organization extorted by Pink.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Helix</strong><span>: The root domain </span><code>passkeyhelpdesk[.]com</code><span> directly overlapped targeting between Falcon and Helix. Furthermore, intermediate target organizations bridged additional infrastructure into clusters of subdomains on </span><code>oskeysync[.]com</code><span> and </span><code>keysyncos[.]com</code><span>. These clusters targeted multiple organizations later listed on the Helix DLS.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>BlackFile</strong><span>: Root domains such as </span><code>setupsso[.]com</code><span> and </span><code>idokta[.]com</code><span> were used to target an organization extorted using the BlackFile brand. Intermediary target organizations on </span><code>setupsso[.]com</code><span> acted as bridges to </span><code>passkeydeploy[.]com</code><span> (Pink). Concurrently, </span><code>passkeyuser[.]com</code><span> was used to target another BlackFile victim, where intermediate target organizations bridged into </span><code>passkeyportal[.]com</code><span> (Helix) and </span><code>mysecurepasskey[.]com</code><span>.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Screenshot_2026-08-06_at_10.23.36AM.max-1000x1000.png" alt="Figure 4 - fixed">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="n0ggv">Figure 4: Shared infrastructure across multiple brands</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Phishing templates</span></h4>
<p><span>Analysis shows that the same phishing templates were used across all these domains, with identical code and design hosted simultaneously on different websites, including </span><code>addssopasskey[.]com</code><span>, </span><code>createssopasskey[.]com</code><span>, and </span><code>passkeyhelpdesk[.]com</code><span>. For instance, while </span><code>addssopasskey[.]com</code><span> was strictly used to target organizations later extorted by Falcon, the identically configured </span><code>passkeyhelpdesk[.]com</code><span> domain was simultaneously used to target two entirely separate victims—one of which was claimed by Falcon, and the other by Helix. The widespread deployment of these matching templates to harvest credentials for multiple DLS brands suggests they rely on shared underlying infrastructure.</span></p>
<h2><span>Evolution of Targeting</span></h2>
<p><span>UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. UNC6671 leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels. Their root domains mimic enterprise authentication enrollment portals pairing terms as "passkey," "mfa," or "sso" paired with verbs.</span></p>
<p><span>Between April and May 2026, we observed domains broadly designed to target mature, large-scale enterprises across multiple industries including the manufacturing, real estate, healthcare, and insurance sectors. During this wave of activity, the threat actors appeared to prioritize high-volume credential harvesting across these established enterprise verticals.</span></p>
<p><span>The observed subdomains in the following months appeared to represent a progression in UNC6671’s extortion model. In June 2026, targeting transitioned toward large technology, transportation, and hospitality organizations, seemingly focusing on entities holding valuable intellectual property, software source code, or sensitive VIP client data. By July 2026, the target profile narrowed to focus on the financial and legal sectors, with observed infrastructure directed at private equity firms, law firms, and financial rating agencies. Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands.</span></p>
<p><span>Comparing these two time periods also illustrates an increase in operational tempo. The volume of newly observed infrastructure was evenly distributed between June 1 and July 31, 2026, establishing an accelerated cadence of approximately one domain every 1.6 days, primarily across Cloudflare and DDOS-GUARD. A brief spike in provisioning also occurred between July 20 and July 22, during which seven domains were operationalized within a 72-hour window. This overall June and July tempo represents a measurable increase from earlier activity observed between April 1 and May 31, 2026, where a set of 28 root domains was provisioned at a less frequent rate of one every 2.2 days.</span></p>
<p><span>On the date of publication of this blog, 7 of 8 still resolving phishing domains did not use wildcard DNS indicating that targets discovered through passive DNS data were likely specifically targeted by UNC6671. </span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/image3_QfZjBRo.max-1000x1000.png" alt="Figure 5: Root domain registrations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="s74u8">Figure 5: Root domain registrations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>New Techniques </span></h3>
<p><span>Since our last blog, the tactics across UNC6671 intrusions have been largely consistent; however, we have observed several new techniques.</span></p>
<h4><span>IT Helpdesk and Passkey Pretexts</span></h4>
<p><span>UNC6671 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls. In at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy. During these phone calls, operating under the false pretext of an urgent helpdesk mandate to enable FIDO2 passkeys or update multi-factor authentication enrollment, the caller directs the employee to a lookalike credential-harvesting subdomain (e.g., [</span><code>company].createssopasskey[.]com</code><span> or [</span><code>company].addssopasskey[.]com</code><span>).</span></p>
<h4><span>EvasionTechniques</span></h4>
<p><span>UNC6671 increasingly relies on defense evasion to maintain account-level persistence and conceal its operations. In recent intrusions, the group used compromised email accounts to initiate unauthorized password resets for non-SSO enterprise applications. To prevent end-user detection or automated security alerts, operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations.</span></p>
<h2><span>Ransom Negotiations and Blockchain Analysis</span></h2>
<p><span>Between January 7, 2026, and May 12, 2026, GTIG reviewed 18 BlackFile Bitcoin wallet addresses receiving a total of 141.65 BTC, representing approximately $10.69 million USD at the time of the transactions. Notably, ransom payments to these wallets continued past the publicized Blackfile data leak site shutdown notice on May 11, 2026. Multiple significant cashout events observed in late April and early May confirm that financial operations proceeded without interruption during the rebranding phase.</span></p>
<p><span>Initial ransom demands typically range from $1 million to upwards of $3 million USD. However, the extortion operators shifted demands during negotiations, often agreeing to reductions between 50% and 75% of the initial ransom demand. In over 53% of tracked cases in this timeframe, final payments averaged $750,000 USD (~10.2 BTC). </span></p>
<h3><span>Remediation and Hardening Guidance</span></h3>
<p><span>GTIG recommends that corporate defenders implement the following controls to mitigate identity-centric vishing, AiTM phishing, and programmatic SaaS exfiltration:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><strong>Enforce Phishing-Resistant Multi-factor Authentication:</strong><span> Mandate phishing-resistant authenticators such as FIDO2-compliant roaming security keys, passkeys, and platform authenticators (e.g., Windows Hello for Business, Okta Fastpass) across all SSO environments and enterprise identity providers (IdPs). These authenticators implement WebAuthn standard to enforce cryptographic origin binding between the authenticator and the specific domains it can authenticate to, rendering lookalike domains and AiTM proxies ineffective.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Integrate SaaS Applications and Cloud Platforms with SSO: </strong><span>Maintaining authentication standards across multiple platforms increases the propensity for configuration drift. Different SaaS applications require or support different security features. Integrating business-critical applications with a standard SSO platform such as Entra ID or Okta allows consistent application of security controls across disparate platforms.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Enforce Session Controls:</strong><span> Reduce session lengths to enforce re-authentication at least once per work day. Enforce idle session timeouts, especially for privileged access. These timeouts can be reduced further during active phishing campaigns. Enforce step-up authentication when accessing critical or sensitive resources. Utilize token theft mitigations within authentication platforms such as IP session binding, Device-Bound Session Credentials, or Continuous Access Evaluation.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Restrict Authentication to Trusted Network Sources:</strong><span> Utilize defined network zones coming from known sources such as corporate networks, VPN ranges, and Secure Access Service Edge (SASE) platforms. Define and enforce these ranges within SaaS apps or cloud platforms as well as within authentication policies in Entra ID or Okta.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Require Corporate-Managed Devices for Access: </strong><span>Enforcing that authentication comes from a corporate-managed endpoint with MDM and EDR reduces the attack surface and likelihood that an attacker can utilize an arbitrary device for access. Device checks can be configured as part of authentication policies in Entra ID or Okta.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Deploy Endpoint and Browser Credential Guarding:</strong><span> Enable Google Workspace Password Alert to trigger automated administrative alerts or resets if corporate password hashes are entered into unauthorized domains. For Microsoft 365 environments, configure Microsoft Defender SmartScreen and Credential Protection to block credential submissions on unverified sites.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Monitor IdP Logs for Abandoned Challenge Patterns:</strong><span> Query Okta and Microsoft Entra ID audit logs for MFA registration events (</span><code>system.multifactor.factor.setup</code><span>) that are immediately preceded by authentication failures (</span><code>user.authentication.auth_via_mfa</code><span>) or abandoned push challenges.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Audit UAL Telemetry for Direct Stream Exfiltration: </strong><span>Configure Security Operations Center (SOC) detection pipelines to treat </span><code>FileAccessed</code><span> events with the same criticality as </span><code>FileDownloaded</code><span> when the </span><code>UserAgent</code><span> string identifies a scripting library (</span><code>python-requests</code><span>, </span><code>WindowsPowerShell</code><span>, </span><code>Go-http-client</code><span>) or when the access volume exceeds normal human browsing thresholds.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Restrict and Alert on Residential Proxy Authentication: </strong><span>Create conditional access policies and anomaly alerts for SSO authentication attempts originating from commercial VPN providers (Mullvad, Private Layer) or unassociated residential broadband proxy pools (AT&amp;T, Comcast, Charter) that diverge from established employee geographic baselines.</span></p>
</li>
</ol>
<h3><span>Outlook and Implications</span></h3>
<p><span>The activity associated with UNC6671 highlights the fluidity of threat actor brands relative to persistent tactics, techniques, and procedures. While the extortion brands associated with this activity continue to multiply, the tradecraft across these operations remains anchored in helpdesk vishing, AiTM session interception, and SaaS exfiltration.</span></p>
<p><span>We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout. This assessment is supported by the tight infrastructure overlaps, shared vishing panel deployments, and overlaps in victim targeting observed across BlackFile, Redact, Pink, Helix, and Falcon. However, there are several other scenarios that could explain the broader dynamics across these brands:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Actor Splintering: Internal rifts, financial disputes, or operational security compromises routinely lead to group fragmentation. Former affiliates or splinter cells retaining access to shared initial access playbooks, panel code, and target lists can easily establish independent extortion fronts while continuing to execute identical TTPs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Shared Ecosystem and Panel use: Separate threat groups may simply be leveraging the same commoditized phishing panels, voice-phishing callers, and shared infrastructure. As these AiTM panels and VaaS services become widely available, distinct threat actors can deploy matching infrastructure and pretexts without requiring direct organizational alignment.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Outsourced Extortion: The intrusion operators driving initial access and cloud data exfiltration could remain the same core group of actors, while the extortion and negotiation phases are outsourced to different actors.</span></p>
</li>
</ul>
<p><span>Regardless of whether this activity reflects a fractured threat group, outsourced extortion negotiators, or a broader affiliate network, the initial infection vector leveraged and goals of these campaigns is consistent. Organizations should prioritize phishing-resistant authenticators and behavioral SaaS auditing to disrupt these identity-centric attacks.</span></p>
<h3><span>Indicators of Compromise (IOCs)</span></h3>
<p><span>To assist the wider community in hunting and identifying activity outlined in this blog post, we have provided </span><a href="https://www.virustotal.com/gui/collection/68a3ad0b80290ff51410cc95d0b1e728d5ffaa933e2230b291bd48fbdc406756" rel="noopener" target="_blank"><span>indicators of compromise (IOCs) in a free GTI Collection for registered users</span></a><span>. At the time of publication, identified phishing domains have been added to Google Safe Browsing.</span></p>
<p><span>While this collection provides a comprehensive list of IOCs, defenders should note that the majority of identified IP addresses are commercial VPN nodes, and actual source IPs tend to vary as the actor continuously cycles through new infrastructure. Furthermore, the domains are often stood up and used within minutes of registration; as such, they are provided primarily as examples of past naming conventions and usage patterns rather than as a primary mechanism for real-time blocking.</span></p>
<p> </p>
<div align="left">
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Domain</strong></p>
</td>
<td>
<p><strong>Creation Date</strong></p>
</td>
<td>
<p><strong>Registrar</strong></p>
</td>
<td>
<p><strong>Name Servers</strong></p>
</td>
<td>
<p><strong>Targeted Industry</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>myoktasso[.]com</code></p>
</td>
<td>
<p><span>2026-04-04</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Njalla / Pipe.ma</span></p>
</td>
<td>
<p><span>Financial Services, Transportation</span></p>
</td>
</tr>
<tr>
<td>
<p><code>mypasskeysso[.]com</code></p>
</td>
<td>
<p><span>2026-04-04</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Healthcare</span></p>
</td>
</tr>
<tr>
<td>
<p><code>setupssopasskey[.]com</code></p>
</td>
<td>
<p><span>2026-04-07</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services, Healthcare, Media &amp; Entertainment</span></p>
</td>
</tr>
<tr>
<td>
<p><code>mspasskey[.]com</code></p>
</td>
<td>
<p><span>2026-04-08</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Real Estate, Healthcare, Technology</span></p>
</td>
</tr>
<tr>
<td>
<p><code>activatepasskey[.]com</code></p>
</td>
<td>
<p><span>2026-04-10</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services, Hospitality, Healthcare</span></p>
</td>
</tr>
<tr>
<td>
<p><code>enrollpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-04-10</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services, Energy, Healthcare</span></p>
</td>
</tr>
<tr>
<td>
<p><code>keyokta[.]com</code></p>
</td>
<td>
<p><span>2026-04-13</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Healthcare, Financial Services</span></p>
</td>
</tr>
<tr>
<td>
<p><code>oktaenroll[.]com</code></p>
</td>
<td>
<p><span>2026-04-13</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Healthcare, Construction &amp; Engineering</span></p>
</td>
</tr>
<tr>
<td>
<p><code>oktaportalsso[.]com</code></p>
</td>
<td>
<p><span>2026-04-16</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Retail &amp; Consumer Goods, Healthcare, Legal</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyportal[.]com</code></p>
</td>
<td>
<p><span>2026-04-16</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><code>portalpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-04-16</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Transportation</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyportalsetup[.]com</code></p>
</td>
<td>
<p><span>2026-04-20</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services, Technology</span></p>
</td>
</tr>
<tr>
<td>
<p><code>addoktapasskey[.]com</code></p>
</td>
<td>
<p><span>2026-04-21</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Private Layer (31.7.56.61)</span></p>
</td>
<td>
<p><span>Financial Services, Technology, Media &amp; Entertainment</span></p>
</td>
</tr>
<tr>
<td>
<p><code>deploypasskey[.]com</code></p>
</td>
<td>
<p><span>2026-04-21</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>DDOS-GUARD</span></p>
</td>
<td>
<p><span>Retail &amp; Consumer Goods</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeydeploy[.]com</code></p>
</td>
<td>
<p><span>2026-04-23</span></p>
</td>
<td>
<p><span>Internet Domain Service BS Corp.</span></p>
</td>
<td>
<p><span>DDOS-GUARD</span></p>
</td>
<td>
<p><span>Healthcare, Technology</span></p>
</td>
</tr>
<tr>
<td>
<p><code>activatemypasskey[.]com</code></p>
</td>
<td>
<p><span>2026-04-24</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services</span></p>
</td>
</tr>
<tr>
<td>
<p><code>registerpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-04-29</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>MEVSPACE (193.34.212.132)</span></p>
</td>
<td>
<p><span>Manufacturing</span></p>
</td>
</tr>
<tr>
<td>
<p><code>createpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-05-03</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyadd[.]com</code></p>
</td>
<td>
<p><span>2026-05-08</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>DDOS-GUARD</span></p>
</td>
<td>
<p><span>Business Services, Technology</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyregister[.]com</code></p>
</td>
<td>
<p><span>2026-05-08</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / MEVSPACE</span></p>
</td>
<td>
<p><span>Energy, Technology, Healthcare</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeycenter[.]com</code></p>
</td>
<td>
<p><span>2026-05-11</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Legal, Financial Services, Healthcare</span></p>
</td>
</tr>
<tr>
<td>
<p><code>secureauthpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-05-14</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Healthcare</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyrollout[.]com</code></p>
</td>
<td>
<p><span>2026-05-18</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / MEVSPACE</span></p>
</td>
<td>
<p><span>Non-Corporate, Insurance, Legal</span></p>
</td>
</tr>
<tr>
<td>
<p><code>setpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-05-22</span></p>
</td>
<td>
<p><span>Internet Domain Service BS Corp.</span></p>
</td>
<td>
<p><span>DDOS-GUARD</span></p>
</td>
<td>
<p><span>Technology, Business Services, Construction &amp; Engineering</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyokta[.]com</code></p>
</td>
<td>
<p><span>2026-05-26</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Media &amp; Entertainment, Transportation</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyset[.]com</code></p>
</td>
<td>
<p><span>2026-05-27</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Transportation</span></p>
</td>
</tr>
<tr>
<td>
<p><code>createmypasskey[.]com</code></p>
</td>
<td>
<p><span>2026-05-27</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Construction &amp; Engineering</span></p>
</td>
</tr>
<tr>
<td>
<p><code>newpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-05-28</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Media &amp; Entertainment</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeysupport[.]com</code></p>
</td>
<td>
<p><span>2026-05-29</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Healthcare, Technology, Legal, Retail &amp; Consumer Goods</span></p>
</td>
</tr>
<tr>
<td>
<p><code>sqfepjvmrd[.]xyz</code></p>
</td>
<td>
<p><span>2026-06-01</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>MY-NDNS</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyregistration[.]com</code></p>
</td>
<td>
<p><span>2026-06-02</span></p>
</td>
<td>
<p><span>PDR Ltd. d/b/a PublicDomainRegistry.com</span></p>
</td>
<td>
<p><span>Suspended-Domain</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><code>addmypasskey[.]com</code></p>
</td>
<td>
<p><span>2026-06-03</span></p>
</td>
<td>
<p><span>TUCOWS.COM, CO.</span></p>
</td>
<td>
<p><span>Private Layer (31.7.56.52)</span></p>
</td>
<td>
<p><span>Financial Services, Healthcare, Transportation</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkey-setup[.]com</code></p>
</td>
<td>
<p><span>2026-06-03</span></p>
</td>
<td>
<p><span>Tucows Domains Inc.</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Legal, Financial Services</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkey-portal[.]com</code></p>
</td>
<td>
<p><span>2026-06-05</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / Private Layer</span></p>
</td>
<td>
<p><span>Retail &amp; Consumer Goods, Technology, Media &amp; Entertainment</span></p>
</td>
</tr>
<tr>
<td>
<p><code>startpasskeysetup[.]com</code></p>
</td>
<td>
<p><span>2026-06-05</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / Private Layer</span></p>
</td>
<td>
<p><span>Technology, Healthcare, Retail &amp; Consumer Goods, Construction &amp; Engineering, Media &amp; Entertainment, Financial Services</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkey-connect[.]com</code></p>
</td>
<td>
<p><span>2026-06-05</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Technology</span></p>
</td>
</tr>
<tr>
<td>
<p><code>portalsetuphub[.]com</code></p>
</td>
<td>
<p><span>2026-06-10</span></p>
</td>
<td>
<p><span>PDR Ltd. d/b/a PublicDomainRegistry.com</span></p>
</td>
<td>
<p><span>Suspended-Domain</span></p>
</td>
<td>
<p><span>Financial Services, Healthcare, Energy, Real Estate, Technology, Construction &amp; Engineering</span></p>
</td>
</tr>
<tr>
<td>
<p><code>activatepasskeyportal[.]com</code></p>
</td>
<td>
<p><span>2026-06-12</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / Private Layer</span></p>
</td>
<td>
<p><span>Technology, Energy</span></p>
</td>
</tr>
<tr>
<td>
<p><code>assignpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-06-13</span></p>
</td>
<td>
<p><span>Internet Domain Service BS Corp.</span></p>
</td>
<td>
<p><span>DDOS-GUARD</span></p>
</td>
<td>
<p><span>Construction &amp; Engineering, Financial Services, Energy</span></p>
</td>
</tr>
<tr>
<td>
<p><code>myconnectkey[.]com</code></p>
</td>
<td>
<p><span>2026-06-13</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Transportation, Financial Services, Construction &amp; Engineering, Real Estate, Business Services, Retail &amp; Consumer Goods, Healthcare</span></p>
</td>
</tr>
<tr>
<td>
<p><code>mynewpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-06-13</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Retail &amp; Consumer Goods, Healthcare, Financial Services, Energy</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeycreate[.]com</code></p>
</td>
<td>
<p><span>2026-06-16</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Construction &amp; Engineering, Financial Services, Retail &amp; Consumer Goods, Legal, Energy</span></p>
</td>
</tr>
<tr>
<td>
<p><code>oskeyconnect[.]com</code></p>
</td>
<td>
<p><span>2026-06-17</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services, Real Estate, Legal, Healthcare, Transportation, Utilities, Construction &amp; Engineering, Retail &amp; Consumer Goods, Hospitality</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeycreator[.]com</code></p>
</td>
<td>
<p><span>2026-06-19</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Non-Corporate, Media &amp; Entertainment, Legal, Healthcare, Energy, Technology</span></p>
</td>
</tr>
<tr>
<td>
<p><code>oskeysync[.]com</code></p>
</td>
<td>
<p><span>2026-06-20</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>EZYDOMAIN</span></p>
</td>
<td>
<p><span>Healthcare, Financial Services, Transportation, Real Estate, Technology, Construction &amp; Engineering, Retail &amp; Consumer Goods, Legal, Energy, Utilities, Hospitality</span></p>
</td>
</tr>
<tr>
<td>
<p><code>enablepasskey[.]com</code></p>
</td>
<td>
<p><span>2026-06-22</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Legal</span></p>
</td>
</tr>
<tr>
<td>
<p><code>enablepasskey2fa[.]com</code></p>
</td>
<td>
<p><span>2026-06-22</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Healthcare, Media &amp; Entertainment</span></p>
</td>
</tr>
<tr>
<td>
<p><code>checkpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-06-22</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / Private Layer</span></p>
</td>
<td>
<p><span>Legal, Construction &amp; Engineering, Retail &amp; Consumer Goods, Transportation</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyuser[.]com</code></p>
</td>
<td>
<p><span>2026-06-25</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Construction &amp; Engineering, Legal, Aerospace &amp; Defense, Financial Services, Technology</span></p>
</td>
</tr>
<tr>
<td>
<p><code>keysyncos[.]com</code></p>
</td>
<td>
<p><span>2026-06-30</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services, Real Estate, Healthcare, Technology, Construction &amp; Engineering, Transportation, Legal, Retail &amp; Consumer Goods, Energy, Utilities, Hospitality</span></p>
</td>
</tr>
<tr>
<td>
<p><code>myaccountsecurity[.]com</code></p>
</td>
<td>
<p><span>2026-06-30</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Construction &amp; Engineering</span></p>
</td>
</tr>
<tr>
<td>
<p><code>addpasskey2fa[.]com</code></p>
</td>
<td>
<p><span>2026-07-01</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / Private Layer</span></p>
</td>
<td>
<p><span>Financial Services, Legal</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyenroll[.]com</code></p>
</td>
<td>
<p><span>2026-07-07</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services</span></p>
</td>
</tr>
<tr>
<td>
<p><code>startpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-07-07</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Construction &amp; Engineering, Retail &amp; Consumer Goods</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyenable[.]com</code></p>
</td>
<td>
<p><span>2026-07-08</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services, Legal</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyactivation[.]com</code></p>
</td>
<td>
<p><span>2026-07-09</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services</span></p>
</td>
</tr>
<tr>
<td>
<p><code>createmfa[.]com</code></p>
</td>
<td>
<p><span>2026-07-09</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / Private Layer</span></p>
</td>
<td>
<p><span>Construction &amp; Engineering, Energy, Financial Services, Healthcare, Transportation</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeyhelpdesk[.]com</code></p>
</td>
<td>
<p><span>2026-07-10</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / Private Layer</span></p>
</td>
<td>
<p><span>Financial Services, Energy, Healthcare</span></p>
</td>
</tr>
<tr>
<td>
<p><code>makepasskey[.]com</code></p>
</td>
<td>
<p><span>2026-07-13</span></p>
</td>
<td>
<p><span>Internet Domain Service BS Corp.</span></p>
</td>
<td>
<p><span>DDOS-GUARD</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><code>add-passkey[.]com</code></p>
</td>
<td>
<p><span>2026-07-13</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Healthcare, Energy</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkey-check[.]com</code></p>
</td>
<td>
<p><span>2026-07-13</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services, Media &amp; Entertainment</span></p>
</td>
</tr>
<tr>
<td>
<p><code>addyourpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-07-20</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services, Utilities</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkey-enable[.]com</code></p>
</td>
<td>
<p><span>2026-07-20</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Aerospace &amp; Defense, Technology</span></p>
</td>
</tr>
<tr>
<td>
<p><code>mypasskeyid[.]com</code></p>
</td>
<td>
<p><span>2026-07-21</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / Private Layer</span></p>
</td>
<td>
<p><span>Technology, Retail &amp; Consumer Goods</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeystatus[.]com</code></p>
</td>
<td>
<p><span>2026-07-21</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Energy, Technology</span></p>
</td>
</tr>
<tr>
<td>
<p><code>secure-passkey[.]com</code></p>
</td>
<td>
<p><span>2026-07-21</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Energy, Financial Services</span></p>
</td>
</tr>
<tr>
<td>
<p><code>addssopasskey[.]com</code></p>
</td>
<td>
<p><span>2026-07-22</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / Private Layer</span></p>
</td>
<td>
<p><span>Financial Services</span></p>
</td>
</tr>
<tr>
<td>
<p><code>ssopasskey[.]com</code></p>
</td>
<td>
<p><span>2026-07-22</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><code>createssopasskey[.]com</code></p>
</td>
<td>
<p><span>2026-07-28</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare / Private Layer</span></p>
</td>
<td>
<p><span>Financial Services</span></p>
</td>
</tr>
<tr>
<td>
<p><code>myssopasskey[.]com</code></p>
</td>
<td>
<p><span>2026-07-31</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services</span></p>
</td>
</tr>
<tr>
<td>
<p><code>hubpasskey[.]com</code></p>
</td>
<td>
<p><span>2026-08-03</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services</span></p>
</td>
</tr>
<tr>
<td>
<p><code>passkeymfa[.]com</code></p>
</td>
<td>
<p><span>2026-08-03</span></p>
</td>
<td>
<p><span>NICENIC INTERNATIONAL GROUP CO., LIMITED</span></p>
</td>
<td>
<p><span>Cloudflare</span></p>
</td>
<td>
<p><span>Financial Services</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
<div align="left">
<div>
<div>
<div>
<div>
<div> </div>
</div>
</div>
</div>
</div>
<p><span>Table 1: Indicators of compromise</span></p>
<h4><span>Network Infrastructure and Exfiltration Observables</span></h4>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><strong>IP Address </strong></p>
</th>
<th scope="col">
<p><strong>Role </strong></p>
</th>
<th scope="col">
<p><strong>ASN</strong></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>31.7.56.61</code></p>
</td>
<td>
<p><span>Panel AiTM Reverse Proxy</span></p>
</td>
<td>
<p><span>AS51852 Private Layer INC (Switzerland)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>31.7.56.52</code></p>
</td>
<td>
<p><span>Panel AiTM Reverse Proxy</span></p>
</td>
<td>
<p><span>AS51852 Private Layer INC (Switzerland)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>193.34.212.132</code></p>
</td>
<td>
<p><span>Phishing Kit Backend Proxy</span></p>
</td>
<td>
<p><span>AS201814 MEVSPACE (Poland)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>185.178.208.153</code></p>
</td>
<td>
<p><span>Phishing Reverse Proxy</span></p>
</td>
<td>
<p><span>AS57724 DDOS-GUARD LTD (Russia)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>23.234.75.84</code></p>
</td>
<td>
<p><span>Automated SaaS Data Exfiltration</span></p>
</td>
<td>
<p><span>AS11878 Tzulo, Inc. (United States)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>195.140.213.114</code></p>
</td>
<td>
<p><span>Automated SaaS Data Exfiltration</span></p>
</td>
<td>
<p><span>AS25369 Hydra Communications Ltd (United Kingdom)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>195.140.213.115</code></p>
</td>
<td>
<p><span>Automated SaaS Data Exfiltration</span></p>
</td>
<td>
<p><span>AS25369 Hydra Communications Ltd (United Kingdom)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>107.128.45.122</code></p>
</td>
<td>
<p><span>M365 / Okta Residential Proxy</span></p>
</td>
<td>
<p><span>AS7018 AT&amp;T Enterprises, LLC (United States)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>76.103.148.180</code></p>
</td>
<td>
<p><span>M365 / Okta Residential Proxy</span></p>
</td>
<td>
<p><span>AS7922 Comcast Cable Communications (United States)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>38.42.59.171</code></p>
</td>
<td>
<p><span>M365 / Okta Residential Proxy</span></p>
</td>
<td>
<p><span>AS395354 Starry, Inc. (United States)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>47.218.103.146</code></p>
</td>
<td>
<p><span>M365 / Okta Residential Proxy</span></p>
</td>
<td>
<p><span>AS19108 Optimum / Suddenlink (United States)</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 2: Network infrastructure and exfiltration observables</span></p>
<h4><span>Scripting and SDK User-Agent Strings</span></h4>
<p><code>python-requests/2.28.1</code></p>
<p><code>WindowsPowerShell/5.1</code></p>
<p><code>Mozilla/5.0</code><code> </code><code>(X11;</code><code> </code><code>Ubuntu;</code><code> </code><code>Linux</code><code> </code><code>x86_64;</code><code> </code><code>rv:146.0)</code><code> </code><code>Gecko/20100101</code><code> </code><code>Firefox/146.0</code></p>
<p><code>0811A9866E.com.okta.android.auth/8.18.0</code><code> </code><code>DeviceSDK/1.0.94</code><code> </code><code>Android/16</code><code> </code><code>Google/Pixel_9_Pro_XL</code></p>
<p><span>Figure 6: Scripting and SDK user-agent strings</span></p>
<h3><span>Google Security Operations (SecOps) Detections</span></h3>
<p><span>Google SecOps customers have access to automated detection rules under the Okta and Microsoft 365 rule packs that identify the vishing, MFA modification, and programmatic streaming activity described in this report:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Okta Admin Console Access Failure</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Okta Suspicious Actions from Anonymized IP</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Okta MFA Factor Setup Following Abandoned Challenge</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>O365 SharePoint Bulk File Access or Download via PowerShell</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>O365 SharePoint High Volume File Access Events</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>O365 SharePoint Query for Proprietary or Privileged Information</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Okta User Authentication with Suspicious Behavioral Flags</span></p>
</li>
</ul>
<h3><span>Acknowledgements</span></h3>
<p><span>Special thanks to researcher ZachXBT for assisting with cryptocurrency analysis.  </span></p>
</div>
</div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise Endpoints]]></title>
<description><![CDATA[A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed across enterprise environments. The research, published by SpecterOps researcher Beyviel David, demonstrates how organizations hosting WSUS on an...]]></description>
<link>https://tsecurity.de/de/3708718/it-security-nachrichten/hackers-can-leverage-wsus-servers-to-deliver-malware-and-compromise-enterprise-endpoints/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708718/it-security-nachrichten/hackers-can-leverage-wsus-servers-to-deliver-malware-and-compromise-enterprise-endpoints/</guid>
<pubDate>Thu, 06 Aug 2026 19:08:21 +0200</pubDate>
<content:encoded><![CDATA[<p>A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed across enterprise environments. The research, published by SpecterOps researcher Beyviel David, demonstrates how organizations hosting WSUS on an external SQL Server database face a critical operational risk: attackers with local network access can coerce authentication, […]</p>
<p>The post <a href="https://cybersecuritynews.com/wsus-servers-leveraged-to-deliver-malware/">Hackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise Endpoints</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Web Application Firewall (WAF) Solutions: Our Top Picks by Use Case (2026)]]></title>
<description><![CDATA[No WAF is best for everyone a five-person e-commerce shop and an API-first enterprise need entirely different protection. So instead of a single ranking, this guide matches web application firewalls to the situations where each genuinely wins. The short version: Cloudflare is the easiest strong c...]]></description>
<link>https://tsecurity.de/de/3708710/it-security-nachrichten/web-application-firewall-waf-solutions-our-top-picks-by-use-case-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708710/it-security-nachrichten/web-application-firewall-waf-solutions-our-top-picks-by-use-case-2026/</guid>
<pubDate>Thu, 06 Aug 2026 19:07:55 +0200</pubDate>
<content:encoded><![CDATA[<p>No WAF is best for everyone a five-person e-commerce shop and an API-first enterprise need entirely different protection. So instead of a single ranking, this guide matches web application firewalls to the situations where each genuinely wins. The short version: Cloudflare is the easiest strong choice for most small and mid-sized sites, Imperva remains the […]</p>
<p>The post <a href="https://cyberpress.org/waf-solutions-by-business-size/">Web Application Firewall (WAF) Solutions: Our Top Picks by Use Case (2026)</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Best Firewall Management Tools, Compared and Priced (2026)]]></title>
<description><![CDATA[The firewall policy management market had its earthquake: Skybox Security shut down overnight in February 2025, selling its technology to Tufin and…
Read more →
The post The Best Firewall Management Tools, Compared and Priced (2026) appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3708694/it-security-nachrichten/the-best-firewall-management-tools-compared-and-priced-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708694/it-security-nachrichten/the-best-firewall-management-tools-compared-and-priced-2026/</guid>
<pubDate>Thu, 06 Aug 2026 19:07:48 +0200</pubDate>
<content:encoded><![CDATA[<p>The firewall policy management market had its earthquake: Skybox Security shut down overnight in February 2025, selling its technology to Tufin and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-best-firewall-management-tools-compared-and-priced-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-best-firewall-management-tools-compared-and-priced-2026/">The Best Firewall Management Tools, Compared and Priced (2026)</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building Trust in AI Starts with Trustworthy Data]]></title>
<description><![CDATA[Enterprise AI is transitioning from the “does it work” phase to the “how can we adopt it safely” phase, creating an unprecedented and complex mix of opportunities and challenges for business leaders.]]></description>
<link>https://tsecurity.de/de/3708688/it-security-nachrichten/building-trust-in-ai-starts-with-trustworthy-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708688/it-security-nachrichten/building-trust-in-ai-starts-with-trustworthy-data/</guid>
<pubDate>Thu, 06 Aug 2026 19:07:47 +0200</pubDate>
<content:encoded><![CDATA[Enterprise AI is transitioning from the “does it work” phase to the “how can we adopt it safely” phase, creating an unprecedented and complex mix of opportunities and challenges for business leaders.]]></content:encoded>
</item>
<item>
<title><![CDATA[Johnson Controls Inc. TL280]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device.
The following versions of Johnson Controls Inc. TL280 are affected:

TL280]]></description>
<link>https://tsecurity.de/de/3708684/it-security-nachrichten/johnson-controls-inc-tl280/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708684/it-security-nachrichten/johnson-controls-inc-tl280/</guid>
<pubDate>Thu, 06 Aug 2026 19:07:23 +0200</pubDate>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-218-02.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device.</strong></p>
<p>The following versions of Johnson Controls Inc. TL280 are affected:</p>
<ul>
<li>TL280 &lt;5.63 </li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 4.1</td>
<td>Johnson Controls Inc.</td>
<td>Johnson Controls Inc. TL280</td>
<td>Use of a Broken or Risky Cryptographic Algorithm</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Ireland</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-27871</a></h3>
<div class="csaf-accordion-content">
<p>Hardcoded credentials refer to usernames, passwords, or other authentication information that are embedded directly into the source code of a firmware file. These credentials are often used to access system login and other areas of an application.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-27871">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Johnson Controls Inc. TL280</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Johnson Controls Inc.</div>
<div class="ics-version"><strong>Product Version:</strong><br>Johnson Controls Inc. TL280: &lt;5.63</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>To help reduce the risk of exploitation, Johnson Control suggests considering the following defensive measures: Apply firmware update 5.63.</p>
<p><strong>Mitigation</strong><br>Johnson Controls suggests the following defensive measures: Restrict network access to affected cameras to trusted management VLANs only - do not expose these devices directly to the internet or untrusted network segments.</p>
<p><strong>Mitigation</strong><br>Monitor device access logs for any anomalous authentication activity.</p>
<p><strong>Mitigation</strong><br>Rotate any shared or downstream credentials that may have been derived from or associated with the hard-coded values.</p>
<p><strong>Mitigation</strong><br>Implement network segmentation and place ICS/SCADA devices and systems behind firewalls, isolating them from the business network.</p>
<p><strong>Mitigation</strong><br>When remote access is required, use secure methods such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be kept up to date.</p>
<p><strong>Mitigation</strong><br>Minimize network exposure for all control system devices and/or systems; ensure they are not accessible from the internet.</p>
<p><strong>Mitigation</strong><br>Conduct regular firmware integrity checks to detect unauthorizedmodifications.</p>
<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-08 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href="https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/327.html">CWE-327 Use of a Broken or Risky Cryptographic Algorithm</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.1</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L</a></td>
</tr>
<tr>
<td>4.0</td>
<td>2.1</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Z of VulnCheck reported this vulnerability to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-08-06</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-08-06</td>
<td>1</td>
<td>Initial Republication of Johnson Controls Security Advisory JCI-PSA-2026-08</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[ABB Ability Zenon]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data.
The following versions of ABB Ability Zenon are affected:

IIoT services with MongoDB (4.2) installed on ABB Ability Zenon ...]]></description>
<link>https://tsecurity.de/de/3708685/it-security-nachrichten/abb-ability-zenon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708685/it-security-nachrichten/abb-ability-zenon/</guid>
<pubDate>Thu, 06 Aug 2026 19:07:23 +0200</pubDate>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-218-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data.</strong></p>
<p>The following versions of ABB Ability Zenon are affected:</p>
<ul>
<li>IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* </li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 7.8</td>
<td>ABB</td>
<td>ABB Ability Zenon</td>
<td>Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data into Unsafe Value, Undefined Behavior for Input to API, Incorrect Regular Expression, Uncaught Exception, Reachable Assertion, Allocation of Resources Without Limits or Throttling, Out-of-bounds Write, Improper Output Neutralization for Logs, Improper Certificate Validation, Execution with Unnecessary Privileges</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Switzerland</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-14847</a></h3>
<div class="csaf-accordion-content">
<p>Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-14847">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/130.html">CWE-130 Improper Handling of Length Parameter Inconsistency</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-7928</a></h3>
<div class="csaf-accordion-content">
<p>A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-7928">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/158.html">CWE-158 Improper Neutralization of Null Byte or NUL Character</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-7921</a></h3>
<div class="csaf-accordion-content">
<p>Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3 and MongoDB Server v3.6 versions prior to 3.6.18.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-7921">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/182.html">CWE-182 Collapse of Data into Unsafe Value</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-7925</a></h3>
<div class="csaf-accordion-content">
<p>Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-7925">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/475.html">CWE-475 Undefined Behavior for Input to API</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-7929</a></h3>
<div class="csaf-accordion-content">
<p>A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-7929">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/185.html">CWE-185 Incorrect Regular Expression</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-7923</a></h3>
<div class="csaf-accordion-content">
<p>A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-7923">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/248.html">CWE-248 Uncaught Exception</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-20330</a></h3>
<div class="csaf-accordion-content">
<p>An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-20330">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/617.html">CWE-617 Reachable Assertion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-32036</a></h3>
<div class="csaf-accordion-content">
<p>An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-32036">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/770.html">CWE-770 Allocation of Resources Without Limits or Throttling</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-32040</a></h3>
<div class="csaf-accordion-content">
<p>It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB Server v4.4 versions prior to and including 4.4.28, MongoDB Server v5.0 versions prior to 5.0.4 and MongoDB Server v4.2 versions prior to 4.2.16. Workaround: &gt;= v4.2.16 users and all v4.4 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-32040">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-20333</a></h3>
<div class="csaf-accordion-content">
<p>Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2 versions prior to 4.2.10.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-20333">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/117.html">CWE-117 Improper Output Neutralization for Logs</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2020-7924</a></h3>
<div class="csaf-accordion-content">
<p>Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates. This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions prior to 3.6.21; 4.0 versions prior to 4.0.21; 4.2 versions prior to 4.2.11; 100 versions prior to 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2020-7924">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/295.html">CWE-295 Improper Certificate Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-20328</a></h3>
<div class="csaf-accordion-content">
<p>Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server's certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered during internal testing and affects all versions of the Java driver that support CSFLE. The Java async, Scala, and reactive streams drivers are not impacted. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services originating from applications residing inside the AWS, GCP, and Azure network fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don't use Field Level Encryption.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-20328">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/295.html">CWE-295 Improper Certificate Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.8</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N">CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-20334</a></h3>
<div class="csaf-accordion-content">
<p>A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. MongoDB Compass 1.x version 1.3.0 on Windows and later versions; 1.x versions prior to 1.25.0 on Windows.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-20334">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Ability Zenon</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:</p>
<p><strong>Mitigation</strong><br>Replace bundled MongoDB with a supported version if IIoT services are required:</p>
<p><strong>Mitigation</strong><br>Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.</p>
<p><strong>Mitigation</strong><br>The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer.</p>
<p><strong>Mitigation</strong><br>Uninstall IIoT Services wherever it's not required:</p>
<p><strong>Mitigation</strong><br>If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure.</p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch">https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&amp;LanguageCode=en&amp;DocumentPartId=pdf&amp;Action=Launch</a></p>
<p><strong>Mitigation</strong><br>For more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .<br><a href="https://psirt.abb.com/csaf/2026/9akk108472a9037.json">https://psirt.abb.com/csaf/2026/9akk108472a9037.json</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/250.html">CWE-250 Execution with Unnecessary Privileges</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>ABB PSIRT reported these vulnerabilities to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-07-30</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-07-30</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
<tr>
<td>2026-08-06</td>
<td>2</td>
<td>Initial Republication of ABB PSIRT 9AKK108472A9037</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Medixant RadiAnt DICOM]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened.
The following versions of Medixant RadiAnt DICOM are affected:

RadiAnt DICOM]]></description>
<link>https://tsecurity.de/de/3708686/it-security-nachrichten/medixant-radiant-dicom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708686/it-security-nachrichten/medixant-radiant-dicom/</guid>
<pubDate>Thu, 06 Aug 2026 19:07:23 +0200</pubDate>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-218-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability could allow an attacker to cause the application to crash if a maliciously crafted DICOM file is opened.</strong></p>
<p>The following versions of Medixant RadiAnt DICOM are affected:</p>
<ul>
<li>RadiAnt DICOM &lt;=2025.2</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 4.3</td>
<td>Medixant</td>
<td>Medixant RadiAnt DICOM</td>
<td>Out-of-bounds Write</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Healthcare and Public Health</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Poland</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-17264</a></h3>
<div class="csaf-accordion-content">
<p>Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-17264">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Medixant RadiAnt DICOM</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Medixant</div>
<div class="ics-version"><strong>Product Version:</strong><br>Medixant RadiAnt DICOM: &lt;=2025.2</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Users should update to version 2026.1. It is also recommended to open DICOM files only from trusted and reliable sources. Additionally, the application is compiled with exploit mitigation mechanisms enabled, including Control Flow Guard (CFG), Data Execution Prevention (DEP), and Address Space Layout Randomization (ASLR), which significantly reduces the practical exploitability of the issue.<br><a href="https://www.radiantviewer.com/files/RadiAnt-2026.1-Setup.exe">https://www.radiantviewer.com/files/RadiAnt-2026.1-Setup.exe</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</a></td>
</tr>
<tr>
<td>4.0</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>banda, oriotie, ax123, jihyeon4725, lacroix, and minzu reported this vulnerability to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-08-06</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-08-06</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records]]></title>
<description><![CDATA[An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and ...]]></description>
<link>https://tsecurity.de/de/3708679/it-security-nachrichten/exposed-sisvisa-database-leaks-102000-brazilian-health-surveillance-records/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708679/it-security-nachrichten/exposed-sisvisa-database-leaks-102000-brazilian-health-surveillance-records/</guid>
<pubDate>Thu, 06 Aug 2026 19:05:40 +0200</pubDate>
<content:encoded><![CDATA[An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransom Cartel Leader Sentenced to 16 Years in U.S.]]></title>
<description><![CDATA[A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes ...]]></description>
<link>https://tsecurity.de/de/3708680/it-security-nachrichten/ransom-cartel-leader-sentenced-to-16-years-in-us/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708680/it-security-nachrichten/ransom-cartel-leader-sentenced-to-16-years-in-us/</guid>
<pubDate>Thu, 06 Aug 2026 19:05:40 +0200</pubDate>
<content:encoded><![CDATA[A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes himself. This week, a federal judge in Virginia […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Broadcaster Wins Broad US Blocking Injunction Covering Pirate Sites That Don't Exist Yet]]></title>
<description><![CDATA[An anonymous reader quotes a report from TorrentFreak: Mexican broadcaster TelevisaUnivision (TU) has obtained (PDF) one of the broadest anti-piracy injunctions ever issued by a U.S. federal court. After initially targeting five pirate IPTV streaming operations, the case expanded to cover well ov...]]></description>
<link>https://tsecurity.de/de/3708648/it-security-nachrichten/broadcaster-wins-broad-us-blocking-injunction-covering-pirate-sites-that-dont-exist-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708648/it-security-nachrichten/broadcaster-wins-broad-us-blocking-injunction-covering-pirate-sites-that-dont-exist-yet/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:19 +0200</pubDate>
<content:encoded><![CDATA[An anonymous reader quotes a report from TorrentFreak: Mexican broadcaster TelevisaUnivision (TU) has obtained (PDF) one of the broadest anti-piracy injunctions ever issued by a U.S. federal court. After initially targeting five pirate IPTV streaming operations, the case expanded to cover well over 500 domain names, requiring intermediaries including Cloudflare, GitHub, and a Mexican bank to comply. In addition, the injunction also covers pirate services and content that hasn't been created yet. [...] The case was relatively targeted, naming the IPTV services Thunder TV, Sunset TV, Pop TV, Kaelus TV, and Tele Latino, as well as their alleged operators. The broadcaster argued that these pirate IPTV services threatened its business. TU holds the World Cup rights for sixteen Latin American territories, and its license with FIFA requires it to keep the Mexican broadcast signal from reaching the United States. The pirate services, it argued, put it in breach of that contract, exposing it to "termination and forfeiture of hundreds of millions of dollars in payments." To stop this immediate threat, the company requested a temporary restraining order, hoping to shut down the IPTV services effective immediately.
 
[...] Judge Kathleen Williams granted the temporary restraining order (PDF) on June 5, one day after the case was filed, without hearing from any of the defendants. The initial order prohibited the defendants from infringing TU's own copyrighted works, which include telenovelas and other programming, and from using its trademarks, including all content linked to its licensed World Cup broadcast. Importantly, the order also targeted third parties acting "in active concert," including ISPs, hosts, CDNs, domain registrars, registries, app stores, ad networks, social platforms, search engines, and payment processors. These were ordered, on TU's request and with notice, to disable the listed domains and IP addresses and unmask whoever was behind them. [...]
 
While the injunction is noteworthy for many reasons, the most striking feature is that it's specifically written to include things that don't yet exist. That starts with the content it protects. The order isn't limited to TU's current catalog or the World Cup rights, it covers the infringement of "any copyrighted works or broadcasts that Plaintiffs may in the future produce, license, or acquire rights to transmit." In other words, it covers future copyrights that did not exist when the order was signed. The same applies to the pirate services themselves. The injunction defines its target as the named IPTV operations "and any comparable system," whether "currently in existence or developed in the future," and it applies "regardless of the branding, domain name, or technical configuration used."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Broadcaster+Wins+Broad+US+Blocking+Injunction+Covering+Pirate+Sites+That+Don't+Exist+Yet%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F06%2F0444235%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F08%2F06%2F0444235%2Fbroadcaster-wins-broad-us-blocking-injunction-covering-pirate-sites-that-dont-exist-yet%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/08/06/0444235/broadcaster-wins-broad-us-blocking-injunction-covering-pirate-sites-that-dont-exist-yet?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Granola lawsuit raises concerns over AI note-taking app privacy]]></title>
<description><![CDATA[AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed July 30 in a California federal court.



It follows a similar ongoing case in the same district, filed last y...]]></description>
<link>https://tsecurity.de/de/3708635/it-nachrichten/granola-lawsuit-raises-concerns-over-ai-note-taking-app-privacy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708635/it-nachrichten/granola-lawsuit-raises-concerns-over-ai-note-taking-app-privacy/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:08 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed<strong> </strong>July 30 in a California federal court.</p>



<p class="wp-block-paragraph">It follows a similar ongoing case in the same district, filed last year, that involves another note-taking and transcription software vendor, Otter.ai.</p>



<p class="wp-block-paragraph">AI note-taking apps have proliferated in recent years, with dedicated tools emerging from vendors including Fellow, Fireflies, Otter, and others, some of which claim to have tens of millions of users. These AI assistants record and transcribe meeting conversations, generating automated summaries and follow-up items. Similar note-taking functionality is also built into virtual meeting platforms such as Google Meet, Microsoft Teams, and Zoom.</p>



<p class="wp-block-paragraph">However, the use of these AI note-taking tools has raised privacy concerns over the ability of some to record and transcribe conversations without the consent of all participants.</p>



<p class="wp-block-paragraph">The proposed class action <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.475308/gov.uscourts.cand.475308.1.0.pdf" target="_blank" rel="noreferrer noopener">complaint</a> against Granola, filed by Florida resident Tarra Chamberlain in the US District Court for the Northern District of California, alleges the company “purposefully” designed its app to record calls without requiring disclosure to all participants.  </p>



<p class="wp-block-paragraph">While some note-taking tools require a bot to join a video or voice call, Granola captures audio directly from the user’s computer, allowing it to transcribe meetings without appearing as a meeting participant.</p>



<p class="wp-block-paragraph">The complaint argues that this violates individual privacy rights as well as the California Invasion of Privacy Act (CIPA) that requires “all-party” consent when recording calls.</p>



<p class="wp-block-paragraph">The complaint also alleges that Granola then by default uses transcription data for commercial purposes, including its use in training its AI models, and “actively advertises the hidden nature of its technology as one of its primary advantages.”</p>



<p class="wp-block-paragraph">Granola did not respond to a request for comment.</p>



<p class="wp-block-paragraph">According to the company’s website, Granola offers two optional “<a href="https://docs.granola.ai/help-center/consent-security-privacy/transparency-solutions/introduction" target="_blank" rel="noreferrer noopener">transparency features</a>” that can be enabled by app users and admins: an automated chat message that alerts participants when transcription begins, and a watermark added to the user’s video feed. The company also <a href="https://docs.granola.ai/help-center/consent-security-privacy/model-training" target="_blank" rel="noreferrer noopener">promises</a> that data used to train its AI models is anonymized and “never sent to third parties.”</p>



<p class="wp-block-paragraph">The Granola case bears similarities to a <a href="https://www.computerworld.com/article/4041849/enterprise-note-taking-apps-face-legal-scrutiny-as-otter-hit-with-privacy-suit.html" target="_blank">separate lawsuit</a> involving Otter.ai. The class action filed last year alleges that Otter.ai records all users without their consent and uses their voices to train its speech recognition AI tools.</p>



<p class="wp-block-paragraph">Reporting on the latest developments in the Otter.ai suit, <em>MLex </em><a href="https://www.mlex.com/mlex/artificial-intelligence/articles/2509190/otter-ai-faces-skeptical-us-judge-in-bid-to-dismiss-privacy-litigation" target="_blank" rel="noreferrer noopener">wrote</a> this week that, during a court hearing Monday, the judge overseeing the case expressed skepticism about the company’s argument to dismiss the case. US District Judge Eumi K. Lee did not issue a ruling from the bench, saying a written judgement would follow.</p>



<p class="wp-block-paragraph">The two cases highlight some of the concerns businesses face when deploying AI note-taking tools.</p>



<p class="wp-block-paragraph">AI notetaking is “more dangerous than any other type of traditional recording apps and tools,” said <a href="https://www.forrester.com/analyst-bio/enza-iannopollo/BIO5004" target="_blank" rel="noreferrer noopener">Enza Iannopollo</a>, Forrester VP and principal analyst, as it raises additional questions about the use of employees’ conversation data.</p>



<p class="wp-block-paragraph">“Specifically, is the recorded data used for training models? Is the voice used for training other AI? How do I get ‘forgotten’ after my data and biometrics have been recorded? These concerns apply to AI specifically and must be added to the traditional privacy and confidentiality concerns organizations have for other type of recording apps and tools,” she said.</p>



<p class="wp-block-paragraph">Before deploying AI note-taking apps, Iannopollo recommends that businesses take appropriate steps to vet the tools and “ensure that all contractual clauses are aligned to the business AI risk appetite and risk management best practices.”</p>



<p class="wp-block-paragraph">“As these tools record, process, store, and share biometric data, organizations must ensure that they comply with all the relevant requirements,” Iannopollo said, adding that transparency and consent notices should be provided to all parties involved in the use of AI note-taking apps.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google to face £5bn lawsuit in UK search advertising row]]></title>
<description><![CDATA[Legal action is being brought by Or Brook which claims thousands of UK businesses were overcharged by Google for search advertising. 
Read more: Google to face £5bn lawsuit in UK search advertising row]]></description>
<link>https://tsecurity.de/de/3708628/it-nachrichten/google-to-face-5bn-lawsuit-in-uk-search-advertising-row/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708628/it-nachrichten/google-to-face-5bn-lawsuit-in-uk-search-advertising-row/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Legal action is being brought by Or Brook which claims thousands of UK businesses were overcharged by Google for search advertising. </p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/business/google-face-5bn-lawsuit-uk-search-advertising-row-fine-breach-legal">Google to face £5bn lawsuit in UK search advertising row</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung: New Galaxy Foldables Beat Previous Preorder Record by 30%]]></title>
<description><![CDATA[Samsung’s Galaxy Z Fold8 leads record foldable preorders in the US and South Korea as more buyers move from Flip models to the larger Fold lineup before launch.
The post Samsung: New Galaxy Foldables Beat Previous Preorder Record by 30% appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3708616/it-nachrichten/samsung-new-galaxy-foldables-beat-previous-preorder-record-by-30/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708616/it-nachrichten/samsung-new-galaxy-foldables-beat-previous-preorder-record-by-30/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Samsung’s Galaxy Z Fold8 leads record foldable preorders in the US and South Korea as more buyers move from Flip models to the larger Fold lineup before launch.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-samsung-foldables-break-preorder-records/">Samsung: New Galaxy Foldables Beat Previous Preorder Record by 30%</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The browser is where attacks land. Why is security still focused on the endpoint?]]></title>
<description><![CDATA[Presented by CloudMosa Enterprise work now happens increasingly inside the browser, and that shift has made the browser a primary point of entry for cyberattacks as well. Browser-based attacks have surged over the past two years, according to industry reports, while Gartner projects that more tha...]]></description>
<link>https://tsecurity.de/de/3708623/it-nachrichten/the-browser-is-where-attacks-land-why-is-security-still-focused-on-the-endpoint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708623/it-nachrichten/the-browser-is-where-attacks-land-why-is-security-still-focused-on-the-endpoint/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:02 +0200</pubDate>
<content:encoded><![CDATA[<p><i>Presented by CloudMosa </i></p><hr><p>Enterprise work now happens increasingly inside the browser, and that shift has made the browser a primary point of entry for cyberattacks as well. Browser-based attacks have surged over the past two years, according to industry reports, while Gartner projects that more than <a href="https://www.paloaltonetworks.com/resources/research/gartner-innovation-insight-secure-enterprise-browsers">85% of enterprise workloads</a> will be accessed through the browser by 2027. </p><p>And yet most enterprise security architecture is still built to protect the device rather than the browser session where that work, and those attacks, actually take place, says Shioupyn Shen, founder and CEO of CloudMosa, the company behind Puffin Cloud Security. </p><p>“CloudMosa originally built its cloud architecture to improve browser performance and accessibility, with the expectation that enterprise work would increasingly move into the browser,” Shen says. “Today’s AI-assisted hacking has validated that architecture, demonstrating that what was designed for performance also provides a strong foundation for modern enterprise security.”</p><h2>The browser as the enterprise's operating environment</h2><p>SaaS platforms, CRM and ERP systems, and collaboration tools have made the browser the primary gateway, and often the central workspace, for enterprise operations. As LLM-powered workflows and autonomous AI agents increasingly operate through that same environment, this shift has also redefined what a threat looks like.</p><p>In a device-centric world, security teams could focus much of their attention on endpoints and networks they could monitor, manage and patch on schedule. But because web code now executes locally on the user’s device, every open browser tab can become a potential entry point for malicious scripts, credential theft, supply chain compromise and other browser-based exploits.</p><p>The browser now interprets and executes remote code, manages authenticated sessions across enterprise applications, and increasingly serves as the execution layer for AI workflows and agents.</p><p>"The browser is no longer just another application running on the endpoint," Shen says. "In practice, it has become the central operating environment for modern enterprise work. Traditional browsers were never designed to carry this level of enterprise responsibility. They were built as local interpreters of remote code, not as enterprise-grade execution environments with strong isolation and policy enforcement."</p><h2>Why detection-first security fails against browser-based attacks</h2><p>Detection-first security has a timing problem: it typically begins only after risky code has reached the device and started executing inside the browser. Because modern browsers execute dynamic, often obfuscated JavaScript and WebAssembly locally, attacks can act on the device before endpoint tools have time to respond. Short-lived or fileless attacks may steal credentials, exfiltrate data or complete their objective before a security team can intervene.</p><p>"It is no longer sufficient to ask only whether a threat can be detected," Shen says. "The stronger approach is to prevent risky or malicious code from ever reaching the device in the first place." </p><h2>AI-generated malware strains signature-based detection</h2><p>AI is a force multiplier that lets attackers automate the creation, mutation and deployment of malware at a scale signature-based tools were never designed to handle. It can generate large volumes of malware variants and help attackers adapt fileless and browser-delivered techniques faster than defenders can analyze them and update signatures.</p><p>That matters because polymorphic malware can alter its code or behavior from one instance to the next, making a known signature less reliable. And when attacks are malware-free — relying instead on legitimate tools, compromised sessions or malicious web content — there may be no conventional file signature to detect at all.</p><p>Enterprises have seen <a href="https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/">an 89% increase in attacks by AI-enabled adversaries</a> over the past year, as increasingly automated and adaptive attacks compress the window available for detection and response.</p><p>"Defenders are no longer just chasing more threats, they are chasing a machine that can keep creating new ones," Shen says. "What was good enough in the past 10 years will not be sufficient in the next six months," he adds.</p><h2>Building architecture that removes the attack surface</h2><p>Rather than continuing to refine detection, the more durable response is to change where web code is allowed to execute in the first place.</p><p>"In a conventional browser, the risk comes to the device," Shen says. "In an isolated cloud model, the risk is kept away from it." </p><p>That principle underlies Puffin Cloud Security. Rather than incrementally improving the browser itself, the platform shifts browser execution into isolated cloud environments. That architectural change improves both performance and security.</p><p>The platform runs the original web session, including its JavaScript, WebAssembly, and other executable payloads, inside a disposable cloud environment and streams only a rendered pixel view to the device. Users keep full interactive control over clicking, typing, and scrolling, but the device itself never parses, executes, or stores the original active code. </p><p>CloudMosa says display rasterization — the layer responsible for the pixel stream — accounts for <a href="https://www.cloudmosa.com/overview">roughly 5% of the browser’s total workload</a>, while the more compute-intensive HTML rendering remains isolated in the cloud. As a result, zero-day exploits and AI-generated polymorphic malware have no executable code to run on the endpoint, while fileless attacks or supply chain compromises within SaaS tools remain contained in the cloud.</p><p>"In CloudMosa's view, that means moving from good-enough security on the device to airtight security in the cloud," Shen says.</p><h2>Fitting browser isolation into SWG, CASB and ZTNA stacks</h2><p>Puffin is designed to extend existing security infrastructure rather than replace it. Secure web gateways, cloud access security broker platforms, and zero trust network access tools remain effective at routing traffic, enforcing policy, and controlling access. But none can fully stop local execution once risky content reaches the browser. </p><p>Puffin closes that gap by routing high-risk sessions through isolated cloud environments and enforcing browser-level policy, whether a user connects over a VPN, a home network, a managed device or an unmanaged, bring-your-own-device setup. </p><p>"Organizations can start with narrow use cases, such as high-risk SaaS access or AI agent workflows, and expand without disrupting tools already in place," Shen says. "The goal is not to undo existing investments, but to make them more complete." </p><h2>The choice between faster detection or endpoint isolation</h2><p>Detection will always have a role in enterprise security, but the more consequential question is no longer how quickly a threat can be caught, but whether attackers can reach the endpoint at all. Recent 2026 surveys found <a href="https://www.darktrace.com/resource/the-state-of-ai-cybersecurity-2026">92% of security professionals</a> are concerned about the impact of AI agents, with <a href="https://www.darkreading.com/threat-intelligence/2026-agentic-ai-attack-surface-poster-child">48% naming agentic AI the top attack vector of the year</a>. Shen noted that agents acting autonomously with user-level privileges are especially exposed to prompt injection, session hijacking, and indirect compromise through compromised web content.</p><p>In designing Puffin Cloud Security, CloudMosa has been “paranoid by design,” meaning it invested in an architecture built for worst-case scenarios and for a threat environment where endpoint security and detection alone may not be enough. </p><p>"This is not just a philosophy, but something that is reflected directly in the architecture itself," Shen says. "CloudMosa built earlier for a harsher threat model than most other organizations did, but today's AI-assisted attacks are now making that posture feel increasingly relevant."</p><p>By dividing a full browser into a very small layer on the device and a much larger layer in the cloud, CloudMosa designed this approach to improve both performance and security at the same time: In Puffin Cloud Security’s architecture, an AI agent’s browser activity takes place inside isolated cloud sandboxes. The endpoint receives only a pixel stream, not the original active code, preventing malicious web content from interacting directly with the device, its credentials or connected systems.</p><p>"AI-assisted hacking represents the kind of structural shift that rewards companies willing to rethink browser from the ground up," Shen says. "And so security leaders now have a choice: redesign for foresight, or wait until hindsight makes the lesson unavoidable."</p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Naïve raises $28.5M to automate the grunt work of setting up and running a company]]></title>
<description><![CDATA[Taking vibe-coding a step further, Naive claims its infra can automate most of the work in setting up and running a business.]]></description>
<link>https://tsecurity.de/de/3708572/it-nachrichten/nave-raises-285m-to-automate-the-grunt-work-of-setting-up-and-running-a-company/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708572/it-nachrichten/nave-raises-285m-to-automate-the-grunt-work-of-setting-up-and-running-a-company/</guid>
<pubDate>Thu, 06 Aug 2026 19:03:55 +0200</pubDate>
<content:encoded><![CDATA[Taking vibe-coding a step further, Naive claims its infra can automate most of the work in setting up and running a business.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Keeps The Global Tablet Lead Even After An Eight Percent Dip]]></title>
<description><![CDATA[The global tablet market is experiencing a rough patch right now, but Apple still holds the top spot. Recent research from Omdia shows that total tablet shipments fell 10% in the second quarter of 2026 to around 36 million units. Even with this industry-wide slowdown, the iPad remains the most po...]]></description>
<link>https://tsecurity.de/de/3708458/ios-mac-os/apple-keeps-the-global-tablet-lead-even-after-an-eight-percent-dip/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708458/ios-mac-os/apple-keeps-the-global-tablet-lead-even-after-an-eight-percent-dip/</guid>
<pubDate>Thu, 06 Aug 2026 16:36:21 +0200</pubDate>
<content:encoded><![CDATA[The global tablet market is experiencing a rough patch right now, but Apple still holds the top spot. Recent research from Omdia shows that total tablet shipments fell 10% in the second quarter of 2026 to around 36 million units. Even with this industry-wide slowdown, the iPad remains the most popular choice worldwide, capturing a massive 38% market share while keeping its main rivals far behind.



Supply shortages push brands to focus on premium tablet models



This recent dip broke the usual trend of strong summer sales driven by students heading back to school. For the first time in years, that seasonal demand simply did not happen. While total sales took a hit, the standard iPad continues to make up the bulk of shipments for the market leader. The higher-tier Air and mini models also added a smaller but meaningful boost to keep it safely in first place.



Samsung kept its position in second place with nearly 6 million shipments, facing a 13% drop. The tech giant is dealing with ongoing limits on parts and supplies. Because it is harder to get affordable components, the company is changing its game plan.



Omdia research manager Himani Mukka noted that the industry is putting its limited resources into flagship models instead of budget options. This helps a business protect its profits when it cannot sell as many devices overall.



Looking ahead, hardware alone will not be enough to drive growth for the rest of 2026. Buyers are delaying their upgrades due to rising costs, which means the market will likely stay quiet for a while.]]></content:encoded>
</item>
<item>
<title><![CDATA[Most US Buyers Still Pick Up Their iPhones Through Mobile Carriers]]></title>
<description><![CDATA[When it comes to picking up a new iPhone, most consumers in the United States still skip shopping directly with the manufacturer. A recent report from Consumer Intelligence Research Partners reveals that about three-quarters of all Apple iPhones sold in the country come straight from carrier reta...]]></description>
<link>https://tsecurity.de/de/3708460/ios-mac-os/most-us-buyers-still-pick-up-their-iphones-through-mobile-carriers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708460/ios-mac-os/most-us-buyers-still-pick-up-their-iphones-through-mobile-carriers/</guid>
<pubDate>Thu, 06 Aug 2026 16:36:21 +0200</pubDate>
<content:encoded><![CDATA[When it comes to picking up a new iPhone, most consumers in the United States still skip shopping directly with the manufacturer. A recent report from Consumer Intelligence Research Partners reveals that about three-quarters of all Apple iPhones sold in the country come straight from carrier retail operations. This deep reliance on mobile providers might end up limiting the reach of a newly announced hardware leasing program.



New leasing options face limits due to low direct sales



The tech giant recently partnered with Klarna to offer a new purchase program that lets you lease devices instead of buying them outright. You just pay a monthly fee to use the device. This setup helps you get a new upgrade faster and gives the company a steady supply of used hardware for its global refurbished business.



However, Consumer Intelligence Research Partners points out a huge catch. This new lease setup is only available in the United States for devices bought directly from a physical Apple Store or through the official apple.com website. Right now, only 14 percent of customers actually buy their phones straight from the source.



The remaining chunk of sales goes to big retail chains like Walmart or Best Buy, along with the major mobile carriers. Since these buying habits have remained steady for years, the new lease partnership might not change how the average consumer gets their next device.



While leasing sounds good on paper, the program will struggle to make a real impact unless shoppers decide to break away from their familiar carrier stores.]]></content:encoded>
</item>
<item>
<title><![CDATA[How a software provider closed unknown paths to cloud compromise]]></title>
<description><![CDATA[A healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily in layered controls across a distributed workforce, separating developer environments, segmenting cloud infrastructure, and tightly managing administrative access. Multifactor...]]></description>
<link>https://tsecurity.de/de/3708451/it-security-nachrichten/how-a-software-provider-closed-unknown-paths-to-cloud-compromise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708451/it-security-nachrichten/how-a-software-provider-closed-unknown-paths-to-cloud-compromise/</guid>
<pubDate>Thu, 06 Aug 2026 16:17:08 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily in layered controls across a distributed workforce, separating developer environments, segmenting cloud infrastructure, and tightly managing administrative access. Multifactor authentication (MFA) was enforced broadly, vulnerability scanning was routine, and annual penetration tests were part of the organization’s broader security and compliance efforts.</p>



<p class="wp-block-paragraph">Then an insider threat penetration test (pentest) with NodeZero<sup>®</sup> showed how quickly a single compromised developer credential could enable lateral movement through the environment and toward cloud infrastructure supporting software delivery.</p>



<p class="wp-block-paragraph">“It owned our network in a matter of minutes,” said the company’s IT operations leader.</p>



<p class="wp-block-paragraph">That result changed the conversation immediately. This was not simply a healthcare organization protecting endpoints and servers. The provider was operating in a position of downstream trust, where a compromise would potentially impact customers, healthcare operations, and the systems relying on their software.</p>



<p class="wp-block-paragraph">The organization realized that annual pentests and scanner output were not enough to answer the question that actually mattered: What can an attacker really do once inside the environment?</p>



<p class="wp-block-paragraph">That realization pushed the company toward continuous validation, repeated testing, and a far more operational approach to exposure management.</p>



<h3 class="wp-block-heading">Outcomes at a glance</h3>



<ul class="wp-block-list">
<li>Eliminated internal exposure stemming from 16 weaknesses that compromised four hosts leading to AWS compromise and sensitive data exposure</li>



<li>Reduced AWS exposure leading to critical business impacts to two low-severity weaknesses that were not able to be chained together to lead to any business impact</li>



<li>Eliminated overly permissive, local-administrator access across the environment after NodeZero demonstrated rapid lateral movement and privilege escalation</li>



<li>Implemented privileged access approval workflows and expanded MFA enforcement</li>



<li>Established a repeatable monthly cadence of testing, remediation, and validation</li>
</ul>



<p class="wp-block-paragraph"> src="https://b2b-contenthub.com/wp-content/uploads/2026/08/Image1.png" alt="Internal Testing"&gt;<a href="https://horizon3.ai/wp-content/uploads/2026/05/image-4.png"></a></p>



<p class="wp-block-paragraph"><em>Image 1: Initial internal testing identified 16 weaknesses compromising 4 hosts which led to AWS compromise and sensitive data exposure.</em></p>



<h3 class="wp-block-heading">Impact</h3>



<p class="wp-block-paragraph">The security team believed their network was secure. That was until they understood what an attacker could do once inside their network. The real question wasn’t whether individual weaknesses existed. It was what an attacker could accomplish when those weaknesses were chained together in a real environment.</p>



<p class="wp-block-paragraph">Like many software providers, the organization operated with a widely distributed workforce, extensive developer access requirements, hybrid infrastructure, and growing cloud dependencies. </p>



<p class="wp-block-paragraph">Before adopting NodeZero, the company relied heavily on traditional vulnerability scanning and annual penetration testing. The team understood the limitations immediately after running NodeZero for the first time because the insider threat pentest exposed how quickly those assumptions did break down.</p>



<p class="wp-block-paragraph">“When you think about what an annual penetration test is, it’s a snapshot at a moment in time,” said the IT operations leader. “Technology does not stand still. It only changes.”</p>



<p class="wp-block-paragraph">The team initially attempted a phishing impact pentest paired with their Microsoft 365 environment, but no employees entered credentials during the exercise. Rather than stopping there and trusting their employees would never fall for a phish, the organization decided to model a more realistic compromise scenario by asking three employees — a developer, someone in HR, and someone in support — to intentionally submit credentials into the phishing pentest so the team could observe what an attacker could actually do with different levels of access.</p>



<p class="wp-block-paragraph">That decision quickly exposed where the real risk existed.</p>



<p class="wp-block-paragraph">The HR and support accounts were effectively contained, but once NodeZero impersonated the developer account, the attack path expanded rapidly. The platform cracked password hashes, escalated privileges, moved laterally across segmented environments, and attempted to traverse toward AWS-connected resources.</p>



<p class="wp-block-paragraph">“We’re completely segmented,” said the operations leader. “We thought we were fine by being siloed. But NodeZero jumped the segments.”</p>



<p class="wp-block-paragraph">The speed of the compromise surprised the team, but the path itself was even more important. A single developer system with elevated access had effectively become the pivot point that would allow attackers to move through the environment.</p>



<p class="wp-block-paragraph">That moment reframed the problem entirely. The organization was no longer looking at isolated vulnerabilities. It was looking at exposure, attack chaining, and the reality that one compromised developer credential could potentially become something much larger.</p>



<p class="wp-block-paragraph"> src="https://b2b-contenthub.com/wp-content/uploads/2026/08/Image2.png" alt="Image2"&gt;<a href="https://horizon3.ai/wp-content/uploads/2026/05/image-3.png"></a></p>



<p class="wp-block-paragraph"><em>Image 2: NodeZero demonstrated how a compromised developer path could move laterally across segmented environments to obtain host compromise.</em></p>



<p class="wp-block-paragraph">Click <a href="https://horizon3.ai/intelligence/blogs/patch-tuesday-to-pentest-wednesday-cloud-compromise/#:~:text=operations%20moving%20forward.-,Mitigation,-The%20insider%20threat" target="_blank" rel="noreferrer noopener">here</a> to explore the details around mitigation and remediation efforts.</p>



<h3 class="wp-block-heading">Conclusion</h3>



<p class="wp-block-paragraph">“Ultimately, our goal is to make sure our staff has jobs to come to each day,” said the IT operations leader.</p>



<p class="wp-block-paragraph">That perspective reframed the problem entirely. Not as compliance or vulnerability management, but as the ongoing responsibility to continuously validate that it is not possible for a real adversary to traverse their environment.</p>



<p class="wp-block-paragraph"><a href="https://horizon3.ai/" target="_blank" rel="noreferrer noopener">Learn more about Horizon3.ai and NodeZero.</a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Snowflake extortionist admits 165-victim cloud crime spree – and squeezing one target twice]]></title>
<description><![CDATA[Connor Moucka pleads guilty over sprawling 2024 campaign that looted billions of records]]></description>
<link>https://tsecurity.de/de/3708434/it-nachrichten/snowflake-extortionist-admits-165-victim-cloud-crime-spree-and-squeezing-one-target-twice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708434/it-nachrichten/snowflake-extortionist-admits-165-victim-cloud-crime-spree-and-squeezing-one-target-twice/</guid>
<pubDate>Thu, 06 Aug 2026 16:07:45 +0200</pubDate>
<content:encoded><![CDATA[Connor Moucka pleads guilty over sprawling 2024 campaign that looted billions of records]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-1728 | WSO2 API Control Plane privileges management (WID-SEC-2026-2085)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in WSO2 API Control Plane, API Manager, Carbon API Manager Rest API Common Functions, Carbon API Manager Rest API Utility, Traffic Manager and Universal Gateway. This affects an unknown function. The manipulation results in improper privilege manag...]]></description>
<link>https://tsecurity.de/de/3708379/sicherheitsluecken/cve-2026-1728-wso2-api-control-plane-privileges-management-wid-sec-2026-2085/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708379/sicherheitsluecken/cve-2026-1728-wso2-api-control-plane-privileges-management-wid-sec-2026-2085/</guid>
<pubDate>Thu, 06 Aug 2026 15:59:09 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/wso2:api_control_plane">WSO2 API Control Plane, API Manager, Carbon API Manager Rest API Common Functions, Carbon API Manager Rest API Utility, Traffic Manager and Universal Gateway</a>. This affects an unknown function. The manipulation results in improper privilege management.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-1728">CVE-2026-1728</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[How a global investment firm reduced security surprises]]></title>
<description><![CDATA[Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty.



Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matter?



For a gl...]]></description>
<link>https://tsecurity.de/de/3708375/it-security-nachrichten/how-a-global-investment-firm-reduced-security-surprises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708375/it-security-nachrichten/how-a-global-investment-firm-reduced-security-surprises/</guid>
<pubDate>Thu, 06 Aug 2026 15:53:44 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty.</p>



<p class="wp-block-paragraph">Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matter?</p>



<p class="wp-block-paragraph">For a global investment firm operating across 18 locations, that question became increasingly important. A small security engineering team was responsible for securing a growing environment while balancing infrastructure projects, identity management, user support, and the countless responsibilities that come with protecting a modern enterprise.</p>



<p class="wp-block-paragraph">The team wasn’t struggling to generate findings. They were struggling to understand which findings represented real risk, whether remediation efforts were working, and how to ensure leadership would never be surprised by an exposure that should have been discovered earlier.</p>



<p class="wp-block-paragraph">That journey led them from point-in-time testing to continuous validation.</p>



<h3 class="wp-block-heading">Outcomes at a glance</h3>



<ul class="wp-block-list">
<li>Reduced impacts from 251 to 0 in a same-scope internal penetration test (pentest)</li>



<li>Reduced compromised credentials from 52 to 0</li>



<li>Reduced compromised hosts from 67 to 0</li>



<li>Reduced cracked Active Directory passwords from 40 to 0</li>



<li>Expanded continuous validation across 18 locations using a phased rollout strategy</li>



<li>Enabled a lean security team to continuously validate risk without significant operational overhead</li>
</ul>



<h3 class="wp-block-heading">Impact</h3>



<p class="wp-block-paragraph">The team wasn’t expecting perfection. Every environment contains weaknesses, and no experienced security practitioner assumes an internal pentest will come back clean.</p>



<p class="wp-block-paragraph">What surprised them was how effectively those weaknesses could be chained together once an attacker gained a foothold.</p>



<p class="wp-block-paragraph">One of the firm’s early internal pentests identified 85 weaknesses. By itself, the number wouldn’t have stood out to most security teams. The real concern wasn’t the weaknesses themselves. It was what those weaknesses enabled.</p>



<p class="wp-block-paragraph">NodeZero<sup>®</sup> showed that those weaknesses could produce 251 impacts, including domain compromise, sensitive data exposure, ransomware exposure, host compromise, domain user compromise, and compromised credentials. </p>



<p class="wp-block-paragraph">That distinction matters because attackers don’t exploit weaknesses in isolation. They chain weaknesses, misconfigurations, and credentials together to achieve an objective. A low-priority finding on its own may appear manageable, but when combined with other weaknesses, it can become part of a pathway to something much more serious.</p>



<p class="wp-block-paragraph"><em>Figure 1. An early internal pentest identified 85 weaknesses that led to 251 impacts, including domain compromise, ransomware exposure, sensitive data exposure, and host compromise.</em></p>



<p class="wp-block-paragraph">As the organization’s senior security engineer explained: “That impact section in NodeZero is just pure evidence of what can happen in a real life scenario.”</p>



<p class="wp-block-paragraph">The shift from theoretical risk to demonstrated impact changed how the team approached remediation, shifting the conversation from identifying weaknesses to understanding their potential business impact.</p>



<h3 class="wp-block-heading">Background</h3>



<p class="wp-block-paragraph">Like many organizations, this organization was already investing in security testing. The challenge wasn’t finding another tool. It was finding an <em>approach that could scale across the business </em>without creating additional work for a small security team already balancing infrastructure projects, identity management, user support, and countless other responsibilities.</p>



<p class="wp-block-paragraph">As the senior security engineer described: “NodeZero is, let’s say, 5% of my work. I’m dealing with a million different things, a million different projects, a million different responsibilities.”</p>



<p class="wp-block-paragraph">That reality made operational simplicity more than a convenience. It became a requirement.</p>



<p class="wp-block-paragraph">The team had experience with security testing platforms that required significant infrastructure and ongoing maintenance to keep running effectively. For a small team juggling competing priorities, that overhead mattered. NodeZero offered a different model. The platform was simple to deploy, easy to operate, and allowed the team to begin testing immediately without dedicating resources to managing complex hardware infrastructure.</p>



<p class="wp-block-paragraph">That ease of deployment became particularly important because the team wasn’t interested in running a proof of concept. They wanted to build a sustainable program that could scale with the business.</p>



<p class="wp-block-paragraph">Click <a href="https://horizon3.ai/intelligence/blogs/patch-tuesday-to-pentest-wednesday-reducing-security-surprises/#:~:text=with%20the%20business.-,Mitigation,-Technology%20wasn%E2%80%99t%20the" target="_blank" rel="noreferrer noopener">here</a> to continue reading about the obstacles the organization faced and how they mitigated them.</p>



<h2 class="wp-block-heading">The need to validate outcomes</h2>



<p class="wp-block-paragraph">The objective was never to eliminate every weakness. It was to eliminate uncertainty around the risks that mattered most.</p>



<p class="wp-block-paragraph">That’s the difference between measuring activity and validating outcomes.</p>



<p class="wp-block-paragraph"><a href="https://horizon3.ai/" target="_blank" rel="noreferrer noopener">Learn more about Horizon3.ai and NodeZero.</a></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Photos: Black Hat USA 2026]]></title>
<description><![CDATA[Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors: Stellar Cyber, Tines, Filigran, Delinea, Prophet AI, Air Security, Legion Security. Featured people: Kunal Modasiya (Qualys) on going from vul...]]></description>
<link>https://tsecurity.de/de/3708372/it-security-nachrichten/photos-black-hat-usa-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708372/it-security-nachrichten/photos-black-hat-usa-2026/</guid>
<pubDate>Thu, 06 Aug 2026 15:48:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors: Stellar Cyber, Tines, Filigran, Delinea, Prophet AI, Air Security, Legion Security. Featured people: Kunal Modasiya (Qualys) on going from vulnerability disclosure to autonomous remediation at machine speed. Jeremiah Grossman and Robert Hansen (Root Evidence) signing their book The End of Guessing. Allie Mellen (Forrester) signing her book Code War: How Nations … <a href="https://www.helpnetsecurity.com/2026/08/06/black-hat-usa-2026-photos/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/06/black-hat-usa-2026-photos/">Photos: Black Hat USA 2026</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Don't tell Tim Cook, but Apple's M5 MacBook Pro 14-inch just got a price cut at Amazon]]></title>
<description><![CDATA[If you want to beat Apple's price hikes, the M5 MacBook Pro for creators, students, and business pros just got a welcome price cut at Amazon.]]></description>
<link>https://tsecurity.de/de/3708364/it-nachrichten/dont-tell-tim-cook-but-apples-m5-macbook-pro-14-inch-just-got-a-price-cut-at-amazon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708364/it-nachrichten/dont-tell-tim-cook-but-apples-m5-macbook-pro-14-inch-just-got-a-price-cut-at-amazon/</guid>
<pubDate>Thu, 06 Aug 2026 15:47:34 +0200</pubDate>
<content:encoded><![CDATA[If you want to beat Apple's price hikes, the M5 MacBook Pro for creators, students, and business pros just got a welcome price cut at Amazon.]]></content:encoded>
</item>
<item>
<title><![CDATA[Buggy microcontrollers making up some of the world's most important servers can be easily backdoored]]></title>
<description><![CDATA[Researchers found more than a dozen new flaws plaguing baseboard management controllers.]]></description>
<link>https://tsecurity.de/de/3708365/it-nachrichten/buggy-microcontrollers-making-up-some-of-the-worlds-most-important-servers-can-be-easily-backdoored/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708365/it-nachrichten/buggy-microcontrollers-making-up-some-of-the-worlds-most-important-servers-can-be-easily-backdoored/</guid>
<pubDate>Thu, 06 Aug 2026 15:47:34 +0200</pubDate>
<content:encoded><![CDATA[Researchers found more than a dozen new flaws plaguing baseboard management controllers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise passkey security under threat from malware]]></title>
<description><![CDATA[Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.
...]]></description>
<link>https://tsecurity.de/de/3708304/it-security-nachrichten/enterprise-passkey-security-under-threat-from-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708304/it-security-nachrichten/enterprise-passkey-security-under-threat-from-malware/</guid>
<pubDate>Thu, 06 Aug 2026 15:27:38 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.</p>



<p class="wp-block-paragraph">They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. </p>



<p class="wp-block-paragraph">“The researchers didn’t break the underlying cryptography. They exploited the seams around it: onboarding flows, recovery mechanisms and trust signals that weren’t being validated,” said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence. “That distinction matters because it tells us where the actual risk lives.”</p>



<p class="wp-block-paragraph">The <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">Palo Alto report</a> showed attacks that, it said, “demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts,” as well as “how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.”</p>



<p class="wp-block-paragraph">Palo Alto described three categories of attack, collectively dubbed Pass-ta-key: Pass-ta-key, where an attacker takes over an account protected by a Google-synced passkey using malware running on the victim’s device, without requiring privilege escalation, device unlock or user interaction; Silver Pass-ta-key, which involves an attacker tricking Google Cloud Authenticator into believing the victim has unlocked the device with biometrics, leading to full account takeover without using the victim’s device during authentication; and Golden Pass-ta-key, which allows an attacker to extract all synced passkeys in a form that lets them be shared or sold on the credential black market.</p>



<p class="wp-block-paragraph">Given the complexity of most global enterprise threat surfaces, <a href="https://www.csoonline.com/article/4085426/your-passwordless-future-may-never-fully-arrive.html" target="_blank">some CISOs have struggled</a> with adapting passwordless processes to environments with legacy and virtual environments. Passcodes have <a href="https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html" target="_blank">been recently embraced</a> by enterprise CISOs as the first step in implementing a passwordless strategy.</p>



<p class="wp-block-paragraph">Analysts and consultants in the main agreed that the flaw Palo Alto reports is significant, despite the fact that it assumes the attacker has already penetrated an environment and successfully installed malware. Sadly, given that such penetration only requires one privileged user anywhere to accidentally click on a poisoned link or attachment, the assumption of prior penetration is likely valid.</p>



<h2 class="wp-block-heading">Implementation issues are the problem</h2>



<p class="wp-block-paragraph">What the report reveals is less about any flaws within passcodes directly, and more about the lack of attention paid to a wide range of mechanisms surrounding them. </p>



<p class="wp-block-paragraph">Greis said CISOs now need to focus on what to do, and what to test, based on the assumption that user behavior is not always as expected. </p>



<p class="wp-block-paragraph">In several cases cited in the report, he pointed out, issues occurred “not because the standard is flawed, but because implementations haven’t caught up to it. It mirrors what we’ve seen repeatedly in security: the specification is sound, but the ecosystem implementing it is uneven.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed. </p>



<p class="wp-block-paragraph">“On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response,” he said. “The researchers found real-world services accepting logins without it, which quietly collapses a multi-factor login back into a single factor.”</p>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, added that he would stress to CISOs that this attack assumes a prior successful penetration. </p>



<p class="wp-block-paragraph">“This isn’t passkeys getting hacked from across the internet. It’s what [an attacker] does once they’re already inside the house. So the real headline is that ‘phishing resistant’ stops being resistant the moment the endpoint stops being clean,” he said.</p>



<p class="wp-block-paragraph">“Stop treating verification as optional,” he advised. “Flip it to required, check it server side every single time, and save your hardware bound keys, the YubiKeys of the world, for the accounts that matter most. A key that never leaves a physical device is a key no attacker can ever harvest in bulk.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/orfink/" target="_blank" rel="noreferrer noopener">Or Finkelstein</a>, head of marketing at Secret Double Octopus, agreed that CISOs have gotten complacent about the way in which systems support passkeys.</p>



<p class="wp-block-paragraph">“CISOs should probably look at how user verification is enforced, how enrollment and recovery work, have a clear and enforced policy on whether credentials are synced or device-bound, and have some ITDR system to quickly mitigate suspicious endpoints and authenticators,” he said. “In most serious enterprise environments, EDR and device management reduce the likelihood of initial attacks, but do not close every post-compromise attack path.”</p>



<h2 class="wp-block-heading">Poor support processes weaken passkeys</h2>



<p class="wp-block-paragraph">Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jwgoerlich/" target="_blank" rel="noreferrer noopener">J. Wolfgang Goerlich</a>, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.</p>



<p class="wp-block-paragraph">“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”</p>



<p class="wp-block-paragraph">Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise passkey security under threat from malware]]></title>
<description><![CDATA[Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.
...]]></description>
<link>https://tsecurity.de/de/3708293/it-nachrichten/enterprise-passkey-security-under-threat-from-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708293/it-nachrichten/enterprise-passkey-security-under-threat-from-malware/</guid>
<pubDate>Thu, 06 Aug 2026 15:22:45 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.</p>



<p class="wp-block-paragraph">They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. </p>



<p class="wp-block-paragraph">“The researchers didn’t break the underlying cryptography. They exploited the seams around it: onboarding flows, recovery mechanisms and trust signals that weren’t being validated,” said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence. “That distinction matters because it tells us where the actual risk lives.”</p>



<p class="wp-block-paragraph">The <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">Palo Alto report</a> showed attacks that, it said, “demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts,” as well as “how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.”</p>



<p class="wp-block-paragraph">Palo Alto described three categories of attack, collectively dubbed Pass-ta-key: Pass-ta-key, where an attacker takes over an account protected by a Google-synced passkey using malware running on the victim’s device, without requiring privilege escalation, device unlock or user interaction; Silver Pass-ta-key, which involves an attacker tricking Google Cloud Authenticator into believing the victim has unlocked the device with biometrics, leading to full account takeover without using the victim’s device during authentication; and Golden Pass-ta-key, which allows an attacker to extract all synced passkeys in a form that lets them be shared or sold on the credential black market.</p>



<p class="wp-block-paragraph">Given the complexity of most global enterprise threat surfaces, <a href="https://www.csoonline.com/article/4085426/your-passwordless-future-may-never-fully-arrive.html" target="_blank">some CISOs have struggled</a> with adapting passwordless processes to environments with legacy and virtual environments. Passcodes have <a href="https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html" target="_blank">been recently embraced</a> by enterprise CISOs as the first step in implementing a passwordless strategy.</p>



<p class="wp-block-paragraph">Analysts and consultants in the main agreed that the flaw Palo Alto reports is significant, despite the fact that it assumes the attacker has already penetrated an environment and successfully installed malware. Sadly, given that such penetration only requires one privileged user anywhere to accidentally click on a poisoned link or attachment, the assumption of prior penetration is likely valid.</p>



<h2 class="wp-block-heading">Implementation issues are the problem</h2>



<p class="wp-block-paragraph">What the report reveals is less about any flaws within passcodes directly, and more about the lack of attention paid to a wide range of mechanisms surrounding them. </p>



<p class="wp-block-paragraph">Greis said CISOs now need to focus on what to do, and what to test, based on the assumption that user behavior is not always as expected. </p>



<p class="wp-block-paragraph">In several cases cited in the report, he pointed out, issues occurred “not because the standard is flawed, but because implementations haven’t caught up to it. It mirrors what we’ve seen repeatedly in security: the specification is sound, but the ecosystem implementing it is uneven.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed. </p>



<p class="wp-block-paragraph">“On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response,” he said. “The researchers found real-world services accepting logins without it, which quietly collapses a multi-factor login back into a single factor.”</p>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, added that he would stress to CISOs that this attack assumes a prior successful penetration. </p>



<p class="wp-block-paragraph">“This isn’t passkeys getting hacked from across the internet. It’s what [an attacker] does once they’re already inside the house. So the real headline is that ‘phishing resistant’ stops being resistant the moment the endpoint stops being clean,” he said.</p>



<p class="wp-block-paragraph">“Stop treating verification as optional,” he advised. “Flip it to required, check it server side every single time, and save your hardware bound keys, the YubiKeys of the world, for the accounts that matter most. A key that never leaves a physical device is a key no attacker can ever harvest in bulk.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/orfink/" target="_blank" rel="noreferrer noopener">Or Finkelstein</a>, head of marketing at Secret Double Octopus, agreed that CISOs have gotten complacent about the way in which systems support passkeys.</p>



<p class="wp-block-paragraph">“CISOs should probably look at how user verification is enforced, how enrollment and recovery work, have a clear and enforced policy on whether credentials are synced or device-bound, and have some ITDR system to quickly mitigate suspicious endpoints and authenticators,” he said. “In most serious enterprise environments, EDR and device management reduce the likelihood of initial attacks, but do not close every post-compromise attack path.”</p>



<h2 class="wp-block-heading">Poor support processes weaken passkeys</h2>



<p class="wp-block-paragraph">Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jwgoerlich/" target="_blank" rel="noreferrer noopener">J. Wolfgang Goerlich</a>, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.</p>



<p class="wp-block-paragraph">“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”</p>



<p class="wp-block-paragraph">Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”</p>



<p class="wp-block-paragraph">This article originally appeared on <a href="https://www.csoonline.com/article/4205751/report-passkey-security-issues-could-allow-account-takeover.html" target="_blank">CSOonline</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Putting A Hot iPhone In The Refrigerator Will Ruin Your Device]]></title>
<description><![CDATA[If you spend any time on TikTok, you have probably seen videos telling you to toss an overheating iPhone into the refrigerator to cool it down fast. The logic seems to make perfect sense when the summer heat is breaking records. You might be tempted to try it out when that high temperature warnin...]]></description>
<link>https://tsecurity.de/de/3708231/ios-mac-os/why-putting-a-hot-iphone-in-the-refrigerator-will-ruin-your-device/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708231/ios-mac-os/why-putting-a-hot-iphone-in-the-refrigerator-will-ruin-your-device/</guid>
<pubDate>Thu, 06 Aug 2026 15:19:54 +0200</pubDate>
<content:encoded><![CDATA[If you spend any time on TikTok, you have probably seen videos telling you to toss an overheating iPhone into the refrigerator to cool it down fast. The logic seems to make perfect sense when the summer heat is breaking records. You might be tempted to try it out when that high temperature warning pops up on your screen. You should ignore this viral advice entirely because it will ruin your device and cost you a lot of money in repairs.



Dropping the temperature too fast causes permanent internal moisture damage



Taking a phone that is running above 110 degrees and dropping it into a cold environment is a recipe for disaster. This drastic shift causes thermal shock. The different materials inside the phone shrink at different speeds when exposed to sudden cold. This uneven shrinking puts massive stress on the internal circuits, the screen, and the camera hardware.



Beyond thermal shock, the cold air introduces a severe risk of condensation. Your phone is not completely sealed against the air. If you put a cold soda can outside on a warm day, water droplets form on the metal. The same thing happens inside your phone when you put it in the fridge. The normal air inside the device turns into liquid water.



This moisture collects on sensitive electronics and damages the battery over time. In a worst-case scenario, a ruined battery can even catch fire.



Move your hot device to a shaded room to cool down



Modern phones have built-in safety features designed by Apple to protect their internal parts from heat. If you see a high temperature warning on your screen, the system is already working to prevent hardware damage. The phone will shut down non-essential functions to keep itself safe.



You do not need to intervene with extreme cold. Instead, just unplug the device if it is attached to a charger. Take off the case to help the trapped heat escape. Move the phone out of direct sunlight and leave it alone in a cool room. Giving it a few hours to rest will bring the internal temperature back down safely.



Avoiding the heat in the first place is always the smartest move. Try not to leave any electronics in a parked car during the summer. A car interior can reach dangerous temperatures in just a few minutes. Keep your phone in your pocket or a bag when walking around outdoors.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare Launches Open-Source OS to Secure AI Agents’ Access to Internal Data]]></title>
<description><![CDATA[Cloudflare has open-sourced Cloudflare OS, a platform designed to provide enterprise AI agents with controlled access to internal systems, company context, and workflows without exposing long-lived credentials or bypassing access controls. This release addresses a significant security challenge f...]]></description>
<link>https://tsecurity.de/de/3708197/hacking/cloudflare-launches-open-source-os-to-secure-ai-agents-access-to-internal-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708197/hacking/cloudflare-launches-open-source-os-to-secure-ai-agents-access-to-internal-data/</guid>
<pubDate>Thu, 06 Aug 2026 15:13:57 +0200</pubDate>
<content:encoded><![CDATA[<p>Cloudflare has open-sourced Cloudflare OS, a platform designed to provide enterprise AI agents with controlled access to internal systems, company context, and workflows without exposing long-lived credentials or bypassing access controls. This release addresses a significant security challenge for enterprises: while agents need access to business data and tools to be effective, conventional API keys […]</p>
<p>The post <a href="https://gbhackers.com/cloudflare-launches-open-source-os-to-secure-ai-agents/">Cloudflare Launches Open-Source OS to Secure AI Agents’ Access to Internal Data</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CTEM isn’t failing. It’s not being operationalized]]></title>
<description><![CDATA[Cybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST, CIS Controls, CMMC, DORA, NIS2, and now Continuous Threat Exposure Management (CTEM) all provide valuable guidance and describe desired outcomes.



The challenge is tha...]]></description>
<link>https://tsecurity.de/de/3708193/it-security-nachrichten/ctem-isnt-failing-its-not-being-operationalized/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708193/it-security-nachrichten/ctem-isnt-failing-its-not-being-operationalized/</guid>
<pubDate>Thu, 06 Aug 2026 15:08:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Cybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST, CIS Controls, CMMC, DORA, NIS2, and now Continuous Threat Exposure Management (CTEM) all provide valuable guidance and describe desired outcomes.</p>



<p class="wp-block-paragraph">The challenge is that most stop at the “what.” They rarely explain the “how.”</p>



<p class="wp-block-paragraph">That is not a criticism. It is by design. Frameworks establish principles, define expectations, and describe desired outcomes. They are not implementation guides.</p>



<p class="wp-block-paragraph">As a result, security leaders and practitioners are left figuring out how to translate principles into processes, assign ownership, establish accountability, and measure success. Those decisions often determine whether a framework delivers results or becomes another initiative that never moves beyond good intentions.</p>



<p class="wp-block-paragraph">The Gartner<sup>®</sup> CTEM framework provides a clear vision through its five phases: scope, discover, prioritize, validate, and mobilize. Yet many organizations that understand those phases still struggle to build a CTEM program that consistently produces measurable outcomes.</p>



<h3 class="wp-block-heading">Understanding CTEM is the easy part</h3>



<p class="wp-block-paragraph">Most security teams do not have a CTEM knowledge problem. Gartner has clearly documented the phases, vendors have built messaging around them, and countless presentations explain how CTEM works. The challenge is that understanding a framework and operating it are two very different things.</p>



<p class="wp-block-paragraph">The question is not whether the pieces exist, but whether those pieces work together to reduce exposure over time. That is where the gap emerges, because the challenge is not understanding CTEM. It is turning CTEM into a repeatable operating model that consistently produces measurable outcomes.</p>



<h3 class="wp-block-heading">The industry has focused on the phases</h3>



<p class="wp-block-paragraph">Most CTEM discussions focus on the framework itself: How do we scope? How do we discover? How do we prioritize? How do we validate? How do we mobilize? Those questions help organizations understand the framework, but they can also create the illusion that adopting CTEM is simply a matter of executing the phases.</p>



<p class="wp-block-paragraph">The organizations making the most progress are focused on a different set of questions:</p>



<ul class="wp-block-list">
<li>Who owns the process?</li>



<li>How do findings move between teams?</li>



<li>How do we establish accountability?</li>



<li>How do we verify that remediation actually reduced exposure?</li>



<li>How do we measure progress over time?</li>
</ul>



<p class="wp-block-paragraph">These are operational questions, and they are often the difference between a CTEM initiative and a CTEM operating model.</p>



<h3 class="wp-block-heading">Where CTEM programs actually stall</h3>



<p class="wp-block-paragraph">Most CTEM programs do not struggle with visibility. They struggle with execution.</p>



<p class="wp-block-paragraph">Security teams often discover exposures, while infrastructure, application, cloud, and identity teams are responsible for fixing them. Each team plays an important role, but no single team owns the end-to-end outcome. As a result, exposures often move from team to team while the original context gets diluted. Security understands why the issue matters. The team responsible for fixing it may only see another ticket in a queue.</p>



<p class="wp-block-paragraph">As findings move across organizational boundaries, priorities compete for attention, ownership becomes fragmented, and validation often becomes inconsistent, leaving organizations uncertain whether risk is actually decreasing.</p>



<p class="wp-block-paragraph">A team may discover an exposure, prioritize it, validate that it matters, and assign remediation to the right group. But if ownership becomes unclear, remediation is delayed, or nobody verifies the outcome, the program has not reduced exposure in any measurable way.</p>



<p class="wp-block-paragraph">Moving work through a process is not the same as reducing exposure. That distinction matters because CTEM is not about generating more findings. It is about creating a repeatable system that helps organizations understand what matters, act on it with confidence, and prove that exposure is decreasing over time.</p>



<p class="wp-block-paragraph">Click <a href="https://horizon3.ai/intelligence/blogs/ctem-isnt-failing-its-being-operationalized/#:~:text=decreasing%20over%20time.-,What%20Operationalization%20Looks%20Like%20in%20Practice,-Most%20organizations%20already" target="_blank" rel="noreferrer noopener">here</a> to see what operationalization looks like in practice, and how to fill your CTEM gaps.</p>



<p class="wp-block-paragraph"><strong>Continue the conversation</strong></p>



<p class="wp-block-paragraph">Understanding CTEM is the easy part. Operationalizing it is where most organizations struggle.</p>



<p class="wp-block-paragraph">As organizations shift from reactive security to proactive security, they need more than visibility. They need the ability to continuously validate what matters, verify that remediation worked, and prove they are becoming harder to attack over time.</p>



<p class="wp-block-paragraph"><a href="https://events.horizon3.ai/introducing-nodezero-webapp/" target="_blank" rel="noreferrer noopener"><strong>Register for the webinar</strong></a><strong> “From Probability to Proof: The Art of the Possible with Proactive Cybersecurity,”</strong> and explore how AI-native proactive security is helping organizations continuously find, fix, and verify exploitable attack paths so they can move beyond assumptions and prove resilience. Also, download the “<a href="https://horizon3.ai/downloads/whitepapers/operationalizing-ctem-practical-playbook/" target="_blank" rel="noreferrer noopener">Operationalizing CTEM: A Practical Playbook for Continuous Threat Exposure Management</a>” playbook for guidance on building a repeatable CTEM operating model.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity needs a new operating model]]></title>
<description><![CDATA[For decades, cybersecurity has been built around one assumption: defenders had enough time to:




Discover vulnerabilities.



Assess exposure.



Deploy patches.



Verify that critical systems remained protected.




That assumption shaped how organizations built security programs, how vendors...]]></description>
<link>https://tsecurity.de/de/3708191/it-security-nachrichten/cybersecurity-needs-a-new-operating-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708191/it-security-nachrichten/cybersecurity-needs-a-new-operating-model/</guid>
<pubDate>Thu, 06 Aug 2026 15:08:16 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For decades, cybersecurity has been built around one assumption: defenders had enough time to:</p>



<ul class="wp-block-list">
<li>Discover vulnerabilities.</li>



<li>Assess exposure.</li>



<li>Deploy patches.</li>



<li>Verify that critical systems remained protected.</li>
</ul>



<p class="wp-block-paragraph">That assumption shaped how organizations built security programs, how vendors developed security products, and how regulators measured cyber resilience.</p>



<p class="wp-block-paragraph"><strong>That assumption no longer holds</strong></p>



<p class="wp-block-paragraph">AI has not created a new category of cyber risk. Rather, it has exposed the limitations of a security operating model built for a time when attackers operated at human speed. When AI can identify vulnerabilities, generate working exploits, analyze attack surfaces, and chain weaknesses together at scale, the timeline between exposure and exploitation compresses dramatically.</p>



<p class="wp-block-paragraph">That shift is beginning to reshape more than cyber operations. It is changing how governments, regulators, and security leaders think about resilience itself.</p>



<p class="wp-block-paragraph">The European Central Bank’s (ECB) recent <a href="https://www.bankingsupervision.europa.eu/press/letterstobanks/shared/pdf/2026/ssm.2026_letter_on_AI_enabled_cybersecurity_threats.ro.pdf" target="_blank" rel="noreferrer noopener">supervisory letter</a> is one of the clearest examples yet.</p>



<p class="wp-block-paragraph">On July 7, 2026, the ECB directed every significant institution under its supervision to submit a comprehensive action plan addressing AI-enabled cybersecurity threats by Oct. 31, 2026.</p>



<p class="wp-block-paragraph">While the letter applies specifically to Europe’s largest banking institutions, its significance extends well beyond financial services. More important than the deadline is the ECB’s conclusion that AI represents a long-term shift in the threat landscape rather than a temporary phenomenon or a risk associated with any single technology.</p>



<p class="wp-block-paragraph">That statement marks an important moment in the evolution of cybersecurity.</p>



<h2 class="wp-block-heading">The ECB isn’t asking for more of the same</h2>



<p class="wp-block-paragraph">At first glance, the ECB’s recommendations appear familiar:</p>



<ul class="wp-block-list">
<li>Protect the attack surface.</li>



<li>Accelerate vulnerability and patch management at scale.</li>



<li>Enhance monitoring, detection, and defense.</li>



<li>Strengthen governance, funding, training, and supply chain assurance.</li>



<li>Reinforce defense-in-depth while modernizing infrastructure.</li>



<li>Improve operational resilience and information-sharing.</li>
</ul>



<p class="wp-block-paragraph">None of those disciplines are new. Mature security programs have invested in them for years, and many are already reflected in frameworks such as DORA and existing supervisory expectations.</p>



<p class="wp-block-paragraph">What the ECB is acknowledging is something more fundamental. Cybersecurity’s traditional operating model was built for a time when attackers operated at human speed, giving organizations time to reduce risk before adversaries could exploit it. AI eliminated that advantage. The ECB’s letter reflects a broader shift that is already underway.</p>



<p class="wp-block-paragraph">The challenge is no longer whether organizations have visibility into their environments. It is whether they can generate enough evidence to make confident security decisions before attackers exploit them.</p>



<ul class="wp-block-list">
<li><strong>Security has become an evidence problem, not a visibility problem. </strong></li>



<li><strong>Visibility tells you what exists. Evidence tells you what matters.</strong></li>
</ul>



<p class="wp-block-paragraph">These distinctions sit at the heart of the ECB’s letter. The objective is no longer to perform more security activities. It is to ensure those activities produce meaningful reductions in operational risk despite dramatically compressed attack timelines.</p>



<h2 class="wp-block-heading">This shift didn’t begin with the ECB</h2>



<p class="wp-block-paragraph">The ECB’s supervisory letter did not emerge in isolation. It is the latest signal in a broader progression that has been unfolding across governments, intelligence agencies, and cybersecurity organizations over the past year.</p>



<p class="wp-block-paragraph">Last month, CISA’s Binding Operational Directive 26-04 signaled an important shift away from treating vulnerability management primarily as a severity problem. Instead, it emphasizes prioritizing remediation based on operational risk, exposure, and the likelihood of exploitation.</p>



<p class="wp-block-paragraph">Around the same time, the Five Eyes intelligence alliance, CERT-EU, the UK’s National Cyber Security Centre, FS-ISAC, and other organizations warned that frontier AI models are fundamentally changing the economics of cyber operations. Activities that once required experienced operators working methodically over days or weeks can increasingly be executed in minutes and repeated at virtually unlimited scale.</p>



<p class="wp-block-paragraph">Although each organization framed the challenge differently, they all point toward the same conclusion: The assumptions that have shaped cybersecurity for decades are no longer sufficient in an era of AI-accelerated attacks.</p>



<p class="wp-block-paragraph">The ECB’s letter represents the next step in that progression. Rather than encouraging institutions to prepare for a future possibility, it acknowledges that AI-enabled cyber threats are already reshaping how regulators evaluate cyber resilience. That distinction matters because it marks a shift from discussing AI as an emerging risk to managing it as an operational reality.</p>



<p class="wp-block-paragraph">Continue reading <a href="https://horizon3.ai/intelligence/blogs/cybersecurity-new-operating-model/#:~:text=The%20Operating%20Model%20Must%20Change" target="_blank" rel="noreferrer noopener">here</a> to discover how to better manage your cybersecurity model.</p>



<p class="wp-block-paragraph">The significance of the ECB’s letter is not that another regulator issued another cybersecurity directive. It is that one of the world’s leading banking supervisors publicly acknowledged what security teams have already been experiencing in practice.</p>



<p class="wp-block-paragraph"><a href="https://horizon3.ai/contact-us/schedule-demo/" target="_blank" rel="noreferrer noopener">See how the NodeZero<sup>®</sup> Proactive Security Platform helps significant institutions address the ECB’s six cybersecurity priorities and build a credible action plan backed by evidence.</a> </p>



<p class="wp-block-paragraph"><a href="https://horizon3.ai/contact-us/schedule-demo/" target="_blank" rel="noreferrer noopener">Schedule a demo now</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[You’re only as secure as your last evaluation]]></title>
<description><![CDATA[The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB). It is more than a regulatory hurdle. It is a direct response to a rapidly changing and increasingly hostile threat lan...]]></description>
<link>https://tsecurity.de/de/3708190/it-security-nachrichten/youre-only-as-secure-as-your-last-evaluation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708190/it-security-nachrichten/youre-only-as-secure-as-your-last-evaluation/</guid>
<pubDate>Thu, 06 Aug 2026 15:08:15 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB). It is more than a regulatory hurdle. It is a direct response to a rapidly changing and increasingly hostile threat landscape faced by the DIB.</p>



<p class="wp-block-paragraph">Updated CMMC guidance issued in 2025 simplifies the prior framework, focusing on the most essential security practices aligned with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171. Its fundamental purpose remains unchanged: to protect sensitive, unclassified defense information — specifically Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) — from foreign adversaries.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/CMMC.png" alt="CMMC phases" class="wp-image-4206154" width="624" height="352" sizes="auto, (max-width: 624px) 100vw, 624px"></figure><p class="imageCredit">Horizon3</p></div><p class="wp-block-paragraph"><em>The updated CMMC phases. Image from </em><a href="https://dodcio.defense.gov/cmmc/About/" target="_blank" rel="noreferrer noopener"><em>https://dodcio.defense.gov/cmmc/About/</em></a><em> </em></p>



<h3 class="wp-block-heading">CMMC implementation phases</h3>



<p class="wp-block-paragraph">The CMMC requirements are being implemented in phases to ease the burden on both organizations and auditors.</p>



<ul class="wp-block-list">
<li><strong>Phase 1 (Nov 10, 2025 – Nov 9, 2026):</strong> Focus on self-assessments for Levels 1 and 2</li>



<li><strong>Beginning Nov 10, 2026:</strong> Solicitations will require Level 2 certifications</li>
</ul>



<p class="wp-block-paragraph">For thousands of companies across the DIB— from prime contractors to small, specialized machine shops — compliance is not optional. It is the prerequisite for doing business with the DoW. It establishes a standardized, measured approach to cybersecurity across the supply chain.</p>



<h3 class="wp-block-heading">A shift in adversary strategy</h3>



<p class="wp-block-paragraph">The strategic focus of adversaries has shifted. Rather than launching costly, direct attacks against well-defended prime contractors, they increasingly target the weakest link in the supply chain.</p>



<p class="wp-block-paragraph">Suppliers and subcontractors often:</p>



<ul class="wp-block-list">
<li>Possess valuable intellectual property, schematics, and operational details</li>



<li>Operate without the same security resources as larger defense firms</li>
</ul>



<p class="wp-block-paragraph">These operational activities create a pathway into the broader ecosystem. A breach at any tier can reverberate across the supply chain, exposing sensitive information and impacting mission outcomes.</p>



<h3 class="wp-block-heading">The limitations of point-in-time security</h3>



<p class="wp-block-paragraph">The traditional model of cybersecurity compliance has relied on periodic, point-in-time assessments. This approach is fundamentally limited in the context of a dynamic and interconnected supply chain.</p>



<p class="wp-block-paragraph">Security is not static. A posture that was compliant weeks ago can become vulnerable due to:</p>



<ul class="wp-block-list">
<li>New exploits or zero-day vulnerabilities</li>



<li>System configuration changes</li>



<li>Introduction of new technologies or shadow IT</li>
</ul>



<p class="wp-block-paragraph"><strong>The core issue is straightforward: You are only as secure as your last evaluation. </strong>In an environment that is constantly evolving, this model leaves a persistent gap between compliance and actual risk.</p>



<h3 class="wp-block-heading">Enabling continuous validation</h3>



<p class="wp-block-paragraph">Horizon3.ai’s <a href="https://horizon3.ai/vertical/federal/" target="_blank" rel="noreferrer noopener">NodeZero Federal</a>™ enables a more continuous approach to security validation. Unlike traditional penetration testing or vulnerability scanning, NodeZero identifies and validates exploitable weaknesses and demonstrates how they can be chained together.</p>



<p class="wp-block-paragraph">This provides organizations with the ability to:</p>



<ul class="wp-block-list">
<li><strong>Validate controls regularly: </strong>Demonstrate effectiveness on an ongoing basis, not just during audits</li>



<li><strong>Close the compliance gap: </strong>Move beyond documentation to show how controls mitigate real-world risk</li>



<li><strong>Identify attack paths: </strong>Understand how an adversary could move through the environment</li>
</ul>



<p class="wp-block-paragraph">This approach supports a more realistic understanding of security posture and risk.</p>



<h3 class="wp-block-heading">Expanding the scope: From enterprise to ecosystem</h3>



<p class="wp-block-paragraph">Elevating supply chain security for FCI and CUI represents a broader shift in how the DoW approaches risk. The focus is no longer limited to securing individual networks. It extends across the entire DIB ecosystem.</p>



<p class="wp-block-paragraph">The objective is not only compliance, but:</p>



<ul class="wp-block-list">
<li>Measurable risk reduction</li>



<li>Greater resilience across interconnected environments</li>



<li>Assurance of mission continuity</li>
</ul>



<h3 class="wp-block-heading">Implications for prime contractors</h3>



<p class="wp-block-paragraph">CMMC reinforces a long-standing reality: The security posture of a prime contractor is directly influenced by the posture of its suppliers.</p>



<p class="wp-block-paragraph">This introduces cascading risks across the supply chain, particularly where subcontractors process, store, or transmit CUI.</p>



<p class="wp-block-paragraph">Key implications include:</p>



<ul class="wp-block-list">
<li><strong>Jeopardized prime contractor posture: </strong>A security incident at a supplier can impact the prime’s certification.</li>



<li><strong>Contract ineligibility and business impact: </strong>Non-compliance may lead to disqualification from DoW contracts.</li>



<li><strong>Mission assurance risk: </strong>Compromised CUI can affect operational integrity and outcomes</li>
</ul>



<h3 class="wp-block-heading">Common sources of compromise</h3>



<p class="wp-block-paragraph">Compromise often originates in predictable areas of the supply chain.</p>



<p class="wp-block-paragraph"><strong>Third-party providers. </strong>Managed service providers (MSPs) and vendors supporting multiple organizations can introduce systemic risk. A single compromise can expose multiple environments.</p>



<p class="wp-block-paragraph"><strong>Specialized suppliers. </strong>Small and medium-sized organizations may handle sensitive data but lack enterprise-grade security controls.</p>



<p class="wp-block-paragraph"><strong>Interconnected access points. </strong>Common weaknesses include:</p>



<ul class="wp-block-list">
<li>Shared credentials</li>



<li>Weak or misconfigured VPN access</li>



<li>Federated identity systems without proper segmentation</li>
</ul>



<h3 class="wp-block-heading">Example: Assume-breach scenario</h3>



<p class="wp-block-paragraph">In a recent assume-breach test, NodeZero began with access to a single host without credentials. From that starting point, it enumerated domain users and executed a password spray, successfully obtaining a valid domain credential.</p>



<p class="wp-block-paragraph">That account had local administrator privileges, enabling further actions:</p>



<ul class="wp-block-list">
<li>Deployment of a remote access tool (RAT)</li>



<li>LSASS access and credential harvesting</li>
</ul>



<p class="wp-block-paragraph">This scenario highlights a common issue: controls that are assumed to be in place may not perform as expected in practice.</p>



<h3 class="wp-block-heading">Why the legacy model does not scale</h3>



<p class="wp-block-paragraph">The legacy model of periodic assessments does not account for the dynamic nature of modern environments.</p>



<p class="wp-block-paragraph">Risk is introduced through:</p>



<ul class="wp-block-list">
<li>Supply chain changes and new vendors</li>



<li>Ongoing system reconfigurations</li>



<li>Expansion of SaaS, APIs, and cloud services</li>



<li>Gradual degradation of controls over time</li>
</ul>



<p class="wp-block-paragraph">As a result, a point-in-time certification can quickly become outdated.</p>



<h3 class="wp-block-heading">Continuous readiness under CMMC</h3>



<p class="wp-block-paragraph">The updated CMMC guidance emphasizes continuous readiness rather than periodic validation. Self-assessments are expected to be supported by documented, day-to-day evidence of control effectiveness.</p>



<p class="wp-block-paragraph">This reflects the need to maintain security posture over time, not just demonstrate it at a single point.</p>



<h3 class="wp-block-heading">Continuous validation as a practical requirement</h3>



<p class="wp-block-paragraph">Moving to continuous validation helps organizations keep pace with:</p>



<ul class="wp-block-list">
<li>Changing threat activity</li>



<li>Evolving supplier ecosystems</li>



<li>The need to maintain confidence in control effectiveness</li>
</ul>



<p class="wp-block-paragraph">Without this, organizations rely on outdated assumptions about their environment and exposure.</p>



<h3 class="wp-block-heading">Closing the gap between compliance and security</h3>



<p class="wp-block-paragraph">HORIZON3.ai’s NodeZero® Proactive Security Platform helps bridge the gap between compliance and operational security. By validating controls through real-world attack scenarios, it provides evidence of effectiveness and identifies gaps across both internal environments and critical suppliers.</p>



<p class="wp-block-paragraph">This enables organizations to treat CMMC not just as a compliance requirement, but as part of an ongoing risk management program.</p>



<h3 class="wp-block-heading">Final thought</h3>



<p class="wp-block-paragraph">True security posture is not defined by a completed assessment.</p>



<p class="wp-block-paragraph">It is defined by how systems perform under real conditions, and how quickly organizations can identify and address weaknesses as they emerge. </p>



<p class="wp-block-paragraph">Learn more about how Horizon3.ai strengthens supply chain security for CMMC.<br><a href="https://horizon3.ai/wp-content/uploads/2026/05/2605_Whitepaper_Supply-Chain-Security-CMMC_US_Digital.pdf" target="_blank" rel="noreferrer noopener">Please refer to the full white paper</a>.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Will Keep Its September iPhone 18 Pro Event Prerecorded]]></title>
<description><![CDATA[Apple September Event Stays Prerecorded Despite Employee Lottery



Many fans are hoping that Apple will finally return to a live stage presentation for its big fall showcase. A recent internal memo revealed the company is inviting retail store employees to help staff the upcoming iPhone 18 Pro l...]]></description>
<link>https://tsecurity.de/de/3708084/ios-mac-os/apple-will-keep-its-september-iphone-18-pro-event-prerecorded/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708084/ios-mac-os/apple-will-keep-its-september-iphone-18-pro-event-prerecorded/</guid>
<pubDate>Thu, 06 Aug 2026 14:25:17 +0200</pubDate>
<content:encoded><![CDATA[Apple September Event Stays Prerecorded Despite Employee Lottery



Many fans are hoping that Apple will finally return to a live stage presentation for its big fall showcase. A recent internal memo revealed the company is inviting retail store employees to help staff the upcoming iPhone 18 Pro launch. While this news quickly sparked rumors about an in-person keynote, the highly anticipated tech gathering will almost certainly stick to the familiar prerecorded video format.



Retail worker lottery points to a standard hybrid hardware gathering



A recent Bloomberg report highlighted a memo asking retail staff to enter a lottery. Winners get to travel to California and help manage the crowd, check in guests, and provide directions during the big day. Since people are trying to guess when the company will announce its September 2026 event, seeing this preparation gave some folks hope that a real live show is coming back.



However, bringing employees to the headquarters is just business as usual for the tech giant. It has done this for the past few years to handle the massive influx of media members who arrive to watch the broadcast on screens and test the physical devices afterward. A live audience will be there, but the presentation itself remains safely filmed in advance.



Prerecorded videos offer absolute control over product demonstrations and graphics



The shift away from live stages started in 2020 due to health restrictions, and the company quickly realized the benefits. Filming everything early eliminates the risk of technical failures on stage. It also allows the production team to use cinematic visuals to show off things like camera upgrades, which might help justify why the base model might start at a higher $1,399 price point this year.



With John Ternus stepping in as the new chief executive, keeping things predictable is a smart move. Running a live broadcast just days after taking the top job invites unnecessary pressure and potential mistakes. Instead of a risky live routine, you can expect another highly polished, flawless video that gets straight to the point. The live keynote era appears to be permanently retired.]]></content:encoded>
</item>
<item>
<title><![CDATA[Canadian Man Pleads Guilty for Hacking U.S. Cloud Storage Provider]]></title>
<description><![CDATA[Connor Riley Moucka, a 26-year-old resident of Kitchener, Ontario, has pleaded guilty in the United States for his role in a major computer hacking and extortion conspiracy. Prosecutors said the campaign compromised more than 165 organizations, exposed billions of sensitive customer records, and ...]]></description>
<link>https://tsecurity.de/de/3708069/it-security-nachrichten/canadian-man-pleads-guilty-for-hacking-us-cloud-storage-provider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708069/it-security-nachrichten/canadian-man-pleads-guilty-for-hacking-us-cloud-storage-provider/</guid>
<pubDate>Thu, 06 Aug 2026 14:12:28 +0200</pubDate>
<content:encoded><![CDATA[<p>Connor Riley Moucka, a 26-year-old resident of Kitchener, Ontario, has pleaded guilty in the United States for his role in a major computer hacking and extortion conspiracy. Prosecutors said the campaign compromised more than 165 organizations, exposed billions of sensitive customer records, and generated millions of dollars in ransom payments. According to court documents, Moucka […]</p>
<p>The post <a href="https://cybersecuritynews.com/canadian-man-pleads-guilty/">Canadian Man Pleads Guilty for Hacking U.S. Cloud Storage Provider</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers hid malware inside Oracle Database after SQL injection breach]]></title>
<description><![CDATA[Huntress has documented a case where the Oracle database itself became the malware host.



The security firm disclosed a campaign in which threat actors exploited a SQL injection vulnerability to store a custom post-exploitation toolkit, dubbed Khunt, inside an Oracle database using the platform...]]></description>
<link>https://tsecurity.de/de/3708066/it-security-nachrichten/attackers-hid-malware-inside-oracle-database-after-sql-injection-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708066/it-security-nachrichten/attackers-hid-malware-inside-oracle-database-after-sql-injection-breach/</guid>
<pubDate>Thu, 06 Aug 2026 14:12:08 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Huntress has documented a case where the Oracle database itself became the malware host.</p>



<p class="wp-block-paragraph">The security firm disclosed a campaign in which threat actors exploited a <a href="https://www.csoonline.com/article/564663/what-is-sql-injection-how-these-attacks-work-and-how-to-prevent-them.html">SQL injection</a> vulnerability to store a custom post-exploitation toolkit, dubbed Khunt, inside an Oracle database using the platform’s built-in Java capabilities.</p>



<p class="wp-block-paragraph">Huntress became aware of the intrusion after investigating a credential theft activity on a server running Oracle Database. The researchers learned that rather than simply executing commands through SQL injection, the attackers had leveraged Oracle’s embedded Java Virtual Machine (OJVM) to upload, compile, and execute malicious Java code directly from within the database.</p>



<p class="wp-block-paragraph">The approach reportedly allowed the attackers to blend into legitimate database functionality while maintaining a persistent foothold on the compromised server.</p>



<p class="wp-block-paragraph">“The attackers managed to gain initial access in this attack thanks to a classic SQL injection,” Huntress researchers said in a blog <a href="https://www.huntress.com/blog/khunt-malware-sql-injection-oracle" target="_blank" rel="noreferrer noopener">post</a>. “There was no need for a novel vulnerability because the autocomplete search feature in the public-facing application was enough to reach PL/SQL and then the operating system.”</p>



<h2 class="wp-block-heading"><a></a>Exploitation beyond SQL injection</h2>



<p class="wp-block-paragraph">The attack revolved around Khunt, a Java-based toolkit that attackers stored as a database object using Oracle’s “CREATE JAVA SOURCE” functionality. Oracle Database includes an embedded Java Virtual Machine that allows organizations to execute Java code from within the database for legitimate business applications.</p>



<p class="wp-block-paragraph">Once compiled inside the database, the Java code could be run through SQL statements to execute operating system commands on the underlying host where Oracle was configured. The malware inserted within the database schema would be considerably harder to detect, Huntress noted.</p>



<p class="wp-block-paragraph">After setting up the code execution path from within the database, the attackers could (and did) carry out post-compromise activities, including credential theft.</p>



<p class="wp-block-paragraph">In the incident Huntress investigated, the attackers ultimately compromised the Windows server hosting Oracle Database, escalating from <a href="https://www.csoonline.com/article/573101/sql-injection-xss-vulnerabilities-continue-to-plague-organizations.html">SQL injection</a> to SYSTEM-level command execution. With that level of access, they were able to dump the Windows SAM, SECURITY, and SYSTEM registry hives, enabling offline extraction of local account password hashes.</p>



<p class="wp-block-paragraph">The campaign’s non-reliance on noisy malware binaries and incorporation of the malice entirely within Oracle’s native functionality was flagged by researchers as an evolved operation that calls for targeted detection.</p>



<p class="wp-block-paragraph">Oracle did not immediately respond to CSO’s requests for comment.</p>



<h2 class="wp-block-heading"><a></a>Mitigation focused on post-exploitation toolkit </h2>



<p class="wp-block-paragraph"><br><strong><br></strong>While the SQL injection pathway provided the initial foothold, Huntress argues that the more important lesson lies in what happened after exploitation.</p>



<p class="wp-block-paragraph">The attackers could have simply extracted or manipulated data through SQL injection, but instead, they expanded the exploit to include long-term persistence and remote command execution. Huntress warned that this is a dangerous evolution.</p>



<p class="wp-block-paragraph">Features such as Oracle’s embedded JVM, while valuable for enterprise workloads, can also expand the blast radius with sufficient database privileges. “To avoid these types of attacks, it is important to ensure the forms aren’t injectable,” the researchers said. “It’s also important to ensure that users with the ability to execute queries aren’t overprovisioned.”</p>



<p class="wp-block-paragraph">Huntress recommended looking beyond indicators of SQL injection during incident response. Examining Oracle environments for unexpected Java source objects, compiled Java classes, and stored procedures could indicate abuse of the embedded Java Virtual Machine, it said. The firm also shared indicators of compromise (IOCs), including file hashes, malicious Java artifacts, SQL statements, and search terms to help defenders identify affected systems.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Autonomy is earned, not claimed]]></title>
<description><![CDATA[After more than 300,000 production penetration tests (pentests), our company has learned something that may surprise people watching the recent wave of autonomous security announcements.



The hardest problem in autonomous security isn’t teaching a machine how to attack. It’s teaching an AI-base...]]></description>
<link>https://tsecurity.de/de/3708065/it-security-nachrichten/autonomy-is-earned-not-claimed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708065/it-security-nachrichten/autonomy-is-earned-not-claimed/</guid>
<pubDate>Thu, 06 Aug 2026 14:12:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">After more than 300,000 production penetration tests (pentests), our company has learned something that may surprise people watching the recent wave of autonomous security announcements.</p>



<p class="wp-block-paragraph">The hardest problem in autonomous security isn’t teaching a machine how to attack. It’s teaching an AI-based system how to operate safely, predictably, and repeatedly inside production environments where mistakes have consequences.</p>



<p class="wp-block-paragraph">Finding an attack path is an engineering problem. Building a platform that organizations trust to operate against healthcare systems, financial institutions, manufacturers, and critical infrastructure is an operational one. The difference only becomes apparent after years of running at scale.</p>



<p class="wp-block-paragraph">As the industry embraces AI agents, autonomous red teaming, and machine-speed operations, much of the conversation remains focused on capability. Can a machine identify a path to compromise? Can it chain weaknesses together? Can it achieve the same outcome as a human operator?</p>



<p class="wp-block-paragraph">Those are reasonable questions. They are not the questions security leaders ultimately care about.</p>



<p class="wp-block-paragraph">Security leaders need confidence that a platform can operate safely in production, consistently produce meaningful results, and help teams make better decisions about risk. In our experience, that’s where the real challenge begins.</p>



<p class="wp-block-paragraph">Since 2019, <a href="https://horizon3.ai/nodezero" target="_blank" rel="noreferrer noopener">NodeZero</a><sup>®</sup> has executed more than 300,000 production pentests across thousands of environments. Those engagements have reinforced a lesson that continues to surface.</p>



<p class="wp-block-paragraph">The biggest security challenges rarely come from what organizations cannot see. They come from separating signal from noise.</p>



<p class="wp-block-paragraph">Most organizations are not struggling to find vulnerabilities</p>



<p class="wp-block-paragraph">The security industry has spent decades improving visibility.</p>



<p class="wp-block-paragraph">Organizations have vulnerability scanners, attack surface management platforms, cloud security tools, exposure management programs, and countless dashboards filled with findings. Most security teams are not suffering from a lack of information. This issue is: They’re struggling to determine which information matters.</p>



<p class="wp-block-paragraph">Attackers do not think in terms of individual findings. They think in terms of outcomes. They identify a weakness, combine it with another weakness, move through the environment, and pursue an objective. The path matters more than any individual step along the way.</p>



<p class="wp-block-paragraph">Security teams often inherit the opposite problem. Thousands of findings arrive in a dashboard, each evaluated independently, with little context around how those weaknesses might connect. As a result, teams spend significant time debating severity while attackers focus on exploitability.</p>



<p class="wp-block-paragraph">The difference sounds subtle, but it changes everything. Severity describes a vulnerability. Exploitability describes risk.</p>



<p class="wp-block-paragraph"><strong>Experience changes how you evaluate risk</strong></p>



<p class="wp-block-paragraph">Trust isn’t built on promises, it’s built on the deep experience gained from executing hundreds of thousands of pentests. Over time, recurring patterns begin to emerge regardless of industry, technology stack, or organizational maturity.</p>



<p class="wp-block-paragraph">We’ve seen organizations trust legacy tools that require enormous effort to remediate vulnerabilities that had little practical impact, while overlooking seemingly minor weaknesses that ultimately enabled significant compromise. That happens because risk rarely exists as a single vulnerability. It exists in the way weaknesses interact with one another.</p>



<p class="wp-block-paragraph">In a <a href="https://horizon3.ai/intelligence/blogs/patch-tuesday-to-pentest-wednesday-cyber-resilience/" target="_blank" rel="noreferrer noopener">financial services environment</a>, a single compromised credential led to 586 critical impacts across 115 hosts, including three separate domain compromises. Viewed independently, the credential did not appear particularly significant. Viewed as part of an attack path, it became something entirely different.</p>



<p class="wp-block-paragraph">In another <a href="https://horizon3.ai/intelligence/blogs/patch-tuesday-to-pentest-wednesday-cloud-compromise/" target="_blank" rel="noreferrer noopener">cloud environment</a>, the path to full Entra ID tenant compromise did not require a common vulnerabilities and exposures (CVE) or zero-day exploit. The weaknesses involved were already known. Existing tools had identified them. What was missing was an understanding of how those weaknesses could be chained together and what that chain of events meant for the organization.</p>



<p class="wp-block-paragraph">We have also seen organizations discover that the initial compromise was not the most important part of the assessment. In one <a href="https://horizon3.ai/intelligence/blogs/pw_measure-blast-radius/" target="_blank" rel="noreferrer noopener">education environment</a>, the larger question was how far an attacker could move after gaining access. Measuring blast radius exposed paths to systems and data that were never expected to be reachable from the original point of compromise.</p>



<p class="wp-block-paragraph">These examples reinforce the same lesson. The challenge is rarely finding weaknesses. The challenge is knowing which weaknesses matter before an attacker does. That kind of judgment isn’t built from demonstrations or benchmarks. It’s earned through years of operating in production environments and seeing how real attack paths emerge across thousands of organizations.</p>



<p class="wp-block-paragraph">Click <a href="https://horizon3.ai/intelligence/blogs/autonomy-is-earned-not-claimed/#:~:text=Capability%20Gets%20Attention.%20Reliability%20Builds%20Trust." target="_blank" rel="noreferrer noopener">here</a> to learn why reliability is the key to building trust and how to get there.</p>



<p class="wp-block-paragraph"><strong>What 7 years of autonomous pentesting taught us</strong></p>



<p class="wp-block-paragraph">Most organizations do not need another source of findings. They already have more findings than they can realistically address. What they need is confidence in what is actually exploitable, how attackers would use it, and whether their fixes reduced risk.</p>



<p class="wp-block-paragraph">That’s the lesson we’ve learned from years of operating in production environments.</p>



<p class="wp-block-paragraph">And it’s the problem we have solved. </p>



<p class="wp-block-paragraph"><a href="https://horizon3.ai/contact-us/schedule-demo/" target="_blank" rel="noreferrer noopener">Get a demo</a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Can Multiple AI Models Improve Enterprise Trust?]]></title>
<description><![CDATA[As AI becomes more persuasive, enterprises are looking beyond single models to improve trust in AI-generated decisions. The post Can Multiple AI Models Improve Enterprise Trust? appeared first on TechNewsWorld.]]></description>
<link>https://tsecurity.de/de/3708032/it-nachrichten/can-multiple-ai-models-improve-enterprise-trust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708032/it-nachrichten/can-multiple-ai-models-improve-enterprise-trust/</guid>
<pubDate>Thu, 06 Aug 2026 14:03:32 +0200</pubDate>
<content:encoded><![CDATA[<div><img width="300" height="156" src="https://www.technewsworld.com/wp-content/uploads/sites/3/2023/04/business-meeting-1-300x156.jpg" class="attachment-medium size-medium wp-post-image" alt="tech executives planning for generative AI" decoding="async" loading="lazy" srcset="https://www.technewsworld.com/wp-content/uploads/sites/3/2023/04/business-meeting-1-300x156.jpg 300w, https://www.technewsworld.com/wp-content/uploads/sites/3/2023/04/business-meeting-1-768x399.jpg 768w, https://www.technewsworld.com/wp-content/uploads/sites/3/2023/04/business-meeting-1.jpg 1000w" sizes="auto, (max-width: 300px) 100vw, 300px"></div>As AI becomes more persuasive, enterprises are looking beyond single models to improve trust in AI-generated decisions. The post <a rel="nofollow" href="https://www.technewsworld.com/story/can-multiple-ai-models-improve-enterprise-trust-180481.html?rss=1">Can Multiple AI Models Improve Enterprise Trust?</a> appeared first on <a rel="nofollow" href="https://www.technewsworld.com/?rss=1">TechNewsWorld</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches Muse Code for complex software work with persistent AI agents]]></title>
<description><![CDATA[Meta has released a beta coding agent designed to handle complex software assignments across large codebases.



Available for macOS and Linux, Muse Code uses the company’s new Muse Spark 1.2 model. It includes specialized background agents that remain active throughout a session instead of being...]]></description>
<link>https://tsecurity.de/de/3708019/ai-nachrichten/meta-launches-muse-code-for-complex-software-work-with-persistent-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708019/ai-nachrichten/meta-launches-muse-code-for-complex-software-work-with-persistent-ai-agents/</guid>
<pubDate>Thu, 06 Aug 2026 14:03:14 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Meta has released a beta coding agent designed to handle complex software assignments across large codebases.</p>



<p class="wp-block-paragraph">Available for macOS and Linux, Muse Code uses the company’s new Muse Spark 1.2 model. It includes specialized background agents that remain active throughout a session instead of being created separately for individual tasks.</p>



<p class="wp-block-paragraph">The agents carry out work asynchronously and decide when to report their findings to the primary agent. Meta said keeping them active reduces repeated information gathering and the need for developer direction during difficult, multi-step tasks.</p>



<p class="wp-block-paragraph">“Muse Code uses a local event log in which every model call, tool run, approval, and edit is appended,” Meta said in a post, adding that the record “makes the runtime replay-exact and restart-safe” and allows the agent to resume precisely where it stopped after a crash.</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4192724/metas-ai-chief-says-new-muse-spark-update-will-sharpen-coding-agentic-ai.html">Muse Spark 1.2</a> is available through Muse Code and the Meta Model API, for which Meta announced expanded global access.</p>



<h2 class="wp-block-heading">Training and evaluation</h2>



<p class="wp-block-paragraph">Meta said it co-trained Muse Spark 1.2 with Muse Code to improve the model’s performance and usability when used with the agent. The training incorporated Muse Code’s tools and agent workflows, while Meta increased the computing resources used for coding and broadened the range of development environments.</p>



<p class="wp-block-paragraph">The model was also trained on longer assignments, including whole-repository generation and large end-to-end software projects.</p>



<p class="wp-block-paragraph"><a href="https://omdia.tech.informa.com/authors/lian-jye-su" target="_blank" rel="noreferrer noopener">Lian Jye Su</a>, chief analyst at Omdia, said Meta’s co-training approach was unlikely to provide a clear advantage because rivals were also developing their coding models and <a href="https://www.infoworld.com/article/4164601/harness-teams-of-coding-agents-with-squad.html">agent harnesses</a> in close coordination.</p>



<p class="wp-block-paragraph">“Other vendors, such as OpenAI and Anthropic, have been treating harness engineering as part of the training process,” Su said.</p>



<p class="wp-block-paragraph">Optimizing the model and agent together could improve planning and context handling, but any competitive advantage would need to be demonstrated through better results on enterprise projects while reducing the need for human intervention, said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting.</p>



<p class="wp-block-paragraph">Meta reported that Muse Spark 1.2 achieved an 82.9% pass@1 score on Terminal-Bench 2.1, behind Claude Opus 5 but slightly ahead of GPT-5.6 Terra. On DeepSWE 1.1, the model scored 59.3%, trailing both rivals.</p>



<p class="wp-block-paragraph">For Terminal-Bench 2.1 and DeepSWE 1.1, Meta evaluated each model with its selected coding agent rather than using the same agent throughout. It also acknowledged that rival proprietary models may have performed differently under tools and prompts designed specifically for them.</p>



<p class="wp-block-paragraph"><a href="https://counterpointresearch.com/en/opinion-leader/10" target="_blank" rel="noreferrer noopener">Neil Shah</a>, vice president of research at Counterpoint Research, said cross-vendor comparisons would be more meaningful if models were evaluated with third-party tools or within the same agent harness.</p>



<p class="wp-block-paragraph">“The key metric for CIOs is the pass rate against an enterprise’s own pipeline, which will determine the success of the model-and-harness bundle, or, in this case, Meta’s Muse Spark 1.2 and Muse Code,” Shah said. “This will be the real <a href="https://www.infoworld.com/article/4033758/why-benchmarks-are-key-to-ai-progress.html">benchmark</a>.”</p>



<h2 class="wp-block-heading">Enterprise adoption hurdles</h2>



<p class="wp-block-paragraph">Su said security and governance requirements could slow enterprise adoption, particularly where coding agents must be connected to existing identity systems.</p>



<p class="wp-block-paragraph">“Many enterprises are still less willing to open up their CI/CD environments for AI tool integration,” Su said.</p>



<p class="wp-block-paragraph">Shah said companies would need controls governing how agents access repositories, along with records showing how models and agent workflows handle enterprise data. He also cited the difficulty of forecasting token consumption and its effect on costs.</p>



<p class="wp-block-paragraph">Meta’s pricing structure also creates a data-governance choice. The company said the lower-priced Contributor model may be used to improve its products, while the standard tier is not used for that purpose.</p>



<p class="wp-block-paragraph">The Contributor tier costs $0.10 per million input tokens and $0.20 per million output tokens, compared with $1.25 and $4.25, respectively, for the standard tier.</p>



<p class="wp-block-paragraph">“There is also a fear of vendor lock-in and reliance, as it may hurt long-term flexibility and system interoperability,” Su added.</p>



<p class="wp-block-paragraph">Jain said adoption was likely to begin with narrowly defined, lower-risk work before companies allowed persistent agents to modify critical production code.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proactive patch management & compliance: Hardening the hybrid Azure fleet at scale]]></title>
<description><![CDATA[Welcome back to SUSE Solutions on Azure: The Technical Series. Bridging the Gap Between Linux Freedom and Azure Scale Enterprise Linux on Azure requires a careful balance between open source flexibility and corporate security control. This series provides technical blueprints to help you shift aw...]]></description>
<link>https://tsecurity.de/de/3707994/unix-server/proactive-patch-management-compliance-hardening-the-hybrid-azure-fleet-at-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707994/unix-server/proactive-patch-management-compliance-hardening-the-hybrid-azure-fleet-at-scale/</guid>
<pubDate>Thu, 06 Aug 2026 13:54:10 +0200</pubDate>
<content:encoded><![CDATA[<p>Welcome back to SUSE Solutions on Azure: The Technical Series. Bridging the Gap Between Linux Freedom and Azure Scale Enterprise Linux on Azure requires a careful balance between open source flexibility and corporate security control. This series provides technical blueprints to help you shift away from managing individual distributions. Learn to build a unified, secure and […]</p>
<p>The post <a href="https://www.suse.com/c/proactive-patch-management-compliance-hardening-the-hybrid-azure-fleet-at-scale/">Proactive patch management &amp; compliance: Hardening the hybrid Azure fleet at scale</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [niedrig] IBM Business Automation Workflow: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in IBM Business Automation Workflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen.]]></description>
<link>https://tsecurity.de/de/3707977/it-security-nachrichten/neu-niedrig-ibm-business-automation-workflow-schwachstelle-ermoeglicht-umgehen-von-sicherheitsvorkehrungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707977/it-security-nachrichten/neu-niedrig-ibm-business-automation-workflow-schwachstelle-ermoeglicht-umgehen-von-sicherheitsvorkehrungen/</guid>
<pubDate>Thu, 06 Aug 2026 13:35:07 +0200</pubDate>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in IBM Business Automation Workflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Structural agile: Why fast delivery quietly loses its meaning]]></title>
<description><![CDATA[Open the history tab of any epic that has been alive for more than two quarters. Go ahead, pick one. Count the edits. Somewhere around edit 11, the description was rewritten to satisfy a stakeholder who has since changed roles. Around edit 19, the scope was trimmed to protect a date that, in the ...]]></description>
<link>https://tsecurity.de/de/3707974/it-security-nachrichten/structural-agile-why-fast-delivery-quietly-loses-its-meaning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707974/it-security-nachrichten/structural-agile-why-fast-delivery-quietly-loses-its-meaning/</guid>
<pubDate>Thu, 06 Aug 2026 13:30:02 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Open the history tab of any epic that has been alive for more than two quarters. Go ahead, pick one. Count the edits. Somewhere around edit 11, the description was rewritten to satisfy a stakeholder who has since changed roles. Around edit 19, the scope was trimmed to protect a date that, in the end, moved anyway. By edit 26 someone renamed the whole thing, and the sentence that explained why the work existed in the first place didn’t survive the paste. 26 edits, several hundred hours of delivery behind them, and nobody left who can say what the money was for.</p>



<p class="wp-block-paragraph">Nobody deleted that reason on purpose. That’s what makes this so hard to see.</p>



<p class="wp-block-paragraph">I’ve been shuttling between the people who fund technology work and the teams who deliver it for a couple of decades now, and something has always struck me as odd: the backlog is probably the only important document in the enterprise that gets edited every day and remembers nothing. Contracts have version control and signatures. Financial statements have audit trails. Even architecture, in mature shops, has decision records. But the artifact that actually steers what hundreds of people build week after week? It has a title, a status and a description that mutates until the original intent becomes archaeology.</p>



<p class="wp-block-paragraph">The most expensive failures I’ve seen were all fast. The teams shipped and shipped, and somewhere along the way the work stopped meaning what everyone assumed it still meant. Nobody slowed down long enough to notice.</p>



<h2 class="wp-block-heading">One problem, two lenses</h2>



<p class="wp-block-paragraph">Strategy and delivery look at the same work through very different mental models. On one side, leaders talk in outcomes, intent and value; they worry about whether the original justification for the investment still holds months later. On the other side, teams think in iterations, flow and momentum, and they worry about keeping complex programs moving in small, manageable steps. Both lenses are legitimate, and in my experience both sides generally believe they’re the ones doing everything right.</p>



<p class="wp-block-paragraph">The disagreement between them is never loud. Strategy quietly assumes the logic will remain constant across every sprint and every decision. Delivery quietly assumes the strategic reasoning will naturally update itself based on what gets learned along the way. There’s nothing wrong with either assumption on its own. But in the absence of a structural bridge between them, every program gradually accumulates small half-measures and shifted meanings that nobody registers until it’s too late.</p>



<p class="wp-block-paragraph">The evidence on how badly intent travels is humbling. Donald Sull and his colleagues, in a multi-year study of strategy execution, found that <a href="https://hbr.org/2015/03/why-strategy-execution-unravelsand-what-to-do-about-it">only half of middle managers can name any of their company’s top five priorities</a>. Those are the managers. Now imagine the epic, eleven edits later.</p>



<p class="wp-block-paragraph">Let me be fair to <a href="https://agilemanifesto.org/">agile</a> here, because agile is not the villain. It does exactly what it says on the tin: it helps teams learn quickly and adjust to what they discover, and <a href="https://hbr.org/2018/05/agile-at-scale">that speed is a genuine strength</a>. The problem is that organizations blur the line between two kinds of change. Some of it is genuine learning: teams discover real behaviors, markets shift, leaders sharpen their thinking. And some of it is erosion, the slow loss of rationale that nobody actually decided and nobody can trace back to a witting choice. From the outside, the two are indistinguishable. They show up the same way in the tooling: movement in the backlog, shifting priorities, even working software. Only one of them stays anchored to the reason the money was spent.</p>



<p class="wp-block-paragraph">Most organizations have no instrument for telling these two apart. Which means they’re flying at full speed without knowing whether they’re navigating or just moving.</p>



<h2 class="wp-block-heading">The pattern we keep seeing</h2>



<h3 class="wp-block-heading">Agile in style, not in substance</h3>



<p class="wp-block-paragraph">The board gets moved every day, stand-ups start on time and retrospectives produce long lists of things to improve. Then you ask why a specific feature exists, what it’s actually meant to change, and the room gets quiet. The rituals persist while the substance underneath them slowly thins out. Teams keep closing tasks, and somewhere along the way they shed the shared sense of purpose that made the tasks worth doing.</p>



<h3 class="wp-block-heading">Velocity becomes a proxy for value</h3>



<p class="wp-block-paragraph">A smooth sprint demo can hide a deeper problem, because progress toward delivery and progress toward outcomes are two different measurements, and only one of them is on the wall. I’ve seen features that were stable, polished and warmly received in the demo, and that contributed absolutely nothing to the decision they were supposed to improve. The pace was real enough; whether any of it mattered took months to find out. And your delivery metrics can be excellent, genuinely excellent, while every one of these patterns is running underneath them.</p>



<p class="wp-block-paragraph">This is not a niche affliction, by the way. Pendo analyzed feature usage across hundreds of software products and found that <a href="https://www.pendo.io/resources/the-2019-feature-adoption-report/">80% of features are rarely or never used</a>. Built at full velocity, shipped into silence.</p>



<h3 class="wp-block-heading">Product owners absorb pressure instead of defending logic</h3>



<p class="wp-block-paragraph">The PO is supposed to hold the thread, to protect the reasoning behind the work when everyone else is pushing on it. In practice, many find themselves wedged between demand and delivery, forced into a permanent state of reactive prioritization. Over time they stop challenging requests. Then they stop defending the logic behind decisions. Eventually they stop framing choices around outcomes at all, and the backlog, which should be a strategic instrument, turns into the place where everything gets dumped because nobody has the space left to ask what actually belongs there.</p>



<h3 class="wp-block-heading">Backlog churn masks strategic drift</h3>



<p class="wp-block-paragraph">Items get revisited, split, recast and reprioritized as everyone works to keep momentum going, and from a distance it can all look like reasonable adaptation. But when the connection to intent is severed, all that motion begins to dissolve into static. Work keeps getting passed around, the board stays busy and the program veers off course without producing a single alarming signal, because busy is what everyone was looking for.</p>



<h3 class="wp-block-heading">Every quarter is a reset</h3>



<p class="wp-block-paragraph">New OKRs arrive. A fresh wave of leadership messaging follows. Sometimes the team gets reshuffled too. With each round, a little of the shared context that held everything together quietly slips away. Epics get new names, stories get rewritten, priorities rearrange themselves almost by accident. The organization keeps rebooting itself without ever asking what it left behind in the reset.</p>



<p class="wp-block-paragraph">Taken one at a time, each of these patterns is understandable, even forgivable. Together they produce a program that looks healthy from every angle while it quietly hollows out the meaning behind the work.</p>



<h2 class="wp-block-heading">Why this keeps happening, and why it’s about to get worse</h2>



<p class="wp-block-paragraph">Big programs tend to assume that intent will simply carry itself forward as the work passes through teams, decisions and iterations. It won’t. Intent doesn’t carry itself. If nobody actively preserves and updates the reasoning, it starts to loosen and fray, quietly and almost politely, one story, one trade-off, one shift in priority at a time.</p>



<p class="wp-block-paragraph">The structural cause is a speed mismatch that most governance was never designed for. The delivery system evolves in hours; the organization’s memory of why updates in quarters, if at all. In between those two clocks, thousands of micro-decisions reshape what the work means, far faster than anyone captures the reasoning behind them.</p>



<p class="wp-block-paragraph">Now add what’s happening in 2026. AI agents inside the delivery tooling can already <a href="https://support.atlassian.com/rovo/docs/agents/">organize, create and edit backlog items</a> on a team’s behalf. Atlassian’s own customers describe agents that <a href="https://www.atlassian.com/software/jira/ai">generate requirements, break them into epics and stories and take delegated work like a teammate</a>, and these capabilities now ship inside the standard Jira plans that most enterprises already pay for. I’m not against any of this; some of it is genuinely useful. But notice what it means for our problem. Every one of those operations is an edit to a document that has no memory. Backlog amnesia at human speed was survivable. Painful, but survivable, because humans forget slowly. Amnesia at machine speed is a different animal altogether. The ratio of motion to memory, already unhealthy in most organizations, is about to go vertical.</p>



<p class="wp-block-paragraph">If your backlog can’t remember why an item exists after a human rewrote it a few times, think about what happens when an agent grooms it continuously.</p>



<h2 class="wp-block-heading">What to do about it</h2>



<p class="wp-block-paragraph">The countermeasures I use are deliberately small. None of them adds a ceremony, a tool, or a governance layer. They simply orient the practices teams already run toward one job: keeping the reasoning alive while the work moves. Together, they form the discipline I call Structural Agile.</p>



<ul class="wp-block-list">
<li><strong>Start with the outcome. </strong>Before an epic or major story enters the backlog, three questions, every time: What behavior are we trying to shift? How will we know if that behavior changes? What signals will confirm success after release? If the room can’t answer, the work waits, because items that lack outcome clarity tend to drift first and drift fastest.</li>



<li><strong>Elevate the PO. </strong>Position the product owner as the carrier of outcome logic, with an explicit mandate to preserve rationale, flag trade-offs that erode intent and track deferred items together with the reasoning behind them. And be realistic about the limits, because many POs inherit chaotic backlogs, rotate mid-stream, or simply lack the authority to push back on stakeholders. The rule I give teams is simple: if the PO can’t carry the logic, someone must: a coach prompting context checks, an architect recording the reasoning behind technical trade-offs, an analyst keeping the outcome picture current. Build logic stewardship into the structure. Left to personality, it leaves with the person.</li>



<li><strong>Anchor epics to why. </strong>Every epic carries its rationale as metadata, inside the tool where the work actually lives. Slide decks from last spring don’t count. When a decision reshapes the epic, the rationale gets updated in the same motion; waivers and scope cuts get recorded next to the item they changed. Do this consistently and the backlog stops being a queue of tasks and becomes a living map of intent, one that a new joiner can read on day one, and that survives a challenge from leadership without anyone having to reconstruct history from memory. It cuts both ways, too: the same rationale that protects the team from whiplash protects the business from a backlog that has drifted away from what they actually asked for. Prioritization turns into a conversation about evidence rather than a contest of opinions.</li>



<li><strong>Rehearse erosion. </strong>This is the practice I’d start with, and the one that surprises teams most. Every two or three sprints, run a short, structured session that is not a retrospective and not a risk review. Its purpose is to test the continuity of intent itself: Does the assumed user behavior still make sense? Where might adoption fail even though delivery is technically correct? Which parts of the outcome logic feel fragile, outdated, or untested? A retro examines how the team worked; an erosion rehearsal examines whether the reasoning still holds. You rehearse erosion the same way pilots rehearse emergencies: you hope the drill is wasted, and you run it anyway, because catching drift early is what makes fixing it cheap. In my experience, a single one of these sessions surfaces more strategic risk than a quarter’s worth of status reporting, and it costs the team about half an hour.</li>



<li><strong>Keep the logic alive. </strong>Capture only what prevents strategic amnesia and nothing more: why a feature was removed or reshaped, who approved it and which assumptions should be revisited, and when. Keep it visible where teams already work. If logic lives in Confluence but dies in conversation, it’s already gone.</li>
</ul>



<h2 class="wp-block-heading">Start Monday</h2>



<p class="wp-block-paragraph">You don’t need a reorganization or a new framework to begin, and frankly you shouldn’t want one. Three entry points, close to zero overhead. Assign a critical reviewer: one team member whose standing job is to periodically ask whether stories still connect to the intended outcome. Add a one-minute outcome check before major refinements: the behavior targeted, the indicator watched, the signal expected. And run a single erosion rehearsal on your most important program; teams usually surface something real in the first session, long before it would have shown up in any metric.</p>



<p class="wp-block-paragraph">For readers keeping score: yes, neighboring practices exist, and they’re good ones. <a href="https://www.cognitect.com/blog/2011/11/15/documenting-architecture-decisions">Architecture decision records</a> preserve the why behind technical choices, and <a href="https://www.impactmapping.org/">impact mapping</a> connects deliverables to goals at planning time. I use both. Neither operates continuously, inside the backlog, at the level of the individual item, which happens to be exactly where the forgetting occurs. OKRs don’t solve it either; objectives at altitude are necessary, but teams still need the rationale embedded in the work itself, so they don’t have to keep a separate decoder.</p>



<h2 class="wp-block-heading">The history tab, revisited</h2>



<p class="wp-block-paragraph">Go back to that epic with the twenty-six edits, and imagine the same history with one difference: each consequential edit carries a line of reasoning, current and human-readable, and every few sprints someone deliberately tested whether that reasoning still held. Same team, same velocity, same tool and a completely different answer when someone finally asks why the work exists.</p>



<p class="wp-block-paragraph">Velocity tells you how fast the work is moving. Only memory can tell you whether anyone still knows where it’s going.</p>



<p class="wp-block-paragraph">I’ve published the full discipline behind this approach (the five principles, the roles, the facilitation guides and the objections seasoned practitioners will raise, along with my answers) as a <a href="https://pmworldlibrary.net/wp-content/uploads/2026/02/pmwj161-Feb2026-Kadaoui-Structural-Agile-featured-paper-1.pdf">featured paper in PM World Journal</a>. The mechanics are free to steal. The forgetting, at this point, is optional.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS targets AI cost concerns with new Marketplace Insights tool]]></title>
<description><![CDATA[AWS has added AI Insights to AWS Marketplace, a feature that it says is designed to help CIOs and developers better evaluate and compare products using AI-generated summaries and recommendations as enterprises grapple with increasing pressure to justify technology spending.



“Available in the p...]]></description>
<link>https://tsecurity.de/de/3707971/it-security-nachrichten/aws-targets-ai-cost-concerns-with-new-marketplace-insights-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707971/it-security-nachrichten/aws-targets-ai-cost-concerns-with-new-marketplace-insights-tool/</guid>
<pubDate>Thu, 06 Aug 2026 13:29:02 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS has added AI Insights to AWS Marketplace, a feature that it says is designed to help CIOs and developers better evaluate and compare products using AI-generated summaries and recommendations as enterprises grapple with increasing pressure to justify technology spending.</p>



<p class="wp-block-paragraph">“Available in the pricing section of the listing in AWS Marketplace, AI Insights explains each product’s pricing in plain language: what a pricing unit maps to, how your bill changes as usage scales, how multiple pricing dimensions combine into one cost, and what is and isn’t included,” AWS wrote in a <a href="https://aws.amazon.com/about-aws/whats-new/2026/08/aws-marketplace-ai-insights/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<h2 class="wp-block-heading">Critical for procurement of AI-based tools, offerings</h2>



<p class="wp-block-paragraph">Analysts say the new feature could prove critical for CIOs procuring AI-based tools and services.</p>



<p class="wp-block-paragraph">“AI pricing in the marketplace has always been a black box. You see a number per token, per API call, or per compute unit, but understanding what that actually means at enterprise scale requires significant effort to piece together,” said <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT Consulting firm Kanerika.</p>



<p class="wp-block-paragraph">“CIOs are increasingly being held to account for AI spend, not just AI adoption, and that shift has created a genuine need for pricing transparency at the point of evaluation,” Jena added.</p>



<p class="wp-block-paragraph">The challenge, according to <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, has compounded for CIOs because AI-based tools are now moving away from simple per-user subscription fees into complex consumption-based pricing.</p>



<p class="wp-block-paragraph">“With tokens, API calls, agent executions, and compute, forecasting total cost of ownership has become very challenging. A feature like AI Insights should give CIOs pre-purchase clarity by translating multi-dimensional pricing into plain language on the listing, letting them calculate budget limits before committing,” Jain said.</p>



<p class="wp-block-paragraph">Prior to the update, evaluating pricing for AI tools required separate research exercises outside the marketplace, with teams having to visit seller websites, read technical documentation written for developers rather than procurement leaders, and build their own cost models from scratch, Jena pointed out.</p>



<p class="wp-block-paragraph">“That process was slow, error-prone, and often resulted in PoC projects frequently getting stalled in legal and <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps</a> reviews,” echoed Jain.</p>



<p class="wp-block-paragraph">“Enterprises that deployed agentic AI tools without clear pricing rules often suffered post-implementation bill shock when autonomous workflows unexpectedly multiplied backend API calls. These runaway costs led CFOs to freeze AI budgets, resulting in abandoned software pilots and failed ROI metrics,” Jain added.</p>



<p class="wp-block-paragraph">The update, then, essentially would help CIOs defend a purchase decision in front of a CFO or board, Jena pointed out, adding that accelerated procurement cycles would also indirectly lead to faster delivery cycles.</p>



<h2 class="wp-block-heading">Quality of pricing information will be key</h2>



<p class="wp-block-paragraph">The analyst, however, cautioned that the usefulness of AI Insights as a feature will ultimately depend on the quality of pricing information published by software vendors offering tools on the Marketplace.</p>



<p class="wp-block-paragraph">“AI Insights draws from seller-published pricing and their public websites, so the quality of the explanation is only as good as what sellers publish. If pricing pages remain vague, the AI-generated explanation will reflect that,” Jena said.</p>



<p class="wp-block-paragraph">Even so, the analyst further pointed out that the feature could have a broader positive effect by encouraging other hyperscalers and enterprise software vendors to make pricing documentation more transparent in their respective marketplaces.</p>



<p class="wp-block-paragraph">“Azure Marketplace and Google Cloud Marketplace will face pressure to offer something equivalent. The underlying driver is the same: enterprise buyers are now accountable for AI ROI in ways they were not two years ago, and pricing opacity is becoming a genuine risk to AI adoption at scale,” Jena said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Structural agile: Why fast delivery quietly loses its meaning]]></title>
<description><![CDATA[Open the history tab of any epic that has been alive for more than two quarters. Go ahead, pick one. Count the edits. Somewhere around edit 11, the description was rewritten to satisfy a stakeholder who has since changed roles. Around edit 19, the scope was trimmed to protect a date that, in the ...]]></description>
<link>https://tsecurity.de/de/3707966/it-nachrichten/structural-agile-why-fast-delivery-quietly-loses-its-meaning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707966/it-nachrichten/structural-agile-why-fast-delivery-quietly-loses-its-meaning/</guid>
<pubDate>Thu, 06 Aug 2026 13:28:37 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Open the history tab of any epic that has been alive for more than two quarters. Go ahead, pick one. Count the edits. Somewhere around edit 11, the description was rewritten to satisfy a stakeholder who has since changed roles. Around edit 19, the scope was trimmed to protect a date that, in the end, moved anyway. By edit 26 someone renamed the whole thing, and the sentence that explained why the work existed in the first place didn’t survive the paste. 26 edits, several hundred hours of delivery behind them, and nobody left who can say what the money was for.</p>



<p class="wp-block-paragraph">Nobody deleted that reason on purpose. That’s what makes this so hard to see.</p>



<p class="wp-block-paragraph">I’ve been shuttling between the people who fund technology work and the teams who deliver it for a couple of decades now, and something has always struck me as odd: the backlog is probably the only important document in the enterprise that gets edited every day and remembers nothing. Contracts have version control and signatures. Financial statements have audit trails. Even architecture, in mature shops, has decision records. But the artifact that actually steers what hundreds of people build week after week? It has a title, a status and a description that mutates until the original intent becomes archaeology.</p>



<p class="wp-block-paragraph">The most expensive failures I’ve seen were all fast. The teams shipped and shipped, and somewhere along the way the work stopped meaning what everyone assumed it still meant. Nobody slowed down long enough to notice.</p>



<h2 class="wp-block-heading">One problem, two lenses</h2>



<p class="wp-block-paragraph">Strategy and delivery look at the same work through very different mental models. On one side, leaders talk in outcomes, intent and value; they worry about whether the original justification for the investment still holds months later. On the other side, teams think in iterations, flow and momentum, and they worry about keeping complex programs moving in small, manageable steps. Both lenses are legitimate, and in my experience both sides generally believe they’re the ones doing everything right.</p>



<p class="wp-block-paragraph">The disagreement between them is never loud. Strategy quietly assumes the logic will remain constant across every sprint and every decision. Delivery quietly assumes the strategic reasoning will naturally update itself based on what gets learned along the way. There’s nothing wrong with either assumption on its own. But in the absence of a structural bridge between them, every program gradually accumulates small half-measures and shifted meanings that nobody registers until it’s too late.</p>



<p class="wp-block-paragraph">The evidence on how badly intent travels is humbling. Donald Sull and his colleagues, in a multi-year study of strategy execution, found that <a href="https://hbr.org/2015/03/why-strategy-execution-unravelsand-what-to-do-about-it">only half of middle managers can name any of their company’s top five priorities</a>. Those are the managers. Now imagine the epic, eleven edits later.</p>



<p class="wp-block-paragraph">Let me be fair to <a href="https://agilemanifesto.org/">agile</a> here, because agile is not the villain. It does exactly what it says on the tin: it helps teams learn quickly and adjust to what they discover, and <a href="https://hbr.org/2018/05/agile-at-scale">that speed is a genuine strength</a>. The problem is that organizations blur the line between two kinds of change. Some of it is genuine learning: teams discover real behaviors, markets shift, leaders sharpen their thinking. And some of it is erosion, the slow loss of rationale that nobody actually decided and nobody can trace back to a witting choice. From the outside, the two are indistinguishable. They show up the same way in the tooling: movement in the backlog, shifting priorities, even working software. Only one of them stays anchored to the reason the money was spent.</p>



<p class="wp-block-paragraph">Most organizations have no instrument for telling these two apart. Which means they’re flying at full speed without knowing whether they’re navigating or just moving.</p>



<h2 class="wp-block-heading">The pattern we keep seeing</h2>



<h3 class="wp-block-heading">Agile in style, not in substance</h3>



<p class="wp-block-paragraph">The board gets moved every day, stand-ups start on time and retrospectives produce long lists of things to improve. Then you ask why a specific feature exists, what it’s actually meant to change, and the room gets quiet. The rituals persist while the substance underneath them slowly thins out. Teams keep closing tasks, and somewhere along the way they shed the shared sense of purpose that made the tasks worth doing.</p>



<h3 class="wp-block-heading">Velocity becomes a proxy for value</h3>



<p class="wp-block-paragraph">A smooth sprint demo can hide a deeper problem, because progress toward delivery and progress toward outcomes are two different measurements, and only one of them is on the wall. I’ve seen features that were stable, polished and warmly received in the demo, and that contributed absolutely nothing to the decision they were supposed to improve. The pace was real enough; whether any of it mattered took months to find out. And your delivery metrics can be excellent, genuinely excellent, while every one of these patterns is running underneath them.</p>



<p class="wp-block-paragraph">This is not a niche affliction, by the way. Pendo analyzed feature usage across hundreds of software products and found that <a href="https://www.pendo.io/resources/the-2019-feature-adoption-report/">80% of features are rarely or never used</a>. Built at full velocity, shipped into silence.</p>



<h3 class="wp-block-heading">Product owners absorb pressure instead of defending logic</h3>



<p class="wp-block-paragraph">The PO is supposed to hold the thread, to protect the reasoning behind the work when everyone else is pushing on it. In practice, many find themselves wedged between demand and delivery, forced into a permanent state of reactive prioritization. Over time they stop challenging requests. Then they stop defending the logic behind decisions. Eventually they stop framing choices around outcomes at all, and the backlog, which should be a strategic instrument, turns into the place where everything gets dumped because nobody has the space left to ask what actually belongs there.</p>



<h3 class="wp-block-heading">Backlog churn masks strategic drift</h3>



<p class="wp-block-paragraph">Items get revisited, split, recast and reprioritized as everyone works to keep momentum going, and from a distance it can all look like reasonable adaptation. But when the connection to intent is severed, all that motion begins to dissolve into static. Work keeps getting passed around, the board stays busy and the program veers off course without producing a single alarming signal, because busy is what everyone was looking for.</p>



<h3 class="wp-block-heading">Every quarter is a reset</h3>



<p class="wp-block-paragraph">New OKRs arrive. A fresh wave of leadership messaging follows. Sometimes the team gets reshuffled too. With each round, a little of the shared context that held everything together quietly slips away. Epics get new names, stories get rewritten, priorities rearrange themselves almost by accident. The organization keeps rebooting itself without ever asking what it left behind in the reset.</p>



<p class="wp-block-paragraph">Taken one at a time, each of these patterns is understandable, even forgivable. Together they produce a program that looks healthy from every angle while it quietly hollows out the meaning behind the work.</p>



<h2 class="wp-block-heading">Why this keeps happening, and why it’s about to get worse</h2>



<p class="wp-block-paragraph">Big programs tend to assume that intent will simply carry itself forward as the work passes through teams, decisions and iterations. It won’t. Intent doesn’t carry itself. If nobody actively preserves and updates the reasoning, it starts to loosen and fray, quietly and almost politely, one story, one trade-off, one shift in priority at a time.</p>



<p class="wp-block-paragraph">The structural cause is a speed mismatch that most governance was never designed for. The delivery system evolves in hours; the organization’s memory of why updates in quarters, if at all. In between those two clocks, thousands of micro-decisions reshape what the work means, far faster than anyone captures the reasoning behind them.</p>



<p class="wp-block-paragraph">Now add what’s happening in 2026. AI agents inside the delivery tooling can already <a href="https://support.atlassian.com/rovo/docs/agents/">organize, create and edit backlog items</a> on a team’s behalf. Atlassian’s own customers describe agents that <a href="https://www.atlassian.com/software/jira/ai">generate requirements, break them into epics and stories and take delegated work like a teammate</a>, and these capabilities now ship inside the standard Jira plans that most enterprises already pay for. I’m not against any of this; some of it is genuinely useful. But notice what it means for our problem. Every one of those operations is an edit to a document that has no memory. Backlog amnesia at human speed was survivable. Painful, but survivable, because humans forget slowly. Amnesia at machine speed is a different animal altogether. The ratio of motion to memory, already unhealthy in most organizations, is about to go vertical.</p>



<p class="wp-block-paragraph">If your backlog can’t remember why an item exists after a human rewrote it a few times, think about what happens when an agent grooms it continuously.</p>



<h2 class="wp-block-heading">What to do about it</h2>



<p class="wp-block-paragraph">The countermeasures I use are deliberately small. None of them adds a ceremony, a tool, or a governance layer. They simply orient the practices teams already run toward one job: keeping the reasoning alive while the work moves. Together, they form the discipline I call Structural Agile.</p>



<ul class="wp-block-list">
<li><strong>Start with the outcome. </strong>Before an epic or major story enters the backlog, three questions, every time: What behavior are we trying to shift? How will we know if that behavior changes? What signals will confirm success after release? If the room can’t answer, the work waits, because items that lack outcome clarity tend to drift first and drift fastest.</li>



<li><strong>Elevate the PO. </strong>Position the product owner as the carrier of outcome logic, with an explicit mandate to preserve rationale, flag trade-offs that erode intent and track deferred items together with the reasoning behind them. And be realistic about the limits, because many POs inherit chaotic backlogs, rotate mid-stream, or simply lack the authority to push back on stakeholders. The rule I give teams is simple: if the PO can’t carry the logic, someone must: a coach prompting context checks, an architect recording the reasoning behind technical trade-offs, an analyst keeping the outcome picture current. Build logic stewardship into the structure. Left to personality, it leaves with the person.</li>



<li><strong>Anchor epics to why. </strong>Every epic carries its rationale as metadata, inside the tool where the work actually lives. Slide decks from last spring don’t count. When a decision reshapes the epic, the rationale gets updated in the same motion; waivers and scope cuts get recorded next to the item they changed. Do this consistently and the backlog stops being a queue of tasks and becomes a living map of intent, one that a new joiner can read on day one, and that survives a challenge from leadership without anyone having to reconstruct history from memory. It cuts both ways, too: the same rationale that protects the team from whiplash protects the business from a backlog that has drifted away from what they actually asked for. Prioritization turns into a conversation about evidence rather than a contest of opinions.</li>



<li><strong>Rehearse erosion. </strong>This is the practice I’d start with, and the one that surprises teams most. Every two or three sprints, run a short, structured session that is not a retrospective and not a risk review. Its purpose is to test the continuity of intent itself: Does the assumed user behavior still make sense? Where might adoption fail even though delivery is technically correct? Which parts of the outcome logic feel fragile, outdated, or untested? A retro examines how the team worked; an erosion rehearsal examines whether the reasoning still holds. You rehearse erosion the same way pilots rehearse emergencies: you hope the drill is wasted, and you run it anyway, because catching drift early is what makes fixing it cheap. In my experience, a single one of these sessions surfaces more strategic risk than a quarter’s worth of status reporting, and it costs the team about half an hour.</li>



<li><strong>Keep the logic alive. </strong>Capture only what prevents strategic amnesia and nothing more: why a feature was removed or reshaped, who approved it and which assumptions should be revisited, and when. Keep it visible where teams already work. If logic lives in Confluence but dies in conversation, it’s already gone.</li>
</ul>



<h2 class="wp-block-heading">Start Monday</h2>



<p class="wp-block-paragraph">You don’t need a reorganization or a new framework to begin, and frankly you shouldn’t want one. Three entry points, close to zero overhead. Assign a critical reviewer: one team member whose standing job is to periodically ask whether stories still connect to the intended outcome. Add a one-minute outcome check before major refinements: the behavior targeted, the indicator watched, the signal expected. And run a single erosion rehearsal on your most important program; teams usually surface something real in the first session, long before it would have shown up in any metric.</p>



<p class="wp-block-paragraph">For readers keeping score: yes, neighboring practices exist, and they’re good ones. <a href="https://www.cognitect.com/blog/2011/11/15/documenting-architecture-decisions">Architecture decision records</a> preserve the why behind technical choices, and <a href="https://www.impactmapping.org/">impact mapping</a> connects deliverables to goals at planning time. I use both. Neither operates continuously, inside the backlog, at the level of the individual item, which happens to be exactly where the forgetting occurs. OKRs don’t solve it either; objectives at altitude are necessary, but teams still need the rationale embedded in the work itself, so they don’t have to keep a separate decoder.</p>



<h2 class="wp-block-heading">The history tab, revisited</h2>



<p class="wp-block-paragraph">Go back to that epic with the twenty-six edits, and imagine the same history with one difference: each consequential edit carries a line of reasoning, current and human-readable, and every few sprints someone deliberately tested whether that reasoning still held. Same team, same velocity, same tool and a completely different answer when someone finally asks why the work exists.</p>



<p class="wp-block-paragraph">Velocity tells you how fast the work is moving. Only memory can tell you whether anyone still knows where it’s going.</p>



<p class="wp-block-paragraph">I’ve published the full discipline behind this approach (the five principles, the roles, the facilitation guides and the objections seasoned practitioners will raise, along with my answers) as a <a href="https://pmworldlibrary.net/wp-content/uploads/2026/02/pmwj161-Feb2026-Kadaoui-Structural-Agile-featured-paper-1.pdf">featured paper in PM World Journal</a>. The mechanics are free to steal. The forgetting, at this point, is optional.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Suno is now letting users press their AI music slop to vinyl, thus alienating streaming services, artists and audiophiles]]></title>
<description><![CDATA[The new service allows users to press their prompt-generated tracks onto vinyl records and even create album artwork.]]></description>
<link>https://tsecurity.de/de/3707960/it-nachrichten/suno-is-now-letting-users-press-their-ai-music-slop-to-vinyl-thus-alienating-streaming-services-artists-and-audiophiles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707960/it-nachrichten/suno-is-now-letting-users-press-their-ai-music-slop-to-vinyl-thus-alienating-streaming-services-artists-and-audiophiles/</guid>
<pubDate>Thu, 06 Aug 2026 13:28:30 +0200</pubDate>
<content:encoded><![CDATA[The new service allows users to press their prompt-generated tracks onto vinyl records and even create album artwork.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Bambu Lab P1S AMS 2 Pro Combo is seeing one of its biggest price drops yet — and it's perfect for leveling up your craft]]></title>
<description><![CDATA[The Bambu Lab P1S AMS 2 Pro Combo gets a big discount, making premium 3D printing far more affordable. It works out of the box, ready to print in 15 minutes]]></description>
<link>https://tsecurity.de/de/3707961/it-nachrichten/the-bambu-lab-p1s-ams-2-pro-combo-is-seeing-one-of-its-biggest-price-drops-yet-and-its-perfect-for-leveling-up-your-craft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707961/it-nachrichten/the-bambu-lab-p1s-ams-2-pro-combo-is-seeing-one-of-its-biggest-price-drops-yet-and-its-perfect-for-leveling-up-your-craft/</guid>
<pubDate>Thu, 06 Aug 2026 13:28:30 +0200</pubDate>
<content:encoded><![CDATA[The Bambu Lab P1S AMS 2 Pro Combo gets a big discount, making premium 3D printing far more affordable. It works out of the box, ready to print in 15 minutes]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Web IQ: Ground your AI agents with up-to-date web data]]></title>
<description><![CDATA[Microsoft has unveiled a suite of IQ products over the last few months. Work IQ, Fabric IQ, and Foundry IQ build on what Microsoft used to call its “Graphs,” the underlying data architecture that underpins its cloud services. These graphs provided a way to query the data your business uses, treat...]]></description>
<link>https://tsecurity.de/de/3707919/ai-nachrichten/microsoft-web-iq-ground-your-ai-agents-with-up-to-date-web-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707919/ai-nachrichten/microsoft-web-iq-ground-your-ai-agents-with-up-to-date-web-data/</guid>
<pubDate>Thu, 06 Aug 2026 13:18:55 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft has unveiled <a href="https://www.microsoft.com/en-us/ai/microsoft-iq#Products">a suite of IQ products</a> over the last few months. Work IQ, Fabric IQ, and Foundry IQ build on what Microsoft used to call its “Graphs,” the underlying data architecture that underpins its cloud services. These graphs provided a way to query the data your business uses, treating that data as nodes in a graph database and using the <a href="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html" data-type="link" data-id="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html">GraphQL API model</a> to extract that data — for example, to pull data related to a specific individual held across the various Microsoft 365 applications.</p>



<p class="wp-block-paragraph">The IQ suite follows a similar approach, using the same data, but treating it as the sparse vector store needed to provide grounding data for <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLM</a>-based applications. By treating the data as a set of <a href="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html" data-type="link" data-id="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html">embedding vectors</a>, and integrating it with <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers, Microsoft is giving you the necessary tools to tie LLM output to your data, reducing the risk of hallucination and improving accuracy. Using your own data is a key part of delivering effective agents, ensuring they work within your constraints.</p>



<h2 class="wp-block-heading">Extending IQ to the web</h2>



<p class="wp-block-paragraph"><a href="https://www.microsoft.com/en-us/webiq" data-type="link" data-id="https://www.microsoft.com/en-us/webiq">Web IQ</a>, the latest member of the IQ suite, was unveiled at Build 2026. A modernization of the retired Bing Search APIs, <a href="https://webiq.microsoft.ai/documentation/overview/">Web IQ is an agent-focused web search tool</a> that builds on the massive Bing search index to provide up-to-date general information for use in your applications.</p>



<p class="wp-block-paragraph">It may seem a little odd to be talking about a web-wide source of grounding data in the context of a suite of tools that exist to improve the accuracy of your AI applications by providing access to your Microsoft-hosted data. However, in many cases you want to link your agent not only to your data but also to related information from the wider world. For example, an agent powering an ecommerce service could use Web IQ and web-based data sources to provide product comparisons. An agent managing stock levels for a product that is weather-sensitive could use Web IQ as a source of weather data, using Bing’s multiple weather feeds and forecasts.</p>



<p class="wp-block-paragraph">Just as Google Gemini drew on Google Search, Microsoft Copilot began by using Bing search data to provide grounding for consumer chatbots. It’s easy to take a service like Bing and use it with a LLM, as the nearest neighbor search algorithms use semantic vector similarity techniques to find results that look like your query, ranking them according to their proximity to your search terms.</p>



<p class="wp-block-paragraph">Microsoft has been tuning its search vector index and the underlying technology stack to work with agents, as agents operate much differently than humans searching the web or querying a chatbot. Providing web search capabilities to agents means having to deal with persistent queries, as the agent hunts for the information it needs, refining queries and applying reasoning algorithms to develop the response it needs. LLM inferencing requires quick responses that deliver large amounts of data, working with queries that go far beyond the one-word or two-word requests that are typical of humans.</p>



<h2 class="wp-block-heading">More than the training weights</h2>



<p class="wp-block-paragraph">Using Web IQ gives you access to up-to-date information, beyond the training data used to build and weight an LLM. Bing’s crawler works within the standards developed by the search engine industry, obeying meta tags and using its own algorithms to crawl regularly updated websites more often. Bing’s crawler ensures that data is both fresh and being used appropriately, with a focus on quality rather than quantity.</p>



<p class="wp-block-paragraph">Providing access to web data is only part of Web IQ. Microsoft is using Web IQ to host its own models to manage embeddings, ranking, and content extraction, all running on the company’s global hyperscale platform. The intent here is to use only a limited number of models, to keep the system performance high while aiming to deliver accurate results. The Web IQ models are different from those used to deliver search results to humans, as they’re designed to deliver responses that are suitable for LLMs to use for reasoning.</p>



<p class="wp-block-paragraph">The underlying search system is based on the <a href="https://www.microsoft.com/en-us/research/project/project-akupara-approximate-nearest-neighbor-search-for-large-scale-semantic-search/" data-type="link" data-id="https://www.microsoft.com/en-us/research/project/project-akupara-approximate-nearest-neighbor-search-for-large-scale-semantic-search/">DiskANN algorithm</a> developed by Microsoft Research, which allows fast search without requiring enormous amounts of in-memory data access. This approach has been extended to manage information retrieval at scale, building on Microsoft’s distributed systems architectures, to support the demands Microsoft is seeing from agent-based systems. At the same time, it must respond to the rapidly changing economics of inference, where token costs now demand the best possible output from the fewest tokens.</p>



<p class="wp-block-paragraph">To meet those economic demands, the Web IQ platform doesn’t deliver whole documents to querying agents. Whole documents can lead to expensive inference further down the chain, as LLMs process results repeatedly to drive the agent workflow. Instead, Web IQ structures the information retrieved from the underlying search engine data, delivering what Microsoft calls “structured evidence objects” as well as passage-level information from unstructured text documents. This should result in a much higher signal-to-noise ratio than simply querying a search engine, with a focus on delivering information that lets agents work using fewer tokens.</p>



<h2 class="wp-block-heading">Using Web IQ in your agent code</h2>



<p class="wp-block-paragraph"><a href="https://webiq.microsoft.ai/documentation/api-reference/web/">The API for Web IQ</a> is a standard REST cal<a href="https://webiq.microsoft.ai/documentation/api-reference/web/">l</a>, delivering a request object to the Web IQ endpoint. Along with your API authorization key, you will send a query, a set of parameters that control the number of results returned, the language and region used, and the maximum size of the responses and the format used. Responses can be returned in text, HTML, or markdown formats, as well as extracted passages that are selected for context. All other options return the full document, so can be more expensive to use. Markdown is an interesting alternative, as it can be used as the basis for giving agents semantic memories.</p>



<p class="wp-block-paragraph">Results include important contextual and citation information, including web page titles and URLs, as well as data about when the site was last crawled and how stale the underlying information is. This can be used to improve grounding and provide more information that can be included in formatted responses — much in the same way as Bing’s Copilot displays context in the form of footnotes in its responses.</p>



<p class="wp-block-paragraph">Responses to <a href="https://webiq.microsoft.ai/documentation/api-reference/videos/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/videos/">video searches</a> include text descriptions. If these aren’t provided as part of the original web content, they will be generated by an LLM. The same approach is used for <a href="https://webiq.microsoft.ai/documentation/api-reference/images/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/images/">image searches</a>, with both offering the same contextual cues as the web search API. If you don’t care about the type of data being returned, you can choose a “<a href="https://webiq.microsoft.ai/documentation/api-reference/classic/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/classic/">classic search</a>,” which will return text, images, video, and news.</p>



<h2 class="wp-block-heading">Supporting autonomous agents</h2>



<p class="wp-block-paragraph">Microsoft provides LLM-ready documentation for the Web IQ service, with an <code>llms.txt</code> file and an OpenAPI description. These allow AI tools to discover Web IQ capabilities and include them in workflows as part of autonomous operations, so that agents and other AI applications can implement grounding calls to Web IQ whenever user interactions require them. The API <a href="https://webiq.microsoft.ai/documentation/error-handling/">descriptions include errors</a> as well as the structure of a standard 200 response.</p>



<p class="wp-block-paragraph">As Web IQ is designed for use by modern agent frameworks, the Web IQ API is available through an MCP server. The <a href="https://webiq.microsoft.ai/documentation/mcp/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/mcp/">Web IQ MCP server</a> exposes tools that map to API calls: web, videos, news, and images. They also include a browse option, which lets you pull content from a target URL. The service can be configured with a standard JSON file and requires an API key to control access and manage billing. If your account doesn’t have access to a specific tool, then it won’t be available from inside the MCP server.</p>



<p class="wp-block-paragraph">If you’re building an agent and you want to evaluate the Web IQ MCP server, it can be added to common coding agents, such as the GitHub Copilot CLI. You can then test it out using familiar tools and generate code that can be dropped into applications via your choice of development tooling. Queries sent to the Web IQ MCP server use the same syntax as REST calls, without having to construct the calls yourself. Working with the MCP server allows you to connect Web IQ to your choice of agent framework, relying on its built-in MCP methods to reduce the code and maintenance overhead.</p>



<p class="wp-block-paragraph">Web IQ is not for human interactions; Microsoft provides an alternative “<a href="https://learn.microsoft.com/en-us/azure/foundry-classic/agents/how-to/tools-classic/bing-grounding?view=azure-python-preview&amp;tabs=python&amp;pivots=overview">Grounding with Bing</a>” service for chatbots. Instead, Web IQ is a tool for agents, providing necessary background information that helps keep results fresh and relevant. It’s easy to use, fast, and, above all, cheap, which makes it an ideal tool for modern inference platforms built around Microsoft Azure’s AI tooling.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agents are coming for data (just slowly)]]></title>
<description><![CDATA[Agents have turned up just about everywhere in software this past year, with one conspicuous exception: data. That’s a little odd, because querying data is exactly the kind of structured, checkable task that agents excel at. The likeliest culprit is timing. Large language models have only been re...]]></description>
<link>https://tsecurity.de/de/3707920/ai-nachrichten/agents-are-coming-for-data-just-slowly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707920/ai-nachrichten/agents-are-coming-for-data-just-slowly/</guid>
<pubDate>Thu, 06 Aug 2026 13:18:55 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Agents have turned up just about everywhere in software this past year, with one conspicuous exception: data. That’s a little odd, because querying data is exactly the kind of structured, checkable task that agents excel at. The likeliest culprit is timing. <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">Large language models</a> have only been reliably good at writing <a href="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html" data-type="link" data-id="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html">SQL</a> for the last six to nine months, and the field hasn’t caught up to what that unlocks. It’s worth separating two flavors of the idea: agents that <em>do</em> analytics, and agents that help you run the data plumbing. Both turn out to be more useful than they first look.</p>



<p class="wp-block-paragraph">Data engineering is hard mostly because you’re at the mercy of systems you don’t control. Schemas change without warning. Sources go offline. The API you pull from ships a new version. A column that only ever holds integers starts returning decimals. A field you assumed was unique sprouts duplicates, and the next join detonates into a Cartesian explosion. Records go missing, or come back wrong for an hour and then quietly fix themselves. If nothing ever changed, data engineering would be easy. But as they say, the only constant is change.</p>



<h2 class="wp-block-heading">The boring work is where agents thrive</h2>



<p class="wp-block-paragraph">Unglamorous maintenance is something agents are genuinely good at. Every data model is a stack of assumptions: this is unique, that’s always populated, these two tables join cleanly. An agent can read those assumptions out of your code and turn them into tests that check whether they still hold. A lot of the fixes are mechanical anyway: a table got renamed, a type got widened, a column moved. An agent can often patch those on its own, and when it can’t, it can still do the legwork, tracing what changed and handing a human a diagnosis and a proposed fix instead of just a 3am stack trace.</p>



<p class="wp-block-paragraph">Context is the other half of the story, and the context landscape is honestly a mess. Vendors are working hard to convince you that only their semantic modeling language can save you, while it is not entirely clear whether these are necessary or even sufficient. Whether you keep your business logic in a semantic layer like <a href="https://github.com/dbt-labs/metricflow" data-type="link" data-id="https://github.com/dbt-labs/metricflow">MetricFlow</a> or <a href="https://github.com/malloydata/malloy" data-type="link" data-id="https://github.com/malloydata/malloy">Malloy</a>, or just in plain <a href="https://www.infoworld.com/article/3983394/what-is-markdown-lightweight-text-formatting-for-human-beings.html" data-type="link" data-id="https://www.infoworld.com/article/3983394/what-is-markdown-lightweight-text-formatting-for-human-beings.html">Markdown</a>, the goal is the same: get that logic into a form an LLM can use. Context is almost always created by hand, and like all hand-written documentation, it starts drifting the moment it gets written down.</p>



<p class="wp-block-paragraph">This highlights an opportunity, namely that agents are good at precisely the parts of context that are mechanical and bad at precisely the parts that aren’t. An agent can infer which tables join to which, what values a column tends to hold, what your sales regions are, and which tables people actually query. What it can’t infer is the stuff that was never really a data question: the <em>right</em> way to calculate revenue, what counts as a “customer,” when the fiscal year starts. Those aren’t facts hiding in the warehouse waiting to be found. They’re decisions, often business ones, that a person has to make. What an agent can do is flag the moment one of them quietly stops being true.</p>



<h2 class="wp-block-heading">Automated agent insights remain a fantasy</h2>



<p class="wp-block-paragraph">The flashier pitch, where agents surface insights you never asked for, is the one I’d bet on last. It sounds wonderful to have hands-free analytics. An agent will keep watch over your data, notice what matters, and drop a dashboard tailored to whatever is happening today. But the bar is high for relevance and false positives can make human users lose confidence. </p>



<p class="wp-block-paragraph">Deterministic alerting systems have the same problem. People end up turning off alarms because they are too hard to tune. But if humans writing pre-canned triggers have a hard time getting it right, it is going to be hard for agents to do better (at least not before we get some form of super-intelligence). While I’d expect proactive insights to be part of the future, they are still a research prototype at this point.</p>



<p class="wp-block-paragraph">Here are three concrete things a data team should do to get their stack ready for agents:</p>



<ol class="wp-block-list">
<li>Lay the groundwork first. Agent use cases that are compelling sit on top of groundwork most teams haven’t laid yet. You don’t need an agent to curate your context until you’ve decided how your context is going to work in the first place.</li>



<li>Then go after context. Write a handful of evals, automate them, and then wait to see what breaks. Evals are the load-bearing part. They’re what makes it safe to let an agent near your pipeline at all, because they tell you the instant it gets something wrong.</li>



<li>Run on infrastructure that fits how agents behave. An agent goes from zero to a flood of queries in an instant, so you want something that scales up and back down quickly. Agents also fan out, chasing several threads at once, so you need both the headroom and the tenant isolation to absorb a burst. One agent’s curiosity shouldn’t take down everyone else’s ability to run queries.</li>
</ol>



<h2 class="wp-block-heading">Latency is a bigger deal than it looks</h2>



<p class="wp-block-paragraph">Latency matters more than you’d expect when you’re using agents. While you might be waiting seconds or minutes for Claude Code to do its thing, it is often running a bunch of tasks. Part of the time that the agent spends is waiting for the LLM, but an increasing amount of time is using other tools, like querying a database. Over time, you can expect LLMs to get a lot faster; you can use smaller models, smarter models, local models, or fancier GPUs. As that happens the tools that an agent uses become the bottleneck.</p>



<p class="wp-block-paragraph">Picture two engines: one answers in 10 milliseconds, the other in 100. A person won’t notice the difference because both feel near instantaneous, and a person will spend far longer thinking up the next question than either engine spends answering it. What feels instantaneous to an agent is very different, and it doesn’t need to stop and think. When its next query depends on the last result, that 10x gap compounds straight into 10x more work per minute.</p>



<p class="wp-block-paragraph">One of the ways to make an agent go faster is to take more of their work and run it in parallel. But this also increases load on the systems. You’d want to make sure you have enough parallel capacity and isolation to be able to scale to all of the parallel agent queries at once. Engines tuned for human patience and engines tuned for agent throughput are not the same engines.</p>



<p class="wp-block-paragraph">The agentic wave is coming whether or not any given team is ready, and the best time to start preparing yourself and your stack is now, before the queries start pouring in. This isn’t just future proofing. The teams that move early are the ones who work out the patterns everyone else ends up copying. A little curiosity now buys a real head start later.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your AI Agent Isn’t a Static Artifact. It’s Growing Up.]]></title>
<description><![CDATA[In July 2025, an AI coding agent on Replit deleted a production database belonging to SaaStr founder Jason Lemkin. It did this during an explicit code freeze. Lemkin had told the agent, in capital letters, not to change anything. The agent ran destructive commands anyway, wiped records on more th...]]></description>
<link>https://tsecurity.de/de/3707914/ai-nachrichten/your-ai-agent-isnt-a-static-artifact-its-growing-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707914/ai-nachrichten/your-ai-agent-isnt-a-static-artifact-its-growing-up/</guid>
<pubDate>Thu, 06 Aug 2026 13:18:36 +0200</pubDate>
<content:encoded><![CDATA[In July 2025, an AI coding agent on Replit deleted a production database belonging to SaaStr founder Jason Lemkin. It did this during an explicit code freeze. Lemkin had told the agent, in capital letters, not to change anything. The agent ran destructive commands anyway, wiped records on more than a thousand executives and companies, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[KI im Management: Ab wann wird Verzicht zum Risiko?]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3707887/videos/ki-im-management-ab-wann-wird-verzicht-zum-risiko/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707887/videos/ki-im-management-ab-wann-wird-verzicht-zum-risiko/</guid>
<pubDate>Thu, 06 Aug 2026 13:17:13 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/0DlNmMPSAn4"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Wants Your Coding Data, and It’ll Cut Muse Code Prices by Up to 20x]]></title>
<description><![CDATA[Meta has launched Muse Code, a new terminal-based coding agent for macOS and Linux, with pricing that drops sharply when users allow the company to train future AI models on their prompts and completions.



The new tool runs on Meta’s Muse Spark 1.2 model and can plan code changes, write code, t...]]></description>
<link>https://tsecurity.de/de/3707862/ios-mac-os/meta-wants-your-coding-data-and-itll-cut-muse-code-prices-by-up-to-20x/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707862/ios-mac-os/meta-wants-your-coding-data-and-itll-cut-muse-code-prices-by-up-to-20x/</guid>
<pubDate>Thu, 06 Aug 2026 13:15:04 +0200</pubDate>
<content:encoded><![CDATA[Meta has launched Muse Code, a new terminal-based coding agent for macOS and Linux, with pricing that drops sharply when users allow the company to train future AI models on their prompts and completions.



The new tool runs on Meta’s Muse Spark 1.2 model and can plan code changes, write code, test results, and work across large software repositories. Meta has released Muse Code in beta, and Mac users can install it through Terminal with a single command.



Meta Muse Code pricing depends on data access



Meta charges Standard users $1.25 per million input tokens and $4.25 per million output tokens. This tier prevents Meta from using prompts and completions to train its models, which makes it the safer option for developers working with private or sensitive code.



The Contributor tier cuts the price to $0.10 per million input tokens and $0.20 per million output tokens. In exchange, users allow Meta to use their data for model training, which lowers input costs by more than 12 times and output costs by more than 20 times.



The cheaper tier also has lower usage limits, with 60 requests per minute and 2.1 million tokens per minute. Standard users receive up to 3,000 requests per minute and 4 million tokens per minute.



Muse Code also includes built-in commands for planning, reviewing, and completing development tasks. Its local event log records model calls, tool activity, approvals, and edits, which allows the agent to resume work after a crash.



Meta Muse Code directly competes with OpenAI Codex and Anthropic Claude Code, although Meta currently offers no dedicated desktop app. Developers must use the tool through Terminal on macOS or Linux.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft filings suggest "around 70%" of its AI revenue is concentrated entirely on OpenAI — which seems rather unhealthy]]></title>
<description><![CDATA[Recent analysis showed that Microsoft's AI business, while seemingly booming, still carries a somewhat enormous Sam Altman-shaped risk.]]></description>
<link>https://tsecurity.de/de/3707823/windows-tipps/microsoft-filings-suggest-around-70-of-its-ai-revenue-is-concentrated-entirely-on-openai-which-seems-rather-unhealthy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707823/windows-tipps/microsoft-filings-suggest-around-70-of-its-ai-revenue-is-concentrated-entirely-on-openai-which-seems-rather-unhealthy/</guid>
<pubDate>Thu, 06 Aug 2026 13:08:12 +0200</pubDate>
<content:encoded><![CDATA[Recent analysis showed that Microsoft's AI business, while seemingly booming, still carries a somewhat enormous Sam Altman-shaped risk.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-19066 | SourceCodester Online Examination & Learning Management System 1.0 view_students.php class_group authorization]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of the argument class_group leads to authorization bypass.

This vulnerability is ...]]></description>
<link>https://tsecurity.de/de/3707787/sicherheitsluecken/cve-2026-19066-sourcecodester-online-examination-learning-management-system-10-viewstudentsphp-classgroup-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707787/sicherheitsluecken/cve-2026-19066-sourcecodester-online-examination-learning-management-system-10-viewstudentsphp-classgroup-authorization/</guid>
<pubDate>Thu, 06 Aug 2026 13:07:43 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/sourcecodester:online_examination__learning_management_system">SourceCodester Online Examination &amp; Learning Management System 1.0</a>. Impacted is an unknown function of the file <em>view_students.php</em>. Such manipulation of the argument <em>class_group</em> leads to authorization bypass.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-19066">CVE-2026-19066</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15459 | WPMU DEV Dashboard Plugin up to 5.0.0 on WordPress validate_hash privileges management (EUVD-2026-53710)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in WPMU DEV Dashboard Plugin up to 5.0.0 on WordPress. Affected is the function validate_hash. Performing a manipulation results in improper privilege management.

This vulnerability is identified as CVE-2026-15459. The attack can be initia...]]></description>
<link>https://tsecurity.de/de/3707798/sicherheitsluecken/cve-2026-15459-wpmu-dev-dashboard-plugin-up-to-500-on-wordpress-validatehash-privileges-management-euvd-2026-53710/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707798/sicherheitsluecken/cve-2026-15459-wpmu-dev-dashboard-plugin-up-to-500-on-wordpress-validatehash-privileges-management-euvd-2026-53710/</guid>
<pubDate>Thu, 06 Aug 2026 13:07:43 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/wpmu_dev:dashboard_plugin">WPMU DEV Dashboard Plugin up to 5.0.0</a> on WordPress. Affected is the function <code>validate_hash</code>. Performing a manipulation results in improper privilege management.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-15459">CVE-2026-15459</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Telefonbetrug: Hacker attackieren Wall-Street-Hedgefonds - FONDS professionell]]></title>
<description><![CDATA[Wie "Bloomberg" berichtet, hat der Hedgefonds Point72 Asset Management seine Investoren am Mittwoch (5.8.) über einen Angriff informiert.]]></description>
<link>https://tsecurity.de/de/3707777/hacking/telefonbetrug-hacker-attackieren-wall-street-hedgefonds-fonds-professionell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707777/hacking/telefonbetrug-hacker-attackieren-wall-street-hedgefonds-fonds-professionell/</guid>
<pubDate>Thu, 06 Aug 2026 13:07:09 +0200</pubDate>
<content:encoded><![CDATA[Wie "Bloomberg" berichtet, hat der Hedgefonds Point72 Asset Management seine Investoren am Mittwoch (5.8.) über einen Angriff informiert.]]></content:encoded>
</item>
<item>
<title><![CDATA[Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers]]></title>
<description><![CDATA[Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to charges related to a large-scale cloud data theft and extortion operation that affected at least 165 organizations. This campaign resulted in the theft of billions of sensitive records, impacting a...]]></description>
<link>https://tsecurity.de/de/3707759/hacking/canadian-hacker-pleads-guilty-to-stealing-billions-of-records-from-165-cloud-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707759/hacking/canadian-hacker-pleads-guilty-to-stealing-billions-of-records-from-165-cloud-customers/</guid>
<pubDate>Thu, 06 Aug 2026 13:06:36 +0200</pubDate>
<content:encoded><![CDATA[<p>Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to charges related to a large-scale cloud data theft and extortion operation that affected at least 165 organizations. This campaign resulted in the theft of billions of sensitive records, impacting an estimated 100 million individuals worldwide. Canadian Hacker Pleads Guilty According to […]</p>
<p>The post <a href="https://gbhackers.com/canadian-hacker-pleads-guilty-to-stealing-billions-of-records/">Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records]]></title>
<description><![CDATA[Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, stole billions of...]]></description>
<link>https://tsecurity.de/de/3707756/hacking/snowflake-hacker-pleads-guilty-after-breaching-165-companies-and-stealing-billions-of-records/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707756/hacking/snowflake-hacker-pleads-guilty-after-breaching-165-companies-and-stealing-billions-of-records/</guid>
<pubDate>Thu, 06 Aug 2026 13:06:34 +0200</pubDate>
<content:encoded><![CDATA[Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, stole billions of customer records, and extorted multiple victims for millions of dollars. “Connor Riley Moucka, 26, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Amsterdam’s De Bijenkorf Hit by Logistics Cyberattack, Orders Delayed]]></title>
<description><![CDATA[A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems ...]]></description>
<link>https://tsecurity.de/de/3707747/it-security-nachrichten/amsterdams-de-bijenkorf-hit-by-logistics-cyberattack-orders-delayed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707747/it-security-nachrichten/amsterdams-de-bijenkorf-hit-by-logistics-cyberattack-orders-delayed/</guid>
<pubDate>Thu, 06 Aug 2026 13:01:56 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="De Bijenkorf cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/De-Bijenkorf-cyberattack-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Amsterdam's De Bijenkorf Hit by Logistics Cyberattack, Orders Delayed 3"></p><p class="PDq2pG_selectionAnchorContainer" data-start="599" data-end="1032">A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the <a href="https://thecyberexpress.com/tce-weekly-roundup-february-2026/" target="_blank" rel="noopener">security incident</a> occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised.</p>
<p data-start="1034" data-end="1259">The Amsterdam-based retailer confirmed that customers can continue placing online orders and stores remain open. However, deliveries, returns, and refunds are expected to take longer than usual as the investigation continues.</p>

<h2 data-section-id="12bsvun" data-start="1261" data-end="1319"><span role="text"><strong data-start="1264" data-end="1319">De Bijenkorf Confirms Third-Party Security Incident</strong></span></h2>
<p data-start="1321" data-end="1558">According to De Bijenkorf, unauthorized individuals gained access to part of its logistics partner's systems. The logistics provider responded by immediately blocking the unauthorized access and implementing additional <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29260">security</a> measures.</p>
<p data-start="1560" data-end="1699">An external investigation is now underway to determine the cause of the incident, its scope, and whether customer information was affected.</p>
<p data-start="1701" data-end="1883">As a precaution, De Bijenkorf has <a href="https://www.debijenkorf.nl/over-de-bijenkorf/beveiligingsincident" target="_blank" rel="nofollow noopener">informed</a> customers about the incident and submitted a report to the Dutch Data Protection Authority while awaiting the investigation's findings.</p>

<h2 data-section-id="1w6flj4" data-start="1885" data-end="1929"><span role="text"><strong data-start="1888" data-end="1929">What Customer Data Could Be Affected in De Bijenkorf Cyberattack?</strong></span></h2>
<p data-start="1931" data-end="2039">The retailer said investigators are still determining whether any personal information has been compromised.</p>
<p data-start="2041" data-end="2122">Based on the information currently available, <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29261">data</a> that may be involved includes:</p>

<ul data-start="2124" data-end="2460">
 	<li data-section-id="1qpgzis" data-start="2124" data-end="2225">Customer names and contact details, including email addresses, postal addresses, and phone numbers.</li>
 	<li data-section-id="enboud" data-start="2226" data-end="2361">Information related to online purchases, such as ordered products, pricing, discounts, delivery details, and the payment method used.</li>
 	<li data-section-id="188b2f8" data-start="2362" data-end="2460">For business customers, company names and VAT numbers stored in My Account may also be involved.</li>
</ul>
<p data-start="2462" data-end="2676">De Bijenkorf emphasized that sensitive financial information is not part of the incident. The company said payment details, bank account numbers, credit card information, usernames, and passwords were not accessed.</p>

<h2 data-section-id="bmbv5j" data-start="2678" data-end="2740"><span role="text"><strong data-start="2681" data-end="2740">Investigation Continues as Customers Await Confirmation</strong></span></h2>
<p data-start="2742" data-end="2964">The retailer said it is still investigating whether individual customers have been affected. Customers whose information is confirmed to be involved will receive direct communication via email from <a class="decorated-link cursor-pointer" rel="noopener" data-start="2942" data-end="2961">info@debijenkorf.nl</a>.</p>
<p data-start="2966" data-end="3169">For those who have not yet received a notification, the company said it cannot currently rule out the possibility that their information was included in the incident until the investigation is completed.</p>
<p data-start="3171" data-end="3343">De Bijenkorf also stressed that no login credentials were compromised, meaning unauthorized individuals cannot access customer accounts using stolen usernames or passwords.</p>

<h2 data-section-id="rlm5of" data-start="3345" data-end="3396"><span role="text"><strong data-start="3348" data-end="3396">Retailer Warns Customers About Phishing Risk</strong></span></h2>
<p data-start="3398" data-end="3584">Although the investigation remains ongoing, De Bijenkorf warned customers to stay alert for a possible <a href="https://thecyberexpress.com/cybles-sensor-intelligence-report/" target="_blank" rel="noopener">phishing risk </a>if personal information is ultimately found to have been exposed.</p>
<p data-start="3586" data-end="3805">The retailer advised customers not to click on suspicious links or open unexpected attachments. It also reminded customers never to share passwords, payment information, or personal details through email or phone calls.</p>
<p data-start="3807" data-end="3931">The company said it will never request credit card details, gift card information, or other sensitive information via email.</p>

<h2 data-section-id="j69i08" data-start="3933" data-end="3996"><span role="text"><strong data-start="3936" data-end="3996">Logistics Cyberattacks Continue to Disrupt Supply Chains</strong></span></h2>
<p data-start="3998" data-end="4281">The incident adds to a growing list of attacks targeting organizations that support retail operations rather than retailers directly. A logistics <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-a-cyber-attack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="29259">cyberattack</a> can interrupt deliveries, returns, and customer service even when the affected retailer's own systems remain operational.</p>
<p data-start="4283" data-end="4631">In July 2026, a ransomware attack on Japan's largest refrigerated logistics company disrupted food deliveries across the country, causing supply shortages for restaurant chains, including <a href="https://thecyberexpress.com/nichirei-cyberattack-disrupts-supply-chain/" target="_blank" rel="noopener">Kentucky Fried Chicken</a>. The incident demonstrated how cyberattacks on logistics providers can quickly impact downstream retail operations and customer services.</p>
<p data-start="4633" data-end="4961" data-is-last-node="" data-is-only-node="">For now, De Bijenkorf said its stores remain open, online ordering continues to operate, and there are no indications that its own systems have been compromised. The retailer said it will provide additional updates as the external investigation establishes whether customer data was affected and the full extent of the incident.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kill switch fears now rival ransomware as a top security risk for European businesses, Proton study finds]]></title>
<description><![CDATA[For years, the security team’s job has been to defend against cyberattacks. New research from Proton suggests that job now needs to extend to a very different kind of threat: the risk that a foreign government orders a US technology provider to cut a business off entirely. A study of 1,500 busine...]]></description>
<link>https://tsecurity.de/de/3707738/it-security-nachrichten/kill-switch-fears-now-rival-ransomware-as-a-top-security-risk-for-european-businesses-proton-study-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707738/it-security-nachrichten/kill-switch-fears-now-rival-ransomware-as-a-top-security-risk-for-european-businesses-proton-study-finds/</guid>
<pubDate>Thu, 06 Aug 2026 13:01:43 +0200</pubDate>
<content:encoded><![CDATA[<p>For years, the security team’s job has been to defend against cyberattacks. New research from Proton suggests that job now needs to extend to a very different kind of threat: the risk that a foreign government orders a US technology provider to cut a business off entirely. A study of 1,500 business decision-makers across the […]</p>
<p>The post <a href="https://www.itsecurityguru.org/2026/08/06/kill-switch-fears-now-rival-ransomware-as-a-top-security-risk-for-european-businesses-proton-study-finds/">Kill switch fears now rival ransomware as a top security risk for European businesses, Proton study finds</a> appeared first on <a href="https://www.itsecurityguru.org/">IT Security Guru</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the ‘rogue AI’ problem will lead to an era of headaches for security practitioners]]></title>
<description><![CDATA[Shortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a story which would reveal shocking new details about OpenAI’s “rogue model” incident: The agent hadn’t just slipped its leash for a few hours, as many assumed...]]></description>
<link>https://tsecurity.de/de/3707739/it-security-nachrichten/why-the-rogue-ai-problem-will-lead-to-an-era-of-headaches-for-security-practitioners/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707739/it-security-nachrichten/why-the-rogue-ai-problem-will-lead-to-an-era-of-headaches-for-security-practitioners/</guid>
<pubDate>Thu, 06 Aug 2026 13:01:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Shortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a <a href="https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/">story</a> which would reveal shocking new details about OpenAI’s “rogue model” incident: The agent hadn’t just slipped its leash for a few hours, as many assumed, but had in fact been wreaking havoc for days without the company’s knowledge.</p>



<p class="wp-block-paragraph">When I hung up, I immediately called a close friend who has worked inside frontier‑AI labs since before the term even existed. When she heard the timeline, she was stunned. In her view, “If proper industry regulations were in place, those four days would be grounds to terminate OpenAI’s R&amp;D GPU clusters until they get a full independent audit.”</p>



<h2 class="wp-block-heading">Demystifying the incident</h2>



<p class="wp-block-paragraph">There have been numerous reports that frame OpenAI’s model as a “rogue agent” escaping captivity and “breaking out” of the research lab, with both <a href="https://www.bbc.com/news/articles/c2el319vzr3o">the BBC and Cloud Security Alliance</a> comparing its actions to the dinosaurs in Jurassic Park.</p>



<p class="wp-block-paragraph">This framing is narratively compelling and is an easy way to communicate the gravity of the situation to a layperson. However, it undermines OpenAI’s agency both before and throughout the incident and plays into a larger problem due to the evangelizing way the company communicated its actions.</p>



<p class="wp-block-paragraph">OpenAI, in simplified terms, had been testing two models against a benchmark which scores how well an agent can find and exploit real-world software vulnerabilities. Both models ran with their cyber refusals deliberately reduced, in a sandbox environment meant to be isolated to a single internally hosted proxy. The models targeted Hugging Face, correctly inferring that the AI platform hosted the benchmark’s answer key — in short, “choosing” to cheat on the test they were given to complete the challenge.</p>



<p class="wp-block-paragraph">Following the breach, Hugging Face’s forensic team found thousands of agent actions in its logs, indicating that the time it took to break into Hugging Face, plus the attack itself, totaled 4 days.</p>



<p class="wp-block-paragraph">Hugging Face went public about the attack before it even knew that OpenAI was responsible. OpenAI, meanwhile, didn’t realize its own agent was the culprit until Hugging Face’s public disclosure made them check their own logs. In total, it took OpenAI nearly two weeks from its agent’s initial escape to come clean, and only once a rival’s hand had forced the issue.</p>



<h2 class="wp-block-heading">OpenAI’s “problem child”</h2>



<p class="wp-block-paragraph">From a human perspective, it’s bewildering that out of all paths the OpenAI agent could have taken to beat a standardized security challenge, it chose a ludicrously convoluted approach taking tens of thousands of attempted paths and barreling through set restrictions. However, it was par for the course given one of the model’s track records.</p>



<p class="wp-block-paragraph">In a <a href="https://openai.com/index/safety-alignment-long-horizon-models/">post published the day before the Hugging Face disclosure</a>, OpenAI describes one of its models that, unlike older versions that would simply stop at a sandbox restriction, would continue to persist until it found a way around, once even spending an hour hunting a sandbox vulnerability only to post its results to GitHub against explicit instructions. This model is GPT Sol 5.6, the public model involved in the Hugging Face attack.</p>



<p class="wp-block-paragraph">Long before the Hugging Face incident, GPT Sol 5.6 was already gaining a reputation for breaking rules, taking laughably long to accomplish simple tasks, and being destructive — in one case <a href="https://x.com/mattshumer_/status/2075657271401390161">deleting an AI entrepreneur’s entire Mac contents.</a></p>



<p class="wp-block-paragraph">Even during internal testing, the model had been caught <a href="https://deploymentsafety.openai.com/gpt-5-6-preview/gpt-5-6-preview.pdf">killing random processes when it couldn’t find the right virtual machines, lying about checking its work, and using credentials it wasn’t supposed to access.</a> However, it was still given public access by the company.</p>



<h2 class="wp-block-heading">Profit before safety</h2>



<p class="wp-block-paragraph"><a href="https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem">CSA’s report</a> states that an OpenAI model escaped a test container in September 2024 for a different evaluation, was contained quietly and “largely celebrated at the time” rather than treated as a warning. The same report calls this kind of escape “the standard, not the exception.” The former head of OpenAI’s “superalignment” safety team resigned in May 2024 and<a href="https://www.vox.com/future-perfect/2024/5/17/24158403/openai-resignations-ai-safety-ilya-sutskever-jan-leike-artificial-intelligence"> </a><a href="https://www.vox.com/future-perfect/2024/5/17/24158403/openai-resignations-ai-safety-ilya-sutskever-jan-leike-artificial-intelligence">wrote publicly</a> that “safety culture and processes have taken a backseat to shiny products.” It was reported that <a href="https://fortune.com/2024/08/26/openai-agi-safety-researchers-exodus/">nearly half of the team working on long-term AI safety had left</a>.</p>



<p class="wp-block-paragraph">Even the language used by OpenAI in their disclosure reads as more braggadocious than concerned. From OpenAI’s perspective, its failure was in not overseeing the agent’s choices as a whole, as each step taken by the model can remain fairly innocuous-seeming until pieced together. The company does not acknowledge that leaving an agent unsupervised in a testing setting with its safety classifiers off for even one hour, let alone days, is potentially catastrophic to begin with.</p>



<p class="wp-block-paragraph"><a href="https://www.wired.com/story/openais-rogue-ai-agent-hacked-more-than-just-hugging-face/">Some researchers have argued</a> that the recent incident is fundamentally a decades-old security failure rather than a narrative about a rogue intelligence: the exploit involved an exposed proxy, reused credentials and infrastructure that should have never had a path outward. However, a skilled human attacker given that same door would have needed weeks to achieve a fraction of what the agent did in days.</p>



<h2 class="wp-block-heading">A symptom of underlying issues</h2>



<p class="wp-block-paragraph">The incident reveals larger issues about the culture of safety at frontier model companies, whose employees are driven to crunch R&amp;D cycles and ignore potential issues until they become active problems. This isn’t unique to OpenAI, either — <a href="https://www.axios.com/2026/07/23/openai-hugging-face-cyber-hacks-testing">the UK’s AI Security Institute has reportedly found</a> that every frontier model it has tested cheats on cybersecurity evaluations at least occasionally, and that pre-deployment testing windows have shrunk industrywide from roughly five weeks to as few as five days.</p>



<p class="wp-block-paragraph">Regulatory bodies have also failed to keep up with or understand the industry’s rapid advancements. The US has no binding legal framework that would have required a different response from OpenAI, as labs are only beholden to voluntary commitments weighed against commercial pressure, and in cases like these, huge security breaches only serve to make the model look extremely smart and powerful.</p>



<p class="wp-block-paragraph">The US has attempted to create guardrails, but they fail to understand the ecosystem. We can see effects stemming from this lack of understanding in the recent attack: when Hugging Face’s responders needed to analyze what its attacker had done, Anthropic’s models declined the forensic work, citing their own guardrails, and<a href="https://en.wikipedia.org/wiki/2026_OpenAI_agent_cyberattacks"> </a>Hugging Face instead ran the analysis on GLM 5.2, an open-weight model from the Beijing company <a href="http://z.ai/">Z.ai</a>. In addition to being an ineffective band-aid, this also drives business outside of the US and therefore outside of its regulatory control. Today, roughly 80 percent of US AI startups now build on Chinese open-source models.</p>



<p class="wp-block-paragraph">US <a href="https://www.politico.com/news/2026/07/23/house-ai-kill-switch-bill-unveiled-as-openai-hack-raises-alarms-01008898">Representatives have introduced a bill</a> citing this incident by name, requiring killswitch capability and incident reporting, but nothing like it has passed, and no jurisdiction anywhere has demonstrated the insight to regulate evaluation-time behavior in addition to deployment-time behavior. This incident happened entirely during testing, before any release decision, in a stage every proposal currently treats as exempt.</p>



<p class="wp-block-paragraph">It’s important to note here that AI safety and practices differ from other branches of cybersecurity in that they have to build from a behavioral and psychological framework instead of one based on capability alone.</p>



<p class="wp-block-paragraph">For example, although Anthropic’s track record is far from spotless, it has invested significantly more energy than others into understanding the unconscious “thought processes” (or “<a href="https://transformer-circuits.pub/2026/workspace/index.html">j-space</a>”) of its models to better predict potential transgressions and set up more effective guardrails. What we can learn from these “rogue models” is that their behavior is actually very predictable; we know that when given a goal to accomplish, models will overstep boundaries freely in pursuit of their objective, simply because they have no actual understanding of the way we categorize “acceptable behavior”. In the real world, vulnerability exploitation encourages rule-breaking and disregard for boundaries by design, so why would a model trained to think this way see a test’s rules any differently?</p>



<p class="wp-block-paragraph">For CSOs and CIOs, the practical implication of this event remains narrow, for now. <a href="https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem">CSA’s post-mortem</a> offers mostly traditional advice: isolate package proxies and credential stores with a path to the open internet by default, log AI evaluation environments the way you log anything customer-facing, and build incident response around machine speed rather than human speed.</p>



<p class="wp-block-paragraph">The key risk factor for now is volume, with agents deploying actions at higher numbers than our pipelines are built to catch, and organizations that survive the next iteration of “rogue agents” will be the ones that assume as much beforehand.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Practical lessons from deploying AI securely at scale]]></title>
<description><![CDATA[When I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our time discussing prompt injection, model security, vector databases or the latest LLM vulnerabilities.



I was wrong — or at least incomplete.


...]]></description>
<link>https://tsecurity.de/de/3707740/it-security-nachrichten/practical-lessons-from-deploying-ai-securely-at-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707740/it-security-nachrichten/practical-lessons-from-deploying-ai-securely-at-scale/</guid>
<pubDate>Thu, 06 Aug 2026 13:01:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our time discussing prompt injection, model security, vector databases or the latest LLM vulnerabilities.</p>



<p class="wp-block-paragraph">I was wrong — or at least incomplete.</p>



<p class="wp-block-paragraph">The technology certainly matters, but after working with multiple enterprise AI initiatives, I’ve learned that the hardest security problems rarely come from the model itself. They emerge when AI becomes part of real business processes.</p>



<p class="wp-block-paragraph">An AI assistant doesn’t simply answer questions. In a single workflow, it might pull a customer record from Salesforce, open a ticket in ServiceNow and send an update through Microsoft 365 before anyone has finished reading the summary. Increasingly, it makes decisions before a human even notices, and that shift changes the threat model. Traditional application security assumes software executes deterministic code. AI systems don’t. They reason, adapt and generate outputs that cannot always be predicted in advance, which means many of the controls we’ve relied on for years remain necessary but are no longer sufficient.</p>



<p class="wp-block-paragraph">What follows is what I keep coming back to in architecture reviews: Not the model vulnerabilities that dominate the headlines, but the quieter failures that show up once an agent is already running.</p>



<h2 class="wp-block-heading">Identity is only the starting point</h2>



<p class="wp-block-paragraph">One of the first surprises I encountered was how quickly organizations focus on authentication while overlooking runtime behavior. Most enterprise AI projects begin with questions such as “Can the AI access SharePoint?” “Can it connect to ServiceNow?” “Can it connect to GitLab?” or “Can it read Microsoft 365 tools like Outlook, Word, etc.?” Those are important questions, but the more important one is: What should the AI be allowed to do after a specific type of access (for example, read-only access) has been granted?</p>



<p class="wp-block-paragraph">Identity answers who the agent is. Authorization answers what it may access. Neither answers whether the AI should perform a particular action; in the above case only performs read-only access.</p>



<p class="wp-block-paragraph">The capability question and the safeguard question are too often answered by different teams on different timelines. Security reviews that focus only on what the AI can access tend to miss the more revealing question of what it is permitted to do once that access exists. I have started treating those two questions as a single design problem, because every gap between them eventually surfaces as an incident.</p>



<p class="wp-block-paragraph">I remember an architecture review where this became concrete. An employee asked an internal assistant — one built on Microsoft 365 and SharePoint — to summarize several incident reports, and during its reasoning the assistant discovered privileged administrative documentation in a linked site and decided it might also be useful to include those details. Nothing technically failed. The credentials were valid. The permissions were correct. Yet the outcome violated business intent. That moment reframed the conversation for everyone in the room. We realized our threat model had been built for outsiders trying to get in, not for authorized systems acting a little too helpfully. Closing that gap meant designing controls that evaluated behavior in context, not just credentials at the door, and it’s why I’ve come to view runtime governance as one of the defining security challenges of enterprise AI.</p>



<p class="wp-block-paragraph">Organizations such as the <a href="https://genai.owasp.org/">OWASP GenAI Security Project</a> and the <a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST AI Risk Management Framework</a> emphasize that AI risks extend well beyond authentication authorizations to include monitoring, governance and continuous oversight throughout execution. <a href="https://www.csoonline.com/article/4193274/identity-the-operational-control-plane-for-agentic-ai.html">CSOonline’s coverage of agentic identity</a> makes the same point: Existing controls weren’t designed for AI agents, and static credentials and standing privileges are no longer sufficient when organizations must rapidly authorize, limit and revoke permissions from autonomous agents, sometimes more than once within a single workflow.</p>



<h2 class="wp-block-heading">The biggest failures rarely look like cyberattacks</h2>



<p class="wp-block-paragraph">Most security professionals naturally look for malicious activity: Prompt injection, data poisoning, credential theft, model manipulation. Those attacks certainly matter. What I’ve seen more frequently, however, are failures caused by legitimate AI behavior. A Finance, HR, Customer or risk management AI assistant retrieves more documents than necessary because it tries to provide a “better” answer. An autonomous workflow performs five approved actions instead of one. An AI agent continues executing after the user’s original intent has already been satisfied. None of these resemble traditional attacks, yet they may create compliance violations, privacy issues or operational disruption.</p>



<p class="wp-block-paragraph">One mental model has consistently helped executives understand why this is so dangerous. I ask them to stop thinking about AI as software and instead think about it as hiring thousands of new digital employees, aka AI agents. Every employee receives training, limited access, monitoring, auditing and oversight. AI agents deserve the same treatment.</p>



<p class="wp-block-paragraph">One deployment I worked on involved multiple specialized AI agents collaborating to complete a single business task. One queried ServiceNow for ticket history, another analyzed documents in SharePoint, a third drafted recommendations and a fourth wrote updates back into Jira. Individually, each agent had relatively limited permissions like read-only and/or write. Collectively, they represented a powerful autonomous workflow. That experience reinforced an important lesson: Security can no longer focus only on individual AI components. It must govern the complete chain of autonomous decision-making. The <a href="https://atlas.mitre.org/">MITRE ATLAS framework</a> is an excellent way to think about adversarial AI techniques, but equally important is understanding how normal autonomous behavior can unintentionally create business risk.</p>



<p class="wp-block-paragraph">The most instructive cases I’ve seen involve agents that delegate to other agents. In one review, a frontline support agent had strictly read-only access to Salesforce, but it could hand tasks to a second agent that held write privileges across ServiceNow and the billing platform. When the first agent couldn’t resolve a customer issue within its own scope, it quietly routed the request through the second agent, which updated the case and issued a credit. Nothing was hacked. The credentials were valid, the delegation was technically permitted, and yet a read-only agent had effectively performed write actions it was never meant to perform. That is the defining difference between an assistant and an agent. An assistant answers; an agent enlists other agents, and that escalation path is itself the vulnerability.</p>



<p class="wp-block-paragraph">That’s why we started asking a different question during architecture reviews. Instead of asking “Can the AI do this?” we asked, “Should the AI still be doing this?” That subtle shift changed many design decisions. It pushed teams to build in stopping conditions, scope checks and confirmation prompts rather than assuming an agent would naturally know when to stop. In one review, simply requiring a human to confirm before an agent crossed from a read-only step into a write action eliminated the majority of the risky paths we had been debating.</p>



<h2 class="wp-block-heading">Start with governance before autonomy</h2>



<p class="wp-block-paragraph">One pattern I’ve repeatedly observed is that organizations become excited about autonomy long before they’re prepared to govern it. Everyone wants AI agents, but few initially invest in runtime policy enforcement. That sequencing should be reversed. In my experience, successful enterprise AI programs put a few foundations in place before expanding automation: Clear business boundaries that an agent isn’t allowed to cross, least-privilege access for every agent, and human approval at any step that touches sensitive/restricted data/systems, including the production data /systems. Only after those exist does it make sense to widen autonomous decision-making. I’ve watched teams try to shortcut this order, and the result is almost always the same: A promising pilot gets pulled back because no one can confidently explain what the AI did or why.</p>



<p class="wp-block-paragraph">A big part of that foundation is visibility. Traditional audit logs record actions, but AI systems also need to record reasoning. When an AI agent creates a ticket, updates a configuration or sends an email, investigators should understand why the decision occurred. This doesn’t mean recording every token generated by a large language model. I’ve found more value in capturing three things: The original business request, the systems the agent touched and the decisions it made along the way. Those records become invaluable during investigations, compliance reviews and operational troubleshooting, and they help organizations build trust. Business leaders become far more comfortable adopting AI when they can explain how an important decision was reached. Approaches like <a href="https://blog.google/innovation-and-ai/technology/safety-security/introducing-googles-secure-ai-framework/">Google’s Secure AI Framework</a> reinforce the same idea: AI security has to be measurable, observable and accountable end to end.</p>



<p class="wp-block-paragraph">One misconception I still encounter is that AI security exists to restrict innovation. In practice, the organizations moving fastest with enterprise AI are often the ones investing most heavily in governance, because executives gain confidence, developers move faster and business units adopt AI more broadly. Done well, security is what makes that speed possible.</p>



<p class="wp-block-paragraph">Looking back, the most valuable lesson hasn’t been about prompt engineering, model selection or agent frameworks. It’s that secure AI isn’t achieved through one perfect control but through hundreds of small engineering decisions that keep autonomous systems aligned with business intent. As we move from assistants toward fully autonomous agents, that distinction only matters more. The teams I trust to scale AI aren’t the ones with the smartest models. They’re the ones who can answer, for any action an agent took, why it took it — and where it would have stopped.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Evidence points to cybercriminals stepping up their AI game]]></title>
<description><![CDATA[More evidence is emerging about how AI is becoming part of the day-to-day workflow for cybercriminals, from building and refining tools to managing infrastructure and accelerating vulnerability research.



Drawing on recovered prompt logs, attack tooling, and threat actor conversations, research...]]></description>
<link>https://tsecurity.de/de/3707741/it-security-nachrichten/evidence-points-to-cybercriminals-stepping-up-their-ai-game/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707741/it-security-nachrichten/evidence-points-to-cybercriminals-stepping-up-their-ai-game/</guid>
<pubDate>Thu, 06 Aug 2026 13:01:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">More evidence is emerging about how AI is becoming part of the day-to-day workflow for cybercriminals, from building and refining tools to managing infrastructure and accelerating vulnerability research.</p>



<p class="wp-block-paragraph">Drawing on recovered prompt logs, attack tooling, and threat actor conversations, research from Cisco Talos documents how AI is being used to develop malicious code, build fraud infrastructure, and accelerate vulnerability research and exploitation.</p>



<p class="wp-block-paragraph">The <a href="https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/">study</a>, released during the Black Hat USA conference, found AI systems guardrails were often ineffective.</p>



<p class="wp-block-paragraph">Cisco Talos researchers write that threat actors frequently bypass guardrails with basic social engineering claims (“this is authorised testing” or “I’m asking this as part of a capture the flag exercise”) that convince most models to comply.</p>



<p class="wp-block-paragraph">This duped permissiveness wasn’t specific to a single model or platform. Instead, analysis of prompt logs related to Claude Code, CodeX, Cursor, and Gemini showed this shortcoming was an issue across the board. And when censored models refuse, threat actors simply switch to uncensored alternatives.</p>



<p class="wp-block-paragraph">Whereas novice cybercriminals continue to produce clunky malware with limited functionality, sophisticated threat groups are increasingly leveraging AI as a development assistant to rapidly build exploits, and some are even deploying it as a system administration tool for managing large-scale attack infrastructure.</p>



<p class="wp-block-paragraph">Cisco Talos found real-world examples of attackers abusing AI systems to build a bulk-mail validation service processing tens of millions of email records, adapting the <a href="https://www.csoonline.com/article/4111888/react2shell-anatomy-of-a-max-severity-flaw-that-sent-shockwaves-through-the-web.html">React2Shell vulnerability</a> into a credential-harvesting pipeline, developing DDoS infrastructure targeting Android TVs, and supporting cryptocurrency theft operations, among other attacks.</p>



<p class="wp-block-paragraph">Joseph Rooke, senior director at Recorded Future’s Insikt Group, sees attacker tradecraft evolving away from traditional code-based exploits toward prompt-based manipulation of large language models.</p>



<p class="wp-block-paragraph">“Targeting weakness in LLMs enables malicious prompts to be embedded in shared text, video, or image files, with the aim of hijacking LLM-based assistants to carry out attacks,” Rooke tells CSO.</p>



<p class="wp-block-paragraph">Norwegian AI researcher Håkon Måløy recently demonstrated such an attack, which could result in a <a href="https://www.csoonline.com/article/4203630/copilot-worm-can-spread-through-microsoft-word-docs.html">Copilot worm spreading through Microsoft Word docs</a>. Attackers are also <a href="https://www.csoonline.com/article/4204731/attackers-are-crafting-malicious-ai-instruction-files-to-turn-your-agentic-workflows-into-quiet-criminal-helpers.html">crafting malicious AI instruction files</a>, like CLAUDE.md, to trick agents into exfiltrating data and other tasks on their behalf.</p>



<p class="wp-block-paragraph">“Malicious prompts will increasingly replace malware as the preferred intrusion method, enabling adversaries to extract sensitive data, override guardrails, or induce harmful actions without breaching traditional defenses,” Rooke says.</p>



<h2 class="wp-block-heading">Attacking AI through the software supply chain</h2>



<p class="wp-block-paragraph">Separately, research from CrowdStrike shows that adversaries are increasingly targeting AI infrastructure through software supply chain-style attacks.</p>



<p class="wp-block-paragraph">For example, in March 2026, North Korean cybercrime group Stardust Chollima used stolen maintainer credentials to <a href="https://www.csoonline.com/article/4152696/attackers-trojanize-axios-http-library-in-highest-impact-npm-supply-chain-attack.html">compromise the Axios npm package</a> and deliver platform-specific variants of their ZshBucket malware.</p>



<p class="wp-block-paragraph">In June 2026, the same group injected a malicious npm package as a dependency into at least 131 <a href="https://www.csoonline.com/article/4072341/introducing-maestro-a-framework-for-securing-generative-and-agentic-ai.html">Mastra AI framework</a> packages, indicating that trusted AI building blocks are becoming targets in supply chain attacks.</p>



<p class="wp-block-paragraph">During 1H 2026, 87% of identified software registry threats involved malicious npm packages. “This indicates adversaries’ preference for JavaScript’s scale, dependency chains, and automatic install scripts to spread downstream risk,” CrowdStrike’s researchers report.</p>



<p class="wp-block-paragraph"><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report/">CrowdStrike’s 2026 Threat Hunting Report</a> also reveals how AI is collapsing the window between vulnerability disclosure and active exploitation.</p>



<p class="wp-block-paragraph">For example, two separate Chinese APT groups exploited critical vulnerabilities within 24 hours of public proof-of-concept (PoC) release. From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC’s release.</p>



<p class="wp-block-paragraph">After the React2Shell vulnerability disclosure, CrowdStrike responded to over 800 hunting leads across more than 80 victims in just four days.</p>



<p class="wp-block-paragraph">Cybercrime group Altered Spider (aka TeamPCP) <a href="https://www.csoonline.com/article/4170284/mistral-ai-sdk-tanstack-router-hit-in-npm-software-supply-chain-attack.html">compromised more than 300 software dependencies</a> in a single day to harvest credentials and pivot into cloud environments.</p>



<h2 class="wp-block-heading">Authentication systems under attack</h2>



<p class="wp-block-paragraph">The study — based on frontline intelligence from CrowdStrike’s threat hunters and intelligence analysts — also found that trusted authentication has become a favored attack path with, for example, vishing intrusions doubling in 1H 2026. On a related front, cybercrime groups Cordial Spider and Snarky Spider compromised single sign-on (SSO) integrated SaaS applications for data exfiltration.</p>



<p class="wp-block-paragraph">Recorded Future’s Rooke points out other ways authentication systems are at the front line of AI-based attacks.</p>



<p class="wp-block-paragraph">“AI-generated deepfake videos and audio are also more likely to be used as part of business email compromise attacks and social engineering,” Rooke tells CSO. “Biometric and identity-verification systems will likely remain vulnerable to spoofing, replay, and cloned credentials, enabling synthetic personas to coerce payments, manipulate employees, and facilitate access handoffs to cyber operators.”</p>



<p class="wp-block-paragraph">Cloud-focused cybercrime activity surged 171% as adversaries executed credential theft, cryptomining, LLM abuse, and digital financial asset theft, according to CrowdStrike.</p>



<h2 class="wp-block-heading">How cyber teams should respond</h2>



<p class="wp-block-paragraph">“AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend,” says Adam Meyers, head of counter adversary operations at CrowdStrike. “The organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary.”</p>



<p class="wp-block-paragraph">Comprehensive industry-wide data remains limited because evidence of AI abuse is often difficult to identify via traditional security telemetry. Incidents documented by Cisco Talos and CrowdStrike, however, show how CISOs need to adapt in response to the growing threat.</p>



<p class="wp-block-paragraph">Cisco Talos urges enterprises to improve detection, prioritization, and their own use of AI platforms and agents to handle the growing volume of alerts and vulnerabilities. “The organisations best equipped to handle the coming deluge of additional vulnerabilities, alerts, and incidents will be the ones that prepare now by deploying their own AI-assisted security capabilities,” according to the report.</p>



<p class="wp-block-paragraph">“Security teams should assume AI is already embedded in attacker workflows; focus on detecting malicious behavior rather than proving AI involvement; treat LLMs and APIs as privileged, high-risk infrastructure; and strengthen logging, patching, and containment,” says Oliver Simonnet, lead cybersecurity researcher at AI security and governance platform CultureAI.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers]]></title>
<description><![CDATA[Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty on August 5, 2026, to a sweeping hacking and extortion conspiracy that compromised at least 165 organizations and exposed billions of sensitive customer records, the U.S. Department of Justice announced. Between February and October 2...]]></description>
<link>https://tsecurity.de/de/3707733/it-security-nachrichten/canadian-hacker-pleads-guilty-to-stealing-billions-of-records-from-165-cloud-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707733/it-security-nachrichten/canadian-hacker-pleads-guilty-to-stealing-billions-of-records-from-165-cloud-customers/</guid>
<pubDate>Thu, 06 Aug 2026 13:01:38 +0200</pubDate>
<content:encoded><![CDATA[<p>Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty on August 5, 2026, to a sweeping hacking and extortion conspiracy that compromised at least 165 organizations and exposed billions of sensitive customer records, the U.S. Department of Justice announced. Between February and October 2024, Moucka and unnamed co-conspirators used stolen login credentials to breach cloud-hosted […]</p>
<p>The post <a href="https://cyberpress.org/canadian-hacker-pleads-guilty/">Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records]]></title>
<description><![CDATA[Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, stole billions of...]]></description>
<link>https://tsecurity.de/de/3707695/it-security-nachrichten/snowflake-hacker-pleads-guilty-after-breaching-165-companies-and-stealing-billions-of-records/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707695/it-security-nachrichten/snowflake-hacker-pleads-guilty-after-breaching-165-companies-and-stealing-billions-of-records/</guid>
<pubDate>Thu, 06 Aug 2026 12:52:04 +0200</pubDate>
<content:encoded><![CDATA[Snowflake hacker Connor Moucka pleads guilty after breaching 165 organizations, stealing billions of records, and extorting victims. Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty this week to a computer hacking conspiracy that compromised over 165 organizations, stole billions of customer records, and extorted multiple victims for millions of dollars. “Connor Riley Moucka, 26, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)]]></title>
<description><![CDATA[Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface. The fix was part of Cisco’s August 5 advisory batch, and unlike the bugs squashed by the hardening rele...]]></description>
<link>https://tsecurity.de/de/3707688/it-security-nachrichten/critical-cisco-imc-bug-gives-attackers-root-poc-is-out-cve-2026-20200/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707688/it-security-nachrichten/critical-cisco-imc-bug-gives-attackers-root-poc-is-out-cve-2026-20200/</guid>
<pubDate>Thu, 06 Aug 2026 12:51:54 +0200</pubDate>
<content:encoded><![CDATA[<p>Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface. The fix was part of Cisco’s August 5 advisory batch, and unlike the bugs squashed by the hardening releases for IOS XE and SD-WAN, this one has a public proof-of-concept exploit. AI-discovered flaws in IOS XE and SD-WAN Cisco made available hardening releases addressing critical-severity flaws in Cisco … <a href="https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/">Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI ROI metrics are measuring the wrong thing]]></title>
<description><![CDATA[The loudest conversation in business right now is about how much value AI actually generates. Over the last year, AI has moved from a side experiment to a strategic priority. It has its own budget line, its own place on the board’s agenda and its own pressure to show results. Every leader is aski...]]></description>
<link>https://tsecurity.de/de/3707685/it-security-nachrichten/why-ai-roi-metrics-are-measuring-the-wrong-thing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707685/it-security-nachrichten/why-ai-roi-metrics-are-measuring-the-wrong-thing/</guid>
<pubDate>Thu, 06 Aug 2026 12:51:47 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The loudest conversation in business right now is about how much value AI actually generates. Over the last year, AI has moved from a side experiment to a strategic priority. It has its own budget line, its own place on the board’s agenda and its own pressure to show results. Every leader is asking a version of the same question: What are we getting back?</p>



<p class="wp-block-paragraph">To answer it, most reach for the three measures they have always trusted to judge a technology:</p>



<ul class="wp-block-list">
<li>How much faster are we now?</li>



<li>How much money has it saved us?</li>



<li>How many of our people are using it?</li>
</ul>



<p class="wp-block-paragraph">Speed, cost and adoption were the right yardsticks for every major technology of the past two decades. They worked because the capability of traditional software was fixed and known on the day you deployed it. The tool did a defined job. Its value had a ceiling you could see, and each metric measured your progress toward that ceiling. Cost reduction told you how much you could save. Adoption told you how much of the capability you had rolled out. Speed told you how much of the promised acceleration was reaching the output.</p>



<p class="wp-block-paragraph">In every case, the tool was a constant, and the metric measured how fully the organization had absorbed that constant.</p>



<p class="wp-block-paragraph">These metrics are not working for AI. The reason starts with how AI entered our organizations.</p>



<p class="wp-block-paragraph">Every technology before this was chosen somewhere above us, deployed to us and trained into us. By the time it arrived on our desks, someone had already decided what it was for. AI came the other way. It landed as a personal productivity tool. You opened a tab, typed a question and something useful came back. Nobody defined its capability in advance, because its capability is not fixed. What it produces depends on who is using it and how well. Metrics built for fixed capabilities have nothing stable to measure, and here is what happens when you apply them anyway.</p>



<h2 class="wp-block-heading"><a></a>Why speed, cost and adoption fail as AI evaluation metrics</h2>



<p class="wp-block-paragraph">Let’s start with speed. Task speed and business speed are different quantities, and AI only touches the former. Suppose a report that took eight hours now takes two. Your dashboard shows a 75% improvement. But the report still waits three days for review and a week for approval before anyone acts on it. The organization sees dramatic task-level gains but no movement in business results and concludes AI failed. The problem is the metric measuring a layer that was never the bottleneck.</p>



<p class="wp-block-paragraph">Speed creates a second problem, and it is worse. Getting good output from AI requires checking it, correcting it and feeding those corrections back into how the tool is used. That work is slow. On any speed metric, it looks like inefficiency. So, people under speed pressure skip it. They accept output uncritically and produce more volume with less scrutiny.</p>



<p class="wp-block-paragraph">Cost reduction has an arithmetic problem. If you frame AI as a way to reduce what you currently spend, your maximum possible win is your current spend. If your content team costs a million dollars, the best case in a cost frame is saving a million dollars. Every general-purpose technology has followed the same sequence:<a href="https://www.mckinsey.com/capabilities/strategy-and-corporate-finance/our-insights/where-ai-will-create-value-and-where-it-wont"> Efficiency gains came first, and the larger value came later,</a> from work that did not exist before.</p>



<p class="wp-block-paragraph">For AI, that means the analysis nobody had time for, the personalization no team could staff, the experiments too expensive to justify. A cost frame makes all of that invisible because new work doesn’t reduce anything. There is no column on the dashboard for things you couldn’t do last year.</p>



<p class="wp-block-paragraph">Cost framing also works against its own inputs. AI improves through use by knowledgeable people. It needs their corrections, their context and their judgment about what good output looks like. When AI’s success is measured in headcount avoided, those people understand exactly what they are being asked to build: Their own replacement. They respond rationally. They use the tools shallowly and keep their expertise to themselves. The metric announces an intent, and the intent destroys the participation the technology depends on.</p>



<p class="wp-block-paragraph">Adoption looks like the safest of the three. The problem is that adoption measures usage, and usage is not a value.<a href="https://www.nber.org/papers/w34836"> </a>Researchers at several central banks recently <a href="https://www.nber.org/papers/w34836">asked thousands of senior executives about this</a> and heard the same two things from most of them: Yes, we use AI across the business, and no, it has not changed our results yet.</p>



<p class="wp-block-paragraph">A thousand employees asking AI to shorten their emails will produce a spectacular adoption number and almost nothing else. Fifty employees using AI on judgment-heavy work, feeding it real context and checking its output against real standards, will barely register on the dashboard and generate most of the actual return. Adoption metrics cannot tell these two groups apart. Worse, they reward the shallow pattern. Shallow use is easy to spread, and deep use is hard, so an organization managed on adoption drifts toward the use that is easiest to count.</p>



<h2 class="wp-block-heading">6 signals that track the real value</h2>



<p class="wp-block-paragraph">A few months ago, I realized the ROI question was aimed at the wrong object. Every company I compete with has access to the same models I do, at the same price. Whatever value comes from the model itself, my competitors receive too, so it cancels out any comparison between us. It cannot be an advantage, and it is not an interesting thing to measure. The only variable left is us. The standards, the context and the judgment we build around the model, because none of that arrives with the subscription and none of it can be bought. So, when I evaluate AI, I am evaluating my own organization and how quickly it turns a commodity everyone has into a capability only we have. The six signals below all measure that second thing.</p>



<h3 class="wp-block-heading">1. Review burden is falling on the same class of work</h3>



<p class="wp-block-paragraph">Take any recurring task the organization runs through AI: Monthly reports, vendor evaluations, code review. Track how much human checking each unit of output needs, quarter over quarter. If a task needed a full senior review in January and needed a spot check in June, something real happened. The organization encoded its quality standards, improved its inputs and learned where the tool fails. If the review burden is flat, the organization is consuming AI, not compounding on it, no matter what the adoption dashboard says.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Pick five recurring workflows, log review hours per output and plot the trend. The trend is the signal. The absolute number matters far less.</li>
</ul>



<h3 class="wp-block-heading">2. Corrections become shared fixes</h3>



<p class="wp-block-paragraph">When someone discovers that the AI gets something wrong, how long does it take for that discovery to become a shared fix? In a healthy system, one person’s correction becomes an updated prompt, a revised guideline or a documented example of good versus bad within days. Nobody else has to rediscover the same failure. In an unhealthy system, every employee privately learns the same lessons. The knowledge lives in individual chat histories, and it leaves with each departure.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Sample recent corrections and trace them. Did they land anywhere reusable? How long did it take? An organization that cannot answer these questions at all has its answer.</li>
</ul>



<h3 class="wp-block-heading">3. The team does work that it could not do before</h3>



<p class="wp-block-paragraph">The largest returns from any general-purpose technology come from previously impossible work, not from old work done faster. So, look at the work itself. Is the organization doing the same portfolio of tasks faster, or is the portfolio expanding?</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Once a year, list what the team produces now that it did not and could not produce before. If the list is empty after a year of heavy AI use, the organization has been optimizing instead of expanding, and it is capturing the smallest slice of the available value.</li>
</ul>



<h3 class="wp-block-heading">4. The delegation boundary is moving</h3>



<p class="wp-block-paragraph">Every organization has an implicit line: Work AI does alone, work AI does with human review, work humans do entirely. Watch whether that line moves. Work that needed full human ownership last year and needs only oversight now is direct evidence of accumulated capability, clearer standards and earned trust. A frozen boundary means frozen capability.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Make the implicit map explicit. Build a simple inventory of task types and their current delegation level, then re-score it quarterly. The change is the signal. It is also one of the few AI metrics a board can grasp intuitively: This category moved from full review to spot check, and here is what we built to make that safe.</li>
</ul>



<h3 class="wp-block-heading">5. Cost per verified outcome is falling</h3>



<p class="wp-block-paragraph">What does it cost, all in, to produce a unit of work you would actually ship: checked, corrected, done? All in means the subscription, the prompting time, the review time and the rework when errors slip through.</p>



<p class="wp-block-paragraph">This number does two jobs. It exposes the true economics, which usually look worse than the dashboard claims early on, because the human labor around the tool costs more than the tool itself. And it gives you the one number that should fall over time if capability is genuinely accumulating, because encoded standards and better context reduce exactly those human hours.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Instrument one workflow end-to-end, honestly, before generalizing. Most organizations have never done this once.</li>
</ul>



<h3 class="wp-block-heading">6. Use is getting deeper, not just wider</h3>



<p class="wp-block-paragraph">Adoption metrics count users. This signal counts the nature of use. Shallow use, such as rewriting emails and summarizing documents, spreads fast and produces little. Deep use, where AI is applied to judgment-heavy work with real context and real evaluation, spreads slowly and produces most of the return.</p>



<ul class="wp-block-list">
<li><strong>How to measure it: </strong>Classify actual usage into shallow and deep, even roughly, and track the ratio. Fifty deep users beat a thousand shallow ones, and only this signal can tell you which group you have.</li>
</ul>



<h2 class="wp-block-heading"><a></a>Two cautions</h2>



<p class="wp-block-paragraph">First, any of these signals can be gamed once it becomes a target. This is <a href="https://en.wikipedia.org/wiki/Goodhart%27s_law">Goodhart’s Law.</a> The review burden can fall because people simply review less. So, pair every efficiency signal with a quality check, such as error rates, rework and downstream complaints.</p>



<p class="wp-block-paragraph">Second, expect the early numbers to look bad. Honest instrumentation usually shows that AI currently costs more per verified outcome than the old process, because the organization is still <a href="https://www.nber.org/papers/w25148">paying its learning costs</a>.</p>



<h2 class="wp-block-heading"><a></a>Final thoughts</h2>



<p class="wp-block-paragraph"><br>I am not saying AI is overhyped, and I am not saying speed, cost and adoption will never matter. Every real gain eventually shows up in those numbers. I am saying they show up last because they are the output of a learning process, not the process itself. Judge AI by them today, and you will make your keep-or-kill decisions years before the evidence arrives.</p>



<p class="wp-block-paragraph">If I could track only one thing, it would be the delegation boundary. It compresses everything else into a single observable fact. The boundary only moves when context has been encoded, standards have been made explicit, corrections have been institutionalized and trust has been earned through verified results. It is the output yardstick of the entire learning system. If this has not moved in a year, no other number on the dashboard means anything, however green it looks.</p>



<p class="wp-block-paragraph">Measure the learning, and the returns will follow. Measure only the returns, and you may kill the learning that produces them.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI takes flight at GE Aerospace]]></title>
<description><![CDATA[The race to adopt AI has left many CIOs wrestling with a fundamental question: How do you move faster without introducing unacceptable risk?



Few leaders face that challenge at a higher level than David Burns, CIO of GE Aerospace. Building on the company’s decade of experience applying AI acros...]]></description>
<link>https://tsecurity.de/de/3707684/it-security-nachrichten/how-ai-takes-flight-at-ge-aerospace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707684/it-security-nachrichten/how-ai-takes-flight-at-ge-aerospace/</guid>
<pubDate>Thu, 06 Aug 2026 12:51:46 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The race to adopt AI has left many CIOs wrestling with a fundamental question: How do you move faster without introducing unacceptable risk?</p>



<p class="wp-block-paragraph">Few leaders face that challenge at a higher level than David Burns, CIO of GE Aerospace. Building on the company’s decade of experience applying AI across its business, Burns is helping lead the next phase of the company’s digital transformation by leveraging AI to simplify and automate processes. Burns’ experience shows how AI can accelerate innovation, improve decision-making, and create value for the business and customers while maintaining the trust, safety, and operational rigor expected in the aerospace industry.</p>



<p class="wp-block-paragraph">In a recent episode of <a href="https://linktr.ee/techwhisperers">the Tech Whisperers podcast</a>, Burns opened up his playbook for leading organizations through turbulence. In this conversation, edited for length and clarity, he shares more practical lessons for technology leaders who are seeking to move beyond experimentation and scale AI responsibly across the enterprise.</p>



<p class="wp-block-paragraph"><strong>Dan Roberts: You’ve described AI as an accelerator. What exactly is AI accelerating inside GE Aerospace?</strong></p>



<p class="wp-block-paragraph"><strong>David Burns:</strong> At GE Aerospace, AI is used across our operations as an accelerator to Flight Deck, our proprietary lean operating model, and is applied to all key aspects of the business — design, manufacture, sales, and services. We identify and solve problems with Flight Deck and use AI to accelerate our problem-solving in ways we can genuinely feel, enabling us to identify issues earlier, solve problems faster for our customers, and improve how work gets done.</p>



<p class="wp-block-paragraph">For example, we are also using AI in:</p>



<p class="wp-block-paragraph"><strong>Design:</strong> While traditional processes for developing engine design concepts take months of manual work, the GE Aerospace Research Center built a proprietary generative AI application capable of producing hundreds of design concepts. As a result, the team produced the hypersonic ramjet engine design concept that met all regulatory requirements more than 90% faster than before, highlighting how AI is possible in engine design to support engineers bringing new technologies to market faster.</p>



<p class="wp-block-paragraph"><strong>Manufacture:</strong> Our team in Indianapolis used an AI coding assistant to automate a part quality inspection workflow, reducing 8 hours of manual measurement data entry for complex parts to just 3 seconds while improving data accuracy and inspection consistency. This has improved both the quality and efficiency for clearing parts to build, which helps drive on-time engine deliveries.</p>



<p class="wp-block-paragraph"><strong>Sales:</strong> Based on customer feedback that GE Aerospace’s responses for proposals needed to be faster, the sales team utilized a generative AI tool to synthesize data and produce deal proposals. The tool improved customer response time by more than two weeks for the GEnx team through reduced proposal development cycle time and standardized creation of more comprehensive deal proposals.</p>



<p class="wp-block-paragraph"><strong>Service:</strong> When LEAP engine rebuilds faced potential turnaround time (TAT) challenges due to material availability at our Maintenance, Repair and Overhaul (MRO) sites, our team in Lafayette, Indiana, applied AI to help reduce delays for customers. Using Daily &amp; Visual Management, they surfaced material flow challenges and their underlying drivers, leading to a new AI solution that leverages data to predict when and where parts are needed faster to reduce delays for our customers with an approximately six-day turnaround time improvement, 16% increase in on-time material orders, and 15% increase in on-time material delivery.</p>



<p class="wp-block-paragraph">Ultimately, by leveraging AI, Flight Deck helps us eliminate waste and identify and accelerate the most value-added steps for our customers, be it designing a part faster or responding to a customer request faster. And I would underscore that it’s value through the eyes of our customer. How we define value is not what we internally say; it’s how our customers define value, and how we’re working to be more customer-driven.</p>



<p class="wp-block-paragraph"><strong>GE Aerospace has been investing in analytics, machine learning, and digital capabilities for more than a decade. What advantages does that foundation create as you move into the generative AI era?</strong></p>



<p class="wp-block-paragraph">We’ve built one of the largest AI patent portfolios in the aviation industry through years of investment and supercomputing through digital technologies, and we continue to do work on our core transactional systems and our data foundations, so that way our data is AI-ready. This has allowed us to build our own AI capabilities and strong talent base. For example, the generative AI app we built to create new propulsion systems design was built in house by GE Aerospace scientists at the <a href="https://www.geaerospace.com/news/press-releases/ge-aerospace-completes-design-studies-hypersonic-ramjet-generative-ai">GE Aerospace Research Center</a>.</p>



<p class="wp-block-paragraph">At the same time, our knowledge and familiarity with the landscape has allowed us to make connections with tech companies, including one where we’re using agentic AI in a multi-year partnership to predict demand and identify constraints to enhance production readiness in the Defense business.</p>



<p class="wp-block-paragraph">We were fortunate to have leaders who were very smart to invest in data scientists 10, 15 years ago, and we’re getting to leverage that talent today. The lesson there is that is you always have to be thinking long term when you’re talking about talent, because you may not know exactly how the world will play out, but making sure you have the best athletes on the field to run the race becomes critically important. For us, some of those investments we did around our people is what’s paying off today.</p>



<p class="wp-block-paragraph"><strong>One of the biggest challenges facing CIOs today is balancing innovation with risk management. How do you approach that balance in an industry where safety, reliability, and trust are non-negotiable?</strong></p>



<p class="wp-block-paragraph">It’s all about risk tolerance. There are certain areas in our business where we don’t have high risk tolerance, and we’re very methodical and cautious about how we deploy technology into those uses and have very stringent processes that we comply consistently with. In areas that are not safety and quality critical, we are more aggressive in looking at how we can use technology to deliver more for our customers and to make our employees more effective. That’s where we strike the balance, and at the end of the day, it’s about making sure we’re never compromising safety or quality in what we do.</p>



<p class="wp-block-paragraph">As for the process, we start with Flight Deck and focus AI where it can help solve critical challenges for our customers and with the highest impact to customer outcomes, enhancing safety, quality, delivery, and cost, in that order, to solve problems that matter most and keep fleets flying. ​</p>



<p class="wp-block-paragraph">We have three guiding principles for safe and responsible AI use: </p>



<ul class="wp-block-list">
<li><strong>Trust:</strong> The data-informing AI must be known, trusted, and reliable. </li>



<li><strong>Transparent:</strong> The AI must be transparent and repeatable, which means we need to know what is informing an AI model’s insights and actions.</li>



<li><strong>Human:</strong> A human must always be in the loop and make the final decision.    </li>
</ul>



<p class="wp-block-paragraph">Our culture of discipline also plays an important role. Our business variation is challenging, so one of the core fundamentals of Flight Deck is standard work. It’s embedded into our culture, and it’s the base expectation that we operate with standards that we’re continuously improving.</p>



<p class="wp-block-paragraph"><strong>Many organizations are struggling to move from AI pilots to enterprise-scale value. What lessons have you learned about successfully scaling AI across a large, complex organization?</strong></p>



<p class="wp-block-paragraph">AI is a tool that strengthens the capabilities of skilled employees; it is not a substitute for their judgment, experience, or accountability. So we focus on testing and validating AI solutions through pilots before scaling, and look for AI applications that meaningfully change how work gets done.</p>



<p class="wp-block-paragraph">Early on, when we started doing a lot of our generative AI work, we focused on 14 big problems in the business, and we didn’t let ourselves stray all over the place. We also didn’t look at it as a technology solution. We looked at the process and where technology played into the process, and then we embedded AI into those core processes. So now, it’s not a separate thing where you go do AI. It’s embedded in the workflow of how things get done.</p>



<p class="wp-block-paragraph">That gave us a foundation to learn and grow from that we’ve now applied. We’re not trying to create popcorn AI solutions all over the place. We’re trying to transform our business processes. In some cases, we’re doing good old process improvement, lean process improvement, eliminating waste, not necessarily a technology play. In other places, we’re applying technology that’s helping to lift us up and accelerate value by embedding it into the way work gets done, with a little bit of burning the boats behind you. You’re not able to do it the old way. You’ve got to use the tools. You’ve got to use the technology, because it’s the best-known way of doing it. The technology becomes part of the standard work.</p>



<p class="wp-block-paragraph">That’s why one of the biggest lessons in scaling AI is that success starts with the core fundamentals and understanding the problem you’re trying to solve. It’s critical to test and validate AI solutions before they are deployed at scale to ensure they improve how work gets done and become embedded in our workflows. If you do not have strong standard work and transparent and reliable data in place, it becomes difficult to move beyond pilot stage and create repeatable value at scale.</p>



<p class="wp-block-paragraph"><strong>Every day brings a new AI announcement, new model, or new prediction about the future. How do you separate what is truly meaningful from what is simply noise, and what advice would you give other leaders trying to do the same?</strong></p>



<p class="wp-block-paragraph">First and foremost is starting with the problem being solved, not the solution. If you’ve got a hammer that you want to use, everything starts looking like a nail. The most effective use of AI begins with an understanding of the problem that needs to be solved, then determining whether AI is the right tool to address it.</p>



<p class="wp-block-paragraph">As far as dealing with distractions, and there are a lot of them right now, it’s important to try a lot of things, but very quickly, and then make decisions on which are the bets you want to make and spend more time and more money on and which are the ones you want to pivot away from. We spend a lot of time doing quick experiments with technology and then having the courage to stop something when it’s not working.</p>



<p class="wp-block-paragraph"><strong>What excites you most about the future intersection of AI, engineering, manufacturing, and aerospace? And what should CIOs be doing today to prepare for that future?</strong></p>



<p class="wp-block-paragraph">Across aviation, AI is already helping to enhance safety, support more efficient operations, strengthen the resilience of global fleets, and improve the overall passenger experience. That includes GE Aerospace. These benefits come from investing not only in technology, but also in people, capacity, and trusted partnerships. </p>



<p class="wp-block-paragraph">They also depend on building mature, fully connected data threads through manufacturing and services that will drive higher value across our operations. The challenge will be ensuring that we enable this data thread across our operations to support AI solutions that will be developed and deployed.</p>



<p class="wp-block-paragraph">The most important thing is to understand that the role of digital technology and information technology is fundamentally going to change. When I came out of university, the only people that knew how to do software coding were computer scientists or information systems majors. We used to frown upon shadow IT, but the reality is, now everyone coming out of college knows how to do some level of software development, and AI tools are only going to make that easier.</p>



<p class="wp-block-paragraph">What CIOs need to start doing today is prepare for the future. The big questions they need to answer: How are they going to make sure they’ve got the platforms and the data set up in a way to serve a workforce that is capable of doing true citizen development, able to develop their own applications, their own solutions? How do you govern that from a data perspective, from a data privacy perspective, from a cybersecurity perspective, while not stifling but enabling the innovation of all those smart people that we’re hiring?</p>



<p class="wp-block-paragraph"><em>While many organizations search for shortcuts to AI success, GE Aerospace’s disciplined investment in data, analytics, talent, and operational excellence sets the company apart. Burns’ experience offers a clear lesson for CIOs: Creating the greatest value from AI requires building the capabilities, culture, and foundations that allow AI to amplify what the organization already does exceptionally well. For more from his leadership playbook, </em><a href="https://linktr.ee/techwhisperers"><em>tune in to the Tech Whisperers</em></a><em>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 1,87ms -->